Done! See below:
ComboFix 09-08-22.06 - Mike 08/24/2009 11:01.3.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1534.834 [GMT -7:00]
Running from: c:\documents and settings\Mike\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mike\Desktop\CFScript.txt
AV: Shaw Secure 8.02 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: Shaw Secure 8.02 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Mike\Application Data\Azureus
c:\documents and settings\Mike\Application Data\Azureus\.certs
c:\documents and settings\Mike\Application Data\Azureus\.keystore
c:\documents and settings\Mike\Application Data\Azureus\.lock
c:\documents and settings\Mike\Application Data\Azureus\active\357FAA07416C3A1BC7E81161EBAC508B9074A2EC.dat
c:\documents and settings\Mike\Application Data\Azureus\active\357FAA07416C3A1BC7E81161EBAC508B9074A2EC.dat.bak
c:\documents and settings\Mike\Application Data\Azureus\active\39EF7E66DF9F549470DACB3C151BCCB111458DB1.dat
c:\documents and settings\Mike\Application Data\Azureus\active\39EF7E66DF9F549470DACB3C151BCCB111458DB1.dat.bak
c:\documents and settings\Mike\Application Data\Azureus\active\5AE4C0869F0D1A2EA69AF2DC9B14619D8D8FE8DF.dat
c:\documents and settings\Mike\Application Data\Azureus\active\5AE4C0869F0D1A2EA69AF2DC9B14619D8D8FE8DF.dat.bak
c:\documents and settings\Mike\Application Data\Azureus\active\8131789773F37A2BD33171CC9147E591ACACACA5.dat
c:\documents and settings\Mike\Application Data\Azureus\active\8131789773F37A2BD33171CC9147E591ACACACA5.dat.bak
c:\documents and settings\Mike\Application Data\Azureus\active\9617D529A813DE113853F0F3ED68F10D726EE7DE.dat
c:\documents and settings\Mike\Application Data\Azureus\active\9617D529A813DE113853F0F3ED68F10D726EE7DE.dat.bak
c:\documents and settings\Mike\Application Data\Azureus\active\9A275B34D27DA30ED291C4E0A9CCE5C20CC1590F.dat
c:\documents and settings\Mike\Application Data\Azureus\active\9A275B34D27DA30ED291C4E0A9CCE5C20CC1590F.dat.bak
c:\documents and settings\Mike\Application Data\Azureus\active\AC99D51AD51D88FC966D5182ECA06BEA8560628A.dat
c:\documents and settings\Mike\Application Data\Azureus\active\AC99D51AD51D88FC966D5182ECA06BEA8560628A.dat.bak
c:\documents and settings\Mike\Application Data\Azureus\active\cache.dat
c:\documents and settings\Mike\Application Data\Azureus\active\DA6474FAD66231716EAD138F1AF40AAFA8CC36E1.dat
c:\documents and settings\Mike\Application Data\Azureus\active\DA6474FAD66231716EAD138F1AF40AAFA8CC36E1.dat.bak
c:\documents and settings\Mike\Application Data\Azureus\azureus.config
c:\documents and settings\Mike\Application Data\Azureus\azureus.config.bak
c:\documents and settings\Mike\Application Data\Azureus\azureus.statistics
c:\documents and settings\Mike\Application Data\Azureus\azureus.statistics.bak
c:\documents and settings\Mike\Application Data\Azureus\banips.config
c:\documents and settings\Mike\Application Data\Azureus\banips.config.bak
c:\documents and settings\Mike\Application Data\Azureus\dht\addresses.dat
c:\documents and settings\Mike\Application Data\Azureus\dht\block.dat
c:\documents and settings\Mike\Application Data\Azureus\dht\contacts.dat
c:\documents and settings\Mike\Application Data\Azureus\dht\diverse.dat
c:\documents and settings\Mike\Application Data\Azureus\dht\general.dat
c:\documents and settings\Mike\Application Data\Azureus\dht\version.dat
c:\documents and settings\Mike\Application Data\Azureus\downloads.config
c:\documents and settings\Mike\Application Data\Azureus\downloads.config.bak
c:\documents and settings\Mike\Application Data\Azureus\filters.config
c:\documents and settings\Mike\Application Data\Azureus\friends.config
c:\documents and settings\Mike\Application Data\Azureus\friends.config.bak
c:\documents and settings\Mike\Application Data\Azureus\ipfilter.cache
c:\documents and settings\Mike\Application Data\Azureus\logs\alerts_1.log
c:\documents and settings\Mike\Application Data\Azureus\logs\AutoSpeed_1.log
c:\documents and settings\Mike\Application Data\Azureus\logs\AutoSpeed_2.log
c:\documents and settings\Mike\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
c:\documents and settings\Mike\Application Data\Azureus\logs\AutoSpeedSearchHistory_2.log
c:\documents and settings\Mike\Application Data\Azureus\logs\clientid_1.log
c:\documents and settings\Mike\Application Data\Azureus\logs\debug_1.log
c:\documents and settings\Mike\Application Data\Azureus\logs\debug_2.log
c:\documents and settings\Mike\Application Data\Azureus\logs\Friends_1.log
c:\documents and settings\Mike\Application Data\Azureus\logs\NetStatus_1.log
c:\documents and settings\Mike\Application Data\Azureus\logs\seltrace_1.log
c:\documents and settings\Mike\Application Data\Azureus\logs\seltrace_2.log
c:\documents and settings\Mike\Application Data\Azureus\logs\SpeedMan_1.log
c:\documents and settings\Mike\Application Data\Azureus\logs\SpeedMan_2.log
c:\documents and settings\Mike\Application Data\Azureus\logs\thread_1.log
c:\documents and settings\Mike\Application Data\Azureus\logs\thread_2.log
c:\documents and settings\Mike\Application Data\Azureus\net\pm_6327.dat
c:\documents and settings\Mike\Application Data\Azureus\net\pm_default.dat
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.7.jar
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.7.zip
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.1.jar
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.1.zip
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.17.jar
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.17.zip
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.2.jar
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.2.zip
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\cd.dat
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\plugin.properties
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.1.7
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.1
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.17
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.2
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\upnp_trace1.log
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\upnp_trace2.log
c:\documents and settings\Mike\Application Data\Azureus\plugins\azupnpav\upnp_trace3.log
c:\documents and settings\Mike\Application Data\Azureus\tables.config
c:\documents and settings\Mike\Application Data\Azureus\tables.config.bak
c:\documents and settings\Mike\Application Data\Azureus\tmp\AZU28785.tmp
c:\documents and settings\Mike\Application Data\Azureus\tmp\AZU28786.tmp
c:\documents and settings\Mike\Application Data\Azureus\tmp\AZU28787.tmp
c:\documents and settings\Mike\Application Data\Azureus\tmp\AZU28788.tmp
c:\documents and settings\Mike\Application Data\Azureus\tmp\AZU28789.tmp
c:\documents and settings\Mike\Application Data\Azureus\tmp\AZU28790.tmp
c:\documents and settings\Mike\Application Data\Azureus\tmp\AZU28791.tmp
c:\documents and settings\Mike\Application Data\Azureus\tmp\AZU28792.tmp
c:\documents and settings\Mike\Application Data\Azureus\tmp\AZU28793.tmp
c:\documents and settings\Mike\Application Data\Azureus\tmp\speedTestTorrent.torrent
c:\documents and settings\Mike\Application Data\Azureus\tracker.config
c:\documents and settings\Mike\Application Data\Azureus\tracker.config.bak
c:\documents and settings\Mike\Application Data\Azureus\update.log
c:\documents and settings\Mike\Application Data\Azureus\update.properties
c:\documents and settings\Mike\Application Data\Azureus\upnp_trace1.log
c:\documents and settings\Mike\Application Data\Azureus\upnp_trace2.log
c:\documents and settings\Mike\Application Data\Azureus\upnp_trace3.log
c:\documents and settings\Mike\Application Data\Azureus\upnp_trace4.log
c:\program files\Azureus
c:\program files\Azureus\az_error.log
c:\program files\Azureus\az_output.log
c:\program files\Azureus\AzureusUpdater.exe
c:\program files\Azureus\msvcr71.dll
c:\program files\Azureus\plugins\azplugins\azplugins_1.9.jar
c:\program files\Azureus\plugins\azplugins\azplugins_2.0.jar
c:\program files\Azureus\plugins\azplugins\azplugins_2.1.1.jar
c:\program files\Azureus\plugins\azplugins\azplugins_2.1.4.jar
c:\program files\Azureus\plugins\azrating\azrating_1.3.1.jar
c:\program files\Azureus\plugins\azrating\azrating_1.3.jar
c:\program files\Azureus\plugins\azupdater\azupdater_1.8.5.zip
c:\program files\Azureus\plugins\azupdater\azupdater_1.8.8.zip
c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.3.jar
c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.5.jar
c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.8.jar
c:\program files\Azureus\plugins\azupdater\plugin.properties
c:\program files\Azureus\plugins\azupdater\plugin.properties_1.8.5
c:\program files\Azureus\plugins\azupdater\plugin.properties_1.8.8
c:\program files\Azureus\plugins\azupdater\Updater.jar
c:\program files\Azureus\plugins\azupdater\Updater.jar.bak
c:\program files\Azureus\swt-awt-win32-3232.dll
c:\program files\Azureus\swt-gdip-win32-3232.dll
c:\program files\Azureus\swt-wgl-win32-3232.dll
c:\program files\Azureus\swt-win32-3232.dll
c:\program files\Azureus\Uninstall.exe
c:\program files\ymlv
c:\program files\ymlv\SmartMenuXP.dll
c:\program files\ymlv\SmartMenuXP.ocx
c:\program files\ymlv\SmartNetButton.ocx
c:\program files\ymlv\SmartSubClass.dll
c:\program files\ymlv\SSubTmr6.dll
c:\program files\ymlv\vbalSGrid6.ocx
.
((((((((((((((((((((((((( Files Created from 2009-07-24 to 2009-08-24 )))))))))))))))))))))))))))))))
.
2009-08-24 06:46 . 2009-08-24 06:45 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-24 06:44 . 2009-08-24 06:44 -------- d-----w- c:\windows\LastGood
2009-08-24 04:59 . 2009-08-24 04:59 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-08-23 08:11 . 2009-08-23 08:11 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2009-08-23 08:10 . 2009-08-23 08:10 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-23 08:10 . 2009-08-23 08:10 -------- d-----w- c:\program files\MSBuild
2009-08-23 08:10 . 2009-08-23 08:10 -------- d-----w- c:\program files\Reference Assemblies
2009-08-23 08:09 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-23 08:09 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-23 08:09 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-23 08:09 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-23 08:09 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-23 08:09 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-23 08:09 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-23 08:08 . 2009-08-23 08:28 -------- d-----w- c:\windows\SxsCaPendDel
2009-08-23 08:00 . 2009-08-23 08:00 -------- d-sh--w- c:\documents and settings\postgres\IETldCache
2009-08-12 14:04 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-08-11 22:03 . 2009-08-12 04:43 20842528 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-08-11 19:44 . 2009-08-11 20:05 -------- d-----w- C:\pebuilder3110a
2009-08-10 17:31 . 2009-08-10 17:31 -------- d-----w- c:\program files\Trend Micro
2009-08-10 17:30 . 2009-08-10 17:30 -------- d-----w- C:\ERDNT
2009-08-10 17:30 . 2009-08-10 17:30 -------- d-----w- c:\program files\ERUNT
2009-08-09 17:31 . 2009-08-09 17:31 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-08-08 22:39 . 2009-08-08 22:39 -------- d-----w- c:\program files\AVG
2009-08-08 07:04 . 2009-08-08 07:04 -------- d-----w- c:\windows\McAfee.com
2009-08-08 04:06 . 2009-08-08 04:07 -------- d-----w- c:\windows\BDOSCAN8
2009-08-08 03:11 . 2009-08-08 03:11 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-05 09:01 . 2009-08-05 09:01 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-31 05:46 . 2009-07-31 05:46 -------- d-----w- c:\documents and settings\Mike\Application Data\PKWARE
2009-07-31 05:46 . 2009-07-31 05:46 -------- d-----w- c:\documents and settings\All Users\Application Data\PKWARE
2009-07-31 05:45 . 2009-07-31 05:45 -------- d-----w- c:\program files\PKWARE
2009-07-31 05:45 . 2009-07-31 05:45 -------- d-----w- c:\program files\Common Files\PKWARE
2009-07-29 12:49 . 2009-07-03 17:09 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll
2009-07-29 12:49 . 2009-07-03 17:09 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-27 18:16 . 2009-07-27 18:16 -------- d-----w- c:\documents and settings\Mike\Local Settings\Application Data\Yahoo
2009-07-27 18:15 . 2009-07-27 18:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-07-27 18:15 . 2009-07-27 18:15 -------- d-----w- c:\documents and settings\Mike\Application Data\Yahoo!
2009-07-27 18:14 . 2009-05-27 02:50 607472 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-24 14:09 . 2005-01-07 05:11 -------- d-----w- c:\program files\Shaw Secure
2009-08-24 06:45 . 2004-10-09 11:31 -------- d-----w- c:\program files\Java
2009-08-24 06:10 . 2004-10-16 15:36 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-12 04:43 . 2009-08-11 22:03 245324 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-10 16:59 . 2008-10-03 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\EnterNHelp
2009-08-10 16:59 . 2008-10-03 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Guitar
2009-08-10 16:59 . 2008-10-03 23:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Hybrid Morph
2009-08-10 16:59 . 2008-10-03 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Ultima_T15
2009-08-09 23:28 . 2008-06-08 02:35 -------- d-----w- c:\documents and settings\Mike\Application Data\Vso
2009-08-09 17:42 . 2004-10-18 01:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-09 07:11 . 2004-10-18 01:49 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-07 22:51 . 2004-10-17 00:00 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-08-05 09:01 . 2004-08-04 10:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 22:15 . 2009-03-18 06:44 -------- d-----w- c:\program files\bwin
2009-07-27 18:15 . 2008-09-18 04:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-07-27 18:15 . 2008-09-18 04:00 -------- d-----w- c:\program files\Yahoo!
2009-07-24 22:25 . 2004-10-16 22:16 -------- d-----w- c:\program files\Google
2009-07-19 21:05 . 2004-10-09 11:32 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-17 19:01 . 2004-08-04 10:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 06:43 . 2004-08-04 10:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 02:33 . 2009-07-14 01:38 33920 ----a-w- c:\windows\system32\drivers\fsbts.sys
2009-07-14 01:38 . 2006-04-01 20:00 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2009-07-14 01:37 . 2007-06-27 05:08 -------- d-----w- c:\documents and settings\All Users\Application Data\fssg
2009-07-12 22:37 . 2006-04-27 05:51 -------- d-----w- c:\program files\Poker Tracker V2
2009-07-11 06:32 . 2007-09-01 18:07 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-09 22:20 . 2009-07-03 20:13 -------- d-----w- c:\documents and settings\Mike\Application Data\postgresql
2009-07-07 22:05 . 2009-07-01 08:09 -------- d-----w- c:\program files\PostgreSQL
2009-07-07 05:23 . 2009-07-07 05:23 -------- d-----w- c:\program files\PokerTracker 3
2009-07-05 22:28 . 2009-07-05 22:28 -------- d-----w- c:\documents and settings\Mike\Application Data\GetRightToGo
2009-07-05 21:05 . 2008-12-22 22:17 -------- d-----w- c:\documents and settings\Mike\Application Data\Microsoft Games
2009-07-03 17:09 . 2004-08-04 10:00 915456 ------w- c:\windows\system32\wininet.dll
2009-07-02 09:09 . 2009-07-02 09:09 -------- d-----w- c:\program files\psqlODBC
2009-06-24 04:50 . 2008-10-03 23:05 57344 ----a-r- c:\documents and settings\Mike\Application Data\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
2009-06-24 04:41 . 2008-10-03 23:06 49152 ----a-r- c:\documents and settings\Mike\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
2009-06-24 04:40 . 2008-10-04 00:07 335872 ----a-r- c:\documents and settings\Mike\Application Data\Microsoft\Installer\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}\ARPPRODUCTICON.exe
2009-06-24 04:36 . 2005-04-18 01:45 106496 ----a-w- c:\windows\system32\ATL71.DLL
2009-06-22 22:23 . 2009-06-22 22:23 239088 ----a-w- c:\documents and settings\Mike\Application Data\Mozilla\plugins\npgoogletalk.dll
2009-06-16 14:36 . 2004-08-04 10:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 10:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2004-08-04 10:00 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 16:19 . 2004-08-04 10:00 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2004-08-04 10:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2008-10-06 08:04 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2004-08-04 10:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2008-06-01 07:49 . 2008-06-01 07:47 24 --sh--w- c:\windows\S3E370B51.tmp
.
((((((((((((((((((((((((((((( SnapShot@2009-08-24_05.47.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-24 06:46 . 2009-08-24 06:46 16384 c:\windows\temp\Perflib_Perfdata_dc8.dat
+ 2009-08-24 06:46 . 2009-08-24 06:45 149280 c:\windows\SYSTEM32\javaws.exe
+ 2009-08-24 06:46 . 2009-08-24 06:45 145184 c:\windows\SYSTEM32\javaw.exe
+ 2009-08-24 06:46 . 2009-08-24 06:45 145184 c:\windows\SYSTEM32\java.exe
+ 2009-01-18 23:05 . 2009-01-18 23:05 675840 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\JP2KLib.dll
+ 2009-08-24 06:45 . 2009-08-24 06:45 1757696 c:\windows\Installer\356cf.msi
+ 2009-08-24 06:12 . 2009-08-24 06:12 1697792 c:\windows\Installer\142921.msp
+ 2009-08-24 06:11 . 2009-08-24 06:11 6653952 c:\windows\Installer\142913.msp
+ 2009-08-24 06:11 . 2009-08-24 06:11 3938816 c:\windows\Installer\1428ef.msi
+ 2008-12-18 23:48 . 2008-12-18 23:48 3645440 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\authplay.dll
+ 2009-02-27 23:37 . 2009-02-27 23:37 20403568 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\AcroRd32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-07 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-03-23 135168]
"CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-15 196608]
"ZSSnp211"="c:\windows\ZSSnp211.exe" [2007-04-06 57344]
"Domino"="c:\windows\Domino.exe" [2006-08-18 49152]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 169984]
"dlcgmon.exe"="c:\program files\Dell AIO 810\dlcgmon.exe" [2005-10-21 425984]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2008-12-16 479232]
"F-Secure Manager"="c:\program files\Shaw Secure\Common\FSM32.EXE" [2009-02-19 182936]
"F-Secure TNB"="c:\program files\Shaw Secure\FSGUI\TNBUtil.exe" [2009-02-19 957024]
"PKWARE Certificate Proxy Client"="c:\progra~1\PKWARE\PKZIPW\pkpcsr.exe" [2009-02-05 2237776]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-24 149280]
"P17Helper"="P17.dll" - c:\windows\SYSTEM32\P17.dll [2004-06-10 60928]
"WD Button Manager"="WDBtnMgr.exe" - c:\windows\SYSTEM32\WDBtnMgr.exe [2007-10-06 364544]
c:\documents and settings\Mike\Start Menu\Programs\Startup\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2008-12-16 479232]
Shortcut to TASKMGR.lnk - c:\windows\SYSTEM32\TASKMGR.EXE [2004-8-4 135680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-01 22:41 10536 ----a-w- c:\program files\Citrix\GoToAssist\516\g2awinlogon.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ImageMixer for HDD Camcorder.lnk]
backup=c:\windows\pss\ImageMixer for HDD Camcorder.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SecureZIP Attachments Status.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SecureZIP Attachments Status.lnk
backup=c:\windows\pss\SecureZIP Attachments Status.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WD Backup Monitor.lnk]
backup=c:\windows\pss\WD Backup Monitor.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Valve\\Steam\\Steam.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\m@hotmail.com\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\m@hotmail.com\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\Roger Wilco\\roger.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbTray.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\xmltv.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Documents and Settings\\Mike\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Mike\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
R0 fsbts;fsbts;c:\windows\SYSTEM32\DRIVERS\fsbts.sys [7/13/2009 6:38 PM 33920]
R0 FSFW;F-Secure Firewall Driver;c:\windows\SYSTEM32\DRIVERS\fsdfw.sys [7/13/2009 6:38 PM 79872]
R0 IABFilt;Iomega Snapshot Volume Filter;c:\windows\SYSTEM32\DRIVERS\IABFilt.sys [3/3/2005 1:23 PM 23040]
R0 pavboot;pavboot;c:\windows\SYSTEM32\DRIVERS\pavboot.sys [11/1/2008 8:08 PM 28544]
R2 postgresql-8.4;PostgreSQL Server 8.4;C:/Program Files/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N "postgresql-8.4" -D "C:/Program Files/PostgreSQL/8.4/data" -w --> C:/Program Files/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N postgresql-8.4 [?]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Shaw Secure\Anti-Virus\minifilter\fsgk.sys [7/13/2009 6:37 PM 99960]
S2 gupdate;Google Update Service (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S3 FSORSPClient;F-Secure ORSP Client;c:\program files\Shaw Secure\ORSP Client\fsorsp.exe [7/13/2009 6:38 PM 55904]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\SYSTEM32\DRIVERS\w300mgmt.sys [12/28/2005 1:48 PM 87824]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\SYSTEM32\DRIVERS\w300obex.sys [12/28/2005 1:49 PM 85696]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Shaw Secure\Anti-Virus\win2k\fsfilter.sys [7/13/2009 6:37 PM 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Shaw Secure\Anti-Virus\win2k\fsrec.sys [7/13/2009 6:37 PM 25184]
S4 pgsql-8.3;PostgreSQL Database Server 8.3;"c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe" runservice -w -N "pgsql-8.3" -D "c:\program files\PostgreSQL\8.3\data\" --> c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - FSBL
*NewlyCreated* - JAVAQUICKSTARTERSERVICE
*Deregistered* - aujasnkj
*Deregistered* - fsbl
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-24 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\SHAWSE~1\ANTI-V~1\fsav.exe [2009-07-14 11:44]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver
LSP: c:\program files\Shaw Secure\FSPS\program\FSLSP.DLL
Trusted Zone: mda.ca\owa2003
Trusted Zone: musicmatch.com\online
DPF: {1F75C3DC-38E2-4424-A028-217AA4CB43CA} - hxxp://24.85.20.123/adm/NetCamMotionDetect.cab
DPF: {D7208880-9B7A-43E1-AABB-8C888A5704F9} - hxxp://192.168.0.115:1024/NetCamPlayerWeb11gv2.cab
FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\ie55b6jg.default\
FF - plugin: c:\documents and settings\Mike\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Mike\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-24 11:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\postgresql-8.4]
"ImagePath"="C:/Program Files/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"C:/Program Files/PostgreSQL/8.4/data\" -w"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\postgresql-8.4]
"ImagePath"="C:/Program Files/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"C:/Program Files/PostgreSQL/8.4/data\" -w"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|ù•Ôw*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\Ati2evxx.dll
c:\program files\Citrix\GoToAssist\516\G2AWinLogon.dll
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
- - - - - - - > 'lsass.exe'(736)
c:\program files\Shaw Secure\FSPS\program\FSLSP.DLL
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
- - - - - - - > 'csrss.exe'(652)
c:\program files\Shaw Secure\FWES\Program\fsdc32.dll
.
Completion time: 2009-08-24 11:11
ComboFix-quarantined-files.txt 2009-08-24 18:11
ComboFix2.txt 2009-08-24 05:58
ComboFix3.txt 2009-08-10 18:32
Pre-Run: 48,741,085,184 bytes free
Post-Run: 48,774,832,128 bytes free
425 --- E O F --- 2009-08-24 08:16
DDS:
DDS (Ver_09-07-30.01) - NTFSx86
Run by Mike at 11:14:57.89 on Mon 08/24/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1534.849 [GMT -7:00]
AV: Shaw Secure 8.02 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: Shaw Secure 8.02 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Shaw Secure\Anti-Virus\fsgk32st.exe
C:\Program Files\Shaw Secure\Common\FSMA32.EXE
C:\Program Files\Shaw Secure\Anti-Virus\FSGK32.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\Domino.exe
C:\Program Files\Dell AIO 810\dlcgmon.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Shaw Secure\Anti-Virus\fssm32.exe
C:\WINDOWS\system32\dlcgcoms.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Shaw Secure\Common\FSLAUNCH.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Mike\Desktop\Virus Removal Tools\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.ca/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [IAAnotif] c:\program files\intel\intel application accelerator\iaanotif.exe
mRun: [CTSysVol] c:\program files\creative\sound blaster live! 24-bit\surround mixer\CTSysVol.exe /r
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe
mRun: [P17Helper] Rundll32 P17.dll,P17Helper
mRun: [WD Button Manager] WDBtnMgr.exe
mRun: [ZSSnp211] c:\windows\ZSSnp211.exe
mRun: [Domino] c:\windows\Domino.exe
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
mRun: [dlcgmon.exe] "c:\program files\dell aio 810\dlcgmon.exe"
mRun: [Nikon Transfer Monitor] c:\program files\common files\nikon\monitor\NkMonitor.exe
mRun: [F-Secure Manager] "c:\program files\shaw secure\common\FSM32.EXE" /splash
mRun: [F-Secure TNB] "c:\program files\shaw secure\fsgui\TNBUtil.exe" /CHECKALL /WAITFORSW
mRun: [PKWARE Certificate Proxy Client] c:\progra~1\pkware\pkzipw\pkpcsr.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\mike\startm~1\programs\startup\nikonm~1.lnk - c:\program files\common files\nikon\monitor\NkMonitor.exe
StartupFolder: c:\docume~1\mike\startm~1\programs\startup\shortc~1.lnk - c:\windows\system32\TASKMGR.EXE
IE: Add to Google Photos Screensa&ver
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {200DB664-75B5-47c0-8B45-A44ACCF73C00} - {D68926FD-18FD-4B0E-A1C7-917D13FAB760} - c:\program files\shaw secure\fspc\fspcmsie.dll
IE: {200DB664-75B5-47c0-8B45-A44ACCF73F01} - {D68926FD-18FD-4B0E-A1C7-917D13FAB760} - c:\program files\shaw secure\fspc\fspcmsie.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\program files\shaw secure\fsps\program\FSLSP.DLL
Trusted Zone: mda.ca\owa2003
Trusted Zone: musicmatch.com\online
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1F75C3DC-38E2-4424-A028-217AA4CB43CA} - hxxp://24.85.20.123/adm/NetCamMotionDetect.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} - hxxp://chat.yahoo.com/cab/yuplapp.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - hxxp://www.pandasoftware.com/activescan/as5free/asinst.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://shawsecure.ca/virusscanner/fscax.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D7208880-9B7A-43E1-AABB-8C888A5704F9} - hxxp://192.168.0.115:1024/NetCamPlayerWeb11gv2.cab
DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} - hxxp://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?323
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5702/mcfscan.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\516\G2AWinLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\mike\applic~1\mozilla\firefox\profiles\ie55b6jg.default\
FF - plugin: c:\documents and settings\mike\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\mike\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2009-7-13 33920]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2009-7-13 79872]
R0 IABFilt;Iomega Snapshot Volume Filter;c:\windows\system32\drivers\IABFilt.sys [2005-3-3 23040]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-1 28544]
R2 F-Secure Gatekeeper Handler Starter;FSGKHS;c:\program files\shaw secure\anti-virus\fsgk32st.exe [2009-7-13 215648]
R2 postgresql-8.4;PostgreSQL Server 8.4;C:/Program Files/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N "postgresql-8.4" -D "C:/Program Files/PostgreSQL/8.4/data" -w --> C:/Program Files/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N postgresql-8.4 [?]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\shaw secure\anti-virus\minifilter\fsgk.sys [2009-7-13 99960]
S2 gupdate;Google Update Service (gupdate);"c:\program files\google\update\googleupdate.exe" /svc --> c:\program files\google\update\GoogleUpdate.exe [?]
S3 FSORSPClient;F-Secure ORSP Client;c:\program files\shaw secure\orsp client\fsorsp.exe [2009-7-13 55904]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [2005-12-28 87824]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [2005-12-28 85696]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\shaw secure\anti-virus\win2k\fsfilter.sys [2009-7-13 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\shaw secure\anti-virus\win2k\fsrec.sys [2009-7-13 25184]
S4 pgsql-8.3;PostgreSQL Database Server 8.3;"c:\program files\postgresql\8.3\bin\pg_ctl.exe" runservice -w -n "pgsql-8.3" -d "c:\program files\postgresql\8.3\data\" --> c:\program files\postgresql\8.3\bin\pg_ctl.exe [?]
=============== Created Last 30 ================
2009-08-24 11:00 <DIR> --ds---- C:\ComboFix
2009-08-23 23:46 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-23 23:46 73,728 a------- c:\windows\system32\javacpl.cpl
2009-08-23 22:20 <DIR> a-dshr-- C:\cmdcons
2009-08-23 22:18 229,376 a------- c:\windows\PEV.exe
2009-08-23 22:18 161,792 a------- c:\windows\SWREG.exe
2009-08-23 22:18 98,816 a------- c:\windows\sed.exe
2009-08-23 21:59 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-08-23 21:55 1,089,593 -------- c:\windows\system32\dllcache\ntprint.cat
2009-08-23 01:10 <DIR> --d----- c:\windows\system32\XPSViewer
2009-08-23 01:09 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-08-23 01:09 1,676,288 -------- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-23 01:09 597,504 -------- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-23 01:09 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-08-23 01:09 575,488 -------- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-23 01:09 117,760 -------- c:\windows\system32\prntvpt.dll
2009-08-23 01:09 89,088 -------- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-23 01:08 <DIR> --d----- c:\windows\SxsCaPendDel
2009-08-12 07:04 128,512 -------- c:\windows\system32\dllcache\dhtmled.ocx
2009-08-12 07:04 1,315,328 -------- c:\windows\system32\dllcache\msoe.dll
2009-08-11 15:03 20,842,528 a--sh--- c:\windows\system32\drivers\fidbox.dat
2009-08-11 15:03 245,324 a--sh--- c:\windows\system32\drivers\fidbox.idx
2009-08-11 12:44 <DIR> --d----- C:\pebuilder3110a
2009-08-10 11:30 <DIR> --d----- c:\windows\system32\dllcache\cache
2009-08-10 10:31 <DIR> --d----- c:\program files\Trend Micro
2009-08-09 14:46 22,189 a------- C:\archpreview.htm
2009-08-08 15:39 <DIR> --d----- c:\program files\AVG
2009-08-08 00:04 <DIR> --d----- c:\windows\McAfee.com
2009-08-07 16:35 1,110,399 a------- c:\windows\system32\UACxwdyuranrs.db
2009-08-05 02:01 204,800 -------- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-30 22:46 <DIR> --d----- c:\docume~1\mike\applic~1\PKWARE
2009-07-30 22:46 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PKWARE
2009-07-30 22:45 <DIR> --d----- c:\program files\PKWARE
2009-07-30 22:45 <DIR> --d----- c:\program files\common files\PKWARE
2009-07-29 05:49 594,432 -------- c:\windows\system32\dllcache\msfeeds.dll
2009-07-29 05:49 55,296 -------- c:\windows\system32\dllcache\msfeedsbs.dll
==================== Find3M ====================
2009-08-05 02:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-19 18:48 11,067,392 -------- c:\windows\system32\dllcache\ieframe.dll
2009-07-19 06:18 5,937,152 a------- c:\windows\system32\dllcache\cache\mshtml.dll
2009-07-19 06:18 5,937,152 -------- c:\windows\system32\dllcache\mshtml.dll
2009-07-17 12:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-17 12:01 58,880 -------- c:\windows\system32\dllcache\atl.dll
2009-07-13 23:43 10,841,088 a------- c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 286,208 -------- c:\windows\system32\dllcache\wmpdxm.dll
2009-07-13 19:33 33,920 a------- c:\windows\system32\drivers\fsbts.sys
2009-07-03 10:09 915,456 a------- c:\windows\system32\dllcache\cache\wininet.dll
2009-07-03 10:09 915,456 -------- c:\windows\system32\wininet.dll
2009-07-03 10:09 915,456 -------- c:\windows\system32\dllcache\wininet.dll
2009-07-03 10:09 12,800 -------- c:\windows\system32\dllcache\xpshims.dll
2009-07-03 10:09 1,208,832 -------- c:\windows\system32\dllcache\urlmon.dll
2009-07-03 10:09 206,848 -------- c:\windows\system32\dllcache\occache.dll
2009-07-03 10:09 1,985,536 -------- c:\windows\system32\dllcache\iertutil.dll
2009-07-03 10:09 25,600 -------- c:\windows\system32\dllcache\jsproxy.dll
2009-07-03 10:09 246,272 -------- c:\windows\system32\dllcache\ieproxy.dll
2009-07-03 10:09 184,320 -------- c:\windows\system32\dllcache\iepeers.dll
2009-07-03 10:09 386,048 -------- c:\windows\system32\dllcache\iedkcs32.dll
2009-07-03 04:01 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-06-23 21:36 106,496 a------- c:\windows\system32\ATL71.DLL
2009-06-16 07:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 07:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-16 07:36 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
2009-06-16 07:36 81,920 -------- c:\windows\system32\dllcache\fontsub.dll
2009-06-12 05:31 76,288 a------- c:\windows\system32\telnet.exe
2009-06-12 05:31 76,288 -------- c:\windows\system32\dllcache\telnet.exe
2009-06-10 09:19 2,066,432 a------- c:\windows\system32\mstscax.dll
2009-06-10 09:19 2,066,432 -------- c:\windows\system32\dllcache\mstscax.dll
2009-06-10 07:13 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-10 07:13 84,992 -------- c:\windows\system32\dllcache\avifil32.dll
2009-06-09 23:14 132,096 a------- c:\windows\system32\wkssvc.dll
2009-06-09 23:14 132,096 -------- c:\windows\system32\dllcache\wkssvc.dll
2009-06-03 12:09 1,291,264 a------- c:\windows\system32\quartz.dll
2009-06-03 12:09 1,291,264 -------- c:\windows\system32\dllcache\quartz.dll
2008-10-01 15:41 61,224 a------- c:\documents and settings\mike\GoToAssistDownloadHelper.exe
2008-06-07 19:35 47,360 a------- c:\docume~1\mike\applic~1\pcouffin.sys
============= FINISH: 11:15:19.70 ===============