ComboFix 10-09-01.04 - Administrator 09/02/2010 20:37:05.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1387 [GMT -4:00]
Running from: d:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe
Command switches used :: d:\documents and settings\Administrator\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: ThreatFire *On-access scanning enabled* (Updated) {67B2B9A1-25C8-4057-962D-807958FFC9E3}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\documents and settings\All Users\Application Data\Toolbar4
d:\program files\Search Toolbar
.
((((((((((((((((((((((((( Files Created from 2010-08-03 to 2010-09-03 )))))))))))))))))))))))))))))))
.
2010-08-18 14:16 . 2008-02-28 17:26 1414440 ----a-w- d:\windows\system32\ShellManager310E2D762.dll
2010-08-18 04:07 . 2010-08-18 04:07 -------- d-----w- d:\documents and settings\Administrator\Application Data\DVDVideoSoftIEHelpers
2010-08-18 04:05 . 2010-08-18 04:06 -------- d-----w- d:\program files\Common Files\DVDVideoSoft
2010-08-18 04:05 . 2010-08-18 04:05 -------- d-----w- d:\program files\DVDVideoSoft
2010-08-18 01:03 . 2010-08-18 01:03 -------- d-----w- d:\program files\NeroInstall.bak
2010-08-18 01:00 . 2010-08-18 01:00 -------- d-----w- d:\documents and settings\Administrator\Application Data\Nero
2010-08-18 00:50 . 2010-08-18 14:17 -------- d-----w- d:\program files\Common Files\Nero
2010-08-18 00:50 . 2010-08-18 14:17 -------- d-----w- d:\documents and settings\All Users\Application Data\Nero
2010-08-17 13:03 . 2010-08-17 13:03 5125664 ----a-w- d:\documents and settings\Administrator\Application Data\Uniblue\RegistryBooster\_temp\ub.exe
2010-08-15 00:29 . 2010-08-15 00:29 -------- d-----w- d:\program files\Pure Networks
2010-08-15 00:17 . 2010-08-15 00:17 -------- d-----w- d:\program files\WebEx
2010-08-15 00:00 . 2010-08-15 00:00 -------- d-----w- d:\documents and settings\Administrator\Local Settings\Application Data\Help
2010-08-14 22:43 . 2010-08-14 22:43 -------- d-----w- d:\program files\Uniblue
2010-08-14 22:22 . 2010-08-14 22:22 -------- d-----w- d:\documents and settings\Administrator\Application Data\Uniblue
2010-08-14 18:20 . 2010-08-14 18:20 5380 ----a-w- d:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109150000000000000000F01FEC.dll
2010-08-14 18:20 . 2010-08-14 18:20 51 ----a-w- d:\documents and settings\All Users\Application Data\SecTaskMan\icn_000021091A0090400000000000F01FEC.dll
2010-08-14 18:20 . 2010-08-14 18:20 10 ----a-w- d:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109411090400000000000F01FEC.dll
2010-08-14 18:20 . 2010-08-14 18:20 13708 ----a-w- d:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109030000000000000000F01FEC.dll
2010-08-14 18:20 . 2010-08-14 18:20 108 ----a-w- d:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109010090400000000000F01FEC.dll
2010-08-14 18:20 . 2010-08-15 00:09 -------- d-----w- d:\documents and settings\All Users\Application Data\SecTaskMan
2010-08-14 18:20 . 2010-08-18 00:35 -------- d-----w- d:\program files\Security Task Manager
2010-08-10 23:50 . 2010-08-10 23:51 -------- d-----w- d:\documents and settings\Administrator\Application Data\Ashampoo
2010-08-10 23:49 . 2010-08-10 23:50 -------- d-----w- d:\documents and settings\Administrator\Local Settings\Application Data\ashampoo
2010-08-10 23:49 . 2010-08-10 23:49 -------- d-----w- d:\documents and settings\All Users\Application Data\ashampoo
2010-08-10 23:42 . 2010-08-10 23:42 -------- d-----w- d:\program files\uTorrent
2010-08-10 23:42 . 2010-08-22 20:50 -------- d-----w- d:\documents and settings\Administrator\Application Data\uTorrent
2010-08-10 22:48 . 2005-01-19 03:18 323584 ----a-w- d:\windows\system32\FoxImager.dll
2010-08-09 00:44 . 2010-08-09 00:57 -------- d-----w- d:\program files\BitLord
2010-08-08 23:48 . 2010-08-08 23:48 503808 ----a-w- d:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-319bf75d-n\msvcp71.dll
2010-08-08 23:48 . 2010-08-08 23:48 499712 ----a-w- d:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-319bf75d-n\jmc.dll
2010-08-08 23:48 . 2010-08-08 23:48 348160 ----a-w- d:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-319bf75d-n\msvcr71.dll
2010-08-08 23:48 . 2010-08-08 23:48 12800 ----a-w- d:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-13ebcf57-n\decora-d3d.dll
2010-08-08 23:48 . 2010-08-08 23:48 61440 ----a-w- d:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-13ebcf57-n\decora-sse.dll
2010-08-08 20:26 . 2010-04-28 11:44 54760 ----a-w- d:\windows\system32\drivers\fssfltr_tdi.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-02 19:57 . 2010-04-08 02:23 -------- d-----w- d:\program files\Call of Duty 1.5
2010-09-02 19:51 . 2010-04-08 02:39 138376 ----a-w- d:\windows\system32\drivers\PnkBstrK.sys
2010-09-02 19:51 . 2010-04-08 02:38 202448 ----a-w- d:\windows\system32\PnkBstrB.exe
2010-09-01 02:18 . 2007-11-15 23:21 384 ----a-w- d:\windows\system32\DVCStateBkp-{00000005-00000000-00000006-00001102-00000004-20021102}.dat
2010-09-01 02:18 . 2007-11-15 23:21 384 ----a-w- d:\windows\system32\DVCState-{00000005-00000000-00000006-00001102-00000004-20021102}.dat
2010-09-01 00:43 . 2010-04-05 23:20 -------- d-----w- d:\program files\Call of Duty Game of the Year Edition
2010-08-18 18:55 . 2007-11-15 22:15 -------- d-----w- d:\documents and settings\Administrator\Application Data\Xfire
2010-08-18 14:17 . 2007-11-15 22:43 -------- d-----w- d:\program files\Nero
2010-08-18 01:11 . 2009-11-04 01:10 107400 ----a-w- d:\windows\system32\GDIPFONTCACHEV1.DAT
2010-08-15 00:17 . 2010-08-15 00:16 8892928 ----a-w- d:\documents and settings\All Users\Application Data\atscie.msi
2010-08-15 00:08 . 2007-11-14 23:34 -------- d--h--w- d:\program files\InstallShield Installation Information
2010-08-12 21:24 . 2007-11-14 17:25 98304 ----a-w- d:\windows\DUMP55b1.tmp
2010-08-11 07:05 . 2008-09-29 19:00 -------- d-----w- d:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-11 00:26 . 2007-11-15 22:43 -------- d-----w- d:\program files\Common Files\Ahead
2010-08-11 00:20 . 2008-04-19 12:41 -------- d-----w- d:\documents and settings\Administrator\Application Data\Ahead
2010-08-10 21:36 . 2007-11-19 00:46 -------- d-----w- d:\program files\Common Files\Java
2010-08-10 21:35 . 2007-11-19 00:46 -------- d-----w- d:\program files\Java
2010-08-09 11:47 . 2009-02-02 02:17 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2010-08-08 20:26 . 2007-11-15 22:47 -------- d-----w- d:\program files\Windows Live
2010-08-04 00:59 . 2010-04-01 18:00 -------- d-----w- d:\program files\Defraggler
2010-08-03 16:33 . 2009-11-20 04:14 -------- d-----w- d:\program files\CCleaner
2010-08-02 05:46 . 2008-01-06 06:16 -------- d-----w- d:\documents and settings\Administrator\Application Data\LimeWire
2010-08-01 21:22 . 2007-11-15 22:15 -------- d-----w- d:\program files\Xfire
2010-07-30 23:31 . 2009-06-01 18:01 -------- d-----w- d:\program files\LimeWire
2010-07-29 05:08 . 2009-02-02 02:33 -------- d-----w- d:\program files\Safari
2010-07-29 05:06 . 2010-07-29 05:06 72488 ----a-w- d:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.17.8\SetupAdmin.exe
2010-07-28 20:14 . 2008-08-19 01:22 -------- d-----w- d:\program files\McAfee
2010-07-25 18:37 . 2010-07-25 18:37 664 ----a-w- d:\windows\system32\d3d9caps.dat
2010-07-22 03:30 . 2010-03-30 00:46 -------- d-----w- d:\program files\CoD RconTool
2010-07-17 09:00 . 2010-05-12 02:54 423656 ----a-w- d:\windows\system32\deployJava1.dll
2010-07-15 19:18 . 2008-08-19 01:23 120136 ----a-w- d:\windows\system32\drivers\Mpfp.sys
2010-07-09 19:04 . 2010-07-09 19:04 41872 ----a-w- d:\windows\system32\xfcodec.dll
2010-07-09 14:31 . 2010-07-09 14:31 -------- d-----w- d:\documents and settings\Administrator\Application Data\Office Genuine Advantage
2010-06-30 12:31 . 2004-08-04 05:56 149504 ----a-w- d:\windows\system32\schannel.dll
2010-06-28 15:53 . 2010-08-03 22:31 15880 ----a-w- d:\windows\system32\lsdelete.exe
2010-06-28 15:52 . 2009-11-20 16:51 64288 ----a-w- d:\windows\system32\drivers\Lbd.sys
2010-06-24 12:15 . 2004-08-04 05:56 832512 ----a-w- d:\windows\system32\wininet.dll
2010-06-24 12:15 . 2004-08-04 05:56 78336 ----a-w- d:\windows\system32\ieencode.dll
2010-06-24 12:15 . 2004-08-04 05:56 17408 ------w- d:\windows\system32\corpol.dll
2010-06-23 13:44 . 2004-08-04 04:17 1851904 ----a-w- d:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-04 04:14 354304 ----a-w- d:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2004-08-04 05:56 80384 ----a-w- d:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2007-11-14 17:43 744448 ----a-w- d:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2004-08-04 05:56 1172480 ----a-w- d:\windows\system32\msxml3.dll
2008-02-08 01:46 . 2008-02-08 01:46 13624 ----a-w- d:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-02-08 01:46 . 2008-02-08 01:46 87360 ----a-w- d:\program files\mozilla firefox\plugins\CgpCore.dll
2008-02-08 01:46 . 2008-02-08 01:46 91448 ----a-w- d:\program files\mozilla firefox\plugins\confmgr.dll
2008-02-08 01:46 . 2008-02-08 01:46 21824 ----a-w- d:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-02-08 01:46 . 2008-02-08 01:46 206136 ----a-w- d:\program files\mozilla firefox\plugins\ctxmui.dll
2008-02-08 01:46 . 2008-02-08 01:46 31544 ----a-w- d:\program files\mozilla firefox\plugins\icafile.dll
2008-02-08 01:46 . 2008-02-08 01:46 40248 ----a-w- d:\program files\mozilla firefox\plugins\icalogon.dll
2007-03-16 21:27 . 2007-03-16 21:27 479232 ----a-w- d:\program files\mozilla firefox\plugins\msvcm80.dll
2007-03-16 21:27 . 2007-03-16 21:27 548864 ----a-w- d:\program files\mozilla firefox\plugins\msvcp80.dll
2007-03-16 21:27 . 2007-03-16 21:27 626688 ----a-w- d:\program files\mozilla firefox\plugins\msvcr80.dll
2007-07-20 16:47 . 2007-07-20 16:47 981170 ----a-w- d:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-02-08 01:46 . 2008-02-08 01:46 24384 ----a-w- d:\program files\mozilla firefox\plugins\TcpPServ.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-08-17_14.42.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-09-02 19:29 . 2010-09-02 19:29 16384 d:\windows\Temp\Perflib_Perfdata_7e4.dat
+ 2010-09-02 19:30 . 2010-09-02 19:30 16384 d:\windows\Temp\Perflib_Perfdata_29c.dat
- 2007-11-15 23:38 . 2010-08-17 14:31 32768 d:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-15 23:38 . 2010-09-03 00:17 32768 d:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-08-17 17:10 . 2010-09-03 00:17 32768 d:\windows\system32\config\systemprofile\Cookies\index.dat
- 2007-11-15 23:38 . 2010-08-17 14:31 32768 d:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-08-18 04:06 . 2010-08-18 04:06 69632 d:\windows\assembly\GAC_MSIL\Google.GData.YouTube\1.5.0.0__af04a32718ae8833\Google.GData.YouTube.dll
+ 2010-08-18 04:06 . 2010-08-18 04:06 81920 d:\windows\assembly\GAC_MSIL\Google.GData.Extensions\1.5.0.0__0b4c5df2ebf20876\Google.GData.Extensions.dll
+ 2006-03-17 18:49 . 2006-03-17 18:49 368640 d:\windows\system32\TwnLib4.dll
- 2006-03-17 20:49 . 2006-03-17 20:49 368640 d:\windows\system32\twnlib4.dll
+ 2006-03-17 15:45 . 2006-03-17 15:45 802816 d:\windows\system32\imagXRA7.dll
- 2008-07-04 15:23 . 2008-07-04 15:23 802816 d:\windows\system32\imagXRA7.dll
- 2008-07-04 15:23 . 2008-07-04 15:23 258048 d:\windows\system32\imagXR7.dll
+ 2006-03-17 15:45 . 2006-03-17 15:45 258048 d:\windows\system32\imagXR7.dll
+ 2006-03-17 15:45 . 2006-03-17 15:45 497296 d:\windows\system32\imagXpr7.dll
- 2008-07-04 15:23 . 2008-07-04 15:23 497296 d:\windows\system32\imagXpr7.dll
+ 2010-08-18 04:06 . 2010-08-18 04:06 184320 d:\windows\assembly\GAC_MSIL\Google.GData.Client\1.5.0.0__04a59ca9b0273830\Google.GData.Client.dll
+ 2010-08-18 04:05 . 2010-08-18 04:05 726456 d:\windows\assembly\GAC_32\NMSDVDNet\1.0.1007.2002__2ff9184220f553d5\NMSDVDNet.dll
- 2008-07-04 15:23 . 2008-07-04 15:23 1757184 d:\windows\system32\imagX7.dll
+ 2006-03-17 15:45 . 2006-03-17 15:45 1757184 d:\windows\system32\imagX7.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteCenter"="d:\program files\Creative\MediaSource\RemoteControl\RCMan.EXE" [2003-10-08 139264]
"NVIDIA nTune"="d:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"msnmsgr"="d:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"nwiz"="nwiz.exe" [2007-12-05 1626112]
"Zboard"="d:\program files\Ideazon\ZEngine\Zboard.exe" [2007-09-24 57344]
"CTSysVol"="d:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"CTDVDDET"="d:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" [2003-06-18 45056]
"CTHelper"="CTHELPER.EXE" [2003-10-06 24576]
"SBDrvDet"="d:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"UpdReg"="d:\windows\UpdReg.EXE" [2000-05-11 90112]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"mcagent_exe"="d:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"Copperhead"="d:\program files\Razer\Copperhead\razerhid.exe" [2005-11-25 155648]
"SunJavaUpdateSched"="d:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="d:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
d:\documents and settings\Administrator\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - d:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "d:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\h:\0autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\D:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Secunia PSI.lnk]
path=d:\documents and settings\Administrator\Start Menu\Programs\Startup\Secunia PSI.lnk
backup=d:\windows\pss\Secunia PSI.lnkStartup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Rainmeter.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Rainmeter.lnk
backup=d:\windows\pss\Rainmeter.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-02-25 04:36 135664 ----atw- d:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-04-28 19:06 142120 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- d:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-17 02:12 3872080 ----a-w- d:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 01:53 421888 ----a-w- d:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
2009-10-18 01:35 1070984 ----a-w- d:\program files\Trojan Remover\Trjscan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"d:\\Program Files\\Xfire\\xfire.exe"=
"d:\\WINDOWS\\system32\\dlbtcoms.exe"=
"d:\\Program Files\\mIRC\\mirc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"d:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"d:\\WINDOWS\\system32\\PnkBstrA.exe"=
"d:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"d:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"d:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\LimeWire\\LimeWire.exe"=
"d:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"d:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1337:UDP"= 1337:UDP:Dtella
"1338:UDP"= 1338:UDP:Dc++
"67:UDP"= 67:UDP:DHCP Discovery Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 Lbd;Lbd;d:\windows\system32\drivers\Lbd.sys [11/20/2009 12:51 PM 64288]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;d:\program files\McAfee\SiteAdvisor\McSACore.exe [9/29/2008 7:19 PM 93320]
R2 PfDetNT;PfDetNT;d:\windows\system32\drivers\PfModNT.sys [11/15/2007 12:16 PM 15840]
R2 WinDefend;Windows Defender;d:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
R3 UsbFltr;Razer Copperhead Driver;d:\windows\system32\drivers\copperhd.sys [11/15/2007 12:15 AM 11596]
S0 TfFsMon;TfFsMon;d:\windows\system32\drivers\TfFsMon.sys --> d:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;d:\windows\system32\drivers\TfSysMon.sys --> d:\windows\system32\drivers\TfSysMon.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;d:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1352832]
S2 ThreatFire;ThreatFire;d:\program files\ThreatFire\TFService.exe service --> d:\program files\ThreatFire\TFService.exe service [?]
S3 PSI;PSI;d:\windows\system32\drivers\psi_mf.sys [12/10/2008 10:17 AM 7808]
S3 TfNetMon;TfNetMon;\??\d:\windows\system32\drivers\TfNetMon.sys --> d:\windows\system32\drivers\TfNetMon.sys [?]
S3 vaxscsi;vaxscsi;d:\windows\system32\drivers\vaxscsi.sys [9/3/2008 4:45 AM 223128]
S4 sptd;sptd;d:\windows\system32\drivers\sptd.sys [9/3/2008 4:39 AM 642560]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - PNKBSTRK
*Deregistered* - PnkBstrK
.
Contents of the 'Scheduled Tasks' folder
2010-08-20 d:\windows\Tasks\Ad-Aware Update (Weekly).job
- d:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 15:52]
2010-08-14 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-08-24 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-507921405-725345543-500Core.job
- d:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-25 04:36]
2010-09-02 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-507921405-725345543-500UA.job
- d:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-25 04:36]
2010-08-15 d:\windows\Tasks\McDefragTask.job
- d:\progra~1\mcafee\mqc\QcConsol.exe [2008-08-19 16:22]
2010-04-01 d:\windows\Tasks\McQcTask.job
- d:\progra~1\mcafee\mqc\QcConsol.exe [2008-08-19 16:22]
2010-09-02 d:\windows\Tasks\MP Scheduled Scan.job
- d:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
2010-09-02 d:\windows\Tasks\OGALogon.job
- d:\windows\system32\OGAEXEC.exe [2009-08-03 19:07]
2010-09-02 d:\windows\Tasks\RegistryBooster.job
- d:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2010-08-17 13:50]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL =
hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page =
hxxp://www.google.commSearch Bar =
hxxp://us.rd.yahoo.com/customize/ie/def ... earch.htmluInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - d:\documents and settings\Administrator\Application Data\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - d:\documents and settings\Administrator\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm
Trusted Zone: aol.com\free
FF - ProfilePath - d:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\yitqid12.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage -
hxxp://bing.zugo.com/?cfg=2-76-0-1Ha5hFF - prefs.js: keyword.URL -
hxxp://bing.zugo.com/s/?src=FF-Address& ... 0-1Ha5h&q=FF - component: d:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: d:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: d:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
Toolbar-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
HKLM-Run-NBKeyScan - d:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-09-02 20:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1852)
d:\windows\system32\WININET.dll
d:\program files\Xfire\xfire_toucan_43094.dll
d:\windows\system32\ieframe.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-09-02 20:48:33
ComboFix-quarantined-files.txt 2010-09-03 00:48
ComboFix2.txt 2010-08-17 14:45
ComboFix3.txt 2008-11-12 02:04
ComboFix4.txt 2008-11-11 17:14
Pre-Run: 88,511,651,840 bytes free
Post-Run: 93,819,318,272 bytes free
- - End Of File - - 03A3D2CEA21917C605EACA437D76237E