.
c:\documents and settings\All Users\Application Data\_VOIDmfeklnmal.dll
c:\documents and settings\All Users\Favorites\_favdata.dat
c:\documents and settings\Compaq_Owner\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\documents and settings\Compaq_Owner\rundll32.exe
c:\program files\Internet Explorer\js.mui
c:\program files\Internet Explorer\wmpscfgs.exe
C:\Thumbs.db
c:\windows\_VOIDxtynticvtg
c:\windows\_VOIDxtynticvtg\_VOIDd.sys
c:\windows\cdmxtras
c:\windows\cdmxtras\uninst.exe
c:\windows\Fonts\mlog
c:\windows\system\hpsysdrv .exe
c:\windows\system32\_VOIDcqnyxecbtk.dll
c:\windows\system32\_VOIDknkrheovmy.dat
c:\windows\system32\_VOIDodlttfruyl.dll
c:\windows\system32\_VOIDukebomeulq.dll
c:\windows\system32\1244273.exe
c:\windows\system32\1871561.exe
c:\windows\system32\2681345.exe
c:\windows\system32\2849.exe
c:\windows\system32\4942286.exe
c:\windows\system32\5408899.exe
c:\windows\system32\5444865.exe
c:\windows\system32\5907862.exe
c:\windows\system32\7153131.exe
c:\windows\system32\BtwSvc.dll
c:\windows\system32\cache329
c:\windows\system32\cache329\B_329_0_0_106800.htm
c:\windows\system32\cache329\B_329_0_0_107400.htm
c:\windows\system32\cache329\B_329_1_0_449200.gif
c:\windows\system32\cache329\B_329_1_0_449600.gif
c:\windows\system32\cache329\B_329_1_0_454300.gif
c:\windows\system32\cache329\B_329_2_0_105300.htm
c:\windows\system32\cache329\B_329_2_0_106800.htm
c:\windows\system32\cache329\B_329_2_0_107400.htm
c:\windows\system32\cache329\B_329_3_0_106800.htm
c:\windows\system32\cache329\B_329_3_0_107400.htm
c:\windows\system32\cache329\B_329_4_0_111600.htm
c:\windows\system32\cache329\B_329_4_0_152400.htm
c:\windows\system32\cache329\B_329_4_0_155300.htm
c:\windows\system32\cache329\B_329_4_0_164100.htm
c:\windows\system32\cache329\t_B_329_0_0_106800.htm
c:\windows\system32\cache329\t_B_329_0_0_107400.htm
c:\windows\system32\cache329\t_B_329_2_0_105300.htm
c:\windows\system32\cache329\t_B_329_2_0_106800.htm
c:\windows\system32\cache329\t_B_329_2_0_107400.htm
c:\windows\system32\cache329\t_B_329_3_0_106800.htm
c:\windows\system32\cache329\t_B_329_3_0_107400.htm
c:\windows\system32\cache329\t_B_329_4_0_111600.htm
c:\windows\system32\cache329\t_B_329_4_0_152400.htm
c:\windows\system32\cache329\t_B_329_4_0_155300.htm
c:\windows\system32\cache329\t_B_329_4_0_164100.htm
c:\windows\system32\cache329\Thumbs.db
c:\windows\system32\ctfmon .exe
c:\windows\system32\drivers\_VOIDhtkewvkxwo.sys
c:\windows\system32\drivers\UACdiomgpkmduslkwc.sys
c:\windows\system32\FInstall.sys
c:\windows\system32\hxxcyvf.dll
c:\windows\system32\Install.txt
c:\windows\system32\ms.bin
c:\windows\system32\msuqddft.dll
c:\windows\system32\opear.exe
c:\windows\system32\PereSvc.exe
c:\windows\system32\PowerDes.exe
c:\windows\system32\regsvr32.dll
c:\windows\system32\rundll32 .exe
c:\windows\system32\so.bin
c:\windows\system32\Thumbs.db
c:\windows\system32\UACatmusccvgviugxx.log
c:\windows\system32\uactmp.db
c:\windows\system32\UACxckauffxsswbgwj.db
c:\windows\system32\w.exe
c:\windows\TEMP\mta13187.dll
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\userinit.exe
c:\windows\system32\svchost.exe . . . is infected!!
Infected copy of c:\windows\system32\spoolsv.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\spoolsv.exe
Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\explorer.exe
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service__VOIDd.sys
-------\Legacy__VOIDd.sys
-------\Service__VOIDxtynticvtg
-------\Legacy__VOIDxtynticvtg
-------\Legacy_BTWSVC
-------\Legacy_WIZMNICA
-------\Service_BtwSvc
-------\Service_wizmnica
-------\Legacy_peresvc
-------\Service_peresvc
((((((((((((((((((((((((( Files Created from 2010-03-08 to 2010-04-08 )))))))))))))))))))))))))))))))
.
2010-04-08 05:23 . 2010-04-08 05:23 200192 ----a-w- c:\windows\system32\8658519.exe
2010-04-08 05:22 . 2010-04-08 05:22 168651 ----a-w- c:\windows\system32\6684992.exe
2010-04-08 05:16 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2010-04-08 04:34 . 2010-04-08 04:42 -------- d-----w- C:\32788R22FWJFW
2010-04-08 04:30 . 2010-04-08 05:08 -------- d-----w- C:\32788R22FWJFW.2.tmp
2010-04-08 03:11 . 2010-04-08 05:07 -------- d-----w- C:\32788R22FWJFW.1.tmp
2010-04-07 21:29 . 2010-04-08 15:41 36864 ----a-w- c:\windows\system32\d.bin
2010-04-07 19:32 . 2010-04-07 19:32 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\avG
2010-04-07 19:32 . 2010-04-07 19:32 -------- d-----w- c:\documents and settings\All Users\Application Data\avG
2010-04-07 09:44 . 2010-04-07 09:44 -------- d-----w- C:\_OTL
2010-04-07 07:26 . 2010-04-07 07:26 -------- d-----w- c:\program files\Your Protection
2010-04-07 07:16 . 2010-04-07 07:16 991744 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\59CB5BD3040C3AFC3A946845ABB0DDDC\dbf70700.exe
2010-04-07 07:16 . 2010-04-07 07:16 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\59CB5BD3040C3AFC3A946845ABB0DDDC
2010-04-01 14:13 . 2010-04-01 14:13 4076824 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-04-01 14:13 . 2010-04-01 14:13 598296 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgsrmx.dll
2010-04-01 14:13 . 2010-04-01 14:13 459544 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcclix.dll
2010-04-01 14:13 . 2010-04-01 14:13 4250976 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-04-01 14:13 . 2010-04-01 14:13 341272 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgxch32.dll
2010-04-01 14:13 . 2010-04-01 14:13 313112 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglogx.dll
2010-04-01 14:13 . 2010-04-01 14:13 2059544 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-04-01 14:13 . 2010-04-01 14:13 1598744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgssie.dll
2010-04-01 14:13 . 2010-04-01 14:13 1515224 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgwd.dll
2010-04-01 14:13 . 2010-04-01 14:13 1274136 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-04-01 14:13 . 2010-04-01 14:13 1086744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgchsvx.exe
2010-04-01 14:13 . 2010-04-01 14:13 556824 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgchjwx.dll
2010-04-01 14:11 . 2010-04-01 14:11 301336 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgchclx.dll
2010-04-01 14:09 . 2010-04-01 14:09 1035032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-04-01 14:08 . 2010-04-01 14:08 1685784 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-03-31 16:02 . 2010-03-31 16:01 1364522 ----a-w- c:\program files\wrar393.exe
2010-03-13 14:26 . 2010-03-13 14:26 360584 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-03-13 14:24 . 2010-03-13 14:24 333192 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-03-13 14:24 . 2010-03-13 14:24 12464 ----a-w- c:\windows\system32\avgrsstx.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-08 05:50 . 2004-08-04 12:00 52480 ----a-w- c:\windows\system32\drivers\i8042prt.sys
2010-04-08 05:20 . 2007-07-30 02:15 -------- d-----w- c:\program files\Lexmark 1200 Series
2010-04-08 05:20 . 2005-11-14 15:33 -------- d-----w- c:\program files\PC-Doctor 5 for Windows
2010-04-08 05:19 . 2009-11-28 04:55 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-04-07 07:56 . 2009-05-28 04:36 -------- d-----w- c:\program files\CCleaner
2010-04-07 07:17 . 2007-07-30 02:16 -------- d-----w- c:\program files\Lexmark Fax Solutions
2010-03-29 22:18 . 2010-01-17 09:46 5918720 -c--a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-03-29 20:24 . 2009-11-10 04:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 20:24 . 2009-11-10 04:30 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-22 14:26 . 2007-08-01 06:03 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\U3
2010-03-13 18:25 . 2006-02-27 02:47 276232 ----a-w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-13 14:24 . 2009-05-22 07:55 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-13 14:24 . 2007-11-08 04:31 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-13 14:23 . 2009-05-22 07:55 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-03 05:16 . 2010-03-03 05:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Slapdash Games
2010-02-25 06:24 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-22 22:43 . 2010-02-22 22:43 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Pogo Games
2010-02-21 15:46 . 2005-11-14 15:02 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-20 08:51 . 2010-02-20 08:51 -------- d-----w- c:\documents and settings\All Users\Application Data\TikGames
2010-02-20 08:50 . 2009-05-23 09:20 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Netscape
2010-02-20 08:49 . 2010-02-03 08:47 -------- d-----w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2010-02-20 08:31 . 2006-11-17 01:39 -------- d-----w- c:\program files\Juno
2010-02-08 08:58 . 2007-03-24 07:41 2514 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\wklnhst.dat
2010-02-03 13:14 . 2008-01-02 05:47 9216 -csha-w- c:\program files\Thumbs.db
2010-02-03 08:47 . 2010-02-03 08:47 3054384 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\Unpack\bfgsetup_s1_l1.exe
2009-11-20 19:34 . 2009-11-20 19:34 6931008 ----a-w- c:\program files\DJVUCTRL-6.1.4-en-r2013.exe
2006-09-14 02:34 . 2006-09-14 02:34 1921 ----a-w- c:\program files\Adobe Illustrator CS2.lnk
2006-09-14 02:33 . 2006-09-14 02:33 786 ----a-w- c:\program files\install.adb
2006-05-29 22:59 . 2006-06-09 07:41 237568 -c--a-w- c:\program files\magnet.exe
2005-09-22 18:31 . 2005-03-25 13:39 68749 -c--a-w- c:\program files\Illustrator Read Me.pdf
2005-03-25 13:39 . 2005-03-25 13:39 13936 -c--a-r- c:\program files\Activation_ReadMe.htm
2005-03-25 13:36 . 2005-03-25 13:36 1824 -c--a-w- c:\program files\Adobe Illustrator CS2.csa
2007-09-13 02:17 . 2007-09-13 02:17 848 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
Code:
<pre>
c:\program files\AVG\AVG9\avgtray .exe
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd .exe
c:\program files\HP\HP Software Update\hpwuschd2 .exe
c:\program files\Lexmark 1200 Series\lxczbmgr .exe
c:\program files\Lexmark Fax Solutions\fm3032 .exe
c:\program files\Messenger\msmsgs .exe
c:\program files\Network Associates\Common Framework\updaterui .exe
c:\program files\PC-Doctor 5 for Windows\pcdsmartmonitor .exe
c:\windows\SMINST\recguard .exe
</pre>
------- Sigcheck -------
[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2008-04-14 . 063E90991783C120CB4AB7198D8AE109 . 82432 . . [5.1.2600.5512] . . c:\windows\system32\spoolsv.exe
[-] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
[7] 2004-08-04 . 7435B108B935E42EA92CA94F59C8E717 . 57856 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896423$\spoolsv.exe
[7] 2008-04-14 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\svchost.exe
[-] 2008-04-14 . D0972A2903A59110634084ED69BD2F36 . 38912 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe
[7] 2004-08-04 . 8F078AE4ED187AAABC0A305146DE6716 . 14336 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\svchost.exe
[7] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe
[-] 2008-04-14 . C738D2D8718DB8F1E7DF237FF76E397D . 51200 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe
[7] 2004-08-04 . 39B1FFB03C2296323832ACBAE50D2AFF . 24576 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\userinit.exe
[-] 2008-04-14 . 5879B03ECC94DDC80A9A978DC7D1F40D . 1058304 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[7] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-14 . E1EB513E34A3D995C38ED073C6381C39 . 40448 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ctfmon.exe
[7] 2004-08-04 . 24232996A38C0B0CF151C2140AE29FC8 . 15360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-08 61952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-08 61952]
"RECGUARD"="c:\windows\SMINST\RECGUARD.EXE" [2010-04-08 61952]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-04-08 61952]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2003-09-29 110592]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2010-04-08 61952]
"PCDrSmartMonitor"="c:\program files\PC-Doctor 5 for Windows\PcdSmartMonitor.exe" [2010-04-08 61952]
"PCDrProfiler"="" [N/A]
"lxczbmgr.exe"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2010-04-08 61952]
"fzwkht"="c:\windows\system32\msuqddft.dll" [N/A]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2005-11-14 51712]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184]
NETGEAR WN111 Smart Wizard.lnk - c:\program files\NETGEAR\WN111\wn111.exe [2008-1-8 2138112]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-13 14:24 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Netscape\\Netscape Browser\\netscape.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\WINDOWS\\system32\\Ati2evxx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21:TCP"= 21:TCP:ftp
R0 tydmworx;tydmworx; [x]
R3 ATIXPGAA;ATIXPGAA;c:\program files\PC-Doctor 5 for Windows\ATIXPGAA.SYS [x]
R3 PCD5SRVC{085326CB-51A3560A-05010003};PCD5SRVC{085326CB-51A3560A-05010003} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\PC-DOC~1\PCD5SRVC.pkms [2005-09-08 21120]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-03-13 216200]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-03-13 242696]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-03-13 308064]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - BTWSVC
*NewlyCreated* - PERESVC
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchURL,(Default) =
hxxp://my.juno.com/s/search?action=minisearch&source=minisearch_dsl&mn=83019351DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} -
hxxp://aolsvc.aol.com/onlinegames/free-trial-fashion-dash/fashiondashweb.1.0.0.21.cabDPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468} -
hxxp://aolsvc.aol.com/onlinegames/ghadventureball/abxgh.cabDPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} -
hxxp://aolsvc.aol.com/onlinegames/free-trial-big-island-blends/gamehouseplayer.cab.
- - - - ORPHANS REMOVED - - - -
BHO-{D5CC50CD-5B07-4097-8B6B-D21CC857FC4D} - (no file)
AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCD5SRVC{085326CB-51A3560A-05010003}]
"ImagePath"="\??\c:\progra~1\PC-DOC~1\PCD5SRVC.pkms"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2773555476-112744085-238773407-1009\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:15,f2,75,49,99,63,14,11,35,0e,54,3c,47,e5,1e,c2,b0,28,f0,b3,5b,02,e8,
0c,be,60,15,7e,47,4f,9d,8b,ce,0a,09,98,12,c1,a0,24,78,9a,a2,b4,b6,d4,c4,29,\
"??"=hex:f7,20,1a,ff,45,41,d8,a0,14,02,48,77,57,1e,88,3a
[HKEY_USERS\S-1-5-21-2773555476-112744085-238773407-1009\Software\SecuROM\License information*]
"datasecu"=hex:aa,91,7c,81,16,cf,f0,d7,83,cc,de,86,9e,b7,36,7f,15,92,b8,c8,da,
95,3f,db,a0,06,07,31,be,ba,86,19,a9,67,1c,73,4d,14,64,0b,e1,16,4f,b8,4f,a0,\
"rkeysecu"=hex:de,b6,88,f1,4a,ef,9e,a7,7b,a7,e0,ef,c4,ac,6c,b4
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(716)
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(776)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2960)
c:\windows\system32\WININET.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\lxczcoms.exe
c:\program files\Network Associates\Common Framework\FrameworkService.exe
c:\program files\Network Associates\VirusScan\Mcshield.exe
c:\progra~1\NETWOR~1\COMMON~1\naPrdMgr.exe
c:\program files\Network Associates\VirusScan\VsTskMgr.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\hp\hp software update\hpwuschd2 .exe
c:\windows\system32\w.exe
c:\windows\System32\Rundll32.exe
c:\windows\system32\PereSvc.exe
c:\program files\McAfee Security Scan\1.0.150\McUICnt.exe
.
**************************************************************************
.
Completion time: 2010-04-08 03:12:52 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-08 08:12
ComboFix2.txt 2007-10-24 16:02
Pre-Run: 64,306,212,864 bytes free
Post-Run: 64,233,254,912 bytes free
- - End Of File - - 8C9691E53EBEBB63484847048EA10D4C