Hello Belahzur,
Followed your guide and the scan results below.
Cheers
Blueboy
ComboFix 10-06-13.01 - Ken 14/06/2010 14:52:55.1.2 - x86
Microsoft
Windows Vista
Business 6.0.6002.2.1252.65.1033.18.3018.1426 [GMT 10:00]
Running from: c:\users\Ken\Desktop\Combo-Fix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\d3d1032.dll
c:\programdata\dot3ui32.dll
c:\programdata\dsdmo32.dll
c:\programdata\unrar.exe
c:\users\Ken\AppData\Roaming\020000001c40465e924C.manifest
c:\users\Ken\AppData\Roaming\020000001c40465e924O.manifest
c:\users\Ken\AppData\Roaming\020000001c40465e924P.manifest
c:\users\Ken\AppData\Roaming\020000001c40465e924S.manifest
c:\users\Ken\AppData\Roaming\984D.tmp
c:\users\Ken\AppData\Roaming\D9A2.tmp
c:\users\Ken\AppData\Roaming\E197.tmp
c:\users\Ken\AppData\Roaming\inst.exe
c:\users\Ken\AppData\Roaming\Mozilla\Firefox\Profiles\fvacugtt.default\extensions\{052a9d35-911b-4e68-af6a-0431ae735258}
c:\users\Ken\AppData\Roaming\Mozilla\Firefox\Profiles\fvacugtt.default\extensions\{052a9d35-911b-4e68-af6a-0431ae735258}\chrome.manifest
c:\users\Ken\AppData\Roaming\Mozilla\Firefox\Profiles\fvacugtt.default\extensions\{052a9d35-911b-4e68-af6a-0431ae735258}\chrome\xulcache.jar
c:\users\Ken\AppData\Roaming\Mozilla\Firefox\Profiles\fvacugtt.default\extensions\{052a9d35-911b-4e68-af6a-0431ae735258}\defaults\preferences\xulcache.js
c:\users\Ken\AppData\Roaming\Mozilla\Firefox\Profiles\fvacugtt.default\extensions\{052a9d35-911b-4e68-af6a-0431ae735258}\install.rdf
c:\users\Ken\AppData\Roaming\SystemProc
c:\users\Ken\AppData\Roaming\SystemProc\lsass.exe
c:\users\Ken\g2ax_customer_downloadhelper_win32_x86.exe
c:\users\kenr\AppData\Roaming\Mozilla\Firefox\Profiles\ljwjaaw4.default\extensions\{052a9d35-911b-4e68-af6a-0431ae735258}
c:\users\kenr\AppData\Roaming\Mozilla\Firefox\Profiles\ljwjaaw4.default\extensions\{052a9d35-911b-4e68-af6a-0431ae735258}\chrome.manifest
c:\users\kenr\AppData\Roaming\Mozilla\Firefox\Profiles\ljwjaaw4.default\extensions\{052a9d35-911b-4e68-af6a-0431ae735258}\chrome\xulcache.jar
c:\users\kenr\AppData\Roaming\Mozilla\Firefox\Profiles\ljwjaaw4.default\extensions\{052a9d35-911b-4e68-af6a-0431ae735258}\defaults\preferences\xulcache.js
c:\users\kenr\AppData\Roaming\Mozilla\Firefox\Profiles\ljwjaaw4.default\extensions\{052a9d35-911b-4e68-af6a-0431ae735258}\install.rdf
c:\users\kenr\GoToAssistDownloadHelper.exe
c:\windows\system32\CRTDLL32.DLL
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((( Files Created from 2010-05-14 to 2010-06-14 )))))))))))))))))))))))))))))))
.
2010-06-14 05:12 . 2010-06-14 05:18 -------- d-----w- c:\users\Ken\AppData\Local\temp
2010-06-14 05:12 . 2010-06-14 05:12 -------- d-----w- c:\users\kenr\AppData\Local\temp
2010-06-14 05:12 . 2010-06-14 05:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-14 04:39 . 2010-06-14 04:49 -------- d-----w- C:\ComboFix
2010-06-11 13:37 . 2010-06-14 04:46 -------- d-----w- c:\programdata\1794963555
2010-06-11 13:10 . 2010-06-11 13:10 -------- d-----w- C:\_OTL
2010-06-11 00:54 . 2010-04-05 17:01 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-11 00:51 . 2010-05-26 17:06 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-11 00:51 . 2010-05-26 14:47 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-06-11 00:50 . 2010-05-01 14:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-06-10 13:45 . 2010-06-10 14:21 -------- d-----w- c:\windows\system32\wbem\Logs
2010-06-08 03:50 . 2010-06-08 03:51 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-08 03:47 . 2010-06-08 03:47 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-08 03:44 . 2010-06-08 14:57 -------- d-----w- c:\programdata\NOS
2010-05-31 04:48 . 2010-05-31 05:24 -------- d-----w- c:\users\Ken\AppData\Local\Microsoft Games
2010-05-31 03:31 . 2010-05-31 03:31 -------- d-----w- c:\program files\Microsoft Games
2010-05-29 10:25 . 2010-05-29 10:51 -------- d-----w- C:\TOY_STORY
2010-05-29 10:04 . 2010-06-11 17:15 -------- d-----w- c:\windows\Debug
2010-05-26 06:10 . 2010-04-23 14:13 2048 ----a-w- c:\windows\system32\tzres.dll
2010-05-25 07:18 . 2010-05-12 01:21 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-25 04:47 . 2010-05-28 11:34 680 ----a-w- c:\users\Ken\AppData\Local\d3d9caps.dat
2010-05-22 11:18 . 2010-05-22 11:18 301056 ----a-w- c:\windows\system32\dmintf32.dll
2010-05-22 09:45 . 2010-04-12 07:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-21 03:17 . 2010-05-21 03:17 -------- d-----w- c:\programdata\McAfee Security Scan
2010-05-21 03:17 . 2010-05-24 04:42 -------- d-----w- c:\program files\McAfee Security Scan
2010-05-18 06:09 . 2010-05-18 06:40 -------- d-----w- C:\RainMan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-14 04:08 . 2010-06-14 04:08 321024 ----a-w- c:\programdata\dimsjob32.dll
2010-06-14 04:08 . 2010-06-14 04:08 321024 ----a-w- c:\programdata\dimsjob32.dll
2010-06-11 17:48 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-11 17:30 . 2008-08-07 23:56 -------- d-----w- c:\programdata\Microsoft Help
2010-06-11 16:00 . 2010-03-30 02:56 -------- d-----w- c:\programdata\DriverCure
2010-06-11 13:07 . 2009-06-05 14:30 -------- d-----w- c:\program files\Safari
2010-06-11 13:01 . 2010-06-11 13:01 71992 ----a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-10 12:33 . 2010-06-10 12:33 321024 ----a-w- c:\programdata\d3d932.dll
2010-06-10 12:33 . 2010-06-10 12:33 321024 ----a-w- c:\programdata\d3d932.dll
2010-06-09 13:35 . 2009-08-01 08:54 -------- d-----w- c:\users\Ken\AppData\Roaming\Skype
2010-06-09 06:14 . 2009-08-01 09:07 -------- d-----w- c:\users\Ken\AppData\Roaming\skypePM
2010-06-08 03:44 . 2010-06-08 03:44 86016 ----a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2010-06-06 07:38 . 2010-06-06 07:38 309248 ----a-w- c:\programdata\encapi32.dll
2010-06-06 07:38 . 2010-06-06 07:38 309248 ----a-w- c:\programdata\encapi32.dll
2010-06-02 13:42 . 2010-06-02 13:42 309248 ----a-w- c:\programdata\eappcfg32.dll
2010-06-02 13:42 . 2010-06-02 13:42 309248 ----a-w- c:\programdata\eappcfg32.dll
2010-06-02 12:41 . 2010-06-02 12:41 311808 ----a-w- c:\programdata\fdSSDP32.dll
2010-06-02 12:41 . 2010-06-02 12:41 311808 ----a-w- c:\programdata\fdSSDP32.dll
2010-05-31 13:35 . 2010-05-31 13:35 311808 ----a-w- c:\programdata\d3dx9_2832.dll
2010-05-31 13:35 . 2010-05-31 13:35 311808 ----a-w- c:\programdata\d3dx9_2832.dll
2010-05-31 12:53 . 2010-05-31 12:53 311808 ----a-w- c:\programdata\dot3gpclnt32.dll
2010-05-31 12:53 . 2010-05-31 12:53 311808 ----a-w- c:\programdata\dot3gpclnt32.dll
2010-05-31 11:53 . 2010-05-31 11:53 311808 ----a-w- c:\programdata\dnsrslvr32.dll
2010-05-31 11:53 . 2010-05-31 11:53 311808 ----a-w- c:\programdata\dnsrslvr32.dll
2010-05-31 10:53 . 2010-05-31 10:53 311808 ----a-w- c:\programdata\dot3api32.dll
2010-05-31 10:53 . 2010-05-31 10:53 311808 ----a-w- c:\programdata\dot3api32.dll
2010-05-31 09:53 . 2010-05-31 09:53 311808 ----a-w- c:\programdata\dinput832.dll
2010-05-31 09:53 . 2010-05-31 09:53 311808 ----a-w- c:\programdata\dinput832.dll
2010-05-31 06:53 . 2010-05-31 06:53 311808 ----a-w- c:\programdata\ds16gt32.dll
2010-05-31 06:53 . 2010-05-31 06:53 311808 ----a-w- c:\programdata\ds16gt32.dll
2010-05-31 05:52 . 2010-05-31 05:52 311808 ----a-w- c:\programdata\glu3232.dll
2010-05-31 05:52 . 2010-05-31 05:52 311808 ----a-w- c:\programdata\glu3232.dll
2010-05-31 04:52 . 2010-05-31 04:52 311808 ----a-w- c:\programdata\FXSCOMPOSERES32.dll
2010-05-31 04:52 . 2010-05-31 04:52 311808 ----a-w- c:\programdata\FXSCOMPOSERES32.dll
2010-05-31 03:52 . 2010-05-31 03:52 311808 ----a-w- c:\programdata\findnetprinters32.dll
2010-05-31 03:52 . 2010-05-31 03:52 311808 ----a-w- c:\programdata\findnetprinters32.dll
2010-05-31 02:52 . 2010-05-31 02:52 311808 ----a-w- c:\programdata\fdWCN32.dll
2010-05-31 02:52 . 2010-05-31 02:52 311808 ----a-w- c:\programdata\fdWCN32.dll
2010-05-30 06:20 . 2010-05-30 06:20 501872 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb193D.tmp.exe
2010-05-29 10:01 . 2010-05-09 10:48 -------- d-----w- c:\users\Ken\AppData\Roaming\Azureus
2010-05-29 09:17 . 2010-03-30 02:56 -------- d-----w- c:\programdata\ParetoLogic
2010-05-29 09:17 . 2010-03-30 02:56 -------- d-----w- c:\program files\Common Files\ParetoLogic
2010-05-29 09:17 . 2010-03-30 02:56 -------- d-----w- c:\program files\ParetoLogic
2010-05-23 11:58 . 2009-02-01 13:32 -------- d-----w- c:\program files\McAfee
2010-05-22 11:16 . 2009-08-05 10:51 -------- d-----w- c:\users\Ken\AppData\Roaming\LimeWire
2010-05-22 09:45 . 2008-10-17 01:03 -------- d-----w- c:\program files\Java
2010-05-21 04:03 . 2008-09-17 04:33 -------- d-----w- c:\programdata\LogiShrd
2010-05-21 04:03 . 2008-09-17 04:30 -------- d-----w- c:\program files\Common Files\LogiShrd
2010-05-21 04:03 . 2008-08-07 23:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-20 04:21 . 2008-10-13 00:37 -------- d-----w- c:\programdata\DVD Shrink
2010-05-11 15:04 . 2010-05-11 15:04 4141117 ----a-w- c:\users\Ken\AppData\Roaming\Azureus\plugins\vuzexcode\mediainfo.exe
2010-05-11 15:04 . 2010-05-11 15:04 7282688 ----a-w- c:\users\Ken\AppData\Roaming\Azureus\plugins\vuzexcode\ffmpeg.exe
2010-05-11 14:53 . 2009-08-06 09:28 -------- d-----w- c:\users\Ken\AppData\Roaming\Ahead
2010-05-10 07:00 . 2010-05-10 07:00 6123008 ----a-w- c:\users\Ken\AppData\Roaming\Azureus\plugins\azemp\vuzeplayer.exe
2010-05-09 10:46 . 2010-05-09 10:45 -------- d-----w- c:\program files\Vuze
2010-05-09 10:45 . 2010-05-09 10:45 101376 ----a-w- c:\users\Ken\AppData\Roaming\Mozilla\Firefox\Profiles\fvacugtt.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll
2010-05-09 10:45 . 2010-05-09 10:45 52224 ----a-w- c:\users\Ken\AppData\Roaming\Mozilla\Firefox\Profiles\fvacugtt.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll
2010-05-09 10:42 . 2010-05-09 10:42 -------- d-----w- c:\program files\Conduit
2010-05-09 10:42 . 2010-05-09 10:42 -------- d-----w- c:\program files\Vuze_Remote
2010-05-06 22:39 . 2009-02-01 13:32 -------- d-----w- c:\program files\McAfee.com
2010-05-06 04:16 . 2009-02-01 13:11 -------- d-----w- c:\programdata\McAfee
2010-05-06 04:15 . 2009-02-01 13:32 -------- d-----w- c:\program files\Common Files\McAfee
2010-05-04 05:59 . 2010-06-11 00:55 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-11 00:55 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 05:55 . 2010-06-11 00:55 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 04:31 . 2010-06-11 00:55 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-03 07:45 . 2010-01-30 12:57 -------- d-----w- c:\users\Ken\AppData\Roaming\HpUpdate
2010-04-29 01:54 . 2010-04-29 01:52 -------- d-----w- c:\program files\iTunes
2010-04-29 01:52 . 2010-04-29 01:52 -------- d-----w- c:\program files\iPod
2010-04-29 01:52 . 2009-05-25 13:35 -------- d-----w- c:\program files\Common Files\Apple
2010-04-29 01:46 . 2010-04-29 01:46 -------- d-----w- c:\program files\Bonjour
2010-04-29 01:40 . 2010-04-29 01:40 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.11\SetupAdmin.exe
2010-04-27 07:16 . 2010-05-06 01:21 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2010-04-27 07:16 . 2010-05-06 01:20 95568 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-04-27 07:16 . 2010-05-06 01:20 83496 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2010-04-27 07:16 . 2010-05-06 01:20 64304 ----a-w- c:\windows\system32\drivers\mfenlfk.sys
2010-04-27 07:16 . 2010-05-06 01:20 55456 ----a-w- c:\windows\system32\drivers\cfwids.sys
2010-04-27 07:16 . 2010-05-06 01:20 51688 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2010-04-27 07:16 . 2010-05-06 01:20 385880 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2010-04-27 07:16 . 2010-05-06 01:20 312616 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2010-04-27 07:16 . 2010-05-06 01:20 160720 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2010-04-27 07:16 . 2010-05-06 01:20 152320 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2010-04-26 14:40 . 2010-03-15 05:57 -------- d-----w- c:\program files\WePrint
2010-04-21 05:06 . 2009-10-09 12:11 -------- d-----w- c:\users\Ken\AppData\Roaming\eBookPro6
2010-04-08 03:20 . 2010-04-08 03:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 03:20 . 2010-04-08 03:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-02 14:33 . 2010-04-02 14:33 125952 ----a-w- c:\programdata\ParetoLogic\UUS2\Temp\Update.exe
2010-03-19 13:14 . 2010-03-19 13:14 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2010-04-27 07:16 . 2010-05-06 01:21 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuze.dll" [2010-04-15 2515552]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0000DB19-BF6D-413C-BDEE-37D6594E583c}]
2010-06-14 04:08 321024 ----a-w- c:\programdata\dimsjob32.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2010-04-15 02:33 2515552 ----a-w- c:\program files\Vuze_Remote\tbVuze.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuze.dll" [2010-04-15 2515552]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\tbVuze.dll" [2010-04-15 2515552]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-27 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-06-27 6295552]
"Skytel"="Skytel.exe" [2008-06-25 1826816]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2008-06-11 634880]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-04 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-04 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-04 145944]
"MGSysCtrl"="c:\program files\System Control Manager\MGSysCtrl.exe" [2008-07-25 704512]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 827392]
"PCMService"="c:\program files\CyberLink\PowerCinema\PCMService.exe" [2007-05-09 159744]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-28 75136]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2008-08-01 675840]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-24 142120]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-04-21 1193336]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
c:\users\kenr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
OneNote Table Of Contents.onetoc2 [2009-2-24 3656]
c:\users\Ken\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
WePrint Server.lnk - c:\program files\WePrint\WePrint Server.exe [2010-3-15 2212352]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2008-2-22 2938184]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-5 2057536]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-5 9116480]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 01:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 05:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):e3,6b,13,b2,f6,61,ca,01
R2 gupdate1c9bfbcf4cb92e4;Google Update Service (gupdate1c9bfbcf4cb92e4);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 133104]
R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-04-27 83496]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-04-27 64304]
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-04-27 160720]
S2 CLHNService;CLHNService;c:\program files\CyberLink\SoftDMA\Kernel\DMP\CLHNService.exe [2007-07-25 77824]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2010-03-26 93320]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-04-27 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-04-27 141792]
S2 Micro Star SCM;Micro Star SCM;c:\program files\System Control Manager\MSIService.exe [2008-06-10 159744]
S2 NTIPPKernel;NTIPPKernel;c:\program files\CyberLink\SoftDMA\Kernel\DMP\NTIPPKernel.sys [2007-07-25 122624]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
S2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-11-04 110592]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-15 20480]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-04-27 55456]
S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y6032.sys [2008-08-01 225920]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-04-27 312616]
S3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-04-28 3658752]
S3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2008-06-11 48472]
S3 O2SDRDR;O2SDRDR;c:\windows\system32\DRIVERS\o2sd.sys [2008-06-11 43480]
--- Other Services/Drivers In Memory ---
*Deregistered* - mfeavfk01
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-06-11 c:\windows\Tasks\DriverCure.job
- c:\program files\ParetoLogic\DriverCure\DriverCure.exe [2009-08-07 19:36]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 00:30]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 00:30]
2010-06-13 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59]
2010-06-13 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2009-10-12 05:01]
2010-06-02 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59]
2010-05-29 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2009-10-12 05:01]
2010-06-09 c:\windows\Tasks\PC Health Advisor.job
- c:\program files\ParetoLogic\PCHA\PCHA.exe [2010-05-05 00:13]
2010-06-14 c:\windows\Tasks\User_Feed_Synchronization-{94578D48-F5D2-4F57-899A-6D6D87535810}.job
- c:\windows\system32\msfeedssync.exe [2010-06-11 04:30]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com.au/mStart Page =
file:///C:/Windows/NECCUST/OWR/OWR_EN.HTMuInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
DPF: {741747F6-83B4-4FB9-A268-8CA4010762C8} -
hxxp://www4.snapfish.com.au/SnapfishActivia2.cabFF - ProfilePath - c:\users\Ken\AppData\Roaming\Mozilla\Firefox\Profiles\fvacugtt.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}FF - prefs.js: browser.search.selectedEngine - Google Powered Search
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - component: c:\program files\Mozilla Firefox\components\Scriptff.dll
FF - component: c:\users\Ken\AppData\Roaming\Mozilla\Firefox\Profiles\fvacugtt.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\FFExternalAlert.dll
FF - component: c:\users\Ken\AppData\Roaming\Mozilla\Firefox\Profiles\fvacugtt.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}\components\RadioWMPCore.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-RTHDBPL - c:\users\Ken\AppData\Roaming\SystemProc\lsass.exe
MSConfigStartUp-Client Access Check Version - c:\program files\IBM\Client Access\cwbckver.exe
MSConfigStartUp-Client Access Express Welcome - c:\program files\IBM\Client Access\cwbwlwiz.exe
MSConfigStartUp-Client Access Help Update - c:\program files\IBM\Client Access\cwbinhlp.exe
MSConfigStartUp-Client Access Service - c:\program files\IBM\Client Access\CwbSvStr.Exe
MSConfigStartUp-MobileConnect - c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.EXE
MSConfigStartUp-Search Protection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
AddRemove-Adobe Flash Player ActiveX - c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-14 15:18
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
RTHDBPL = c:\users\Ken\AppData\Roaming\SystemProc\lsass.exe?? ????????????????????????????????#???????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(540)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
c:\windows\system32\rundll32.exe
c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe
c:\program files\Cyberlink\Shared files\RichVideo.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Common Files\McAfee\SystemCore\mfefire.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\sdclt.exe
c:\windows\system32\rundll32.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2010-06-14 15:29:42 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-14 05:29
Pre-Run: 70,506,102,784 bytes free
Post-Run: 83,668,680,704 bytes free
- - End Of File - - DDDF328062F398321CC3FEE2C136AA7B