ComboFix 10-06-23.02 - Elena 06/23/2010 22:23:39.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.2045.884 [GMT -4:00]
Running from: c:\users\Elena\Desktop\commy.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Elena\AppData\Roaming\drivers\downld
c:\users\Elena\AppData\Roaming\FieryAds
c:\users\Elena\GoToAssistDownloadHelper.exe
c:\windows\xpsp1hfm.log
.
((((((((((((((((((((((((( Files Created from 2010-05-24 to 2010-06-24 )))))))))))))))))))))))))))))))
.
2010-06-24 02:28 . 2010-06-24 02:29 -------- d-----w- c:\users\Elena\AppData\Local\temp
2010-06-24 02:28 . 2010-06-24 02:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-22 03:35 . 2010-06-22 03:35 -------- d-----w- c:\program files\temp
2010-06-22 03:10 . 2010-06-22 03:10 -------- d-----w- C:\_OTL
2010-06-22 01:54 . 2010-06-22 01:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-18 05:48 . 2010-06-18 05:48 -------- d-----w- C:\audio
2010-06-18 05:48 . 1998-04-30 18:56 129024 ----a-w- c:\windows\UNWISE.EXE
2010-06-18 05:15 . 2005-11-17 16:19 109568 ------w- c:\windows\system32\pxinsi64.exe
2010-06-18 05:15 . 2005-11-17 16:19 108544 ------w- c:\windows\system32\pxcpyi64.exe
2010-06-11 16:45 . 2010-06-14 05:21 -------- d-----w- c:\users\Elena\AppData\Roaming\BitTorrent
2010-06-11 16:45 . 2010-06-11 16:45 -------- d-----w- c:\program files\BitTorrent
2010-06-10 02:54 . 2010-04-05 17:01 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-10 02:54 . 2010-05-26 14:47 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-06-10 02:54 . 2010-05-26 17:06 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-10 02:54 . 2010-05-04 19:15 834048 ----a-w- c:\windows\system32\wininet.dll
2010-06-10 02:54 . 2010-05-04 18:37 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-06-10 02:53 . 2010-05-01 14:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-06-08 21:51 . 2010-06-18 05:07 695 ---ha-w- C:\os848618.bin
2010-06-08 21:35 . 2010-06-08 21:35 -------- d-----w- c:\program files\Common Files\Vbox
2010-06-03 12:14 . 2010-06-03 12:14 29512 ----a-w- c:\programdata\avg9\update\backup\avgmfx86.sys
2010-06-03 12:14 . 2010-06-03 12:14 242896 ----a-w- c:\programdata\avg9\update\backup\avgtdix.sys
2010-05-28 00:34 . 2010-05-28 00:34 -------- d-----w- c:\program files\iPod
2010-05-28 00:34 . 2010-05-28 00:34 -------- d-----w- c:\program files\iTunes
2010-05-28 00:31 . 2010-05-28 00:31 -------- d-----w- c:\program files\Bonjour
2010-05-28 00:30 . 2010-05-28 00:30 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-26 00:51 . 2010-04-23 14:13 2048 ----a-w- c:\windows\system32\tzres.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-24 02:27 . 2009-05-17 01:35 -------- d--h--w- c:\users\Elena\AppData\Roaming\drivers
2010-06-24 01:43 . 2009-12-20 20:58 0 ----a-w- c:\users\Elena\AppData\Local\prvlcl.dat
2010-06-23 22:51 . 2010-01-12 23:55 -------- d-----w- c:\users\Elena\AppData\Roaming\vlc
2010-06-23 11:14 . 2009-10-31 19:53 9 ----a-w- c:\program files\USDownloader.lst
2010-06-23 11:14 . 2009-10-31 19:47 2943 ----a-w- c:\program files\USDownloader.ini
2010-06-23 05:39 . 2009-10-31 19:53 9 ----a-w- c:\program files\USDownloader.lst1.bak
2010-06-23 05:39 . 2009-10-31 19:47 1046403 ----a-w- c:\program files\USDownloader.log
2010-06-23 05:08 . 2009-10-31 19:53 213 ----a-w- c:\program files\USDownloader.lst2.bak
2010-06-23 04:48 . 2009-10-31 19:53 417 ----a-w- c:\program files\USDownloader.lst3.bak
2010-06-23 04:17 . 2009-10-31 19:53 621 ----a-w- c:\program files\USDownloader.lst4.bak
2010-06-23 03:46 . 2009-10-31 19:53 825 ----a-w- c:\program files\USDownloader.lst5.bak
2010-06-23 03:31 . 2009-10-31 19:53 1096 ----a-w- c:\program files\USDownloader.lst6.bak
2010-06-23 03:27 . 2009-10-31 19:53 1096 ----a-w- c:\program files\USDownloader.lst7.bak
2010-06-23 02:35 . 2009-10-31 19:53 1029 ----a-w- c:\program files\USDownloader.lst8.bak
2010-06-23 02:04 . 2009-10-31 19:53 1233 ----a-w- c:\program files\USDownloader.lst9.bak
2010-06-22 04:11 . 2008-12-03 00:10 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-06-18 05:15 . 2009-02-27 19:30 -------- d-----w- c:\program files\DivX
2010-06-15 19:30 . 2008-12-01 15:19 -------- d-----w- c:\programdata\Roxio
2010-06-10 07:38 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-08 21:35 . 2008-11-28 18:15 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-08 21:32 . 2008-11-18 04:04 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-06 16:43 . 2010-03-07 23:21 -------- d-----w- c:\program files\Minitab 15
2010-06-03 12:13 . 2009-01-31 16:33 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-03 12:13 . 2008-11-18 23:52 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-28 00:34 . 2008-11-19 03:11 -------- d-----w- c:\program files\Common Files\Apple
2010-05-21 18:14 . 2009-10-03 05:59 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 14:55 . 2008-11-24 04:03 -------- d-----w- c:\program files\Canon
2010-05-08 19:28 . 2009-04-24 00:47 -------- d-----w- c:\program files\Paint.NET
2010-04-08 17:20 . 2010-04-08 17:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 17:20 . 2010-04-08 17:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-03-31 19:06 . 2010-03-31 19:06 143976 ----a-w- c:\users\Elena\AppData\Roaming\Move Networks\uninstall.exe
2010-03-31 19:06 . 2009-10-15 00:50 5642688 ----a-w- c:\users\Elena\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll
2010-01-05 17:12 . 2010-01-05 17:12 51354 ----a-w- c:\program files\HotFileCom.bmp
2010-01-05 17:12 . 2010-01-05 17:12 3655 ----a-w- c:\program files\HotFileCom.jpg
2009-10-31 20:14 . 2009-10-31 20:14 655 ----a-w- c:\program files\USDownloader - Shortcut.lnk
2009-10-31 19:47 . 2009-10-31 19:47 506 --sha-w- c:\program files\USDownloader.exe.manifest
2009-05-28 22:32 . 2009-10-31 19:36 530432 ----a-w- c:\program files\USDownloader.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ISUSPM"="c:\programdata\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-03-29 222128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-01-14 132392]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-03 2065248]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-12-14 467240]
"VX1000"="c:\windows\vVX1000.exe" [2009-06-26 757248]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2009-07-24 118640]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
c:\users\Elena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-6-20 1221928]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-6-8 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):c6,2a,bc,0a,80,74,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3557314420-4042277559-3280422289-1000]
"EnableNotificationsRef"=dword:00000001
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-03-16 916760]
R3 AsAudioDevice_352;AsAudioDevice_352;c:\windows\system32\drivers\AsAudioDevice_352.sys [2009-01-07 16640]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-03-16 216200]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-06-03 242896]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-03-16 308064]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-05-02 161048]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - AVG9WD
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC}]
2008-06-18 19:04 8192 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
2010-06-23 c:\windows\Tasks\User_Feed_Synchronization-{710BD501-5BB5-439B-BE39-2697B243FE11}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.ask.com?o=15438&l=disuDefault_Search_URL =
hxxp://www.google.com/ieuInternet Settings,ProxyOverride = *.local
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Elena\AppData\Roaming\Mozilla\Firefox\Profiles\44n3uofq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://us.mc560.mail.yahoo.com/mc/welcome?.rand=0eovnhh655sj4#_pg=showFolder;_ylc=X3oDMTBuNGM1a2ppBF9TAzM5ODMwMTA0MQRhYwNjaGtNYWls&&.rand=332221452&order=down&pSize=25&tt=487&clean&.jsrand=8946753FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdjvu.dll
FF - plugin: c:\users\Elena\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-Weather - c:\program files\AWS\WeatherBug\Weather.exe
HKLM-Run-NWEReboot - (no file)
Notify-GoToAssist - c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
AddRemove-com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 - c:\program files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-23 22:29
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-06-23 22:31:38
ComboFix-quarantined-files.txt 2010-06-24 02:31
Pre-Run: 39,079,727,104 bytes free
Post-Run: 40,237,162,496 bytes free
- - End Of File - - FDA4CA839169BB720EEABA87C7A28A79