ComboFix 09-10-04.01 - L 10/05/2009 17:10.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1024.590 [GMT -7:00]
Running from: c:\documents and settings\L\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\check_LSA7.txt
c:\program files\fnts~1
c:\program files\icroso~1.net
c:\program files\ystem3~1
c:\winnt\fgjilm.ini
c:\winnt\gggfgh.ini
c:\winnt\illoqr.ini
c:\winnt\jiikmp.ini
c:\winnt\onprss.ini
c:\winnt\sstvut.ini
c:\winnt\stuvxx.ini
c:\winnt\system32\42KJE738.ocx
c:\winnt\system32\avouorjh.ini
c:\winnt\system32\bdsocrsf.ini
c:\winnt\system32\bnhbhgxm.ini
c:\winnt\system32\Cache
c:\winnt\system32\cdeeg.ini
c:\winnt\system32\cdyvuilb.ini
c:\winnt\system32\ckhbnvnf.ini
c:\winnt\system32\dccdd.ini
c:\winnt\system32\dgiygyjt.ini
c:\winnt\system32\dgjlm.bak2
c:\winnt\system32\dgjlm.ini
c:\winnt\system32\dllnnlcj.ini
c:\winnt\system32\ekmxbfjg.ini
c:\winnt\system32\exsdivkb.ini
c:\winnt\system32\fetsmuui.ini
c:\winnt\system32\gkvflark.ini
c:\winnt\system32\gsrkhphe.ini
c:\winnt\system32\hjjlm.bak2
c:\winnt\system32\hjjlm.ini
c:\winnt\system32\hmbbbtmf.ini
c:\winnt\system32\hovqyset.ini
c:\winnt\system32\hsgdposv.ini
c:\winnt\system32\icxmoxjw.ini
c:\winnt\system32\ihfwgrtp.ini
c:\winnt\system32\inhydctn.ini
c:\winnt\system32\iorfxcyg.ini
c:\winnt\system32\ivqulxds.ini
c:\winnt\system32\jjkmp.ini
c:\winnt\system32\jlkkj.ini
c:\winnt\system32\jmllm.ini
c:\winnt\system32\jpricdov.ini
c:\winnt\system32\kvmlmhln.ini
c:\winnt\system32\kxywmyqm.ini
c:\winnt\system32\lgbtaoaf.ini
c:\winnt\system32\llyhnhyy.ini
c:\winnt\system32\logs
c:\winnt\system32\lpqfcjdo.ini
c:\winnt\system32\lsfhvkvw.ini
c:\winnt\system32\ltbmgjve.ini
c:\winnt\system32\lwvybvuv.ini
c:\winnt\system32\mgxcqnoo.ini
c:\winnt\system32\mlkkj.bak2
c:\winnt\system32\mnnmp.ini
c:\winnt\system32\mxhusoof.ini
c:\winnt\system32\nfxdbdqe.ini
c:\winnt\system32\nmllm.bak2
c:\winnt\system32\nmllm.ini
c:\winnt\system32\ntrciawt.ini
c:\winnt\system32\nwkpvblp.ini
c:\winnt\system32\nwsfgckx.ini
c:\winnt\system32\omjgwavc.ini
c:\winnt\system32\oplnklpr.ini
c:\winnt\system32\oqstv.bak2
c:\winnt\system32\oqstv.ini
c:\winnt\system32\oqstv.ini2
c:\winnt\system32\polwqwuv.ini
c:\winnt\system32\psnjwhfs.ini
c:\winnt\system32\qiqdftra.ini
c:\winnt\system32\qqmijjtd.ini
c:\winnt\system32\qqtss.ini
c:\winnt\system32\qrpfnngs.ini
c:\winnt\system32\qrutv.bak2
c:\winnt\system32\qrutv.ini
c:\winnt\system32\qsjodmts.ini
c:\winnt\system32\rrqss.bak2
c:\winnt\system32\rtstv.ini
c:\winnt\system32\rytsscmo.ini
c:\winnt\system32\scunnbsm.ini
c:\winnt\system32\sjkiteye.ini
c:\winnt\system32\srlopokg.ini
c:\winnt\system32\sxgrltmv.ini
c:\winnt\system32\tbynvijv.ini
c:\winnt\system32\tnimajif.ini
c:\winnt\system32\trcshbcq.ini
c:\winnt\system32\txsslspc.ini
c:\winnt\system32\uayocxww.ini
c:\winnt\system32\usliimuf.ini
c:\winnt\system32\usqyfeik.ini
c:\winnt\system32\uvokpevn.ini
c:\winnt\system32\vcnqcfdk.ini
c:\winnt\system32\wcuchqgq.ini
c:\winnt\system32\wpmicoaw.ini
c:\winnt\system32\wrbisyvb.ini
c:\winnt\system32\wvvwa.bak2
c:\winnt\system32\xmrpcurx.ini
c:\winnt\system32\xvotjhxo.ini
c:\winnt\system32\ybeeg.bak2
c:\winnt\system32\ybeeg.ini
c:\winnt\system32\yllhfjnw.ini
c:\winnt\system32\ynthdssu.ini
c:\winnt\system32\yyaayeho.ini
c:\winnt\uxwwwa.ini
c:\winnt\vwxbbc.ini
c:\winnt\Web\default.htt
c:\winnt\winsock.reg
c:\winnt\winsock2.reg
c:\winnt\yceghk.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_IAS
((((((((((((((((((((((((( Files Created from 2009-09-06 to 2009-10-06 )))))))))))))))))))))))))))))))
.
2009-10-04 19:50 . 2008-12-11 15:38 159600 ----a-w- c:\winnt\system32\drivers\pctgntdi.sys
2009-10-04 19:50 . 2009-08-24 21:05 206256 ----a-w- c:\winnt\system32\drivers\PCTCore.sys
2009-10-04 19:50 . 2009-08-19 18:01 86888 ----a-w- c:\winnt\system32\drivers\PCTAppEvent.sys
2009-10-04 19:49 . 2009-10-04 19:51 -------- d-----w- c:\program files\Common Files\PC Tools
2009-10-04 19:49 . 2008-12-10 18:36 64392 ----a-w- c:\winnt\system32\drivers\pctplsg.sys
2009-10-04 19:49 . 2009-10-05 06:38 -------- d-----w- c:\program files\Spyware Doctor
2009-10-04 19:49 . 2009-10-04 19:49 -------- d-----w- c:\documents and settings\L\Application Data\PC Tools
2009-10-04 19:49 . 2009-10-04 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-10-04 19:48 . 2009-10-06 00:48 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-04 19:42 . 2009-10-04 19:42 -------- d-----w- c:\documents and settings\L\Local Settings\Application Data\Mozilla
2009-10-04 19:28 . 2009-10-04 19:28 124 ----a-w- c:\documents and settings\L\Local Settings\Application Data\fusioncache.dat
2009-10-04 19:23 . 2009-07-08 20:44 40552 ----a-w- c:\winnt\system32\drivers\mfesmfk.sys
2009-10-04 19:23 . 2009-07-08 20:44 35272 ----a-w- c:\winnt\system32\drivers\mfebopk.sys
2009-10-04 19:23 . 2009-07-08 20:44 79816 ----a-w- c:\winnt\system32\drivers\mfeavfk.sys
2009-10-04 19:23 . 2009-07-16 19:32 120136 ----a-w- c:\winnt\system32\drivers\Mpfp.sys
2009-10-04 19:22 . 2009-10-04 19:23 -------- d-----w- c:\program files\Common Files\McAfee
2009-10-04 19:22 . 2009-10-04 19:22 -------- d-----w- c:\program files\McAfee.com
2009-10-04 19:21 . 2009-10-04 20:16 -------- d-----w- c:\program files\McAfee
2009-10-04 19:17 . 2009-07-08 20:43 34248 ----a-w- c:\winnt\system32\drivers\mferkdk.sys
2009-10-04 18:55 . 2009-10-04 18:55 -------- d-----w- c:\program files\VS Revo Group
2009-10-04 16:54 . 2009-10-04 16:54 -------- d-sh--w- c:\documents and settings\Tina\IETldCache
2009-10-04 16:17 . 2009-10-04 16:17 -------- d-----w- c:\documents and settings\L\Application Data\Malwarebytes
2009-10-04 16:17 . 2009-09-10 21:54 38224 ----a-w- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-10-04 16:17 . 2009-10-04 16:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-04 16:17 . 2009-09-10 21:53 19160 ----a-w- c:\winnt\system32\drivers\mbam.sys
2009-10-04 16:17 . 2009-10-04 18:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-09 09:53 . 2009-06-21 21:44 153088 -c----w- c:\winnt\system32\dllcache\triedit.dll
2009-09-09 03:32 . 2009-09-09 03:31 737280 ----a-w- c:\winnt\iun6002.exe
2009-09-09 03:32 . 2009-09-29 00:59 -------- d-----w- C:\SpeedItup-Checkup
2009-09-08 18:52 . 2009-09-08 18:52 -------- d-----w- c:\winnt\system32\XPSViewer
2009-09-08 18:52 . 2009-09-08 18:52 -------- d-----w- c:\program files\MSBuild
2009-09-08 18:52 . 2009-09-08 18:52 -------- d-----w- c:\program files\Reference Assemblies
2009-09-08 18:51 . 2008-07-06 12:06 89088 -c----w- c:\winnt\system32\dllcache\filterpipelineprintproc.dll
2009-09-08 18:51 . 2008-07-06 12:06 117760 ------w- c:\winnt\system32\prntvpt.dll
2009-09-08 18:51 . 2008-07-06 10:50 597504 -c----w- c:\winnt\system32\dllcache\printfilterpipelinesvc.exe
2009-09-08 18:51 . 2008-07-06 12:06 575488 -c----w- c:\winnt\system32\dllcache\xpsshhdr.dll
2009-09-08 18:51 . 2008-07-06 12:06 575488 ------w- c:\winnt\system32\xpsshhdr.dll
2009-09-08 18:51 . 2008-07-06 12:06 1676288 -c----w- c:\winnt\system32\dllcache\xpssvcs.dll
2009-09-08 18:51 . 2008-07-06 12:06 1676288 ------w- c:\winnt\system32\xpssvcs.dll
2009-09-08 18:51 . 2009-09-08 18:51 -------- d-----w- C:\aacfab24290bb803bbebb2
2009-09-07 21:28 . 2009-09-07 21:28 -------- d-sh--w- c:\documents and settings\L\IECompatCache
2009-09-07 21:28 . 2009-09-07 21:28 -------- d-----w- c:\documents and settings\L\Application Data\Red Kawa
2009-09-07 21:16 . 2009-09-07 21:16 -------- d-----w- c:\program files\AviSynth 2.5
2009-09-07 21:16 . 2009-09-07 21:16 -------- d-----w- c:\program files\Red Kawa
2009-09-07 21:00 . 2009-09-07 21:00 -------- d-----w- c:\program files\DVD Decrypter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-06 00:46 . 2003-02-13 05:44 288 ----a-w- c:\winnt\system32\DVCStateBkp-{00000000-00000000-0000000B-00001102-00000004-10021102}.dat
2009-10-06 00:46 . 2003-02-13 05:44 288 ----a-w- c:\winnt\system32\DVCState-{00000000-00000000-0000000B-00001102-00000004-10021102}.dat
2009-10-05 17:32 . 2003-03-25 03:27 -------- d-----w- c:\program files\Paint Shop Pro 5
2009-10-05 00:16 . 2006-07-13 01:11 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-04 19:16 . 2003-12-21 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-04 19:01 . 2007-11-14 02:56 -------- d-----w- c:\documents and settings\L\Application Data\McAfee
2009-09-09 04:39 . 2008-10-25 23:17 -------- d-----w- c:\program files\Speeditup Free
2009-09-09 02:39 . 2003-02-13 05:19 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-09 02:37 . 2003-02-14 07:02 -------- d-----w- c:\program files\Ahead
2009-09-09 02:36 . 2007-11-01 02:42 -------- d-----w- c:\program files\Verizon
2009-09-08 20:31 . 2004-01-25 18:53 115024 ----a-w- c:\documents and settings\L\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-07 20:49 . 2007-11-03 19:56 -------- d-----w- c:\documents and settings\L\Application Data\Verizon
2009-08-14 13:58 . 2009-10-04 19:50 7396 ----a-w- c:\winnt\system32\drivers\pctcore.cat
2009-08-05 09:01 . 2003-02-25 03:53 204800 ----a-w- c:\winnt\system32\mswebdvd.dll
2009-07-17 19:01 . 2001-08-23 12:00 58880 ----a-w- c:\winnt\system32\atl.dll
2009-07-14 06:43 . 2003-02-21 05:47 286208 ----a-w- c:\winnt\system32\wmpdxm.dll
2009-07-08 20:44 . 2009-07-08 20:44 214024 ----a-w- c:\winnt\system32\drivers\mfehidk.sys
2003-02-13 04:50 . 2003-02-13 04:50 21952 ---ha-w- c:\program files\folder.htt
2001-08-23 12:00 . 2001-08-23 12:00 94784 --sh--w- c:\winnt\twain.dll
2008-04-14 00:12 . 2001-08-23 12:00 50688 --sh--w- c:\winnt\twain_32.dll
2008-04-14 00:11 . 2001-08-23 12:00 1028096 --sha-w- c:\winnt\system32\mfc42.dll
2008-04-14 00:12 . 2001-08-23 12:00 57344 --sh--w- c:\winnt\system32\msvcirt.dll
2008-04-14 00:12 . 2001-08-23 12:00 551936 --sh--w- c:\winnt\system32\oleaut32.dll
2008-04-14 00:12 . 2001-08-23 12:00 84992 --sha-w- c:\winnt\system32\olepro32.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-01-26 16:55 . 2007-01-26 16:55 171448 c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe
2006-07-01 03:25 . 2006-07-01 03:25 282624 c:\program files\QuickTime\bak\qttask.exe
2003-02-13 05:32 . 2000-05-11 09:00 90112 c:\winnt\bak\UpdReg.EXE
2003-02-14 06:28 . 2001-06-12 09:13 200704 c:\winnt\system32\spool\drivers\w32x86\3\bak\hpztsb03.exe
2009-02-20 02:33 . 2001-06-12 09:13 200704 c:\winnt\system32\spool\drivers\w32x86\3\hpztsb03.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-12 39408]
"AOL Fast Start"="c:\program files\AOL 9.1\AOL.EXE" [2007-10-27 50528]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-06-06 936960]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 2061816]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
"HPDJ Taskbar Utility"="c:\winnt\system32\spool\drivers\w32x86\3\hpztsb03.exe" [2001-06-12 200704]
"PC-Checkup"="c:\speeditup-checkup\SpeedCheckUp.exe" [2009-09-25 5359104]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-07-10 645328]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-07-23 1181064]
"MsmqIntCert"="mqrt.dll" - c:\winnt\system32\mqrt.dll [2008-04-14 177152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\winnt\system32\tscupgrd.exe" [2004-08-04 44544]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ lsdelete\0autocheck autochk /k:C *
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, msnsspc.dll, digest.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
backup=c:\winnt\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 8.0 Tray Icon.lnk]
backup=c:\winnt\pss\America Online 8.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
backup=c:\winnt\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ExifLauncher2.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk
backup=c:\winnt\pss\ExifLauncher2.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GStartup.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Instant Update Reminder.lnk]
backup=c:\winnt\pss\Instant Update Reminder.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
backup=c:\winnt\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
backup=c:\winnt\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\winnt\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\winnt\pss\WinZip Quick Pick.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreateCD50
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailScan
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Insider
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISMModule4
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Salestart
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SfKg6w
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sscRun
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uwas7cw
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAble
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAntiSpyware 2007 Free
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsService
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinTouch
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Words
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{4F-F5-59-90-ZN}
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCCClient.exe]
[N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pccguide.exe]
[N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pop3trap.exe]
[N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPodService"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"GEARSecurity_BackUp"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"Schedule"=2 (0x2)
"Nla"=3 (0x3)
"Network Monitor"=2 (0x2)
"Netlogon"=3 (0x3)
"napagent"=3 (0x3)
"MSMQ"=2 (0x2)
"MSFTPSVC"=2 (0x2)
"mnmsrvc"=3 (0x3)
"Lavasoft Ad-Aware Service"=2 (0x2)
"KodakCCS"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ImapiService"=3 (0x3)
"hkmsvc"=3 (0x3)
"helpsvc"=2 (0x2)
"Fax"=2 (0x2)
"bgsvcgen"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINNT\\system32\\mqsvc.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Morpheus\\Morpheus.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1178771139\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 Lbd;Lbd;c:\winnt\system32\drivers\Lbd.sys [2/24/2009 9:04 PM 64160]
R0 PCTCore;PCTools KDS;c:\winnt\system32\drivers\PCTCore.sys [10/4/2009 12:50 PM 206256]
R2 IOPort;IOPort;c:\winnt\system32\IOPORT.SYS [2/12/2003 10:09 PM 6144]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/4/2009 12:49 PM 348824]
R3 ctgame;Game Port;c:\winnt\system32\drivers\ctgame.sys [2/12/2003 10:30 PM 10368]
S2 nvTUNEP;nVidia WDM TVTuner;c:\winnt\system32\drivers\NVTUNEP.SYS [2/12/2003 10:19 PM 16032]
S2 nvtvSND;nVidia WDM TVAudio Crossbar;c:\winnt\system32\drivers\NVTVSND.SYS [2/12/2003 10:19 PM 13600]
S3 CA500AI;SPCA500A Still Image Capture, Sunplus Version 1.00;c:\winnt\system32\Drivers\BULKUSB.sys --> c:\winnt\system32\Drivers\BULKUSB.sys [?]
S3 CA500AV;Digital Video Camera(Video);c:\winnt\system32\DRIVERS\CA500AV.SYS --> c:\winnt\system32\DRIVERS\CA500AV.SYS [?]
S3 GearAspiWDM_BackUp;GEARAspiWDM;c:\winnt\system32\drivers\GEARAspiWDM.sys [3/7/2005 12:52 PM 14408]
S4 GEARSecurity_BackUp;GEARSecurity_BackUp;system32\gearsec.exe --> system32\gearsec.exe [?]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 2:34 PM 953168]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\winnt\system32\rundll32.exe" "c:\winnt\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-04-28 c:\winnt\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 03:04]
2009-10-04 c:\winnt\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-04 04:26]
2009-10-04 c:\winnt\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-04 04:26]
2009-10-05 c:\winnt\Tasks\WGASetup.job
- c:\winnt\system32\KB905474\wgasetup.exe [2009-05-12 05:18]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.aol.com/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
Trusted Zone: aol.com\free
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: DirectAnimation Java Classes -
file://c:\winnt\Java\classes\dajava.cabDPF: Microsoft XML Parser for Java -
file://c:\winnt\Java\classes\xmldso.cabDPF: vzTCPConfig -
hxxp://www2.verizon.net/help/fios_settings/include/vzTCPConfig.CABDPF: {D5EC5989-671B-476D-AC86-090793776FB1} -
hxxp://download.ispeedway.com/AuctionBlast/XAuctionBlast.cabDPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} -
hxxp://aolsvc.aol.com/onlinegames/dinerdash/DinerDash.1.0.0.72.cabFF - ProfilePath - c:\documents and settings\L\Application Data\Mozilla\Firefox\Profiles\u144xrxo.default\
FF - prefs.js: browser.startup.homepage -
hxxp://netscape.aol.com/FF - plugin: c:\program files\Common Files\mpDRM\NPMPDRM.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\winnt\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
BHO-{9BDB86D0-49C0-40FB-B790-95F06D9FB3AA} - (no file)
BHO-{D61F7D1C-E004-4C42-81A6-6DF26A89AA3E} - (no file)
Notify-cipldm - cipldm.dll
SafeBoot-sglfb.sys
SafeBoot-tga.sys
AddRemove-AOLAntivirus - c:\program files\mcafee.com\antivirus\uninst.exe
AddRemove-hp deskjet 940c series - c:\program files\hp deskjet 940c series\hpfiui.exe
AddRemove-{F5223680-993A-11D4-86F6-0001031E5712} - c:\program files\InterVideo\Installer\IVIUninstaller.exe
**************************************************************************
disk not found C:\
please note that you need administrator rights to perform deep scan
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\mpDRM\LicenseStore*]
@DACL=
"CheckValue"=dword:ba3464ba
"DA39A3EE"="E5E6B4B0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3696)
c:\winnt\system32\WININET.dll
c:\program files\Spyware Doctor\pctgmhk.dll
c:\program files\AOL Deskbar\deskbar.dll
c:\program files\Common Files\AOL\AOL Toolbar\AOLHelper.dll
c:\program files\Windows Media Player\wmpband.dll
c:\winnt\system32\webcheck.dll
c:\winnt\system32\IEFRAME.dll
c:\winnt\system32\WPDShServiceObj.dll
c:\program files\Common Files\aolshare\aolshcpy.dll
c:\winnt\system32\PortableDeviceTypes.dll
c:\winnt\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\AOL\acs\AOLacsd.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\Command Software\dvpapi.exe
c:\winnt\system32\inetsrv\inetinfo.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\program files\AOL 9.1\waol.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\winnt\PCHEALTH\HELPCTR\Binaries\helpsvc.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\winnt\system32\nvsvc32.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\winnt\system32\tcpsvcs.exe
c:\winnt\system32\snmp.exe
c:\winnt\system32\MsPMSPSv.exe
c:\winnt\system32\wscntfy.exe
c:\program files\AOL 9.1\shellmon.exe
.
**************************************************************************
.
Completion time: 2009-10-06 18:02 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-06 01:02
Pre-Run: 17,150,021,632 bytes free
Post-Run: 17,283,633,152 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINNT
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINNT="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
461 --- E O F --- 2009-10-05 20:21