ComboFix 10-01-04.01 - H3ad Tr1p 01/05/2010 17:02:17.3.1 - x86
Microsoft
Windows Vista
Home Basic 6.0.6002.2.1252.1.1033.18.1012.242 [GMT -6:00]
Running from: c:\users\H3ad Tr1p\Downloads\Combo-Fix.exe
Command switches used :: c:\users\H3ad Tr1p\Desktop\CFScript.txt
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-12-05 to 2010-01-05 )))))))))))))))))))))))))))))))
.
2010-01-05 23:31 . 2010-01-05 23:31 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2010-01-05 23:31 . 2010-01-05 23:31 -------- d-----w- c:\users\H3ad Tr1p\AppData\Local\temp
2010-01-05 23:31 . 2010-01-05 23:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-05 05:55 . 2010-01-05 05:55 -------- d-----w- c:\programdata\McAfee Security Scan
2010-01-05 05:55 . 2010-01-05 05:55 -------- d-----w- c:\program files\McAfee Security Scan
2010-01-04 19:37 . 2010-01-04 19:37 -------- d-----w- c:\program files\TrendMicro
2010-01-04 19:21 . 2010-01-04 19:21 -------- d-----w- c:\users\H3ad Tr1p\AppData\Roaming\Malwarebytes
2010-01-04 07:27 . 2010-01-04 07:27 -------- d-----w- C:\%APPDATA%
2010-01-04 06:44 . 2010-01-04 06:44 -------- d-----w- c:\windows\system32\config\systemprofile\Tracing
2010-01-04 06:08 . 2010-01-04 06:08 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-01-04 06:08 . 2010-01-04 06:57 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-04 06:08 . 2010-01-04 06:08 -------- d-----w- c:\users\H3ad Tr1p\AppData\Roaming\SUPERAntiSpyware.com
2010-01-04 05:47 . 2009-12-30 20:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-04 05:47 . 2010-01-04 05:47 -------- d-----w- c:\programdata\Malwarebytes
2010-01-04 05:47 . 2010-01-04 19:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-04 05:47 . 2009-12-30 20:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-26 04:17 . 2009-12-26 04:17 -------- d-----w- c:\users\H3ad Tr1p\dwhelper
2009-12-26 02:56 . 2009-12-26 02:56 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2009-12-22 01:57 . 2009-12-30 11:05 -------- d-----w- c:\users\H3ad Tr1p\AppData\Local\RapidShare_
2009-12-17 20:31 . 2010-01-05 00:18 -------- d-----w- c:\program files\PeerBlock
2009-12-11 21:43 . 2009-12-12 20:59 -------- d-----w- c:\program files\Windows Live Safety Center
2009-12-11 02:42 . 2009-12-11 02:42 -------- d-----w- c:\programdata\Motive
2009-12-11 02:42 . 2009-12-11 02:42 -------- d-----w- c:\program files\Common Files\Motive
2009-12-11 02:42 . 2009-12-11 02:43 -------- d-----w- c:\program files\ATT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-05 22:49 . 2009-02-15 19:12 -------- d-----w- c:\programdata\Apple Computer
2010-01-05 22:45 . 2008-04-01 22:45 -------- d-----w- c:\program files\Java
2010-01-05 22:39 . 2009-09-10 22:18 -------- d-----w- c:\programdata\NOS
2010-01-05 22:33 . 2008-09-20 10:43 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2010-01-05 10:59 . 2009-06-13 08:59 -------- d-----w- c:\program files\Mozilla Firefox 3.5 Beta 4
2010-01-05 03:44 . 2008-09-25 11:56 -------- d-----w- c:\program files\VstPlugins
2010-01-04 22:00 . 2008-09-19 19:46 -------- d-----w- c:\program files\BitComet
2010-01-04 19:37 . 2010-01-04 19:37 388096 ----a-r- c:\users\H3ad Tr1p\AppData\Roaming\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-04 19:20 . 2010-01-05 14:46 423192 ----a-w- c:\programdata\avg8\update\backup\fixcfg.exe
2010-01-04 19:13 . 2010-01-04 19:16 1126168 ----a-w- c:\programdata\avg8\update\backup\avgupd.exe
2010-01-04 19:13 . 2010-01-04 19:16 1471768 ----a-w- c:\programdata\avg8\update\backup\avgupd.dll
2010-01-04 19:13 . 2010-01-04 19:16 587032 ----a-w- c:\programdata\avg8\update\backup\avgiproxy.exe
2010-01-04 19:13 . 2010-01-04 19:16 758040 ----a-w- c:\programdata\avg8\update\backup\avginet.dll
2010-01-04 08:24 . 2009-10-24 03:48 -------- d-----w- c:\program files\PlaySushi
2010-01-04 06:44 . 2006-11-02 12:59 1356 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\d3d9caps.dat
2010-01-04 06:09 . 2010-01-04 06:09 52224 ----a-w- c:\users\H3ad Tr1p\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-04 06:09 . 2010-01-04 06:09 117760 ----a-w- c:\users\H3ad Tr1p\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-04 05:57 . 2008-12-27 21:33 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-04 05:15 . 2008-09-19 18:44 1095200 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-04 00:41 . 2008-12-27 21:24 -------- d-----w- c:\programdata\avg8
2010-01-03 22:07 . 2010-01-04 19:23 98440 ----a-w- c:\programdata\avg8\update\backup\avgldx86.sys
2010-01-03 22:07 . 2010-01-04 19:23 90632 ----a-w- c:\programdata\avg8\update\backup\avgtdix.sys
2010-01-03 22:07 . 2010-01-04 19:23 26824 ----a-w- c:\programdata\avg8\update\backup\avgmfx86.sys
2010-01-03 22:07 . 2010-01-04 19:23 287000 ----a-w- c:\programdata\avg8\update\backup\avgrsx.exe
2010-01-03 22:07 . 2010-01-04 19:23 10520 ----a-w- c:\programdata\avg8\update\backup\avgrsstx.dll
2010-01-03 22:07 . 2010-01-04 19:23 12936 ----a-w- c:\programdata\avg8\update\backup\avgrkx86.sys
2009-12-31 08:49 . 2008-11-23 21:06 3452 ----a-w- c:\users\H3ad Tr1p\AppData\Roaming\wklnhst.dat
2009-12-26 21:12 . 2009-12-26 21:12 7631232 ----a-w- c:\users\H3ad Tr1p\AppData\Roaming\MySpace\IM\Install\MSIMClientSetup.1.0.823.0-static-A.exe
2009-12-26 03:00 . 2008-09-19 18:52 1095200 ----a-w- c:\users\H3ad Tr1p\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-26 02:56 . 2008-04-01 22:53 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-24 01:32 . 2008-09-26 07:17 -------- d-----w- c:\program files\Common Files\Apple
2009-12-19 23:00 . 2008-09-20 10:24 -------- d-----w- c:\programdata\Yahoo! Companion
2009-11-22 09:18 . 2009-10-29 06:37 -------- d-----w- c:\program files\Native Instruments
2009-11-21 07:46 . 2009-11-02 05:18 256 ----a-w- c:\windows\system32\pool.bin
2009-11-14 05:19 . 2008-11-25 10:05 5216 ----a-w- c:\users\H3ad Tr1p\AppData\Local\d3d9caps.dat
2009-11-03 02:42 . 2009-10-03 06:36 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-31 12:15 . 2009-10-31 12:15 3128 ----a-r- c:\users\H3ad Tr1p\AppData\Roaming\Microsoft\Installer\{DB1299AF-9EE0-422B-959E-F4171B2AE0F7}\ARPPRODUCTICON.exe
2009-10-25 09:44 . 2009-10-25 09:44 2899968 ----a-w- c:\programdata\TuneUp Software\TuneUp Utilities\WinStyler\LogonScreens\Asightforsoreeyes[1].tls.dll
2009-10-17 02:53 . 2009-10-28 00:22 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-04-02 06:25 . 2008-04-02 06:08 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
2008-01-19 07:33 . 2008-10-01 01:24 397312 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fb\WinMail.exe
2008-01-19 07:33 . 2008-10-01 01:24 397312 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_f343a6944cd6fe47\WinMail.exe
.
(((((((((((((((((((((((((((((
SnapShot@2010-01-05_01.37.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-01 23:07 . 2010-01-05 22:41 79970 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:02 . 2010-01-05 22:41 99930 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-09-19 19:07 . 2010-01-05 22:41 18000 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3456936367-870237319-2048447241-1000_UserData.bin
+ 2010-01-05 05:55 . 2010-01-05 05:55 84507 c:\windows\System32\Macromed\Flash\uninstall_activeX.exe
+ 2008-09-19 18:40 . 2010-01-05 22:52 49152 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-09-19 18:40 . 2010-01-05 00:22 49152 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-20 23:01 . 2010-01-05 00:22 16384 c:\windows\System32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
+ 2009-10-20 23:01 . 2010-01-05 22:38 16384 c:\windows\System32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
+ 2009-08-01 02:20 . 2010-01-05 02:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-08-01 02:20 . 2010-01-04 22:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-08-01 02:20 . 2010-01-05 02:11 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-08-01 02:20 . 2010-01-04 22:08 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-08-01 02:20 . 2010-01-05 02:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-08-01 02:20 . 2010-01-04 22:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-20 09:36 . 2010-01-05 22:36 6664 c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2008-09-20 09:36 . 2010-01-05 00:20 6664 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2010-01-05 22:38 . 2010-01-05 22:38 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-01-05 00:21 . 2010-01-05 00:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-01-05 00:21 . 2010-01-05 00:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-01-05 22:38 . 2010-01-05 22:38 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-09-20 10:43 . 2010-01-05 22:33 2560 c:\windows\_MSRSTRT.EXE
- 2008-09-20 10:43 . 2008-09-20 10:43 2560 c:\windows\_MSRSTRT.EXE
+ 2009-11-03 00:24 . 2009-11-03 00:24 257440 c:\windows\System32\Macromed\Flash\FlashUtil10d.exe
+ 2009-10-20 22:49 . 2010-01-05 22:46 262144 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\UsrClass.dat
- 2009-10-20 22:49 . 2009-10-20 22:49 262144 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\UsrClass.dat
+ 2008-09-19 18:40 . 2010-01-05 22:52 753664 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-19 18:40 . 2010-01-05 00:22 753664 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-19 18:40 . 2010-01-05 00:22 147456 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-19 18:40 . 2010-01-05 22:52 147456 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-01 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\aafc447d-9e50-4f0b-b9aa-681047ef7c9b.exe" [2009-12-16 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="realsched.exe -osboot" [X]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-12-18 307200]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-01-05 2043160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2009-12-01 6373376]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10c.exe" [2009-07-18 257440]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
2008-08-14 05:04 206064 ----a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2008-02-14 00:21 16384 ----a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
2008-01-18 11:40 17920 ----a-w- c:\dell\E-Center\EULALauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-02-12 01:13 166424 ----a-w- c:\windows\System32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-02-12 01:13 141848 ----a-w- c:\windows\System32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-05-27 02:06 4351216 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 21:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2007-09-17 16:56 124200 ------w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-02-12 01:13 133656 ----a-w- c:\windows\System32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-01-17 12:22 4907008 ----a-w- c:\windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 ----a-w- c:\program files\Winamp\winampa.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" -autorun
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"BlackBerryAutoUpdate"=c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
"Persistence"=c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):01,68,28,59,0e,34,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3456936367-870237319-2048447241-1000]
"EnableNotificationsRef"=dword:00000001
R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [12/27/2008 3:25 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [12/27/2008 3:25 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [1/12/2009 8:53 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/16/2009 4:26 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/16/2009 4:26 PM 74480]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [1/4/2010 1:20 PM 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/4/2010 1:20 PM 297752]
R3 CLEDX;Team H2O CLEDX service;c:\windows\System32\drivers\cledx.sys [10/29/2009 2:53 PM 33792]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/16/2009 4:27 PM 7408]
R3 wsvad_driver;WS Audio Device;c:\windows\System32\drivers\VirtualAudio.sys [11/3/2009 1:35 PM 16896]
S2 gupdate1c9b6aef4017230;Google Update Service (gupdate1c9b6aef4017230);c:\program files\Google\Update\GoogleUpdate.exe [4/6/2009 5:57 AM 133104]
S3 DsAudioDevice_286;DsAudioDevice_286;c:\windows\System32\drivers\DsAudioDevice_286.sys [11/3/2009 1:01 PM 16640]
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\System32\drivers\netr28u.sys [9/19/2008 12:59 PM 552448]
S3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [12/17/2009 2:31 PM 16472]
S4 sptd;sptd;c:\windows\System32\drivers\sptd.sys [9/23/2008 2:11 AM 717296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-01-01 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2008-01-08 19:31]
2010-01-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-04-01 09:36]
2010-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-06 11:55]
2010-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-06 11:55]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.att.netuInternet Settings,ProxyOverride = *.local
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: {{5CFA5B80-01F4-420F-B18B-545712C8A1C8} -
http://www.playsushi.com/About.ps?l=6&t=nG78JEwyBFF - ProfilePath - c:\users\H3ad Tr1p\AppData\Roaming\Mozilla\Firefox\Profiles\gboxs65v.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.realraptalk.comFF - component: c:\program files\MySpace\Toolbar\1.0.56.0\components\MySpaceFFoxTB.dll
FF - component: c:\users\H3ad Tr1p\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@playsushi.com\components\PlaySushiFF.dll
FF - component: c:\users\H3ad Tr1p\AppData\Roaming\Mozilla\Firefox\Profiles\gboxs65v.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - plugin: c:\program files\Common Files\Motive\npMotive.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox 3.5 Beta 4\plugins\NPMyWebS.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\H3ad Tr1p\AppData\Roaming\Mozilla\Firefox\Profiles\gboxs65v.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 3
FF - user.js: content.max.tokenizing.time - 1500000
FF - user.js: content.notify.interval - 750000
FF - user.js: content.switch.threshold - 750000
FF - user.js: nglayout.initialpaint.delay - 100
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
**************************************************************************
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files:
**************************************************************************
.
Completion time: 2010-01-05 17:40:38
ComboFix-quarantined-files.txt 2010-01-05 23:40
ComboFix2.txt 2010-01-05 01:47
ComboFix3.txt 2010-01-04 08:51
Pre-Run: 1,800,892,416 bytes free
Post-Run: 2,081,329,152 bytes free
- - End Of File - - 1226399DE19173FF3FCCAB28B0B5917D