ComboFix 10-09-01.04 - Debbie 09/02/2010 18:58:17.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2257 [GMT -5:00]
Running from: c:\documents and settings\Debbie\desktop\commy.exe
Command switches used :: /stepdel
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\wpcap.dll
c:\documents and settings\All Users\Application Data\vlc-1.1.3-win32.exe
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\vmreg32.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2010-08-03 to 2010-09-03 )))))))))))))))))))))))))))))))
.
2010-09-02 19:45 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-02 19:45 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-02 17:53 . 2010-09-02 17:54 -------- d-----w- c:\program files\Microsoft Money 2007
2010-09-01 23:55 . 2010-09-01 23:55 -------- d-----w- c:\documents and settings\Debbie\Local Settings\Application Data\Threat Expert
2010-09-01 21:06 . 2010-09-02 00:42 -------- d-----w- c:\program files\Common Files\PC Tools
2010-09-01 21:06 . 2010-09-01 21:06 -------- d-----w- c:\documents and settings\Debbie\Application Data\PC Tools
2010-09-01 21:02 . 2010-09-01 21:04 80729096 ----a-w- c:\documents and settings\All Users\Application Data\PC Tools\DownloadManager\Spyware Doctor8.0\sdsetup_aff_dl.exe
2010-09-01 21:02 . 2010-09-02 00:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-09-01 20:39 . 2010-09-01 20:39 -------- d-----w- c:\documents and settings\Debbie\Application Data\Malwarebytes
2010-09-01 20:39 . 2010-09-01 20:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-31 16:19 . 2010-08-31 17:39 -------- d-----w- c:\program files\Microsoft
2010-08-31 16:19 . 2010-08-31 16:19 -------- d-----w- c:\program files\Microsoft Silverlight
2010-08-31 16:13 . 2010-08-31 16:13 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-08-31 16:12 . 2010-08-31 16:13 -------- d-----w- c:\windows\SHELLNEW
2010-08-31 16:12 . 2010-08-31 16:12 -------- d-----w- c:\program files\Microsoft.NET
2010-08-31 00:47 . 2010-08-31 00:48 -------- d-----w- c:\documents and settings\Debbie\Application Data\SolSuite
2010-08-31 00:47 . 2010-08-31 00:47 -------- d-----w- c:\documents and settings\All Users\Application Data\TreeCardGames
2010-08-30 17:00 . 2010-08-30 17:00 -------- d-----w- c:\documents and settings\Debbie\Application Data\Outertech
2010-08-29 21:06 . 2010-08-29 21:06 -------- d-----w- c:\documents and settings\Debbie\Application Data\TheGreatPharaoh
2010-08-29 04:29 . 2010-08-29 04:29 -------- d-----w- c:\documents and settings\Debbie\Application Data\SpinTop Games
2010-08-29 04:03 . 2010-08-29 04:03 -------- d-----w- c:\documents and settings\Debbie\Local Settings\Application Data\SpiritVG
2010-08-27 17:50 . 2010-08-27 17:50 -------- d-----w- c:\documents and settings\Debbie\Application Data\Enki Games
2010-08-26 01:04 . 2010-08-26 01:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Veronica&BoD
2010-08-25 18:24 . 2006-10-27 00:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-08-25 18:24 . 2008-11-10 16:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2010-08-25 18:18 . 2010-08-25 18:18 -------- d-----w- c:\documents and settings\Debbie\Local Settings\Application Data\Microsoft Help
2010-08-25 18:18 . 2010-08-27 15:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-24 18:16 . 2010-08-24 18:16 -------- d-----w- c:\documents and settings\Debbie\Local Settings\Application Data\Yahoo
2010-08-24 18:15 . 2010-08-24 18:18 -------- d-----w- c:\documents and settings\Debbie\Application Data\vlc
2010-08-24 18:14 . 2010-08-24 18:14 -------- d-----w- c:\documents and settings\Debbie\Local Settings\Application Data\WeatherBug
2010-08-24 18:14 . 2010-08-24 18:14 -------- d-----w- c:\documents and settings\Debbie\Application Data\WeatherBug
2010-08-24 18:14 . 2010-08-24 18:14 18944 ----a-r- c:\documents and settings\Debbie\Application Data\Microsoft\Installer\{8F018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A16301.exe
2010-08-24 18:14 . 2010-08-24 18:14 -------- d-----w- c:\program files\VideoLAN
2010-08-24 18:14 . 2010-08-24 18:14 -------- d-----w- c:\program files\Free Offers from Freeze.com
2010-08-24 18:14 . 2010-08-24 19:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-08-24 18:14 . 2010-08-24 18:14 646144 ----a-w- c:\documents and settings\Debbie\Application Data\FCSB000062035\Toolbar\ShoppingBHO.dll
2010-08-24 18:14 . 2010-08-24 18:14 -------- d-----w- c:\documents and settings\Debbie\Application Data\FCSB000062035
2010-08-24 18:13 . 2010-08-24 18:13 -------- d-----w- c:\documents and settings\Debbie\Application Data\Yahoo!
2010-08-23 03:36 . 2010-08-23 03:36 -------- d-----w- c:\documents and settings\Debbie\Application Data\Gamers Digital
2010-08-23 03:36 . 2010-08-23 03:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Gamers Digital
2010-08-21 04:00 . 2010-08-21 04:00 -------- d-----w- c:\documents and settings\Debbie\Application Data\TOMI2.THE GATES OF FATE
2010-08-19 17:04 . 2004-03-08 23:40 57344 ----a-w- c:\windows\system32\icmfilter.dll
2010-08-19 17:04 . 2004-03-08 23:40 32768 ----a-w- c:\windows\system32\plugin.dll
2010-08-19 17:04 . 2004-03-08 23:40 210944 ----a-w- c:\windows\system32\Msvcrt10.dll
2010-08-18 20:41 . 2010-08-18 20:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Gogii
2010-08-18 19:42 . 2010-08-18 19:42 -------- d-----w- c:\documents and settings\Debbie\Application Data\SunRay Games
2010-08-13 18:36 . 2010-08-13 18:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Exorcist DS 7
2010-08-12 18:17 . 2010-08-12 18:17 -------- d-----w- c:\documents and settings\Debbie\Application Data\GameHouse
2010-08-09 14:25 . 2010-08-09 14:25 -------- d-----w- c:\documents and settings\Debbie\Local Settings\Application Data\Thinstall
2010-08-09 14:25 . 2010-08-09 14:25 -------- d-----w- c:\documents and settings\Debbie\Application Data\Thinstall
2010-08-08 21:00 . 2010-08-08 21:00 -------- d-----w- c:\windows\Sun
2010-08-08 16:30 . 2010-08-08 16:30 -------- d-----w- c:\documents and settings\Debbie\Application Data\Anarchy
2010-08-08 15:34 . 2010-08-08 15:34 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-08 15:32 . 2010-08-08 15:32 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-08-08 15:32 . 2010-08-08 15:32 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-08-08 15:31 . 2010-08-08 15:31 77184 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-08-08 15:31 . 2010-08-17 21:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-08-08 02:22 . 2010-08-08 02:22 -------- d-----w- c:\documents and settings\Debbie\Application Data\Bicyclestudios
2010-08-08 02:22 . 2010-08-08 02:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Bicyclestudios
2010-08-06 20:24 . 2010-08-06 20:24 -------- d-----w- c:\documents and settings\Debbie\Application Data\Enlightenus2_BFG
2010-08-06 20:04 . 2010-08-06 20:04 -------- d-----w- c:\documents and settings\Debbie\Application Data\Orneon
2010-08-05 04:27 . 2010-08-05 04:27 503808 ----a-w- c:\documents and settings\Debbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-30d79a20-n\msvcp71.dll
2010-08-05 04:27 . 2010-08-05 04:27 499712 ----a-w- c:\documents and settings\Debbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-30d79a20-n\jmc.dll
2010-08-05 04:27 . 2010-08-05 04:27 348160 ----a-w- c:\documents and settings\Debbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-30d79a20-n\msvcr71.dll
2010-08-05 04:27 . 2010-08-05 04:27 61440 ----a-w- c:\documents and settings\Debbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-4e9dda51-n\decora-sse.dll
2010-08-05 04:27 . 2010-08-05 04:27 12800 ----a-w- c:\documents and settings\Debbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-4e9dda51-n\decora-d3d.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-03 00:01 . 2010-06-07 18:23 8544 ----a-w- c:\windows\system32\drivers\sthdae.log
2010-09-02 00:41 . 2010-06-08 01:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-31 18:12 . 2010-07-14 03:21 -------- d-----w- c:\documents and settings\Debbie\Application Data\Big Fish Games
2010-08-30 16:51 . 2010-06-12 15:20 -------- d-----w- c:\documents and settings\Debbie\Application Data\HpUpdate
2010-08-30 16:40 . 2010-06-06 20:47 67216 ----a-w- c:\documents and settings\Debbie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-30 16:21 . 2010-08-01 20:04 517464 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-08-27 15:31 . 2010-06-07 00:15 -------- d-----w- c:\program files\MSBuild
2010-08-24 19:28 . 2010-06-12 03:21 117537 ----a-w- c:\windows\hpoins11.dat
2010-08-24 00:30 . 2010-06-14 20:25 -------- d-----w- c:\documents and settings\All Users\Application Data\MumboJumbo
2010-08-21 15:19 . 2010-06-27 19:29 46 ----a-w- c:\documents and settings\Debbie\jagex_runescape_preferences.dat
2010-08-21 15:18 . 2010-06-27 19:30 99 ----a-w- c:\documents and settings\Debbie\jagex_runescape_preferences2.dat
2010-08-21 04:00 . 2010-06-21 17:43 -------- d-----w- c:\documents and settings\All Users\Application Data\AlawarWrapper
2010-08-16 04:50 . 2010-08-01 18:35 -------- d-----w- c:\documents and settings\Debbie\Application Data\RunningPillow
2010-08-12 18:17 . 2010-06-22 01:18 -------- d-----w- c:\documents and settings\All Users\Application Data\GameHouse
2010-08-01 18:45 . 2010-08-01 18:45 -------- d-----w- c:\program files\Common Files\Java
2010-08-01 18:44 . 2010-08-01 18:44 61440 ----a-w- c:\documents and settings\Debbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4fdb862f-n\decora-sse.dll
2010-08-01 18:44 . 2010-08-01 18:44 12800 ----a-w- c:\documents and settings\Debbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4fdb862f-n\decora-d3d.dll
2010-08-01 18:44 . 2010-08-01 18:44 503808 ----a-w- c:\documents and settings\Debbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5eeab882-n\msvcp71.dll
2010-08-01 18:44 . 2010-08-01 18:44 499712 ----a-w- c:\documents and settings\Debbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5eeab882-n\jmc.dll
2010-08-01 18:44 . 2010-08-01 18:44 348160 ----a-w- c:\documents and settings\Debbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5eeab882-n\msvcr71.dll
2010-08-01 18:44 . 2010-08-01 18:44 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-01 18:44 . 2010-08-01 18:44 -------- d-----w- c:\program files\Java
2010-07-31 17:48 . 2010-07-31 17:47 -------- d-----w- c:\documents and settings\Debbie\Application Data\Trio
2010-07-30 21:54 . 2010-07-30 21:54 -------- d-----w- c:\documents and settings\Debbie\Application Data\ERS Game Studios
2010-07-29 20:12 . 2010-07-29 20:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Alawar Stargaze
2010-07-29 04:45 . 2010-07-29 04:45 -------- d-----w- c:\documents and settings\Debbie\Application Data\Vast Studios
2010-07-28 18:04 . 2010-07-28 18:04 -------- d-----w- c:\documents and settings\Debbie\Application Data\MysteriousCaseOfJekyllAndHyde
2010-07-27 23:48 . 2010-07-27 18:00 -------- d-----w- c:\documents and settings\Debbie\Application Data\Total Eclipse
2010-07-25 18:08 . 2010-07-25 18:08 -------- d-----w- c:\program files\Western Digital Corporation
2010-07-21 20:39 . 2010-07-21 20:39 -------- d-----w- c:\documents and settings\Debbie\Application Data\GameMill Entertainment
2010-07-21 19:56 . 2010-07-21 19:55 -------- d-----w- c:\documents and settings\Debbie\Application Data\SprillBermudeEng
2010-07-19 20:27 . 2010-07-19 20:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Particles
2010-07-19 20:26 . 2010-07-19 20:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Far Mills
2010-07-18 14:53 . 2010-06-06 23:38 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-18 14:53 . 2010-07-18 14:53 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-18 14:53 . 2010-06-06 23:38 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-18 01:28 . 2010-07-18 01:28 -------- d-----w- c:\documents and settings\Debbie\Application Data\Vogat Interactive
2010-07-17 20:41 . 2010-07-17 20:41 -------- d-----w- c:\documents and settings\Debbie\Application Data\CannyGames
2010-07-14 17:59 . 2010-07-14 17:59 -------- d-----w- c:\documents and settings\Debbie\Application Data\TikisLab
2010-07-14 17:57 . 2010-07-14 17:50 -------- d-----w- c:\documents and settings\Debbie\Application Data\OtherSide Realm of Eons
2010-07-14 17:50 . 2010-07-05 18:34 -------- d-----w- c:\documents and settings\Debbie\Application Data\PlayFirst
2010-07-14 17:50 . 2010-07-05 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2010-07-13 23:55 . 2010-07-13 23:55 -------- d-----w- c:\documents and settings\Debbie\Application Data\Floodlight Games
2010-07-13 23:55 . 2010-07-13 23:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Floodlight Games
2010-07-12 00:17 . 2010-07-12 00:17 -------- d-----w- c:\documents and settings\Debbie\Application Data\Silverback Productions
2010-07-12 00:16 . 2010-07-12 00:16 4096 ----a-w- c:\windows\d3dx.dat
2010-07-11 21:47 . 2010-07-11 21:47 -------- d-----w- c:\documents and settings\Debbie\Application Data\Pi Eye Games
2010-07-10 19:15 . 2010-07-10 19:15 -------- d-----w- c:\documents and settings\Debbie\Application Data\KranX Productions
2010-07-06 17:31 . 2010-07-06 17:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Redrum
2010-07-06 16:33 . 2010-06-17 18:43 -------- d-----w- c:\documents and settings\Debbie\Application Data\ERS G-Studio
2010-07-06 16:25 . 2010-07-06 16:15 -------- d-----w- c:\documents and settings\Debbie\Application Data\Paige Harper and the Tome of Mystery
2010-07-06 15:58 . 2010-07-06 15:58 -------- d-----w- c:\documents and settings\Debbie\Application Data\VendelGAMES
2010-07-05 04:16 . 2010-07-05 04:16 -------- d-----w- c:\documents and settings\All Users\Application Data\GamePlastic
2010-06-30 12:31 . 2001-08-23 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-27 19:30 . 2010-06-27 19:30 0 ----a-w- c:\documents and settings\Debbie\jagex__preferences3.dat
2010-06-27 19:28 . 2010-06-27 19:28 33982 ----a-r- c:\documents and settings\Debbie\Application Data\Microsoft\Installer\{8EE72D39-DE32-4069-9E72-C1974546EFDD}\runescape.exe
2010-06-26 00:06 . 2010-06-26 00:06 16384 ----a-r- c:\documents and settings\Debbie\Application Data\Microsoft\Installer\{D085A1B6-90A4-11D3-82B7-00C04FA309DE}\MnyIco.exe
2010-06-24 12:15 . 2001-08-23 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 12:15 . 2004-08-04 07:56 78336 ------w- c:\windows\system32\ieencode.dll
2010-06-24 12:15 . 2001-08-23 12:00 17408 ------w- c:\windows\system32\corpol.dll
2010-06-23 13:44 . 2001-08-23 12:00 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2001-08-23 12:00 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2001-08-23 12:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2010-06-06 20:25 744448 ----a-w- c:\windows\PCHEALTH\HELPCTR\Binaries\helpsvc.exe
2010-06-14 07:41 . 2001-08-23 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-07 15:04 . 2010-06-06 20:25 86327 ----a-w- c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat
2010-06-07 14:57 . 2010-06-06 23:38 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-06-07 00:43 . 2010-06-07 00:43 1956808 ----a-w- c:\documents and settings\Debbie\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdateax\fpupdateax.exe2010-06-06 23:10 . 2010-06-06 23:10 409600 ----a-w- c:\windows\system32\wrap_oal.dll
2010-06-06 23:10 . 2010-06-06 23:10 114688 ----a-w- c:\windows\system32\OpenAL32.dll
2010-06-06 23:09 . 2010-06-06 23:09 230 ----a-w- c:\windows\ctrunonce.reg
2010-06-06 20:36 . 2010-06-06 20:36 45056 ----a-r- c:\documents and settings\Debbie\Application Data\Microsoft\Installer\{2764CA82-DFB9-4498-AF85-719340BF5305}\NewShortcut1_2764CA82DFB94498AF85719340BF5305.exe
2010-06-06 20:36 . 2010-06-06 20:36 10134 ----a-r- c:\documents and settings\Debbie\Application Data\Microsoft\Installer\{2764CA82-DFB9-4498-AF85-719340BF5305}\ARPPRODUCTICON.exe
2010-06-06 20:24 . 2010-06-06 20:24 21640 ----a-w- c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
"AVG9_TRAY"="p:\avg\AVG9~1\avgtray.exe" [2010-07-18 2065760]
"IDTSysTrayApp"="sttray.exe" [2007-09-06 405504]
"cctray"="p:\ca internet security suite\cctray\cctray.exe" [2010-06-10 177392]
"QOELOADER"="p:\ca internet security suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2010-06-10 14088]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"UnlockerAssistant"="p:\unnlocker\UnlockerAssistant.exe" [2010-07-04 17408]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2010-5-10 4456448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-18 14:53 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"p:\\AVG\\AVG 9\\avgemc.exe"=
"p:\\AVG\\AVG 9\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"p:\\Pando\\Pando.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56137:TCP"= 56137:TCP:Pando
"56137:UDP"= 56137:UDP:Pando
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/6/2010 6:38 PM 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/6/2010 6:38 PM 243024]
R2 avg9emc;AVG Free E-mail Scanner;p:\avg\AVG 9\avgemc.exe [7/18/2010 9:53 AM 921952]
R2 avg9wd;AVG Free WatchDog;p:\avg\AVG 9\avgwdsvc.exe [7/18/2010 9:53 AM 308136]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [5/10/2010 11:33 AM 110592]
R2 WDFME;WD File Management Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [5/10/2010 11:32 AM 1858048]
R2 WDSC;WD File Management Shadow Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [5/10/2010 11:32 AM 482304]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/2/2010 2:45 PM 20952]
R3 PPCtlPriv;PPCtlPriv;p:\ca internet security suite\CA Anti-Spyware\PPCtlPriv.exe [8/16/2007 9:10 PM 189704]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [6/8/2010 12:20 PM 11520]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 MBAMService;MBAMService;"p:\malwarebytes' anti-malware\mbamservice.exe" --> p:\malwarebytes' anti-malware\mbamservice.exe [?]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [3/10/2010 8:18 AM 24216]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
2010-09-02 c:\windows\Tasks\CAAntiSpywareScan_Daily as Debbie at 2 43 PM.job
- p:\ca internet security suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-17 02:10]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://wendysforum.net/index.php/board,4.0.htmlIE: Druid: Download All Files - p:\download druid\Druid.html
IE: Druid: Download Highlighted Files - p:\download druid\DruidHighLighted.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Weather - c:\program files\AWS\WeatherBug\Weather.exe
HKCU-Run-DriverCure - c:\program files\ParetoLogic\DriverCure\DriverCure.exe
HKLM-Run-Malwarebytes' Anti-Malware - p:\malwarebytes' anti-malware\mbamgui.exe
AddRemove-A Gypsys Tale The Tower of Secrets 1.00 - g:\wendysforum\A Gypsy's Tale - The Tower of Secrets\A Gypsy's Tale - The Tower of Secrets\Uninstall.exe
AddRemove-Adrianne Stone: Hidden Relics - g:\!hogs #a\Adrianne Stone Hidden Relics\Adrianne Stone Hidden Relics\uninstall.exe
AddRemove-Agatha Christie 450 from Paddington 1.00 - g:\wendysforum\Agatha Christie - 450 from Paddington\Agatha Christie - 450 from Paddington\Uninstall.exe
AddRemove-Al Emmos Postcards from Anozira 1.00 - g:\wendysforum\Al Emmo's Postcards from Anozira\Al Emmo's Postcards from Anozira\Uninstall.exe
AddRemove-Ancient Adventures Gift of Zeus 1.00 - g:\wendysforum\Ancient Adventures - Gift of Zeus\Ancient Adventures - Gift of Zeus\Uninstall.exe
AddRemove-Artifacts of the Past Ancient Mysteries 1.00 - g:\wendysforum\Artifacts of The Past - Ancient Mysteries\Artifacts of The Past - Ancient Mysteries\Uninstall.exe
AddRemove-Barnyard Sherlock Hooves 1.00 - g:\wendysforum\Barnyard Sherlock Hooves\Barnyard Sherlock Hooves\Uninstall.exe
AddRemove-Biggest Little Adventure 1.00 - g:\wendysforum\Biggest Little Adventure\Biggest Little Adventure\Uninstall.exe
AddRemove-Blood Oath 1.00 - g:\wendysforum\Blood Oath\Blood Oath\Uninstall.exe
AddRemove-Brunhilda and the Dark Crystal 1.00 - g:\wendysforum\Brunhilda and The Dark Crystal\Brunhilda and The Dark Crystal\Uninstall.exe
AddRemove-BumbleBee Jewel 1.00 - g:\wendysforum\_Match 3\Bumblebee Jewel\Bumblebee Jewel\Uninstall.exe
AddRemove-Classic Adventures The Great Gatsby 1.00 - g:\wendysforum\Classic Adventures - The Great Gatsby\Classic Adventures - The Great Gatsby\Uninstall.exe
AddRemove-Dr Despicables Dastardly Deeds 1.00 - g:\wendysforum\_Match 3\Dr Despicable's Dastardly Deeds\Dr Despicable's Dastardly Deeds\Uninstall.exe
AddRemove-Drawn 2 Dark Flight Collectors Edition 1.00 - i:\wendysforum\Drawn 2 - Dark Flight CE\Drawn 2 - Dark Flight CE\Uninstall.exe
AddRemove-Dream Chronicles 4 Book of Air CE 1.00 - g:\wendysforum\Dream Chronicles 4 - Book of Air CE\Dream Chronicles 4 - Book of Air CE\Uninstall.exe
AddRemove-Echoes of the Past The Castle of Shadows Collectors Edition 1.00 - g:\wendysforum\Echoes of The Past - The Castle of Shodows CE\Echoes of The Past - The Castle of Shadows CE\Uninstall.exe
AddRemove-El Sello Magico The False Heiress 1.00 - i:\wendysforum\_Match 3\El Sello Magico - The False Heiress\El Sello Magico - The False Heiress\Uninstall.exe
AddRemove-Elixir of Immortality 1.00 - g:\wendysforum\Elixir of Immortality\Elixir of Immortality\Uninstall.exe
AddRemove-Enlightenus 2 The Timeless Tower Collectors Edition 1.00 - g:\wendysforum\Enlightenus 2 - The Timeless Tower CE\Enlightenus 2 - The Timeless Tower CE\Uninstall.exe
AddRemove-Exorcist 1.00 - g:\wendysforum\Exorcist\Exorcist\Uninstall.exe
AddRemove-Explorer Contraband Mystery 1.00 - g:\wendysforum\Explorer - Contraband Mystery\Explorer - Contraband Mystery\Uninstall.exe
AddRemove-Flux Family Secrets The Rabbit Hole Collectors Edition 1.00 - g:\wendysforum\Flux Family Secrets - The Rabbit Hole\Flux Family Secrets - The Rabbit Hole\Uninstall.exe
AddRemove-Golden Trails The New Western Rush 1.00 - g:\wendysforum\Golden Trails - The New Western Rush\Golden Trails - The New Western Rush\Uninstall.exe
AddRemove-Haunted Hotel 3 Lonely Dream 1.00 - i:\wendysforum\Haunted Hotel 3 - Lonely Dream\Haunted Hotel 3 - Lonely Dream\Uninstall.exe
AddRemove-Hidden Mysteries Vampire Secrets 1.00 - g:\wendysforum\Hidden Mysteries - Vampire Secrets\Hidden Mysteries - Vampire Secrets\Uninstall.exe
AddRemove-Hotel Collectors Edition 1.00 - g:\wendysforum\Hotel Collectors Edition\Hotel Collectors Edition\Uninstall.exe
AddRemove-I Spy Fantasy 1.00 - g:\wendysforum\I Spy Fantasy\I Spy Fantasy\Uninstall.exe
AddRemove-I SPY Mystery 1.00 - g:\wendysforum\I Spy Mystery\I Spy Mystery\Uninstall.exe
AddRemove-Immortal Lovers 1.00 - g:\wendysforum\Immortal Lovers\Immortal Lovers\Uninstall.exe
AddRemove-Insider Tales Vanished In Rome 1.00 - g:\wendysforum\Insider Tales - Vanished in Rome\Insider Tales - Vanished in Rome\Uninstall.exe
AddRemove-It's All About Masks 1.00 - g:\wendysforum\It's All About Masks\It's All About Masks\Uninstall.exe
AddRemove-Journalistic Investigations Stolen Inheritance 1.00 - g:\wendysforum\Journalistic Investigations - Stolen Inheritance\Journalistic Investigations - Stolen Inheritance\Uninstall.exe
AddRemove-Journalistic Stories 1.00 - g:\wendysforum\Journalistic Stories\Journalistic Stories\Uninstall.exe
AddRemove-Kate Arrow Deserted Wood 1.00 - g:\wendysforum\Kate Arrow - Deserted Wood\Kate Arrow - Deserted Wood\Uninstall.exe
AddRemove-Laby 1.00 - g:\wendysforum\_Match 3\Laby\Laby\Uninstall.exe
AddRemove-Legacy Lonesome Mansion 1.00 - g:\wendysforum\_Match 3\Legacy - Lonesome Mansion\Legacy - Lonesome Mansion\Uninstall.exe
AddRemove-Love Chronicles The Spell Collectors Edition 1.00 - g:\wendysforum\Love Chronicles - The Spell CE\Love Chronicles - The Spell CE\Uninstall.exe
AddRemove-Memorabilia Mias Mysterious Memory Machine 1.00 - g:\wendysforum\Memorabilia - Mia's Mysterious Memory Machine\Memorabilia - Mia's Mysterious Memory Machine\Uninstall.exe
AddRemove-Midnight Mysteries 2 Salem Witch Trials 1.00 - g:\wendysforum\Midnight Mysteries 2 - Salem Witch Trials\Midnight Mysteries 2 - Salem Witch Trials\Uninstall.exe
AddRemove-Mysterious Travel The Magic Diary 1.00 - g:\wendysforum\Mysterious Travel - The Magic Diary\Mysterious Travel - The Magic Diary\Uninstall.exe
AddRemove-Mystery P.I. Stolen in San Francisco 1.00 - i:\wendysforum\Mystery PI - Stolen in San Francisco\Mystery PI - Stolen in San Francisco\Uninstall.exe
AddRemove-Mystic Diary Haunted Island 1.00 - g:\wendysforum\Mystic Diary - Haunted Island\Mystic Diary - Haunted Island\Uninstall.exe
AddRemove-Nemos Secret The Nautilus 1.00 - g:\wendysforum\Nemo's Secret - The Nautilus\Nemo's Secret - The Nautilus\Uninstall.exe
AddRemove-Nightfall Mysteries Asylum Conspiracy 1.00 - g:\wendysforum\Nightfall Mysteries - Asylum Conspiracy\Nightfall Mysteries - Asylum Conspiracy\Uninstall.exe
AddRemove-Paige Harper and the Tome of Mystery 1.00 - g:\wendysforum\Paige Harper and The Tome of Mystery\Paige Harper and The Tome of Mystery\Uninstall.exe
AddRemove-PJ Pride Pet Detective 2.10 - g:\wendysforum\PJ Pride Pet Detective\PJ Pride Pet Detective\Uninstall.exe
AddRemove-Puppet Show Souls of the Innocent CE 1.00 - g:\wendysforum\Puppet Show - Souls of The Innocent CE\Puppet Show - Souls of The Innocent CE\Uninstall.exe
AddRemove-Redemption Cemetery Curse of the Raven Collectors Edition 1.00 - g:\wendysforum\Redemption Cemetery - Curse of the Raven CE\Redemption Cemetery - Curse of the Raven CE\Uninstall.exe
AddRemove-Redrum 2 Time Lies 1.00 - g:\wendysforum\Redrum 2 - Time Lies\Redrum 2 - Time Lies\Uninstall.exe
AddRemove-Redrum Dead Diary 1.00 - g:\wendysforum\Redrum - Dead Diary\Redrum - Dead Diary\Uninstall.exe
AddRemove-Reincarnations 2 Uncover the Past Collectors Edition 1.00 - i:\wendysforum\Reincarnations 2 - Uncover the Past CE\Reincarnations 2 - Uncover the Past CE\Uninstall.exe
AddRemove-Robins Quest 1.00 - g:\wendysforum\Robin's Quest - A Legend Born\Robin's Quest - A Legend Born\Uninstall.exe
AddRemove-Romancing the Seven Wonders Great Pyramids 1.00 - g:\wendysforum\Romancing the Seven Wonders 2 - Great Pyramids\Romancing the Seven Wonders 2 - Great Pyramids\Uninstall.exe
AddRemove-Samantha Swift and the Fountains of Fate 1.00 - g:\wendysforum\Samantha Swift and The Fountains of Fate\Samantha Swift and The Fountains of Fate\Uninstall.exe
AddRemove-Secrets of the Dragon Wheel 1.00 - g:\wendysforum\Secrets of The Dragon Wheel\Secrets of The Dragon Wheel\Uninstall.exe
AddRemove-Shaolin Mystery Tale of the Jade Dragon Staff 1.00 - g:\wendysforum\Shaolin Mystery Tale of The Jade Dragon Staff\Shaolin Mystery Tale of The Jade Dragon Staff\Uninstall.exe
AddRemove-Skymist The Lost Spirit Stones 1.00 - g:\wendysforum\Skymist - The Lost Spirit Stones\Skymist - The Lost Spirit Stones\Uninstall.exe
AddRemove-Snark Busters Welcome to the Club 1.00 - g:\wendysforum\Snark Busters - Welcome to The Club\Snark Busters - Welcome to The Club\Uninstall.exe
AddRemove-Special Enquiry Detail The Hand that Feeds 1.00 - g:\wendysforum\Special Enquiry Detail - The Hand that Feeds\Special Enquiry Detail - The Hand that Feeds\Uninstall.exe
AddRemove-Sprill - The Mystery of the Bermuda Triangle 1.00 - g:\wendysforum\Sprill 2 - The Mystery of The Bermuda Triangle\Sprill 2 - The Mystery of The Bermuda Triangle\Uninstall.exe
AddRemove-The Clockwork Man 2 - Ultimate Edition Game Guide - g:\wendysforum\The Clockwork Man 2 - The Hidden World Ultimate Edition\Guide\Uninstall The Clockwork Man 2 - Ultimate Edition Game Guide.exe
AddRemove-The Clockwork Man 2 The Hidden World Ultimate Edition 1.00 - g:\wendysforum\The Clockwork Man 2 - The Hidden World\The Clockwork Man 2 - The Hidden World Ultimate Edition\Uninstall.exe
AddRemove-The Crop Circles Mystery 1.00 - g:\wendysforum\The Crop Circles Mystery\The Crop Circles Mystery\Uninstall.exe
AddRemove-The Great Pharaoh 1.00 - i:\wendysforum\_Match 3\The Great Pharaoh\The Great Pharaoh\Uninstall.exe
AddRemove-The Lost Kingdom Prophecy 1.00 - g:\wendysforum\The Lost Kingdom Prophecy\The Lost Kingdom Prophecy\Uninstall.exe
AddRemove-The Mysterious Case of Dr. Jekyll and Mr. Hyde 1.00 - g:\wendysforum\The Mysterious Case of Dr Jekyll and Mr Hyde\The Mysterious Case of Dr Jekyll and Mr Hyde\Uninstall.exe
AddRemove-The Otherside Realm of Eons 1.00 - g:\wendysforum\The Otherside - Realms of Eons\The Otherside - Realms of Eons\Uninstall.exe
AddRemove-The Otherside Realm of Eons 1.10 - g:\wendysforum\The Otherside - Realms of Eons (BFG)\The Otherside - Realm of Eons\Uninstall.exe
AddRemove-The Seawise Chronicles Untamed Legacy 1.00 - g:\wendysforum\The Seawise Chronicles - Untamed Legacy\The Seawise Chronicles - Untamed Legacy\Uninstall.exe
AddRemove-The Treasures of Mystery Island The Gates of Fate 1.00 - g:\wendysforum\The Treasures of Mystery Island 2 - The Gates of Fate\The Treasures of Mystery Island 2 - The Gates of Fate\Uninstall.exe
AddRemove-Time Dreamer 1.00 - g:\wendysforum\Time Dreamer\Time Dreamer\Uninstall.exe
AddRemove-Tropical Shop Fish Annabels Adventure 1.00 - g:\wendysforum\_Match 3\Tropical Fish Shop - Annabel's Adventures\Tropical Fish Shop - Annabel's Adventure\Uninstall.exe
AddRemove-Vampire Brides Love Over Death 1.00 - g:\wendysforum\Vampire Brides - Love Over Death\Vampire Brides - Love Over Death\Uninstall.exe
AddRemove-Veronica and the Book of Dreams 1.00 - i:\wendysforum\_Match 3\Veronica and The Book of Dreams\Veronica and The Book of Dreams\Uninstall.exe
AddRemove-{72B1C9BA-16C8-4800-B804-FEEFF087C2BD}_is1 - g:\giveawayoftheday\King's Smith\King's Smith\unins000.exe
AddRemove-Splotches - i:\giveawayoftheday\Splotches\Splotches\Uninstal.exe
AddRemove-The Sandbox of God Remastered - g:\giveawayoftheday\The Sandbox of God\The Sandbox of God\Uninstal.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-09-02 19:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(640)
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
- - - - - - - > 'explorer.exe'(3524)
c:\windows\system32\WININET.dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
p:\avg\AVG 9\avgchsvx.exe
p:\avg\AVG 9\avgrsx.exe
p:\avg\AVG 9\avgcsrvx.exe
p:\diskeeper\DkService.exe
c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
p:\ca internet security suite\CA Anti-Spyware\CAPPActiveProtection.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
p:\avg\AVG 9\avgcsrvx.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wscntfy.exe
p:\ca internet security suite\ccprovsp.exe
.
**************************************************************************
.
Completion time: 2010-09-02 19:05:21 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-03 00:05
Pre-Run: 45,909,008,384 bytes free
Post-Run: 48,780,193,792 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - DBD57EC8FCB9D01196476DF936B72924