ComboFix 10-12-13.02 - Bryson Price 12/13/2010 11:56:38.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1982.834 [GMT -6:00]
Running from: c:\users\Bryson Price\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Bryson Price\AppData\Local\Microsoft\Windows\Temporary Internet Files\TestBrowser.html
.
((((((((((((((((((((((((( Files Created from 2010-11-13 to 2010-12-13 )))))))))))))))))))))))))))))))
.
2010-12-13 18:08 . 2010-12-13 18:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-10 21:30 . 2010-12-10 21:30 477184 --sh--w- c:\windows\system32\rassvc10.dll
2010-12-10 21:30 . 2010-12-10 21:30 62464 --sh--w- c:\windows\system32\catapi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-06 00:02 . 2010-11-06 00:02 33019 ----a-w- c:\windows\system32\CoreAAC-uninstall.exe
2010-10-09 21:22 . 2008-06-30 06:14 164880 ---ha-w- c:\users\Bryson Price\AppData\Roaming\Microsoft\Virtual PC\VPCKeyboard.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\Bryson Price\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-06-15 136176]
"Nokia Internet Modem"="c:\program files\Nokia\Nokia Internet Modem\WellPhone2.exe" [2009-07-29 1962648]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-12-18 307200]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\itunes\iTunesHelper.exe" [2009-07-13 292128]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-10-04 198160]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"PLFSet"="c:\windows\PLFSet.dll" [2007-04-24 45056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
c:\users\Bryson Price\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Clean Access Agent.lnk - c:\program files\Cisco Systems\Clean Access Agent\CCAAgent.exe [2007-9-6 2056275]
Suitcase 11.0.lnk - c:\windows\Installer\{7451C9B5-3E10-4E59-AD37-AB7438D84288}\_01D57C9244869186542E24.exe [2010-10-9 9062]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=catapi.dll rassvc10.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi4"=KORGUMDD.DRV
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2007-03-12 18:54 50696 ----a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-17 06:11 49152 ----a-w- c:\program files\Hp\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
2007-03-20 22:23 1773568 ----a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2007-02-28 18:26 7770112 ----a-w- c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2007-02-28 18:26 81920 ----a-w- c:\windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
2007-02-28 18:26 90191 ----a-w- c:\windows\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2007-03-29 00:45 176128 ----a-w- c:\program files\Hp\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2007-01-13 03:36 827392 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2006-11-02 12:34 2159104 ----a-w- c:\windows\System32\oobefldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3107727049-4258720162-1291377375-1000]
"EnableNotificationsRef"=dword:00000002
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-28 133104]
R3 KORGUMDS;KORG USB-MIDI Driver for Windows;c:\windows\system32\Drivers\KORGUMDS.SYS [2008-10-29 21720]
R3 nokiacpo;Nokia Internet Stick Wireless Modem Service Install;c:\windows\system32\DRIVERS\nokiacpo.sys [2009-06-22 19968]
R3 nokiappo;Nokia Internet Stick Wireless Modem Power Policy Service;c:\windows\system32\DRIVERS\nokiappo.sys [2009-06-22 27648]
R3 UKS11LDR;M-Audio USB Keystation Loader;c:\windows\system32\drivers\uks11ldr.sys [2007-11-14 20168]
S3 CLEDX;Team H2O CLEDX service;c:\windows\system32\DRIVERS\cledx.sys [2005-05-10 33792]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - KLMD25
*Deregistered* - klmd25
.
Contents of the 'Scheduled Tasks' folder
2010-12-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-28 23:51]
2010-12-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-28 23:51]
2010-12-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3107727049-4258720162-1291377375-1000Core.job
- c:\users\Bryson Price\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-01 20:46]
2010-12-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3107727049-4258720162-1291377375-1000UA.job
- c:\users\Bryson Price\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-01 20:46]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://search.conduit.com?SearchSource=10&ctid=CT1572363mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptopuInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Bryson Price\AppData\Roaming\Mozilla\Firefox\Profiles\klrwl6uh.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1572363&SearchSource=3&q={searchTerms}FF - prefs.js: browser.search.selectedEngine - ooVoo Chat Customized Web Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com/FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - d:\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - d:\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Skype extension for Firefox: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - d:\mozilla firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Google Gears: {000a9d1c-beef-4f90-9363-039d445309b8} - c:\program files\Google\Google Gears\Firefox
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-hpWirelessAssistant - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
MSConfigStartUp-QlbCtrl - %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0\bin\jusched.exe
MSConfigStartUp-WAWifiMessage - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
AddRemove-Cakewalk Rapture_is1 - z:\vst instruments back up\Cakewalk Rapture 1.2.1\Rapture\unins000.exe
AddRemove-FabFilter Twin 2 VSTi_is1 - z:\vst instruments back up\FabFilter.Twin.VSTi.VST3.RTAS.Standalone.v.2.01.READ.NFO-ViP\Twin 2\Uninstall\unins000.exe
AddRemove-FL Studio 8 - z:\vst instruments back up\FL Studio XXL Producer Edition 8.0.0\uninstall.exe
AddRemove-HijackThis - c:\users\Bryson Price\Downloads\HijackThis.exe
AddRemove-IK Multimedia SampleTank XL DXi VSTi RTAS v2.1.1 Inc. Keygen - z:\vstins~1\IKMULT~1.1\SAMPLE~1\UNWISE.EXE
AddRemove-Native Instruments Absynth 4 - z:\vst instruments back up\Native Instruments Komplete 5\Native Instruments\Absynth 4\uninstall.exe
AddRemove-Native Instruments B4 II - z:\vst instruments back up\Native Instruments Komplete 5\Native Instruments\B4 II\uninstall.exe
AddRemove-Native Instruments Battery 3 - z:\vst instruments back up\Native Instruments Komplete 5\Native Instruments\Battery 3\uninstall.exe
AddRemove-Native Instruments Elektrik Piano 1.5 - z:\vst instruments back up\Native Instruments Komplete 5\Native Instruments\Elektrik Piano 1.5\uninstall.exe
AddRemove-Native Instruments FM8 - z:\vst instruments back up\Native Instruments Komplete 5\Native Instruments\FM8\uninstall.exe
AddRemove-Native Instruments Guitar Rig 3 - z:\vst instruments back up\Native Instruments Komplete 5\Native Instruments\Guitar Rig 3\uninstall.exe
AddRemove-Native Instruments Komplete 5 - z:\vstins~1\NATIVE~2\NATIVE~1\KOMPLE~1\UNWISE.EXE
AddRemove-Native Instruments Kontakt 3 - c:\program files\Native Instruments\Kontakt 3\uninstall.exe
AddRemove-Native Instruments Kore 2 - z:\vstins~1\NATIVE~1\KORE2~1\UNWISE.EXE
AddRemove-Native Instruments Massive - z:\vst instruments back up\Native Instruments Komplete 5\Native Instruments\Massive\uninstall.exe
AddRemove-Native Instruments Pro-53 - z:\vst instruments back up\Native Instruments Komplete 5\Native Instruments\Pro-53\uninstall.exe
AddRemove-Native Instruments Reaktor 5 - z:\vst instruments back up\Native Instruments Komplete 5\Native Instruments\Reaktor 5\uninstall.exe
AddRemove-Pinguin Audio Meter - z:\vst instruments back up\MasterPinguin PG-AM Standard 2.3.0.550\Pinguin Audio Meter\Uninst.exe
AddRemove-Pinguin Audio Meter v2.2 - z:\vst instruments back up\pinguin audio meter 2.2\DeIsL1.isu
AddRemove-Reason4_is1 - z:\reason 4.0\Uninstall Reason\unins000.exe
AddRemove-reFX Nexus 1.0.9_is1 - z:\vst instruments back up\ReFX Nexus\Nexus 1.09\VST dll files\unins000.exe
AddRemove-reFX Vanguard_is1 - z:\vst instruments back up\Vanguard\VST dll files\Vanguard\Uninstall\unins000.exe
AddRemove-Sonik Synth 2 - z:\vstins~1\IKMULT~1\UNWISE.EXE
AddRemove-Tone2 Gladiator full_is1 - z:\vst instruments back up\Tone2 Gladiator 2.0\VST dll files\unins000.exe
AddRemove-{676FAD0D-40C3-4911-93E7-5C70C201ADEA}_is1 - z:\vst instruments back up\Project SAM Symphobia\Project SAM Symphobia\unins000.exe
AddRemove-{84D04D4F-2201-4AED-BE9A-FFA62069CA19}_is1 - z:\vst instruments back up\ReFX Nexus\reFX\Nexus\Uninstall\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-12-13 12:08
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3107727049-4258720162-1291377375-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ÿ**‘%\OpenWithList]
@Class="Shell"
[HKEY_USERS\S-1-5-21-3107727049-4258720162-1291377375-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*V%µ**%]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-3107727049-4258720162-1291377375-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*V%µ**%\OpenWithList]
@Class="Shell"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-12-13 12:22:34
ComboFix-quarantined-files.txt 2010-12-13 18:22
Pre-Run: 10,383,904,768 bytes free
Post-Run: 22,053,187,584 bytes free
- - End Of File - - 06E1DEC8CC93C3E56038C002A6A22E6D