This is
Part 2 of my ComboFix log
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="d:\program files\DNA\btdna.exe" [2009-04-07 342848]
"swg"="d:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-13 39408]
"MSMSGS"="d:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Google Update"="d:\documents and settings\john\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-06 133104]
"CallStation"="d:\program files\CallStation\CStation.exe" [2009-05-01 1327104]
"LogitechSoftwareUpdate"="d:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"RoboForm"="d:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-08-03 160592]
"Orb"="d:\program files\Winamp Remote\bin\OrbTray.exe" [2008-04-01 507904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="d:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-02-23 112216]
"McAfeeUpdaterUI"="d:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 136768]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"HPDJ Taskbar Utility"="d:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2006-01-13 196608]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-03-18 61440]
"Google Desktop Search"="d:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-04-13 30192]
"Google Quick Search Box"="d:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-04-13 68592]
"googletalk"="d:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"CloneCDTray"="d:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344]
"00Hotkeys"="d:\program files\Qliner Hotkeys\HotKeys.exe" [2006-12-02 45056]
"AdobeCS4ServiceManager"="d:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Acrobat Speed Launcher"="d:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="d:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376]
"HPHmon06"="d:\windows\system32\hphmon06.exe" [2006-01-07 622592]
"HP Software Update"="d:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NBKeyScan"="d:\program files\Nero\Nero BackItUp 4\NBKeyScan.exe" [2008-09-24 2254120]
"LVCOMSX"="d:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="d:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"HPHped06"="d:\progra~1\HP\{BA2D9~1\pexpress\hphPED06.exe" [2004-12-16 339968]
"Nikon Transfer Monitor"="d:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2009-02-24 479232]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"ZoneAlarm Client"="d:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-10-17 1037192]
"RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.EXE [2008-09-30 16864768]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - d:\windows\KHALMNPR.Exe [2008-12-19 76304]
d:\documents and settings\john\Start Menu\Programs\Startup\
Yankee Clipper III.lnk - d:\program files\YCIII\YankClip.exe [2009-5-24 1368064]
d:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - d:\program files\HP\digital imaging\bin\hpqtra08.exe [2004-11-4 258048]
Logitech SetPoint.lnk - d:\program files\Logitech\SetPoint\SetPoint.exe [2009-7-4 809488]
Subsonic.lnk - d:\program files\Subsonic\subsonic-agent.exe [2009-10-23 160768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explo rer]
"NoWinKeys"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-19 05:30 72208 ----a-w- d:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoa dGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ShellHWDetection"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="d:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"HPHUPD06"=d:\program files\HP\{BA2D9411-DBB4-43e4-9421-780413650A67}\hphupd06.exe
"LogitechVideoTray"=d:\program files\Logitech\Video\LogiTray.exe
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"d:\\Program Files\\DNA\\btdna.exe"=
"d:\\Program Files\\BitTorrent\\bittorrent.exe"=
"d:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Documents and Settings\\john\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"d:\\Documents and Settings\\john\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"d:\\Program Files\\Winamp\\winamp.exe"=
"d:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"d:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"d:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"d:\\WINDOWS\\system32\\mmc.exe"=
"d:\\Documents and Settings\\Rose\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"d:\\Documents and Settings\\Rose\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"d:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"d:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"d:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"d:\\Program Files\\Folder Lock 6\\Folder Lock 6.exe"=
"d:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"d:\\Program Files\\Verizon\\Verizon Media Manager\\Release\\Verizon Media Manager.exe"=
"d:\\Program Files\\Adobe\\Adobe Dreamweaver CS4\\Dreamweaver.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Subsonic\\subsonic-service.exe"=
"d:\\Program Files\\Subsonic\\subsonic-agent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5353:TCP"= 5353:TCP:*

isabled:Adobe CSI CS4
"3703:TCP"= 3703:TCP:*

isabled:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:*

isabled:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:*

isabled:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:*

isabled:Adobe Version Cue CS4 Server
R1 ATMhelpr;ATMhelpr;d:\windows\system32\drivers\ATMHELPR.SYS [6/29/2009 10:26 PM 4064]
R2 fssfltr;FssFltr;d:\windows\system32\drivers\fssfltr_tdi.sys [4/5/2009 9:13 AM 55152]
R2 IntuitUpdateService;Intuit Update Service;d:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 4:45 AM 13088]
R2 LBeepKE;LBeepKE;d:\windows\system32\drivers\LBeepKE.sys [7/4/2009 11:06 PM 10384]
R2 WinFLdrv;WinFLdrv;d:\windows\system32\WinFLdrv.sys [10/20/2009 10:51 PM 10752]
R2 ZoneEdit Dynamic DNS Update;ZoneEdit Dynamic DNS Update;d:\program files\ZoneEditDynDNS\ZoneEditDynDNS.exe [2/2/2009 8:30 PM 40960]
R3 Dot4Usb HPH09;Dot4Usb HPH09;d:\windows\system32\drivers\hphius09.sys [2/11/2008 7:18 PM 18864]
S2 gupdate1c9bbe019fe2f6;Google Update Service (gupdate1c9bbe019fe2f6);d:\program files\Google\Update\GoogleUpdate.exe [4/12/2009 8:31 PM 133104]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;d:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 4:46 AM 284016]
S3 fsssvc;Windows Live Family Safety;d:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 5:08 PM 533360]
S3 GoogleDesktopManager-110408-113106;Google Desktop Manager 5.8.811.4345;d:\program files\Google\Google Desktop Search\GoogleDesktop.exe [4/11/2009 2:39 PM 30192]
S3 ntkvpn;Loki VPN Driver Service;d:\windows\system32\DRIVERS\ntkvpn.sys --> d:\windows\system32\DRIVERS\ntkvpn.sys [?]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;d:\windows\system32\drivers\nvhda32.sys --> d:\windows\system32\drivers\nvhda32.sys [?]
S3 pfsvgae;pfsvgae;\??\d:\docume~1\john\LOCALS~1\Temp\pfsvgae.sys --> d:\docume~1\john\LOCALS~1\Temp\pfsvgae.sys [?]
S3 slicedisk.sys;slicedisk.sys;d:\windows\system32\slicedisk.sys [7/20/2009 5:38 AM 8832]
S3 SliceDisk5;SliceDisk5;\??\d:\docume~1\john\LOCALS~1\Temp\FindAndMount\slice disk.sys --> d:\docume~1\john\LOCALS~1\Temp\FindAndMount\slicedisk.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-11-09 d:\windows\Tasks\GlaryInitialize.job
- d:\program files\Glary Utilities\initialize.exe [2009-04-05 21:55]
2009-11-09 d:\windows\Tasks\Google Software Updater.job
- d:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-13 02:30]
2009-11-09 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 02:31]
2009-11-09 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 02:31]
2009-11-08 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-1004336348-839522115-1003Core.job
- d:\documents and settings\john\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-12 19:26]
2009-11-09 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-1004336348-839522115-1003UA.job
- d:\documents and settings\john\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-12 19:26]
2009-11-07 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-1004336348-839522115-1005Core.job
- d:\documents and settings\Rose\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-04 11:34]
2009-11-09 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-1004336348-839522115-1005UA.job
- d:\documents and settings\Rose\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-04 11:34]
.
.
------- Supplementary Scan -------
.
uStart Page = about
:blank
IE: Add to Google Photos Screensa&ver - d:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - d:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Customize Menu - file://d:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Fill Forms - file://d:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://d:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://d:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Trusted Zone: utdallas.edu\webmail
DPF: {8BE5651C-D60B-4B59-B5B2-F0EB93733D17} - hxxps://www36.verizon.com/CallAssistant/UnProtected/Voice%20Mail/VCAVMUtil.CAB
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://utdvpn.utdallas.edu/dana-cached/sc/JuniperSetupClient.cab
FF - ProfilePath - d:\documents and settings\john\Application Data\Mozilla\Firefox\Profiles\o8g8ihz1.BruceWayne\
FF - prefs.js: browser.search.selectedEngine - IMDB
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/|
http://us.mg4.mail.yahoo.com/dc/launch?.gx=1&.rand=e6a9pmhmp9dvp|http://www.google.com/ig|https://mail.google.com/mail/?shva=1#inbox
FF - component: d:\documents and settings\john\Application Data\Mozilla\Firefox\Profiles\o8g8ihz1.BruceWayne\extensions\{DD43485F-44CC-4452-A6C6-69356A7E33DA}\platform\WINNT_x86-msvc\components\ahWinUtils_32.dll
FF - component: d:\program files\Mozilla Firefox 3.1 Beta 3\components\GoogleDesktopMozilla.dll
FF - component: d:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll
FF - plugin: d:\documents and settings\john\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: d:\documents and settings\john\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: d:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: d:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: d:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: d:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: d:\program files\Mozilla Firefox 3.1 Beta 3\plugins\npbittorrent.dll
FF - plugin: d:\program files\Mozilla Firefox 3.1 Beta 3\plugins\npWebLaunch.dll
FF - plugin: d:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
d:\program files\Mozilla Firefox 3.1 Beta 3\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
disk not found D:\
please note that you need administrator rights to perform deep scan
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(680)
d:\windows\system32\Ati2evxx.dll
d:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
d:\program files\common files\logishrd\bluetooth\LBTServ.dll
d:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(5876)
d:\windows\system32\WININET.dll
d:\program files\Logitech\SetPoint\GameHook.dll
d:\program files\Logitech\SetPoint\lgscroll.dll
d:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
d:\windows\system32\ieframe.dll
d:\windows\system32\webcheck.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
d:\windows\system32\Ati2evxx.exe
d:\windows\system32\Ati2evxx.exe
d:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\program files\Bonjour\mDNSResponder.exe
d:\program files\Juniper Networks\Common Files\dsNcService.exe
d:\windows\system32\inetsrv\inetinfo.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\program files\McAfee\Common Framework\FrameworkService.exe
d:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
d:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
d:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
d:\program files\McAfee\Common Framework\naPrdMgr.exe
d:\program files\Winamp Remote\bin\OrbMediaService.exe
d:\program files\Nero\Nero BackItUp 4\IoctlSvc.exe
d:\windows\system32\HPZipm12.exe
d:\windows\system32\slserv.exe
d:\windows\System32\snmp.exe
d:\windows\system32\wbem\wmiapsrv.exe
d:\program files\Winamp Remote\bin\Orb.exe
d:\program files\McAfee\Common Framework\McTray.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
d:\program files\iPod\bin\iPodService.exe
d:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
d:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-11-09 7:01 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-09 13:01
ComboFix2.txt 2008-07-24 02:16
ComboFix3.txt 2008-07-22 02:16
ComboFix4.txt 2008-07-20 17:10
ComboFix5.txt 2008-08-26 03:18
Pre-Run: 15,817,981,952 bytes free
Post-Run: 31,376,580,608 bytes free
- - End Of File - - 4D08798132AA8D336FFCAB36B73B729F