ComboFix 09-07-09.06 - Jeremy Hay 10/07/2009 12:08.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1524 [GMT 12:00]
Running from: c:\my documents\Downloads\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\documents and settings\All Users\documents\setup.exe
e:\windows\system32\Data
e:\windows\winhelp.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_KAVSYS
((((((((((((((((((((((((( Files Created from 2009-06-10 to 2009-07-10 )))))))))))))))))))))))))))))))
.
2009-07-09 23:44 . 2009-06-29 05:19 327688 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgldx86.sys
2009-07-09 23:44 . 2009-06-29 05:19 2052376 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-07-09 23:44 . 2009-06-29 05:19 906520 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgemc.exe
2009-07-09 23:44 . 2009-06-29 05:19 493336 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgtbapi.dll
2009-07-09 23:44 . 2009-06-29 05:19 3402008 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-07-09 23:44 . 2009-06-29 05:19 2167576 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgresf.dll
2009-07-09 23:44 . 2009-06-29 05:19 1204504 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgabout.dll
2009-07-09 23:43 . 2009-06-29 05:19 337176 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avglogx.dll
2009-07-09 23:43 . 2009-06-29 05:19 829208 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-07-09 23:43 . 2009-06-29 05:19 3298072 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-07-09 23:42 . 2009-06-29 05:15 1454360 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-07-09 23:42 . 2009-06-29 05:15 1085208 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-07-07 08:55 . 2009-07-07 08:55 -------- d-----w- E:\Arrested Development
2009-07-07 05:54 . 2009-07-07 10:37 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\Canon
2009-07-07 03:00 . 2009-07-08 04:50 -------- d-----w- E:\Dane
2009-07-06 21:54 . 2008-04-14 01:11 21504 ----a-w- e:\windows\system32\drivers\hidserv.dll
2009-07-04 23:41 . 2009-07-04 23:41 -------- d-----w- e:\program files\Trend Micro
2009-07-03 00:10 . 2006-01-15 23:45 360288 ----a-w- e:\windows\system32\drivers\ar5523.sys
2009-07-03 00:10 . 2006-01-15 23:45 360288 ----a-w- e:\windows\system32\ar5523.sys
2009-07-03 00:10 . 2005-07-27 09:16 44160 ----a-w- e:\windows\system32\athfmwdl.sys
2009-07-03 00:10 . 2005-07-27 09:15 149392 ----a-w- e:\windows\system32\drivers\ar5523.bin
2009-07-03 00:10 . 2005-07-27 09:15 149392 ----a-w- e:\windows\system32\ar5523.bin
2009-07-02 12:31 . 2009-07-02 12:31 -------- d-----w- e:\documents and settings\Jeremy Hay\Local Settings\Application Data\AVG Security Toolbar
2009-06-30 12:22 . 2009-06-30 12:22 -------- d-----w- e:\windows\usb-audio.deTascam
2009-06-30 10:28 . 2009-06-30 10:28 -------- d-----w- e:\program files\Common Files\Adobe Systems Shared
2009-06-29 23:17 . 2009-07-04 01:56 -------- d-----w- E:\Audition files
2009-06-29 05:19 . 2009-06-29 05:19 832144 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\AVGToolbarInstall.exe
2009-06-29 05:19 . 2009-06-29 05:19 -------- d-----w- e:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-29 05:19 . 2009-06-29 05:19 -------- d-----w- e:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-27 05:18 . 2004-05-20 20:04 79622 ----a-w- e:\windows\system32\EBPMON24.DLL
2009-06-27 05:18 . 2004-02-17 16:10 98304 ----a-w- e:\windows\system32\E_SAGSET.DLL
2009-06-27 05:18 . 2003-07-16 04:14 31744 ----a-w- e:\windows\system32\E_DCINST.DLL
2009-06-27 05:18 . 2003-05-20 17:27 64000 ----a-w- e:\windows\system32\ECBTEG.DLL
2009-06-27 05:18 . 2000-06-06 16:01 34304 ----a-w- e:\windows\system32\EBPCHP.DLL
2009-06-27 05:18 . 2008-04-13 19:47 25856 -c--a-w- e:\windows\system32\dllcache\usbprint.sys
2009-06-27 05:18 . 2008-04-13 19:47 25856 ----a-w- e:\windows\system32\drivers\usbprint.sys
2009-06-27 05:11 . 2009-06-27 05:11 -------- d-----w- e:\program files\Canon
2009-06-27 05:10 . 2009-06-27 05:10 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\ScanSoft
2009-06-27 05:10 . 2009-06-27 05:10 -------- d-----w- e:\documents and settings\All Users\Application Data\SSScanWizard
2009-06-27 05:10 . 2009-06-27 05:10 -------- d-----w- e:\documents and settings\All Users\Application Data\SSScanAppDataDir
2009-06-27 05:10 . 2009-06-27 05:10 -------- d-----w- e:\program files\Common Files\ScanSoft Shared
2009-06-27 05:10 . 2009-06-27 05:10 -------- d-----w- e:\program files\ScanSoft
2009-06-27 05:09 . 2002-05-23 15:04 389180 ----a-w- e:\windows\system32\UCS32P.DLL
2009-06-27 05:09 . 2002-09-27 02:56 69632 ----a-w- e:\windows\system32\CNQU70.DLL
2009-06-27 05:09 . 2002-04-12 08:23 339968 ----a-w- e:\windows\system32\N124UFW.dll
2009-06-27 05:09 . 2009-06-27 05:09 -------- d--h--w- E:\CanoScan
2009-06-27 04:34 . 2004-11-30 04:00 286720 ----a-r- e:\windows\878RMT.exe
2009-06-27 04:34 . 2009-06-27 04:34 -------- d-----w- e:\windows\MyInstall
2009-06-27 04:33 . 2009-06-27 04:33 -------- d-----w- e:\program files\honestech
2009-06-27 04:33 . 2001-05-16 04:54 309616 ----a-w- e:\windows\system32\wmv8dmod.dll
2009-06-27 04:33 . 2001-05-11 00:18 420240 ----a-w- e:\windows\system32\mpg4c32.dll
2009-06-27 04:32 . 2005-01-28 04:00 9216 ----a-r- e:\windows\system32\drivers\BtTuner.sys
2009-06-27 04:32 . 2005-01-28 04:00 8448 ----a-r- e:\windows\system32\drivers\BtXbar.sys
2009-06-27 04:32 . 2005-01-28 04:00 196736 ----a-r- e:\windows\system32\drivers\Bt878.sys
2009-06-27 04:30 . 2009-06-27 04:31 -------- d-----w- e:\windows\MustRead
2009-06-27 04:17 . 2009-06-27 04:17 8 ----a-w- e:\windows\system32\nvModes.dat
2009-06-14 12:27 . 2009-06-24 10:33 -------- d-----w- e:\program files\TP-LINK
2009-06-14 12:07 . 2009-06-14 12:07 -------- d-----w- e:\program files\PC Drivers HeadQuarters
2009-06-14 12:07 . 2009-06-14 12:07 -------- d-----w- e:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-06-14 10:42 . 2009-06-14 12:39 146976 ----a-w- e:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-14 10:21 . 2009-06-14 10:21 -------- d-----w- e:\documents and settings\Jeremy Hay\Local Settings\Application Data\Linksys_LLC_-_A_Division_
2009-06-14 10:13 . 2009-06-14 10:13 -------- d-----w- e:\program files\WebEx
2009-06-14 10:12 . 2009-06-14 10:14 -------- d-----w- e:\documents and settings\All Users\Application Data\Linksys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-10 00:14 . 2007-04-17 20:59 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\Orbit
2009-07-10 00:13 . 2007-12-17 20:56 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\WTablet
2009-07-09 23:43 . 2008-06-16 21:02 335752 ----a-w- e:\windows\system32\drivers\avgldx86.sys
2009-07-09 23:40 . 2007-12-14 03:40 -------- d-----w- e:\documents and settings\All Users\Application Data\Google Updater
2009-07-09 04:06 . 2008-02-05 01:27 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\dvdcss
2009-07-08 04:49 . 2007-04-20 09:56 12884 --sha-w- e:\windows\system32\KGyGaAvL.sys
2009-07-07 23:07 . 2008-10-22 21:13 -------- d-----w- e:\documents and settings\LocalService\Application Data\WTablet
2009-07-06 21:55 . 2009-07-06 21:55 0 ---ha-w- e:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-07-06 21:55 . 2009-07-06 21:55 0 ---ha-w- e:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-07-03 23:15 . 2009-03-10 12:17 664 ----a-w- e:\windows\system32\d3d9caps.dat
2009-07-03 22:29 . 2007-04-16 04:39 -------- d--h--w- e:\program files\InstallShield Installation Information
2009-06-30 12:10 . 2007-04-16 06:06 26040 ----a-w- e:\documents and settings\Jeremy Hay\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-30 11:33 . 2007-04-16 04:41 -------- d-----w- e:\program files\Common Files\Adobe
2009-06-30 10:29 . 2009-06-30 10:29 -------- d-----w- e:\documents and settings\All Users\Application Data\Adobe Systems
2009-06-30 00:06 . 2008-09-12 04:13 -------- d-----w- e:\program files\Belkin
2009-06-29 05:19 . 2008-06-16 21:02 11952 ----a-w- e:\windows\system32\avgrsstx.dll
2009-06-29 05:19 . 2007-04-23 05:10 27784 ----a-w- e:\windows\system32\drivers\avgmfx86.sys
2009-06-27 05:16 . 2007-04-21 02:14 -------- d-----w- e:\program files\EPSON
2009-06-14 12:07 . 2007-04-17 09:44 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\GetRightToGo
2009-06-14 10:12 . 2007-04-28 02:21 -------- d-----w- e:\program files\Java
2009-05-22 13:39 . 2009-05-20 05:49 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\.purple
2009-05-22 13:28 . 2009-05-22 13:28 2087 ----a-w- e:\documents and settings\Jeremy Hay\Application Data\.purple\certificates\x509\tls_peers\omega.contacts.msn.com
2009-05-20 05:52 . 2009-05-20 05:52 1065 ----a-w- e:\documents and settings\Jeremy Hay\Application Data\.purple\certificates\x509\tls_peers\gmail.com
2009-05-20 05:49 . 2009-05-20 05:49 2099 ----a-w- e:\documents and settings\Jeremy Hay\Application Data\.purple\certificates\x509\tls_peers\login.live.com
2009-05-20 05:49 . 2009-05-20 05:49 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\gtk-2.0
2009-05-20 05:47 . 2009-05-20 05:47 -------- d-----w- e:\program files\Common Files\GTK
2009-05-20 05:11 . 2009-05-20 05:11 -------- d-----w- e:\program files\Microsoft
2009-05-20 05:11 . 2009-05-20 05:11 -------- d-----w- e:\program files\Windows Live SkyDrive
2009-05-20 05:11 . 2008-06-03 22:54 -------- d-----w- e:\program files\Windows Live
2009-05-20 05:09 . 2009-05-20 05:09 -------- d-----w- e:\program files\Common Files\Windows Live
2009-05-16 12:40 . 2007-04-16 08:03 -------- d-----w- e:\program files\Creative
2009-05-14 02:15 . 2007-04-17 20:59 -------- d-----w- e:\program files\Orbitdownloader
2009-05-14 02:13 . 2009-03-10 12:46 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\AVGTOOLBAR
2009-05-11 02:53 . 2009-05-11 02:52 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\Creative
2009-05-11 01:48 . 2009-05-11 01:48 -------- d-----w- e:\documents and settings\All Users\Application Data\Creative
2009-05-08 13:14 . 2009-05-08 13:14 1418120 ----a-w- e:\windows\system32\wdfcoinstaller01005.dll
2009-05-08 13:14 . 2009-05-08 13:14 14736 ----a-w- e:\windows\system32\drivers\nuidfltr.sys
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- e:\windows\system32\localspl.dll
2009-05-02 22:28 . 2008-06-16 21:02 108552 ----a-w- e:\windows\system32\drivers\avgtdix.sys
2009-04-29 04:56 . 2004-08-04 12:00 827392 ----a-w- e:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 12:00 78336 ----a-w- e:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- e:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- e:\windows\system32\rpcrt4.dll
2007-01-23 02:07 . 2007-06-08 07:45 1847296 ----a-w- e:\program files\mozilla firefox\plugins\Seadragon.dll
2007-06-04 03:18 . 2007-04-20 09:56 56 --sh--r- e:\windows\system32\72E1C1C693.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 04:07 1004800 ----a-w- e:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="e:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="e:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-14 68856]
"MsnMsgr"="e:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"MSMSGS"="e:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Google Update"="e:\documents and settings\Jeremy Hay\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TV Card Remote Control Applet"="e:\windows\878RMT.exe" [2004-11-30 286720]
"WinampAgent"="e:\program files\Winamp\winampa.exe" [2007-05-14 35328]
"UpdReg"="e:\windows\UpdReg.EXE" [2000-05-10 90112]
"SunJavaUpdateSched"="e:\program files\Java\jre6\bin\jusched.exe" [2008-10-04 144792]
"QuickTime Task"="e:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"PhilipsSA33XXDM"="e:\program files\Philips\SA33XX\Philips Device Manager\Bin\SA33XXDeviceManager.exe" [2007-08-06 892928]
"Omnipage"="e:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-02 49152]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"NeroFilterCheck"="e:\windows\system32\NeroCheck.exe" [2001-07-08 155648]
"IntelliPoint"="e:\program files\Microsoft IntelliPoint\ipoint.exe" [2005-12-04 461584]
"googletalk"="e:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"EPSON Stylus C45 Series"="e:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE" [2004-01-13 99840]
"CTSysVol"="e:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-02-15 57344]
"AVG8_TRAY"="e:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-29 1948440]
"AppleSyncNotifier"="e:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-30 111936]
"Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Adobe Acrobat Speed Launcher"="e:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-02-27 38768]
"Acrobat Assistant 8.0"="e:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"SkyTel"="SkyTel.EXE" - e:\windows\SkyTel.exe [2006-05-16 2879488]
"RTHDCPL"="RTHDCPL.EXE" - e:\windows\RTHDCPL.EXE [2006-11-14 16270848]
"P17Helper"="P17.dll" - e:\windows\system32\P17.dll [2006-03-17 81408]
"nwiz"="nwiz.exe" - e:\windows\system32\nwiz.exe [2009-02-18 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - e:\windows\system32\narrator.exe [2008-04-14 53760]
e:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - e:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Launchy.lnk - e:\program files\Launchy\Launchy.exe [2007-10-1 274432]
Microsoft Office.lnk - e:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Orbit.lnk - e:\program files\Orbitdownloader\orbitdm.exe [2007-4-18 1690824]
QuickBooks Update Agent.lnk - e:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-4-20 972320]
ScheduleTV.lnk - e:\program files\honestech\honestech TVR\scheduleTV.exe [2009-6-27 307200]
TabUserW.exe.lnk - e:\windows\system32\WTablet\TabUserW.exe [2007-4-17 132656]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-29 05:19 11952 ----a-w- e:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;e:\windows\system32\drivers\avgldx86.sys [17/06/2008 9:02 a.m. 335752]
R1 AvgTdiX;AVG8 Network Redirector;e:\windows\system32\drivers\avgtdix.sys [17/06/2008 9:02 a.m. 108552]
R2 878TVCard;Bt878 TV Card - Video Capture;e:\windows\system32\drivers\Bt878.sys [27/06/2009 4:32 p.m. 196736]
R2 878TVTuner;Bt878 TV Card - TV Tuner;e:\windows\system32\drivers\BtTuner.sys [27/06/2009 4:32 p.m. 9216]
R2 878Xbar;Bt878 TV Card - Crossbar;e:\windows\system32\drivers\BtXbar.sys [27/06/2009 4:32 p.m. 8448]
R2 avg8emc;AVG Free8 E-mail Scanner;e:\progra~1\AVG\AVG8\avgemc.exe [4/07/2008 9:13 a.m. 907032]
R2 avg8wd;AVG8 WatchDog;e:\progra~1\AVG\AVG8\avgwdsvc.exe [4/07/2008 9:12 a.m. 298776]
R3 p17filt;p17filt;e:\windows\system32\drivers\p17filt.sys [20/03/2006 6:34 p.m. 1452032]
S3 TASCAM_US122144;TASCAM USB 2.0 Audio Device driver;e:\windows\system32\drivers\tascusb2.sys [21/05/2009 3:47 p.m. 396192]
S3 TASCAM_US144_MIDI;TASCAM US-144 WDM MIDI Device;e:\windows\system32\drivers\tscusb2m.sys [21/05/2009 3:47 p.m. 10752]
S3 TASCAM_US144_WDM;TASCAM US-144 WDM;e:\windows\system32\drivers\tscusb2a.sys [21/05/2009 3:47 p.m. 19904]
S3 V0090VID;Creative WebCam Vista Plus;e:\windows\system32\drivers\V0090Vid.sys [31/03/2008 8:17 a.m. 138112]
.
Contents of the 'Scheduled Tasks' folder
2009-07-03 e:\windows\Tasks\AppleSoftwareUpdate.job
- e:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 00:34]
2009-07-10 e:\windows\Tasks\Google Software Updater.job
- e:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-12-14 07:28]
2009-07-08 e:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-616249376-725345543-1004Core.job
- e:\documents and settings\Jeremy Hay\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 10:44]
2009-07-09 e:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-616249376-725345543-1004UA.job
- e:\documents and settings\Jeremy Hay\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 10:44]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Steam - (no file)
HKLM-Run-LELA - e:\program files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe
HKLM-Run-removecpl - RemoveCpl.exe
HKLM-Run-CTXFIREG - CTxfiReg.exe
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - e:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - e:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Append Link Target to Existing PDF - e:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - e:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - e:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - e:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Do&wnload selected by Orbit - e:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - e:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - e:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
TCP: {D86DD133-9159-47B3-B340-588CF0A2828E} = 58.28.4.2,58.28.6.2
FF - ProfilePath - e:\documents and settings\Jeremy Hay\Application Data\Mozilla\Firefox\Profiles\b32aab5b.default\
FF - prefs.js: browser.search.selectedEngine - Dictionary.com
FF - prefs.js: browser.startup.homepage - hxxp://google.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1641676&SearchSource=2&q=
FF - component: e:\documents and settings\Jeremy Hay\Application Data\Mozilla\Firefox\Profiles\b32aab5b.default\extensions\piclens@cooliris. com\components\coolirisstub.dll
FF - component: e:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: e:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils 2.dll
FF - component: e:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils 3.dll
FF - component: e:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils 35.dll
FF - component: e:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: e:\documents and settings\Jeremy Hay\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: e:\program files\eMusic Download Manager\plugin\npemusic.dll
FF - plugin: e:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\nppsynth.dll
FF - plugin: e:\windows\system32\Photosynth\nppsynth.dll
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-10 12:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
TV Card Remote Control Applet = e:\windows\878RMT.exe?????????????????????????????????????????????????????? ?????????????????????????????????????????????????????6?B~!?B~A???????T???q? @?A????8????@?X???????????????d???A???Bt878 TV Card Remote Control Receiver?@?????????W?SN????:?A~}(@??akC?(@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-220523388-616249376-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:b1,65,8a,74,54,9e,f7,87,0b,9b,0e,ba,0b,c2,81,e1,6d,26,be,55, fe,
90,62,37,95,e4,02,70,48,11,c5,54,0d,56,ea,cb,87,69,98,0e,a1,3e,6b,c5,cd,5b, \
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:06,24,62,cd,bf,cf,1c,af,2a,20,02,ed,16,ea,eb,ea,b7,7d,5b,e1,0 9,
bd,5e,7b,c9,72,93,ab,bd,ef,68,e9,2f,36,c1,fb,23,61,94,1a,bc,37,9d,c2,fa,a4, \
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\User Data\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscripti ons\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\User Data\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscripti ons\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:06,24,62,cd,bf,cf,1c,af,2a,20,02,ed,16,ea,eb,ea,b7,7d,5b,e1,0 9,
bd,5e,7b,c9,72,93,ab,bd,ef,68,e9,2f,36,c1,fb,23,61,94,1a,bc,37,9d,c2,fa,a4, \
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3136)
e:\program files\ScanSoft\OmniPageSE\ophook32.dll
e:\windows\system32\WPDShServiceObj.dll
e:\windows\system32\PortableDeviceTypes.dll
e:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
e:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
e:\program files\Java\jre6\bin\jqs.exe
e:\windows\system32\nvsvc32.exe
e:\windows\system32\Tablet.exe
e:\program files\AVG\AVG8\avgrsx.exe
e:\progra~1\AVG\AVG8\avgnsx.exe
e:\program files\AVG\AVG8\avgcsrvx.exe
e:\windows\system32\rundll32.exe
e:\windows\system32\Tablet.exe
e:\program files\Orbitdownloader\orbitnet.exe
e:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-10 12:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-10 00:19
Pre-Run: 101,787,332,608 bytes free
Post-Run: 116,984,266,752 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
e:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
310 --- E O F --- 2009-07-06 21:55