Right... Sorry.
---------------------------------
ComboFix 09-06-11.06 - Wendy 12/06/2009 11:55.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.1918.1013 [GMT -4:00]
Running from: c:\users\Wendy\Desktop\ComboFix\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 081203-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1296 [VPS 081203-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
c:\windows\TEMP\3276364.tmp . . . . failed to delete
D:\Desktop.ini
.
((((((((((((((((((((((((( Files Created from 2009-05-12 to 2009-06-12 )))))))))))))))))))))))))))))))
.
2009-06-11 17:51 . 2009-06-11 17:51 -------- d-----w- c:\program files\Trend Micro
2009-06-10 00:23 . 2009-03-09 19:06 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-10 00:23 . 2009-06-10 00:23 682500 ----a-w- c:\programdata\Lavasoft\Ad-Aware\ThreatWork\Submit\DivX.dll
2009-06-10 00:23 . 2009-06-10 00:23 473604 ----a-w- c:\programdata\Lavasoft\Ad-Aware\ThreatWork\Submit\uninstall.exe
2009-06-10 00:23 . 2009-06-10 00:23 39428 ----a-w- c:\programdata\Lavasoft\Ad-Aware\ThreatWork\Submit\WNASPINT.DLL
2009-06-09 21:38 . 2009-03-09 19:06 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-09 21:38 . 2009-03-12 08:17 2902048 -c--a-w- c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-09 21:38 . 2009-06-09 21:38 -------- d-----w- c:\program files\Lavasoft
2009-06-09 21:37 . 2009-06-09 21:38 -------- dc-h--w- c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-08 15:30 . 2009-06-08 15:30 -------- d-----w- c:\program files\ABC Amber Audio Converter
2009-06-08 13:21 . 2009-06-08 13:21 -------- d-----w- c:\program files\Common Files\Motorola Shared
2009-06-08 13:19 . 2009-06-08 13:19 -------- d-----w- c:\users\Wendy\AppData\Local\BVRP Software
2009-06-08 13:17 . 2009-06-08 13:19 -------- d-----w- c:\program files\Avanquest update
2009-06-08 13:12 . 2009-06-08 13:26 -------- d-----w- c:\programdata\BVRP Software
2009-06-08 13:12 . 2009-06-08 13:24 -------- d-----w- c:\program files\Motorola Phone Tools
2009-06-08 13:08 . 2009-06-08 13:08 9232 ----a-w- c:\users\Wendy\mqdmmdfl.sys
2009-06-08 13:08 . 2009-06-08 13:08 92064 ----a-w- c:\users\Wendy\mqdmmdm.sys
2009-06-08 13:08 . 2009-06-08 13:08 79328 ----a-w- c:\users\Wendy\mqdmserd.sys
2009-06-08 13:08 . 2009-06-08 13:08 66656 ----a-w- c:\users\Wendy\mqdmbus.sys
2009-06-08 13:08 . 2009-06-08 13:08 6208 ----a-w- c:\users\Wendy\mqdmcmnt.sys
2009-06-08 13:08 . 2009-06-08 13:08 5936 ----a-w- c:\users\Wendy\mqdmwhnt.sys
2009-06-08 13:08 . 2009-06-08 13:08 4048 ----a-w- c:\users\Wendy\mqdmcr.sys
2009-06-08 13:08 . 2009-06-08 13:08 25600 ----a-w- c:\users\Wendy\usbsermptxp.sys
2009-06-08 13:08 . 2009-06-08 13:08 22768 ----a-w- c:\users\Wendy\usbsermpt.sys
2009-06-08 12:05 . 2009-06-08 12:05 1915520 ----a-w- c:\users\Wendy\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-05-14 19:45 . 2009-06-09 21:38 -------- dc----w- c:\windows\system32\DRVSTORE
2009-05-14 19:45 . 2009-03-19 20:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-14 19:45 . 2008-04-17 16:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-05-14 19:45 . 2009-05-14 19:45 -------- d-----w- c:\program files\iPod
2009-05-14 19:45 . 2009-05-14 19:45 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-14 19:45 . 2009-05-14 19:45 -------- d-----w- c:\program files\iTunes
2009-05-14 19:43 . 2009-05-14 19:43 -------- d-----w- c:\program files\Bonjour
2009-05-14 19:42 . 2009-05-14 19:42 -------- d-----w- c:\program files\QuickTime
2009-05-14 19:36 . 2009-05-14 19:36 75048 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 21:38 . 2008-04-27 02:24 -------- d-----w- c:\programdata\Lavasoft
2009-06-09 21:25 . 2008-02-16 06:54 -------- d-----w- c:\program files\MediaCoder
2009-06-09 21:25 . 2009-04-22 19:38 -------- d-----w- c:\users\Wendy\AppData\Roaming\Broad Intelligence
2009-06-09 21:25 . 2007-08-30 11:49 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-09 21:18 . 2009-04-22 19:30 -------- d-----w- c:\users\Wendy\AppData\Roaming\Any Video Converter
2009-06-06 13:52 . 2007-12-13 03:59 -------- d-----w- c:\users\Wendy\AppData\Roaming\uTorrent
2009-06-04 03:47 . 2009-06-04 03:47 16760 ----a-w- c:\programdata\tmp9284.tmp
2009-06-04 03:46 . 2009-06-04 03:46 16762 ----a-w- c:\programdata\tmpE87.tmp
2009-06-04 03:45 . 2009-06-04 03:45 16762 ----a-w- c:\programdata\tmp3D92.tmp
2009-06-04 03:45 . 2009-06-04 03:45 16762 ----a-w- c:\programdata\tmpABDE.tmp
2009-06-03 16:53 . 2007-08-30 12:03 -------- d-----w- c:\programdata\Roxio
2009-05-28 03:18 . 2008-01-09 23:25 -------- d-----w- c:\users\Wendy\AppData\Roaming\Canon
2009-05-14 19:45 . 2008-02-12 05:52 -------- d-----w- c:\program files\Common Files\Apple
2009-05-13 23:16 . 2007-12-06 16:08 -------- d-----w- c:\programdata\Microsoft Help
2009-05-13 23:14 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-13 01:00 . 2007-08-30 12:07 -------- d-----w- c:\program files\Java
2009-05-13 00:56 . 2009-05-13 00:56 -------- d-----w- c:\program files\Common Files\Java
2009-04-27 12:41 . 2009-04-27 12:41 -------- d-----w- c:\programdata\TVU Networks
2009-04-17 06:24 . 2009-04-17 06:24 574335 ----a-w- c:\programdata\tmp7458.tmp
2009-04-17 06:02 . 2009-04-17 06:02 314677 ----a-w- c:\programdata\tmp650C.tmp
2009-04-17 06:01 . 2009-04-17 06:01 314677 ----a-w- c:\programdata\tmp9DF7.tmp
2009-04-17 06:00 . 2009-04-17 06:00 314677 ----a-w- c:\programdata\tmpB52E.tmp
2009-03-19 20:32 . 2009-03-19 20:32 23400 ----a-w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-18 00:38 . 2008-10-16 08:26 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-03-17 03:38 . 2009-04-15 18:22 13824 ----a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 18:22 24064 ----a-w- c:\windows\system32\amxread.dll
2008-06-16 01:54 . 2007-12-04 14:20 848 --sha-w- c:\windows\System32\KGyGaAvL.sys
2007-08-30 12:30 . 2007-08-30 12:24 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2008-08-24 4067328]
"WeatherEye"="c:\program files\TheWeatherNetwork\WeatherEye\WeatherEye.exe" [2009-01-16 4519832]
"Google Update"="c:\users\Wendy\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"OPSE reminder"="c:\program files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" [2003-07-07 729088]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
"OpenDNS Update"="c:\program files\OpenDNS Updater\OpenDNS Updater.exe" [2008-06-09 209408]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-04-03 44168]
c:\users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{5DBB0B68-602C-4751-8916-CD57C9021764}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{F5F420D8-3923-41F4-991B-E85942BA23E9}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{C700B50C-32EF-4AFD-BC57-841E7DDB2602}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{0E22A5CB-19C4-4D64-ABFD-47D06A7D5C0C}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{0229018C-0272-4D0E-9BFA-15930A5A90F0}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{FC242A90-BEFE-4C22-95FB-85FA7708640B}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{6524BC32-945D-44FA-A55A-3BB61BB9EDB6}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EC933EC0-4B2E-4B6D-AC35-1CE40B321589}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{FD6C5D4B-E55B-4D10-9746-FA38A087F8F0}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{0F27E9C3-23EB-494A-A55C-E5DCA10FE747}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{B98847E7-E423-4A1A-9A91-5361B2B11E88}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{C80B1091-43C0-4DB5-83A0-C5A554E88974}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D8ACBEE2-97E2-4A52-ADB6-EDE979DBD9F2}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3D2D1A56-B41D-4A6C-A3A3-5624DCC55372}"= UDP:c:\windows\System32\muzapp.exe:MUZ AOD APP player
"{B56FEA37-8902-4513-9C59-C64537D2958C}"= TCP:c:\windows\System32\muzapp.exe:MUZ AOD APP player
"{69A53251-9494-4D71-82B1-5DB8469EB761}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{393C663E-DB1A-4958-A3F3-F3D9D736E466}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{A37FDD27-461B-4850-8359-2D0F0BAC1E84}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{F7483CC2-34CA-4E2E-8426-0C03A6B7FEC2}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{3F03DCBE-C89E-4178-85EF-C14977E2500C}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
"UDP Query User{62FE9A2B-ACAF-4C45-97F9-1413A2F346FF}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent
"TCP Query User{F4262AF3-0874-4C1F-A355-C1EC131CD6F6}c:\\program files\\maple 12\\jre\\bin\\maple.exe"= UDP:c:\program files\maple 12\jre\bin\maple.exe:Maple 12
"UDP Query User{E6FC5259-F7F9-4F06-9231-B120BD24B3D0}c:\\program files\\maple 12\\jre\\bin\\maple.exe"= TCP:c:\program files\maple 12\jre\bin\maple.exe:Maple 12
"TCP Query User{968B7F4A-5AF4-4DB4-99FA-EEBE9F0E5B39}c:\\program files\\maple 12\\jre\\bin\\java.exe"= UDP:c:\program files\maple 12\jre\bin\java.exe:Java Platform SE binary
"UDP Query User{F9904E5D-E760-4228-B438-C2BE8068537A}c:\\program files\\maple 12\\jre\\bin\\java.exe"= TCP:c:\program files\maple 12\jre\bin\java.exe:Java Platform SE binary
"TCP Query User{1C9AD4E8-BB9E-4BE8-B542-2FD12089BF25}c:\\users\\wendy\\appdata\\local\\google\\chrome\\application\\chrome.exe"= UDP:c:\users\wendy\appdata\local\google\chrome\application\chrome.exe:chrome.exe
"UDP Query User{D614DD8C-2759-40FB-8CBC-10D27E8E6903}c:\\users\\wendy\\appdata\\local\\google\\chrome\\application\\chrome.exe"= TCP:c:\users\wendy\appdata\local\google\chrome\application\chrome.exe:chrome.exe
"TCP Query User{6B99A883-6AC8-4F80-B8C1-B9C2292BF1F7}c:\\program files\\matlab\\r2007b\\bin\\win32\\matlab.exe"= UDP:c:\program files\matlab\r2007b\bin\win32\matlab.exe:MATLAB
"UDP Query User{B7E6329D-C634-47F5-9385-3AABFDA8DA6A}c:\\program files\\matlab\\r2007b\\bin\\win32\\matlab.exe"= TCP:c:\program files\matlab\r2007b\bin\win32\matlab.exe:MATLAB
"TCP Query User{8CF34956-293F-40D3-8F6C-DD3E81430BF6}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{3AB60645-9035-4347-9F61-60DD0908EE4F}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{B0495F4F-A2FB-4317-A085-98C34F39CC42}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{991EF9F2-253B-4C32-8165-67182C8F4198}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{C5438878-A51E-4EAE-AA9A-E56B73065D9A}"= UDP:c:\windows\System32\muzapp.exe:MUZ AOD APP player
"{EA6FCA48-2D7A-467F-9C6C-2E1B71ECAE92}"= TCP:c:\windows\System32\muzapp.exe:MUZ AOD APP player
"{B656E96C-45E4-422B-AB1F-7D49D15B2EBB}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{D86ECA13-F192-4C53-9EE7-23CC29CF3DA7}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"TCP Query User{F703F8C6-0DC4-4D19-9214-4CDB4B04E895}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{C4869371-952A-4A4E-A25F-BDDF10B83B2C}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"{E8C8D1ED-DA31-410E-AE6E-6AD145DED204}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C084BA32-B3A4-47E6-AD35-4A0244123A4C}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{39EFA0A5-D14B-457C-9AEB-F0B7592D56A1}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{1DC869CB-F524-4491-9ED6-F571DC10C59D}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [09/06/2009 5:38 PM 64160]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [01/12/2008 10:19 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [01/12/2008 10:19 AM 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [01/12/2008 10:18 AM 51792]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [09/03/2009 3:06 PM 951632]
.
Contents of the 'Scheduled Tasks' folder
2009-06-09 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]
2009-06-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1091376947-1128869515-4083372758-1000.job
- c:\users\Wendy\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-02 19:38]
2009-06-12 c:\windows\Tasks\User_Feed_Synchronization-{11161191-2D90-4C28-A826-B401A52D7A26}.job
- c:\windows\system32\msfeedssync.exe [2008-04-23 07:33]
.
.
------- Supplementary Scan -------
.
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=74&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
FF - ProfilePath - c:\users\Wendy\AppData\Roaming\Mozilla\Firefox\Profiles\qu2oeu5d.default\
FF - prefs.js: browser.startup.homepage - hxxp://ca.yahoo.com/|http://www.ledevoir.com/
FF - plugin: c:\program files\Java\jre1.5.0_18\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_18\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_18\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_18\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_18\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_18\bin\NPJPI150_18.dll
FF - plugin: c:\program files\Java\jre1.5.0_18\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\users\Wendy\AppData\Local\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-12 12:06
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(3820)
c:\program files\ScanSoft\OmniPageSE2.0\ophookSE2.dll
c:\program files\WinSCP\DragExt.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\System32\PSIService.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\conime.exe
c:\windows\System32\CF30397.exe
c:\windows\System32\rundll32.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\hp\KBD\kbd.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-06-12 12:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-12 16:10
Pre-Run: 172,445,208,576 bytes free
Post-Run: 172,920,741,888 bytes free
270 --- E O F --- 2009-06-04 16:52