Hi,
hope you are doing ok.
System is ok, has been ok all this time in fact, just kinda slowly sometimes.
I want to tell you that even when I uninstalled a couple of things there are still there, like Opera and Kaspersky; time ago I used Opera but changed for Mozilla and when Spyboot is inmunize it show not just IE and Firefox but Opera and MyWebSearch or something like this...and once I used Kasperksy and I dont remember even how but I noticed there was a file even when I used that uninstall thing they have. Oh and I also noticed that VideoEgg that I didnt install but can't uninstall it.
And finally

weeks ago someone hacked my Facebook account, nothing else but that (or so it seems! because I had no problems with anything else) and after that was when Ad-aware found that trojan (boy! I think I should told you all this before! sorry
Can't attatch the new combofix log, dont know why so Im copying it here, the other 2 are attached.
So, what do I do now to get ride of that??
PS Why shows Windows Defender as "enabled" if I disabled it??
Thanks, thanks, thanks!
Ivette
NewLogCombofix:
ComboFix 09-09-27.05 - Ivi 30/09/2009 14:25.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.52.3082.18.1021.474 [GMT -5:00]
Running from: c:\users\Ivi\Desktop\ComboFix.exe
Command switches used :: c:\users\Ivi\Desktop\CFScript.txt
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FILE ::
"c:\users\Fam\AppData\Roaming\qoyxvh.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Ivi\AppData\Roaming\Microsoft\Clip Organizer\mstore10.mgc
c:\users\Ivi\AppData\Roaming\Microsoft\Clip Organizer\Offic10.MGC
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_arqkvjsb
((((((((((((((((((((((((( Files Created from 2009-08-28 to 2009-09-30 )))))))))))))))))))))))))))))))
.
2009-09-30 19:36 . 2009-09-30 19:42 -------- d-----w- c:\users\Ivi\AppData\Local\temp
2009-09-30 19:36 . 2009-09-30 19:36 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-09-30 19:36 . 2009-09-30 19:36 -------- d-----w- c:\users\Fam\AppData\Local\temp
2009-09-30 19:36 . 2009-09-30 19:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-29 04:19 . 2009-09-29 04:19 -------- d-----w- c:\program files\Opera
2009-09-22 19:09 . 2009-09-22 19:09 -------- d-----w- c:\windows\CheckSur
2009-09-21 23:39 . 2009-09-28 20:16 -------- d-----w- c:\users\Ivi\AppData\Local\Yahoo!
2009-09-08 21:53 . 2009-08-14 16:27 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-08 21:53 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-08 21:53 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-08 21:53 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-08 21:53 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-08 21:53 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-08 21:53 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-08 21:53 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-08 21:53 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-08 21:53 . 2009-08-14 13:48 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-09-08 21:53 . 2009-08-14 15:53 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-08 21:53 . 2009-07-11 19:01 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-08 21:52 . 2009-07-11 19:01 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-08 21:52 . 2009-07-11 17:03 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-08 21:52 . 2009-07-11 19:01 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-09-08 21:52 . 2009-07-11 19:01 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-08 21:52 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-02 23:16 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-02 23:15 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 18:09 . 2009-09-11 23:45 -------- d-----w- c:\program files\FileASSASSIN
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-30 19:37 . 2007-07-11 18:24 12 ----a-w- c:\windows\bthservsdp.dat
2009-09-30 19:03 . 2009-05-06 17:27 -------- d-----w- c:\program files\Common Files\Adobe
2009-09-30 18:54 . 2009-08-09 01:04 -------- d-----w- c:\program files\MyDefrag v4.1.2
2009-09-28 21:43 . 2006-11-02 15:46 667966 ----a-w- c:\windows\system32\perfh00A.dat
2009-09-28 21:43 . 2006-11-02 15:46 129720 ----a-w- c:\windows\system32\perfc00A.dat
2009-09-26 18:17 . 2009-05-22 20:08 -------- d-----w- c:\programdata\avg8
2009-09-21 20:18 . 2009-05-28 00:14 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-09-15 16:12 . 2009-07-30 00:16 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-09-15 09:57 . 2008-03-31 19:48 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-09-08 22:19 . 2008-02-27 17:11 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-08 22:13 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-08 21:59 . 2007-03-31 16:45 -------- d-----w- c:\programdata\Microsoft Help
2009-09-07 23:09 . 2009-05-22 20:09 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-07 23:09 . 2009-05-22 20:09 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-07 23:09 . 2009-05-22 20:08 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-20 02:19 . 2009-07-30 14:55 680 ----a-w- c:\users\Fam\AppData\Local\d3d9caps.dat
2009-08-18 00:35 . 2009-05-02 19:20 -------- d-----w- c:\users\Ivi\AppData\Roaming\Skype
2009-08-18 00:24 . 2008-01-01 23:47 -------- d-----w- c:\users\Ivi\AppData\Roaming\skypePM
2009-08-11 18:59 . 2009-06-12 18:41 -------- d-----w- c:\program files\MP3MyMP3 3.0
2009-08-08 05:06 . 2007-01-30 13:34 -------- d-----w- c:\programdata\UIB
2009-08-08 04:06 . 2007-01-30 13:34 -------- d-----w- c:\program files\Protector Suite QL
2009-08-04 20:46 . 2007-01-30 14:08 -------- d-----w- c:\program files\Java
2009-08-03 20:07 . 2009-08-03 20:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 20:07 . 2009-08-03 20:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 20:07 . 2009-08-03 20:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-08-02 19:26 . 2009-08-09 01:04 95232 ----a-w- c:\windows\system32\MyDefragScreenSaver.scr
2009-08-02 19:26 . 2009-08-09 01:04 861184 ----a-w- c:\windows\system32\MyDefragScreenSaver.exe
2009-07-25 10:23 . 2008-12-13 00:14 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-18 16:01 . 2009-07-28 19:38 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-18 11:35 . 2009-07-28 19:38 828416 ----a-w- c:\windows\system32\wininet.dll
2009-07-17 13:54 . 2009-08-12 01:14 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-15 12:40 . 2009-08-12 01:12 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-15 12:39 . 2009-08-12 01:12 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-15 12:39 . 2009-08-12 01:12 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-15 12:39 . 2009-08-12 01:12 7680 ----a-w- c:\windows\system32\spwmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-28_21.02.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-01-30 12:56 . 2009-09-30 18:11 91292 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-09-30 19:43 78454 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-03-13 02:02 . 2009-09-30 19:43 24584 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-904869689-1801085728-3973605862-1000_UserData.bin
- 2006-11-02 13:02 . 2009-09-28 20:44 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:02 . 2009-09-30 19:41 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-09-28 20:44 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-09-30 19:41 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:02 . 2009-09-28 20:44 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 13:02 . 2009-09-30 19:41 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-03-31 17:17 . 2009-09-29 06:05 5932 c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2007-03-31 17:17 . 2009-09-24 02:16 5932 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-06-13 01:08 . 2009-09-29 13:27 5720 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-904869689-1801085728-3973605862-1002_UserData.bin
- 2009-09-28 20:43 . 2009-09-28 20:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-09-30 19:41 . 2009-09-30 19:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-09-28 20:43 . 2009-09-28 20:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-09-30 19:41 . 2009-09-30 19:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2007-04-01 03:05 . 2009-09-29 03:07 307488 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2006-11-02 10:33 . 2009-09-17 18:28 590082 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-09-28 21:43 590082 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-09-17 18:28 102094 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-09-28 21:43 102094 c:\windows\System32\perfc009.dat
+ 2009-09-30 19:05 . 2009-09-30 19:05 3938816 c:\windows\Installer\230d45.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-11-14 17:22 3186440 ----a-w- c:\program files\Protector Suite QL\farchns.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-11-14 17:22 3186440 ----a-w- c:\program files\Protector Suite QL\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Anonymizer"="c:\program files\Anonymizer\Anonymizer Software\Anonymizer.exe" [2008-11-17 1557176]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-11-14 17:07 96008 ----a-w- c:\windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Inicio rápido de Adobe Reader.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Inicio rápido de Adobe Reader.lnk
backup=c:\windows\pss\Inicio rápido de Adobe Reader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Ivi^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Recorte de pantalla e Inicio rápido de OneNote 2007.lnk]
path=c:\users\Ivi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recorte de pantalla e Inicio rápido de OneNote 2007.lnk
backup=c:\windows\pss\Recorte de pantalla e Inicio rápido de OneNote 2007.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"muBlinder"=c:\users\Ivi\Desktop\MuBlinder\muBlinder.exe -startup
"VX3000"=c:\windows\vVX3000.exe
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"Apoint"=c:\program files\Apoint2K\Apoint.exe
"Ad-Watch"=c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
"AVG8_TRAY"=c:\progra~1\AVG\AVG8\avgtray.exe
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"PSQLLauncher"="c:\program files\Protector Suite QL\launcher.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(

:49,62,59,f2,62,df,c9,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-904869689-1801085728-3973605862-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C1EF0E41-9AAB-4CD1-87C0-3F53CC8F0834}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{ED7A25BD-99B0-4DE6-861C-D9007804DCF9}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{0C3DD8D6-4495-48B2-BE98-AE6D33344F35}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{6FEB6E19-BEB0-4C16-A71A-ACBD2D0A8DEA}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7FE8A03E-D769-4023-8DF4-138FF3D0EE11}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{E4C3B889-ED44-4136-84D3-96DB506DDAB8}"= UDP:c:\program files\Grisoft\AVG7\avginet.exe:avginet.exe
"{CD82A5AA-0F71-4D89-86F2-C867AA4F9E2D}"= TCP:c:\program files\Grisoft\AVG7\avginet.exe:avginet.exe
"{D0CC714C-3E91-497E-A1F8-DFA61C19783E}"= UDP:c:\program files\Grisoft\AVG7\avgamsvr.exe:avgamsvr.exe
"{AFFF785A-1F14-4092-885A-395668FB68B0}"= TCP:c:\program files\Grisoft\AVG7\avgamsvr.exe:avgamsvr.exe
"{3A042FAB-3CAC-41FD-979D-10790F9681D8}"= UDP:c:\program files\Grisoft\AVG7\avgcc.exe:avgcc.exe
"{FCFCA2F4-556B-41FC-A5AE-38EB24979438}"= TCP:c:\program files\Grisoft\AVG7\avgcc.exe:avgcc.exe
"{8418321C-6736-4B7C-9875-B15DB2016F2D}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{510334F8-963A-4E34-BA05-9F4D059B7F72}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"TCP Query User{D570035F-2260-4D3D-A815-48C3FA28F3D2}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{5515ED47-5EF1-4B6D-9D52-310AD8678AB3}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{8FCB405B-62EC-4288-A38C-444A42886236}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{F8011464-E642-47F5-9DA4-5851ED5CD558}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"{92AF8512-8F94-423E-89F8-CF0D93F4F103}"= Profile=Private|c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{1117014B-0CB1-46AF-9286-AFFA5D2A4847}"= Profile=Private|c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{C6E2D977-C93C-43B3-9956-6CCAA3E1FD74}"= Profile=Private|c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{917E45F6-E18A-4C9E-AF03-EFFFA367C072}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{B92D5E0A-F0B2-46B0-8771-5817D0C9422F}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"{75CE39AC-DC55-4002-8BA8-27FE926F50E0}"= UDP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{D6B16123-EC4B-4095-A4BE-D0E083B3AD5E}"= TCP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"TCP Query User{75CB092E-4567-469A-B84D-5376E6A1BF37}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= UDP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"UDP Query User{759397E6-6174-44F6-9E4B-54278190C11B}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= TCP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"TCP Query User{AC9D0467-A5AE-426D-8F45-446D35C32A27}c:\\program files\\sony ericsson\\update service\\update service.exe"= UDP:c:\program files\sony ericsson\update service\update service.exe:Update Service
"UDP Query User{362BD414-879C-4060-A454-9797BF60F548}c:\\program files\\sony ericsson\\update service\\update service.exe"= TCP:c:\program files\sony ericsson\update service\update service.exe:Update Service
"TCP Query User{F789D1C8-9755-4EA5-B5BE-13FFBA681C8C}c:\\program files\\icq6\\icq.exe"= Disabled:UDP:c:\program files\icq6\icq.exe:ICQ Library
"UDP Query User{385B31A6-1CD0-4369-BFB7-1F057E5A2411}c:\\program files\\icq6\\icq.exe"= Disabled:TCP:c:\program files\icq6\icq.exe:ICQ Library
"TCP Query User{58AA1397-C5D2-4380-A02C-28C8AE7EA1D9}c:\\program files\\icqlite\\icqlite.exe"= Disabled:UDP:c:\program files\icqlite\icqlite.exe:ICQLite
"UDP Query User{2CB63049-3DBF-4BE8-9903-ABDF15677242}c:\\program files\\icqlite\\icqlite.exe"= Disabled:TCP:c:\program files\icqlite\icqlite.exe:ICQLite
"TCP Query User{AD89F28F-72E9-45F4-84F4-07D466C242B9}c:\\program files\\google\\google desktop search\\googledesktop.exe"= UDP:c:\program files\google\google desktop search\googledesktop.exe:Google Desktop
"UDP Query User{BF5A7338-F66A-4285-9485-3A4327A261C3}c:\\program files\\google\\google desktop search\\googledesktop.exe"= TCP:c:\program files\google\google desktop search\googledesktop.exe:Google Desktop
"TCP Query User{1FCA809D-BE3A-40CD-A03D-5343FDA22E18}c:\\program files\\mozilla firefox\\firefox.exe"= Disabled:UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{2F1EBF1B-029C-4F45-8517-1C85A3911020}c:\\program files\\mozilla firefox\\firefox.exe"= Disabled:TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{CCD953EB-C391-4D86-8FDE-88F1351825EA}"= Disabled:UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{87B50A18-7D99-4372-8E84-ABB0EA67BF1D}"= Disabled:TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{59A5EEA6-57E1-48C5-B9CA-6A96E82D1034}"= Profile=Private|c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{E4D440F1-BBC3-4AB5-AE3D-90D479E2DFDA}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{8BF7824A-4ECD-4FB3-BBE9-6A9C619ED4CC}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{9A3B52F3-99C1-4F2D-97FD-004D5B18364C}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"{243844BC-426D-4C38-B83B-30D10BD758BE}"= UDP:c:\windows\Temp\~osEEE1.tmp\ossproxy.exe:ossproxy.exe
"TCP Query User{4D15A6BC-C341-4380-BE53-DDB53DC156A4}c:\\program files\\anonymizer\\anonymizer software\\common\\anonproxy.exe"= UDP:c:\program files\anonymizer\anonymizer software\common\anonproxy.exe:AnonProxy
"UDP Query User{E800DC83-B6E3-44E9-BC63-D23794A8E0F1}c:\\program files\\anonymizer\\anonymizer software\\common\\anonproxy.exe"= TCP:c:\program files\anonymizer\anonymizer software\common\anonproxy.exe:AnonProxy
"TCP Query User{7F747124-8466-4AF9-89DE-19C67580216B}c:\\program files\\microsoft games\\age of empires\\empires.exe"= Disabled:UDP:c:\program files\microsoft games\age of empires\empires.exe:Age of Empires
"UDP Query User{9F136848-D74E-41B0-98E4-70225DEC640F}c:\\program files\\microsoft games\\age of empires\\empires.exe"= Disabled:TCP:c:\program files\microsoft games\age of empires\empires.exe:Age of Empires
"{34510B57-AE4F-4545-B262-9BEE5A6C2553}"= Disabled:UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{199A2AAE-68D8-46AD-B4F9-DBF808C9C5FA}"= Disabled:TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{3727E6B6-DB82-4D49-BB7C-114E9079E757}"= Disabled:UDP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{23A06118-0434-4AB0-BBC3-C22BFFA45CD5}"= Disabled:TCP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"TCP Query User{C7AFA94B-10A0-4703-AC9F-A199F9E241B9}c:\\program files\\opera\\opera.exe"= Disabled:UDP:c:\program files\opera\opera.exe:Opera Internet Browser
"UDP Query User{13380904-1485-448D-A16F-906C8EB9779B}c:\\program files\\opera\\opera.exe"= Disabled:TCP:c:\program files\opera\opera.exe:Opera Internet Browser
"{6EB4137C-E461-4F17-8DE7-AD6F9501BE6D}"= Disabled:c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{783A0406-E46A-4D9A-A872-63F64B6F6A5B}"= Disabled:c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{40D14533-682D-40CF-960C-9DFFE0F845A2}"= Disabled:c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{4B4472ED-D34E-4279-B39F-6913F3219BF2}"= Disabled:c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{0A48223F-5FCD-465B-A3FD-B7FF283DDD34}"= Disabled:UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{17EBADC6-299B-487C-B9E5-84001921E1FB}"= Disabled:TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"= c:\toshiba\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\toshiba\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [22/05/2009 03:27 p.m. 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [22/05/2009 03:09 p.m. 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [22/05/2009 03:09 p.m. 108552]
R2 AnonMgmtSvc;Anonymizer Management Service;c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe [17/11/2008 03:58 p.m. 37560]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [22/05/2009 03:08 p.m. 297752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [09/03/2009 02:06 p.m. 1028432]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [04/04/2009 05:26 p.m. 1153368]
R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [17/11/2008 04:40 p.m. 3668480]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [20/03/2009 06:29 p.m. 55280]
S3 fsssvc;Windows Live Protección Infantil;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 07:08 p.m. 533360]
SUnknown getPlusHelper;getPlusHelper; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2009-09-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 20:17]
2009-05-11 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-05-22 20:31]
2009-09-30 c:\windows\Tasks\User_Feed_Synchronization-{8B467D37-6037-44C2-BCAC-0BFAAE9E82A6}.job
- c:\windows\system32\msfeedssync.exe [2008-04-23 07:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: bancomer.com\www
TCP: {FA4687D2-FD04-4021-B7CB-6FA1FF68E999} = 172.16.0.1
FF - ProfilePath - c:\users\Ivi\AppData\Roaming\Mozilla\Firefox\Profiles\ukn4fddo.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.fr
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 00\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 01\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 02\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 03\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 04\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(576)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infql2.dll
- - - - - - - > 'Explorer.exe'(3804)
c:\program files\Protector Suite QL\farchns.dll
c:\program files\Protector Suite QL\infql2.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\program files\Protector Suite QL\upeksvr.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\windows\System32\TODDSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Common Files\microsoft shared\Source Engine\OSE.EXE
.
**************************************************************************
.
Completion time: 2009-09-30 14:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-30 19:50
ComboFix2.txt 2009-09-28 21:07
Pre-Run: 65,216,491,520 bytes libres
Post-Run: 64,731,840,512 bytes libres
338 --- E O F --- 2009-09-28 19:00