Result of the ComboFix thing:
ComboFix 09-10-04.01 - Owner 05/10/2009 18:27.2.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.44.1033.18.1014.257 [GMT 1:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
file zipped: C:\kgroapow.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\kgroapow.sys
.
--------------- FCopy ---------------
c:\windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll --> c:\windows\system32\cngaudit.dll
.
((((((((((((((((((((((((( Files Created from 2009-09-05 to 2009-10-05 )))))))))))))))))))))))))))))))
.
2009-10-05 15:47 . 2009-10-05 17:42 -------- d-----w- c:\users\Owner\AppData\Local\temp
2009-10-03 08:41 . 2009-10-01 09:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-29 21:06 . 2009-10-05 15:08 -------- dc----w- c:\windows\system32\DRVSTORE
2009-09-29 21:04 . 2009-10-05 15:08 -------- d-----w- c:\programdata\Lavasoft
2009-09-28 12:45 . 2009-03-08 11:32 72704 ----a-w- c:\windows\system32\admparse.dll
2009-09-27 20:20 . 2009-09-27 20:20 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-09-26 11:30 . 2009-09-26 15:28 -------- d-----w- c:\program files\Super Mario 64
2009-09-26 09:02 . 2009-09-26 09:02 8854 ----a-r- c:\users\Owner\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\Uninstall_Project64__9559F7CA5E344237A2D9D856464AD727.exe
2009-09-26 09:02 . 2009-09-26 09:02 40960 ----a-r- c:\users\Owner\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2009-09-26 09:02 . 2009-09-26 09:02 40960 ----a-r- c:\users\Owner\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2009-09-26 09:02 . 2009-09-26 09:02 -------- d-----w- c:\program files\Project64 1.6
2009-09-24 18:10 . 2009-09-24 18:10 -------- d-----w- c:\program files\Common Files\Uninstall
2009-09-21 15:03 . 2009-09-21 15:03 -------- d--h--r- c:\users\Owner\AppData\Roaming\SecuROM
2009-09-21 15:01 . 2007-07-19 17:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2009-09-21 14:56 . 2009-10-05 15:51 -------- d--h--w- c:\windows\msdownld.tmp
2009-09-21 12:56 . 2009-09-21 12:56 -------- d-----w- c:\programdata\Amazon
2009-09-09 17:28 . 2009-07-11 19:32 502272 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-09 17:28 . 2009-07-11 19:32 297984 ----a-w- c:\windows\system32\wlansec.dll
2009-09-09 17:28 . 2009-07-11 19:32 290816 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-09 17:28 . 2009-07-11 19:26 123904 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-09 17:28 . 2009-07-11 19:32 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2009-09-09 17:28 . 2009-07-11 19:32 47104 ----a-w- c:\windows\system32\wlanapi.dll
2009-09-09 17:28 . 2009-06-10 12:07 2855424 ----a-w- c:\windows\system32\mf.dll
2009-09-09 17:28 . 2009-06-10 12:07 98816 ----a-w- c:\windows\system32\mfps.dll
2009-09-09 17:28 . 2009-06-10 10:15 24576 ----a-w- c:\windows\system32\mfpmp.exe
2009-09-09 17:28 . 2009-06-10 10:14 52736 ----a-w- c:\windows\system32\rrinstaller.exe
2009-09-09 17:28 . 2009-06-10 08:50 2048 ----a-w- c:\windows\system32\mferror.dll
2009-09-08 11:05 . 2009-09-08 11:05 -------- d-----w- c:\programdata\DAEMON Tools Lite
2009-09-08 10:40 . 2009-09-08 10:40 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-08 10:28 . 2009-09-08 11:09 -------- d-----w- c:\users\Owner\AppData\Roaming\DAEMON Tools Lite
2009-09-08 09:37 . 1997-05-12 16:53 314368 ----a-w- c:\windows\uninst.exe
2009-09-08 09:16 . 2009-09-08 09:16 -------- d-----w- c:\users\Owner\AppData\Local\AVG Security Toolbar
2009-09-08 09:11 . 2009-09-08 09:11 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-08 09:11 . 2009-09-08 09:11 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-08 09:11 . 2009-09-08 09:11 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-08 09:11 . 2009-09-08 09:11 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-08 09:10 . 2009-10-05 08:22 -------- d-----w- c:\windows\system32\drivers\Avg
2009-09-08 09:10 . 2009-09-08 09:10 -------- d-----w- c:\programdata\AVG Security Toolbar
2009-09-08 09:08 . 2009-09-08 09:08 -------- d-----w- c:\program files\AVG
2009-09-08 09:07 . 2009-10-05 15:16 -------- d-----w- c:\programdata\avg8
2009-09-08 08:51 . 2009-09-08 08:51 -------- d-----w- c:\users\Owner\AppData\Roaming\AVG8
2009-09-07 15:28 . 2009-09-07 15:28 -------- d-----w- c:\program files\ReflexiveArcade
2009-09-07 14:46 . 2009-10-05 15:51 -------- d-----w- c:\windows\~TEMPEX.DIR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-04 17:52 . 2009-07-31 17:38 -------- d-----w- c:\program files\BackgammonMasters
2009-10-04 15:39 . 2009-07-08 10:59 -------- d-----w- c:\users\Owner\AppData\Roaming\Spotify
2009-10-03 08:28 . 2009-07-08 11:53 1 ----a-w- c:\users\Owner\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-09-26 14:56 . 2009-06-24 11:58 -------- d-----w- c:\program files\DivX
2009-09-10 18:46 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-04 16:44 . 2009-09-21 15:02 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-09-04 16:44 . 2009-09-21 15:02 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-09-04 16:44 . 2009-09-21 15:02 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-09-04 16:29 . 2009-09-21 15:02 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-09-04 16:29 . 2009-09-21 15:02 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-09-04 16:29 . 2009-09-21 15:02 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-09-04 16:29 . 2009-09-21 15:02 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-09-04 16:29 . 2009-09-21 15:02 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-08-29 03:41 . 2009-09-04 11:12 1686528 ----a-w- c:\windows\system32\gameux.dll
2009-08-29 03:40 . 2009-09-04 11:12 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 23:31 . 2009-09-04 11:12 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-25 14:53 . 2009-08-25 14:43 -------- d-----w- c:\users\Owner\AppData\Roaming\NewsLeecher
2009-08-25 14:36 . 2009-08-25 14:32 -------- d-----w- c:\users\Owner\AppData\Roaming\SuperNZB
2009-07-31 17:39 . 2009-07-31 17:38 32854 ----a-w- c:\windows\iniLS.dat
2009-07-31 17:39 . 2009-07-31 17:39 14368 ----a-w- c:\windows\skype.dat
2009-07-21 21:52 . 2009-09-28 12:51 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-09-28 12:51 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-09-28 12:51 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-09-28 12:51 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:52 . 2009-08-12 16:35 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-14 13:02 . 2009-08-12 16:34 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 13:01 . 2009-08-12 16:34 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-14 13:00 . 2009-08-12 16:34 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-14 11:11 . 2009-08-12 16:34 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-09 15:03 . 2009-06-09 13:47 52776 ----a-w- c:\users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-10-05_15.55.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-11 02:27 . 2009-10-05 17:43 32694 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:03 . 2009-10-05 17:43 48706 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2006-11-02 13:00 . 2009-10-05 15:57 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:00 . 2009-10-05 17:19 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:00 . 2009-10-05 15:57 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:00 . 2009-10-05 17:19 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:00 . 2009-10-05 15:57 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 13:00 . 2009-10-05 17:19 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-02 11:43 . 2009-10-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-02 11:43 . 2009-10-02 11:43 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-10-02 11:43 . 2009-10-05 17:10 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-10-02 11:43 . 2009-10-02 11:43 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-10-02 11:43 . 2009-10-05 17:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-10-02 11:43 . 2009-10-02 11:43 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-06-09 16:51 . 2009-10-05 17:43 8058 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-45019957-4159803797-1902044427-1000_UserData.bin
- 2009-10-05 15:54 . 2009-10-05 15:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-10-05 17:41 . 2009-10-05 17:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-10-05 15:54 . 2009-10-05 15:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-10-05 17:41 . 2009-10-05 17:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-09-28 23:21 . 2009-10-05 15:57 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-09-28 23:21 . 2009-10-05 17:19 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2006-11-02 10:22 . 2009-10-05 17:40 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 10:22 . 2009-09-30 09:30 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-10-05 17:24 . 2009-10-05 17:24 6307840 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
+ 2009-06-15 16:21 . 2009-10-05 17:08 50339882 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 08:55 1090816 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-06-11 1232896]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-22 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2009-06-09 1006264]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-06-22 68592]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-25 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-08 2007832]
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{49417473-3C7F-4592-AC63-8AA302E54C08}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java Platform SE binary
"UDP Query User{065F6DFA-10C8-46BF-A994-37CFDC0DBECB}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java Platform SE binary
"TCP Query User{E65FF888-76C9-4F41-A1C1-E4ADD062981D}c:\\program files\\spotify\\spotify.exe"= UDP:c:\program files\spotify\spotify.exe:Spotify
"UDP Query User{E9F254D0-03D8-4CFA-9AF4-DC167A2D535F}c:\\program files\\spotify\\spotify.exe"= TCP:c:\program files\spotify\spotify.exe:Spotify
"{F84FFBE3-2372-4399-9337-E22A0F2F1D93}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{BF6EECB7-666D-4BEE-B5AB-F3FC96860C7A}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{48F46257-1108-44EE-A70F-12F3402E9D32}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{CEE7D65C-696B-436D-8612-9EF024914BB1}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{1474725F-66B7-4F69-9479-366F34A69A38}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [08/09/2009 10:11 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [08/09/2009 10:11 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [08/09/2009 10:08 297752]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [08/09/2009 10:08 908056]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24}]
%SystemRoot%\system32\soundschemes2.exe /AddRegistration
.
Contents of the 'Scheduled Tasks' folder
2009-10-05 c:\windows\Tasks\User_Feed_Synchronization-{6814F26E-01B1-4C53-B53E-FB47DBDC7EB5}.job
- c:\windows\system32\msfeedssync.exe [2009-09-28 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/webhp?sourceid=navclient&hl=en-gb&ie=utf-8
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\skon3eto.default\
FF - prefs.js: keyword.URL - hxxp://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_uk&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-05 18:42
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-45019957-4159803797-1902044427-1000\Software\SecuROM\License information*]
"datasecu"=hex:07,45,b8,55,96,4b,fb,0b,a5,3e,47,82,04,d6,e0,a2,6a,97,30,de,d3,
cc,62,93,6e,3b,8c,7f,31,f8,5a,a3,60,53,57,73,f6,43,8d,f9,ad,26,b4,46,1c,36,\
"rkeysecu"=hex:4e,23,4b,cd,86,10,07,51,15,4e,c4,f0,f2,cf,3e,ca
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 00\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\windows\System32\igfxsrvc.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-10-05 19:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-05 18:05
ComboFix2.txt 2009-10-05 16:19
Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
Post-Run: 6,779,117,568 bytes free
236 --- E O F --- 2009-10-05 08:38
Upload was successful
Unfortunately I can't get the flashpayer uninstall to work and get this message:
'C:\Users\Owner\uninstall_flash_player.exe
The directory name is invalid.'
and with the same happens with the java update.
I also failed at getting rid of Ask toolbar and got this message:
'Error 1905.Module C:\ProgramFiles\Ask.com\GenericAskToolbar.dll failed to unregister. HRESULT-2147220472. Contact your support personnel.'
Everything else before that seemed to go fine. Shall I go on and do ATF anyway?