ComboFix log
ComboFix 12-04-11.03 - Steve 12/04/2012 9:19.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3326.2212 [GMT 1:00]
Running from: c:\users\Steve\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\NOTEPAD.EXE-x.txt
c:\programdata\RUNDLL32.EXE-x.txt
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc106A.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc10F7.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1132.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1289.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc128B.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1410.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc14BB.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1607.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc17F6.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1885.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1900.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1B8E.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1BFC.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1C87.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1D9.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc1EE8.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2006.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc21F5.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2223.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2232.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc22EF.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc233B.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2458.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2695.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc26B5.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc280D.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc28E6.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2944.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2963.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2AF9.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2BB4.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2C35.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc2F8C.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3066.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc341F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3623.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3A44.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3CC.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3E69.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc3F89.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc400E.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc409C.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc40A.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4443.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc453D.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc453E.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc47DB.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc482A.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc482B.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4869.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4914.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc49C1.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc49EF.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4B48.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4CA0.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc4F5D.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc517D.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc523A.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc52B5.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5328.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5370.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5544.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5595.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc55E1.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5729.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5766.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5775.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc591D.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc59B8.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5A44.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc5D8E.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc602F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6451.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc677F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6CA.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6E90.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc6EEB.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7023.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7448.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7718.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc77E1.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc780F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc78CB.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc79B4.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7ACD.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7D6C.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7EF.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc7F0.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8345.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc83D3.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc85A6.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8670.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc869F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc878E.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8AC5.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8B04.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8BDD.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8C1D.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8DD0.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc8E1F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9090.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc91C6.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc93A.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc94E2.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9502.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc953F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc958F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc984.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9906.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc99A5.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9A26.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9AFA.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9B67.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9D5A.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9E34.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9E92.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mcc9EF0.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA028.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA0A5.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA3A6.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA527.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA749.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA825.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccA9E8.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccAA28.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccAAC5.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccAB3F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccABFA.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccAD32.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccAD61.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccAEC8.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccAFE0.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB0AD.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB1F3.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB4A1.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB658.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB694.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB751.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB77F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB85A.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccB934.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccBCCC.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccBE33.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccBEFD.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccBFA9.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC008.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC0D2.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC209.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC3CE.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC479.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC6AB.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccC71.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCB0E.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCB6E.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCD52.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCF15.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCF59.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCF81.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccCFE.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD0E8.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD0F7.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD10.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD126.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD30B.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD367.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD425.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD4F1.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD7AE.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccD9D1.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccDB95.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccDBF1.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccDF1B.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccDF49.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE14F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE1CB.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE227.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE265.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE33F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE410.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE497.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE4A8.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE727.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE745.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE800.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE810.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE8DF.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccE93.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccEB9A.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccEC35.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccECF0.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccEF50.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF174.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF24D.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF28B.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF3D4.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF3E2.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF46F.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF54A.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF663.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF6F0.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF72E.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF73C.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF74C.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF856.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccF9EB.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFA67.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFAF7.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFBD.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFBFF.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFD64.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFD83.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFDE1.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFEAB.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFEF.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFFB.tmp
c:\users\Steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\mccFFC4.tmp
c:\windows\$NtUninstallKB59839$
c:\windows\$NtUninstallKB59839$\2289590727\L\xtqaoywe
c:\windows\iun6002.exe
c:\windows\system32\269630729.dat
c:\windows\system32\3870957726.dat
c:\windows\system32\dds_trash_log.cmd
L:\Autorun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_AeLookupSvcMDMehRecvrhkmsvcQWAVE
-------\Service_Apache2slsvc
-------\Service_BITSslsvcAppinfoBFEWPDBusEnum
-------\Service_BITSslsvcp2pimsvcupnphostmsiserver
-------\Service_BrlAPIEventSystemwscsvcmsvsmon80
-------\Service_DPSupnphostmsiserverThemesNetTcpPortSharing
-------\Service_IDriverTBrowserSQLBrowserProtectedStorageusnjsvc
-------\Service_lltdsvcSQLWriterSstpSvcoseSPTISRV
-------\Service_lltdsvcSQLWriterSstpSvcoseSPTISRVplaOracleXETNSListenerwudfsvc
-------\Service_Mcx2SvcShellHWDetectionupnphostplaMMCSSWdiSystemHostnvsvc
-------\Service_Mcx2SvcTHREADORDERusnjsvcRasManFontCache3.0.0.0
-------\Service_Mcx2SvcWinHttpAutoProxySvcAeLookupSvcMDMNlaSvcSENSswprv
-------\Service_MpsSvcNlaSvcCertPropSvc
-------\Service_MpsSvcSCPolicySvclmhostshkmsvc
-------\Service_MSCSPTISRVTapiSrvMSCSPTISRVSENSSysMainSQLWriterWecsvc
-------\Service_MSiSCSISSScsiSVSENSMSDTCSharedAccess
-------\Service_MySQLmsftesql$SQLEXPRESS
-------\Service_MySQLWPDBusEnumBITS
-------\Service_nsinapagentBFETHREADORDERBrowserhkmsvcSLUINotify
-------\Service_nvsvcNetTcpPortSharingW32TimeDPS
-------\Service_nvsvcW32TimeSstpSvcoseSPTISRVusnjsvc
-------\Service_OracleJobSchedulerXEShellHWDetectionupnphost
-------\Service_OracleServiceXELanmanServer
-------\Service_OracleXEClrAgentswprvCOMSysAppALGmsvsmon80
-------\Service_OracleXETNSListenerwudfsvc
-------\Service_oseTermServicePlugPlay
-------\Service_RasManmsiserverMpsSvcNlaSvcAppinfoBFEWPDBusEnum
-------\Service_RemoteRegistryProfSvcRpcSsvdswercplsupport
-------\Service_RpcSsvdswercplsupportMpsSvcSPTISRV
-------\Service_SENSSysMainSQLWriterWecsvc
-------\Service_SQLBrowserUI0Detect
-------\Service_SQLWriterWecsvcBITSSENSSysMain
-------\Service_SQLWriterWecsvcupnphostmsiserver Back-End Service
-------\Service_SSScsiSVSENS
-------\Service_SstpSvcoseSPTISRV
-------\Service_SstpSvcoseSPTISRVApache2EventSystemMSiSCSI
-------\Service_SstpSvcoseSPTISRVApache2NetTcpPortSharingnvsvcMcx2SvcShellHWDetectionupnphostpla
-------\Service_TapiSrvDcomLaunchNetTcpPortSharingWebClientIPBusEnum
-------\Service_usnjsvc
-------\Service_usnjsvcRasMan
-------\Service_usnjsvcRasManMMCSSPNRPsvc
-------\Service_vdswercplsupportWerSvc
-------\Service_WinDefendBFE
-------\Service_WinDefendBFEAppinfoBFEnapagent
-------\Service_WinDefendBFESQLWriterWecsvcBITSSENSSysMainiphlpsvcRemoteAccessPNRPAutoRegehstart
-------\Service_WLSetupSvcWecsvc
-------\Service_WSearchnapagentDPSupnphostmsiserverThemesNetTcpPortSharing
-------\Service_wuauservSessionEnvWSearchwuauservTapiSrvDcomLaunchNetTcpPortSharing
.
.
((((((((((((((((((((((((( Files Created from 2012-03-12 to 2012-04-12 )))))))))))))))))))))))))))))))
.
.
2012-04-12 08:38 . 2012-04-12 08:41 -------- d-----w- c:\users\Steve\AppData\Local\temp
2012-04-12 08:38 . 2012-04-12 08:38 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-04-12 08:38 . 2012-04-12 08:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-12 08:38 . 2012-04-12 08:38 -------- d-----w- c:\users\Linda\AppData\Local\temp
2012-04-12 01:00 . 2012-03-06 06:39 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-12 01:00 . 2012-03-06 06:39 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-12 00:44 . 2012-03-01 11:01 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-04-11 15:37 . 2012-04-11 15:37 -------- d-----w- C:\TDSSKiller_Quarantine
2012-04-10 15:40 . 2012-04-10 15:40 -------- d-----w- c:\users\Steve\AppData\Roaming\Malwarebytes
2012-04-10 15:40 . 2012-04-10 15:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-04-10 15:40 . 2012-04-10 15:40 -------- d-----w- c:\programdata\Malwarebytes
2012-04-10 15:40 . 2012-04-04 14:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-06 14:29 . 2012-04-06 14:29 -------- d-----w- c:\program files\iPod
2012-04-06 14:29 . 2012-04-06 14:31 -------- d-----w- c:\program files\iTunes
2012-04-01 12:02 . 2012-04-01 12:18 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-03-17 17:58 . 2012-03-17 17:58 592824 ----a-w- c:\program files\Mozilla Firefox\gkmedias.dll
2012-03-17 17:58 . 2012-03-17 17:58 44472 ----a-w- c:\program files\Mozilla Firefox\mozglue.dll
2012-03-14 12:57 . 2012-02-02 15:16 2044416 ----a-w- c:\windows\system32\win32k.sys
2012-03-14 12:57 . 2012-02-14 15:45 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-03-14 12:57 . 2012-02-13 14:12 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-03-14 12:57 . 2012-02-13 13:47 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-03-14 12:57 . 2012-02-13 13:44 1068544 ----a-w- c:\windows\system32\DWrite.dll
2012-03-14 12:57 . 2012-02-14 15:45 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-03-14 12:54 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2012-03-14 12:54 . 2012-01-09 13:58 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-13 12:20 . 2010-02-18 13:30 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2012-03-13 12:20 . 2010-02-18 11:28 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-11 15:40 . 2008-07-23 11:17 83456 ----a-w- c:\windows\system32\drivers\serial.sys
2012-04-01 12:18 . 2011-05-14 06:30 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-17 17:58 . 2011-04-30 17:06 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-01-17 14:54 175912 ----a-w- c:\program files\Vuze_Remote\prxtbVuz0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\prxtbVuz0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-11-27 1032376]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-10 4431872]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-11-27 1032376]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"Skytel"="Skytel.exe" [2007-04-04 1822720]
"btbb_McciTrayApp"="c:\program files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" [2009-12-07 1584640]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"M-Audio Taskbar Icon"="c:\windows\system32\M-AudioTaskBarIcon.exe" [2010-12-07 644104]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
.
c:\users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-7-11 576000]
SDK Tray Menu.lnk - c:\program files\Java\jdk1.6.0_03\bin\javaw.exe [2007-12-21 135168]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2008-12-15 303104]
Monitor Apache Servers.lnk - c:\web\Apache2\bin\ApacheMonitor.exe [2008-1-17 41042]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2011-2-14 608584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKLM\~\startupfolder\C:^Users^Steve^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^nnnv0.13162810356833832.exe.lnk]
path=c:\users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\nnnv0.13162810356833832.exe.lnk
backup=c:\windows\pss\nnnv0.13162810356833832.exe.lnk.Startup
backupExtension=.Startup
.
R2 AeLookupSvcMDM;Application Experience AeLookupSvcMDM;o% srv [x]
R2 AeLookupSvcMDMCryptSvc;Application Experience AeLookupSvcMDM AeLookupSvcMDMCryptSvc;c:\windows\system32\adsmsexto.exe [x]
R2 AeLookupSvcMDMehRecvr;Application Experience AeLookupSvcMDM AeLookupSvcMDMehRecvr;c:\windows\system32\adsmsexto.exe [x]
R2 AeLookupSvcMDMehRecvrhkmsvcQWAVEEPSON_PM_RPCV4_01;Application Experience AeLookupSvcMDM AeLookupSvcMDMehRecvr AeLookupSvcMDMehRecvrhkmsvcQWAVE AeLookupSvcMDMehRecvrhkmsvcQWAVEEPSON_PM_RPCV4_01;€û srv [x]
R2 AeLookupSvcMDMehRecvrhkmsvcQWAVEKeyIso;Application Experience AeLookupSvcMDM AeLookupSvcMDMehRecvr AeLookupSvcMDMehRecvrhkmsvcQWAVE AeLookupSvcMDMehRecvrhkmsvcQWAVEKeyIso;€û srv [x]
R2 AeLookupSvcMDMehRecvrW32Timep2pimsvc;Application Experience AeLookupSvcMDM AeLookupSvcMDMehRecvr AeLookupSvcMDMehRecvrW32Timep2pimsvc;€s/ srv [x]
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 253600]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
elagopro
qcdonner
MXOPSWD
fallback
ANC
ser2pl
DCamUSBGrandTek
cobbmservice
sandradatasrv
mclserviceatl
cmudau
imonitor
changer
WinVd32
SNC
naveng
dwmrcs
bwsvc
vci
tosrfnds
iomegaaccess
nbservice
zenos1
lvuvc
alcxsens
cbidf2k
pptchpad
se2Cunic
savrt
wusb54gv2svc
RR2Mjpeg
nuvaud2
vpctcom
ulcdrhlp
savscan
netw4x32
mfcom
lvselsus
DcPTP
atmarpc
tng-doba
firesvc
UsbDiag
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 12:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bbc.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: localhost
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate
TCP: DhcpNameServer = 192.168.1.254
DPF: {047C3241-279D-438A-BC34-9AD1C1910FC0} - hxxp://www.mathtutor.ac.uk/Differentiation/drs/DrsDnldProj1.cab
FF - ProfilePath - c:\users\Steve\AppData\Roaming\Mozilla\Firefox\Profiles\vfue9ge0.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bbc.co.uk/|
http://www.google.co.uk/|http://www...showthread.php?p=1166386&posted=1#post1166386
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bc85cb29a-10cf-4480-9a00-01060b6e0c30%7D&mid=c9326b458a7892fb5e580bd9ef323fd3-9a17500a96d428a5cdb8b2643968b9a928fc107f&ds=AVG&v=10.2.0.3&lang=en&pr=fr&d=2011-10-12%2018%3A58%3A59&sap=ku&q=
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
HKCU-Run-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
HKLM-Run-ROC_roc_dec12 - c:\program files\AVG Secure Search\ROC_roc_dec12.exe
HKU-Default-RunServices-Win32Update - c:\windows\system32\adsmsexto.exe
SafeBoot-07378305.sys
AddRemove-LDraw2006 3rd Quarter - c:\windows\iun6002.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-04-12 09:45
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msftesql$SQLEXPRESS]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:SQLEXPRESS"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AeLookupSvcMDM]
"ImagePath"="o% srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AeLookupSvcMDMehRecvrhkmsvcQWAVEEPSON_PM_RPCV4_01]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AeLookupSvcMDMehRecvrhkmsvcQWAVEKeyIso]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AeLookupSvcMDMehRecvrW32Timep2pimsvc]
"ImagePath"="€s/ srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AudioEndpointBuilderMSDTCLanmanServer]
"ImagePath"="àq% srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BFEDPSmsvsmon80]
"ImagePath"="@p\1e srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BITSslsvc]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BITSslsvcAppinfoBFEWPDBusEnumehSched]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BITSslsvcp2pimsvcupnphostmsiserverBrowser]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BITSslsvcp2pimsvcupnphostmsiserverTapiSrvDcomLaunch]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrowserhkmsvcNetTcpPortSharingnvsvc]
"ImagePath"="0q& srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrowserhkmsvcNetTcpPortSharingnvsvchidserv]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrowserhkmsvcPACSPTISVR]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BrowserhkmsvcSLUINotifynvsvcW32Time]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\clr_optimization_v2.0.50727_32SstpSvcoseSPTISRV]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DFSRWinHttpAutoProxySvc]
"ImagePath"="o# srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\dot3svcSpooler]
"ImagePath"="Øo\1b srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DPSmsvsmon80IDriverTBrowser]
"ImagePath"="àq\15 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\DPSupnphostmsiserver]
"ImagePath"="øo` srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EapHostTBS]
"ImagePath"="øo\1b srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EMDMgmtplaWMPNetworkSvcehstart]
"ImagePath"="¨p srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventSystemMSiSCSI]
"ImagePath"="@p) srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventSystemwscsvcmsvsmon80]
"ImagePath"="Èp% srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventSystemwscsvcmsvsmon80OracleXETNSListenerwudfsvcW32TimefdPHost]
"ImagePath"="w) srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hkmsvcQWAVE]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IDriverTBrowser]
"ImagePath"="øo# srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\idsvcwcncsvc]
"ImagePath"="(o\1a srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IKEEXTehstart]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iphlpsvciphlpsvc]
"ImagePath"="(o\14 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iphlpsvcPolicyAgent]
"ImagePath"="Øo* srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\iphlpsvcRemoteAccessPNRPAutoRegnvsvcW32Time]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IrmonShellHWDetection]
"ImagePath"="¨p\1e srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KtmRmp2pimsvc]
"ImagePath"="xq* srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\KtmRmTapiSrvDcomLaunchNetTcpPortSharing]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanmanServerfdPHostUI0DetectDFSR]
"ImagePath"="@p+ srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lltdsvcidsvc]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lltdsvcSQLWriter]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lmhostsALGmsvsmon80TapiSrvDcomLaunchNetTcpPortSharing]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Mcx2SvcDhcp]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MMCSSMMCSSWdiSystemHostKtmRmTapiSrvDcomLaunchNetTcpPortSharing]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MMCSSWdiSystemHost]
"ImagePath"="øo* srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MMCSSWdiSystemHostnvsvc]
"ImagePath"="àq* srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MpsSvcBrlAPI]
"ImagePath"="(oa srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MpsSvcSCPolicySvclmhostshkmsvcWMPNetworkSvc]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSCSPTISRViphlpsvcRemoteAccessPNRPAutoRegnvsvcW32Time]
"ImagePath"="àq! srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSCSPTISRVTapiSrvMSCSPTISRV]
"ImagePath"="@p srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msftesql$SQLEXPRESSseclogon]
"ImagePath"="àq\1e srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSSQLServerADHelperIKEEXT]
"ImagePath"="Èp0 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\web\mysql\bin\mysqld-nt\" --defaults-file=\"c:\web\mysql\my.ini\" MySQL"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MySQLmsftesql$SQLEXPRESSSpoolerPlugPlay]
"ImagePath"="àq* srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MySQLWPDBusEnum]
"ImagePath"="Àn\1a srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MySQLWPDBusEnumSCPolicySvcWinDefendBFE]
"ImagePath"="xq\14 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetlogonNetlogon]
"ImagePath"="Øo\1c srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetTcpPortSharingnvsvcSamSs]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetTcpPortSharingnvsvcWinmgmt]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NlaSvcswprvCOMSysApp]
"ImagePath"="¨p% srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsinapagentBFEDnscachewmiApSrv]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsinapagentBFEDnscachewmiApSrvupnphostmsiserver]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsinapagentBFETHREADORDER]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nsinapagentBFETHREADORDERBrowserhkmsvcSLUINotifyDPSSENSSysMain]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nvsvcNetTcpPortSharing]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\OracleMTSRecoveryServiceCryptSvc]
"ImagePath"="xq) srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\OracleServiceXEUxSms]
"ImagePath"="@p` srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\OracleXEClrAgentMpsSvc]
"ImagePath"="o' srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\OracleXETNSListenerwudfsvcmsftesql$SQLEXPRESS]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\oseidsvcclr_optimization_v2.0.50727_32]
"ImagePath"="Èp( srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\oseSstpSvcose]
"ImagePath"="o- srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\p2psvcWerSvcidsvcwcncsvc]
"ImagePath"="xq\1c srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PACSPTISVR Back-End Service]
"ImagePath"="@p+ srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PACSPTISVRAeLookupSvc]
"ImagePath"="o\" srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PcaSvcMMCSS]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\plaAeLookupSvc]
"ImagePath"="¨p\" srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\plausnjsvcRasMan]
"ImagePath"="¨p% srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\plaWMPNetworkSvcehstart]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PNRPsvcNetlogonDPSmsvsmon80]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProtectedStorageMcx2Svc]
"ImagePath"="øo\19 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ProtectedStorageusnjsvc]
"ImagePath"="øo\" srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasAutoBITSSCPolicySvc]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccesswuauservSessionEnvWSearchwuauservSQLWriterWecsvcBITSSENSSysMain]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteRegistryMSCSPTISRV]
"ImagePath"="øo/ srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteRegistryProfSvc]
"ImagePath"="@p\1d srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SCPolicySvcWinDefendBFE]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SENSswprv]
"ImagePath"="øo, srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SENSswprvwercplsupportBITSslsvc]
"ImagePath"="€s\" srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SENSSysMainWdiServiceHostp2pimsvcSSScsiSVSENS]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SENSSysMainWdiServiceHostp2pimsvcSSScsiSVSENSSstpSvcoseSPTISRV]
"ImagePath"="w& srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ShellHWDetectionnetprofm]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ShellHWDetectionPlugPlay]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ShellHWDetectionProfSvc]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ShellHWDetectionupnphostpla]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SQLWriternsinapagentBFETHREADORDERBrowserhkmsvcSLUINotify]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SQLWriterWecsvcBITSSENSSysMainCOMSysApp]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SQLWriterWecsvcupnphostmsiserver]
"ImagePath"="àq\1d srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SSDPSRVMMCSS]
"ImagePath"="(o) srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SSDPSRVProfSvc]
"ImagePath"="(o\17 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SSScsiSVTabletInputService]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SSScsiSVwscsvc]
"ImagePath"="o_ srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SSScsiSVwscsvcMpsSvc]
"ImagePath"="xqa srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SstpSvcoseSPTISRVApache2NetTcpPortSharingnvsvc]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SstpSvcoseSPTISRVDhcphidserv]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SstpSvcoseSPTISRVusnjsvcusnjsvcRasMan]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\swprvFontCache3.0.0.0]
"ImagePath"="xq$ srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrvMSCSPTISRVhkmsvc]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ThemesNetTcpPortSharing]
"ImagePath"="(o! srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ThemesNetTcpPortSharingusnjsvcRasManMMCSSPNRPsvc]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ThemesTrustedInstallerWinmgmt]
"ImagePath"="@p. srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\THREADORDERMpsSvc]
"ImagePath"="¨p\1c srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWksmsvsmon80RpcLocator]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrustedInstallerWinmgmtiphlpsvcRemoteAccessPNRPAutoRegnvsvcW32Time]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usnjsvcRasManFontCache3.0.0.0usnjsvcRasManhkmsvc]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usnjsvcRasMannsinapagentBFE]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\usnjsvcSNMPTRAP]
"ImagePath"="àq\15 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSSMcx2Svc]
"ImagePath"="Øo\17 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W32TimefdPHostUI0Detect]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W32Timeoseidsvcclr_optimization_v2.0.50727_32]
"ImagePath"="xq& srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WdiSystemHostRasManmsiserver]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebClientIPBusEnum]
"ImagePath"="(o. srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinDefendBFEAppinfoBFE]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinDefendBFENlaSvcSstpSvcoseSPTISRVusnjsvc]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinDefendBFESQLWriterWecsvcBITSSENSSysMainiphlpsvcRemoteAccessPNRPAutoReg]
"ImagePath"="€s0 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WlansvcWinDefendBFE]
"ImagePath"="@p\17 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WlansvcWinDefendKServiceOracleXEClrAgent]
"ImagePath"="€s\1c srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wmiApSrvMcx2SvcShellHWDetectionupnphostpla]
"ImagePath"="àq+ srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WPCSvcPNRPAutoReg]
"ImagePath"="@p\17 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WPDBusEnumnsi]
"ImagePath"="€û\12 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvcPNRPsvcALG]
"ImagePath"="¨p\14 srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvcSCPolicySvc]
"ImagePath"="o, srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvcTBS]
"ImagePath"="(o- srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WSearchwuauserv]
"ImagePath"="(o! srv"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauservSessionEnv]
"ImagePath"="o. srv"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(736)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\web\Apache2\bin\Apache.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\programdata\EPSON\EPW!3 SSRP\E_S30RP1.EXE
c:\program files\Kontiki\KService.exe
c:\web\Apache2\bin\Apache.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\web\mysql\bin\mysqld-nt.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\System32\nvSCPAPISvr.exe
c:\windows\system32\WUDFHost.exe
c:\windows\RtHDVCpl.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\system32\DllHost.exe
.
**************************************************************************
.
Completion time: 2012-04-12 09:49:42 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-12 08:49
.
Pre-Run: 50,468,646,912 bytes free
Post-Run: 55,963,762,688 bytes free
.
- - End Of File - - C0C27EDFEFBAA7F12287E9DC89507FC9