ComboFix 10-10-07.02 - Nate 10/08/2010 22:44:52.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2047.1196 [GMT -5:00]
Running from: c:\users\Nate\Desktop\ComboFix.exe.exe
Command switches used :: c:\users\Nate\Desktop\CFScript.txt
FILE ::
"c:\users\Nate\AppData\Roaming\OpenCandy\OpenCandy_18C31CC45A9647C6A420D5B4E 5AE8A78\p1v2USWoW_Installer.exe"
"c:\users\Nate\AppData\Roaming\OpenCandy\OpenCandy_18C31CC45A9647C6A420D5B4E 5AE8A78\World of WarCraft Trial.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
Infected copy of c:\windows\system32\drivers\rdprefmp.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASWSP
-------\Service_aswSP
((((((((((((((((((((((((( Files Created from 2010-09-09 to 2010-10-09 )))))))))))))))))))))))))))))))
.
2010-10-09 03:54 . 2010-10-09 03:54 -------- d-----w- c:\users\Nate\AppData\Local\temp
2010-10-09 03:41 . 2010-10-09 03:41 -------- d-----w- C:\Device
2010-10-09 03:12 . 2010-10-09 03:13 -------- d-----w- C:\32788R22FWJFW
2010-10-09 03:03 . 2010-10-09 03:03 -------- d-----w- c:\program files\Common Files\Adobe
2010-10-08 20:40 . 2010-10-08 20:40 -------- d-----w- c:\program files\MSECache
2010-10-07 11:59 . 2010-10-07 11:59 -------- d-----w- c:\windows\system32\wbem\Logs
2010-10-07 04:49 . 2010-10-07 04:49 388096 ----a-r- c:\users\Nate\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-07 04:49 . 2010-10-07 04:49 -------- d-----w- c:\program files\Trend Micro
2010-10-06 04:49 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-06 04:49 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-04 21:48 . 2010-06-19 06:15 2048 ----a-w- c:\windows\system32\tzres.dll
2010-10-04 18:58 . 2006-06-19 18:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2010-10-04 18:58 . 2006-05-25 20:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2010-10-04 18:58 . 2005-08-26 06:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2010-10-04 18:58 . 2002-03-06 06:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2010-10-04 18:58 . 2010-10-04 18:58 -------- d-----w- c:\program files\Trojan Remover
2010-10-04 18:58 . 2010-10-04 18:58 -------- d-----w- c:\users\Nate\AppData\Roaming\Simply Super Software
2010-10-04 18:58 . 2010-10-04 18:58 -------- d-----w- c:\programdata\Simply Super Software
2010-10-04 18:58 . 2003-02-03 01:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2010-10-04 00:44 . 2010-10-08 00:38 -------- d-----w- c:\program files\SpywareBlaster
2010-10-03 18:39 . 2010-10-06 06:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-03 06:25 . 2010-10-03 20:07 -------- dc----w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-10-03 06:24 . 2010-10-03 06:24 -------- d-----w- c:\program files\Lavasoft
2010-10-01 20:13 . 2010-10-03 20:07 -------- d-----w- c:\program files\PDF Creator
2010-09-27 18:00 . 2010-10-08 21:56 -------- d-----w- C:\N8
2010-09-24 00:54 . 2010-09-24 00:54 -------- d-----w- c:\program files\AirPort
2010-09-24 00:49 . 2010-09-24 00:49 -------- d-----w- c:\windows\Downloaded Installations
2010-09-21 19:35 . 2010-09-21 19:35 -------- d-----w- c:\program files\Drug Wars
2010-09-15 23:04 . 2010-09-15 23:05 -------- d-----w- c:\program files\QuickTime
2010-09-15 08:06 . 2010-09-15 08:06 -------- d-----w- c:\windows\PCHEALTH
2010-09-15 06:55 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-14 02:17 . 2009-05-18 18:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-09-14 02:17 . 2008-04-17 17:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-09-14 02:15 . 2010-09-14 02:15 -------- d-----w- c:\program files\iPod
2010-09-14 02:15 . 2010-09-14 02:17 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-09-14 02:15 . 2010-09-14 02:17 -------- d-----w- c:\program files\iTunes
2010-09-14 02:14 . 2010-09-14 02:14 -------- d-----w- c:\program files\Apple Software Update
2010-09-14 02:07 . 2010-09-14 02:07 -------- d-----w- c:\program files\Bonjour
2010-09-13 23:00 . 2010-09-14 01:44 -------- d-----w- c:\users\Nate\.bh_gui
2010-09-13 12:20 . 2010-07-25 02:24 344064 ----a-w- c:\users\Nate\AppData\Roaming\Mozilla\Firefox\Profiles\so4xtik1.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
2010-09-09 15:32 . 2010-09-09 15:32 -------- d-----w- c:\programdata\SRI
2010-09-09 15:27 . 2010-09-09 15:28 -------- d-----w- c:\program files\WinPcap
2010-09-09 14:34 . 2010-09-14 02:15 -------- d-----w- c:\program files\Common Files\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-09 03:58 . 2010-01-21 12:20 -------- d-----w- c:\users\Nate\AppData\Roaming\Tor
2010-10-07 22:44 . 2010-01-21 12:20 -------- d-----w- c:\users\Nate\AppData\Roaming\Vidalia
2010-10-07 05:23 . 2010-03-24 01:57 -------- d-----w- c:\users\Nate\AppData\Roaming\vlc
2010-10-06 05:54 . 2010-07-23 13:22 -------- d-----w- c:\users\Nate\AppData\Roaming\install
2010-10-06 05:36 . 2010-07-09 18:50 -------- d-----w- c:\program files\LogMeIn
2010-10-03 20:07 . 2009-07-14 02:37 -------- d-----w- c:\program files\Windows Mail
2010-10-03 20:07 . 2010-03-03 05:45 -------- d-----w- c:\users\Nate\AppData\Roaming\Winamp
2010-10-03 20:07 . 2010-02-02 03:20 -------- d-----w- c:\users\Nate\AppData\Roaming\uTorrent
2010-10-03 06:24 . 2010-01-22 02:10 -------- d-----w- c:\programdata\Lavasoft
2010-09-29 00:46 . 2009-10-30 13:16 -------- d-----w- c:\users\Nate\AppData\Roaming\.purple
2010-09-28 18:50 . 2009-10-27 15:28 -------- d-----w- c:\users\Nate\AppData\Roaming\gtk-2.0
2010-09-28 16:20 . 2009-10-03 15:29 -------- d-----w- c:\users\Nate\AppData\Roaming\GrabIt
2010-09-28 14:36 . 2009-09-24 23:27 -------- d-----w- c:\programdata\Microsoft Help
2010-09-24 00:58 . 2010-03-27 23:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-24 00:49 . 2010-08-25 22:48 -------- d-----w- c:\program files\Common Files\InstallShield
2010-09-23 19:26 . 2009-10-01 04:30 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-09-18 23:19 . 2009-11-06 06:44 -------- d-----w- c:\program files\Winamp
2010-09-16 23:23 . 2009-09-24 23:29 -------- d-----w- c:\program files\Microsoft.NET
2010-09-15 03:27 . 2009-10-04 20:37 -------- d-----w- c:\users\Nate\AppData\Roaming\Apple Computer
2010-09-09 14:32 . 2009-10-04 20:36 -------- d-----w- c:\programdata\Apple Computer
2010-09-01 14:12 . 2010-09-01 14:12 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 10.0.0.68\SetupAdmin.exe
2010-08-26 12:55 . 2010-08-26 12:55 -------- d-----w- c:\users\Nate\AppData\Roaming\GeoVid
2010-08-25 22:43 . 2010-08-25 22:43 -------- d-----w- c:\program files\Common Files\PctelEapPeer Authentication
2010-08-25 22:42 . 2010-08-25 22:42 -------- d-----w- c:\program files\Common Files\Research in Motion
2010-08-25 22:42 . 2010-08-25 22:42 -------- d-----w- c:\programdata\AT&T
2010-08-25 22:42 . 2010-08-25 22:42 -------- d-----w- c:\program files\AT&T
2010-08-25 22:40 . 2010-08-25 22:40 -------- d-----w- c:\program files\Common Files\Motorola Shared
2010-08-25 22:39 . 2010-08-25 22:39 -------- d-----w- c:\program files\Option
2010-08-25 22:38 . 2010-08-25 22:45 26504 ----a-w- c:\windows\system32\drivers\swmsflt.sys
2010-08-25 22:38 . 2010-08-25 22:38 -------- d-----w- c:\users\Nate\AppData\Roaming\Sierra Wireless
2010-08-25 22:38 . 2010-08-25 22:38 -------- d-----w- c:\program files\Sierra Wireless Inc
2010-08-24 11:35 . 2010-06-27 02:58 -------- d-----w- c:\users\Nate\AppData\Roaming\DVD Flick
2010-08-11 02:14 . 2010-08-11 02:14 -------- d-----w- c:\programdata\GeoVid
2010-08-11 02:14 . 2010-08-11 02:14 -------- d-----w- c:\program files\Common Files\GeoVid
2010-08-11 02:14 . 2010-08-11 02:14 -------- d-----w- c:\program files\GeoVid
2010-08-10 22:55 . 2010-08-10 22:55 -------- d-----w- c:\program files\Wondershare
2010-08-10 22:20 . 2010-08-10 22:20 -------- d-----w- c:\users\Nate\AppData\Roaming\U3
2010-08-10 21:56 . 2010-08-10 21:56 -------- d-----w- c:\program files\MagicISO
2010-08-10 17:03 . 2010-08-10 17:03 -------- d-----w- c:\program files\Microsoft
2010-07-29 06:30 . 2010-08-12 22:21 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-12 22:21 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-27 23:44 . 2010-07-27 23:44 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-07-27 23:44 . 2010-07-27 23:44 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-07-27 23:44 . 2010-07-27 23:44 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-07-24 05:01 . 2010-07-24 05:01 890900 ----a-w- c:\users\Nate\AppData\Roaming\OpenCandy\OpenCandy_18C31CC45A9647C6A420D5B4E5AE8A78\p1v2USWoW_Installer.exe
2010-07-23 17:10 . 2005-04-08 02:16 8148 ---ha-w- c:\users\Nate\AppData\Roaming\Natelog.dat
2010-07-22 19:23 . 2010-07-22 19:23 160928 ----a-w- c:\users\Nate\AppData\Roaming\OpenCandy\OpenCandy_18C31CC45A9647C6A420D5B4E5AE8A78\World of WarCraft Trial.exe
2010-07-14 08:00 . 2010-07-26 20:40 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\N8 ----
2010-10-08 21:56 . 2010-10-08 21:56 165 ---ha-w- c:\n8\~$finance.xlsx
2010-10-08 16:11 . 2010-10-08 16:11 268570 ----a-w- c:\n8\Timothy-Leary-The-Psychedelic-Experience-The-Tibetan-Book-Of-The-Dead.pdf
2010-10-04 00:49 . 2010-10-04 00:49 427799 ----a-w- c:\n8\bookmarks-2010-10-03.json
2010-09-25 20:57 . 2010-10-07 17:23 14785 ----a-w- c:\n8\finance.xlsx
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vidalia"="c:\program files\Vidalia Bundle\Vidalia\vidalia.exe" [2009-11-20 5262834]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2010-08-02 1167808]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BumpTop.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\BumpTop.lnk
backup=c:\windows\pss\BumpTop.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SABnzbd.lnk]
backup=c:\windows\pss\SABnzbd.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SABnzbd.lnk
[HKLM\~\startupfolder\C:^Users^Nate^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
backup=c:\windows\pss\OpenOffice.org 3.1.lnk.Startup
backupExtension=.Startup
path=c:\users\Nate\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 04:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 09:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-09-08 22:31 47904 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AT&T Communication Manager]
2008-06-10 03:27 33280 ----a-w- c:\program files\AT&T\Communication Manager\ATTCM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoStartNPSAgent]
2010-07-05 00:13 95576 ----a-w- c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 21:24 54840 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-01 13:32 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
2010-01-27 17:22 63048 ----a-w- c:\program files\LogMeIn\x86\LogMeInSystray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 16:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-09-02 20:27 25623336 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2007-02-22 00:14 1183744 ----a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-06-08 23:05 322352 ----a-w- c:\program files\uTorrent\uTorrent.exe
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-09-24 721904]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\AT&T\Communication Manager\RcAppSvc.exe [2008-05-23 106496]
R3 CAATT;AT&T Con App Svc;c:\program files\AT&T\Communication Manager\ConAppsSvc.exe [2008-05-23 118784]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 ssecbus;Samsung Mobile Modem Device driver (WDM);c:\windows\system32\DRIVERS\ssecbus.sys [2010-04-27 86528]
R3 ssecmdfl;Samsung Mobile Modem Device 2 Filter;c:\windows\system32\DRIVERS\ssecmdfl.sys [2010-04-27 14976]
R3 ssecmdm;Samsung Mobile Modem Device 2 Driver;c:\windows\system32\DRIVERS\ssecmdm.sys [2010-04-27 114304]
R3 SWNC8U80;Sierra Wireless MUX NDIS Driver (UMTS80);c:\windows\system32\DRIVERS\swnc8u80.sys [2008-01-10 165248]
R3 SWUMX80;Sierra Wireless USB MUX Driver (UMTS80);c:\windows\system32\DRIVERS\swumx80.sys [2008-01-10 142976]
R3 vpcuxd;USB Virtualization Stub Service;c:\windows\system32\DRIVERS\vpcuxd.sys [2009-09-23 12800]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-25 1343400]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-09-15 53328]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-07-05 238952]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [2010-01-27 12856]
S3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\Drivers\ATSwpWDF.sys [2009-04-10 520704]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-06-14 36608]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-10-03 6000640]
S3 RICOH SmartCard Reader;RICOH SmartCard Reader;c:\windows\system32\DRIVERS\rismc32.sys [2006-10-03 47488]
S3 SMSCIRDA;SMSC Infrared Device Driver;c:\windows\system32\DRIVERS\SMSCirda.sys [2007-04-25 31232]