Broni,
I followed your instructions. I created the text file and also ran Combofix again.
Below is the Combofix report file.
Thank you,
Allandncr
ComboFix 12-07-31.06 - Owner 08/03/2012 20:46:36.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.594 [GMT -4:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFscript.txt
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
FILE ::
"c:\windows\winstart.bat"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\SET291.tmp
c:\windows\system32\SET292.tmp
c:\windows\system32\SET293.tmp
c:\windows\system32\SET294.tmp
c:\windows\system32\SET295.tmp
c:\windows\system32\SET296.tmp
c:\windows\system32\SET297.tmp
c:\windows\system32\SET298.tmp
c:\windows\system32\SET29A.tmp
c:\windows\system32\SET29B.tmp
c:\windows\system32\SET29E.tmp
c:\windows\system32\SET2A0.tmp
c:\windows\system32\SET2A1.tmp
c:\windows\system32\SET2A3.tmp
c:\windows\system32\SET2A4.tmp
c:\windows\system32\SET2A5.tmp
c:\windows\system32\SET2A6.tmp
c:\windows\system32\SET2A7.tmp
c:\windows\system32\SET2A8.tmp
c:\windows\system32\SET2A9.tmp
c:\windows\system32\SET2AA.tmp
c:\windows\system32\SET2AB.tmp
c:\windows\system32\SET2AC.tmp
c:\windows\system32\SET2AD.tmp
c:\windows\system32\SET2AE.tmp
c:\windows\system32\SET2B0.tmp
c:\windows\system32\SET2B1.tmp
c:\windows\system32\SET2B2.tmp
c:\windows\system32\SET2B3.tmp
c:\windows\system32\SET2B5.tmp
c:\windows\system32\SET2B7.tmp
c:\windows\system32\SET2B8.tmp
c:\windows\system32\SET2BA.tmp
c:\windows\system32\SET2BB.tmp
c:\windows\system32\SET2BC.tmp
c:\windows\system32\SET2BD.tmp
c:\windows\system32\SET2BE.tmp
c:\windows\system32\SET2BF.tmp
c:\windows\system32\SET2C0.tmp
c:\windows\system32\SET2C1.tmp
c:\windows\system32\SET2C3.tmp
c:\windows\system32\SET2C4.tmp
c:\windows\system32\SET2C5.tmp
c:\windows\system32\SET2C6.tmp
c:\windows\system32\SET2C7.tmp
c:\windows\system32\SET2C8.tmp
c:\windows\system32\SET2C9.tmp
c:\windows\system32\SET2CC.tmp
c:\windows\system32\SET2CE.tmp
c:\windows\system32\SET2D0.tmp
c:\windows\system32\SET2D1.tmp
c:\windows\system32\SET2D2.tmp
c:\windows\system32\SET2D3.tmp
c:\windows\system32\SET2D4.tmp
c:\windows\system32\SET2D5.tmp
c:\windows\system32\SET2D8.tmp
c:\windows\system32\SET2D9.tmp
c:\windows\system32\SET2DA.tmp
c:\windows\system32\SET2DD.tmp
c:\windows\system32\SET2DE.tmp
c:\windows\system32\SET2DF.tmp
c:\windows\system32\SET2E0.tmp
c:\windows\system32\SET2E2.tmp
c:\windows\system32\SET2E4.tmp
c:\windows\system32\SET2E5.tmp
c:\windows\system32\SET2E6.tmp
c:\windows\system32\SET2E7.tmp
c:\windows\system32\SET2E8.tmp
c:\windows\system32\SET2E9.tmp
c:\windows\system32\SET2EA.tmp
c:\windows\system32\SET2EB.tmp
c:\windows\system32\SET2EC.tmp
c:\windows\system32\SET2ED.tmp
c:\windows\system32\SET2EE.tmp
c:\windows\system32\SET2F0.tmp
c:\windows\system32\SET2F1.tmp
c:\windows\system32\SET2F2.tmp
c:\windows\system32\SET2F3.tmp
c:\windows\system32\SET2F4.tmp
c:\windows\system32\SET2F5.tmp
c:\windows\system32\SET2F6.tmp
c:\windows\system32\SET2F7.tmp
c:\windows\system32\SET2F8.tmp
c:\windows\system32\SET2F9.tmp
c:\windows\system32\SET2FA.tmp
c:\windows\system32\SET2FB.tmp
c:\windows\system32\SET2FC.tmp
c:\windows\system32\SET2FD.tmp
c:\windows\system32\SET2FE.tmp
c:\windows\system32\SET2FF.tmp
c:\windows\system32\SET300.tmp
c:\windows\system32\SET301.tmp
c:\windows\system32\SET302.tmp
c:\windows\system32\SET303.tmp
c:\windows\system32\SET305.tmp
c:\windows\system32\SET307.tmp
c:\windows\system32\SET308.tmp
c:\windows\system32\SET309.tmp
c:\windows\system32\SET30A.tmp
c:\windows\system32\SET30E.tmp
c:\windows\system32\SET30F.tmp
c:\windows\system32\SET310.tmp
c:\windows\system32\SET311.tmp
c:\windows\system32\SET312.tmp
c:\windows\system32\SET315.tmp
c:\windows\system32\SET316.tmp
c:\windows\system32\SET318.tmp
c:\windows\system32\SET319.tmp
c:\windows\system32\SET31A.tmp
c:\windows\system32\SET31C.tmp
c:\windows\system32\SET31E.tmp
c:\windows\system32\SET31F.tmp
c:\windows\system32\SET320.tmp
c:\windows\system32\SET322.tmp
c:\windows\system32\SET323.tmp
c:\windows\system32\SET324.tmp
c:\windows\system32\SET325.tmp
c:\windows\system32\SET327.tmp
c:\windows\system32\SET328.tmp
c:\windows\system32\SET329.tmp
c:\windows\system32\SET32B.tmp
c:\windows\system32\SET32C.tmp
c:\windows\system32\SET32E.tmp
c:\windows\system32\SET330.tmp
c:\windows\system32\SET331.tmp
c:\windows\system32\SET332.tmp
c:\windows\system32\SET333.tmp
c:\windows\system32\SET334.tmp
c:\windows\system32\SET335.tmp
c:\windows\system32\SET336.tmp
c:\windows\system32\SET337.tmp
c:\windows\system32\SET338.tmp
c:\windows\system32\SET339.tmp
c:\windows\system32\SET33A.tmp
c:\windows\system32\SET33B.tmp
c:\windows\system32\SET33C.tmp
c:\windows\system32\SET33D.tmp
c:\windows\system32\SET33F.tmp
c:\windows\system32\SET340.tmp
c:\windows\system32\SET341.tmp
c:\windows\system32\SET342.tmp
c:\windows\system32\SET343.tmp
c:\windows\system32\SET344.tmp
c:\windows\system32\SET345.tmp
c:\windows\system32\SET347.tmp
c:\windows\system32\SET349.tmp
c:\windows\system32\SET34C.tmp
c:\windows\system32\SET34D.tmp
c:\windows\system32\SET34E.tmp
c:\windows\system32\SET350.tmp
c:\windows\system32\SET351.tmp
c:\windows\system32\SET352.tmp
c:\windows\system32\SET354.tmp
c:\windows\system32\SET357.tmp
c:\windows\system32\SET358.tmp
c:\windows\system32\SET359.tmp
c:\windows\system32\SET35A.tmp
c:\windows\system32\SET35B.tmp
c:\windows\system32\SET35C.tmp
c:\windows\system32\SET35D.tmp
c:\windows\system32\SET35E.tmp
c:\windows\system32\SET35F.tmp
c:\windows\system32\SET360.tmp
c:\windows\system32\SET362.tmp
c:\windows\system32\SET364.tmp
c:\windows\system32\SET365.tmp
c:\windows\system32\SET367.tmp
c:\windows\system32\SET368.tmp
c:\windows\system32\SET36B.tmp
c:\windows\system32\SET36D.tmp
c:\windows\system32\SET36E.tmp
c:\windows\system32\SET370.tmp
c:\windows\system32\SET371.tmp
c:\windows\system32\SET372.tmp
c:\windows\system32\SET376.tmp
c:\windows\system32\SET377.tmp
c:\windows\system32\SET378.tmp
c:\windows\system32\SET379.tmp
c:\windows\system32\SET37A.tmp
c:\windows\system32\SET37C.tmp
c:\windows\system32\SET37D.tmp
c:\windows\system32\SET37E.tmp
c:\windows\system32\SET37F.tmp
c:\windows\system32\SET381.tmp
c:\windows\system32\SET382.tmp
c:\windows\system32\SET383.tmp
c:\windows\system32\SET384.tmp
c:\windows\system32\SET385.tmp
c:\windows\system32\SET386.tmp
c:\windows\system32\SET387.tmp
c:\windows\system32\SET389.tmp
c:\windows\system32\SET38B.tmp
c:\windows\system32\SET38C.tmp
c:\windows\system32\SET38D.tmp
c:\windows\system32\SET38F.tmp
c:\windows\system32\SET390.tmp
c:\windows\system32\SET391.tmp
c:\windows\system32\SET394.tmp
c:\windows\system32\SET395.tmp
c:\windows\system32\SET398.tmp
c:\windows\system32\SET399.tmp
c:\windows\system32\SET39A.tmp
c:\windows\system32\SET39B.tmp
c:\windows\system32\SET39C.tmp
c:\windows\system32\SET39E.tmp
c:\windows\system32\SET39F.tmp
c:\windows\system32\SET3A0.tmp
c:\windows\system32\SET3A1.tmp
c:\windows\system32\SET3A2.tmp
c:\windows\system32\SET3A3.tmp
c:\windows\system32\SET3A4.tmp
c:\windows\system32\SET3A5.tmp
c:\windows\system32\SET3A6.tmp
c:\windows\system32\SET3A7.tmp
c:\windows\system32\SET3A8.tmp
c:\windows\system32\SET3A9.tmp
c:\windows\system32\SET3AA.tmp
c:\windows\system32\SET3AC.tmp
c:\windows\system32\SET3AD.tmp
c:\windows\system32\SET3AE.tmp
c:\windows\system32\SET3AF.tmp
c:\windows\system32\SET3B0.tmp
c:\windows\system32\SET3B2.tmp
c:\windows\system32\SET3B4.tmp
c:\windows\system32\SET3B6.tmp
c:\windows\system32\SET3B7.tmp
c:\windows\system32\SET3B9.tmp
c:\windows\system32\SET3BA.tmp
c:\windows\system32\SET3BB.tmp
c:\windows\system32\SET3BC.tmp
c:\windows\system32\SET3BD.tmp
c:\windows\system32\SET3BE.tmp
c:\windows\system32\SET3BF.tmp
c:\windows\system32\SET3C0.tmp
c:\windows\system32\SET3C1.tmp
c:\windows\system32\SET3C6.tmp
c:\windows\system32\SET3C7.tmp
c:\windows\system32\SET3C8.tmp
c:\windows\system32\SET3C9.tmp
c:\windows\system32\SET3CB.tmp
c:\windows\system32\SET3CD.tmp
c:\windows\system32\SET3CE.tmp
c:\windows\system32\SET3CF.tmp
c:\windows\system32\SET3D0.tmp
c:\windows\system32\SET3D1.tmp
c:\windows\system32\SET3D2.tmp
c:\windows\system32\SET3D3.tmp
c:\windows\system32\SET3D4.tmp
c:\windows\system32\SET3D5.tmp
c:\windows\system32\SET3D6.tmp
c:\windows\system32\SET3D7.tmp
c:\windows\system32\SET3D8.tmp
c:\windows\system32\SET3D9.tmp
c:\windows\system32\SET3DA.tmp
c:\windows\system32\SET3DB.tmp
c:\windows\system32\SET3DC.tmp
c:\windows\system32\SET3DE.tmp
c:\windows\system32\SET3E0.tmp
c:\windows\system32\SET3E1.tmp
c:\windows\system32\SET3E2.tmp
c:\windows\system32\SET3E5.tmp
c:\windows\system32\SET3E6.tmp
c:\windows\system32\SET3E7.tmp
c:\windows\system32\SET3E9.tmp
c:\windows\system32\SET3EA.tmp
c:\windows\system32\SET3EB.tmp
c:\windows\system32\SET3EC.tmp
c:\windows\system32\SET3ED.tmp
c:\windows\system32\SET3EE.tmp
c:\windows\system32\SET3EF.tmp
c:\windows\system32\SET3F0.tmp
c:\windows\system32\SET3F1.tmp
c:\windows\system32\SET3F2.tmp
c:\windows\system32\SET3F4.tmp
c:\windows\system32\SET3F5.tmp
c:\windows\system32\SET3F7.tmp
c:\windows\system32\SET3F8.tmp
c:\windows\system32\SET3F9.tmp
c:\windows\system32\SET3FC.tmp
c:\windows\system32\SET3FE.tmp
c:\windows\system32\SET3FF.tmp
c:\windows\system32\SET400.tmp
c:\windows\system32\SET402.tmp
c:\windows\system32\SET404.tmp
c:\windows\system32\SET405.tmp
c:\windows\system32\SET407.tmp
c:\windows\system32\SET408.tmp
c:\windows\system32\SET409.tmp
c:\windows\system32\SET40A.tmp
c:\windows\system32\SET40B.tmp
c:\windows\system32\SET40C.tmp
c:\windows\system32\SET40D.tmp
c:\windows\system32\SET40F.tmp
c:\windows\system32\SET410.tmp
c:\windows\system32\SET411.tmp
c:\windows\system32\SET412.tmp
c:\windows\system32\SET414.tmp
c:\windows\system32\SET416.tmp
c:\windows\system32\SET417.tmp
c:\windows\system32\SET419.tmp
c:\windows\system32\SET41B.tmp
c:\windows\system32\SET41C.tmp
c:\windows\system32\SET41E.tmp
c:\windows\system32\SET41F.tmp
c:\windows\system32\SET420.tmp
c:\windows\system32\SET421.tmp
c:\windows\system32\SET422.tmp
c:\windows\system32\SET423.tmp
c:\windows\system32\SET424.tmp
c:\windows\system32\SET425.tmp
c:\windows\system32\SET427.tmp
c:\windows\system32\SET428.tmp
c:\windows\system32\SET429.tmp
c:\windows\system32\SET42B.tmp
c:\windows\system32\SET42E.tmp
c:\windows\system32\SET42F.tmp
c:\windows\system32\SET430.tmp
c:\windows\system32\SET432.tmp
c:\windows\system32\SET433.tmp
c:\windows\system32\SET434.tmp
c:\windows\system32\SET435.tmp
c:\windows\system32\SET436.tmp
c:\windows\system32\SET437.tmp
c:\windows\system32\SET438.tmp
c:\windows\system32\SET439.tmp
c:\windows\system32\SET43B.tmp
c:\windows\system32\SET43C.tmp
c:\windows\system32\SET43D.tmp
c:\windows\system32\SET43E.tmp
c:\windows\system32\SET43F.tmp
c:\windows\system32\SET440.tmp
c:\windows\system32\SET441.tmp
c:\windows\system32\SET444.tmp
c:\windows\system32\SET44C.tmp
c:\windows\system32\SET44E.tmp
c:\windows\system32\SET44F.tmp
c:\windows\system32\SET450.tmp
c:\windows\system32\SET451.tmp
c:\windows\system32\SET453.tmp
c:\windows\system32\SET454.tmp
c:\windows\system32\SET455.tmp
c:\windows\system32\SET456.tmp
c:\windows\system32\SET457.tmp
c:\windows\system32\SET458.tmp
c:\windows\system32\SET459.tmp
c:\windows\system32\SET45A.tmp
c:\windows\system32\SET45D.tmp
c:\windows\system32\SET45F.tmp
c:\windows\system32\SET460.tmp
c:\windows\system32\SET461.tmp
c:\windows\system32\SET462.tmp
c:\windows\system32\SET463.tmp
c:\windows\system32\SET464.tmp
c:\windows\system32\SET467.tmp
c:\windows\system32\SET468.tmp
c:\windows\system32\SET469.tmp
c:\windows\system32\SET46A.tmp
c:\windows\system32\SET46C.tmp
c:\windows\system32\SET46D.tmp
c:\windows\system32\SET46E.tmp
c:\windows\system32\SET471.tmp
c:\windows\system32\SET478.tmp
c:\windows\system32\SET47C.tmp
c:\windows\system32\SET47D.tmp
c:\windows\system32\SET47E.tmp
c:\windows\system32\SET47F.tmp
c:\windows\system32\SET483.tmp
c:\windows\system32\SET488.tmp
c:\windows\system32\SET48B.tmp
c:\windows\system32\SET48C.tmp
c:\windows\system32\SET48D.tmp
c:\windows\system32\SET48E.tmp
c:\windows\system32\SET492.tmp
c:\windows\system32\SET494.tmp
c:\windows\system32\SET497.tmp
c:\windows\system32\SET498.tmp
c:\windows\system32\SET499.tmp
c:\windows\system32\SET49C.tmp
c:\windows\system32\SET49D.tmp
c:\windows\system32\SET49E.tmp
c:\windows\system32\SET49F.tmp
c:\windows\system32\SET4A0.tmp
c:\windows\system32\SET4A1.tmp
c:\windows\system32\SET4A2.tmp
c:\windows\system32\SET4A4.tmp
c:\windows\system32\SET4A5.tmp
c:\windows\system32\SET4A6.tmp
c:\windows\system32\SET4A8.tmp
c:\windows\system32\SET4A9.tmp
c:\windows\system32\SET4AA.tmp
c:\windows\system32\SET4AB.tmp
c:\windows\system32\SET4AC.tmp
c:\windows\system32\SET4AE.tmp
c:\windows\system32\SET4B1.tmp
c:\windows\system32\SET4B3.tmp
c:\windows\system32\SET4B4.tmp
c:\windows\system32\SET4B5.tmp
c:\windows\system32\SET4B7.tmp
c:\windows\system32\SET4B8.tmp
c:\windows\system32\SET4B9.tmp
c:\windows\system32\SET4BA.tmp
c:\windows\system32\SET4BC.tmp
c:\windows\system32\SET4BE.tmp
c:\windows\system32\SET4BF.tmp
c:\windows\system32\SET4C0.tmp
c:\windows\system32\SET4C1.tmp
c:\windows\system32\SET4C2.tmp
c:\windows\system32\SET4C3.tmp
c:\windows\system32\SET4C4.tmp
c:\windows\system32\SET4C5.tmp
c:\windows\system32\SET4C6.tmp
c:\windows\system32\SET4CA.tmp
c:\windows\system32\SET4CB.tmp
c:\windows\system32\SET4CC.tmp
c:\windows\system32\SET4CE.tmp
c:\windows\system32\SET4CF.tmp
c:\windows\system32\SET4D0.tmp
c:\windows\system32\SET4D1.tmp
c:\windows\system32\SET4D2.tmp
c:\windows\system32\SET4D3.tmp
c:\windows\system32\SET4D5.tmp
c:\windows\system32\SET4D7.tmp
c:\windows\system32\SET4D9.tmp
c:\windows\system32\SET4DA.tmp
c:\windows\system32\SET4DC.tmp
c:\windows\system32\SET4DD.tmp
c:\windows\system32\SET4DE.tmp
c:\windows\system32\SET4E1.tmp
c:\windows\system32\SET4E2.tmp
c:\windows\system32\SET4E3.tmp
c:\windows\system32\SET4E4.tmp
c:\windows\system32\SET4E7.tmp
c:\windows\system32\SET4E8.tmp
c:\windows\system32\SET4E9.tmp
c:\windows\system32\SET4EC.tmp
c:\windows\system32\SET4ED.tmp
c:\windows\system32\SET4EE.tmp
c:\windows\system32\SET4F0.tmp
c:\windows\system32\SET4F1.tmp
c:\windows\system32\SET4F2.tmp
c:\windows\system32\SET4F5.tmp
c:\windows\system32\SET4F6.tmp
c:\windows\system32\SET4F7.tmp
c:\windows\system32\SET4FB.tmp
c:\windows\system32\SET4FC.tmp
c:\windows\system32\SET4FD.tmp
c:\windows\system32\SET4FF.tmp
c:\windows\system32\SET501.tmp
c:\windows\system32\SET502.tmp
c:\windows\system32\SET503.tmp
c:\windows\system32\SET505.tmp
c:\windows\system32\SET506.tmp
c:\windows\system32\SET507.tmp
c:\windows\system32\SET508.tmp
c:\windows\system32\SET50B.tmp
c:\windows\system32\SET50C.tmp
c:\windows\system32\SET50E.tmp
c:\windows\system32\SET510.tmp
c:\windows\system32\SET512.tmp
c:\windows\system32\SET513.tmp
c:\windows\system32\SET514.tmp
c:\windows\system32\SET515.tmp
c:\windows\system32\SET517.tmp
c:\windows\system32\SET518.tmp
c:\windows\system32\SET519.tmp
c:\windows\system32\SET51B.tmp
c:\windows\system32\SET51C.tmp
c:\windows\system32\SET51E.tmp
c:\windows\system32\SET521.tmp
c:\windows\system32\SET522.tmp
c:\windows\system32\SET524.tmp
c:\windows\system32\SET525.tmp
c:\windows\system32\SET526.tmp
c:\windows\system32\SET52C.tmp
c:\windows\system32\SET52D.tmp
c:\windows\system32\SET52E.tmp
c:\windows\system32\SET530.tmp
c:\windows\system32\SET531.tmp
c:\windows\system32\SET532.tmp
c:\windows\system32\SET533.tmp
c:\windows\system32\SET534.tmp
c:\windows\system32\SET535.tmp
c:\windows\system32\SET536.tmp
c:\windows\system32\SET537.tmp
c:\windows\system32\SET539.tmp
c:\windows\system32\SET53B.tmp
c:\windows\system32\SET53E.tmp
c:\windows\system32\SET53F.tmp
c:\windows\system32\SET543.tmp
c:\windows\system32\SET548.tmp
c:\windows\system32\SET54C.tmp
c:\windows\system32\SET54E.tmp
c:\windows\system32\SET54F.tmp
c:\windows\system32\SET550.tmp
c:\windows\system32\SET551.tmp
c:\windows\system32\SET553.tmp
c:\windows\system32\SET554.tmp
c:\windows\system32\SET559.tmp
c:\windows\system32\SET55B.tmp
c:\windows\system32\SET55C.tmp
c:\windows\system32\SET55E.tmp
c:\windows\system32\SET55F.tmp
c:\windows\system32\SET565.tmp
c:\windows\system32\SET570.tmp
c:\windows\system32\SET574.tmp
c:\windows\system32\SET575.tmp
c:\windows\system32\SET579.tmp
c:\windows\system32\SET581.tmp
c:\windows\system32\SET583.tmp
c:\windows\system32\SET588.tmp
c:\windows\system32\SET589.tmp
c:\windows\system32\SET58B.tmp
c:\windows\system32\SET58C.tmp
c:\windows\system32\SET591.tmp
c:\windows\system32\SET593.tmp
c:\windows\system32\SET594.tmp
c:\windows\system32\SET595.tmp
c:\windows\system32\SET597.tmp
c:\windows\system32\SET598.tmp
c:\windows\system32\SET599.tmp
c:\windows\system32\SET59A.tmp
c:\windows\system32\SET59C.tmp
c:\windows\system32\SET59D.tmp
c:\windows\system32\SET59E.tmp
c:\windows\system32\SET59F.tmp
c:\windows\system32\SET5A0.tmp
c:\windows\system32\SET5A3.tmp
c:\windows\system32\SET5A5.tmp
c:\windows\system32\SET5AA.tmp
c:\windows\system32\SET5AB.tmp
c:\windows\system32\SET5B3.tmp
c:\windows\system32\SET5BA.tmp
c:\windows\system32\SET5BF.tmp
c:\windows\system32\SET5C1.tmp
c:\windows\system32\SET5C4.tmp
c:\windows\system32\SET5C5.tmp
c:\windows\system32\SET5C7.tmp
c:\windows\system32\SET5C8.tmp
c:\windows\system32\SET5C9.tmp
c:\windows\system32\SET5CB.tmp
c:\windows\system32\SET5CD.tmp
c:\windows\system32\SET5D0.tmp
c:\windows\system32\SET5D1.tmp
c:\windows\system32\SET5D2.tmp
c:\windows\system32\SET5D5.tmp
c:\windows\system32\SET5D6.tmp
c:\windows\system32\SET5D7.tmp
c:\windows\system32\SET5DB.tmp
c:\windows\system32\SET5DC.tmp
c:\windows\system32\SET5DD.tmp
c:\windows\system32\SET5E5.tmp
c:\windows\system32\SET5E8.tmp
c:\windows\system32\SET5EC.tmp
c:\windows\system32\SET5EE.tmp
c:\windows\system32\SET5F0.tmp
c:\windows\system32\SET5F3.tmp
c:\windows\system32\SET5F9.tmp
c:\windows\system32\SET5FB.tmp
c:\windows\system32\SET5FC.tmp
c:\windows\system32\SET5FD.tmp
c:\windows\system32\SET5FF.tmp
c:\windows\system32\SET603.tmp
c:\windows\system32\SET607.tmp
c:\windows\system32\SET60E.tmp
c:\windows\system32\SET611.tmp
c:\windows\system32\SET613.tmp
c:\windows\system32\SET619.tmp
c:\windows\system32\SET622.tmp
c:\windows\system32\SET628.tmp
c:\windows\system32\SET62A.tmp
c:\windows\system32\SET62B.tmp
c:\windows\system32\SET62C.tmp
c:\windows\system32\SET638.tmp
c:\windows\system32\SET63D.tmp
c:\windows\system32\SET643.tmp
c:\windows\system32\SET653.tmp
c:\windows\system32\SET654.tmp
c:\windows\system32\SET67E.tmp
c:\windows\system32\SET681.tmp
c:\windows\system32\SET688.tmp
c:\windows\system32\SET689.tmp
c:\windows\system32\SET68A.tmp
c:\windows\system32\SET68C.tmp
c:\windows\system32\SET68D.tmp
c:\windows\system32\SET68E.tmp
c:\windows\system32\SET68F.tmp
c:\windows\system32\SET691.tmp
c:\windows\system32\SET693.tmp
c:\windows\system32\SET694.tmp
c:\windows\system32\SET695.tmp
c:\windows\system32\SET698.tmp
c:\windows\system32\SET69A.tmp
c:\windows\system32\SET69F.tmp
c:\windows\system32\SET6A0.tmp
c:\windows\system32\SET6A8.tmp
c:\windows\system32\SET6AF.tmp
c:\windows\system32\SET6B6.tmp
c:\windows\system32\SET6B9.tmp
c:\windows\system32\SET6BC.tmp
c:\windows\system32\SET6BE.tmp
c:\windows\system32\SET6C2.tmp
c:\windows\system32\SET6C5.tmp
c:\windows\system32\SET6C6.tmp
c:\windows\system32\SET6CB.tmp
c:\windows\system32\SET6CC.tmp
c:\windows\system32\SET6D0.tmp
c:\windows\system32\SET6D1.tmp
c:\windows\system32\SET6DA.tmp
c:\windows\system32\SET6DD.tmp
c:\windows\system32\SET6E1.tmp
c:\windows\system32\SET6E3.tmp
c:\windows\system32\SET6E5.tmp
c:\windows\system32\SETEC0.tmp
c:\windows\system32\SETEC3.tmp
c:\windows\system32\SETEC4.tmp
c:\windows\system32\SETEC8.tmp
c:\windows\system32\SETEF7.tmp
c:\windows\system32\SETEF9.tmp
c:\windows\system32\SETFA6.tmp
c:\windows\system32\SETFA9.tmp
c:\windows\system32\SETFAE.tmp
c:\windows\system32\SETFDD.tmp
c:\windows\system32\SETFDF.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-07-04 to 2012-08-04 )))))))))))))))))))))))))))))))
.
.
2012-08-03 07:03 . 2012-08-03 07:0356200----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{B81702FE-42CA-4C47-8725-8431F6B7EB09}\offreg.dll
2012-08-03 06:32 . 2012-06-29 08:446891424----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{B81702FE-42CA-4C47-8725-8431F6B7EB09}\mpengine.dll
2012-07-27 00:17 . 2012-07-27 00:17--------d-----w-c:\documents and settings\New Administrator\Local Settings\Application Data\Apple Computer
2012-07-27 00:16 . 2012-07-27 00:16--------d-----w-c:\documents and settings\New Administrator\Local Settings\Application Data\Adobe
2012-07-27 00:16 . 2012-07-27 00:16--------d-----w-c:\documents and settings\New Administrator\Application Data\Apple Computer
2012-07-27 00:12 . 2012-07-27 00:12--------d-sh--w-c:\documents and settings\New Administrator\IETldCache
2012-07-26 21:59 . 2012-08-03 04:43--------d-----w-c:\documents and settings\Administrator
2012-07-26 20:55 . 2012-07-26 20:5535816----a-w-c:\windows\system32\drivers\Partizan.sys
2012-07-26 20:55 . 2012-07-26 20:5539184----a-w-c:\windows\system32\Partizan.exe
2012-07-26 20:55 . 2012-07-26 20:55--------d-----r-C:\comment.htt
2012-07-23 13:24 . 2012-07-26 20:5924416----a-w-c:\windows\system32\drivers\regguard.sys
2012-07-20 20:10 . 2012-07-30 20:54--------d-----w-c:\documents and settings\All Users\Application Data\RegRun
2012-07-20 20:07 . 2012-07-20 20:072--shatr-c:\windows\winstart.bat
2012-07-20 20:07 . 2012-06-27 20:0112800----a-w-c:\windows\system32\drivers\UnHackMeDrv.sys
2012-07-20 20:07 . 2012-07-24 20:44--------d-----w-c:\program files\UnHackMe
2012-07-17 13:59 . 2012-07-17 13:59--------d-----w-C:\7da463663ba65c59d53132b59029
2012-07-13 18:27 . 2012-07-13 18:27--------d-----w-C:\70d9dacbc4d71b5b4c
2012-07-11 12:55 . 2012-07-11 12:55--------d-----w-C:\avastscans
2012-07-08 17:29 . 2012-07-08 17:29--------d-----w-c:\documents and settings\Owner\Application Data\Malwarebytes
2012-07-08 17:28 . 2012-07-08 17:28--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2012-07-08 17:28 . 2012-07-20 05:51--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2012-07-08 17:28 . 2012-07-03 17:4622344----a-w-c:\windows\system32\drivers\mbam.sys
2012-07-08 16:48 . 2012-07-08 16:47205072----a-w-c:\windows\system32\drivers\tmcomm.sys
2012-07-08 16:47 . 2012-07-13 04:45131344----a-w-c:\windows\system32\drivers\tmrkb.sys
2012-07-08 15:02 . 2012-07-08 15:0214664----a-w-c:\windows\stinger.sys
2012-07-08 15:01 . 2012-07-08 15:42--------d-----w-c:\program files\stinger
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-02 14:44 . 2004-05-12 12:083997----a-w-c:\windows\viassary-hp.reg
2012-06-29 08:44 . 2006-06-30 14:336891424----a-w-c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-06-28 12:52 . 2010-12-13 22:29353688----a-w-c:\windows\system32\drivers\aswSP.sys
2012-06-28 12:52 . 2010-12-13 22:2954232----a-w-c:\windows\system32\drivers\aswTdi.sys
2012-06-28 12:52 . 2011-07-03 12:11721000----a-w-c:\windows\system32\drivers\aswSnx.sys
2012-06-28 12:52 . 2010-12-13 22:2935928----a-w-c:\windows\system32\drivers\aswRdr.sys
2012-06-28 12:52 . 2010-12-13 22:2997352----a-w-c:\windows\system32\drivers\aswmon2.sys
2012-06-28 12:52 . 2010-12-13 22:2989624----a-w-c:\windows\system32\drivers\aswmon.sys
2012-06-28 12:52 . 2010-12-13 22:2921256----a-w-c:\windows\system32\drivers\aswFsBlk.sys
2012-06-28 12:52 . 2010-12-13 22:2925256----a-w-c:\windows\system32\drivers\aavmker4.sys
2012-06-28 12:52 . 2010-12-13 22:2841224----a-w-c:\windows\avastSS.scr
2012-06-28 12:51 . 2010-12-13 22:28227648----a-w-c:\windows\system32\aswBoot.exe
2012-06-02 19:19 . 2007-05-23 20:5522040----a-w-c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2007-05-23 20:5515384----a-w-c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2005-07-21 18:29329240----a-w-c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2005-07-21 18:29219160----a-w-c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2005-07-21 18:29210968----a-w-c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2007-05-23 20:5515384----a-w-c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2005-07-21 18:2935864----a-w-c:\windows\system32\wups.dll
2012-06-02 19:19 . 2005-05-26 08:1645080----a-w-c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2004-06-04 22:2497304----a-w-c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2004-06-04 21:5153784----a-w-c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2007-05-23 20:5517944----a-w-c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2005-07-21 18:29577048----a-w-c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2004-06-04 21:511933848----a-w-c:\windows\system32\wuaueng.dll
2012-06-02 19:18 . 2011-07-19 09:41214256----a-w-c:\windows\system32\muweb.dll
2012-06-02 19:18 . 2011-07-19 09:4117136----a-w-c:\windows\system32\mucltui.dll.mui
2012-06-02 19:18 . 2011-07-19 09:41275696----a-w-c:\windows\system32\mucltui.dll
2012-05-31 16:25 . 2009-10-03 16:39237072------w-c:\windows\system32\MpSigStub.exe
2012-05-31 13:22 . 2004-05-12 10:06599040----a-w-c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2004-01-22 06:16916992----a-w-c:\windows\system32\wininet.dll
2012-05-15 13:20 . 2010-12-14 22:091863168----a-w-c:\windows\system32\win32k.sys
2012-05-15 00:39 . 2012-05-15 00:39419488----a-w-c:\windows\system32\FlashPlayerApp.exe
2012-05-15 00:39 . 2011-05-27 10:5070304----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-11 14:42 . 2004-06-04 22:2643520----a-w-c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2004-06-04 22:251469440----a-w-c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2004-08-04 05:59385024----a-w-c:\windows\system32\html.iec
2008-02-28 05:30 . 2008-02-28 05:302293848----a-w-c:\program files\FLV PlayerFCSetup.exe
2008-02-28 05:19 . 2008-02-28 05:193955352----a-w-c:\program files\FLV PlayerRCATSetup.exe
2008-02-28 05:18 . 2008-02-28 05:18411248----a-w-c:\program files\FLV PlayerRCSetup.exe
2007-03-09 08:1227648--sha-w-c:\windows\system32\AVSredirect.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-06-28 12:51121528----a-w-c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CuteReminder"="c:\program files\CuteReminder\CuteReminder.exe" [2004-10-28 807424]
"BackupNotify"="c:\program files\HP\Digital Imaging\bin\backupnotify.exe" [2004-01-09 32768]
"Akamai NetSession Interface"="c:\documents and settings\Owner\Local Settings\Application Data\Akamai\netsession_win.exe" [2012-05-26 4327744]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-04-21 118784]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPHUPD05"="c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 49152]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-08-21 483328]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 101136]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 101136]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-10-19 4355576]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2009-10-19 960640]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-10-19 377320]
"Iomega Startup Options"="c:\program files\Iomega\Common\ImgStart.exe" [2000-06-02 32768]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2000-06-13 36864]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 57344]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-02-24 3026944]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-07 421160]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2011-03-18 1043968]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-19 421888]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2003-12-18 118784]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"nwiz"="nwiz.exe" [2004-02-24 753664]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\Owner\Start Menu\Programs\Startup\
HP Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [2004-5-12 36864]
IMStart.lnk - c:\program files\InterMute\IMStart.exe [2004-5-12 57344]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Reminder.lnk - c:\program files\PrintMaster 16\pmremind.exe [2004-1-20 339968]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-9-16 237568]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-8-11 688128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Quicken Scheduled Updates.lnk - c:\program files\Quicken\bagent.exe [2003-7-30 57344]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecuteREG_MULTI_SZ autocheck autochk *\0Partizan
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]
2009-06-05 11:38468408----a-w-c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150600.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MySql"=2 (0x2)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"AlcxMonitor"=ALCXMNTR.EXE
"MsgCenterExe"="c:\program files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\WS_FTP Pro\\wsftppro.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Owner\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
R0 tdrpman251;Acronis Try&Decide and Restore Points filter (build 251);c:\windows\system32\drivers\tdrpm251.sys [2/16/2010 8:52 PM 902432]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [7/3/2011 8:11 AM 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [12/13/2010 6:29 PM 353688]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [6/4/2004 5:49 PM 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/13/2010 6:29 PM 21256]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [7/8/2012 1:28 PM 655944]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [7/8/2012 1:28 PM 22344]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/1/2011 11:55 PM 136176]
S2 mrtRate;mrtRate; [x]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/1/2011 11:55 PM 136176]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [6/4/2004 5:49 PM 14336]
S3 RegGuard;RegGuard;c:\windows\system32\drivers\regguard.sys [7/23/2012 9:24 AM 24416]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ASWMBR
*NewlyCreated* - TRUESIGHT
*Deregistered* - aswMBR
*Deregistered* - TrueSight
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelperREG_MULTI_SZ nosGetPlusHelper
AkamaiREG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-02 03:54]
.
2012-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-02 03:54]
.
2012-08-03 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.google.com/finance?q=ntwk
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
IE: Add To HP Organize... - c:\progra~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 167.206.245.129 167.206.245.130
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\e3o27581.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.com/webhp?complete=1&hl=...ient=firefox-a&rls=org.mozilla:en-US:official
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: CLC-4-TTS: {7529D455-3392-4a17-A489-0C737D1DBAC0} - %profile%\extensions\{7529D455-3392-4a17-A489-0C737D1DBAC0}
FF - Ext: CLC-Utilities: {C12D2FDC-2ECA-42a5-BA3C-DB93E0E8B70A} - %profile%\extensions\{C12D2FDC-2ECA-42a5-BA3C-DB93E0E8B70A}
FF - Ext: CLC-CLiCkSpeak: {D1517460-5F8F-11DB-B0DE-0800200CA666} - %profile%\extensions\{D1517460-5F8F-11DB-B0DE-0800200CA666}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: avast! WebRep:
wrc@avast.com - c:\program files\Alwil Software\Avast5\WebRep\FF
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-08-03 21:18
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_4f7fccd.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
Completion time: 2012-08-03 21:27:55
ComboFix-quarantined-files.txt 2012-08-04 01:27
ComboFix2.txt 2012-08-03 04:59
.
Pre-Run: 95,815,979,008 bytes free
Post-Run: 95,797,727,232 bytes free
.
- - End Of File - - C3E30BFB4A04DD8415EEBDAA7903F419