ComboFix 10-11-10.02 - user 11/11/2010 17:18:18.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.274 [GMT -8:00]
Running from: c:\documents and settings\user\My Documents\ComboFix.exe
Command switches used :: c:\documents and settings\user\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}"
"c:\program files\viewpoint\viewpoint media player\npViewpoint.dll"
"c:\windows\ltumps.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\$AVG
c:\$avg\$VAULT\V_00000001.fil
c:\$avg\$VAULT\V_00000002.fil
c:\$avg\$VAULT\vvfolder.idx
c:\docume~1\alluse~1\applic~1\AVG10
c:\docume~1\alluse~1\applic~1\AVG10\Chjw\be4cddeb4cdd9f09\avgcchff.dat
c:\docume~1\alluse~1\applic~1\AVG10\Chjw\be4cddeb4cdd9f09\avgcchfi.dat
c:\docume~1\alluse~1\applic~1\AVG10\Chjw\be4cddeb4cdd9f09\avgcchmf.dat
c:\docume~1\alluse~1\applic~1\AVG10\Chjw\be4cddeb4cdd9f09\avgcchmi.dat
c:\docume~1\alluse~1\applic~1\AVG10\Chjw\be4cddeb4cdd9f09\f0f34b4b-0deb-4e34-8467-d853ef48293c
c:\docume~1\alluse~1\applic~1\AVG10\Chjw\be4cddeb4cdd9f09\f6511b71-4c04-4322-a377-0749eec8584e
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcfg.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcfg.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcfgex.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcfgex.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgchjw.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgchjw.log.1
c:\docume~1\alluse~1\applic~1\AVG10\log\avgchjw.log.2
c:\docume~1\alluse~1\applic~1\AVG10\log\avgchjw.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgchjwsrv.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgchjwsrv.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcore.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcore.log.1
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcore.log.2
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcore.log.3
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcore.log.4
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcore.log.5
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcore.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcsl.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcsl.log.1
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcsl.log.2
c:\docume~1\alluse~1\applic~1\AVG10\log\avgcsl.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgemc.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgemc.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgexc.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgexc.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgldr.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgldr.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avglng.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avglng.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgns.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgns.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgpostinst.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgpostinst.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgrs.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgrs.log.1
c:\docume~1\alluse~1\applic~1\AVG10\log\avgrs.log.10
c:\docume~1\alluse~1\applic~1\AVG10\log\avgrs.log.2
c:\docume~1\alluse~1\applic~1\AVG10\log\avgrs.log.3
c:\docume~1\alluse~1\applic~1\AVG10\log\avgrs.log.4
c:\docume~1\alluse~1\applic~1\AVG10\log\avgrs.log.5
c:\docume~1\alluse~1\applic~1\AVG10\log\avgrs.log.6
c:\docume~1\alluse~1\applic~1\AVG10\log\avgrs.log.7
c:\docume~1\alluse~1\applic~1\AVG10\log\avgrs.log.8
c:\docume~1\alluse~1\applic~1\AVG10\log\avgrs.log.9
c:\docume~1\alluse~1\applic~1\AVG10\log\avgrs.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgscan.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgscan.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsched.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsched.log.1
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsched.log.2
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsched.log.3
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsched.log.4
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsched.log.5
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsched.log.6
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsched.log.7
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsched.log.8
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsched.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsrm.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsrm.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsrmac.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgsrmac.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgtdi.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgtdi.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgual.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgual.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgui.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgui.log.1
c:\docume~1\alluse~1\applic~1\AVG10\log\avgui.log.10
c:\docume~1\alluse~1\applic~1\AVG10\log\avgui.log.2
c:\docume~1\alluse~1\applic~1\AVG10\log\avgui.log.3
c:\docume~1\alluse~1\applic~1\AVG10\log\avgui.log.4
c:\docume~1\alluse~1\applic~1\AVG10\log\avgui.log.5
c:\docume~1\alluse~1\applic~1\AVG10\log\avgui.log.6
c:\docume~1\alluse~1\applic~1\AVG10\log\avgui.log.7
c:\docume~1\alluse~1\applic~1\AVG10\log\avgui.log.8
c:\docume~1\alluse~1\applic~1\AVG10\log\avgui.log.9
c:\docume~1\alluse~1\applic~1\AVG10\log\avgui.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgupd.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgupd.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwd.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwd.log.1
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwd.log.10
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwd.log.2
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwd.log.3
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwd.log.4
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwd.log.5
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwd.log.6
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwd.log.7
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwd.log.8
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwd.log.9
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwd.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwdsvc.log
c:\docume~1\alluse~1\applic~1\AVG10\log\avgwdsvc.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\avgxobniinstaller.log
c:\docume~1\alluse~1\applic~1\AVG10\log\commonpriv.log
c:\docume~1\alluse~1\applic~1\AVG10\log\commonpriv.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\fixcfg.log
c:\docume~1\alluse~1\applic~1\AVG10\log\fixcfg.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\log\history.xml
c:\docume~1\alluse~1\applic~1\AVG10\log\vault.log
c:\docume~1\alluse~1\applic~1\AVG10\log\vault.log.lock
c:\docume~1\alluse~1\applic~1\AVG10\lsdb\prev\prvcache.dat
c:\docume~1\alluse~1\applic~1\AVG10\lsdb\prev\prvglbl.dat
c:\docume~1\alluse~1\applic~1\AVG10\scanlogs\I_00000001.log
c:\docume~1\alluse~1\applic~1\AVG10\scanlogs\I_00000004.log
c:\docume~1\alluse~1\applic~1\AVG10\scanlogs\I_00000008.log
c:\docume~1\alluse~1\applic~1\AVG10\scanlogs\I_00000009.log
c:\docume~1\alluse~1\applic~1\AVG10\scanlogs\I_00000010.log
c:\docume~1\alluse~1\applic~1\AVG10\scanlogs\I_00000011.log
c:\docume~1\alluse~1\applic~1\AVG10\scanlogs\srm.idx
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\AntiRkx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\Antivirx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\Avgx86.msi
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\AVIsx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\basex.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\COREx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\COREx86.msi
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\Emailsx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\GUIx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\idatx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\IDPx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\lng_usx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\OnlnScx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\ResShldx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\SrchSrfx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\SSHttpBx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\TDIDrvx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\TuneUpx.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\Update2x.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\Updatex.cab
c:\docume~1\alluse~1\applic~1\AVG10\SetupBackup\xplx.cab
c:\docume~1\alluse~1\applic~1\Common Files
c:\docume~1\alluse~1\applic~1\Common Files\B00E8F0D-DF1B-30AE-E08F-1A98DCE6CE0F.dat
c:\docume~1\user\applic~1\AVG10
c:\docume~1\user\applic~1\AVG10\cfgall\usergui.cfg
c:\program files\AVG
c:\program files\AVG\AVG10\avgfree_zh.mht
c:\program files\AVG\AVG10\avgfree_zt.mht
c:\program files\AVG\AVG10\Notification\avgxobni_installerxTE.exe
c:\program files\AVG\AVG10\Notification\XobniMiniAVGSetup.exe
c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MNMNUXXG
-------\Service_Mnmnuxxg
((((((((((((((((((((((((( Files Created from 2010-10-12 to 2010-11-12 )))))))))))))))))))))))))))))))
.
2010-11-11 19:42 . 2010-11-11 19:42 -------- d-----w- C:\_OTM
2010-11-10 12:35 . 2010-11-10 12:35 -------- d-----w- c:\program files\ESET
2010-11-09 07:27 . 2010-11-09 07:27 -------- d-----w- c:\documents and settings\user\Application Data\Avira
2010-11-09 07:00 . 2010-08-03 00:10 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-11-09 07:00 . 2010-08-03 00:10 126856 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-11-09 07:00 . 2010-06-17 23:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-11-09 07:00 . 2010-06-17 23:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-11-09 07:00 . 2010-11-09 07:00 -------- d-----w- c:\program files\Avira
2010-11-09 07:00 . 2010-11-09 07:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-11-05 05:37 . 2010-11-05 05:46 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2010-10-30 17:52 . 2010-10-30 17:52 -------- d-----w- c:\program files\iPod
2010-10-30 17:52 . 2010-10-30 17:53 -------- d-----w- c:\program files\iTunes
2010-10-30 17:39 . 2010-10-30 17:39 -------- d-----w- c:\program files\Bonjour
2010-10-16 17:09 . 2010-10-23 09:15 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-10-13 08:09 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-13 08:09 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-13 08:08 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-10-13 06:57 . 2010-10-13 06:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-10-13 06:57 . 2010-10-13 06:57 -------- d-----w- c:\program files\Alwil Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 19:23 . 2003-03-31 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2003-03-31 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2003-03-31 12:00 954368 ------w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2003-03-31 12:00 953856 ------w- c:\windows\system32\mfc40u.dll
2010-09-09 13:38 . 2004-08-24 03:32 832512 ----a-w- c:\windows\system32\wininet.dll
2010-09-09 13:38 . 2003-03-31 12:00 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-09 13:38 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-09-09 13:38 . 2003-03-31 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-09-08 18:17 . 2010-09-08 18:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 18:17 . 2010-09-08 18:17 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-09-08 15:57 . 2004-08-04 05:59 389120 ----a-w- c:\windows\system32\html.iec
2010-09-01 11:51 . 2003-03-31 12:00 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2003-03-31 12:00 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2003-03-31 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2003-03-31 12:00 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2003-03-31 12:00 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-04-15 20:36 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2003-03-31 12:00 617472 ------w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2003-03-31 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2004-12-04 00:35 590848 ----a-w- c:\windows\system32\rpcrt4.dll
.
------- Sigcheck -------
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ERDNT\cache\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[7] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
c:\windows\explorer.exe ... is missing !!
.
((((((((((((((((((((((((((((( SnapShot@2010-11-11_19.33.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-12 01:02 . 2010-11-12 01:02 16384 c:\windows\Temp\Perflib_Perfdata_210.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-23 68856]
"Steam"="c:\program files\Steam\Steam.exe" [2010-09-11 1242448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"t`~y?:MBVhfk?{)c:\program files\ISTsvc\istsvc.exe"="c:\windows\ltumps.exe" [?]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2003-03-31 455168]
"PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2003-03-31 455168]
"VTTimer"="VTTimer.exe" [2004-10-22 53248]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 88209]
"Motive SmartBridge"="c:\progra~1\VERIZO~1\SMARTB~1\MotiveSB.exe" [2004-12-08 385024]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-08 136600]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-03 281768]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\SteamApps\\ymditd\\counter-strike source\\hl2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"5869:TCP"= 5869:TCP:Services
"5870:TCP"= 5870:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
"9212:TCP"= 9212:TCP:Services
"9211:TCP"= 9211:TCP:Services
"6820:TCP"= 6820:TCP:Services
"6821:TCP"= 6821:TCP:Services
"4210:TCP"= 4210:TCP:Services
"6920:TCP"= 6920:TCP:Services
"8831:TCP"= 8831:TCP:Services
"8832:TCP"= 8832:TCP:Services
"3345:TCP"= 3345:TCP:Services
"5190:TCP"= 5190:TCP:Services
"6515:TCP"= 6515:TCP:Services
"6516:TCP"= 6516:TCP:Services
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [11/8/2010 11:00 PM 135336]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/1/2010 3:48 AM 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-10-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2010-11-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-01 11:48]
2010-11-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-01 11:48]
2010-11-12 c:\windows\Tasks\System Restore.job
- c:\windows\system32\Restore\rstrui.exe [2004-10-10 00:12]
2010-11-12 c:\windows\Tasks\Volume Control.job
- c:\windows\system32\sndvol32.exe [2004-10-10 12:00]
2010-11-12 c:\windows\Tasks\Windows Update.job
- c:\windows\system32\wupdmgr.exe [2003-03-31 12:00]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: &eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: ShaPlus Google Translator - c:\program files\ShaPlus Google Translator\GoogleTranslator.dll/HTML/IE
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\9218o7z1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
FF - component: c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\9218o7z1.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\user\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\user\Application Data\Move Networks\plugins\npqmp071505000011.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-c:\windows\ltumps.exe - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-11-11 17:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"\" ??DnR???OV?c:\\Program Files\\ISTsvc\\istsvc.exe"="c:\\WINDOWS\\ltumps.exe"
.
Completion time: 2010-11-11 17:31:06
ComboFix-quarantined-files.txt 2010-11-12 01:31
ComboFix2.txt 2010-11-11 19:37
ComboFix3.txt 2010-04-05 22:56
Pre-Run: 87,588,888,576 bytes free
Post-Run: 87,571,976,192 bytes free
- - End Of File - - 0682113A31ACE08F0CE91FEA06784389