ComboFix 10-10-09.03 - Roger 10/09/2010 21:01:43.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2835 [GMT -5:00]
Running from: c:\documents and settings\Roger\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Roger\Application Data\PriceGong
c:\documents and settings\Roger\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Roger\Application Data\PriceGong\Data\z.xml
c:\windows\system32\Cache
.
((((((((((((((((((((((((( Files Created from 2010-09-10 to 2010-10-10 )))))))))))))))))))))))))))))))
.
2010-10-09 15:03 . 2010-10-09 15:03 -------- d-----w- c:\documents and settings\Roger\Application Data\Malwarebytes
2010-10-09 15:03 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-09 15:03 . 2010-10-09 15:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-10-09 15:03 . 2010-10-09 16:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-09 15:03 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-01 18:08 . 2010-10-01 18:08 -------- d-sh--w- c:\documents and settings\NetworkService\PrivacIE
2010-10-01 18:08 . 2010-10-01 18:08 -------- d-sh--w- c:\documents and settings\NetworkService\IECompatCache
2010-10-01 15:20 . 2010-10-01 15:20 -------- d-----w- c:\documents and settings\All Users\Application Data\AT&T
2010-09-30 04:45 . 2010-09-30 05:18 -------- d-----w- c:\documents and settings\Roger\Application Data\DivX
2010-09-30 04:45 . 2010-09-30 04:45 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-09-30 04:44 . 2010-09-30 04:46 -------- d-----w- c:\program files\DivX
2010-09-30 04:43 . 2010-09-30 04:46 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-09-30 02:38 . 2010-09-30 02:38 -------- d-----w- c:\program files\Cosmi
2010-09-30 02:37 . 2010-09-30 02:37 -------- d-----w- c:\program files\NZCSM
2010-09-29 22:46 . 2010-09-29 22:46 -------- d-----w- c:\documents and settings\Roger\Application Data\ElevatedDiagnostics
2010-09-16 22:06 . 2010-10-01 15:21 -------- d-----w- c:\documents and settings\Roger\Local Settings\Application Data\Conduit
2010-09-16 22:06 . 2010-09-16 22:06 -------- d-----w- c:\documents and settings\Roger\Local Settings\Application Data\Temp
2010-09-16 22:05 . 2010-09-16 22:05 2468688 ----a-w- c:\documents and settings\Free_TV_Bar_c3.exe
2010-09-15 23:17 . 2010-09-15 23:17 -------- d-----w- c:\documents and settings\Roger\Application Data\Leadertech
2010-09-15 23:17 . 2010-09-15 23:17 53248 ----a-r- c:\documents and settings\Roger\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-09-15 23:17 . 2010-09-15 23:17 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-09-15 23:16 . 2010-03-18 09:01 10448 ----a-w- c:\windows\system32\drivers\LBeepKE.sys
2010-09-15 23:16 . 2010-09-15 23:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Logishrd
2010-09-15 23:16 . 2010-09-15 23:16 -------- d-----w- c:\program files\Logitech
2010-09-15 23:15 . 2010-09-15 23:17 -------- d-----w- c:\program files\Common Files\LogiShrd
2010-09-15 23:15 . 2010-09-15 23:17 -------- d-----w- c:\documents and settings\Roger\Application Data\Logitech
2010-09-15 23:15 . 2010-09-15 23:15 -------- d-----w- c:\documents and settings\Roger\Application Data\Logishrd
2010-09-15 23:10 . 2008-04-13 23:11 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2010-09-15 23:10 . 2008-04-13 23:11 21504 ----a-w- c:\windows\system32\hidserv.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2008-02-22 1245184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-22 13594624]
"nwiz"="nwiz.exe" [2008-11-22 1657376]
"NVHotkey"="nvHotkey.dll" [2008-11-22 90112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-22 86016]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2009-10-07 2498560]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 52840]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-10-08 125368]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-06-26 1311312]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
c:\documents and settings\Roger\Start Menu\Programs\Startup\
Logitech . Product Registration.lnk - c:\program files\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-05-06 09:29 64592 ----a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [12/19/2006 3:21 PM 79432]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [9/15/2010 6:16 PM 10448]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/10/2010 8:51 AM 102448]
S2 Cache_c-_intersystems_cache;Caché Controller for CACHEWEB;c:\intersystems\Cache\bin\cservice.exe [12/22/2009 5:12 PM 20992]
S2 WinkZink Service;WinkZink Service;c:\documents and settings\All Users\Application Data\WinkZink\winkzink131.exe [9/9/2010 12:55 AM 57608]
S3 CACHEWEBhttpd;Web Server for CACHEWEB;c:\intersystems\Cache\httpd\bin\httpd.exe -k runservice --> c:\intersystems\Cache\httpd\bin\httpd.exe -k runservice [?]
S3 EraserUtilDrvI3;EraserUtilDrvI3;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI3.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI3.sys [?]
S3 EraserUtilDrvI9;EraserUtilDrvI9;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI9.sys [?]
S3 I97DRIVER;I97DRIVER;\??\d:\qa+win32\dgs.sys --> d:\qa+win32\dgs.sys [?]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [10/7/2007 9:48 PM 116664]
S3 SWNC8U56;Sierra Wireless MUX NDIS Driver (UMTS56);c:\windows\system32\drivers\swnc8u56.sys [6/27/2007 11:41 AM 101248]
S3 SWUMX56;Sierra Wireless USB MUX Driver (UMTS56);c:\windows\system32\drivers\swumx56.sys [6/27/2007 11:42 AM 73856]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/4/2004 5:00 AM 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
.
.
------- File Associations -------
.
vbefile\shell\open2\command=%SystemRoot%\System32\CScript.exe "%1" %*
vbsfile\shell\open2\command=%SystemRoot%\System32\CScript.exe "%1" %*
jsefile\shell\open2\command=%SystemRoot%\System32\CScript.exe "%1" %*
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Weather - c:\program files\AWS\WeatherBug\Weather.exe
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(660)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
.
Completion time: 2010-10-09 21:05:32
ComboFix-quarantined-files.txt 2010-10-10 02:05
Pre-Run: 111,108,059,136 bytes free
Post-Run: 111,079,690,240 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 39FA953D91B323C6C423F37DEEFD3800