I erased the 3 things frm hijackthis, heres the log what are u seeing so far? I still havent removed bitcommt..cant find it
ComboFix 10-12-18.02 - KA 12/20/2010 0:36.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1270.786 [GMT -5:00]
Running from: c:\documents and settings\KA\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\KA\Desktop\CFScript.txt.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\KA\Application Data\PriceGong
c:\documents and settings\KA\Application Data\PriceGong\Data\1.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\a.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\b.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\c.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\d.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\e.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\f.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\g.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\h.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\i.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\J.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\k.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\l.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\m.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\n.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\o.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\p.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\q.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\r.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\s.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\t.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\u.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\v.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\w.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\x.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\y.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\z.xml
.
((((((((((((((((((((((((( Files Created from 2010-11-20 to 2010-12-20 )))))))))))))))))))))))))))))))
.
2010-12-16 17:42 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2010-12-16 06:32 . 2010-12-17 04:14 -------- d-----w- C:\HijackThis
2010-12-16 06:28 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-15 00:37 . 2010-12-15 00:40 -------- d-----w- c:\documents and settings\KA\Local Settings\Application Data\uTorrentBar
2010-12-13 20:06 . 2010-12-13 20:06 -------- d-----w- c:\program files\Common Files\Java
2010-12-13 20:06 . 2010-11-12 23:53 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-13 20:06 . 2010-11-12 23:53 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2010-12-09 00:48 . 2010-12-09 00:48 -------- d-----w- c:\program files\ESET
2010-12-07 12:49 . 2010-11-03 19:08 237568 ----a-w- c:\windows\system32\yv12vfw.dll
2010-12-07 12:49 . 2010-01-17 16:18 151552 ----a-w- c:\windows\system32\ac3acm.acm
2010-12-07 12:49 . 2008-09-24 19:41 839680 ----a-w- c:\windows\system32\lameACM.acm
2010-12-07 12:49 . 2010-11-24 08:00 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-12-07 12:49 . 2010-06-08 17:10 790528 ----a-w- c:\windows\system32\xvidcore.dll
2010-12-07 12:49 . 2010-06-08 17:10 134144 ----a-w- c:\windows\system32\xvidvfw.dll
2010-12-05 18:33 . 2009-08-07 00:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-12-05 18:33 . 2009-08-07 00:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-12-05 03:34 . 2010-12-05 03:34 -------- d-----w- c:\program files\Microsoft Silverlight
2010-12-03 05:05 . 2009-01-30 22:13 58208 ----a-w- c:\windows\system32\drivers\wsimd.sys
2010-12-01 11:56 . 2010-12-01 11:56 -------- d-----w- c:\documents and settings\KA\Local Settings\Application Data\Sunbelt Software
2010-11-30 02:13 . 2010-03-15 10:31 165376 ----a-w- c:\windows\system32\unrar.dll
2010-11-30 02:13 . 2010-12-07 12:50 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-11-29 07:22 . 2010-11-30 07:47 -------- d-----w- c:\program files\Real
2010-11-26 22:26 . 2010-11-26 22:26 -------- d-----w- c:\program files\MPEGTOWAV
2010-11-26 05:50 . 2010-12-17 04:11 -------- d-----w- c:\documents and settings\KA\Local Settings\Application Data\Conduit
2010-11-26 05:47 . 2010-11-26 05:47 -------- d-----w- c:\documents and settings\All Users~
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-02 02:50 . 2010-03-27 13:22 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-11-29 22:42 . 2009-11-19 08:27 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-29 22:42 . 2009-11-19 08:27 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-18 18:12 . 2009-04-19 22:43 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-12 21:34 . 2009-06-22 16:41 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-05 05:05 . 2004-08-04 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2010-11-05 05:05 . 2004-08-04 12:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2010-11-05 05:05 . 2009-08-16 02:48 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-11-03 12:59 . 2004-08-04 12:00 369664 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-04 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2004-08-04 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2004-08-04 12:00 1853312 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-12-10_02.54.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-12-19 21:36 . 2010-12-19 21:36 16384 c:\windows\temp\Perflib_Perfdata_5cc.dat
- 2008-10-22 09:47 . 2010-06-21 14:46 46080 c:\windows\system32\tzchange.exe
+ 2008-10-22 09:47 . 2010-11-03 13:12 46080 c:\windows\system32\tzchange.exe
- 2004-08-04 12:00 . 2010-12-10 00:41 67714 c:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2010-12-17 04:57 67714 c:\windows\system32\perfc009.dat
+ 2010-11-18 18:12 . 2010-11-18 18:12 81920 c:\windows\system32\dllcache\isign32.dll
- 2009-08-16 02:48 . 2010-09-09 14:16 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2009-08-16 02:48 . 2010-11-05 05:05 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 629760 c:\windows\system32\urlmon.dll
+ 2004-08-04 12:00 . 2010-12-17 04:57 432924 c:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2010-12-10 00:41 432924 c:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2008-04-14 00:12 532480 c:\windows\system32\mstime.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 532480 c:\windows\system32\mstime.dll
- 2004-08-04 12:00 . 2010-09-09 14:16 449024 c:\windows\system32\mshtmled.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 449024 c:\windows\system32\mshtmled.dll
+ 2010-12-19 04:43 . 2010-11-12 23:53 157472 c:\windows\system32\javaws.exe
+ 2010-12-19 04:43 . 2010-11-12 23:53 145184 c:\windows\system32\javaw.exe
+ 2010-12-19 04:43 . 2010-11-12 23:53 145184 c:\windows\system32\java.exe
+ 2004-08-04 12:00 . 2010-11-05 05:05 251904 c:\windows\system32\iepeers.dll
- 2004-08-04 12:00 . 2010-09-09 14:16 251904 c:\windows\system32\iepeers.dll
- 2009-04-19 18:31 . 2010-10-22 21:29 131688 c:\windows\system32\FNTCACHE.DAT
+ 2009-04-19 18:31 . 2010-12-16 17:39 131688 c:\windows\system32\FNTCACHE.DAT
+ 2009-02-20 08:10 . 2010-11-05 05:05 667136 c:\windows\system32\dllcache\wininet.dll
- 2009-02-20 08:10 . 2010-09-09 14:16 667136 c:\windows\system32\dllcache\wininet.dll
+ 2009-02-20 08:10 . 2010-11-05 05:05 629760 c:\windows\system32\dllcache\urlmon.dll
+ 2010-11-05 05:05 . 2010-11-05 05:05 532480 c:\windows\system32\dllcache\mstime.dll
+ 2010-09-09 14:16 . 2010-11-05 05:05 449024 c:\windows\system32\dllcache\mshtmled.dll
- 2010-09-09 14:16 . 2010-09-09 14:16 449024 c:\windows\system32\dllcache\mshtmled.dll
- 2010-09-09 14:16 . 2010-09-09 14:16 251904 c:\windows\system32\dllcache\iepeers.dll
+ 2010-09-09 14:16 . 2010-11-05 05:05 251904 c:\windows\system32\dllcache\iepeers.dll
+ 2010-04-20 05:30 . 2010-10-28 13:13 290048 c:\windows\system32\dllcache\atmfd.dll
+ 2010-12-13 20:06 . 2010-12-13 20:06 180224 c:\windows\Installer\88d9f0.msi
+ 2010-09-22 23:10 . 2010-09-22 23:10 103864 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\nppdf32.dll
- 2004-08-04 12:00 . 2010-09-09 14:16 1510400 c:\windows\system32\shdocvw.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 1510400 c:\windows\system32\shdocvw.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 3076096 c:\windows\system32\mshtml.dll
+ 2009-02-09 11:13 . 2010-10-26 13:25 1853312 c:\windows\system32\dllcache\win32k.sys
+ 2009-03-02 23:04 . 2010-11-05 05:05 1510400 c:\windows\system32\dllcache\shdocvw.dll
- 2009-03-02 23:04 . 2010-09-09 14:16 1510400 c:\windows\system32\dllcache\shdocvw.dll
+ 2009-02-20 08:11 . 2010-11-05 05:05 3076096 c:\windows\system32\dllcache\mshtml.dll
- 2010-09-09 14:16 . 2010-09-09 14:16 1025024 c:\windows\system32\dllcache\browseui.dll
+ 2010-09-09 14:16 . 2010-11-05 05:05 1025024 c:\windows\system32\dllcache\browseui.dll
- 2004-08-04 12:00 . 2010-09-09 14:16 1025024 c:\windows\system32\browseui.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 1025024 c:\windows\system32\browseui.dll
+ 2010-11-08 07:14 . 2010-11-08 07:14 3402752 c:\windows\Installer\6cdda2.msp
+ 2010-09-16 08:08 . 2010-09-16 08:08 6210560 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\authplay.dll
+ 2009-04-22 13:31 . 2010-12-16 08:00 37366216 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-06-26 1311312]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WNA1100 Smart Wizard.lnk - c:\program files\NETGEAR\WNA1100\WNA1100.exe [2010-12-3 4562944]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-01-29 21:17 64592 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-05-30 16:30 292136 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\aol\\1264685876\\ee\\aolsoftware.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13227:TCP"= 13227:TCP:BitComet 13227 TCP
"13227:UDP"= 13227:UDP:BitComet 13227 UDP
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [10/29/2009 8:36 PM 28552]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [1/26/2010 6:26 PM 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/26/2010 6:26 PM 17744]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [8/12/2010 4:11 AM 10448]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [6/20/2009 6:38 PM 88176]
R2 WSWNA1100;WSWNA1100;c:\program files\NETGEAR\WNA1100\WifiSvc.exe [12/3/2010 12:04 AM 278528]
R3 AR9271;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [12/3/2010 12:04 AM 1710944]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [12/3/2010 12:04 AM 57440]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/17/2010 11:44 PM 136176]
S3 jswpsapi;JumpStart Wi-Fi Protected Setup;c:\program files\NETGEAR\WNA1100\jswpsapi.exe [12/3/2010 12:04 AM 360529]
.
Contents of the 'Scheduled Tasks' folder
2010-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-18 04:44]
2010-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-18 04:44]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://espn.go.com/nfl/
uInternet Connection Wizard,ShellNext = iexplore
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
Trusted Zone: intuit.com\ttlc
FF - ProfilePath - c:\documents and settings\KA\Application Data\Mozilla\Firefox\Profiles\ostsccu7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=100000000000000002&tb_oid=01-05-2010&tb_mrud=01-05-2010
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.netflix.com/WiHome?lnkctr=mhWN
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbarsearch.com/?prt=pinballtb02ff&Keywords=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files\McAfee\SiteAdvisor
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - user.js: keyword.URL - hxxp://mp3tubetoolbarsearch.com/?prt=pinballtb02ff&Keywords=
FF - user.js: keyword.enabled - 1
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-20 00:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1092)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\windows\system32\athgina.dll
.
Completion time: 2010-12-20 00:45:54
ComboFix-quarantined-files.txt 2010-12-20 05:45
ComboFix2.txt 2010-12-13 20:34
ComboFix3.txt 2010-12-10 02:57
Pre-Run: 22,318,411,776 bytes free
Post-Run: 22,343,516,160 bytes free
- - End Of File - - 035979AA1DA9F4C02AA0F0AB8F3A0E50
ComboFix 10-12-18.02 - KA 12/20/2010 0:36.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1270.786 [GMT -5:00]
Running from: c:\documents and settings\KA\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\KA\Desktop\CFScript.txt.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\KA\Application Data\PriceGong
c:\documents and settings\KA\Application Data\PriceGong\Data\1.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\a.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\b.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\c.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\d.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\e.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\f.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\g.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\h.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\i.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\J.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\k.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\l.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\m.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\n.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\o.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\p.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\q.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\r.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\s.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\t.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\u.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\v.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\w.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\x.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\y.xml
c:\documents and settings\KA\Application Data\PriceGong\Data\z.xml
.
((((((((((((((((((((((((( Files Created from 2010-11-20 to 2010-12-20 )))))))))))))))))))))))))))))))
.
2010-12-16 17:42 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2010-12-16 06:32 . 2010-12-17 04:14 -------- d-----w- C:\HijackThis
2010-12-16 06:28 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-15 00:37 . 2010-12-15 00:40 -------- d-----w- c:\documents and settings\KA\Local Settings\Application Data\uTorrentBar
2010-12-13 20:06 . 2010-12-13 20:06 -------- d-----w- c:\program files\Common Files\Java
2010-12-13 20:06 . 2010-11-12 23:53 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-13 20:06 . 2010-11-12 23:53 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2010-12-09 00:48 . 2010-12-09 00:48 -------- d-----w- c:\program files\ESET
2010-12-07 12:49 . 2010-11-03 19:08 237568 ----a-w- c:\windows\system32\yv12vfw.dll
2010-12-07 12:49 . 2010-01-17 16:18 151552 ----a-w- c:\windows\system32\ac3acm.acm
2010-12-07 12:49 . 2008-09-24 19:41 839680 ----a-w- c:\windows\system32\lameACM.acm
2010-12-07 12:49 . 2010-11-24 08:00 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-12-07 12:49 . 2010-06-08 17:10 790528 ----a-w- c:\windows\system32\xvidcore.dll
2010-12-07 12:49 . 2010-06-08 17:10 134144 ----a-w- c:\windows\system32\xvidvfw.dll
2010-12-05 18:33 . 2009-08-07 00:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-12-05 18:33 . 2009-08-07 00:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-12-05 03:34 . 2010-12-05 03:34 -------- d-----w- c:\program files\Microsoft Silverlight
2010-12-03 05:05 . 2009-01-30 22:13 58208 ----a-w- c:\windows\system32\drivers\wsimd.sys
2010-12-01 11:56 . 2010-12-01 11:56 -------- d-----w- c:\documents and settings\KA\Local Settings\Application Data\Sunbelt Software
2010-11-30 02:13 . 2010-03-15 10:31 165376 ----a-w- c:\windows\system32\unrar.dll
2010-11-30 02:13 . 2010-12-07 12:50 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-11-29 07:22 . 2010-11-30 07:47 -------- d-----w- c:\program files\Real
2010-11-26 22:26 . 2010-11-26 22:26 -------- d-----w- c:\program files\MPEGTOWAV
2010-11-26 05:50 . 2010-12-17 04:11 -------- d-----w- c:\documents and settings\KA\Local Settings\Application Data\Conduit
2010-11-26 05:47 . 2010-11-26 05:47 -------- d-----w- c:\documents and settings\All Users~
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-02 02:50 . 2010-03-27 13:22 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-11-29 22:42 . 2009-11-19 08:27 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-29 22:42 . 2009-11-19 08:27 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-18 18:12 . 2009-04-19 22:43 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-12 21:34 . 2009-06-22 16:41 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-05 05:05 . 2004-08-04 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2010-11-05 05:05 . 2004-08-04 12:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2010-11-05 05:05 . 2009-08-16 02:48 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-11-03 12:59 . 2004-08-04 12:00 369664 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-04 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2004-08-04 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2004-08-04 12:00 1853312 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-12-10_02.54.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-12-19 21:36 . 2010-12-19 21:36 16384 c:\windows\temp\Perflib_Perfdata_5cc.dat
- 2008-10-22 09:47 . 2010-06-21 14:46 46080 c:\windows\system32\tzchange.exe
+ 2008-10-22 09:47 . 2010-11-03 13:12 46080 c:\windows\system32\tzchange.exe
- 2004-08-04 12:00 . 2010-12-10 00:41 67714 c:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2010-12-17 04:57 67714 c:\windows\system32\perfc009.dat
+ 2010-11-18 18:12 . 2010-11-18 18:12 81920 c:\windows\system32\dllcache\isign32.dll
- 2009-08-16 02:48 . 2010-09-09 14:16 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2009-08-16 02:48 . 2010-11-05 05:05 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 629760 c:\windows\system32\urlmon.dll
+ 2004-08-04 12:00 . 2010-12-17 04:57 432924 c:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2010-12-10 00:41 432924 c:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2008-04-14 00:12 532480 c:\windows\system32\mstime.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 532480 c:\windows\system32\mstime.dll
- 2004-08-04 12:00 . 2010-09-09 14:16 449024 c:\windows\system32\mshtmled.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 449024 c:\windows\system32\mshtmled.dll
+ 2010-12-19 04:43 . 2010-11-12 23:53 157472 c:\windows\system32\javaws.exe
+ 2010-12-19 04:43 . 2010-11-12 23:53 145184 c:\windows\system32\javaw.exe
+ 2010-12-19 04:43 . 2010-11-12 23:53 145184 c:\windows\system32\java.exe
+ 2004-08-04 12:00 . 2010-11-05 05:05 251904 c:\windows\system32\iepeers.dll
- 2004-08-04 12:00 . 2010-09-09 14:16 251904 c:\windows\system32\iepeers.dll
- 2009-04-19 18:31 . 2010-10-22 21:29 131688 c:\windows\system32\FNTCACHE.DAT
+ 2009-04-19 18:31 . 2010-12-16 17:39 131688 c:\windows\system32\FNTCACHE.DAT
+ 2009-02-20 08:10 . 2010-11-05 05:05 667136 c:\windows\system32\dllcache\wininet.dll
- 2009-02-20 08:10 . 2010-09-09 14:16 667136 c:\windows\system32\dllcache\wininet.dll
+ 2009-02-20 08:10 . 2010-11-05 05:05 629760 c:\windows\system32\dllcache\urlmon.dll
+ 2010-11-05 05:05 . 2010-11-05 05:05 532480 c:\windows\system32\dllcache\mstime.dll
+ 2010-09-09 14:16 . 2010-11-05 05:05 449024 c:\windows\system32\dllcache\mshtmled.dll
- 2010-09-09 14:16 . 2010-09-09 14:16 449024 c:\windows\system32\dllcache\mshtmled.dll
- 2010-09-09 14:16 . 2010-09-09 14:16 251904 c:\windows\system32\dllcache\iepeers.dll
+ 2010-09-09 14:16 . 2010-11-05 05:05 251904 c:\windows\system32\dllcache\iepeers.dll
+ 2010-04-20 05:30 . 2010-10-28 13:13 290048 c:\windows\system32\dllcache\atmfd.dll
+ 2010-12-13 20:06 . 2010-12-13 20:06 180224 c:\windows\Installer\88d9f0.msi
+ 2010-09-22 23:10 . 2010-09-22 23:10 103864 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\nppdf32.dll
- 2004-08-04 12:00 . 2010-09-09 14:16 1510400 c:\windows\system32\shdocvw.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 1510400 c:\windows\system32\shdocvw.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 3076096 c:\windows\system32\mshtml.dll
+ 2009-02-09 11:13 . 2010-10-26 13:25 1853312 c:\windows\system32\dllcache\win32k.sys
+ 2009-03-02 23:04 . 2010-11-05 05:05 1510400 c:\windows\system32\dllcache\shdocvw.dll
- 2009-03-02 23:04 . 2010-09-09 14:16 1510400 c:\windows\system32\dllcache\shdocvw.dll
+ 2009-02-20 08:11 . 2010-11-05 05:05 3076096 c:\windows\system32\dllcache\mshtml.dll
- 2010-09-09 14:16 . 2010-09-09 14:16 1025024 c:\windows\system32\dllcache\browseui.dll
+ 2010-09-09 14:16 . 2010-11-05 05:05 1025024 c:\windows\system32\dllcache\browseui.dll
- 2004-08-04 12:00 . 2010-09-09 14:16 1025024 c:\windows\system32\browseui.dll
+ 2004-08-04 12:00 . 2010-11-05 05:05 1025024 c:\windows\system32\browseui.dll
+ 2010-11-08 07:14 . 2010-11-08 07:14 3402752 c:\windows\Installer\6cdda2.msp
+ 2010-09-16 08:08 . 2010-09-16 08:08 6210560 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0400000010\9.4.0\authplay.dll
+ 2009-04-22 13:31 . 2010-12-16 08:00 37366216 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-06-26 1311312]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WNA1100 Smart Wizard.lnk - c:\program files\NETGEAR\WNA1100\WNA1100.exe [2010-12-3 4562944]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-01-29 21:17 64592 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-05-30 16:30 292136 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\aol\\1264685876\\ee\\aolsoftware.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13227:TCP"= 13227:TCP:BitComet 13227 TCP
"13227:UDP"= 13227:UDP:BitComet 13227 UDP
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [10/29/2009 8:36 PM 28552]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [1/26/2010 6:26 PM 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/26/2010 6:26 PM 17744]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [8/12/2010 4:11 AM 10448]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [6/20/2009 6:38 PM 88176]
R2 WSWNA1100;WSWNA1100;c:\program files\NETGEAR\WNA1100\WifiSvc.exe [12/3/2010 12:04 AM 278528]
R3 AR9271;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [12/3/2010 12:04 AM 1710944]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [12/3/2010 12:04 AM 57440]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/17/2010 11:44 PM 136176]
S3 jswpsapi;JumpStart Wi-Fi Protected Setup;c:\program files\NETGEAR\WNA1100\jswpsapi.exe [12/3/2010 12:04 AM 360529]
.
Contents of the 'Scheduled Tasks' folder
2010-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-18 04:44]
2010-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-18 04:44]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://espn.go.com/nfl/
uInternet Connection Wizard,ShellNext = iexplore
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
Trusted Zone: intuit.com\ttlc
FF - ProfilePath - c:\documents and settings\KA\Application Data\Mozilla\Firefox\Profiles\ostsccu7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=100000000000000002&tb_oid=01-05-2010&tb_mrud=01-05-2010
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.netflix.com/WiHome?lnkctr=mhWN
FF - prefs.js: keyword.URL - hxxp://mp3tubetoolbarsearch.com/?prt=pinballtb02ff&Keywords=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files\McAfee\SiteAdvisor
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - user.js: keyword.URL - hxxp://mp3tubetoolbarsearch.com/?prt=pinballtb02ff&Keywords=
FF - user.js: keyword.enabled - 1
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-20 00:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1092)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\windows\system32\athgina.dll
.
Completion time: 2010-12-20 00:45:54
ComboFix-quarantined-files.txt 2010-12-20 05:45
ComboFix2.txt 2010-12-13 20:34
ComboFix3.txt 2010-12-10 02:57
Pre-Run: 22,318,411,776 bytes free
Post-Run: 22,343,516,160 bytes free
- - End Of File - - 035979AA1DA9F4C02AA0F0AB8F3A0E50