All done!
ComboFix 12-03-22.01 - Robert Moulton 03/25/2012 18:20:29.2.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.724 [GMT -5:00]
Running from: c:\documents and settings\Robert Moulton\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\~WOhO5XNhVoOkVe
c:\documents and settings\All Users\Application Data\~WOhO5XNhVoOkVer
c:\documents and settings\All Users\Application Data\WOhO5XNhVoOkVe
c:\documents and settings\Robert Moulton\Application Data\inst.exe
c:\documents and settings\Robert Moulton\Start Menu\Programs\System Check\System Check.lnk
c:\documents and settings\Robert Moulton\Start Menu\Programs\System Check\Uninstall System Check.lnk
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\EventSystem.log
c:\windows\kb913800.exe
c:\windows\SwSys1.bmp
c:\windows\SwSys2.bmp
c:\windows\system32\ctfmon(2).exe
c:\windows\system32\dxmjwtkj.ini
c:\windows\system32\pldyfgmm.ini
c:\windows\system32\qqtwa.bak1
c:\windows\system32\qqtwa.bak2
c:\windows\system32\qqtwa.tmp
c:\windows\system32\windrv.sys
c:\windows\system32\ylqprtms.ini
c:\windows\system32\yudecppu.ini
C:\xcrashdump.dat
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SYSTEM
-------\Service_usnjsvc
.
.
((((((((((((((((((((((((( Files Created from 2012-02-25 to 2012-03-25 )))))))))))))))))))))))))))))))
.
.
2012-03-25 22:44 . 2012-03-25 22:44 -------- d-----w- C:\avast! sandbox
2012-03-25 22:42 . 2012-03-25 22:42 -------- d-----w- c:\windows\LastGood
2012-03-24 00:24 . 2012-03-24 00:24 -------- d-----w- c:\program files\GUM16.tmp
2012-03-24 00:24 . 2012-03-24 00:24 3993600 ----a-w- c:\program files\GUT17.tmp
2012-03-23 23:34 . 2012-03-23 23:34 -------- d-sh--w- c:\documents and settings\NetworkService.NT AUTHORITY
2012-03-22 02:50 . 2012-03-22 02:50 592824 ----a-w- c:\program files\Mozilla Firefox\gkmedias.dll
2012-03-22 02:50 . 2012-03-22 02:50 44472 ----a-w- c:\program files\Mozilla Firefox\mozglue.dll
2012-03-19 22:44 . 2012-02-23 15:12 337112 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-03-19 22:44 . 2012-02-23 15:10 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-03-19 22:44 . 2012-02-23 15:10 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-03-19 22:44 . 2012-02-23 15:12 610648 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-19 22:44 . 2012-02-23 15:10 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-03-19 22:44 . 2012-02-23 15:10 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-03-19 22:44 . 2012-02-23 15:10 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-03-19 22:44 . 2012-02-23 15:07 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-03-19 22:43 . 2012-02-23 15:23 41184 ----a-w- c:\windows\avastSS.scr
2012-03-19 22:43 . 2012-02-23 15:23 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-03-19 22:43 . 2012-03-19 22:43 -------- d-----w- c:\program files\AVAST Software
2012-03-19 22:43 . 2012-03-19 22:43 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-03-03 21:08 . 2012-03-03 21:08 -------- d-----w- c:\documents and settings\Robert Moulton\Application Data\GRETECH
2012-03-03 21:06 . 2012-03-03 21:06 -------- d-----w- c:\program files\GRETECH
2012-02-25 23:33 . 2012-03-22 02:50 19384 ----a-w- c:\program files\Mozilla Firefox\AccessibleMarshal.dll
2012-02-25 23:33 . 2012-03-22 02:50 97208 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2012-02-25 23:33 . 2012-03-22 02:50 125880 ----a-w- c:\program files\Mozilla Firefox\crashreporter.exe
2012-02-25 23:33 . 2012-02-25 23:33 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-24 22:39 . 2011-07-21 21:54 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2012-03-22 02:50 . 2012-02-25 23:33 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-06-29 22:34 . 2008-10-09 21:36 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{96b985b7-3cf9-456a-9db6-791710e60f5f}"= "c:\program files\MyPoints Toolbar 2.0\Helper.dll" [2009-10-25 242688]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn2\yt.dll" [2012-01-12 1517368]
.
[HKEY_CLASSES_ROOT\clsid\{96b985b7-3cf9-456a-9db6-791710e60f5f}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{9FEBEA6D-4801-4D23-97E7-A771B698E442}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-C1EA-F165BB85A330}]
2007-10-14 22:55 1909248 ----a-w- c:\progra~1\mypoints\mypoints.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{614BDA1F-9BEF-4CD1-BDE4-FA4804929B4A}]
2009-10-25 01:48 1432576 ----a-w- c:\program files\MyPoints Toolbar 2.0\Toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-08-24 02:20 1515688 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4E7BD74F-2B8D-469E-C1EA-F165BB85A330}"= "c:\progra~1\mypoints\mypoints.dll" [2007-10-14 1909248]
"{89A2510A-B4B6-4683-BEC9-1B96700BC7F1}"= "c:\program files\MyPoints Toolbar 2.0\Toolbar.dll" [2009-10-25 1432576]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-24 1515688]
.
[HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-c1ea-f165bb85a330}]
[HKEY_CLASSES_ROOT\mypoints.MYPOINTS]
.
[HKEY_CLASSES_ROOT\clsid\{89a2510a-b4b6-4683-bec9-1b96700bc7f1}]
[HKEY_CLASSES_ROOT\FCTB000060497.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{061ED138-E065-4356-82AA-578F7F1EEAF1}]
[HKEY_CLASSES_ROOT\FCTB000060497.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{4E7BD74F-2B8D-469E-C1EA-F165BB85A330}"= "c:\progra~1\mypoints\mypoints.dll" [2007-10-14 1909248]
"{89A2510A-B4B6-4683-BEC9-1B96700BC7F1}"= "c:\program files\MyPoints Toolbar 2.0\Toolbar.dll" [2009-10-25 1432576]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-24 1515688]
.
[HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-c1ea-f165bb85a330}]
[HKEY_CLASSES_ROOT\mypoints.MYPOINTS]
.
[HKEY_CLASSES_ROOT\clsid\{89a2510a-b4b6-4683-bec9-1b96700bc7f1}]
[HKEY_CLASSES_ROOT\FCTB000060497.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{061ED138-E065-4356-82AA-578F7F1EEAF1}]
[HKEY_CLASSES_ROOT\FCTB000060497.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-02-23 15:23 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="c:\program files\AWS\WeatherBug\Weather.exe" [2007-08-29 1347584]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-09 7110656]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2006-05-03 98304]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-20 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-29 30192]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-20 213936]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"NoteBurner"="c:\program files\NoteBurner\VTBurnerGUI.exe" [BU]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"CTHelper"="CTHELPER.EXE" [2006-12-12 19456]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-03-02 18944]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-07-13 1312384]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-08-24 887976]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-02-23 4031368]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-26 282624]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SetDefaultMIDI"="MIDIDEF.EXE" [2005-11-08 25600]
.
c:\documents and settings\Robert Moulton\Start Menu\Programs\Startup\
Scheduler.lnk - c:\program files\SpyCatcher\Scheduler daemon.exe [2007-7-20 86133]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-6-10 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-7-5 24576]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
SpyCatcher Protector.lnk - c:\program files\SpyCatcher\Protector.exe [2007-7-20 91576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\e4ff1b2b548]
[BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2007-08-14 00:11 24576 ----a-w- c:\program files\Stardock\MyColors\fastload.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
backup=c:\windows\pss\NkbMonitor.exe.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpyCatcher Protector.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SpyCatcher Protector.lnk
backup=c:\windows\pss\SpyCatcher Protector.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Robert Moulton^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\documents and settings\Robert Moulton\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 10:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTCheck]
2007-11-06 16:08 397312 ------w- c:\program files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
c:\program files\DAEMON Tools Lite\daemon.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\doubleTwist]
2010-03-16 00:15 24576 ----a-w- c:\program files\doubleTwist 2.0\DoubleTwist.DeviceHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-10-26 00:58 282624 ----a-w- c:\program files\QuickTime\qttask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyCatcher Reminder]
2007-07-09 15:56 103864 ----a-w- c:\program files\SpyCatcher\SpyCatcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2011-05-31 22:28 273544 ----a-w- c:\program files\Real\RealPlayer\Update\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\System\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{65BD8956-3DDB-41D2-BE0F-E377D64DF6B1}\Connection]
"PnpInstanceID"="PCI\\VEN_8086&DEV_109A&SUBSYS_01D11028&REV_01\\4&22443A69&0&00E5"
"MediaSubType"=dword:00000001
"Name"="Local Area Connection 3"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth (tm) II\\game.dat"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe"=
"c:\\Program Files\\Firefly Studios\\Stronghold 2\\Stronghold2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War Forces of Corruption\\swfoc.exe"=
"c:\\Program Files\\Electronic Arts\\The Lord of the Rings, The Rise of the Witch-king\\game.dat"=
"c:\\Program Files\\EA GAMES\\The Battle for Middle-earth (tm)\\game.dat"=
"c:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"c:\\Program Files\\Microsoft Games\\Rise of Nations\\thrones.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\MyPoints Toolbar 2.0\\TroubleShooter.exe"=
"c:\\Program Files\\MyPoints Toolbar 2.0\\ToolbarUpdate.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\RelicDownloader\\RelicDownloader.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\Mimo.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"%windir%\explorer.exe"= %windir%\explorer.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\SOFTWARE\McAfee\MSC\Cache\ProviderInfo\Menu\MSC\8D6E2B44-4004-488d-A7A6-8B5CB377EE81\00]
"MenuItemID"= 9C8324D3-5625-4b5a-BA48-F9CF9A3D33DC
"ActionURL"= misp://mcshlui.dll::config.htm
"Display"= SecurityCenter
"Level"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\SOFTWARE\McAfee\MSC\Cache\ProviderInfo\Menu\MSC\B55C9DFB-9CA9-4024-92CA-4050C02FB287\03]
"MenuItemID"= 941B5D48-6CA4-47c3-AB9F-70B2FBA86921
"ActionURL"= misp://mcshlui.dll::RecentEvents.htm
"Display"= View Recent Events
"Level"= 1 (0x1)
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/6/2009 7:33 PM 717296]
R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [9/8/2006 5:53 PM 120320]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys --> c:\windows\system32\DRIVERS\ntcdrdrv.sys [?]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [3/19/2012 5:44 PM 610648]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3/19/2012 5:44 PM 337112]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3/19/2012 5:44 PM 20696]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/11/2009 6:54 PM 133104]
S2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [3/9/2010 11:00 PM 6656]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2/2/2011 9:18 AM 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2/2/2011 9:18 AM 8456]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [7/5/2006 11:31 PM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/11/2009 6:54 PM 133104]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 7:49 AM 227232]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [8/16/2005 4:18 AM 14336]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [2/19/2008 5:24 PM 47360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 09:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-11 23:53]
.
2012-03-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-11 23:53]
.
2012-03-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1103233014-2229641168-2263940352-1005Core.job
- c:\documents and settings\Robert Moulton\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-02-27 23:13]
.
2012-03-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1103233014-2229641168-2263940352-1005UA.job
- c:\documents and settings\Robert Moulton\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-02-27 23:13]
.
2012-03-25 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2011-08-24 02:20]
.
2012-03-17 c:\windows\Tasks\Spybot - Search & Destroy.job
- c:\progra~1\SPYBOT~1\SpybotSD.exe [2008-06-08 20:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*
http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*
http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
FF - ProfilePath - c:\documents and settings\Robert Moulton\Application Data\Mozilla\Firefox\Profiles\pt8x6cw0.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo Search
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{A057A204-BACC-4D26-CEC4-75A487FD6484} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-03-25 18:39
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1103233014-2229641168-2263940352-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:2c,b6,55,7a,36,1f,64,82,fc,bc,cf,19,34,0a,8e,35,11,cb,a6,59,26,a2,81,
c3,13,07,37,e5,94,52,43,b0,59,c0,8b,ad,ac,f4,ad,78,ab,ed,7b,bd,5d,a4,1d,d6,\
"??"=hex:9b,21,3f,42,d4,3b,e3,c0,58,f3,2b,de,63,eb,3e,f2
.
[HKEY_USERS\S-1-5-21-1103233014-2229641168-2263940352-1005\Software\SecuROM\License information*]
"datasecu"=hex:64,ca,f5,1e,60,17,4c,0f,3d,01,32,a1,4c,de,7c,d2,bc,15,44,74,ed,
fd,8d,e5,e5,08,15,2f,da,ee,3c,ae,38,3e,62,c6,a4,d4,c2,5b,0f,73,ec,10,53,47,\
"rkeysecu"=hex:0c,01,85,43,d9,94,1a,d5,71,29,87,48,26,17,d9,45
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(684)
c:\program files\Stardock\MyColors\fastload.dll
c:\windows\system32\l3codeca.acm
.
Completion time: 2012-03-25 18:47:54
ComboFix-quarantined-files.txt 2012-03-25 23:47
.
Pre-Run: 23,855,771,648 bytes free
Post-Run: 23,821,524,992 bytes free
.
- - End Of File - - C6EF183E1EF52268053B7B0A2DF1A607