ComboFix 10-09-24.03 - 252468 09/24/2010 18:10:43.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3003.1744 [GMT -5:00]
Running from: c:\users\252468\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Search Settings
c:\program files\Search Settings\kb128\SeARchsettings.dll
c:\program files\Search Settings\kb128\SearchSettingsRes409.dll
c:\program files\Search Settings\SearchSettings.exe
c:\users\252468\g2mdlhlpx.exe
.
((((((((((((((((((((((((( Files Created from 2010-08-24 to 2010-09-24 )))))))))))))))))))))))))))))))
.
2010-09-24 23:08 . 2010-09-24 23:09 -------- d-----w- C:\32788R22FWJFW
2010-09-24 03:09 . 2010-09-24 03:09 -------- d-----w- c:\users\252468\AppData\Roaming\Malwarebytes
2010-09-24 03:09 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-24 03:09 . 2010-09-24 03:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-24 03:09 . 2010-09-24 03:09 -------- d-----w- c:\programdata\Malwarebytes
2010-09-24 03:09 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-24 01:37 . 2010-09-24 01:37 -------- d-----w- c:\program files\ESET
2010-09-23 16:59 . 2010-09-23 16:59 1377632 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-09-23 16:59 . 2010-09-23 16:59 942432 ----a-w- c:\programdata\avg9\update\backup\avgcfgx.dll
2010-09-23 16:59 . 2010-09-23 16:59 598368 ----a-w- c:\programdata\avg9\update\backup\avgsrmx.dll
2010-09-23 16:59 . 2010-09-23 16:59 4371296 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-09-23 16:59 . 2010-09-23 16:59 300896 ----a-w- c:\programdata\avg9\update\backup\avgchclx.dll
2010-09-23 16:58 . 2010-09-23 16:58 1690952 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2010-09-20 14:56 . 2010-09-20 14:56 -------- d-----w- c:\users\252468\New folder
2010-09-15 16:29 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-02 00:01 . 2010-09-02 00:01 -------- d-----w- c:\program files\Common Files\Adobe
2010-09-01 14:22 . 2010-09-01 14:22 -------- d-----w- c:\users\252468\AppData\Roaming\DVDVideoSoftIEHelpers
2010-09-01 14:22 . 2010-09-01 14:22 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2010-09-01 14:22 . 2010-09-01 14:22 -------- d-----w- c:\program files\DVDVideoSoft
2010-08-29 20:44 . 2009-10-05 14:31 1221632 ----a-w- c:\windows\system32\drivers\athr.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-20 15:08 . 2009-04-22 15:14 -------- d-----w- c:\program files\Java
2010-09-20 15:08 . 2009-04-22 15:14 -------- d-----w- c:\program files\Common Files\Java
2010-09-20 15:07 . 2010-07-19 21:09 -------- d-----w- c:\users\252468\AppData\Roaming\IrfanView
2010-09-17 00:41 . 2010-08-18 00:35 -------- d-----w- c:\program files\Dl_cats
2010-09-15 21:52 . 2009-04-22 14:57 -------- d-----w- c:\programdata\Microsoft Help
2010-09-03 12:41 . 2009-04-22 15:13 -------- d-----w- c:\program files\Microsoft Silverlight
2010-08-29 20:44 . 2009-06-01 18:45 -------- d-----w- c:\program files\Atheros
2010-08-18 19:16 . 2010-08-18 19:16 -------- d-----w- c:\program files\BitZipper
2010-08-18 19:16 . 2010-08-18 19:16 -------- d-----w- c:\users\252468\AppData\Roaming\BitZipper
2010-08-18 00:35 . 2010-08-18 00:35 -------- d-----w- c:\program files\Dell AIO Printer 946
2010-08-11 23:06 . 2009-04-22 14:45 -------- d-----w- c:\program files\Microsoft Works
2010-08-11 22:02 . 2010-08-11 22:02 -------- d-----w- c:\users\Guest\AppData\Roaming\Apple Computer
2010-08-04 22:53 . 2010-08-04 22:53 -------- d-----w- c:\program files\Veoh Networks
2010-07-31 01:49 . 2010-07-31 01:24 -------- d-----w- c:\users\252468\AppData\Roaming\vlc
2010-07-31 01:24 . 2010-07-31 01:24 -------- d-----w- c:\program files\VideoLAN
2010-07-29 06:30 . 2010-08-11 16:22 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-11 16:22 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-18 22:37 . 2010-07-18 22:37 56 ---ha-w- c:\programdata\ezsidmv.dat
2010-07-16 22:18 . 2010-07-16 22:18 98304 ----a-w- c:\programdata\WebEx\WebEx\500\webexrcd\atplayim.dll
2010-07-16 22:18 . 2010-07-16 22:18 5702 ----a-w- c:\programdata\WebEx\WebEx\500\atkbctl.dll
2010-07-16 22:18 . 2010-07-16 22:18 24576 ----a-w- c:\programdata\WebEx\WebEx\500\atmemmgr.dll
2010-07-15 20:25 . 2009-10-12 00:27 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-15 20:25 . 2010-07-15 20:25 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-15 20:24 . 2009-10-12 00:27 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-30 06:25 . 2010-08-11 16:22 978432 ----a-w- c:\windows\system32\wininet.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 144384]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"Speech Recognition"="c:\windows\Speech\Common\sapisvr.exe" [2009-07-14 51712]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2010-07-06 2634048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-24 468264]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2008-11-15 218408]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-07 210216]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-15 2065760]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"DLCICATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCItime.dll" [2006-10-20 73728]
"dlcimon.exe"="c:\program files\Dell AIO Printer 946\dlcimon.exe" [2007-01-12 435696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
c:\users\252468\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ScreenHunter 5.1 Free.lnk - c:\program files\Wisdom-soft ScreenHunter 5 Free\ScreenHunter.exe [2009-12-26 5689344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 PAC207;Webcam 1200;c:\windows\system32\DRIVERS\PFC027.SYS [2007-06-29 611584]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-02 1343400]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-15 216400]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-07-15 243024]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-20 921952]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-15 308136]
S2 dlci_device;dlci_device;c:\windows\system32\dlcicoms.exe [2006-12-08 537480]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-10-06 365952]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-06-29 112128]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
Contents of the 'Scheduled Tasks' folder
2010-09-05 c:\windows\Tasks\HPCeeScheduleFor252468.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2009-04-22 18:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube to Mp3 Converter - c:\users\252468\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
DPF: {36299202-09EF-4ABF-ADB9-47C599DBE778} - hxxps://www.hpwindows7upgrade.arvato.com/north_america/Endcustomer/HPProdDetect.cab
FF - ProfilePath - c:\users\252468\AppData\Roaming\Mozilla\Firefox\Profiles\kl5qu4jw.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=616163&p=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\users\252468\AppData\Roaming\Mozilla\plugins\npatgpc.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKLM-Run-SearchSettings - c:\program files\Search Settings\SearchSettings.exe
AddRemove-Adobe Acrobat Connect Add-in - c:\users\252468\AppData\Roaming\Macromedia\Flash Player\
www.macromedia.com\bin\connectaddin\connectaddin.exe
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-09-24 18:18:14
ComboFix-quarantined-files.txt 2010-09-24 23:18
Pre-Run: 228,556,029,952 bytes free
Post-Run: 228,461,342,720 bytes free
- - End Of File - - EEE95533AA227E63FA5F64FEB0F60A89