ComboFix 12-08-15.02 - Randy 08/16/2012 8:31.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.982.387 [GMT -7:00]
Running from: c:\documents and settings\Randy\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Randy\Desktop\WinXP_EN_PRO_BF.EXE
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\TPAPSLOG.LOG
c:\windows\system32\TPHDLOG0.LOG
.
.
((((((((((((((((((((((((( Files Created from 2012-07-16 to 2012-08-16 )))))))))))))))))))))))))))))))
.
.
2012-08-16 15:24 . 2012-08-16 15:24 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{00059AC7-1425-48E9-8AD6-FFB9A6F50661}\offreg.dll
2012-08-16 10:38 . 2012-08-16 10:38 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{00059AC7-1425-48E9-8AD6-FFB9A6F50661}\MpKsl36329d1b.sys
2012-08-15 19:15 . 2012-08-15 19:15 -------- d-----w- c:\documents and settings\Randy\Application Data\Malwarebytes
2012-08-15 19:15 . 2012-08-15 19:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-08-15 19:15 . 2012-08-15 19:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-15 19:15 . 2012-07-03 20:46 22344 ------w- c:\windows\system32\drivers\mbam.sys
2012-08-15 15:07 . 2012-06-29 08:44 6891424 ------w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{00059AC7-1425-48E9-8AD6-FFB9A6F50661}\mpengine.dll
2012-08-13 23:20 . 2012-06-29 08:44 6891424 ------w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-20 20:37 . 2012-07-20 20:37 -------- d-----w- c:\documents and settings\All Users\Application Data\ClubSanDisk
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-14 23:44 . 2012-05-06 00:01 426184 ------w- c:\windows\system32\FlashPlayerApp.exe
2012-08-14 23:44 . 2011-08-14 01:15 70344 ------w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2006-04-30 06:55 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2006-04-30 06:55 139784 ------w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40 . 2006-04-30 06:55 1866112 ------w- c:\windows\system32\win32k.sys
2012-07-02 17:49 . 2006-04-30 06:56 916992 ----a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49 . 2006-04-30 06:55 43520 ------w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2006-04-30 06:55 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2006-04-30 06:55 385024 ------w- c:\windows\system32\html.iec
2012-06-07 03:59 . 2012-06-07 03:59 1070152 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-06-05 15:50 . 2007-05-15 23:43 1372672 ------w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2006-04-30 06:55 1172480 ------w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2006-04-30 06:55 152576 ------w- c:\windows\system32\schannel.dll
2012-06-02 22:19 . 2007-07-31 03:18 22040 ------w- c:\windows\system32\wucltui.dll.mui
2012-06-02 22:19 . 2007-07-31 03:19 15384 ------w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 22:19 . 2006-04-30 07:11 329240 ------w- c:\windows\system32\wucltui.dll
2012-06-02 22:19 . 2006-04-30 07:11 210968 ------w- c:\windows\system32\wuweb.dll
2012-06-02 22:19 . 2006-04-30 07:11 219160 ------w- c:\windows\system32\wuaucpl.cpl
2012-06-02 22:19 . 2007-07-31 03:19 45080 ------w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2007-07-31 03:19 15384 ------w- c:\windows\system32\wuapi.dll.mui
2012-06-02 22:19 . 2006-04-30 07:11 53784 ------w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2006-04-30 07:11 35864 ------w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2006-04-30 06:55 97304 ------w- c:\windows\system32\cdm.dll
2012-06-02 22:19 . 2007-07-31 03:18 17944 ------w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 22:19 . 2006-04-30 07:11 577048 ------w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2006-04-30 07:11 1933848 ------w- c:\windows\system32\wuaueng.dll
2012-06-02 22:18 . 2008-01-02 03:48 275696 ------w- c:\windows\system32\mucltui.dll
2012-06-02 22:18 . 2008-01-02 03:48 214256 ------w- c:\windows\system32\muweb.dll
2012-06-02 22:18 . 2008-01-02 03:48 17136 ------w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2006-04-30 06:55 599040 ------w- c:\windows\system32\crypt32.dll
.
.
(((((((((((((((((((((((((((((
SnapShot@2012-08-16_04.25.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-16 10:38 . 2012-08-16 10:38 16384 c:\windows\Temp\Perflib_Perfdata_38c.dat
+ 2006-04-30 06:55 . 2012-07-02 17:49 67072 c:\windows\system32\mshtmled.dll
- 2006-04-30 06:55 . 2012-05-11 14:42 67072 c:\windows\system32\mshtmled.dll
- 2006-11-08 05:03 . 2012-05-11 14:42 55296 c:\windows\system32\msfeedsbs.dll
+ 2006-11-08 05:03 . 2012-07-02 17:49 55296 c:\windows\system32\msfeedsbs.dll
+ 2006-04-30 06:55 . 2012-07-02 17:49 25600 c:\windows\system32\jsproxy.dll
- 2006-04-30 06:55 . 2012-05-11 14:42 25600 c:\windows\system32\jsproxy.dll
- 2009-06-21 17:37 . 2012-05-11 14:42 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2009-06-21 17:37 . 2012-07-02 17:49 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2006-11-08 05:03 . 2012-07-02 17:49 67072 c:\windows\system32\dllcache\mshtmled.dll
- 2006-11-08 05:03 . 2012-05-11 14:42 67072 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-10-10 23:55 . 2012-07-02 17:49 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2007-10-10 23:55 . 2012-05-11 14:42 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2006-10-17 20:05 . 2012-07-02 17:49 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2006-10-17 20:05 . 2012-05-11 14:42 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2006-11-08 05:03 . 2012-05-11 14:42 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-11-08 05:03 . 2012-07-02 17:49 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2012-07-06 13:58 . 2012-07-06 13:58 78336 c:\windows\system32\dllcache\browser.dll
- 2011-11-17 23:01 . 2012-07-13 20:09 35088 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
+ 2011-11-17 23:01 . 2012-08-16 10:17 35088 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
- 2011-11-17 23:01 . 2012-07-13 20:09 18704 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
+ 2011-11-17 23:01 . 2012-08-16 10:17 18704 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
+ 2011-11-17 23:01 . 2012-08-16 10:17 20240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
- 2011-11-17 23:01 . 2012-07-13 20:09 20240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
+ 2012-08-16 10:02 . 2012-05-11 14:42 12800 c:\windows\ie8updates\KB2722913-IE8\xpshims.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 67072 c:\windows\ie8updates\KB2722913-IE8\mshtmled.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 55296 c:\windows\ie8updates\KB2722913-IE8\msfeedsbs.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 43520 c:\windows\ie8updates\KB2722913-IE8\licmgr10.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 25600 c:\windows\ie8updates\KB2722913-IE8\jsproxy.dll
+ 2006-04-30 06:56 . 2012-07-02 17:49 105984 c:\windows\system32\url.dll
- 2006-04-30 06:56 . 2012-05-11 14:42 105984 c:\windows\system32\url.dll
- 2006-04-30 06:55 . 2012-05-11 14:42 206848 c:\windows\system32\occache.dll
+ 2006-04-30 06:55 . 2012-07-02 17:49 206848 c:\windows\system32\occache.dll
+ 2006-04-30 06:55 . 2012-07-06 13:58 337920 c:\windows\system32\netapi32.dll
- 2006-04-30 06:55 . 2012-05-11 14:42 611840 c:\windows\system32\mstime.dll
+ 2006-04-30 06:55 . 2012-07-02 17:49 611840 c:\windows\system32\mstime.dll
- 2006-11-08 05:03 . 2012-05-11 14:42 629760 c:\windows\system32\msfeeds.dll
+ 2006-11-08 05:03 . 2012-07-02 17:49 629760 c:\windows\system32\msfeeds.dll
- 2006-04-30 06:55 . 2009-05-07 15:32 345600 c:\windows\system32\localspl.dll
+ 2006-04-30 06:55 . 2012-05-14 09:22 345600 c:\windows\system32\localspl.dll
- 2006-04-30 06:55 . 2012-05-11 14:42 184320 c:\windows\system32\iepeers.dll
+ 2006-04-30 06:55 . 2012-07-02 17:49 184320 c:\windows\system32\iepeers.dll
- 2006-04-30 06:55 . 2012-05-11 14:42 387584 c:\windows\system32\iedkcs32.dll
+ 2006-04-30 06:55 . 2012-07-02 17:49 387584 c:\windows\system32\iedkcs32.dll
+ 2006-04-30 06:55 . 2012-07-02 12:05 174080 c:\windows\system32\ie4uinit.exe
- 2006-04-30 06:55 . 2012-05-11 11:38 174080 c:\windows\system32\ie4uinit.exe
- 2006-04-30 00:03 . 2012-07-13 20:29 328296 c:\windows\system32\FNTCACHE.DAT
+ 2006-04-30 00:03 . 2012-08-16 10:37 328296 c:\windows\system32\FNTCACHE.DAT
+ 2006-11-08 05:03 . 2012-07-02 17:49 916992 c:\windows\system32\dllcache\wininet.dll
- 2006-11-08 05:03 . 2012-05-16 15:08 916992 c:\windows\system32\dllcache\wininet.dll
+ 2006-10-17 20:05 . 2012-07-02 17:49 105984 c:\windows\system32\dllcache\url.dll
- 2006-10-17 20:05 . 2012-05-11 14:42 105984 c:\windows\system32\dllcache\url.dll
+ 2011-08-11 02:58 . 2012-07-04 14:05 139784 c:\windows\system32\dllcache\rdpwd.sys
+ 2006-10-17 20:04 . 2012-07-02 17:49 206848 c:\windows\system32\dllcache\occache.dll
- 2006-10-17 20:04 . 2012-05-11 14:42 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-10-25 01:16 . 2012-07-06 13:58 337920 c:\windows\system32\dllcache\netapi32.dll
+ 2006-11-08 05:03 . 2012-07-02 17:49 611840 c:\windows\system32\dllcache\mstime.dll
- 2006-11-08 05:03 . 2012-05-11 14:42 611840 c:\windows\system32\dllcache\mstime.dll
- 2007-10-10 23:55 . 2012-05-11 14:42 629760 c:\windows\system32\dllcache\msfeeds.dll
+ 2007-10-10 23:55 . 2012-07-02 17:49 629760 c:\windows\system32\dllcache\msfeeds.dll
- 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll
+ 2009-05-07 15:32 . 2012-05-14 09:22 345600 c:\windows\system32\dllcache\localspl.dll
+ 2012-06-24 20:11 . 2012-07-02 17:49 521728 c:\windows\system32\dllcache\jsdbgui.dll
- 2012-06-24 20:11 . 2012-05-11 14:42 521728 c:\windows\system32\dllcache\jsdbgui.dll
- 2009-06-21 17:37 . 2012-05-11 14:42 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2009-06-21 17:37 . 2012-07-02 17:49 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2006-11-08 05:03 . 2012-07-02 17:49 184320 c:\windows\system32\dllcache\iepeers.dll
- 2006-11-08 05:03 . 2012-05-11 14:42 184320 c:\windows\system32\dllcache\iepeers.dll
- 2010-06-15 21:34 . 2012-05-11 14:42 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2010-06-15 21:34 . 2012-07-02 17:49 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2006-11-07 11:27 . 2012-05-11 14:42 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2006-11-07 11:27 . 2012-07-02 17:49 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2006-11-07 11:26 . 2012-05-11 11:38 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2006-11-07 11:26 . 2012-07-02 12:05 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2012-07-18 22:46 . 2012-07-18 22:46 593408 c:\windows\Installer\139cdc5.msp
- 2011-11-17 23:01 . 2012-07-13 20:09 888080 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
+ 2011-11-17 23:01 . 2012-08-16 10:17 888080 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
- 2011-11-17 23:01 . 2012-07-13 20:09 272648 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
+ 2011-11-17 23:01 . 2012-08-16 10:17 272648 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
- 2011-11-17 23:01 . 2012-07-13 20:09 922384 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
+ 2011-11-17 23:01 . 2012-08-16 10:17 922384 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
+ 2011-11-17 23:01 . 2012-08-16 10:17 845584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
- 2011-11-17 23:01 . 2012-07-13 20:09 845584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
- 2011-11-17 23:01 . 2012-07-13 20:09 217864 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
+ 2011-11-17 23:01 . 2012-08-16 10:17 217864 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
+ 2011-06-23 17:54 . 2011-06-23 17:54 119160 c:\windows\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6612\MSCONV97.DLL
+ 2012-08-16 10:02 . 2012-05-16 15:08 916992 c:\windows\ie8updates\KB2722913-IE8\wininet.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 105984 c:\windows\ie8updates\KB2722913-IE8\url.dll
+ 2012-08-16 10:02 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2722913-IE8\spuninst\updspapi.dll
+ 2012-08-16 10:02 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2722913-IE8\spuninst\spuninst.exe
+ 2012-08-16 10:02 . 2012-05-11 14:42 206848 c:\windows\ie8updates\KB2722913-IE8\occache.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 611840 c:\windows\ie8updates\KB2722913-IE8\mstime.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 629760 c:\windows\ie8updates\KB2722913-IE8\msfeeds.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 521728 c:\windows\ie8updates\KB2722913-IE8\jsdbgui.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 247808 c:\windows\ie8updates\KB2722913-IE8\ieproxy.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 184320 c:\windows\ie8updates\KB2722913-IE8\iepeers.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 743424 c:\windows\ie8updates\KB2722913-IE8\iedvtool.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 387584 c:\windows\ie8updates\KB2722913-IE8\iedkcs32.dll
+ 2012-08-16 10:02 . 2012-05-11 11:38 174080 c:\windows\ie8updates\KB2722913-IE8\ie4uinit.exe
+ 2006-04-30 06:56 . 2012-07-02 17:49 1212416 c:\windows\system32\urlmon.dll
- 2006-04-30 06:56 . 2012-05-11 14:42 1212416 c:\windows\system32\urlmon.dll
+ 2006-04-30 06:55 . 2012-07-02 17:49 6008320 c:\windows\system32\mshtml.dll
- 2006-10-17 19:57 . 2012-05-11 14:42 2000384 c:\windows\system32\iertutil.dll
+ 2006-10-17 19:57 . 2012-07-02 17:49 2000384 c:\windows\system32\iertutil.dll
+ 2008-10-15 02:11 . 2012-07-03 13:40 1866112 c:\windows\system32\dllcache\win32k.sys
- 2008-10-15 02:11 . 2012-06-13 13:19 1866112 c:\windows\system32\dllcache\win32k.sys
- 2006-11-08 05:03 . 2012-05-11 14:42 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2006-11-08 05:03 . 2012-07-02 17:49 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2006-11-08 05:03 . 2012-07-02 17:49 6008320 c:\windows\system32\dllcache\mshtml.dll
+ 2007-10-10 23:55 . 2012-07-02 17:49 2000384 c:\windows\system32\dllcache\iertutil.dll
- 2007-10-10 23:55 . 2012-05-11 14:42 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2012-06-27 01:03 . 2012-06-27 01:03 3875840 c:\windows\Installer\146d551.msp
+ 2012-07-18 22:53 . 2012-07-18 22:53 5009920 c:\windows\Installer\139cd9f.msp
+ 2011-11-17 23:01 . 2012-08-16 10:17 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
- 2011-11-17 23:01 . 2012-07-13 20:09 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
+ 2011-11-17 23:01 . 2012-08-16 10:17 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
- 2011-11-17 23:01 . 2012-07-13 20:09 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
+ 2012-08-16 10:02 . 2012-05-11 14:42 1212416 c:\windows\ie8updates\KB2722913-IE8\urlmon.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 6007808 c:\windows\ie8updates\KB2722913-IE8\mshtml.dll
+ 2012-08-16 10:02 . 2012-05-11 14:42 2000384 c:\windows\ie8updates\KB2722913-IE8\iertutil.dll
+ 2007-12-31 04:15 . 2012-08-16 10:07 59884088 c:\windows\system32\MRT.exe
+ 2006-11-08 05:03 . 2012-07-03 06:19 11111424 c:\windows\system32\ieframe.dll
- 2006-11-08 05:03 . 2012-05-12 03:12 11111424 c:\windows\system32\ieframe.dll
+ 2007-10-10 23:55 . 2012-07-03 06:19 11111424 c:\windows\system32\dllcache\ieframe.dll
- 2007-10-10 23:55 . 2012-05-12 03:12 11111424 c:\windows\system32\dllcache\ieframe.dll
+ 2012-07-25 23:59 . 2012-07-25 23:59 11032064 c:\windows\Installer\139cdd8.msp
+ 2012-07-18 22:53 . 2012-07-18 22:53 10937344 c:\windows\Installer\139cdb2.msp
+ 2011-08-04 03:53 . 2011-08-04 03:53 17324928 c:\windows\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6612\MSO.DLL
+ 2012-08-16 10:02 . 2012-05-12 03:12 11111424 c:\windows\ie8updates\KB2722913-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn3\yt.dll" [2012-06-11 1524056]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{8660E5B3-6C41-44DE-8503-98D99BBECD41}"= "c:\program files\Coupons.com CouponBar\tbcore3.dll" [2012-02-06 2664864]
.
[HKEY_CLASSES_ROOT\clsid\{8660e5b3-6c41-44de-8503-98d99bbecd41}]
[HKEY_CLASSES_ROOT\TBSB07898.TBSB07898.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB07898.TBSB07898]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{8660E5B3-6C41-44DE-8503-98D99BBECD41}"= "c:\program files\Coupons.com CouponBar\tbcore3.dll" [2012-02-06 2664864]
.
[HKEY_CLASSES_ROOT\clsid\{8660e5b3-6c41-44de-8503-98d99bbecd41}]
[HKEY_CLASSES_ROOT\TBSB07898.TBSB07898.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB07898.TBSB07898]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-05-29 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2007-04-09 58416]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-07 137752]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-07 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-07 162328]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"TpShocks"="TpShocks.exe" [2007-09-28 181544]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2007-03-09 66176]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2007-07-05 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-05 512000]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-04-09 1015808]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2007-09-05 200704]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-28 81920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-12-06 196608]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-03-28 243248]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
"BYR_AGENT"="c:\documents and settings\All Users\Application Data\LGMOBILEAX\BYR_Client\VZWNotiAgent.exe" [2012-03-15 392280]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-27 931200]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\pmremind.exe [2008-1-8 331776]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 07:37 34344 ------w- c:\program files\Lenovo\HOTKEY\notifyf2.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2006-12-14 02:06 28672 ------w- c:\program files\Lenovo\HOTKEY\tphklock.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMSG]
2007-02-01 18:00 419376 ------w- c:\progra~1\THINKV~1\AMSG\Amsg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BLOG]
2007-09-05 16:18 208896 ------w- c:\progra~1\ThinkPad\UTILIT~1\BATLOGEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPManager]
2007-04-26 17:10 120368 ------w- c:\progra~1\THINKV~1\PrdCtr\LPMGR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:0.0.0.0/255.255.255.255:Enabled

HCP Discovery Service
.
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [9/28/2007 5:28 PM 19504]
R1 MpKsl36329d1b;MpKsl36329d1b;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{00059AC7-1425-48E9-8AD6-FFB9A6F50661}\MpKsl36329d1b.sys [8/16/2012 3:38 AM 29904]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/15/2012 12:15 PM 655944]
R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [3/11/2008 9:13 PM 34916]
R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2/8/2007 2:11 PM 569344]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/15/2012 12:15 PM 22344]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [5/22/2007 4:59 PM 30336]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/28/2012 10:27 PM 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [5/5/2012 5:02 PM 250056]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [5/28/2012 10:27 PM 136176]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL36329D1B
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 09:32 128512 ------w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-06 23:44]
.
2012-08-16 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 17:20]
.
2012-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-05-29 05:27]
.
2012-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-05-29 05:27]
.
2012-07-27 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PC-Doctor\uaclauncher.exe [2011-03-31 22:04]
.
2012-08-15 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\PC-Doctor\uaclauncher.exe [2011-03-31 22:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.yahoo.com/?fr=fptb-yie8
mStart Page = hxxp://search.coupons.com/
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
Trusted Zone: iact1.com\www
Trusted Zone: myvoffice.com\
www.doterra
TCP: DhcpNameServer = 192.168.1.5
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-08-16 08:42
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1195841968-921038128-693736591-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1352)
c:\program files\Lenovo\HOTKEY\tphklock.dll
.
Completion time: 2012-08-16 08:46:32
ComboFix-quarantined-files.txt 2012-08-16 15:46
ComboFix2.txt 2012-08-16 04:32
.
Pre-Run: 27,528,601,600 bytes free
Post-Run: 27,504,832,512 bytes free
.
WinXP_EN_PRO_BF.EXE
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 07319D9D7126A93026724731F551FD2E