==========================================================================
COMBO FIX LOG
==========================================================================
ComboFix 11-05-30.07 - Raj 31/05/2011 7:52.1.3 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3582.2328 [GMT 1:00]
Running from: c:\users\Raj\AppData\Local\Temp\9357gxlj.tmp\ComboFix.exe
AV: Kaspersky PURE *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
FW: Kaspersky PURE *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
SP: Kaspersky PURE *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\AutocompletePro
c:\program files\AutocompletePro\64\AutocompletePro64.dll
c:\program files\AutocompletePro\AutocompletePro.dll
c:\program files\AutocompletePro\chrome\autocompleteprochrome.crx
c:\program files\AutocompletePro\FireFoxExtension.exe
c:\program files\AutocompletePro\InstTracker.exe
c:\program files\AutocompletePro\
[email protected]\chrome.manifest
c:\program files\AutocompletePro\
[email protected]\chrome\content\browserOverlay.xul
c:\program files\AutocompletePro\
[email protected]\chrome\content\options.js
c:\program files\AutocompletePro\
[email protected]\chrome\content\options.xul
c:\program files\AutocompletePro\
[email protected]\chrome\content\utils.js
c:\program files\AutocompletePro\
[email protected]\defaults\preferences\predictad.js
c:\program files\AutocompletePro\
[email protected]\install.rdf
c:\program files\AutocompletePro\unins000.dat
c:\program files\AutocompletePro\unins000.exe
c:\users\Raj\AppData\Local\{C33DA028-E847-45A0-AB7E-3176C37C55FE}
c:\users\Raj\AppData\Local\{C33DA028-E847-45A0-AB7E-3176C37C55FE}\chrome.manifest
c:\users\Raj\AppData\Local\{C33DA028-E847-45A0-AB7E-3176C37C55FE}\chrome\content\_cfg.js
c:\users\Raj\AppData\Local\{C33DA028-E847-45A0-AB7E-3176C37C55FE}\chrome\content\overlay.xul
c:\users\Raj\AppData\Local\{C33DA028-E847-45A0-AB7E-3176C37C55FE}\install.rdf
c:\users\Raj\AppData\Roaming\.#
c:\users\Raj\AppData\Roaming\Microsoft\AdjMmsVista.dll
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.3.inf
c:\windows\system32\drivers\npf.sys
c:\windows\system32\jusched.exe
c:\windows\system32\Packet.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_NPF
.
.
((((((((((((((((((((((((( Files Created from 2011-04-28 to 2011-05-31 )))))))))))))))))))))))))))))))
.
.
2011-05-31 07:11 . 2011-05-31 07:18 -------- d-----w- c:\users\Raj\AppData\Local\temp
2011-05-31 07:11 . 2011-05-31 07:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-05-30 15:05 . 2011-05-30 15:05 -------- d-----w- C:\VritualRoot
2011-05-30 14:47 . 2011-05-30 16:14 -------- d-----w- c:\users\Raj\AppData\Local\Adobe
2011-05-29 16:49 . 2011-05-29 16:49 -------- d-----w- c:\program files\Safari
2011-05-29 16:47 . 2011-05-29 16:47 -------- d-----w- c:\program files\Common Files\Apple
2011-05-29 16:47 . 2011-05-29 16:47 -------- d-----w- c:\program files\Apple Software Update
2011-05-29 13:52 . 2011-05-29 14:16 97859 ----a-w- c:\windows\system32\drivers\klick.dat
2011-05-29 13:52 . 2011-05-29 14:16 115369 ----a-w- c:\windows\system32\drivers\klin.dat
2011-05-29 13:51 . 2009-12-14 11:44 88632 ----a-w- c:\windows\system32\drivers\CSCrySec.sys
2011-05-29 13:51 . 2009-12-14 11:44 39352 ----a-w- c:\windows\system32\drivers\CSVirtualDiskDrv.sys
2011-05-29 13:49 . 2011-05-29 13:49 -------- d-----w- c:\program files\Common Files\InfoWatch
2011-05-29 13:49 . 2011-05-29 13:49 -------- d-----w- c:\program files\Kaspersky Lab
2011-05-29 13:18 . 2011-05-29 13:18 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2011-05-29 11:19 . 2011-05-29 11:19 -------- d-----w- c:\users\Raj\AppData\Roaming\SUPERAntiSpyware.com
2011-05-29 11:04 . 2011-05-29 11:18 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-05-29 08:54 . 2011-05-29 08:54 -------- d-----w- c:\users\Raj\AppData\Roaming\Malwarebytes
2011-05-29 08:54 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 08:54 . 2011-05-29 08:54 -------- d-----w- c:\programdata\Malwarebytes
2011-05-29 08:54 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-29 08:54 . 2011-05-29 08:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-28 12:30 . 2010-04-27 02:25 98432 ---ha-w- c:\windows\system32\drivers\ss_bbus.sys
2011-05-28 12:30 . 2010-04-27 02:25 14848 ---ha-w- c:\windows\system32\drivers\ss_bmdfl.sys
2011-05-28 12:30 . 2010-04-27 02:25 12416 ---ha-w- c:\windows\system32\drivers\ss_bcmnt.sys
2011-05-28 12:30 . 2010-04-27 02:25 12416 ---ha-w- c:\windows\system32\drivers\ss_bcm.sys
2011-05-28 12:30 . 2010-04-27 02:25 123648 ---ha-w- c:\windows\system32\drivers\ss_bmdm.sys
2011-05-28 12:30 . 2010-04-27 02:25 12288 ---ha-w- c:\windows\system32\drivers\ss_bwhnt.sys
2011-05-28 12:30 . 2010-04-27 02:25 12288 ---ha-w- c:\windows\system32\drivers\ss_bwh.sys
2011-05-28 12:26 . 2011-05-28 12:26 -------- d-----w- c:\program files\MarkAny
2011-05-28 12:03 . 2011-05-28 12:03 -------- d-----w- c:\users\Raj\AppData\Local\Downloaded Installations
2011-05-28 06:37 . 2011-05-28 06:37 -------- d-----w- c:\users\Raj\AppData\Roaming\CoreFTP
2011-05-28 06:37 . 2011-05-28 06:37 -------- d-----w- c:\program files\CoreFTP
2011-05-28 06:31 . 2011-05-30 21:47 -------- d-----w- c:\users\Raj\AppData\Local\Altaro
2011-05-28 06:31 . 2011-05-30 21:52 -------- d-----w- c:\programdata\OopsBackup
2011-05-26 15:14 . 2011-05-26 15:14 -------- d-----w- c:\programdata\Samsung
2011-05-26 06:09 . 2011-05-28 06:30 -------- d-----w- c:\users\Raj\AppData\Local\Mango_Enterprise_-_http__
2011-05-22 15:27 . 2011-05-22 15:27 -------- d-----w- c:\program files\AGEIA Technologies
2011-05-22 15:27 . 2011-05-22 15:27 -------- d-----w- c:\windows\system32\AGEIA
2011-05-22 15:27 . 2011-05-22 15:27 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2011-05-22 14:37 . 2011-05-22 14:37 -------- d-----w- c:\program files\7-Zip
2011-05-22 07:17 . 2009-10-22 12:54 37392 ---ha-w- c:\windows\system32\drivers\20609872.sys
2011-05-22 07:17 . 2009-10-09 22:31 311312 ---ha-w- c:\windows\system32\drivers\2060987.sys
2011-05-22 07:17 . 2009-09-25 16:59 128016 ---ha-w- c:\windows\system32\drivers\20609871.sys
2011-05-21 18:02 . 2011-05-24 18:12 -------- d-----w- c:\program files\RegDefense
2011-05-21 16:35 . 2011-05-21 16:35 -------- d-----w- c:\users\Raj\AppData\Roaming\ParetoLogic
2011-05-21 16:35 . 2011-05-21 16:35 -------- d-----w- c:\users\Raj\AppData\Roaming\DriverCure
2011-05-21 16:34 . 2011-05-21 16:34 -------- d-----w- c:\programdata\ParetoLogic
2011-05-21 16:34 . 2011-05-21 16:34 -------- d-----w- c:\program files\ParetoLogic
2011-05-21 16:34 . 2011-05-21 16:34 -------- d-----w- c:\program files\Common Files\ParetoLogic
2011-05-21 12:37 . 2011-05-21 14:42 -------- d-----w- c:\program files\Hide My IP
2011-05-21 12:11 . 2011-05-21 12:11 -------- d-----w- c:\users\Raj\AppData\Local\Media Get LLC
2011-05-21 12:11 . 2011-05-21 12:11 -------- d-----w- c:\users\Raj\AppData\Local\MediaGet2
2011-05-21 12:06 . 2011-05-21 12:06 -------- d-----w- c:\users\Raj\AppData\Local\SKIDROW
2011-05-19 17:44 . 2011-05-19 17:44 -------- d-----w- c:\users\Raj\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-05-18 17:04 . 2011-05-18 17:04 -------- d-----w- c:\windows\Sun
2011-05-18 06:30 . 2011-05-18 06:30 784136 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-05-11 06:00 . 2011-04-07 12:01 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-05-08 07:16 . 2011-05-08 07:16 -------- d-----w- c:\program files\SystemRequirementsLab
2011-05-08 07:16 . 2011-05-08 07:16 -------- d-----w- c:\users\Raj\AppData\Roaming\SystemRequirementsLab
2011-05-01 13:05 . 2011-05-01 13:12 -------- d-----w- c:\programdata\Blueberry
2011-05-01 12:33 . 2011-05-01 13:12 -------- d-----w- c:\users\Raj\AppData\Roaming\Blueberry
2011-05-01 12:31 . 2011-05-01 12:31 4608 ----a-w- c:\windows\system32\bbchlp.dll
2011-05-01 12:31 . 2011-05-01 12:31 4096 ---ha-w- c:\windows\system32\drivers\bbcap.sys
2011-05-01 12:31 . 2011-05-01 12:31 30720 ----a-w- c:\windows\system32\bbcap.dll
2011-05-01 12:31 . 2011-05-01 12:33 -------- d-----w- c:\users\Raj\AppData\Roaming\LogSys
2011-05-01 12:31 . 2011-05-01 12:31 -------- d-----w- c:\programdata\LogSys
2011-05-01 12:31 . 2011-05-01 12:31 -------- d-----w- c:\program files\Common Files\Blueberry Software
2011-05-01 12:31 . 2011-05-01 12:31 -------- d-----w- c:\program files\Blueberry Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-28 13:34 . 2011-04-28 13:34 53816 ---ha-w- c:\windows\system32\drivers\RapportKELL.sys
2011-04-13 06:06 . 2009-08-18 10:30 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2011-04-13 06:06 . 2009-08-18 10:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-04-06 20:49 . 2011-04-06 20:49 218688 ---ha-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-03-12 21:55 . 2011-04-28 15:29 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-03-10 17:03 . 2011-04-15 06:28 1162240 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-10 17:03 . 2011-04-15 06:28 1136640 ----a-w- c:\windows\system32\mfc42.dll
2011-03-03 15:42 . 2011-04-15 06:28 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-03 15:40 . 2011-04-28 15:29 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-03-03 15:40 . 2011-04-28 15:29 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40 . 2011-04-28 15:29 542720 ----a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40 . 2011-04-28 15:29 458752 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40 . 2011-04-28 15:29 2159616 ----a-w- c:\windows\apppatch\AcGenral.dll
2011-03-03 13:35 . 2011-04-28 15:29 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-03-03 13:25 . 2011-04-15 06:28 2041856 ----a-w- c:\windows\system32\win32k.sys
2011-03-02 15:44 . 2011-04-15 06:28 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\KAVOverlayIcon]
@="{dd230880-495a-11d1-b064-008048ec2fc5}"
[HKEY_CLASSES_ROOT\CLSID\{dd230880-495a-11d1-b064-008048ec2fc5}]
2010-10-01 21:05 129624 ----a-w- c:\program files\Kaspersky Lab\Kaspersky PURE\shellex.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Switcher"="c:\program files\Switcher\Switcher.exe" [2007-10-28 425984]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-04 95576]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-23 2424192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky PURE\avp.exe" [2010-10-01 348760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 01:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 02:44 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 07:58 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-22 03:57 406992 ----a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoStartNPSAgent]
2010-07-04 18:13 95576 ----a-w- c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CAMONITOR]
2007-10-16 17:32 249856 ----a-w- c:\program files\USB2.0 2MP UVC Camera\Monitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-01-20 09:20 1305408 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager]
2008-05-07 15:28 591696 ------w- c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25 125952 ----a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON SX600FW Series]
2008-03-05 06:00 188928 ----a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATIEKE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON622828]
2008-03-05 06:00 188928 ----a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATIEKE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2008-06-02 14:14 75008 ----a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 15:24 54840 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
2007-04-18 15:01 65536 ----a-w- c:\hp\support\hpsysdrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2006-12-08 16:16 65536 ----a-w- c:\hp\KBD\KbdStub.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2009-06-17 16:55 55824 ----a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2008-11-05 21:59 4347120 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVRaidService]
2008-06-06 18:17 203296 ----a-w- c:\windows\System32\nvraidservice.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock]
2007-09-02 13:58 495616 ----a-w- c:\program files\RocketDock\RocketDock.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-04-07 01:56 132760 ----a-w- c:\program files\Java\jre1.6.0_01\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2011-05-23 15:00 2424192 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 12:37 517096 ----a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Switcher]
2007-10-28 11:35 425984 ----a-w- c:\program files\Switcher\Switcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-03-17 18:18 399736 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:25 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3699171474-4233505151-127562807-1000]
"EnableNotificationsRef"=dword:00000002
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 ALSysIO;ALSysIO;c:\users\Raj\AppData\Local\Temp\ALSysIO.sys [x]
R3 Ca810av;CA810A WebCam Driver;c:\windows\system32\Drivers\Ca810av.sys [2007-10-16 2329216]
R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena\safedrv.sys [x]
R3 MobileAdapter;Huawei Mobile Adapter USB Modem and USB Serial;c:\windows\system32\DRIVERS\hmvmdm.sys [2007-03-27 92032]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2010-04-27 98432]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2010-04-27 14848]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2010-04-27 123648]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-21 16896]
R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-04-11 19968]
R4 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-04-28 870200]
S0 20609872;20609872 Boot Guard Driver;c:\windows\system32\DRIVERS\20609872.sys [2009-10-22 37392]
S0 CSCrySec;InfoWatch Encrypt Sector Library driver;c:\windows\system32\DRIVERS\CSCrySec.sys [2009-12-14 88632]
S0 KLBG;Kaspersky Lab Boot Guard Driver;c:\windows\system32\DRIVERS\klbg.sys [2009-10-14 36880]
S0 RapportKELL;RapportKELL;c:\windows\System32\Drivers\RapportKELL.sys [2011-04-28 53816]
S1 20609871;20609871;c:\windows\system32\DRIVERS\20609871.sys [2009-09-25 128016]
S1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;c:\windows\system32\DRIVERS\CSVirtualDiskDrv.sys [2009-12-14 39352]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-04-06 218688]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2009-09-14 21520]
S1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [2010-03-07 390528]
S1 RapportCerberus_26169;RapportCerberus_26169;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\26169\RapportCerberus_26169.sys [2011-05-02 57144]
S1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [2011-04-28 66360]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2011-04-28 158904]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\HP\DVDPlay\000.fcl [2008-06-11 61424]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 CSObjectsSrv;CryptoStorage control service;c:\program files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [2009-12-21 743992]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-07-04 238952]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-11-20 240232]
S3 bbcap;bbcap;c:\windows\system32\DRIVERS\bbcap.sys [2011-05-01 4096]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-06-14 36608]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-10-02 19472]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.2;c:\windows\system32\DRIVERS\libusb0.sys [2006-05-30 29184]
S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2007-08-15 552448]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-30 c:\windows\Tasks\HPCeeScheduleForRaj.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-09-23 19:03]
.
2011-05-31 c:\windows\Tasks\User_Feed_Synchronization-{2BDB8D55-462F-4297-B3C2-3FE801E7AF2E}.job
- c:\windows\system32\msfeedssync.exe [2011-04-15 04:43]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bbc.co.uk/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_gb&c=84&bd=Pavilion&pf=cndt
IE: &AOL Toolbar Search - c:\programdata\AOL\ieToolbar\resources\en-GB\local\search.html
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{83F776CF-6AFD-44E8-A640-222AA9C9262F}: NameServer = 156.154.70.22,156.154.71.22
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-NPSStartup - (no file)
MSConfigStartUp-COMODO Internet Security - c:\program files\COMODO\COMODO Internet Security\cfp.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-OneCareUI - c:\program files\Microsoft Windows OneCare Live\winssnotify.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
MSConfigStartUp-WinDefender - c:\users\Raj\AppData\Roaming\svchost.exe
AddRemove-AutocompletePro3_is1 - c:\program files\AutocompletePro\unins000.exe
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
.
.
.
**************************************************************************
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files:
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}]
"ImagePath"="\??\c:\program files\HP\DVDPlay\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(7136)
c:\windows\System32\NLSData0009.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
c:\windows\system32\nvvsvc.exe
c:\windows\System32\LEXBCES.EXE
c:\windows\System32\LEXPPS.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
c:\windows\system32\sdclt.exe
.
**************************************************************************
.
Completion time: 2011-05-31 08:30:57 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-31 07:30
.
Pre-Run: 418,783,600,640 bytes free
Post-Run: 418,024,968,192 bytes free
.
- - End Of File - - 5E0BE6253A360D83054F1EFEF044E1CF
==========================================================================