ComboFix 11-03-06.02 - GM 03/06/2011 21:28:57.1.2 - x86
Microsoft® Windows Vista™ Business 6.0.6000.0.1252.1.1033.18.3070.1516 [GMT -5:00]
Running from: c:\users\gm\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\netzeroinstaller\NetZeroInstaller.exe
c:\users\gm\g2mdlhlpx.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-02-07 to 2011-03-07 )))))))))))))))))))))))))))))))
.
.
2011-03-07 02:35 . 2011-03-07 02:42 -------- d-----w- c:\users\gm\AppData\Local\temp
2011-03-07 02:35 . 2011-03-07 02:35 -------- d-----w- c:\users\sylvia\AppData\Local\temp
2011-03-07 02:35 . 2011-03-07 02:35 -------- d-----w- c:\users\robert\AppData\Local\temp
2011-03-07 02:35 . 2011-03-07 02:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-03-07 02:35 . 2011-03-07 02:35 -------- d-----w- c:\users\mac\AppData\Local\temp
2011-03-07 02:35 . 2011-03-07 02:35 -------- d-----w- c:\users\Anand\AppData\Local\temp
2011-03-07 02:35 . 2011-03-07 02:35 -------- d-----w- c:\users\anand.HRM\AppData\Local\temp
2011-03-07 02:35 . 2011-03-07 02:35 -------- d-----w- c:\users\tina\AppData\Local\temp
2011-03-07 02:35 . 2011-03-07 02:35 -------- d-----w- c:\users\administrator\AppData\Local\temp
2011-03-06 03:06 . 2011-03-06 03:08 -------- d-----w- C:\Attach.zip
2011-03-06 02:49 . 2011-03-06 02:49 -------- d-----w- c:\program files\7-Zip
2011-03-06 02:47 . 2011-03-06 19:01 -------- d-----w- C:\Downloads
2011-03-06 01:07 . 2011-03-06 01:07 -------- d-----w- c:\program files\Common Files\Windows Live
2011-03-05 00:47 . 2006-09-13 01:00 69632 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP83.DLL
2011-03-05 00:47 . 2006-09-13 01:00 27136 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD83.DLL
2011-03-05 00:45 . 2008-04-03 01:00 198656 ----a-w- c:\windows\system32\CNMLM83.DLL
2011-03-04 15:22 . 2011-02-23 14:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-03-04 15:21 . 2011-02-23 15:04 40648 ----a-w- c:\windows\avastSS.scr
2011-03-04 15:21 . 2011-03-04 15:21 -------- d-----w- c:\program files\AVAST Software
2011-03-04 15:20 . 2011-03-04 15:20 -------- d-----w- c:\programdata\AVAST Software
2011-03-04 14:43 . 2011-03-04 14:43 95232 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2011-03-04 14:43 . 2011-03-04 14:43 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2011-03-04 14:43 . 2011-03-04 14:43 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2011-03-04 14:42 . 2006-09-13 10:00 197632 ----a-w- c:\windows\system32\CNMLM7R.DLL
2011-03-04 14:40 . 2011-03-04 14:40 713728 ----a-w- c:\windows\system32\timedate.cpl
2011-03-04 14:40 . 2011-03-04 14:40 712192 ----a-w- c:\windows\system32\WindowsCodecs.dll
2011-03-04 14:40 . 2011-03-04 14:40 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2011-03-04 14:40 . 2011-03-04 14:40 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2011-03-04 14:38 . 2011-03-04 14:38 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2011-03-04 14:38 . 2011-03-04 14:38 515584 ----a-w- c:\windows\system32\RMActivate.exe
2011-03-04 14:38 . 2011-03-04 14:38 473088 ----a-w- c:\windows\system32\secproc_isv.dll
2011-03-04 14:38 . 2011-03-04 14:38 472576 ----a-w- c:\windows\system32\secproc.dll
2011-03-04 14:38 . 2011-03-04 14:38 435712 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2011-03-04 14:38 . 2011-03-04 14:38 431104 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2011-03-04 14:38 . 2011-03-04 14:38 312320 ----a-w- c:\windows\system32\msdrm.dll
2011-03-04 14:38 . 2011-03-04 14:38 154624 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2011-03-04 14:38 . 2011-03-04 14:38 154112 ----a-w- c:\windows\system32\secproc_ssp.dll
2011-03-04 14:37 . 2011-03-04 14:37 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-03-04 14:37 . 2011-03-04 14:37 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-03-04 14:37 . 2011-03-04 14:37 1686528 ----a-w- c:\windows\system32\gameux.dll
2011-03-04 14:36 . 2011-03-04 14:36 1645568 ----a-w- c:\windows\system32\connect.dll
2011-03-04 14:35 . 2011-03-04 14:35 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2011-03-04 14:35 . 2011-03-04 14:35 7680 ----a-w- c:\windows\system32\spwmp.dll
2011-03-04 14:35 . 2011-03-04 14:35 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2011-03-04 14:35 . 2011-03-04 14:35 107520 ----a-w- c:\program files\Windows Media Player\wmpshare.exe
2011-03-04 14:35 . 2011-03-04 14:35 4096 ----a-w- c:\windows\system32\msdxm.ocx
2011-03-04 14:35 . 2011-03-04 14:35 4096 ----a-w- c:\windows\system32\dxmasf.dll
2011-03-04 14:35 . 2011-03-04 14:35 107520 ----a-w- c:\program files\Windows Media Player\wmpconfig.exe
2011-03-04 14:35 . 2011-03-04 14:35 311296 ----a-w- c:\windows\system32\unregmp2.exe
2011-03-04 14:35 . 2011-03-04 14:35 1418240 ----a-w- c:\program files\Windows Media Player\setup_wm.exe
2011-03-04 13:12 . 2011-02-11 06:54 5943120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B9AFB3C5-C6E6-4BB8-AD54-34E0F209F0CB}\mpengine.dll
2011-03-04 13:12 . 2011-03-04 13:12 378368 ----a-w- c:\windows\system32\winhttp.dll
2011-03-04 07:00 . 2011-03-04 07:00 72704 ----a-w- c:\windows\system32\fontsub.dll
2011-03-04 07:00 . 2011-03-04 07:00 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-03-04 07:00 . 2011-03-04 07:00 289792 ----a-w- c:\windows\system32\atmfd.dll
2011-03-04 07:00 . 2011-03-04 07:00 24064 ----a-w- c:\windows\system32\lpk.dll
2011-03-04 07:00 . 2011-03-04 07:00 156672 ----a-w- c:\windows\system32\t2embed.dll
2011-03-04 07:00 . 2011-03-04 07:00 10240 ----a-w- c:\windows\system32\dciman32.dll
2011-03-04 06:58 . 2011-03-04 06:58 78336 ----a-w- c:\windows\system32\ieencode.dll
2011-03-04 06:56 . 2011-03-04 06:56 61440 ----a-w- c:\windows\system32\winipsec.dll
2011-03-04 06:56 . 2011-03-04 06:56 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2011-03-04 06:56 . 2011-03-04 06:56 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2011-03-04 06:56 . 2011-03-04 06:56 272896 ----a-w- c:\windows\system32\polstore.dll
2011-03-04 06:55 . 2011-03-04 06:55 84992 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-03-04 06:55 . 2011-03-04 06:55 306688 ----a-w- c:\windows\system32\drivers\srv.sys
2011-03-04 06:53 . 2011-03-04 06:53 15360 ----a-w- c:\windows\system32\netevent.dll
2011-03-04 06:53 . 2011-03-04 06:53 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2011-03-04 06:53 . 2011-03-04 06:53 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2011-03-04 06:53 . 2011-03-04 06:53 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2011-03-04 06:53 . 2011-03-04 06:53 19968 ----a-w- c:\windows\system32\ARP.EXE
2011-03-04 06:53 . 2011-03-04 06:53 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2011-03-04 06:53 . 2011-03-04 06:53 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2011-03-04 06:53 . 2011-03-04 06:53 103936 ----a-w- c:\windows\system32\netiohlp.dll
2011-03-04 06:53 . 2011-03-04 06:53 10240 ----a-w- c:\windows\system32\finger.exe
2011-03-04 06:52 . 2011-03-04 06:52 123904 ----a-w- c:\windows\system32\L2SecHC.dll
2011-03-04 06:52 . 2011-03-04 06:52 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2011-03-04 06:52 . 2011-03-04 06:52 502272 ----a-w- c:\windows\system32\wlansvc.dll
2011-03-04 06:52 . 2011-03-04 06:52 47104 ----a-w- c:\windows\system32\wlanapi.dll
2011-03-04 06:52 . 2011-03-04 06:52 297984 ----a-w- c:\windows\system32\wlansec.dll
2011-03-04 06:52 . 2011-03-04 06:52 290816 ----a-w- c:\windows\system32\wlanmsm.dll
2011-03-04 06:51 . 2011-03-04 06:51 2048 ----a-w- c:\windows\system32\msxml3r.dll
2011-03-04 06:51 . 2011-03-04 06:51 1260032 ----a-w- c:\windows\system32\msxml3.dll
2011-03-04 06:51 . 2011-03-04 06:51 2048 ----a-w- c:\windows\system32\msxml6r.dll
2011-03-04 06:51 . 2011-03-04 06:51 1406464 ----a-w- c:\windows\system32\msxml6.dll
2011-03-04 06:50 . 2011-03-04 06:50 216576 ----a-w- c:\windows\system32\msv1_0.dll
2011-03-04 06:48 . 2011-03-04 06:48 58368 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-03-04 06:48 . 2011-03-04 06:48 211968 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-03-04 06:48 . 2011-03-04 06:48 102400 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-03-04 06:47 . 2011-03-04 06:47 98816 ----a-w- c:\windows\system32\mfps.dll
2011-03-04 06:47 . 2011-03-04 06:47 52736 ----a-w- c:\windows\system32\rrinstaller.exe
2011-03-04 06:47 . 2011-03-04 06:47 2855424 ----a-w- c:\windows\system32\mf.dll
2011-03-04 06:47 . 2011-03-04 06:47 24576 ----a-w- c:\windows\system32\mfpmp.exe
2011-03-04 06:47 . 2011-03-04 06:47 2048 ----a-w- c:\windows\system32\mferror.dll
2011-03-04 06:46 . 2011-03-04 06:46 3502480 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-03-04 06:46 . 2011-03-04 06:46 3468168 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-03-04 06:44 . 2011-03-04 06:44 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-04 06:43 . 2011-03-04 06:43 71680 ----a-w- c:\windows\system32\atl.dll
2011-03-04 06:42 . 2011-03-04 06:42 297472 ----a-w- c:\windows\system32\gdi32.dll
2011-03-04 06:39 . 2011-03-04 06:39 500736 ----a-w- c:\windows\system32\msdtcprx.dll
2011-03-04 06:39 . 2011-03-04 06:39 30208 ----a-w- c:\windows\system32\xolehlp.dll
2011-03-04 06:38 . 2011-03-04 06:38 156160 ----a-w- c:\windows\system32\wkssvc.dll
2011-03-04 06:37 . 2011-03-04 06:37 36352 ----a-w- c:\windows\system32\tsgqec.dll
2011-03-04 06:37 . 2011-03-04 06:37 116736 ----a-w- c:\windows\system32\aaclient.dll
2011-03-04 06:37 . 2011-03-04 06:37 1871872 ----a-w- c:\windows\system32\mstscax.dll
2011-03-04 06:36 . 2011-03-04 06:36 268800 ----a-w- c:\windows\system32\es.dll
2011-03-04 06:35 . 2011-03-04 06:35 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2011-03-04 06:32 . 2011-03-04 06:32 150016 ----a-w- c:\program files\Movie Maker\MOVIEMK.exe
2011-03-04 06:32 . 2011-03-04 06:32 10922496 ----a-w- c:\program files\Movie Maker\MOVIEMK.dll
2011-03-04 06:32 . 2011-03-04 06:32 23040 ----a-w- c:\program files\Movie Maker\WMM2EXT.dll
2011-03-04 06:32 . 2011-03-04 06:32 195072 ----a-w- c:\program files\Movie Maker\WMM2AE.dll
2011-03-04 06:28 . 2011-03-04 06:28 2048 ----a-w- c:\windows\system32\tzres.dll
2011-03-04 06:27 . 2011-03-04 06:27 696832 ----a-w- c:\windows\system32\localspl.dll
2011-03-04 06:26 . 2011-03-04 06:26 2923520 ----a-w- c:\windows\explorer.exe
2011-03-04 06:24 . 2011-03-04 06:24 171520 ----a-w- c:\windows\system32\wintrust.dll
2011-03-04 06:23 . 2011-03-04 06:23 7680 ----a-w- c:\windows\system32\lsass.exe
2011-03-04 06:23 . 2011-03-04 06:23 72704 ----a-w- c:\windows\system32\secur32.dll
2011-03-04 06:23 . 2011-03-04 06:23 494592 ----a-w- c:\windows\system32\kerberos.dll
2011-03-04 06:23 . 2011-03-04 06:23 408136 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2011-03-04 06:23 . 2011-03-04 06:23 175104 ----a-w- c:\windows\system32\wdigest.dll
2011-03-04 06:23 . 2011-03-04 06:23 1233920 ----a-w- c:\windows\system32\lsasrv.dll
2011-03-04 06:23 . 2011-03-04 06:23 272384 ----a-w- c:\windows\system32\schannel.dll
2011-03-04 06:18 . 2011-03-04 06:18 220160 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-03-04 06:18 . 2011-03-04 06:18 19456 ----a-w- c:\windows\system32\drivers\bthenum.sys
2011-03-04 06:18 . 2011-03-04 06:18 181760 ----a-w- c:\windows\system32\fsquirt.exe
2011-03-04 06:18 . 2011-03-04 06:18 29184 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-04 14:37 . 2011-03-04 14:37 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2011-03-04 14:37 . 2011-03-04 14:37 537600 ----a-w- c:\windows\apppatch\AcLayers.dll
2011-03-04 14:37 . 2011-03-04 14:37 449024 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-04 14:37 . 2011-03-04 14:37 2143744 ----a-w- c:\windows\apppatch\AcGenral.dll
2011-03-04 14:37 . 2011-03-04 14:37 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-04 13:10 . 2011-03-04 13:10 36864 ----a-w- c:\windows\system32\drivers\en-US\http.sys.mui
2011-03-04 06:59 . 2011-03-04 06:59 52736 ----a-w- c:\windows\apppatch\iebrshim.dll
2011-03-04 06:07 . 2011-03-04 06:07 40960 ----a-w- c:\windows\apppatch\apihex86.dll
2011-02-23 15:04 . 2008-02-20 19:33 190016 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-23 14:56 . 2008-04-16 02:15 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-23 14:55 . 2008-02-20 19:33 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-23 14:55 . 2008-02-20 19:33 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-23 14:55 . 2008-02-20 19:33 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-02-23 14:54 . 2008-04-16 02:15 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-02 22:11 . 2009-10-08 19:11 222080 ------w- c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AOLOverlayIcon]
@="{AB0C8BE3-041C-47d6-8195-E089D32B38DD}"
[HKEY_CLASSES_ROOT\CLSID\{AB0C8BE3-041C-47d6-8195-E089D32B38DD}]
2007-10-05 18:54 303104 ------w- c:\ddi\OverIcon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-06-06 07:16 2955264 ----a-w- c:\program files\Protector Suite QL\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-06-06 07:16 2955264 ----a-w- c:\program files\Protector Suite QL\farchns.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-21 39408]
"SmileboxTray"="c:\users\gm\AppData\Roaming\Smilebox\SmileboxTray.exe" [2011-01-22 312640]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-05-23 1232896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VWLASU"="c:\program files\Sony\VAIO PC Wireless LAN Wizard\AutoLaunchWLASU.exe" [2007-10-13 45056]
"VAIOSurvey"="c:\program files\Sony\VAIO Survey\Vista VAIO Survey.exe" [2007-07-20 577536]
"VAIORegistration"="c:\program files\Sony\First Experience\WelcomeLauncher.exe" [2007-10-17 20480]
"VAIO Help and Support Demo"="c:\program files\Sony\VAIO Help and Support Demo\LaunchVHSD.exe" [2007-08-28 290816]
"VAIO Center Access Bar"="c:\program files\sony\VAIO Center Access Bar\VCAB.exe" [2007-09-06 53248]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"SmartWiHelper"="c:\program files\Sony Corporation\SmartWi Connection Utility\SmartWiHelper.exe" [2007-07-06 65536]
"PSQLLauncher"="c:\program files\Protector Suite QL\launcher.exe" [2007-06-06 49168]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-07-24 86016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-24 81920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-24 8429568]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-09-19 311296]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
"DRCU"="c:\program files\Sony\DRCU\DRCU.exe" [2007-06-18 73728]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-10-12 118784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
.
c:\users\gm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
2X Client.lnk - c:\program files\2X\Client\APPServerClient.exe [2009-6-25 1108472]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-10-30 748072]
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\PMremind.exe [2009-7-15 331776]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-1-13 972064]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-06-06 07:03 90112 ----a-w- c:\windows\System32\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-08-15 04:05 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwusbser2.sys [2007-04-19 99200]
R3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-11 745472]
R3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2007-08-09 397312]
R3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-08-09 1089536]
R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2007-09-29 292128]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2007-09-21 79136]
S0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\DRIVERS\shpf.sys [2007-10-09 21408]
S1 aswSnx;aswSnx;
S1 aswSP;aswSP;
S2 2X SSO Service;2X SSO Service;c:\program files\2X\Client\\TUXCredProv.exe [2009-06-25 268792]
S2 aswFsBlk;aswFsBlk;
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-02-23 53592]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032]
S2 uCamMonitor;CamMonitor;c:\program files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [2007-10-31 125440]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2007-10-30 17920]
S3 BTHprint;Microsoft Bluetooth Printer Class;c:\windows\system32\DRIVERS\bthprint.sys [2006-11-02 28672]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2007-11-16 28464]
S3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\Drivers\R5U870FLx86.sys [2007-06-06 75392]
S3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\Drivers\R5U870FUx86.sys [2007-06-06 43904]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [2007-09-06 9344]
S3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\DRIVERS\SonyPI.sys [2007-09-01 14720]
S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-07-09 812544]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 19:14]
.
2011-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 19:14]
.
2011-03-07 c:\windows\Tasks\User_Feed_Synchronization-{3743522E-0CBA-4DCF-9594-9EE1CBD6F9D4}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
------- Supplementary Scan -------
.
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKCU-Run-RegistryBooster - c:\program files\Uniblue\RegistryBooster\launcher.exe
SSODL-xkefqtgs-{4D2F6D91-DC54-4A85-BD6D-AA63A02DDECC} - c:\windows\xkefqtgs.dll
SSODL-rnopbfgt-{45EF9A8B-2C64-442C-921E-8141696A5A7C} - c:\windows\rnopbfgt.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-03-06 21:40
Windows 6.0.6000 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(3532)
c:\program files\ScanSoft\OmniPageSE2.0\ophookSE2.dll
c:\ddi\overicon.dll
c:\program files\Protector Suite QL\farchns.dll
c:\program files\Protector Suite QL\infra.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\2X\Client\TUXCredProv.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PSIService.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\stacsv.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Sony\VAIO Event Service\VESMgrSub.exe
c:\program files\Protector Suite QL\upeksvr.exe
c:\program files\Sony\VAIO Power Management\SPMgr.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\Apoint\ApMsgFwd.exe
c:\program files\Apoint\Apntex.exe
c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2011-03-06 21:47:29 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-07 02:47
.
Pre-Run: 164,771,500,032 bytes free
Post-Run: 164,442,165,248 bytes free
.
Current=1 Default=1 Failed=0 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - 8DA354271D95D7CE08BAABF83BB24806