okay same old server not found when I try to browse
ComboFix 10-06-29.04 - Owner 06/30/2010 15:28:15.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1483 [GMT -4:00]
Running from: G:\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Local Settings\Application Data\{CE8B155C-5441-4B09-8D8C-48E0F645D3CC}
c:\documents and settings\Owner\Local Settings\Application Data\{CE8B155C-5441-4B09-8D8C-48E0F645D3CC}\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{CE8B155C-5441-4B09-8D8C-48E0F645D3CC}\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{CE8B155C-5441-4B09-8D8C-48E0F645D3CC}\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{CE8B155C-5441-4B09-8D8C-48E0F645D3CC}\install.rdf
c:\windows\system32\spool\prtprocs\w32x86\E5a55.dll
c:\windows\system32\spool\prtprocs\w32x86\M3179o1o9.dll
c:\windows\system32\spool\prtprocs\w32x86\MYWSKUOC.dll
.
---- Previous Run -------
.
c:\documents and settings\Owner\Local Settings\Application Data\mjrifhuyc\vynthhatssd.exe
c:\documents and settings\Owner\Local Settings\Application Data\ndqicbwed\hxcvmnctssd.exe
c:\documents and settings\Owner\Recent\randominess.pif
c:\program files\Cheat Engine\dbk32.sys
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\ijugirifad.dll
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\BReWErS.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\ernel32.dll
c:\windows\system32\GQsvvyxx.ini
c:\windows\system32\GQsvvyxx.ini2
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\spool\prtprocs\w32x86\C1s9e179.dll
c:\windows\system32\spool\prtprocs\w32x86\C93u79i.dll
c:\windows\system32\spool\prtprocs\w32x86\G7iQG7.dll
c:\windows\system32\spool\prtprocs\w32x86\K93g79a.dll
c:\windows\system32\spool\prtprocs\w32x86\O3oC9s17s.dll
c:\windows\system32\spool\prtprocs\w32x86\OC9sK7.dll
c:\windows\system32\spool\prtprocs\w32x86\UO555.dll
c:\windows\system32\spool\prtprocs\w32x86\W5u5m.dll
c:\windows\system32\spool\prtprocs\w32x86\Y1cE3a79.dll
c:\windows\system32\spool\prtprocs\w32x86\Y31oC317y.dll
c:\windows\system32\spool\prtprocs\w32x86\Y5cE5.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\Thumbs.db
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\wpe pro.INI
D:\Autorun.inf
H:\Autorun.inf
-- Previous Run --
Infected copy of c:\windows\system32\drivers\compbatt.sys was found and disinfected
Restored copy from - Kitty had a snack :p
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
--------
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DBKDRVR54
-------\Service_DBKDRVR54
((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-30 )))))))))))))))))))))))))))))))
.
2010-06-29 23:56 . 2010-02-28 00:46 3691384 ----a-w- c:\documents and settings\Owner\Application Data\Simply Super Software\Trojan Remover\oubA7.exe
2010-06-29 23:40 . 2006-06-19 16:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2010-06-29 23:40 . 2006-05-25 18:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2010-06-29 23:40 . 2005-08-26 04:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2010-06-29 23:40 . 2003-02-02 23:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2010-06-29 23:40 . 2002-03-06 04:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2010-06-29 23:40 . 2010-06-29 23:55 -------- d-----w- c:\program files\Trojan Remover
2010-06-29 23:40 . 2010-06-29 23:40 -------- d-----w- c:\documents and settings\Owner\Application Data\Simply Super Software
2010-06-29 23:40 . 2010-06-29 23:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Simply Super Software
2010-06-29 02:22 . 2008-04-14 00:12 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2010-06-29 02:22 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2010-06-25 21:18 . 2010-06-27 21:56 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-25 18:14 . 2010-06-25 18:16 -------- d-----w- c:\documents and settings\LocalService\Application Data\PriceGong
2010-06-25 18:14 . 2010-06-25 18:14 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Conduit
2010-06-25 18:14 . 2010-06-25 18:14 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Hotspot_Shield
2010-06-25 18:14 . 2010-06-25 18:14 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\DVDVideoSoftTB
2010-06-25 02:51 . 2010-06-25 02:51 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2010-06-24 18:58 . 2010-06-24 18:58 -------- d-----w- C:\spoolerlogs
2010-06-24 18:46 . 2010-06-24 18:46 203968 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-06-24 14:29 . 2010-06-24 15:56 -------- d-----w- c:\documents and settings\Owner\Application Data\Command and Conquer 4
2010-06-24 14:12 . 2010-06-24 14:12 49664 ----a-w- c:\documents and settings\Owner\Application Data\dbd85940.exe
2010-06-24 13:49 . 2010-06-29 23:08 -------- d-----w- c:\documents and settings\Owner\Application Data\PriceGong
2010-06-23 09:47 . 2010-06-23 09:47 -------- d-----w- c:\documents and settings\Owner\Command & Conquer 3 Tiberium Wars
2010-06-23 03:28 . 2010-06-29 22:43 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\DVDVideoSoftTB
2010-06-23 03:28 . 2010-06-24 13:49 -------- d-----w- c:\program files\DVDVideoSoftTB
2010-06-23 03:28 . 2010-06-23 03:28 52224 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\xxruvh3u.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll
2010-06-23 03:28 . 2010-06-23 03:28 101376 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\xxruvh3u.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll
2010-06-21 01:35 . 2010-06-21 01:35 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Ironclad Games
2010-06-21 01:35 . 2010-06-21 01:35 -------- d--h--w- c:\documents and settings\All Users\Application Data\{0E8E33D8-193A-414A-A909-0F101A142D26}
2010-06-21 01:35 . 2008-01-18 20:26 2763784 ----a-w- c:\documents and settings\All Users\Application Data\{0E8E33D8-193A-414A-A909-0F101A142D26}\setup.exe
2010-06-21 01:29 . 2010-06-21 01:29 -------- d-----w- c:\program files\Stardock Games
2010-06-21 01:22 . 2010-06-21 01:22 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Stardock
2010-06-20 17:53 . 2010-06-20 17:53 -------- d-----w- c:\program files\Daniusoft
2010-06-20 17:47 . 2003-03-19 02:20 1060864 ----a-w- c:\windows\system32\MFC71.DLL
2010-06-20 17:47 . 2010-06-20 17:47 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Cucusoft
2010-06-20 17:47 . 2009-07-01 19:16 94854 ----a-w- c:\windows\system32\HKCU_GNU.reg
2010-06-20 17:47 . 2009-02-26 20:34 2004 ----a-w- c:\windows\system32\HKLM_GNU.reg
2010-06-20 17:47 . 2008-12-18 05:22 57344 ----a-w- c:\windows\system32\ff_vfw.dll
2010-06-20 17:47 . 2008-06-15 14:01 60273 ----a-w- c:\windows\system32\pthreadGC2.dll
2010-06-20 17:47 . 2009-08-12 20:48 270336 ----a-w- c:\windows\system32\cdg.dll
2010-06-20 17:47 . 2006-09-27 21:46 348160 ----a-w- c:\windows\system32\cdga.dll
2010-06-20 17:47 . 2006-07-18 01:42 14909 ----a-w- c:\windows\system32\A_reg.reg
2010-06-20 17:47 . 2010-06-20 17:47 -------- d-----w- c:\program files\Cucusoft
2010-06-20 17:46 . 2010-06-20 17:47 -------- d-----w- c:\documents and settings\Owner\Application Data\GetRightToGo
2010-06-20 17:14 . 2010-06-20 17:51 -------- d-----w- c:\documents and settings\Owner\Application Data\Apple Computer
2010-06-20 17:14 . 2009-05-18 17:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-06-19 19:54 . 2010-06-19 19:54 4710 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{1FEA83F9-7B47-47FF-8297-08E0D07C26F4}\_7fdf717c.exe
2010-06-19 19:54 . 2010-06-19 19:54 4710 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{1FEA83F9-7B47-47FF-8297-08E0D07C26F4}\_3f947574.exe
2010-06-19 19:54 . 2010-06-19 19:54 4710 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{1FEA83F9-7B47-47FF-8297-08E0D07C26F4}\_188e3184.exe
2010-06-19 19:54 . 2010-06-19 19:54 1078 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{1FEA83F9-7B47-47FF-8297-08E0D07C26F4}\_2e8633c1.exe
2010-06-19 19:54 . 2010-06-19 19:54 -------- d-----w- c:\program files\PAK Explorer
2010-06-19 00:33 . 2010-06-30 19:34 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi
2010-06-19 00:33 . 2010-06-30 19:19 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\LogMeIn Hamachi
2010-06-19 00:33 . 2010-06-19 00:33 -------- d-----w- c:\program files\LogMeIn Hamachi
2010-06-18 14:02 . 2010-06-19 04:27 -------- d-----w- c:\program files\SpeedFan
2010-06-18 13:49 . 2010-06-18 13:54 -------- d-----w- c:\program files\CPU Thermometer
2010-06-16 00:01 . 2010-06-16 00:01 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-15 01:36 . 2010-06-15 01:41 -------- d-----w- c:\documents and settings\Owner\wurm
2010-06-15 01:35 . 2010-06-15 01:35 61952 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\34\f83d062-3122e20d-2.4.2--n\jinput-dx8.dll
2010-06-15 01:35 . 2010-06-15 01:35 59392 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\34\f83d062-3122e20d-2.4.2--n\jinput-raw.dll
2010-06-15 01:35 . 2010-06-15 01:35 20480 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\30\3ab3ff1e-5d215454-1.1.1--n\jogl_awt.dll
2010-06-15 01:35 . 2010-06-15 01:35 315392 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\30\3ab3ff1e-5d215454-1.1.1--n\jogl.dll
2010-06-15 01:35 . 2010-06-15 01:35 20480 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\20\68ca514-35036d87-1.0b06--n\gluegen-rt.dll
2010-06-15 01:35 . 2010-06-15 01:35 193024 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\34\f83d062-3122e20d-2.4.2--n\lwjgl.dll
2010-06-15 01:35 . 2010-06-15 01:35 114688 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\30\3ab3ff1e-5d215454-1.1.1--n\jogl_cg.dll
2010-06-15 01:35 . 2010-06-15 01:35 108032 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\34\f83d062-3122e20d-2.4.2--n\OpenAL32.dll
2010-06-13 00:53 . 2010-06-13 00:57 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Oblivion
2010-06-09 09:37 . 2010-06-09 09:37 -------- d-----w- c:\program files\Ubisoft
2010-06-08 02:18 . 2010-06-08 02:18 -------- d-----w- c:\program files\MegaDev
2010-06-08 02:16 . 2010-06-29 01:19 120 ----a-w- c:\windows\Ivedetilarejuco.dat
2010-06-08 02:16 . 2010-06-28 12:11 0 ----a-w- c:\windows\Xsuyo.bin
2010-06-08 02:15 . 2010-06-08 02:15 -------- d-----w- c:\windows\system32\msapps
2010-06-06 12:30 . 2010-06-06 12:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Solidshield
2010-06-06 11:32 . 2010-06-06 11:32 -------- d-----w- c:\program files\GameSpy
2010-06-06 04:35 . 2010-06-06 04:35 503808 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7514f039-n\msvcp71.dll
2010-06-06 04:35 . 2010-06-06 04:35 499712 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7514f039-n\jmc.dll
2010-06-06 04:35 . 2010-06-06 04:35 348160 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7514f039-n\msvcr71.dll
2010-06-06 04:35 . 2010-06-06 04:35 12800 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-404cc129-n\decora-d3d.dll
2010-06-06 04:35 . 2010-06-06 04:35 61440 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-404cc129-n\decora-sse.dll
2010-06-06 01:57 . 2010-06-06 12:30 -------- d-----w- c:\documents and settings\Owner\Application Data\Ubisoft
2010-06-06 01:55 . 2010-06-06 01:55 -------- d-----w- c:\documents and settings\Owner\Application Data\SeriousBit
2010-06-06 01:54 . 2010-06-06 01:54 -------- d-----w- C:\SeriousBit
2010-06-06 01:54 . 2010-06-06 01:55 -------- d-----w- c:\program files\NetBalancer
2010-06-06 01:51 . 2010-05-15 04:04 28776 ----a-w- c:\windows\system32\drivers\nbdrv.sys
2010-06-06 00:32 . 2010-06-06 00:32 -------- d-----w- c:\documents and settings\Owner\Application Data\Roaming
2010-06-05 17:48 . 2010-06-05 17:48 -------- d-----w- c:\documents and settings\All Users\Application Data\hsswpr
2010-06-05 17:38 . 2010-06-24 13:49 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Conduit
2010-06-05 17:38 . 2010-06-05 17:49 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Hotspot_Shield
2010-06-05 17:38 . 2010-06-05 17:38 -------- d-----w- c:\program files\Conduit
2010-06-05 17:38 . 2010-06-05 17:49 -------- d-----w- c:\program files\Hotspot_Shield
2010-06-05 17:36 . 2010-06-05 17:48 -------- d-----w- C:\Hotspot Shield
2010-06-05 01:09 . 2010-06-05 01:09 411368 ----a-w- c:\windows\system32\deployJava1.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-30 02:02 . 2006-09-26 18:28 -------- d-----w- c:\program files\Java
2010-06-30 01:52 . 2009-03-19 11:33 -------- d-----w- c:\documents and settings\Owner\Application Data\BitTorrent
2010-06-29 23:58 . 2009-01-25 04:49 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-06-29 13:43 . 2010-03-20 05:05 52224 ----a-w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-06-29 13:43 . 2009-05-31 18:44 117760 ----a-w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-06-29 13:38 . 2006-09-26 18:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-06-29 02:21 . 2008-11-16 04:07 -------- d-----w- c:\program files\Cheat Engine
2010-06-28 00:29 . 2006-09-26 18:27 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-24 22:28 . 2009-06-03 01:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-24 13:28 . 2008-01-13 16:48 -------- d-----w- c:\program files\Electronic Arts
2010-06-23 03:23 . 2010-05-01 02:03 -------- d-----w- c:\documents and settings\Owner\Application Data\DVDVideoSoftIEHelpers
2010-06-23 03:22 . 2008-12-19 15:19 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2010-06-20 17:14 . 2010-06-20 17:13 -------- d-----w- c:\program files\iTunes
2010-06-20 17:14 . 2010-06-20 17:13 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-20 17:13 . 2010-06-20 17:13 -------- d-----w- c:\program files\iPod
2010-06-20 17:13 . 2010-06-20 17:10 -------- d-----w- c:\program files\Common Files\Apple
2010-06-20 17:13 . 2010-06-20 17:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-06-20 17:12 . 2006-09-26 18:36 -------- d-----w- c:\program files\QuickTime
2010-06-20 17:11 . 2010-06-20 17:11 -------- d-----w- c:\program files\Apple Software Update
2010-06-20 17:10 . 2010-06-20 17:10 -------- d-----w- c:\program files\Bonjour
2010-06-20 17:10 . 2010-06-20 17:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-06-11 19:00 . 2008-05-08 00:02 -------- d-----w- c:\program files\Post Nuke 2 D Game
2010-06-10 17:07 . 2008-11-04 21:43 42 ----a-w- c:\documents and settings\Owner\jagex_runescape_preferences.dat
2010-06-07 19:49 . 2009-09-13 20:08 87 ----a-w- c:\documents and settings\Owner\jagex_runescape_preferences2.dat
2010-06-06 18:17 . 2007-12-26 00:59 101984 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-06 11:33 . 2008-01-02 21:31 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-06-06 11:31 . 2010-03-27 12:42 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-06-06 11:31 . 2009-07-13 20:08 22328 ----a-w- c:\documents and settings\Owner\Application Data\PnkBstrK.sys
2010-06-06 11:31 . 2009-07-13 20:08 22328 ----a-w- c:\documents and settings\Owner\Application Data\PnkBstrK.sys
2010-06-06 11:31 . 2008-02-09 20:00 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-06-06 11:31 . 2008-02-09 20:00 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-06-06 11:31 . 2009-07-13 20:07 669184 ----a-w- c:\windows\system32\pbsvc.exe
2010-06-05 01:10 . 2006-09-26 18:28 -------- d-----w- c:\program files\Common Files\Java
2010-06-05 01:01 . 2010-01-23 05:53 -------- d-----w- c:\program files\RS2Botv2
2010-05-31 20:19 . 2009-10-19 12:15 0 ----a-w- c:\documents and settings\Owner\ntuser.tmp
2010-05-30 20:16 . 2008-04-26 15:13 -------- d-----w- c:\program files\EA GAMES
2010-05-29 15:25 . 2010-01-08 21:51 -------- d-----w- c:\documents and settings\Owner\Application Data\Tropico 3
2010-05-21 01:07 . 2010-05-21 01:07 -------- d-----w- c:\documents and settings\Owner\Application Data\ElevatedDiagnostics
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2010-05-18 20:35 . 2010-05-18 20:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-13 22:05 . 2010-05-13 22:05 32768 ----a-w- c:\windows\system32\drivers\taphss.sys
2010-05-13 10:11 . 2009-05-14 13:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-05-12 10:22 . 2006-09-26 18:23 -------- d-----w- c:\program files\Google
2010-05-09 19:12 . 2009-03-19 11:32 -------- d-----w- c:\documents and settings\Owner\Application Data\DNA
2010-05-06 20:34 . 2009-03-19 11:32 -------- d-----w- c:\program files\DNA
2010-05-06 01:22 . 2009-03-19 21:19 -------- d-----w- c:\program files\AV Vcs 6.0 DIAMOND
2010-05-06 00:06 . 2010-05-06 00:06 -------- d-----w- c:\program files\CPUID
2010-05-04 21:48 . 2008-10-14 02:25 -------- d-----w- c:\program files\GameSpy Arcade
2010-05-01 15:56 . 2010-05-01 15:56 0 ----a-w- c:\documents and settings\Owner\jagex__preferences3.dat
2010-04-29 19:39 . 2009-06-03 01:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2009-06-03 01:14 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 00:47 . 2010-06-20 17:11 3062048 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-04-20 00:47 . 2010-06-20 17:11 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-04-14 23:56 . 2009-09-04 19:32 25 ----a-w- c:\windows\popcinfot.dat
2008-10-25 16:38 . 2008-10-25 16:38 13065 ----a-w- c:\program files\Common Files\ferowe.db
2008-03-20 02:34 . 2008-03-19 23:41 414944 ----a-w- c:\program files\COMCT332.OCX
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
------- Sigcheck -------
[-] 2009-05-01 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\TCPIP.SYS
[-] 2009-05-01 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\TCPIP.SYS
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\TCPIP.SYS
[-] 2007-10-30 . 90CAFF4B094573449A0872A0F919B178 . 360064 . . [5.1.2600.3244] . . c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[-] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[-] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2006-04-20 . 1DBF125862891817F374F407626967F4 . 359808 . . [5.1.2600.2892] . . c:\windows\$NtUninstallKB941644$\tcpip.sys
[-] 2006-01-14 . 5562CC0A47B2AEF06D3417B733F3C195 . 360448 . . [5.1.2600.2827] . . c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[-] 2006-01-13 . 583E063FDC888CA30D05C2724B0D7EF4 . 359808 . . [5.1.2600.2827] . . c:\windows\$NtUninstallKB917953$\tcpip.sys
[-] 2005-05-26 . 63FDFEA54EB53DE2D863EE454937CE1E . 359936 . . [5.1.2600.2685] . . c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[-] 2005-05-26 . 88763A98A4C26C409741B4AA162720C9 . 359808 . . [5.1.2600.2685] . . c:\windows\$NtUninstallKB913446$\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2010-06-24 13:49 2736736 ----a-w- c:\program files\DVDVideoSoftTB\tbDVD1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
2010-06-05 17:49 2515552 ----a-w- c:\program files\Hotspot_Shield\tbHot1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{c95a4e8e-816d-4655-8c79-d736da1adb6d}"= "c:\program files\Hotspot_Shield\tbHot1.dll" [2010-06-05 2515552]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVD1.dll" [2010-06-24 2736736]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}"= "c:\program files\Hotspot_Shield\tbHot1.dll" [2010-06-05 2515552]
"{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"= "c:\program files\DVDVideoSoftTB\tbDVD1.dll" [2010-06-24 2736736]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-07-09 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-14 13877248]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-07-14 86016]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2010-02-28 1165192]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WN111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WN111v2\WN111V2.exe [2008-12-2 1503306]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
backup=c:\windows\pss\BigFix.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
NA [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-09-11 07:43 67488 ----a-w- c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
2009-07-09 20:07 49968 ----a-w- c:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ----a-w- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
2004-10-19 00:42 79448 ----a-w- c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2008-04-17 22:14 98616 ----a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-08-14 04:05 344064 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2010-05-06 20:34 323392 ----a-w- c:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
2009-03-28 21:11 3325952 ----a-w- c:\program files\Electronic Arts\EADM\Core.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2006-09-26 18:23 169984 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 18:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Portfolio]
2005-08-17 19:41 749568 ----a-w- c:\program files\Microsoft Works\WksSb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2000-07-13 20:00 28739 ----a-w- c:\program files\Microsoft Works\WkDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2007-01-19 19:54 5674352 ----a-w- c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2009-06-10 15:29 1657376 ----a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-19 02:16 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-14 06:42 212992 -c--a-w- c:\windows\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
2005-02-26 01:24 966656 ----a-w- c:\windows\creator\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2005-01-12 10:01 32768 ----a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2006-04-17 07:34 16143872 ----a-w- c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2008-08-30 01:11 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-05-30 23:45 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2009]
2008-08-26 16:48 2019624 ----a-w- c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorksFUD]
2000-07-13 20:00 24576 ----a-w- c:\program files\Microsoft Works\wkfud.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"h:\\Files\\Steam\\Steam.exe"=
"h:\\Files\\Steam\\steamapps\\binkow195\\half-life\\hl.exe"=
"h:\\Files\\Steam\\steamapps\\binkow195\\dedicated server\\hlds.exe"=
"h:\\Files\\Steam\\steamapps\\binkow195\\counter-strike\\hl.exe"=
"h:\\Files\\Steam\\steamapps\\binkow195\\team fortress classic\\hl.exe"=
"h:\\Files\\Steam\\steamapps\\common\\borderlands\\Binaries\\Borderlands.exe"=
"h:\\Files\\Steam\\steamapps\\binkow195\\day of defeat\\hl.exe"=
"h:\\Files\\Steam\\steamapps\\common\\family feud\\FamilyFeud.exe"=
"h:\\Files\\Steam\\steamapps\\common\\cabela's trophy bucks\\Bin\\Ctb.exe"=
"h:\\Files\\Steam\\steamapps\\common\\family feud 2\\FamilyFeud.exe"=
"h:\\Files\\Steam\\steamapps\\binkow195\\opposing force\\hl.exe"=
"h:\\Files\\Steam\\steamapps\\common\\family feud 3\\FamilyFeud3.exe"=
"h:\\Files\\Steam\\steamapps\\binkow195\\ricochet\\hl.exe"=
"h:\\Files\\Steam\\steamapps\\common\\family feud 4\\FamilyFeud4.exe"=
"h:\\Files\\Steam\\steamapps\\common\\battlefield bad company 2\\Support\\EA Help\\Electronic_Arts_Technical_Support.htm"=
"h:\\Files\\Steam\\steamapps\\common\\bioshock\\Builds\\Release\\Bioshock.exe"=
"h:\\Files\\Steam\\steamapps\\common\\world in conflict\\wic.exe"=
"h:\\Files\\Steam\\steamapps\\common\\call of duty 4\\iw3sp.exe"=
"h:\\Files\\Steam\\steamapps\\common\\call of duty 4\\iw3mp.exe"=
"h:\\Files\\Steam\\steamapps\\common\\battlefield bad company 2\\BFBC2Game.exe"=
"h:\\Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"h:\\Files\\Steam\\steamapps\\common\\defensegridtheawakening\\DefenseGrid.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"h:\\Files\\Steam\\steamapps\\common\\tropico 3\\tropico3.exe"=
"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"h:\\Files\\Steam\\steamapps\\common\\dawn of discovery\\tools\\AddonWeb.exe"=
"h:\\Files\\Steam\\steamapps\\common\\dawn of war 2\\DOW2.exe"=
"h:\\Files\\Steam\\steamapps\\binkow195\\zombie panic! source\\hl2.exe"=
"h:\\Files\\Steam\\steamapps\\common\\oblivion\\OblivionLauncher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"h:\\Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"h:\\Files\\Steam\\steamapps\\common\\left 4 dead 2\\left4dead2.exe"=
"h:\\Files\\Steam\\steamapps\\binkow195\\counter-strike source\\hl2.exe"=
"h:\\Files\\Steam\\steamapps\\common\\crysis\\Bin32\\Crysis.exe"=
"h:\\Files\\Games\\Settlers7\\Data\\Base\\_Dbg\\Bin\\Release\\Settlers7R.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"h:\\Files\\Steam\\steamapps\\common\\men of war\\mow.exe"=
"c:\\Program Files\\Microsoft Games\\Rise of Nations\\thrones.exe"=
"c:\\Program Files\\Microsoft Games\\Rise of Nations\\nations.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"h:\\Files\\Steam\\steamapps\\common\\arma 2\\ArmA2Server.exe"=
"h:\\Files\\Steam\\steamapps\\binkow195\\garrysmod\\hl2.exe"=
"h:\\Files\\Steam\\steamapps\\common\\arma 2\\arma2.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6881:TCP"= 6881:TCP:Downloads
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/14/2009 5:22 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/14/2009 5:22 PM 72944]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/12/2009 6:42 PM 135336]
R2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [5/5/2010 8:06 PM 20968]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [3/30/2010 11:16 AM 1107336]
R2 NetBalancer Windows Service;NetBalancer Windows Service;c:\program files\NetBalancer\SeriousBit.NetBalancer.Service.exe [6/5/2010 9:54 PM 10752]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [10/1/2008 7:45 PM 57440]
R3 Nbdrv;NetBalancer Service;c:\windows\system32\drivers\nbdrv.sys [6/5/2010 9:51 PM 28776]
S2 gupdate1c9a9d8168cc888;Google Update Service (gupdate1c9a9d8168cc888);c:\program files\Google\Update\GoogleUpdate.exe [3/20/2009 11:49 PM 133104]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [7/24/2003 3:10 PM 17149]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\windows\system32\drivers\el575ND5.sys [7/1/2006 12:44 AM 69692]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\NETGEAR\WN111v2\jswpsapi.exe [2/27/2008 2:54 PM 360547]
S3 Mnmderywwcd;Mnmderywwcd;
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/14/2009 5:22 PM 7408]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [3/27/2009 5:23 PM 23064]
S3 WN111v2;NETGEAR WN111v2 USB2.0 Wireless Card Service;c:\windows\system32\drivers\WN111v2.sys [9/30/2008 6:24 AM 453120]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/19/2009 6:35 PM 691696]
.
Contents of the 'Scheduled Tasks' folder
2010-06-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
2010-06-30 c:\windows\Tasks\dbd85940.job
- c:\documents and settings\Owner\Application Data\dbd85940.exe [2010-06-24 14:12]
2010-06-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-21 03:49]
2010-06-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-21 03:49]
2007-12-26 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-05-07 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = <local>
DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} - hxxp://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\xxruvh3u.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?invocationType=bu10aiminstabie7&sredir=2706&query=
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\xxruvh3u.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\xxruvh3u.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll
FF - component: c:\program files\Common Files\DVDVideoSoft\Dll\FFContextMenuY\components\FFContextMenu.dll
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_
everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a
s_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
ShellExecuteHooks-{3ccae3b2-9dc3-4f1f-998d-6f9e21bdaef9} - (no file)
MSConfigStartUp-MCAgentExe - c:\progra~1\mcafee.com\agent\mcagent.exe
MSConfigStartUp-MCUpdateExe - c:\progra~1\mcafee.com\agent\McUpdate.exe
MSConfigStartUp-MPFEXE - c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
MSConfigStartUp-MSKDetectorExe - c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe
MSConfigStartUp-OASClnt - c:\program files\McAfee.com\VSO\oasclnt.exe
MSConfigStartUp-Odegetabejuyoku - c:\windows\ijugirifad.dll
MSConfigStartUp-Steam - c:\documents and settings\owner\desktop\steam\steam.exe
MSConfigStartUp-VirusScan Online - c:\progra~1\mcafee.com\vso\mcvsshld.exe
MSConfigStartUp-VSOCheckTask - c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe
AddRemove-ArmA 2 - h:\files\Games\Bohemia Interactive\UnInstall.exe
AddRemove-CrosuS - c:\program files\CrosuS\uninstall.exe
AddRemove-Logon Loader - c:\program files\Logon Loader\uninst.exe
AddRemove-NSSSetupTemp.{3FADAA19-E595-44CA-A072-58B6B0851768} - c:\program files\Common Files\Symantec Shared\NSSSetup\{3FADAA19-E595-44CA-A072-58B6B0851768}_2_0_0\NSSSetup.exe
AddRemove-SSIII Solo Ultratus - c:\program files\SSIII Solo Ultratus\uninst.exe
AddRemove-Steam - c:\docume~1\Owner\Desktop\steam\UNWISE.EXE
AddRemove-Steam App 17500 - c:\documents and settings\owner\desktop\steam\steam.exe
AddRemove-Steam App 205 - c:\documents and settings\Owner\Desktop\steam\steam.exe
AddRemove-Steam App 218 - c:\documents and settings\owner\desktop\steam\steam.exe
AddRemove-Steam App 33900 - c:\documents and settings\Owner\Desktop\steam\steam.exe
AddRemove-Steam App 4000 - c:\documents and settings\Owner\Desktop\steam\steam.exe
AddRemove-Steam App 5 - c:\documents and settings\owner\desktop\steam\steam.exe
AddRemove-Steam App 550 - c:\documents and settings\Owner\Desktop\steam\steam.exe
AddRemove-Steam App 70 - c:\documents and settings\owner\desktop\steam\steam.exe
AddRemove-Wyvern Client - c:\progra~1\Java\JRE15~1.0_0\bin\javaw.exe
AddRemove-Wyvern Map Editor - c:\progra~1\Java\JRE15~1.0_0\bin\javaw.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-30 15:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3622105252-4212685542-302905379-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ee,51,dc,78,11,1e,2d,6e,32,46,b3,96,8a,47,b1,23,24,da,51,8c,e6,d8,a6,
43,44,8d,09,e2,25,b1,e1,2b,09,e2,91,16,b3,16,83,ed,aa,e1,7a,cd,35,e4,a2,fd,\
"??"=hex:d2,8a,3d,7f,d6,ee,ff,ab,38,51,7b,8c,dc,d7,d2,0c
[HKEY_USERS\S-1-5-21-3622105252-4212685542-302905379-1003\Software\SecuROM\License information*]
"datasecu"=hex:79,50,6f,67,d0,1b,76,a1,5c,00,75,9c,a3,1a,39,64,45,51,4b,4e,86,
48,5a,7e,d4,ec,62,74,5f,97,b7,e1,34,15,2e,99,21,b2,24,7a,ae,dd,e0,f1,ed,08,\
"rkeysecu"=hex:7d,40,10,cb,c7,39,e0,67,0a,69,a8,47,07,da,5b,5c
[HKEY_LOCAL_MACHINE\software\Microsoft\MS Optimization\JKWL]
@DACL=(02 0000)
"LU"="
http://www.google.com/search?hl=en&q=&rlz=1R2GWYE_en&aq=f&oq="
"CT"=dword:00000001
"LT"=hex:59,35,4e,0e,31,d6,c9,01
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1568)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-06-30 15:42:44
ComboFix-quarantined-files.txt 2010-06-30 19:42
Pre-Run: 24,838,205,440 bytes free
Post-Run: 24,280,346,624 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
Current=2 Default=2 Failed=3 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 3A96BF718C1CFC8BF4B59B073C75F974
]