ComboFix 10-01-20.05 - Gregory 01/21/2010 4:41.9.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1625 [GMT -8:00]
Running from: c:\documents and settings\Gregory\Desktop\123ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100121-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((( Files Created from 2009-12-21 to 2010-01-21 )))))))))))))))))))))))))))))))
.
2010-01-20 00:48 . 2010-01-20 00:48 -------- d-----w- c:\documents and settings\Gregory\Application Data\Malwarebytes
2010-01-20 00:48 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-20 00:48 . 2010-01-20 00:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-20 00:48 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-20 00:48 . 2010-01-20 00:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-19 21:16 . 2010-01-19 21:16 52224 ----a-w- c:\documents and settings\Gregory\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-19 21:16 . 2010-01-19 21:16 117760 ----a-w- c:\documents and settings\Gregory\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-19 21:07 . 2010-01-19 21:07 -------- d-----w- c:\program files\CCleaner
2010-01-19 12:26 . 2010-01-19 12:26 -------- d-----w- c:\documents and settings\Gregory\Application Data\NeroDCTemplates
2010-01-19 06:33 . 2010-01-19 06:33 -------- d-----w- c:\documents and settings\Administrator\Application Data\DivX
2010-01-19 04:05 . 2010-01-19 04:05 -------- d-----w- c:\program files\VirusTotalUploader2
2010-01-16 03:41 . 2009-10-05 20:34 796400 ----a-w- c:\documents and settings\Gregory\Application Data\Mozilla\Firefox\Profiles\dm7jno9d.default\extensions\
[email protected]\components\KeyScramblerIE.dll
2010-01-16 03:39 . 2010-01-16 03:39 -------- d-----w- c:\program files\KeyScrambler
2010-01-16 03:39 . 2009-10-04 21:33 115312 ----a-w- c:\windows\system32\drivers\keyscrambler.sys
2010-01-15 18:09 . 2010-01-15 18:09 -------- d-----w- C:\New Folder
2010-01-13 09:23 . 2010-01-13 10:57 -------- d-----w- c:\documents and settings\Gregory\photos archive
2010-01-13 08:37 . 2010-01-13 08:37 -------- d-----w- C:\Documents
2010-01-12 21:15 . 2010-01-12 21:15 -------- d-----w- C:\$WIN_NT$.~BT
2010-01-09 18:12 . 2010-01-09 18:13 -------- d-----w- c:\program files\WinPcap
2010-01-07 20:44 . 2010-01-07 20:44 -------- d-----w- c:\program files\Common Files\SWF Studio
2010-01-07 20:43 . 2010-01-07 20:43 -------- d-----w- c:\program files\The Action Machine
2010-01-06 19:49 . 2010-01-06 19:49 -------- d-----w- c:\documents and settings\Gregory\Local Settings\Application Data\Scansoft
2010-01-05 20:31 . 2010-01-05 20:36 -------- d-----w- c:\documents and settings\Gregory\dwhelper
2010-01-05 20:16 . 2010-01-05 20:16 -------- d-----w- c:\program files\ConvertHelper
2010-01-05 03:34 . 2010-01-05 03:34 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2010-01-05 03:34 . 2010-01-21 11:00 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-05 03:33 . 2010-01-05 03:33 -------- d-----w- c:\documents and settings\Gregory\Application Data\Nuance
2010-01-05 03:30 . 2010-01-05 03:30 -------- d-----w- c:\documents and settings\All Users\Application Data\ScanSoft
2010-01-05 03:30 . 2010-01-05 03:30 -------- d-----w- c:\program files\Common Files\ScanSoft Shared
2010-01-05 03:30 . 2010-01-05 03:30 -------- d-----w- c:\program files\Common Files\Nuance
2010-01-05 03:30 . 2010-01-05 03:30 -------- d-----w- c:\program files\Nuance
2010-01-05 03:30 . 2010-01-05 03:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Nuance
2010-01-05 03:29 . 2010-01-05 03:34 -------- d-----w- c:\windows\speech
2010-01-04 18:43 . 2010-01-04 21:32 -------- d-----w- c:\windows\BDOSCAN8
2009-12-31 15:55 . 2009-06-30 17:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-12-31 15:55 . 2009-12-31 15:55 -------- d-----w- c:\program files\Panda Security
2009-12-28 02:29 . 2009-12-28 02:29 -------- d-----w- c:\program files\Common Files\DivX Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-21 12:37 . 2008-09-16 17:09 -------- d-----w- c:\documents and settings\Gregory\Application Data\Skype
2010-01-21 10:09 . 2008-10-16 05:56 -------- d-----w- c:\program files\DScaler
2010-01-21 08:05 . 2008-03-26 22:09 -------- d-----w- c:\documents and settings\Gregory\Application Data\skypePM
2010-01-21 01:04 . 2008-09-15 21:21 71720 ----a-w- c:\documents and settings\Gregory\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-19 21:15 . 2009-11-11 04:23 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-19 21:15 . 2009-11-11 04:23 -------- d-----w- c:\documents and settings\Gregory\Application Data\SUPERAntiSpyware.com
2010-01-19 21:15 . 2009-04-05 06:11 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-19 21:12 . 2007-08-21 07:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-19 04:46 . 2008-09-21 05:41 -------- d-----w- c:\program files\Trend Micro
2010-01-19 03:46 . 2009-11-11 04:03 -------- d-----w- c:\program files\Everything
2010-01-18 19:30 . 2010-01-05 05:11 1833 ----a-w- c:\documents and settings\Gregory\Application Data\SAS7_000.DAT
2010-01-15 09:38 . 2009-04-22 07:47 -------- d-----w- c:\program files\Bonjour
2010-01-13 09:24 . 2008-08-20 18:45 -------- d-----w- c:\documents and settings\Gregory\Application Data\gtk-2.0
2010-01-08 16:55 . 2007-08-21 05:15 -------- d-----w- c:\program files\a-squared Free
2010-01-05 03:30 . 2007-03-18 10:41 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-04 10:34 . 2007-03-22 06:51 -------- d-----w- c:\program files\Webteh
2010-01-03 01:02 . 2007-08-21 07:49 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-31 07:23 . 2008-09-27 20:34 -------- d-----w- c:\program files\Replay Media Catcher
2009-12-30 00:31 . 2008-09-27 20:36 156672 ----a-w- c:\windows\system32\rmc_fixasf.exe
2009-12-30 00:31 . 2008-09-27 20:36 237568 ----a-w- c:\windows\system32\rmc_rtspdl.dll
2009-12-30 00:31 . 2008-09-27 20:35 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL
2009-12-28 02:29 . 2007-03-22 07:02 -------- d-----w- c:\program files\DivX
2009-12-20 11:43 . 2009-06-04 06:39 -------- d-----w- c:\program files\The KMPlayer
2009-12-16 05:58 . 2004-08-04 12:00 2864 ----a-w- c:\windows\system32\winsock.dll
2009-12-08 07:27 . 2009-12-03 02:27 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-04 00:40 . 2009-12-04 00:40 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-04 00:40 . 2007-03-20 21:59 -------- d-----w- c:\program files\Java
2009-12-04 00:40 . 2009-12-04 00:40 152576 ----a-w- c:\documents and settings\Gregory\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-04 00:38 . 2009-12-04 00:38 79488 ----a-w- c:\documents and settings\Gregory\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-03 02:21 . 2008-08-19 16:56 -------- d-----w- c:\program files\MagicDisc
2009-12-03 02:20 . 2009-12-03 02:20 577536 ----a-w- c:\windows\SOUNDMAN.EXE
2009-12-02 06:05 . 2008-08-19 18:15 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-11-24 23:54 . 2009-12-12 22:11 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-12-12 22:11 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-12-12 22:11 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-12-12 22:11 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-12-12 22:11 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-12-12 22:11 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-12-12 22:11 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-12-12 22:11 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-12-12 22:11 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-23 08:40 . 2009-05-03 17:17 -------- d-----w- c:\program files\phpDesigner
2009-11-21 08:00 . 2009-11-21 08:00 46 ----a-w- c:\windows\system32\DonationCoder_urlsnooper_InstallInfo.dat
2009-11-21 08:00 . 2009-11-21 08:00 142096 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-11-21 08:00 . 2009-11-21 08:00 12872 ----a-w- c:\windows\system32\bootdelete.exe
2009-11-13 22:51 . 2009-11-13 22:51 25992 ----a-w- c:\windows\system32\pgdfgsvc.exe
2009-10-31 16:31 . 2009-11-11 00:16 926720 ----a-w- c:\windows\system32\MyDefragScreenSaver.exe
2009-10-28 17:58 . 2009-11-11 00:16 93696 ----a-w- c:\windows\system32\MyDefragScreenSaver.scr
2009-03-06 20:06 . 2009-03-06 20:06 27976 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2009-03-06 20:06 . 2009-03-06 20:06 126360 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
.
------- Sigcheck -------
[-] 2008-09-23 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\TCPIP.SYS
[-] 2008-09-23 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\TCPIP.SYS
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\TCPIP.SYS
[-] 2007-10-30 . 90CAFF4B094573449A0872A0F919B178 . 360064 . . [5.1.2600.3244] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[-] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[-] 2007-03-23 . 8D8949936913B041C6A0E184FBF1030B . 359808 . . [5.1.2600.2892] . . c:\windows\$NtUninstallKB941644$\tcpip.sys
[-] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[7] 2004-08-04 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB917953$\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AutoSizer"="c:\program files\AutoSizer\AutoSizer.exe" [2009-04-08 131072]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-15 623992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2007-08-11 292152]
"nwiz"="nwiz.exe" [2009-03-27 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-01-23 81920]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-19 76304]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2008-09-10 1655552]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.EXE" [2005-02-17 221184]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NVMCTRAY.DLL" [2009-03-27 86016]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-6 809488]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-19 07:30 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [12/31/2009 7:55 AM 28552]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [12/12/2009 2:11 PM 114768]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [9/10/2008 10:07 AM 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [9/10/2008 10:07 AM 24208]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 vcdrom;Virtual CD-ROM Device Driver;c:\installers\winxpvirtualcdcontrolpanel_21\VCdRom.sys [3/3/2009 5:57 AM 8576]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [12/2/2009 6:21 PM 1858144]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/12/2009 2:11 PM 20560]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [4/6/2009 8:57 AM 10384]
R3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\system32\drivers\hcw18bda.sys [8/31/2007 11:13 AM 384896]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [1/15/2010 7:39 PM 115312]
S0 AmdAcpi;AmdAcpi Bus Filter Driver;c:\windows\system32\DRIVERS\AmdAcpi.sys --> c:\windows\system32\DRIVERS\AmdAcpi.sys [?]
S1 amdtools;AMD Special Tools Driver;c:\windows\system32\DRIVERS\amdtools.sys --> c:\windows\system32\DRIVERS\amdtools.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [10/20/2009 10:19 AM 50704]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-02-25 18:12 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-01-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 22:42]
2010-01-21 c:\windows\Tasks\Clean System Memory.job
- c:\windows\system32\CleanMem.exe [2009-11-11 23:22]
2010-01-19 c:\windows\Tasks\NatSpeak Periodic Acoustic Optimization.job
- c:\program files\Nuance\NaturallySpeaking10\Program\schedmgr.exe [2009-03-17 03:45]
2010-01-21 c:\windows\Tasks\NatSpeak Periodic Language Model Optimization.job
- c:\program files\Nuance\NaturallySpeaking10\Program\schedmgr.exe [2009-03-17 03:45]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {05960036-C0EF-42A9-84B2-A10A35E7256A} = 4.2.2.1,4.2.2.2
FF - ProfilePath - c:\documents and settings\Gregory\Application Data\Mozilla\Firefox\Profiles\dm7jno9d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
FF - component: c:\documents and settings\Gregory\Application Data\Mozilla\Firefox\Profiles\dm7jno9d.default\extensions\
[email protected]\components\KeyScramblerIE.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-21 04:47
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(808)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
- - - - - - - > 'explorer.exe'(2896)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
Completion time: 2010-01-21 04:49:58
ComboFix-quarantined-files.txt 2010-01-21 12:49
Pre-Run: 65,431,519,232 bytes free
Post-Run: 65,391,431,680 bytes free
- - End Of File - - C077F035F8190B7930F702759FF88067