ComboFix Log:
ComboFix 10-09-12.03 - Whitney 09/13/2010 3:03.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.1109 [GMT -7:00]
Running from: c:\users\Whitney\Desktop\ComboFix.exe
Command switches used :: c:\users\Whitney\Desktop\CFScript.txt
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FILE ::
"c:\programdata\comsnap32.dll"
"c:\users\Whitney\AppData\Local\Temp\CVGWULIWOJ.exe"
"c:\users\Whitney\AppData\Roaming\1F39.tmp"
"c:\users\Whitney\AppData\Roaming\2043.tmp"
"c:\users\Whitney\AppData\Roaming\5022.tmp"
"c:\users\Whitney\AppData\Roaming\E336.tmp"
"c:\users\Whitney\AppData\Roaming\E337.tmp"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\comsnap32.dll
c:\users\Whitney\AppData\Roaming\1F39.tmp
c:\users\Whitney\AppData\Roaming\2043.tmp
c:\users\Whitney\AppData\Roaming\5022.tmp
c:\users\Whitney\AppData\Roaming\E336.tmp
c:\users\Whitney\AppData\Roaming\E337.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AHNRPTTFFREGFNT
-------\Service_AhnRptTfFRegFNT
-------\Service_CVGWULIWOJ
((((((((((((((((((((((((( Files Created from 2010-08-13 to 2010-09-13 )))))))))))))))))))))))))))))))
.
2010-09-13 10:15 . 2010-09-13 10:21 -------- d-----w- c:\users\Whitney\AppData\Local\temp
2010-09-13 10:15 . 2010-09-13 10:15 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-13 10:15 . 2010-09-13 10:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-11 17:20 . 2010-09-11 17:20 -------- d-----w- c:\program files\Trend Micro
2010-09-10 18:58 . 2010-09-10 18:58 -------- d-----w- c:\users\Whitney\AppData\Roaming\SUPERAntiSpyware.com
2010-09-10 18:58 . 2010-09-10 18:58 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-09-10 18:58 . 2010-09-10 18:58 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-09-10 18:27 . 2010-09-10 18:27 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-09-09 03:13 . 2010-09-09 03:14 -------- d-----w- c:\programdata\PrevxCSI
2010-09-06 22:59 . 2010-09-06 22:59 -------- d-----w- c:\programdata\Electronic Arts
2010-09-06 22:58 . 2010-09-06 23:00 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-09-06 22:56 . 2010-09-06 22:56 -------- d-----w- c:\program files\Electronic Arts
2010-09-06 22:45 . 2010-09-06 22:45 1180 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2010-09-06 22:04 . 2010-09-06 22:04 -------- d-----w- c:\program files\EA Games
2010-09-06 18:04 . 2010-09-06 18:04 -------- d-----w- c:\programdata\Media Center Programs
2010-09-06 17:53 . 2010-09-06 17:53 -------- d-----w- c:\program files\Codemasters
2010-09-02 01:29 . 2010-09-02 01:29 -------- d-----w- c:\program files\iPod
2010-08-29 07:07 . 2010-08-29 07:07 -------- d-----w- c:\users\Whitney\AppData\Roaming\LolClient
2010-08-29 04:42 . 2008-07-31 17:41 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2010-08-29 04:42 . 2008-07-31 17:40 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2010-08-29 04:42 . 2008-07-12 15:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-08-29 04:42 . 2008-07-12 15:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-08-29 04:42 . 2008-07-12 15:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-08-29 04:36 . 2010-08-29 04:36 -------- d-----w- C:\Riot Games
2010-08-27 07:03 . 2010-08-27 07:31 -------- d-----w- c:\program files\SWGANH Client
2010-08-27 06:32 . 2010-08-27 06:32 -------- d-----w- c:\users\Whitney\AppData\Local\LaunchpadEnhanced
2010-08-26 08:26 . 2010-08-27 07:05 -------- d-----w- C:\SWGEmu
2010-08-26 08:26 . 2010-08-26 08:26 -------- d-----w- c:\users\Whitney\AppData\Roaming\LPECommon
2010-08-26 08:25 . 2010-08-26 08:26 -------- d-----w- c:\program files\Launchpad Enhanced
2010-08-26 08:24 . 2010-09-06 22:44 -------- d-----w- c:\users\Whitney\AppData\Local\Downloaded Installations
2010-08-26 08:12 . 2010-08-27 07:25 -------- d-----w- c:\program files\StarWarsGalaxies
2010-08-25 21:27 . 2010-08-25 21:27 -------- d-----w- c:\program files\Sony
2010-08-19 07:31 . 2010-08-19 07:31 -------- d-----w- C:\$AVG
2010-08-19 07:17 . 2010-09-13 01:58 -------- d-----w- c:\windows\system32\drivers\Avg
2010-08-19 07:17 . 2010-08-19 07:17 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-08-19 07:15 . 2010-08-19 07:15 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-08-19 07:15 . 2010-08-19 07:15 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-08-19 07:14 . 2010-08-19 07:14 -------- d-----w- c:\program files\AVG
2010-08-19 07:13 . 2010-09-09 04:29 -------- d-----w- c:\programdata\avg9
2010-08-19 06:48 . 2010-08-19 17:05 -------- d-----w- c:\users\Whitney\AppData\Roaming\FrostWire
2010-08-17 08:43 . 2010-08-17 08:50 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-08-16 17:00 . 2010-08-16 17:00 -------- d-----w- c:\program files\Common Files\Skype
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-13 09:51 . 2007-04-19 18:30 -------- d-----w- c:\programdata\Symantec
2010-09-13 09:51 . 2007-04-19 18:30 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-09-13 09:49 . 2007-04-19 19:43 -------- d-----w- c:\program files\Java
2010-09-13 09:49 . 2007-04-19 19:43 -------- d-----w- c:\program files\Common Files\Java
2010-09-13 09:46 . 2008-02-19 03:31 -------- d-----w- c:\users\Whitney\AppData\Roaming\Skype
2010-09-13 09:44 . 2008-02-19 03:33 -------- d-----w- c:\users\Whitney\AppData\Roaming\skypePM
2010-09-12 21:24 . 2007-06-27 03:02 -------- d-----w- c:\programdata\Viewpoint
2010-09-11 17:20 . 2010-09-11 17:20 388096 ----a-r- c:\users\Whitney\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-10 18:58 . 2010-09-10 18:58 63488 ----a-w- c:\users\Whitney\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-09-10 18:58 . 2010-09-10 18:58 52224 ----a-w- c:\users\Whitney\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-09-10 18:58 . 2010-09-10 18:58 117760 ----a-w- c:\users\Whitney\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-09-10 18:55 . 2008-01-01 01:17 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-08 07:30 . 2009-07-08 07:06 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-06 22:59 . 2010-09-06 23:00 53632 ----a-w- c:\users\Whitney\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-09-06 22:59 . 2010-09-06 22:58 53632 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-09-06 22:57 . 2007-04-19 18:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-06 18:18 . 2010-01-07 20:20 -------- d-----w- c:\program files\AGEIA Technologies
2010-09-06 18:18 . 2010-01-07 20:20 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-09-06 18:06 . 2010-01-07 20:36 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-09-02 01:30 . 2010-06-28 03:33 -------- d-----w- c:\program files\iTunes
2010-09-02 01:28 . 2007-09-21 02:35 -------- d-----w- c:\program files\Common Files\Apple
2010-09-02 01:21 . 2010-09-02 01:21 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-08-29 04:00 . 2008-12-29 05:09 -------- d-----w- c:\programdata\PMB Files
2010-08-19 06:51 . 2010-08-19 06:51 0 ----a-w- c:\users\Whitney\AppData\Roaming\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
2010-08-18 15:10 . 2009-01-08 08:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-16 17:00 . 2008-02-19 03:30 -------- d-----r- c:\program files\Skype
2010-08-16 17:00 . 2008-02-19 03:30 -------- d-----w- c:\programdata\Skype
2010-08-13 10:03 . 2007-04-19 18:46 -------- d-----w- c:\programdata\Microsoft Help
2010-08-13 10:02 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-05 21:04 . 2010-03-22 05:51 765952 ----a-w- c:\programdata\NexonUS\NGM\NGMDll.dll
2010-08-05 16:52 . 2007-04-19 18:14 -------- d-----w- c:\program files\Hewlett-Packard
2010-07-17 12:00 . 2010-06-28 04:47 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-27 20:49 . 2007-09-23 00:31 680 ----a-w- c:\users\Whitney\AppData\Local\d3d9caps.dat
2010-06-26 06:05 . 2010-08-12 22:17 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-08-12 22:17 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-08-12 22:17 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-08-12 22:17 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-06-21 13:37 . 2010-08-12 22:17 2037760 ----a-w- c:\windows\system32\win32k.sys
2010-06-18 17:31 . 2010-08-12 22:17 36864 ----a-w- c:\windows\system32\rtutils.dll
2010-06-18 15:04 . 2010-08-12 22:17 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 15:04 . 2010-08-12 22:17 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-06-16 16:04 . 2010-08-12 22:17 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-03-20 1773568]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-03-22 2937528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-02-26 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-02-26 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-02-26 133912]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-03-29 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 159744]
"HostManager"="c:\program files\Common Files\AOL\1182913076\ee\AOLSoftware.exe" [2006-09-26 50736]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-04 111936]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"hpqSRMon"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-19 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-08-19 2065760]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
c:\users\Whitney\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-08-19 216400]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-08-19 308136]
S2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\supportsoft\bin\sprtlisten.exe [2008-01-08 1213728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-08-24 c:\windows\Tasks\HPCeeScheduleForWhitney.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-04-19 21:23]
2010-09-13 c:\windows\Tasks\User_Feed_Synchronization-{B03C6987-6114-4E67-AC33-138A9BE347B4}.job
- c:\windows\system32\msfeedssync.exe [2010-08-12 04:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.hotmail.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {226ACC34-3194-40E2-9AE8-834FCFE9E80D} - hxxp://aolsvc.aol.com/onlinegames/free-trial-mystery-of-shark-island/MysteryOfSharkIslandWeb.1.0.0.8.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-141832275-3565902227-3691053196-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:3b,17,8f,e3,71,c2,6e,70,b4,80,33,b5,11,0a,d4,4d,48,8d,aa,1e,18,09,21,
8a,6b,57,89,24,26,5d,93,8e,99,5c,ff,ed,74,b8,da,8f,8d,04,3e,23,96,94,f7,81,\
"??"=hex:ec,5c,64,33,3e,25,07,8d,a9,be,f0,f5,44,b0,15,dd
[HKEY_USERS\S-1-5-21-141832275-3565902227-3691053196-1000\Software\SecuROM\License information*]
"datasecu"=hex:a0,e1,d1,53,4b,89,9f,98,77,58,f3,6d,69,ff,51,57,6b,0a,4d,03,be,
42,a4,76,1e,bb,80,62,20,c3,3c,ee,30,2a,42,87,c7,7e,e6,6b,a9,7a,f9,70,ed,52,\
"rkeysecu"=hex:95,15,48,c9,66,df,77,db,9c,3e,96,07,b9,3c,d8,c6
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\HP\QuickPlay\Kernel\TV\CLSched.exe
c:\program files\AVG\AVG9\avgtray.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
c:\windows\ehome\ehmsas.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\program files\Hewlett-Packard\HP Advisor\SSDK04.exe
c:\windows\system32\WUDFHost.exe
.
**************************************************************************
.
Completion time: 2010-09-13 03:32:01 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-13 10:31
ComboFix2.txt 2010-09-12 21:52
ComboFix3.txt 2010-09-10 17:37
Pre-Run: 44,194,054,144 bytes free
Post-Run: 49,908,961,280 bytes free
- - End Of File - - F2A8F3FFDCC5B4947CB8CCA6246E4064
----------
Comps running a little faster, and the net doesn't seem to be thinking about every little thing before loading
By the by, sorry for the late reply. Went out with some friends then was too tired when I got home to post.