Dear Evilfantasy,
Many thanks for the instructions. Here is the log file as requested.
Regards,
garddfon
ComboFix 09-09-20.01 - simonp 21/09/2009 15:43.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.305 [GMT 1:00]
Running from: c:\documents and settings\simonp\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\simonp\Desktop\CFScript.txt
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
"c:\windows\svchast.exe"
"c:\windows\system32\drivers\hxwtqzjh.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\messenger
c:\program files\messenger\custsat.dll
c:\program files\messenger\logowin.gif
c:\program files\messenger\lvback.gif
c:\program files\messenger\msgsc.dll
c:\program files\messenger\msgslang.dll
c:\program files\messenger\msmsgs.exe
c:\program files\messenger\newalert.wav
c:\program files\messenger\newemail.wav
c:\program files\messenger\online.wav
c:\program files\messenger\type.wav
c:\program files\messenger\xpmsgr.chm
c:\windows\Installer\15af4d.msi
c:\windows\Installer\1c4d5.msi
c:\windows\Installer\59923.msi
c:\windows\Installer\807ce.msi
c:\windows\Installer\aaf8d.msi
c:\windows\Installer\b36f6c.msp
c:\windows\Installer\debc.msi
c:\windows\Installer\e1b68.msi
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ANTIPPRO2009_100
-------\Legacy_HAKGU
-------\Service_AntipPro2009_100
-------\Service_hakgu
((((((((((((((((((((((((( Files Created from 2009-08-21 to 2009-09-21 )))))))))))))))))))))))))))))))
.
2009-09-21 11:48 . 2009-09-21 11:47 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-02 17:45 . 2009-09-03 11:58 -------- d-----w- C:\$AVG8.VAULT$
2009-09-02 17:05 . 2009-09-02 17:05 -------- d-----w- c:\documents and settings\simonp\Local Settings\Application Data\AVG Security Toolbar
2009-09-02 16:50 . 2009-09-02 16:50 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-02 16:50 . 2009-09-04 12:36 -------- d-----w- c:\documents and settings\simonp\Application Data\SUPERAntiSpyware.com
2009-09-02 16:50 . 2009-09-04 12:32 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-02 14:31 . 2009-09-02 14:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-09-02 14:31 . 2009-09-02 14:31 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-09-02 14:31 . 2009-09-02 14:31 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-02 14:31 . 2009-09-02 14:31 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-02 14:31 . 2009-09-02 14:31 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-02 14:31 . 2009-09-02 14:31 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-02 14:31 . 2009-09-21 11:30 -------- d-----w- c:\windows\system32\drivers\Avg
2009-09-02 14:31 . 2009-09-02 14:31 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-09-02 14:29 . 2009-09-02 14:29 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2009-09-02 14:29 . 2009-09-02 14:29 29208 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-21 14:53 . 2008-10-27 16:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Kontiki
2009-09-21 14:52 . 2009-08-19 14:23 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-21 14:36 . 2007-07-11 10:14 -------- d-----w- c:\documents and settings\simonp\Application Data\Skype
2009-09-21 12:08 . 2006-03-20 21:41 -------- d-----w- c:\program files\Java
2009-09-21 11:46 . 2007-05-29 11:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-20 21:38 . 2009-01-06 13:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-02 14:29 . 2009-08-20 10:57 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-19 17:30 . 2009-08-19 17:30 -------- d-----w- c:\documents and settings\simonp\Application Data\Malwarebytes
2009-08-19 16:51 . 2009-08-19 16:51 -------- d-----w- c:\program files\CCleaner
2009-08-19 16:47 . 2009-05-03 11:39 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-08-19 16:46 . 2009-08-19 16:46 -------- d-----w- c:\documents and settings\simonp\Application Data\AVG8
2009-08-19 16:04 . 2009-08-19 16:01 -------- d-----w- c:\program files\TestMW
2009-08-19 16:01 . 2009-08-19 16:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-19 15:58 . 2009-08-19 15:58 -------- d-----w- c:\program files\Inncognito
2009-08-18 20:31 . 2009-08-18 20:31 -------- d-----w- c:\documents and settings\simonp\Application Data\McAfee
2009-08-05 09:11 . 2004-08-11 17:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 12:36 . 2009-08-19 16:01 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 12:36 . 2009-08-19 16:01 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-01 10:28 . 2009-05-08 21:53 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-08-01 10:24 . 2006-03-27 21:11 52304 ----a-w- c:\documents and settings\simonp\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-01 00:56 . 2009-08-01 00:56 -------- d-----w- c:\program files\MSBuild
2009-08-01 00:56 . 2009-08-01 00:56 -------- d-----w- c:\program files\Reference Assemblies
2009-07-22 16:23 . 2009-07-22 16:23 74760 ----a-w- c:\windows\system32\drivers\UniversalDD.sys
2009-07-22 16:23 . 2009-07-22 16:23 25608 ----a-w- c:\windows\system32\drivers\AVGIDSErHr.sys
2009-07-17 18:55 . 2004-08-11 17:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 09:08 . 2004-08-11 17:00 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2004-08-11 17:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-11 17:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-11 17:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 18:36 . 2004-08-11 17:00 95744 ----a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2004-08-11 17:00 661504 ----a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2004-08-11 17:00 517120 ----a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2004-08-11 17:00 48640 ----a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2004-08-11 17:00 471552 ----a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2004-08-11 17:00 47104 ----a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2004-08-11 17:00 225280 ----a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2004-08-11 17:00 186880 ----a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2004-08-11 17:00 177152 ----a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2004-08-11 17:00 16896 ----a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2004-08-11 17:00 138240 ----a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 2004-08-11 17:00 123392 ----a-w- c:\windows\system32\mqrtdep.dll
2008-05-20 14:55 . 2008-05-20 14:55 604 ---ha-w- c:\program files\STLL Notifier
2008-03-14 15:28 . 2008-03-14 15:13 1941 ----a-w- c:\program files\uninstal.log
2009-04-28 18:45 . 2006-10-06 00:41 88 --sh--r- c:\windows\system32\107A2D91F8.sys
2009-01-09 13:54 . 2006-03-27 21:10 104 --sh--r- c:\windows\system32\F8912D7A10.sys
2009-04-28 18:45 . 2006-03-27 21:10 6736 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 08:56 1062144 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2007-07-02 23237416]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="1 (0x1)" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-19 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-19 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-21 149280]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2005-12-15 839680]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-05-11 200069]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-02-23 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-04-13 155648]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-02-09 106496]
"4oD"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2008-10-28 181544]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-02 2007832]
"AVGIDS"="c:\program files\AVG\AVG8\IdentityProtection\agent\bin\AVGIDSUI.exe" [2009-07-22 1600008]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-11-16 397312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-3-20 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-02 14:31 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 AVGIDSErHr;AVGIDSErHr;c:\windows\system32\drivers\AVGIDSErHr.sys [22/07/2009 17:23 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [02/09/2009 15:31 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [02/09/2009 15:31 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [02/09/2009 15:31 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [02/09/2009 15:30 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [02/09/2009 15:30 297752]
R2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [02/09/2009 15:30 1370488]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSAgent.exe [22/07/2009 17:23 5641736]
R2 AVGIDSWatcher;AVGIDSWatcher;c:\program files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSWatcher.exe [22/07/2009 17:23 571912]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [28/10/2008 16:42 156968]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 18:19 13592]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [02/09/2009 15:29 29208]
R3 AVGIDSDriver;AVGIDSDriver;c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_XP\AVGIDSDriver.sys [22/07/2009 17:23 121352]
R3 AVGIDSFilter;AVGIDSFilter;c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_XP\AVGIDSFilter.sys [22/07/2009 17:23 30216]
R3 AVGIDSShim;AVGIDSShim;c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_XP\AVGIDSShim.sys [22/07/2009 17:23 27232]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [27/03/2006 18:27 33792]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [02/09/2009 15:29 29208]
S3 ffPro26IO_1394;ffPro26IO_1394;c:\windows\system32\drivers\ffPro26IO_1394.sys [10/04/2008 15:48 116736]
S3 ffPro26IO_avs;ffPro26IO_avs;c:\windows\system32\drivers\ffPro26IO_avs.sys [10/04/2008 15:48 44544]
S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\synasUSB.sys [27/03/2006 18:27 16896]
S3 UKS11LDR;M-Audio USB Keystation Loader;c:\windows\system32\drivers\uks11ldr.sys [28/03/2006 09:29 13504]
S3 US122;US122 Driver;c:\windows\system32\drivers\US122.sys [23/04/2009 11:50 131968]
S3 US122DL;US122 Firmware Downloader;c:\windows\system32\drivers\US122DL.sys [30/07/2004 12:02 18304]
S3 Us122WdmService;US122 Wdm Audio;c:\windows\system32\drivers\US122Wdm.sys [23/04/2009 11:50 39168]
S3 USBKT1X1;M-Audio USB Keystation;c:\windows\system32\drivers\usbkt1x1.sys [28/03/2006 09:29 22304]
.
Contents of the 'Scheduled Tasks' folder
2009-09-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-06 22:28]
2009-09-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
2009-09-20 c:\windows\Tasks\User_Feed_Synchronization-{74E648E9-0735-49EE-BE00-E2FDFD544E18}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
2009-09-21 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-03-25 22:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = hxxp://www.hackerwatch.org/probe/?lips=c0a80067
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\documents and settings\simonp\Application Data\Mozilla\Firefox\Profiles\an2kcd0c.default\
FF - prefs.js: browser.search.selectedEngine - Google.co.uk
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPBOARDS.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Anarchy Effects VST v1.3 - c:\progra~1\STEINB~1\VSTPLU~1\ANARCH~2\UNWISE.EXE
AddRemove-Anarchy Rhythms VST v1.0 - c:\progra~1\STEINB~1\VSTPLU~1\ANARCH~1\UNWISE.EXE
AddRemove-HijackThis - c:\program files\Inncognito\Incog\HijackThis.exe
AddRemove-Native Instruments Absynth v3.0.2 - c:\progra~1\ABSYNT~1\UNWISE.EXE
AddRemove-Ohmforce Hematohm VST v1.20 - c:\progra~1\STEINB~1\VSTPLU~1\Hematohm\UNWISE.EXE
AddRemove-Ohmforce Mobilohm VST v1.04 - c:\progra~1\STEINB~1\VSTPLU~1\Ohmforce\Mobilohm\UNWISE.EXE
AddRemove-Ohmforce OhmBoyz VST v1.40 - c:\progra~1\STEINB~1\VSTPLU~1\OhmBoyz\UNWISE.EXE
AddRemove-Ohmforce Predatohm VST v1.30 - c:\progra~1\STEINB~1\VSTPLU~1\PREDAT~1\UNWISE.EXE
AddRemove-Ohmforce Quad Frohmage Pro VST v1.10 - c:\progra~1\STEINB~1\VSTPLU~1\OHMFOR~1\QUADFR~1\UNWISE.EXE
AddRemove-Prosoniq Morph VST v1.0 - c:\progra~1\STEINB~1\VSTPLU~1\PROSON~1\UNWISE.EXE
AddRemove-Warp VST V1.0 - c:\progra~1\STEINB~1\VSTPLU~1\WARPVS~1.0\UNWISE.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-21 15:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\TEMP\TMP000000294AF21BCF2303176A 524288 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-770456451-3562159303-2418692189-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1727FC36-5D3D-4896-9DEE-AFE8A6A530BF}\Version*Version]
"Version"=hex:ac,6b,4e,f9,2e,07,46,fc,be,30,0c,b0,01,30,18,29,be,30,0c,b0,01,
30,18,29,be,30,0c,b0,01,30,18,29,be,30,0c,b0,01,30,18,29,be,30,0c,b0,01,30,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(328)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\Kontiki\KService.exe
c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSMonitor.exe
c:\progra~1\MICROS~3\rapimgr.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2009-09-21 16:00 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-21 15:00
Pre-Run: 20,419,534,848 bytes free
Post-Run: 20,494,442,496 bytes free
309 --- E O F --- 2009-08-18 09:29