alrighty, here they are:
ComboFix 09-11-03.03 - Griffin 11/04/2009 10:12.3.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.3070.1837 [GMT -8:00]
Running from: c:\users\Griffin\Desktop\ComboFix.exe
Command switches used :: c:\users\Griffin\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys --> c:\windows\System32\drivers\atapi.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_pr2apj8b
((((((((((((((((((((((((( Files Created from 2009-10-04 to 2009-11-04 )))))))))))))))))))))))))))))))
.
2009-11-04 18:22 . 2009-11-04 18:24 -------- d-----w- c:\users\Griffin\AppData\Local\temp
2009-11-04 18:22 . 2009-11-04 18:22 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-11-04 18:22 . 2009-11-04 18:22 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-02 23:38 . 2009-11-02 23:41 -------- d-----w- C:\$AVG
2009-11-02 23:38 . 2009-11-02 23:38 -------- d-----w- c:\programdata\avg9
2009-10-29 01:07 . 2009-09-10 15:21 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-29 01:07 . 2009-09-10 15:21 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-16 04:21 . 2009-10-16 04:21 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-10-16 04:16 . 2009-10-16 04:16 -------- d-----w- c:\program files\ffdshow
2009-10-14 23:00 . 2009-09-10 17:30 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-14 23:00 . 2009-08-05 14:22 3597896 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-14 23:00 . 2009-08-05 14:22 3546184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-14 18:23 . 2009-10-14 18:23 -------- d-----w- c:\windows\SQL9_KB970892_ENU
2009-10-14 04:21 . 2009-10-14 04:21 -------- d-----w- c:\users\Griffin\AppData\Local\AVG Security Toolbar
2009-10-14 03:04 . 2009-11-02 23:38 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-14 03:04 . 2009-11-02 23:38 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-14 03:04 . 2009-11-02 23:38 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-14 03:04 . 2009-11-02 23:38 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-14 03:04 . 2009-11-04 18:07 -------- d-----w- c:\windows\system32\drivers\Avg
2009-10-14 03:04 . 2009-10-14 03:05 -------- d-----w- c:\programdata\AVG Security Toolbar
2009-10-14 03:04 . 2009-11-02 23:38 -------- d-----w- c:\program files\AVG
2009-10-14 02:46 . 2009-10-14 02:46 -------- d-----w- c:\programdata\McAfee
2009-10-14 02:33 . 2009-09-04 12:24 61440 ----a-w- c:\windows\system32\msasn1.dll
2009-10-14 02:33 . 2009-09-14 09:44 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-14 02:33 . 2009-04-02 12:37 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-13 21:36 . 2009-10-13 21:36 -------- d-----w- c:\program files\Griffin
2009-10-13 16:45 . 2009-10-13 19:16 -------- d-----w- c:\programdata\SITEguard
2009-10-13 16:44 . 2009-10-15 16:01 -------- d-----w- c:\programdata\STOPzilla!
2009-10-13 16:44 . 2009-10-13 16:44 -------- d-----w- c:\program files\Common Files\iS3
2009-10-13 02:00 . 2009-10-13 02:00 -------- d-----w- c:\windows\CheckSur
2009-10-13 00:24 . 2009-10-13 00:24 -------- d-----w- c:\users\Griffin\AppData\Roaming\Malwarebytes
2009-10-12 23:44 . 2009-10-12 23:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-12 23:23 . 2009-10-12 23:23 -------- d-sh--w- c:\windows\system32\%APPDATA%
2009-10-12 23:22 . 2009-09-10 21:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-12 23:22 . 2009-10-13 21:37 -------- d-----w- c:\program files\g1pictures
2009-10-12 23:22 . 2009-10-12 23:22 -------- d-----w- c:\programdata\Malwarebytes
2009-10-12 23:22 . 2009-09-10 21:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-12 23:19 . 2009-10-12 23:19 0 ----a-w- c:\windows\nsreg.dat
2009-10-12 18:54 . 2009-10-12 18:54 -------- d-----w- c:\programdata\WindowsSearch
2009-10-12 17:50 . 2009-10-14 02:08 -------- d-----w- c:\users\Griffin\AppData\Local\AntivirusPro_2010
2009-10-12 07:50 . 2009-10-12 07:50 118983 ----a-w- c:\windows\zAdBHO.dll
2009-10-12 07:19 . 2009-10-12 07:19 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-10-12 07:18 . 2009-10-12 07:18 107832 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-10-12 07:18 . 2009-10-12 07:18 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-10-12 07:18 . 2009-10-12 07:18 2250024 ----a-w- c:\windows\system32\pbsvc.exe
2009-10-12 07:11 . 2009-10-12 07:11 -------- d-----w- c:\program files\Ubisoft
2009-10-08 19:11 . 2005-05-26 22:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2009-10-08 18:52 . 2009-10-08 18:52 -------- d-----w- C:\Left4Dead
2009-10-08 18:45 . 2009-11-03 16:57 -------- d-----w- c:\program files\Common Files\Steam
2009-10-08 18:45 . 2009-11-04 18:02 -------- d-----w- c:\program files\Steam
2009-10-08 04:03 . 2009-10-08 04:03 -------- d-----w- c:\users\Griffin\AppData\Roaming\Samsung
2009-10-08 01:03 . 2009-10-08 01:03 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-10-07 18:22 . 2003-02-22 01:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-10-07 18:13 . 2009-10-07 18:18 -------- d-----w- c:\windows\system32\Samsung_USB_Drivers
2009-10-07 18:12 . 2009-10-07 18:45 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-10-07 18:12 . 2009-10-07 18:12 -------- d-----w- c:\program files\Samsung
2009-10-07 17:46 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-10-07 17:46 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-10-07 17:46 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-10-07 17:46 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
2009-10-07 17:46 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
2009-10-07 17:46 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2009-10-07 17:46 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
2009-10-06 18:12 . 2009-10-01 17:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-06 18:04 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-06 18:04 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-06 18:04 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-06 18:04 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-06 18:04 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-06 18:04 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-06 18:04 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-06 18:04 . 2009-08-07 02:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-06 18:04 . 2009-08-07 01:44 33792 ----a-w- c:\windows\system32\wuapp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-04 18:01 . 2008-10-26 19:38 -------- d-----w- c:\users\Griffin\AppData\Roaming\DNA
2009-11-03 01:09 . 2008-10-26 19:49 -------- d-----w- c:\users\Griffin\AppData\Roaming\BitTorrent
2009-11-02 23:44 . 2008-09-09 18:44 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-25 16:01 . 2007-06-11 23:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-25 15:53 . 2007-06-12 00:13 -------- d-----w- c:\programdata\WildTangent
2009-10-17 02:02 . 2008-07-31 05:27 -------- d-----w- c:\program files\ATI
2009-10-16 04:22 . 2008-10-17 03:40 -------- d-----w- c:\program files\DivX
2009-10-16 04:04 . 2008-10-20 07:58 -------- d-----w- c:\users\Griffin\AppData\Roaming\DivX
2009-10-15 15:59 . 2009-10-15 15:58 1448 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-10-15 05:36 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-14 18:28 . 2008-07-31 05:08 -------- d-----w- c:\programdata\Microsoft Help
2009-10-14 18:24 . 2008-07-31 05:13 -------- d-----w- c:\program files\Microsoft SQL Server
2009-10-12 07:44 . 2008-08-13 19:30 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-10-12 07:19 . 2009-10-12 07:19 22328 ----a-w- c:\users\Griffin\AppData\Roaming\PnkBstrK.sys
2009-10-12 06:48 . 2008-10-26 19:38 -------- d-----w- c:\program files\DNA
2009-09-25 16:41 . 2008-09-25 08:03 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-09-25 16:41 . 2009-09-25 16:41 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-09-25 16:41 . 2009-09-25 16:41 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-09-25 16:41 . 2009-09-25 16:41 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-09-25 16:41 . 2009-09-25 16:41 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-09-25 16:41 . 2009-09-25 16:41 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-09-25 16:41 . 2009-09-25 16:41 696320 ----a-w- c:\windows\system32\DivX.dll
2009-09-24 02:38 . 2008-07-31 07:31 1356 ----a-w- c:\users\Griffin\AppData\Local\d3d9caps.dat
2009-09-18 17:51 . 2009-09-17 23:48 -------- d-----w- c:\users\Griffin\AppData\Roaming\Skype
2009-09-18 17:48 . 2009-09-17 23:49 -------- d-----w- c:\users\Griffin\AppData\Roaming\skypePM
2009-09-18 00:46 . 2009-04-17 16:05 -------- d-----w- c:\users\Griffin\AppData\Roaming\Apple Computer
2009-09-18 00:06 . 2009-09-18 00:05 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-18 00:06 . 2009-09-18 00:05 -------- d-----w- c:\program files\iTunes
2009-09-18 00:05 . 2009-09-18 00:05 -------- d-----w- c:\program files\iPod
2009-09-18 00:05 . 2009-04-17 15:59 -------- d-----w- c:\program files\Common Files\Apple
2009-09-18 00:04 . 2009-09-18 00:03 -------- d-----w- c:\program files\QuickTime
2009-09-17 23:49 . 2009-09-17 23:49 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-09-17 23:47 . 2009-09-17 23:46 -------- d-----r- c:\program files\Skype
2009-09-17 23:46 . 2009-09-17 23:46 -------- d-----w- c:\program files\Common Files\Skype
2009-09-17 23:46 . 2009-09-17 23:46 -------- d-----w- c:\programdata\Skype
2009-09-16 17:52 . 2009-09-16 17:46 -------- d-----w- c:\users\Griffin\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2009-09-16 17:33 . 2009-09-16 17:33 -------- d-----w- c:\users\Griffin\AppData\Roaming\Ulead Systems
2009-09-16 17:31 . 2009-09-16 17:31 -------- d-----w- c:\program files\Electronic Arts
2009-09-05 00:44 . 2009-10-08 19:12 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-09-05 00:44 . 2009-10-08 19:12 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-09-05 00:44 . 2009-10-08 19:12 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-09-05 00:29 . 2009-10-08 19:12 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-09-05 00:29 . 2009-10-08 19:12 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-09-05 00:29 . 2009-10-08 19:12 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-09-05 00:29 . 2009-10-08 19:12 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-09-05 00:29 . 2009-10-08 19:12 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-08-28 12:39 . 2009-09-16 23:32 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 10:15 . 2009-09-16 23:32 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-27 05:22 . 2009-10-14 22:59 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-14 22:59 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17 . 2009-10-14 22:59 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42 . 2009-10-14 22:59 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-18 06:33 . 2009-08-18 06:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 17:07 . 2009-09-16 23:36 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 16:29 . 2009-09-16 23:36 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:29 . 2009-09-16 23:36 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:16 . 2009-09-16 23:36 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16 . 2009-09-16 23:36 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:16 . 2009-09-16 23:36 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:16 . 2009-09-16 23:36 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16 . 2009-09-16 23:36 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:16 . 2009-09-16 23:36 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16 . 2009-09-16 23:36 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-11-02_22.51.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-02 23:37 . 2009-11-02 23:37 65536 c:\windows\winsxs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.4053_none_3b0e32bdc9afe437\vcomp.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 49152 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80KOR.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 49152 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80JPN.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 61440 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ITA.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 61440 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80FRA.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 61440 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ESP.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 57344 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ENU.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 65536 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80DEU.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 45056 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80CHT.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 40960 c:\windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80CHS.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 57856 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfcm80u.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 69632 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfcm80.dll
+ 2007-06-20 17:55 . 2009-11-04 18:03 67740 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:02 . 2009-11-04 18:03 76026 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-07-31 05:58 . 2009-11-04 18:03 12362 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3074739374-1649422935-3759921920-1003_UserData.bin
+ 2008-07-31 05:54 . 2009-11-04 18:06 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-07-31 05:54 . 2009-11-02 22:00 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-07-31 05:54 . 2009-11-04 18:06 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-07-31 05:54 . 2009-11-02 22:00 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-10-15 08:04 . 2008-10-15 08:04 39792 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A3100000030\8.1.3\reader_sl.exe
+ 2008-10-15 04:33 . 2008-10-15 04:33 95600 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A3100000030\8.1.3\nppdf32.dll
+ 2006-10-23 06:29 . 2006-10-23 06:29 14456 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A3100000030\8.1.3\AcroRd32Info.exe
- 2009-11-02 22:00 . 2009-11-02 22:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-11-04 18:23 . 2009-11-04 18:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-11-04 18:23 . 2009-11-04 18:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-11-02 22:00 . 2009-11-02 22:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-11-04 18:07 645412 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-11-02 22:07 645412 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-11-02 22:07 119832 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-11-04 18:07 119832 c:\windows\System32\perfc009.dat
- 2008-07-31 05:54 . 2009-11-02 22:00 442368 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-31 05:54 . 2009-11-04 18:06 442368 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-06-12 01:01 . 2009-10-29 17:54 813744 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2007-06-12 01:01 . 2009-11-04 18:22 813744 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-11-02 23:37 . 2009-11-02 23:37 424448 c:\windows\Installer\5930dc.msi
+ 2009-03-12 04:48 . 2009-11-02 23:45 295606 c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A81300000003}\SC_Reader.exe
- 2009-03-12 04:48 . 2009-10-16 03:31 295606 c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A81300000003}\SC_Reader.exe
+ 2007-04-16 04:56 . 2007-04-16 04:56 389120 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A3100000030\8.1.3\AdobeXMP.dll
+ 2007-05-11 10:06 . 2007-05-11 10:06 341616 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A3100000030\8.1.3\AcroRd32.exe
+ 2008-10-15 04:29 . 2008-10-15 04:29 632168 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A3100000030\8.1.3\AcroPDF.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 1093120 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfc80u.dll
+ 2009-11-02 23:37 . 2009-11-02 23:37 1105920 c:\windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfc80.dll
+ 2006-11-02 10:22 . 2009-11-04 18:22 6115328 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2008-10-15 03:55 . 2008-10-15 03:55 1945600 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A3100000030\8.1.3\rt3d.dll
+ 2008-10-15 07:35 . 2008-10-15 07:35 4906496 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A3100000030\8.1.3\AGM.dll
+ 2009-11-04 18:22 . 2009-11-04 18:22 6115328 c:\windows\ERDNT\subs\schema.dat
+ 2009-11-04 18:10 . 2009-11-04 18:10 6115328 c:\windows\ERDNT\Hiv-backup\schema.dat
+ 2009-10-29 17:44 . 2009-10-29 17:44 33281024 c:\windows\Installer\3450b.msp
+ 2009-05-17 06:47 . 2009-11-04 18:06 193707260 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{447E64C2-C073-4C31-9D1F-FF37219C8524}]
2009-10-12 07:50 118983 ----a-w- c:\windows\zAdBHO.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-10-16 20:12 1119488 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2006-12-04 00:03 2854912 ----a-w- c:\program files\Protector Suite QL\farchns.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2006-12-04 00:03 2854912 ----a-w- c:\program files\Protector Suite QL\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\users\Griffin\Program Files\DNA\btdna.exe" [2009-10-15 323392]
"Steam"="c:\program files\Steam\Steam.exe" [2009-10-26 1217808]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-19 2153472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"PSQLLauncher"="c:\program files\Protector Suite QL\launcher.exe" [2006-12-03 49168]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-05-04 865840]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-03-22 448632]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-10-03 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Griffin\mbam.exe" [2009-09-10 1312080]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2008-05-02 307200]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-02 2010904]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-04-25 4444160]
"NDSTray.exe"="NDSTray.exe" [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2006-12-03 23:50 90112 ----a-w- c:\windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll c:\windows\System32\avgrsstx.dll c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
R0 pf2apj8b;FlatOut File System Driver (pf2apj8b);c:\windows\System32\drivers\pf2apj8b.sys [11/27/2007 5:52 AM 83568]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [10/13/2009 7:04 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [10/13/2009 7:04 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/2/2009 3:38 PM 285392]
R3 FwLnk;FwLnk Driver;c:\windows\System32\drivers\FwLnk.sys [6/11/2007 4:05 PM 7168]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [5/26/2009 2:50 PM 4232704]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.toshibadirect.com/dpdstart
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Griffin\AppData\Roaming\Mozilla\Firefox\Profiles\3t9l20jv.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\users\Griffin\Program Files\DNA\plugins\npbtdna.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-04 10:25
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x853211F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x853211f8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\S-1-5-21-3074739374-1649422935-3759921920-1003\Software\SecuROM\License information*]
"datasecu"=hex:8c,32,87,11,1d,ea,a8,82,51,a6,66,74,4e,4c,d0,5f,b8,f0,f5,96,3f,
16,66,2e,3a,87,64,6e,ce,bf,77,0d,b2,59,59,20,f2,c8,44,1e,ff,08,9d,3e,56,ba,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infra.dll
- - - - - - - > 'Explorer.exe'(3636)
c:\program files\Protector Suite QL\farchns.dll
c:\program files\Protector Suite QL\infra.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\toshiba\IVP\ISM\pinger.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\wbem\unsecapp.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2009-11-04 10:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-04 18:28
ComboFix2.txt 2009-11-04 07:19
ComboFix3.txt 2009-11-02 22:53
Pre-Run: 48,208,482,304 bytes free
Post-Run: 48,457,031,680 bytes free