ComboFix 11-06-22.02 - Bantas 06/22/2011 17:04:04.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.1069 [GMT -4:00] Running from: c:\users\Bantas\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\install.exe c:\programdata\ntuser.dat C:\Uninstall.exe c:\uninstall.exe\.DEFAULT.re5 c:\uninstall.exe\@2.re5 c:\uninstall.exe\@3.re5 c:\uninstall.exe\@4.re5 c:\uninstall.exe\@5.re5 c:\uninstall.exe\@6.re5 c:\uninstall.exe\@7.re5 c:\uninstall.exe\023.dat c:\uninstall.exe\023v.dat c:\uninstall.exe\AppData.folder c:\uninstall.exe\AppData.folder.dat c:\uninstall.exe\AppDataFile.cfx c:\uninstall.exe\AppDataFolder.cfx c:\uninstall.exe\appinit.bad c:\uninstall.exe\asp.str c:\uninstall.exe\Assoc.cmd c:\uninstall.exe\ATTRIB.cfxxe c:\uninstall.exe\Auto-RC.cmd c:\uninstall.exe\av.cmd c:\uninstall.exe\av.vbs c:\uninstall.exe\AWF.cmd c:\uninstall.exe\badclsid c:\uninstall.exe\Bantas.user.cf c:\uninstall.exe\Boot-Rk.cmd c:\uninstall.exe\Boot.bat c:\uninstall.exe\BootDrv.vbs c:\uninstall.exe\c.bat c:\uninstall.exe\c.mrk c:\uninstall.exe\Cache.folder c:\uninstall.exe\Cache.folder.dat c:\uninstall.exe\Catch-sub.cmd c:\uninstall.exe\catchme.cfxxe c:\uninstall.exe\CCS.bat c:\uninstall.exe\CF-Script.cmd c:\uninstall.exe\CF29475.cfxxe c:\uninstall.exe\CHCP.bat c:\uninstall.exe\clsid.c c:\uninstall.exe\clsid.dat c:\uninstall.exe\clsid.hiv c:\uninstall.exe\cmd.cfxxe c:\uninstall.exe\Combobatch.bat c:\uninstall.exe\ComboFix-Download.cfxxe c:\uninstall.exe\Cookies.folder c:\uninstall.exe\Cookies.folder.dat c:\uninstall.exe\Create.cmd c:\uninstall.exe\Creg.dat c:\uninstall.exe\CregC.cmd c:\uninstall.exe\CregC.dat c:\uninstall.exe\CregC_.dat c:\uninstall.exe\CSCRIPT.cfxxe c:\uninstall.exe\CSet.cmd c:\uninstall.exe\d-delA.dat c:\uninstall.exe\dd.cfxxe c:\uninstall.exe\ddsDo.sed c:\uninstall.exe\DelClsid.bat c:\uninstall.exe\DelClsid64.bat c:\uninstall.exe\Desktop.folder c:\uninstall.exe\Desktop.folder.dat c:\uninstall.exe\desktop.ini c:\uninstall.exe\DesktopFile.cfx c:\uninstall.exe\DisclaimED.dat c:\uninstall.exe\DPF.str c:\uninstall.exe\DrvRun.vbs c:\uninstall.exe\dumphive.cfxxe c:\uninstall.exe\embedded.sed c:\uninstall.exe\en-US\ATTRIB.cfxxe.mui c:\uninstall.exe\en-US\CF29475.cfxxe.mui c:\uninstall.exe\en-US\cmd.cfxxe.mui c:\uninstall.exe\en-US\CSCRIPT.cfxxe.mui c:\uninstall.exe\en-US\PING.cfxxe.mui c:\uninstall.exe\en-US\REGT.cfxxe.mui c:\uninstall.exe\en-US\ROUTE.cfxxe.mui c:\uninstall.exe\ERDNT.e_e c:\uninstall.exe\ERDNTDOS.LOC c:\uninstall.exe\ERDNTWIN.LOC c:\uninstall.exe\ERUNT.cfxxe c:\uninstall.exe\erunt.dat c:\uninstall.exe\ERUNT.LOC c:\uninstall.exe\Exe.reg c:\uninstall.exe\extract.cfxxe c:\uninstall.exe\f_system c:\uninstall.exe\FavoriteFolder.cfx c:\uninstall.exe\Favorites.folder c:\uninstall.exe\Favorites.folder.dat c:\uninstall.exe\FavoritesFile.cfx c:\uninstall.exe\FD-SV.cmd c:\uninstall.exe\ffdefstr.dll c:\uninstall.exe\FileKill.cfxxe c:\uninstall.exe\files.pif c:\uninstall.exe\Fin.dat c:\uninstall.exe\FIND3M.bat c:\uninstall.exe\FIXLSP.bat c:\uninstall.exe\FKMGen.cmd c:\uninstall.exe\ForeignWht c:\uninstall.exe\GetHive.cmd c:\uninstall.exe\grep.cfxxe c:\uninstall.exe\gsar.cfxxe c:\uninstall.exe\handle.cfxxe c:\uninstall.exe\HDPEInfo.cfxxe c:\uninstall.exe\hidec.cfxxe c:\uninstall.exe\history.bat c:\uninstall.exe\History.folder c:\uninstall.exe\History.folder.dat c:\uninstall.exe\hwid.pif c:\uninstall.exe\iexplore.exe c:\uninstall.exe\image001.gif c:\uninstall.exe\Imefile.dat c:\uninstall.exe\Install-RC.cmd c:\uninstall.exe\katch.cmd c:\uninstall.exe\Kill-All.cmd c:\uninstall.exe\kmd.dat c:\uninstall.exe\Lang.bat c:\uninstall.exe\List-B.bat c:\uninstall.exe\List-C.bat c:\uninstall.exe\List-D.bat c:\uninstall.exe\List.bat c:\uninstall.exe\lnkread.vbs c:\uninstall.exe\LocalAppData.folder c:\uninstall.exe\LocalAppData.folder.dat c:\uninstall.exe\LocalAppDataFile.cfx c:\uninstall.exe\LocalAppDataFolder.cfx c:\uninstall.exe\LocalService.dat c:\uninstall.exe\LocalServiceNetworkRestricted.dat c:\uninstall.exe\LocalSettings.folder.dat c:\uninstall.exe\LocalSettingsFile.cfx c:\uninstall.exe\LocalSystemNetworkRestricted.dat c:\uninstall.exe\mbr.cfxxe c:\uninstall.exe\mbr.chk c:\uninstall.exe\md5sum.pif c:\uninstall.exe\Mirrors c:\uninstall.exe\MoveIt.bat c:\uninstall.exe\mtee.cfxxe c:\uninstall.exe\MtPt00 c:\uninstall.exe\MUI c:\uninstall.exe\Music.folder c:\uninstall.exe\Music.folder.dat c:\uninstall.exe\MWindows.dat c:\uninstall.exe\mynul.dat c:\uninstall.exe\N_\23990 c:\uninstall.exe\N_\24794 c:\uninstall.exe\ncmd.com c:\uninstall.exe\ND_.bat c:\uninstall.exe\ND_64.bat c:\uninstall.exe\ndis_combofix.dat c:\uninstall.exe\NetHood.folder c:\uninstall.exe\NetHood.folder.dat c:\uninstall.exe\netsvc.bad.dat c:\uninstall.exe\netsvc.dat c:\uninstall.exe\NetworkService.dat c:\uninstall.exe\NirCmd.cfxxe c:\uninstall.exe\NircmdB.exe c:\uninstall.exe\NirCmdC.cfxxe c:\uninstall.exe\NIRKMD.cfxxe c:\uninstall.exe\NlsLanguageDefault c:\uninstall.exe\NoUpdateCF c:\uninstall.exe\NT-OS.cmd c:\uninstall.exe\NULL c:\uninstall.exe\OsId.txt c:\uninstall.exe\OSid.vbs c:\uninstall.exe\OsVer c:\uninstall.exe\pausep.cfxxe c:\uninstall.exe\Personal.folder c:\uninstall.exe\Personal.folder.dat c:\uninstall.exe\PersonalFile.cfx c:\uninstall.exe\PersonalFolder.cfx c:\uninstall.exe\pev.cfxxe c:\uninstall.exe\pevb.cfxxe c:\uninstall.exe\Pictures.folder c:\uninstall.exe\Pictures.folder.dat c:\uninstall.exe\PING.cfxxe c:\uninstall.exe\Policies.dat c:\uninstall.exe\powp.dat c:\uninstall.exe\Prep.inf c:\uninstall.exe\PrintHood.folder c:\uninstall.exe\PrintHood.folder.dat c:\uninstall.exe\Profiles.Folder.cfx c:\uninstall.exe\Profiles.Folder.dat c:\uninstall.exe\Profiles.Folder.folder c:\uninstall.exe\Profiles.Folder.folder.dat c:\uninstall.exe\ProfilesFile.cfx c:\uninstall.exe\ProfilesFolder.cfx c:\uninstall.exe\progfile.dat c:\uninstall.exe\Programs.folder c:\uninstall.exe\Programs.folder.dat c:\uninstall.exe\ProgramsFile.cfx c:\uninstall.exe\ProgramsFolder.cfx c:\uninstall.exe\Purity.dat c:\uninstall.exe\PV.cfxxe c:\uninstall.exe\pv.com c:\uninstall.exe\rar_sfx.cmd c:\uninstall.exe\RCLink.dat c:\uninstall.exe\RcVer00 c:\uninstall.exe\Recent.folder c:\uninstall.exe\Recent.folder.dat c:\uninstall.exe\REGDACL.sed c:\uninstall.exe\RegDo.sed c:\uninstall.exe\region.dat c:\uninstall.exe\RegScan.cmd c:\uninstall.exe\RegScan64.cmd c:\uninstall.exe\REGT.cfxxe c:\uninstall.exe\Resident.txt c:\uninstall.exe\restore_pt.dat c:\uninstall.exe\restore_pt.vbs c:\uninstall.exe\Rkey.cmd c:\uninstall.exe\rmbr.cfxxe c:\uninstall.exe\rogues.dat c:\uninstall.exe\ROUTE.cfxxe c:\uninstall.exe\run2.sed c:\uninstall.exe\Rust.str c:\uninstall.exe\S-1-5-18.re5 c:\uninstall.exe\S-1-5-19.re5 c:\uninstall.exe\S-1-5-20.re5 c:\uninstall.exe\S-1-5-21-2179227837-3419367426-1334409123-1000.re5 c:\uninstall.exe\s0rt.cfxxe c:\uninstall.exe\safeboot.dat c:\uninstall.exe\safeboot.def.dat c:\uninstall.exe\sed.cfxxe c:\uninstall.exe\SendTo.folder c:\uninstall.exe\SendTo.folder.dat c:\uninstall.exe\SetEnvmt.bat c:\uninstall.exe\SetPath.bat c:\uninstall.exe\setpath.cfxxe c:\uninstall.exe\setpath_N.cmd c:\uninstall.exe\SF.exe c:\uninstall.exe\sfx.cmd c:\uninstall.exe\Shell.sed c:\uninstall.exe\SnapShot.cmd c:\uninstall.exe\SRestore.cmd c:\uninstall.exe\srizbi.md5 c:\uninstall.exe\Start_dat c:\uninstall.exe\StartMenu.folder c:\uninstall.exe\StartMenu.folder.dat c:\uninstall.exe\StartMenuFile.cfx c:\uninstall.exe\StartMenuFolder.cfx c:\uninstall.exe\StartUp.folder c:\uninstall.exe\StartUp.folder.dat c:\uninstall.exe\StartUpFile.cfx c:\uninstall.exe\SuppScan.cmd c:\uninstall.exe\svc_wht.dat c:\uninstall.exe\SvcDrv.vbs c:\uninstall.exe\svchost.dat c:\uninstall.exe\swreg.cfxxe c:\uninstall.exe\swsc.cfxxe c:\uninstall.exe\swxcacls.cfxxe c:\uninstall.exe\SysPath.dat c:\uninstall.exe\system_ini.dat c:\uninstall.exe\tail.cfxxe c:\uninstall.exe\temp00 c:\uninstall.exe\Templates.folder c:\uninstall.exe\Templates.folder.dat c:\uninstall.exe\TemplatesFile.cfx c:\uninstall.exe\TemplatesFolder.cfx c:\uninstall.exe\toolbar.sed c:\uninstall.exe\Update-CF.cmd c:\uninstall.exe\VerCF.bat c:\uninstall.exe\version.txt c:\uninstall.exe\VInfo c:\uninstall.exe\VInfo2 c:\uninstall.exe\Vipev.dat c:\uninstall.exe\Vista.krl c:\uninstall.exe\Vista.mac c:\uninstall.exe\vistaMcode.dat c:\uninstall.exe\vistareg.dat c:\uninstall.exe\vun.dat c:\uninstall.exe\VwinTemp.dacl c:\uninstall.exe\w_sock.dll c:\uninstall.exe\w7Mcode.dat c:\uninstall.exe\Wmi_rem.vbs c:\uninstall.exe\xpmcode.dat c:\uninstall.exe\XPSBoot.reg c:\uninstall.exe\zDomain.dat c:\uninstall.exe\zhsvc.dat c:\uninstall.exe\zip.cfxxe c:\windows\jestertb.dll . . ((((((((((((((((((((((((( Files Created from 2011-05-22 to 2011-06-22 ))))))))))))))))))))))))))))))) . . 2011-06-22 21:14 . 2011-06-22 21:14 -------- d-----w- c:\users\Mcx2\AppData\Local\temp 2011-06-22 21:14 . 2011-06-22 21:14 -------- d-----w- c:\users\Mcx1\AppData\Local\temp 2011-06-22 21:14 . 2011-06-22 21:14 -------- d-----w- c:\users\Guest\AppData\Local\temp 2011-06-22 21:14 . 2011-06-22 21:14 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-06-22 20:57 . 2011-05-29 13:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-06-22 20:57 . 2011-06-22 20:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-06-22 20:57 . 2011-05-29 13:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-06-22 01:11 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{52886FB3-8DB0-4A9F-81E2-E13D37291492}\mpengine.dll 2011-06-19 06:24 . 2011-06-19 06:24 -------- d-----w- c:\program files\Common Files\Adobe 2011-06-16 03:06 . 2011-06-16 03:06 -------- d-----w- c:\users\Bantas\AppData\Roaming\Malwarebytes 2011-06-16 03:05 . 2011-06-16 03:05 -------- d-----w- c:\programdata\Malwarebytes 2011-06-16 01:37 . 2011-04-14 14:59 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys 2011-06-16 01:37 . 2011-04-21 13:58 273408 ----a-w- c:\windows\system32\drivers\afd.sys 2011-06-16 01:37 . 2011-04-29 13:25 146432 ----a-w- c:\windows\system32\drivers\srv2.sys 2011-06-16 01:37 . 2011-04-29 13:25 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys 2011-06-16 01:37 . 2010-12-20 16:35 563712 ----a-w- c:\windows\system32\oleaut32.dll 2011-06-16 01:37 . 2011-05-02 17:16 739328 ----a-w- c:\windows\system32\inetcomm.dll 2011-06-16 01:37 . 2011-04-29 13:24 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-16 01:37 . 2011-04-29 13:24 79872 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-06-16 01:37 . 2011-04-29 13:24 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-06-16 01:37 . 2011-05-02 12:02 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat 2011-06-15 15:55 . 2011-06-15 16:30 -------- d-----w- C:\aaa BantaBrain 2011-06-13 01:15 . 2010-03-10 19:23 319488 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp101.dll 2011-06-13 01:14 . 2009-10-22 00:55 452736 ----a-w- c:\windows\system32\hpzids01.dll 2011-06-13 01:14 . 2010-03-10 19:23 125952 ----a-w- c:\windows\system32\hpf3l101.dll 2011-06-02 12:37 . 2011-06-02 12:37 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-05-24 18:57 . 2011-05-24 18:57 -------- d-----w- c:\program files\DIFX 2011-05-24 18:57 . 2011-05-24 18:57 -------- d-----w- c:\program files\Palm, Inc . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-24 23:14 . 2010-04-23 21:07 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-04-09 22:55 . 2011-04-09 22:55 15453336 ----a-w- c:\windows\system32\xlive.dll 2011-04-09 22:55 . 2011-04-09 22:55 13642904 ----a-w- c:\windows\system32\xlivefnt.dll 2011-04-06 20:20 . 2011-04-06 20:20 91424 ----a-w- c:\windows\system32\dnssd.dll 2011-04-06 20:20 . 2011-04-06 20:20 107808 ----a-w- c:\windows\system32\dns-sd.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-14 68856] "TranscodingService"="c:\program files\TiVo\Desktop\TranscodingService.exe" [2009-01-27 520192] "TivoNotify"="c:\program files\TiVo\Desktop\TiVoNotify.exe" [2009-01-27 425472] "TivoServer"="c:\program files\TiVo\Desktop\TiVoServer.exe" [2009-01-27 2143232] "Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-04-12 2937528] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-04-18 15146376] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-04-18 159744] "OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-09 36864] "VolPanel"="c:\program files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" [2006-11-27 180224] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "Logitech Hardware Abstraction Layer"="c:\program files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2007-01-12 101136] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920] "pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960] "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320] "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 17920] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-28 30192] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-12 101136] "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392] "LoadMSvcmm"="c:\program files\Blockbuster\BLOCKBUSTERMovielink\Movielink User.exe" [2009-03-27 455112] "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-06-25 405504] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-16 13793824] "NVHotkey"="c:\windows\system32\nvHotkey.dll" [2009-06-16 92704] "accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2008-05-02 294440] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "Mobile Connectivity Suite"="c:\program files\HTC\HTC Sync\Application Launcher\Application Launcher.exe" [2009-11-19 598016] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-27 421160] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-05-27 40368] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ ActivClient Agent.lnk - c:\program files\ActivIdentity\ActivClient\acsagent.exe [2008-5-2 130864] Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280] Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-8-21 50688] Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2008-10-2 546288] Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] Quicken Scheduled Updates.lnk - c:\program files\Quicken\bagent.exe [2003-7-29 57344] QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-8-21 45056] SetPoint.lnk - c:\program files\SetPoint\SetPoint.exe [2007-8-21 679936] ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-2-5 54512] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-22 133104] R2 mrtRate;mrtRate; [x] R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2006-09-25 345696] R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2006-11-09 923216] R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2006-11-09 566872] R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560] R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-28 30192] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-07-22 133104] R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-06-10 24576] R3 SCR3xx USB Smart Card Reader;SCR3xx USB Smart Card Reader;c:\windows\system32\DRIVERS\SCR3XX2K.sys [2007-06-21 56448] R3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\DRIVERS\SCR3XX2K.sys [2007-06-21 56448] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S2 accoca;ActivClient Middleware Service;c:\program files\ActivIdentity\ActivClient\accoca.exe [2008-05-02 188456] S2 dlbk_device;dlbk_device;c:\windows\system32\dlbkcoms.exe [2007-06-26 537840] S2 NovacomD;Palm Novacom;c:\program files\Palm, Inc\novacom\x86\novacomd.exe [2010-01-12 33792] S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2008-11-26 36368] S3 stdriver;Sound Tap Upper Class Filter Driver v2.0.0.0;c:\windows\system32\DRIVERS\stdriver32.sys [2010-11-19 52824] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder . 2011-06-22 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-14 23:18] . 2011-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-22 10:49] . 2011-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-22 10:49] . 2011-06-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2179227837-3419367426-1334409123-1000Core.job - c:\users\Bantas\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-29 18:08] . 2011-06-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2179227837-3419367426-1334409123-1000UA.job - c:\users\Bantas\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-29 18:08] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ig uInternet Settings,ProxyOverride = *.local IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm Trusted Zone: navy.mil\webmail.east.nmci Trusted Zone: navy.mil\webmail.nmci TCP: DhcpNameServer = 192.168.1.1 71.252.0.12 . - - - - ORPHANS REMOVED - - - - . HKLM-Run-Corel Photo Downloader - c:\program files\Corel\Corel Snapfire Plus\PhotoDownloader.exe AddRemove-The Weather Channel Desktop 6 - c:\program files\The Weather Channel FW\Desktop\TheWeatherChannelCustomUninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-06-22 17:15 Windows 6.0.6002 Service Pack 2 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice] @Denied: (2) (LocalSystem) "Progid"="YMP.Media" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2011-06-22 17:23:48 ComboFix-quarantined-files.txt 2011-06-22 21:23 . Pre-Run: 54,580,109,312 bytes free Post-Run: 55,215,112,192 bytes free . - - End Of File - - 2EEC0B0E86021C963F7C9EA7A517BDF0