ComboFix 06.09.28 - Running from: "C:\"
((((((((((((((((((((((((((((((( Files Created from 2006-08-30 to 2006-09-30 ))))))))))))))))))))))))))))))))))
2006-09-29 01:06 1,492 --a------ C:\WINDOWSvundofix.reg
2006-09-28 10:05 94,208 --a------ C:\XPProfiles.exe
2006-09-28 10:00 276,526 --a------ C:\combofix.exe
2006-09-24 13:32 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
2006-09-22 12:49 970,752 --a------ C:\WINDOWS\system32\VchReg.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-09-30 09:49 -------- d-------- C:\Program Files\Common Files
2006-09-28 22:46 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-09-28 12:50 -------- d-------- C:\Program Files\Symantec
2006-09-27 10:22 -------- d-------- C:\Documents and Settings\Adam\Application Data\uTorrent
2006-09-26 23:03 -------- d-------- C:\Program Files\Windows Defender
2006-09-26 12:32 -------- d-------- C:\Program Files\Valve
2006-09-26 10:20 -------- d-------- C:\Program Files\Lavasoft
2006-09-26 10:20 -------- d-------- C:\Documents and Settings\Adam\Application Data\Lavasoft
2006-09-25 23:26 -------- d-------- C:\Program Files\AntiSpyware
2006-09-25 12:40 -------- d-------- C:\Program Files\Common Files\Ahead
2006-09-25 09:57 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-09-25 09:57 -------- d-------- C:\Program Files\QuickTime
2006-09-25 09:51 -------- d-------- C:\Program Files\BT Broadband 2091
2006-09-25 09:49 -------- d-------- C:\Program Files\Midway Home Entertainment
2006-09-25 03:11 -------- d-------- C:\Program Files\CCP
2006-09-24 13:28 -------- d-------- C:\Program Files\OGPlanet
2006-09-24 10:08 -------- d-------- C:\Program Files\THQ
2006-09-24 10:00 34308 --a------ C:\WINDOWS\system32\BASSMOD.dll
2006-09-22 13:20 -------- d-------- C:\Program Files\AdWare SpyWare Blocker and Removal
2006-09-17 17:12 -------- d-------- C:\Program Files\Ubisoft
2006-09-15 22:52 91904 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2006-09-15 22:52 124016 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2006-09-12 22:30 -------- d-------- C:\Program Files\Google
2006-09-10 12:33 -------- d-------- C:\Program Files\EA GAMES
2006-09-09 23:32 -------- dr-h----- C:\Documents and Settings\Adam\Application Data\SecuROM
2006-09-09 23:25 -------- d-------- C:\Program Files\Electronic Arts
2006-09-05 12:07 -------- d-------- C:\Program Files\EndItAll
2006-09-01 09:57 -------- d-------- C:\Program Files\MSN Messenger
2006-08-28 22:08 -------- d-------- C:\Program Files\LimeWire
2006-08-21 16:13 -------- d-------- C:\Documents and Settings\Adam\Application Data\Ahead
2006-08-21 16:08 -------- d-------- C:\Program Files\Nero
2006-08-21 13:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 10:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 10:14 128896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-13 17:39 -------- d-------- C:\Program Files\Empire Interactive
2006-08-13 00:44 -------- d-------- C:\Program Files\Internet Explorer
2006-07-31 14:52 -------- d-------- C:\Program Files\Windows Media Connect 2
2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-27 14:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-23 09:08 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-07-21 09:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"EA Core"="C:\\Program Files\\Electronic Arts\\EA Downloader\\Core.exe -silent"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"LDM"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\BackWeb-8876480.exe"
"LogitechSoftwareUpdate"="\"C:\\Program Files\\Logitech\\Video\\ManifestEngine.exe\" boot"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.0.720.3640\\GoogleToolbarNotifier.exe"
"Steam"="\"c:\\program files\\valve\\steam\\steam.exe\" -silent"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RaidTool"="C:\\Program Files\\VIA\\RAID\\raid_tool.exe"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\SoundMAX\\SMax4PNP.exe"
"SoundMAX"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe\" /tray"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"URLLSTCK.exe"="C:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"YBrowser"="C:\\PROGRA~1\\Yahoo!\\browser\\ybrwicon.exe"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
C:\WINDOWS\tasks\Symantec NetDetect.job
Completion time: 06-09-30 9:58:17.37
ComboFix.txt
ComboFix2.txt
ComboFix3.txt