thanks andrew
ComboFix 08-03-27.5 - Dara 2008-03-29 16:32:40.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.970 [GMT 0:00]
Running from: C:\Users\Dara\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_npf
-------\Service_npf
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-29 )))))))))))))))))))))))))))))))
.
2008-03-27 22:11 . 2008-03-27 22:11 <DIR> d-------- C:\Users\Dara\AppData\Roaming\Malwarebytes
2008-03-27 22:11 . 2008-03-27 22:11 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-03-27 22:11 . 2008-03-27 22:11 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-03-27 22:11 . 2008-03-27 22:11 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-24 23:29 . 2008-03-24 23:29 <DIR> d-------- C:\Deckard
2008-03-22 00:21 . 2008-03-22 00:21 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-03-18 23:39 . 2008-03-19 00:01 <DIR> d-------- C:\Program Files\BitComet
2008-03-18 23:39 . 2008-03-18 23:39 <DIR> d-------- C:\Downloads
2008-03-17 19:49 . 2008-03-17 19:49 40 --a------ C:\Windows\ujf635.bin
2008-03-17 19:48 . 2008-03-17 19:48 <DIR> d-------- C:\Users\Dara\AppData\Roaming\Betfair
2008-03-17 19:48 . 2008-03-17 19:48 <DIR> d-------- C:\Program Files\Betfair
2008-03-17 00:09 . 2008-03-17 00:09 <DIR> d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-03-17 00:09 . 2008-03-17 00:09 <DIR> d-------- C:\ProgramData\SUPERAntiSpyware.com
2008-03-16 23:55 . 2008-03-16 23:55 <DIR> d-------- C:\Users\Dara\AppData\Roaming\SUPERAntiSpyware.com
2008-03-16 23:55 . 2008-03-17 11:41 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-16 21:54 . 2008-03-16 21:54 <DIR> d-------- C:\Users\Dara\AppData\Roaming\Grisoft
2008-03-16 21:54 . 2007-05-30 12:10 10,872 --a------ C:\Windows\System32\drivers\AvgAsCln.sys
2008-03-14 22:27 . 2007-12-16 22:50 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-03-14 22:27 . 2007-12-16 09:56 41,984 --a------ C:\Windows\System32\drivers\monitor.sys
2008-03-02 21:39 . 2008-03-02 21:39 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-01 22:46 . 2008-03-01 22:47 286,723,685 --a------ C:\Windows\MEMORY.DMP
2008-03-01 22:34 . 2008-03-01 22:34 <DIR> d-------- C:\Users\Dara\AppData\Roaming\CyberLink
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-19 00:37 --------- d-----w C:\Users\Dara\AppData\Roaming\AVG7
2008-03-17 11:39 --------- d-----w C:\ProgramData\McAfee
2008-03-16 23:55 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-16 21:54 --------- d-----w C:\ProgramData\Grisoft
2008-03-15 16:17 --------- d-----w C:\Program Files\Windows Mail
2008-03-14 22:25 53,768 ----a-w C:\Windows\system32\drivers\avgwfp.sys
2008-03-01 22:34 --------- d-----w C:\ProgramData\CyberLink
2008-02-28 21:16 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-02-27 23:52 --------- d-----w C:\ProgramData\Lavasoft
2008-02-27 23:51 --------- d-----w C:\Program Files\Lavasoft
2008-02-27 23:26 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-27 20:20 --------- d-----w C:\ProgramData\Roxio
2008-02-26 19:51 --------- d-----w C:\Program Files\Windows Sidebar
2008-02-26 19:45 --------- d-----w C:\Users\Dara\AppData\Roaming\Apple Computer
2008-02-26 19:45 --------- d-----w C:\ProgramData\Apple Computer
2008-02-26 19:45 --------- d-----w C:\Program Files\iTunes
2008-02-26 19:45 --------- d-----w C:\Program Files\iPod
2008-02-26 19:43 --------- d-----w C:\Program Files\QuickTime
2008-02-26 19:43 --------- d-----w C:\Program Files\Bonjour
2008-02-26 19:41 --------- d-----w C:\Program Files\Apple Software Update
2008-02-26 19:40 --------- d-----w C:\ProgramData\Apple
2008-02-26 19:40 --------- d-----w C:\Program Files\Common Files\Apple
2008-02-26 19:23 --------- d-----w C:\Users\Dara\AppData\Roaming\Intel
2008-02-26 19:03 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-26 19:03 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-26 19:00 595,456 ----a-w C:\Windows\System32\schedsvc.dll
2008-02-26 18:58 --------- d-----w C:\Users\Dara\AppData\Roaming\Talkback
2008-02-26 18:55 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-26 18:55 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-26 18:55 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-26 18:55 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-26 18:55 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-26 18:55 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-02-26 18:55 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-26 18:54 --------- d-----w C:\Program Files\MSXML 4.0
2008-02-26 18:52 --------- d-----w C:\ProgramData\avg7
2008-02-26 18:51 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-26 18:51 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-26 18:50 9,216 ----a-w C:\Windows\System32\avgwlntf.dll
2008-02-26 18:50 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-26 18:50 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-26 18:49 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2008-02-26 18:31 53,080 ----a-w C:\Windows\System32\wuauclt.exe
2008-02-26 18:31 43,352 ----a-w C:\Windows\System32\wups2.dll
2008-02-26 18:31 1,712,984 ----a-w C:\Windows\System32\wuaueng.dll
2008-02-26 18:31 1,524,224 ----a-w C:\Windows\System32\wucltux.dll
2008-02-26 18:30 80,896 ----a-w C:\Windows\System32\wudriver.dll
2008-02-26 18:30 549,720 ----a-w C:\Windows\System32\wuapi.dll
2008-02-26 18:30 33,624 ----a-w C:\Windows\System32\wups.dll
2008-02-26 18:29 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-02-26 18:29 163,000 ----a-w C:\Windows\System32\wuwebv.dll
2008-02-26 18:15 --------- d-----w C:\Users\Dara\AppData\Roaming\Roxio
2008-02-26 17:47 --------- d-----w C:\Program Files\Common Files\Corel
2008-02-26 17:46 --------- d-----w C:\ProgramData\My Music
2008-02-26 17:46 --------- d-----w C:\ProgramData\Corel
2008-02-26 17:45 1,353,296 ----a-w C:\Users\All Users\pswi_preloaded.exe
2008-02-26 17:45 1,353,296 ----a-w C:\ProgramData\pswi_preloaded.exe
2008-02-26 17:45 --------- d-----w C:\Program Files\Corel
2008-02-26 17:28 --------- d-----w C:\Users\Dara\AppData\Roaming\Creative
2008-02-26 17:14 --------- d-----w C:\Users\Dara\AppData\Roaming\Template
2008-02-26 17:13 0 ----a-w C:\Users\Dara\AppData\Roaming\wklnhst.dat
2008-02-26 17:03 27,240 ----a-w C:\Users\Dara\AppData\Roaming\nvModes.dat
2008-02-26 16:26 --------- d-----w C:\ProgramData\NVIDIA
2008-02-26 16:23 --------- d-sh--w C:\ProgramData\Templates
2008-02-26 16:23 --------- d-sh--w C:\ProgramData\Start Menu
2008-02-26 16:23 --------- d-sh--w C:\ProgramData\Favorites
2008-02-26 16:23 --------- d-sh--w C:\ProgramData\Documents
2008-02-26 16:23 --------- d-sh--w C:\ProgramData\Desktop
2008-02-26 16:23 --------- d-sh--w C:\ProgramData\Application Data
2008-02-23 22:48 25,784 ------w C:\Windows\system32\drivers\msahci.sys
2008-02-23 22:48 20,152 ------w C:\Windows\system32\drivers\viaide.sys
2008-02-23 22:48 19,128 ------w C:\Windows\system32\drivers\cmdide.sys
2008-02-23 22:48 18,104 ------w C:\Windows\system32\drivers\amdide.sys
2008-02-23 22:48 17,592 ----a-w C:\Windows\system32\drivers\intelide.sys
2008-02-23 22:48 17,592 ------w C:\Windows\system32\drivers\aliide.sys
2008-02-23 22:48 --------- d-----w C:\Program Files\DellTPad
2008-02-23 22:47 229,888 ----a-w C:\Windows\System32\msshsq.dll
2008-02-23 22:46 87,040 ----a-w C:\Windows\System32\msoert2.dll
2008-02-23 22:46 750,080 ----a-w C:\Windows\System32\qmgr.dll
2008-02-23 22:46 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2008-02-23 22:46 205,824 ----a-w C:\Windows\System32\msoeacct.dll
2008-02-23 22:46 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
2008-02-23 22:43 974,336 ----a-w C:\Windows\System32\crypt32.dll
2008-02-23 22:42 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-02-23 22:42 57,856 ----a-w C:\Windows\System32\SLUINotify.dll
2008-02-23 22:42 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll
2008-02-23 22:42 39,936 ----a-w C:\Windows\System32\slcinst.dll
2008-02-23 22:42 351,232 ----a-w C:\Windows\System32\SLUI.exe
2008-02-23 22:42 33,280 ----a-w C:\Windows\System32\slwmi.dll
2008-02-23 22:42 268,288 ----a-w C:\Windows\System32\mcbuilder.exe
2008-02-23 22:42 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2008-02-23 22:42 223,232 ----a-w C:\Windows\System32\SLC.dll
2008-02-23 22:42 2,605,568 ----a-w C:\Windows\System32\SLsvc.exe
2008-02-23 22:42 186,368 ----a-w C:\Windows\System32\SLLUA.exe
2008-02-23 22:40 82,432 ----a-w C:\Windows\system32\drivers\sdbus.sys
2008-02-23 22:40 13,312 ------w C:\Windows\system32\drivers\sffdisk.sys
2008-02-23 22:40 12,800 ------w C:\Windows\system32\drivers\sffp_sd.sys
2008-02-23 22:40 12,800 ------w C:\Windows\system32\drivers\sffp_mmc.sys
2008-02-23 22:38 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2008-02-23 22:38 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@={F2F31467-B1AC-4df0-AE79-FD5FA085E22B}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@={A3E208F7-0E3A-4182-A7A6-B169D5D691AA}
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-04-16 23:13 721408 --a------ C:\Program Files\Fingerprint Reader Suite\farchns.dll
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-04-16 23:13 721408 --a------ C:\Program Files\Fingerprint Reader Suite\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 12:34 2159104 C:\Windows\System32\oobefldr.dll]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-02-23 22:36 1006264]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2007-05-25 06:03 17920]
"Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-09-07 08:50 159744]
"OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-08-28 05:51 36864]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-12-03 04:28 405504]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-28 06:24 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-28 06:24 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-28 06:24 81920]
"NVHotkey"="C:\Windows\system32\nvHotkey.dll" [2007-09-28 06:24 81920]
"SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2008-02-23 15:05 77824]
"DeStatusMon"="C:\Program Files\Dell\MFP_DELL\deDvcStatus.exe" [2007-06-28 14:07 286720]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-03-12 18:10 79400]
"PSQLLauncher"="C:\Program Files\Fingerprint Reader Suite\launcher.exe" [2007-04-16 22:50 49168]
"DELL Webcam Manager"="C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 16:43 118784]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 13:00 174872]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-23 15:23 1838592]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 15:39 189736]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe" [2007-03-21 01:33 478800]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-26 18:54 579072]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25 6731312]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-26 18:49 219136]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-03 17:55:50 703280]
QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [2007-09-07 16:27:08 1180952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2008-02-26 18:50 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
C:\Windows\system32\psqlpwd.dll 2007-04-16 23:04 86528 C:\Windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F3D6EFA9-D79C-4868-AF84-E306859A4499}"= C:\Program Files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
"{95A9AFC5-C45C-4457-8D6E-421C9ED7F46C}"= C:\Program Files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{466465A2-8BFF-4F00-85FC-E6CDD0213AD6}"= C:\Program Files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{2556B595-F4D6-4DDC-B109-6FFD1652D863}"= C:\Program Files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{298A1AD5-4AEC-42CF-AB7E-3202CEBC3191}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{6229C76B-3F78-4337-B776-AB5B7FCC579B}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{2F523086-ED0A-46AE-84AA-99EFD2C943B6}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{3FE8BF21-A95A-4298-9300-530F6499F7B1}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-12-03 04:27]
R2 deMntrService;Dell AIO Center Service;"C:\Program Files\Dell\MFP_DELL\deMntrService.exe" [2007-06-28 14:05]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R3 AvgWFP;AVG7 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfp.sys [2008-03-14 22:25]
R3 btwaudio;Bluetooth Audio Device Service;C:\Windows\system32\drivers\btwaudio.sys [2006-11-07 01:37]
R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2006-11-06 23:13]
R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2006-11-06 23:13]
R3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-08-28 05:51]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-08-28 05:51]
R3 TcUsb;TC USB Kernel Driver;C:\Windows\system32\Drivers\tcusb.sys [2007-04-16 22:44]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-28 06:40]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 07:36]
S4 iaNvStor;Intel® Turbo Memory Controller;C:\Windows\system32\drivers\ianvstor.sys [2007-09-07 09:27]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-29 16:37:45
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Fingerprint Reader Suite\upeksvr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Windows\system32\WLANExt.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Windows\system32\PSIService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\conime.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Fingerprint Reader Suite\psqltray.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
.
**************************************************************************
.
Completion time: 2008-03-29 16:39:25 - machine was rebooted [Dara]
ComboFix-quarantined-files.txt 2008-03-29 16:39:19
Pre-Run: 189,393,960,960 bytes free
Post-Run: 188,939,837,440 bytes free
.
2008-03-28 18:23:25 --- E O F ---
-----------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:42:35, on 24/03/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Dell\MFP_DELL\deDvcStatus.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Fingerprint Reader Suite\psqltray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conime.exe
C:\Users\Dara\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Dara.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ie...amp;ibd=3080223R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [DeStatusMon] "C:\Program Files\Dell\MFP_DELL\deDvcStatus.exe" dvcStatusMinimize
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Fingerprint Reader Suite\launcher.exe" /startup
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [BitComet] C:\Program Files\BitComet\BitComet.exe /tray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dell AIO Center Service (deMntrService) - Dell - C:\Program Files\Dell\MFP_DELL\deMntrService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
--
End of file - 10959 bytes