ComboFix 09-07-14.08 - Joshlin 07/17/2009 13:35.4.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.585 [GMT -7:00]
Running from: c:\documents and settings\Joshlin\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: StopSign Antivirus FREE TRIAL diagnostic version *On-access scanning enabled* (Outdated) {3E1D4556-3240-40c8-BBED-64A8690A3FB4}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Joshlin\Application Data\bcrypt.html
c:\recycler\S-1-5-21-0431149003-6720943573-621924096-1817
c:\recycler\S-1-5-21-1774254304-0893637155-141166456-7100
.
((((((((((((((((((((((((( Files Created from 2009-06-17 to 2009-07-17 )))))))))))))))))))))))))))))))
.
2009-07-17 17:48 . 2009-07-02 21:44 2301208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avguiadv.dll
2009-07-17 17:48 . 2009-07-02 21:44 1107224 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgssie.dll
2009-07-17 17:48 . 2009-07-02 21:44 353048 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgxch32.dll
2009-07-15 18:13 . 2009-07-15 19:57 -------- d-----w- C:\32788R22FWJFW.0.tmp
2009-07-15 06:17 . 2009-07-15 06:17 -------- d-----w- c:\documents and settings\Joshlin\Application Data\Malwarebytes
2009-07-15 06:17 . 2009-07-13 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-15 06:17 . 2009-07-15 06:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-15 06:17 . 2009-07-15 06:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-15 06:17 . 2009-07-13 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-15 03:52 . 2009-07-15 04:09 -------- d-s---w- C:\vfh5349fj9b5j9-bvj9b3j9-536
2009-07-15 01:50 . 2009-07-15 01:50 -------- d-sh--w- C:\found.001
2009-07-10 04:40 . 2009-07-10 04:41 3629946 ----a-w- c:\program files\Acceleration Software.zip
2009-07-09 15:45 . 2009-07-02 21:44 327688 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgldx86.sys
2009-07-09 15:45 . 2009-07-09 15:44 3403032 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-07-09 15:45 . 2009-07-02 21:44 3298072 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-07-09 15:45 . 2009-07-02 21:44 1204504 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgabout.dll
2009-07-09 15:45 . 2009-07-02 21:44 337176 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avglogx.dll
2009-07-09 15:45 . 2009-07-02 21:44 2167576 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgresf.dll
2009-07-09 15:45 . 2009-07-02 21:44 829208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-07-09 15:44 . 2009-07-02 21:44 1085208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-07-09 15:44 . 2009-07-02 21:44 1454360 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-07-08 22:04 . 2009-07-08 22:04 -------- d-----w- c:\documents and settings\Joshlin\Application Data\eAcceleration
2009-07-08 22:03 . 2009-07-08 22:03 -------- d-----w- c:\program files\TheProblem
2009-07-08 22:02 . 2009-07-08 22:04 -------- d-----w- c:\documents and settings\All Users\Application Data\eAcceleration
2009-07-08 22:02 . 2009-07-08 22:03 -------- d-----w- c:\program files\Common Files\eAcceleration
2009-07-08 15:20 . 2009-07-08 15:20 -------- d-sh--w- C:\found.000
2009-07-04 22:47 . 2009-07-04 22:47 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-07-04 10:17 . 2009-07-04 10:17 -------- d-----w- c:\program files\MSXML 4.0
2009-07-03 17:55 . 2009-07-03 17:55 -------- d-----w- c:\documents and settings\Joshlin\Local Settings\Application Data\My Games
2009-07-03 16:45 . 2009-07-03 16:45 2052376 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-07-03 14:03 . 2009-07-17 14:30 -------- d--h--w- C:\$AVG8.VAULT$
2009-07-03 10:54 . 2009-07-03 10:54 -------- d-----w- c:\documents and settings\Joshlin\Application Data\DivX
2009-07-03 10:51 . 2009-07-03 10:51 -------- d-----w- c:\documents and settings\Joshlin\Local Settings\Application Data\GameSpy
2009-07-03 10:40 . 2009-07-03 10:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-07-03 10:34 . 2009-07-03 10:53 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-07-03 10:15 . 2009-07-03 10:15 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-07-03 10:15 . 2009-05-13 21:56 9336 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-07-03 10:15 . 2009-05-13 21:56 9464 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-07-03 10:15 . 2009-05-13 21:56 129784 ------w- c:\windows\system32\pxafs.dll
2009-07-03 10:14 . 2009-07-03 10:15 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-07-03 10:14 . 2009-07-03 10:15 -------- d-----w- c:\program files\DivX
2009-07-03 10:12 . 2004-08-10 12:00 25600 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-07-03 07:08 . 2009-07-03 07:08 -------- d-----w- c:\program files\GameSpy
2009-07-03 07:02 . 2009-07-03 07:02 -------- d-----w- c:\documents and settings\Joshlin\Application Data\InstallShield
2009-07-03 06:59 . 2009-07-03 06:59 -------- d-----w- c:\documents and settings\Joshlin\Application Data\Xfire
2009-07-03 06:58 . 2009-07-03 06:59 -------- d-s---w- c:\program files\Xfire
2009-07-03 06:43 . 2009-07-03 06:43 -------- d-----w- c:\program files\Firaxis Games
2009-07-03 06:42 . 2005-05-26 22:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2009-07-03 06:37 . 2009-07-03 06:37 -------- d-----w- c:\program files\PowerISO
2009-07-03 02:37 . 2008-10-16 21:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-07-03 02:37 . 2008-10-16 21:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-07-03 01:58 . 2009-07-03 01:58 -------- d-----w- c:\program files\Windows Media Connect 2
2009-07-03 01:56 . 2009-07-03 01:57 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-07-03 01:56 . 2009-07-03 01:56 -------- d-----w- c:\windows\system32\LogFiles
2009-07-03 01:20 . 2009-07-03 01:41 -------- d-----w- c:\program files\Trillian
2009-07-03 00:36 . 2009-07-03 00:36 -------- d-----w- c:\documents and settings\Joshlin\Application Data\Apple Computer
2009-07-02 23:08 . 2009-07-02 23:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-07-02 22:51 . 2009-07-02 22:51 -------- d-----w- c:\program files\uTorrent
2009-07-02 22:51 . 2009-07-17 14:50 -------- d-----w- c:\documents and settings\Joshlin\Application Data\uTorrent
2009-07-02 22:47 . 2009-07-02 22:47 -------- d-----w- c:\program files\Messenger Plus! Live
2009-07-02 21:54 . 2001-08-17 21:02 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-07-02 21:54 . 2001-08-17 21:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-07-02 21:54 . 2004-08-04 06:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-07-02 21:54 . 2004-08-04 06:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-07-02 21:53 . 2009-07-03 02:03 -------- d-----w- c:\documents and settings\Joshlin\Tracing
2009-07-02 21:51 . 2009-07-02 21:51 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-07-02 21:51 . 2009-07-03 02:08 -------- d-----w- c:\program files\Windows Live
2009-07-02 21:47 . 2009-07-02 21:47 -------- d-----w- c:\program files\Common Files\Windows Live
2009-07-02 21:45 . 2009-07-02 21:45 -------- d-----w- c:\documents and settings\Joshlin\Local Settings\Application Data\Mozilla
2009-07-02 21:44 . 2009-07-02 21:44 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-02 21:44 . 2009-07-02 21:44 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-07-02 21:44 . 2009-07-09 15:44 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-02 21:44 . 2009-07-02 21:44 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-02 21:44 . 2009-07-17 17:49 -------- d-----w- c:\windows\system32\drivers\Avg
2009-07-02 21:44 . 2009-07-02 21:44 -------- d-----w- c:\program files\AVG
2009-07-02 21:44 . 2009-07-17 17:43 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-07-02 21:34 . 2009-07-02 21:34 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee.com Personal Firewall
2009-07-02 21:27 . 2009-07-02 21:27 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\McAfee.com Personal Firewall
2009-07-02 21:27 . 2009-07-02 21:27 -------- d-----w- c:\documents and settings\Joshlin\Application Data\McAfee.com Personal Firewall
2009-07-02 21:25 . 2009-07-02 21:25 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-02 21:25 . 2009-07-02 21:25 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Intel
2009-07-02 21:25 . 2009-07-02 21:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2009-07-02 21:25 . 2009-07-02 21:25 -------- d-----w- c:\documents and settings\Administrator\Application Data\Intel
2009-07-02 21:25 . 2009-07-03 00:36 -------- dc----w- c:\windows\system32\DRVSTORE
2009-07-02 21:25 . 2006-02-16 09:18 -------- d-----w- c:\documents and settings\Default User\WINDOWS
2009-07-02 21:17 . 2009-07-02 21:17 -------- d-----w- c:\program files\AVerMedia
2009-07-02 21:16 . 2009-07-02 21:16 -------- d-----w- c:\program files\Common Files\InterVideo
2009-07-02 21:16 . 2005-11-28 05:51 135168 ----a-w- c:\windows\system32\igfxres.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-05 10:52 . 2006-02-16 10:39 -------- d-----w- c:\program files\Microsoft Works
2009-07-04 12:29 . 2006-02-16 09:55 -------- d-----w- c:\program files\Pure Networks
2009-07-04 11:33 . 2006-02-16 16:59 35920 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-04 11:31 . 2006-02-18 15:56 -------- d-----w- c:\program files\Google
2009-07-04 00:46 . 2006-02-15 15:37 87931 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-03 14:06 . 2006-02-17 09:57 -------- d-----w- c:\program files\DIGStream
2009-07-03 11:19 . 2006-02-16 09:55 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-07-03 11:19 . 2006-02-16 09:55 -------- d-----w- c:\program files\Common Files\AOL
2009-07-03 10:50 . 2009-07-02 21:26 130 ----a-w- c:\documents and settings\Joshlin\Local Settings\Application Data\fusioncache.dat
2009-07-03 07:08 . 2006-02-15 16:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-03 00:36 . 2009-07-03 00:36 -------- d-----w- c:\program files\iTunes
2009-07-03 00:36 . 2009-07-03 00:36 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-03 00:36 . 2009-07-03 00:36 -------- d-----w- c:\program files\iPod
2009-07-03 00:36 . 2009-07-03 00:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-03 00:35 . 2009-07-03 00:35 -------- d-----w- c:\program files\Bonjour
2009-07-03 00:35 . 2009-07-03 00:35 -------- d-----w- c:\program files\QuickTime
2009-07-03 00:34 . 2009-07-03 00:34 -------- d-----w- c:\program files\Apple Software Update
2009-07-03 00:34 . 2009-07-03 00:34 -------- d-----w- c:\program files\Common Files\Apple
2009-07-03 00:34 . 2009-07-03 00:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-07-02 21:27 . 2006-05-13 23:44 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2009-07-02 21:25 . 2006-02-15 16:18 -------- d-----w- c:\program files\Intel
2009-07-02 21:25 . 2009-07-02 21:26 -------- d-----w- c:\documents and settings\Joshlin\Application Data\Intel
2009-07-02 21:16 . 2006-02-16 09:25 -------- d-----w- c:\program files\InterVideo
2009-06-05 20:57 . 2009-06-05 20:57 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-05-13 21:56 . 2005-10-26 20:12 43528 ------w- c:\windows\system32\drivers\pxhelp20.sys
2009-05-13 21:56 . 2006-02-16 09:50 120056 ------w- c:\windows\system32\pxcpyi64.exe
2009-05-13 21:56 . 2006-02-16 09:50 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-05-13 21:54 . 2009-05-13 21:54 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-05-13 21:54 . 2009-05-13 21:54 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-05-13 21:54 . 2009-05-13 21:54 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-05-13 21:54 . 2009-05-13 21:54 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-05-13 21:54 . 2009-05-13 21:54 811008 ----a-w- c:\windows\system32\divx_xx16.dll
2009-05-13 21:54 . 2009-05-13 21:54 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-05-13 21:54 . 2009-05-13 21:54 685056 ----a-w- c:\windows\system32\DivX.dll
2009-06-03 03:00 . 2009-07-02 21:45 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-05-13 21:55 . 2009-05-13 21:55 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-13 21:55 . 2009-05-13 21:55 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-15_04.05.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-05 17:21 . 2009-07-07 15:10 24539592 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-12-16 82009]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2004-08-18 184320]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-27 122880]
"dla"="c:\windows\system32\dla\DLACTRLW.exe" [2005-10-06 122940]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-18 151552]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-02 1948440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-03-11 73728]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-10-15 88203]
"NDSTray.exe"="NDSTray.exe" [BU]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-02 21:44 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RAMASST.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk
backup=c:\windows\pss\RAMASST.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Joshlin\\Desktop\\utorrent.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/2/2009 2:44 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7/2/2009 2:44 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/2/2009 2:44 PM 298776]
S2 eac_notifysvc;eAcceleration Notification Service;"c:\progra~1\EACCEL~1\FRAMEW~1\eac_svc.exe" --> c:\progra~1\EACCEL~1\FRAMEW~1\eac_svc.exe [?]
S2 eac_productsvc;eAcceleration Product Manager Service;"c:\progra~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe" --> c:\progra~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe [?]
S2 gupdate1c9fbc7338d9430;Google Update Service (gupdate1c9fbc7338d9430);c:\program files\Google\Update\GoogleUpdate.exe [7/3/2009 3:15 AM 133104]
S2 sstsmonsvc;StopSign Antivirus Security Center Provider;"c:\progra~1\EACCEL~1\FRAMEW~1\eac_svc.exe" --> c:\progra~1\EACCEL~1\FRAMEW~1\eac_svc.exe [?]
S3 SVRPEDRV;SVRPEDRV;\??\c:\sysprep\PEDrv.sys --> c:\sysprep\PEDrv.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-07-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-03 10:15]
2009-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-03 10:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.toshibadirect.com/dpdstart
uInternet Connection Wizard,ShellNext = hxxp://www.toshibadirect.com/dpdstart
uInternet Settings,ProxyOverride = local
uInternet Settings,ProxyServer = http=127.0.0.1:5656
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Joshlin\Application Data\Mozilla\Firefox\Profiles\wf1nzhjc.default\
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJPI150_04.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-17 13:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-07-17 13:43
ComboFix-quarantined-files.txt 2009-07-17 20:43
ComboFix2.txt 2009-07-15 21:13
ComboFix3.txt 2009-07-15 04:08
Pre-Run: 46,111,244,288 bytes free
Post-Run: 46,123,212,800 bytes free
256 --- E O F --- 2009-07-16 10:02