Yes remove punkbuster if it helps get rid of malware
Still get redirected to sites btw
ComboFix 10-01-28.05 - Jason Mak 29/01/2010 0:28.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2038.1137 [GMT -8:00]
Running from: c:\users\Jason Mak\Desktop\ComboFix.exe
Command switches used :: c:\users\Jason Mak\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FILE ::
"c:\windows\system32\GameMon.des.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\1f600600f0bbdf5156e2a253c613ae63
c:\1f600600f0bbdf5156e2a253c613ae63\MRT.exe
c:\program files\AskBarDis
c:\users\Jason Mak\AppData\Roaming\Azureus
c:\users\Jason Mak\AppData\Roaming\Azureus\.certs
c:\users\Jason Mak\AppData\Roaming\Azureus\.keystore
c:\users\Jason Mak\AppData\Roaming\Azureus\.lock
c:\users\Jason Mak\AppData\Roaming\Azureus\active\4601DEFB2877A5C1F5132E5ACF57E45ACEEC5180.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\active\4EA451667268162E57ABAC0482EE4A57DF032794.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\active\cache.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\active\D211E7D44FDDCDBD3277D1C59C6B77AEA24EB0CD.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\azureus.config
c:\users\Jason Mak\AppData\Roaming\Azureus\azureus.statistics
c:\users\Jason Mak\AppData\Roaming\Azureus\cache\1191085919.ico
c:\users\Jason Mak\AppData\Roaming\Azureus\cnetworks.config
c:\users\Jason Mak\AppData\Roaming\Azureus\devices.config
c:\users\Jason Mak\AppData\Roaming\Azureus\dht\addresses.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\dht\contacts.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\dht\diverse.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\dht\general.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\dht\net3\addresses.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\dht\net3\contacts.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\dht\net3\diverse.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\dht\net3\version.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\dht\version.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\downloads.config
c:\users\Jason Mak\AppData\Roaming\Azureus\friends.config
c:\users\Jason Mak\AppData\Roaming\Azureus\ipfilter.cache
c:\users\Jason Mak\AppData\Roaming\Azureus\metasearch.config
c:\users\Jason Mak\AppData\Roaming\Azureus\net\pm_6327.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\net\pm_default.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\plugins\azupnpav\cd.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\sidebarauto.config
c:\users\Jason Mak\AppData\Roaming\Azureus\subs\75073EF5A9EA448FA71D.vuze
c:\users\Jason Mak\AppData\Roaming\Azureus\subscriptions.config
c:\users\Jason Mak\AppData\Roaming\Azureus\tables.config
c:\users\Jason Mak\AppData\Roaming\Azureus\torrents\AZU4069166486322495536.tmp
c:\users\Jason Mak\AppData\Roaming\Azureus\torrents\AZU4941580240540332587.tmp
c:\users\Jason Mak\AppData\Roaming\Azureus\torrents\Call of Duty(R) 4 - Modern Warfare.torrent
c:\users\Jason Mak\AppData\Roaming\Azureus\torrents\NHL.09-RELOADED.4463451.TPB.torrent
c:\users\Jason Mak\AppData\Roaming\Azureus\tracker.config
c:\users\Jason Mak\AppData\Roaming\Azureus\unsentdata.config
c:\users\Jason Mak\AppData\Roaming\Azureus\update.properties
c:\users\Jason Mak\AppData\Roaming\Azureus\v3.Friends.dat
c:\users\Jason Mak\AppData\Roaming\Azureus\VuzeActivities.config
c:\users\Jason Mak\AppData\Roaming\LimeWire
c:\users\Jason Mak\AppData\Roaming\LimeWire\.AppSpecialShare\NHL.09-RELOADED.torrent.bak
c:\users\Jason Mak\AppData\Roaming\LimeWire\414splashfree.png
c:\users\Jason Mak\AppData\Roaming\LimeWire\active.mojito
c:\users\Jason Mak\AppData\Roaming\LimeWire\certificate\limewire.keystore
c:\users\Jason Mak\AppData\Roaming\LimeWire\createtimes.cache
c:\users\Jason Mak\AppData\Roaming\LimeWire\downloads.dat
c:\users\Jason Mak\AppData\Roaming\LimeWire\fileurns.bak
c:\users\Jason Mak\AppData\Roaming\LimeWire\fileurns.cache
c:\users\Jason Mak\AppData\Roaming\LimeWire\filters.props
c:\users\Jason Mak\AppData\Roaming\LimeWire\gnutella.net
c:\users\Jason Mak\AppData\Roaming\LimeWire\installation.props
c:\users\Jason Mak\AppData\Roaming\LimeWire\library.dat
c:\users\Jason Mak\AppData\Roaming\LimeWire\limewire.props
c:\users\Jason Mak\AppData\Roaming\LimeWire\mojito.props
c:\users\Jason Mak\AppData\Roaming\LimeWire\promotion\promodb.backup
c:\users\Jason Mak\AppData\Roaming\LimeWire\promotion\promodb.data
c:\users\Jason Mak\AppData\Roaming\LimeWire\promotion\promodb.properties
c:\users\Jason Mak\AppData\Roaming\LimeWire\promotion\promodb.script
c:\users\Jason Mak\AppData\Roaming\LimeWire\questions.props
c:\users\Jason Mak\AppData\Roaming\LimeWire\responses.cache
c:\users\Jason Mak\AppData\Roaming\LimeWire\simpp.xml
c:\users\Jason Mak\AppData\Roaming\LimeWire\spam.dat
c:\users\Jason Mak\AppData\Roaming\LimeWire\tables.props
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme.lwtp
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\01_star.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\02_star.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\03_star.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\04_star.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\05_star.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\chat.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\forward_dn.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\forward_up.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\kill.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\kill_on.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\logo.png
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\notsearching.png
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\pause_dn.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\pause_up.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\play_dn.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\play_up.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\question.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\rewind_dn.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\rewind_up.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\searching.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\splash.png
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\splashpro.png
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\stop_dn.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\stop_up.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\theme.txt
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\version.txt
c:\users\Jason Mak\AppData\Roaming\LimeWire\themes\windows_theme\warning.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\ttree.cache
c:\users\Jason Mak\AppData\Roaming\LimeWire\ttrees.cache
c:\users\Jason Mak\AppData\Roaming\LimeWire\ttroot.cache
c:\users\Jason Mak\AppData\Roaming\LimeWire\version.xml
c:\users\Jason Mak\AppData\Roaming\LimeWire\versions.props
c:\users\Jason Mak\AppData\Roaming\LimeWire\xml\data\audio.sxml2
c:\users\Jason Mak\AppData\Roaming\LimeWire\xml\data\delete_me
c:\users\Jason Mak\AppData\Roaming\LimeWire\xml\misc\application.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\xml\misc\audio.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\xml\misc\document.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\xml\misc\image.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\xml\misc\video.gif
c:\users\Jason Mak\AppData\Roaming\LimeWire\xml\schemas\application.xsd
c:\users\Jason Mak\AppData\Roaming\LimeWire\xml\schemas\audio.xsd
c:\users\Jason Mak\AppData\Roaming\LimeWire\xml\schemas\document.xsd
c:\users\Jason Mak\AppData\Roaming\LimeWire\xml\schemas\image.xsd
c:\users\Jason Mak\AppData\Roaming\LimeWire\xml\schemas\video.xsd
.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-29 )))))))))))))))))))))))))))))))
.
2010-01-29 08:38 . 2010-01-29 08:38 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2010-01-29 08:38 . 2010-01-29 08:38 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-01-29 08:38 . 2010-01-29 08:38 -------- d-----w- c:\users\jason\AppData\Local\temp
2010-01-29 08:38 . 2010-01-29 08:38 -------- d-----w- c:\users\IUSR_NMPR\AppData\Local\temp
2010-01-29 08:38 . 2010-01-29 08:38 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-01-29 08:38 . 2010-01-29 08:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-28 07:30 . 2010-01-28 07:30 -------- d-----w- c:\program files\Messenger Plus! Live
2010-01-27 23:52 . 2010-01-29 08:38 -------- d-----w- c:\users\Jason Mak\AppData\Local\temp
2010-01-27 23:23 . 2010-01-27 23:23 -------- d-----w- c:\program files\ERUNT
2010-01-26 23:48 . 2010-01-26 23:48 5115824 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-26 23:41 . 2010-01-14 23:29 1260800 ----a-w- c:\programdata\avg9\update\backup\avgfrw.exe
2010-01-26 23:41 . 2010-01-14 23:29 3777280 ----a-w- c:\programdata\avg9\update\backup\setup.exe
2010-01-23 09:39 . 2010-01-23 09:39 -------- d-----w- C:\rsit
2010-01-23 08:52 . 2010-01-23 08:52 44288 ----a-w- c:\windows\system32\SysProtDrv.sys
2010-01-16 08:13 . 2010-01-16 08:13 -------- d-----w- c:\users\Jason Mak\AppData\Local\Cooliris
2010-01-16 08:13 . 2010-01-06 20:08 4726272 ----a-w- c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2010-01-16 08:13 . 2010-01-06 20:08 103424 ----a-w- c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2010-01-16 08:13 . 2010-01-06 20:08 57856 ----a-w- c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2010-01-16 08:13 . 2010-01-06 20:08 545280 ----a-w- c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2010-01-16 08:13 . 2010-01-06 20:08 4725760 ----a-w- c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
2010-01-16 08:13 . 2010-01-06 20:08 344064 ----a-w- c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2010-01-16 08:13 . 2010-01-06 20:08 153600 ----a-w- c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2010-01-16 03:01 . 2010-01-16 03:01 40 ----a-w- c:\windows\RSoftInfo.dat
2010-01-16 03:01 . 2010-01-16 03:01 352256 ----a-w- c:\windows\eSellerateEngine.dll
2010-01-15 00:12 . 2009-09-05 01:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2010-01-15 00:12 . 2009-09-05 01:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2010-01-15 00:12 . 2009-09-05 01:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2010-01-15 00:12 . 2009-09-05 01:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-01-15 00:12 . 2009-09-05 01:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2010-01-15 00:12 . 2009-09-05 01:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2010-01-15 00:12 . 2009-09-05 01:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-01-15 00:11 . 2010-01-15 00:11 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-01-15 00:11 . 2010-01-15 00:11 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-01-15 00:11 . 2010-01-15 00:11 -------- d-----w- c:\program files\OpenAL
2010-01-14 07:31 . 2010-01-17 02:57 -------- d-----w- c:\program files\a-squared Free
2010-01-14 07:29 . 2010-01-21 23:42 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-14 07:29 . 2010-01-21 23:35 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-01-13 03:38 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 03:38 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-07 02:55 . 2006-06-19 20:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2010-01-07 02:55 . 2006-05-25 22:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2010-01-07 02:55 . 2005-08-26 08:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2010-01-07 02:55 . 2003-02-03 03:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2010-01-07 02:55 . 2002-03-06 08:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2010-01-07 02:55 . 2010-01-07 02:55 -------- d-----w- c:\program files\Trojan Remover
2010-01-07 02:55 . 2010-01-07 02:55 -------- d-----w- c:\users\Jason Mak\AppData\Roaming\Simply Super Software
2010-01-07 02:55 . 2010-01-07 02:55 -------- d-----w- c:\programdata\Simply Super Software
2010-01-07 00:20 . 2010-01-07 00:20 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-01-07 00:20 . 2010-01-21 23:35 -------- d-----w- c:\users\Jason Mak\AppData\Roaming\SUPERAntiSpyware.com
2010-01-07 00:20 . 2010-01-21 23:35 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-07 00:17 . 2010-01-07 00:17 -------- d-----w- c:\users\Jason Mak\AppData\Roaming\Malwarebytes
2010-01-07 00:17 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 00:17 . 2010-01-26 23:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-07 00:17 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 00:17 . 2010-01-07 00:17 -------- d-----w- c:\programdata\Malwarebytes
2010-01-07 00:16 . 2010-01-07 00:16 -------- d-----w- c:\program files\Trend Micro
2010-01-07 00:13 . 2010-01-07 00:13 -------- d-----w- c:\program files\CCleaner
2010-01-01 05:11 . 2010-01-01 05:14 239 ----a-w- c:\windows\PowerReg.dat
2010-01-01 05:11 . 1999-05-29 08:08 45568 ----a-w- c:\windows\UniFish3.exe
2010-01-01 00:05 . 2010-01-01 00:10 -------- d-----w- c:\program files\Garena
14109-05-05 22:57 . 2009-06-05 00:03 -------- d-----w- c:\programdata\Kaspersky Lab
14109-05-05 22:55 . 14109-05-05 22:55 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
14109-05-04 06:46 . 2009-12-26 10:41 -------- d-----w- c:\program files\AVG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-29 07:47 . 2009-12-23 10:34 0 ----a-w- c:\users\Jason Mak\AppData\Local\prvlcl.dat
2010-01-28 22:22 . 2008-12-20 21:59 -------- d-----w- c:\program files\Steam
2010-01-28 07:30 . 2008-01-16 01:28 -------- d-----w- c:\programdata\Messenger Plus!
2010-01-26 02:08 . 2009-12-26 10:41 -------- d-----w- c:\programdata\avg9
2010-01-23 20:38 . 2008-12-20 22:42 -------- d-----w- c:\program files\Common Files\Steam
2010-01-21 23:33 . 2007-08-12 01:42 -------- d-----w- c:\program files\Java
2010-01-20 23:20 . 2009-04-16 06:17 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-18 05:37 . 2007-11-29 06:01 3756 ----a-w- c:\users\Jason Mak\AppData\Roaming\wklnhst.dat
2010-01-16 02:57 . 2007-08-12 01:25 -------- d-----w- c:\programdata\WildTangent
2010-01-15 06:20 . 2008-04-13 23:51 -------- d-----w- c:\programdata\Microsoft Help
2010-01-14 14:40 . 2009-05-10 23:50 -------- d-----w- c:\program files\Cheat Engine
2010-01-13 23:55 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-08 06:37 . 2009-12-21 10:45 -------- d-----w- c:\users\Jason Mak\AppData\Roaming\DivX
2010-01-07 02:04 . 2009-08-20 03:28 -------- d-----w- c:\program files\iWin Games
2010-01-02 06:38 . 2010-01-21 23:32 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-21 23:32 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-21 23:32 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-21 23:32 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-26 11:21 . 2009-12-26 11:21 -------- d-----w- c:\users\Jason Mak\AppData\Roaming\AVG9
2009-12-26 11:07 . 2009-12-26 10:42 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-26 11:07 . 2009-12-26 10:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-26 11:07 . 2009-12-26 10:42 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-26 11:07 . 2009-12-26 10:42 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-12-26 10:42 . 2009-12-26 10:42 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-24 02:41 . 2009-12-24 09:05 52224 ----a-w- c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\{4a8f88b8-4a70-41bd-bc89-385c364116d9}\components\FFExternalAlert.dll
2009-12-24 02:41 . 2009-12-24 09:05 101376 ----a-w- c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\{4a8f88b8-4a70-41bd-bc89-385c364116d9}\components\RadioWMPCore.dll
2009-12-21 10:43 . 2009-12-21 10:42 -------- d-----w- c:\program files\DivX
2009-12-21 10:43 . 2007-08-12 01:35 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-12-21 10:42 . 2009-12-21 10:42 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-12-08 04:53 . 2009-07-26 06:19 -------- d-----w- c:\users\Jason Mak\AppData\Roaming\HpUpdate
2009-12-08 00:14 . 2009-11-18 04:55 -------- d-----w- c:\program files\DriftCity
2009-12-04 03:19 . 2009-12-04 03:19 764168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-01 06:58 . 2007-08-12 01:10 -------- d-----w- c:\program files\Hewlett-Packard
2009-12-01 06:58 . 2007-11-28 07:07 -------- d-----w- c:\users\Jason Mak\AppData\Roaming\Hewlett-Packard
2009-12-01 06:58 . 2007-08-12 02:12 -------- d-----w- c:\programdata\Hewlett-Packard
2009-11-19 03:49 . 2009-11-19 03:49 201356 ---ha-w- c:\windows\system32\mlfcache.dat
2009-11-19 03:48 . 2009-11-19 03:48 2165 ----a-w- c:\users\Jason Mak\AppData\Roaming\Raptr\config\certificates\x509\tls_peers\rsi.hotmail.com
2009-11-18 23:31 . 2009-11-18 23:31 2141 ----a-w- c:\users\Jason Mak\AppData\Roaming\Raptr\config\certificates\x509\tls_peers\omega.contacts.msn.com
2009-11-18 23:31 . 2009-11-18 23:31 2095 ----a-w- c:\users\Jason Mak\AppData\Roaming\Raptr\config\certificates\x509\tls_peers\login.live.com
2009-11-18 23:31 . 2009-11-18 23:31 1251 ----a-w- c:\users\Jason Mak\AppData\Roaming\Raptr\config\certificates\x509\tls_peers\xmpp.raptr.com
2009-11-18 06:23 . 2009-11-18 06:24 38208 ----a-w- c:\users\Jason Mak\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-17 23:36 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-16 10:21 . 2009-06-08 11:15 205448 ----a-w- c:\users\Jason Mak\AppData\Roaming\Smilebox\SmileboxDvd.exe
2009-11-16 10:21 . 2009-06-08 11:15 266888 ----a-w- c:\users\Jason Mak\AppData\Roaming\Smilebox\SmileboxTray.exe
2009-11-16 10:21 . 2009-06-08 11:08 373384 ----a-w- c:\users\Jason Mak\AppData\Roaming\Smilebox\SmileboxStarter.exe
2009-11-16 10:21 . 2009-06-08 10:45 168584 ----a-w- c:\users\Jason Mak\AppData\Roaming\Smilebox\SmileboxBrowserEngine.dll
2009-11-16 10:12 . 2009-11-16 10:12 1581704 ----a-w- c:\users\Jason Mak\AppData\Roaming\Smilebox\SmileboxClient.exe
2009-11-16 09:17 . 2009-11-16 09:17 340616 ----a-w- c:\users\Jason Mak\AppData\Roaming\Smilebox\SmileboxDvdEngine.dll
2009-11-16 09:17 . 2009-11-16 09:17 123528 ----a-w- c:\users\Jason Mak\AppData\Roaming\Smilebox\SmileboxUpdater.exe
2009-11-15 09:37 . 2008-06-25 19:33 393216 ----a-w- c:\programdata\NexonUS\NGM\NGMResource.dll
2009-11-15 09:37 . 2008-06-25 19:33 258352 ----a-w- c:\programdata\NexonUS\NGM\unicows.dll
2009-11-15 09:37 . 2007-12-25 08:13 90112 ----a-w- c:\programdata\NexonUS\NGM\npNxGameUS.dll
2009-11-15 09:37 . 2007-12-25 08:13 118784 ----a-w- c:\programdata\NexonUS\NGM\nxgameus.dll
2009-11-15 09:37 . 2007-12-25 08:14 561152 ----a-w- c:\programdata\NexonUS\NGM\NGMDll.dll
2009-11-15 09:37 . 2007-12-25 08:13 167936 ----a-w- c:\programdata\NexonUS\NGM\NGM.exe
2009-11-14 02:59 . 2009-11-14 02:59 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-14 02:59 . 2009-11-14 02:59 22328 ----a-w- c:\users\Jason Mak\AppData\Roaming\PnkBstrK.sys
2009-11-14 02:59 . 2009-11-14 02:59 22328 ----a-w- c:\users\Jason Mak\AppData\Roaming\PnkBstrK.sys
2009-11-14 02:58 . 2009-11-14 02:33 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-11-14 02:33 . 2009-11-14 02:33 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-11-14 00:49 . 2007-08-12 01:39 120056 ------w- c:\windows\system32\pxcpyi64.exe
2009-11-14 00:49 . 2007-08-12 01:39 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-11-14 00:49 . 2007-02-06 23:03 129784 ------w- c:\windows\system32\PxAFS.DLL
2009-11-14 00:47 . 2009-11-14 00:47 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 . 2009-11-14 00:47 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 . 2009-11-14 00:47 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 . 2009-11-14 00:47 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47 . 2009-11-14 00:47 696320 ----a-w- c:\windows\system32\DivX.dll
2009-11-10 02:16 . 2008-06-04 02:37 46128 ----a-w- c:\programdata\iWin Games\firefox\iWinArcadeLauncher.exe
2009-11-09 12:31 . 2009-12-12 21:14 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-12 21:14 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-12 21:14 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-11-09 05:20 . 2009-11-09 05:20 138240 ----a-w- c:\users\Jason Mak\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_d.dll
2009-11-09 05:20 . 2009-11-09 05:20 138240 ----a-w- c:\users\Jason Mak\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_c.dll
2009-11-09 05:20 . 2009-11-09 05:20 138240 ----a-w- c:\users\Jason Mak\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_b.dll
2009-11-09 05:20 . 2009-11-09 05:20 138240 ----a-w- c:\users\Jason Mak\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_a.dll
2009-11-03 23:29 . 2007-11-28 07:18 123696 ----a-w- c:\users\Jason Mak\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-03 04:42 . 2009-10-03 01:47 195456 ------w- c:\windows\system32\MpSigStub.exe
14109-05-05 06:17 . 2007-08-12 01:54 -------- d--h--w- c:\programdata\yahoo!
14109-05-05 06:17 . 2007-08-12 01:54 -------- d-----w- c:\program files\Yahoo!
2007-08-12 01:51 . 2007-08-12 01:46 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-11-13 2923192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCUTRAYICON"="FactoryMode" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 4874240]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 71176]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2009-10-11 55072]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-27 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-27 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-27 150552]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-12-26 2033432]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-27 3883856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish Media Detector.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk
backup=c:\windows\pss\Snapfish Media Detector.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):8c,30,c2,f3,84,32,ca,01
R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [26/12/2009 2:42 AM 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [26/12/2009 2:42 AM 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\System32\drivers\avgtdix.sys [26/12/2009 2:42 AM 360584]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [13/01/2010 11:31 PM 1858144]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [26/12/2009 3:07 AM 285392]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [29/10/2009 12:27 PM 1074568]
R2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [09/11/2009 6:17 PM 78104]
S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [03/09/2006 9:32 AM 208896]
S2 IntelDHSvcConf;Intel DH Service;c:\program files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [10/05/2006 8:13 AM 29696]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [02/06/2008 4:45 PM 21504]
S3 VST_DPV;VST_DPV;c:\windows\System32\drivers\VSTDPV3.SYS [02/06/2008 4:43 PM 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\System32\drivers\VSTBS23.SYS [02/06/2008 4:43 PM 251904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 11:32 128512 ----a-w- c:\windows\System32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
2010-01-29 c:\windows\Tasks\HPCeeScheduleForJason Mak.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-08-12 23:55]
2010-01-29 c:\windows\Tasks\User_Feed_Synchronization-{F032D026-57FC-4605-A0FD-B7937CDBE7AB}.job
- c:\windows\system32\msfeedssync.exe [2010-01-21 04:56]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://google.ca/mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktopIE: &Search
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.ca/firefox?client=fir ... S:officialFF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\{4a8f88b8-4a70-41bd-bc89-385c364116d9}\components\FFExternalAlert.dll
FF - component: c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\{4a8f88b8-4a70-41bd-bc89-385c364116d9}\components\RadioWMPCore.dll
FF - component: c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\users\Jason Mak\AppData\Roaming\Mozilla\Firefox\Profiles\45wuh27w.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-29 00:38
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x85219841]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x881abd24
\Driver\ACPI -> acpi.sys @ 0x80696d68
\Driver\atapi -> ataport.SYS @ 0x807aca2c
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\users\JASONM~1\AppData\Local\Temp\LWPB325.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1222584859-2993816260-699220527-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:2b,68,35,b7,ec,77,bf,f1,a4,3d,ce,96,25,b2,37,22,c0,a9,8a,a6,0c,54,c3,
ca,cf,c2,a0,d4,14,66,2b,59,d3,21,f1,20,30,db,1d,7b,80,56,0c,8c,33,be,b4,a7,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
[HKEY_USERS\S-1-5-21-1222584859-2993816260-699220527-1001\Software\SecuROM\License information*]
"datasecu"=hex:77,31,6a,0e,13,09,86,59,3c,92,23,29,c4,f8,43,65,c0,ae,e4,6b,b6,
e1,a5,77,6a,9f,cb,24,38,00,fe,e1,21,ac,b1,af,06,d6,31,81,81,2b,d8,04,18,65,\
"rkeysecu"=hex:f7,57,41,d2,e2,5c,1f,b6,fd,f3,e0,18,25,d3,77,f3
[HKEY_USERS\S-1-5-21-1222584859-2993816260-699220527-1001_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):9e,05,74,ff,bb,6c,d9,d9,89,e5,19,7e,24,60,ec,e7,36,a2,2c,2e,ab,
8c,a5,85,ac,e6,f8,50,3a,d0,a8,23,bf,e6,9e,68,e3,05,80,dc,00,00,00,00,00,00,\
[HKEY_USERS\S-1-5-21-1222584859-2993816260-699220527-1001_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):e5,6b,38,29,df,dd,2d,1d,25,7c,b7,f0,b9,dc,59,e0,b2,bb,ab,68,97,
48,0d,36,8a,f6,ea,22,8a,60,31,8f,93,82,33,80,55,fc,41,ff,00,00,00,00,00,00,\
[HKEY_USERS\S-1-5-21-1222584859-2993816260-699220527-1001_Classes\CLSID\{9296d726-1cd2-46e1-917a-2eaf4d627d0d}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:000000de
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,bd,fc,19,8f,58,3c,8e,25,96,94,16,7a,19,d5,dc,a7,3f,cb,c4,3f,5b,b9,\
[HKEY_USERS\S-1-5-21-1222584859-2993816260-699220527-1001_Classes\CLSID\{d2bf510e-03fa-4ac3-90a6-f6df4a25b1a1}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:0000013a
"Therad"=dword:00000001
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-01-29 00:41:56
ComboFix-quarantined-files.txt 2010-01-29 08:41
ComboFix2.txt 2010-01-27 23:52
Pre-Run: 259,162,300,416 bytes free
Post-Run: 259,116,814,336 bytes free
- - End Of File - - 4725526467752087FFA9FF2642B5B546