ComboFix 09-11-30.05 - adam 01/12/2009 13:44.1.2 - x86 Microsoft� Windows Vista� Home Premium 6.0.6001.1.1252.44.1033.18.2814.1451 [GMT 0:00] Running from: c:\users\[removed]\Desktop\AdamskyyCF.exe.exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-2760852498-2543259003-1422614318-1000 c:\$recycle.bin\S-1-5-21-887134994-1243305392-2542070696-500 c:\users\adam\AppData\Roaming\inst.exe c:\windows\system32\tdlclk.dll c:\windows\system32\tdlcmd.dll F:\install.exe . ((((((((((((((((((((((((( Files Created from 2009-11-01 to 2009-12-01 ))))))))))))))))))))))))))))))) . 2009-12-01 13:55 . 2009-12-01 13:55 -------- d-----w- c:\users\Default\AppData\Local\temp 2009-11-30 14:02 . 2009-11-30 14:02 -------- d-----w- C:\_OTL 2009-11-28 23:14 . 2009-11-28 23:14 -------- d-----w- C:\temp 2009-11-28 23:13 . 2009-11-28 23:13 -------- d-----w- c:\users\adam\AppData\Local\Pinnacle 2009-11-28 23:06 . 2006-04-11 16:03 233472 ------w- c:\windows\system32\DiskIO.dll 2009-11-28 23:06 . 2006-04-11 16:03 184320 ------w- c:\windows\system32\RALMain.dll 2009-11-28 23:06 . 2001-12-11 23:21 73728 ------w- c:\windows\system32\MMAviAx.dll 2009-11-28 23:06 . 2006-07-06 14:32 39936 ------w- c:\windows\system32\CacheX.dll 2009-11-28 23:06 . 2005-12-12 16:57 32768 ------w- c:\windows\system32\MLPagAx.dll 2009-11-28 23:06 . 2004-01-02 13:28 126976 ------w- c:\windows\system32\AVIPrAx.dll 2009-11-28 23:04 . 2005-06-02 19:28 171008 ----a-w- c:\windows\system32\drivers\MarvinBus.sys 2009-11-28 23:02 . 2005-12-21 10:14 19712 ----a-w- c:\windows\system32\drivers\emAudio.sys 2009-11-28 23:00 . 2002-01-05 13:40 487424 ------w- c:\windows\system32\MSVCP70.DLL 2009-11-28 23:00 . 2002-01-05 12:18 84992 ------w- c:\windows\system32\ATL70.DLL 2009-11-28 22:59 . 2009-11-28 23:01 -------- d-----w- c:\programdata\Pinnacle 2009-11-28 22:59 . 2009-11-28 23:00 -------- d-----w- c:\program files\Pinnacle 2009-11-28 22:59 . 2009-11-28 22:59 -------- d-----w- c:\users\adam\AppData\Roaming\InstallShield 2009-11-28 10:38 . 2009-11-28 10:38 4096 d-----w- C:\MGADiagToolOutput 2009-11-28 10:37 . 2009-11-28 10:37 -------- d-----w- c:\programdata\Office Genuine Advantage 2009-11-26 09:59 . 2009-10-29 09:41 2048 ----a-w- c:\windows\system32\tzres.dll 2009-11-25 11:27 . 2009-08-10 11:01 1399296 ----a-w- c:\windows\system32\msxml6.dll 2009-11-25 11:27 . 2009-08-10 11:00 1257472 ----a-w- c:\windows\system32\msxml3.dll 2009-11-24 12:09 . 2009-11-24 12:09 -------- d-----w- c:\users\adam\AppData\Local\Temporary Projects 2009-11-24 11:49 . 2009-11-24 11:49 -------- d-----w- c:\program files\Windows Resource Kits 2009-11-23 21:47 . 2009-11-23 21:47 -------- d-----w- c:\program files\Microsoft Synchronization Services 2009-11-23 21:46 . 2009-11-23 21:46 193824 ----a-w- c:\programdata\Microsoft\VBExpress\9.0\1033\ResourceCache.dll 2009-11-23 21:46 . 2009-11-23 21:46 416 ----a-w- c:\programdata\Microsoft\MSDN\9.0\1033\ResourceCache.dll 2009-11-23 21:45 . 2009-11-23 21:45 -------- d-----w- c:\users\adam\AppData\Local\Microsoft Help 2009-11-23 21:43 . 2009-11-23 21:47 4096 d-----w- c:\program files\Microsoft Visual Studio 9.0 2009-11-23 21:43 . 2009-11-23 21:43 -------- d-----w- c:\program files\Microsoft SDKs 2009-11-21 11:42 . 2009-12-01 13:33 63 ----a-w- c:\users\adam\jagex_runescape_preferences2.dat 2009-11-21 11:42 . 2009-12-01 13:35 38 ----a-w- c:\users\adam\jagex_runescape_preferences.dat 2009-11-21 10:46 . 2009-11-21 10:58 -------- d-----w- c:\users\adam\AppData\Roaming\ImgBurn 2009-11-21 10:36 . 2009-11-21 10:36 4096 d-----w- c:\program files\ImgBurn 2009-11-20 13:43 . 2009-11-19 19:30 497944 ----a-w- c:\programdata\avg9\update\backup\avgchjwx.dll 2009-11-20 13:43 . 2009-11-19 19:30 3963648 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll 2009-11-20 13:41 . 2009-11-19 19:30 877848 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe 2009-11-20 13:41 . 2009-11-19 19:30 1657112 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll 2009-11-19 19:30 . 2009-11-19 19:35 -------- d-----w- C:\$AVG 2009-11-19 19:30 . 2009-11-19 19:30 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2009-11-19 19:30 . 2009-11-19 19:30 12464 ----a-w- c:\windows\system32\avgrsstx.dll 2009-11-19 19:30 . 2009-11-19 19:30 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-11-19 19:30 . 2009-11-19 19:30 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-11-19 19:30 . 2009-12-01 11:50 4096 d-----w- c:\windows\system32\drivers\Avg 2009-11-19 19:30 . 2009-11-19 19:30 -------- d-----w- c:\program files\AVG 2009-11-19 19:30 . 2009-11-26 09:54 4096 d-----w- c:\programdata\avg9 2009-11-19 18:40 . 2009-11-19 18:40 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files 2009-11-19 17:58 . 2009-11-19 17:58 -------- d-----w- c:\program files\Trend Micro 2009-11-19 16:36 . 2009-08-14 13:53 2035712 ----a-w- c:\windows\system32\win32k.sys 2009-11-19 16:35 . 2009-11-02 20:42 195456 ------w- c:\windows\system32\MpSigStub.exe 2009-11-18 21:06 . 2009-11-18 21:16 4096 d-----w- c:\programdata\Spybot - Search & Destroy 2009-11-18 21:06 . 2009-11-18 21:06 4096 d-----w- c:\program files\Spybot - Search & Destroy 2009-11-18 20:45 . 2009-11-18 20:45 -------- d-----w- c:\users\adam\AppData\Roaming\Malwarebytes 2009-11-18 20:45 . 2009-11-18 20:45 4096 d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-11-18 20:45 . 2009-11-18 20:45 -------- d-----w- c:\programdata\Malwarebytes 2009-11-15 20:29 . 2009-11-15 20:29 -------- d-----w- c:\program files\Quantum 2009-11-13 13:33 . 2009-11-13 13:33 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2 2009-11-11 13:53 . 2009-11-11 13:53 -------- d-----w- c:\users\adam\AppData\Local\LogiShrd 2009-11-11 13:52 . 2009-11-11 13:52 -------- d-----w- c:\users\adam\AppData\Roaming\Leadertech 2009-11-11 13:49 . 2009-11-12 14:50 -------- d-----w- c:\programdata\LogiShrd 2009-11-11 13:49 . 2009-11-11 13:52 -------- d-----w- c:\program files\Logitech 2009-11-11 11:28 . 2009-08-10 13:05 351232 ----a-w- c:\windows\system32\WSDApi.dll 2009-11-11 11:28 . 2009-08-10 13:05 351232 ----a-w- c:\windows\system32\WSDApi(543).dll 2009-11-09 22:03 . 2009-11-09 22:04 4096 d-----w- c:\program files\Web Site Change Monitor 2009-11-06 20:26 . 2009-11-25 16:49 -------- d-----w- C:\Games 2009-11-02 16:28 . 2009-11-02 16:28 -------- d-----w- c:\program files\CCleaner 2009-11-01 16:28 . 2009-11-01 16:28 -------- d-----w- C:\.jagex_cache_32 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-01 13:54 . 2009-10-08 13:28 4096 d-----w- c:\users\adam\AppData\Roaming\Skype 2009-12-01 11:44 . 2009-10-08 13:30 4096 d-----w- c:\users\adam\AppData\Roaming\skypePM 2009-12-01 11:43 . 2009-11-30 14:10 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs 2009-11-30 21:48 . 2009-10-25 12:07 12288 d-----w- c:\program files\SwiftKit 2009-11-29 11:46 . 2009-10-12 14:19 4096 d-----w- c:\users\adam\AppData\Roaming\vlc 2009-11-28 23:11 . 2009-10-05 16:13 79904 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT 2009-11-28 23:00 . 2009-01-09 18:12 8192 d--h--w- c:\program files\InstallShield Installation Information 2009-11-25 11:30 . 2009-10-06 12:21 784120 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2009-11-23 21:59 . 2009-10-03 17:43 4096 d-----w- c:\users\adam\AppData\Roaming\mIRC 2009-11-23 21:47 . 2009-10-08 14:40 -------- d-----w- c:\program files\Microsoft SQL Server 2009-11-23 21:47 . 2009-01-09 18:50 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition 2009-11-23 21:47 . 2009-01-09 18:30 12288 d-----w- c:\programdata\Microsoft Help 2009-11-23 18:57 . 2009-10-03 17:43 4096 d-----w- c:\program files\mIRC 2009-11-20 21:21 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail 2009-11-20 14:43 . 2009-01-09 19:00 4096 d-----w- c:\program files\Acer GameZone 2009-11-20 13:45 . 2009-10-11 21:13 -------- d-----w- c:\program files\freebird 2009-11-19 18:48 . 2009-01-09 18:38 4096 d-----w- c:\program files\McAfee 2009-11-19 18:48 . 2009-01-09 18:37 4096 d-----w- c:\programdata\McAfee 2009-11-19 16:16 . 2009-10-03 15:31 8224 ----a-w- c:\users\adam\AppData\Local\GDIPFONTCACHEV1.DAT 2009-11-19 16:11 . 2009-01-09 18:32 32768 d-----w- c:\program files\Microsoft Works 2009-11-19 16:11 . 2009-10-03 19:26 4096 d-----w- c:\program files\Common Files\logishrd 2009-11-17 16:13 . 2009-10-17 16:10 -------- d-----w- c:\users\adam\AppData\Roaming\Pamela 2009-11-07 11:56 . 2009-10-21 17:37 4096 d-----w- c:\users\adam\AppData\Roaming\Vso 2009-11-02 13:43 . 2009-01-09 18:45 4096 d-----w- c:\program files\Google 2009-11-01 12:03 . 2009-11-01 12:03 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll 2009-11-01 11:04 . 2009-10-11 10:23 -------- d-----w- c:\program files\Yahoo! 2009-11-01 11:02 . 2009-10-17 16:02 4096 d-----w- c:\program files\HotRecorder 2009-11-01 11:00 . 2009-10-20 17:21 4096 d-----w- c:\program files\Free DVD Creator 2009-11-01 11:00 . 2009-10-13 13:06 4096 d-----w- c:\program files\Freecorder 2009-10-25 12:07 . 2009-10-25 12:07 -------- d-----w- c:\programdata\SwiftKit 2009-10-23 14:08 . 2009-10-23 14:08 4096 d-----w- c:\program files\DivX 2009-10-23 14:08 . 2009-10-23 14:08 -------- d-----w- c:\program files\Common Files\DivX Shared 2009-10-22 12:03 . 2009-10-21 18:24 4096 d-----w- c:\programdata\vsosdk 2009-10-21 17:37 . 2009-10-21 17:37 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys 2009-10-21 17:37 . 2009-10-21 17:37 47360 ----a-w- c:\users\adam\AppData\Roaming\pcouffin.sys 2009-10-21 17:37 . 2009-10-21 17:37 47360 ----a-w- c:\users\adam\AppData\Roaming\pcouffin.sys 2009-10-21 17:37 . 2009-10-21 17:37 -------- d-----w- c:\program files\VSO 2009-10-20 17:37 . 2009-10-20 17:21 8192 d-----w- c:\program files\ffdshow 2009-10-20 17:14 . 2009-10-20 17:14 -------- d-----w- c:\users\adam\AppData\Roaming\Broad Intelligence 2009-10-20 17:14 . 2009-10-20 17:13 4096 d-----w- c:\program files\MediaCoder 2009-10-20 16:54 . 2009-10-20 16:54 59992 ----a-w- c:\programdata\Kaspersky Lab Setup Files\Kaspersky Internet Security 2010 9.0.0.736\English\setup.exe 2009-10-17 16:10 . 2009-10-17 16:10 4096 d-----w- c:\program files\Pamela 2009-10-17 16:10 . 2009-10-17 16:10 155136 ----a-w- c:\windows\system32\RemoteControl.dll 2009-10-17 15:57 . 2009-10-13 13:06 737280 ----a-w- c:\windows\iun6002.exe 2009-10-17 15:55 . 2009-10-17 15:48 4096 d-----w- c:\users\adam\AppData\Roaming\Call Graph 2009-10-17 15:50 . 2009-10-17 15:50 -------- d-----w- c:\users\adam\AppData\Roaming\Sedna Wireless 2009-10-17 15:48 . 2009-10-17 15:48 4096 d-----w- c:\program files\Call Graph 2009-10-14 21:29 . 2009-10-14 21:24 4096 d-----w- c:\program files\Acez Mp3 Wav Converter 2009-10-14 21:03 . 2009-10-14 21:03 -------- d-----w- c:\program files\Common Files\SWF Studio 2009-10-12 14:18 . 2009-10-12 14:18 -------- d-----w- c:\program files\VideoLAN 2009-10-11 21:20 . 2009-10-11 21:20 -------- d-----w- c:\users\adam\AppData\Roaming\Screaming Bee 2009-10-08 15:00 . 2009-10-08 15:00 -------- d-----w- c:\users\adam\AppData\Roaming\Publish Providers 2009-10-08 15:00 . 2009-10-08 14:39 -------- d-----w- c:\users\adam\AppData\Roaming\Sony 2009-10-08 14:39 . 2009-10-08 14:38 -------- d-----w- c:\programdata\Sony 2009-10-08 14:38 . 2009-10-08 14:38 -------- d-----w- c:\program files\Vstplugins 2009-10-08 14:37 . 2009-10-08 14:37 -------- d-----w- c:\program files\Sony 2009-10-08 14:35 . 2009-10-08 14:35 -------- d-----w- c:\program files\Sony Setup 2009-10-08 13:30 . 2009-10-08 13:30 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2009-10-08 13:28 . 2009-10-08 13:27 -------- d-----r- c:\program files\Skype 2009-10-08 13:27 . 2009-10-08 13:27 -------- d-----w- c:\program files\Common Files\Skype 2009-10-08 13:27 . 2009-10-08 13:21 -------- d-----w- c:\programdata\Skype 2009-10-06 13:41 . 2009-10-06 13:41 -------- d-----w- c:\program files\Java 2009-10-06 12:28 . 2009-01-09 18:51 4096 d-----w- c:\programdata\CyberLink 2009-10-06 12:28 . 2009-10-06 12:28 -------- d-----w- c:\users\adam\AppData\Roaming\CyberLink 2009-10-06 12:21 . 2009-10-06 12:21 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll 2009-10-04 16:55 . 2009-10-04 16:55 4096 d-----w- c:\program files\Convert AVI to MP4 2009-10-04 07:25 . 2009-10-04 07:25 -------- d-----w- c:\program files\MSXML 4.0 2009-10-03 22:05 . 2009-10-03 22:05 -------- d-----w- c:\program files\Common Files\PlayOnline 2009-10-03 21:03 . 2009-10-03 21:02 108 ----a-w- c:\programdata\Last.fm\Client\uninst2.bat 2009-10-03 21:03 . 2009-10-03 21:03 683801 ----a-w- c:\programdata\Last.fm\Client\UninstWMP\unins000.exe 2009-10-03 21:02 . 2009-10-03 21:02 -------- d-----w- c:\programdata\Last.fm 2009-10-03 21:02 . 2009-10-03 18:44 4096 d-----w- c:\program files\iTunes 2009-10-03 21:02 . 2009-10-03 21:02 683801 ----a-w- c:\programdata\Last.fm\Client\UninstITW\unins000.exe 2009-10-03 21:02 . 2009-10-03 21:02 8192 d-----w- c:\program files\Last.fm 2009-10-03 19:02 . 2009-10-03 19:02 4096 ----a-w- c:\windows\d3dx.dat 2009-10-03 18:56 . 2009-10-03 18:45 4096 d-----w- c:\users\adam\AppData\Roaming\Apple Computer 2009-10-03 18:45 . 2009-10-03 18:44 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-10-03 18:44 . 2009-10-03 18:44 -------- d-----w- c:\program files\iPod 2009-10-03 18:44 . 2009-10-03 18:41 -------- d-----w- c:\program files\Common Files\Apple 2009-10-03 18:44 . 2009-10-03 18:43 -------- d-----w- c:\programdata\Apple Computer 2009-10-03 18:43 . 2009-10-03 18:43 -------- d-----w- c:\program files\Bonjour 2009-10-03 18:43 . 2009-10-03 18:43 4096 d-----w- c:\program files\QuickTime 2009-10-03 18:43 . 2009-10-03 18:43 4096 d-----w- c:\program files\Apple Software Update 2009-10-03 18:41 . 2009-10-03 18:41 -------- d-----w- c:\programdata\Apple 2009-10-03 18:12 . 2009-10-03 18:12 -------- d-----w- c:\program files\PlayOnline 2009-10-03 18:12 . 2009-01-09 18:18 -------- d-----w- c:\program files\Common Files\InstallShield 2009-10-03 18:09 . 2009-10-03 18:09 -------- d-----w- c:\program files\directx 2009-10-03 17:26 . 2009-10-03 17:26 17801 ----a-w- c:\windows\system32\drivers\AegisP.sys 2009-10-03 17:20 . 2009-10-03 17:20 -------- d-----w- c:\program files\BT Voyager 2009-10-03 17:05 . 2009-01-09 18:48 4096 d-----w- c:\program files\Windows Live 2009-10-03 17:03 . 2009-10-03 17:03 -------- d-----w- c:\program files\Microsoft 2009-10-03 16:23 . 2009-10-03 16:23 0 ----a-w- c:\windows\nsreg.dat 2009-10-03 15:29 . 2009-01-09 18:29 -------- d-----w- c:\program files\Acer 2009-09-21 16:09 . 2009-09-21 16:09 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe 2009-09-16 09:22 . 2009-01-09 18:40 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys 2009-09-16 09:22 . 2009-01-09 18:40 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys 2009-09-16 09:22 . 2009-01-09 18:40 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys 2009-09-16 09:22 . 2009-01-09 18:40 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys 2009-09-16 09:22 . 2009-01-09 18:40 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys 2009-09-14 09:44 . 2009-10-16 13:16 144896 ----a-w- c:\windows\system32\drivers\srv2.sys 2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 01:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-07-03 135680] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-09-02 25623336] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "Acer Empowering Technology Monitor"="c:\program files\Acer\Empowering Technology\SysMonitor.exe" [2008-10-01 319488] "eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-07-30 526896] "PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-05-21 204908] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-08 13584928] "wltray.exe"="c:\windows\system32\wltray.exe" [2005-01-29 696422] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-06 148888] "AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-19 2020120] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-03-26 5369856] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [19/11/2009 19:30 333192] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\drivers\avgtdix.sys [19/11/2009 19:30 360584] R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [09/01/2009 18:54 269448] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [19/11/2009 19:30 906520] R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [19/11/2009 19:30 285392] R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [09/01/2009 18:29 24576] R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [23/09/2008 22:11 144632] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [09/01/2009 16:50 43552] R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\System32\drivers\vcsvad.sys [11/10/2009 21:02 17792] S2 0201691259589367mcinstcleanup;McAfee Application Installer Cleanup (0201691259589367);c:\users\adam\AppData\Local\Temp\020169~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\users\adam\AppData\Local\Temp\020169~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?] S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [23/09/2008 22:11 50424] S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\System32\drivers\ScreamingBAudio.sys [06/04/2009 12:19 23064] . . ------- Supplementary Scan ------- . uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=1&o=vp32&d=1006&m=aspire_x3200 mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=1&o=vp32&d=1006&m=aspire_x3200 uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 LSP: %SYSTEMROOT%\system32\nvLsp.dll FF - ProfilePath - c:\users\adam\AppData\Roaming\Mozilla\Firefox\Profiles\nfqifbzn.default\ FF - prefs.js: browser.startup.homepage - hxxp://facebook.com FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); . - - - - ORPHANS REMOVED - - - - HKLM-Run-PCLEUSBTip - c:\program files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe SafeBoot-mcmscsvc SafeBoot-MCODS AddRemove-mIRC - c:\program files\mIRC\uninstall.exe _?=c:\program files\mIRC AddRemove-NVIDIA Drivers - c:\windows\system32\nvuninst.exe UninstallGUI ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-01 13:55 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll nvstor32.sys >>UNKNOWN [0x87C14F61]<< kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> CLASSPNP.SYS @ 0x82b9e322 \Driver\ACPI -> acpi.sys @ 0x80614d4c \Driver\atapi -> ataport.SYS @ 0x8072b9a8 IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK ************************************************************************** . Completion time: 2009-12-01 13:59 ComboFix-quarantined-files.txt 2009-12-01 13:58 Pre-Run: 95,167,725,568 bytes free Post-Run: 95,144,329,216 bytes free - - End Of File - - 4D140A24F0D3ADD67048B2F542CDA532