Hi chaps
Newbie here. My computer had been running perfectly until last week when Windows Defender alerted me to the detection of a tron rnos or something of that nature. Tried deleting/quaranting it and eventually Defender said this had been done. Immiditiately after i couldnt run Hijackthis. When try to run it comes back saying windows cannot access the specified device, path or file. You may not have approriate permissions to access the item. Tried installed Sbybod S +D and when tried run it it too came back saying the same. I am the only user on this computer and automatically run it as administrator so it cannot be admin issues
Have already run the following on advice of a mate
Combofix and here is the log
ComboFix 09-10-05.01 - user1 06/10/2009 18:54.1.1 - NTFSx86
Microsoft® Windows Vista Home Basic 6.0.6002.2.1252.44.1033.18.1917.1132 [GMT 1:00]
Running from: c:\users\user1\Documents\Ulead DVD MovieFactory\Downloads\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Anti-Virus *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2365545147-1999384947-2466353664-500
c:\$recycle.bin\S-1-5-21-2393766080-3187394018-3383541026-500
c:\$recycle.bin\S-1-5-21-899496415-1834721142-2599837188-500
c:\program files\Common Files\System\Uninstall
c:\users\user1\AppData\Local\{0F714ABA-74F2-40FA-9D7C-5BA031B1883F}
c:\users\user1\AppData\Local\{0F714ABA-74F2-40FA-9D7C-5BA031B1883F}\chrome.manifest
c:\users\user1\AppData\Local\{0F714ABA-74F2-40FA-9D7C-5BA031B1883F}\chrome\content\_cfg.js
c:\users\user1\AppData\Local\{0F714ABA-74F2-40FA-9D7C-5BA031B1883F}\chrome\content\overlay.xul
c:\users\user1\AppData\Local\{0F714ABA-74F2-40FA-9D7C-5BA031B1883F}\install.rdf
c:\users\user1\AppData\Roaming\02000000e71caa19530C.manifest
c:\users\user1\AppData\Roaming\02000000e71caa19530O.manifest
c:\users\user1\AppData\Roaming\02000000e71caa19530P.manifest
c:\users\user1\AppData\Roaming\02000000e71caa19530S.manifest
c:\users\user1\AppData\Roaming\Desktopicon
c:\users\user1\AppData\Roaming\Desktopicon\eBayShortcuts.exe
c:\windows\Installer\WMEncoder.msi
c:\windows\system32\drivers\Sonyhcp.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-09-06 to 2009-10-06 )))))))))))))))))))))))))))))))
.
2009-10-06 18:02 . 2009-10-06 18:06 -------- d-----w- c:\users\user1\AppData\Local\temp
2009-10-06 18:02 . 2009-10-06 18:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-03 01:54 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-03 01:54 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-03 01:54 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-03 01:54 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-03 01:53 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-03 01:53 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-03 01:53 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-03 01:53 . 2009-08-06 18:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-03 01:53 . 2009-08-06 17:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-03 00:42 . 2009-10-01 09:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-01 23:16 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-01 23:16 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-01 23:16 . 2009-10-01 23:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-30 22:51 . 2009-09-30 22:51 0 ----a-w- c:\windows\system32\wmtog32.dat
2009-09-30 22:34 . 2009-10-02 21:54 0 ----a-w- c:\windows\win32k.sys
2009-09-30 21:41 . 2009-09-30 21:47 237568 ----a-w- c:\windows\system32\rmc_rtspdl.dll
2009-09-30 21:41 . 2009-09-30 21:47 156672 ----a-w- c:\windows\system32\rmc_fixasf.exe
2009-09-30 21:38 . 2009-09-30 22:28 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL
2009-09-30 21:38 . 2009-09-30 21:38 -------- d-----w- c:\windows\Replay Media Catcher
2009-09-30 17:50 . 2009-10-03 21:15 -------- d-----w- c:\users\user1\AppData\Roaming\DVD Flick
2009-09-30 17:50 . 2003-01-26 12:41 40960 ----a-w- c:\windows\system32\ssubtmr6.dll
2009-09-30 17:50 . 2009-09-30 17:50 -------- d-----w- c:\program files\DVD Flick
2009-09-30 13:38 . 2009-10-05 20:55 -------- d-----w- C:\YouTubeVideos
2009-09-30 13:35 . 2009-09-30 13:35 -------- d-----w- c:\program files\4U Computing
2009-09-29 21:06 . 2009-09-29 21:07 -------- d-----w- c:\program files\Ask.com
2009-09-29 21:05 . 2009-09-29 21:05 -------- d-----w- c:\program files\uTorrent
2009-09-29 21:05 . 2009-10-06 18:03 -------- d-----w- c:\users\user1\AppData\Roaming\uTorrent
2009-09-26 15:53 . 2009-09-26 15:53 -------- d-----w- c:\program files\iPod
2009-09-26 15:53 . 2009-09-26 15:55 -------- d-----w- c:\program files\iTunes
2009-09-22 17:30 . 2009-09-22 17:30 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2009-09-22 17:29 . 2009-09-22 17:29 -------- d-----w- c:\users\user1\AppData\Local\Downloaded Installations
2009-09-22 17:28 . 2009-09-22 17:38 -------- d-----w- c:\users\user1\AppData\Roaming\GetRightToGo
2009-09-22 16:17 . 2009-09-22 17:05 -------- d-----w- c:\users\user1\AppData\Local\ElevatedDiagnostics
2009-09-22 16:13 . 2009-09-22 16:13 -------- d-----w- c:\program files\Microsoft ATS
2009-09-21 21:28 . 2009-07-28 15:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-21 21:28 . 2009-03-30 09:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-09-21 21:28 . 2009-09-21 21:28 -------- d-----w- c:\programdata\Avira
2009-09-21 21:28 . 2009-09-21 21:28 -------- d-----w- c:\program files\Avira
2009-09-21 14:14 . 2009-09-21 14:14 -------- d-----w- c:\program files\ERUNT
2009-09-21 02:23 . 2009-09-21 02:23 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-09-21 02:05 . 2009-09-21 02:06 -------- d-----w- c:\windows\system32\ca-ES
2009-09-21 02:05 . 2009-09-21 02:06 -------- d-----w- c:\windows\system32\eu-ES
2009-09-21 02:05 . 2009-09-21 02:06 -------- d-----w- c:\windows\system32\vi-VN
2009-09-21 00:52 . 2009-09-21 00:52 -------- d-----w- c:\windows\system32\EventProviders
2009-09-21 00:49 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-09-21 00:47 . 2009-04-11 06:28 327168 ----a-w- c:\windows\system32\P2PGraph.dll
2009-09-21 00:46 . 2009-04-11 06:28 443392 ----a-w- c:\windows\system32\win32spl.dll
2009-09-21 00:45 . 2009-04-11 06:28 449024 ----a-w- c:\windows\system32\termsrv.dll
2009-09-21 00:44 . 2009-04-11 06:28 825856 ----a-w- c:\windows\system32\rasdlg.dll
2009-09-21 00:43 . 2009-04-11 06:28 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll
2009-09-21 00:43 . 2009-04-11 06:28 744448 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2009-09-21 00:43 . 2009-04-11 06:28 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2009-09-21 00:43 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
2009-09-21 00:43 . 2009-04-11 06:28 189440 ----a-w- c:\windows\system32\wbem\mofd.dll
2009-09-21 00:43 . 2009-04-11 06:28 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-09-21 00:43 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\esscli.dll
2009-09-21 00:43 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll
2009-09-21 00:43 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll
2009-09-21 00:43 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2009-09-21 00:42 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-09-21 00:07 . 2009-07-31 14:23 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-17 18:29 . 2009-09-17 18:29 -------- d-----w- c:\windows\system32\SDA
2009-09-14 19:36 . 2009-09-11 12:15 2491192 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
2009-09-14 19:36 . 2006-10-16 17:44 196608 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\ssleay32.dll
2009-09-14 19:36 . 2008-03-04 17:52 286720 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\libcurl.dll
2009-09-14 19:36 . 2007-10-31 08:39 59904 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\zlib1.dll
2009-09-14 19:36 . 2007-05-17 12:58 143360 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\libexpatw.dll
2009-09-14 19:36 . 2006-10-18 16:32 499712 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\msvcp71.dll
2009-09-14 19:36 . 2006-10-18 16:32 348160 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\msvcr71.dll
2009-09-14 19:36 . 2006-10-16 17:44 1028096 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\libeay32.dll
2009-09-14 00:37 . 2009-09-26 09:56 -------- d-----w- c:\users\user1\AppData\Roaming\skypePM
2009-09-12 15:44 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-12 15:44 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-09-12 15:43 . 2009-09-12 15:44 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-12 15:39 . 2009-09-12 15:39 -------- d-----w- c:\program files\QuickTime
2009-09-12 00:39 . 2009-09-12 00:39 -------- d-----w- c:\users\user1\AppData\Local\WinZip
2009-09-12 00:38 . 2009-09-12 00:39 -------- d-----w- c:\programdata\WinZip
2009-09-12 00:31 . 2009-09-12 00:31 -------- d-----w- C:\USB_DRV
2009-09-07 11:37 . 2009-09-07 11:37 -------- d-----w- c:\program files\Veetle
2009-09-07 00:25 . 2009-09-07 00:25 -------- d-----w- c:\users\user1\AppData\Roaming\InstallShield
2009-09-07 00:14 . 2009-09-07 00:26 -------- d-----w- c:\program files\Sony
2009-09-06 23:25 . 2009-09-06 23:26 -------- d-----w- c:\users\user1\AppData\Roaming\Sony Corporation
2009-09-06 23:16 . 2006-07-28 08:30 236824 ----a-w- c:\windows\system32\xactengine2_3.dll
2009-09-06 23:16 . 2006-07-28 08:30 62744 ----a-w- c:\windows\system32\xinput1_2.dll
2009-09-06 23:13 . 2009-09-06 23:13 -------- d-----w- C:\Drivers
2009-09-06 23:13 . 2006-10-30 12:46 6097 ----a-w- c:\windows\system32\drivers\sonyhcb.sys
2009-09-06 23:13 . 2006-10-30 12:46 53248 ----a-w- c:\windows\system32\SONYHCY.DLL
2009-09-06 23:13 . 2006-10-30 12:46 38739 ----a-w- c:\windows\system32\drivers\sonyhcc.sys
2009-09-06 23:13 . 2006-10-30 12:46 299923 ----a-w- c:\windows\system32\drivers\sonyhcs.sys
2009-09-06 23:13 . 2006-10-30 12:46 102220 ----a-w- c:\windows\system32\drivers\sonypvs1.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-06 17:51 . 2009-01-28 01:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-06 17:51 . 2009-01-28 01:24 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-10-02 02:37 . 2007-10-25 22:36 -------- d-----w- c:\program files\CCleaner
2009-10-01 21:45 . 2006-12-20 11:58 -------- d-----w- c:\program files\Java
2009-10-01 18:59 . 2009-08-20 19:29 -------- d-----w- c:\program files\Trend Micro
2009-09-30 20:54 . 2007-10-25 22:37 -------- d-----w- c:\program files\Yahoo!
2009-09-30 20:54 . 2009-01-29 18:14 -------- d--h--w- c:\programdata\yahoo!
2009-09-29 22:32 . 2009-08-20 01:25 -------- d-----w- c:\users\user1\AppData\Roaming\Skype
2009-09-26 15:53 . 2009-02-04 00:36 -------- d-----w- c:\program files\Common Files\Apple
2009-09-26 15:53 . 2009-02-14 16:36 -------- d-----w- c:\programdata\Apple Computer
2009-09-24 18:37 . 2008-08-15 01:19 -------- d-----w- c:\users\user1\AppData\Roaming\Ulead Systems
2009-09-22 21:23 . 2007-11-01 20:47 -------- d-----w- c:\users\user1\AppData\Roaming\Apple Computer
2009-09-22 18:47 . 2007-10-21 12:26 -------- d-----w- c:\program files\DigitalCamera
2009-09-22 17:38 . 2006-12-20 12:01 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-21 02:06 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-09-21 02:06 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2009-09-21 02:06 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-09-21 02:06 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-21 02:06 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2009-09-21 02:06 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-09-17 18:29 . 2006-12-20 11:29 -------- d-----w- c:\program files\TOSHIBA
2009-09-14 00:37 . 2009-09-14 00:37 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-09-10 20:12 . 2009-01-26 19:12 -------- d-----w- c:\program files\Common Files\Motive
2009-09-10 18:21 . 2009-01-26 14:01 -------- d-----w- c:\programdata\Motive
2009-09-10 18:14 . 2009-01-26 13:59 -------- d-----w- c:\program files\BT Broadband Desktop Help
2009-09-10 16:18 . 2009-02-04 12:17 61480 ----a-w- c:\users\user1\GoToAssistDownloadHelper.exe
2009-09-09 18:10 . 2009-02-09 17:32 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-03 17:44 . 2009-09-03 17:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-31 19:35 . 2009-05-08 16:19 -------- d-----w- c:\programdata\ScanSoft
2009-08-29 00:27 . 2009-09-04 01:23 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-04 01:23 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-25 18:05 . 2007-10-25 16:52 -------- d-----w- c:\users\user1\AppData\Roaming\LimeWire
2009-08-20 01:24 . 2009-08-20 01:24 -------- d-----r- c:\program files\Skype
2009-08-20 01:24 . 2009-08-20 01:24 -------- d-----w- c:\program files\Common Files\Skype
2009-08-20 01:24 . 2009-08-20 01:24 -------- d-----w- c:\programdata\Skype
2009-08-16 19:53 . 2007-11-17 01:41 -------- d-----w- c:\programdata\Lavasoft
2009-08-14 16:27 . 2009-09-09 07:20 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 15:53 . 2009-09-09 07:20 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49 . 2009-09-09 07:20 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49 . 2009-09-09 07:20 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49 . 2009-09-09 07:20 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49 . 2009-09-09 07:20 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49 . 2009-09-09 07:20 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49 . 2009-09-09 07:20 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49 . 2009-09-09 07:20 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:48 . 2009-09-09 07:20 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48 . 2009-09-09 07:20 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-03 14:07 . 2009-08-03 14:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 14:07 . 2009-08-03 14:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 14:07 . 2009-08-03 14:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-08-02 17:49 . 2009-07-23 00:31 0 ----a-w- c:\users\user1\AppData\Local\prvlcl.dat
2009-07-21 21:52 . 2009-07-29 02:05 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 02:05 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 02:05 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 02:05 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-12 09:41 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-16 14:37 . 2009-08-03 02:42 1032192 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}-trash\components\IBitCometExtension.dll
2009-07-15 20:16 . 2009-01-28 00:24 1 ----a-w- c:\users\user1\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-15 12:40 . 2009-08-12 09:41 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-15 12:39 . 2009-08-12 09:41 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-15 12:39 . 2009-08-12 09:41 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-15 12:39 . 2009-08-12 09:41 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-11 19:01 . 2009-09-09 07:20 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-07-11 19:01 . 2009-09-09 07:20 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-07-11 19:01 . 2009-09-09 07:20 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-07-11 19:01 . 2009-09-09 07:20 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-07-11 17:03 . 2009-09-09 07:20 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-05-25 02:13 . 2009-05-24 19:17 10044192 --sha-w- c:\windows\System32\drivers\fidbox.dat
2009-05-25 02:13 . 2009-05-24 19:17 127776 --sha-w- c:\windows\System32\drivers\fidbox2.dat
.
------- Sigcheck -------
[7] 2006-11-02 . 7F15B4953378C8B5161D65C26D5FED4D . 11776 . . [6.0.6000.16386] . . c:\windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
c:\windows\system32\cngaudit.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-09-02 13:56 1175944 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-09-29 289072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Volume Indicator"="c:\program files\Toshiba\Utilities\VolControl.exe" [2006-12-13 94208]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2006-12-15 577536]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-27 815104]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
c:\users\user1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-6-10 525640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(
:7c,82,0f,02,62,3a,ca,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{80BE1601-6551-449E-9CA6-878748AF1A76}"= UDP:c:\program files\LogMeIn\x86\LMIGuardian.exe:LMIGuardian
"{B3A3D5FD-FFD5-4425-B341-74002ED31BB7}"= TCP:c:\program files\LogMeIn\x86\LMIGuardian.exe:LMIGuardian
"{BDAB0203-C8EB-449C-B3A8-541D97621944}"= UDP:c:\program files\LogMeIn\x86\LogMeInSystray.exe:LogMeInSystray
"{B8F7BE44-0948-4214-A346-FEDBB032CE3F}"= TCP:c:\program files\LogMeIn\x86\LogMeInSystray.exe:LogMeInSystray
"{A794F050-2A5A-4F27-B01E-6323233C4DC5}"= UDP:c:\program files\LogMeIn\x86\LogMeIn.exe:LogMeIn
"{1EA79DCF-C5B9-491D-AAFF-196A8D154F37}"= TCP:c:\program files\LogMeIn\x86\LogMeIn.exe:LogMeIn
"{770E4F08-E579-4091-BAF3-838A857BE337}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{78B159E0-3778-454A-B2A2-E16BA0D7A11A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{848DECDE-5A75-4D6C-A7A4-05EF008C4A30}c:\\program files\\safari\\safari.exe"= UDP:c:\program files\safari\safari.exe:Safari Web Browser
"UDP Query User{FDB49948-3003-4D62-B020-1472A15189A9}c:\\program files\\safari\\safari.exe"= TCP:c:\program files\safari\safari.exe:Safari Web Browser
"{A33B109C-6B8F-4388-8808-03ECB7D69FBA}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C8049DF9-7558-40E1-95D9-388B16FEACAA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{1572EFF6-C655-4FC2-AB15-BEF27B736011}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{B07AA5D6-E7E2-46A3-B4C0-E49260ADF842}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"TCP Query User{C1FDA377-6506-4D80-8D36-7265F354190E}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{3328C8C2-6E63-4806-BC21-4EA966FFBE7D}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"TCP Query User{78DBC0A9-F1CE-419B-B509-193937FA8345}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{43F5DA85-61E0-4509-8AF9-CD4AA4434BAD}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{C0C72D45-7F43-4C74-B4C2-4ECA7DEBFF3B}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{A0E9EAD2-D884-4D73-85C4-8F8F2C14B8CF}"= UDP:c:\users\user1\AppData\Local\Temp\7zSB42D.tmp\SymNRT.exe:Norton Removal Tool
"{57682660-C9FD-47F2-AD38-3CD139833A46}"= TCP:c:\users\user1\AppData\Local\Temp\7zSB42D.tmp\SymNRT.exe:Norton Removal Tool
"{D61E4AAB-841B-4D9D-A1B5-BB64ADB00FAB}"= UDP:c:\users\user1\AppData\Local\Temp\7zSC4E5.tmp\SymNRT.exe:Norton Removal Tool
"{F2202DB6-93E8-4297-9E0B-A8EE2F182B91}"= TCP:c:\users\user1\AppData\Local\Temp\7zSC4E5.tmp\SymNRT.exe:Norton Removal Tool
"{0815600B-85D4-447A-9B4E-B6EA7A8EA706}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{28344828-3B2D-441E-BD8B-D707E2841410}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{DF4CE634-7490-48B9-BEA7-822AA203B483}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{6D475C6F-076D-41EA-A781-70DB673D534C}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [21/09/2009 22:28 108289]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [30/03/2009 16:28 1533808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-06 c:\windows\Tasks\User_Feed_Synchronization-{A3992335-F067-4B0F-ACDF-84ECC1497315}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\
FF - prefs.js: browser.search.defaulturl - hxxp://uk.search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?ei=UTF-8&fr=ytff-cclean&p=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Common Files\Motive\npMotive.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: browser.search.defaulturl - hxxp://www15.yoog.com/search.php?q=
FF - user.js: browser.search.selectedEngine - Yoog Search
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: keyword.enabled - true
FF - user.js: keyword.URL - hxxp://www15.yoog.com/search.php?q=
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\vsdatant]
"ImagePath"=""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-4232574698-228105880-4154739431-1000\Software\ALWIL Software\Avast]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-21-4232574698-228105880-4154739431-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop]
@DACL=(02 0000)
"Toolbars"=hex:11,00,00,00,00,00,00,00
"Upgrade"=dword:00000001
"TaskbarWinXP"=hex:0c,00,00,00,08,00,00,00,01,00,00,00,00,00,00,00,aa,4f,28,68,
48,6a,d0,11,8c,78,00,c0,4f,d9,18,b4,fd,03,00,00,40,0d,00,00,00,00,00,00,16,\
[HKEY_USERS\S-1-5-21-4232574698-228105880-4154739431-1000\Software\Microsoft\Windows\Shell\Bags\1]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\ALWIL Software\Avast]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\windows\System32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\program files\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Completion time: 2009-10-06 19:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-06 18:12
Pre-Run: 10,040,426,496 bytes free
Post-Run: 9,695,068,160 bytes free
418 --- E O F --- 2009-10-05 17:43
Newbie here. My computer had been running perfectly until last week when Windows Defender alerted me to the detection of a tron rnos or something of that nature. Tried deleting/quaranting it and eventually Defender said this had been done. Immiditiately after i couldnt run Hijackthis. When try to run it comes back saying windows cannot access the specified device, path or file. You may not have approriate permissions to access the item. Tried installed Sbybod S +D and when tried run it it too came back saying the same. I am the only user on this computer and automatically run it as administrator so it cannot be admin issues
Have already run the following on advice of a mate
Combofix and here is the log
ComboFix 09-10-05.01 - user1 06/10/2009 18:54.1.1 - NTFSx86
Microsoft® Windows Vista Home Basic 6.0.6002.2.1252.44.1033.18.1917.1132 [GMT 1:00]
Running from: c:\users\user1\Documents\Ulead DVD MovieFactory\Downloads\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Anti-Virus *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2365545147-1999384947-2466353664-500
c:\$recycle.bin\S-1-5-21-2393766080-3187394018-3383541026-500
c:\$recycle.bin\S-1-5-21-899496415-1834721142-2599837188-500
c:\program files\Common Files\System\Uninstall
c:\users\user1\AppData\Local\{0F714ABA-74F2-40FA-9D7C-5BA031B1883F}
c:\users\user1\AppData\Local\{0F714ABA-74F2-40FA-9D7C-5BA031B1883F}\chrome.manifest
c:\users\user1\AppData\Local\{0F714ABA-74F2-40FA-9D7C-5BA031B1883F}\chrome\content\_cfg.js
c:\users\user1\AppData\Local\{0F714ABA-74F2-40FA-9D7C-5BA031B1883F}\chrome\content\overlay.xul
c:\users\user1\AppData\Local\{0F714ABA-74F2-40FA-9D7C-5BA031B1883F}\install.rdf
c:\users\user1\AppData\Roaming\02000000e71caa19530C.manifest
c:\users\user1\AppData\Roaming\02000000e71caa19530O.manifest
c:\users\user1\AppData\Roaming\02000000e71caa19530P.manifest
c:\users\user1\AppData\Roaming\02000000e71caa19530S.manifest
c:\users\user1\AppData\Roaming\Desktopicon
c:\users\user1\AppData\Roaming\Desktopicon\eBayShortcuts.exe
c:\windows\Installer\WMEncoder.msi
c:\windows\system32\drivers\Sonyhcp.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-09-06 to 2009-10-06 )))))))))))))))))))))))))))))))
.
2009-10-06 18:02 . 2009-10-06 18:06 -------- d-----w- c:\users\user1\AppData\Local\temp
2009-10-06 18:02 . 2009-10-06 18:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-03 01:54 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-03 01:54 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-03 01:54 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-03 01:54 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-03 01:53 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-03 01:53 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-03 01:53 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-03 01:53 . 2009-08-06 18:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-03 01:53 . 2009-08-06 17:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-03 00:42 . 2009-10-01 09:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-01 23:16 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-01 23:16 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-01 23:16 . 2009-10-01 23:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-30 22:51 . 2009-09-30 22:51 0 ----a-w- c:\windows\system32\wmtog32.dat
2009-09-30 22:34 . 2009-10-02 21:54 0 ----a-w- c:\windows\win32k.sys
2009-09-30 21:41 . 2009-09-30 21:47 237568 ----a-w- c:\windows\system32\rmc_rtspdl.dll
2009-09-30 21:41 . 2009-09-30 21:47 156672 ----a-w- c:\windows\system32\rmc_fixasf.exe
2009-09-30 21:38 . 2009-09-30 22:28 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL
2009-09-30 21:38 . 2009-09-30 21:38 -------- d-----w- c:\windows\Replay Media Catcher
2009-09-30 17:50 . 2009-10-03 21:15 -------- d-----w- c:\users\user1\AppData\Roaming\DVD Flick
2009-09-30 17:50 . 2003-01-26 12:41 40960 ----a-w- c:\windows\system32\ssubtmr6.dll
2009-09-30 17:50 . 2009-09-30 17:50 -------- d-----w- c:\program files\DVD Flick
2009-09-30 13:38 . 2009-10-05 20:55 -------- d-----w- C:\YouTubeVideos
2009-09-30 13:35 . 2009-09-30 13:35 -------- d-----w- c:\program files\4U Computing
2009-09-29 21:06 . 2009-09-29 21:07 -------- d-----w- c:\program files\Ask.com
2009-09-29 21:05 . 2009-09-29 21:05 -------- d-----w- c:\program files\uTorrent
2009-09-29 21:05 . 2009-10-06 18:03 -------- d-----w- c:\users\user1\AppData\Roaming\uTorrent
2009-09-26 15:53 . 2009-09-26 15:53 -------- d-----w- c:\program files\iPod
2009-09-26 15:53 . 2009-09-26 15:55 -------- d-----w- c:\program files\iTunes
2009-09-22 17:30 . 2009-09-22 17:30 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2009-09-22 17:29 . 2009-09-22 17:29 -------- d-----w- c:\users\user1\AppData\Local\Downloaded Installations
2009-09-22 17:28 . 2009-09-22 17:38 -------- d-----w- c:\users\user1\AppData\Roaming\GetRightToGo
2009-09-22 16:17 . 2009-09-22 17:05 -------- d-----w- c:\users\user1\AppData\Local\ElevatedDiagnostics
2009-09-22 16:13 . 2009-09-22 16:13 -------- d-----w- c:\program files\Microsoft ATS
2009-09-21 21:28 . 2009-07-28 15:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-21 21:28 . 2009-03-30 09:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-09-21 21:28 . 2009-09-21 21:28 -------- d-----w- c:\programdata\Avira
2009-09-21 21:28 . 2009-09-21 21:28 -------- d-----w- c:\program files\Avira
2009-09-21 14:14 . 2009-09-21 14:14 -------- d-----w- c:\program files\ERUNT
2009-09-21 02:23 . 2009-09-21 02:23 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-09-21 02:05 . 2009-09-21 02:06 -------- d-----w- c:\windows\system32\ca-ES
2009-09-21 02:05 . 2009-09-21 02:06 -------- d-----w- c:\windows\system32\eu-ES
2009-09-21 02:05 . 2009-09-21 02:06 -------- d-----w- c:\windows\system32\vi-VN
2009-09-21 00:52 . 2009-09-21 00:52 -------- d-----w- c:\windows\system32\EventProviders
2009-09-21 00:49 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-09-21 00:47 . 2009-04-11 06:28 327168 ----a-w- c:\windows\system32\P2PGraph.dll
2009-09-21 00:46 . 2009-04-11 06:28 443392 ----a-w- c:\windows\system32\win32spl.dll
2009-09-21 00:45 . 2009-04-11 06:28 449024 ----a-w- c:\windows\system32\termsrv.dll
2009-09-21 00:44 . 2009-04-11 06:28 825856 ----a-w- c:\windows\system32\rasdlg.dll
2009-09-21 00:43 . 2009-04-11 06:28 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll
2009-09-21 00:43 . 2009-04-11 06:28 744448 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2009-09-21 00:43 . 2009-04-11 06:28 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2009-09-21 00:43 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
2009-09-21 00:43 . 2009-04-11 06:28 189440 ----a-w- c:\windows\system32\wbem\mofd.dll
2009-09-21 00:43 . 2009-04-11 06:28 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-09-21 00:43 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\esscli.dll
2009-09-21 00:43 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll
2009-09-21 00:43 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll
2009-09-21 00:43 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2009-09-21 00:42 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-09-21 00:07 . 2009-07-31 14:23 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-17 18:29 . 2009-09-17 18:29 -------- d-----w- c:\windows\system32\SDA
2009-09-14 19:36 . 2009-09-11 12:15 2491192 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
2009-09-14 19:36 . 2006-10-16 17:44 196608 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\ssleay32.dll
2009-09-14 19:36 . 2008-03-04 17:52 286720 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\libcurl.dll
2009-09-14 19:36 . 2007-10-31 08:39 59904 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\zlib1.dll
2009-09-14 19:36 . 2007-05-17 12:58 143360 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\libexpatw.dll
2009-09-14 19:36 . 2006-10-18 16:32 499712 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\msvcp71.dll
2009-09-14 19:36 . 2006-10-18 16:32 348160 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\msvcr71.dll
2009-09-14 19:36 . 2006-10-16 17:44 1028096 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\libeay32.dll
2009-09-14 00:37 . 2009-09-26 09:56 -------- d-----w- c:\users\user1\AppData\Roaming\skypePM
2009-09-12 15:44 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-12 15:44 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-09-12 15:43 . 2009-09-12 15:44 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-12 15:39 . 2009-09-12 15:39 -------- d-----w- c:\program files\QuickTime
2009-09-12 00:39 . 2009-09-12 00:39 -------- d-----w- c:\users\user1\AppData\Local\WinZip
2009-09-12 00:38 . 2009-09-12 00:39 -------- d-----w- c:\programdata\WinZip
2009-09-12 00:31 . 2009-09-12 00:31 -------- d-----w- C:\USB_DRV
2009-09-07 11:37 . 2009-09-07 11:37 -------- d-----w- c:\program files\Veetle
2009-09-07 00:25 . 2009-09-07 00:25 -------- d-----w- c:\users\user1\AppData\Roaming\InstallShield
2009-09-07 00:14 . 2009-09-07 00:26 -------- d-----w- c:\program files\Sony
2009-09-06 23:25 . 2009-09-06 23:26 -------- d-----w- c:\users\user1\AppData\Roaming\Sony Corporation
2009-09-06 23:16 . 2006-07-28 08:30 236824 ----a-w- c:\windows\system32\xactengine2_3.dll
2009-09-06 23:16 . 2006-07-28 08:30 62744 ----a-w- c:\windows\system32\xinput1_2.dll
2009-09-06 23:13 . 2009-09-06 23:13 -------- d-----w- C:\Drivers
2009-09-06 23:13 . 2006-10-30 12:46 6097 ----a-w- c:\windows\system32\drivers\sonyhcb.sys
2009-09-06 23:13 . 2006-10-30 12:46 53248 ----a-w- c:\windows\system32\SONYHCY.DLL
2009-09-06 23:13 . 2006-10-30 12:46 38739 ----a-w- c:\windows\system32\drivers\sonyhcc.sys
2009-09-06 23:13 . 2006-10-30 12:46 299923 ----a-w- c:\windows\system32\drivers\sonyhcs.sys
2009-09-06 23:13 . 2006-10-30 12:46 102220 ----a-w- c:\windows\system32\drivers\sonypvs1.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-06 17:51 . 2009-01-28 01:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-06 17:51 . 2009-01-28 01:24 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-10-02 02:37 . 2007-10-25 22:36 -------- d-----w- c:\program files\CCleaner
2009-10-01 21:45 . 2006-12-20 11:58 -------- d-----w- c:\program files\Java
2009-10-01 18:59 . 2009-08-20 19:29 -------- d-----w- c:\program files\Trend Micro
2009-09-30 20:54 . 2007-10-25 22:37 -------- d-----w- c:\program files\Yahoo!
2009-09-30 20:54 . 2009-01-29 18:14 -------- d--h--w- c:\programdata\yahoo!
2009-09-29 22:32 . 2009-08-20 01:25 -------- d-----w- c:\users\user1\AppData\Roaming\Skype
2009-09-26 15:53 . 2009-02-04 00:36 -------- d-----w- c:\program files\Common Files\Apple
2009-09-26 15:53 . 2009-02-14 16:36 -------- d-----w- c:\programdata\Apple Computer
2009-09-24 18:37 . 2008-08-15 01:19 -------- d-----w- c:\users\user1\AppData\Roaming\Ulead Systems
2009-09-22 21:23 . 2007-11-01 20:47 -------- d-----w- c:\users\user1\AppData\Roaming\Apple Computer
2009-09-22 18:47 . 2007-10-21 12:26 -------- d-----w- c:\program files\DigitalCamera
2009-09-22 17:38 . 2006-12-20 12:01 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-21 02:06 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-09-21 02:06 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2009-09-21 02:06 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-09-21 02:06 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-21 02:06 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2009-09-21 02:06 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-09-17 18:29 . 2006-12-20 11:29 -------- d-----w- c:\program files\TOSHIBA
2009-09-14 00:37 . 2009-09-14 00:37 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-09-10 20:12 . 2009-01-26 19:12 -------- d-----w- c:\program files\Common Files\Motive
2009-09-10 18:21 . 2009-01-26 14:01 -------- d-----w- c:\programdata\Motive
2009-09-10 18:14 . 2009-01-26 13:59 -------- d-----w- c:\program files\BT Broadband Desktop Help
2009-09-10 16:18 . 2009-02-04 12:17 61480 ----a-w- c:\users\user1\GoToAssistDownloadHelper.exe
2009-09-09 18:10 . 2009-02-09 17:32 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-03 17:44 . 2009-09-03 17:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-31 19:35 . 2009-05-08 16:19 -------- d-----w- c:\programdata\ScanSoft
2009-08-29 00:27 . 2009-09-04 01:23 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-04 01:23 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-25 18:05 . 2007-10-25 16:52 -------- d-----w- c:\users\user1\AppData\Roaming\LimeWire
2009-08-20 01:24 . 2009-08-20 01:24 -------- d-----r- c:\program files\Skype
2009-08-20 01:24 . 2009-08-20 01:24 -------- d-----w- c:\program files\Common Files\Skype
2009-08-20 01:24 . 2009-08-20 01:24 -------- d-----w- c:\programdata\Skype
2009-08-16 19:53 . 2007-11-17 01:41 -------- d-----w- c:\programdata\Lavasoft
2009-08-14 16:27 . 2009-09-09 07:20 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 15:53 . 2009-09-09 07:20 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49 . 2009-09-09 07:20 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49 . 2009-09-09 07:20 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49 . 2009-09-09 07:20 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49 . 2009-09-09 07:20 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49 . 2009-09-09 07:20 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49 . 2009-09-09 07:20 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49 . 2009-09-09 07:20 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:48 . 2009-09-09 07:20 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48 . 2009-09-09 07:20 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-03 14:07 . 2009-08-03 14:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 14:07 . 2009-08-03 14:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 14:07 . 2009-08-03 14:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-08-02 17:49 . 2009-07-23 00:31 0 ----a-w- c:\users\user1\AppData\Local\prvlcl.dat
2009-07-21 21:52 . 2009-07-29 02:05 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 02:05 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 02:05 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 02:05 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-12 09:41 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-16 14:37 . 2009-08-03 02:42 1032192 ----a-w- c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}-trash\components\IBitCometExtension.dll
2009-07-15 20:16 . 2009-01-28 00:24 1 ----a-w- c:\users\user1\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-15 12:40 . 2009-08-12 09:41 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-15 12:39 . 2009-08-12 09:41 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-15 12:39 . 2009-08-12 09:41 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-15 12:39 . 2009-08-12 09:41 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-11 19:01 . 2009-09-09 07:20 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-07-11 19:01 . 2009-09-09 07:20 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-07-11 19:01 . 2009-09-09 07:20 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-07-11 19:01 . 2009-09-09 07:20 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-07-11 17:03 . 2009-09-09 07:20 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-05-25 02:13 . 2009-05-24 19:17 10044192 --sha-w- c:\windows\System32\drivers\fidbox.dat
2009-05-25 02:13 . 2009-05-24 19:17 127776 --sha-w- c:\windows\System32\drivers\fidbox2.dat
.
------- Sigcheck -------
[7] 2006-11-02 . 7F15B4953378C8B5161D65C26D5FED4D . 11776 . . [6.0.6000.16386] . . c:\windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
c:\windows\system32\cngaudit.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-09-02 13:56 1175944 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-09-29 289072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Volume Indicator"="c:\program files\Toshiba\Utilities\VolControl.exe" [2006-12-13 94208]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2006-12-15 577536]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-27 815104]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
c:\users\user1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-6-10 525640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{80BE1601-6551-449E-9CA6-878748AF1A76}"= UDP:c:\program files\LogMeIn\x86\LMIGuardian.exe:LMIGuardian
"{B3A3D5FD-FFD5-4425-B341-74002ED31BB7}"= TCP:c:\program files\LogMeIn\x86\LMIGuardian.exe:LMIGuardian
"{BDAB0203-C8EB-449C-B3A8-541D97621944}"= UDP:c:\program files\LogMeIn\x86\LogMeInSystray.exe:LogMeInSystray
"{B8F7BE44-0948-4214-A346-FEDBB032CE3F}"= TCP:c:\program files\LogMeIn\x86\LogMeInSystray.exe:LogMeInSystray
"{A794F050-2A5A-4F27-B01E-6323233C4DC5}"= UDP:c:\program files\LogMeIn\x86\LogMeIn.exe:LogMeIn
"{1EA79DCF-C5B9-491D-AAFF-196A8D154F37}"= TCP:c:\program files\LogMeIn\x86\LogMeIn.exe:LogMeIn
"{770E4F08-E579-4091-BAF3-838A857BE337}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{78B159E0-3778-454A-B2A2-E16BA0D7A11A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{848DECDE-5A75-4D6C-A7A4-05EF008C4A30}c:\\program files\\safari\\safari.exe"= UDP:c:\program files\safari\safari.exe:Safari Web Browser
"UDP Query User{FDB49948-3003-4D62-B020-1472A15189A9}c:\\program files\\safari\\safari.exe"= TCP:c:\program files\safari\safari.exe:Safari Web Browser
"{A33B109C-6B8F-4388-8808-03ECB7D69FBA}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C8049DF9-7558-40E1-95D9-388B16FEACAA}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{1572EFF6-C655-4FC2-AB15-BEF27B736011}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{B07AA5D6-E7E2-46A3-B4C0-E49260ADF842}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"TCP Query User{C1FDA377-6506-4D80-8D36-7265F354190E}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{3328C8C2-6E63-4806-BC21-4EA966FFBE7D}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"TCP Query User{78DBC0A9-F1CE-419B-B509-193937FA8345}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{43F5DA85-61E0-4509-8AF9-CD4AA4434BAD}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{C0C72D45-7F43-4C74-B4C2-4ECA7DEBFF3B}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{A0E9EAD2-D884-4D73-85C4-8F8F2C14B8CF}"= UDP:c:\users\user1\AppData\Local\Temp\7zSB42D.tmp\SymNRT.exe:Norton Removal Tool
"{57682660-C9FD-47F2-AD38-3CD139833A46}"= TCP:c:\users\user1\AppData\Local\Temp\7zSB42D.tmp\SymNRT.exe:Norton Removal Tool
"{D61E4AAB-841B-4D9D-A1B5-BB64ADB00FAB}"= UDP:c:\users\user1\AppData\Local\Temp\7zSC4E5.tmp\SymNRT.exe:Norton Removal Tool
"{F2202DB6-93E8-4297-9E0B-A8EE2F182B91}"= TCP:c:\users\user1\AppData\Local\Temp\7zSC4E5.tmp\SymNRT.exe:Norton Removal Tool
"{0815600B-85D4-447A-9B4E-B6EA7A8EA706}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{28344828-3B2D-441E-BD8B-D707E2841410}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{DF4CE634-7490-48B9-BEA7-822AA203B483}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{6D475C6F-076D-41EA-A781-70DB673D534C}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [21/09/2009 22:28 108289]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [30/03/2009 16:28 1533808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-06 c:\windows\Tasks\User_Feed_Synchronization-{A3992335-F067-4B0F-ACDF-84ECC1497315}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\
FF - prefs.js: browser.search.defaulturl - hxxp://uk.search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?ei=UTF-8&fr=ytff-cclean&p=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Common Files\Motive\npMotive.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\m8qw4nsa.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: browser.search.defaulturl - hxxp://www15.yoog.com/search.php?q=
FF - user.js: browser.search.selectedEngine - Yoog Search
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: keyword.enabled - true
FF - user.js: keyword.URL - hxxp://www15.yoog.com/search.php?q=
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\vsdatant]
"ImagePath"=""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-4232574698-228105880-4154739431-1000\Software\ALWIL Software\Avast]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-21-4232574698-228105880-4154739431-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop]
@DACL=(02 0000)
"Toolbars"=hex:11,00,00,00,00,00,00,00
"Upgrade"=dword:00000001
"TaskbarWinXP"=hex:0c,00,00,00,08,00,00,00,01,00,00,00,00,00,00,00,aa,4f,28,68,
48,6a,d0,11,8c,78,00,c0,4f,d9,18,b4,fd,03,00,00,40,0d,00,00,00,00,00,00,16,\
[HKEY_USERS\S-1-5-21-4232574698-228105880-4154739431-1000\Software\Microsoft\Windows\Shell\Bags\1]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\ALWIL Software\Avast]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\windows\System32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\program files\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Completion time: 2009-10-06 19:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-06 18:12
Pre-Run: 10,040,426,496 bytes free
Post-Run: 9,695,068,160 bytes free
418 --- E O F --- 2009-10-05 17:43

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked


Back to top










