ComboFix 11-09-03.01 - Administrator 09/03/2011 17:53:58.4.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1352 [GMT -7:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
file zipped: c:\windows\system32\oozoenme.dll
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\oozoenme.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-08-04 to 2011-09-04 )))))))))))))))))))))))))))))))
.
.
2011-09-03 21:02 . 2011-09-03 21:02 -------- d-----w- C:\found.000
2011-09-03 20:52 . 2011-09-03 20:52 -------- d-----w- c:\documents and settings\Administrator\Application Data\AVG2012
2011-09-03 20:49 . 2011-09-03 21:13 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG2012
2011-09-03 20:45 . 2011-09-03 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2011-09-03 16:39 . 2011-09-03 16:39 -------- d-----w- c:\program files\ESET
2011-09-03 00:53 . 2011-09-03 16:24 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\TSVNCache
2011-09-02 16:01 . 2011-09-02 17:05 -------- d-----w- c:\program files\Tricky Truck
2011-09-02 00:47 . 2011-09-02 00:47 -------- d-----w- C:\TDSSKiller_Quarantine
2011-08-26 06:48 . 2011-08-31 20:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\Azureus
2011-08-26 06:47 . 2011-08-26 06:47 -------- d-----w- c:\program files\Vuze
2011-08-22 21:33 . 2011-08-22 21:34 -------- d-----w- c:\program files\DVDStyler
2011-08-22 01:22 . 2011-08-22 21:32 -------- d-----w- c:\program files\Free Download Manager
2011-08-21 21:33 . 2011-08-21 21:33 -------- d-----w- c:\documents and settings\Administrator\Application Data\WinFF
2011-08-21 21:33 . 2011-08-21 21:33 -------- d-----w- c:\program files\WinFF
2011-08-21 21:21 . 2011-08-21 21:21 -------- d-----w- c:\documents and settings\Administrator\Application Data\XMedia Recode
2011-08-21 21:18 . 2011-08-21 21:19 -------- d-----w- c:\program files\XMedia Recode
2011-08-18 02:21 . 2011-08-18 02:21 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\GameMaker8.1
2011-08-18 02:21 . 2011-08-18 02:21 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\YoYo_Games_Ltd
2011-08-18 02:20 . 2011-08-20 00:05 -------- d-----w- c:\documents and settings\Administrator\GameMaker 8.1
2011-08-16 00:19 . 2011-08-16 00:19 -------- d-----w- C:\Nexon
2011-08-15 23:05 . 2011-09-04 01:06 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\PMB Files
2011-08-15 23:05 . 2011-08-16 00:59 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2011-08-10 15:11 . 2011-08-10 15:11 -------- d-----w- c:\program files\LogMeIn Hamachi
2011-08-10 12:59 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-10 12:58 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-09 22:39 . 2011-08-09 22:39 -------- d-----w- c:\program files\Microsoft XNA
2011-08-09 22:36 . 2011-08-09 22:36 -------- d-----w- c:\program files\Microsoft.NET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-03 03:18 . 2004-08-04 05:59 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-08-21 23:13 . 2011-07-24 07:49 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-08 13:08 . 2009-11-13 00:25 40016 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2011-07-15 13:29 . 2004-08-04 06:15 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-11 08:14 . 2011-07-11 08:14 295248 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2011-07-11 08:14 . 2011-07-11 08:14 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-07-11 08:14 . 2011-07-11 08:14 24272 ----a-w- c:\windows\system32\drivers\AVGIDSFilter.sys
2011-07-11 08:14 . 2011-07-11 08:14 23120 ----a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2011-07-11 08:14 . 2011-07-11 08:14 134608 ----a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
2011-07-11 08:13 . 2009-11-13 00:25 229840 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2011-07-11 08:13 . 2011-07-11 08:13 32464 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-07-08 14:02 . 2001-08-23 19:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-07 02:52 . 2009-05-15 19:29 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-07 02:52 . 2009-05-15 19:29 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-24 14:10 . 2008-10-30 21:42 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-20 17:44 . 2004-08-04 07:56 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-01-07 05:16 . 2011-01-07 05:16 34778 ----a-w- c:\program files\uninst.exe
2005-07-15 17:21 . 2005-07-15 17:21 1722929 ----a-w- c:\program files\Wax.dll
2005-06-28 04:20 . 2005-06-28 04:20 41016 ----a-w- c:\program files\WaxInvoker.exe
2004-04-25 17:28 . 2004-04-25 17:28 27648 ----a-w- c:\program files\CrashInform.exe
2003-07-11 19:14 . 2003-07-11 19:14 813568 ----a-w- c:\program files\dbghelp.dll
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-09-03_03.34.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-09-04 01:05 . 2011-09-04 01:05 16384 c:\windows\temp\Perflib_Perfdata_360.dat
+ 2004-08-04 07:56 . 2008-04-14 00:11 640000 c:\windows\system32\dllcache\dbghelp.dll
+ 2011-09-03 20:51 . 2011-09-03 20:51 4644864 c:\windows\Installer\f178ae.msi
+ 2011-09-03 20:49 . 2011-09-03 20:49 2185216 c:\windows\Installer\f178a9.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 15:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 15:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 15:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 15:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 15:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 15:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 15:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 15:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 15:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2011-08-15 3077528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-01-27 63048]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2010-07-22 1778064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-01-08 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-08 13880424]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-08-04 1955208]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-08-19 2387296]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HD Writer.lnk - c:\program files\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe [2010-12-25 308640]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-06-02 23:06 87424 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^MagicDisc.lnk]
backup=c:\windows\pss\MagicDisc.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HD Writer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HD Writer.lnk
backup=c:\windows\pss\HD Writer.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Registration Tool.lnk]
backup=c:\windows\pss\Run Registration Tool.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 19:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-06 19:55 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-11-17 03:04 139264 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ------w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2011-08-04 21:34 1955208 ----a-w- c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 23:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-01-08 03:56 13880424 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-01-08 03:56 111208 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-07-27 02:37 180224 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 00:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-08-06 02:44 1242448 ----a-w- c:\program files\Steam\steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 22:49 249064 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2008-05-02 04:15 15872 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\RealVNC\\VNC4\\vncviewer.exe"=
"c:\\Program Files\\Alcohol Soft\\Alcohol 120\\ACID.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\orbd.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\rmid.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\tnameserv.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\Valve\\Garry's Mod\\hl2.exe"=
"c:\\Program Files\\Valve\\Garry's Mod\\srcds.exe"=
"c:\\Program Files\\Steam\\steamapps\\tx134\\sourcesdk\\bin\\SDKLauncher.exe"=
"c:\\Program Files\\TightVNC\\tvnserver.exe"=
"c:\\Program Files\\Steam\\steamapps\\tx134\\synergy\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\tx134\\synergy dedicated server\\srcds.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\forsaken world\\patcher.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead 2\\left4dead2.exe"=
"c:\\Program Files\\Steam\\steamapps\\tx134\\garrysmod\\hl2.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc
"5900:UDP"= 5900:UDP:vnc
"6112:TCP"= 6112:TCP:blizzard
"6881:TCP"= 6881:TCP:blizzard
"6882:TCP"= 6882:TCP:blizzard
"6883:TCP"= 6883:TCP:blizzard
"6884:TCP"= 6884:TCP:blizzard
"6885:TCP"= 6885:TCP:blizzard
"6886:TCP"= 6886:TCP:blizzard
"6887:TCP"= 6887:TCP:blizzard
"6888:TCP"= 6888:TCP:blizzard
"6889:TCP"= 6889:TCP:blizzard
"6890:TCP"= 6890:TCP:blizzard
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3333:TCP"= 3333:TCP:3333
"58014:TCP"= 58014:TCP:Pando Media Booster
"58014:UDP"= 58014:UDP:Pando Media Booster
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [7/11/2011 1:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [7/11/2011 1:13 AM 32464]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/27/2009 7:25 PM 722416]
R1 AvgLdx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [11/12/2009 5:25 PM 229840]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 1:14 AM 295248]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [1/15/2009 5:17 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 5:17 PM 66632]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [8/4/2011 2:34 PM 1361288]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/27/2010 12:22 PM 12856]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys [9/6/2010 4:11 PM 44432]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5/15/2009 12:29 PM 22712]
S0 mv61xx;mv61xx;c:\windows\system32\DRIVERS\mv61xx.sys --> c:\windows\system32\DRIVERS\mv61xx.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 MBAMService;MBAMService;"f:\malwarebytes' anti-malware\mbamservice.exe" --> f:\malwarebytes' anti-malware\mbamservice.exe [?]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [7/11/2011 1:14 AM 134608]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [7/11/2011 1:14 AM 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [7/11/2011 1:14 AM 16720]
S3 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [4/7/2009 6:09 PM 33792]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\534.tmp --> c:\windows\system32\534.tmp [?]
S3 OCRQNL;OCRQNL;c:\docume~1\ADMINI~1\LOCALS~1\Temp\OCRQNL.exe --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\OCRQNL.exe [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 5:17 PM 12872]
S3 u2kg54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service;c:\windows\system32\drivers\rt2500usb.sys [2/23/2009 5:51 PM 104320]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [6/25/2010 4:01 PM 100496]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S3 XDva337;XDva337; [x]
S4 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/11/2010 7:47 PM 308136]
S4 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [8/16/2011 6:27 AM 5264736]
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-02 c:\windows\Tasks\CCleaner.job
- c:\program files\CCleaner\CCleaner.exe [2011-01-24 15:25]
.
2011-08-29 c:\windows\Tasks\Defraggler Volume C Task.job
- c:\program files\Defraggler\df.exe [2011-07-07 05:40]
.
.
------- Supplementary Scan -------
.
TCP: DhcpNameServer = 10.0.1.1
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\99euqsjb.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Shooter: {11b496ea-481a-11dc-8314-0800200c9a66} - %profile%\extensions\{11b496ea-481a-11dc-8314-0800200c9a66}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\AVG\AVG2012\Firefox4
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Malwarebytes' Anti-Malware_is1 - f:\malwarebytes' anti-malware\unins000.exe
AddRemove-Sophos-AntiRootkit - f:\sophos anti-rootkit\helper.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-09-03 18:06
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\534.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-682003330-789336058-725345543-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7FC51300-27C0-E60D-28B0-F6E1CDAFF338}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-682003330-789336058-725345543-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:40,da,78,d1,e2,bd,d1,58,8e,62,73,3e,f3,87,d1,8c,b4,28,5f,fb,90,31,ed,
3e,03,df,90,5b,11,e9,bd,6d,20,64,ac,f1,76,de,e1,4a,1f,9d,94,d9,5b,36,6d,79,\
"??"=hex:5f,2d,42,30,d2,db,5f,a8,44,3c,5c,94,1a,2d,71,db
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="3796D4CAC4C716EC9BCB334CC815CF4B7EC12E1A0B915496C1F07BCD987C2390631356F967F179CE3A67B4131A14CE4842CC0B24D70C5F387D9C9ADC2F4FC450E06B58E414C1A33256015E89DFA3E0484537EA31E9C57362B5177926ADA1B8237D545CAF842963C7FE88F8F9E3FD6EB277D181CD3F6AB34D5B2ED19A63A9FB3ACAB8434D770AAC5488A6AEFB77D685FE0D1F63D7D796E448266142FD22142A579E36D5892F3E182F8834FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB3452A9C6AECB7A5D14075D575E7D6A3B980830E3799613252274B8BF4D04B136B993C8D49F532240A8B9B3CCF6CBFA2F206F81C659C5F78E410A93E68402634ECF7AD342B4DA91508A5A7A9976BEE84C04D4DE5D94F8817A91D95A878AD5CB1A4C22B9C70A8A49BF1E06C07791F05E73DD1CBFE2179324A403362D653A91D7EA5F9DE24B8B3F5591712E591264AD9F7E3FB57C6A4DED7CDCC5AA8E9571379E237C339B882AC9E0E05AF5F6E990B111DAFC3E54D7A8D2C7065273670113BFD4BDD95D940C586F3DD86FB4B5523AB0BC0D308C6BE39FFEE996608302680617D944F1C9623C8D685FBD8E7690F289D051A9B6A8C61CAA28E91C6FFE0F5AB41D2BD806DB7C4CC5E25F6257F9EA47AA2AA0DAB04E4F604873F1B3C1BF20BD8EA56D2F18A9404981FD7B312D330821D04C9F60046ED5E4F97CD111DDD22D4D05F9688F6F7EED1143D09327B74914A12D38690A5A2E0CB3C5537BFB8C7B12948ED3875617D729559364AC56E4989AC17B65BA419FE6082934F986CFDB2E0F7827E5DBF2DD697C20FCB4F0E264318D4DF6BCF57D052243F555682EFA1F93452C4DD118EAD71851C810B22B062A5442645F1CA1CE80A31E9FB7875081EC0BBDBA823115D55C007A00DF434E8DEC7BF179FAD566D64B5DD9FC7238F07B9DA4E3814E8FCD60056FAA4884416DDAAB513A5612B093CBE27A1DBD20CDB511512607323B6CE3CAB1677BF6197743E224B41C15F0E59AF7075473DFDC0DEA05680A5952D73D1968862069B93FA7AAAFDB3B7D266823903ABC7DC8384BB37DA90AFCF33D3768D5A2E883538C9708A6DC1A2B274CCC8BB004CE3BF07211EF03659F60D19E6FCAA77506B0FEC34B3F5B1DEA8048A1773457DB4A05228957E2B0B358CA51799AB4BC71CBF91506076D10B6A0E8EF8FC3A708DCFE86774DCA26E1A4A68337A3D969E93A6C6421CD7820347FCBCA15D61464E6330221ED631FC315DABE8BA8C54CA1A608E0AB93E8545F5768C73C108B4C5BBF24AEE9E94509BA6D0E1C11B45E1C090EA8643F417C53A2AEF02F089F95D4F27F8320A82F3F42FDB1887D7BC74071BFE1F97440E1FCAED7922EE1AEE2B01A85383C37D9EA7188744DAA"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1204)
c:\windows\system32\LMIinit.dll
c:\windows\system32\WINSPOOL.DRV
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(3604)
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\windows\system32\LMIRfsClientNP.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\windows\system32\bgsvcgen.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
.
**************************************************************************
.
Completion time: 2011-09-03 18:09:32 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-04 01:09
ComboFix2.txt 2011-09-03 03:37
ComboFix3.txt 2010-03-12 01:21
ComboFix4.txt 2010-03-12 01:03
.
Pre-Run: 48,922,828,800 bytes free
Post-Run: 48,916,799,488 bytes free
.
- - End Of File - - 1257742CDDE5BBD1A29F051673B0B935
Upload was successful
I just uploaded the quarantine list due to it's length, hope you don't mind.