ComboFix 10-09-28.03 - Andi 29/09/2010 9:09.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2015.1128 [GMT 1:00]
Running from: c:\documents and settings\Andi\Desktop\comfix.exe
Command switches used :: c:\documents and settings\Andi\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-29 )))))))))))))))))))))))))))))))
.
2010-09-28 17:48 . 2010-09-29 07:57 20042 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3165u3164uq.bin
2010-09-28 06:41 . 2010-09-28 17:41 22904 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3164u3163iv.bin
2010-09-28 05:02 . 2010-09-28 17:41 317 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsb_242d241gl.bin
2010-09-27 18:02 . 2010-09-28 07:57 21421 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3163u3162jb.bin
2010-09-27 06:42 . 2010-09-27 17:42 29062 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3162u3161cm.bin
2010-09-27 05:04 . 2010-09-27 17:42 609 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_355d354cm.bin
2010-09-26 18:48 . 2010-09-27 08:25 45706 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3161u3160ua.bin
2010-09-26 07:08 . 2010-09-26 16:21 7623 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3160u3159hx.bin
2010-09-26 05:29 . 2010-09-26 16:21 1131 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_354d3539a.bin
2010-09-25 17:52 . 2010-09-26 07:49 38435 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3159u3158jm.bin
2010-09-25 06:42 . 2010-09-25 16:12 28393 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3158u3157iu.bin
2010-09-24 17:23 . 2010-09-25 07:49 26575 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3157u3156dz.bin
2010-09-24 06:43 . 2010-09-24 16:13 21127 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3156u3155sy.bin
2010-09-24 05:00 . 2010-09-24 16:13 837 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_353d352f.bin
2010-09-23 18:43 . 2010-09-24 07:49 47342 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3155u3154uz.bin
2010-09-23 08:14 . 2010-09-23 08:14 620896 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgnsx.exe
2010-09-23 08:14 . 2010-09-23 08:14 4093792 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-09-23 08:14 . 2010-09-23 08:14 3586912 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-09-23 08:14 . 2010-09-23 08:14 1619296 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgssie.dll
2010-09-23 08:14 . 2010-09-23 08:14 1377632 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgssff.dll
2010-09-23 08:14 . 2010-09-23 08:14 942432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-09-23 08:14 . 2010-09-23 08:14 598368 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgsrmx.dll
2010-09-23 08:14 . 2010-09-23 08:14 4371296 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-09-23 08:14 . 2010-09-23 08:14 300896 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgchclx.dll
2010-09-23 08:12 . 2010-09-23 08:12 1690952 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-09-23 06:43 . 2010-09-23 16:17 23965 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3154u3153ey.bin
2010-09-23 05:02 . 2010-09-24 07:49 595 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_352d351wf.bin
2010-09-22 18:49 . 2010-09-23 08:12 36812 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3153u3152xm.bin
2010-09-22 17:52 . 2010-09-23 08:12 731 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_351d349dt.bin
2010-09-22 13:57 . 2010-09-23 08:12 317 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsb_241d2407a.bin
2010-09-22 06:44 . 2010-09-22 17:35 11271 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3152u3151ew.bin
2010-09-22 05:01 . 2010-09-22 17:35 887 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_349d348sd.bin
2010-09-22 05:00 . 2010-09-22 17:35 7542 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsb_240d239sc.bin
2010-09-21 22:23 . 2010-09-22 08:11 50409 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3151u3149en.bin
2010-09-21 06:43 . 2010-09-21 17:27 47252 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3149u3147ol.bin
2010-09-21 05:00 . 2010-09-21 17:27 797 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_348d347ob.bin
2010-09-21 05:00 . 2010-09-21 17:27 4296 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsb_239d238ob.bin
2010-09-20 06:42 . 2010-09-20 17:53 71646 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3147u3145pp.bin
2010-09-20 05:01 . 2010-09-20 17:53 1906 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_347d346kb.bin
2010-09-20 05:00 . 2010-09-20 17:53 24577 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsb_238d237ka.bin
2010-09-19 06:43 . 2010-09-19 16:49 353776 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3145u3135jp.bin
2010-09-18 11:36 . 2010-09-23 08:12 42387 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\f9lng855df.bin
2010-09-17 05:00 . 2010-09-19 16:49 875 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_346d34387.bin
2010-09-16 17:04 . 2010-09-16 17:05 -------- d-----w- c:\program files\QuickTime
2010-09-16 16:59 . 2010-09-16 16:59 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.18.5\SetupAdmin.exe
2010-09-16 06:41 . 2010-09-16 17:44 26193 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3138u3137ej.bin
2010-09-16 05:00 . 2010-09-19 16:49 7824 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsb_237d23646.bin
2010-09-15 18:42 . 2010-09-16 04:48 53577 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3137u3135sx.bin
2010-09-15 05:01 . 2010-09-16 04:48 773 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_343d3426.bin
2010-09-15 05:00 . 2010-09-16 04:48 374771 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsb_236d2355.bin
2010-09-14 18:41 . 2010-09-15 07:48 27657 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3135u3134yi.bin
2010-09-14 06:42 . 2010-09-14 13:12 33104 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3134u3132iu.bin
2010-09-14 05:00 . 2010-09-14 13:12 940 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_342d341w3.bin
2010-09-13 06:42 . 2010-09-13 17:17 12858 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3132u3131pi.bin
2010-09-13 05:00 . 2010-09-13 17:17 868 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_341d339s2.bin
2010-09-12 18:40 . 2010-09-13 08:26 17494 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3131u3130bd.bin
2010-09-12 06:43 . 2010-09-12 10:16 88674 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3130u3125om.bin
2010-09-10 11:32 . 2010-09-23 14:32 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-09-10 07:14 . 2010-09-10 16:11 38359 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3126u3125zc.bin
2010-09-10 05:00 . 2010-09-13 17:17 9056 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsb_235d234fz.bin
2010-09-09 18:39 . 2010-09-10 08:19 20825 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3125u3124lw.bin
2010-09-09 15:00 . 2010-09-23 08:12 400 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\f9lsimg855b847ga.bin
2010-09-09 15:00 . 2010-09-23 08:12 129578 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\f9lsie856b845pu.bin
2010-09-09 15:00 . 2010-09-23 08:12 111242 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\f9lsff855b847dg.bin
2010-09-09 15:00 . 2010-09-23 08:12 4562 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\f9lngus855b851cy.bin
2010-09-09 15:00 . 2010-09-23 08:12 157572 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\f9krnl855b847ny.bin
2010-09-09 15:00 . 2010-09-23 08:12 263053 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\f9core856b846dn.bin
2010-09-09 15:00 . 2010-09-23 08:12 207612 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\f9ui856b832zm.bin
2010-09-09 15:00 . 2010-09-23 08:12 140187 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\f9upd855b839vh.bin
2010-09-09 15:00 . 2010-09-23 08:12 326598 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\f9setup855b832me.bin
2010-09-09 15:00 . 2010-09-23 08:12 62192 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\f9nsx855b832dt.bin
2010-09-09 14:59 . 2010-09-23 08:12 27706 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\f9chjc855b832ur.bin
2010-09-09 06:45 . 2010-09-09 17:47 213829 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3124u3113ib.bin
2010-09-09 05:00 . 2010-09-09 17:47 232601 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_339by.bin
2010-09-09 05:00 . 2010-09-09 17:47 425468 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsb_234d232by.bin
2010-09-08 06:16 . 2010-09-08 21:00 202041 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3121u3111sr.bin
2010-09-08 05:00 . 2010-09-08 21:00 1219 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_338d3347x.bin
2010-09-05 18:29 . 2010-09-05 18:29 -------- d-----w- c:\program files\SpywareBlaster
2010-09-05 16:26 . 2010-08-12 12:15 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-09-05 05:20 . 2010-09-08 21:00 413430 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsb_233d232wd.bin
2010-09-04 18:41 . 2010-09-05 07:23 39740 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3114u3113cp.bin
2010-09-04 16:38 . 2010-09-04 16:38 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-09-04 16:03 . 2010-08-12 12:15 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-09-04 16:03 . 2010-09-04 16:03 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-09-04 15:49 . 2010-09-04 15:49 63488 ----a-w- c:\documents and settings\Andi\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-09-04 15:49 . 2010-09-04 15:49 52224 ----a-w- c:\documents and settings\Andi\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-09-04 15:48 . 2010-09-04 15:48 117760 ----a-w- c:\documents and settings\Andi\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-09-04 15:47 . 2010-09-04 15:47 -------- d-----w- c:\documents and settings\Andi\Application Data\SUPERAntiSpyware.com
2010-09-04 15:47 . 2010-09-04 15:47 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-09-04 15:46 . 2010-09-16 05:05 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-09-04 15:42 . 2010-09-04 15:55 -------- d-----w- c:\program files\SpywareGuard
2010-09-04 15:07 . 2010-09-04 15:07 -------- d-----w- c:\documents and settings\Andi\Local Settings\Application Data\Sunbelt Software
2010-09-04 15:05 . 2010-08-12 12:16 574219 -c--a-w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}\mia.lib
2010-09-04 15:05 . 2010-09-04 15:05 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-09-04 15:05 . 2010-08-12 12:16 2979848 -c--a-w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}\Ad-AwareInstall.exe
2010-09-04 15:05 . 2010-09-04 15:05 -------- d-----w- c:\program files\Lavasoft
2010-09-04 15:05 . 2010-09-04 16:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-09-04 08:55 . 2010-09-04 08:55 -------- d-----w- c:\documents and settings\All Users\Application Data\VOWSoft
2010-09-04 08:54 . 2010-09-04 08:54 -------- d-----w- c:\program files\iPodRobot
2010-09-04 06:42 . 2010-09-04 16:50 13470 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3113u3112bp.bin
2010-09-04 05:18 . 2010-09-04 16:50 581 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_334d333sa.bin
2010-09-03 18:41 . 2010-09-04 07:23 43244 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3112u3111zm.bin
2010-09-03 06:41 . 2010-09-03 20:56 20112 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3111u3110xi.bin
2010-09-03 05:00 . 2010-09-03 20:56 1136 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_333d332nr.bin
2010-09-02 18:56 . 2010-09-03 07:25 35984 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3110u3108dv.bin
2010-09-02 15:05 . 2010-09-02 15:05 -------- d-----w- c:\program files\iPod
2010-09-02 15:05 . 2010-09-02 15:07 -------- d-----w- c:\program files\iTunes
2010-09-02 14:47 . 2010-09-02 14:47 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 10.0.0.68\SetupAdmin.exe
2010-09-02 13:51 . 2010-09-02 13:51 -------- d-----w- c:\program files\Regensoft
2010-09-02 13:51 . 2010-09-02 13:51 -------- d-----w- c:\program files\Red Kawa
2010-09-02 09:27 . 2010-09-02 20:58 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-09-02 09:27 . 2010-09-02 10:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-09-02 06:41 . 2010-09-02 17:04 31029 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3108u3107iu.bin
2010-09-02 05:53 . 2010-09-02 17:04 768 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_332d331l7.bin
2010-09-02 05:53 . 2010-09-02 17:04 8986 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsb_232d231l7.bin
2010-09-01 20:32 . 2010-09-01 20:32 -------- d-----w- c:\documents and settings\Andi\Application Data\Malwarebytes
2010-09-01 20:31 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-01 20:31 . 2010-09-01 20:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-01 20:31 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-01 20:31 . 2010-09-27 20:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-01 18:41 . 2010-09-02 08:07 51872 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3107u3106uz.bin
2010-09-01 10:28 . 2010-09-01 10:28 -------- d-----w- c:\program files\Apple Software Update
2010-09-01 06:42 . 2010-09-01 17:24 15966 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3106u3105uk.bin
2010-09-01 05:00 . 2010-09-01 17:24 557 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_331d330fp.bin
2010-08-31 18:41 . 2010-09-01 06:08 49568 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3105u3103xg.bin
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-26 15:10 . 2010-05-15 15:10 0 ----a-w- c:\documents and settings\Andi\Local Settings\Application Data\prvlcl.dat
2010-09-26 11:40 . 2010-05-10 20:02 -------- d-----w- c:\documents and settings\Andi\Application Data\Dropbox
2010-09-26 11:36 . 2010-05-10 17:12 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-09-16 17:00 . 2010-07-20 22:03 -------- d-----w- c:\program files\Safari
2010-09-02 15:05 . 2009-11-20 11:28 -------- d-----w- c:\program files\Common Files\Apple
2010-09-02 06:01 . 2010-05-11 14:39 -------- d-----w- c:\documents and settings\Andi\Application Data\BitTorrent
2010-08-31 12:47 . 2010-06-16 10:01 -------- d-----w- c:\documents and settings\Andi\Application Data\PTGui
2010-08-30 17:52 . 2010-08-30 06:41 24320 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3102u3101lh.bin
2010-08-30 17:52 . 2010-08-30 05:00 550 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\x8xplsc_328d327ol.bin
2010-08-30 09:02 . 2009-11-20 11:38 -------- d-----w- c:\documents and settings\Andi\Application Data\Apple Computer
2010-08-30 08:02 . 2010-08-29 18:41 29869 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\download\u9iavi3101u3100qu.bin
2010-08-26 11:35 . 2010-08-26 11:26 -------- d-----w- c:\program files\Google
2010-08-26 10:34 . 2010-08-25 15:41 -------- d-----w- c:\documents and settings\Andi\Application Data\onOne Software
2010-08-25 15:44 . 2010-08-25 15:44 -------- d-----w- c:\program files\Common Files\onOne Software Shared
2010-08-25 15:44 . 2010-08-25 15:36 -------- d-----w- c:\program files\onOne Software
2010-08-25 15:43 . 2010-08-25 15:36 -------- d-----w- c:\documents and settings\All Users\Application Data\onOne Software
2010-08-25 15:36 . 2009-11-12 21:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-20 17:21 . 2010-05-13 08:59 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-20 15:36 . 2010-05-13 08:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Easy CD-DA Extractor
2010-08-20 15:36 . 2010-05-13 08:59 -------- d-----w- c:\program files\Easy CD-DA Extractor 2010
2010-08-17 08:29 . 2010-08-17 08:29 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-08-17 07:53 . 2010-06-17 16:52 86892 ---ha-w- c:\windows\system32\mlfcache.dat
2010-08-15 08:56 . 2009-11-19 11:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-15 08:56 . 2010-08-14 09:35 1680064 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2010-08-15 08:43 . 2010-08-14 09:35 18368 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2010-08-15 08:35 . 2009-12-03 14:11 -------- d-----w- c:\program files\Common Files\Merge Modules
2010-08-14 15:54 . 2009-11-16 17:24 117544 ----a-w- c:\documents and settings\Andi\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-14 15:54 . 2009-11-18 14:20 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-14 12:31 . 2009-12-03 14:11 -------- d-----w- c:\documents and settings\All Users\Application Data\PreEmptive Solutions
2010-08-14 09:45 . 2010-08-14 09:10 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2010-08-14 09:45 . 2010-08-14 09:45 -------- d-----w- c:\program files\Business Objects
2010-08-14 09:45 . 2010-08-14 09:45 -------- d-----w- c:\program files\Microsoft Device Emulator
2010-08-14 09:44 . 2010-08-14 09:42 -------- d-----w- c:\program files\Windows Mobile 5.0 SDK R2
2010-08-14 09:41 . 2010-08-14 09:41 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-08-14 09:41 . 2010-08-14 09:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-08-14 09:38 . 2009-12-03 14:11 -------- d-----w- c:\program files\Microsoft.NET
2010-08-14 09:10 . 2010-08-14 09:10 -------- d-----w- c:\program files\Microsoft SDKs
2010-08-14 09:08 . 2010-08-14 09:08 -------- d-----w- c:\program files\Microsoft Web Designer Tools
2010-08-14 09:06 . 2010-08-14 09:06 416 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2010-08-11 07:33 . 2010-08-11 07:33 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.17.8\SetupAdmin.exe
2010-07-20 21:45 . 2010-07-20 21:45 71992 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-07-17 08:11 . 2010-07-17 08:11 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-17 08:10 . 2010-05-10 17:12 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Andi\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Andi\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Andi\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-09-16 2424560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 577536]
"RaidTool"="c:\program files\VIA\RAID\raid_tool.exe" [2005-06-20 1056768]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-17 2065760]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-06-16 2039240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
c:\documents and settings\Andi\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Andi\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
MonacoGamma.lnk - c:\program files\Monaco Systems\MonacoOPTIX 2.0\MonacoGamma.exe [2009-11-17 102400]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-17 08:11 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2010-06-19 11:36 640440 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2010-06-19 18:04 38840 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2010-05-11 06:13 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-01 07:32 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-02-26 14:08 2289664 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 05:42 1695232 --sh--w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
2005-10-11 18:25 1961984 ------w- c:\program files\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
2009-10-26 16:26 753664 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-11-11 09:57 1451520 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 10:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 10:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"odserv"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Documents and Settings\\Andi\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [04/09/2010 17:03 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/05/2010 18:12 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/05/2010 18:12 243024]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [23/03/2010 18:40 229312]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [03/03/2010 17:54 25240]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 19:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19:41 67656]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [17/07/2010 09:11 308136]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [12/08/2010 13:15 15008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 13:16 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [26/08/2010 12:27 136176]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/08/2010 13:15 1356952]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe --> c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [?]
S3 CoachVid;CoachVid;c:\windows\system32\drivers\CoachVid.sys [25/02/2010 23:20 45344]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [23/08/2001 13:00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 13:16 753504]
S3 X-Rite;X-Rite USB Service;c:\windows\system32\drivers\XrUsb.sys [17/11/2009 16:30 14936]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - KLMDB
*NewlyCreated* - LAVASOFT_KERNEXPLORER
*Deregistered* - klmdb
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-02-26 14:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-09-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 16:12]
2010-09-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]
2010-09-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-26 11:26]
2010-09-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-26 11:26]
2010-09-26 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.developingperceptions.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
FF - ProfilePath - c:\documents and settings\Andi\Application Data\Mozilla\Firefox\Profiles\su9jtr2g.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://developingperceptions.co.uk/
FF - component: c:\documents and settings\Andi\Application Data\Mozilla\Firefox\Profiles\su9jtr2g.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc_fireftp.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.search.selectedEngine - Google
FF - user.js: browser.search.order.1 - Google
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-09-29 09:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1343024091-1390067357-1801674531-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(720)
c:\windows\system32\guard32.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'lsass.exe'(776)
c:\windows\system32\guard32.dll
- - - - - - - > 'explorer.exe'(1648)
c:\windows\system32\WININET.dll
c:\documents and settings\Andi\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2010-09-29 10:04:07
ComboFix-quarantined-files.txt 2010-09-29 09:03
Pre-Run: 13,614,141,440 bytes free
Post-Run: 13,598,658,560 bytes free
- - End Of File - - 100C22AC8860A34BBE915BD7CDBCE139