Hi again,
I managed to get the ComboFix log that you wanted, this machine is getting very difficult to use at times.
I saved it in the name you specified etavaresCF.exe but I dont see it anywhere, I hope its ok
thanks,
paul
ComboFix 10-10-30.01 - paul 10/30/2010 23:48:25.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2046.1546 [GMT 1:00]
Running from: c:\documents and settings\paul\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DFx34.tmp
C:\DFxA7.tmp
c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe
c:\documents and settings\paul\Application Data\.#
c:\documents and settings\paul\Application Data\.#\MBX@290@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@290@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@290@384248.###
c:\documents and settings\paul\Application Data\.#\MBX@2F8@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@2F8@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@2F8@384248.###
c:\documents and settings\paul\Application Data\.#\MBX@470@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@470@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@470@384248.###
c:\documents and settings\paul\Application Data\.#\MBX@478@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@478@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@478@384248.###
c:\documents and settings\paul\Application Data\.#\MBX@6B4@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@6B4@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@6B4@384248.###
c:\documents and settings\paul\Application Data\.#\MBX@700@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@700@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@700@384248.###
c:\documents and settings\paul\Application Data\.#\MBX@840@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@840@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@840@384248.###
c:\documents and settings\paul\Application Data\.#\MBX@930@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@930@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@930@384248.###
c:\documents and settings\paul\Application Data\.#\MBX@97C@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@97C@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@97C@384248.###
c:\documents and settings\paul\Application Data\.#\MBX@AC4@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@AC4@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@AC4@384248.###
c:\documents and settings\paul\Application Data\.#\MBX@CC4@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@CC4@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@CC4@384248.###
c:\documents and settings\paul\Application Data\.#\MBX@E54@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@E54@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@E54@384248.###
c:\documents and settings\paul\Application Data\.#\MBX@FE0@3841E8.###
c:\documents and settings\paul\Application Data\.#\MBX@FE0@384218.###
c:\documents and settings\paul\Application Data\.#\MBX@FE0@384248.###
c:\documents and settings\paul\Application Data\4DA66A4AEE82C2BBE7CC43CDEB9D7297
c:\documents and settings\paul\Application Data\4DA66A4AEE82C2BBE7CC43CDEB9D7297\enemies-names.txt
c:\documents and settings\paul\Application Data\4DA66A4AEE82C2BBE7CC43CDEB9D7297\local.ini
c:\documents and settings\paul\Application Data\4DA66A4AEE82C2BBE7CC43CDEB9D7297\lsrslt.ini
c:\documents and settings\paul\Local Settings\Application Data\{75481872-07D8-42B0-A55D-30B2151FA691}
c:\documents and settings\paul\Local Settings\Application Data\{75481872-07D8-42B0-A55D-30B2151FA691}\chrome.manifest
c:\documents and settings\paul\Local Settings\Application Data\{75481872-07D8-42B0-A55D-30B2151FA691}\chrome\content\_cfg.js
c:\documents and settings\paul\Local Settings\Application Data\{75481872-07D8-42B0-A55D-30B2151FA691}\chrome\content\overlay.xul
c:\documents and settings\paul\Local Settings\Application Data\{75481872-07D8-42B0-A55D-30B2151FA691}\install.rdf
c:\documents and settings\paul\Local Settings\Application Data\Windows Server
c:\documents and settings\paul\Local Settings\Application Data\Windows Server\flags.ini
c:\documents and settings\paul\Local Settings\Application Data\Windows Server\uses32.dat
c:\documents and settings\paul\System
c:\documents and settings\paul\System\win_qs8.jqx
c:\progra~1\PANICW~1\POP-UP~1\PSFree.exe
c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
c:\program files\Common Files\Java\Java Update\jusched.exe
c:\program files\Dell\QuickSet\Quickset.exe
c:\program files\Intel\Wireless\bin\ZCfgSvc.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\program files\Virgin Broadband Wireless\Wireless Manager.exe
c:\program files\Windows Media Player\run.exe
c:\program files\Windows Media Player\wmupdater.exe
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\Fonts\xXIFA4s.com
c:\windows\system32\6to4ex.dll
c:\windows\system32\Data
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At100.job
c:\windows\Tasks\At101.job
c:\windows\Tasks\At102.job
c:\windows\Tasks\At103.job
c:\windows\Tasks\At104.job
c:\windows\Tasks\At105.job
c:\windows\Tasks\At106.job
c:\windows\Tasks\At107.job
c:\windows\Tasks\At108.job
c:\windows\Tasks\At109.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At110.job
c:\windows\Tasks\At111.job
c:\windows\Tasks\At112.job
c:\windows\Tasks\At113.job
c:\windows\Tasks\At114.job
c:\windows\Tasks\At115.job
c:\windows\Tasks\At116.job
c:\windows\Tasks\At117.job
c:\windows\Tasks\At118.job
c:\windows\Tasks\At119.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At120.job
c:\windows\Tasks\At121.job
c:\windows\Tasks\At122.job
c:\windows\Tasks\At123.job
c:\windows\Tasks\At124.job
c:\windows\Tasks\At125.job
c:\windows\Tasks\At126.job
c:\windows\Tasks\At127.job
c:\windows\Tasks\At128.job
c:\windows\Tasks\At129.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At130.job
c:\windows\Tasks\At131.job
c:\windows\Tasks\At132.job
c:\windows\Tasks\At133.job
c:\windows\Tasks\At134.job
c:\windows\Tasks\At135.job
c:\windows\Tasks\At136.job
c:\windows\Tasks\At137.job
c:\windows\Tasks\At138.job
c:\windows\Tasks\At139.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At140.job
c:\windows\Tasks\At141.job
c:\windows\Tasks\At142.job
c:\windows\Tasks\At143.job
c:\windows\Tasks\At144.job
c:\windows\Tasks\At145.job
c:\windows\Tasks\At146.job
c:\windows\Tasks\At147.job
c:\windows\Tasks\At148.job
c:\windows\Tasks\At149.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At150.job
c:\windows\Tasks\At151.job
c:\windows\Tasks\At152.job
c:\windows\Tasks\At153.job
c:\windows\Tasks\At154.job
c:\windows\Tasks\At155.job
c:\windows\Tasks\At156.job
c:\windows\Tasks\At157.job
c:\windows\Tasks\At158.job
c:\windows\Tasks\At159.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At160.job
c:\windows\Tasks\At161.job
c:\windows\Tasks\At162.job
c:\windows\Tasks\At163.job
c:\windows\Tasks\At164.job
c:\windows\Tasks\At165.job
c:\windows\Tasks\At166.job
c:\windows\Tasks\At167.job
c:\windows\Tasks\At168.job
c:\windows\Tasks\At169.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At170.job
c:\windows\Tasks\At171.job
c:\windows\Tasks\At172.job
c:\windows\Tasks\At173.job
c:\windows\Tasks\At174.job
c:\windows\Tasks\At175.job
c:\windows\Tasks\At176.job
c:\windows\Tasks\At177.job
c:\windows\Tasks\At178.job
c:\windows\Tasks\At179.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At180.job
c:\windows\Tasks\At181.job
c:\windows\Tasks\At182.job
c:\windows\Tasks\At183.job
c:\windows\Tasks\At184.job
c:\windows\Tasks\At185.job
c:\windows\Tasks\At186.job
c:\windows\Tasks\At187.job
c:\windows\Tasks\At188.job
c:\windows\Tasks\At189.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At190.job
c:\windows\Tasks\At191.job
c:\windows\Tasks\At192.job
c:\windows\Tasks\At193.job
c:\windows\Tasks\At194.job
c:\windows\Tasks\At195.job
c:\windows\Tasks\At196.job
c:\windows\Tasks\At197.job
c:\windows\Tasks\At198.job
c:\windows\Tasks\At199.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At200.job
c:\windows\Tasks\At201.job
c:\windows\Tasks\At202.job
c:\windows\Tasks\At203.job
c:\windows\Tasks\At204.job
c:\windows\Tasks\At205.job
c:\windows\Tasks\At206.job
c:\windows\Tasks\At207.job
c:\windows\Tasks\At208.job
c:\windows\Tasks\At209.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At210.job
c:\windows\Tasks\At211.job
c:\windows\Tasks\At212.job
c:\windows\Tasks\At213.job
c:\windows\Tasks\At214.job
c:\windows\Tasks\At215.job
c:\windows\Tasks\At216.job
c:\windows\Tasks\At217.job
c:\windows\Tasks\At218.job
c:\windows\Tasks\At219.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At220.job
c:\windows\Tasks\At221.job
c:\windows\Tasks\At222.job
c:\windows\Tasks\At223.job
c:\windows\Tasks\At224.job
c:\windows\Tasks\At225.job
c:\windows\Tasks\At226.job
c:\windows\Tasks\At227.job
c:\windows\Tasks\At228.job
c:\windows\Tasks\At229.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At230.job
c:\windows\Tasks\At231.job
c:\windows\Tasks\At232.job
c:\windows\Tasks\At233.job
c:\windows\Tasks\At234.job
c:\windows\Tasks\At235.job
c:\windows\Tasks\At236.job
c:\windows\Tasks\At237.job
c:\windows\Tasks\At238.job
c:\windows\Tasks\At239.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At240.job
c:\windows\Tasks\At241.job
c:\windows\Tasks\At242.job
c:\windows\Tasks\At243.job
c:\windows\Tasks\At244.job
c:\windows\Tasks\At245.job
c:\windows\Tasks\At246.job
c:\windows\Tasks\At247.job
c:\windows\Tasks\At248.job
c:\windows\Tasks\At249.job
c:\windows\Tasks\At25.job
c:\windows\Tasks\At250.job
c:\windows\Tasks\At251.job
c:\windows\Tasks\At252.job
c:\windows\Tasks\At253.job
c:\windows\Tasks\At254.job
c:\windows\Tasks\At255.job
c:\windows\Tasks\At256.job
c:\windows\Tasks\At257.job
c:\windows\Tasks\At258.job
c:\windows\Tasks\At259.job
c:\windows\Tasks\At26.job
c:\windows\Tasks\At260.job
c:\windows\Tasks\At261.job
c:\windows\Tasks\At262.job
c:\windows\Tasks\At263.job
c:\windows\Tasks\At264.job
c:\windows\Tasks\At265.job
c:\windows\Tasks\At266.job
c:\windows\Tasks\At267.job
c:\windows\Tasks\At268.job
c:\windows\Tasks\At269.job
c:\windows\Tasks\At27.job
c:\windows\Tasks\At270.job
c:\windows\Tasks\At271.job
c:\windows\Tasks\At272.job
c:\windows\Tasks\At273.job
c:\windows\Tasks\At274.job
c:\windows\Tasks\At275.job
c:\windows\Tasks\At276.job
c:\windows\Tasks\At277.job
c:\windows\Tasks\At278.job
c:\windows\Tasks\At279.job
c:\windows\Tasks\At28.job
c:\windows\Tasks\At280.job
c:\windows\Tasks\At281.job
c:\windows\Tasks\At282.job
c:\windows\Tasks\At283.job
c:\windows\Tasks\At284.job
c:\windows\Tasks\At285.job
c:\windows\Tasks\At286.job
c:\windows\Tasks\At287.job
c:\windows\Tasks\At288.job
c:\windows\Tasks\At289.job
c:\windows\Tasks\At29.job
c:\windows\Tasks\At290.job
c:\windows\Tasks\At291.job
c:\windows\Tasks\At292.job
c:\windows\Tasks\At293.job
c:\windows\Tasks\At294.job
c:\windows\Tasks\At295.job
c:\windows\Tasks\At296.job
c:\windows\Tasks\At297.job
c:\windows\Tasks\At298.job
c:\windows\Tasks\At299.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At30.job
c:\windows\Tasks\At300.job
c:\windows\Tasks\At301.job
c:\windows\Tasks\At302.job
c:\windows\Tasks\At303.job
c:\windows\Tasks\At304.job
c:\windows\Tasks\At305.job
c:\windows\Tasks\At306.job
c:\windows\Tasks\At307.job
c:\windows\Tasks\At308.job
c:\windows\Tasks\At309.job
c:\windows\Tasks\At31.job
c:\windows\Tasks\At310.job
c:\windows\Tasks\At311.job
c:\windows\Tasks\At312.job
c:\windows\Tasks\At313.job
c:\windows\Tasks\At314.job
c:\windows\Tasks\At315.job
c:\windows\Tasks\At316.job
c:\windows\Tasks\At317.job
c:\windows\Tasks\At318.job
c:\windows\Tasks\At319.job
c:\windows\Tasks\At32.job
c:\windows\Tasks\At320.job
c:\windows\Tasks\At321.job
c:\windows\Tasks\At322.job
c:\windows\Tasks\At323.job
c:\windows\Tasks\At324.job
c:\windows\Tasks\At325.job
c:\windows\Tasks\At326.job
c:\windows\Tasks\At327.job
c:\windows\Tasks\At328.job
c:\windows\Tasks\At329.job
c:\windows\Tasks\At33.job
c:\windows\Tasks\At330.job
c:\windows\Tasks\At331.job
c:\windows\Tasks\At332.job
c:\windows\Tasks\At333.job
c:\windows\Tasks\At334.job
c:\windows\Tasks\At335.job
c:\windows\Tasks\At336.job
c:\windows\Tasks\At337.job
c:\windows\Tasks\At338.job
c:\windows\Tasks\At339.job
c:\windows\Tasks\At34.job
c:\windows\Tasks\At340.job
c:\windows\Tasks\At341.job
c:\windows\Tasks\At342.job
c:\windows\Tasks\At343.job
c:\windows\Tasks\At344.job
c:\windows\Tasks\At345.job
c:\windows\Tasks\At346.job
c:\windows\Tasks\At347.job
c:\windows\Tasks\At348.job
c:\windows\Tasks\At349.job
c:\windows\Tasks\At35.job
c:\windows\Tasks\At350.job
c:\windows\Tasks\At351.job
c:\windows\Tasks\At352.job
c:\windows\Tasks\At353.job
c:\windows\Tasks\At354.job
c:\windows\Tasks\At355.job
c:\windows\Tasks\At356.job
c:\windows\Tasks\At357.job
c:\windows\Tasks\At358.job
c:\windows\Tasks\At359.job
c:\windows\Tasks\At36.job
c:\windows\Tasks\At360.job
c:\windows\Tasks\At361.job
c:\windows\Tasks\At362.job
c:\windows\Tasks\At363.job
c:\windows\Tasks\At364.job
c:\windows\Tasks\At365.job
c:\windows\Tasks\At366.job
c:\windows\Tasks\At367.job
c:\windows\Tasks\At368.job
c:\windows\Tasks\At369.job
c:\windows\Tasks\At37.job
c:\windows\Tasks\At370.job
c:\windows\Tasks\At371.job
c:\windows\Tasks\At372.job
c:\windows\Tasks\At373.job
c:\windows\Tasks\At374.job
c:\windows\Tasks\At375.job
c:\windows\Tasks\At376.job
c:\windows\Tasks\At377.job
c:\windows\Tasks\At378.job
c:\windows\Tasks\At379.job
c:\windows\Tasks\At38.job
c:\windows\Tasks\At380.job
c:\windows\Tasks\At381.job
c:\windows\Tasks\At382.job
c:\windows\Tasks\At383.job
c:\windows\Tasks\At384.job
c:\windows\Tasks\At385.job
c:\windows\Tasks\At386.job
c:\windows\Tasks\At387.job
c:\windows\Tasks\At388.job
c:\windows\Tasks\At389.job
c:\windows\Tasks\At39.job
c:\windows\Tasks\At390.job
c:\windows\Tasks\At391.job
c:\windows\Tasks\At392.job
c:\windows\Tasks\At393.job
c:\windows\Tasks\At394.job
c:\windows\Tasks\At395.job
c:\windows\Tasks\At396.job
c:\windows\Tasks\At397.job
c:\windows\Tasks\At398.job
c:\windows\Tasks\At399.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At40.job
c:\windows\Tasks\At400.job
c:\windows\Tasks\At401.job
c:\windows\Tasks\At402.job
c:\windows\Tasks\At403.job
c:\windows\Tasks\At404.job
c:\windows\Tasks\At405.job
c:\windows\Tasks\At406.job
c:\windows\Tasks\At407.job
c:\windows\Tasks\At408.job
c:\windows\Tasks\At409.job
c:\windows\Tasks\At41.job
c:\windows\Tasks\At410.job
c:\windows\Tasks\At411.job
c:\windows\Tasks\At412.job
c:\windows\Tasks\At413.job
c:\windows\Tasks\At414.job
c:\windows\Tasks\At415.job
c:\windows\Tasks\At416.job
c:\windows\Tasks\At417.job
c:\windows\Tasks\At418.job
c:\windows\Tasks\At419.job
c:\windows\Tasks\At42.job
c:\windows\Tasks\At420.job
c:\windows\Tasks\At421.job
c:\windows\Tasks\At422.job
c:\windows\Tasks\At423.job
c:\windows\Tasks\At424.job
c:\windows\Tasks\At425.job
c:\windows\Tasks\At426.job
c:\windows\Tasks\At427.job
c:\windows\Tasks\At428.job
c:\windows\Tasks\At429.job
c:\windows\Tasks\At43.job
c:\windows\Tasks\At430.job
c:\windows\Tasks\At431.job
c:\windows\Tasks\At432.job
c:\windows\Tasks\At433.job
c:\windows\Tasks\At434.job
c:\windows\Tasks\At435.job
c:\windows\Tasks\At436.job
c:\windows\Tasks\At437.job
c:\windows\Tasks\At438.job
c:\windows\Tasks\At439.job
c:\windows\Tasks\At44.job
c:\windows\Tasks\At440.job
c:\windows\Tasks\At441.job
c:\windows\Tasks\At442.job
c:\windows\Tasks\At443.job
c:\windows\Tasks\At444.job
c:\windows\Tasks\At445.job
c:\windows\Tasks\At446.job
c:\windows\Tasks\At447.job
c:\windows\Tasks\At448.job
c:\windows\Tasks\At449.job
c:\windows\Tasks\At45.job
c:\windows\Tasks\At450.job
c:\windows\Tasks\At451.job
c:\windows\Tasks\At452.job
c:\windows\Tasks\At453.job
c:\windows\Tasks\At454.job
c:\windows\Tasks\At455.job
c:\windows\Tasks\At456.job
c:\windows\Tasks\At457.job
c:\windows\Tasks\At458.job
c:\windows\Tasks\At459.job
c:\windows\Tasks\At46.job
c:\windows\Tasks\At460.job
c:\windows\Tasks\At461.job
c:\windows\Tasks\At462.job
c:\windows\Tasks\At463.job
c:\windows\Tasks\At464.job
c:\windows\Tasks\At465.job
c:\windows\Tasks\At466.job
c:\windows\Tasks\At467.job
c:\windows\Tasks\At468.job
c:\windows\Tasks\At469.job
c:\windows\Tasks\At47.job
c:\windows\Tasks\At470.job
c:\windows\Tasks\At471.job
c:\windows\Tasks\At472.job
c:\windows\Tasks\At473.job
c:\windows\Tasks\At474.job
c:\windows\Tasks\At475.job
c:\windows\Tasks\At476.job
c:\windows\Tasks\At477.job
c:\windows\Tasks\At478.job
c:\windows\Tasks\At479.job
c:\windows\Tasks\At48.job
c:\windows\Tasks\At480.job
c:\windows\Tasks\At481.job
c:\windows\Tasks\At482.job
c:\windows\Tasks\At483.job
c:\windows\Tasks\At484.job
c:\windows\Tasks\At485.job
c:\windows\Tasks\At486.job
c:\windows\Tasks\At487.job
c:\windows\Tasks\At488.job
Infected copy of c:\windows\system32\drivers\ohci1394.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_NPF
-------\Legacy_USNJSVC
-------\Service_6to4
-------\Service_NPF
-------\Service_usnjsvc
((((((((((((((((((((((((( Files Created from 2010-09-28 to 2010-10-30 )))))))))))))))))))))))))))))))
.
2010-10-26 21:15 . 2010-10-26 21:15 -------- d-----w- c:\documents and settings\paul\Local Settings\Application Data\WMTools Downloaded Files
2010-10-06 11:56 . 2010-10-06 11:56 253952 ----a-w- c:\program files\win32config.exe
2010-10-05 19:14 . 2010-10-05 19:14 -------- d-----w- c:\documents and settings\paul\Local Settings\Application Data\Opera
2010-10-03 00:28 . 2010-10-03 00:28 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-10-01 17:16 . 2010-10-01 17:15 73728 ----a-w- c:\windows\system32\javacpl.cpl
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-01 17:15 . 2010-09-29 13:26 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-30 20:04 . 2010-07-09 00:14 33 ----a-w- c:\documents and settings\paul\DelIndex.BAT
2010-08-17 13:17 . 2004-08-11 17:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-11 22:40 . 2009-07-06 09:45 71259 ----a-w- c:\windows\Huawei ModemsUninstall.exe
.
<pre>
c:\program files\Adobe\Reader 9.0\Reader\Reader_sl .exe
c:\program files\Common Files\Java\Java Update\jusched .exe
c:\program files\Dell\QuickSet\Quickset .exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc .exe
c:\program files\Panicware\Pop-Up Stopper Free Edition\PSFree .exe
c:\program files\Sigmatel\C-Major Audio\WDM\stsystra .exe
c:\program files\Synaptics\SynTP\SynTPEnh .exe
c:\program files\Virgin Broadband Wireless\Wireless Manager .exe
c:\windows\system32\rundll32 .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2010-10-06 2475336]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-10-06 10:31 2475336 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2010-10-06 2475336]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2010-10-06 2475336]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~1\PSFree.exe" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [N/A]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2007-09-05 57344]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [N/A]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [N/A]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2010-10-01 94212]
"Dell QuickSet"="c:\program files\Dell\QuickSet\Quickset .exe c:\program files\Dell\QuickSet\Quickset.exe" [N/A]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
fyyrte.exe [2010-9-30 136192]
rupe.exe [2010-9-27 125440]
c:\documents and settings\rob\Start Menu\Programs\Startup\
huedtu.exe [2010-9-30 136192]
xoluud.exe [2010-9-27 125440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-15 09:25 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Update Agent.lnk]
backup=c:\windows\pss\Update Agent.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\3FWHZQA3LT
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMH2B46TDP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\handlerfix70700en00.exe]
[N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-12-13 16:41 77824 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-12-13 16:45 118784 ----a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-12-13 16:44 98304 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2006-10-03 11:35 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2006-10-03 11:37 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ncwoarmsex.tmp]
c:\docume~1\paul\LOCALS~1\Temp\ncwoarmsex.tmp [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryBooster]
c:\program files\Uniblue\RegistryBooster\launcher.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
c:\program files\Common Files\Java\Java Update\jusched.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tvagaki]
2008-04-14 00:12 76288 ----a-w- c:\windows\sirdrol.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 01:00 90112 ----a-w- c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"stllssvr"=3 (0x3)
"rpcapd"=2 (0x2)
"Creative Labs Licensing Service"=2 (0x2)
"BecHelperService"=2 (0x2)
"AffinegyService"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/29/2008 2:57 AM 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2/1/2009 5:56 PM 297752]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/25/2010 3:12 PM 136176]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG8\Toolbar\ToolbarBroker.exe [10/26/2010 2:35 PM 517448]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [8/10/2010 11:44 AM 103168]
S4 BecHelperService;BecHelperService;c:\program files\3\3Connect\BecHelperService.exe [8/11/2010 11:40 PM 1737464]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-10-29 c:\windows\Tasks\At489.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-28 c:\windows\Tasks\At49.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At490.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At491.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At492.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At493.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At494.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At495.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At496.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At497.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At498.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At499.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At50.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At500.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At501.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At502.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At503.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At504.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At505.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At506.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At507.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At508.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At509.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-20 c:\windows\Tasks\At51.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At510.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At511.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At512.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At513.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At514.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At515.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At516.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At517.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At518.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At519.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At52.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At520.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At521.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At522.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At523.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At524.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At525.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At526.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At527.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At528.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At529.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At53.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At530.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At531.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At532.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At533.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At534.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At535.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At536.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At537.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At538.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At539.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At54.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At540.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At541.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At542.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At543.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At544.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At545.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At546.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At547.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At548.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At549.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At55.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At550.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At551.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At552.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At553.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At554.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At555.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At556.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At557.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At558.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At559.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At56.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At560.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At561.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At562.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At563.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At564.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At565.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At566.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At567.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At568.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At569.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At57.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At570.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At571.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At572.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At573.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At574.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At575.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At576.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At577.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At578.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At579.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At58.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At580.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At581.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At582.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At583.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At584.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At585.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At586.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At587.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At588.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At589.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-22 c:\windows\Tasks\At59.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At590.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At591.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At592.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At593.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At594.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At595.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At596.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At597.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At598.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At599.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-25 c:\windows\Tasks\At60.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At600.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At601.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At602.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At603.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At604.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At605.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At606.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At607.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At608.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At609.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At61.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At610.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At611.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At612.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At613.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At614.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At615.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At616.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At617.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At618.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At619.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At62.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At620.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At621.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At622.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At623.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At624.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At625.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At626.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At627.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At628.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At629.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At63.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At630.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At631.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At632.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At633.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At634.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At635.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At636.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At637.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At638.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At639.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At64.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At640.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At641.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At642.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At643.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At644.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At645.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At646.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At647.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At648.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At65.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At66.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At67.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At68.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At69.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At70.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At71.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At72.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-28 c:\windows\Tasks\At73.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At74.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-20 c:\windows\Tasks\At75.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At76.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At77.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At78.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At79.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At80.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At81.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-14 c:\windows\Tasks\At82.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-22 c:\windows\Tasks\At83.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-25 c:\windows\Tasks\At84.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At85.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At86.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At87.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At88.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At89.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At90.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At91.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At92.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At93.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At94.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At95.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\At96.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-28 c:\windows\Tasks\At97.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-29 c:\windows\Tasks\At98.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-20 c:\windows\Tasks\At99.job
- c:\documents and settings\All Users\Application Data\iwcL2Kn7.exe [2010-10-30 23:26]
2010-10-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-25 14:12]
2010-10-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-25 14:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel
TCP: {51A10F13-CC46-4B63-9987-01EE78CFD2DB} = 208.67.220.220,208.67.222.222
TCP: {52C4170E-9E41-4DF4-B0F0-EE83C5330A70} = 208.67.220.220,208.67.222.222
TCP: {7FB7CA09-E371-4579-917E-F7A5E0EFE96D} = 208.67.220.220,208.67.222.222
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\documents and settings\paul\Application Data\Mozilla\Firefox\Profiles\4zxw83yo.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-10-31 00:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(952)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
c:\windows\system32\netprovcredman.dll
- - - - - - - > 'explorer.exe'(3584)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Intel\Wireless\Bin\WLKeeper.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\program files\SigmaTel\C-Major Audio\WDM\stsystra .exe
c:\docume~1\paul\LOCALS~1\Temp\hki208.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\windows\system32\dwwin.exe
.
**************************************************************************
.
Completion time: 2010-10-31 00:30:40 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-30 23:30
Pre-Run: 134,406,696,960 bytes free
Post-Run: 135,407,566,848 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 6C89111A15BEB0BF4CFD6785A3DA69F6