Here is the CFScript.txt log
Ivan
ComboFix 11-01-12.04 - Ivan 01/13/2011 14:31:48.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1427 [GMT -8:00]
Running from: d:\download\virus_tools\ComboFix.exe
Command switches used :: d:\download\virus_tools\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2010-12-13 to 2011-01-13 )))))))))))))))))))))))))))))))
.
2011-01-07 04:25 . 2011-01-07 04:25 -------- d-----w- c:\program files\ESET
2011-01-07 04:20 . 2011-01-07 04:20 -------- d-----w- C:\downloads
2011-01-03 04:05 . 2011-01-03 04:05 40960 ----a-r- c:\documents and settings\Ivan\Application Data\Microsoft\Installer\{FF1C72E2-203C-4E95-8D24-735196D29E04}\NewShortcut1_DC5EDBF7D08241849400BC64FF8DD4BE.exe
2011-01-03 03:58 . 2004-05-20 10:41 499712 ----a-w- c:\windows\system32\msvcp71.3
2011-01-03 03:58 . 2007-06-09 01:39 278528 ----a-w- c:\windows\hpzjut01.dll
2011-01-03 03:58 . 2007-04-27 04:06 40960 ----a-w- c:\windows\uninstallrq.exe
2011-01-03 03:58 . 2006-05-26 08:27 835584 ----a-w- c:\windows\tls7912d.dll
2010-12-31 05:24 . 2010-12-31 05:24 -------- d-----w- c:\documents and settings\Ivan\Application Data\JGsoft
2010-12-29 18:31 . 2010-12-29 18:30 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-12-25 09:34 . 2010-12-25 09:34 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-12-25 09:30 . 2010-12-25 09:30 20672 ----a-w- c:\windows\system32\mv2.dll
2010-12-25 09:30 . 2010-12-25 09:30 10688 ----a-w- c:\windows\system32\drivers\mv2.sys
2010-12-24 11:21 . 2010-12-24 11:26 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2010-12-24 11:06 . 2010-11-10 04:33 6273872 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{29DF3B89-6CC3-4767-A673-43F421934B2E}\mpengine.dll
2010-12-23 21:23 . 2010-12-23 21:24 -------- d-----w- c:\documents and settings\Ivan\Application Data\QuickScan
2010-12-23 09:36 . 2010-01-13 19:15 57800 ----a-w- c:\windows\system32\drivers\CBDisk.sys
2010-12-23 08:01 . 2010-12-23 08:01 -------- d-----w- c:\documents and settings\Ivan\Application Data\Enplase
2010-12-21 08:14 . 2010-12-21 08:14 -------- d-----w- c:\program files\SWFObject 2 generator v1.2 AIR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-12 17:30 . 2005-11-06 01:29 7304 ----a-w- c:\windows\TMP0001.TMP
2011-01-10 02:07 . 2009-10-08 06:55 74 ----a-w- c:\documents and settings\Ivan\Application Data\fspro2_0.tmp
2011-01-10 02:07 . 2009-10-08 06:55 66 ----a-w- c:\documents and settings\Ivan\Application Data\ispro4_0.tmp
2011-01-10 02:07 . 2010-01-29 02:34 66 ----a-w- c:\documents and settings\Ivan\Application Data\ispresenter4_0.tmp
2010-12-31 20:06 . 2010-06-29 20:08 38848 ----a-w- c:\windows\avastSS.scr
2010-12-31 20:06 . 2010-04-27 09:40 188216 ----a-w- c:\windows\system32\aswBoot.exe
2010-12-31 20:00 . 2010-04-27 09:40 293968 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-12-31 19:59 . 2010-04-27 09:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-12-31 19:59 . 2010-04-27 09:40 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-12-31 19:59 . 2010-04-27 09:40 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-12-31 19:56 . 2010-04-27 09:40 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-12-31 19:56 . 2010-04-27 09:40 29264 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-12-31 19:56 . 2010-04-27 09:40 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-12-29 18:30 . 2010-05-04 23:47 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-21 02:09 . 2009-01-21 23:28 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 02:08 . 2009-01-21 23:28 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-30 01:38 . 2010-11-30 01:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-30 01:38 . 2010-11-30 01:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-18 18:12 . 2006-07-28 08:41 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-15 19:08 . 2008-11-05 01:31 644976 ----a-w- c:\windows\system32\Wacom_Tablet.dll
2010-11-15 19:08 . 2008-11-05 01:31 506736 ----a-w- c:\windows\system32\Wintab32.dll
2010-11-10 04:33 . 2009-07-05 05:24 6273872 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2010-11-09 14:52 . 2008-04-14 08:00 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26 . 2008-07-12 19:10 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2008-04-23 00:16 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2008-04-23 00:16 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2008-07-12 19:09 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2008-04-14 08:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-11-01 05:08 . 2007-12-02 04:05 57344 ----a-r- c:\documents and settings\Ivan\Application Data\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
2010-10-28 20:23 . 2010-12-08 23:15 2217088 ----a-w- c:\windows\system32\BootMan.exe
2010-10-28 13:13 . 2008-04-14 08:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 15:07 . 2010-10-26 15:07 64512 ----a-w- c:\windows\system32\nlssrv32.exe
2010-10-26 13:25 . 2008-04-14 08:00 1853312 ----a-w- c:\windows\system32\win32k.sys
2010-10-25 16:50 . 2010-12-08 19:59 82696 ----a-w- c:\windows\system32\lmdimon8.dll
2010-10-25 16:50 . 2010-12-08 19:59 82184 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\lmdippr8.dll
2010-10-20 06:40 . 2010-10-18 07:09 74 ----a-w- c:\documents and settings\Ivan\Application Data\fspro2_1.tmp
2010-10-20 06:40 . 2010-10-18 07:09 66 ----a-w- c:\documents and settings\Ivan\Application Data\ispro4_1.tmp
2010-10-20 06:40 . 2010-10-18 07:09 66 ----a-w- c:\documents and settings\Ivan\Application Data\ispresenter4_1.tmp
2010-10-19 18:41 . 2009-10-05 16:47 222080 ------w- c:\windows\system32\MpSigStub.exe
2009-06-10 16:55 . 2008-08-14 00:22 28488 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2009-09-29 22:19 . 2008-08-14 00:22 185232 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\opera\program\plugins\ssldivx.dll
2005-09-16 01:26 . 2008-08-14 00:21 44153 ----a-w- c:\program files\mozilla firefox\components\inspector.dll
2006-05-03 09:06 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 216064 --sh--r- c:\windows\system32\nbDX.dll
.
------- Sigcheck -------
[-] 2008-07-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-01-11_21.16.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-12 17:31 . 2011-01-12 17:31 16384 c:\windows\Temp\Perflib_Perfdata_a1c.dat
- 2009-08-23 22:56 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2009-08-23 22:56 . 2010-02-22 14:23 17272 c:\windows\system32\spmsg.dll
- 2009-09-01 08:11 . 2010-12-16 01:05 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-09-01 08:11 . 2011-01-12 17:12 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-09-01 08:11 . 2010-12-16 01:05 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-09-01 08:11 . 2011-01-12 17:12 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-01-29 06:21 . 2010-12-16 01:05 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-01-29 06:21 . 2011-01-12 17:12 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-04-14 08:00 . 2008-04-14 08:00 249856 c:\windows\system32\dllcache\odbc32.dll
+ 2008-04-14 08:00 . 2010-11-09 14:52 249856 c:\windows\system32\dllcache\odbc32.dll
- 2006-07-28 08:41 . 2008-04-14 08:00 102400 c:\windows\system32\dllcache\msjro.dll
+ 2006-07-28 08:41 . 2010-11-09 14:52 102400 c:\windows\system32\dllcache\msjro.dll
+ 2006-07-28 08:41 . 2010-11-09 14:52 200704 c:\windows\system32\dllcache\msadox.dll
- 2006-07-28 08:41 . 2008-04-14 08:00 200704 c:\windows\system32\dllcache\msadox.dll
+ 2006-07-28 08:41 . 2010-11-09 14:52 180224 c:\windows\system32\dllcache\msadomd.dll
- 2006-07-28 08:41 . 2008-04-14 08:00 180224 c:\windows\system32\dllcache\msadomd.dll
- 2006-07-28 08:41 . 2008-04-14 08:00 536576 c:\windows\system32\dllcache\msado15.dll
+ 2006-07-28 08:41 . 2010-11-09 14:52 536576 c:\windows\system32\dllcache\msado15.dll
+ 2006-07-28 08:41 . 2010-11-09 14:52 143360 c:\windows\system32\dllcache\msadco.dll
- 2006-07-28 08:41 . 2008-04-14 08:00 143360 c:\windows\system32\dllcache\msadco.dll
- 2009-09-01 08:11 . 2010-12-16 01:05 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-09-01 08:11 . 2011-01-12 17:12 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-09-01 08:11 . 2011-01-12 17:12 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2009-09-01 08:11 . 2010-12-16 01:05 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2009-09-01 08:11 . 2010-12-16 01:05 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-09-01 08:11 . 2011-01-12 17:12 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-09-01 08:11 . 2011-01-12 17:12 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-09-01 08:11 . 2010-12-16 01:05 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-09-01 08:11 . 2011-01-12 17:12 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2009-09-01 08:11 . 2010-12-16 01:05 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-09-01 08:11 . 2011-01-12 17:12 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2009-09-01 08:11 . 2010-12-16 01:05 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-09-01 08:11 . 2011-01-12 17:12 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2009-09-01 08:11 . 2010-12-16 01:05 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2010-12-17 08:17 . 2010-12-17 08:17 3362304 c:\windows\Installer\2f9f3fd.msp
+ 2009-09-01 08:11 . 2011-01-12 17:12 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-09-01 08:11 . 2010-12-16 01:05 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-09-01 08:11 . 2010-12-16 01:05 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-09-01 08:11 . 2011-01-12 17:12 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2005-06-19 19:10 . 2011-01-12 17:12 37403080 c:\windows\system32\MRT.exe
+ 2010-12-21 21:06 . 2010-12-21 21:06 11570688 c:\windows\Installer\2f9f3e5.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Ivan\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Ivan\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Ivan\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LClock"="c:\program files\utils\LClock\lclock.exe" [2004-09-19 65536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960]
"AGRSMMSG"="AGRSMMSG.exe" [2004-07-22 88361]
"kmw_run.exe"="kmw_run.exe" [2006-08-03 106496]
"Opware14"="c:\program files\apps\OmniPagePro14.0\Opware14.exe" [2004-03-08 57344]
"Contour Shuttle Device Helper"="c:\program files\utils\Contour Shuttle\ShuttleHelper.exe" [2007-02-23 118784]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2010-03-27 5107232]
"WFXSwtch"="c:\progra~1\apps\winfax\WFXSWTCH.exe" [2002-12-12 28160]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2002-12-12 45568]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2010-03-27 362232]
"avast5"="c:\progra~1\Avast5\avastUI.exe" [2010-12-31 3395600]
"MacDrive 8 application"="c:\program files\Mediafour\MacDrive 8\MacDrive.exe" [2010-02-04 289368]
"Getting started with MacDrive 8"="c:\program files\Mediafour\MacDrive 8\MDGetStarted.exe" [2009-04-01 141312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\Ivan\Start Menu\Programs\Startup\
Launchy.lnk - c:\program files\utils\Launchy\Launchy.exe [2009-8-16 380928]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-6-20 110592]
Launchy.lnk - c:\program files\utils\Launchy\Launchy.exe [2009-8-16 380928]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 01000000
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\apps\Eudora\EuShlExt.dll" [2005-06-08 86016]
"{1214FBE7-4464-4A7E-9958-B5851A7A30A3}"= "c:\program files\utils\RecentX\RXShell.dll" [2008-06-12 77824]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\utils\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{A213B520-C6C2-11d0-AF9D-008029E1027E}"= "c:\program files\apps\winfax\WfxSeh32.Dll" [1998-07-27 38400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w- c:\program files\utils\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave"=DrvTrNTm.dll
"mixer"=DrvTrNTm.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ASTSRV]
@="service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2010-09-23 21:36 624056 ----a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-12-12 05:29 133104 ----atw- c:\documents and settings\Ivan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-14 01:16 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NexusServer]
2007-03-27 01:45 389120 ----a-w- c:\program files\Common Files\Grass Valley\ProCoder 3\Kernel\PNXSERVR.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 01:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 19:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-01-27 01:36 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-08-25 02:39 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vspdfprsrv.exe]
2007-07-03 02:58 1179648 ----a-w- c:\program files\utils\eXPert PDF 5\vspdfprsrv.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\support.com\\client\\bin\\tgcmd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\apps\\aol9\\waol.exe"=
"c:\\Program Files\\apps\\AIM\\aim.exe"=
"c:\\Program Files\\utils\\SmartFTP\\SmartFTP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\mmedia\\River Past\\PlayDV\\PlayDV.exe"=
"c:\\Program Files\\mmedia\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\mmedia\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\mmedia\\CyberLink\\PowerDVD8\\PowerDVD8\\PowerDVD8.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Gizmo5\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\utils\\UltraVNC\\winvnc.exe"=
"c:\\Program Files\\utils\\UltraVNC\\vncviewer.exe"=
"c:\\Documents and Settings\\Ivan\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [6/4/2009 5:10 PM 40560]
R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [2/4/2010 10:52 AM 231016]
R0 MDPMGRNT;MacDrive partition driver;c:\windows\system32\drivers\MDPMGRNT.SYS [1/22/2010 11:20 AM 29792]
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\drivers\tdrpm258.sys [12/30/2009 1:49 AM 911680]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/27/2010 1:40 AM 293968]
R1 CBDisk;CBDisk;c:\windows\system32\drivers\CBDisk.sys [12/23/2010 1:36 AM 57800]
R1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [5/30/2010 6:59 AM 7936]
R1 SASDIFSV;SASDIFSV;c:\program files\utils\SUPERAntiSpyware\SASDIFSV.SYS [1/15/2009 4:17 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\utils\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 4:17 PM 55024]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [8/14/2008 2:47 PM 95592]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [10/30/2009 10:44 PM 2480048]
R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;c:\program files\utils\ASTRA32\astra32.sys [2/22/2007 10:28 AM 30864]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/27/2010 1:40 AM 17744]
R2 CoLinuxDriver;CoLinuxDriver;c:\temp\Portable_Ubuntu\linux.sys [4/5/2009 11:46 AM 68096]
R2 MacDrive8Service;MacDrive 8 service;c:\program files\Mediafour\MacDrive 8\MacDrive8Service.exe [1/7/2010 10:22 AM 192512]
R2 TabletServiceWacom;TabletServiceWacom;c:\program files\Tablet\Wacom\Wacom_Tablet.exe [10/15/2010 11:42 PM 4807536]
R2 uvnc_service;uvnc_service;c:\program files\utils\UltraVNC\winvnc.exe [6/16/2009 10:50 PM 1737200]
R2 VDDriver;Virtual Disk Driver;c:\program files\Virtual Disk\VDDriver.sys [5/22/2009 9:24 PM 40952]
R2 ZentimoService;Zentimo Assistant;c:\program files\utils\Zentimo\ZentimoService.exe [11/3/2010 11:41 AM 240976]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [10/30/2009 10:44 PM 160704]
R3 DsAudioDevice_286;DsAudioDevice_286;c:\windows\system32\drivers\DsAudioDevice_286.sys [12/24/2008 7:50 PM 16640]
R3 m4cxw2k3;NDIS5.1 Miniport Driver for D-Link DGE-5xx Gigabit Ethernet Adapter;c:\windows\system32\drivers\m4cxw2k3.sys [12/3/2007 6:28 PM 298752]
R3 mv2;mv2;c:\windows\system32\drivers\mv2.sys [12/25/2010 1:30 AM 10688]
R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [8/14/2008 10:02 PM 130128]
R3 TotRec8;Total Recorder WDM audio filter driver;c:\windows\system32\drivers\TotRec8.sys [4/21/2010 3:03 PM 90192]
R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [5/14/2009 1:57 PM 16640]
S0 PCGenFAM;PCGenFAM;c:\windows\system32\drivers\PCGenFAM.sys [6/12/2010 7:33 PM 179144]
S2 VRDVC20;Sony VRD-VC20 [Video Capture];c:\windows\system32\drivers\VRDVC20X.SYS [12/14/2007 6:13 PM 31104]
S3 ASTSRV;Nalpeiron Licensing Service;c:\windows\system32\ASTSRV.EXE [12/6/2008 12:25 AM 57344]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [12/8/2010 3:15 PM 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [12/8/2010 3:15 PM 8456]
S3 FNETTBOH;FNETTBOH;c:\windows\system32\drivers\FNETTBOH.SYS [5/30/2010 6:59 AM 23680]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 12:22 PM 34064]
S3 Otis;Audible Otis Service;c:\windows\system32\drivers\OtisPlay.sys [6/23/2005 12:15 PM 9472]
S3 palmusb;USB Comm driver (WDM);c:\windows\system32\drivers\palmusb.sys [12/20/2001 8:21 PM 72800]
S3 PortRST;BaromTec HMS30C6001 Reset Driver;c:\windows\system32\drivers\PortRST.sys [6/23/2005 12:15 PM 12721]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [5/28/2010 3:04 AM 14896]
S3 RIOUSB;RioPort.Com Rio500 USB Driver;c:\windows\system32\drivers\RioUSB.sys [6/23/2005 12:16 PM 10020]
S3 SASENUM;SASENUM;c:\program files\utils\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 4:17 PM 7408]
S3 SkLaggProtocol;Marvell Link Aggregation Protocol;c:\windows\system32\drivers\yk51x86l.sys [9/22/2009 1:10 AM 60928]
S3 SkVlanProtocol;Marvell VLAN Protocol;c:\windows\system32\drivers\yk51x86v.sys [8/27/2009 1:10 AM 20992]
S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [5/25/2009 2:43 PM 32408]
S3 Sr31a0;Sr31a0;c:\windows\system32\drivers\ati1ttxx.sys [6/19/2005 10:53 AM 21343]
S3 STVqx3;Intel Play QX3 Microscope;c:\windows\system32\drivers\STVqx3.SYS [6/7/2009 2:53 PM 131776]
S3 XIRLINK;IBM PC Camera;c:\windows\system32\drivers\C-itNT.sys [8/14/2006 7:48 PM 899884]
S3 XLoader;PLEXTOR EZ-USB FX2 FIRMWARE LOADER (XLoader.sys);c:\windows\system32\drivers\XLoader.sys [1/21/2004 6:55 PM 13696]
S4 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S4 mrtRate;mrtRate; [x]
S4 scsiscan;SCSI Scanner Driver;c:\windows\system32\DRIVERS\scsiscan.sys --> c:\windows\system32\DRIVERS\scsiscan.sys [?]
S4 SolutoService;Soluto PCGenome Core Service;"c:\program files\Soluto\SolutoService.exe" --> c:\program files\Soluto\SolutoService.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1/22/2007 5:26 PM 697328]
S4 vaxscsi;vaxscsi;c:\windows\system32\Drivers\vaxscsi.sys --> c:\windows\system32\Drivers\vaxscsi.sys [?]
S4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-04-19 20:23 452136 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2006-07-29 c:\windows\Tasks\1 Copernic Intra-Daily ~IVAN_VAIO Ivan.job
- c:\program files\apps\Copernic Agent\CopernicAgent.exe [2005-08-01 02:16]
2006-07-29 c:\windows\Tasks\2 Copernic Daily ~IVAN_VAIO Ivan.job
- c:\program files\apps\Copernic Agent\CopernicAgent.exe [2005-08-01 02:16]
2006-07-29 c:\windows\Tasks\3 Copernic Weekly ~IVAN_VAIO Ivan.job
- c:\program files\apps\Copernic Agent\CopernicAgent.exe [2005-08-01 02:16]
2006-07-29 c:\windows\Tasks\4 Copernic Monthly ~IVAN_VAIO Ivan.job
- c:\program files\apps\Copernic Agent\CopernicAgent.exe [2005-08-01 02:16]
2011-01-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]
2011-01-13 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-12-06 16:00]
2011-01-13 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]
2011-01-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3755968889-2878311043-70394834-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 10:02]
2011-01-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3755968889-2878311043-70394834-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 10:02]
2011-01-08 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-02-04 23:50]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.sony.com/vaiopeople
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - c:\program files\mmedia\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\mmedia\Orbitdownloader\orbitmxt.dll/204
IE: Add to EverNote - c:\program files\apps\EverNote\enbar.dll/2000
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Do&wnload selected by Orbit - c:\program files\mmedia\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\mmedia\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Open RSS Feed - c:\program files\apps\Feed Mix\getlink.htm
IE: Save &frame with MetaProducts Inquiry - c:\program files\apps\MetaProducts Inquiry\inquiry.dll/saveframe.htm
IE: Save &image with MetaProducts Inquiry - c:\program files\apps\MetaProducts Inquiry\inquiry.dll/saveimg.htm
IE: Save &page with MetaProducts Inquiry - c:\program files\apps\MetaProducts Inquiry\inquiry.dll/savepage.htm
IE: Save &selection with MetaProducts Inquiry - c:\program files\apps\MetaProducts Inquiry\inquiry.dll/savesel.htm
IE: Search Using Copernic Agent - c:\program files\apps\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: SurfSaver &QuickSave - c:\program files\apps\SurfSaver\QuickSave.htm
IE: SurfSaver Sav&e... - c:\program files\apps\SurfSaver\Add.htm
IE: SurfSaver Searc&h... - c:\program files\apps\SurfSaver\Search.htm
IE: { - c:\program files\Messenger\msmsgs.exe
IE: {{FDD900B6-E210-462A-8526-8F225845B3B3}
IE: {{55AD98FF-3CB9-4718-B28B-E18F932D7FAB} - {6766A865-215F-465A-B266-9CB9C7BA71FA} - c:\program files\apps\MetaProducts Inquiry\inquiry.dll
IE: {{7FDB9AEE-D04A-440C-8D1D-52B807115C59} - {D1917456-D76D-48DF-9981-B3978EACCD8F} - c:\program files\apps\MetaProducts Inquiry\inquiry.dll
IE: {{8F36E80B-AD7C-434E-AB92-DA3938EA01E5} - {3680299D-8B37-4F8A-9975-EDD867F10E94} - c:\program files\apps\MetaProducts Inquiry\inquiry.dll
IE: {{B98EEB00-A0F2-11D7-9FD9-0080481ADA61} - {F1F3B320-A0F9-11D7-9FD9-0080481ADA61} - c:\program files\apps\MetaProducts Inquiry\inquiry.dll
Handler: asksam - {F9FF9EDA-4916-11D1-B6C1-002018305A61} - c:\program files\apps\SurfSaver\AS_AIPP.dll
Handler: copernicagent - {A979B6BD-E40B-4A07-ABDD-A62C64A4EBF6} - c:\progra~1\apps\COPERN~1\COPERN~1.DLL
Handler: copernicagentcache - {AAC34CFD-274D-4A9D-B0DC-C74C05A67E1D} - c:\progra~1\apps\COPERN~1\COPERN~1.DLL
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
DPF: {BDEE1959-AB6B-4745-A29B-F492861102CC}
FF - ProfilePath - c:\documents and settings\Ivan\Application Data\Mozilla\Firefox\Profiles\jxegbc6z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Crack Spider
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=FF&o=14594&locale=en_US&q=
FF - Ext: ScrapBook: {53A03D43-5363-4669-8190-99061B2DEBA5} - %profile%\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
FF - Ext: ChatZilla: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2} - %profile%\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
FF - Ext: ColorZilla: {6AC85730-7D0F-4de0-B3FA-21142DD85326} - %profile%\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
FF - Ext: IE View: {6e84150a-d526-41f1-a480-a67d3fed910d} - %profile%\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
FF - Ext: MeasureIt: {75CEEE46-9B64-46f8-94BF-54012DE155F0} - %profile%\extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}
FF - Ext: FireFTP: {a7c6cf7f-112c-4500-a7ea-39801a327e5f} - %profile%\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
FF - Ext: Tab Mix Plus: {dc572301-7619-498c-a57d-39143191b318} - %profile%\extensions\{dc572301-7619-498c-a57d-39143191b318}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: MR Tech Toolkit: {9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC} - %profile%\extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Media Converter: {6e764c17-863a-450f-bdd0-6772bd5aaa18} - %profile%\extensions\{6e764c17-863a-450f-bdd0-6772bd5aaa18}
FF - Ext: S3 Firefox Organizer(S3Fox): {7CEA821D-3DAB-4238-B424-BF7324531750} - %profile%\extensions\{7CEA821D-3DAB-4238-B424-BF7324531750}
FF - Ext: Web Developer: {c45c406e-ab73-11d8-be73-000a95be3b12} - %profile%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
FF - Ext: Firebug: firebug@software.joehewitt.com - %profile%\extensions\firebug@software.joehewitt.com
FF - Ext: Book Burro: {c7d1f80d-de65-49ee-852b-2b00b3b19a5d} - %profile%\extensions\{c7d1f80d-de65-49ee-852b-2b00b3b19a5d}
FF - Ext: Snagit Firefox Extension: {6FF1D3C4-61BC-4021-89B7-AF8A8F784EBB} - %profile%\extensions\{6FF1D3C4-61BC-4021-89B7-AF8A8F784EBB}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: BitDefender QuickScan: {e001c731-5e37-4538-a5cb-8168736a2360} - %profile%\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-13 14:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{238B46B1-DB3F-FF9F-817885D113BABB65}\{C7A1A506-D491-606A-8FAD8C1E4DD81C50}\{5DBD0FCF-797E-7771-3B3D82FCE9F240F9}*]
"1D1OWFM6WKF6TLM3S2BGKKUUDG1"=hex:01,00,01,00,00,00,00,00,71,4a,e0,45,b7,4f,44,
fb,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{44BD4CEF-0E4D-C558-6DFE23FFC881A6CD}\{A2EC7C34-2018-E83B-27DF1E7548223FEC}\{5151FD78-1E6F-B5B8-7B478C2CB67D678B}*]
"1D1OWFM6WKF6TLM3S2BGKKUUDG1"=hex:01,00,01,00,00,00,00,00,71,4a,e0,45,b7,4f,44,
fb,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4E801B1F-2C34-C71B-55752B4DE71FAE4A}\{6707E13D-DFA5-4083-2A160A7F601D7F5F}\{38345692-AD4C-2D4A-1F4885FC450939AB}*]
"{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,09,8b,ba,
a2,1d,9e,dc,aa,73,95,c6,08,e2,24,2a,ef,a9,dd,02,7e,a2,5a,30,8f,25,80,32,b7,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{580924E7-4534-80EF-AD4675C17646FF10}\{0EFB2AA0-1A3E-507D-F9B34D5CF29081CD}\{BBABFA65-B0A6-C96D-B621BCAFF6A8D6D6}*]
"1D1OWFM6WKF6TLM3S2BGKKUUDG1"=hex:01,00,01,00,00,00,00,00,71,4a,e0,45,b7,4f,44,
fb,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8AC0FFDC-D68A-4D5F-75BF0D842EDCB137}\{3647E330-7B13-5DC9-623E15C2DE512604}\{FDA52484-33A0-4DF1-40A7FB2F70E68E7D}*]
"1D1OWFM6WKF6TLM3S2BGKKUUDG1"=hex:01,00,01,00,00,00,00,00,71,4a,e0,45,b7,4f,44,
fb,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{966E1176-98BD-E3A3-1649E4659438A716}\{7D188DDB-E560-5BB6-20EABCAAB28395D5}\{0998E78C-7C0A-2C8B-9F05FD29FB8035CC}*]
"{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,09,8b,ba,
a2,1d,9e,dc,aa,73,95,c6,08,e2,24,2a,ef,a9,dd,02,7e,a2,5a,30,8f,25,80,32,b7,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AD7DA6D0-C8A5-2AB7-AFAFBAF6CCA2EFA4}\{BFF22B84-84BD-C376-CF902D4CFF2D2B8A}\{C30500AE-8022-F8A1-791309212C4775E7}*]
"{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,09,8b,ba,
a2,1d,9e,dc,aa,73,95,c6,08,e2,24,2a,ef,a9,dd,02,7e,a2,5a,30,8f,25,80,32,b7,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B9046776-195D-89EA-3E66F9BC5DAE5B9B}\{E7989E73-D3F8-C437-CB8470F59A56421D}\{FFD68A1F-1364-19C2-ECF1A15A7898EBE6}*]
"{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,09,8b,ba,
a2,1d,9e,dc,aa,73,95,c6,08,e2,24,2a,ef,a9,dd,02,7e,a2,5a,30,8f,25,80,32,b7,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:f8,8c,ff,40,38,f3,d9,1b,2a,2c,53,27,f3,1d,a9,2d,cc,41,e2,32,14,
71,81,51,a8,c2,71,ef,57,c0,82,cd,ec,e6,65,a7,ff,59,2e,a5,1f,58,00,02,c0,9c,\
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\|"|w*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ؕ||A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\\Registered"
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:f8,8c,ff,40,38,f3,d9,1b,2a,2c,53,27,f3,1d,a9,2d,cc,41,e2,32,14,
71,81,51,a8,c2,71,ef,57,c0,82,cd,ec,e6,65,a7,ff,59,2e,a5,1f,58,00,02,c0,9c,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(800)
c:\program files\utils\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(1440)
c:\windows\system32\WININET.dll
c:\windows\system32\kmw_dll.dll
c:\windows\system32\WOW32.dll
c:\program files\apps\OmniPagePro14.0\OpHook14.dll
c:\documents and settings\Ivan\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\ieframe.dll
c:\program files\utils\LClock\LC.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-01-13 14:52:12
ComboFix-quarantined-files.txt 2011-01-13 22:51
ComboFix2.txt 2011-01-11 21:23
Pre-Run: 36,488,511,488 bytes free
Post-Run: 36,480,040,960 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 559DB141CE3BC099BF7E62761FA55467