ComboFix 12-12-17.02 - Jim 12/17/2012 11:37:18.8.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2013.1141 [GMT -6:00]
Running from: c:\documents and settings\Jim\My Documents\ComboFix.exe
Command switches used :: c:\documents and settings\Jim\Desktop\CFScript.txt
AV: BitDefender Antivirus *Disabled/Outdated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
FILE ::
"c:\windows\system32\rsvpspc.dll"
"c:\windows\Tasks\PC Utility Kit Registration3.job"
"c:\windows\Tasks\PC Utility Kit Update3.job"
"c:\windows\Tasks\PC Utility Kit.job"
"c:\windows\Tasks\Zblyc.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\PC Utility Kit
c:\documents and settings\All Users\Application Data\PC Utility Kit\PC Utility Kit\dc_db.db
c:\documents and settings\All Users\Application Data\PC Utility Kit\UUS3\Master.xml
c:\documents and settings\All Users\Application Data\PC Utility Kit\UUS3\Patch.xml
c:\documents and settings\All Users\Application Data\PC Utility Kit\UUS3\pcutilitykit\Database.xml
c:\documents and settings\All Users\Application Data\PC Utility Kit\UUS3\pcutilitykit\Master.xml
c:\documents and settings\All Users\Application Data\PC Utility Kit\UUS3\pcutilitykit\Patch.xml
c:\documents and settings\All Users\Application Data\PC Utility Kit\UUS3\pcutilitykit\Update.xml
c:\documents and settings\All Users\Application Data\PC Utility Kit\UUS3\Update.xml
c:\documents and settings\Jim\Application Data\PC Utility Kit
c:\documents and settings\Jim\Local Settings\Application Data\AskToolbar
c:\documents and settings\Jim\Local Settings\Application Data\AskToolbar\APNU\config.xml
c:\documents and settings\Jim\Local Settings\Application Data\AskToolbar\cache.dat
c:\documents and settings\Jim\Local Settings\Application Data\AskToolbar\config.xml
c:\program files\Ask.com
c:\program files\Ask.com\assets\oobe\b.png
c:\program files\Ask.com\assets\oobe\bl.png
c:\program files\Ask.com\assets\oobe\br.png
c:\program files\Ask.com\assets\oobe\l.png
c:\program files\Ask.com\assets\oobe\pointer.png
c:\program files\Ask.com\assets\oobe\r.png
c:\program files\Ask.com\assets\oobe\t.png
c:\program files\Ask.com\assets\oobe\tl.png
c:\program files\Ask.com\assets\oobe\tr.png
c:\program files\Ask.com\cb_1d1.ico
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_1ce.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\precache.exe
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\Updater\config.xml
c:\program files\Ask.com\Updater\Updater.exe
c:\program files\Ask.com\UpdateTask.exe
c:\program files\Common Files\PC Utility Kit
c:\program files\Common Files\PC Utility Kit\UUS3\Images\close.png
c:\program files\Common Files\PC Utility Kit\UUS3\Images\close_md.png
c:\program files\Common Files\PC Utility Kit\UUS3\Images\close_mo.png
c:\program files\Common Files\PC Utility Kit\UUS3\Images\close_pu.png
c:\program files\Common Files\PC Utility Kit\UUS3\Images\close_pu_md.png
c:\program files\Common Files\PC Utility Kit\UUS3\Images\close_pu_mo.png
c:\program files\Common Files\PC Utility Kit\UUS3\Images\Logo.png
c:\program files\Common Files\PC Utility Kit\UUS3\Images\min.png
c:\program files\Common Files\PC Utility Kit\UUS3\Images\min_md.png
c:\program files\Common Files\PC Utility Kit\UUS3\Images\min_mo.png
c:\program files\Common Files\PC Utility Kit\UUS3\Images\topbar_gradient.png
c:\program files\Common Files\PC Utility Kit\UUS3\LiteUnzip.dll
c:\program files\Common Files\PC Utility Kit\UUS3\settings.xml
c:\program files\Common Files\PC Utility Kit\UUS3\Update3.exe
c:\program files\Common Files\PC Utility Kit\UUS3\UUS3.dll
c:\program files\Inbox Toolbar
c:\program files\PC Utility Kit
c:\program files\PC Utility Kit\PC Utility Kit\7ZipDLL.dll
c:\program files\PC Utility Kit\PC Utility Kit\colors.xml
c:\program files\PC Utility Kit\PC Utility Kit\CommonLoggingExtension.pxt
c:\program files\PC Utility Kit\PC Utility Kit\CommonSpecialist.pxt
c:\program files\PC Utility Kit\PC Utility Kit\ExtensionManager.dll
c:\program files\PC Utility Kit\PC Utility Kit\filecachedb.xml
c:\program files\PC Utility Kit\PC Utility Kit\HandleUpdate.dll
c:\program files\PC Utility Kit\PC Utility Kit\HTML\0_days.htm
c:\program files\PC Utility Kit\PC Utility Kit\HTML\1_days.htm
c:\program files\PC Utility Kit\PC Utility Kit\HTML\15_days.htm
c:\program files\PC Utility Kit\PC Utility Kit\HTML\2_days.htm
c:\program files\PC Utility Kit\PC Utility Kit\HTML\30_days.htm
c:\program files\PC Utility Kit\PC Utility Kit\HTML\5_days.htm
c:\program files\PC Utility Kit\PC Utility Kit\HTML\container_content_bkimg.gif
c:\program files\PC Utility Kit\PC Utility Kit\HTML\container_content_leftimg.gif
c:\program files\PC Utility Kit\PC Utility Kit\HTML\container_content_rightimg.gif
c:\program files\PC Utility Kit\PC Utility Kit\HTML\error_connect.html
c:\program files\PC Utility Kit\PC Utility Kit\HTML\images\10x10.gif
c:\program files\PC Utility Kit\PC Utility Kit\HTML\images\10x10tile.gif
c:\program files\PC Utility Kit\PC Utility Kit\HTML\images\background.jpg
c:\program files\PC Utility Kit\PC Utility Kit\HTML\images\contentwrapper.gif
c:\program files\PC Utility Kit\PC Utility Kit\HTML\images\error_internet.jpg
c:\program files\PC Utility Kit\PC Utility Kit\HTML\images\footerbarfill.gif
c:\program files\PC Utility Kit\PC Utility Kit\HTML\images\info_bubble.jpg
c:\program files\PC Utility Kit\PC Utility Kit\HTML\images\tile_footerbarbase.jpg
c:\program files\PC Utility Kit\PC Utility Kit\HTML\images\tile_subheadbarbase.jpg
c:\program files\PC Utility Kit\PC Utility Kit\HTML\images\tile_titlebarbase.jpg
c:\program files\PC Utility Kit\PC Utility Kit\HTML\main.css
c:\program files\PC Utility Kit\PC Utility Kit\HTML\main_error.css
c:\program files\PC Utility Kit\PC Utility Kit\HTML\package_titlebar_bkimg.jpg
c:\program files\PC Utility Kit\PC Utility Kit\HTML\uninstall\box_screen.jpg
c:\program files\PC Utility Kit\PC Utility Kit\HTML\uninstall\default_button.gif
c:\program files\PC Utility Kit\PC Utility Kit\HTML\uninstall\default_button_over.gif
c:\program files\PC Utility Kit\PC Utility Kit\HTML\uninstall\header_background.jpg
c:\program files\PC Utility Kit\PC Utility Kit\HTML\uninstall\index.html
c:\program files\PC Utility Kit\PC Utility Kit\Images\Audio\cancel.wav
c:\program files\PC Utility Kit\PC Utility Kit\Images\Audio\complete.wav
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\btn.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\btn_over.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\button_bho.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\button_defrag.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\button_file.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\button_generalsettings.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\button_ignore.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\button_junk.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\button_privacy.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\button_process.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\button_registry.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\button_schedule.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\button_startup.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\register.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\register_over.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\register_over_small.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\register_small.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\renew.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\renew_over.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\settings_button.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\settings_button_over.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\start.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\buttons\start_over.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\defrag\c_empty.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\defrag\c_frag.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\defrag\c_unfrag.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\defrag\c_unknown.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\defrag\c_unmove.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\close.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\dlg_title.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\logo.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\max.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\min.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\register.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\register_close.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\register_close_over.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\register_over.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\renew.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\renew_over.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\restore.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\tab_bg.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\tabactive_bg.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\tabover_bg.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\tfn_bg.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\tfn_logo.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\title_bar.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Frame\upper_divider.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\general\collapse.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\general\delete.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\general\expand.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\general\progress_glow.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\bho.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\dup_audio.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\dup_doc.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\dup_image.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\dup_other.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\dup_video.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\ig_drivers.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\ig_proc.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\ig_reg.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\junk.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\priv_3rd.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\priv_browser.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\priv_email.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\priv_fs.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\priv_im.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\priv_multi.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\priv_office.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\priv_other.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\priv_windows.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\reg_apppath.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\reg_com.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\reg_dll.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\reg_empty.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\reg_extensions.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\reg_filepath.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\reg_font.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\reg_help.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\reg_shortcut.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\reg_startup.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\reg_uninstall.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\group\startup.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_about.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_bho.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_clean.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_defrag.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_file.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_junk.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_junk_settings.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_malware.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_performance.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_privacy.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_process.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_registry.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_restore.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_settings.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_startup.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\header_tools.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\settings_general.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\settings_ignore.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\settings_privacy.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\settings_registry.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\headers\settings_schedule.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Icons\info.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Icons\warning.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\other.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\process\bho.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\process\process.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\process\startup.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_malware16.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_malware24.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_malware32.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_system16.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_system24.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_system32.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_unknown16.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_unknown24.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_unknown32.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_unwanted16.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_unwanted24.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_unwanted32.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_userapp16.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_userapp24.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\list\recommendations\rec_userapp32.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\011.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\012.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\animation\01.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\animation\02.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\animation\03.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\animation\04.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\animation\05.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\animation\06.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\animation\07.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\animation\08.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\animation\09.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\check.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\damage1.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\damage2.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\damage3.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\damage4.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\damage5.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\damage6.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\error.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\error_large.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\Fix.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\Fix_over.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\junk.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\malware.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\md5.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\privacy.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\process-animation copy.gif
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\process-animation.gif
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\rating_h.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\rating_h_scan.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\rating_l.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\rating_l_scan.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\rating_m.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\rating_m_scan.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\rating_mh.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\rating_mh_scan.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\rating_ml.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\rating_ml_scan.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\registry.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\security_high.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\security_low.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Scan\warning.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Tabs\overview.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Tabs\restore.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Tabs\scan.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Tabs\settings.png
c:\program files\PC Utility Kit\PC Utility Kit\Images\Tabs\tools.png
c:\program files\PC Utility Kit\PC Utility Kit\LiteUnzip.dll
c:\program files\PC Utility Kit\PC Utility Kit\LiteZip.dll
c:\program files\PC Utility Kit\PC Utility Kit\LogSettings.xml
c:\program files\PC Utility Kit\PC Utility Kit\MyResources.dll
c:\program files\PC Utility Kit\PC Utility Kit\pcutilitykit.exe
c:\program files\PC Utility Kit\PC Utility Kit\privacy.db
c:\program files\PC Utility Kit\PC Utility Kit\RegHookSpecialist.pxt
c:\program files\PC Utility Kit\PC Utility Kit\SandBoxer.dll
c:\program files\PC Utility Kit\PC Utility Kit\settings.xml
c:\program files\PC Utility Kit\PC Utility Kit\sqlite3.dll
c:\program files\PC Utility Kit\PC Utility Kit\tfn.xml
c:\program files\PC Utility Kit\PC Utility Kit\uninstall.exe
c:\program files\PC Utility Kit\PC Utility Kit\UNS.xml
c:\program files\PC Utility Kit\PC Utility Kit\Utility.pxt
c:\program files\PC Utility Kit\PC Utility Kit\whitelist.dat
c:\windows\system32\rsvpspc.dll
c:\windows\Tasks\PC Utility Kit Registration3.job
c:\windows\Tasks\PC Utility Kit Update3.job
c:\windows\Tasks\PC Utility Kit.job
c:\windows\Tasks\Zblyc.job
.
.
((((((((((((((((((((((((( Files Created from 2012-11-17 to 2012-12-17 )))))))))))))))))))))))))))))))
.
.
2012-12-17 17:15 . 2012-12-17 17:34 -------- d-----w- C:\32788R22FWJFW
2012-12-16 23:25 . 2012-12-16 23:25 -------- d-----w- c:\windows\LastGood
2012-12-16 18:08 . 2012-12-16 18:08 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2012-12-16 18:08 . 2012-12-16 18:08 -------- d-----w- c:\program files\McAfee Security Scan
2012-12-16 18:07 . 2012-09-25 05:16 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-12-15 14:43 . 2012-12-15 14:43 -------- d-----w- c:\program files\ESET
2012-11-23 17:48 . 2012-12-12 13:31 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-11-22 18:35 . 2012-11-22 18:35 -------- d-----w- c:\documents and settings\Jim\Local Settings\Application Data\Flickr
2012-11-22 18:35 . 2012-11-22 18:35 -------- d-----w- c:\documents and settings\Jim\Application Data\Flickr
2012-11-19 14:16 . 2012-11-19 14:17 -------- d-----w- c:\program files\Common Files\Adobe
2012-11-19 13:15 . 2012-11-19 13:15 -------- d-----w- c:\windows\system32\wbem\Repository
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-11 20:45 . 2012-08-18 12:06 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-11 20:45 . 2011-07-23 17:03 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-11 20:45 . 2012-09-21 07:45 16363960 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-11-13 01:25 . 2008-04-14 07:00 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-11-06 00:41 . 2008-04-14 11:39 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-11-02 02:02 . 2008-04-14 11:41 375296 ----a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:17 . 2008-04-14 11:42 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-11-01 12:17 . 2008-04-14 11:42 916992 ----a-w- c:\windows\system32\wininet.dll
2012-11-01 12:17 . 2008-04-14 11:41 43520 ------w- c:\windows\system32\licmgr10.dll
2012-11-01 00:35 . 2008-04-14 06:07 385024 ------w- c:\windows\system32\html.iec
2012-10-28 05:01 . 2012-10-28 05:02 4588344 ----a-w- c:\windows\uninst.exe
2012-10-18 23:24 . 2012-10-18 23:22 32072 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2012-10-02 18:04 . 2008-04-14 11:42 58368 ----a-w- c:\windows\system32\synceng.dll
2012-09-30 01:54 . 2012-05-02 09:28 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-20 10:43 . 2012-08-18 11:27 821736 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-09-20 10:43 . 2010-09-21 00:07 746984 ----a-w- c:\windows\system32\deployJava1.dll
2010-03-29 23:40 . 2010-03-29 23:40 100256 ----a-w- c:\program files\Common Files\LinkInstaller.exe
2012-12-05 01:44 . 2012-12-05 01:44 262112 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Gadwin PrintScreen"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2008-12-09 495616]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-12-29 620376]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-11-11 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-09-20 19523616]
"D-Link AirPremier AG DWL-AG530 Utility"="c:\program files\D-Link\AirPremier AG DWL-AG530 Utility\AirPMCFG.exe" [2007-07-13 1720320]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-09-20 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-09-20 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-09-20 142360]
"ThreatFire"="c:\program files\ThreatFire\TFTray.exe" [2010-01-14 378128]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-07 1848648]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-12-12 722256]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2012-06-22 296056]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-24 926896]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.1.121\SSScheduler.exe [2010-9-3 255536]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [9/20/2010 5:36 PM 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [9/20/2010 5:36 PM 59664]
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [9/20/2010 4:44 PM 11448]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [12/14/2012 5:19 PM 399432]
R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service --> c:\program files\ThreatFire\TFService.exe service [?]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [9/20/2010 5:36 PM 33552]
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [1/21/2012 11:55 AM 497496]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [5/2/2012 3:28 AM 676936]
S2 RadioRage_4jService;RadioRageService;c:\progra~1\RADIOR~2\bar\1.bin\4jbarsvc.exe --> c:\progra~1\RADIOR~2\bar\1.bin\4jbarsvc.exe [?]
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [9/20/2010 5:22 PM 547744]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [9/20/2010 4:24 PM 1691480]
S3 jswimd;jswimd Service;c:\windows\system32\DRIVERS\jswimd.sys --> c:\windows\system32\DRIVERS\jswimd.sys [?]
S3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [10/18/2012 5:22 PM 32072]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5/2/2012 3:28 AM 22856]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.1.121\McCHSvc.exe [9/3/2010 12:45 AM 227232]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - HTTPFILTER
*NewlyCreated* - MPKSLDB60BF7D
*Deregistered* - MpKsldb60bf7d
.
Contents of the 'Scheduled Tasks' folder
.
2012-12-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-18 20:45]
.
2012-12-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-11-06 14:15]
.
2012-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-11-06 14:15]
.
2012-12-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1343024091-527237240-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-04-30 23:21]
.
2012-12-11 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1343024091-527237240-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-04-30 23:21]
.
2012-12-17 c:\windows\Tasks\User_Feed_Synchronization-{3F21ED5A-86A3-46A6-BBC9-B7635D4981C9}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 10:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
TCP: DhcpNameServer = 64.71.219.3 64.71.208.7
FF - ProfilePath - c:\documents and settings\Jim\Application Data\Mozilla\Firefox\Profiles\gof2v5bh.default\
FF - ExtSQL: 2012-10-30 10:55; ffxtlbr@babylon.com; c:\program files\Mozilla Firefox\extensions\ffxtlbr@babylon.com
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
AddRemove-{106DADAD-B062-4de5-8D1F-3FD2AD195E49} - c:\program files\PC Utility Kit\PC Utility Kit\uninstall.exe
AddRemove-{79A765E1-C399-405B-85AF-466F52E918B0} - c:\program files\Ask.com\Updater\Updater.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-12-17 11:57
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ThreatFire]
"AlternateImagePath"=""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(668)
c:\program files\ThreatFire\TFWAH.dll
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
.
- - - - - - - > 'lsass.exe'(724)
c:\program files\ThreatFire\TFWAH.dll
.
Completion time: 2012-12-17 12:03:15
ComboFix-quarantined-files.txt 2012-12-17 18:03
ComboFix2.txt 2012-12-16 22:02
ComboFix3.txt 2012-11-16 12:56
ComboFix4.txt 2012-11-09 14:07
ComboFix5.txt 2012-12-17 17:34
.
Pre-Run: 214,611,525,632 bytes free
Post-Run: 214,679,851,008 bytes free
.
- - End Of File - - CC3EA2D8531801B41846845C9EBE8F33
Combofix and CFScript merged and ran with no problems.
I had to totally remove Micro Security Essentials to turn it off. I couldn't find any other way to do it. Will reload now as well as opening what's currenyly installed.
Thanks again, I envy your knowledge.