ComboFix 09-01-05.05 - naneee88 2009-07-25 22:56:10.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1014.86 [GMT 10:00]
Running from: c:\users\naneee88\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
AV: Norton Internet Security *On-access scanning enabled* (Outdated)
FW: Norton Internet Security *enabled*
FW: Kaspersky Internet Security *disabled*
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2009-06-25 to 2009-07-25 )))))))))))))))))))))))))))))))
.
2009-07-23 15:00 . 2009-07-23 15:00 <DIR> d-------- c:\users\naneee88\AppData\Roaming\IObit
2009-07-20 20:27 . 2009-07-20 20:27 <DIR> d-------- c:\users\naneee88\AppData\Roaming\Ahead
2009-07-20 20:19 . 2009-07-20 20:19 <DIR> d-------- c:\program files\Nero
2009-07-20 20:19 . 2009-07-20 20:19 <DIR> d-------- c:\program files\Common Files\Ahead
2009-07-15 22:21 . 2009-07-15 22:21 <DIR> d-------- c:\users\naneee88\AppData\Roaming\Nokia Multimedia Player
2009-07-15 22:01 . 2009-07-15 22:22 <DIR> d-------- c:\users\naneee88\AppData\Roaming\Nokia
2009-07-15 22:01 . 2009-07-15 22:01 <DIR> d-------- c:\users\naneee88\AppData\Roaming\Datalayer
2009-07-15 21:58 . 2009-07-19 15:28 <DIR> d-------- c:\users\naneee88\Phone Browser
2009-07-15 21:22 . 2009-07-15 21:22 <DIR> d-------- c:\program files\Common Files\Nokia
2009-07-15 21:21 . 2009-07-15 21:24 <DIR> d-------- c:\users\naneee88\AppData\Roaming\PC Suite
2009-07-15 21:21 . 2009-07-15 21:21 <DIR> d-------- c:\users\All Users\PC Suite
2009-07-15 21:21 . 2009-07-15 21:21 <DIR> d-------- c:\programdata\PC Suite
2009-07-15 21:21 . 2009-07-15 21:22 <DIR> d-------- c:\program files\Common Files\PCSuite
2009-07-15 21:20 . 2009-07-15 21:22 <DIR> d-------- c:\program files\Nokia
2009-07-15 21:18 . 2009-07-15 21:18 <DIR> d-------- c:\users\All Users\Downloaded Installations
2009-07-15 21:18 . 2009-07-15 21:18 <DIR> d-------- c:\programdata\Downloaded Installations
2009-07-15 20:46 . 2009-06-15 22:52 289,792 --a------ c:\windows\System32\atmfd.dll
2009-07-15 20:46 . 2009-06-16 01:24 156,672 --a------ c:\windows\System32\t2embed.dll
2009-07-15 20:46 . 2009-06-16 01:20 72,704 --a------ c:\windows\System32\fontsub.dll
2009-07-15 20:46 . 2009-06-16 01:20 10,240 --a------ c:\windows\System32\dciman32.dll
2009-07-05 13:49 . 2009-07-05 14:47 105,395 --a------ c:\windows\System32\drivers\klin.dat
2009-07-05 13:49 . 2009-07-05 14:47 94,643 --a------ c:\windows\System32\drivers\klick.dat
2009-07-05 13:46 . 2009-07-05 13:46 <DIR> d-------- c:\program files\Kaspersky Lab
2009-07-05 13:46 . 2009-07-25 22:07 3,885,088 --ahs---- c:\windows\System32\drivers\fidbox.dat
2009-07-05 13:46 . 2009-07-25 22:07 598,048 --ahs---- c:\windows\System32\drivers\fidbox2.dat
2009-07-05 13:46 . 2009-07-25 22:07 34,576 --ahs---- c:\windows\System32\drivers\fidbox.idx
2009-07-05 13:46 . 2009-07-25 22:07 4,172 --ahs---- c:\windows\System32\drivers\fidbox2.idx
2009-07-04 23:49 . 2009-07-24 10:57 <DIR> d-------- c:\program files\Common Files\delet
2009-07-04 23:21 . 2009-07-04 23:21 <DIR> d-------- c:\program files\Alfa Autorun Killer 2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-25 12:49 --------- d-----w c:\programdata\Kaspersky Lab
2009-07-23 04:50 --------- d-----w c:\program files\Microsoft Silverlight
2009-07-17 03:44 737,280 ----a-w c:\windows\iun6002.exe
2009-07-17 03:44 --------- d-----w c:\program files\Athan
2009-07-16 01:18 --------- d-----w c:\program files\Windows Mail
2009-07-16 01:17 --------- d-----w c:\programdata\Microsoft Help
2009-07-05 04:47 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-07-04 12:44 --------- d-----w c:\programdata\Avira
2009-06-17 05:58 --------- d-----w c:\program files\Microsoft Works
2009-05-09 05:50 915,456 ----a-w c:\windows\System32\wininet.dll
2009-05-09 05:34 71,680 ----a-w c:\windows\System32\iesetup.dll
2009-04-30 12:37 428,544 ----a-w c:\windows\System32\EncDec.dll
2009-04-30 12:37 293,376 ----a-w c:\windows\System32\psisdecd.dll
2009-04-04 05:08 174 --sha-w c:\program files\desktop.ini
2008-08-31 03:20 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-08-31 03:20 56 ---ha-w c:\programdata\ezsidmv.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Sidebar"="c:\program files\windows sidebar\sidebar.exe" [2008-01-19 1233920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-20 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-20 154136]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-20 137752]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-06-10 118784]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-07-05 201992]
"Athan"="c:\program files\Athan\Athan.exe" [2009-05-01 1130496]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-08-15 14:05 98304 c:\windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll,c:\progra~1\KASPER~1\KASPER~1\adialhk.dll,c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\program files\Common Files\Sony Shared\VideoLib\sonydv.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Unwired Launchpad.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Unwired Launchpad.lnk
backup=c:\windows\pss\Unwired Launchpad.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^naneee88^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Audio Filter.lnk]
path=c:\users\naneee88\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Audio Filter.lnk
backup=c:\windows\pss\Audio Filter.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^naneee88^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^UltimateZip Quick Start.lnk]
path=c:\users\naneee88\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\UltimateZip Quick Start.lnk
backup=c:\windows\pss\UltimateZip Quick Start.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2009-02-27 17:10 35696 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
--a------ 2007-06-10 10:12 118784 c:\program files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Athan]
--a------ 2009-05-01 20:09 1130496 c:\program files\Athan\Athan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
--a------ 2008-01-19 17:33 125952 c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2008-10-25 11:44 31072 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISBMgr.exe]
--a------ 2007-09-20 05:09 311296 c:\program files\Sony\ISB Utility\ISBMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeChat]
--a------ 2007-01-26 14:31 259440 c:\program files\Microsoft LifeChat\LifeChat.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileConnect]
--a------ 2008-07-04 11:52 2072576 c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2009-02-06 17:51 3885408 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 2006-04-26 08:29 237568 c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
--a------ 2006-04-11 17:52 1409024 c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 2008-01-19 17:33 1233920 c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-11-24 01:20 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{89EFB501-8F2C-4204-9854-6731656C6E2F}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{B48C881D-E139-4389-B101-06461DAF6502}"= Disabled:UDP:c:\program files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{3A04004D-892F-4CAB-BD86-B6F918C731EF}"= Disabled:TCP:c:\program files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{A6839A80-17B3-4C5C-922E-A1DB2C73B000}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{62F14C41-6086-4E01-86D4-38B04230A2BA}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{5C944FA1-3862-4CE9-9091-97932D0E4C98}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{180EF42A-17CB-4B5A-B9FD-45EF0FB6362F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{46190876-9E8D-45FF-B6E4-54DA1A3C553F}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{F98E8FF7-0B4D-46F0-9A8E-BE8C8F3F7BF0}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{BEAD5E0A-E470-423A-9100-3B9EDE022386}c:\\programdata\\kaspersky lab setup files\\kaspersky internet security 2009\\english\\setup.exe"= UDP:c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe:Kaspersky Internet Security 2009 Setup
"UDP Query User{F80B3413-0AEE-488C-AB54-CE06AD77183F}c:\\programdata\\kaspersky lab setup files\\kaspersky internet security 2009\\english\\setup.exe"= TCP:c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe:Kaspersky Internet Security 2009 Setup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [2008-01-29 33808]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [2008-03-26 20496]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\System32\drivers\klfltdev.sys [2008-03-13 26640]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [2007-12-28 75008]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [2007-12-28 43904]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\System32\drivers\SFEP.sys [2007-12-28 9344]
R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [2007-12-28 812544]
R4 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-11 30312]
R4 regi;regi;c:\windows\System32\drivers\regi.sys [2007-04-18 11032]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\System32\drivers\btwl2cap.sys [2007-12-28 28464]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [2009-03-08 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 ICScsiSV;Image Converter SCSI Service;c:\program files\Sony\Image Converter 3\ICScsiSV.exe [2008-01-20 75952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0d5754fa-b4f0-11dd-aab4-001a80a49f89}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL h:\resycled\boot.com e:
\shell\Open\command - h:\resycled\boot.com e:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{115e62fa-c428-11dd-9140-001e3d3d6bf7}]
\shell\AutoRun\command - sysinfo.exe
\shell\explore\command - sysinfo.exe
\shell\open\command - sysinfo.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1dcd97fb-1dc8-11dd-a8ae-001e3d3d6bf7}]
\shell\AutoRun\command - G:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1dcd9814-1dc8-11dd-a8ae-001e3d3d6bf7}]
\shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{248a71ae-1b8c-11de-b93d-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{248a71b0-1b8c-11de-b93d-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{248a71b7-1b8c-11de-b93d-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{248a71b9-1b8c-11de-b93d-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5baa20ea-74ff-11de-badb-f8faf1e4e711}]
\shell\AutoRun\command - J:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ab464239-17e8-11de-98bf-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ab464240-17e8-11de-98bf-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ab464243-17e8-11de-98bf-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc9d4881-1e45-11de-b597-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc9d4883-1e45-11de-b597-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc9d4885-1e45-11de-b597-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc9d488d-1e45-11de-b597-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc9d488f-1e45-11de-b597-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d64bb971-0935-11de-8677-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d64bb973-0935-11de-8677-001e3d3d6bf7}]
\shell\AutoRun\command - I:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d64bb9a8-0935-11de-8677-001e3d3d6bf7}]
\shell\AutoRun\command - L:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f55a73f2-5fdb-11dd-933b-001e3d3d6bf7}]
\shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f74939af-0869-11de-b937-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f74939b5-0869-11de-b937-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f74939d6-0869-11de-b937-001e3d3d6bf7}]
\shell\AutoRun\command - H:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f74939d8-0869-11de-b937-001e3d3d6bf7}]
\shell\AutoRun\command - I:\setup_vmc_lite.exe /checkApplicationPresence
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe685ab5-52ed-11dd-9a55-001e3d3d6bf7}]
\shell\AutoRun\command - G:\AutoRun.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-25 c:\windows\Tasks\User_Feed_Synchronization-{B578AF6D-8A72-4DF6-AB6F-C8C05BB6E987}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 21:31]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-CanonMyPrinter - c:\program files\Canon\MyPrinter\BJMyPrt.exe
MSConfigStartUp-CanonSolutionMenu - c:\program files\Canon\SolutionMenu\CNSLMAIN.exe
MSConfigStartUp-Yahoo Messengger - c:\windows\system32\scvshosts.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.latrobe.edu.au/
mStart Page = about:blank
IE: Add to Windows &Live Favorites -
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: {23A00904-F692-4F09-9402-3A5EE68D1BB0} = 202.124.76.98 202.124.68.130
.
.
------- File Associations -------
.
txtfile=c:\windows\notepad.exe %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-25 22:56:50
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1032)
c:\progra~1\KASPER~1\KASPER~1\adialhk.dll
c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
- - - - - - - > 'lsass.exe'(616)
c:\progra~1\KASPER~1\KASPER~1\adialhk.dll
c:\progra~1\KASPER~1\KASPER~1\kloehk.dll
- - - - - - - > 'Explorer.exe'(5488)
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\windows\system32\ConnAPI.DLL
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
.
Completion time: 2009-07-25 23:02:05
ComboFix-quarantined-files.txt 2009-07-25 13:01:47
Pre-Run: 81,095,413,760 bytes free
Post-Run: 81,043,320,832 bytes free
288 --- E O F --- 2009-07-24 06:46:45