ComboFix 09-10-08.04 - Nadiah 10/10/2009 4:35.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1256.966.1025.18.1976.805 [GMT 3:00]
Running from: c:\users\Nadiah\Documents\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1734433746-357569766-3798666168-500
c:\program files\Hewlett-Packard\IAM\bin\brand.dll
c:\windows\Installer\58151090.msi
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
.
((((((((((((((((((((((((( Files Created from 2009-09-10 to 2009-10-10 )))))))))))))))))))))))))))))))
.
2009-10-10 01:47 . 2009-10-10 01:51 -------- d-----w- c:\users\Nadiah\AppData\Local\temp
2009-10-07 11:34 . 2009-10-07 11:34 -------- d-----w- c:\program files\Trend Micro
2009-10-03 06:12 . 2009-10-01 07:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-02 00:02 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-02 00:02 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-02 00:02 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-02 00:02 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-02 00:02 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-02 00:02 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-02 00:02 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-02 00:02 . 2009-08-06 16:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-02 00:02 . 2009-08-06 15:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-09-29 13:51 . 2009-10-06 20:06 -------- d-----w- c:\programdata\Messenger Plus!
2009-09-29 13:46 . 2009-10-09 17:57 -------- d-----w- c:\users\Nadiah\Tracing
2009-09-29 11:57 . 2009-09-29 11:57 -------- d-----w- c:\users\Nadiah\AppData\Local\Apps
2009-09-25 05:51 . 2009-09-25 05:59 -------- d-----w- c:\program files\Quick Screen Recorder
2009-09-18 16:05 . 2009-09-18 16:06 -------- d-----w- c:\windows\system32\ca-ES
2009-09-18 16:05 . 2009-09-18 16:06 -------- d-----w- c:\windows\system32\eu-ES
2009-09-18 16:05 . 2009-09-18 16:06 -------- d-----w- c:\windows\system32\vi-VN
2009-09-18 06:58 . 2009-09-18 07:01 -------- dcsh--w- c:\program files\Common Files\WindowsLiveInstaller
2009-09-18 06:57 . 2009-09-18 06:57 -------- d-----w- c:\program files\Circle Devlopement
2009-09-18 06:39 . 2009-09-29 12:00 -------- d-----w- c:\program files\Messenger Plus! Live
2009-09-16 18:14 . 2009-09-16 18:14 -------- d-----w- c:\windows\system32\EventProviders
2009-09-16 17:59 . 2009-09-16 18:01 -------- d-----w- c:\users\Nadiah\AppData\Roaming\Windows Live Writer
2009-09-16 17:59 . 2009-09-16 17:59 -------- d-----w- c:\users\Nadiah\AppData\Local\Windows Live Writer
2009-09-16 17:53 . 2009-09-16 17:53 -------- dc----w- c:\windows\system32\DRVSTORE
2009-09-16 17:53 . 2009-08-05 19:48 54632 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2009-09-16 17:52 . 2009-09-16 17:52 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-09-16 17:51 . 2009-09-18 17:41 -------- d-----w- c:\program files\Windows Live
2009-09-16 17:49 . 2009-09-16 17:49 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-16 16:31 . 2009-09-18 06:39 -------- d-----w- c:\program files\Circle Developemen
2009-09-16 07:12 . 2009-04-11 06:28 29184 ----a-w- c:\windows\system32\wsepno.dll
2009-09-16 07:11 . 2009-04-11 06:28 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll
2009-09-16 07:11 . 2009-04-11 06:28 744448 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2009-09-16 07:11 . 2009-04-11 06:28 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2009-09-16 07:11 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
2009-09-16 07:11 . 2009-04-11 06:28 189440 ----a-w- c:\windows\system32\wbem\mofd.dll
2009-09-16 07:11 . 2009-04-11 06:28 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-09-16 07:11 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\esscli.dll
2009-09-16 07:11 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll
2009-09-16 07:11 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll
2009-09-16 07:11 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2009-09-16 07:11 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-09-16 02:58 . 2009-09-16 02:58 -------- d-----w- c:\program files\Microsoft
2009-09-15 20:06 . 2009-09-15 20:25 -------- d-----w- c:\program files\Happy Karaoke
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-10 01:49 . 2008-09-29 16:13 -------- d-----w- c:\programdata\hpqLog
2009-10-10 01:48 . 2009-05-02 19:19 876576 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-10 01:48 . 2009-05-02 19:19 6375968 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-10 01:48 . 2009-05-02 19:19 52988 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-10 01:48 . 2009-05-02 19:19 5124 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-10 01:48 . 2009-04-21 20:28 4855 ----a-w- c:\windows\bthservsdp.dat
2009-10-10 01:36 . 2009-05-02 19:19 -------- d-----w- c:\programdata\Kaspersky Lab
2009-10-09 17:47 . 2009-10-09 17:47 -------- d-----w- c:\program files\FairStars Audio Converter
2009-09-22 12:55 . 2009-04-21 20:08 207928 ----a-w- c:\users\Nadiah\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-22 12:43 . 2009-05-02 19:20 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-09-22 12:43 . 2009-05-02 19:20 107547 ----a-w- c:\windows\system32\drivers\klin.dat
2009-09-22 08:06 . 2009-05-03 09:21 72886 ----a-w- c:\windows\system32\perfh001.dat
2009-09-22 08:06 . 2009-05-03 09:21 23392 ----a-w- c:\windows\system32\perfc001.dat
2009-09-18 17:09 . 2009-09-09 05:03 -------- d-----w- c:\programdata\WLInstaller
2009-09-18 16:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-09-18 16:06 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-18 16:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-09-18 16:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-09-18 16:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-09-18 16:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-09-18 16:06 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-09-09 06:20 . 2009-09-09 06:20 -------- d-----w- c:\program files\Crcle Developement
2009-09-09 06:16 . 2009-09-09 06:16 -------- d-----w- c:\program files\Windows Installer Clean Up
2009-09-09 06:15 . 2009-09-09 06:15 -------- d-----w- c:\program files\MSECACHE
2009-09-09 05:41 . 2008-09-29 16:50 -------- d-----w- c:\programdata\Microsoft Help
2009-08-29 02:20 . 2009-07-10 21:28 -------- d-----w- c:\program files\Java
2009-08-29 00:27 . 2009-09-03 01:08 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-03 01:08 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-14 16:27 . 2009-09-09 04:28 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 15:53 . 2009-09-09 04:28 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49 . 2009-09-09 04:28 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49 . 2009-09-09 04:28 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49 . 2009-09-09 04:28 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49 . 2009-09-09 04:28 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49 . 2009-09-09 04:28 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49 . 2009-09-09 04:28 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49 . 2009-09-09 04:28 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:48 . 2009-09-09 04:28 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48 . 2009-09-09 04:28 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-10 07:58 . 2009-08-10 07:58 680 ----a-w- c:\users\Nadiah\AppData\Local\d3d9caps.dat
2009-07-26 13:44 . 2009-07-26 13:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-25 02:23 . 2009-05-02 19:00 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-21 21:52 . 2009-07-29 07:46 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 07:46 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 07:46 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 07:46 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-12 18:59 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-15 12:40 . 2009-08-12 18:58 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-15 12:39 . 2009-08-12 18:58 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-15 12:39 . 2009-08-12 18:58 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-15 12:39 . 2009-08-12 18:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2008-09-29 16:21 . 2008-09-29 16:21 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cast one"="c:\programdata\InsideCityCity.ipz5s" [X]
"style cool 2 city"="c:\programdata\log warn 1.ryk8d" [X]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-03-18 2289664]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-06-20 178712]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-27 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-27 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-27 145944]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2007-05-15 293168]
"PTHOSTTR"="c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE" [2008-07-09 238896]
"CognizanceTS"="c:\progra~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2008-06-18 24848]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2008-05-12 318488]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-27 1045800]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"WatchDog"="c:\program files\InterVideo\DVD Check\DVDCheck.exe" [2008-05-24 197904]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-23 198160]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-07-21 208616]
"pdfFactory Pro Dispatcher v3"="c:\windows\system32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2006-12-10 512000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-04-04 1314816]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-4-29 113664]
DVD Check.lnk - c:\program files\InterVideo\DVD Check\DVDCheck.exe [2008-9-29 197904]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-1-14 525664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\APSHook.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli ASWLNPkg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):43,40,62,f9,7a,38,ca,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{B2CF1363-A77B-4A64-8C8F-06C3BC61DB57}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{3558F897-0F34-4855-9734-E9D1A9CCC26C}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{A53FE484-FEAA-477F-BAFD-69481B627BE8}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [29/01/08 06:29 م 33808]
R0 SbAlg;SbAlg;c:\windows\System32\drivers\SbAlg.sys [12/07/08 12:50 ص 51376]
R0 SbFsLock;SbFsLock;c:\windows\System32\drivers\SbFsLock.sys [12/07/08 12:50 ص 12928]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [09/07/08 06:28 م 20496]
R1 RsvLock;RsvLock;c:\windows\System32\drivers\rsvlock.sys [12/07/08 12:50 ص 12496]
R2 accoca;ActivClient Middleware Service;c:\program files\ActivIdentity\ActivClient\accoca.exe [16/05/07 02:08 ص 182576]
R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Cognizance [21/01/08 05:23 ص 21504]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [21/01/08 05:23 ص 21504]
R2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [12/06/08 10:21 م 1164536]
R2 HP ProtectTools Service;HP ProtectTools Service;c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe [09/07/08 04:18 ص 19968]
R2 HpFkCryptService;Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [12/07/08 12:49 ص 256512]
R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [07/04/08 09:13 م 24936]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [29/09/08 07:26 م 576024]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\System32\drivers\ATSwpWDF.sys [13/06/08 12:40 ص 477696]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\System32\drivers\IntcHdmi.sys [28/06/08 12:35 ص 113664]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\System32\drivers\klfltdev.sys [13/03/08 07:02 م 26640]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [17/11/08 03:40 م 3668480]
S2 0248781240344905mcinstcleanup;McAfee Application Installer Cleanup (0248781240344905);c:\users\Nadiah\AppData\Local\Temp\024878~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\users\Nadiah\AppData\Local\Temp\024878~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S2 gupdate1ca05b457c7fadb;خدمة تحديث Google (gupdate1ca05b457c7fadb);c:\program files\Google\Update\GoogleUpdate.exe [16/07/09 04:25 ص 133104]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [21/01/08 05:23 ص 179712]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [16/09/09 08:53 م 54632]
S3 fsssvc;خدمة أمان العائلة في Windows Live;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/09 10:48 م 704864]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [08/04/08 03:12 م 1112560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker ASChannel
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-10-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-16 01:25]
2009-10-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-16 01:25]
2009-09-23 c:\windows\Tasks\HPCeeScheduleForNadiah.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2008-09-29 22:07]
2009-10-10 c:\windows\Tasks\User_Feed_Synchronization-{730DDD56-1C94-4B2E-8B31-13C8541D5E98}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://alharbi4040.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=all&pf=cmnb
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Save Flash with Flash Catcher - c:\program files\Common Files\Justdo\IECatcher.DLL/FlashCatcher.htm
DPF: Microsoft XML Parser for Java -
DPF: {B7FDB0C3-4724-46D2-B8DB-6FA1DC63F7CA} - hxxp://174.37.178.26:1999/ReadUid.CAB
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Uniblue RegistryBooster 2 - c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel
AddRemove-Ev0 - c:\program files\MSN Messenger\uninstallEv0.exe
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(736)
c:\program files\Hewlett-Packard\IAM\bin\ASWLNPkg.dll
c:\program files\Hewlett-Packard\IAM\bin\ItMsg.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\windows\System32\AEADISRV.EXE
c:\windows\System32\agrsmsvc.exe
c:\windows\System32\Crypserv.exe
c:\program files\ActivIdentity\ActivClient\acevents.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Hewlett-Packard\IAM\Bin\asghost.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
.
**************************************************************************
.
Completion time: 2009-10-10 4:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-10 01:56
Pre-Run: 171,831,537,664 bytes free
Post-Run: 171,577,860,096 bytes free
271 --- E O F --- 2009-10-05 14:28