Here we go.....
ComboFix 09-08-09.04 - Jack 11/08/2009 10:39.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1162 [GMT 1:00]
Running from: c:\users\Jack\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Kaspersky Anti-Virus *enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-07-11 to 2009-08-11 )))))))))))))))))))))))))))))))
.
2009-08-11 09:53 . 2009-08-11 09:53 -------- d-----w- c:\users\Jack\AppData\Local\temp
2009-08-11 09:53 . 2009-08-11 09:53 -------- d-----w- c:\users\User\AppData\Local\temp
2009-08-11 09:53 . 2009-08-11 09:53 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-08-11 09:53 . 2009-08-11 09:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-08-07 00:06 . 2009-08-07 00:06 -------- d-----w- c:\users\Jack\AppData\Roaming\CyberLink
2009-08-06 13:20 . 2009-08-06 13:20 -------- d-----w- C:\registry backup
2009-08-06 13:17 . 2009-08-06 13:17 -------- d-----w- c:\program files\CCleaner
2009-08-05 18:44 . 2009-08-05 19:30 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-08-05 18:44 . 2009-08-05 19:18 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-05 18:35 . 2009-07-03 14:49 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-08-05 15:36 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-05 15:30 . 2009-08-05 15:30 -------- dc-h--w- c:\programdata\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-05 15:30 . 2009-07-08 17:28 2920112 -c--a-w- c:\programdata\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
2009-08-05 15:30 . 2009-08-05 15:36 -------- d-----w- c:\programdata\Lavasoft
2009-08-05 15:30 . 2009-08-05 15:30 -------- d-----w- c:\program files\Lavasoft
2009-08-04 18:41 . 2009-08-04 18:41 -------- d-----w- c:\users\Jack\AppData\Roaming\Uniblue
2009-08-04 18:41 . 2009-06-29 04:36 2568260 -c----w- c:\programdata\{81D4BDA8-1F33-4633-B176-8A7E942ABDE1}\Uniblue RegistryBooster.exe
2009-08-04 18:40 . 2009-08-04 23:06 -------- dc-h--w- c:\programdata\{81D4BDA8-1F33-4633-B176-8A7E942ABDE1}
2009-08-04 18:10 . 2009-08-04 18:10 -------- d-----w- c:\users\Jack\AppData\Roaming\Malwarebytes
2009-08-04 18:10 . 2009-08-03 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-04 18:10 . 2009-08-04 18:10 -------- d-----w- c:\programdata\Malwarebytes
2009-08-04 18:09 . 2009-08-04 18:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-04 18:09 . 2009-08-03 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-04 17:15 . 2009-08-04 20:38 -------- d-----w- c:\programdata\NVIDIA
2009-08-04 16:43 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-08-04 16:43 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNativ e_v0300.dll
2009-08-04 16:43 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2009-08-04 16:43 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-08-04 16:43 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-08-04 16:43 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-08-04 16:43 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-08-04 16:21 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll
2009-08-04 16:21 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll
2009-08-04 16:21 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-08-04 16:20 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
2009-08-04 16:20 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
2009-08-02 18:48 . 2009-08-02 18:48 -------- d-----w- c:\users\User\AppData\Roaming\CyberLink
2009-07-31 16:32 . 2009-07-31 16:32 -------- d-----w- c:\users\User\AppData\Local\Adobe
2009-07-28 10:13 . 2008-05-27 05:17 34816 ----a-w- c:\windows\system32\msscb.dll
2009-07-28 09:32 . 2008-04-26 08:26 891448 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-07-27 22:06 . 2009-07-27 22:06 -------- d-----w- C:\PerfLogs
2009-07-27 10:34 . 2006-10-26 18:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2009-07-27 10:31 . 2009-07-27 10:31 -------- d-----w- c:\windows\PCHEALTH
2009-07-27 10:31 . 2009-07-27 10:31 -------- d-----w- c:\program files\Microsoft.NET
2009-07-27 10:29 . 2009-07-27 10:29 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-07-27 10:28 . 2009-07-27 10:28 -------- d-----w- c:\users\Jack\AppData\Local\Microsoft Help
2009-07-27 10:27 . 2009-07-27 10:35 -------- d-----w- c:\programdata\Microsoft Help
2009-07-27 10:26 . 2009-07-27 10:26 -------- d--h--r- C:\MSOCache
2009-07-27 09:35 . 2009-07-27 09:35 -------- d-----w- c:\program files\PowerISO
2009-07-26 23:01 . 2009-07-27 10:06 -------- d-----w- c:\users\Jack\AppData\Roaming\BitTorrent
2009-07-26 23:01 . 2009-07-26 23:01 -------- d-----w- c:\program files\BitTorrent
2009-07-26 21:55 . 2009-08-04 23:07 -------- d-----w- c:\users\Jack\AppData\Roaming\DivX
2009-07-26 21:54 . 2009-08-06 12:02 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-07-26 20:58 . 2009-07-26 23:00 -------- d-----w- c:\program files\BitLord
2009-07-26 20:23 . 2009-07-26 20:23 -------- d-----w- c:\users\Jack\AppData\Roaming\AdobeUM
2009-07-24 18:32 . 2009-07-24 18:32 -------- d-----w- c:\users\Jack\AppData\Roaming\Template
2009-07-24 17:03 . 2009-07-24 17:03 -------- d-----w- c:\program files\HarBal 1.5
2009-07-24 16:57 . 2009-07-24 16:57 -------- d-----w- c:\program files\Roger Nichols Digital, Inc
2009-07-24 16:47 . 2009-07-24 16:47 -------- d-----w- c:\program files\TC Native Bundle DX 2.02
2009-07-24 16:44 . 2009-07-24 16:44 -------- d-----w- c:\program files\PSP VintageWarmer
2009-07-24 16:43 . 2009-07-24 16:43 -------- d-----w- c:\program files\Common Files\iZotope
2009-07-24 16:43 . 2009-07-24 16:59 -------- d-----w- c:\program files\iZotope
2009-07-24 16:12 . 2003-03-18 17:04 765952 ----a-w- c:\windows\system32\msvcp71d.dll
2009-07-24 16:12 . 2003-03-18 17:03 544768 ----a-w- c:\windows\system32\msvcr71d.dll
2009-07-24 16:12 . 2009-07-24 16:36 -------- d-----w- c:\program files\Nomad Factory
2009-07-24 15:58 . 1999-12-17 09:13 86016 ----a-w- c:\windows\unvise32.exe
2009-07-24 15:58 . 2009-07-24 15:58 -------- d-----w- C:\Ohm Force
2009-07-24 13:55 . 2009-07-24 13:55 -------- d-----w- c:\program files\VirSyn Software Synthesizer
2009-07-24 13:54 . 2003-06-20 12:28 1777664 ----a-w- c:\windows\system32\gdiplus.dll
2009-07-24 13:41 . 2009-07-24 13:50 -------- d-----w- c:\users\Jack\AppData\Local\Native Instruments
2009-07-24 13:34 . 2009-07-24 13:45 -------- d-----w- c:\program files\Common Files\Native Instruments
2009-07-24 13:34 . 2009-07-24 13:44 -------- d-----w- c:\program files\Native Instruments
2009-07-24 13:28 . 2009-07-24 13:28 -------- d-----w- c:\program files\Steinberg
2009-07-24 13:19 . 2009-07-24 13:19 -------- d-----w- c:\program files\GFORCE_SOFTWARE
2009-07-24 13:05 . 2008-03-14 12:22 368640 ----a-w- c:\windows\system32\ReWire.dll
2009-07-24 13:05 . 2008-03-14 12:22 233472 ----a-w- c:\windows\system32\REX Shared Library.dll
2009-07-24 10:15 . 2008-01-19 07:37 351232 ----a-w- c:\windows\system32\WSDApi.dll
2009-07-24 10:14 . 2008-01-19 07:36 161792 ----a-w- c:\windows\system32\wbem\WMIsvc.dll
2009-07-24 10:13 . 2008-01-19 07:36 26624 ----a-w- c:\windows\system32\pcadm.dll
2009-07-24 10:12 . 2008-01-19 07:34 8192 ----a-w- c:\windows\system32\iscsied.dll
2009-07-24 10:11 . 2008-01-19 07:33 599552 ----a-w- c:\windows\system32\vsp1cln.exe
2009-07-24 10:11 . 2008-01-19 07:36 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll
2009-07-24 10:11 . 2008-01-19 07:36 742912 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2009-07-24 10:11 . 2008-01-19 07:36 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2009-07-24 10:11 . 2008-01-19 07:36 357888 ----a-w- c:\windows\system32\wbemcomn.dll
2009-07-24 10:11 . 2008-01-19 07:36 264704 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
2009-07-24 10:11 . 2008-01-19 07:34 191488 ----a-w- c:\windows\system32\wbem\mofd.dll
2009-07-24 10:11 . 2008-01-19 07:34 102400 ----a-w- c:\windows\system32\wbem\mofinstall.dll
2009-07-24 10:11 . 2008-01-19 07:34 263168 ----a-w- c:\windows\system32\wbem\esscli.dll
2009-07-24 10:11 . 2008-01-19 07:36 129536 ----a-w- c:\windows\system32\sqmapi.dll
2009-07-24 10:11 . 2008-01-19 07:36 704512 ----a-w- c:\windows\system32\SmiEngine.dll
2009-07-24 10:11 . 2008-01-19 07:36 139264 ----a-w- c:\windows\system32\SmiInstaller.dll
2009-07-24 10:10 . 2008-01-19 07:36 218624 ----a-w- c:\windows\system32\wdscore.dll
2009-07-24 10:10 . 2008-01-19 07:33 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2009-07-24 10:10 . 2008-01-19 07:34 246784 ----a-w- c:\windows\system32\drvstore.dll
2009-07-24 10:10 . 2008-01-19 07:35 35328 ----a-w- c:\windows\system32\mspatcha.dll
2009-07-24 10:10 . 2008-01-19 07:34 305152 ----a-w- c:\windows\system32\msdelta.dll
2009-07-24 10:10 . 2008-01-19 07:34 258560 ----a-w- c:\windows\system32\dpx.dll
2009-07-23 15:14 . 2009-07-23 15:14 -------- d-----w- C:\Temporary Conversions
2009-07-23 15:14 . 2009-07-23 15:14 -------- d-----w- C:\presets
2009-07-23 15:14 . 2009-07-23 15:14 -------- d-----w- C:\default
2009-07-23 15:13 . 2006-10-04 13:13 393216 ----a-w- c:\windows\system32\NI_IRC_1_2.dll
2009-07-23 15:13 . 2006-10-04 13:13 61440 ----a-w- c:\windows\system32\NI_DFD_1_5.dll
2009-07-23 15:13 . 2006-10-04 13:13 1870336 ----a-w- c:\windows\system32\bconvert.dll
2009-07-23 14:49 . 2009-07-28 10:45 724992 ----a-w- c:\windows\iun6002.exe
2009-07-23 14:48 . 2009-07-28 10:45 -------- d-----w- c:\program files\M-Audio USB Keyboard Device
2009-07-23 14:48 . 2009-07-23 14:48 82944 ----a-w- c:\windows\system32\usbkt1x1.dll
2009-07-23 14:48 . 2009-07-23 14:48 22304 ----a-w- c:\windows\system32\drivers\usbkt1x1.sys
2009-07-23 14:48 . 2009-07-23 14:48 13504 ----a-w- c:\windows\system32\drivers\uks11ldr.sys
2009-07-23 14:31 . 2009-07-26 20:23 -------- d-----w- c:\users\Jack\AppData\Local\Adobe
2009-07-23 14:25 . 2009-07-24 13:12 -------- d-----w- c:\program files\Ableton
2009-07-23 13:58 . 2009-07-23 13:58 -------- d-----w- c:\programdata\Ableton
2009-07-23 13:58 . 2009-07-24 13:05 -------- d-----w- c:\users\Jack\AppData\Roaming\Ableton
2009-07-23 13:22 . 2009-08-11 09:32 -------- d-----w- c:\users\Jack\AppData\Roaming\skypePM
2009-07-23 13:17 . 2009-08-11 09:47 -------- d-----w- c:\users\Jack\AppData\Roaming\Skype
2009-07-23 13:17 . 2009-07-23 13:17 -------- d-----w- c:\program files\Common Files\Skype
2009-07-23 13:17 . 2009-07-23 13:17 -------- d-----r- c:\program files\Skype
2009-07-23 13:17 . 2009-07-23 13:17 -------- d-----w- c:\programdata\Skype
2009-07-23 12:58 . 2009-07-23 12:58 -------- d-----w- C:\My tunes
2009-07-23 12:55 . 2009-07-28 17:46 -------- d-----w- C:\Music projects
2009-07-23 12:52 . 2009-07-26 21:50 -------- d-----w- c:\users\Jack\AppData\Local\Apple Computer
2009-07-23 12:52 . 2009-08-05 16:37 -------- d-----w- c:\users\Jack\AppData\Roaming\Apple Computer
2009-07-23 12:46 . 2009-07-23 12:46 -------- d-----w- c:\programdata\Apple
2009-07-23 12:45 . 2009-07-23 12:45 -------- d-----w- C:\Jacks Comps
2009-07-23 12:33 . 2009-07-23 12:37 -------- d-----w- C:\DJ tunes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-08-04 11:39 . 2007-11-08 14:11 -------- d-----w- c:\programdata\Gtek
2009-08-02 18:48 . 2007-11-08 14:09 -------- d-----w- c:\programdata\CyberLink
2009-07-27 22:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-07-27 22:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-07-27 22:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-07-27 22:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-07-27 22:08 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-27 22:07 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-07-27 22:07 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-07-27 22:06 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-07-27 14:11 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-07-27 14:11 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-07-27 13:46 . 2009-07-21 14:27 27240 ----a-w- c:\users\Jack\AppData\Roaming\nvModes.dat
2009-07-27 11:19 . 2009-07-22 10:29 117696 ----a-w- c:\users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-27 10:33 . 2007-11-08 14:11 -------- d-----w- c:\program files\Microsoft Works
2009-07-27 10:32 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2009-07-26 13:44 . 2009-07-22 10:35 27240 ----a-w- c:\users\User\AppData\Roaming\nvModes.dat
2009-07-24 18:32 . 2009-07-24 18:32 0 ----a-w- c:\users\Jack\AppData\Roaming\wklnhst.dat
2009-07-24 16:34 . 2007-11-08 13:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-23 13:22 . 2009-07-23 13:22 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-07-23 12:51 . 2009-07-23 12:51 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-23 12:51 . 2009-07-23 12:51 -------- d-----w- c:\program files\iTunes
2009-07-23 12:51 . 2009-07-23 12:51 -------- d-----w- c:\program files\iPod
2009-07-23 12:51 . 2009-07-23 12:46 -------- d-----w- c:\program files\Common Files\Apple
2009-07-23 12:51 . 2009-07-23 12:49 -------- d-----w- c:\programdata\Apple Computer
2009-07-23 12:50 . 2009-07-23 12:50 -------- d-----w- c:\program files\Bonjour
2009-07-23 12:50 . 2009-07-23 12:49 -------- d-----w- c:\program files\QuickTime
2009-07-23 12:48 . 2009-07-23 12:48 -------- d-----w- c:\program files\Apple Software Update
2009-07-22 10:29 . 2009-07-22 10:29 551424 ----a-w- c:\windows\system32\rpcss.dll
2009-07-21 21:52 . 2009-07-29 08:48 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 08:48 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 08:48 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 08:48 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-21 15:28 . 2007-11-08 14:09 -------- d-----w- c:\programdata\Dell
2009-07-21 15:15 . 2007-11-08 14:07 -------- d-----w- c:\programdata\McAfee
2009-07-21 15:14 . 2009-05-24 14:30 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
2009-07-21 14:54 . 2009-07-21 14:54 23 ----a-w- c:\windows\system32\drivers\adidsl.cfg
2009-07-20 19:30 . 2009-07-20 19:30 -------- d-sh--we c:\programdata\Templates
2009-07-20 19:30 . 2009-07-20 19:30 -------- d-sh--we c:\programdata\Start Menu
2009-07-20 19:30 . 2009-07-20 19:30 -------- d-sh--we c:\programdata\Favorites
2009-07-20 19:30 . 2009-07-20 19:30 -------- d-sh--we c:\programdata\Documents
2009-07-20 19:30 . 2009-07-20 19:30 -------- d-sh--we c:\programdata\Desktop
2009-06-04 15:59 . 2009-06-04 15:59 59976 ----a-w- c:\programdata\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2010 9.0.0.459\English\setup.exe
2009-05-25 04:21 . 2009-05-25 04:21 219664 ----a-w- c:\windows\system32\klogon.dll
2009-05-25 04:18 . 2009-05-25 04:18 27507 ----a-w- c:\windows\system32\drivers\klopp.dat
2009-05-16 19:59 . 2009-05-16 19:59 19472 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2009-05-15 17:50 . 2009-05-15 17:50 21008 ----a-w- c:\windows\system32\drivers\klim6.sys
2007-11-08 14:03 . 2007-11-08 14:03 76 --sha-r- c:\windows\CT4CET.bin
2007-11-08 21:43 . 2007-11-08 21:36 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-08-10_16.47.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-08 14:18 . 2009-08-10 23:08 36686 c:\windows\System32\WDI\ShutdownPerformanceDiagnos tics_SystemData.bin
+ 2006-11-02 13:05 . 2009-08-11 09:32 65008 c:\windows\System32\WDI\BootPerformanceDiagnostics _SystemData.bin
+ 2009-07-22 11:08 . 2009-08-10 19:44 4288 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1270223739-246048384-1330680-1001_UserData.bin
- 2009-07-20 19:38 . 2009-08-10 16:30 6612 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1270223739-246048384-1330680-1000_UserData.bin
+ 2009-07-20 19:38 . 2009-08-11 09:32 6612 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1270223739-246048384-1330680-1000_UserData.bin
+ 2009-08-10 23:06 . 2009-08-11 09:29 2048 c:\windows\ServiceProfiles\LocalService\AppData\Lo cal\lastalive1.dat
- 2009-08-10 16:28 . 2009-08-10 16:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Lo cal\lastalive1.dat
- 2009-08-10 16:28 . 2009-08-10 16:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Lo cal\lastalive0.dat
+ 2009-08-10 23:06 . 2009-08-11 09:29 2048 c:\windows\ServiceProfiles\LocalService\AppData\Lo cal\lastalive0.dat
+ 2006-11-02 10:33 . 2009-08-11 09:38 600378 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-08-10 16:35 600378 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-08-11 09:38 105852 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-08-10 16:35 105852 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-07-16 25604904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-04-18 159744]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-08-29 36864]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-05-25 303376]
"M-Audio Taskbar Icon"="c:\windows\System32\M-AudioTaskBarIcon.exe" [2008-05-15 356864]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-04 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2007-10-04 81920]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2007-10-04 86016]
"PMX Daemon"="ICO.EXE" - c:\windows\System32\ico.exe [2006-11-08 49152]
"SigmatelSysTrayApp"="sttray.exe" - c:\windows\sttray.exe [2007-03-06 303104]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2009-7-21 962661]
QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D 39BF83DC4.exe [2007-11-8 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkb d.dll c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\session manager]
BootExecute REG_MULTI_SZ lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Wind ows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Wind ows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\FirewallRules]
"{6B4B9555-FE26-4E74-846A-FBD608422E55}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{D5CED3A8-42FA-46F6-AC64-836745C6A4D8}"= c:\program files\Dell\MediaDirect\PowerCinema.exe:CyberLink PowerCinema
"{116BE280-3797-446A-872B-94325513577E}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{0C6D2F67-8F74-4770-B487-48B34BA8BF0E}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine. exe:Cyberlink Media Server Browser Engine
"{99A7BF1A-AF39-4718-9764-8A7CC7071C6D}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe: CyberLink Media Server
"{465EB43C-7117-4BF1-9804-F829120A8CBA}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3B86B3C7-22FE-4266-95E4-434F7D4177F8}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1C7CE643-E25F-42BF-80BF-84607C6CBD7D}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{617A6B5A-F54A-4F51-8B44-95863E5C4A74}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{6E2D7E83-6871-4C49-BD8B-EC7A66954511}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{FDC865EF-03B6-49AE-9897-9BACAFD7F58A}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{BBE6CD11-B129-4277-960B-40B81C8D27FC}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"{739F3B4B-F22D-4967-81FC-AF6F5F4BEEFB}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{A4901222-4EAC-4C54-A521-3E3A843D9F0D}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{D3681411-F12D-433D-8650-8F430E12F460}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{CFC37CF3-A25D-4A55-8819-104EB1F7382F}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{BC3EFC41-B69C-4896-BC52-546BA13C9923}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{1A9CBD04-0ADD-4A9B-ADC4-B2CC86C2E9AB}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B0FEFB94-241D-49F3-BA16-CCCEABBE19D5}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [15/12/2008 20:41 33808]
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [05/08/2009 16:36 64160]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [15/05/2009 18:50 21008]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [05/08/2009 19:44 1153368]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\System32\drivers\klmouflt.sys [16/05/2009 20:59 19472]
R3 MAUSBFTP;Service for M-Audio Fast Track Pro (WDM);c:\windows\System32\drivers\mausb.sys [23/07/2009 11:20 143624]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [10/10/2007 17:03 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [08/11/2007 22:43 7424]
R3 USBKT1X1;M-Audio USB Keystation;c:\windows\System32\drivers\usbkt1x1.sy s [23/07/2009 15:48 22304]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [03/07/2009 15:49 1029456]
S3 UKS11LDR;M-Audio USB Keystation Loader;c:\windows\System32\drivers\uks11ldr.sys [23/07/2009 15:48 13504]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSe tup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
2009-08-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1270223739-246048384-1330680-1000Core.job
- c:\users\Jack\AppData\Local\Google\Update\GoogleUp date.exe [2009-07-21 15:31]
2009-08-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1270223739-246048384-1330680-1000UA.job
- c:\users\Jack\AppData\Local\Google\Update\GoogleUp date.exe [2009-07-21 15:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www1.euro.dell.com/content/default.aspx?c=eu&l=en&s=gen
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-08-11 10:53
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-08-11 11:01
ComboFix-quarantined-files.txt 2009-08-11 10:00
ComboFix2.txt 2009-08-10 16:54
Pre-Run: 54,537,420,800 bytes free
Post-Run: 60,270,944,256 bytes free
321 --- E O F --- 2009-08-11 09:37
Hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:08:55, on 11/08/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Windows\System32\ico.exe
C:\Windows\System32\M-AudioTaskBarIcon.exe
C:\Windows\sttray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
Dell EMEA
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
MSN.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe"
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\Windows\System32\M-AudioTaskBarIcon.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: QuickSet.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 6692 bytes
I got a error message when Hijackthis was running. It said:-
An unexpected error has occurred at procedure:
modRegistry_IniGetString(sFile=system.ini, sSection=boot,
sValue=Shell)
Error #5 - Invalid procedure call or argument
But then it ran anyway