ComboFix 09-07-24.01 - Timothy Hayes 07/25/2009 1:39.2.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2724 [GMT -7:00]
Running from: c:\documents and settings\Timothy Hayes\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Timothy Hayes\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FILE ::
"c:\windows\system32\drivers\kgpcpy.cfg"
"c:\windows\system32\drivers\kgpfr2.cfg"
"d:\fxdrv32.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\kgpcpy.cfg
c:\windows\system32\drivers\kgpfr2.cfg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FXDRV32
-------\Service_FXDrv32
((((((((((((((((((((((((( Files Created from 2009-06-25 to 2009-07-25 )))))))))))))))))))))))))))))))
.
2009-07-23 17:37 . 2009-07-23 17:37 -------- d-----w- c:\documents and settings\Timothy Hayes\Application Data\Malwarebytes
2009-07-23 17:37 . 2009-07-13 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-23 17:37 . 2009-07-23 17:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-23 17:37 . 2009-07-23 17:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-23 17:37 . 2009-07-13 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-23 11:03 . 2009-07-24 01:55 117760 ----a-w- c:\documents and settings\Timothy Hayes\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\ UIREPAIR.DLL
2009-07-23 11:02 . 2009-07-23 11:02 65024 ----a-r- c:\documents and settings\Timothy Hayes\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
2009-07-23 11:02 . 2009-07-23 11:02 18944 ----a-r- c:\documents and settings\Timothy Hayes\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
2009-07-23 11:02 . 2009-07-23 11:02 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-20 02:50 . 2009-06-28 16:32 353048 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgxch32.dll
2009-07-20 02:50 . 2009-07-09 15:04 3403032 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-07-20 02:50 . 2009-06-28 16:32 2301208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avguiadv.dll
2009-07-06 10:08 . 2009-02-07 18:38 -------- d-----w- c:\program files\Dungeon Keeper
2009-07-05 01:08 . 2009-07-05 01:08 -------- d-----w- c:\program files\AskBarDis
2009-07-05 01:08 . 2009-07-05 01:08 -------- d-----w- c:\program files\uTorrent
2009-07-05 01:08 . 2009-07-05 02:46 -------- d-----w- c:\documents and settings\Timothy Hayes\Application Data\uTorrent
2009-07-03 07:50 . 2009-07-03 07:50 -------- d-----w- c:\program files\CCleaner
2009-06-30 01:56 . 2009-07-01 06:53 -------- d-----w- c:\documents and settings\Timothy Hayes\Tracing
2009-06-30 01:54 . 2009-06-30 01:54 -------- d-----w- c:\program files\Microsoft
2009-06-30 01:54 . 2009-06-30 01:54 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-06-30 01:52 . 2009-06-30 01:52 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-07-25 08:45 . 2008-12-31 06:23 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-07-25 02:07 . 2008-08-27 19:37 -------- d-----w- c:\program files\QuickTime
2009-07-25 01:19 . 2007-12-20 20:18 -------- d-----w- c:\program files\City of Heroes
2009-07-23 23:35 . 2009-07-23 23:35 1408 ----a-w- c:\program files\amtffd.txt
2009-07-23 11:02 . 2008-02-06 07:40 -------- d-----w- c:\documents and settings\Timothy Hayes\Application Data\SUPERAntiSpyware.com
2009-07-23 11:02 . 2008-02-06 07:40 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-22 07:41 . 2008-01-07 08:28 -------- d-----w- c:\documents and settings\Timothy Hayes\Application Data\dvdcss
2009-07-22 05:01 . 2009-02-27 05:52 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-18 19:06 . 2008-12-05 07:22 -------- d-----w- c:\documents and settings\Timothy Hayes\Application Data\Skype
2009-07-15 10:02 . 2008-04-28 16:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-09 15:04 . 2009-01-06 08:42 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-05 18:48 . 2008-02-04 05:23 -------- d-----w- c:\documents and settings\Timothy Hayes\Application Data\BitTorrent
2009-07-05 00:58 . 2009-06-18 04:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-06-30 01:54 . 2008-01-13 23:11 -------- d-----w- c:\program files\Windows Live
2009-06-28 16:32 . 2009-01-29 16:39 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-28 16:32 . 2009-01-06 08:42 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-25 01:30 . 2009-06-25 01:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Free Labs
2009-06-25 01:28 . 2009-06-25 01:28 766 ----a-r- c:\documents and settings\Timothy Hayes\Application Data\Microsoft\Installer\{67DD11CB-7C27-4072-B970-B57755294B28}\_C3160024059FB0EDCFC673.exe
2009-06-25 01:28 . 2009-06-25 01:28 766 ----a-r- c:\documents and settings\Timothy Hayes\Application Data\Microsoft\Installer\{67DD11CB-7C27-4072-B970-B57755294B28}\_6FEFF9B68218417F98F549.exe
2009-06-25 01:28 . 2009-06-25 01:28 -------- d-----w- c:\program files\Free Labs
2009-06-24 23:39 . 2009-06-24 23:39 -------- d-----w- c:\program files\Web Macros
2009-06-24 23:39 . 2007-12-20 20:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-18 07:17 . 2007-12-26 02:31 -------- d-----w- c:\documents and settings\Timothy Hayes\Application Data\Yahoo!
2009-06-18 04:47 . 2009-06-18 04:47 262144 ----a-w- C:\ntuser.dat
2009-06-18 04:47 . 2007-12-20 20:31 -------- d-----w- c:\program files\Yahoo!
2009-06-18 04:47 . 2007-12-21 10:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-06-18 04:46 . 2009-06-18 04:46 18186048 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\msgup900_2162_us_v2.exe
2009-06-16 17:48 . 2007-12-30 02:21 -------- d-----w- c:\program files\AIM6
2009-06-16 17:48 . 2009-06-16 17:48 -------- d-----w- c:\program files\Viewpoint
2009-06-16 17:48 . 2007-12-30 02:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-16 17:47 . 2008-02-18 23:59 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2009-06-16 17:45 . 2008-12-31 06:23 -------- d-----w- c:\program files\STOPzilla!
2009-06-16 14:36 . 2003-04-15 13:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2003-04-15 13:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 07:19 . 2009-06-16 07:19 10134 ----a-r- c:\documents and settings\Timothy Hayes\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-16 07:19 . 2009-06-16 07:19 -------- d-----w- c:\program files\Microsoft WSE
2009-06-16 07:13 . 2008-06-23 22:56 -------- d-----w- c:\program files\Electronic Arts
2009-06-11 22:18 . 2009-05-05 23:18 -------- d-----w- c:\program files\Coupons
2009-06-11 20:24 . 2009-06-11 20:24 -------- d-----w- c:\program files\AGEIA Technologies
2009-06-11 20:19 . 2009-06-11 20:19 -------- d-----w- c:\program files\SystemRequirementsLab
2009-06-03 19:09 . 2005-08-30 04:02 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-28 21:16 . 2009-05-28 21:16 17408 ----a-r- c:\windows\system32\SZIO5.dll
2009-05-28 21:15 . 2009-05-28 21:15 294912 ----a-r- c:\windows\system32\SZBase5.dll
2009-05-28 21:14 . 2009-05-28 21:14 540672 ----a-r- c:\windows\system32\SZComp5.dll
2009-05-19 08:36 . 2009-06-16 17:47 97072 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\bsetutil.exe
2009-05-19 08:36 . 2009-06-16 17:47 2884832 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\vwpt.exe
2009-05-19 08:36 . 2009-06-16 17:47 28 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\unregister.bat
2009-05-19 08:36 . 2009-06-16 17:47 25 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\register.bat
2009-05-19 08:36 . 2009-06-16 17:47 1484856 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\toolbar.exe
2009-05-19 08:36 . 2009-06-16 17:47 142040 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\alsetup.exe
2009-05-19 08:36 . 2009-06-16 17:47 30512 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\Uninstaller.exe
2009-05-19 08:36 . 2009-06-16 17:47 111920 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\AOLSearch.dll
2009-05-12 21:13 . 2009-05-12 21:13 61328 ----a-r- c:\windows\system32\drivers\SZKG.sys
2009-05-07 15:32 . 2003-04-15 13:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 07:31 . 2009-05-01 07:31 1657376 ----a-w- c:\windows\system32\nwiz.exe
2009-05-01 07:31 . 2009-05-01 07:31 449056 ----a-w- c:\windows\system32\nvappbar.exe
2009-05-01 07:31 . 2009-05-01 07:31 436768 ----a-w- c:\windows\system32\keystone.exe
2009-05-01 07:31 . 2009-05-01 07:31 466944 ----a-w- c:\windows\system32\nvshell.dll
2009-05-01 07:31 . 2009-05-01 07:31 1724416 ----a-w- c:\windows\system32\nvwdmcpl.dll
2009-05-01 07:31 . 2009-05-01 07:31 1507328 ----a-w- c:\windows\system32\nview.dll
2009-05-01 07:31 . 2009-05-01 07:31 1101824 ----a-w- c:\windows\system32\nvwimg.dll
2009-05-01 05:02 . 2009-05-01 05:02 663552 ----a-w- c:\windows\system32\nvcuvid.dll
2009-05-01 05:02 . 2009-05-01 05:02 1720320 ----a-w- c:\windows\system32\nvcuda.dll
2009-05-01 05:02 . 2009-05-01 05:02 1579630 ----a-w- c:\windows\system32\nvdata.bin
2009-05-01 05:02 . 2009-05-01 05:02 1314816 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-05-01 05:02 . 2007-12-20 20:08 457248 ----a-w- c:\windows\system32\nvudisp.exe
2009-05-01 05:02 . 2007-06-28 16:43 9994240 ----a-w- c:\windows\system32\nvoglnt.dll
2009-05-01 05:02 . 2007-06-28 16:43 806912 ----a-w- c:\windows\system32\nvapi.dll
2009-05-01 05:02 . 2007-06-28 16:43 8055584 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-05-01 05:02 . 2007-06-28 16:43 5896320 ----a-w- c:\windows\system32\nv4_disp.dll
2009-05-01 05:02 . 2007-06-28 16:43 143360 ----a-w- c:\windows\system32\nvcodins.dll
2009-05-01 05:02 . 2007-06-28 16:43 143360 ----a-w- c:\windows\system32\nvcod.dll
2009-04-29 04:56 . 2006-06-23 19:33 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-27 21:45 . 2009-04-27 21:45 17801 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-04-27 07:42 . 2007-12-20 20:08 457248 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-07-22 18:29 . 2008-08-27 19:34 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-24_18.15.30 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-25 08:46 . 2009-07-25 08:46 16384 c:\windows\temp\Perflib_Perfdata_b60.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 19:47 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-28 1948440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-01 13750272]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2009-05-01 86016]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-10-30 16269312]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WPN311 Smart Wizard.lnk - c:\program files\NETGEAR\WPN311\wlancfg5.exe [2006-12-4 1503232]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-28 16:32 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"PrismXL"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"IDriverT"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)
"usnjsvc"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
"ZuneNetworkSvc"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\City of Heroes\\CovUpdater.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [5/12/2009 2:13 PM 61328]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/6/2009 1:42 AM 335752]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/29/2009 9:39 AM 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/16/2009 10:48 AM 24652]
R3 P1130VID;Creative WebCam NX Pro;c:\windows\system32\drivers\P1130Vid.sys [5/17/2008 12:28 AM 90229]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [7/4/2009 6:08 PM 234888]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Supplementary Scan -------
.
uStart Page = yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source? }
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
FF - ProfilePath - c:\documents and settings\Timothy Hayes\Application Data\Mozilla\Firefox\Profiles\vhc11xtm.default\
FF - prefs.
js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - prefs.
js: browser.search.selectedEngine - Yahoo
FF - prefs.
js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.
js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - component: c:\documents and settings\Timothy Hayes\Application Data\Mozilla\Firefox\Profiles\vhc11xtm.default\ext ensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFAlert.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: XUL Cache: {93AC5297-EC57-4B82-9675-E3658FA44711} - c:\windows\system32\config\systemprofile\Local Settings\Application Data\{93AC5297-EC57-4B82-9675-E3658FA44711}\
---- FIREFOX POLICIES ----
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-25 01:46
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-790525478-261478967-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:bc,cd,d4,42,b3,d6,50,e9,da,04,7b,6d ,50,8d,b0,48,0c,83,f8,2c,06,
36,29,c5,9a,6b,b5,b2,a7,9e,28,b8,e9,b5,5a,69,f6,69 ,3f,28,6a,1b,fd,85,1d,be,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49 ,64,ac,f8,d9
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(772)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'lsass.exe'(828)
c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
- - - - - - - > 'explorer.exe'(308)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\acs.exe
c:\program files\AVG\AVG8\avgwdsvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\rundll32.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
************************************************** ************************
.
Completion time: 2009-07-25 1:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-25 08:49
ComboFix2.txt 2009-07-24 18:17
Pre-Run: 256,946,569,216 bytes free
Post-Run: 256,906,469,376 bytes free
287 --- E O F --- 2009-07-21 19:59