Hi,
I have updated the firmware on my router and attached the Combofix log file as requested.
Thanks for your help.
Stormin
ComboFix 10-10-05.06 - Norman 06/10/2010 19:42:46.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1983.1121 [GMT 1:00]
Running from: c:\documents and settings\Norman\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Norman\Application Data\Desktopicon
c:\documents and settings\Norman\Application Data\Desktopicon\config.ini
c:\documents and settings\Norman\Application Data\inst.exe
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\NetMonInstaller.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2010-09-06 to 2010-10-06 )))))))))))))))))))))))))))))))
.
2010-10-05 13:00 . 2010-10-05 13:01 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-10-05 12:58 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-10-05 10:06 . 2010-10-05 10:06 -------- d-----w- c:\program files\CCleaner
2010-09-21 18:44 . 2010-09-21 18:44 -------- d-----w- c:\program files\Common Files\Sony Shared
2010-09-19 09:35 . 2010-09-19 09:35 114 ----a-w- C:\ISF_ID.dat
2010-09-19 09:35 . 2010-09-19 09:35 -------- d-----w- C:\Log
2010-09-19 09:35 . 2010-09-19 09:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Clarus
2010-09-19 09:30 . 2010-09-19 09:30 -------- d-----w- c:\program files\Clarus
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-06 18:50 . 2010-02-17 18:25 -------- d-----w- c:\documents and settings\Norman\Application Data\Dropbox
2010-10-05 20:41 . 2010-05-07 17:36 -------- d-----w- c:\program files\Microsoft Silverlight
2010-10-05 19:55 . 2008-05-28 17:49 -------- d-----w- c:\program files\EPSON Print CD
2010-10-05 14:25 . 2009-04-12 10:38 -------- d-----w- c:\documents and settings\Norman\Application Data\Vso
2010-10-05 13:02 . 2010-06-17 14:51 63488 ----a-w- c:\documents and settings\Norman\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-10-05 13:02 . 2010-06-17 14:51 117760 ----a-w- c:\documents and settings\Norman\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-10-05 10:11 . 2009-01-14 16:29 -------- d-----w- c:\documents and settings\Norman\Application Data\Media Player Classic
2010-10-05 09:55 . 2007-09-05 16:51 9728 ----a-w- c:\windows\system32\drivers\videX32.sys
2010-10-05 09:31 . 2008-08-19 14:28 -------- d-----w- c:\program files\WMR11
2010-10-05 09:30 . 2008-11-18 10:06 -------- d-----w- c:\program files\valodas
2010-10-05 09:24 . 2010-01-26 21:08 -------- d-----w- c:\program files\DRM Converter
2010-10-05 09:18 . 2009-11-17 20:38 -------- d-----w- c:\program files\ABC Amber LIT Converter
2010-10-04 22:09 . 2010-08-13 13:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-02 09:31 . 2009-03-31 17:42 -------- d-----w- c:\program files\Free Flash FLV Video Converter
2010-09-30 06:34 . 2008-10-14 10:41 -------- d-----w- c:\program files\Google
2010-09-22 09:37 . 2008-05-30 12:26 145400 ----a-w- c:\documents and settings\Norman\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-19 09:30 . 2007-09-05 16:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-18 22:24 . 2010-07-21 06:47 -------- d-----w- c:\program files\Brother's Keeper 6 dart
2010-08-17 13:17 . 2006-02-28 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-15 15:48 . 2010-08-15 15:48 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
2010-08-13 22:16 . 2010-08-13 22:16 -------- d-----w- c:\program files\Common Files\Java
2010-08-13 22:16 . 2010-08-13 22:16 503808 ----a-w- c:\documents and settings\Norman\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1169c936-n\msvcp71.dll
2010-08-13 22:16 . 2010-08-13 22:16 499712 ----a-w- c:\documents and settings\Norman\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1169c936-n\jmc.dll
2010-08-13 22:16 . 2010-08-13 22:16 348160 ----a-w- c:\documents and settings\Norman\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1169c936-n\msvcr71.dll
2010-08-13 22:16 . 2010-08-13 22:16 61440 ----a-w- c:\documents and settings\Norman\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-3b148717-n\decora-sse.dll
2010-08-13 22:16 . 2010-08-13 22:16 12800 ----a-w- c:\documents and settings\Norman\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-3b148717-n\decora-d3d.dll
2010-08-13 22:16 . 2010-08-13 22:16 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-13 22:15 . 2008-06-18 12:09 -------- d-----w- c:\program files\Java
2010-08-13 14:05 . 2010-08-13 14:05 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-08-10 19:45 . 2010-07-20 19:39 452104 ----a-w- c:\documents and settings\Norman\Application Data\Real\Update\setup3.12\setup.exe
2010-07-22 15:49 . 2006-02-28 12:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2009-04-15 18:33 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-20 20:16 . 2010-07-20 20:16 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-16 11:25 . 2009-03-30 12:54 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-16 11:25 . 2010-07-16 11:25 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-16 11:24 . 2009-03-30 12:54 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-15 13:45 . 2010-07-15 13:45 187128 ----a-w- c:\documents and settings\Norman\Application Data\Virgin Media\Digital Home Support\downloads\VirginDetectionScriptsBundle.41.zip.dir\tools\NetworkFinder.signed.exe
2010-07-12 08:56 . 2010-08-15 15:48 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe
2010-07-12 08:55 . 2009-03-30 16:23 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-07-12 08:55 . 2009-03-30 21:02 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-02-12 09:43 . 2010-02-12 09:42 33242832 ----a-w- c:\program files\RAVSetup.exe
2007-10-01 15:44 . 2007-10-01 15:44 150192 ----a-w- c:\program files\TweakUiPowertoySetup.exe
2007-10-01 15:40 . 2007-10-01 15:40 212849 ----a-w- c:\program files\hijackthis.zip
2007-10-01 15:27 . 2007-10-01 15:26 1821544 ----a-w- c:\program files\eulalyzersetup.exe
2007-10-01 15:19 . 2007-10-01 15:19 2614072 ----a-w- c:\program files\ccsetup200.exe
2007-10-01 15:12 . 2007-10-01 15:12 1494536 ----a-w- c:\program files\Belarc Advisor.exe
2007-09-01 00:06 . 2007-09-05 20:03 1372160 ----a-w- c:\program files\siw.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 14:04 1664256 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Norman\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Norman\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Norman\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2006-09-21 53248]
"S3Trayp"="S3trayp.exe" [2007-09-30 200704]
"RTHDCPL"="RTHDCPL.EXE" [2006-12-19 16062464]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-30 36864]
"36X Raid Configurer"="c:\windows\system32\JMRaidSetup.exe" [2006-11-16 1953792]
"AsusStartupHelp"="c:\program files\ASUS\AASP\1.00.24\AsRunHelp.exe" [2006-12-29 363008]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"SetDefPrt"="c:\program files\Brother\Brmfl05a\BrStDvPt.exe" [2005-01-26 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2005-05-17 933888]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-10-04 2067808]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-08-31 623960]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"DigitalHomeSupport.exe"="c:\program files\Virgin Media\Digital Home Support\DigitalHomeSupport.exe" [2010-03-12 4314352]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-07-08 236016]
"PCMService"="c:\program files\CyberLink\PowerCinema\PCMService.exe" [2005-05-11 127118]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-09-29 864624]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-08-20 202256]
"Reader Library Launcher"="c:\program files\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe" [2010-07-13 906648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Norman\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Norman\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
Samsung Auto Backup Guage.lnk - c:\program files\Clarus\Samsung Auto Backup\ISFGuage.exe [2010-9-19 888832]
Samsung Auto Backup Real-Time Daemon.lnk - c:\program files\Clarus\Samsung Auto Backup\ISFRealTimeD.exe [2010-9-19 77824]
Samsung Auto Backup Scheduler.lnk - c:\program files\Clarus\Samsung Auto Backup\ISFTimerD.exe [2010-9-19 102400]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-19 4742184]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-9-5 113664]
CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk - c:\program files\CreataCard\Gold\FMRemind.exe [2009-11-23 189952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-16 11:25 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Yahoo!\\Widgets\\YahooWidgets.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Documents and Settings\\Norman\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Virgin Media\\Digital Home Support\\ServicepointService.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [30/03/2009 17:23 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [30/03/2009 13:54 216400]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [30/03/2009 13:54 243024]
R1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [12/05/2009 15:58 7040]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 19:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19:41 67656]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [16/07/2010 12:25 308136]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/07/2010 09:55 1356952]
R2 ServicepointService;ServicepointService;c:\program files\Virgin Media\Digital Home Support\ServicepointService.exe [28/06/2010 23:06 689392]
S1 SABKUTIL;SABKUTIL;\??\c:\program files\SUPERAntiSpyware\SABKUTIL.sys --> c:\program files\SUPERAntiSpyware\SABKUTIL.sys [?]
S2 gupdate1c9b1d627e979e0;Google Update Service (gupdate1c9b1d627e979e0);c:\program files\Google\Update\GoogleUpdate.exe [31/03/2009 08:56 133104]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
S3 DrmCAudio;DrmCAudio;c:\windows\system32\drivers\DrmCAudio.sys [26/01/2010 22:08 23096]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [15/08/2010 16:52 15008]
S3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [05/06/2008 10:18 91797]
.
Contents of the 'Scheduled Tasks' folder
2010-10-06 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 13:14]
2010-10-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
2010-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-31 07:56]
2010-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-31 07:56]
2008-05-28 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2007-08-31 19:01]
2010-10-06 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-583907252-1004336348-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]
2010-10-06 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-583907252-1004336348-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 02:02]
2010-10-06 c:\windows\Tasks\User_Feed_Synchronization-{FB58DD77-08B3-4CC8-8E6F-F53C35E5EA48}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.altavista.com/
uInternet Connection Wizard,ShellNext = hxxp://free.grisoft.com/register
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:5643
DPF: {96816368-C1E3-414D-A193-63C3CC921990} - hxxp://hotelforumrome.remotemanager.co.uk/common/activex/MJPEGRender.ocx
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
.
.
------- File Associations -------
.
.txt=
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
HKCU-Run-NoteMagic Lite - c:\program files\JSoft Consulting\NoteMagic\notemag.exe
HKLM-Run-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
HKLM-Run-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
SafeBoot-klmdb.sys
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
@=""
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
@=""
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
@=""
"Installed"="1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(628)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(152)
c:\windows\system32\WININET.dll
c:\program files\Unlocker\UnlockerHook.dll
c:\documents and settings\Norman\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\brss01a.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\VTTimer.exe
c:\windows\system32\S3trayp.exe
c:\windows\RTHDCPL.EXE
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-10-06 19:58:23 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-06 18:58
Pre-Run: 5,004,476,416 bytes free
Post-Run: 4,961,890,304 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - F455F625A689AC5B3A9181021C4567A6