ok done..
ComboFix 09-07-09.08 - Manu 11/07/2009 10:48.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.61.1033.18.2046.1236 [GMT 8:00]
Running from: c:\users\Manu\Desktop\ComboFix.exe
.
ADS - Windows: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-857502479-4244170445-3684516530-500
c:\windows\Installer\451c67.msi
.
((((((((((((((((((((((((( Files Created from 2009-06-11 to 2009-07-11 )))))))))))))))))))))))))))))))
.
2009-07-10 14:24 . 2009-06-26 08:00 327688 ----a-w- c:\programdata\avg8\update\backup\avgldx86.sys
2009-07-10 14:24 . 2009-06-26 08:00 2052376 ----a-w- c:\programdata\avg8\update\backup\avgcorex.dll
2009-07-10 14:24 . 2009-06-26 08:00 493336 ----a-w- c:\programdata\avg8\update\backup\avgtbapi.dll
2009-07-10 14:24 . 2009-06-26 08:00 2167576 ----a-w- c:\programdata\avg8\update\backup\avgresf.dll
2009-07-10 14:24 . 2009-06-26 08:00 3402008 ----a-w- c:\programdata\avg8\update\backup\avgui.exe
2009-07-10 14:24 . 2009-06-26 08:00 1204504 ----a-w- c:\programdata\avg8\update\backup\avgabout.dll
2009-07-10 14:24 . 2009-06-26 08:00 337176 ----a-w- c:\programdata\avg8\update\backup\avglogx.dll
2009-07-10 14:24 . 2009-06-26 08:00 829208 ----a-w- c:\programdata\avg8\update\backup\avgcfgx.dll
2009-07-10 14:24 . 2009-06-26 08:00 3298072 ----a-w- c:\programdata\avg8\update\backup\setup.exe
2009-07-10 14:22 . 2009-06-26 07:58 1085208 ----a-w- c:\programdata\avg8\update\backup\avgupd.exe
2009-07-10 14:22 . 2009-06-26 07:58 1454360 ----a-w- c:\programdata\avg8\update\backup\avgupd.dll
2009-07-10 06:19 . 2009-07-10 06:19 -------- d-----w- c:\program files\CCleaner
2009-07-10 05:11 . 2009-07-10 05:11 3561743 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-07-09 11:16 . 2009-07-10 13:58 -------- d-----w- c:\users\Manu\AppData\Roaming\Canon
2009-07-09 07:27 . 2009-07-10 02:15 45056 ----a-r- c:\users\Manu\AppData\Roaming\Microsoft\Installer\{193428D8-940D-4351-88F6-0AFA7D1E3CB8}\MapleStory.exe1_193428D8940D435188F60AFA7D1E3CB8.exe
2009-07-09 07:27 . 2009-07-10 02:15 45056 ----a-r- c:\users\Manu\AppData\Roaming\Microsoft\Installer\{193428D8-940D-4351-88F6-0AFA7D1E3CB8}\MapleStory.exe_193428D8940D435188F60AFA7D1E3CB8.exe
2009-07-09 07:24 . 2009-07-09 07:24 -------- d-----w- C:\Nexon
2009-07-09 05:17 . 2009-07-10 13:56 -------- d-----w- c:\program files\Pando Networks
2009-07-03 13:18 . 2009-07-10 13:57 -------- d-----w- c:\program files\Persona
2009-07-03 09:02 . 2009-07-03 09:02 -------- d-----w- C:\Netgame
2009-07-01 23:26 . 2009-07-01 23:26 -------- d-----w- c:\program files\Conduit
2009-07-01 23:26 . 2009-07-01 23:26 -------- d-----w- c:\program files\PHPNukeEN
2009-07-01 11:11 . 2009-07-01 12:17 -------- d-----w- c:\users\Manu\AppData\Roaming\Nero
2009-07-01 10:53 . 2009-07-01 11:07 -------- d-----w- c:\program files\Nero
2009-07-01 10:52 . 2009-07-01 10:57 -------- d-----w- c:\programdata\Nero
2009-07-01 10:52 . 2009-07-01 11:09 -------- d-----w- c:\program files\Common Files\Nero
2009-07-01 10:51 . 2008-08-20 03:33 1315328 ----a-w- c:\windows\system32\ole32.dll
2009-07-01 00:02 . 2009-07-03 09:00 -------- d-----w- c:\program files\SlySoft
2009-06-30 23:46 . 2009-07-08 09:22 -------- d-----w- c:\program files\Warcraft III
2009-06-28 14:02 . 2009-07-09 11:16 -------- d-----w- c:\programdata\CanonIJPLM
2009-06-28 13:57 . 2009-06-28 13:57 -------- d-----w- c:\program files\Common Files\CANON
2009-06-28 13:50 . 2008-02-25 20:00 230912 ----a-w- c:\windows\system32\CNMLM9I.DLL
2009-06-28 13:50 . 2009-06-28 13:52 -------- d-----w- c:\users\Manu\{670849b5-97e4-402a-8128-8c926975cd77}
2009-06-26 09:23 . 2009-06-26 09:23 -------- d-----w- c:\users\Manu\AppData\Local\AVG Security Toolbar
2009-06-26 08:01 . 2009-06-26 08:01 -------- d-----w- c:\programdata\AVG Security Toolbar
2009-06-16 23:41 . 2008-09-16 19:23 168448 ----a-w- c:\windows\system32\unrar.dll
2009-06-16 23:41 . 2009-06-16 23:42 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-06-16 08:52 . 2009-06-16 08:53 -------- d-----w- c:\program files\BitTorrent
2009-06-13 13:51 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-06-13 13:51 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-10 14:29 . 2008-09-26 14:38 -------- d-----w- c:\programdata\McAfee
2009-07-10 14:23 . 2008-12-03 10:40 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-10 13:58 . 2009-05-01 13:15 -------- d-----w- c:\program files\AviSynth 2.5
2009-07-10 13:58 . 2008-10-14 08:30 -------- d-----w- c:\program files\Canon
2009-07-10 05:11 . 2008-12-29 09:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-10 05:05 . 2008-12-03 10:39 -------- d-----w- c:\programdata\avg8
2009-07-10 04:04 . 2008-09-26 13:51 -------- d-----w- c:\program files\Steam
2009-07-08 09:04 . 2008-09-26 15:29 189800 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-07-08 08:48 . 2008-09-26 15:29 138608 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-04 09:10 . 2009-01-24 07:16 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-07-03 10:27 . 2008-09-26 13:51 -------- d-----w- c:\program files\Common Files\Steam
2009-07-03 10:26 . 2008-12-19 07:19 119504 ----a-w- c:\users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-03 09:56 . 2007-12-11 04:24 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-03 09:09 . 2007-12-11 04:14 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-03 09:08 . 2007-12-11 04:14 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-03 09:02 . 2009-03-31 08:16 -------- d-----w- c:\program files\Netgame
2009-06-26 08:00 . 2009-01-27 12:19 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-26 08:00 . 2008-12-03 10:40 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-17 03:27 . 2008-12-29 09:58 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 03:27 . 2008-12-29 09:58 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-16 08:52 . 2009-04-15 11:04 -------- d-----w- c:\program files\DNA
2009-06-14 23:25 . 2007-12-11 04:27 -------- d-----w- c:\programdata\Microsoft Help
2009-06-11 08:46 . 2007-12-11 04:26 -------- d-----w- c:\program files\Microsoft Works
2009-06-05 13:53 . 2009-05-30 07:49 -------- d-----w- c:\users\Manu\AppData\Roaming\Bioshock
2009-05-31 10:01 . 2009-05-31 10:01 -------- d-----w- c:\users\Manu\AppData\Roaming\EBookSys
2009-05-30 07:43 . 2008-09-26 14:31 -------- d-----w- c:\users\Manu\AppData\Roaming\Media Center Programs
2009-05-30 07:40 . 2009-05-30 07:40 16311648 ----a-w- c:\users\Manu\AppData\Roaming\2K Games\BioShock\Builds\Release\Bioshock.exe
2009-05-30 07:39 . 2009-05-30 07:39 108144 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-05-30 07:24 . 2009-05-30 07:24 -------- d-----w- c:\users\Manu\AppData\Roaming\InstallShield Installation Information
2009-05-30 07:24 . 2009-05-30 07:24 -------- d-----w- c:\users\Manu\AppData\Roaming\2K Games
2009-05-24 14:04 . 2009-05-24 14:04 -------- d-----w- c:\program files\Apple Software Update
2009-05-24 14:04 . 2009-05-24 14:04 -------- d-----w- c:\programdata\Apple
2009-05-15 08:17 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-15 00:02 . 2009-05-15 00:02 2373416 ----a-w- c:\programdata\Nero\Nero\DrWeb\DrWeb32.dll
2009-05-14 23:50 . 2009-05-14 23:50 2373416 ----a-w- c:\programdata\Nero\Nero 9\DrWeb\DrWeb32.dll
2009-05-13 15:25 . 2008-09-26 15:38 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-05-13 15:25 . 2008-09-26 15:38 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-05-13 15:25 . 2008-09-26 15:38 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-05-13 15:25 . 2008-06-26 22:08 214024 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-05-13 15:24 . 2008-09-26 15:37 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-05-09 05:50 . 2009-06-10 09:10 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-10 09:09 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-04-23 12:43 . 2009-06-10 08:55 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-10 09:14 636928 ----a-w- c:\windows\system32\localspl.dll
2009-04-22 06:49 . 2008-09-26 14:36 119504 ----a-w- c:\users\Manu\AppData\Local\GDIPFONTCACHEV1.DAT
2009-04-21 11:55 . 2009-06-10 09:28 2033152 ----a-w- c:\windows\system32\win32k.sys
2007-12-11 03:49 . 2007-12-11 03:35 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 08:07 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}]
2009-02-16 07:44 1882136 ----a-w- c:\program files\PHPNukeEN\tbPHPN.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"Steam"="c:\program files\steam\steam.exe" [2009-06-14 1217784]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-04-03 3558648]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-26 1948440]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-13 611712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13683232]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 92704]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-10-25 652624]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-09-13 1603152]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{6FE061E2-6D09-4E49-B04A-F70822468311}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{8689B1A0-C88B-45A9-BAE4-0EA68AE0FCFE}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{49D68890-468E-473C-A3F8-363D47569278}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{4770A1D3-3DCC-4C34-BB0B-A68BC24E7D8D}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{9C8D30A8-064B-4847-AEE4-5B9A4EF8B7D2}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{8F71029B-E015-42D1-8370-9F101AE1235A}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{72EA5B3B-DF06-4BCA-8D6A-EA66DD2FFAD0}c:\\program files\\softnyx\\gunboundwc\\gunbound.gme"= UDP:c:\program files\softnyx\gunboundwc\gunbound.gme:GunBound
"UDP Query User{125ED9B1-ADAC-449D-B34A-7C57A73FDB9C}c:\\program files\\softnyx\\gunboundwc\\gunbound.gme"= TCP:c:\program files\softnyx\gunboundwc\gunbound.gme:GunBound
"{5140C26E-7B5D-47EA-8C53-25CFEB79854B}"= UDP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{B0C00538-CBB0-4B46-A543-48E422FFA74B}"= TCP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"TCP Query User{3B9CEE44-91FD-45B5-87DB-594AAEAA8516}c:\\program files\\steam\\steamapps\\caha11\\team fortress 2\\hl2.exe"= UDP:c:\program files\steam\steamapps\caha11\team fortress 2\hl2.exe:hl2
"UDP Query User{70DF8705-B306-4028-9F79-043BA58580CD}c:\\program files\\steam\\steamapps\\caha11\\team fortress 2\\hl2.exe"= TCP:c:\program files\steam\steamapps\caha11\team fortress 2\hl2.exe:hl2
"{8856FBE3-2F47-484F-B38D-D691031B7BB7}"= UDP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{63710C16-05D6-43C5-B211-516AA07C549F}"= TCP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{4361748C-88AA-4569-A3EA-7FFB82AD8C01}"= UDP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{11F4D765-1545-4E23-A001-597289BF71ED}"= TCP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{43CBC44A-F141-4325-9B21-A16BCEF50E91}"= UDP:c:\program files\AeriaGames\ProjectTorque\ProjectTorque.bin:Project Torque
"{9A777DD1-1D17-4702-8EA7-166199E66B35}"= TCP:c:\program files\AeriaGames\ProjectTorque\ProjectTorque.bin:Project Torque
"TCP Query User{84D6C7D9-25C4-476F-9AA2-B1686B3F6853}c:\\users\\manu\\dragonbot1.4a_full\\dragonbot\\mirc.exe"= UDP:c:\users\manu\dragonbot1.4a_full\dragonbot\mirc.exe:mirc.exe
"UDP Query User{C089B7D5-2F40-402D-A2A1-FA50DF753BE8}c:\\users\\manu\\dragonbot1.4a_full\\dragonbot\\mirc.exe"= TCP:c:\users\manu\dragonbot1.4a_full\dragonbot\mirc.exe:mirc.exe
"TCP Query User{E6798FBB-06E0-49B1-809E-F17A0E1860AA}c:\\program files\\softnyx\\wolfteam\\wolfteam.bin"= UDP:c:\program files\softnyx\wolfteam\wolfteam.bin:WolfTeam
"UDP Query User{39CAF706-8E19-454B-A2B9-8D2CB270B9A4}c:\\program files\\softnyx\\wolfteam\\wolfteam.bin"= TCP:c:\program files\softnyx\wolfteam\wolfteam.bin:WolfTeam
"{6BD9DB6E-4D5F-4D61-9677-6F8379D0A856}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{F0C5C463-6FBD-4333-BF5F-DDA8EE22C6E3}"= TCP:c:\program files\DNA\btdna.exe:DNA
"TCP Query User{47474CC2-F32F-40FE-A7FD-6B880976E89F}c:\\users\\manu\\program files\\dna\\btdna.exe"= UDP:c:\users\manu\program files\dna\btdna.exe:btdna.exe
"UDP Query User{89832368-05BB-447A-ACBD-605B25A7D9AA}c:\\users\\manu\\program files\\dna\\btdna.exe"= TCP:c:\users\manu\program files\dna\btdna.exe:btdna.exe
"{E8CCCB1F-D909-4CC7-BEC7-FD77CEE45BBE}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{841BE63E-D49C-46ED-B763-0844DFEE9A40}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{D64A2B40-07E8-427E-ABF0-25D7E9375E6C}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{6D1DCF9A-45F3-448E-B601-F2004AE68D90}"= UDP:5353:Adobe CSI CS4
"{523E5D3B-4EE6-4BBB-9BE0-34EF7C7B22BE}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{A0204CFE-C4C7-4A13-9F3E-B26F8D30908F}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{564E2297-1347-4623-B39A-62280B125B1E}"= UDP:c:\program files\Steam\Steam.exe:Steam
"{DCFEF150-9A6E-4FFC-BDB2-5AEAE420F848}"= TCP:c:\program files\Steam\Steam.exe:Steam
"TCP Query User{7B35C3B1-C266-4BF6-8EF1-F88714C32EE8}c:\\program files\\steam\\steamapps\\caha11\\team fortress 2\\hl2.exe"= UDP:c:\program files\steam\steamapps\caha11\team fortress 2\hl2.exe:hl2
"UDP Query User{843E054E-2D52-4B75-BD01-F0719C71D2E1}c:\\program files\\steam\\steamapps\\caha11\\team fortress 2\\hl2.exe"= TCP:c:\program files\steam\steamapps\caha11\team fortress 2\hl2.exe:hl2
"{E3BD4F78-96F0-43C3-A6E9-43CC579900F2}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty(R) - World at War(TM)
"{AE6F7D62-D39C-47FC-ADB4-AFCBD62EC82F}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty(R) - World at War(TM)
"{9A4E9918-171C-43D7-A2B1-667B645E14CC}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty(R) - World at War(TM)
"{A6D28D2D-E910-4447-80BA-41A770443CB2}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty(R) - World at War(TM)
"{1B87B773-D143-4238-BA69-B03F6EB3A56B}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{9145A047-C1FA-4CC0-8C90-FB966C003222}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{8FC35CA2-5CFD-4558-9DDF-E06286781DF7}"= UDP:c:\program files\Garena\Garena.exe:Garena
"{9F933FB3-3EC0-437D-A385-0E3BB7ED64B2}"= TCP:c:\program files\Garena\Garena.exe:Garena
"{CF87C846-3045-4A1F-981E-D45B710A91F1}"= UDP:c:\program files\Steam\steamapps\common\left 4 dead\left4dead.exe:Left 4 Dead
"{0D39BD40-8ABB-4318-8E7A-B51CB98D6D8F}"= TCP:c:\program files\Steam\steamapps\common\left 4 dead\left4dead.exe:Left 4 Dead
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [3/12/2008 6:40 PM 335752]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [27/01/2009 8:19 PM 298776]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [18/03/2009 6:08 AM 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [6/02/2009 5:08 PM 533360]
S3 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20070823.002\IDSvix86.sys [11/12/2007 12:39 PM 180272]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
Contents of the 'Scheduled Tasks' folder
2009-07-10 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2009-01-15 01:55]
2009-07-11 c:\windows\Tasks\User_Feed_Synchronization-{61F0EE8C-A87D-4AE8-AA15-83606F46CACA}.job
- c:\windows\system32\msfeedssync.exe [2009-03-27 11:31]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
SafeBoot-mcmscsvc
SafeBoot-MCODS
.
------- Supplementary Scan -------
.
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_au&c=81&bd=Presario&pf=desktop
uSearchURL,(Default) = hxxp://au.search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
TCP: {3FA7D6CE-8903-40F9-8594-4A7586BC7A97} = 192.168.2.1,10.0.0.138
FF - ProfilePath - c:\users\Manu\AppData\Roaming\Mozilla\Firefox\Profiles\1zd68qst.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPHoldemFireLauncher.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMFireLauncher.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2009-07-11 10:54
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\users\Manu\AppData\Local\Temp\BSQ5BDC.tmp"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3420107519-1398025699-341120056-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:cd,2c,0b,a6,ce,89,ec,c6,75,8e,ec,c2,6f,0c,bc,78,66,83,c5,b0,20,34,2a,
0f,7f,31,45,7a,b0,ff,2b,90,22,db,93,fd,60,59,0b,71,ac,d7,d1,57,3a,6a,52,93,\
"??"=hex:cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b,19,52,fe,22
.
Completion time: 2009-07-11 10:55
ComboFix-quarantined-files.txt 2009-07-11 02:55
Pre-Run: 204,443,254,784 bytes free
Post-Run: 203,776,655,360 bytes free
271 --- E O F --- 2009-07-10 00:37