ComboFix 09-07-01.01 - ******* 02/07/2009 2:30.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1253.30.1033.18.1023.482 [GMT 3:00]
Running from: c:\documents and settings\*******\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: NVIDIA Firewall *disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\*******\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\*******\Local Settings\Temp\IadHide5.dll
.
---- Previous Run -------
.
c:\docume~1\Tatiana\APPLIC~1\MessengerSkinner\User data\languages_v2.xml
c:\docume~1\Tatiana\APPLIC~1\MessengerSkinner\User data\pack1.cab
c:\docume~1\Tatiana\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\Tatiana\Local Settings\Temp\IadHide5.dll
.
((((((((((((((((((((((((( Files Created from 2009-06-01 to 2009-07-01 )))))))))))))))))))))))))))))))
.
2009-07-01 15:12 . 2009-06-17 08:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-01 15:12 . 2009-07-01 15:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-01 15:12 . 2009-06-17 08:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-30 19:24 . 2009-06-30 19:24 -------- d-----w- c:\documents and settings\Tatiana\Local Settings\Application Data\AVG Security Toolbar
2009-06-30 19:23 . 2009-06-30 19:23 -------- d-----w- c:\program files\MouseHunt Toolbar
2009-06-29 15:55 . 2009-06-29 15:55 -------- d-----w- C:\8f2c36756d5a1f3132d0d20d414580df
2009-06-29 05:30 . 2009-06-29 05:31 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-29 05:30 . 2009-06-29 05:30 -------- d-----w- c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-22 13:54 . 2009-06-22 13:54 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-06-14 21:03 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-14 21:03 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-03 12:12 . 2009-06-03 12:12 -------- d-----w- c:\program files\Common Files\Skype
2009-06-03 12:12 . 2009-06-03 12:12 -------- d-----r- c:\program files\Skype
2009-06-03 12:09 . 2009-06-03 12:09 -------- d-sh--w- c:\documents and settings\Tatiana\IECompatCache
2009-06-03 12:09 . 2009-06-03 12:09 -------- d-sh--w- c:\documents and settings\Tatiana\PrivacIE
2009-06-03 12:00 . 2009-06-03 12:00 -------- d-sh--w- c:\documents and settings\Tatiana\IETldCache
2009-06-03 11:58 . 2009-06-03 11:58 -------- d-----w- c:\windows\ie8updates
2009-06-03 11:57 . 2009-05-12 05:11 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-06-03 11:55 . 2009-06-03 11:56 -------- dc-h--w- c:\windows\ie8
2009-06-02 23:06 . 2009-06-02 23:06 -------- d-----w- c:\documents and settings\Tatiana\Local Settings\Application Data\Yahoo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-07-01 23:34 . 2009-02-02 12:11 -------- d-----w- c:\program files\FlashGet
2009-07-01 14:37 . 2009-04-26 14:45 -------- d-----w- c:\program files\Common Files\ParetoLogic
2009-07-01 14:37 . 2009-04-26 14:45 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-06-30 21:32 . 2008-03-05 02:50 -------- d-----w- c:\docume~1\Tatiana\APPLIC~1\Azureus
2009-06-29 16:48 . 2005-12-15 17:54 21808 ----a-w- c:\documents and settings\Tatiana\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-29 05:30 . 2008-08-12 23:53 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-29 05:30 . 2008-08-12 23:53 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-29 05:30 . 2008-08-12 23:53 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-24 14:18 . 2008-05-20 21:22 -------- d-----w- c:\docume~1\Tatiana\APPLIC~1\Skype
2009-06-22 21:04 . 2008-05-20 21:24 -------- d-----w- c:\docume~1\Tatiana\APPLIC~1\skypePM
2009-06-15 23:47 . 2008-08-19 19:50 -------- d-----w- c:\docume~1\Tatiana\APPLIC~1\LimeWire
2009-06-03 12:12 . 2008-05-20 21:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-06-03 11:42 . 2006-07-04 15:47 -------- d-----w- c:\docume~1\Tatiana\APPLIC~1\Yahoo!
2009-06-02 23:05 . 2005-12-15 18:13 -------- d-----w- c:\program files\Yahoo!
2009-06-02 23:05 . 2005-12-15 20:26 -------- d-----w- c:\documents and settings\All Users\Application Data\yahoo!
2009-06-02 23:05 . 2005-12-15 18:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-05-26 09:05 . 2005-12-15 20:18 -------- d-----w- c:\docume~1\Tatiana\APPLIC~1\Upload Cool
2009-05-17 19:50 . 2008-08-12 23:53 -------- d-----w- c:\docume~1\Tatiana\APPLIC~1\AVGTOOLBAR
2009-05-17 19:49 . 2009-02-02 11:53 -------- d-----w- c:\documents and settings\All Users\Application Data\comp two long internet
2009-05-17 06:54 . 2008-08-12 23:53 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-13 05:15 . 2002-08-29 03:41 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2002-08-29 03:41 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-26 15:15 . 2009-04-26 14:55 292128 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-04-26 15:15 . 2009-04-26 14:55 15136 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-04-17 12:26 . 2002-08-29 02:14 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2002-08-29 03:41 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-14 19:18 . 2005-12-15 18:18 44944 ------w- c:\windows\system32\drivers\pxhelp20.sys
2009-04-14 19:18 . 2009-04-14 19:18 158192 ------w- c:\windows\system32\pxwma.dll
2006-01-23 12:40 . 2006-01-23 12:40 2167119 ----a-w- c:\program files\dMC-r11[1].5.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-07-01_23.21.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-01 23:35 . 2009-07-01 23:35 16384 c:\windows\Temp\Perflib_Perfdata_434.dat
+ 2009-07-01 23:36 . 2009-07-01 23:36 16384 c:\windows\Temp\Perflib_Perfdata_1400.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91B53B55-36CE-4ABE-A248-F97D6D9F0CFF}]
2009-06-30 19:23 1302528 ----a-w- c:\program files\MouseHunt Toolbar\Toolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 13:07 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-10-08 10:22 1172792 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe" [2006-09-25 36864]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-07-23 68856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-28 3660848]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-03-07 3558136]
"Messenger (Yahoo!)"="~c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [BU]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-05-26 24264488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-12-09 225280]
"LogitechCameraAssistant"="c:\program files\Logitech\Video\CameraAssistant.exe" [2006-01-05 489472]
"LogitechVideo[inspector]"="c:\program files\Logitech\Video\InstallHelper.exe" [2006-01-05 05:15 73728]
"LogitechCameraService(E)"="c:\windows\system32\El kCtrl.exe" [2004-11-01 262144]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-12-15 77824]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-08 222208]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-19 136600]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-29 1948440]
"Flashget"="c:\program files\FlashGet\flashget.exe" [2007-09-25 2007088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-25 198160]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-03-05 111928]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"Tweak UI"="TWEAKUI.CPL" - c:\windows\system32\TWEAKUI.CPL [2000-06-18 106544]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 1634304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-12-15 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-9-25 196608]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
Nokia Nseries PC Suite.lnk - c:\program files\Nokia\NNPCS\RunLauncher.exe [2008-5-8 943568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-29 05:30 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessen ger.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Documents and Settings\\Tatiana\\My Documents\\Ληφθέντα αρχεία\\eMule0.48a\\eMule0.48a\\emule.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\MouseHunt Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\MouseHunt Toolbar\\ToolbarUpdate.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13/08/2008 02:53 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13/08/2008 02:53 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [13/08/2008 02:52 906520]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [13/08/2008 02:52 298776]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssflt r_tdi.sys [22/03/2009 20:37 55152]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19:08 533360]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [24/11/2008 23:39 138112]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSe tup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-01 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]
2009-05-28 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]
.
- - - - ORPHANS REMOVED - - - -
BHO-{09898850-B383-4774-24A2-6BB7156A309D} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = about
:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
Yahoo! SearchBar Home Page
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
Yahoo!
IE: &Winamp Toolbar Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Yahoo! Search -
file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: &Λήψη όλων με το FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Λήψη με χρήση του FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Yahoo! &Dictionary -
file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps -
file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS -
file:///c:\program files\Yahoo!\Common/ycsms.htm
TCP: {DFCCCD4C-0546-403D-A426-165BF82DA5A8} = 195.170.2.2,195.170.0.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\docume~1\Tatiana\APPLIC~1\Mozilla\Firefox\Profi les\55ud1l6i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=58819&p=
FF - component: c:\documents and settings\Tatiana\Application Data\Mozilla\Firefox\Profiles\55ud1l6i.default\ext ensions\{916ab64c-bc3e-471b-8e60-29551922a7ba}\components\Engine.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\compone nts\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\compone nts\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\compone nts\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\compone nts\xpavgtbapi.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\npr pbrowserrecordplugin.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.d ll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-07-02 02:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{467431f 6-7bc0-41cb-9d3a-c4db4d3913f6}]
@Denied: (Full) (Everyone)
"Model"=dword:000000bc
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5 ,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe ,41,71,cb,3f,46,a4,7c,ab,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED6077 9-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):53,f9,3a,bf,c6,d4,d6,58,79,25,a0,0 4,13,f6,81,d0,82,9b,ea,86,a2,
e9,4b,54,6f,3f,e2,ff,27,a2,49,c0,6c,bd,78,76,16,02 ,d2,02,00,00,00,00,00,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(732)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(304)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
c:\program files\FlashGet\fgmgr.dll
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\PC Connectivity Solution\ConnAPI.DLL
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_gre.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe
c:\windows\system32\ati2evxx.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\Canon\IJPLM\ijplmsvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.ex e
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\Nokia\PC Connectivity Solution\ServiceLayer.exe
c:\program files\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\Nokia\PC Connectivity Solution\Transports\NclIrSrv.exe
c:\program files\Nokia\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\Nokia\PC Connectivity Solution\Transports\NclMSBTSrv.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
************************************************** ************************
.
Completion time: 2009-07-01 2:39 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-01 23:39
Pre-Run: 39.884.324.864 bytes free
Post-Run: 39.869.472.768 bytes free
294 --- E O F --- 2009-06-30 00:01