Okay... Here it is:
ComboFix 10-03-28.01 - Calvin 28/03/2010 19:13:39.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.3325.2507 [GMT -7:00]
Running from: c:\users\Calvin\Desktop\cbf.exe
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1400113804-1914402855-3429530994-500
c:\$recycle.bin\S-1-5-21-1790924192-2944971578-4197939686-1001
c:\$recycle.bin\S-1-5-21-1790924192-2944971578-4197939686-1002
c:\$recycle.bin\S-1-5-21-1790924192-2944971578-4197939686-1003
c:\$recycle.bin\S-1-5-21-1790924192-2944971578-4197939686-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\users\Calvin\AppData\Roaming\logs.dat
c:\users\Mom\AppData\Roaming\logs.dat
c:\windows\system32\bin
c:\windows\system32\logs
c:\windows\system32\logs\settings.dat
c:\windows\system32\Microsoft\svchost.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ILVMONEYDRIVER53
-------\Service_DUMeterSvc
-------\Service_IlvMoneyDRIVER53
((((((((((((((((((((((((( Files Created from 2010-02-28 to 2010-03-29 )))))))))))))))))))))))))))))))
.
2010-03-29 02:26 . 2010-03-29 02:31 -------- d-----w- c:\users\Calvin\AppData\Local\temp
2010-03-29 02:26 . 2010-03-29 02:26 -------- d-----w- c:\users\Mom\AppData\Local\temp
2010-03-29 02:26 . 2010-03-29 02:26 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-03-29 02:26 . 2010-03-29 02:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-28 18:07 . 2010-03-28 18:07 -------- d-----w- c:\program files\EA Sports
2010-03-28 01:31 . 2010-03-28 01:31 -------- d-----w- c:\users\Calvin\AppData\Roaming\Leadertech
2010-03-27 15:53 . 2010-03-27 15:53 -------- d-----w- c:\program files\Microsoft IntelliPoint
2010-03-27 05:09 . 2010-03-27 05:09 0 ----a-w- c:\users\Calvin\jagex__preferences3.dat
2010-03-26 14:27 . 2010-03-27 20:12 -------- d-----w- c:\program files\Qtracker
2010-03-23 05:27 . 2010-03-23 05:27 -------- d-----w- c:\users\Calvin\AppData\Local\Greyfirst
2010-03-20 20:57 . 2010-03-20 20:57 -------- d-----w- c:\users\Calvin\.netbeans-derby
2010-03-20 20:32 . 2010-03-20 21:27 -------- d-----w- c:\users\Calvin\.netbeans
2010-03-20 20:31 . 2010-03-20 20:31 -------- d-----w- c:\users\Calvin\.netbeans-registration
2010-03-20 20:28 . 2010-03-20 21:31 -------- d-----w- c:\program files\NetBeans 6.8
2010-03-20 19:05 . 2010-03-20 19:05 -------- d-----w- c:\program files\SystemRequirementsLab
2010-03-20 19:05 . 2010-03-20 19:05 -------- d-----w- c:\users\Calvin\AppData\Roaming\SystemRequirementsLab
2010-03-20 16:12 . 2010-03-20 20:56 2795 ----a-w- c:\users\Calvin\AppData\Local\DreamCalc DC4P.dat
2010-03-20 16:11 . 2010-03-20 16:12 -------- d-----w- c:\program files\DreamCalc DC4P
2010-03-15 13:33 . 2010-03-15 13:33 -------- d-----w- c:\program files\2K Sports
2010-03-15 13:25 . 2010-03-15 13:25 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-03-15 13:25 . 2010-03-15 13:32 -------- d-----w- c:\users\Calvin\AppData\Roaming\DAEMON Tools Lite
2010-03-15 13:25 . 2010-03-15 13:25 -------- d-----w- c:\progra~2\DAEMON Tools Lite
2010-03-15 01:26 . 2010-03-15 01:26 -------- d-----w- C:\.jagex_cache_32
2010-03-14 17:45 . 2010-03-14 17:45 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-03-14 17:45 . 2010-03-14 17:45 -------- d-----w- c:\program files\Microsoft.NET
2010-03-14 17:45 . 2010-03-14 17:45 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-03-14 17:45 . 2010-03-14 17:45 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-03-14 17:40 . 2010-03-14 17:40 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-03-14 17:39 . 2010-03-14 17:39 -------- d-----w- c:\program files\Microsoft Analysis Services
2010-03-14 02:39 . 2010-03-14 02:39 -------- d-----w- c:\program files\ESET
2010-03-13 19:29 . 2010-02-25 09:56 21320 ----a-w- c:\windows\system32\authuitu.dll
2010-03-13 19:29 . 2010-02-25 09:56 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-03-11 04:11 . 2010-03-11 04:11 -------- d-----w- C:\MSSoap
2010-03-11 04:10 . 2010-03-11 04:20 -------- d-----w- c:\program files\UFile 2009
2010-03-10 06:34 . 2010-02-20 23:06 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-03-10 06:34 . 2010-02-20 20:53 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-03-10 06:34 . 2010-02-20 23:05 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-03-01 06:18 . 2010-03-28 04:56 -------- d-----w- C:\FarmVilleBot_2.1
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-29 02:32 . 2010-02-11 01:48 -------- d-----w- c:\users\Calvin\AppData\Roaming\.purple
2010-03-29 02:30 . 2008-02-05 00:52 -------- d-----w- c:\program files\Dl_cats
2010-03-29 01:48 . 2009-03-21 01:22 128728 ----a-w- c:\users\Mom\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-28 20:58 . 2010-01-14 07:11 69 ----a-w- c:\users\Calvin\jagex_runescape_preferences2.dat
2010-03-28 20:58 . 2010-01-14 07:10 41 ----a-w- c:\users\Calvin\jagex_runescape_preferences.dat
2010-03-28 20:48 . 2007-09-14 03:27 128728 ----a-w- c:\users\Calvin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-28 20:41 . 2007-09-05 11:22 -------- d-----w- c:\progra~2\Microsoft Help
2010-03-28 20:03 . 2009-01-17 19:07 -------- d-----w- c:\users\Calvin\AppData\Roaming\Download Manager
2010-03-28 19:31 . 2007-09-05 11:28 -------- d-----w- c:\progra~2\SupportSoft
2010-03-27 20:34 . 2007-09-05 11:16 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-23 13:31 . 2010-02-11 03:14 -------- d-----w- c:\users\Calvin\AppData\Roaming\uTorrent
2010-03-22 23:27 . 2010-02-11 03:14 -------- d-----w- c:\program files\uTorrent
2010-03-20 22:12 . 2008-11-03 12:43 -------- d-----w- c:\program files\NCH Swift Sound
2010-03-16 01:49 . 2008-04-21 04:53 1356 ----a-w- c:\users\Calvin\AppData\Local\d3d9caps.dat
2010-03-15 14:04 . 2009-03-15 05:11 -------- d-----w- c:\users\Calvin\AppData\Roaming\2K Sports
2010-03-15 13:25 . 2008-05-24 17:38 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-03-14 17:46 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2010-03-14 17:18 . 2009-02-25 14:23 -------- d-----w- c:\program files\Google
2010-03-13 19:29 . 2009-11-01 18:55 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-03-12 00:59 . 2009-05-16 20:48 -------- d-----w- c:\users\Calvin\AppData\Roaming\NCH Software
2010-03-10 15:42 . 2008-10-16 02:19 -------- d-----w- c:\program files\Windows Mail
2010-03-10 15:10 . 2007-11-16 07:38 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-01 14:57 . 2009-11-23 23:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-01 14:56 . 2010-03-01 14:56 696832 ----a-w- c:\windows\isRS-000.tmp
2010-03-01 14:38 . 2009-06-05 13:58 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-03-01 06:28 . 2009-06-05 13:58 -------- d-----w- c:\program files\DivX
2010-02-27 05:34 . 2010-02-11 01:51 -------- d-----w- c:\users\Calvin\AppData\Roaming\gtk-2.0
2010-02-26 16:09 . 2010-02-01 02:52 -------- d-----w- c:\users\Calvin\AppData\Roaming\TortoiseSVN
2010-02-25 10:03 . 2009-11-01 18:55 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-02-24 17:16 . 2009-10-03 04:17 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-24 00:40 . 2010-02-24 00:40 -------- d-----w- c:\program files\Common Files\Java
2010-02-24 00:39 . 2007-09-05 11:16 -------- d-----w- c:\program files\Java
2010-02-23 00:51 . 2010-02-23 00:51 96896 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2010-02-23 00:50 . 2010-02-23 00:50 114984 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2010-02-23 00:47 . 2010-02-23 00:47 133512 ----a-w- c:\windows\system32\drivers\eamonm.sys
2010-02-20 17:50 . 2010-02-20 17:49 -------- d-----w- c:\program files\Pidgin
2010-02-19 22:59 . 2009-01-21 01:19 -------- d-----w- c:\users\Calvin\AppData\Roaming\LimeWire
2010-02-19 22:41 . 2008-07-04 20:09 142172 ---ha-w- c:\windows\system32\mlfcache.dat
2010-02-19 16:39 . 2008-11-04 13:37 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2010-02-15 02:41 . 2010-02-15 02:41 -------- d-----w- c:\program files\Maxis
2010-02-14 18:43 . 2007-12-20 06:42 -------- d-----w- c:\progra~2\NVIDIA
2010-02-14 05:52 . 2009-06-19 16:49 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-02-14 04:57 . 2010-02-14 04:49 -------- d-----w- c:\program files\Rockstar Games
2010-02-13 21:06 . 2009-01-28 00:33 -------- d-----w- c:\program files\iTunes
2010-02-13 00:22 . 2010-02-13 00:06 -------- d-----w- c:\program files\Common Files\AOL
2010-02-13 00:11 . 2010-02-13 00:07 -------- d-----w- c:\users\Calvin\AppData\Roaming\acccore
2010-02-11 10:50 . 2009-01-10 23:54 -------- d-----w- c:\users\Calvin\AppData\Roaming\BitTyrant
2010-02-11 01:47 . 2010-02-11 01:47 -------- d-----w- c:\program files\Common Files\GTK
2010-02-07 19:47 . 2010-02-07 19:47 -------- d-----w- c:\users\Mom\AppData\Roaming\Subversion
2010-02-02 00:51 . 2010-02-02 00:51 -------- d-----w- c:\program files\iPod
2010-02-02 00:51 . 2008-12-14 20:47 -------- d-----w- c:\program files\Common Files\Apple
2010-02-02 00:45 . 2008-01-22 01:20 -------- d-----w- c:\program files\QuickTime
2010-02-01 02:39 . 2010-02-01 02:39 -------- d-----w- c:\program files\Common Files\TortoiseOverlays
2010-02-01 02:39 . 2010-02-01 02:39 -------- d-----w- c:\program files\TortoiseSVN
2010-01-25 12:00 . 2010-02-23 22:16 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:00 . 2010-02-23 22:16 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:00 . 2010-02-23 22:16 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00 . 2010-02-23 22:16 471552 ----a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58 . 2010-02-23 22:16 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21 . 2010-02-23 22:16 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:21 . 2010-02-23 22:16 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:21 . 2010-02-23 22:16 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-25 08:21 . 2010-02-23 22:16 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-23 09:26 . 2010-02-23 22:17 2048 ----a-w- c:\windows\system32\tzres.dll
2010-01-08 00:07 . 2009-11-23 23:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-08 00:07 . 2009-11-23 23:42 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 15:39 . 2010-02-23 22:16 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-01-06 15:38 . 2010-02-23 22:16 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-01-06 15:38 . 2010-02-23 22:16 173056 ----a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-01-06 15:38 . 2010-02-23 22:16 542720 ----a-w- c:\windows\AppPatch\AcLayers.dll
2010-01-06 15:38 . 2010-02-23 22:16 458752 ----a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-01-06 15:38 . 2010-02-23 22:16 2159616 ----a-w- c:\windows\AppPatch\AcGenral.dll
2010-01-06 13:30 . 2010-02-23 22:16 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-01-02 06:38 . 2010-01-22 02:24 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 02:24 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 06:32 . 2010-01-22 02:24 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 04:57 . 2010-01-22 02:24 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2008-12-19 05:20 . 2008-12-18 21:41 2048 --sha-w- c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
2008-12-19 05:20 . 2008-12-18 21:41 2048 --sha-w- c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
2007-09-05 18:57 . 2007-09-05 18:54 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 03:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 03:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 03:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 03:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 03:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 03:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 03:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 03:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-01-19 03:12 86280 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2008-06-11 2645528]
"Pidgin"="c:\program files\Pidgin\pidgin.exe" [2010-02-16 45603]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"DLCQCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-16 106496]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-03 13683232]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-03 92704]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-01-08 429392]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-02-23 2140880]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-01-07 1468296]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWinKeys"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\M:\0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-11-02 08:38 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-09-06 22:09 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" /startup
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" -s
"Google Update"="c:\users\Calvin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"TrackerChecker2"="c:\program files\Tracker Checker 2\Tracker Checker 2.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 966\memcard.exe"
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe"
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"Windows Mobile-based device management"=%windir%\WindowsMobile\wmdSync.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
"UpdatePDRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\program files\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
"Adobe_ID0ENQBO"=c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
"dlcqmon.exe"="c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):41,78,12,b6,39,e3,c9,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1790924192-2944971578-4197939686-1000]
"EnableNotificationsRef"=dword:00000001
R2 gupdate1c9abf8da83d74e;Google Update Service (gupdate1c9abf8da83d74e);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-23 133104]
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
R3 JvBwAUOiwO;JvBwAUOiwO;c:\users\Calvin\Desktop\MQXDVKG [x]
R3 lfUKnytvc;lfUKnytvc;c:\users\Calvin\Desktop\PEYNY [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 MyBotDriver;MyBotDriver;c:\users\Calvin\Desktop\MyBotDriver.sys [x]
R3 npkycryp;npkycryp;c:\program files\Nexon\MapleStory\npkycryp.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2009-09-26 4639136]
R3 ROCKSTAR;ROCKSTAR;c:\users\Calvin\Desktop\Hack Trainer\ksysdrv.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-03-15 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-02-23 114984]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-02-23 133512]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-02-23 810120]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-02-23 96896]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-01-08 236368]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-02-25 1047880]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-01-08 19160]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-03-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-23 20:49]
2010-03-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-23 20:49]
2010-03-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1790924192-2944971578-4197939686-1011Core.job
- c:\users\Mom\AppData\Local\Google\Update\GoogleUpdate.exe [2009-03-21 01:23]
2010-03-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1790924192-2944971578-4197939686-1011UA.job
- c:\users\Mom\AppData\Local\Google\Update\GoogleUpdate.exe [2009-03-21 01:23]
2010-03-29 c:\windows\Tasks\User_Feed_Synchronization-{0FC40BB8-6DE1-4C3A-BFFC-6DC12BF1D332}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
2010-03-29 c:\windows\Tasks\User_Feed_Synchronization-{2B3DF531-795E-4B8F-852D-F9141689C0CD}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
2010-03-29 c:\windows\Tasks\User_Feed_Synchronization-{893D5EE2-FA10-4615-B039-239B29105AB9}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.facebook.com/mStart Page =
hxxp://sympatico.msn.ca/uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Download all with Free Download Manager
IE: Download selected with Free Download Manager
IE: Download video with Free Download Manager
IE: Download with Free Download Manager
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Save YouTube Video - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP4.htm
IE: Save YouTube Video as MP3 - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
IE: Se&nd to OneNote - /105
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: youtube.com\www
TCP: {A4317457-1F4F-4725-A304-0136F144D81B} = 208.67.222.222,64.59.144.92,208.67.220.220,64.59.144.93
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
DPF: CabBuilder -
hxxp://kiw.imgag.com/imgag/kiw/toolbar/ ... ontrol.cabDPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
BHO-{B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\progra~1\MICROS~2\Office14\URLREDIR.DLL
WebBrowser-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
HKLM-Run-BCSSync - c:\program files\Microsoft Office\Office14\BCSSync.exe
ActiveSetup-{I2NDSL15-0JO7-AK4F-1YU5-L1XDV608D046} - c:\windows\System32\Microsoft\Svchost.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-03-28 19:30
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x85DB21F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x8b5abd24
\Driver\ACPI -> acpi.sys @ 0x80f66d68
\Driver\atapi -> 0x85db21f8
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\JvBwAUOiwO]
"ImagePath"="\??\c:\users\Calvin\Desktop\MQXDVKG"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lfUKnytvc]
"ImagePath"="\??\c:\users\Calvin\Desktop\PEYNY"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1790924192-2944971578-4197939686-1000\Software\SecuROM\License information*]
"datasecu"=hex:cf,bc,8e,71,51,46,79,4e,be,ef,98,a1,1f,77,5f,4a,0d,82,23,a6,4b,
5a,4e,1a,ee,19,d8,79,c6,9e,cf,ef,0c,04,33,f0,52,f0,72,b2,ed,cc,9f,2f,f6,19,\
"rkeysecu"=hex:48,c8,d3,40,bc,b3,78,5b,8f,07,56,76,5f,7b,95,2d
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(3348)
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\Google\Update\1.2.183.23\GoogleCrashHandler.exe
c:\windows\system32\conime.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dlcqcoms.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\WUDFHost.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\windows\RtHDVCpl.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\vssvc.exe
.
**************************************************************************
.
Completion time: 2010-03-28 19:42:11 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-29 02:42
Pre-Run: 179,468,861,440 bytes free
Post-Run: 180,194,516,992 bytes free
- - End Of File - - 40CE8A833C5301ECE3191725399E2F26