Ty for the reply and sorry for the double threads i was just a bit paranoid. Also before i post the log i would like to know since i have two computer that i used to transfer files and do backups via Network Sharing with USB is there a chance that the other pc can have a keylogger and it keylogs both computers? If so should i do a hijack scan on the other pc?
And here is the combo log.
ComboFix 10-01-04.01 - Dean 01/11/2010 10:33:28.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.741 [GMT -5:00]
Running from: c:\users\Dean\Desktop\ComboFix.exe
AV: AVG Internet Security *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Internet Security *enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3678024670-894085293-2732371526-500
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\GammaTray.lnk
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-12-11 to 2010-01-11 )))))))))))))))))))))))))))))))
.
2010-01-11 15:42 . 2010-01-11 15:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-11 15:42 . 2010-01-11 15:43 -------- d-----w- c:\users\Dean\AppData\Local\temp
2010-01-11 01:07 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-01-11 01:07 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-01-11 01:07 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-01-11 00:55 . 2010-01-11 15:30 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-11 00:55 . 2010-01-11 15:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-01-11 00:54 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-01-11 00:51 . 2009-11-21 06:34 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-11 00:49 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
2010-01-10 19:49 . 2010-01-10 19:49 -------- d-----w- c:\program files\ESET
2010-01-10 19:27 . 2010-01-10 19:27 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2010-01-08 21:11 . 2010-01-08 21:16 55325 ----a-w- c:\windows\War3Unin.dat
2010-01-08 21:11 . 2010-01-08 21:15 2829 ----a-w- c:\windows\War3Unin.pif
2010-01-08 21:11 . 2010-01-08 21:15 139264 ----a-w- c:\windows\War3Unin.exe
2010-01-08 21:08 . 2010-01-08 21:28 -------- d-----w- c:\program files\Warcraft III
2010-01-04 01:49 . 2010-01-04 01:49 -------- d-----w- c:\program files\Redbana
2009-12-25 06:44 . 2009-12-25 06:44 -------- d-----w- C:\Windows.old
2009-12-24 02:53 . 1998-09-14 13:41 285216 ----a-w- c:\windows\system32\drivers\Onsio.sys
2009-12-24 02:53 . 1998-08-01 17:00 60928 ----a-w- c:\windows\system32\drivers\Smplscsi.sys
2009-12-24 02:53 . 1997-02-14 18:10 7680 ----a-w- c:\windows\system32\drivers\Onsreged.sys
2009-12-24 02:53 . 2009-12-24 02:53 -------- d-----w- C:\Kpcms
2009-12-24 02:53 . 2003-07-17 21:12 12499 ----a-w- c:\windows\system32\Msmusd7.dll
2009-12-24 02:53 . 2003-06-11 17:03 15396 ----a-w- c:\windows\system32\Msmusd5.dll
2009-12-24 02:53 . 2001-06-20 20:44 13962 ----a-w- c:\windows\system32\Msmusd6.dll
2009-12-24 02:53 . 2009-12-24 02:53 -------- d-----w- c:\program files\Microtek
2009-12-24 02:52 . 2009-12-24 02:52 -------- d-----w- C:\ScanWizard 5 V6.63
2009-12-19 15:59 . 2009-12-19 15:59 -------- d-----w- c:\programdata\Messenger Plus!
2009-12-19 07:55 . 2010-01-08 16:48 -------- d-----w- c:\users\Dean\AppData\Roaming\vlc
2009-12-19 07:54 . 2009-12-19 07:54 -------- d-----w- c:\program files\VideoLAN
2009-12-19 07:53 . 2009-12-19 07:53 -------- d-----w- c:\users\Dean\AppData\Roaming\ShopperReports3
2009-12-19 07:53 . 2009-12-19 07:53 -------- d-----w- c:\program files\ShopperReports3
2009-12-19 03:47 . 2009-12-19 03:47 -------- d-----w- c:\program files\Messenger Plus! Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-11 15:29 . 2009-12-09 20:03 -------- d-----w- c:\users\Dean\AppData\Roaming\Skype
2010-01-11 13:06 . 2009-12-09 20:11 -------- d-----w- c:\users\Dean\AppData\Roaming\skypePM
2010-01-11 01:25 . 2009-12-05 02:00 -------- d-----w- c:\users\Dean\AppData\Roaming\uTorrent
2010-01-11 01:20 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-11 01:06 . 2009-12-01 19:09 -------- d-----w- c:\programdata\Microsoft Help
2010-01-04 07:18 . 2009-12-04 16:34 70888 ----a-w- c:\users\Dean\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-04 01:49 . 2009-12-01 19:04 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-21 13:39 . 2009-12-11 03:26 2066200 ----a-w- c:\programdata\avg8\update\backup\avgcorex.dll
2009-12-18 18:23 . 2009-12-05 06:27 -------- d-----w- c:\program files\Left 4 Dead
2009-12-11 18:04 . 2009-12-05 19:49 393216 ----a-w- c:\programdata\NexonUS\NGM\NGMResource.dll
2009-12-11 18:04 . 2009-12-05 19:49 258352 ----a-w- c:\programdata\NexonUS\NGM\unicows.dll
2009-12-11 18:04 . 2009-12-05 19:49 118784 ----a-w- c:\programdata\NexonUS\NGM\nxgameus.dll
2009-12-11 18:04 . 2009-12-05 19:49 561152 ----a-w- c:\programdata\NexonUS\NGM\NGMDll.dll
2009-12-11 18:04 . 2009-12-05 19:49 167936 ----a-w- c:\programdata\NexonUS\NGM\NGM.exe
2009-12-11 04:08 . 2009-12-11 04:08 45056 ----a-r- c:\users\Dean\AppData\Roaming\Microsoft\Installer\{A6CCAEF5-F141-4BBE-A6DA-EA8A8362C7A6}\MapleStory.exe1_A6CCAEF5F1414BBEA6DAEA8A8362C7A6.exe
2009-12-11 04:08 . 2009-12-11 04:08 45056 ----a-r- c:\users\Dean\AppData\Roaming\Microsoft\Installer\{A6CCAEF5-F141-4BBE-A6DA-EA8A8362C7A6}\MapleStory.exe_A6CCAEF5F1414BBEA6DAEA8A8362C7A6.exe
2009-12-11 04:08 . 2009-12-11 04:08 10134 ----a-r- c:\users\Dean\AppData\Roaming\Microsoft\Installer\{A6CCAEF5-F141-4BBE-A6DA-EA8A8362C7A6}\ARPPRODUCTICON.exe
2009-12-11 03:46 . 2009-12-05 01:11 -------- d-----w- c:\programdata\PMB Files
2009-12-11 03:19 . 2009-12-05 00:41 -------- d-----w- c:\users\Dean\AppData\Roaming\Ventrilo
2009-12-11 02:41 . 2009-12-11 02:41 552 ----a-w- c:\users\Dean\AppData\Local\d3d8caps.dat
2009-12-10 16:09 . 2009-12-10 16:09 -------- d-sh--w- c:\programdata\SecuROM
2009-12-10 15:46 . 2009-12-10 15:46 -------- d-----w- c:\program files\2K Games
2009-12-10 15:43 . 2009-12-10 15:43 -------- d-----w- c:\program files\AGEIA Technologies
2009-12-09 20:11 . 2009-12-09 20:11 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-12-09 20:02 . 2009-12-09 20:02 -------- d-----w- c:\program files\tbh
2009-12-09 20:01 . 2009-12-09 20:01 -------- d-----r- c:\program files\Skype
2009-12-09 20:01 . 2009-12-09 20:01 -------- d-----w- c:\program files\Common Files\Skype
2009-12-09 20:01 . 2009-12-09 20:01 -------- d-----w- c:\programdata\Skype
2009-12-09 06:23 . 2009-12-08 01:30 -------- d-----w- c:\program files\SINS
2009-12-08 19:14 . 2009-12-08 19:14 -------- d-----w- c:\users\Dean\AppData\Roaming\Publish Providers
2009-12-08 19:14 . 2009-12-05 06:01 -------- d-----w- c:\users\Dean\AppData\Roaming\Sony
2009-12-08 19:06 . 2009-12-05 06:00 -------- d-----w- c:\programdata\Sony
2009-12-08 19:05 . 2009-12-05 06:00 -------- d-----w- c:\program files\Sony
2009-12-08 18:56 . 2009-12-08 18:42 -------- d-----w- c:\users\Dean\AppData\Roaming\DAEMON Tools Lite
2009-12-08 18:43 . 2009-12-08 18:43 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-12-08 18:43 . 2009-12-08 01:33 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-08 18:42 . 2009-12-08 01:49 -------- d-----w- c:\programdata\DAEMON Tools Lite
2009-12-08 01:33 . 2009-12-08 01:33 -------- d-----w- c:\users\Dean\AppData\Roaming\DAEMON Tools Pro
2009-12-08 01:30 . 2009-12-06 22:58 -------- d-----w- c:\program files\Stardock Games
2009-12-07 20:01 . 2009-12-07 19:42 -------- d-----w- c:\users\Dean\AppData\Roaming\GameRanger
2009-12-07 19:41 . 2009-12-07 19:28 -------- d-----w- c:\program files\GameSpy Arcade
2009-12-07 17:45 . 2006-11-02 12:37 -------- d-----w- c:\program files\Microsoft Games
2009-12-07 08:02 . 2009-12-05 05:52 -------- d-----w- c:\program files\Microsoft SQL Server
2009-12-07 01:10 . 2009-12-07 01:10 -------- d-----w- c:\programdata\Ironclad Games
2009-12-06 14:41 . 2009-12-06 14:41 680 ----a-w- c:\users\Dean\AppData\Local\d3d9caps.dat
2009-12-06 14:29 . 2009-12-01 19:10 -------- d-----w- c:\program files\Microsoft Works
2009-12-06 08:43 . 2009-12-06 08:43 -------- d-----w- c:\program files\Windows Portable Devices
2009-12-06 08:43 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-12-06 08:43 . 2009-12-06 08:43 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-12-06 08:04 . 2009-12-06 08:04 -------- d-----w- c:\program files\MSXML 4.0
2009-12-05 20:06 . 2009-12-05 20:06 -------- d-----w- c:\programdata\Nexon
2009-12-05 20:06 . 2009-12-05 19:49 -------- d-----w- c:\programdata\NexonUS
2009-12-05 19:49 . 2009-12-05 19:49 90112 ----a-w- c:\programdata\NexonUS\NGM\npNxGameUS.dll
2009-12-05 06:17 . 2009-12-05 01:33 -------- d-----w- c:\users\Dean\AppData\Roaming\Winamp
2009-12-05 06:03 . 2009-12-05 05:52 -------- d-----w- c:\program files\Sony Setup
2009-12-05 05:54 . 2009-12-01 19:10 -------- d-----w- c:\program files\Microsoft.NET
2009-12-05 05:40 . 2009-12-05 05:40 -------- d-----w- c:\programdata\FLEXnet
2009-12-05 05:36 . 2009-12-01 19:08 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-05 05:35 . 2009-12-05 05:35 -------- d-----w- c:\program files\Adobe Media Player
2009-12-05 05:34 . 2009-12-05 05:34 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-12-05 05:31 . 2009-12-05 05:31 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-12-05 05:15 . 2009-12-05 05:14 -------- d-----w- c:\program files\MagicISO
2009-12-05 05:10 . 2009-12-05 05:10 -------- d-----w- c:\users\Dean\AppData\Roaming\CyberLink
2009-12-05 05:10 . 2009-12-05 05:10 -------- d-----w- c:\programdata\CyberLink
2009-12-05 02:01 . 2009-12-05 02:01 -------- d-----w- c:\program files\uTorrent
2009-12-05 01:50 . 2009-12-05 01:50 -------- d-----w- c:\users\Dean\AppData\Roaming\AusLogics
2009-12-05 01:43 . 2009-12-05 01:43 -------- d-----w- c:\program files\Auslogics
2009-12-05 01:33 . 2009-12-05 01:33 -------- d-----w- c:\program files\Winamp
2009-12-05 01:33 . 2009-12-05 01:33 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-12-05 01:18 . 2009-12-05 01:18 -------- d-----w- c:\program files\SEC
2009-12-05 01:14 . 2009-12-05 01:14 -------- d-----w- c:\program files\MagicTune Premium
2009-12-05 01:14 . 2009-12-05 01:14 -------- d-----w- c:\users\Dean\AppData\Roaming\InstallShield
2009-12-05 01:11 . 2009-12-05 01:11 -------- d-----w- c:\program files\Pando Networks
2009-12-05 01:02 . 2009-12-05 00:59 -------- d-----w- c:\program files\Windows Live
2009-12-05 01:01 . 2009-12-05 01:01 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-12-05 01:00 . 2009-12-05 01:00 -------- d-----w- c:\program files\Microsoft
2009-12-05 01:00 . 2009-12-05 01:00 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-12-05 00:55 . 2009-12-05 00:55 -------- d-----w- c:\program files\Common Files\Windows Live
2009-12-05 00:34 . 2009-12-01 19:13 -------- d-----w- c:\programdata\McAfee
2009-12-05 00:29 . 2009-12-05 00:18 -------- d-----w- c:\programdata\avg8
2009-12-05 00:29 . 2009-12-05 00:18 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-05 00:29 . 2009-12-05 00:18 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-05 00:29 . 2009-12-05 00:18 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-05 00:29 . 2009-12-05 00:29 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-05 00:29 . 2009-12-05 00:29 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-12-05 00:18 . 2009-12-05 00:18 -------- d-----w- c:\program files\AVG
2009-12-04 23:54 . 2009-12-04 23:54 -------- d-----w- c:\programdata\Downloaded Installations
2009-12-04 22:02 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-12-04 22:02 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-12-04 22:02 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-12-04 22:02 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-12-04 22:02 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-12-04 22:02 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-12-04 22:00 . 2009-12-04 22:00 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-12-04 21:06 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-12-04 21:06 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-12-04 16:58 . 2009-12-01 19:12 -------- d-----w- c:\program files\Google
2009-12-04 16:52 . 2009-12-04 16:52 -------- d-----w- c:\users\Dean\AppData\Roaming\Logitech
2009-12-04 16:51 . 2009-12-04 16:51 -------- d-----w- c:\users\Dean\AppData\Roaming\Leadertech
2009-12-04 16:51 . 2009-12-04 16:49 -------- d-----w- c:\program files\Common Files\Logishrd
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-12-05 289584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SigmatelSysTrayApp"="sttray.exe" [2006-11-02 303104]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-04-06 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-06 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-06 81920]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-11 2043160]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-12-4 809488]
Microtek Scanner Finder.lnk - c:\program files\Microtek\ScanWizard 5\ScannerFinder.exe [2009-12-23 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NCProTray.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\NCProTray.lnk
backup=c:\windows\pss\NCProTray.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Dean^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
path=c:\users\Dean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
backup=c:\windows\pss\Logitech . Product Registration.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Dean^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Sins of a Solar Empire Launcher.lnk]
path=c:\users\Dean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sins of a Solar Empire Launcher.lnk
backup=c:\windows\pss\Sins of a Solar Empire Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 12:58 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigFix]
2006-11-17 00:04 2348584 ----a-w- c:\program files\BigFix\bigfix.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCUTRAYICON]
2006-11-18 15:01 182744 ----a-w- c:\program files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-10-30 11:57 369200 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2009-12-04 16:36 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ledpointer]
2006-11-10 00:01 5585408 ----a-w- c:\windows\CNYHKey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoLed]
2006-11-10 00:15 53248 ----a-w- c:\windows\ModLEDKey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NMSSupport]
2006-09-26 18:56 423424 ----a-w- c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-11-02 20:38 303104 ----a-w- c:\windows\sttray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tbhSystray]
2010-01-11 15:31 492840 ----a-w- c:\program files\tbh\base\bin\tbhSystray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2009-12-05 02:01 289584 ----a-w- c:\program files\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 ----a-w- c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2009-04-11 04:28 2153472 ----a-w- c:\windows\System32\oobefldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):9f,63,2b,4f,2e,75,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3678024670-894085293-2732371526-500]
"EnableNotificationsRef"=dword:00000002
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [12/4/2009 7:18 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [12/4/2009 7:29 PM 108552]
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [5/14/2009 3:47 PM 107256]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [12/4/2009 7:29 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/4/2009 7:29 PM 297752]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [5/14/2009 3:47 PM 731840]
R2 epfwwfpr;epfwwfpr;c:\windows\System32\drivers\epfwwfpr.sys [5/14/2009 3:49 PM 93312]
R2 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\System32\drivers\nmsgopro.sys [9/27/2006 7:37 PM 28672]
R2 nmsunidr;UniDriver for NMS;c:\windows\System32\drivers\nmsunidr.sys [10/19/2006 6:49 PM 7424]
R2 tbhMonitor.exe;The Browser Highlighter Monitor;c:\program files\tbh\monitor\bin\tbhMonitor.exe [10/22/2009 1:57 PM 70952]
R3 IntelDH;IntelDH Driver;c:\windows\System32\drivers\IntelDH.sys [12/1/2009 1:58 PM 5504]
R3 xcbdaNtsc;ViXS Tuner Card (NTSC);c:\windows\System32\drivers\xcbda.sys [12/1/2009 2:42 PM 147328]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [12/7/2009 8:33 PM 691696]
S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [10/29/2006 12:03 PM 208896]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [12/4/2009 12:33 PM 21504]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12/1/2009 2:12 PM 30192]
S3 MSSQL$SONY_MEDIAMGR2;SQL Server (SONY_MEDIAMGR2);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [5/27/2009 3:27 AM 29262680]
S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [11/2/2006 5:25 AM 2589184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.gateway.com/g/startpage.html ... &M=GM5457EmStart Page =
hxxp://www.gateway.com/g/startpage.html ... &M=GM5457EuInternet Settings,ProxyOverride = <local>
TCP: {5CEFEF1B-4110-48FB-85C4-C235D38A3217} = 192.168.1.1
FF - ProfilePath - c:\users\Dean\AppData\Roaming\Mozilla\Firefox\Profiles\jfy60p36.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\users\Dean\AppData\Roaming\Mozilla\Firefox\Profiles\jfy60p36.default\extensions\browserhighlighter@ebay.com\components\Shim.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-mcagent_exe - c:\program files\McAfee.com\Agent\mcagent.exe
MSConfigStartUp-MskAgentexe - c:\program files\McAfee\MSK\MskAgent.exe
MSConfigStartUp-NapsterShell - c:\program files\Napster\napster.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-11 10:42
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(672)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2010-01-11 10:45:10
ComboFix-quarantined-files.txt 2010-01-11 15:45
Pre-Run: 301,906,710,528 bytes free
Post-Run: 301,958,610,944 bytes free
- - End Of File - - 346160B8099B8035B783A2563622776E