ComboFix 10-06-27.02 - Rexel 06/27/2010 13:43:37.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.1377 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\sysmon
c:\windows\TEMP\logishrd\LVPrcInj03.dll
c:\windows\xpsp1hfm.log
.
((((((((((((((((((((((((( Files Created from 2010-05-27 to 2010-06-27 )))))))))))))))))))))))))))))))
.
2010-06-27 18:55 . 2010-06-27 18:56 -------- d-----w- c:\users\Rexel\AppData\Local\VirtualStore
2010-06-27 18:51 . 2010-06-27 18:51 -------- d-----w- c:\users\Roselle\AppData\Local\temp
2010-06-27 18:51 . 2010-06-27 18:51 -------- d-----w- c:\users\laureanofamily\AppData\Local\temp
2010-06-27 18:51 . 2010-06-27 18:56 -------- d-----w- c:\users\Rexel\AppData\Local\temp
2010-06-27 18:51 . 2010-06-27 18:51 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-06-27 18:51 . 2010-06-27 18:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-27 18:33 . 2010-06-27 18:33 -------- d-----w- c:\program files\ERUNT
2010-06-27 17:29 . 2010-06-27 17:30 -------- d-----w- C:\rsit
2010-06-27 17:27 . 2010-06-27 17:27 -------- d-----w- c:\programdata\Avira
2010-06-27 17:27 . 2010-06-27 17:27 -------- d-----w- c:\program files\Avira
2010-06-27 17:27 . 2010-03-01 15:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-06-27 17:27 . 2010-02-16 19:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-06-27 17:27 . 2009-05-11 17:49 51992 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-06-27 17:27 . 2009-05-11 17:49 17016 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-06-27 17:03 . 2010-06-27 17:03 -------- d-----w- c:\users\Rexel\AppData\Roaming\Malwarebytes
2010-06-27 17:02 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-27 17:02 . 2010-06-27 17:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-27 17:02 . 2010-06-27 17:02 -------- d-----w- c:\programdata\Malwarebytes
2010-06-27 17:02 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-27 03:15 . 2010-06-27 17:30 -------- d-----w- c:\program files\Trend Micro
2010-06-25 22:06 . 2010-06-25 22:06 -------- d-----w- c:\users\Roselle\AppData\Roaming\Exent Technologies
2010-06-25 21:08 . 2010-06-25 21:08 -------- d-----w- c:\users\laureanofamily\AppData\Local\Yahoo
2010-06-25 21:08 . 2010-06-25 21:08 -------- d-----w- c:\users\laureanofamily\AppData\Roaming\Yahoo!
2010-06-25 17:55 . 2010-06-25 17:55 204704 ---ha-w- c:\windows\system32\mlfcache.dat
2010-06-25 12:45 . 2010-06-25 12:45 -------- d-----w- c:\users\Rexel\AppData\Local\Yahoo
2010-06-25 12:45 . 2010-06-25 12:45 -------- d-----w- c:\users\Rexel\AppData\Roaming\Yahoo!
2010-06-25 02:47 . 2010-06-25 03:00 -------- d-----w- c:\users\Roselle\AppData\Local\Yahoo
2010-06-25 02:46 . 2010-06-25 02:46 -------- d-----w- c:\users\Roselle\AppData\Local\Yahoo!
2010-06-25 02:45 . 2010-06-25 11:08 -------- d-----w- c:\programdata\Yahoo! Companion
2010-06-25 02:45 . 2010-06-25 02:47 -------- d-----w- c:\users\Roselle\AppData\Roaming\Yahoo!
2010-06-25 02:45 . 2010-06-25 02:45 -------- d-----w- c:\programdata\Yahoo!
2010-06-25 02:43 . 2010-06-25 02:45 -------- d-----w- c:\program files\Yahoo!
2010-06-24 14:03 . 2009-11-08 15:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-24 14:03 . 2009-11-08 15:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-24 14:03 . 2009-11-08 15:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-24 14:03 . 2009-11-08 15:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-24 14:03 . 2009-11-08 15:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-24 05:00 . 2010-06-24 05:00 -------- d-----w- c:\program files\iPod
2010-06-24 05:00 . 2010-06-24 05:00 -------- d-----w- c:\program files\iTunes
2010-06-24 04:55 . 2010-06-24 04:55 -------- d-----w- c:\program files\Bonjour
2010-06-23 22:50 . 2010-04-16 16:43 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-23 22:50 . 2010-04-16 14:39 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-23 21:40 . 2010-06-23 21:40 -------- d-----w- c:\users\Roselle\Office Genuine Advantage
2010-06-23 03:20 . 2010-06-23 03:20 -------- d-----w- c:\programdata\Motive
2010-06-22 22:32 . 2010-06-22 22:32 -------- d-----w- c:\users\Rexel\AppData\Local\Apple
2010-06-20 18:52 . 2010-06-20 18:52 -------- d-----w- c:\program files\Windows Portable Devices
2010-06-20 18:35 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2010-06-20 18:34 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-06-20 18:34 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-06-20 18:34 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-06-20 04:44 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-06-19 22:58 . 2010-06-19 22:59 -------- d-----w- c:\windows\system32\ca-ES
2010-06-19 22:58 . 2010-06-19 22:59 -------- d-----w- c:\windows\system32\eu-ES
2010-06-19 22:58 . 2010-06-19 22:59 -------- d-----w- c:\windows\system32\vi-VN
2010-06-19 22:04 . 2010-06-19 22:04 -------- d-----w- c:\windows\system32\EventProviders
2010-06-19 02:39 . 2010-06-27 01:49 -------- d-----w- c:\users\Roselle\Tracing
2010-06-19 01:26 . 2010-06-27 16:26 -------- d-----w- c:\users\laureanofamily\Tracing
2010-06-17 06:07 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2010-06-16 18:02 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2010-06-16 18:02 . 2009-04-11 06:28 1081344 ----a-w- c:\windows\system32\SLCExt.dll
2010-06-16 18:02 . 2009-04-11 06:27 3408896 ----a-w- c:\windows\system32\SLsvc.exe
2010-06-16 18:02 . 2009-04-11 06:28 2134528 ----a-w- c:\windows\system32\FunctionDiscoveryFolder.dll
2010-06-16 18:02 . 2009-04-11 06:27 65536 ----a-w- c:\windows\system32\DevicePairingWizard.exe
2010-06-16 18:02 . 2009-04-11 05:03 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2010-06-16 18:00 . 2009-04-11 06:28 29184 ----a-w- c:\windows\system32\wsepno.dll
2010-06-16 17:46 . 2010-01-29 15:40 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-06-16 17:46 . 2010-04-05 17:01 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-16 17:46 . 2010-04-23 14:13 2048 ----a-w- c:\windows\system32\tzres.dll
2010-06-16 17:46 . 2010-05-26 14:47 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-06-16 17:46 . 2010-05-26 17:06 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-16 04:32 . 2010-06-16 04:32 -------- d-----w- c:\users\Rexel\AppData\Roaming\Ventrilo
2010-06-15 02:22 . 2010-06-15 02:37 -------- d-----w- c:\users\Roselle\AppData\Roaming\Righteous Kill
2010-06-14 02:37 . 2010-06-14 02:37 -------- d-----w- c:\users\Guest\AppData\Local\AskToolbar
2010-06-14 02:37 . 2010-06-14 02:37 -------- d-----w- c:\users\Guest\AppData\Local\Google
2010-06-13 19:21 . 2010-06-25 17:55 -------- d-----w- c:\users\Rexel\AppData\Local\Apple Computer
2010-06-13 04:00 . 2010-06-13 04:00 -------- d-----w- c:\windows\system32\F01744F2FC1
2010-06-13 04:00 . 2010-06-13 04:00 -------- d-----w- c:\windows\system32\F016D353D7B
2010-06-13 04:00 . 2010-06-13 04:00 -------- d-----w- c:\windows\system32\F0157A43D16
2010-06-13 03:54 . 2010-06-25 17:55 -------- d-----w- c:\users\Rexel\AppData\Roaming\Apple Computer
2010-06-13 03:54 . 2010-06-13 03:54 125888 ----a-w- c:\users\Rexel\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-13 01:13 . 2010-06-13 01:13 -------- d-----w- c:\users\Rexel\AppData\Local\Blizzard Entertainment
2010-06-13 01:05 . 2010-06-26 04:09 -------- d-----w- c:\users\Rexel\AppData\Local\Google
2010-06-13 01:03 . 2010-06-13 01:03 -------- d-----w- c:\windows\system32\F013AAE60B7
2010-06-13 00:49 . 2010-06-13 00:49 -------- d-----w- c:\windows\system32\F01330A791A
2010-06-13 00:48 . 2010-06-13 00:48 -------- d-----w- c:\windows\system32\F011FD80175
2010-06-13 00:48 . 2010-06-13 00:48 -------- d-----w- c:\windows\system32\F010428152A
2010-06-13 00:48 . 2010-06-13 00:48 -------- d-----w- c:\users\Public\Games.edfad0a4.temp
2010-06-12 11:26 . 2010-06-12 11:26 -------- d-----w- c:\users\Public\Games.temp
2010-06-10 16:51 . 2010-06-10 16:51 -------- d-----w- c:\users\laureanofamily\AppData\Local\AskToolbar
2010-06-10 00:58 . 2010-06-24 17:59 64 ----a-w- c:\windows\GPlrLanc.dat
2010-06-10 00:58 . 2010-06-24 17:59 -------- d-----w- c:\programdata\Free Ride Games
2010-06-08 00:34 . 2010-06-08 00:34 -------- d-----w- c:\users\laureanofamily\AppData\Local\Google
2010-06-07 12:19 . 2010-06-07 12:20 -------- d-----w- c:\users\Roselle\AppData\Roaming\Farm Mania 2
2010-06-07 12:13 . 2010-06-09 03:15 -------- d-----w- c:\users\Roselle\AppData\Local\Google
2010-06-07 12:05 . 2010-06-26 04:09 -------- d-----w- c:\program files\Google
2010-06-07 12:05 . 2010-06-07 12:05 -------- d-----w- c:\windows\system32\Adobe
2010-06-04 17:25 . 2010-06-04 17:25 -------- d-----w- c:\program files\ATT
2010-06-02 00:39 . 2010-06-02 00:39 -------- d-----w- c:\users\Roselle\AppData\Roaming\Go-Go Gourmet Chef of the Year
2010-06-01 21:00 . 2010-06-07 23:48 -------- d-----w- c:\users\Roselle\AppData\Roaming\Oberon Media
2010-06-01 02:52 . 2010-06-01 02:52 -------- d-----w- c:\programdata\GameHouse
2010-05-31 20:51 . 2010-05-31 20:51 -------- d-----w- c:\programdata\Meridian93
2010-05-31 20:51 . 2010-05-31 20:51 -------- d-----w- c:\users\Roselle\AppData\Roaming\Meridian93
2010-05-31 20:51 . 2010-05-31 20:51 -------- d-----w- c:\users\Roselle\AppData\Roaming\game
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-27 18:56 . 2010-03-26 03:36 88975 ----a-w- c:\programdata\nvModes.dat
2010-06-27 18:56 . 2010-03-27 01:12 -------- d-----w- c:\program files\Dl_cats
2010-06-26 13:01 . 2010-03-26 20:18 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-06-26 04:07 . 2010-04-24 03:33 -------- d-----w- c:\program files\Yahoo! Games
2010-06-26 04:07 . 2010-05-28 04:16 -------- d-----w- c:\program files\Ask.com
2010-06-26 04:06 . 2010-03-28 04:16 -------- d-----w- c:\program files\MSN Games
2010-06-26 04:05 . 2010-04-25 00:53 -------- d-----w- c:\programdata\Oberon Media
2010-06-26 03:56 . 2010-03-26 03:41 -------- d-----w- c:\program files\Common Files\InstallShield
2010-06-25 21:11 . 2010-03-26 01:40 -------- d-----w- c:\programdata\LogiShrd
2010-06-25 11:08 . 2010-04-16 22:36 -------- d-----w- c:\program files\Microsoft.NET
2010-06-24 05:00 . 2010-03-26 19:55 -------- d-----w- c:\program files\Common Files\Apple
2010-06-24 04:51 . 2010-03-26 19:56 -------- d-----w- c:\program files\Safari
2010-06-23 21:44 . 2010-04-08 22:25 86 ----a-w- c:\users\Roselle\AppData\Roaming\wklnhst.dat
2010-06-22 19:07 . 2010-05-28 04:20 -------- d-----w- c:\users\Roselle\AppData\Roaming\LimeWire
2010-06-20 18:52 . 2010-06-20 18:52 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-06-20 18:52 . 2010-06-20 18:52 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-06-19 22:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-06-19 22:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-06-19 22:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-06-19 22:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-06-19 22:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-06-19 22:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-06-19 22:59 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-19 22:58 . 2010-06-19 22:58 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2010-06-19 22:58 . 2010-06-19 22:58 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2010-06-17 05:54 . 2010-03-26 02:32 330 ----a-w- c:\users\laureanofamily\AppData\Roaming\wklnhst.dat
2010-06-16 11:06 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2010-06-16 11:06 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2010-06-14 02:38 . 2010-05-12 22:18 -------- d-----w- c:\users\Guest\AppData\Roaming\Apple Computer
2010-06-10 01:01 . 2010-05-02 04:25 -------- d-----w- c:\users\Roselle\AppData\Roaming\PlayFirst
2010-06-10 01:01 . 2010-05-02 04:25 -------- d-----w- c:\programdata\PlayFirst
2010-06-07 12:18 . 2010-03-28 04:16 -------- d-----w- c:\program files\Oberon Media
2010-06-06 00:41 . 2010-03-26 21:00 -------- d-----w- c:\users\laureanofamily\AppData\Roaming\Apple Computer
2010-05-28 04:23 . 2010-05-28 04:15 -------- d-----w- c:\users\Roselle\AppData\Roaming\Apple Computer
2010-05-28 04:19 . 2010-05-28 04:19 -------- d-----w- c:\program files\Common Files\Java
2010-05-28 04:19 . 2010-05-28 04:19 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-28 04:19 . 2010-05-28 04:19 -------- d-----w- c:\program files\Java
2010-05-28 04:15 . 2010-05-28 04:14 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-05-28 04:14 . 2010-03-26 19:56 -------- d-----w- c:\programdata\Apple Computer
2010-05-28 04:13 . 2010-05-28 04:12 -------- d-----w- c:\program files\QuickTime
2010-05-28 04:12 . 2010-05-28 04:12 -------- d-----w- c:\program files\Apple Software Update
2010-05-26 20:51 . 2010-05-26 20:10 -------- d-----w- c:\programdata\FarmFrenzy3_Russia
2010-05-26 04:20 . 2010-05-26 04:20 -------- d-----w- c:\users\Roselle\AppData\Roaming\Flood Light Games
2010-05-26 04:20 . 2010-05-26 04:20 -------- d-----w- c:\programdata\Flood Light Games
2010-05-26 04:06 . 2010-05-26 04:05 -------- d-----w- c:\programdata\Deadtime Stories
2010-05-26 03:20 . 2010-05-21 23:31 -------- d-----w- c:\users\Roselle\AppData\Roaming\Artogon
2010-05-24 03:41 . 2010-05-24 03:41 -------- d-----w- c:\users\Roselle\AppData\Roaming\Oberon
2010-05-23 05:47 . 2010-05-23 05:47 -------- d-----w- c:\programdata\SpecialBit
2010-05-23 02:10 . 2010-05-23 02:10 -------- d-----w- c:\users\Roselle\AppData\Roaming\Boolat Games
2010-05-23 01:28 . 2010-05-23 01:28 -------- d-----w- c:\users\Roselle\AppData\Roaming\LaJangada
2010-05-23 00:29 . 2010-05-23 00:29 -------- d-----w- c:\users\Roselle\AppData\Roaming\Big Fish Games
2010-05-22 04:31 . 2010-05-22 04:31 -------- d-----w- c:\users\Roselle\AppData\Roaming\Namco
2010-05-21 19:14 . 2010-03-26 02:03 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 21:35 . 2010-05-18 21:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 21:35 . 2010-05-18 21:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-16 04:41 . 2010-05-16 04:41 -------- d-----w- c:\users\Roselle\AppData\Roaming\GameInvest
2010-05-10 20:48 . 2010-04-05 22:26 125888 ----a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-04 05:59 . 2010-06-16 17:45 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-16 17:45 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 05:55 . 2010-06-16 17:45 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 04:31 . 2010-06-16 17:45 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-01 14:13 . 2010-06-16 17:45 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 12:01 . 2010-04-29 12:01 10978776 ----a-w- c:\programdata\SPL8841.tmp
2010-04-29 06:20 . 2010-04-29 06:20 10978776 ----a-w- c:\programdata\SPL426.tmp
2010-04-28 19:54 . 2010-04-28 19:53 -------- d-----w- c:\programdata\Go Go Gourmet
2010-04-19 11:25 . 2010-03-26 01:15 125888 ----a-w- c:\users\laureanofamily\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-19 03:51 . 2010-04-08 22:12 125888 ----a-w- c:\users\Roselle\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-31 06:00 . 2010-03-31 06:00 86016 ----a-w- c:\windows\system32\frapsvid.dll
2007-02-21 19:49 . 2007-02-21 19:49 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" [2009-07-16 5458704]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-06-26 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 304008]
"DLCXCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0360.0\mswinext.exe" [2009-11-18 240480]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\wlanapi.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):e2,6f,78,e1,03,10,cb,01
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-26 136176]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
S2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe [2006-11-04 537480]
S3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 251904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LPDService REG_MULTI_SZ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-26 04:09]
2010-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-26 04:09]
2010-06-26 c:\windows\Tasks\User_Feed_Synchronization-{86B33D2A-102E-4517-904C-BF5E2454C7EF}.job
- c:\windows\system32\msfeedssync.exe [2010-06-16 04:30]
2010-06-27 c:\windows\Tasks\User_Feed_Synchronization-{9E7639ED-B112-4179-B7CC-E00746ACDA36}.job
- c:\windows\system32\msfeedssync.exe [2010-06-16 04:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
LSP: c:\windows\system32\wpclsp.dll
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(5972)
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2010-06-27 14:06:01 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-27 19:05
Pre-Run: 107,039,059,968 bytes free
Post-Run: 109,407,997,952 bytes free
- - End Of File - - 167FA9C94326CF6CEFF01DD5F7BBF764
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.1377 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\sysmon
c:\windows\TEMP\logishrd\LVPrcInj03.dll
c:\windows\xpsp1hfm.log
.
((((((((((((((((((((((((( Files Created from 2010-05-27 to 2010-06-27 )))))))))))))))))))))))))))))))
.
2010-06-27 18:55 . 2010-06-27 18:56 -------- d-----w- c:\users\Rexel\AppData\Local\VirtualStore
2010-06-27 18:51 . 2010-06-27 18:51 -------- d-----w- c:\users\Roselle\AppData\Local\temp
2010-06-27 18:51 . 2010-06-27 18:51 -------- d-----w- c:\users\laureanofamily\AppData\Local\temp
2010-06-27 18:51 . 2010-06-27 18:56 -------- d-----w- c:\users\Rexel\AppData\Local\temp
2010-06-27 18:51 . 2010-06-27 18:51 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-06-27 18:51 . 2010-06-27 18:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-27 18:33 . 2010-06-27 18:33 -------- d-----w- c:\program files\ERUNT
2010-06-27 17:29 . 2010-06-27 17:30 -------- d-----w- C:\rsit
2010-06-27 17:27 . 2010-06-27 17:27 -------- d-----w- c:\programdata\Avira
2010-06-27 17:27 . 2010-06-27 17:27 -------- d-----w- c:\program files\Avira
2010-06-27 17:27 . 2010-03-01 15:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-06-27 17:27 . 2010-02-16 19:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-06-27 17:27 . 2009-05-11 17:49 51992 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-06-27 17:27 . 2009-05-11 17:49 17016 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-06-27 17:03 . 2010-06-27 17:03 -------- d-----w- c:\users\Rexel\AppData\Roaming\Malwarebytes
2010-06-27 17:02 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-27 17:02 . 2010-06-27 17:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-27 17:02 . 2010-06-27 17:02 -------- d-----w- c:\programdata\Malwarebytes
2010-06-27 17:02 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-27 03:15 . 2010-06-27 17:30 -------- d-----w- c:\program files\Trend Micro
2010-06-25 22:06 . 2010-06-25 22:06 -------- d-----w- c:\users\Roselle\AppData\Roaming\Exent Technologies
2010-06-25 21:08 . 2010-06-25 21:08 -------- d-----w- c:\users\laureanofamily\AppData\Local\Yahoo
2010-06-25 21:08 . 2010-06-25 21:08 -------- d-----w- c:\users\laureanofamily\AppData\Roaming\Yahoo!
2010-06-25 17:55 . 2010-06-25 17:55 204704 ---ha-w- c:\windows\system32\mlfcache.dat
2010-06-25 12:45 . 2010-06-25 12:45 -------- d-----w- c:\users\Rexel\AppData\Local\Yahoo
2010-06-25 12:45 . 2010-06-25 12:45 -------- d-----w- c:\users\Rexel\AppData\Roaming\Yahoo!
2010-06-25 02:47 . 2010-06-25 03:00 -------- d-----w- c:\users\Roselle\AppData\Local\Yahoo
2010-06-25 02:46 . 2010-06-25 02:46 -------- d-----w- c:\users\Roselle\AppData\Local\Yahoo!
2010-06-25 02:45 . 2010-06-25 11:08 -------- d-----w- c:\programdata\Yahoo! Companion
2010-06-25 02:45 . 2010-06-25 02:47 -------- d-----w- c:\users\Roselle\AppData\Roaming\Yahoo!
2010-06-25 02:45 . 2010-06-25 02:45 -------- d-----w- c:\programdata\Yahoo!
2010-06-25 02:43 . 2010-06-25 02:45 -------- d-----w- c:\program files\Yahoo!
2010-06-24 14:03 . 2009-11-08 15:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-24 14:03 . 2009-11-08 15:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-24 14:03 . 2009-11-08 15:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-24 14:03 . 2009-11-08 15:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-24 14:03 . 2009-11-08 15:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-24 05:00 . 2010-06-24 05:00 -------- d-----w- c:\program files\iPod
2010-06-24 05:00 . 2010-06-24 05:00 -------- d-----w- c:\program files\iTunes
2010-06-24 04:55 . 2010-06-24 04:55 -------- d-----w- c:\program files\Bonjour
2010-06-23 22:50 . 2010-04-16 16:43 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-23 22:50 . 2010-04-16 14:39 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-23 21:40 . 2010-06-23 21:40 -------- d-----w- c:\users\Roselle\Office Genuine Advantage
2010-06-23 03:20 . 2010-06-23 03:20 -------- d-----w- c:\programdata\Motive
2010-06-22 22:32 . 2010-06-22 22:32 -------- d-----w- c:\users\Rexel\AppData\Local\Apple
2010-06-20 18:52 . 2010-06-20 18:52 -------- d-----w- c:\program files\Windows Portable Devices
2010-06-20 18:35 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2010-06-20 18:34 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-06-20 18:34 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-06-20 18:34 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-06-20 04:44 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-06-19 22:58 . 2010-06-19 22:59 -------- d-----w- c:\windows\system32\ca-ES
2010-06-19 22:58 . 2010-06-19 22:59 -------- d-----w- c:\windows\system32\eu-ES
2010-06-19 22:58 . 2010-06-19 22:59 -------- d-----w- c:\windows\system32\vi-VN
2010-06-19 22:04 . 2010-06-19 22:04 -------- d-----w- c:\windows\system32\EventProviders
2010-06-19 02:39 . 2010-06-27 01:49 -------- d-----w- c:\users\Roselle\Tracing
2010-06-19 01:26 . 2010-06-27 16:26 -------- d-----w- c:\users\laureanofamily\Tracing
2010-06-17 06:07 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2010-06-16 18:02 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2010-06-16 18:02 . 2009-04-11 06:28 1081344 ----a-w- c:\windows\system32\SLCExt.dll
2010-06-16 18:02 . 2009-04-11 06:27 3408896 ----a-w- c:\windows\system32\SLsvc.exe
2010-06-16 18:02 . 2009-04-11 06:28 2134528 ----a-w- c:\windows\system32\FunctionDiscoveryFolder.dll
2010-06-16 18:02 . 2009-04-11 06:27 65536 ----a-w- c:\windows\system32\DevicePairingWizard.exe
2010-06-16 18:02 . 2009-04-11 05:03 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2010-06-16 18:00 . 2009-04-11 06:28 29184 ----a-w- c:\windows\system32\wsepno.dll
2010-06-16 17:46 . 2010-01-29 15:40 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-06-16 17:46 . 2010-04-05 17:01 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-16 17:46 . 2010-04-23 14:13 2048 ----a-w- c:\windows\system32\tzres.dll
2010-06-16 17:46 . 2010-05-26 14:47 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-06-16 17:46 . 2010-05-26 17:06 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-16 04:32 . 2010-06-16 04:32 -------- d-----w- c:\users\Rexel\AppData\Roaming\Ventrilo
2010-06-15 02:22 . 2010-06-15 02:37 -------- d-----w- c:\users\Roselle\AppData\Roaming\Righteous Kill
2010-06-14 02:37 . 2010-06-14 02:37 -------- d-----w- c:\users\Guest\AppData\Local\AskToolbar
2010-06-14 02:37 . 2010-06-14 02:37 -------- d-----w- c:\users\Guest\AppData\Local\Google
2010-06-13 19:21 . 2010-06-25 17:55 -------- d-----w- c:\users\Rexel\AppData\Local\Apple Computer
2010-06-13 04:00 . 2010-06-13 04:00 -------- d-----w- c:\windows\system32\F01744F2FC1
2010-06-13 04:00 . 2010-06-13 04:00 -------- d-----w- c:\windows\system32\F016D353D7B
2010-06-13 04:00 . 2010-06-13 04:00 -------- d-----w- c:\windows\system32\F0157A43D16
2010-06-13 03:54 . 2010-06-25 17:55 -------- d-----w- c:\users\Rexel\AppData\Roaming\Apple Computer
2010-06-13 03:54 . 2010-06-13 03:54 125888 ----a-w- c:\users\Rexel\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-13 01:13 . 2010-06-13 01:13 -------- d-----w- c:\users\Rexel\AppData\Local\Blizzard Entertainment
2010-06-13 01:05 . 2010-06-26 04:09 -------- d-----w- c:\users\Rexel\AppData\Local\Google
2010-06-13 01:03 . 2010-06-13 01:03 -------- d-----w- c:\windows\system32\F013AAE60B7
2010-06-13 00:49 . 2010-06-13 00:49 -------- d-----w- c:\windows\system32\F01330A791A
2010-06-13 00:48 . 2010-06-13 00:48 -------- d-----w- c:\windows\system32\F011FD80175
2010-06-13 00:48 . 2010-06-13 00:48 -------- d-----w- c:\windows\system32\F010428152A
2010-06-13 00:48 . 2010-06-13 00:48 -------- d-----w- c:\users\Public\Games.edfad0a4.temp
2010-06-12 11:26 . 2010-06-12 11:26 -------- d-----w- c:\users\Public\Games.temp
2010-06-10 16:51 . 2010-06-10 16:51 -------- d-----w- c:\users\laureanofamily\AppData\Local\AskToolbar
2010-06-10 00:58 . 2010-06-24 17:59 64 ----a-w- c:\windows\GPlrLanc.dat
2010-06-10 00:58 . 2010-06-24 17:59 -------- d-----w- c:\programdata\Free Ride Games
2010-06-08 00:34 . 2010-06-08 00:34 -------- d-----w- c:\users\laureanofamily\AppData\Local\Google
2010-06-07 12:19 . 2010-06-07 12:20 -------- d-----w- c:\users\Roselle\AppData\Roaming\Farm Mania 2
2010-06-07 12:13 . 2010-06-09 03:15 -------- d-----w- c:\users\Roselle\AppData\Local\Google
2010-06-07 12:05 . 2010-06-26 04:09 -------- d-----w- c:\program files\Google
2010-06-07 12:05 . 2010-06-07 12:05 -------- d-----w- c:\windows\system32\Adobe
2010-06-04 17:25 . 2010-06-04 17:25 -------- d-----w- c:\program files\ATT
2010-06-02 00:39 . 2010-06-02 00:39 -------- d-----w- c:\users\Roselle\AppData\Roaming\Go-Go Gourmet Chef of the Year
2010-06-01 21:00 . 2010-06-07 23:48 -------- d-----w- c:\users\Roselle\AppData\Roaming\Oberon Media
2010-06-01 02:52 . 2010-06-01 02:52 -------- d-----w- c:\programdata\GameHouse
2010-05-31 20:51 . 2010-05-31 20:51 -------- d-----w- c:\programdata\Meridian93
2010-05-31 20:51 . 2010-05-31 20:51 -------- d-----w- c:\users\Roselle\AppData\Roaming\Meridian93
2010-05-31 20:51 . 2010-05-31 20:51 -------- d-----w- c:\users\Roselle\AppData\Roaming\game
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-27 18:56 . 2010-03-26 03:36 88975 ----a-w- c:\programdata\nvModes.dat
2010-06-27 18:56 . 2010-03-27 01:12 -------- d-----w- c:\program files\Dl_cats
2010-06-26 13:01 . 2010-03-26 20:18 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-06-26 04:07 . 2010-04-24 03:33 -------- d-----w- c:\program files\Yahoo! Games
2010-06-26 04:07 . 2010-05-28 04:16 -------- d-----w- c:\program files\Ask.com
2010-06-26 04:06 . 2010-03-28 04:16 -------- d-----w- c:\program files\MSN Games
2010-06-26 04:05 . 2010-04-25 00:53 -------- d-----w- c:\programdata\Oberon Media
2010-06-26 03:56 . 2010-03-26 03:41 -------- d-----w- c:\program files\Common Files\InstallShield
2010-06-25 21:11 . 2010-03-26 01:40 -------- d-----w- c:\programdata\LogiShrd
2010-06-25 11:08 . 2010-04-16 22:36 -------- d-----w- c:\program files\Microsoft.NET
2010-06-24 05:00 . 2010-03-26 19:55 -------- d-----w- c:\program files\Common Files\Apple
2010-06-24 04:51 . 2010-03-26 19:56 -------- d-----w- c:\program files\Safari
2010-06-23 21:44 . 2010-04-08 22:25 86 ----a-w- c:\users\Roselle\AppData\Roaming\wklnhst.dat
2010-06-22 19:07 . 2010-05-28 04:20 -------- d-----w- c:\users\Roselle\AppData\Roaming\LimeWire
2010-06-20 18:52 . 2010-06-20 18:52 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-06-20 18:52 . 2010-06-20 18:52 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-06-19 22:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-06-19 22:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-06-19 22:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-06-19 22:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-06-19 22:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-06-19 22:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-06-19 22:59 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-19 22:58 . 2010-06-19 22:58 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2010-06-19 22:58 . 2010-06-19 22:58 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2010-06-17 05:54 . 2010-03-26 02:32 330 ----a-w- c:\users\laureanofamily\AppData\Roaming\wklnhst.dat
2010-06-16 11:06 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2010-06-16 11:06 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2010-06-14 02:38 . 2010-05-12 22:18 -------- d-----w- c:\users\Guest\AppData\Roaming\Apple Computer
2010-06-10 01:01 . 2010-05-02 04:25 -------- d-----w- c:\users\Roselle\AppData\Roaming\PlayFirst
2010-06-10 01:01 . 2010-05-02 04:25 -------- d-----w- c:\programdata\PlayFirst
2010-06-07 12:18 . 2010-03-28 04:16 -------- d-----w- c:\program files\Oberon Media
2010-06-06 00:41 . 2010-03-26 21:00 -------- d-----w- c:\users\laureanofamily\AppData\Roaming\Apple Computer
2010-05-28 04:23 . 2010-05-28 04:15 -------- d-----w- c:\users\Roselle\AppData\Roaming\Apple Computer
2010-05-28 04:19 . 2010-05-28 04:19 -------- d-----w- c:\program files\Common Files\Java
2010-05-28 04:19 . 2010-05-28 04:19 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-28 04:19 . 2010-05-28 04:19 -------- d-----w- c:\program files\Java
2010-05-28 04:15 . 2010-05-28 04:14 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-05-28 04:14 . 2010-03-26 19:56 -------- d-----w- c:\programdata\Apple Computer
2010-05-28 04:13 . 2010-05-28 04:12 -------- d-----w- c:\program files\QuickTime
2010-05-28 04:12 . 2010-05-28 04:12 -------- d-----w- c:\program files\Apple Software Update
2010-05-26 20:51 . 2010-05-26 20:10 -------- d-----w- c:\programdata\FarmFrenzy3_Russia
2010-05-26 04:20 . 2010-05-26 04:20 -------- d-----w- c:\users\Roselle\AppData\Roaming\Flood Light Games
2010-05-26 04:20 . 2010-05-26 04:20 -------- d-----w- c:\programdata\Flood Light Games
2010-05-26 04:06 . 2010-05-26 04:05 -------- d-----w- c:\programdata\Deadtime Stories
2010-05-26 03:20 . 2010-05-21 23:31 -------- d-----w- c:\users\Roselle\AppData\Roaming\Artogon
2010-05-24 03:41 . 2010-05-24 03:41 -------- d-----w- c:\users\Roselle\AppData\Roaming\Oberon
2010-05-23 05:47 . 2010-05-23 05:47 -------- d-----w- c:\programdata\SpecialBit
2010-05-23 02:10 . 2010-05-23 02:10 -------- d-----w- c:\users\Roselle\AppData\Roaming\Boolat Games
2010-05-23 01:28 . 2010-05-23 01:28 -------- d-----w- c:\users\Roselle\AppData\Roaming\LaJangada
2010-05-23 00:29 . 2010-05-23 00:29 -------- d-----w- c:\users\Roselle\AppData\Roaming\Big Fish Games
2010-05-22 04:31 . 2010-05-22 04:31 -------- d-----w- c:\users\Roselle\AppData\Roaming\Namco
2010-05-21 19:14 . 2010-03-26 02:03 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 21:35 . 2010-05-18 21:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 21:35 . 2010-05-18 21:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-16 04:41 . 2010-05-16 04:41 -------- d-----w- c:\users\Roselle\AppData\Roaming\GameInvest
2010-05-10 20:48 . 2010-04-05 22:26 125888 ----a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-04 05:59 . 2010-06-16 17:45 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-16 17:45 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 05:55 . 2010-06-16 17:45 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 04:31 . 2010-06-16 17:45 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-01 14:13 . 2010-06-16 17:45 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 12:01 . 2010-04-29 12:01 10978776 ----a-w- c:\programdata\SPL8841.tmp
2010-04-29 06:20 . 2010-04-29 06:20 10978776 ----a-w- c:\programdata\SPL426.tmp
2010-04-28 19:54 . 2010-04-28 19:53 -------- d-----w- c:\programdata\Go Go Gourmet
2010-04-19 11:25 . 2010-03-26 01:15 125888 ----a-w- c:\users\laureanofamily\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-19 03:51 . 2010-04-08 22:12 125888 ----a-w- c:\users\Roselle\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-31 06:00 . 2010-03-31 06:00 86016 ----a-w- c:\windows\system32\frapsvid.dll
2007-02-21 19:49 . 2007-02-21 19:49 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" [2009-07-16 5458704]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-06-26 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 304008]
"DLCXCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0360.0\mswinext.exe" [2009-11-18 240480]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\wlanapi.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):e2,6f,78,e1,03,10,cb,01
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-26 136176]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
S2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe [2006-11-04 537480]
S3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 251904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LPDService REG_MULTI_SZ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-26 04:09]
2010-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-26 04:09]
2010-06-26 c:\windows\Tasks\User_Feed_Synchronization-{86B33D2A-102E-4517-904C-BF5E2454C7EF}.job
- c:\windows\system32\msfeedssync.exe [2010-06-16 04:30]
2010-06-27 c:\windows\Tasks\User_Feed_Synchronization-{9E7639ED-B112-4179-B7CC-E00746ACDA36}.job
- c:\windows\system32\msfeedssync.exe [2010-06-16 04:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
LSP: c:\windows\system32\wpclsp.dll
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(5972)
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2010-06-27 14:06:01 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-27 19:05
Pre-Run: 107,039,059,968 bytes free
Post-Run: 109,407,997,952 bytes free
- - End Of File - - 167FA9C94326CF6CEFF01DD5F7BBF764

icon.
button.

