(post continued from above)
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_ienwhoixjuxptvrx
-------\Service_pibivvrxqjibcofv
((((((((((((((((((((((((( Files Created from 2009-08-09 to 2009-09-09 )))))))))))))))))))))))))))))))
.
2009-09-08 02:11 . 2009-09-08 02:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-08-29 17:07 . 2009-08-29 17:08 -------- d-----w- C:\rsit
2009-08-29 03:34 . 2009-08-29 03:34 -------- d-----w- c:\documents and settings\Mica Gries\Local Settings\Application Data\{EC912E71-D645-44EA-AFFD-8D2B380911F7}
2009-08-25 17:53 . 2009-08-25 17:53 -------- d-----w- c:\program files\Common Files\xing shared
2009-08-25 17:53 . 2009-08-25 17:53 -------- d-----w- c:\program files\Real
2009-08-25 05:27 . 2009-08-25 05:27 -------- d-----w- c:\windows\system32\scripting
2009-08-25 05:27 . 2009-08-25 05:27 -------- d-----w- c:\windows\l2schemas
2009-08-25 05:27 . 2009-08-25 05:27 -------- d-----w- c:\windows\system32\en
2009-08-25 05:27 . 2009-08-25 05:27 -------- d-----w- c:\windows\system32\bits
2009-08-25 05:19 . 2009-08-25 05:19 -------- d-----w- c:\windows\EHome
2009-08-23 06:02 . 2009-08-25 05:25 -------- d-----w- c:\windows\ServicePackFiles
2009-08-23 05:21 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-08-23 05:21 . 2009-06-10 16:19 2066432 ------w- c:\windows\system32\dllcache\mstscax.dll
2009-08-23 05:15 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-08-23 05:15 . 2008-04-21 12:08 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2009-08-22 03:11 . 2009-08-22 03:11 -------- d-----w- c:\program files\Trend Micro
2009-08-21 21:04 . 2009-08-21 22:36 -------- d-----w- c:\windows\BDOSCAN8
2009-08-21 21:02 . 2009-08-21 21:02 -------- d-----w- c:\program files\Windows Live Safety Center
2009-08-21 20:18 . 2009-08-21 20:18 -------- d-----w- c:\documents and settings\LocalService\Application Data\Yahoo!
2009-08-19 03:00 . 2009-08-26 03:02 -------- d-----w- c:\documents and settings\Mica Gries\Application Data\HpUpdate
2009-08-19 03:00 . 2009-08-19 03:00 -------- d-----w- c:\windows\Hewlett-Packard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-09 16:42 . 2008-09-18 17:13 -------- d-----w- c:\documents and settings\Mica Gries\Application Data\Skype
2009-09-09 15:09 . 2008-09-18 17:14 -------- d-----w- c:\documents and settings\Mica Gries\Application Data\skypePM
2009-09-08 22:07 . 2008-08-10 20:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-08 20:43 . 2008-08-10 20:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-08 02:12 . 2008-06-24 01:32 -------- d-----w- c:\program files\World of Warcraft
2009-09-07 17:32 . 2008-07-05 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-01 17:23 . 2009-09-01 17:23 19865 ----a-w- c:\program files\Common Files\quviqufy.lib
2009-09-01 17:12 . 2008-08-30 23:31 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-29 21:39 . 2009-04-25 05:42 -------- d-----w- c:\program files\MSN Messenger
2009-08-28 15:57 . 2008-07-05 23:02 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-28 15:57 . 2008-07-05 23:02 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-28 15:57 . 2008-07-05 23:02 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-26 16:27 . 2008-07-05 21:33 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-25 17:53 . 2009-01-08 01:07 -------- d-----w- c:\program files\Common Files\Real
2009-08-25 17:53 . 2008-05-21 22:49 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-08-25 16:58 . 2008-05-30 18:04 33840 ----a-w- c:\documents and settings\Mica Gries\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-23 06:14 . 2008-05-21 22:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-19 03:00 . 2008-11-12 03:24 -------- d-----w- c:\program files\HP
2009-08-08 01:05 . 2008-05-21 22:58 -------- d-----w- c:\program files\Google
2009-08-08 01:03 . 2009-08-08 01:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-05 17:03 . 2009-07-09 19:07 -------- d-----w- c:\program files\Trillian
2009-08-05 09:01 . 2004-08-10 16:51 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 05:32 . 2009-08-05 05:29 -------- d-----w- c:\program files\Graboid
2009-08-05 05:30 . 2009-08-05 05:30 -------- d-----w- c:\program files\Mozilla ActiveX Control v1.7.12
2009-08-03 18:57 . 2009-08-03 18:57 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-08-03 00:18 . 2008-06-08 00:55 -------- d-----w- c:\documents and settings\Mica Gries\Application Data\Yahoo!
2009-08-03 00:18 . 2008-06-08 00:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-08-02 16:20 . 2009-08-02 16:20 -------- d-----w- c:\program files\ElcomSoft
2009-08-02 05:14 . 2009-08-01 02:18 -------- d-----w- c:\program files\Native Instruments
2009-07-29 04:37 . 2004-08-10 16:51 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2004-08-10 16:51 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-27 17:05 . 2008-07-05 22:28 33840 ----a-w- c:\documents and settings\Guinevere Morgan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-21 18:34 . 2008-05-21 22:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Dell
2009-07-20 03:36 . 2009-07-20 03:36 -------- d-----w- c:\program files\Groundspeak
2009-07-20 03:24 . 2009-07-20 03:24 -------- d-----w- c:\program files\YouTube Downloader
2009-07-20 02:48 . 2009-07-20 02:48 -------- d-----w- c:\program files\MSBuild
2009-07-20 02:48 . 2009-07-20 02:48 -------- d-----w- c:\program files\Reference Assemblies
2009-07-17 19:01 . 2004-08-10 16:50 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 06:43 . 2004-08-10 16:51 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 03:33 . 2008-06-02 22:35 -------- d-----w- c:\program files\Bethesda Softworks
2009-07-12 22:01 . 2009-06-13 22:49 -------- d-----w- c:\program files\Runes of Magic
2009-07-11 20:07 . 2008-06-06 16:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-07-11 20:07 . 2008-06-06 16:37 -------- d-----w- c:\program files\Yahoo!
2009-06-26 16:50 . 2004-08-10 16:51 666624 ------w- c:\windows\system32\wininet.dll
2009-06-26 16:50 . 2004-08-10 16:51 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-25 08:25 . 2004-08-10 16:51 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-10 16:51 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-10 16:51 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-10 16:51 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-08-10 16:51 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-10 16:51 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-10 16:51 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-12 12:31 . 2004-08-10 16:51 76288 ----a-w- c:\windows\system32\telnet.exe
2008-05-21 22:50 . 2008-05-21 22:50 76 --sh--r- c:\windows\CT4CET.bin
.
((((((((((((((((((((((((((((( SnapShot@2009-09-01_17.13.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-09 16:41 . 2009-09-09 16:41 16384 c:\windows\temp\Perflib_Perfdata_588.dat
- 2009-07-20 02:45 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2009-07-20 02:45 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll
+ 2009-06-25 08:25 . 2009-06-25 08:25 54272 c:\windows\system32\dllcache\wdigest.dll
+ 2009-02-03 19:59 . 2009-06-25 08:25 56832 c:\windows\system32\dllcache\secur32.dll
- 2009-02-03 19:59 . 2009-02-03 19:59 56832 c:\windows\system32\dllcache\secur32.dll
+ 2009-06-24 11:18 . 2009-06-24 11:18 92928 c:\windows\system32\dllcache\ksecdd.sys
+ 2008-05-30 17:54 . 2009-09-07 17:30 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-30 17:54 . 2009-08-25 16:46 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-30 17:54 . 2009-09-07 17:30 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-05-30 17:54 . 2009-08-25 16:46 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-05-30 17:54 . 2009-08-25 16:46 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-05-30 17:54 . 2009-09-07 17:30 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2004-08-10 16:50 . 2004-08-04 09:00 4224 c:\windows\system32\dllcache\beep.sys
+ 2008-12-05 06:54 . 2009-06-25 08:25 147456 c:\windows\system32\dllcache\schannel.dll
+ 2009-06-25 08:25 . 2009-06-25 08:25 136192 c:\windows\system32\dllcache\msv1_0.dll
+ 2009-08-23 05:23 . 2009-06-25 08:25 730112 c:\windows\system32\dllcache\lsasrv.dll
+ 2009-06-25 08:25 . 2009-06-25 08:25 301568 c:\windows\system32\dllcache\kerberos.dll
+ 2009-03-20 18:48 . 2009-03-20 18:48 183808 c:\windows\Installer\275c8d2.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DELL Webcam Manager"="c:\program files\DELL\DELL Webcam Manager\DellWMgr.exe" [2007-06-07 118784]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-21 68856]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-08-12 21741864]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-21 29744]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-16 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-16 138008]
"OEM03Mon.exe"="c:\windows\OEM03Mon.exe" [2007-06-17 36864]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-11-08 128920]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-28 2007832]
"TELUS_McciTrayApp"="c:\program files\TELUS\TELUS Support Centre\bin\McciTrayApp.exe" [2007-10-08 1462272]
"TelusWCC_McciTrayApp"="c:\program files\TELUS\TELUS Wireless Connection Manager\McciTrayApp.exe" [2006-03-10 543232]
"TEPA.exe"="c:\program files\TELUS\eProtect Advisor\TEPA.exe" [2007-05-14 2061816]
"TELUS eProtect"="c:\program files\TELUS\TELUS eProtect\Rps.exe" [2007-09-13 310000]
"-FreedomNeedsReboot"="c:\program files\TELUS\TELUS eProtect\ZkRunOnceR.exe" [2007-09-13 13552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-02-21 366400]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-08-25 198160]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-02-04 18085888]
c:\documents and settings\Mica Gries\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-05-21 23:03 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 15:57 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Ubisoft\\Lost Via Domus\\Yeti_Final_Win32.exe"=
"c:\\Program Files\\Ubisoft\\Lost Via Domus\\gu.exe"=
"c:\\Program Files\\Ubisoft\\Lost Via Domus\\detection\\Launcher.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver 8\\Dreamweaver.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Mica Gries\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Documents and Settings\\Mica Gries\\Desktop\\mirc\\mirc32.exe"=
"c:\\Program Files\\World of Warcraft\\Repair.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/5/2008 4:02 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7/5/2008 4:02 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/6/2008 12:00 PM 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/6/2008 12:00 PM 297752]
R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;c:\windows\system32\drivers\livecamv.sys [5/21/2008 3:49 PM 31616]
S2 gupdate1ca17c427846f60;Google Update Service (gupdate1ca17c427846f60);c:\program files\Google\Update\GoogleUpdate.exe [8/7/2009 6:04 PM 133104]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2/13/2009 10:51 AM 1684736]
S3 gUSBSTOi;gUSBSTOi;\??\c:\docume~1\MICAGR~1\LOCALS~1\Temp\gUSBSTOi.sys --> c:\docume~1\MICAGR~1\LOCALS~1\Temp\gUSBSTOi.sys [?]
S3 OEM03Afx;Provides a software interface to control audio effects of OEM003 camera.;c:\windows\system32\drivers\OEM03Afx.sys [5/21/2008 3:31 PM 141376]
S3 OEM03Vfx;Creative Camera OEM003 Video VFX Driver;c:\windows\system32\drivers\OEM03Vfx.sys [5/21/2008 3:31 PM 7424]
S3 OEM03Vid;Creative Camera OEM003 Driver;c:\windows\system32\drivers\OEM03Vid.sys [5/21/2008 3:31 PM 235808]
S3 Radialpoint Security Services;TELUS eProtect;c:\windows\system32\dllhost.exe [8/10/2004 9:50 AM 5120]
S3 SysProtDrv.sys;SysProtDrv.sys;\??\c:\documents and settings\Mica Gries\Desktop\SysProt\SysProtDrv.sys --> c:\documents and settings\Mica Gries\Desktop\SysProt\SysProtDrv.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-09-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-09-09 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 18:20]
2009-09-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-21 01:03]
2009-09-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-08 01:04]
2009-09-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-08 01:04]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com
uSearch Page =
hxxp://www.google.com
uSearch Bar =
hxxp://www.google.com/ie
mStart Page =
hxxp://www.google.com
mSearch Bar =
hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Mica Gries\Application Data\Mozilla\Firefox\Profiles\oz5ojilq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdjvu.dll
FF - HiddenExtension: XUL Cache: {EC912E71-D645-44EA-AFFD-8D2B380911F7} - c:\documents and settings\Mica Gries\Local Settings\Application Data\{EC912E71-D645-44EA-AFFD-8D2B380911F7}\
FF - HiddenExtension: XUL Cache: {1D46326B-522B-4FE3-86B8-F0DC7A05C6BB} - c:\documents and settings\Guinevere Morgan\Local Settings\Application Data\{1D46326B-522B-4FE3-86B8-F0DC7A05C6BB}\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-09 09:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-4256185878-1621736987-725487831-1006\Software\SecuROM\License information*]
"datasecu"=hex:be,65,86,69,4f,f9,b2,e6,e9,9e,86,a5,c6,37,79,43,cc,82,24,24,ce,
94,97,ed,79,37,e7,9e,89,b1,ad,46,bd,da,e4,dd,80,1c,82,1e,78,ca,fd,05,51,9c,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(996)
c:\windows\system32\Ati2evxx.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
- - - - - - - > 'explorer.exe'(1844)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\TELUS\TELUS eProtect\Fws.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Authentium\AntiVirus\dvpapi.exe
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\CA\PPRT\bin\ITMRTSVC.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Raxco\PerfectDisk\PDAgent.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\msiexec.exe
c:\program files\Raxco\PerfectDisk\PDEngine.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\msiexec.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\windows\system32\igfxsrvc.exe
.
**************************************************************************
.
Completion time: 2009-09-09 9:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-09 16:45
ComboFix2.txt 2009-09-08 01:25
ComboFix3.txt 2009-09-01 17:16
Pre-Run: 353,458,274,304 bytes free
Post-Run: 353,845,350,400 bytes free
1205 --- E O F --- 2009-09-04 21:2
(continued next post)