I ran Combofix. Here is the log:
ComboFix 09-10-04.01 - Andy 10/05/2009 17:33.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2046.861 [GMT -4:00]
Running from: k:\andy's files\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1400113804-1914402855-3429530994-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-3990554762-1353642550-3768045812-500
c:\program files\IEToolbar
c:\users\Andy\AppData\Roaming\inst.exe
c:\users\Andy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoViewer.exe
c:\windows\Installer\4a9749.msi
c:\windows\Installer\WMEncoder.msi
Infected copy of c:\windows\System32\drivers\nvstor32.sys was found and disinfected
Kitty ate it
.
((((((((((((((((((((((((( Files Created from 2009-09-05 to 2009-10-05 )))))))))))))))))))))))))))))))
.
2009-10-05 21:40 . 2009-10-05 21:40 -------- d-----w- c:\users\Mcx1\AppData\Local\temp
2009-10-05 21:40 . 2009-10-05 21:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-05 21:40 . 2009-10-05 21:40 -------- d-----w- c:\users\Andy\AppData\Local\temp
2009-10-05 19:30 . 2009-10-05 19:30 680 ----a-w- c:\users\Andy\AppData\Local\d3d9caps.dat
2009-10-05 03:18 . 2009-10-05 03:18 -------- d-----w- c:\users\Harriette\AppData\Roaming\SUPERAntiSpyware.com
2009-10-05 03:17 . 2009-10-05 03:17 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-05 03:00 . 2009-10-05 03:00 -------- d-----w- c:\program files\CCleaner
2009-10-05 02:56 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-05 02:56 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-05 02:34 . 2009-10-05 02:36 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-05 02:29 . 2009-10-05 02:29 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-05 02:29 . 2009-10-05 02:29 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-05 02:29 . 2009-10-05 02:29 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-05 02:29 . 2009-10-05 02:29 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-05 02:29 . 2009-10-05 16:15 -------- d-----w- c:\windows\system32\drivers\Avg
2009-10-05 01:46 . 2009-10-01 14:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-05 00:19 . 2009-10-05 00:21 -------- d-----w- c:\windows\system32\catroot2(270)
2009-10-04 21:51 . 2009-10-04 22:01 -------- d-----w- C:\$AVG8.VAULT$
2009-10-04 21:33 . 2009-10-05 03:18 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-04 21:33 . 2009-10-04 21:33 -------- d-----w- c:\users\Andy\AppData\Roaming\SUPERAntiSpyware.com
2009-10-04 20:58 . 2009-10-05 02:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-04 20:35 . 2009-10-04 20:35 11952 ----a-w- c:\windows\system32\avgrsstx(269).dll
2009-10-04 20:28 . 2009-10-04 20:28 -------- d-----w- c:\users\Andy\AppData\Roaming\AVG8
2009-10-04 12:30 . 2009-10-04 12:30 -------- d-----w- c:\users\Harriette\AppData\Roaming\Malwarebytes
2009-10-03 18:26 . 2009-10-03 18:26 -------- d-----w- c:\users\Andy\AppData\Roaming\Malwarebytes
2009-09-30 00:01 . 2009-10-05 01:30 -------- d-----w- c:\program files\Ask.com
2009-09-30 00:01 . 2009-10-05 01:30 -------- d-----w- c:\program files\PFPortChecker
2009-09-27 19:04 . 2009-10-05 01:31 -------- d-----w- c:\users\Andy\AppData\Roaming\vlc
2009-09-27 17:58 . 2009-09-27 17:58 -------- d-----w- c:\program files\VideoLAN
2009-09-27 02:48 . 2009-09-27 02:48 -------- d-----w- c:\program files\Digiarty
2009-09-27 00:17 . 2009-09-27 03:02 -------- d-----w- c:\users\Harriette\AppData\Roaming\uTorrent
2009-09-22 23:10 . 2009-10-05 21:19 -------- d-----w- c:\users\Andy\Tracing
2009-09-16 12:23 . 2009-10-05 20:57 -------- d-----w- c:\users\Harriette\Tracing
2009-09-16 12:22 . 2009-09-16 12:22 -------- d-----w- c:\program files\Microsoft
2009-09-16 12:22 . 2009-09-16 12:22 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-16 12:22 . 2009-09-16 12:22 -------- d-----w- c:\program files\Windows Live
2009-09-13 00:06 . 2009-05-18 18:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-13 00:06 . 2008-04-17 17:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-09-13 00:06 . 2009-09-13 00:06 -------- d-----w- c:\program files\iPod
2009-09-13 00:03 . 2009-09-13 00:03 -------- d-----w- c:\program files\QuickTime
2009-09-12 03:43 . 2009-09-12 03:43 -------- d-----w- C:\found.000
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-05 19:03 . 2009-01-09 01:40 -------- d-----w- c:\users\Andy\AppData\Roaming\uTorrent
2009-10-05 18:30 . 2007-10-23 05:52 84440 ----a-w- c:\users\Andy\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-05 16:19 . 2007-10-29 01:14 -------- d-----w- c:\users\Harriette\AppData\Roaming\MSN6
2009-10-05 01:41 . 2007-12-11 03:24 -------- d-----w- c:\program files\PeerGuardian2
2009-10-05 01:31 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-10-05 01:30 . 2009-05-02 17:02 -------- d-----w- c:\program files\PHP
2009-10-05 01:30 . 2008-02-10 04:13 -------- d-----w- c:\program files\Netflix
2009-10-05 01:30 . 2007-10-25 01:17 -------- d-----w- c:\program files\Roxio
2009-10-05 01:30 . 2009-08-31 13:44 -------- d-----w- c:\program files\MyDVDTools
2009-10-05 01:30 . 2009-07-13 02:10 -------- d-----w- c:\program files\Bonjour
2009-10-05 01:30 . 2008-04-15 00:34 -------- d-----w- c:\program files\ImTOO
2009-10-05 01:30 . 2008-02-16 13:04 -------- d-----w- c:\program files\megui
2009-10-05 01:30 . 2007-10-27 17:51 -------- d-----w- c:\program files\LimeWire
2009-10-05 01:30 . 2007-10-27 00:52 -------- d-----w- c:\program files\Eastside Hockey Manager
2009-10-05 01:30 . 2008-12-27 03:57 -------- d-----w- c:\program files\AutoGK
2009-10-05 00:18 . 2009-10-05 00:18 -------- d--h--w- c:\users\Administrator\AppData\Roaming\GTek
2009-10-03 16:07 . 2007-10-27 17:52 -------- d-----w- c:\users\Andy\AppData\Roaming\LimeWire
2009-09-28 13:21 . 2008-11-15 12:40 -------- d-----w- c:\users\Harriette\AppData\Roaming\Move Networks
2009-09-22 02:38 . 2007-10-24 02:24 -------- d-----w- c:\users\Andy\AppData\Roaming\Apple Computer
2009-09-22 02:33 . 2009-05-02 19:13 -------- d-----w- c:\users\Harriette\AppData\Roaming\LimeWire
2009-09-15 23:58 . 2007-11-14 01:17 -------- d-----w- c:\users\Harriette\AppData\Roaming\Apple Computer
2009-09-13 14:40 . 2007-10-23 20:55 -------- d-----w- c:\users\Andy\AppData\Roaming\MSN6
2009-09-13 00:06 . 2008-11-25 19:32 -------- d-----w- c:\program files\iTunes
2009-09-13 00:06 . 2007-10-24 02:19 -------- d-----w- c:\program files\Common Files\Apple
2009-09-12 03:30 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-12 03:29 . 2008-02-16 01:40 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-05 16:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-09-05 16:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-09-05 16:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-09-05 16:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-09-05 16:59 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-09-05 16:53 . 2009-09-05 16:53 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-09-01 13:03 . 2009-02-21 01:07 84440 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-08-31 13:54 . 2007-10-23 22:11 84440 ----a-w- c:\users\Harriette\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-31 13:54 . 2009-08-31 13:54 -------- d-----w- c:\program files\avi.NET
2009-08-31 13:44 . 2009-08-31 13:44 1 ----a-w- c:\windows\system32\SysDVDtoMPeg.dat
2009-08-29 02:44 . 2009-08-29 02:44 -------- d-----w- c:\program files\Common Files\Remote Control Software Common
2009-08-29 02:44 . 2009-08-29 02:44 -------- d-----w- c:\program files\Logitech
2009-08-29 00:27 . 2009-09-02 23:08 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-02 23:08 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 23:42 . 2009-08-28 23:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-28 23:42 . 2009-08-28 23:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-14 16:27 . 2009-09-09 12:47 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 15:53 . 2009-09-09 12:47 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49 . 2009-09-09 12:47 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49 . 2009-09-09 12:47 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49 . 2009-09-09 12:47 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49 . 2009-09-09 12:47 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49 . 2009-09-09 12:47 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49 . 2009-09-09 12:47 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49 . 2009-09-09 12:47 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:48 . 2009-09-09 12:47 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48 . 2009-09-09 12:47 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-13 23:04 . 2009-08-13 00:21 -------- d-----w- c:\program files\CARCare
2009-07-26 20:44 . 2009-07-26 20:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-21 21:52 . 2009-07-29 21:27 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 21:27 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 21:27 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 21:27 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 13:54 . 2009-08-11 23:01 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-15 12:40 . 2009-08-11 23:01 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-15 12:39 . 2009-08-11 23:01 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-15 12:39 . 2009-08-11 23:01 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-15 12:39 . 2009-08-11 23:01 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-11 19:01 . 2009-09-09 12:47 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-07-11 19:01 . 2009-09-09 12:47 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-07-11 19:01 . 2009-09-09 12:47 513536 ----a-w- c:\windows\system32\wlansvc.dll
2009-07-11 19:01 . 2009-09-09 12:47 65024 ----a-w- c:\windows\system32\wlanapi.dll
2009-07-11 17:03 . 2009-09-09 12:47 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-07-09 14:29 . 2009-07-09 14:29 103720 ----a-w- c:\users\Harriette\GoToAssistDownloadHelper.exe
2007-10-23 21:14 . 2007-10-23 21:14 32 --sha-w- c:\windows\{6D38D17B-4A43-4423-96A2-FF93B6833A5F}.dat
2006-05-03 10:06 . 2009-06-04 15:51 163328 --sh--r- c:\windows\System32\flvDX.dll
2007-02-21 11:47 . 2009-06-04 15:51 31232 --sh--r- c:\windows\System32\msfDX.dll
2008-03-16 13:30 . 2009-06-04 15:51 216064 --sh--r- c:\windows\System32\nbDX.dll
2007-10-23 21:14 . 2007-10-23 21:14 32 --sha-w- c:\windows\System32\{FC390924-02D5-4D03-A57B-4726D89EB48E}.dat
2007-10-19 03:29 . 2007-10-19 03:22 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-07-10 21:28 1174920 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-24 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Dell DataSafe Scheduler"="c:\program files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe" [2007-12-02 308464]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-05-24 86016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-24 81920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-24 8429568]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 218032]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2007-11-20 731136]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-05 2007832]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-03-15 4390912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"VistaSp2"=hex(b):6d,3a,62,18,4b,2e,ca,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"= c:\program files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{29B24D81-112F-473A-8EBE-7D05E48F812B}"= UDP:c:\program files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{DF67F39F-F4B6-4DFE-ACEA-A20EDD672488}"= TCP:c:\program files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{91097CD1-1E51-4B7E-8B24-FFB30477A0CF}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{B3637C88-5562-4BA0-BE2C-521D8EB0B732}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"TCP Query User{F634D995-D08A-4138-A9F6-9980387CBB53}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"UDP Query User{64030202-F034-4F29-BCAA-5D7CC07819CB}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"TCP Query User{878266A6-8874-4CC7-9399-222A64F26427}c:\\users\\andy\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= UDP:c:\users\andy\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"UDP Query User{5776A8F9-3384-4E17-A389-11680BA9DBB5}c:\\users\\andy\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= TCP:c:\users\andy\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"TCP Query User{311F1BE7-42AA-4215-813B-A2EAE3DDE625}c:\\program files\\nero\\nero8\\nero home\\nerohome.exe"= UDP:c:\program files\nero\nero8\nero home\nerohome.exe:Nero Home
"UDP Query User{1427A126-0481-4404-B9A5-1EBA2274AA00}c:\\program files\\nero\\nero8\\nero home\\nerohome.exe"= TCP:c:\program files\nero\nero8\nero home\nerohome.exe:Nero Home
"TCP Query User{B3EFAE3D-6F45-4205-94B5-4D87B77F69A7}c:\\program files\\nero\\nero8\\nero mediahome\\nmmediaserver.exe"= UDP:c:\program files\nero\nero8\nero mediahome\nmmediaserver.exe:Nero MediaHome
"UDP Query User{139EF927-C3C3-48A4-B0D5-B520BAF27228}c:\\program files\\nero\\nero8\\nero mediahome\\nmmediaserver.exe"= TCP:c:\program files\nero\nero8\nero mediahome\nmmediaserver.exe:Nero MediaHome
"{A8F53EDB-5D74-413D-97E1-AB84A03BCE09}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{BC64B2A3-EDCC-4996-B98A-228C0A349660}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{EEA7D974-4827-4A00-AE3A-DC6B69E4F48C}c:\\program files\\bittornado\\btdownloadgui.exe"= UDP:c:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"UDP Query User{4B702A09-9504-4CB3-9043-4B46836884C6}c:\\program files\\bittornado\\btdownloadgui.exe"= TCP:c:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"{E8BBAF43-BA7D-4A2B-BDFB-E4D0684FB4A6}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{40DCF2E2-2B92-46D6-88E0-B621840348F9}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{99F6431A-59E0-41E2-AD0D-841B605539B0}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{93552AE1-4E04-4504-9225-8B646123412C}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"TCP Query User{2FE6EFE2-4FEF-41C3-9A24-C2B20443F2D9}c:\\program files\\bitpim\\bitpimw.exe"= UDP:c:\program files\bitpim\bitpimw.exe:Open Source Mobile Phone Tool
"UDP Query User{DAA10E33-B5F1-465D-83A3-637FDD9D3779}c:\\program files\\bitpim\\bitpimw.exe"= TCP:c:\program files\bitpim\bitpimw.exe:Open Source Mobile Phone Tool
"{83B0D1F3-BE47-4F25-9279-E868F49509F0}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{B32861D5-43B4-474B-BCE2-E60BDC866792}"= UDP:c:\program files\TVersity\Media Server\MediaServer.exe:TVersity Media Server
"{45A5D1EB-C05D-4492-AC70-0579DE0342A8}"= TCP:c:\program files\TVersity\Media Server\MediaServer.exe:TVersity Media Server
"TCP Query User{41E85C56-F7C9-49C8-BD0F-4B273DDF42D8}c:\\easywamp\\apache2\\bin\\apache.exe"= UDP:c:\easywamp\apache2\bin\apache.exe:Apache HTTP Server
"UDP Query User{E24C01C0-2F3D-4ED9-972D-CB958200C001}c:\\easywamp\\apache2\\bin\\apache.exe"= TCP:c:\easywamp\apache2\bin\apache.exe:Apache HTTP Server
"{E88C4A36-9B9B-4E01-9145-B57DD14F4DEC}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{6C0ECBC7-A632-40E3-BC03-26CF9EC51B53}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{206836AA-B7FF-4DC2-A3E3-B13B2C7ECE5B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{ABA1BFB0-2ABC-4C22-81CE-387BCFE60F29}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{37048BD8-8F1C-4AF8-8442-4F0B0B34D35B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{53682534-8537-4E84-B499-A6ED6C59D445}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{1C74C2AD-2E70-4A2A-907A-1BC6073C865A}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{83902DAB-1C7A-4101-AAFA-D5898F89E08B}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{DA23A22D-67FD-4C8B-BA4D-3E2296AFB34B}"= UDP:51163:utorrent
"TCP Query User{2E06560A-CD9B-4DD4-8825-1FB81E5724E1}c:\\program files\\pfportchecker\\pfportchecker.exe"= UDP:c:\program files\pfportchecker\pfportchecker.exe:PFPortchecker by portforward.com helps check if your ports are properly forwarded.
"UDP Query User{0009DCEE-8E72-423E-9919-264307704C5F}c:\\program files\\pfportchecker\\pfportchecker.exe"= TCP:c:\program files\pfportchecker\pfportchecker.exe:PFPortchecker by portforward.com helps check if your ports are properly forwarded.
"{AA47F8BA-A26D-45F6-9DB5-77B71966F3D2}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{06C3581D-1F4B-4833-A9B2-DAEE2850AAB9}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"= c:\program files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [10/4/2009 10:29 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [10/4/2009 10:29 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/4/2009 10:28 PM 297752]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [10/4/2009 10:34 PM 1153368]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-24 23:56]
2009-10-05 c:\windows\Tasks\User_Feed_Synchronization-{68B48EDF-47A2-48CC-B00F-D1BE1FE55026}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1254492326&rver=6.0.5285.0&wp=MBI&wreply=http:%2F%2Fmail.live.com%2Fdefault.aspx&lc=1033&id=64855&mkt=en-us
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SymTray - Norton SystemWorks - c:\program files\Common Files\Symantec Shared\Symtray.exe
HKU-Default-Run-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
AddRemove-SantaGames.Net - c:\windows\SantaGames.Net
AddRemove-SantaGames.Net - c:\windows\SantaGames.Net
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-05 17:40
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 00\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 01\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 02\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 03\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 04\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 05\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-10-05 17:42
ComboFix-quarantined-files.txt 2009-10-05 21:42
Pre-Run: 45,258,469,376 bytes free
Post-Run: 44,983,230,464 bytes free
386 --- E O F --- 2009-10-05 01:46