1
Tech Clinic / BITS does not work Error 2 file not found
« on: October 15, 2010, 07:21:14 PM »
[quote name='guestolo' date='16 October 2010 - 12:19 AM' timestamp='1287188385' post='472382']
Can you do me a favor, your log wasn't very legible
I tried to fix it with d'Rap, but it didn't work all that well
Can you reopen ComboFix.txt in Notepad
Click on FORMAT on the top menu and uncheck WORD WRAP then repost that log
[/quote]
ComboFix 10-10-14.04 - Li 15/10/2010 23:01:49.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3032.1860 [GMT 1:00]
Running from: c:\users\Li\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\fheydbueyj.exe
c:\fheydbueyj.exe\config.bin
c:\windows\system32\5c89e87aa3.dat
.
((((((((((((((((((((((((( Files Created from 2010-09-15 to 2010-10-15 )))))))))))))))))))))))))))))))
.
2010-10-15 22:19 . 2010-10-15 22:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-15 21:58 . 2010-10-15 21:59 -------- d-----w- C:\32788R22FWJFW
2010-10-15 21:44 . 2010-10-15 22:19 -------- d-----w- c:\users\Li\AppData\Local\temp
2010-10-15 20:28 . 2010-10-15 20:28 -------- d-----w- c:\users\Li\AppData\Roaming\Malwarebytes
2010-10-15 20:28 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-15 20:28 . 2010-10-15 20:28 -------- d-----w- c:\programdata\Malwarebytes
2010-10-15 20:28 . 2010-10-15 20:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-15 20:28 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-15 18:17 . 2010-10-15 18:17 388096 ----a-r- c:\users\Li\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-15 18:17 . 2010-10-15 18:17 -------- d-----w- c:\program files\Trend Micro
2010-10-15 11:54 . 2010-10-15 12:57 -------- d-----w- c:\users\Li\AppData\Roaming\AVG
2010-10-15 10:38 . 2010-10-15 10:38 -------- d-----w- c:\windows\CheckSur
2010-10-15 10:30 . 2010-10-15 10:30 -------- d-----w- c:\users\Li\AppData\Roaming\Sunbelt
2010-10-15 10:30 . 2010-10-15 10:30 -------- d-----w- c:\programdata\Sunbelt
2010-10-15 10:30 . 2010-10-15 10:30 -------- d-----w- c:\program files\Sunbelt Software
2010-10-15 09:24 . 2010-10-15 09:24 -------- d-----w- C:\8212b806078424617daad2
2010-10-15 09:22 . 2010-10-15 09:22 -------- d-----w- C:\933005583f2654c61388bf5e
2010-10-15 08:52 . 2010-10-15 09:26 -------- d-----w- C:\037172ef4a8cb5d6ced02f48
2010-10-14 15:05 . 2010-10-14 15:05 -------- d-----w- C:\5c250211bac71a1e100fc47942
2010-10-14 14:59 . 2010-10-14 14:59 -------- d-----w- C:\cd55a624b5fb66d6eff42459f55c
2010-10-14 14:50 . 2010-10-14 14:50 -------- d-----w- C:\8152dc79096dc4402aca
2010-10-14 14:09 . 2010-10-14 14:19 -------- d-----w- c:\programdata\DAEMON Tools Pro
2010-10-14 11:13 . 2010-10-14 11:13 -------- d-----w- C:\$AVG
2010-10-14 10:44 . 2010-10-14 10:44 -------- d--h--w- c:\programdata\Common Files
2010-10-14 10:43 . 2010-10-15 17:12 -------- d-----w- c:\windows\system32\drivers\AVG
2010-10-14 10:43 . 2010-10-14 14:05 -------- d-----w- c:\programdata\AVG10
2010-10-14 10:42 . 2010-10-15 11:52 -------- d-----w- c:\program files\AVG
2010-10-14 10:38 . 2010-10-14 10:42 -------- d-----w- c:\programdata\MFAData
2010-10-14 09:39 . 2009-10-09 21:55 39424 ----a-w- c:\windows\system32\bitsigd.dll
2010-10-14 09:39 . 2009-10-09 21:55 18432 ----a-w- c:\windows\system32\bitsperf.dll
2010-10-14 09:39 . 2009-10-09 21:55 584704 ----a-w- c:\windows\system32\qmgr.dll
2010-10-14 09:39 . 2009-10-09 21:55 17920 ----a-w- c:\windows\system32\bitsprx5.dll
2010-10-14 09:39 . 2009-10-09 21:55 10240 ----a-w- c:\windows\system32\bitsprx6.dll
2010-10-14 09:39 . 2009-10-09 21:55 9216 ----a-w- c:\windows\system32\bitsprx4.dll
2010-10-14 09:39 . 2009-10-09 21:55 10752 ----a-w- c:\windows\system32\bitsprx2.dll
2010-10-14 09:39 . 2009-10-09 21:55 10240 ----a-w- c:\windows\system32\bitsprx3.dll
2010-10-14 09:39 . 2009-10-09 21:55 20480 ----a-w- c:\windows\system32\qmgrprxy.dll
2010-10-14 09:22 . 2010-10-15 09:37 -------- d-----w- c:\program files\Windows Live Safety Center
2010-10-13 21:46 . 2010-10-13 21:46 -------- d-----w- c:\program files\CCleaner
2010-10-13 21:01 . 2009-10-05 14:20 907832 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-10-13 21:01 . 2009-10-05 11:39 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2010-10-13 20:59 . 2009-09-18 10:21 170496 ----a-w- c:\windows\system32\tcpipcfg.dll
2010-10-13 20:59 . 2009-09-18 10:20 22528 ----a-w- c:\windows\system32\netiougc.exe
2010-10-13 20:55 . 2009-11-06 10:51 197632 ----a-w- c:\windows\system32\drivers\usbhub.sys
2010-10-13 20:55 . 2009-11-06 10:51 73216 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-10-13 20:55 . 2009-11-06 10:51 228352 ----a-w- c:\windows\system32\drivers\usbport.sys
2010-10-13 20:55 . 2009-11-06 10:50 39936 ----a-w- c:\windows\system32\drivers\usbehci.sys
2010-10-13 20:55 . 2009-11-06 10:50 23552 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2010-10-13 20:55 . 2009-11-06 10:50 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
2010-10-13 20:42 . 2010-10-13 20:42 -------- d-----w- C:\ba8cf1429f4fac3d2f0de7
2010-10-13 20:42 . 2009-07-18 09:23 33280 ----a-w- c:\windows\system32\drivers\watchdog.sys
2010-10-13 20:30 . 2010-02-26 01:03 527360 ------w- c:\windows\system32\stapi32.dll
2010-10-13 20:29 . 2010-01-12 01:01 139776 ----a-w- c:\windows\system32\aestacap.dll
2010-10-13 20:29 . 2009-10-09 23:45 380928 ----a-w- c:\windows\system32\aestecap.dll
2010-10-13 20:29 . 2009-03-03 00:57 61440 ----a-w- c:\windows\system32\aestaren.dll
2010-10-13 20:29 . 2009-05-13 02:26 47104 ----a-w- c:\windows\system32\ctppld.dll
2010-10-13 20:29 . 2010-02-26 01:03 536576 ----a-w- c:\windows\system32\idtmini1.exe
2010-10-13 20:29 . 2010-02-26 01:03 3350528 ----a-w- c:\windows\system32\stlang.dll
2010-10-13 20:29 . 2010-02-26 01:03 12460124 ----a-w- c:\windows\system32\idtcpl.cpl
2010-10-13 20:28 . 2010-02-26 01:03 175616 ----a-w- c:\windows\system32\st326272.dll
2010-10-13 20:26 . 2009-07-14 17:45 445008 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2010-10-13 20:26 . 2009-07-14 17:45 38480 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2010-10-13 20:24 . 2009-07-14 11:27 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2010-10-13 20:24 . 2010-04-15 12:36 252536 ----a-w- c:\windows\system32\drivers\Apfiltr.sys
2010-10-13 19:58 . 2010-10-13 19:58 -------- d-----w- c:\users\Li\AppData\Local\Dell
2010-10-05 22:27 . 2010-10-05 22:27 -------- d-----w- c:\users\Li\AppData\Local\DBControl
2010-09-29 14:47 . 2010-09-29 14:47 -------- d-----w- c:\program files\iPod
2010-09-29 14:47 . 2010-09-29 14:48 -------- d-----w- c:\program files\iTunes
2010-09-29 14:43 . 2010-09-29 14:43 -------- d-----w- c:\program files\Bonjour
2010-09-29 12:42 . 2009-11-08 17:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-09-29 12:42 . 2009-11-08 17:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-09-29 12:42 . 2009-11-08 17:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-09-29 12:42 . 2009-11-08 17:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-09-29 12:42 . 2009-11-08 17:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-09-17 10:50 . 2010-09-17 10:50 -------- d-----w- c:\users\Li\AppData\Local\Orange
2010-09-17 10:49 . 2010-10-06 21:04 -------- d-----w- c:\program files\Orange Toolbar UK
2010-09-17 10:49 . 2010-09-17 10:49 -------- d-----w- c:\program files\Orange
2010-09-17 10:49 . 2007-06-21 11:05 116736 ----a-w- c:\windows\Uninstall_Livebox.EXE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-11-12 2923192]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-11 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-04-05 288040]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-11-17 3810304]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-05-07 178712]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-08-20 1164584]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-02-26 495708]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-01-16 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-01-16 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-01-16 150552]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2010-09-15 2745696]
"SBAMTray"="c:\program files\Sunbelt Software\CounterSpy\SBAMTray.exe" [2010-08-20 1348944]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
c:\users\Li\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-24 1295656]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Audible Download Manager.lnk - c:\program files\Audible\Bin\AudibleDownloadHelper.exe [2010-4-23 1795488]
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-24 1295656]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-03-17 22:40 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBPIMSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2009-10-19 09:57 323392 ----a-w- c:\users\Li\Program Files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-24 01:10 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-16 21:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2008-05-23 19:06 128296 ------w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 10:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QvodPlayer]
2009-06-11 11:06 537992 ----a-w- c:\program files\QvodPlayer\QvodTerminal.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-10-24 10:20 1217808 ----a-w- c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-04-01 19:59 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1ca1a74e50fc337;Google Update Service (gupdate1ca1a74e50fc337);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-11 133104]
R3 rsvcdwdr;rsvcdwdr;c:\windows\system32\DRIVERS\rsvcdwdr.sys [2010-04-19 33384]
R3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [2008-11-11 23096]
R3 SndTVideo;SndTVideo;c:\windows\system32\DRIVERS\SndTVideo.sys [2008-11-11 3768]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-10-12 436792]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2010-09-07 26064]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2010-09-07 249424]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2010-09-07 298448]
S1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2010-05-13 98392]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\aestsrv.exe [2009-03-03 81920]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-09-03 6104144]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [2010-09-10 265400]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-09-24 155648]
S2 SBAMSvc;CounterSpy Antispyware;c:\program files\Sunbelt Software\CounterSpy\SBAMSvc.exe [2010-08-20 2763080]
S2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys [2010-06-14 69976]
S2 SBPIMSvc;SB Recovery Service;c:\program files\Sunbelt Software\CounterSpy\SBPIMSvc.exe [2010-08-20 181584]
S2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2010-08-19 123472]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2010-08-19 30288]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2010-08-19 27216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
ComnGrp REG_MULTI_SZ ComnCena
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}]
2010-02-16 18:02 114688 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
2010-10-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-11 11:13]
2010-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-11 11:14]
2010-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-11 11:14]
2010-10-10 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-02-27 15:30]
2010-10-15 c:\windows\Tasks\User_Feed_Synchronization-{3BBF72A4-3175-489E-8690-9A51A8D140CD}.job
- c:\windows\system32\msfeedssync.exe [2009-10-19 03:41]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://uk.ask.com?o=15438&l=dis
mStart Page = hxxp://www.Google.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: 111222.cn\list1
Trusted Zone: pps.tv\kan
Trusted Zone: pps.tv\list1
Trusted Zone: pps.tv\tvguide
Trusted Zone: pps.tv\vodguide
Trusted Zone: ppstream.com\list1
Trusted Zone: ppstream.com\notice
Trusted Zone: ppstream.com\xml1
Trusted Zone: ppstream.com\xml2
Trusted Zone: ppstream.com\xml3
Trusted Zone: ppstream.net\list1
Trusted Zone: ppstv.com\list1
Trusted Zone: ppstv.net\list1
Trusted Zone: security_PPStream.exe
DPF: {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} - hxxp://t.live.cctv.com/ieocx/CCTVUpdateInstall.dll
FF - ProfilePath - c:\users\Li\AppData\Roaming\Mozilla\Firefox\Profiles\1nzx694r.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=BT5&o=15435&locale=en_UK&apn_uid=BBD1ED93-83EA-4395-9FCD-2D2F5FB5A448&apn_ptnrs=GG&apn_sauid=43CCB9ED-EFB8-47BA-A6F6-F73D363E5053&apn_dtid=YYYYYYB3GB&q=
FF - component: c:\program files\AVG\AVG10\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Li\AppData\Roaming\Mozilla\Firefox\Profiles\1nzx694r.default\extensions\[email protected]\plugins\npCCTVplayer.dll
FF - plugin: c:\users\Li\AppData\Roaming\Mozilla\Firefox\Profiles\1nzx694r.default\extensions\[email protected]\plugins\npTVUAx.dll
FF - plugin: c:\users\Li\Program Files\DNA\plugins\npbtdna.dll
FF - plugin: c:\users\Li\Program Files\DNA\plugins\npbtdna.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
MSConfigStartUp-mcagent_exe - c:\program files\McAfee.com\Agent\mcagent.exe
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3487666453-464672847-2176158843-1000\Software\G*e*n*i*e*"!\FM Genie Scout 10]
"GameDir"="c:\\Users\\Li\\Documents\\Sports Interactive\\Football Manager 2010\\games"
"ShortlistDir"=""
"ScreenshotsDir"="c:\\Users\\Li\\Documents\\Sports Interactive\\Football Manager 2010"
"SaveDir"="c:\\Users\\Li\\Documents\\Sports Interactive\\Football Manager 2010\\"
"HistoryDir"="c:\\Users\\Li\\Desktop\\New Folder (2)\\FM Genie Scout 10\\History Points"
"LangDB"=""
"LastSaveGame"=""
"Language"="English"
"LoadLangDB"=dword:00000000
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"GraphStep"=dword:00000000
"SkinName"="Steklo Black"
"LastUpdateCheck"=dword:00009d10
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000072
"UniqueID"="E5-8380-E7DF"
"Currency"=dword:00000056
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
.
Completion time: 2010-10-15 23:23:30
ComboFix-quarantined-files.txt 2010-10-15 22:23
Pre-Run: 52,884,918,272 bytes free
Post-Run: 52,851,712,000 bytes free
- - End Of File - - 5B496AEA557E394CE5521BD2803A16DF
Can you do me a favor, your log wasn't very legible
I tried to fix it with d'Rap, but it didn't work all that well
Can you reopen ComboFix.txt in Notepad
Click on FORMAT on the top menu and uncheck WORD WRAP then repost that log
[/quote]
ComboFix 10-10-14.04 - Li 15/10/2010 23:01:49.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3032.1860 [GMT 1:00]
Running from: c:\users\Li\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\fheydbueyj.exe
c:\fheydbueyj.exe\config.bin
c:\windows\system32\5c89e87aa3.dat
.
((((((((((((((((((((((((( Files Created from 2010-09-15 to 2010-10-15 )))))))))))))))))))))))))))))))
.
2010-10-15 22:19 . 2010-10-15 22:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-15 21:58 . 2010-10-15 21:59 -------- d-----w- C:\32788R22FWJFW
2010-10-15 21:44 . 2010-10-15 22:19 -------- d-----w- c:\users\Li\AppData\Local\temp
2010-10-15 20:28 . 2010-10-15 20:28 -------- d-----w- c:\users\Li\AppData\Roaming\Malwarebytes
2010-10-15 20:28 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-15 20:28 . 2010-10-15 20:28 -------- d-----w- c:\programdata\Malwarebytes
2010-10-15 20:28 . 2010-10-15 20:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-15 20:28 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-15 18:17 . 2010-10-15 18:17 388096 ----a-r- c:\users\Li\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-15 18:17 . 2010-10-15 18:17 -------- d-----w- c:\program files\Trend Micro
2010-10-15 11:54 . 2010-10-15 12:57 -------- d-----w- c:\users\Li\AppData\Roaming\AVG
2010-10-15 10:38 . 2010-10-15 10:38 -------- d-----w- c:\windows\CheckSur
2010-10-15 10:30 . 2010-10-15 10:30 -------- d-----w- c:\users\Li\AppData\Roaming\Sunbelt
2010-10-15 10:30 . 2010-10-15 10:30 -------- d-----w- c:\programdata\Sunbelt
2010-10-15 10:30 . 2010-10-15 10:30 -------- d-----w- c:\program files\Sunbelt Software
2010-10-15 09:24 . 2010-10-15 09:24 -------- d-----w- C:\8212b806078424617daad2
2010-10-15 09:22 . 2010-10-15 09:22 -------- d-----w- C:\933005583f2654c61388bf5e
2010-10-15 08:52 . 2010-10-15 09:26 -------- d-----w- C:\037172ef4a8cb5d6ced02f48
2010-10-14 15:05 . 2010-10-14 15:05 -------- d-----w- C:\5c250211bac71a1e100fc47942
2010-10-14 14:59 . 2010-10-14 14:59 -------- d-----w- C:\cd55a624b5fb66d6eff42459f55c
2010-10-14 14:50 . 2010-10-14 14:50 -------- d-----w- C:\8152dc79096dc4402aca
2010-10-14 14:09 . 2010-10-14 14:19 -------- d-----w- c:\programdata\DAEMON Tools Pro
2010-10-14 11:13 . 2010-10-14 11:13 -------- d-----w- C:\$AVG
2010-10-14 10:44 . 2010-10-14 10:44 -------- d--h--w- c:\programdata\Common Files
2010-10-14 10:43 . 2010-10-15 17:12 -------- d-----w- c:\windows\system32\drivers\AVG
2010-10-14 10:43 . 2010-10-14 14:05 -------- d-----w- c:\programdata\AVG10
2010-10-14 10:42 . 2010-10-15 11:52 -------- d-----w- c:\program files\AVG
2010-10-14 10:38 . 2010-10-14 10:42 -------- d-----w- c:\programdata\MFAData
2010-10-14 09:39 . 2009-10-09 21:55 39424 ----a-w- c:\windows\system32\bitsigd.dll
2010-10-14 09:39 . 2009-10-09 21:55 18432 ----a-w- c:\windows\system32\bitsperf.dll
2010-10-14 09:39 . 2009-10-09 21:55 584704 ----a-w- c:\windows\system32\qmgr.dll
2010-10-14 09:39 . 2009-10-09 21:55 17920 ----a-w- c:\windows\system32\bitsprx5.dll
2010-10-14 09:39 . 2009-10-09 21:55 10240 ----a-w- c:\windows\system32\bitsprx6.dll
2010-10-14 09:39 . 2009-10-09 21:55 9216 ----a-w- c:\windows\system32\bitsprx4.dll
2010-10-14 09:39 . 2009-10-09 21:55 10752 ----a-w- c:\windows\system32\bitsprx2.dll
2010-10-14 09:39 . 2009-10-09 21:55 10240 ----a-w- c:\windows\system32\bitsprx3.dll
2010-10-14 09:39 . 2009-10-09 21:55 20480 ----a-w- c:\windows\system32\qmgrprxy.dll
2010-10-14 09:22 . 2010-10-15 09:37 -------- d-----w- c:\program files\Windows Live Safety Center
2010-10-13 21:46 . 2010-10-13 21:46 -------- d-----w- c:\program files\CCleaner
2010-10-13 21:01 . 2009-10-05 14:20 907832 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-10-13 21:01 . 2009-10-05 11:39 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2010-10-13 20:59 . 2009-09-18 10:21 170496 ----a-w- c:\windows\system32\tcpipcfg.dll
2010-10-13 20:59 . 2009-09-18 10:20 22528 ----a-w- c:\windows\system32\netiougc.exe
2010-10-13 20:55 . 2009-11-06 10:51 197632 ----a-w- c:\windows\system32\drivers\usbhub.sys
2010-10-13 20:55 . 2009-11-06 10:51 73216 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-10-13 20:55 . 2009-11-06 10:51 228352 ----a-w- c:\windows\system32\drivers\usbport.sys
2010-10-13 20:55 . 2009-11-06 10:50 39936 ----a-w- c:\windows\system32\drivers\usbehci.sys
2010-10-13 20:55 . 2009-11-06 10:50 23552 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2010-10-13 20:55 . 2009-11-06 10:50 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
2010-10-13 20:42 . 2010-10-13 20:42 -------- d-----w- C:\ba8cf1429f4fac3d2f0de7
2010-10-13 20:42 . 2009-07-18 09:23 33280 ----a-w- c:\windows\system32\drivers\watchdog.sys
2010-10-13 20:30 . 2010-02-26 01:03 527360 ------w- c:\windows\system32\stapi32.dll
2010-10-13 20:29 . 2010-01-12 01:01 139776 ----a-w- c:\windows\system32\aestacap.dll
2010-10-13 20:29 . 2009-10-09 23:45 380928 ----a-w- c:\windows\system32\aestecap.dll
2010-10-13 20:29 . 2009-03-03 00:57 61440 ----a-w- c:\windows\system32\aestaren.dll
2010-10-13 20:29 . 2009-05-13 02:26 47104 ----a-w- c:\windows\system32\ctppld.dll
2010-10-13 20:29 . 2010-02-26 01:03 536576 ----a-w- c:\windows\system32\idtmini1.exe
2010-10-13 20:29 . 2010-02-26 01:03 3350528 ----a-w- c:\windows\system32\stlang.dll
2010-10-13 20:29 . 2010-02-26 01:03 12460124 ----a-w- c:\windows\system32\idtcpl.cpl
2010-10-13 20:28 . 2010-02-26 01:03 175616 ----a-w- c:\windows\system32\st326272.dll
2010-10-13 20:26 . 2009-07-14 17:45 445008 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2010-10-13 20:26 . 2009-07-14 17:45 38480 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2010-10-13 20:24 . 2009-07-14 11:27 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2010-10-13 20:24 . 2010-04-15 12:36 252536 ----a-w- c:\windows\system32\drivers\Apfiltr.sys
2010-10-13 19:58 . 2010-10-13 19:58 -------- d-----w- c:\users\Li\AppData\Local\Dell
2010-10-05 22:27 . 2010-10-05 22:27 -------- d-----w- c:\users\Li\AppData\Local\DBControl
2010-09-29 14:47 . 2010-09-29 14:47 -------- d-----w- c:\program files\iPod
2010-09-29 14:47 . 2010-09-29 14:48 -------- d-----w- c:\program files\iTunes
2010-09-29 14:43 . 2010-09-29 14:43 -------- d-----w- c:\program files\Bonjour
2010-09-29 12:42 . 2009-11-08 17:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-09-29 12:42 . 2009-11-08 17:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-09-29 12:42 . 2009-11-08 17:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-09-29 12:42 . 2009-11-08 17:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-09-29 12:42 . 2009-11-08 17:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-09-17 10:50 . 2010-09-17 10:50 -------- d-----w- c:\users\Li\AppData\Local\Orange
2010-09-17 10:49 . 2010-10-06 21:04 -------- d-----w- c:\program files\Orange Toolbar UK
2010-09-17 10:49 . 2010-09-17 10:49 -------- d-----w- c:\program files\Orange
2010-09-17 10:49 . 2007-06-21 11:05 116736 ----a-w- c:\windows\Uninstall_Livebox.EXE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-11-12 2923192]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-11 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-04-05 288040]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-11-17 3810304]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-05-07 178712]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-08-20 1164584]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-02-26 495708]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-01-16 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-01-16 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-01-16 150552]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2010-09-15 2745696]
"SBAMTray"="c:\program files\Sunbelt Software\CounterSpy\SBAMTray.exe" [2010-08-20 1348944]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
c:\users\Li\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-24 1295656]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Audible Download Manager.lnk - c:\program files\Audible\Bin\AudibleDownloadHelper.exe [2010-4-23 1795488]
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-24 1295656]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-03-17 22:40 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBPIMSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2009-10-19 09:57 323392 ----a-w- c:\users\Li\Program Files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-24 01:10 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-16 21:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2008-05-23 19:06 128296 ------w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 10:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QvodPlayer]
2009-06-11 11:06 537992 ----a-w- c:\program files\QvodPlayer\QvodTerminal.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-10-24 10:20 1217808 ----a-w- c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-04-01 19:59 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1ca1a74e50fc337;Google Update Service (gupdate1ca1a74e50fc337);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-11 133104]
R3 rsvcdwdr;rsvcdwdr;c:\windows\system32\DRIVERS\rsvcdwdr.sys [2010-04-19 33384]
R3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [2008-11-11 23096]
R3 SndTVideo;SndTVideo;c:\windows\system32\DRIVERS\SndTVideo.sys [2008-11-11 3768]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-10-12 436792]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2010-09-07 26064]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2010-09-07 249424]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2010-09-07 298448]
S1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2010-05-13 98392]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_0145da1d\aestsrv.exe [2009-03-03 81920]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-09-03 6104144]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [2010-09-10 265400]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-09-24 155648]
S2 SBAMSvc;CounterSpy Antispyware;c:\program files\Sunbelt Software\CounterSpy\SBAMSvc.exe [2010-08-20 2763080]
S2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys [2010-06-14 69976]
S2 SBPIMSvc;SB Recovery Service;c:\program files\Sunbelt Software\CounterSpy\SBPIMSvc.exe [2010-08-20 181584]
S2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2010-08-19 123472]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2010-08-19 30288]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2010-08-19 27216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
ComnGrp REG_MULTI_SZ ComnCena
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}]
2010-02-16 18:02 114688 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
2010-10-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-11 11:13]
2010-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-11 11:14]
2010-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-11 11:14]
2010-10-10 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-02-27 15:30]
2010-10-15 c:\windows\Tasks\User_Feed_Synchronization-{3BBF72A4-3175-489E-8690-9A51A8D140CD}.job
- c:\windows\system32\msfeedssync.exe [2009-10-19 03:41]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://uk.ask.com?o=15438&l=dis
mStart Page = hxxp://www.Google.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: 111222.cn\list1
Trusted Zone: pps.tv\kan
Trusted Zone: pps.tv\list1
Trusted Zone: pps.tv\tvguide
Trusted Zone: pps.tv\vodguide
Trusted Zone: ppstream.com\list1
Trusted Zone: ppstream.com\notice
Trusted Zone: ppstream.com\xml1
Trusted Zone: ppstream.com\xml2
Trusted Zone: ppstream.com\xml3
Trusted Zone: ppstream.net\list1
Trusted Zone: ppstv.com\list1
Trusted Zone: ppstv.net\list1
Trusted Zone: security_PPStream.exe
DPF: {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} - hxxp://t.live.cctv.com/ieocx/CCTVUpdateInstall.dll
FF - ProfilePath - c:\users\Li\AppData\Roaming\Mozilla\Firefox\Profiles\1nzx694r.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=BT5&o=15435&locale=en_UK&apn_uid=BBD1ED93-83EA-4395-9FCD-2D2F5FB5A448&apn_ptnrs=GG&apn_sauid=43CCB9ED-EFB8-47BA-A6F6-F73D363E5053&apn_dtid=YYYYYYB3GB&q=
FF - component: c:\program files\AVG\AVG10\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Li\AppData\Roaming\Mozilla\Firefox\Profiles\1nzx694r.default\extensions\[email protected]\plugins\npCCTVplayer.dll
FF - plugin: c:\users\Li\AppData\Roaming\Mozilla\Firefox\Profiles\1nzx694r.default\extensions\[email protected]\plugins\npTVUAx.dll
FF - plugin: c:\users\Li\Program Files\DNA\plugins\npbtdna.dll
FF - plugin: c:\users\Li\Program Files\DNA\plugins\npbtdna.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
MSConfigStartUp-mcagent_exe - c:\program files\McAfee.com\Agent\mcagent.exe
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3487666453-464672847-2176158843-1000\Software\G*e*n*i*e*"!\FM Genie Scout 10]
"GameDir"="c:\\Users\\Li\\Documents\\Sports Interactive\\Football Manager 2010\\games"
"ShortlistDir"=""
"ScreenshotsDir"="c:\\Users\\Li\\Documents\\Sports Interactive\\Football Manager 2010"
"SaveDir"="c:\\Users\\Li\\Documents\\Sports Interactive\\Football Manager 2010\\"
"HistoryDir"="c:\\Users\\Li\\Desktop\\New Folder (2)\\FM Genie Scout 10\\History Points"
"LangDB"=""
"LastSaveGame"=""
"Language"="English"
"LoadLangDB"=dword:00000000
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"GraphStep"=dword:00000000
"SkinName"="Steklo Black"
"LastUpdateCheck"=dword:00009d10
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000072
"UniqueID"="E5-8380-E7DF"
"Currency"=dword:00000056
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
.
Completion time: 2010-10-15 23:23:30
ComboFix-quarantined-files.txt 2010-10-15 22:23
Pre-Run: 52,884,918,272 bytes free
Post-Run: 52,851,712,000 bytes free
- - End Of File - - 5B496AEA557E394CE5521BD2803A16DF