ComboFix 10-08-06.01 - Marshall 08/06/2010 21:10:34.1.1 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1899 [GMT -4:00]
Running from: c:\users\Marshall\Downloads\Combo-Fix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Marshall\AppData\Local\brslppjiv
c:\users\Marshall\AppData\Local\brslppjiv\egkqlxwtssd.exe
c:\users\Marshall\AppData\Roaming\data.dat
.
((((((((((((((((((((((((( Files Created from 2010-07-07 to 2010-08-07 )))))))))))))))))))))))))))))))
.
2010-08-07 01:24 . 2010-08-07 01:24 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-04 19:56 . 2008-03-19 15:12 1140056 ------w- c:\programdata\HP\Installer\Temp\hpzmsi01.exe
2010-07-29 05:32 . 2010-07-29 05:32 -------- d-----w- c:\users\Marshall\AppData\Roaming\Publish Providers
2010-07-29 05:30 . 2010-07-29 20:50 -------- d-----w- c:\users\Marshall\AppData\Roaming\Sony
2010-07-29 05:30 . 2010-07-29 05:30 -------- d-----w- c:\users\Marshall\AppData\Local\Sony
2010-07-29 05:27 . 2009-05-20 20:17 -------- d-----w- c:\users\Marshall\Sony.Products.Multikeygen.v1.5.Keygen.Only-DI
2010-07-29 05:23 . 2010-07-29 05:23 -------- d-----w- c:\programdata\Sony
2010-07-29 05:22 . 2010-07-29 05:22 -------- d-----w- c:\program files\Sony
2010-07-28 06:19 . 2010-07-28 06:19 -------- d-----w- c:\program files\iPod
2010-07-28 06:13 . 2010-07-28 06:13 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-20 05:56 . 2010-07-20 05:56 -------- d-----w- c:\users\Marshall\AppData\Local\ElevatedDiagnostics
2010-07-20 05:08 . 2010-07-20 05:12 -------- d-----w- c:\program files\Microsoft ATS
2010-07-19 03:55 . 2009-05-18 17:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-07-19 03:55 . 2008-04-17 16:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-07-19 03:53 . 2010-07-28 06:20 -------- d-----w- c:\program files\iTunes
2010-07-19 03:47 . 2010-07-19 03:49 -------- d-----w- c:\program files\QuickTime
2010-07-19 03:38 . 2010-07-19 03:38 -------- d-----w- c:\program files\Bonjour
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-05 23:05 . 2010-01-05 09:18 -------- d-----w- c:\program files\wowmodelview-r672
2010-08-05 00:05 . 2009-07-01 23:39 -------- d-----w- c:\users\Marshall\AppData\Roaming\uTorrent
2010-08-04 23:35 . 2009-10-12 03:28 -------- d-----w- c:\program files\IZArc
2010-07-30 18:57 . 2009-07-02 01:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-30 00:42 . 2009-07-16 22:43 -------- d-----w- c:\program files\WeGame
2010-07-28 06:19 . 2010-04-19 23:42 -------- d-----w- c:\program files\Common Files\Apple
2010-07-19 04:22 . 2009-07-02 00:03 -------- d-----w- c:\users\Marshall\AppData\Roaming\Apple Computer
2010-07-15 07:02 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-25 07:01 . 2010-06-25 07:01 -------- d-----w- c:\program files\Microsoft.NET
2010-06-22 18:56 . 2009-08-19 21:06 -------- d-----w- c:\programdata\Blizzard Entertainment
2010-05-26 17:06 . 2010-06-10 19:48 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-10 19:48 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-21 18:14 . 2009-10-03 03:01 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2008-07-30 14:43 . 2008-07-30 14:43 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 16:47 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2009-05-13 19:34 238968 ----a-w- c:\program files\Webroot\Spy Sweeper\Backup\CtxMenu_1_0_0_10.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\Marshall\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-07-01 133104]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-08-25 288048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-02 75008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-20 148888]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-26 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"DVDAgent"="c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2009-09-09 1148200]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-03-29 2145000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2009-05-13 6345840]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
PictureMover.lnk - c:\program files\PictureMover\Bin\PictureMover.exe [2008-6-3 413696]
WeGame.lnk - c:\program files\WeGame\wegame.exe [2009-7-16 1527296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):ca,87,f3,35,a5,68,ca,01
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [2009-04-02 234888]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 netr28u;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr28u.sys [2007-12-14 570880]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 ssfs0bbc;ssfs0bbc;c:\windows\system32\DRIVERS\ssfs0bbc.sys [2009-04-21 29808]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-03-29 114984]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-03-29 134024]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-03-29 810120]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-03-29 96896]
S2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\Spy Sweeper\WRConsumerService.exe [2009-07-02 1205760]
S3 HSXHWBS3;HSXHWBS3;c:\windows\system32\DRIVERS\HSXHWBS3.sys [2008-02-12 207360]
S3 WUSB54GSCv2.NTx86;Compact Wireless-G USB Network Adapter with SpeedBooster Service;c:\windows\system32\DRIVERS\WUSB54GSCV2_X86.sys [2008-01-08 238072]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-08-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-656297243-3801516935-1174647162-1001Core.job
- c:\users\Marshall\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-01 21:55]
2010-08-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-656297243-3801516935-1174647162-1001UA.job
- c:\users\Marshall\AppData\Local\Google\Update\GoogleUpdate.exe [2009-07-01 21:55]
2009-01-06 c:\windows\Tasks\HPCeeScheduleForEudora.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-07-30 03:03]
2010-08-06 c:\windows\Tasks\wrSpySweeper_L4C4DC96FF8634D1B8F378459361D40F4.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2009-07-02 19:40]
2010-08-06 c:\windows\Tasks\wrSpySweeper_L4C4DC96FF8634D1B8F378459361D40F4.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2009-07-02 19:40]
2010-08-03 c:\windows\Tasks\wrSpySweeper_L926A508A80214CA0A80874F33901AF29.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2009-07-02 19:40]
2010-08-03 c:\windows\Tasks\wrSpySweeper_L926A508A80214CA0A80874F33901AF29.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2009-07-02 19:40]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ask.com/?o=13920&l=dis
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Presario&pf=cndt
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Presario&pf=cndt
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:6522
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-HostManager - c:\program files\Common Files\AOL\1232289610\ee\AOLSoftware.exe
ActiveSetup-{BFF8B6B0-DAF6-CF92-6F4C-81BCAEAEACC9}t - c:\users\Marshall\AppData\Roaming\mswhelp.exe
ActiveSetup-{CECDFBDF-7C6B-AC6D-FD6A-7DC2E1E6301C} - c:\users\Marshall\AppData\Local\Temp\incognito.exe
AddRemove-AOL Uninstaller - c:\program files\Common Files\AOL\uninstaller.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-06 21:25
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-08-06 21:31:14
ComboFix-quarantined-files.txt 2010-08-07 01:31
Pre-Run: 105,763,741,696 bytes free
Post-Run: 105,774,116,864 bytes free
- - End Of File - - C029A6B4978ECCE180A732A0C8832337