ComboFix 09-10-18.06 - Philip 06/11/2009 12:25:47.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.34.3082.18.3069.2091 [GMT 1:00]
Running from: C:\Users\Philip\Downloads\ComboFix.exe
FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2009-10-06 to 2009-11-06 )))))))))))))))))))))))))))))))
.
2009-11-06 11:26:48 . 2009-11-06 11:26:53 0 d-----w- C:\Users\Philip\AppData\Local\temp
2009-11-06 11:26:48 . 2009-11-06 11:26:48 0 d-----w- C:\Users\Default\AppData\Local\temp
2009-11-06 11:15:14 . 2009-11-06 11:15:14 0 d-----w- C:\found.003
2009-11-05 12:47:47 . 2009-11-05 12:47:51 0 d--h--w- C:\Users\Philip\AppData\Local\acer eNM
2009-11-05 12:47:42 . 2009-11-05 12:47:42 0 d-----w- C:\Users\Philip\AppData\Local\ATI
2009-11-05 12:15:36 . 2009-09-10 14:58:28 310784 ----a-w- C:\Windows\system32\unregmp2.exe
2009-11-05 12:15:35 . 2009-09-10 14:59:26 8147456 ----a-w- C:\Windows\system32\wmploc.DLL
2009-10-21 10:25:00 . 2009-08-07 02:24:08 44768 ----a-w- C:\Windows\system32\wups2.dll
2009-10-21 10:25:00 . 2009-08-07 02:24:04 53472 ----a-w- C:\Windows\system32\wuauclt.exe
2009-10-21 10:25:00 . 2009-08-07 02:23:45 1929952 ----a-w- C:\Windows\system32\wuaueng.dll
2009-10-21 10:25:00 . 2009-08-07 01:45:15 2421760 ----a-w- C:\Windows\system32\wucltux.dll
2009-10-21 10:24:47 . 2009-08-07 02:24:09 35552 ----a-w- C:\Windows\system32\wups.dll
2009-10-21 10:24:47 . 2009-08-07 02:23:52 575704 ----a-w- C:\Windows\system32\wuapi.dll
2009-10-21 10:24:47 . 2009-08-07 01:44:40 87552 ----a-w- C:\Windows\system32\wudriver.dll
2009-10-21 10:24:35 . 2009-08-06 17:23:06 171608 ----a-w- C:\Windows\system32\wuwebv.dll
2009-10-21 10:24:35 . 2009-08-06 16:44:46 33792 ----a-w- C:\Windows\system32\wuapp.exe
2009-10-19 20:54:11 . 2009-10-19 20:54:11 0 d-----w- C:\$AVG
2009-10-19 20:54:07 . 2009-10-24 08:37:35 360584 ----a-w- C:\Windows\system32\drivers\avgtdix.sys
2009-10-19 20:54:07 . 2009-10-19 20:54:07 12464 ----a-w- C:\Windows\system32\avgrsstx.dll
2009-10-19 20:53:59 . 2009-10-19 20:53:59 333192 ----a-w- C:\Windows\system32\drivers\avgldx86.sys
2009-10-19 20:53:59 . 2009-10-19 20:53:59 28424 ----a-w- C:\Windows\system32\drivers\avgmfx86.sys
2009-10-19 20:53:58 . 2009-11-06 10:15:31 0 d-----w- C:\Windows\system32\drivers\Avg
2009-10-19 20:53:27 . 2009-10-19 20:53:27 0 d-----w- C:\ProgramData\avg9
2009-10-19 18:50:35 . 2009-10-19 18:50:35 0 d-----w- C:\found.002
2009-10-19 08:51:17 . 2009-10-19 08:51:17 0 d-----w- C:\Users\Philip\DoctorWeb
2009-10-18 13:53:26 . 2009-10-18 13:53:26 0 d-----w- C:\Program Files\Sophos
2009-10-17 11:43:48 . 2009-10-17 11:43:48 0 d-----w- C:\Program Files\Trend Micro
2009-10-17 10:04:56 . 2009-07-28 14:33:56 55656 ----a-w- C:\Windows\system32\drivers\avgntflt.sys
2009-10-17 07:51:32 . 2009-10-17 07:51:32 0 d-----w- C:\found.001
2009-10-16 19:47:01 . 2009-10-16 19:47:01 0 d-----w- C:\found.000
2009-10-14 08:01:07 . 2009-09-10 16:48:01 218624 ----a-w- C:\Windows\system32\msv1_0.dll
2009-10-14 08:01:04 . 2009-09-04 11:41:59 60928 ----a-w- C:\Windows\system32\msasn1.dll
2009-10-14 08:00:50 . 2009-09-14 09:29:50 144896 ----a-w- C:\Windows\system32\drivers\srv2.sys
2009-10-14 07:58:30 . 2009-05-08 12:53:00 604672 ----a-w- C:\Windows\system32\WMSPDMOD.DLL
2009-10-07 17:37:04 . 2009-10-01 08:29:14 195440 ------w- C:\Windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-05 12:07:53 . 2008-09-15 14:32:23 0 d-----w- C:\Program Files\PC Tools Firewall Plus
2009-10-21 15:13:31 . 2009-09-12 12:34:51 0 d-----w- C:\Users\Philip\AppData\Roaming\Spotify
2009-10-21 10:19:50 . 2008-09-17 13:13:42 0 d-----w- C:\Program Files\Java
2009-10-21 09:57:45 . 2009-04-10 08:32:50 0 d-----w- C:\ProgramData\NCH Swift Sound
2009-10-19 20:53:27 . 2008-10-30 10:07:38 0 d-----w- C:\Program Files\AVG
2009-10-19 16:54:22 . 2008-01-21 07:23:13 124696 ----a-w- C:\Windows\system32\perfc00A.dat
2009-10-19 16:54:22 . 2008-01-21 07:23:13 0 ----a-w- C:\Windows\system32\perfh00A.dat
2009-10-19 16:07:19 . 2008-09-15 14:30:59 0 d-----w- C:\Program Files\Spybot - Search & Destroy
2009-10-19 16:07:18 . 2008-09-15 14:31:00 0 d-----w- C:\ProgramData\Spybot - Search & Destroy
2009-10-18 13:26:14 . 2009-09-07 15:51:54 0 d-----w- C:\Users\Philip\AppData\Roaming\vlc
2009-10-16 20:31:33 . 2008-09-18 08:35:20 45156 ----a-w- C:\Users\Philip\AppData\Roaming\wklnhst.dat
2009-10-15 15:18:22 . 2008-09-22 15:47:21 0 d-----w- C:\Users\Philip\AppData\Roaming\uTorrent
2009-10-14 08:35:34 . 2006-11-02 11:18:33 0 d-----w- C:\Program Files\Windows Mail
2009-10-14 08:08:54 . 2008-03-28 20:24:22 0 d-----w- C:\ProgramData\Microsoft Help
2009-10-14 08:06:23 . 2008-03-28 20:26:37 0 d-----w- C:\Program Files\Microsoft Works
2009-10-12 11:48:43 . 2008-09-17 13:15:20 0 d-----w- C:\Users\Philip\AppData\Roaming\LimeWire
2009-10-09 09:07:20 . 2008-09-15 20:02:16 0 d-----w- C:\Users\Philip\AppData\Roaming\Skype
2009-09-16 09:47:24 . 2009-09-16 09:35:26 0 d-----w- C:\Users\Philip\AppData\Roaming\TeamViewer
2009-09-16 09:35:20 . 2009-09-16 09:35:20 0 d-----w- C:\Program Files\TeamViewer
2009-09-14 11:13:35 . 2009-07-24 12:43:34 0 d-----w- C:\Program Files\Microsoft Silverlight
2009-09-12 12:34:48 . 2009-09-12 12:34:47 0 d-----w- C:\Program Files\Spotify
2009-09-07 15:50:26 . 2009-09-07 15:50:26 0 d-----w- C:\Program Files\VideoLAN
2009-08-29 00:27:49 . 2009-09-02 08:52:03 4240384 ----a-w- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14:38 . 2009-09-02 08:52:04 28672 ----a-w- C:\Windows\system32\Apphlpdm.dll
2009-08-27 05:22:28 . 2009-10-14 08:02:22 916480 ----a-w- C:\Windows\system32\wininet.dll
2009-08-27 05:17:43 . 2009-10-14 08:02:21 71680 ----a-w- C:\Windows\system32\iesetup.dll
2009-08-27 05:17:43 . 2009-10-14 08:02:21 109056 ----a-w- C:\Windows\system32\iesysprep.dll
2009-08-27 03:42:29 . 2009-10-14 08:02:21 133632 ----a-w- C:\Windows\system32\ieUnatt.exe
2009-08-24 22:04:57 . 2008-09-14 15:45:37 101856 ----a-w- C:\Users\Philip\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-21 10:01:05 . 2009-08-21 10:01:05 2892 ----a-w- C:\Windows\system32\audcon.sys
2009-08-17 21:33:52 . 2009-08-17 21:33:52 1193832 ----a-w- C:\Windows\system32\FM20.DLL
2009-08-14 16:27:34 . 2009-09-14 10:31:39 904776 ----a-w- C:\Windows\system32\drivers\tcpip.sys
2009-08-14 15:53:34 . 2009-09-14 10:31:38 17920 ----a-w- C:\Windows\system32\netevent.dll
2009-08-14 13:49:20 . 2009-09-14 10:31:38 9728 ----a-w- C:\Windows\system32\TCPSVCS.EXE
2009-08-14 13:49:18 . 2009-09-14 10:31:38 17920 ----a-w- C:\Windows\system32\ROUTE.EXE
2009-08-14 13:49:18 . 2009-09-14 10:31:38 11264 ----a-w- C:\Windows\system32\MRINFO.EXE
2009-08-14 13:49:15 . 2009-09-14 10:31:38 27136 ----a-w- C:\Windows\system32\NETSTAT.EXE
2009-08-14 13:49:14 . 2009-09-14 10:31:38 8704 ----a-w- C:\Windows\system32\HOSTNAME.EXE
2009-08-14 13:49:14 . 2009-09-14 10:31:38 19968 ----a-w- C:\Windows\system32\ARP.EXE
2009-08-14 13:49:13 . 2009-09-14 10:31:38 10240 ----a-w- C:\Windows\system32\finger.exe
2009-08-14 13:48:21 . 2009-09-14 10:31:38 30720 ----a-w- C:\Windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48:02 . 2009-09-14 10:31:38 105984 ----a-w- C:\Windows\system32\netiohlp.dll
2009-07-28 05:41:04 . 2009-07-28 05:41:03 82129 ----a-w- C:\Program Files\UninstalAlpha.exe
2009-07-28 05:21:04 . 2009-07-28 05:15:43 3667 ----a-w- C:\Program Files\unins000.dat
2003-06-16 13:23:22 . 2003-06-16 13:23:22 131072 ----a-w- C:\Program Files\T2DXi.dll
2003-06-16 13:17:50 . 2003-06-16 13:17:50 4317184 ----a-w- C:\Program Files\Triangle II.dll
2003-06-03 10:33:38 . 2003-06-03 10:33:38 90112 ----a-w- C:\Program Files\Triangle II.exe
2002-12-17 01:00:00 . 2002-12-17 01:00:00 82253 ----a-w- C:\Program Files\unins000.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-01-03 01:00:48 39472 ----a-w- C:\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CollaborationHost"="C:\Windows\system32\p2phost.exe" [2008-01-21 02:25:26 192000]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-21 02:25:11 125952]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 02:25:33 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-21 02:23:32 1008184]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2008-03-11 02:11:00 92704]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-03-11 02:11:00 8534560]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-03-11 02:11:00 88608]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2008-01-24 02:28:00 102400]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-02-25 08:53:24 518656]
"eAudio"="C:\Acer\Empowering Technology\eAudio\eAudio.exe" [2007-10-10 05:41:54 1286144]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-11-22 08:01:00 178712]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 10:17:18 61440]
"LManager"="C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE" [2008-01-02 13:17:28 707080]
"PlayMovie"="C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2008-01-22 09:14:24 200704]
"PLFSet"="C:\Windows\PLFSet.dll" [2007-04-25 11:47:34 45056]
"WarReg_PopUp"="C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 07:03:46 303104]
"00PCTFW"="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [2008-03-28 12:37:34 2598808]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 09:44:34 31072]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 00:04:34 39792]
"AVG9_TRAY"="C:\PROGRA~1\AVG\AVG9\avgtray.exe" [2009-10-24 08:37:40 2010904]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-07-31 13:23:21 149280]
"RtHDVCpl"="RtHDVCpl.exe" - C:\Windows\RtHDVCpl.exe [2008-01-24 02:29:00 4702208]
"Skytel"="Skytel.exe" - C:\Windows\SkyTel.exe [2008-01-24 02:29:00 1826816]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-9-15 110592]
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2008-3-28 535336]
SETAUDIO.EXE [2008-4-4 20480]
SETRES.EXE [2008-4-4 20480]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\Windows\System32\avgrsstx.dll C:\Windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):82,9e,88,8b,4e,0c,ca,01
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\Windows\System32\drivers\avgldx86.sys [19/10/2009 21:53:59 333192]
R1 AvgTdiX;AVG Free Network Redirector;C:\Windows\System32\drivers\avgtdix.sys [19/10/2009 21:54:07 360584]
R1 pctfw2;pctfw2;C:\Windows\System32\drivers\pctfw2.sys [15/09/2008 15:32:25 159896]
R1 pctmp;PC Tools Firewall Memory Protection Driver;C:\Windows\System32\drivers\pctmp.sys [15/09/2008 15:32:25 40856]
R1 pctssipc;PC Tools Security Suite IPC Driver;C:\Windows\System32\drivers\pctssipc.sys [15/09/2008 15:32:25 18328]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files\Acer Arcade Deluxe\Play Movie\000.fcl [24/06/2008 3:22:41 41456]
R2 ALaunchService;ALaunch Service;C:\Acer\ALaunch\ALaunchSvc.exe [28/03/2008 21:48:50 51200]
R2 avg9wd;AVG Free WatchDog;C:\Program Files\AVG\AVG9\avgwdsvc.exe [19/10/2009 21:53:28 285392]
R2 TeamViewer4;TeamViewer 4;C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe [24/08/2009 15:51:46 185640]
R3 winbondcir;Winbond IR Transceiver;C:\Windows\System32\drivers\winbondcir.sys [29/03/2008 3:57:01 43008]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\b57nd60x.sys [29/03/2008 3:57:01 179712]
S3 fssfltr;FssFltr;C:\Windows\System32\drivers\fssfltr.sys [19/03/2009 13:03:32 55280]
S3 fsssvc;Windows Live Family Safety;C:\Program Files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08:58 533360]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;C:\Windows\System32\drivers\ewdcsc.sys [29/09/2008 18:56:13 23424]
S3 TASCAM_US122144;TASCAM USB 2.0 Audio Device driver;C:\Windows\System32\drivers\tascusb2.sys [20/07/2009 10:54:46 360448]
S3 TASCAM_US122L_MIDI;TASCAM US-122L WDM MIDI Device;C:\Windows\System32\drivers\tscusb2m.sys [20/07/2009 10:54:46 18944]
S3 TASCAM_US122L_WDM;TASCAM US-122L WDM;C:\Windows\System32\drivers\tscusb2a.sys [20/07/2009 10:54:46 33792]
S3 V0090VID;Creative WebCam Vista Plus;C:\Windows\System32\drivers\V0090Vid.sys [15/09/2008 9:57:04 138112]
.
.
------- Supplementary Scan -------
.
mStart Page = hxxp://es.es.acer.yahoo.com
IE: E&xportar a Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {AEBF5237-CB87-46BE-896A-D90B09991B48} = 194.179.1.100 194.179.1.101
FF - ProfilePath - C:\Users\Philip\AppData\Roaming\Mozilla\Firefox\Profiles\unbmf3yv.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - [url]www.hln.be[/url]
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=IM3DJUN09FFAB&search=
FF - component: C:\Program Files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: C:\Program Files\Microsoft\Office Live\npOLW.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: C:\Program Files\Virtual Earth 3D\npVE3D.dll
FF - plugin: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.