Combo Fix Log.
ComboFix 12-05-13.03 - 05/13/2012 13:09:25.3.2 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3454.2215 [GMT -7:00]
Running from: c:\users\\Downloads\ComboFix.exe
Command switches used :: c:\users\\Desktop\CFScript - Shortcut.lnk
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-04-13 to 2012-05-13 )))))))))))))))))))))))))))))))
.
.
2012-05-13 20:12 . 2012-05-13 20:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-05-12 21:45 . 2012-05-13 20:12 -------- d-----w- c:\users\Robert Rantzow\AppData\Local\temp
2012-05-11 21:08 . 2012-03-30 12:39 905600 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-05-11 21:08 . 2012-03-20 23:28 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-05-08 03:05 . 2012-05-08 03:05 388096 ----a-r- c:\users\Robert Rantzow\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-05-08 03:05 . 2012-05-08 03:05 -------- d-----w- c:\program files\Trend Micro
2012-05-08 02:46 . 2012-05-08 02:46 -------- d-----w- C:\TDSSKiller_Quarantine
2012-05-05 02:46 . 2012-03-01 11:01 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-05-03 03:10 . 2012-05-13 15:58 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-05-03 03:10 . 2012-05-12 21:55 85432 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2012-05-03 03:10 . 2012-04-25 22:58 770384 ----a-w- c:\program files\Mozilla Firefox\msvcr100.dll
2012-05-03 03:10 . 2012-04-25 22:58 421200 ----a-w- c:\program files\Mozilla Firefox\msvcp100.dll
2012-05-03 03:10 . 2012-05-12 21:55 624568 ----a-w- c:\program files\Mozilla Firefox\gkmedias.dll
2012-05-03 03:10 . 2012-05-12 21:55 43448 ----a-w- c:\program files\Mozilla Firefox\mozglue.dll
2012-05-03 03:10 . 2012-05-12 21:55 157560 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe
2012-05-03 03:10 . 2012-05-12 21:55 113080 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
2012-04-29 16:17 . 2012-04-29 16:17 -------- d-----w- c:\programdata\NVIDIA Corporation
2012-04-29 16:17 . 2012-04-29 16:18 -------- d-----w- c:\program files\NVIDIA Corporation
2012-04-29 16:16 . 2010-06-07 23:57 56936 ----a-w- c:\windows\system32\OpenCL.dll
2012-04-29 16:16 . 2010-06-07 23:57 10888168 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-04-29 16:16 . 2010-06-07 23:57 4513384 ----a-w- c:\windows\system32\nvcuda.dll
2012-04-29 16:16 . 2010-06-07 23:57 2632296 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-04-29 16:16 . 2010-06-07 23:57 2145896 ----a-w- c:\windows\system32\nvcuvid.dll
2012-04-29 16:16 . 2010-06-07 23:57 15764072 ----a-w- c:\windows\system32\nvoglv32.dll
2012-04-29 16:16 . 2010-06-07 23:57 232040 ----a-w- c:\windows\system32\nvcod1921.dll
2012-04-29 16:16 . 2010-06-07 23:57 232040 ----a-w- c:\windows\system32\nvcod.dll
2012-04-29 16:16 . 2010-06-07 23:57 10263144 ----a-w- c:\windows\system32\nvcompiler.dll
2012-04-29 16:16 . 2012-04-29 16:16 -------- d-----w- C:\NVIDIA
2012-04-26 23:26 . 2012-05-12 10:24 -------- d-----w- c:\program files\Microsoft Silverlight
2012-04-16 14:20 . 2012-05-07 14:12 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-07 14:12 . 2011-12-18 02:45 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-04 22:56 . 2012-02-01 17:38 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-17 18:55 . 2012-01-16 02:48 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-29 15:11 . 2012-04-12 10:04 5120 ----a-w- c:\windows\system32\wmi.dll
2012-02-29 15:11 . 2012-04-12 10:04 172032 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 15:09 . 2012-04-12 10:04 157696 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 13:32 . 2012-04-12 10:04 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-02-28 01:18 . 2012-04-12 10:04 1799168 ----a-w- c:\windows\system32\jscript9.dll
2012-02-28 01:11 . 2012-04-12 10:04 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2012-02-28 01:11 . 2012-04-12 10:04 1127424 ----a-w- c:\windows\system32\wininet.dll
2012-02-28 01:03 . 2012-04-12 10:04 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-02-15 18:01 . 2012-02-15 18:01 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll
2012-02-15 18:01 . 2012-02-15 18:01 43520 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2012-05-12 21:55 . 2012-05-03 03:10 85432 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn\YTNavAssist.dll" [2011-07-21 214840]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"InstallIQUpdater"="c:\program files\W3i\InstallIQUpdater\InstallIQUpdater.exe" [2011-10-11 1179648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-25 2416480]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 4874240]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-07 421736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PHOTOfunSTUDIO 5.0.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOfunSTUDIO 5.0.lnk
backup=c:\windows\pss\PHOTOfunSTUDIO 5.0.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-02-21 04:28 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-12 05:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-03-07 02:05 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
2008-04-12 01:23 38400 ----a-w- c:\windows\System32\SoundSchemes.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24}]
2008-08-28 18:50 30720 ----a-w- c:\windows\System32\soundschemes2.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://verizon.my.yahoo.com
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.1 68.238.64.12
FF - ProfilePath - c:\users\Robert Rantzow\AppData\Roaming\Mozilla\Firefox\Profiles\dww3028f.default\
FF - prefs.js: browser.startup.homepage - hxxp://verizon.my.yahoo.com/
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-05-13 13:12
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2012-05-13 13:21:53
ComboFix-quarantined-files.txt 2012-05-13 20:21
ComboFix2.txt 2012-05-13 16:47
ComboFix3.txt 2012-05-12 21:45
.
Pre-Run: 242,084,917,248 bytes free
Post-Run: 242,059,182,080 bytes free
.
- - End Of File - - 17818D1E45EF609FD00EC25E045C19BD