Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.232 [GMT -6:00]
Running from: c:\documents and settings\Owner\Desktop\combo.com.exe
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\EventSystem.log
c:\windows\system32\5041230.dll
c:\windows\system32\702642.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FCI
-------\Service_npf
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-29 )))))))))))))))))))))))))))))))
.
2010-01-28 04:02 . 2010-01-28 04:02 -------- d-sh--w- c:\documents and settings\Administrator.YOUR-4BC5110200\IETldCache
2010-01-27 03:31 . 2010-01-27 03:31 -------- d-----w- C:\_OTL
2010-01-27 01:04 . 2010-01-27 01:16 -------- d-----w- c:\program files\LALALA
2010-01-27 00:54 . 2010-01-07 22:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-27 00:54 . 2010-01-27 01:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-27 00:54 . 2010-01-07 22:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-24 03:48 . 2010-01-24 03:48 -------- d-----w- c:\documents and settings\Owner\Application Data\Red Kawa
2010-01-24 03:10 . 2010-01-24 03:10 -------- d-----w- c:\documents and settings\Owner\Application Data\Regensoft
2010-01-22 02:55 . 2010-01-22 02:55 -------- d-----w- c:\program files\Red Kawa
2010-01-19 23:37 . 2010-01-19 23:37 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-12 22:17 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 01:51 . 2010-01-12 01:51 -------- d-----w- c:\documents and settings\Owner\Application Data\Music Recognition
2010-01-09 01:04 . 2010-01-09 01:06 -------- d-----w- c:\documents and settings\Owner\Application Data\ooVoo Details
2010-01-07 23:20 . 2010-01-07 23:20 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-01-07 03:56 . 2009-10-07 08:48 539160 ----a-r- c:\windows\system32\LVUI2RC.dll
2010-01-07 03:56 . 2009-10-07 08:48 539160 ----a-r- c:\windows\system32\LVUI2.dll
2010-01-07 03:56 . 2009-10-07 08:43 416280 ----a-r- c:\windows\system32\lvcodec2.dll
2010-01-07 03:56 . 2009-10-07 08:49 6756632 ----a-r- c:\windows\system32\drivers\lvuvc.sys
2010-01-07 03:56 . 2010-01-07 03:56 -------- d-----w- c:\documents and settings\Owner\Application Data\Leadertech
2010-01-07 03:53 . 2009-10-07 08:47 266008 ----a-r- c:\windows\system32\drivers\lvrs.sys
2010-01-07 03:53 . 2009-10-07 08:43 199192 ----a-r- c:\windows\system32\lvci12101110.dll
2010-01-07 03:53 . 2009-10-07 08:24 34068 ----a-r- c:\windows\system32\Repository.reg
2010-01-07 03:52 . 2009-10-07 08:49 23832 ----a-r- c:\windows\system32\drivers\lvuvcflt.sys
2010-01-07 03:51 . 2010-01-07 03:56 -------- d-----w- c:\program files\Common Files\LogiShrd
2010-01-07 03:51 . 2010-01-08 21:30 -------- d-----w- c:\documents and settings\All Users\Application Data\LogiShrd
2010-01-07 03:50 . 2010-01-07 03:50 -------- d-----w- c:\program files\Logitech
2010-01-04 05:19 . 2010-01-29 05:15 -------- d-----w- c:\documents and settings\Owner\Tracing
2010-01-04 05:17 . 2010-01-04 05:17 -------- d-----w- c:\program files\Microsoft
2010-01-04 05:16 . 2010-01-04 05:16 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-01-04 05:16 . 2010-01-04 05:17 -------- d-----w- c:\program files\Windows Live
2010-01-04 05:05 . 2010-01-04 05:05 -------- d-----w- c:\program files\Common Files\Windows Live
2010-01-04 04:27 . 2010-01-04 04:27 -------- d-----w- c:\program files\Common Files\Skype
2010-01-04 04:27 . 2010-01-04 04:28 -------- d-----r- c:\program files\Skype
2010-01-01 00:00 . 2009-04-28 16:08 461824 ----a-w- c:\windows\system32\drivers\PAC7302.SYS
2010-01-01 00:00 . 2007-11-02 17:07 6656 ----a-w- c:\windows\system32\CoInst.dll
2010-01-01 00:00 . 2010-01-01 00:00 -------- d-----w- c:\windows\Pixart
2009-12-31 21:50 . 2009-12-31 21:50 -------- d-----w- c:\documents and settings\Taylor\Application Data\DivX
2009-12-31 21:45 . 2009-12-31 21:46 -------- d-----w- c:\documents and settings\Taylor\Application Data\ArcSoft
2009-12-30 23:55 . 2009-12-30 23:55 -------- d-----w- c:\documents and settings\Owner\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-29 05:15 . 2006-11-27 22:45 -------- d-----w- c:\documents and settings\Owner\Application Data\OpenOffice.org2
2010-01-29 05:11 . 2009-11-24 03:43 -------- d-----w- c:\documents and settings\Owner\Application Data\WTablet
2010-01-29 03:56 . 2010-01-07 17:05 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-01-29 03:56 . 2010-01-07 03:52 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-01-29 03:42 . 2006-11-12 21:07 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-01-29 00:45 . 2008-09-01 20:33 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-27 22:22 . 2009-06-09 19:57 -------- d-----w- c:\documents and settings\Owner\Application Data\Skype
2010-01-27 21:56 . 2009-06-09 20:00 -------- d-----w- c:\documents and settings\Owner\Application Data\skypePM
2010-01-27 00:06 . 2006-06-30 04:57 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-27 00:04 . 2008-12-07 23:25 -------- d-----w- c:\program files\Winamp
2010-01-26 23:49 . 2010-01-26 23:53 3807232 ----a-w- c:\windows\Internet Logs\xDBB4.tmp
2010-01-26 23:49 . 2010-01-26 23:53 262144 ----a-w- c:\windows\Internet Logs\xDBB3.tmp
2010-01-25 02:26 . 2009-06-09 20:19 -------- d-----w- c:\documents and settings\Taylor\Application Data\Skype
2010-01-25 02:22 . 2009-06-09 20:20 -------- d-----w- c:\documents and settings\Taylor\Application Data\skypePM
2010-01-24 18:42 . 2006-11-27 05:36 -------- d-----w- c:\documents and settings\Taylor\Application Data\OpenOffice.org2
2010-01-22 02:56 . 2009-12-30 01:01 -------- d-----w- c:\program files\AviSynth 2.5
2010-01-20 21:24 . 2009-07-22 22:11 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-19 04:48 . 2010-01-19 12:21 1155584 ----a-w- c:\windows\Internet Logs\xDBB2.tmp
2010-01-13 03:26 . 2009-04-07 03:10 -------- d-----w- c:\documents and settings\Owner\Application Data\gtk-2.0
2010-01-11 05:55 . 2009-12-25 15:51 -------- d-----w- c:\program files\ArcSoft
2010-01-09 22:07 . 2006-08-30 22:13 51216 ----a-w- c:\documents and settings\Taylor\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-04 04:26 . 2009-06-09 19:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-12-31 04:44 . 2006-08-06 19:29 51216 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-31 04:41 . 2009-12-31 14:09 840192 ----a-w- c:\windows\Internet Logs\xDBB1.tmp
2009-12-29 22:42 . 2009-06-27 22:07 -------- d-----w- c:\documents and settings\Taylor\Application Data\gtk-2.0
2009-12-29 22:37 . 2009-12-29 22:37 46848 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-29 22:34 . 2009-12-29 22:31 -------- d-----w- c:\documents and settings\Taylor\Application Data\Apple Computer
2009-12-29 04:17 . 2009-12-29 04:05 -------- d-----w- c:\program files\NCH Software
2009-12-29 04:06 . 2009-12-29 04:06 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Software
2009-12-28 06:49 . 2009-12-28 06:13 -------- d-----w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-12-28 06:13 . 2009-12-28 06:11 -------- d-----w- c:\program files\iTunes
2009-12-28 06:13 . 2009-12-28 06:11 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-28 06:11 . 2009-12-28 06:11 -------- d-----w- c:\program files\iPod
2009-12-28 06:11 . 2009-12-28 06:07 -------- d-----w- c:\program files\Common Files\Apple
2009-12-28 06:11 . 2009-12-28 06:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-28 06:10 . 2009-12-28 06:10 -------- d-----w- c:\program files\Bonjour
2009-12-28 06:10 . 2009-12-28 06:09 -------- d-----w- c:\program files\QuickTime
2009-12-28 06:08 . 2009-12-28 06:08 -------- d-----w- c:\program files\Apple Software Update
2009-12-28 06:07 . 2009-12-28 06:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-12-25 16:32 . 2009-12-25 16:32 -------- d-----w- c:\documents and settings\Owner\Application Data\DivX
2009-12-25 16:01 . 2009-12-25 16:00 -------- d-----w- c:\documents and settings\Owner\Application Data\ArcSoft
2009-12-22 05:13 . 2009-12-22 05:12 -------- d-----w- c:\documents and settings\Taylor\Application Data\HpUpdate
2009-12-21 19:14 . 2004-08-26 16:12 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-21 17:14 . 2009-12-21 17:14 79488 ----a-w- c:\documents and settings\Taylor\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-21 05:59 . 2009-12-21 17:06 1515520 ----a-w- c:\windows\Internet Logs\xDBB0.tmp
2009-12-16 21:31 . 2007-01-30 05:08 23385342 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2009-12-15 02:45 . 2009-12-15 02:45 -------- d-----w- c:\program files\Veoh Networks
2009-12-15 02:24 . 2009-01-15 21:58 -------- d-----w- c:\documents and settings\Owner\Application Data\Winamp
2009-12-13 02:58 . 2009-12-13 02:58 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\WTablet
2009-12-09 06:14 . 2009-11-09 10:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-07 08:01 . 2009-12-07 08:01 2238 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{7B4C7725-C677-43EE-BD57-68C30B150CAF}\_D64105F3D74E680CF36D93.exe
2009-12-07 08:01 . 2009-12-07 08:01 2238 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{7B4C7725-C677-43EE-BD57-68C30B150CAF}\_49A77C426E6216142CDC1D.exe
2009-12-07 05:21 . 2009-12-07 03:53 -------- d--h--w- c:\program files\InstallJammer Registry
2009-12-02 04:30 . 2009-12-02 21:26 258560 ----a-w- c:\windows\Internet Logs\xDBAF.tmp
2009-12-02 01:20 . 2009-04-07 00:36 -------- d-----w- c:\program files\GIMP-2.0
2009-11-30 22:14 . 2009-11-30 22:14 -------- d-----w- c:\documents and settings\LocalService\Application Data\WTablet
2009-11-26 04:28 . 2009-11-26 14:33 595968 ----a-w- c:\windows\Internet Logs\xDBAE.tmp
2009-11-24 21:52 . 2009-11-21 21:44 79488 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-21 15:51 . 2004-08-26 16:11 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-16 03:05 . 2009-11-16 03:45 8704 ----a-w- c:\windows\Internet Logs\xDBC5.tmp
2009-11-16 02:54 . 2009-11-16 03:05 66560 ----a-w- c:\windows\Internet Logs\xDBAD.tmp
2009-11-16 01:58 . 2009-11-16 02:12 8704 ----a-w- c:\windows\Internet Logs\xDBAC.tmp
2009-11-16 01:49 . 2009-11-16 01:58 40960 ----a-w- c:\windows\Internet Logs\xDBAB.tmp
2009-11-16 01:34 . 2009-11-16 01:47 3156480 ----a-w- c:\windows\Internet Logs\xDBAA.tmp
2009-11-16 01:34 . 2009-11-16 01:47 22528 ----a-w- c:\windows\Internet Logs\xDBA9.tmp
2009-11-16 01:10 . 2009-11-16 01:32 16384 ----a-w- c:\windows\Internet Logs\xDBA7.tmp
2009-11-16 01:10 . 2009-11-16 01:32 3156480 ----a-w- c:\windows\Internet Logs\xDBA8.tmp
2009-11-16 00:58 . 2009-11-16 01:08 3156480 ----a-w- c:\windows\Internet Logs\xDBA6.tmp
2009-11-16 00:58 . 2009-11-16 01:08 66560 ----a-w- c:\windows\Internet Logs\xDBA5.tmp
2009-11-15 01:00 . 2009-11-15 01:02 31744 ----a-w- c:\windows\Internet Logs\xDBA4.tmp
2009-11-14 15:28 . 2009-11-14 15:47 3144192 ----a-w- c:\windows\Internet Logs\xDBA3.tmp
2009-11-14 15:28 . 2009-11-14 15:47 81920 ----a-w- c:\windows\Internet Logs\xDBA2.tmp
2009-11-13 16:48 . 2009-11-13 16:59 3143680 ----a-w- c:\windows\Internet Logs\xDBA1.tmp
2009-11-13 16:48 . 2009-11-13 16:59 35840 ----a-w- c:\windows\Internet Logs\xDBA0.tmp
2009-11-12 23:59 . 2009-11-13 16:26 3142144 ----a-w- c:\windows\Internet Logs\xDB9F.tmp
2009-11-12 23:07 . 2009-11-12 23:07 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-12 17:06 . 2009-11-12 17:10 3141632 ----a-w- c:\windows\Internet Logs\xDB9E.tmp
2009-11-12 17:06 . 2009-11-12 17:10 25088 ----a-w- c:\windows\Internet Logs\xDB9D.tmp
2009-11-12 16:52 . 2009-11-12 16:59 16384 ----a-w- c:\windows\Internet Logs\xDB9B.tmp
2009-11-12 16:44 . 2009-11-12 16:59 3141120 ----a-w- c:\windows\Internet Logs\xDB9C.tmp
2009-11-12 16:26 . 2009-11-12 16:42 22016 ----a-w- c:\windows\Internet Logs\xDB9A.tmp
2009-11-12 16:18 . 2009-11-12 16:24 24576 ----a-w- c:\windows\Internet Logs\xDB98.tmp
2009-11-12 16:18 . 2009-11-12 16:24 3141632 ----a-w- c:\windows\Internet Logs\xDB99.tmp
2009-11-12 14:52 . 2009-11-12 14:59 3142144 ----a-w- c:\windows\Internet Logs\xDB97.tmp
2009-11-12 14:52 . 2009-11-12 14:59 29696 ----a-w- c:\windows\Internet Logs\xDB96.tmp
2009-11-12 00:23 . 2009-11-12 14:33 3139072 ----a-w- c:\windows\Internet Logs\xDB95.tmp
2009-11-11 16:10 . 2009-11-11 16:15 3138560 ----a-w- c:\windows\Internet Logs\xDB94.tmp
2009-11-11 16:10 . 2009-11-11 16:15 22016 ----a-w- c:\windows\Internet Logs\xDB93.tmp
2009-11-11 16:00 . 2009-11-11 16:08 3138560 ----a-w- c:\windows\Internet Logs\xDB92.tmp
2009-11-11 15:53 . 2009-11-11 16:08 23552 ----a-w- c:\windows\Internet Logs\xDB91.tmp
2009-11-11 15:42 . 2009-11-11 15:51 3138560 ----a-w- c:\windows\Internet Logs\xDB90.tmp
2009-11-11 15:42 . 2009-11-11 15:51 22528 ----a-w- c:\windows\Internet Logs\xDB8F.tmp
2009-11-11 15:33 . 2009-11-11 15:40 22016 ----a-w- c:\windows\Internet Logs\xDB8D.tmp
2009-11-11 15:33 . 2009-11-11 15:40 3138560 ----a-w- c:\windows\Internet Logs\xDB8E.tmp
2009-11-11 15:29 . 2009-11-11 15:31 3138048 ----a-w- c:\windows\Internet Logs\xDB8C.tmp
2009-11-11 15:24 . 2009-11-11 15:31 32256 ----a-w- c:\windows\Internet Logs\xDB8B.tmp
2009-11-11 15:11 . 2009-11-11 15:22 3139072 ----a-w- c:\windows\Internet Logs\xDB8A.tmp
2009-11-11 05:06 . 2009-11-11 14:50 3137024 ----a-w- c:\windows\Internet Logs\xDB89.tmp
2009-11-11 01:07 . 2009-11-11 02:12 3136512 ----a-w- c:\windows\Internet Logs\xDB88.tmp
2009-11-10 22:10 . 2009-11-10 22:29 3136000 ----a-w- c:\windows\Internet Logs\xDB87.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-29 344064]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-26 966656]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-10-17 1037192]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-05-26 1468296]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-7-14 393216]
c:\documents and settings\Taylor\Start Menu\Programs\Startup\MRI_DISABLED
OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-7-14 393216]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MRI_DISABLED]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2005-01-12 10:01 32768 ----a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AppMgmt"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\ATT-HSI\\McciBrowser.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58910:TCP"= 58910:TCP:Pando Media Booster
"58910:UDP"= 58910:UDP:Pando Media Booster
"443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443
"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [11/23/2009 9:42 PM 3032360]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [6/29/2006 10:52 PM 200576]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [11/23/2009 9:42 PM 15144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2009-12-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
.
- - - - ORPHANS REMOVED - - - -
BHO-{99756919-C498-4D97-9E20-2076DE0E42B9} - c:\documents and settings\Owner\My Documents\Avi Art\ext\eiexxpw.dll
HKCU-Run-Search Protection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
HKCU-Run-Messenger (Yahoo!) - c:\program files\Yahoo!\Messenger\YahooMessenger.exe
SafeBoot-MRI_DISABLED\AppMgmt
MSConfigStartUp-9c5b2548 - c:\windows\system32\rarayuna.dll
MSConfigStartUp-CPM9f6816d4 - c:\windows\system32\boliraka.dll
MSConfigStartUp-gurojifori - c:\windows\system32\wakozawa.dll
MSConfigStartUp-WinampAgent - c:\program files\Winamp\winampa.exe
AddRemove-HijackThis - c:\documents and settings\Daddy\My Documents\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-28 23:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Windows\MRI_DISABLED]
"AppInit_Dlls"=multi:"c:\\windows\\system32\\boliraka.dll\00c:\\windows\\system32\\tajojeti.dll\00c:\\windows\\system32\\jukohani.dll\00c:\\WINDOWS\\system32\\pisesiro.dll\00\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(880)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2520)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\wltrysvc.exe
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\OpenOffice.org 2.0\program\soffice.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\OpenOffice.org 2.0\program\soffice.BIN
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2010-01-28 23:21:26 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-29 05:21
Pre-Run: 39,430,475,776 bytes free
Post-Run: 39,498,055,680 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /bootlog
- - End Of File - - FA56A237F46DB35F636CD56E8A358E89