Hi tomk,
This is the result of the ComboFix scanning.
ComboFix 09-03-03.01 - Alvin Osana 2009-03-04 14:34:49.2 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.238.75 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Alvin Osana\Desktop\CFScript.txt.txt
* Created a new restore point
FILE ::
c:\documents and settings\Mommy\Templates\WowTumpeh.com
c:\documents and settings\NetworkService\Local Settings\Application Data\smss.exe
c:\windows\Tasks\Symantec NetDetect.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Tasks\At1.job
.
((((((((((((((((((((((((( Files Created from 2009-02-04 to 2009-03-04 )))))))))))))))))))))))))))))))
.
2009-03-03 15:23 . 2009-03-03 15:23 d——– c:\documents and settings\All Users\Application Data\NortonInstaller
2009-03-01 21:45 . 2003-01-03 16:12 113,728 –a—— c:\windows\system32\drivers\ino_fltr.sys
2009-03-01 21:45 . 2003-02-10 14:48 36,864 –a—— c:\windows\RmvDir.exe
2009-03-01 21:45 . 2003-02-14 05:50 28,441 –a—— c:\windows\inoc6.icf
2009-03-01 21:45 . 2003-01-03 14:08 19,776 –a—— c:\windows\system32\drivers\ino_flpy.sys
2009-03-01 21:45 . 2009-03-01 21:45 47 –a—— c:\windows\InoSetup.ini
2009-02-24 11:51 . 2009-02-24 11:51 d——– c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-16 13:35 3,594,752 —-a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-19 09:10 70,656 —-a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 —-a-w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\dllcache\srv.sys
2008-02-03 16:51 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-02-25_16.25.37.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-26 07:24:28 124,928 ——w c:\windows\ie7updates\KB961260-IE7\advpack.dll
+ 2008-08-26 07:24:28 347,136 ——w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll
+ 2008-08-26 07:24:28 214,528 ——w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll
+ 2008-08-26 07:24:28 133,120 ——w c:\windows\ie7updates\KB961260-IE7\extmgr.dll
+ 2008-08-26 07:24:28 63,488 ——w c:\windows\ie7updates\KB961260-IE7\icardie.dll
+ 2008-08-25 08:38:00 70,656 ——w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe
+ 2008-08-26 07:24:28 153,088 ——w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll
+ 2008-08-26 07:24:28 230,400 ——w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll
+ 2008-08-23 05:54:52 161,792 ——w c:\windows\ie7updates\KB961260-IE7\ieakui.dll
+ 2008-08-26 07:24:28 383,488 ——w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll
+ 2008-08-26 07:24:30 384,512 ——w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll
+ 2008-10-03 17:41:16 6,066,176 ——w c:\windows\ie7updates\KB961260-IE7\ieframe.dll
+ 2008-08-26 07:24:30 44,544 ——w c:\windows\ie7updates\KB961260-IE7\iernonce.dll
+ 2008-08-26 07:24:30 267,776 ——w c:\windows\ie7updates\KB961260-IE7\iertutil.dll
+ 2008-08-25 08:38:00 13,824 ——w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe
+ 2008-08-23 05:56:16 635,848 ——w c:\windows\ie7updates\KB961260-IE7\iexplore.exe
+ 2008-08-26 07:24:30 27,648 ——w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll
+ 2008-08-26 07:24:30 459,264 ——w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll
+ 2008-08-26 07:24:30 52,224 ——w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll
+ 2008-08-27 08:24:32 3,593,216 ——w c:\windows\ie7updates\KB961260-IE7\mshtml.dll
+ 2008-08-26 07:24:30 477,696 ——w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll
+ 2008-08-26 07:24:30 193,024 ——w c:\windows\ie7updates\KB961260-IE7\msrating.dll
+ 2008-08-26 07:24:30 671,232 ——w c:\windows\ie7updates\KB961260-IE7\mstime.dll
+ 2008-08-26 07:24:30 102,912 ——w c:\windows\ie7updates\KB961260-IE7\occache.dll
+ 2008-08-26 07:24:30 44,544 ——w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll
+ 2007-03-06 01:22:42 213,216 ——w c:\windows\ie7updates\KB961260-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:52 371,424 ——w c:\windows\ie7updates\KB961260-IE7\spuninst\updspapi.dll
+ 2008-08-26 07:24:30 105,984 ——w c:\windows\ie7updates\KB961260-IE7\url.dll
+ 2008-08-26 07:24:32 1,159,680 ——w c:\windows\ie7updates\KB961260-IE7\urlmon.dll
+ 2008-08-26 07:24:32 233,472 ——w c:\windows\ie7updates\KB961260-IE7\webcheck.dll
+ 2008-08-26 07:24:32 826,368 ——w c:\windows\ie7updates\KB961260-IE7\wininet.dll
- 2007-07-19 01:41:14 3,640 —-a-r c:\windows\Installer\{30C10EE3-EFB3-4B7A-9CDC-50790C2B5200}\ARPPRODUCTICON.exe
+ 2009-03-01 13:46:34 3,640 —-a-r c:\windows\Installer\{30C10EE3-EFB3-4B7A-9CDC-50790C2B5200}\ARPPRODUCTICON.exe
- 2008-08-26 07:24:28 124,928 —-a-w c:\windows\system32\advpack.dll
+ 2008-12-20 23:15:12 124,928 —-a-w c:\windows\system32\advpack.dll
- 2008-08-26 07:24:28 124,928 —-a-w c:\windows\system32\dllcache\advpack.dll
+ 2008-12-20 23:15:12 124,928 —-a-w c:\windows\system32\dllcache\advpack.dll
- 2008-08-26 07:24:28 347,136 —-a-w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 —-a-w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 —-a-w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-12-20 23:15:14 214,528 —-a-w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-26 07:24:28 133,120 —-a-w c:\windows\system32\dllcache\extmgr.dll
+ 2008-12-20 23:15:14 133,120 —-a-w c:\windows\system32\dllcache\extmgr.dll
- 2008-08-26 07:24:28 63,488 ——w c:\windows\system32\dllcache\icardie.dll
+ 2008-12-20 23:15:14 63,488 ——w c:\windows\system32\dllcache\icardie.dll
- 2008-08-26 07:24:28 153,088 —-a-w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 —-a-w c:\windows\system32\dllcache\ieakeng.dll
- 2008-08-26 07:24:28 230,400 —-a-w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 —-a-w c:\windows\system32\dllcache\ieaksie.dll
- 2008-08-26 07:24:28 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-12-20 23:15:16 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-08-26 07:24:30 384,512 —-a-w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 —-a-w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-03 17:41:16 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
+ 2008-12-20 23:15:22 6,066,688 ——w c:\windows\system32\dllcache\ieframe.dll
- 2008-08-26 07:24:30 44,544 —-a-w c:\windows\system32\dllcache\iernonce.dll
+ 2008-12-20 23:15:22 44,544 —-a-w c:\windows\system32\dllcache\iernonce.dll
- 2008-08-26 07:24:30 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
+ 2008-12-20 23:15:22 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
- 2008-08-26 07:24:30 27,648 —-a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-12-20 23:15:24 27,648 —-a-w c:\windows\system32\dllcache\jsproxy.dll
- 2008-08-26 07:24:30 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-12-20 23:15:24 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
- 2008-08-26 07:24:30 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-08-26 07:24:30 477,696 —-a-w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 —-a-w c:\windows\system32\dllcache\mshtmled.dll
- 2008-08-26 07:24:30 193,024 —-a-w c:\windows\system32\dllcache\msrating.dll
+ 2008-12-20 23:15:32 193,024 —-a-w c:\windows\system32\dllcache\msrating.dll
- 2008-08-26 07:24:30 671,232 —-a-w c:\windows\system32\dllcache\mstime.dll
+ 2008-12-20 23:15:32 671,232 —-a-w c:\windows\system32\dllcache\mstime.dll
- 2008-08-26 07:24:30 102,912 —-a-w c:\windows\system32\dllcache\occache.dll
+ 2008-12-20 23:15:38 102,912 —-a-w c:\windows\system32\dllcache\occache.dll
- 2008-08-26 07:24:30 44,544 —-a-w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 —-a-w c:\windows\system32\dllcache\pngfilt.dll
- 2007-10-26 03:36:52 8,454,656 —-a-w c:\windows\system32\dllcache\shell32.dll
+ 2008-07-03 13:16:58 8,454,656 —-a-w c:\windows\system32\dllcache\shell32.dll
- 2008-08-26 07:24:30 105,984 —-a-w c:\windows\system32\dllcache\url.dll
+ 2008-12-20 23:15:40 105,984 —-a-w c:\windows\system32\dllcache\url.dll
- 2008-08-26 07:24:32 1,159,680 —-a-w c:\windows\system32\dllcache\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 —-a-w c:\windows\system32\dllcache\urlmon.dll
- 2008-08-26 07:24:32 233,472 —-a-w c:\windows\system32\dllcache\webcheck.dll
+ 2008-12-20 23:15:40 233,472 —-a-w c:\windows\system32\dllcache\webcheck.dll
- 2008-08-26 07:24:32 826,368 —-a-w c:\windows\system32\dllcache\wininet.dll
+ 2008-12-20 23:15:42 826,368 —-a-w c:\windows\system32\dllcache\wininet.dll
- 2008-08-26 07:24:28 347,136 —-a-w c:\windows\system32\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 —-a-w c:\windows\system32\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 —-a-w c:\windows\system32\dxtrans.dll
+ 2008-12-20 23:15:14 214,528 —-a-w c:\windows\system32\dxtrans.dll
- 2008-08-26 07:24:28 133,120 —-a-w c:\windows\system32\extmgr.dll
+ 2008-12-20 23:15:14 133,120 —-a-w c:\windows\system32\extmgr.dll
- 2008-08-26 07:24:28 63,488 —-a-w c:\windows\system32\icardie.dll
+ 2008-12-20 23:15:14 63,488 —-a-w c:\windows\system32\icardie.dll
- 2008-08-25 08:38:00 70,656 —-a-w c:\windows\system32\ie4uinit.exe
+ 2008-12-19 09:10:16 70,656 —-a-w c:\windows\system32\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 —-a-w c:\windows\system32\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 —-a-w c:\windows\system32\ieakeng.dll
- 2008-08-26 07:24:28 230,400 —-a-w c:\windows\system32\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 —-a-w c:\windows\system32\ieaksie.dll
- 2008-08-23 05:54:52 161,792 —-a-w c:\windows\system32\ieakui.dll
+ 2008-12-19 05:23:56 161,792 —-a-w c:\windows\system32\ieakui.dll
- 2008-08-26 07:24:28 383,488 —-a-w c:\windows\system32\ieapfltr.dll
+ 2008-12-20 23:15:16 383,488 —-a-w c:\windows\system32\ieapfltr.dll
- 2008-08-26 07:24:30 384,512 —-a-w c:\windows\system32\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 —-a-w c:\windows\system32\iedkcs32.dll
- 2008-10-03 17:41:16 6,066,176 —-a-w c:\windows\system32\ieframe.dll
+ 2008-12-20 23:15:22 6,066,688 —-a-w c:\windows\system32\ieframe.dll
- 2008-08-26 07:24:30 44,544 —-a-w c:\windows\system32\iernonce.dll
+ 2008-12-20 23:15:22 44,544 —-a-w c:\windows\system32\iernonce.dll
- 2008-08-26 07:24:30 267,776 —-a-w c:\windows\system32\iertutil.dll
+ 2008-12-20 23:15:22 267,776 —-a-w c:\windows\system32\iertutil.dll
- 2008-08-25 08:38:00 13,824 —-a-w c:\windows\system32\ieudinit.exe
+ 2008-12-19 09:10:16 13,824 —-a-w c:\windows\system32\ieudinit.exe
- 2008-08-26 07:24:30 27,648 —-a-w c:\windows\system32\jsproxy.dll
+ 2008-12-20 23:15:24 27,648 —-a-w c:\windows\system32\jsproxy.dll
- 2008-08-26 07:24:30 459,264 —-a-w c:\windows\system32\msfeeds.dll
+ 2008-12-20 23:15:24 459,264 —-a-w c:\windows\system32\msfeeds.dll
- 2008-08-26 07:24:30 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
- 2008-08-27 08:24:32 3,593,216 —-a-w c:\windows\system32\mshtml.dll
+ 2009-01-16 13:35:14 3,594,752 —-a-w c:\windows\system32\mshtml.dll
- 2008-08-26 07:24:30 477,696 —-a-w c:\windows\system32\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 —-a-w c:\windows\system32\mshtmled.dll
- 2008-08-26 07:24:30 193,024 —-a-w c:\windows\system32\msrating.dll
+ 2008-12-20 23:15:32 193,024 —-a-w c:\windows\system32\msrating.dll
- 2008-08-26 07:24:30 671,232 —-a-w c:\windows\system32\mstime.dll
+ 2008-12-20 23:15:32 671,232 —-a-w c:\windows\system32\mstime.dll
- 2008-08-26 07:24:30 102,912 —-a-w c:\windows\system32\occache.dll
+ 2008-12-20 23:15:38 102,912 —-a-w c:\windows\system32\occache.dll
- 2007-10-22 16:59:34 42,520 —-a-w c:\windows\system32\perfc009.dat
+ 2009-03-01 13:45:06 43,130 —-a-w c:\windows\system32\perfc009.dat
- 2007-10-22 16:59:34 317,028 —-a-w c:\windows\system32\perfh009.dat
+ 2009-03-01 13:45:06 317,638 —-a-w c:\windows\system32\perfh009.dat
- 2008-08-26 07:24:30 44,544 —-a-w c:\windows\system32\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 —-a-w c:\windows\system32\pngfilt.dll
- 2007-10-26 03:36:52 8,454,656 —-a-w c:\windows\system32\shell32.dll
+ 2008-07-03 13:16:58 8,454,656 —-a-w c:\windows\system32\shell32.dll
- 2007-07-27 01:41:40 16,760 ——w c:\windows\system32\spmsg.dll
+ 2008-07-09 07:38:24 17,272 ——w c:\windows\system32\spmsg.dll
- 2008-08-26 07:24:30 105,984 —-a-w c:\windows\system32\url.dll
+ 2008-12-20 23:15:40 105,984 —-a-w c:\windows\system32\url.dll
- 2008-08-26 07:24:32 1,159,680 —-a-w c:\windows\system32\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 —-a-w c:\windows\system32\urlmon.dll
- 2008-08-26 07:24:32 233,472 —-a-w c:\windows\system32\webcheck.dll
+ 2008-12-20 23:15:40 233,472 —-a-w c:\windows\system32\webcheck.dll
- 2008-08-26 07:24:32 826,368 —-a-w c:\windows\system32\wininet.dll
+ 2008-12-20 23:15:42 826,368 —-a-w c:\windows\system32\wininet.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-14 1694208]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-05 4347120]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-04 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-20 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-20 532480]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-21 40960]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2004-07-14 151552]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2004-09-01 2876416]
"LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2004-07-30 319488]
"Ulead AutoDetector"="c:\program files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-02-27 45056]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"Realtime Monitor"="c:\progra~1\CA\ETRUST~1\realmon.exe" [2003-02-13 493024]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2003-07-14 34880]
c:\documents and settings\Alvin Osana\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2005-06-06 23:46 57344 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AttuneClientEngine]
–a—— 2000-07-24 23:47 356728 c:\progra~1\Aveo\Attune\bin\attune_ce.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2008-11-05 21:59 4347120 c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Corel\\Graphics10\\Register\\NAVBrowser.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16757:TCP"= 16757:TCP:NortonAV
"18956:TCP"= 18956:TCP:NortonAV
"18172:TCP"= 18172:TCP:NortonAV
"15998:TCP"= 15998:TCP:NortonAV
"14877:TCP"= 14877:TCP:NortonAV
"16666:TCP"= 16666:TCP:NortonAV
"17119:TCP"= 17119:TCP:NortonAV
"14950:TCP"= 14950:TCP:NortonAV
"18323:TCP"= 18323:TCP:NortonAV
"14496:TCP"= 14496:TCP:NortonAV
"14292:TCP"= 14292:TCP:NortonAV
"13345:TCP"= 13345:TCP:NortonAV
"14842:TCP"= 14842:TCP:NortonAV
"12293:TCP"= 12293:TCP:NortonAV
"15490:TCP"= 15490:TCP:NortonAV
"13291:TCP"= 13291:TCP:NortonAV
"12944:TCP"= 12944:TCP:NortonAV
"15616:TCP"= 15616:TCP:NortonAV
"13346:TCP"= 13346:TCP:NortonAV
"14037:TCP"= 14037:TCP:NortonAV
"16436:TCP"= 16436:TCP:NortonAV
"13789:TCP"= 13789:TCP:NortonAV
"14565:TCP"= 14565:TCP:NortonAV
"16744:TCP"= 16744:TCP:NortonAV
"18712:TCP"= 18712:TCP:NortonAV
"14205:TCP"= 14205:TCP:NortonAV
R1 SMBHC;Microsoft SM Bus Host Controller Driver;c:\windows\system32\drivers\smbhc.sys [2004-08-30 6784]
R2 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2004-12-27 4096]
R2 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2004-12-27 78208]
R2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2002-09-21 53248]
R2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2004-06-01 10594]
R2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2004-06-01 4054]
R3 IPN2220;acer IPN2220 Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [1980-01-01 140288]
R3 SMBBATT;Microsoft Smart Battery Driver;c:\windows\system32\drivers\smbbatt.sys [2004-08-30 16128]
S3 CA_LIC_CLNT;CA License Client;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [2002-09-21 77824]
S3 CA_LIC_SRVR;CA License Server;c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [2002-09-21 77824]
.
Contents of the 'Scheduled Tasks' folder
2009-03-04 c:\windows\Tasks\User_Feed_Synchronization-{7F7830BF-DBE3-4406-877D-B08A57D64E7F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-PCSuiteTrayApplication - c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://global.acer.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://ph.yahoo.com/
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-04 14:36:48
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-03-04 14:38:16
ComboFix-quarantined-files.txt 2009-03-04 06:38:14
ComboFix2.txt 2009-02-25 08:26:34
Pre-Run: 2,535,374,848 bytes free
Post-Run: 2,595,487,744 bytes free
305 — E O F — 2009-02-25 09:43:50
UNlike the first time, the taskbar appeared after the scan.
Shall i proceed with the other scans?
MasterOfDisaster