ComboFix 09-02-19.01 - Jason Tanner 2009-02-20 8:57:43.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1156 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Jason Tanner\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
FILE ::
c:\windows\system32\#digeste.dll
c:\windows\system32\drivers\Lbd.sys
c:\windows\system32\uacinit.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Jason Tanner\Application Data\LimeWire
c:\documents and settings\Jason Tanner\Application Data\LimeWire\.AppSpecialShare\Battlestar Galactica.S04.E13.VOSTFR.XviD.avi.torrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire\.AppSpecialShare\Battlestar.Galactica.S04E11.HDTV.XviD-aAF.torrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire\.AppSpecialShare\Battlestar.Galactica.S04E12.A.Disquiet.Follows.My.Soul.HDTV.XviD-FQM.torrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire\.AppSpecialShare\Battlestar.Galactica.S04E14.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire\.AppSpecialShare\Lost S05E04 VOSTFR XviD.avi.torrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire\.AppSpecialShare\Lost.S05E05.HDTV,XviD.SWESUB-KickFoot.torrent
c:\documents and settings\Jason Tanner\Application Data\LimeWire\certificate\limewire.keystore
c:\documents and settings\Jason Tanner\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Jason Tanner\Application Data\LimeWire\downloads.dat
c:\documents and settings\Jason Tanner\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Jason Tanner\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Jason Tanner\Application Data\LimeWire\filters.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\gnutella.net
c:\documents and settings\Jason Tanner\Application Data\LimeWire\installation.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\library.dat
c:\documents and settings\Jason Tanner\Application Data\LimeWire\limewire.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\mojito.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\promotion\promodb.backup
c:\documents and settings\Jason Tanner\Application Data\LimeWire\promotion\promodb.data
c:\documents and settings\Jason Tanner\Application Data\LimeWire\promotion\promodb.properties
c:\documents and settings\Jason Tanner\Application Data\LimeWire\promotion\promodb.script
c:\documents and settings\Jason Tanner\Application Data\LimeWire\questions.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\responses.cache
c:\documents and settings\Jason Tanner\Application Data\LimeWire\simpp.xml
c:\documents and settings\Jason Tanner\Application Data\LimeWire\spam.dat
c:\documents and settings\Jason Tanner\Application Data\LimeWire\tables.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\
01_star.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\
02_star.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\
03_star.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\
04_star.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\
05_star.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\Jason Tanner\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\Jason Tanner\Application Data\LimeWire\version.xml
c:\documents and settings\Jason Tanner\Application Data\LimeWire\versions.props
c:\documents and settings\Jason Tanner\Application Data\LimeWire\xml\data\video.sxml2
c:\documents and settings\Jason Tanner\Application Data\uTorrent
c:\documents and settings\Jason Tanner\Application Data\uTorrent\dht.dat
c:\documents and settings\Jason Tanner\Application Data\uTorrent\resume.dat
c:\documents and settings\Jason Tanner\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Jason Tanner\Application Data\uTorrent\rss.dat
c:\documents and settings\Jason Tanner\Application Data\uTorrent\settings.dat
c:\documents and settings\Jason Tanner\Application Data\uTorrent\settings.dat.old
c:\program files\LimeWire
c:\program files\LimeWire\.NetworkShare\LimeWireWin4.18.8.exe
c:\program files\LimeWire\Buy LimeWire PRO.url
c:\program files\LimeWire\COPYING
c:\program files\LimeWire\data.ser
c:\program files\LimeWire\inspection.props
c:\program files\LimeWire\install.log
c:\program files\LimeWire\language.prop
c:\program files\LimeWire\lib\aopalliance.jar
c:\program files\LimeWire\lib\clink.jar
c:\program files\LimeWire\lib\commons-codec-1.3.jar
c:\program files\LimeWire\lib\commons-logging.jar
c:\program files\LimeWire\lib\commons-net.jar
c:\program files\LimeWire\lib\daap.jar
c:\program files\LimeWire\lib\dnsjava.jar
c:\program files\LimeWire\lib\forms.jar
c:\program files\LimeWire\lib\foxtrot.jar
c:\program files\LimeWire\lib\gettext-commons.jar
c:\program files\LimeWire\lib\guice-1.0.jar
c:\program files\LimeWire\lib\hashes
c:\program files\LimeWire\lib\hsqldb.jar
c:\program files\LimeWire\lib\httpclient-4.0-alpha5-20080522.192134-5.jar
c:\program files\LimeWire\lib\httpcore-4.0-beta2-20080510.140437-10.jar
c:\program files\LimeWire\lib\httpcore-nio-4.0-beta2-20080510.140437-10.jar
c:\program files\LimeWire\lib\icu4j.jar
c:\program files\LimeWire\lib\jaudiotagger.jar
c:\program files\LimeWire\lib\jcraft.jar
c:\program files\LimeWire\lib\jdic.dll
c:\program files\LimeWire\lib\jdic.jar
c:\program files\LimeWire\lib\jdic_stub.jar
c:\program files\LimeWire\lib\jflac.jar
c:\program files\LimeWire\lib\jl.jar
c:\program files\LimeWire\lib\jmdns.jar
c:\program files\LimeWire\lib\jogg.jar
c:\program files\LimeWire\lib\jorbis.jar
c:\program files\LimeWire\lib\LimeWire.ico
c:\program files\LimeWire\lib\LimeWire.jar
c:\program files\LimeWire\lib\log4j.jar
c:\program files\LimeWire\lib\log4j.properties
c:\program files\LimeWire\lib\looks.jar
c:\program files\LimeWire\lib\messages.jar
c:\program files\LimeWire\lib\mp3spi.jar
c:\program files\LimeWire\lib\onion-common.jar
c:\program files\LimeWire\lib\onion-fec.jar
c:\program files\LimeWire\lib\ProgressTabs.jar
c:\program files\LimeWire\lib\swt.jar
c:\program files\LimeWire\lib\SystemUtilities.dll
c:\program files\LimeWire\lib\SystemUtilitiesA.dll
c:\program files\LimeWire\lib\themes.jar
c:\program files\LimeWire\lib\tray.dll
c:\program files\LimeWire\lib\tritonus.jar
c:\program files\LimeWire\lib\vorbisspi.jar
c:\program files\LimeWire\LimeWire On Startup.lnk
c:\program files\LimeWire\LimeWire.exe
c:\program files\LimeWire\LimeWire.ico
c:\program files\LimeWire\pmf.ico
c:\program files\LimeWire\root\magnet10\badge.img
c:\program files\LimeWire\root\magnet10\canHandle.img
c:\program files\LimeWire\root\magnet10\limewire.gif
c:\program files\LimeWire\root\magnet10\options.js
c:\program files\LimeWire\root\magnet10\silentdetect.js
c:\program files\LimeWire\SOURCE
c:\program files\LimeWire\spacer.gif
c:\program files\LimeWire\uninstall.exe
c:\program files\LimeWire\unpack.log
c:\program files\uTorrent
c:\program files\uTorrent\uTorrent.exe
c:\windows\system32\drivers\Lbd.sys
c:\windows\system32\uacinit.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_ADXAPIE
——-\Legacy_LBD
——-\Service_adxapie
——-\Service_Lbd
((((((((((((((((((((((((( Files Created from 2009-01-20 to 2009-02-20 )))))))))))))))))))))))))))))))
.
2009-02-19 00:55 . 2009-02-19 00:55 d——– c:\program files\Trend Micro
2009-02-14 14:07 . 2009-02-14 14:07 22,043 –a—— c:\windows\system32\AAWService_2009_02_14_14_07_38.dmp
2009-02-14 14:06 . 2009-02-14 14:06 d——– c:\program files\MSXML 4.0
2009-02-14 01:11 . 2009-02-14 01:11 22,043 –a—— c:\windows\system32\AAWService_2009_02_14_01_11_02.dmp
2009-02-14 00:19 . 2009-02-14 00:19 22,043 –a—— c:\windows\system32\AAWService_2009_02_14_00_19_24.dmp
2009-02-13 23:22 . 2009-02-13 23:22 24,899 –a—— c:\windows\system32\AAWService_2009_02_13_23_22_52.dmp
2009-02-13 23:09 . 2009-02-13 22:28 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-02-13 22:29 . 2009-02-13 22:29 d—-c— c:\windows\system32\DRVSTORE
2009-02-13 22:25 . 2009-02-13 22:25 d–h-c— c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-13 22:24 . 2009-02-13 22:28 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-13 20:32 . 2009-02-13 20:32 775,168 –a—— c:\windows\isRS-000.tmp
2009-02-13 20:31 . 2009-02-13 20:31 d——– C:\Binaries
2009-02-13 20:28 . 2009-02-13 20:28 164 –a—— C:\install.dat
2009-02-13 19:58 . 2009-02-16 18:37 d——– c:\documents and settings\LocalService\Application Data\SACore
2009-02-13 18:13 . 2009-02-13 18:13 d——– c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-02-13 18:13 . 2009-02-20 09:03 8,965 –a—— c:\windows\system32\Config.MPF
2009-02-13 18:08 . 2009-02-13 18:08 d——– c:\program files\McAfee.com
2009-02-13 18:08 . 2007-11-22 06:44 201,320 –a—— c:\windows\system32\drivers\mfehidk.sys
2009-02-13 18:08 . 2007-07-13 06:20 113,952 –a—— c:\windows\system32\drivers\Mpfp.sys
2009-02-13 18:08 . 2007-11-22 06:44 79,304 –a—— c:\windows\system32\drivers\mfeavfk.sys
2009-02-13 18:08 . 2007-12-02 12:51 40,488 –a—— c:\windows\system32\drivers\mfesmfk.sys
2009-02-13 18:08 . 2007-11-22 06:44 35,240 –a—— c:\windows\system32\drivers\mfebopk.sys
2009-02-13 18:08 . 2007-11-22 06:44 33,832 –a—— c:\windows\system32\drivers\mferkdk.sys
2009-02-13 18:07 . 2009-02-16 12:01 d——– c:\program files\McAfee
2009-02-13 18:07 . 2009-02-13 18:08 d——– c:\program files\Common Files\McAfee
2009-02-13 17:20 . 2009-02-13 18:13 d——– c:\documents and settings\All Users\Application Data\McAfee
2009-02-03 00:02 . 2009-02-13 20:39 54,156 –ah—– c:\windows\QTFont.qfn
2009-02-03 00:02 . 2009-02-03 00:02 1,409 –a—— c:\windows\QTFont.for
2009-01-30 01:53 . 2009-02-18 09:53 d——– C:\Incomplete
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-20 17:04 ——— d—–w c:\documents and settings\Jason Tanner\Application Data\Skype
2009-02-20 16:45 ——— d—–w c:\documents and settings\Jason Tanner\Application Data\skypePM
2009-02-14 06:24 ——— d—–w c:\program files\Lavasoft
2009-02-03 08:31 ——— d—–w c:\documents and settings\Jason Tanner\Application Data\ArcSoft
2009-02-03 08:30 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-03 08:30 ——— d—–w c:\program files\ArcSoft
2009-01-20 06:53 ——— d—–w c:\program files\Skype
2009-01-20 06:53 ——— d—–w c:\program files\Common Files\Skype
2009-01-20 06:53 ——— d—–w c:\documents and settings\All Users\Application Data\Skype
2009-01-06 05:38 ——— d—–w c:\program files\Common Files\Adobe
2009-01-06 05:38 ——— d—–w c:\documents and settings\Jason Tanner\Application Data\AdobeUM
2009-01-02 02:34 ——— d—–w c:\program files\Java
2005-06-06 06:05 90,702 —-a-w c:\documents and settings\Jason Tanner\BlindTop.zip
2005-06-06 06:05 74,052 —-a-w c:\documents and settings\Jason Tanner\ZapWars.zip
2005-06-06 06:05 255,840 —-a-w c:\documents and settings\Jason Tanner\Raj.zip
2005-05-14 01:12 217,073 –sha-r c:\windows\meta4.exe
2005-10-24 19:13 66,560 –sha-r c:\windows\MOTA113.exe
2005-10-14 05:27 422,400 –sha-r c:\windows\x2.64.exe
2005-10-08 03:14 308,224 –sha-r c:\windows\system32\avisynth.dll
2005-07-14 20:31 27,648 –sha-r c:\windows\system32\AVSredirect.dll
2005-06-26 23:32 616,448 –sha-r c:\windows\system32\cygwin1.dll
2005-06-22 06:37 45,568 –sha-r c:\windows\system32\cygz.dll
2004-01-25 08:00 70,656 –sha-r c:\windows\system32\i420vfw.dll
2006-04-27 18:24 2,945,024 –sha-r c:\windows\system32\Smab.dll
2005-02-28 21:16 240,128 –sha-r c:\windows\system32\x.264.exe
2004-01-25 08:00 70,656 –sha-r c:\windows\system32\yv12vfw.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-02-19_ 0.45.38.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 04:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2009-02-19 08:28:32 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-20 16:53:00 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-19 08:28:32 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-20 16:53:00 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-20 17:02:37 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_254.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-r 49,152 2002-12-17 18:40:22 c:\program files\Hewlett-Packard\HP Software Update\bak\HPWuSchd.exe
—-a-w 184,320 2003-12-18 21:37:58 c:\program files\HP DVD\Umbrella\bak\DVDBitSet.exe
—-a-w 69,632 2003-07-23 17:42:04 c:\program files\HP DVD\Umbrella\bak\DVDTray.exe
—-a-w 32,881 2004-02-23 06:44:44 c:\program files\Java\j2re1.4.2_04\bin\bak\jusched.exe
—-a-w 458,752 2004-06-01 19:09:50 c:\program files\Logitech\Video\bak\ISStart.exe
—-a-w 217,088 2004-06-01 19:03:18 c:\program files\Logitech\Video\bak\LogiTray.exe
—-a-w 196,608 2004-06-01 10:46:37 c:\program files\Logitech\Video\bak\ManifestEngine.exe
—-a-w 155,648 2005-12-16 18:10:10 c:\program files\QuickTime\bak\qttask.exe
—-a-w 991,232 2006-03-18 17:18:00 c:\program files\Real\RealPlayer\bak\realplay.exe
—-a-w 1,269,760 2007-01-09 07:07:43 c:\program files\Valve\Steam\bak\Steam.exe
—-a-w 3,084,288 2005-08-20 02:34:02 c:\program files\Yahoo!\Messenger\bak\ypager.exe
—-a-w 221,184 2004-05-22 03:11:22 c:\windows\system32\bak\LVCOMSX.EXE
—-a-w 99,840 2003-06-04 10:00:00 c:\windows\system32\spool\drivers\w32x86\3\bak\E_S4I2F1.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [N/A]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\ypager.exe" [N/A]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-01 136600]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2007-11-30 1164576]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-13 509784]
"C-Media Mixer"="Mixer.exe" [2001-12-07 c:\windows\Mixer.exe]
"nwiz"="nwiz.exe" [2006-08-11 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"SENTINEL"= snti386.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Red Storm Entertainment\\Ghost Recon\\GhostRecon.exe"=
"c:\\Program Files\\Java\\j2re1.4.2_04\\bin\\javaw.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\GlobalSCAPE\\CuteFTP\\cutftp32.exe"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-02-13 203280]
S3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [2004-05-31 759050]
S3 PhilCam8116_XP;Logitech QuickCam Pro 3000(PID_08B1);c:\windows\system32\drivers\CamDrL20.sys [2005-03-12 245760]
.
Contents of the 'Scheduled Tasks' folder
2009-02-14 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-13 22:28]
2009-02-14 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2009-02-14 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
Trusted Zone: aol.com\free
Trusted Zone: the-holocron.com
Trusted Zone: turbotax.com
TCP: {9A876265-EA61-4452-9EFF-8E8E80FC6F69} = 68.94.156.1,68.94.157.1
FF - ProfilePath - c:\documents and settings\Jason Tanner\Application Data\Mozilla\Firefox\Profiles\ddmn4gtn.default\
FF - plugin: c:\documents and settings\Jason Tanner\Application Data\Real\RhapsodyPlayerEngine\nprhapengine.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-20 09:04:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2009-02-20 9:11:44 - machine was rebooted [Jason Tanner]
ComboFix-quarantined-files.txt 2009-02-20 17:11:38
ComboFix2.txt 2009-02-19 08:48:01
Pre-Run: 10,833,260,544 bytes free
Post-Run: 10,755,223,552 bytes free
337 — E O F — 2009-02-14 22:07:03