& Here is the COmboFix log … HJT to follow
ComboFix 09-02-27.01 - Philip Ingber 2009-02-27 16:14:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2558.1905 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\SPYWARE STUFF\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Updated)
FW: Norton AntiVirus *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Philip Ingber\Application Data\MBSLaunchServicesPlugin7339.dll
c:\documents and settings\Philip Ingber\Application Data\RBInternetEncodings550.dll
c:\documents and settings\Philip Ingber\Application Data\RBShell550.dll
c:\windows\system32\init32.exe
c:\windows\system32\tmp.reg
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\$NtServicePackUninstall$\userinit.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2009-01-27 to 2009-02-27 )))))))))))))))))))))))))))))))
.
2009-02-26 20:05 . 2009-02-26 20:05 d——– c:\program files\Intuit
2009-02-25 16:54 . 2009-02-25 16:54 d——– c:\documents and settings\All Users\Application Data\Zenturi
2009-02-25 12:04 . 2009-02-25 12:15 250 –a—— c:\windows\gmer.ini
2009-02-25 11:48 . 2009-02-25 11:48 d——– c:\program files\ERUNT
2009-02-25 09:40 . 2009-02-25 09:40 d——– C:\_OTMoveIt
2009-02-24 23:57 . 2009-02-24 23:57 d——– c:\program files\Common Files\Adobe AIR
2009-02-24 23:53 . 2009-02-24 23:53 d——– c:\program files\NOS
2009-02-24 23:53 . 2009-02-24 23:53 d——– c:\documents and settings\All Users\Application Data\NOS
2009-02-19 12:03 . 2009-02-19 12:03 579,464 –a—— c:\windows\SYSTEM32\SymNeti.dll
2009-02-19 12:03 . 2009-02-19 12:03 207,240 –a—— c:\windows\SYSTEM32\SymRedir.dll
2009-02-19 11:31 . 2009-02-19 11:31 184,496 –a—— c:\windows\SYSTEM32\DRIVERS\symtdi.sys
2009-02-19 11:31 . 2009-02-19 11:31 96,560 –a—— c:\windows\SYSTEM32\DRIVERS\symfw.sys
2009-02-19 11:31 . 2009-02-19 11:31 41,008 –a—— c:\windows\SYSTEM32\DRIVERS\symndisv.sys
2009-02-19 11:31 . 2009-02-19 11:31 38,576 –a—— c:\windows\SYSTEM32\DRIVERS\symids.sys
2009-02-19 11:31 . 2009-02-19 11:31 37,424 –a—— c:\windows\SYSTEM32\DRIVERS\symndis.sys
2009-02-19 11:31 . 2009-02-19 11:31 31,280 –a—— c:\windows\SYSTEM32\DRIVERS\SymIM.sys
2009-02-19 11:31 . 2009-02-19 11:31 22,320 –a—— c:\windows\SYSTEM32\DRIVERS\symredrv.sys
2009-02-19 11:31 . 2009-02-19 11:31 13,616 –a—— c:\windows\SYSTEM32\DRIVERS\symdns.sys
2009-02-19 11:31 . 2009-02-19 11:31 9,844 –a—— c:\windows\SYSTEM32\DRIVERS\SymRedir.cat
2009-02-19 11:31 . 2009-02-19 11:31 1,611 –a—— c:\windows\SYSTEM32\DRIVERS\SymRedir.inf
2009-02-14 19:53 . 2009-02-14 19:53 d——– c:\program files\Common Files\AnswerWorks 5.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-27 20:55 ——— d—–w c:\documents and settings\Philip Ingber\Application Data\HPAppData
2009-02-27 20:54 ——— d—–w c:\documents and settings\Philip Ingber\Application Data\SlimBrowser
2009-02-27 10:01 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-02-26 22:41 ——— d—–w c:\program files\Quicken
2009-02-26 21:05 ——— d—–w c:\program files\Windows Live Safety Center
2009-02-25 14:37 ——— d—–w c:\program files\Java
2009-02-25 10:58 ——— d—–w c:\program files\SlimBrowser
2009-02-25 04:56 ——— d—–w c:\program files\Common Files\Adobe
2009-02-25 02:49 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-02-25 02:49 ——— d—–w c:\documents and settings\Philip Ingber\Application Data\SUPERAntiSpyware.com
2009-02-25 00:06 ——— d—–w c:\documents and settings\Philip Ingber\Application Data\uTorrent
2009-02-24 21:13 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-20 18:18 ——— d–h–w c:\documents and settings\Philip Ingber\Application Data\Move Networks
2009-02-15 00:51 ——— d—–w c:\documents and settings\All Users\Application Data\Intuit
2009-02-15 00:50 ——— d—–w c:\program files\Common Files\Intuit
2009-02-15 00:45 ——— d—–w c:\program files\TurboTax
2009-02-13 00:34 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-13 00:31 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-02-11 23:27 ——— d—–w c:\program files\MozyHome
2009-02-11 15:19 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-02-04 14:45 6 —-a-w c:\windows\Fonts\wfonts.key
2009-01-20 23:08 ——— d—–w c:\program files\Red Kawa
2009-01-20 23:08 ——— d—–w c:\program files\AviSynth 2.5
2009-01-20 23:01 ——— d—–w c:\documents and settings\Philip Ingber\Application Data\Xilisoft Corporation
2009-01-20 22:51 ——— d—–w c:\documents and settings\Philip Ingber\Application Data\ImTOO Software Studio
2009-01-20 22:42 ——— d—–w c:\program files\Amazon
2009-01-20 22:42 ——— d—–w c:\documents and settings\Philip Ingber\Application Data\Amazon
2009-01-20 22:34 ——— d—–w c:\program files\NCH Software
2009-01-19 17:17 ——— d—–w c:\program files\Norton SystemWorks
2009-01-17 02:35 3,594,752 ——w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
2009-01-11 00:01 ——— d—–w c:\documents and settings\Philip Ingber\Application Data\Ahead
2009-01-10 22:46 ——— d—–w c:\program files\FLAC
2009-01-10 13:28 ——— d—–w c:\program files\Alwil Software
2009-01-09 10:15 806 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-09 10:15 60,808 —-a-w c:\windows\SYSTEM32\S32EVNT1.DLL
2009-01-09 10:15 124,464 —-a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-09 10:15 10,635 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-09 10:15 ——— d—–w c:\program files\Symantec
2009-01-05 23:01 ——— d—–w c:\documents and settings\Philip Ingber\Application Data\Malwarebytes
2009-01-05 23:00 ——— d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-05 22:39 ——— d—–w c:\program files\RegCure
2009-01-01 15:18 ——— d—–w c:\program files\Common Files\Roxio Shared
2009-01-01 14:56 ——— d—–w c:\documents and settings\All Users\Application Data\Ahead
2009-01-01 14:54 ——— d—–w c:\program files\Common Files\Ahead
2009-01-01 14:52 ——— d—–w c:\program files\Nero
2009-01-01 14:52 ——— d—–w c:\documents and settings\All Users\Application Data\Nero
2009-01-01 14:28 ——— d—–w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-21 12:41 410,984 —-a-w c:\windows\SYSTEM32\deploytk.dll
2008-12-19 09:10 70,656 ——w c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
2008-12-19 09:10 13,824 ——w c:\windows\SYSTEM32\DLLCACHE\ieudinit.exe
2008-12-19 05:25 634,024 ——w c:\windows\SYSTEM32\DLLCACHE\iexplore.exe
2008-12-19 05:23 161,792 ——w c:\windows\SYSTEM32\DLLCACHE\ieakui.dll
2008-12-12 16:18 87,336 —-a-w c:\windows\SYSTEM32\dns-sd.exe
2008-12-12 16:11 61,440 —-a-w c:\windows\SYSTEM32\dnssd.dll
2008-12-11 10:57 333,952 ——w c:\windows\SYSTEM32\DLLCACHE\srv.sys
2008-06-24 22:37 114,320 —-a-w c:\documents and settings\Philip Ingber\Application Data\GDIPFONTCACHEV1.DAT
2007-08-30 01:58 96 —-a-w c:\program files\appletfile.props
2006-10-06 12:03 560 —-a-w c:\documents and settings\Philip Ingber\Application Data\ViewerApp.dat
2005-04-28 22:07 32 —-a-r c:\documents and settings\All Users\hash.dat
2004-12-03 22:33 35,121,138 —-a-w c:\program files\NIS_Retail.EXE
2008-06-27 02:05 32,768 –sha-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012008062620080627\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2009-01-30 14:05 2788152 –a—— c:\program files\MozyHome\mozyshell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2009-01-30 14:05 2788152 –a—— c:\program files\MozyHome\mozyshell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"NvMediaCenter"="c:\windows\system32\NVMCTRAY.DLL" [2005-12-10 86016]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2006-10-30 392832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
"DwlClient"="c:\program files\Common Files\Dell\EUSW\Support.exe" [2004-05-27 323584]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-26 204800]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-10 7311360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-12-10 86016]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-04-07 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-04-07 114688]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"NSWosCheck"="c:\program files\Norton SystemWorks\osCheck.exe" [2007-09-18 25472]
"osCheck"="c:\program files\Norton AntiVirus\osCheck.exe" [2007-08-24 714608]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"AirPort Base Station Agent"="c:\program files\AirPort\APAgent.exe" [2008-05-20 737280]
"QuickTime Task"="c:\program files\QT Lite\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-02-11 399504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-21 136600]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 c:\windows\SYSTEM32\bthprops.cpl]
"nwiz"="nwiz.exe" [2005-12-10 c:\windows\SYSTEM32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Symantec NetDriver Warning"="c:\progra~1\SYMNET~1\SNDWarn.exe" [2004-10-29 218232]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SRUUninstall"="c:\windows\System32\msiexec.exe" [2008-04-13 78848]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\IOGEAR\Bluetooth Software\BTTray.exe [2005-05-31 577597]
DataViz Inc Messenger.lnk - c:\program files\Common Files\DataViz\DvzIncMsgr.exe [2006-01-14 28672]
HOTSYNCSHORTCUTNAME.lnk - c:\program files\Handspring\HOTSYNC.EXE [2004-06-09 471040]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-09 28672]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-12-17 809488]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
MozyHome Status.lnk - c:\program files\MozyHome\mozystat.exe [2009-01-30 2737464]
officejet 6100.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2003-04-09 147456]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-11-07 16:41 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= c:\windows\System32\ctmp3.acm
"WAVE3"= vscapi.dll
"Midi1"= vscapi.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0aswBoot.exe /M:9da046202aa
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vsc32cnf.exe]
–a—— 2000-02-07 02:02 36864 c:\program files\Roland\VSC32\Vsc32Cnf.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vscvol.exe]
–a—— 2000-02-08 22:19 36864 c:\program files\Roland\VSC32\vscvol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\AirPort\\APAgent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:UDP"= 5353:UDP:Bonjour
R1 mozyFilter;mozyFilter;c:\windows\SYSTEM32\DRIVERS\mozy.sys [2008-12-08 53752]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [2009-01-28 13088]
R2 LBeepKE;LBeepKE;c:\windows\SYSTEM32\DRIVERS\LBeepKE.sys [2008-12-17 10384]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2007-08-25 149352]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-01-05 179856]
R2 NProtectService;Norton UnErase Protection;c:\progra~1\NORTON~3\NORTON~2\NPROTECT.EXE [2005-11-03 95832]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-25 101936]
R3 MBAMProtector;MBAMProtector;c:\windows\SYSTEM32\DRIVERS\mbam.sys [2009-01-05 15504]
R3 vsc32;Virtual Sound Canvas 3.2;c:\windows\SYSTEM32\DRIVERS\vsc.sys [2007-04-04 951284]
S2 mrtRate;mrtRate; [x]
S3 COH_Mon;COH_Mon;c:\windows\SYSTEM32\DRIVERS\COH_Mon.sys [2007-05-29 23888]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-02-24 33752]
S3 MAUSBJL;Service for M-Audio JamLab Driver (WDM);c:\windows\system32\DRIVERS\mausbjl.sys –> c:\windows\system32\DRIVERS\mausbjl.sys [?]
S3 wg121;NETGEAR WG121 802.11g Wireless USB2.0 Adapter;c:\windows\SYSTEM32\DRIVERS\wg121nd5.sys [2008-09-05 337216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
2009-02-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
2009-01-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-02-26 c:\windows\Tasks\Malwarebytes' Scheduled Update for Philip Ingber.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-02-11 10:19]
2009-02-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2009-02-09 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - Philip Ingber.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-26 20:19]
2009-01-19 c:\windows\Tasks\Norton SystemWorks One Button Checkup.job
- c:\program files\Norton SystemWorks\OBC.exe [2007-09-18 07:22]
2009-02-27 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 04:20]
2009-01-05 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 04:20]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
HKCU-Run-Aim6 - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1;localhost;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\IOGEAR\Bluetooth Software\btsendto_ie_ctx.htm
Trusted Zone: aol.com\free
Trusted Zone: turbotax.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: Yahoo! Pyramids - hxxp://origin.games.yahoo.net/games/clients/y/pyt1_x.cab
DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} - hxxp://www.imgag.com/cp/install/AxCtp.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
DPF: {A364AF35-0CDF-41E8-8F3B-E0E55E15EBA1} - hxxp://www.programchecker.com/dll/nixon.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-27 16:21:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DwlClient = c:\program files\Common Files\Dell\EUSW\Support.exe?l?e?s?\?D?e?l?l?\?E?U?S?W?\?S?u?p?p?o?r?t?.?e?x?e???x???x???????????????????x???h???????x???x???????????x???`???????x???x???????????????????????X??????????????????w????????????j??w????x???x??????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3555281675-418566156-79606422-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-3555281675-418566156-79606422-1007\Software\YourCompanyName\YourProductName\Version*]
"VersionData"=hex:9b,02,a6,a7,ad,b8,a1,6f,4e,11,c9,35,1c,75,21,75,fe,99,21,76,
46,3a,a8,11,b2,bc,38,d1,89,81,23,b8,0f,23,6d,b6,3b,12,f5,75,a5,0b,c1,13,6f,\
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1120)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
- - - - - - - > 'explorer.exe'(6084)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\program files\MozyHome\mozyshell.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\IOGEAR\Bluetooth Software\bin\btwdins.exe
c:\windows\SYSTEM32\CTsvcCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\MozyHome\mozybackup.exe
c:\windows\SYSTEM32\nvsvc32.exe
c:\progra~1\NORTON~3\NORTON~2\SPEEDD~1\NOPDB.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\SYSTEM32\MsPMSPSv.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\SYSTEM32\rundll32.exe
c:\progra~1\IOGEAR\BLUETO~1\BTSTAC~1.EXE
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
c:\program files\Symantec\LiveUpdate\LuComServer_3_4.EXE
c:\program files\Symantec\LiveUpdate\AUPDATE.EXE
.
**************************************************************************
.
Completion time: 2009-02-27 16:38:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-27 21:38:45
Pre-Run: 30,748,790,784 bytes free
Post-Run: 30,607,810,560 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
344 — E O F — 2009-02-26 21:01:39