Good Morning CB!!
Finally some good news, I was in fact able to run ComboFix in Safe Mode..
It wasnt able to install the Recovery Tool, i tried to cancel the scan but it ran anyway, it said it was unable to install it.
Here is the Log from the scan.. my machine seems to be running better it feels so good to know we are starting to make some progress!! I still have a few pop ups but no where near what it was!! I am also having some program crashes on my antivirus programs..not sure if its due to this or not! I will also rerun HJT and post its log next…
Mary!
ComboFix 09-03-31.01 - Lea Family 2009-04-01 7:21:00.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.809 [GMT -5:00]
Running from: c:\documents and settings\[removed]\desktop\combofix.exe
AV: CyberDefender Internet Security *On-access scanning enabled* (Updated)
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers
c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers\c.cgm
c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers\egdieexaru.dll
c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers\hdddriver.dll
c:\documents and settings\Lea Family\Start Menu\Programs\Malware Defender 2009
c:\documents and settings\Lea Family\Start Menu\Programs\Malware Defender 2009\Malware Defender 2009.lnk
c:\documents and settings\Lea Family\Start Menu\Programs\Malware Defender 2009\Uninstall.lnk
c:\program files\Malware Defender 2009
c:\program files\Malware Defender 2009\conf.cfg
c:\program files\Malware Defender 2009\malwaredef.exe
c:\program files\Malware Defender 2009\mbase.vdb
c:\program files\Malware Defender 2009\quarantine.vdb
c:\program files\Malware Defender 2009\queue.vdb
c:\program files\Malware Defender 2009\uninstall.exe
c:\program files\Malware Defender 2009\vbase.vdb
c:\windows\IE4 Error Log.txt
c:\windows\system32\AccessibleMarshal.dll
c:\windows\system32\AcroIEHelpe.dll
c:\windows\system32\cks
c:\windows\system32\cks\lea [removed][1].txt
c:\windows\system32\cks\lea [removed][2].txt
c:\windows\system32\cks\lea family@adbrite[1].txt
c:\windows\system32\cks\lea family@apmebf[1].txt
c:\windows\system32\cks\lea family@atdmt[1].txt
c:\windows\system32\cks\lea family@doubleclick[1].txt
c:\windows\system32\cks\lea family@doubleclick[2].txt
c:\windows\system32\cks\lea [removed][1].txt
c:\windows\system32\cks\lea family@hitbox[1].txt
c:\windows\system32\cks\lea [removed][1].txt
c:\windows\system32\cks\lea family@tribalfusion[1].txt
c:\windows\system32\cks\lea family@tribalfusion[2].txt
c:\windows\system32\cks\lea family@zedo[1].txt
c:\windows\system32\cks\lea family@zedo[2].txt
c:\windows\system32\components
c:\windows\system32\components\aboutRights.js
c:\windows\system32\components\aboutRobots.js
c:\windows\system32\components\browser.xpt
c:\windows\system32\components\browserdirprovider.dll
c:\windows\system32\components\brwsrcmp.dll
c:\windows\system32\components\FeedConverter.js
c:\windows\system32\components\FeedProcessor.js
c:\windows\system32\components\FeedWriter.js
c:\windows\system32\components\fuelApplication.js
c:\windows\system32\components\jsconsole-clhandler.js
c:\windows\system32\components\nsAddonRepository.js
c:\windows\system32\components\nsBadCertHandler.js
c:\windows\system32\components\nsBlocklistService.js
c:\windows\system32\components\nsBrowserContentHandler.js
c:\windows\system32\components\nsBrowserGlue.js
c:\windows\system32\components\nsContentDispatchChooser.js
c:\windows\system32\components\nsContentPrefService.js
c:\windows\system32\components\nsDefaultCLH.js
c:\windows\system32\components\nsDownloadManagerUI.js
c:\windows\system32\components\nsExtensionManager.js
c:\windows\system32\components\nsHandlerService.js
c:\windows\system32\components\nsHelperAppDlg.js
c:\windows\system32\components\nsLivemarkService.js
c:\windows\system32\components\nsLoginInfo.js
c:\windows\system32\components\nsLoginManager.js
c:\windows\system32\components\nsLoginManagerPrompter.js
c:\windows\system32\components\nsMicrosummaryService.js
c:\windows\system32\components\nsPlacesTransactionsService.js
c:\windows\system32\components\nsPostUpdateWin.js
c:\windows\system32\components\nsProxyAutoConfig.js
c:\windows\system32\components\nsSafebrowsingApplication.js
c:\windows\system32\components\nsSearchService.js
c:\windows\system32\components\nsSearchSuggestions.js
c:\windows\system32\components\nsSessionStartup.js
c:\windows\system32\components\nsSessionStore.js
c:\windows\system32\components\nsSetDefaultBrowser.js
c:\windows\system32\components\nsSidebar.js
c:\windows\system32\components\nsTaggingService.js
c:\windows\system32\components\nsTryToClose.js
c:\windows\system32\components\nsUpdateService.js
c:\windows\system32\components\nsUrlClassifierLib.js
c:\windows\system32\components\nsUrlClassifierListManager.js
c:\windows\system32\components\nsURLFormatter.js
c:\windows\system32\components\nsWebHandlerApp.js
c:\windows\system32\components\pluginGlue.js
c:\windows\system32\components\storage-Legacy.js
c:\windows\system32\components\txEXSLTRegExFunctions.js
c:\windows\system32\components\WebContentConverter.js
c:\windows\system32\dtw5d
c:\windows\system32\dtw5d\1396_0000000001.key
c:\windows\system32\dtw5d\1396_0000000002.clb
c:\windows\system32\dtw5d\1396_0000000003.htm
c:\windows\system32\dtw5d\1420_0000000041.clb
c:\windows\system32\dtw5d\1420_0000000042.htm
c:\windows\system32\dtw5d\1420_0000000043.frm
c:\windows\system32\dtw5d\1420_0000000044.pst
c:\windows\system32\dtw5d\1420_0000000046.clb
c:\windows\system32\dtw5d\1420_0000000047.htm
c:\windows\system32\dtw5d\188_0000000007.key
c:\windows\system32\dtw5d\188_0000000008.clb
c:\windows\system32\dtw5d\188_0000000009.htm
c:\windows\system32\dtw5d\252_0000000010.key
c:\windows\system32\dtw5d\252_0000000011.clb
c:\windows\system32\dtw5d\252_0000000012.htm
c:\windows\system32\dtw5d\2696_0000000029.clb
c:\windows\system32\dtw5d\2696_0000000030.htm
c:\windows\system32\dtw5d\2996_0000000013.key
c:\windows\system32\dtw5d\2996_0000000014.clb
c:\windows\system32\dtw5d\2996_0000000015.htm
c:\windows\system32\dtw5d\3688_0000000004.key
c:\windows\system32\dtw5d\3688_0000000005.clb
c:\windows\system32\dtw5d\3688_0000000006.htm
c:\windows\system32\dtw5d\3724_0000000032.clb
c:\windows\system32\dtw5d\3724_0000000033.htm
c:\windows\system32\dtw5d\3788_0000000017.clb
c:\windows\system32\dtw5d\3788_0000000018.htm
c:\windows\system32\dtw5d\4440_0000000026.clb
c:\windows\system32\dtw5d\4440_0000000027.htm
c:\windows\system32\dtw5d\4592_0000000048.key
c:\windows\system32\dtw5d\4592_0000000049.clb
c:\windows\system32\dtw5d\4592_0000000050.htm
c:\windows\system32\dtw5d\4592_0000000051.frm
c:\windows\system32\dtw5d\4592_0000000052.frm
c:\windows\system32\dtw5d\4592_0000000053.frm
c:\windows\system32\dtw5d\4592_0000000054.pst
c:\windows\system32\dtw5d\4592_0000000055.pst
c:\windows\system32\dtw5d\4592_0000000056.key
c:\windows\system32\dtw5d\4592_0000000057.clb
c:\windows\system32\dtw5d\4592_0000000058.htm
c:\windows\system32\dtw5d\4592_0000000059.frm
c:\windows\system32\dtw5d\4592_0000000060.key
c:\windows\system32\dtw5d\4592_0000000061.htm
c:\windows\system32\dtw5d\4592_0000000062_ifrm.htm
c:\windows\system32\dtw5d\4592_0000000063_ifrm.htm
c:\windows\system32\dtw5d\4592_0000000064.frm
c:\windows\system32\dtw5d\5276_0000000022.key
c:\windows\system32\dtw5d\5276_0000000023.clb
c:\windows\system32\dtw5d\5276_0000000024.htm
c:\windows\system32\dtw5d\5280_0000000034.key
c:\windows\system32\dtw5d\5280_0000000035.clb
c:\windows\system32\dtw5d\5280_0000000036.htm
c:\windows\system32\dtw5d\5280_0000000037_ifrm.htm
c:\windows\system32\dtw5d\5280_0000000038_ifrm.htm
c:\windows\system32\dtw5d\5280_0000000039.pst
c:\windows\system32\dtw5d\6136_0000000019.key
c:\windows\system32\dtw5d\6136_0000000020.clb
c:\windows\system32\dtw5d\6136_0000000021.htm
c:\windows\system32\dtw5d\AcroRd32_UAs001.dat
c:\windows\system32\dtw5d\AcroRd32_UAs002.dat
c:\windows\system32\dtw5d\buildintime-wt_UAs001.dat
c:\windows\system32\dtw5d\buildintime-wt_UAs002.dat
c:\windows\system32\dtw5d\cdasc9_UAs001.dat
c:\windows\system32\dtw5d\cdasc9_UAs002.dat
c:\windows\system32\dtw5d\cdasc9_UAs003.dat
c:\windows\system32\dtw5d\cdasc9_UAs004.dat
c:\windows\system32\dtw5d\cdasc9_UAs005.dat
c:\windows\system32\dtw5d\cdasc9_UAs006.dat
c:\windows\system32\dtw5d\cdasc9_UAs007.dat
c:\windows\system32\dtw5d\cdasc9_UAs008.dat
c:\windows\system32\dtw5d\cdasc9_UAs009.dat
c:\windows\system32\dtw5d\cdasc9_UAs010.dat
c:\windows\system32\dtw5d\cdinstx_UAs001.dat
c:\windows\system32\dtw5d\cdinstx_UAs002.dat
c:\windows\system32\dtw5d\countyfair-wt_UAs001.dat
c:\windows\system32\dtw5d\countyfair-wt_UAs002.dat
c:\windows\system32\dtw5d\daisy-wt_UAs001.dat
c:\windows\system32\dtw5d\download_snm-2.67_swpl_UAs001.dat
c:\windows\system32\dtw5d\dw20_UAs001.dat
c:\windows\system32\dtw5d\dwwin_UAs001.dat
c:\windows\system32\dtw5d\explorer_UAs004.dat
c:\windows\system32\dtw5d\farm2-wt_UAs001.dat
c:\windows\system32\dtw5d\farm2-wt_UAs002.dat
c:\windows\system32\dtw5d\farm2_UAs001.dat
c:\windows\system32\dtw5d\gameconsole-wt_UAs001.dat
c:\windows\system32\dtw5d\gameconsole-wt_UAs002.dat
c:\windows\system32\dtw5d\helpctr_UAs001.dat
c:\windows\system32\dtw5d\HelpHost_UAs001.dat
c:\windows\system32\dtw5d\HelpHost_UAs002.dat
c:\windows\system32\dtw5d\hprbupdate_UAs001.dat
c:\windows\system32\dtw5d\iexplore_UAs005.dat
c:\windows\system32\dtw5d\javaw_UAs001.dat
c:\windows\system32\dtw5d\jre-6u12-windows-i586-p-iftw_UAs001.dat
c:\windows\system32\dtw5d\jre-6u12-windows-i586-p-iftw_UAs002.dat
c:\windows\system32\dtw5d\jusched_UAs001.dat
c:\windows\system32\dtw5d\malwaredefender2009[1]_UAs001.dat
c:\windows\system32\dtw5d\malwaredefender2009[2]_UAs001.dat
c:\windows\system32\dtw5d\MsiExec_UAs001.dat
c:\windows\system32\dtw5d\mvtapp_UAs001.dat
c:\windows\system32\dtw5d\netbanke_2009.03.11.041751_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041751_lea family@atdmt[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041751_lea family@doubleclick[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041751_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041751_lea family@hitbox[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041752_lea family@adbrite[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041752_lea family@apmebf[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041752_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041752_lea family@tribalfusion[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.11.041752_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.070953_lea family@apmebf[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.070953_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.070953_lea family@fastclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071003_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071446_lea family@atdmt[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071446_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071446_lea family@hitbox[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071457_lea family@atdmt[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071623_lea family@fastclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071936_lea family@fastclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.12.071951_lea family@apmebf[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075436_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075436_lea family@hitbox[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075442_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075442_lea family@hitbox[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075447_lea family@hitbox[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075642_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075642_lea family@realmedia[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.13.075648_lea family@fastclick[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.14.110537_lea family@fastclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.15.082844_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.15.082844_lea family@hitbox[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.15.083424_lea family@adbrite[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.16.092026_lea family@adbrite[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.085050_lea family@tribalfusion[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.085055_lea family@tribalfusion[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.085110_lea family@tribalfusion[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.094846_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.101154_lea family@apmebf[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.101154_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.101154_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.101154_lea family@hitbox[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.101204_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.17.101807_lea family@casalemedia[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124043_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124049_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124054_lea family@advertising[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124054_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124059_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124105_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124105_lea family@advertising[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124105_lea family@atdmt[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124110_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124115_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124120_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124125_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124131_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124136_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124141_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124141_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124146_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124146_lea family@atdmt[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124147_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124152_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124157_lea family@atdmt[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124157_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124203_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124208_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124213_lea family@zedo[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124218_lea family@atdmt[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124218_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.20.124224_lea family@zedo[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.22.051346_lea family@advertising[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.23.055751_lea family@casalemedia[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.23.070251_lea family@casalemedia[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.24.102742_lea family@advertising[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.24.105303_lea family@tribalfusion[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.062112_lea family@fastclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.062118_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.062138_lea family@microsoftwindows.112.2o7[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.082940_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083015_lea family@advertising[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083021_lea family@advertising[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083026_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083031_lea family@advertising[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083552_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083659_lea family@fastclick[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083700_lea family@apmebf[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.083705_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.104213_lea family@casalemedia[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.104219_lea family@casalemedia[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.104401_lea family@tribalfusion[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.104406_lea family@tribalfusion[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.104412_lea family@doubleclick[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.104412_lea family@tribalfusion[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.105030_lea family@advertising[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.114144_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.25.114144_lea family@hitbox[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.26.052414_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.26.052521_lea family@tribalfusion[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.062431_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.062437_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.062954_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.064149_lea family@trafficmp[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.064206_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.065039_lea family@trafficmp[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.065732_lea family@trafficmp[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.070332_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.27.074336_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.30.064004_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.30.064009_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.30.070812_lea family@casalemedia[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.055300_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.055306_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062059_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062109_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062220_lea family@2o7[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062220_lea family@msnportal.112.2o7[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062225_lea family@msnservices.112.2o7[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062942_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062952_lea [removed][1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.062958_lea [removed][2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.063008_lea family@doubleclick[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.095208_lea family@atdmt[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.095615_lea family@atdmt[2].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.101945_lea family@apmebf[1].txt
c:\windows\system32\dtw5d\netbanke_2009.03.31.101945_lea family@doubleclick[1].txt
c:\windows\system32\dtw5d\ranchrush-wt_UAs001.dat
c:\windows\system32\dtw5d\ranchrush-wt_UAs002.dat
c:\windows\system32\dtw5d\SNM_UAs001.dat
c:\windows\system32\dtw5d\sprtcmd_UAs001.dat
c:\windows\system32\dtw5d\VRM2009_UAs001.dat
c:\windows\system32\dtw5d\win_UAs001.dat
c:\windows\system32\firefox.exe
c:\windows\system32\freebl3.dll
c:\windows\system32\korlg.ini
c:\windows\system32\ldshyr.old
c:\windows\system32\mozcrt19.dll
c:\windows\system32\nspr4.dll
c:\windows\system32\nss3.dll
c:\windows\system32\nssckbi.dll
c:\windows\system32\nssdbm3.dll
c:\windows\system32\nssutil3.dll
c:\windows\system32\nwklr.ini
c:\windows\system32\nwpp.ini
c:\windows\system32\nwwlnt.ini
c:\windows\system32\plc4.dll
c:\windows\system32\plds4.dll
c:\windows\system32\Plugins
c:\windows\system32\Plugins\npnul32.dll
c:\windows\system32\ppdnp.ini
c:\windows\system32\pporlg.ini
c:\windows\system32\smime3.dll
c:\windows\system32\softokn3.dll
c:\windows\system32\srvblck.tmp
c:\windows\system32\ssl3.dll
c:\windows\system32\UAs
c:\windows\system32\UAs\AcroRd32_UAs001.dat
c:\windows\system32\UAs\AcroRd32_UAs002.dat
c:\windows\system32\UAs\bb2_UAs001.dat
c:\windows\system32\UAs\buildintime-wt_UAs001.dat
c:\windows\system32\UAs\buildintime-wt_UAs002.dat
c:\windows\system32\UAs\cdasc9_UAs001.dat
c:\windows\system32\UAs\cdasc9_UAs002.dat
c:\windows\system32\UAs\cdasc9_UAs003.dat
c:\windows\system32\UAs\cdasc9_UAs004.dat
c:\windows\system32\UAs\cdasc9_UAs005.dat
c:\windows\system32\UAs\cdasc9_UAs006.dat
c:\windows\system32\UAs\cdasc9_UAs007.dat
c:\windows\system32\UAs\cdasc9_UAs008.dat
c:\windows\system32\UAs\cdasc9_UAs009.dat
c:\windows\system32\UAs\cdasc9_UAs010.dat
c:\windows\system32\UAs\cdinstx_UAs001.dat
c:\windows\system32\UAs\cdinstx_UAs002.dat
c:\windows\system32\UAs\countyfair-wt_UAs001.dat
c:\windows\system32\UAs\countyfair-wt_UAs002.dat
c:\windows\system32\UAs\crashreporter_UAs001.dat
c:\windows\system32\UAs\daisy-wt_UAs001.dat
c:\windows\system32\UAs\download_snm-2.67_swpl_UAs001.dat
c:\windows\system32\UAs\dsagnt_UAs001.dat
c:\windows\system32\UAs\dw20_UAs001.dat
c:\windows\system32\UAs\dwwin_UAs001.dat
c:\windows\system32\UAs\Explorer_UAs001.dat
c:\windows\system32\UAs\Explorer_UAs002.dat
c:\windows\system32\UAs\Explorer_UAs003.dat
c:\windows\system32\UAs\explorer_UAs004.dat
c:\windows\system32\UAs\farm2-wt_UAs001.dat
c:\windows\system32\UAs\farm2-wt_UAs002.dat
c:\windows\system32\UAs\farm2_UAs001.dat
c:\windows\system32\UAs\firefox_UAs001.dat
c:\windows\system32\UAs\firefox_UAs002.dat
c:\windows\system32\UAs\firefox_UAs003.dat
c:\windows\system32\UAs\gameconsole-wt_UAs001.dat
c:\windows\system32\UAs\gameconsole-wt_UAs002.dat
c:\windows\system32\UAs\googletoolbarnotifier_UAs001.dat
c:\windows\system32\UAs\googletoolbarnotifier_UAs002.dat
c:\windows\system32\UAs\helpctr_UAs001.dat
c:\windows\system32\UAs\HelpHost_UAs001.dat
c:\windows\system32\UAs\HelpHost_UAs002.dat
c:\windows\system32\UAs\hprbupdate_UAs001.dat
c:\windows\system32\UAs\iexplore_UAs001.dat
c:\windows\system32\UAs\iexplore_UAs002.dat
c:\windows\system32\UAs\iexplore_UAs003.dat
c:\windows\system32\UAs\iexplore_UAs004.dat
c:\windows\system32\UAs\iexplore_UAs005.dat
c:\windows\system32\UAs\javaw_UAs001.dat
c:\windows\system32\UAs\jre-6u12-windows-i586-p-iftw_UAs001.dat
c:\windows\system32\UAs\jre-6u12-windows-i586-p-iftw_UAs002.dat
c:\windows\system32\UAs\jucheck_UAs001.dat
c:\windows\system32\UAs\jusched_UAs001.dat
c:\windows\system32\UAs\malwaredefender2009[1]_UAs001.dat
c:\windows\system32\UAs\malwaredefender2009[2]_UAs001.dat
c:\windows\system32\UAs\mcshell_UAs001.dat
c:\windows\system32\UAs\mcsvrcnt_UAs001.dat
c:\windows\system32\UAs\McSync_UAs001.dat
c:\windows\system32\UAs\mcupdmgr_UAs001.dat
c:\windows\system32\UAs\mcvsmap_UAs001.dat
c:\windows\system32\UAs\MsiExec_UAs001.dat
c:\windows\system32\UAs\msimn_UAs001.dat
c:\windows\system32\UAs\msimn_UAs002.dat
c:\windows\system32\UAs\mvtapp_UAs001.dat
c:\windows\system32\UAs\npswf32_flashutil_UAs001.dat
c:\windows\system32\UAs\ranchrush-wt_UAs001.dat
c:\windows\system32\UAs\ranchrush-wt_UAs002.dat
c:\windows\system32\UAs\SNM_UAs001.dat
c:\windows\system32\UAs\softwareupdate_UAs001.dat
c:\windows\system32\UAs\sprtcmd_UAs001.dat
c:\windows\system32\UAs\sprtsvc_UAs001.dat
c:\windows\system32\UAs\VRM2009_UAs001.dat
c:\windows\system32\UAs\win_UAs001.dat
c:\windows\system32\UAs\winlogon_UAs001.dat
c:\windows\system32\UAs\wmplayer_UAs001.dat
c:\windows\system32\updater.exe
c:\windows\system32\windmlp.ini
c:\windows\system32\worlg.ini
c:\windows\system32\xpcom.dll
.
((((((((((((((((((((((((( Files Created from 2009-03-01 to 2009-04-01 )))))))))))))))))))))))))))))))
.
2009-04-01 07:29 . 2009-04-01 07:30 d——– c:\windows\system32\UAs
2009-04-01 07:28 . 2009-04-01 07:30 d——– c:\windows\system32\Dtw5d
2009-04-01 07:18 . 2009-04-01 07:18 552 –a—— c:\windows\system32\d3d8caps.dat
2009-04-01 07:02 . 2006-07-17 11:48 d——– c:\documents and settings\Administrator\Application Data\Symantec
2009-04-01 07:02 . 2009-04-01 07:02 d——– c:\documents and settings\Administrator
2009-03-31 14:19 . 2008-12-12 00:45 d——– c:\windows\system32\SmitfraudFix
2009-03-31 14:11 . 2009-03-31 14:12 d—-c— C:\Combo-Fix
2009-03-31 13:17 . 2009-03-31 13:17 d—-c— C:\ComboFix1
2009-03-31 10:33 . 2009-03-31 10:33 d——– c:\program files\Trend Micro
2009-03-29 23:14 . 2009-03-29 23:14 381,440 –a—— c:\windows\system32\wcenter.exe
2009-03-29 22:23 . 2009-03-29 22:23 1,152 –a—— c:\windows\system32\windrv.sys
2009-03-29 22:17 . 2009-03-29 22:23 d——– c:\documents and settings\Lea Family\Application Data\GetRightToGo
2009-03-29 21:35 . 2009-03-29 21:35 d——– c:\documents and settings\Lea Family\Application Data\CyberDefender
2009-03-29 09:31 . 2009-03-29 09:31 73 –a—— c:\windows\st_affiliate.ini
2009-03-29 09:23 . 2009-03-29 09:23 63 –a—— c:\windows\av_affiliate.ini
2009-03-29 09:23 . 2009-03-29 09:23 63 –a—— c:\windows\as_affiliate.ini
2009-03-29 09:19 . 2009-03-29 21:31 d——– c:\program files\CyberDefender
2009-03-29 09:19 . 2009-03-29 09:16 67,424 –a—— c:\windows\system32\drivers\CDAVFS.sys
2009-03-28 10:32 . 2009-03-28 10:32 d——– c:\windows\system32\config\systemprofile\Application Data\SACore
2009-03-11 16:17 . 2009-03-31 18:22 d——– c:\windows\system32\cock
2009-03-10 18:43 . 2009-03-10 18:43 41,168 –a—— c:\windows\system32\ldshyf.old
2009-03-04 09:09 . 2009-03-04 09:07 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2009-03-04 09:05 . 2009-03-04 09:24 d——– c:\documents and settings\Lea Family\.housecall6.6
2009-03-04 09:00 . 2009-03-23 16:15 d——– c:\program files\Panda Security
2009-03-04 01:33 . 2009-04-01 06:02 1,546 –a—— c:\windows\system32\urhtps.dat
2009-03-03 21:14 . 2009-03-10 18:46 997,888 –a—— c:\windows\system32\dllcache\kernel32.dll
2009-03-03 21:14 . 2009-03-10 18:46 21,504 –a—— c:\windows\system32\dllcache\powrprof.dll
2009-03-01 20:03 . 2009-03-01 20:03 d——– c:\documents and settings\Lea Family\Application Data\ViquaSoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-31 23:09 ——— d—–w c:\program files\LimeWire
2009-03-27 12:36 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2009-03-27 12:35 ——— d—–w c:\documents and settings\Lea Family\Application Data\McAfee
2009-03-25 02:13 ——— d—–w c:\program files\McAfee
2009-03-24 00:01 ——— d—–w c:\program files\WildTangent
2009-03-23 22:56 ——— d—–w c:\program files\Dell Games
2009-03-22 22:26 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-03-17 14:46 5,018 –sha-w c:\windows\system32\KGyGaAvL.sys
2009-03-11 21:14 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-11 12:59 84,992 ——w c:\windows\system32\zazofose.dll
2009-03-11 12:59 79,872 ——w c:\windows\system32\sazisuhi.dll
2009-03-10 23:46 690,688 —-a-w c:\windows\system32\wininet.dll
2009-03-10 23:46 21,504 —-a-w c:\windows\system32\powrprof.dll
2009-03-10 15:23 ——— d—–w c:\documents and settings\Lea Family\Application Data\SPORE Creature Creator
2009-03-09 12:58 79,872 ——w c:\windows\system32\melunule.dll
2009-03-06 02:59 9,742,840 —-a-w c:\windows\system32\xul.dll
2009-03-06 02:59 696,312 —-a-w c:\windows\system32\js3250.dll
2009-03-06 02:59 395,768 —-a-w c:\windows\system32\sqlite3.dll
2009-03-06 02:59 185,848 —-a-w c:\windows\system32\crashreporter.exe
2009-03-02 02:42 ——— d—–w c:\documents and settings\All Users\Application Data\WildTangent
2009-03-02 00:57 ——— d—–w c:\program files\FinePixViewer
2009-03-02 00:50 ——— d—–w c:\program files\Oberon Media
2009-02-24 18:26 ——— d—–w c:\documents and settings\All Users\Application Data\FarmFrenzy-PizzaParty
2009-02-20 22:02 ——— d—–w c:\documents and settings\Lea Family\Application Data\Apple Computer
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2009-02-09 11:13 1,846,784 ——w c:\windows\system32\dllcache\win32k.sys
2008-12-11 05:23 88 –sh–r c:\windows\system32\CF87502B0D.sys
.
——- Sigcheck ——-
2006-01-09 13:02 662016 dde9597a3311748c1519444e2bc147bd c:\windows\$hf_mig$\KB912945\SP2QFE\wininet.dll
2006-05-10 00:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
2008-04-21 01:44 666112 2b0c24aa747a93a28987b6d65a4a74bc c:\windows\$hf_mig$\KB950759\SP3GDR\wininet.dll
2008-04-21 01:24 666624 26f240c250e5b4b395cb4b178ba75437 c:\windows\$hf_mig$\KB950759\SP3QFE\wininet.dll
2008-06-23 10:09 666112 f12fbb673de9cc802c5dc518fe99aa2f c:\windows\$hf_mig$\KB953838\SP3GDR\wininet.dll
2008-06-23 09:54 666624 972299b7241ec325d8c7e5638c884925 c:\windows\$hf_mig$\KB953838\SP3QFE\wininet.dll
2008-08-19 23:58 666624 94418f53d2612c26dbadc04dafbc197c c:\windows\$hf_mig$\KB956390\SP3QFE\wininet.dll
2008-10-15 20:04 667136 e8fce58a470999350f64c591557f9e42 c:\windows\$hf_mig$\KB958215\SP3QFE\wininet.dll
2008-06-23 11:12 667136 611ace3f4201e9610af8452f7c268995 c:\windows\$NtServicePackUninstall$\wininet.dll
2006-05-10 00:23 658432 38ab7a56f566d9aaad31812494944824 c:\windows\$NtUninstallKB916281$\wininet.dll
2006-05-10 00:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$NtUninstallKB942615$\wininet.dll
2007-10-11 00:57 666112 80d660a49e0d118144423099b2a9f5da c:\windows\$NtUninstallKB944533$\wininet.dll
2007-12-06 19:44 666112 085a7c37f9c6ede1ba870b7dbec06399 c:\windows\$NtUninstallKB947864$\wininet.dll
2008-04-13 19:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\$NtUninstallKB950759$\wininet.dll
2008-02-16 04:32 666112 bb1eacd6ab47e78ebca02eb781550d55 c:\windows\$NtUninstallKB950759_0$\wininet.dll
2008-04-21 01:44 666112 2b0c24aa747a93a28987b6d65a4a74bc c:\windows\$NtUninstallKB953838$\wininet.dll
2008-04-21 01:56 666624 2e7de1bf9418b071799eb53de8cc22f5 c:\windows\$NtUninstallKB953838_0$\wininet.dll
2008-06-23 10:09 666112 f12fbb673de9cc802c5dc518fe99aa2f c:\windows\$NtUninstallKB956390$\wininet.dll
2008-08-20 00:30 666112 9af5f25124fbdc36e2b510729cba2674 c:\windows\$NtUninstallKB958215$\wininet.dll
2008-04-13 19:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\ServicePackFiles\i386\wininet.dll
2009-03-10 18:46 690688 a4c471050b3c631b42951d7e32237987 c:\windows\system32\wininet.dll
2009-03-10 18:46 690688 a4c471050b3c631b42951d7e32237987 c:\windows\system32\dllcache\wininet.dll
2007-04-16 11:07 986112 09f7cb3687f86edaa4ca081f7ab66c03 c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
2007-04-16 10:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\$NtServicePackUninstall$\kernel32.dll
2004-08-04 05:00 983552 888190e31455fad793312f8d087146eb c:\windows\$NtUninstallKB935839$\kernel32.dll
2008-04-13 19:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows\ServicePackFiles\i386\kernel32.dll
2009-03-10 18:46 997888 ac26a98dbbd5b924d53efe4b50c451a5 c:\windows\system32\kernel32.dll
2009-03-10 18:46 997888 ac26a98dbbd5b924d53efe4b50c451a5 c:\windows\system32\dllcache\kernel32.dll
2004-08-04 05:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\$NtServicePackUninstall$\powrprof.dll
2008-04-13 19:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\ServicePackFiles\i386\powrprof.dll
2009-03-10 18:46 21504 84797238ddd10b9990701398f3c879d0 c:\windows\system32\powrprof.dll
2009-03-10 18:46 21504 84797238ddd10b9990701398f3c879d0 c:\windows\system32\dllcache\powrprof.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}"= "c:\documents and settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll" [2009-03-29 3851592]
[HKEY_CLASSES_ROOT\clsid\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}]
[HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{CD24EB02-9831-4838-99D0-726D411B1328}]
[HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}]
2009-03-29 09:15 3851592 –a—— c:\documents and settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}"= "c:\documents and settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll" [2009-03-29 3851592]
[HKEY_CLASSES_ROOT\clsid\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}]
[HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{CD24EB02-9831-4838-99D0-726D411B1328}]
[HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}"= "c:\documents and settings\Lea Family\Local Settings\Application Data\CyberDefender\cdmyidd.dll" [2009-03-29 3851592]
[HKEY_CLASSES_ROOT\clsid\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}]
[HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{CD24EB02-9831-4838-99D0-726D411B1328}]
[HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-31 68856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"CyberDefender Early Detection Center"="c:\program files\CyberDefender\AntiSpyware\cdasc9.exe" [2009-03-29 664904]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DelayShred"="c:\program files\mcafee.com\shredder\SHRED32.EXE" [2005-07-15 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2005-07-12 1117184]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-08 645328]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"MSKAGENTEXE"="c:\progra~1\mcafee\spamki~1\mskagent.exe" [2005-07-12 110592]
"QuickTime Task"="c:\program files\quicktime\qttask.exe" [2008-11-04 413696]
"CPM53824205"="c:\windows\system32\zazofose.dll" [2009-03-11 84992]
"50b17199"="c:\windows\system32\sazisuhi.dll" [2009-03-11 79872]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-22 148888]
"CyberDefender Early Detection Center"="c:\program files\CyberDefender\AntiSpyware\ISSIntro.exe" [2009-03-29 570696]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\zazofose.dll" [2009-03-11 84992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\zazofose.dll [2009-03-11 84992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\zazofose.dll
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Turbosurf\\PxClient.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\WINDOWS\\system32\\DLA\\DLACTRLW.EXE"=
"c:\\Program Files\\CyberDefender\\AntiSpyware\\cdasc9.exe"=
S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-09-29 210216]
S3 CDAVFS;CDAVFS;c:\windows\system32\drivers\CDAVFS.sys [2009-03-29 67424]
.
Contents of the 'Scheduled Tasks' folder
2009-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]
2009-03-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-09 11:53]
2009-04-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-09 11:53]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
HKLM-Run-hitejabofu - c:\windows\system32\wapetose.dll
SSODL-HardwareDrivers-{2EA7E4D0-622A-479D-A00F-C1529665D5F6} - c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers\hdddriver.dll
SSODL-DriversLoad-{52745E8B-F4E4-4C0C-963F-2CB9675B4F1F} - c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers\egdieexaru.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Lea Family\Application Data\Mozilla\Firefox\Profiles\kdlamel2.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-01 07:29:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-77453670-2768504289-846323367-1006\Software\SecuROM\License information*]
"datasecu"=hex:e7,e9,83,ea,9b,c5,c3,aa,a7,2a,74,c7,37,10,0f,00,2c,ae,c0,cb,24,
1d,4c,b0,e2,34,2e,02,76,2e,a3,32,f0,ba,6b,ff,1a,aa,bf,8b,35,e5,27,28,9c,9c,\
"rkeysecu"=hex:e2,12,2a,1c,07,b2,61,76,3d,83,d3,aa,3e,e6,b1,38
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\rundll32.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MSK\msksrver.exe
c:\progra~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\program files\FinePixViewer\QuickDCF2.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\wdfmgr.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\Java\jre6\bin\jucheck.exe
c:\progra~1\McAfee\MSC\mcupdui.exe
c:\windows\system32\wscript.exe
.
**************************************************************************
.
Completion time: 2009-04-01 7:36:51 - machine was rebooted [Lea Family]
ComboFix-quarantined-files.txt 2009-04-01 12:35:50
Pre-Run: 37,034,020,864 bytes free
Post-Run: 36,888,227,840 bytes free
697 — E O F — 2009-03-29 08:04:11