ComboFix 09-04-04.01 - Jon 2009-04-08 21:32:38.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3581.2502 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Jon\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\users\Jon\AppData\Local\Temp\systeminit.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-09 to 2009-04-09 )))))))))))))))))))))))))))))))
.
2009-04-08 18:53 . 2009-04-08 18:53 d——– c:\program files\Movie Maker 2.6
2009-04-08 17:44 . 2009-04-08 17:45 327,802,161 –a—— c:\windows\MEMORY.DMP
2009-04-08 17:14 . 2009-04-08 17:35 d——– C:\ComboFix(0)
2009-04-08 17:01 . 2009-04-08 17:01 dr——- c:\program files\Norton Support
2009-04-07 12:33 . 2009-04-07 12:33 d——– c:\users\Jon\AppData\Roaming\Malwarebytes
2009-04-07 12:33 . 2009-04-07 12:33 d——– c:\users\All Users\Malwarebytes
2009-04-07 12:33 . 2009-04-07 12:33 d——– c:\programdata\Malwarebytes
2009-04-07 12:33 . 2009-04-07 12:33 d——– c:\program files\Malwarebytes' Anti-Malware
2009-04-07 12:33 . 2009-04-06 15:32 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2009-04-07 12:33 . 2009-04-06 15:32 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2009-04-07 00:19 . 2008-04-17 12:12 107,368 –a—— c:\windows\System32\GEARAspi.dll
2009-04-07 00:19 . 2009-03-19 16:32 23,400 –a—— c:\windows\System32\drivers\GEARAspiWDM.sys
2009-04-07 00:18 . 2009-04-07 00:19 d——– c:\users\All Users\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-07 00:18 . 2009-04-07 00:19 d——– c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-07 00:18 . 2009-04-07 00:19 d——– c:\program files\iTunes
2009-04-07 00:18 . 2009-04-07 00:18 d——– c:\program files\iPod
2009-04-07 00:16 . 2009-04-07 00:17 d——– c:\program files\QuickTime
2009-04-07 00:08 . 2009-04-07 00:08 d——– c:\program files\Safari
2009-04-07 00:06 . 2009-04-07 00:06 d——– c:\program files\Bonjour
2009-04-06 23:27 . 2009-04-06 23:27 d——– c:\program files\Trend Micro
2009-04-06 23:13 . 2009-04-06 23:13 d——– c:\program files\ERUNT
2009-04-06 22:30 . 2008-06-19 21:14 781,344 –a—— c:\windows\System32\PresentationNative_v0300.dll
2009-04-06 22:30 . 2008-06-19 21:14 622,080 –a—— c:\windows\System32\icardagt.exe
2009-04-06 22:30 . 2008-06-19 21:14 326,160 –a—— c:\windows\System32\PresentationHost.exe
2009-04-06 22:30 . 2008-06-19 21:14 105,016 –a—— c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-04-06 22:30 . 2008-06-19 21:14 97,800 –a—— c:\windows\System32\infocardapi.dll
2009-04-06 22:30 . 2008-06-19 21:14 43,544 –a—— c:\windows\System32\PresentationHostProxy.dll
2009-04-06 22:30 . 2008-06-19 21:14 37,384 –a—— c:\windows\System32\infocardcpl.cpl
2009-04-06 22:30 . 2008-06-19 21:14 11,264 –a—— c:\windows\System32\icardres.dll
2009-04-06 22:20 . 2008-07-27 14:03 282,112 –a—— c:\windows\System32\mscoree.dll
2009-04-06 22:20 . 2008-07-27 14:03 158,720 –a—— c:\windows\System32\mscorier.dll
2009-04-06 22:20 . 2008-07-27 14:03 96,760 –a—— c:\windows\System32\dfshim.dll
2009-04-06 22:20 . 2008-07-27 14:03 83,968 –a—— c:\windows\System32\mscories.dll
2009-04-06 22:20 . 2008-07-27 14:03 41,984 –a—— c:\windows\System32\netfxperf.dll
2009-04-06 00:13 . 2009-04-06 00:13 1,430,456 —hs—- c:\windows\System32\ayunijuh.tmp
2009-03-31 20:03 . 2009-03-31 20:03 d——– c:\program files\Symantec
2009-03-31 20:03 . 2009-03-31 20:05 d——– c:\program files\Common Files\Symantec Shared
2009-03-31 20:03 . 2009-03-31 20:03 124,464 –a—— c:\windows\System32\drivers\SYMEVENT.SYS
2009-03-31 20:03 . 2009-03-31 20:02 25,136 -ra—— c:\windows\System32\drivers\SymIMV.sys
2009-03-31 20:03 . 2009-03-31 20:03 7,386 –a—— c:\windows\System32\drivers\SYMEVENT.CAT
2009-03-31 20:03 . 2009-03-31 20:03 805 –a—— c:\windows\System32\drivers\SYMEVENT.INF
2009-03-31 20:01 . 2009-03-31 20:01 d——– c:\windows\System32\drivers\NIS
2009-03-31 20:01 . 2009-04-01 17:18 d——– c:\users\All Users\Symantec
2009-03-31 20:01 . 2009-04-01 17:18 d——– c:\programdata\Symantec
2009-03-31 20:01 . 2009-03-31 20:02 d——– c:\program files\Norton Internet Security
2009-03-31 19:53 . 2009-03-31 20:01 d——– c:\users\All Users\NortonInstaller
2009-03-31 19:53 . 2009-03-31 20:01 d——– c:\users\All Users\Norton
2009-03-31 19:53 . 2009-03-31 20:01 d——– c:\programdata\NortonInstaller
2009-03-31 19:53 . 2009-03-31 20:01 d——– c:\programdata\Norton
2009-03-31 19:53 . 2009-03-31 19:53 d——– c:\program files\NortonInstaller
2009-03-31 19:49 . 2009-03-31 19:49 d——– c:\users\All Users\Symantec Temporary Files
2009-03-31 19:49 . 2009-03-31 19:49 d——– c:\programdata\Symantec Temporary Files
2009-03-31 18:24 . 2009-02-16 00:10 109,960 –a—— c:\windows\System32\~GLH0028.TMP
2009-03-26 15:23 . 2009-03-26 15:23 1,900,544 –a—— c:\windows\System32\usbaaplrc.dll
2009-03-26 15:23 . 2009-03-26 15:23 36,864 –a—— c:\windows\System32\drivers\usbaapl.sys
2009-03-24 20:25 . 2009-03-24 20:25 131,584 ——— c:\windows\combatfs.exe
2009-03-24 20:19 . 2009-03-24 20:19 d——– c:\users\All Users\DVD Shrink
2009-03-24 20:19 . 2009-03-24 20:19 d——– c:\programdata\DVD Shrink
2009-03-24 20:19 . 2009-03-24 20:19 d——– c:\program files\DVD Shrink
2009-03-19 19:41 . 2009-03-19 20:01 d——– c:\program files\DOSBox-0.72
2009-03-19 19:39 . 2009-03-19 19:39 d–h—– c:\windows\PIF
2009-03-19 19:38 . 2009-03-19 19:39 d——– C:\CCUSA
2009-03-17 17:55 . 2009-03-17 17:55 d——– c:\program files\Microsoft Virtual PC
2009-03-14 19:26 . 2009-03-14 19:26 d——– c:\program files\Common Files\Logitech
2009-03-10 17:58 . 2008-12-15 23:29 8,147,456 –a—— c:\windows\System32\wmploc.DLL
2009-03-10 17:58 . 2009-02-08 23:10 2,033,152 –a—— c:\windows\System32\win32k.sys
2009-03-10 17:58 . 2008-11-27 00:43 268,288 –a—— c:\windows\System32\schannel.dll
2009-03-10 17:58 . 2008-12-16 01:31 7,680 –a—— c:\windows\System32\spwmp.dll
2009-03-10 17:58 . 2008-12-16 01:31 4,096 –a—— c:\windows\System32\msdxm.ocx
2009-03-10 17:58 . 2008-12-16 01:31 4,096 –a—— c:\windows\System32\dxmasf.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-09 01:43 ——— d—–w c:\program files\SpywareGuard
2009-04-08 21:47 ——— d—–w c:\programdata\Google Updater
2009-04-07 19:12 ——— d—–w c:\programdata\Spybot - Search & Destroy
2009-04-07 04:18 ——— d—–w c:\program files\Common Files\Apple
2009-03-31 22:26 ——— d—–w c:\program files\AskBarDis
2009-03-29 21:56 27,145 —-a-w c:\users\Jon\AppData\Roaming\nvModes.dat
2009-03-26 16:18 31,693,590 —-a-w c:\windows\Internet Logs\vsmon_on_demand_thread_2009_03_26_00_26_26_full.dmp.zip
2009-03-25 21:06 2,821,617 —-a-w c:\windows\Internet Logs\tvDebug.Zip
2009-03-14 23:26 ——— d—–w c:\program files\Logitech
2009-03-11 22:51 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-11 21:51 ——— d—–w c:\program files\Windows Mail
2009-03-10 23:59 ——— d—–w c:\users\Jon\AppData\Roaming\dvdcss
2009-02-17 23:26 ——— d—–w c:\users\Jon\AppData\Roaming\Apple Computer
2009-02-17 23:25 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-02-16 04:11 293,528 —-a-w c:\windows\system32\drivers\vsdatant.sys
2009-02-14 02:25 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-02-12 17:39 ——— d—–w c:\program files\CCleaner
2009-02-12 16:02 64,160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-02-12 16:02 15,688 —-a-w c:\windows\System32\lsdelete.exe
2009-02-12 16:02 ——— d—–w c:\programdata\Lavasoft
2009-02-12 16:00 ——— dc-h–w c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-12 16:00 ——— d—–w c:\program files\Lavasoft
2009-02-12 15:58 ——— d—–w c:\program files\Google
2009-01-18 23:28 410,984 —-a-w c:\windows\System32\deploytk.dll
2009-01-18 05:56 174 –sha-w c:\program files\desktop.ini
2009-01-18 05:38 82,432 —-a-w c:\windows\System32\axaltocm.dll
2009-01-18 05:38 101,888 —-a-w c:\windows\System32\ifxcardm.dll
2009-01-17 03:00 269,312 —-a-w c:\windows\System32\es.dll
2009-01-16 05:40 61,440 —-a-w c:\windows\System32\winipsec.dll
2009-01-16 05:40 361,984 —-a-w c:\windows\System32\IPSECSVC.DLL
2009-01-16 05:40 28,672 —-a-w c:\windows\System32\FwRemoteSvr.dll
2009-01-16 05:40 272,896 —-a-w c:\windows\System32\polstore.dll
2009-01-16 05:38 94,720 —-a-w c:\windows\System32\PortableDeviceClassExtension.dll
2009-01-16 05:38 241,152 —-a-w c:\windows\System32\PortableDeviceApi.dll
2009-01-16 05:38 160,768 —-a-w c:\windows\System32\PortableDeviceTypes.dll
2009-01-16 05:32 296,960 —-a-w c:\windows\System32\gdi32.dll
2009-01-16 05:30 541,696 —-a-w c:\windows\AppPatch\AcLayers.dll
2009-01-16 05:30 52,736 —-a-w c:\windows\AppPatch\iebrshim.dll
2009-01-16 05:30 460,288 —-a-w c:\windows\AppPatch\AcSpecfc.dll
2009-01-16 05:30 4,240,384 —-a-w c:\windows\System32\GameUXLegacyGDFs.dll
2009-01-16 05:30 28,672 —-a-w c:\windows\System32\Apphlpdm.dll
2009-01-16 05:30 2,560 —-a-w c:\windows\AppPatch\AcRes.dll
2009-01-16 05:30 2,154,496 —-a-w c:\windows\AppPatch\AcGenral.dll
2009-01-16 05:30 173,056 —-a-w c:\windows\AppPatch\AcXtrnal.dll
2009-01-16 05:30 1,695,744 —-a-w c:\windows\System32\gameux.dll
2009-01-16 05:29 303,616 —-a-w c:\windows\System32\wmpeffects.dll
2009-01-16 05:28 2,048 —-a-w c:\windows\System32\msxml3r.dll
2009-01-16 05:28 1,191,936 —-a-w c:\windows\System32\msxml3.dll
2009-01-16 05:25 2,048 —-a-w c:\windows\System32\tzres.dll
2009-01-16 05:22 2,927,104 —-a-w c:\windows\explorer.exe
2009-01-16 05:16 988,216 —-a-w c:\windows\System32\winload.exe
2009-01-16 05:16 927,288 —-a-w c:\windows\System32\winresume.exe
2009-01-16 05:16 615,992 —-a-w c:\windows\System32\ci.dll
2009-01-16 05:16 6,656 —-a-w c:\windows\System32\kbd106n.dll
2009-01-16 05:16 46,592 —-a-w c:\windows\System32\setbcdlocale.dll
2009-01-16 05:16 40,960 —-a-w c:\windows\System32\srclient.dll
2009-01-16 05:16 378,368 —-a-w c:\windows\System32\srcore.dll
2009-01-16 05:16 318,464 —-a-w c:\windows\System32\rstrui.exe
2009-01-16 05:16 19,000 —-a-w c:\windows\System32\kd1394.dll
2009-01-16 05:16 14,848 —-a-w c:\windows\System32\srdelayed.exe
2009-01-16 03:32 712,704 —-a-w c:\windows\System32\WindowsCodecs.dll
2009-01-16 03:32 425,472 —-a-w c:\windows\System32\PhotoMetadataHandler.dll
2009-01-16 03:32 347,136 —-a-w c:\windows\System32\WindowsCodecsExt.dll
2009-01-16 03:30 443,392 —-a-w c:\windows\System32\win32spl.dll
2009-01-16 03:30 37,888 —-a-w c:\windows\System32\printcom.dll
2009-01-16 03:30 14,848 —-a-w c:\windows\System32\wshrm.dll
2009-01-16 03:28 996,352 —-a-w c:\windows\System32\WMNetMgr.dll
2009-01-16 03:28 98,816 —-a-w c:\windows\System32\mfps.dll
2009-01-16 03:28 94,720 —-a-w c:\windows\System32\logagent.exe
2009-01-16 03:28 53,248 —-a-w c:\windows\System32\rrinstaller.exe
2009-01-16 03:28 24,576 —-a-w c:\windows\System32\mfpmp.exe
2009-01-16 03:28 2,868,736 —-a-w c:\windows\System32\mf.dll
2009-01-16 03:28 2,048 —-a-w c:\windows\System32\mferror.dll
2009-01-16 03:27 84,480 —-a-w c:\windows\System32\INETRES.dll
2009-01-16 03:27 738,304 —-a-w c:\windows\System32\inetcomm.dll
2009-01-16 03:27 1,645,568 —-a-w c:\windows\System32\connect.dll
2009-01-16 03:26 1,314,816 —-a-w c:\windows\System32\quartz.dll
2009-01-16 03:25 3,601,464 —-a-w c:\windows\System32\ntkrnlpa.exe
2009-01-16 03:25 3,549,240 —-a-w c:\windows\System32\ntoskrnl.exe
2009-01-16 03:24 2,048 —-a-w c:\windows\System32\msxml6r.dll
2009-01-16 03:24 1,334,272 —-a-w c:\windows\System32\msxml6.dll
2009-01-16 02:14 83,456 —-a-w c:\windows\System32\wudriver.dll
2009-01-16 02:14 561,688 —-a-w c:\windows\System32\wuapi.dll
2009-01-16 02:14 51,224 —-a-w c:\windows\System32\wuauclt.exe
2009-01-16 02:14 43,544 —-a-w c:\windows\System32\wups2.dll
2009-01-16 02:14 34,328 —-a-w c:\windows\System32\wups.dll
2009-01-16 02:14 31,232 —-a-w c:\windows\System32\wuapp.exe
2009-01-16 02:14 162,064 —-a-w c:\windows\System32\wuwebv.dll
2009-01-16 02:14 1,809,944 —-a-w c:\windows\System32\wuaueng.dll
2009-01-16 02:14 1,524,736 —-a-w c:\windows\System32\wucltux.dll
2009-01-15 06:11 827,392 —-a-w c:\windows\System32\wininet.dll
2009-01-13 23:13 244,232 —-a-w c:\windows\System32\WmJoyFrc.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-04-08_18.29.59.86 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-08 22:54:03 3,274,752 —-a-r c:\windows\Installer\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}\MOVIEMK.exe
- 2009-04-08 22:23:58 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-04-09 01:25:40 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-04-08 22:23:58 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-04-09 01:25:40 2,048 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-04-08 22:25:45 151,552 —-a-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-04-09 01:27:11 151,552 —-a-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
- 2009-04-08 22:25:44 151,552 —-a-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-04-09 01:27:05 151,552 —-a-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
- 2009-04-08 22:24:00 49,152 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-04-09 01:25:43 49,152 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-04-08 22:24:00 311,296 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-04-09 01:25:43 311,296 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-04-08 22:24:00 49,152 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-04-09 01:25:43 49,152 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-04-08 21:50:29 102,910 —-a-w c:\windows\System32\perfc009.dat
+ 2009-04-09 01:31:36 102,910 —-a-w c:\windows\System32\perfc009.dat
- 2009-04-08 21:50:29 600,264 —-a-w c:\windows\System32\perfh009.dat
+ 2009-04-09 01:31:36 600,264 —-a-w c:\windows\System32\perfh009.dat
- 2009-04-08 21:46:29 10,492 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3952132311-1714827031-4215795686-1000_UserData.bin
+ 2009-04-09 01:27:31 10,890 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3952132311-1714827031-4215795686-1000_UserData.bin
- 2009-04-08 21:46:29 63,160 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-04-09 01:27:31 63,478 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-04-07 19:18:55 35,250 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-04-09 01:27:30 35,250 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-10-16 18:22 333192 –a—— c:\program files\AskBarDis\bar\bin\askBar1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar1.dll" [2008-10-16 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar1.dll" [2008-10-16 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-03-16 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-08-07 1548288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-18 136600]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-13 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-13 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-13 81920]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2007-09-13 81920]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-12 509784]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2008-02-15 405504]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2009-01-21 92168]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [BU]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe]
c:\users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-01-16 809488]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2007-09-07 1180952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{61CC2CBC-37DF-4D5C-99A9-EFB9D38A761F}"= UDP:c:\windows\System32\BCMWLTRY.EXE:bcmwltry
"{4B05BE9C-3469-4ACA-9EEE-7D7EC4CCB0DE}"= TCP:c:\windows\System32\BCMWLTRY.EXE:bcmwltry
"{D984C0F1-BEC5-4FDD-A249-609C481B14F7}"= UDP:c:\windows\explorer.exe:Explorer
"{D6BE0FAF-2C33-44D2-B6D6-4076006AB9FD}"= TCP:c:\windows\explorer.exe:Explorer
"{A7403CB3-3C2C-4EB6-8E65-F3B736A65C7D}"= UDP:c:\program files\Internet Explorer\iexplore.exe:iexplore
"{BC667654-2874-4781-8155-C6CEDAF455B2}"= TCP:c:\program files\Internet Explorer\iexplore.exe:iexplore
"{5B3D8633-CE16-4164-945E-B2B19068ECCB}"= UDP:c:\windows\System32\TKL0Dq18.exe:TKL0Dq18
"{24F27D91-B6D8-4B4E-A221-A1DAB8BCFD75}"= TCP:c:\windows\System32\TKL0Dq18.exe:TKL0Dq18
"{3ECE1C9A-5046-4267-AC5D-C4859A24C9F9}"= UDP:c:\windows\System32\winlogon.exe:winlogon
"{0361CFC8-23F3-4281-8C48-6C8C3B2FB61E}"= TCP:c:\windows\System32\winlogon.exe:winlogon
"{A6E2680A-4BAB-4593-B9F2-E74E5B912507}"= UDP:c:\windows\System32\wininit.exe:wininit
"{31A51577-3A75-4040-BE14-C9745D6B1709}"= TCP:c:\windows\System32\wininit.exe:wininit
"{64C09E2B-2963-4CD7-84C9-C2E23FB405F4}"= UDP:c:\windows\System32\dwm.exe:Dwm
"{7F241BD0-946C-488B-83F9-AF0E827F8060}"= TCP:c:\windows\System32\dwm.exe:Dwm
"{EBD600B2-34F0-44F9-99A1-857324C67DE4}"= UDP:c:\program files\Google\Google Earth\googleearth.exe:googleearth
"{A82A2C39-9090-4027-98F5-C6B1D0A69C82}"= TCP:c:\program files\Google\Google Earth\googleearth.exe:googleearth
"{2362CD5D-C082-4759-B35E-E85A1BBFAE94}"= UDP:c:\windows\System32\LogonUI.exe:LogonUI
"{2E8ADCBB-ED0C-46A2-8E62-9695E1409F62}"= TCP:c:\windows\System32\LogonUI.exe:LogonUI
"{E844669B-18D6-40DB-8E0D-048F4A649A57}"= UDP:c:\windows\System32\lsass.exe:lsass
"{100239A4-1B4A-4CAB-A910-DED16BBF49A3}"= TCP:c:\windows\System32\lsass.exe:lsass
"{87DBD8CE-4A91-4C8C-8E7F-099B0287E34E}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{AAF139A8-80EC-4B8C-B4F0-19FCC22ABE7A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3BF2B11A-B583-45F6-8340-854C335E3FBC}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{6CE23A8C-3114-4790-B13D-521EC5B639B8}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [2009-02-12 64160]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\NIS\1005000.087\SymEFA.sys [2009-03-31 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\NIS\1005000.087\BHDrvx86.sys [2009-03-31 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NIS\1005000.087\cchpx86.sys [2009-03-31 482352]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090331.007\IDSvix86.sys [2009-04-02 292912]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [2009-01-15 73728]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [2009-01-16 464264]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [2009-03-31 115560]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-02-13 1153368]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-31 101936]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [2007-10-10 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [2007-03-05 7424]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\NIS\1005000.087\symndisv.sys [2009-03-31 39984]
S2 gupdate1c98a0acf968bae;Google Update Service (gupdate1c98a0acf968bae);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
.
Contents of the 'Scheduled Tasks' folder
2009-02-12 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-12 12:01]
2009-04-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-23 20:37]
2009-04-09 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 12:32]
2009-03-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3952132311-1714827031-4215795686-1000.job
- c:\users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe [2009-03-16 19:39]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\nojrflrp.default\
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-08 21:34:45
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(5976)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
Completion time: 2009-04-08 21:37:05
ComboFix-quarantined-files.txt 2009-04-09 01:37:03
ComboFix2.txt 2009-04-08 22:31:57
ComboFix3.txt 2009-04-08 02:02:34
ComboFix4.txt 2009-04-07 19:37:06
Pre-Run: 258,366,746,624 bytes free
Post-Run: 258,333,708,288 bytes free
340 — E O F — 2009-04-07 02:37:42
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:38:52 PM, on 4/8/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jon\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Google Update Service (gupdate1c98a0acf968bae) (gupdate1c98a0acf968bae) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
–
End of file - 7173 bytes