ComboFix 09-11-13.02 - HP_Owner 11/12/2009 11:50.6.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.247 [GMT -8:00]
Running from: c:\documents and settings\HP_Owner\Desktop\ComboFix1.exe
AV: Norton AntiVirus *On-access scanning disabled* (Outdated) {B5510F6F-87E1-47F7-A411-360BC453007C}
FW: Norton Personal Firewall *disabled* {825036E0-9F94-4752-8789-8B92454AF49B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\HP_Owner\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Owner\Local Settings\Temp\IadHide5.dll
c:\program files\System Search Dispatcher\1.3.5.960\ssD.dll
c:\windows\viassary-hp.reg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DRIVER
-------\Legacy_DRIVERDRV
((((((((((((((((((((((((( Files Created from 2009-10-12 to 2009-11-12 )))))))))))))))))))))))))))))))
.
2009-11-12 17:54 . 2009-11-12 17:54 -------- d-----w- c:\program files\ESET
2009-11-10 01:37 . 2006-10-27 03:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2009-11-06 20:04 . 2009-11-06 20:04 152576 ----a-w- c:\documents and settings\HP_Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-06 20:03 . 2009-11-06 20:03 -------- d-----w- c:\program files\SDM20
2009-11-06 19:32 . 2009-11-06 19:49 -------- d-----w- c:\documents and settings\HP_Owner\.SunDownloadManager
2009-11-06 19:26 . 2009-11-06 22:13 -------- d-----w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Google
2009-11-06 19:04 . 2009-02-12 09:35 38208 ----a-w- c:\documents and settings\HP_Owner\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-06 19:01 . 2009-11-06 19:03 -------- d-----w- c:\program files\Google
2009-11-04 18:00 . 2009-11-04 18:00 78888 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-03 19:32 . 2009-11-03 19:32 20480 ----a-w- c:\documents and settings\HP_Owner\Application Data\LimeWire\browser\xulrunner\components\autoconfig.dll
2009-11-03 19:32 . 2009-11-03 19:32 18944 ----a-w- c:\documents and settings\HP_Owner\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.dll
2009-11-03 19:32 . 2009-11-03 19:32 17408 ----a-w- c:\documents and settings\HP_Owner\Application Data\LimeWire\browser\xulrunner\components\auth.dll
2009-11-03 19:32 . 2009-11-03 19:32 20480 ----a-w- c:\documents and settings\HP_Owner\Application Data\LimeWire\browser\xulrunner\IA2Marshal.dll
2009-11-03 19:32 . 2009-11-03 19:32 8192 ----a-w- c:\documents and settings\HP_Owner\Application Data\LimeWire\browser\xulrunner\AccessibleMarshal.dll
2009-11-03 19:31 . 2009-11-04 07:04 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\LimeWire
2009-11-03 19:28 . 2009-11-04 07:15 -------- d-----w- c:\program files\LimeWire
2009-11-03 19:14 . 2009-11-03 19:14 -------- d-----w- c:\documents and settings\All Users\Application Data\175B
2009-10-28 01:08 . 2009-11-06 05:45 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-27 15:53 . 2009-10-27 15:53 -------- d-----w- c:\program files\ERUNT
2009-10-25 23:15 . 2009-10-26 14:47 63 ----a-w- c:\documents and settings\Guest\jagex_runescape_preferences2.dat
2009-10-22 08:18 . 2009-10-22 08:18 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2009-10-17 17:25 . 2009-10-17 17:26 -------- d-----w- c:\program files\iTunes
2009-10-17 17:25 . 2009-10-17 17:26 -------- d-----w- c:\program files\iPod
2009-10-17 17:00 . 2009-10-17 17:00 -------- d-----w- C:\My Downloads
2009-10-17 16:57 . 2009-10-17 16:57 -------- d-----w- c:\documents and settings\All Users\Application Data\D20D
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-12 20:05 . 2009-11-12 20:05 3651 ----a-w- c:\windows\viassary-hp.reg
2009-11-11 16:34 . 2009-07-12 20:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-10 01:41 . 2009-06-20 05:01 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\GetRightToGo
2009-11-06 20:26 . 2009-06-28 01:48 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-06 20:04 . 2009-06-11 14:09 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-06 19:44 . 2004-08-12 02:36 -------- d-----w- c:\program files\Java
2009-11-06 19:11 . 2009-06-13 05:17 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-04 18:03 . 2009-07-03 01:38 -------- d-----w- c:\documents and settings\Guest\Application Data\Apple Computer
2009-11-04 07:15 . 2009-08-02 22:11 -------- d-----w- c:\program files\BearShare Applications
2009-11-03 19:21 . 2009-06-08 18:08 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Apple Computer
2009-10-28 01:53 . 2009-06-20 05:04 78888 ----a-w- c:\documents and settings\HP_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-27 15:28 . 2004-08-12 04:02 -------- d-----w- c:\program files\Microsoft Works
2009-10-26 14:53 . 2009-07-03 01:48 38 ----a-w- c:\documents and settings\Guest\jagex_runescape_preferences.dat
2009-10-23 00:33 . 2004-08-12 04:27 -------- d-----w- c:\program files\Easy Internet signup
2009-10-17 20:59 . 2009-09-15 22:46 45 ----a-w- c:\documents and settings\mrs.beautiful\jagex_runescape_preferences2.dat
2009-10-17 20:59 . 2009-06-17 04:23 38 ----a-w- c:\documents and settings\mrs.beautiful\jagex_runescape_preferences.dat
2009-10-17 17:25 . 2009-09-09 05:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-10-17 17:25 . 2009-09-09 04:19 -------- d-----w- c:\program files\Common Files\Apple
2009-09-26 00:30 . 2009-06-08 18:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-09-19 22:37 . 2009-09-19 22:36 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-19 22:32 . 2009-09-19 22:31 -------- d-----w- c:\program files\QuickTime
2009-09-19 22:25 . 2009-09-19 22:25 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.0.70\SetupAdmin.exe
2009-09-11 14:33 . 2004-08-18 23:10 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 05:57 . 2009-07-11 18:16 78888 ----a-w- c:\documents and settings\mrs.beautiful\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-04 20:45 . 2004-08-18 23:10 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-18 23:13 916480 ------w- c:\windows\system32\wininet.dll
2009-08-29 02:42 . 2009-09-09 04:21 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-29 02:42 . 2009-09-09 04:21 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-26 08:16 . 2004-08-18 23:11 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 06:33 . 2009-08-18 06:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-15 20:13 . 2009-08-15 20:13 593876 -c--a-w- c:\documents and settings\All Users\Application Data\{AAAE891E-DC50-4DD4-A79D-C19DDB94E30E}\OFFLINE\mFileBagIDE.dll\bag\HJSetup.exe
2009-08-15 20:13 . 2009-08-15 20:13 599351 -c--a-w- c:\documents and settings\All Users\Application Data\{AAAE891E-DC50-4DD4-A79D-C19DDB94E30E}\OFFLINE\mFileBagIDE.dll\bag\AdwareSetup.exe
2009-08-15 20:13 . 2009-08-15 20:13 416928 -c--a-w- c:\documents and settings\All Users\Application Data\{AAAE891E-DC50-4DD4-A79D-C19DDB94E30E}\OFFLINE\mFileBagIDE.dll\bag\SSD.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-11-06_16.09.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-12 20:03 . 2009-11-12 20:03 16384 c:\windows\Temp\Perflib_Perfdata_d0.dat
+ 2009-11-10 01:37 . 2006-10-27 03:56 33104 c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
+ 2009-11-10 01:36 . 2006-10-27 03:56 67408 c:\windows\system32\spool\drivers\w32x86\msonpui.dll
+ 2009-11-10 01:36 . 2006-10-27 03:56 67408 c:\windows\system32\spool\drivers\w32x86\3\msonpui.dll
+ 2009-11-06 19:05 . 2009-11-06 19:05 20480 c:\windows\Installer\1b1553.msi
+ 2009-11-06 19:02 . 2009-11-06 19:02 24064 c:\windows\Installer\1b154d.msi
+ 2009-11-10 01:37 . 2009-11-11 16:33 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-11-10 01:37 . 2009-11-11 16:33 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-11-10 01:37 . 2009-11-11 16:33 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-07-12 20:38 . 2009-11-11 16:34 35088 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-07-12 20:38 . 2009-10-27 15:33 35088 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-07-12 20:38 . 2009-10-27 15:33 18704 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-07-12 20:38 . 2009-11-11 16:34 18704 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-07-12 20:38 . 2009-10-27 15:33 20240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-07-12 20:38 . 2009-11-11 16:34 20240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
+ 2006-10-27 04:24 . 2006-10-27 04:24 72504 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ONFILTER.DLL
+ 2006-10-27 04:24 . 2006-10-27 04:24 98632 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ONENOTEM.EXE
+ 2009-11-10 01:36 . 2009-11-10 01:36 17208 c:\windows\assembly\GAC\Microsoft.Office.Interop.OneNote\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OneNote.dll
+ 2009-11-10 01:36 . 2009-11-10 01:36 82784 c:\windows\assembly\GAC\IALoader\1.7.6223.0__31bf3856ad364e35\IALoader.dll
+ 2009-11-10 01:36 . 2006-10-27 03:56 864080 c:\windows\system32\spool\drivers\w32x86\msonpdrv.dll
+ 2009-11-10 01:36 . 2006-10-27 03:56 864080 c:\windows\system32\spool\drivers\w32x86\3\msonpdrv.dll
+ 2009-11-06 20:05 . 2009-11-06 20:04 149280 c:\windows\system32\javaws.exe
+ 2009-11-06 20:05 . 2009-11-06 20:04 145184 c:\windows\system32\javaw.exe
+ 2009-11-06 20:05 . 2009-11-06 20:04 145184 c:\windows\system32\java.exe
- 2004-08-11 18:05 . 2009-10-27 16:52 286904 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-11 18:05 . 2009-11-11 19:06 286904 c:\windows\system32\FNTCACHE.DAT
+ 2009-11-06 20:04 . 2009-11-06 20:04 537600 c:\windows\Installer\53d9c6.msi
+ 2009-11-10 01:37 . 2009-11-11 16:33 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-11-10 01:37 . 2009-11-11 16:33 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-11-10 01:37 . 2009-11-11 16:33 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2009-11-10 01:37 . 2009-11-11 16:33 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2009-07-12 20:38 . 2009-10-27 15:33 888080 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-07-12 20:38 . 2009-11-11 16:34 888080 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-07-12 20:38 . 2009-11-11 16:34 272648 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
- 2009-07-12 20:38 . 2009-10-27 15:33 272648 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-07-12 20:38 . 2009-11-11 16:34 922384 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
- 2009-07-12 20:38 . 2009-10-27 15:33 922384 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-07-12 20:38 . 2009-11-11 16:34 845584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
- 2009-07-12 20:38 . 2009-10-27 15:33 845584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
- 2009-07-12 20:38 . 2009-10-27 15:33 217864 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
+ 2009-07-12 20:38 . 2009-11-11 16:34 217864 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
+ 2006-10-27 04:32 . 2006-10-27 04:32 604000 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ONBTTNIE.DLL
+ 2004-08-18 23:13 . 2009-08-14 12:19 1850112 c:\windows\system32\win32k.sys
+ 2004-08-18 23:13 . 2009-08-14 12:19 1850112 c:\windows\system32\dllcache\win32k.sys
+ 2009-10-16 15:03 . 2009-10-16 15:03 5003776 c:\windows\Installer\45e64.msp
+ 2009-08-18 20:58 . 2009-08-18 20:58 8301056 c:\windows\Installer\45e14.msp
+ 2009-08-18 20:57 . 2009-08-18 20:57 9122304 c:\windows\Installer\45dc4.msp
+ 2008-05-21 08:45 . 2008-05-21 08:45 5246976 c:\windows\Installer\45db0.msp
+ 2009-11-10 01:37 . 2009-11-10 01:37 9613312 c:\windows\Installer\1d9dde0.msi
+ 2009-11-10 01:33 . 2009-11-10 01:33 1640960 c:\windows\Installer\1d9dd93.msi
+ 2009-11-06 19:12 . 2009-11-06 19:12 3940352 c:\windows\Installer\1b1559.msi
+ 2009-11-10 01:37 . 2009-11-11 16:33 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-07-12 20:38 . 2009-11-11 16:34 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-07-12 20:38 . 2009-10-27 15:33 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-07-12 20:38 . 2009-11-11 16:34 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
- 2009-07-12 20:38 . 2009-10-27 15:33 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
+ 2006-10-27 23:03 . 2006-10-27 23:03 6579512 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ONMAIN.DLL
+ 2006-10-27 04:24 . 2006-10-27 04:24 1165112 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ONLIBS.DLL
+ 2006-10-27 23:03 . 2006-10-27 23:03 1018664 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.4518\ONENOTE.EXE
+ 2009-11-10 01:36 . 2009-11-10 01:36 1215328 c:\windows\assembly\GAC\IACore\1.7.6223.0__31bf3856ad364e35\IACore.dll
+ 2009-06-28 02:16 . 2009-11-05 17:36 26768832 c:\windows\system32\MRT.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"SmileyApp"="c:\program files\DoubleD\GamingHarbor Toolbar\4.2.0.21210\stbapp.exe" [2009-08-04 602112]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-06 39408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-08 49152]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-08 659456]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-08-12 180269]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-12-12 71328]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-06 149280]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2004-03-27 49152]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-30 88363]
"AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-07 57344]
c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\
HP Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [2004-8-11 36864]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2009-6-8 36954]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-29 241664]
Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2004-8-11 16423]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-10-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-11-07 c:\windows\Tasks\Norton AntiVirus - Scan my computer - HP_Owner.job
- c:\progra~1\NORTON~1\Navw32.exe [2004-06-05 00:47]
2009-06-11 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-08-12 08:38]
2009-11-12 c:\windows\Tasks\User_Feed_Synchronization-{35D4F142-0FB1-459A-8853-6A369624B037}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
2009-11-11 c:\windows\Tasks\User_Feed_Synchronization-{97DDCCD8-F326-4F44-B654-781F4E7EFC02}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.theprizeday.com/today.php
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=pavilion&pf=desktop
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Add To HP Organize... - c:\progra~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
FF - ProfilePath - c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\h7s74cbt.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-12 12:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2124)
c:\windows\system32\WININET.dll
c:\program files\DoubleD\GamingHarbor Toolbar\4.2.0.21210\stbapp.dll
c:\program files\DoubleD\GamingHarbor Toolbar\4.2.0.21210\ProductInfo.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Norton AntiVirus\navapsvc.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Norton AntiVirus\SAVScan.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\wanmpsvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\HEWLET~1\HPORGA~1\bin\nda.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
c:\program files\DoubleD\GamingHarbor Toolbar\4.2.0.21210\stbappHelper.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
.
**************************************************************************
.
Completion time: 2009-11-12 12:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-12 20:11
ComboFix2.txt 2009-11-06 18:19
ComboFix3.txt 2009-11-06 16:15
Pre-Run: 53,171,572,736 bytes free
Post-Run: 53,458,472,960 bytes free
- - End Of File - - A03FFBEE12A9B2BA21C19D19C70DADEC