SLOW GO
Topic Starter
The computer is behaving fine at the moment. Regular CPU usage. Was there anything of concern in the first logs I posted, or is their any in the following logs. This is the result I got when doing as you directed.
Sorry for the slow reply. This is my off day now. Thanks for your time and attention.
ComboFix 10-02-24.01 - Dan 02/24/2010 20:11:29.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2039.1024 [GMT -6:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\setup.exe
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\EventSystem.log
c:\windows\Imgtask.exe
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\AutoRun.inf
c:\windows\system32\COMCTL32.OCA
c:\windows\system32\SIntf16.dll
c:\windows\system32\twain_32.dll
.
((((((((((((((((((((((((( Files Created from 2010-01-25 to 2010-02-25 )))))))))))))))))))))))))))))))
.
2010-02-25 02:08 . 2010-02-25 02:08 ——– d—–w- c:\program files\iPod
2010-02-25 02:08 . 2010-02-25 02:09 ——– d—–w- c:\program files\iTunes
2010-02-25 00:48 . 2010-02-25 00:48 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-24 09:00 . 2010-02-24 09:00 ——– d—–w- c:\windows\LastGood
2010-02-19 18:05 . 2010-02-19 18:05 ——– d—–w- c:\program files\2BrightSparks
2010-02-19 17:18 . 2010-02-19 17:18 ——– d—–w- c:\documents and settings\Dan\Application Data\Malwarebytes
2010-02-19 17:18 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-19 17:18 . 2010-02-19 17:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-19 17:18 . 2010-02-19 17:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-19 17:18 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-19 16:49 . 2010-02-19 16:50 ——– d—–w- c:\program files\ERUNT
2010-02-19 16:19 . 2010-02-19 16:19 ——– d—–w- c:\program files\Trend Micro
2010-02-18 02:44 . 2010-02-18 02:44 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2010-02-18 02:44 . 2010-02-18 02:44 ——– d—–w- c:\program files\DVD Shrink
2010-02-18 02:42 . 2006-09-01 21:53 110592 —-a-w- c:\documents and settings\Dan\Application Data\U3\temp\cleanup.exe
2010-02-18 02:34 . 2006-10-04 20:21 3072000 —ha-w- c:\documents and settings\Dan\Application Data\U3\temp\Launchpad Removal.exe
2010-02-18 02:34 . 2010-02-18 02:42 ——– d—–w- c:\documents and settings\Dan\Application Data\U3
2010-02-13 17:39 . 2010-02-13 17:39 ——– d—–w- c:\program files\Lavalys
2010-02-12 01:20 . 2010-02-12 01:20 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-02-07 15:26 . 2010-02-07 15:26 ——– d—–w- c:\documents and settings\Mom\Application Data\OpenOffice.org
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-25 02:08 . 2009-12-04 04:02 ——– d—–w- c:\program files\Common Files\Apple
2010-02-24 17:44 . 2008-12-21 19:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-02-23 12:14 . 2009-10-07 03:16 1 —-a-w- c:\documents and settings\Dan\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-02-23 05:15 . 2005-12-25 22:21 ——– d—–w- c:\program files\Common Files\Java
2010-02-23 05:14 . 2005-12-25 22:26 ——– d—–w- c:\program files\Java
2010-02-20 18:25 . 2005-12-24 22:38 ——– d—–w- c:\program files\Common Files\Adobe
2010-02-01 18:28 . 2007-04-12 22:54 ——– d—–w- c:\program files\Google
2010-01-25 02:19 . 2005-12-24 22:50 ——– d—–w- c:\documents and settings\Dan\Application Data\Apple Computer
2010-01-21 00:55 . 2009-03-22 13:53 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-05 02:31 . 2010-01-05 02:18 ——– d—–w- c:\program files\TweakNow RegCleaner
2010-01-05 02:18 . 2010-01-05 02:18 ——– d—–w- c:\documents and settings\Dan\Application Data\TweakNow RegCleaner
2010-01-05 01:38 . 2010-01-05 01:38 ——– d—–w- c:\program files\TweakNow PowerPack 2009
2010-01-05 01:38 . 2010-01-05 01:38 ——– d—–w- c:\documents and settings\Dan\Application Data\TweakNow PowerPack 2009
2009-12-31 16:50 . 2001-08-18 12:00 353792 ——w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-01-08 21:23 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-17 23:14 . 2008-12-04 03:53 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-16 18:43 . 2003-01-01 09:12 343040 ——w- c:\windows\system32\mspaint.exe
2009-12-14 19:15 . 2009-12-14 19:15 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-14 07:08 . 2001-08-18 12:00 33280 ——w- c:\windows\system32\csrsrv.dll
2009-12-11 03:42 . 2009-12-11 03:42 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-12-08 19:27 . 2001-08-18 12:00 2189184 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2001-08-17 13:48 2066048 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2001-08-18 12:00 455424 ——w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-03 19:47 . 2003-03-18 19:14 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-12-03 19:47 . 2003-02-21 11:42 348160 —-a-w- c:\windows\system32\msvcr71.dll
2009-11-27 17:11 . 2001-08-18 12:00 1291776 ——w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2001-08-17 22:36 17920 ——w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2001-08-18 12:00 28672 ——w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 ——w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2001-08-18 12:00 84992 ——w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2001-08-18 12:00 11264 ——w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2001-08-17 22:36 48128 ——w- c:\windows\system32\iyuv_32.dll
2007-04-12 22:54 . 2007-04-12 22:54 774144 -c–a-w- c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 77824]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-11-02 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-11-02 126976]
"Omnipage"="c:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-02-21 49152]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]
"WD Button Manager"="WDBtnMgr.exe" [2008-08-28 331776]
"RAM Idle Professional"="c:\program files\TweakNow PowerPack 2009\Module32\RAM2_XP.exe" [2009-11-14 27392]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-03 198160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-16 141608]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2007-3-3 221247]
ESET NOD32 Antivirus.lnk - c:\program files\ESET\ESET NOD32 Antivirus\egui.exe [2007-12-21 1443072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-12 03:34 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-02-16 00:07 141608 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2008-12-09 10:12 234856 —-a-w- c:\program files\TomTom HOME 2\HOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbLauncher.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbSetupWizard.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbControlPanel.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [12/21/2007 8:21 AM 33800]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12/21/2007 8:21 AM 468224]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [3/22/2009 7:52 AM 55152]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [4/8/2009 4:38 AM 92008]
S2 gupdate1c9639fc0e640b8;Google Update Service (gupdate1c9639fc0e640b8);c:\program files\Google\Update\GoogleUpdate.exe [12/21/2008 1:10 PM 133104]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 5:08 PM 533360]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys –> d:\NTGLM7X.sys [?]
— Other Services/Drivers In Memory —
*NewlyCreated* - IPOD_SERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
2010-02-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2010-02-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-21 19:03]
2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-21 15:24]
2010-02-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-21 15:24]
2010-02-25 c:\windows\Tasks\Orb Index when idle.job
- c:\program files\Orb Networks\Orb\bin\OrbLauncher.exe [2009-10-07 23:28]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = http=192.168.0.1:87
uInternet Settings,ProxyOverride = www.direcwaysupport.com;192.168.0.*;;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Mom\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: astroempires.com\alpha
Trusted Zone: citimortgage.com\www
Trusted Zone: express-scripts.com\member
Trusted Zone: fidelity.com\workplaceservices100
Trusted Zone: runescape.com\www
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/mygarmin/m/GarminAxControl.CAB
DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} - hxxp://aolsvc.aol.com/onlinegames/free-trial-doggie-dash/DoggieDash.1.0.0.6.cab
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-big-island-blends/gamehouseplayer.cab
DPF: {D441AB53-A39C-42AE-AB79-3C05B7298F34} - hxxp://aolsvc.aol.com/onlinegames/free-trial-astro-avenger-ii/AstroAvenger2Loader.cab
FF - ProfilePath - c:\documents and settings\Dan\Application Data\Mozilla\Firefox\Profiles\ha1rsfrv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1441.4352\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-24 20:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RAM Idle Professional = c:\program files\TweakNow PowerPack 2009\Module32\RAM2_XP.exe?m???????>?"c:\program files\TweakNow PowerPack 2009\Module32
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-02-24 20:17:52
ComboFix-quarantined-files.txt 2010-02-25 02:17
Pre-Run: 14,738,321,408 bytes free
Post-Run: 14,937,956,352 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - A08719F5A80E9A980C6B67517B62F1C8
Sorry for the slow reply. This is my off day now. Thanks for your time and attention.
ComboFix 10-02-24.01 - Dan 02/24/2010 20:11:29.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2039.1024 [GMT -6:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\setup.exe
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\EventSystem.log
c:\windows\Imgtask.exe
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\AutoRun.inf
c:\windows\system32\COMCTL32.OCA
c:\windows\system32\SIntf16.dll
c:\windows\system32\twain_32.dll
.
((((((((((((((((((((((((( Files Created from 2010-01-25 to 2010-02-25 )))))))))))))))))))))))))))))))
.
2010-02-25 02:08 . 2010-02-25 02:08 ——– d—–w- c:\program files\iPod
2010-02-25 02:08 . 2010-02-25 02:09 ——– d—–w- c:\program files\iTunes
2010-02-25 00:48 . 2010-02-25 00:48 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-24 09:00 . 2010-02-24 09:00 ——– d—–w- c:\windows\LastGood
2010-02-19 18:05 . 2010-02-19 18:05 ——– d—–w- c:\program files\2BrightSparks
2010-02-19 17:18 . 2010-02-19 17:18 ——– d—–w- c:\documents and settings\Dan\Application Data\Malwarebytes
2010-02-19 17:18 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-19 17:18 . 2010-02-19 17:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-19 17:18 . 2010-02-19 17:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-19 17:18 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-19 16:49 . 2010-02-19 16:50 ——– d—–w- c:\program files\ERUNT
2010-02-19 16:19 . 2010-02-19 16:19 ——– d—–w- c:\program files\Trend Micro
2010-02-18 02:44 . 2010-02-18 02:44 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2010-02-18 02:44 . 2010-02-18 02:44 ——– d—–w- c:\program files\DVD Shrink
2010-02-18 02:42 . 2006-09-01 21:53 110592 —-a-w- c:\documents and settings\Dan\Application Data\U3\temp\cleanup.exe
2010-02-18 02:34 . 2006-10-04 20:21 3072000 —ha-w- c:\documents and settings\Dan\Application Data\U3\temp\Launchpad Removal.exe
2010-02-18 02:34 . 2010-02-18 02:42 ——– d—–w- c:\documents and settings\Dan\Application Data\U3
2010-02-13 17:39 . 2010-02-13 17:39 ——– d—–w- c:\program files\Lavalys
2010-02-12 01:20 . 2010-02-12 01:20 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-02-07 15:26 . 2010-02-07 15:26 ——– d—–w- c:\documents and settings\Mom\Application Data\OpenOffice.org
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-25 02:08 . 2009-12-04 04:02 ——– d—–w- c:\program files\Common Files\Apple
2010-02-24 17:44 . 2008-12-21 19:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-02-23 12:14 . 2009-10-07 03:16 1 —-a-w- c:\documents and settings\Dan\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-02-23 05:15 . 2005-12-25 22:21 ——– d—–w- c:\program files\Common Files\Java
2010-02-23 05:14 . 2005-12-25 22:26 ——– d—–w- c:\program files\Java
2010-02-20 18:25 . 2005-12-24 22:38 ——– d—–w- c:\program files\Common Files\Adobe
2010-02-01 18:28 . 2007-04-12 22:54 ——– d—–w- c:\program files\Google
2010-01-25 02:19 . 2005-12-24 22:50 ——– d—–w- c:\documents and settings\Dan\Application Data\Apple Computer
2010-01-21 00:55 . 2009-03-22 13:53 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-05 02:31 . 2010-01-05 02:18 ——– d—–w- c:\program files\TweakNow RegCleaner
2010-01-05 02:18 . 2010-01-05 02:18 ——– d—–w- c:\documents and settings\Dan\Application Data\TweakNow RegCleaner
2010-01-05 01:38 . 2010-01-05 01:38 ——– d—–w- c:\program files\TweakNow PowerPack 2009
2010-01-05 01:38 . 2010-01-05 01:38 ——– d—–w- c:\documents and settings\Dan\Application Data\TweakNow PowerPack 2009
2009-12-31 16:50 . 2001-08-18 12:00 353792 ——w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-01-08 21:23 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-17 23:14 . 2008-12-04 03:53 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-16 18:43 . 2003-01-01 09:12 343040 ——w- c:\windows\system32\mspaint.exe
2009-12-14 19:15 . 2009-12-14 19:15 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-14 07:08 . 2001-08-18 12:00 33280 ——w- c:\windows\system32\csrsrv.dll
2009-12-11 03:42 . 2009-12-11 03:42 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-12-08 19:27 . 2001-08-18 12:00 2189184 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2001-08-17 13:48 2066048 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2001-08-18 12:00 455424 ——w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-03 19:47 . 2003-03-18 19:14 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-12-03 19:47 . 2003-02-21 11:42 348160 —-a-w- c:\windows\system32\msvcr71.dll
2009-11-27 17:11 . 2001-08-18 12:00 1291776 ——w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2001-08-17 22:36 17920 ——w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2001-08-18 12:00 28672 ——w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 ——w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2001-08-18 12:00 84992 ——w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2001-08-18 12:00 11264 ——w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2001-08-17 22:36 48128 ——w- c:\windows\system32\iyuv_32.dll
2007-04-12 22:54 . 2007-04-12 22:54 774144 -c–a-w- c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 77824]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-11-02 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-11-02 126976]
"Omnipage"="c:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-02-21 49152]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]
"WD Button Manager"="WDBtnMgr.exe" [2008-08-28 331776]
"RAM Idle Professional"="c:\program files\TweakNow PowerPack 2009\Module32\RAM2_XP.exe" [2009-11-14 27392]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-03 198160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-16 141608]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2007-3-3 221247]
ESET NOD32 Antivirus.lnk - c:\program files\ESET\ESET NOD32 Antivirus\egui.exe [2007-12-21 1443072]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-12 03:34 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-02-16 00:07 141608 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2008-12-09 10:12 234856 —-a-w- c:\program files\TomTom HOME 2\HOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbLauncher.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbSetupWizard.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbControlPanel.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [12/21/2007 8:21 AM 33800]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12/21/2007 8:21 AM 468224]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [3/22/2009 7:52 AM 55152]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [4/8/2009 4:38 AM 92008]
S2 gupdate1c9639fc0e640b8;Google Update Service (gupdate1c9639fc0e640b8);c:\program files\Google\Update\GoogleUpdate.exe [12/21/2008 1:10 PM 133104]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 5:08 PM 533360]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys –> d:\NTGLM7X.sys [?]
— Other Services/Drivers In Memory —
*NewlyCreated* - IPOD_SERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
2010-02-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2010-02-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-21 19:03]
2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-21 15:24]
2010-02-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-21 15:24]
2010-02-25 c:\windows\Tasks\Orb Index when idle.job
- c:\program files\Orb Networks\Orb\bin\OrbLauncher.exe [2009-10-07 23:28]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = http=192.168.0.1:87
uInternet Settings,ProxyOverride = www.direcwaysupport.com;192.168.0.*;;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Mom\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: astroempires.com\alpha
Trusted Zone: citimortgage.com\www
Trusted Zone: express-scripts.com\member
Trusted Zone: fidelity.com\workplaceservices100
Trusted Zone: runescape.com\www
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/mygarmin/m/GarminAxControl.CAB
DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} - hxxp://aolsvc.aol.com/onlinegames/free-trial-doggie-dash/DoggieDash.1.0.0.6.cab
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-big-island-blends/gamehouseplayer.cab
DPF: {D441AB53-A39C-42AE-AB79-3C05B7298F34} - hxxp://aolsvc.aol.com/onlinegames/free-trial-astro-avenger-ii/AstroAvenger2Loader.cab
FF - ProfilePath - c:\documents and settings\Dan\Application Data\Mozilla\Firefox\Profiles\ha1rsfrv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1441.4352\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-24 20:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
RAM Idle Professional = c:\program files\TweakNow PowerPack 2009\Module32\RAM2_XP.exe?m???????>?"c:\program files\TweakNow PowerPack 2009\Module32
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-02-24 20:17:52
ComboFix-quarantined-files.txt 2010-02-25 02:17
Pre-Run: 14,738,321,408 bytes free
Post-Run: 14,937,956,352 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - A08719F5A80E9A980C6B67517B62F1C8