It just occurred to me that I downloaded a cursor from I believe it was cursor mania a few months ago. Would it be safe to keep it?
Do I keep the logs of Hi Jack This, DDS, gmer, and ComboFix?
Here is the log from ComboFix:
ComboFix 10-08-03.04 - PC-SILVIA 08/04/2010 10:12:33.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.163 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\PC-SILVIA\Application Data\FunWebProducts
c:\documents and settings\PC-SILVIA\Application Data\inst.exe
c:\program files\FunWebProducts
c:\program files\FunWebProducts\ScreenSaver\Cache\0103C4FA
c:\program files\FunWebProducts\ScreenSaver\Cache\0105298B.swf
c:\program files\FunWebProducts\ScreenSaver\Cache\011361EC.jpg
c:\program files\FunWebProducts\ScreenSaver\Cache\files.ini
c:\program files\FunWebProducts\ScreenSaver\Images\01009AFA.urr
c:\program files\FunWebProducts\ScreenSaver\Images\0103C400.urr
c:\program files\FunWebProducts\ScreenSaver\Images\0103F1E6.dat
c:\program files\FunWebProducts\ScreenSaver\Images\0104376A.dat
c:\program files\FunWebProducts\ScreenSaver\Images\010540CC.dat
c:\program files\FunWebProducts\ScreenSaver\Images\0107D40A.dat
c:\program files\FunWebProducts\ScreenSaver\Images\01091C39.dat
c:\program files\FunWebProducts\ScreenSaver\Images\010B076F.dat
c:\program files\FunWebProducts\ScreenSaver\Images\010C90AF.dat
c:\program files\FunWebProducts\ScreenSaver\Images\01137C5A.dat
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\01137C5A.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\Thumbs.db
c:\program files\FunWebProducts\ScreenSaver\Images\wrkparam.lst
c:\program files\FunWebProducts\Shared\011887BC.dat
c:\program files\FunWebProducts\Shared\Cache\AvatarSmallBtn-new.html
c:\program files\FunWebProducts\Shared\Cache\AvatarSmallBtn.html
c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
c:\program files\FunWebProducts\Shared\Cache\FunBuddyIconBtn.html
c:\program files\FunWebProducts\Shared\Cache\MailStampBtn.html
c:\program files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn-new.html
c:\program files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
c:\program files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Cache\00057C9A.bin
c:\program files\MyWebSearch\bar\Cache\0006448D
c:\program files\MyWebSearch\bar\Cache\0006EAEF
c:\program files\MyWebSearch\bar\Cache\0009E226
c:\program files\MyWebSearch\bar\Cache\0009E4B7
c:\program files\MyWebSearch\bar\Cache\000CF17A
c:\program files\MyWebSearch\bar\Cache\0010C778
c:\program files\MyWebSearch\bar\Cache\00112AD6
c:\program files\MyWebSearch\bar\Cache\00145AFF.bin
c:\program files\MyWebSearch\bar\Cache\00145D9F.bin
c:\program files\MyWebSearch\bar\Cache\00145F26.bin
c:\program files\MyWebSearch\bar\Cache\0014609D.bin
c:\program files\MyWebSearch\bar\Cache\00146281.bin
c:\program files\MyWebSearch\bar\Cache\001CB08B.bin
c:\program files\MyWebSearch\bar\Cache\001CBD0E.bin
c:\program files\MyWebSearch\bar\Cache\001CBE66.bin
c:\program files\MyWebSearch\bar\Cache\00502044.bin
c:\program files\MyWebSearch\bar\Cache\005029AA.bin
c:\program files\MyWebSearch\bar\Cache\00503003.bin
c:\program files\MyWebSearch\bar\Cache\00FF1FD4
c:\program files\MyWebSearch\bar\Cache\00FF239C
c:\program files\MyWebSearch\bar\Cache\00FF25BF.bin
c:\program files\MyWebSearch\bar\Cache\00FF288E.bin
c:\program files\MyWebSearch\bar\Cache\00FF2E4B.bin
c:\program files\MyWebSearch\bar\Cache\00FF2FC2.bin
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\History\search2
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Message\COMMON\ask_logo.gif
c:\program files\MyWebSearch\bar\Message\COMMON\autoup.gif
c:\program files\MyWebSearch\bar\Message\COMMON\autoup.htm
c:\program files\MyWebSearch\bar\Message\COMMON\center.htm
c:\program files\MyWebSearch\bar\Message\COMMON\index.htm
c:\program files\MyWebSearch\bar\Message\COMMON\mid_dots.gif
c:\program files\MyWebSearch\bar\Message\COMMON\mws_logo.gif
c:\program files\MyWebSearch\bar\Message\COMMON\protect.htm
c:\program files\MyWebSearch\bar\Message\COMMON\shocked.gif
c:\program files\MyWebSearch\bar\Message\COMMON\stop.gif
c:\program files\MyWebSearch\bar\Message\COMMON\systray.htm
c:\program files\MyWebSearch\bar\Message\COMMON\systrayp.htm
c:\program files\MyWebSearch\bar\Message\COMMON\tp_grad.gif
c:\program files\MyWebSearch\bar\Message\COMMON\warn.gif
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\bar\Settings\setting2.htm
c:\program files\MyWebSearch\bar\Settings\settings.dat
c:\windows\Downloaded Program Files\f3initialsetup1.0.0.15-3.inf
c:\windows\system32\_000003_.tmp.dll
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\_000011_.tmp.dll
c:\windows\system32\Cache
c:\windows\system32\DmarAnti v1.ocx
c:\windows\system32\keylog.txt
c:\windows\system32\win.exe
.
((((((((((((((((((((((((( Files Created from 2010-07-04 to 2010-08-04 )))))))))))))))))))))))))))))))
.
2010-08-02 02:43 . 2010-08-02 02:43 ——– d—–w- c:\program files\Trend Micro
2010-08-02 02:25 . 2010-08-02 02:25 351 —-a-w- c:\documents and settings\PC-SILVIA\KiweeChatbarCleanup.bat
2010-08-02 02:24 . 2010-08-02 02:24 310 —-a-w- c:\documents and settings\PC-SILVIA\UnifiedToolbarCleanup.bat
2010-07-31 02:57 . 2010-07-31 02:57 ——– d—–w- c:\program files\iPod
2010-07-31 02:56 . 2010-07-31 02:59 ——– d—–w- c:\program files\iTunes
2010-07-30 20:59 . 2010-07-30 20:59 ——– d—–w- c:\documents and settings\PC-SILVIA\Local Settings\Application Data\ESET
2010-07-30 20:59 . 2010-07-30 20:59 ——– d—–w- c:\documents and settings\PC-SILVIA\Application Data\ESET
2010-07-30 20:57 . 2010-07-30 20:57 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2010-07-30 20:42 . 2010-07-30 20:42 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2010-07-14 21:17 . 2010-06-14 14:31 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-04 17:04 . 2007-12-05 00:35 ——– d—–w- c:\program files\Common Files\Java
2010-08-04 17:04 . 2007-12-05 00:35 ——– d—–w- c:\program files\Java
2010-08-04 16:14 . 2010-08-01 00:23 79488 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll
2010-08-04 16:14 . 2010-08-01 00:23 152576 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\jre1.6.0_20\lzma.dll
2010-08-04 03:12 . 2010-08-04 03:12 503808 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-7a48822b-n\msvcp71.dll
2010-08-04 03:12 . 2010-08-04 03:12 61440 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-65bd594f-n\decora-sse.dll
2010-08-04 03:12 . 2010-08-04 03:12 499712 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-7a48822b-n\jmc.dll
2010-08-04 03:12 . 2010-08-04 03:12 348160 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-7a48822b-n\msvcr71.dll
2010-08-04 03:12 . 2010-08-04 03:12 12800 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-65bd594f-n\decora-d3d.dll
2010-08-02 03:23 . 2010-08-02 03:23 388096 —-a-r- c:\documents and settings\PC-SILVIA\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-02 02:27 . 2007-12-05 03:54 ——– d—–w- c:\program files\Yahoo!
2010-08-02 02:26 . 2008-04-16 16:17 ——– d—–w- c:\program files\mypoints
2010-08-02 02:22 . 2007-12-05 01:44 ——– d—–w- c:\program files\Google
2010-08-01 16:12 . 2010-06-24 15:42 ——– d—–w- c:\program files\ESET
2010-07-31 16:47 . 2010-05-23 18:38 57344 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-31 16:47 . 2010-05-23 18:29 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-07-31 16:43 . 2010-07-31 16:43 56765 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-31 16:43 . 2010-05-23 18:56 ——– d—–w- c:\program files\DivX
2010-07-31 16:43 . 2010-07-31 16:43 57715 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-07-31 16:42 . 2010-07-31 16:42 54153 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-07-31 16:37 . 2010-07-31 16:37 144696 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-07-31 16:37 . 2010-05-23 19:02 1062184 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-07-31 16:35 . 2010-05-23 18:36 895256 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-07-31 02:57 . 2009-12-24 23:13 ——– d—–w- c:\program files\Common Files\Apple
2010-07-31 02:19 . 2010-07-31 02:19 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-31 02:04 . 2008-01-06 02:17 ——– d—–w- c:\documents and settings\PC-SILVIA\Application Data\DivX
2010-07-17 12:00 . 2010-05-10 03:23 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-06-26 06:08 . 2008-01-06 02:31 ——– d—–w- c:\documents and settings\PC-SILVIA\Application Data\FrostWire
2010-06-26 05:04 . 2010-05-10 03:33 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-06-26 05:03 . 2010-06-26 05:06 53632 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-06-24 16:27 . 2010-06-24 16:27 55256 —-a-w- c:\windows\system32\drivers\epfwtdi.sys
2010-06-24 16:26 . 2010-06-24 16:26 140752 —-a-w- c:\windows\system32\drivers\eamon.sys
2010-06-24 15:35 . 2007-12-05 02:06 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-06-24 15:35 . 2007-12-05 02:07 ——– d—–w- c:\program files\Symantec
2010-06-24 15:35 . 2007-12-05 02:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-06-22 01:18 . 2010-06-22 01:18 ——– d—–w- c:\program files\Bonjour
2010-06-19 19:14 . 2010-05-10 03:30 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-06-19 19:07 . 2007-12-05 03:22 ——– d—–w- c:\program files\EPSON
2010-06-19 18:41 . 2010-02-25 01:44 253241 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sony Online Entertainment\npsoeact.dll
2010-06-19 18:41 . 2010-02-25 01:44 ——– d—–w- c:\documents and settings\PC-SILVIA\Application Data\Sony Online Entertainment
2010-06-19 18:08 . 2010-06-19 18:08 56997 —-a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-06-19 18:08 . 2010-06-19 18:08 53600 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-06-19 18:07 . 2010-06-19 18:07 54128 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-06-19 18:07 . 2010-06-19 18:07 54644 —-a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-06-19 18:06 . 2010-06-19 18:06 54101 —-a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-16 20:57 . 2007-12-05 02:03 29280 —-a-w- c:\documents and settings\PC-SILVIA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-16 04:27 . 2010-06-16 04:27 ——– d—–w- c:\program files\MSECache
2010-06-14 14:31 . 2007-12-04 23:14 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-06 23:42 . 2010-06-06 23:42 ——– d—–w- c:\program files\Secunia
2010-05-28 11:04 . 2010-05-28 11:04 14896 —-a-w- c:\windows\system32\drivers\psi_mf.sys
2010-05-26 02:57 . 2010-05-26 02:57 61440 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-5cc2605c-n\decora-sse.dll
2010-05-26 02:57 . 2010-05-26 02:57 12800 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-5cc2605c-n\decora-d3d.dll
2010-05-26 02:57 . 2010-05-26 02:57 503808 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4507de58-n\msvcp71.dll
2010-05-26 02:57 . 2010-05-26 02:57 499712 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4507de58-n\jmc.dll
2010-05-26 02:57 . 2010-05-26 02:57 348160 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4507de58-n\msvcr71.dll
2010-05-23 19:01 . 2010-05-23 19:01 84040 —-a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-05-23 19:01 . 2010-05-23 19:01 57054 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-05-23 19:01 . 2010-05-23 19:01 54166 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-05-23 19:01 . 2010-05-23 19:01 57532 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-05-23 19:01 . 2010-05-23 19:01 56458 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-05-23 19:01 . 2010-05-23 19:01 54174 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-05-23 19:00 . 2010-05-23 19:00 57409 —-a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-05-23 19:00 . 2010-05-23 19:00 52963 —-a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-05-23 19:00 . 2010-05-23 19:00 54073 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-05-23 19:00 . 2010-05-23 19:00 56969 —-a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-05-21 21:14 . 2009-10-03 00:13 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-05-18 23:35 . 2010-05-18 23:35 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-05-18 23:35 . 2010-05-18 23:35 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-05-10 03:31 . 2010-05-10 03:31 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-05-10 03:24 . 2010-05-10 03:24 503808 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-59cdb1d1-n\msvcp71.dll
2010-05-10 03:24 . 2010-05-10 03:24 499712 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-59cdb1d1-n\jmc.dll
2010-05-10 03:24 . 2010-05-10 03:24 348160 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-59cdb1d1-n\msvcr71.dll
2010-05-10 03:24 . 2010-05-10 03:24 61440 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-542efc4d-n\decora-sse.dll
2010-05-10 03:24 . 2010-05-10 03:24 12800 —-a-w- c:\documents and settings\PC-SILVIA\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-542efc4d-n\decora-d3d.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-27 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-23 7630848]
"nwiz"="nwiz.exe" [2006-08-23 1617920]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-23 86016]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 282624]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-06-24 2202704]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-27 3883856]
c:\documents and settings\PC-SILVIA\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2010-5-28 911920]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-1-5 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 23:39 5244216 —-a-w- c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [4/28/2010 8:17 AM 114984]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [6/24/2010 9:27 AM 810144]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [5/28/2010 4:04 AM 14896]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/29/2010 9:41 AM 135664]
S3 CoachVid;CoachVid;c:\windows\system32\drivers\CoachVid.sys [4/6/2009 8:13 PM 45344]
— Other Services/Drivers In Memory —
*NewlyCreated* - JAVAQUICKSTARTERSERVICE
.
Contents of the 'Scheduled Tasks' folder
2010-06-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]
2010-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 16:41]
2010-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 16:41]
2010-08-04 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 03:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\documents and settings\PC-SILVIA\Application Data\Mozilla\Firefox\Profiles\7d2s70v8.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.imgag.com/?appid=kwtb&component=UnifiedToolbarFF&c=GNKWO50020&sbs=1&sc=&f=web&vernum=3.2&uid=&did={5c271d21-4042-11de-8d46-00188b784626}&q=
FF - plugin: c:\documents and settings\PC-SILVIA\Application Data\Mozilla\Firefox\Profiles\7d2s70v8.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\nppanda3d.dll
FF - plugin: c:\documents and settings\PC-SILVIA\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Sony Online Entertainment\npsoe.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
BHO-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
WebBrowser-{A057A204-BACC-4D26-CEC4-75A487FD6484} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-04 10:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2010-08-04 10:28:25
ComboFix-quarantined-files.txt 2010-08-04 17:28
Pre-Run: 129,200,762,880 bytes free
Post-Run: 129,969,369,088 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - 768E63DBDF59B7D0F708C7D6950D476B