Hello, Here is the combofix log. Thanks
ComboFix 10-08-09.03 - Owner 08/10/2010 14:09:16.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.507 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\GoToAssistDownloadHelper.exe
c:\windows\system32\CBUTTON.OCX
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_NPF
——-\Legacy_OSPPSVC
——-\Service_NPF
——-\Service_osppsvc
((((((((((((((((((((((((( Files Created from 2010-07-10 to 2010-08-10 )))))))))))))))))))))))))))))))
.
2010-08-10 05:36 . 2010-08-10 05:36 17 —-a-w- c:\windows\system32\shortcut_ex.dat
2010-08-09 21:20 . 2010-08-09 21:21 503808 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4ff360e5-n\msvcp71.dll
2010-08-09 21:20 . 2010-08-09 21:20 499712 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4ff360e5-n\jmc.dll
2010-08-09 21:20 . 2010-08-09 21:20 12800 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-2cd5803d-n\decora-d3d.dll
2010-08-09 21:20 . 2010-08-09 21:20 61440 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-2cd5803d-n\decora-sse.dll
2010-08-09 21:20 . 2010-08-09 21:20 348160 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-4ff360e5-n\msvcr71.dll
2010-08-05 14:04 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-05 14:04 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-05 14:04 . 2010-08-05 14:04 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-30 15:14 . 2010-07-06 11:52 30016 —-a-w- c:\windows\system32\uxtuneup.dll
2010-07-30 14:31 . 2010-07-30 14:31 388096 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-28 23:41 . 2010-07-28 23:41 ——– d—–w- c:\documents and settings\All Users\Application Data\VirtualizedApplications
2010-07-28 21:11 . 2010-07-28 21:11 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\SoftGrid Client
2010-07-28 21:11 . 2010-07-31 10:06 ——– d—–w- c:\documents and settings\Owner\Application Data\SoftGrid Client
2010-07-28 21:10 . 2010-07-28 21:10 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\{90140011-0061-0409-0000-0000000FF1CE}
2010-07-28 21:09 . 2010-08-10 18:24 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client
2010-07-28 21:06 . 2010-07-31 10:05 ——– d—–w- c:\program files\Microsoft Application Virtualization Client
2010-07-28 21:06 . 2010-07-28 21:06 ——– d—–w- c:\documents and settings\All Users\Microsoft
2010-07-28 20:59 . 2010-07-28 21:17 ——– d—–w- c:\documents and settings\Owner\Application Data\TP
2010-07-28 20:41 . 2010-07-28 20:40 8192 —-a-w- c:\windows\system32\srvany.exe
2010-07-28 20:41 . 2010-07-28 20:40 151552 —-a-w- c:\windows\KMService.exe
2010-07-14 19:15 . 2010-06-14 14:31 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-12 22:57 . 2010-07-12 23:00 ——– d—–w- c:\windows\$regcmp$
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-02 21:53 . 2010-06-21 23:38 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-07-30 15:15 . 2010-04-30 02:01 ——– d—–w- c:\program files\TuneUp Utilities 2010
2010-07-21 19:27 . 2010-05-07 15:56 1232 —-a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat
2010-07-17 21:30 . 2009-09-20 20:31 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2010-07-14 19:32 . 2008-12-11 16:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-06 11:58 . 2010-04-30 02:01 30528 —-a-w- c:\windows\system32\TURegOpt.exe
2010-07-03 18:58 . 2009-01-04 03:23 71152 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-30 20:59 . 2009-02-17 01:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-06-30 20:55 . 2010-02-08 22:18 ——– d—–w- c:\program files\Symantec
2010-06-30 20:55 . 2010-02-08 22:18 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-06-30 20:55 . 2010-02-08 22:18 7443 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-06-30 20:55 . 2010-02-08 22:18 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2010-06-30 20:55 . 2010-02-08 22:18 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-06-30 20:38 . 2010-06-30 20:38 ——– d—–w- c:\program files\Norton Support
2010-06-14 14:31 . 2006-05-07 01:36 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-04 22:15 . 2010-06-04 22:15 503808 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-34857b00-n\msvcp71.dll
2010-06-04 22:15 . 2010-06-04 22:15 499712 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-34857b00-n\jmc.dll
2010-06-04 22:15 . 2010-06-04 22:15 348160 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-34857b00-n\msvcr71.dll
2010-06-04 22:15 . 2010-06-04 22:15 61440 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4b5c59e1-n\decora-sse.dll
2010-06-04 22:15 . 2010-06-04 22:15 12800 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4b5c59e1-n\decora-d3d.dll
2010-06-04 22:14 . 2010-06-04 22:14 411368 —-a-w- c:\windows\system32\deployJava1.dll
.
((((((((((((((((((((((((((((( SnapShot_2010-07-07_18.06.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-10 18:04 . 2010-08-10 18:04 16384 c:\windows\Temp\Perflib_Perfdata_7d0.dat
+ 2010-08-10 18:27 . 2010-08-10 18:27 16384 c:\windows\Temp\Perflib_Perfdata_784.dat
+ 2010-08-10 18:26 . 2010-08-10 18:26 16384 c:\windows\Temp\Perflib_Perfdata_704.dat
+ 2010-07-28 21:12 . 2010-03-30 00:26 54656 c:\windows\system32\spool\drivers\w32x86\SendToOneNoteUI.dll
+ 2010-07-28 21:12 . 2010-03-30 00:26 94088 c:\windows\system32\spool\drivers\w32x86\SendToOneNoteFilter.dll
+ 2010-07-28 21:12 . 2010-03-30 00:26 54656 c:\windows\system32\spool\drivers\w32x86\3\SendToOneNoteUI.dll
+ 2010-07-28 21:12 . 2010-03-30 00:26 94088 c:\windows\system32\spool\drivers\w32x86\3\SendToOneNoteFilter.dll
+ 2006-05-07 01:24 . 2010-07-31 10:05 72090 c:\windows\system32\perfc009.dat
+ 2010-06-30 23:38 . 2010-04-22 02:29 43696 c:\windows\system32\drivers\srtspx.sys
+ 2009-12-03 02:23 . 2010-04-24 05:10 18280 c:\windows\system32\drivers\Sftvolxp.sys
+ 2009-12-03 02:23 . 2010-04-24 05:10 20584 c:\windows\system32\drivers\Sftredirxp.sys
- 2010-04-16 20:04 . 2010-06-11 03:50 35088 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 35088 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\oisicon.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 18704 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 18704 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\mspicons.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 20240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 20240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\cagicon.exe
+ 2010-07-31 10:05 . 2010-07-31 10:05 89952 c:\windows\Installer\{90140000-006D-0409-0000-0000000FF1CE}\cvhicon.exe
+ 2010-07-28 21:12 . 2008-03-13 04:52 761344 c:\windows\system32\spool\drivers\w32x86\unires.dll
+ 2010-07-28 21:12 . 2008-07-06 12:06 744960 c:\windows\system32\spool\drivers\w32x86\unidrvui.dll
+ 2010-07-28 21:12 . 2008-07-06 12:06 373248 c:\windows\system32\spool\drivers\w32x86\unidrv.dll
+ 2010-07-28 21:12 . 2008-07-06 12:06 765440 c:\windows\system32\spool\drivers\w32x86\mxdwdrv.dll
+ 2006-05-07 01:24 . 2010-07-31 10:05 444472 c:\windows\system32\perfh009.dat
+ 2010-07-13 16:09 . 2010-07-13 16:09 231888 c:\windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe
+ 2010-06-30 23:38 . 2010-05-06 04:01 361904 c:\windows\system32\drivers\symtdi.sys
+ 2010-06-30 23:38 . 2010-04-22 03:02 173104 c:\windows\system32\drivers\symefa.sys
+ 2010-06-30 23:38 . 2010-02-04 01:40 328752 c:\windows\system32\drivers\symds.sys
+ 2009-12-03 02:23 . 2010-04-24 05:10 211432 c:\windows\system32\drivers\Sftplayxp.sys
+ 2009-12-03 02:23 . 2010-04-24 05:10 554344 c:\windows\system32\drivers\Sftfsxp.sys
+ 2010-06-30 23:38 . 2010-04-29 05:03 116784 c:\windows\system32\drivers\ironx86.sys
+ 2010-06-30 23:38 . 2010-02-26 00:22 501888 c:\windows\system32\drivers\cchpx86.sys
+ 2010-06-14 21:04 . 2010-06-14 21:04 605696 c:\windows\Installer\54beda.msp
+ 2010-07-06 18:30 . 2010-07-06 18:30 747520 c:\windows\Installer\54bd87.msp
+ 2010-06-14 21:04 . 2010-06-14 21:04 549376 c:\windows\Installer\54bd86.msp
+ 2010-04-16 20:04 . 2010-07-14 19:32 888080 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 888080 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 272648 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 272648 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pubs.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 922384 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 922384 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\pptico.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 845584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 845584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\outicon.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 217864 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 217864 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\misc.exe
+ 2009-03-06 06:37 . 2009-03-06 06:37 501640 c:\windows\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6425\SOA.DLL
+ 2008-10-26 10:26 . 2008-10-26 10:26 162680 c:\windows\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6425\ACCWIZ.DLL
+ 2010-07-28 21:12 . 2008-07-06 12:06 1676288 c:\windows\system32\spool\drivers\w32x86\XpsSvcs.dll
+ 2006-05-07 01:24 . 2010-07-27 06:30 8462336 c:\windows\system32\shell32.dll
+ 2010-04-24 05:10 . 2010-04-24 05:10 1015144 c:\windows\system32\sftldr.dll
+ 2010-01-27 01:07 . 2010-07-13 16:09 5612496 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2008-06-17 19:02 . 2010-07-27 06:30 8462336 c:\windows\system32\dllcache\shell32.dll
+ 2010-07-28 21:08 . 2010-07-28 21:08 4201984 c:\windows\Installer\6ccb50.msi
+ 2010-07-06 18:29 . 2010-07-06 18:29 1460224 c:\windows\Installer\54bedb.msp
+ 2010-06-11 00:22 . 2010-06-11 00:22 8934912 c:\windows\Installer\460c461.msp
+ 2010-06-11 00:22 . 2010-06-11 00:22 5893120 c:\windows\Installer\460c460.msp
+ 2010-07-30 14:31 . 2010-07-30 14:31 1094656 c:\windows\Installer\2f61f4.msi
+ 2010-05-20 23:57 . 2010-05-20 23:57 4989952 c:\windows\Installer\2130d55.msp
+ 2010-05-20 23:57 . 2010-05-20 23:57 5907456 c:\windows\Installer\2130d54.msp
+ 2010-06-11 15:03 . 2010-06-11 15:03 5021184 c:\windows\Installer\2130d37.msp
+ 2010-04-16 20:04 . 2010-07-14 19:32 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
- 2010-04-16 20:04 . 2010-06-11 03:50 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
+ 2010-04-16 20:04 . 2010-07-14 19:32 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
+ 2010-02-28 06:33 . 2010-02-28 06:33 4817336 c:\windows\Installer\$PatchCache$\Managed\00004109D60090400000000000F01FEC\14.0.4763\CVH.DLL
+ 2008-12-11 18:00 . 2010-07-02 19:39 34045896 c:\windows\system32\MRT.exe
+ 2010-05-20 23:58 . 2010-05-20 23:58 12114432 c:\windows\Installer\2130d23.msp
+ 2009-03-06 06:37 . 2009-03-06 06:37 10222432 c:\windows\Installer\$PatchCache$\Managed\00002119410000000000000000F01FEC\12.0.6425\MSACCESS.EXE
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 14854144]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CanonSolutionMenu"=c:\program files\Canon\SolutionMenu\CNSLMAIN.exe /logon
"Persistence"=c:\windows\system32\igfxpers.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
"CanonMyPrinter"=c:\program files\Canon\MyPrinter\BJMyPrt.exe /logon
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0402000.00C\symds.sys [6/30/2010 7:38 PM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0402000.00C\symefa.sys [6/30/2010 7:38 PM 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20100719.001\BHDrvx86.sys [7/19/2010 7:28 PM 692272]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0402000.00C\cchpx86.sys [6/30/2010 7:38 PM 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0402000.00C\ironx86.sys [6/30/2010 7:38 PM 116784]
R2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2/28/2010 2:33 AM 821664]
R2 KMService;KMService;c:\windows\system32\srvany.exe [7/28/2010 4:41 PM 8192]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/5/2010 10:04 AM 304464]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\4.2.0.12\ccsvchst.exe [6/30/2010 7:37 PM 126392]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\Norton PC Checkup\Engine\2.0.1.247\SymcPCCULaunchSvc.exe [12/30/2009 5:48 PM 115056]
R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\Norton PC Checkup\Engine\2.0.1.247\ccSvcHst.exe [12/30/2009 5:48 PM 126392]
R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [4/24/2010 1:10 AM 483688]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/24/2010 2:28 AM 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20100805.004\IDSXpx86.sys [8/6/2010 6:18 AM 331640]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/5/2010 10:04 AM 20952]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [12/2/2009 10:23 PM 554344]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [12/2/2009 10:23 PM 211432]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [12/2/2009 10:23 PM 20584]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [12/2/2009 10:23 PM 18280]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [4/24/2010 1:10 AM 209768]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10/14/2009 7:24 AM 10064]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [7/6/2010 7:55 AM 1051968]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\windows\system32\drivers\el575ND5.sys [7/1/2006 1:44 AM 69692]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-07-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-07-23 c:\windows\Tasks\Automatic maintenance.job
- c:\program files\TuneUp Utilities 2010\OneClickStarter.exe [2010-07-06 12:02]
2008-12-11 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-05-07 00:12]
2008-12-11 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-05-07 00:12]
2008-12-11 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-05-07 00:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=EM&Loc=ENG_US&Sys=DTP&M=W3650
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\gyk9q362.default\
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\progra~1\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-10 14:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\4.2.0.12\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\4.2.0.12\diMaster.dll\" /prefetch:1"
–
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCCUJobMgr]
"ImagePath"="\"c:\program files\Norton PC Checkup\Engine\2.0.1.247\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files\Norton PC Checkup\Engine\2.0.1.247\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1716337210-622666185-3795375381-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(2164)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\KMService.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\RTHDCPL.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-08-10 14:37:08 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-10 18:37
ComboFix2.txt 2010-07-07 18:12
ComboFix3.txt 2010-06-14 14:09
ComboFix4.txt 2010-05-29 02:56
ComboFix5.txt 2010-08-10 16:36
Pre-Run: 116,731,428,864 bytes free
Post-Run: 116,619,464,704 bytes free
- - End Of File - - C0B85F1DB0D092789274C960F8C2F5E4