Thanks!
I downloaded Combofix and ran it in safe mode. Then I was able to run it in normal mode also. In safe mode, it told me that my anti-virus was enabled - but I couldn't find anyway to find out of it was on or to turn it off.
Here are my logs:
ComboFix 10-09-11.02 - default 09/11/2010 23:20:55.3.1 - FAT32x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.254.67 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Microsoft
c:\microsoft\Protect\CREDHIST
c:\windows\Downloaded Program Files\ODCTOOLS
.
((((((((((((((((((((((((( Files Created from 2010-08-12 to 2010-09-12 )))))))))))))))))))))))))))))))
.
2010-09-10 15:27 . 2010-09-07 23:00 20464696 —-a-w- c:\documents and settings\default\Application Data\Google\Update\Download\{A28F1E34-AA28-4428-B7F6-D3B4E8717FFD}\chrome_installer.exe
2010-09-10 05:26 . 2010-09-10 05:26 5395512 —-a-w- c:\documents and settings\default\Application Data\Google\Update\Download\{1CDD5048-9203-40C6-BA4C-C5E80EA0822B}\chrome_updater.exe
2010-09-08 15:46 . 2010-09-08 15:46 ——– d—–w- c:\program files\ESET
2010-09-07 15:40 . 2010-09-07 15:40 ——– d—–w- c:\documents and settings\default\Application Data\Avira
2010-09-07 15:40 . 2010-09-07 15:40 ——– d—–w- c:\documents and settings\default\Application Data\Avira
2010-09-07 15:20 . 2010-03-01 15:05 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-09-07 15:20 . 2009-05-11 17:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-09-07 15:20 . 2010-02-16 19:24 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-09-07 15:20 . 2009-05-11 17:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-09-07 15:20 . 2010-09-07 15:20 ——– d—–w- c:\program files\Avira
2010-09-07 15:20 . 2010-09-07 15:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2010-09-06 07:19 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-06 07:18 . 2010-09-06 07:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-09-06 07:18 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-04 03:19 . 2010-09-04 03:19 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-08-29 16:13 . 2008-04-13 18:45 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-08-21 04:45 . 2010-09-09 00:06 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-08-20 22:26 . 2010-09-07 17:46 63488 —-a-w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-08-20 22:25 . 2010-08-20 22:25 52224 —-a-w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-08-20 17:40 . 2010-08-20 17:40 27288 —-a-w- c:\documents and settings\default\Application Data\Google\Update\1.2.183.29\goopdateres_tr.dll
2010-08-20 07:17 . 2010-08-20 07:17 ——– d—–w- c:\documents and settings\default\Application Data\Temp
2010-08-20 07:17 . 2010-08-20 07:17 ——– d—–w- c:\documents and settings\default\Application Data\Temp
2010-08-20 06:46 . 2010-05-21 19:14 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-08-20 06:42 . 2010-08-20 06:42 ——– d—–w- c:\program files\Windows Defender
2010-08-20 06:34 . 2010-09-07 17:45 117760 —-a-w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-08-20 04:31 . 2010-06-24 12:21 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-08-15 17:09 . 2010-09-09 00:12 593 —-a-w- C:\register.bat
2010-08-15 16:23 . 2010-06-18 13:36 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe
2010-08-15 16:18 . 2010-06-14 14:31 744448 ——w- c:\windows\system32\dllcache\helpsvc.exe
2010-08-15 16:07 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll
2010-08-15 15:57 . 2010-08-15 15:57 ——– d—–w- c:\windows\SDOLD2
2010-08-14 18:42 . 2010-08-14 18:42 ——– d—–w- c:\documents and settings\default\Apps
2010-08-14 07:55 . 2010-08-14 07:55 ——– d—–w- c:\program files\Windows Live Safety Center
2010-08-14 05:51 . 2010-09-07 07:13 452104 —-a-w- c:\documents and settings\default\Application Data\Real\Update\setup3.12\setup.exe
2010-08-13 07:07 . 2010-08-13 07:07 ——– d—–w- c:\documents and settings\default\.ehdc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-10 06:30 . 2002-12-10 18:58 3667 —-a-w- c:\program files\i_view32.ini
2010-08-18 01:58 . 2010-08-20 17:43 945720 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\chrome.exe
2010-08-18 01:57 . 2010-08-20 17:43 216120 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\sr.dll
2010-08-18 01:56 . 2010-08-20 17:43 3184184 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\gears.dll
2010-08-18 01:56 . 2010-08-20 17:43 8760 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\chrome_launcher.exe
2010-08-18 01:56 . 2010-08-20 17:43 17939512 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\chrome.dll
2010-08-18 01:56 . 2010-08-20 17:43 71224 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\avutil-50.dll
2010-08-18 01:56 . 2010-08-20 17:43 151608 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\avformat-52.dll
2010-08-18 01:56 . 2010-08-20 17:43 1186360 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\avcodec-52.dll
2010-08-18 00:26 . 2010-08-20 17:43 5964752 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\gcswf32.dll
2010-08-18 00:00 . 2010-08-20 17:43 1127992 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Installer\setup.exe
2010-08-08 04:45 . 2010-08-08 04:45 ——– d—–w- c:\program files\SpywareBlaster
2010-08-08 04:45 . 2010-08-08 04:45 ——– d—–w- c:\program files\eCleaner
2010-08-08 04:45 . 2010-08-08 04:45 ——– d—–w- c:\program files\CCleaner
2010-08-08 04:44 . 2010-08-08 04:44 ——– d—–w- c:\program files\Ulead Systems
2010-08-08 03:37 . 2010-08-08 03:37 34144 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-07 21:33 . 2010-08-07 21:33 ——– d—–w- c:\program files\Trend Micro
2010-06-30 12:31 . 2003-08-30 17:05 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2004-02-06 23:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2003-08-30 17:06 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2003-08-30 17:05 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2003-08-30 17:03 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2003-08-30 17:33 744448 —-a-w- c:\windows\PCHEALTH\HELPCTR\BINARIES\HelpSvc.exe
2010-06-14 07:41 . 2003-08-30 17:04 1172480 —-a-w- c:\windows\system32\msxml3.dll
2006-12-24 23:56 . 2002-09-03 01:05 19129 —ha-w- c:\program files\I_VIEW32.GID
2006-10-11 23:21 . 2006-09-29 20:12 11177 —ha-w- c:\program files\hpothb07.dat
2006-10-11 23:21 . 2005-05-14 00:48 152081 —ha-w- c:\program files\hpothb07.tif
2006-10-05 20:34 . 2006-10-05 20:34 11996626 —-a-w- c:\program files\Scan0007.tif
2006-10-05 19:33 . 2006-10-05 19:33 1555 —-a-w- c:\program files\ganttproject.jnlp
2006-09-29 20:14 . 2006-09-29 20:14 11996628 —-a-w- c:\program files\Scan0006.tif
2006-09-28 03:32 . 2006-09-28 03:32 11996604 —-a-w- c:\program files\Scan0005.tif
2006-09-28 01:31 . 2006-09-28 01:31 11996604 —-a-w- c:\program files\Scan0004.tif
2006-09-28 01:21 . 2006-09-28 01:21 11996628 —-a-w- c:\program files\Scan0003.tif
2006-09-27 23:36 . 2006-09-27 23:36 11996628 —-a-w- c:\program files\Scan0002.tif
2006-09-27 23:32 . 2006-09-27 23:32 11996604 —-a-w- c:\program files\Scan0001.tif
2006-02-18 22:12 . 2003-10-05 12:55 5120 –sha-w- c:\program files\Thumbs.db
2005-01-11 18:53 . 2004-07-22 21:23 17 —-a-w- c:\program files\stinger.opt
2004-11-18 02:56 . 2002-08-16 01:15 661 —-a-w- c:\program files\i_view32.exe.manifest
2004-11-18 02:56 . 2001-12-23 02:42 765 —-a-w- c:\program files\i_languages.txt
2004-11-18 02:56 . 2001-12-23 02:42 5754 —-a-w- c:\program files\i_plugins.txt
2004-11-18 02:56 . 2001-12-23 02:42 55822 —-a-w- c:\program files\i_changes.txt
2004-11-18 02:56 . 2001-12-23 02:42 432128 —-a-w- c:\program files\i_view32.exe
2004-11-18 02:56 . 2001-12-23 02:42 3940 —-a-w- c:\program files\i_view32.cnt
2004-11-18 02:56 . 2001-12-23 02:42 31744 —-a-w- c:\program files\iv_uninstall.exe
2004-11-18 02:56 . 2001-12-23 02:42 2189 —-a-w- c:\program files\i_about.txt
2004-11-18 02:56 . 2001-12-23 02:42 168929 —-a-w- c:\program files\i_view32.hlp
2004-11-18 02:56 . 2001-12-23 02:42 10579 —-a-w- c:\program files\i_options.txt
2004-07-22 20:59 . 2004-07-22 20:57 800263 —-a-w- c:\program files\stinger.exe
2004-02-28 23:57 . 2004-02-28 23:57 36864 —-a-w- c:\program files\soc. paper.doc
2004-02-27 19:31 . 2004-02-27 01:30 29696 —-a-w- c:\program files\Capital Punishment.doc
2004-02-26 22:41 . 2004-02-26 22:41 10752 —-a-w- c:\program files\abortion paper-work cited.wps
2004-02-26 22:40 . 2004-02-26 22:40 26624 —-a-w- c:\program files\abortion paper-1.wps
2004-02-23 13:54 . 2004-02-23 13:54 1167762 —-a-w- c:\program files\kibler.pdf
2003-06-14 03:04 . 2003-06-14 03:04 487428 —-a-w- c:\program files\nokia.mpeg
2002-11-15 17:55 . 2002-11-15 17:55 456128 —-a-w- c:\program files\PopUpStopper.exe
2002-10-21 03:11 . 2002-10-21 03:11 553687 —-a-w- c:\program files\RegCleaner.exe
2002-08-16 01:14 . 2002-08-16 01:14 827392 —-a-w- c:\program files\iview375.exe
2002-05-29 04:22 . 2002-05-29 04:18 27 —-a-w- c:\program files\alias.dat
2002-05-29 04:20 . 2002-05-29 04:18 27 —-a-w- c:\program files\cfilter.dat
2002-05-29 04:18 . 2002-05-29 04:18 1688 —-a-w- c:\program files\cverinfo.ini
2002-05-29 04:18 . 2002-05-29 04:18 4484 —-a-w- c:\program files\unins000.dat
2002-05-29 04:18 . 2002-02-10 08:00 72748 —-a-w- c:\program files\unins000.exe
2002-05-21 14:55 . 2002-05-21 14:55 0 —-a-w- c:\program files\CUSTDATA.INI
2002-04-26 05:11 . 2002-04-26 05:11 1069056 —-a-w- c:\program files\cstub.exe
2002-04-15 20:34 . 2002-04-15 20:34 172032 —-a-w- c:\program files\cchat.exe
2002-03-25 17:59 . 2002-03-25 17:59 77824 —-a-w- c:\program files\CUpdater.exe
2002-03-23 03:04 . 2002-03-23 03:04 3222744 —-a-w- c:\program files\acdzip.exe
2002-03-20 13:56 . 2002-03-20 13:57 3877 —-a-w- c:\program files\AGBP.csv
2002-03-10 18:17 . 2002-03-10 18:17 877531 —-a-w- c:\program files\aaw.exe
2002-03-10 18:12 . 2002-03-10 18:12 14270 —-a-w- c:\program files\reflist.zip
2002-02-09 14:18 . 2002-02-09 14:18 383 —-a-w- c:\program files\smileys.txt
2002-01-16 02:05 . 2002-01-16 02:05 2654 —-a-w- c:\program files\catlist.dat
2002-01-14 23:30 . 2002-01-14 23:30 21823560 —-a-w- c:\program files\dotnetfx.exe
2001-12-23 02:41 . 2001-12-23 02:41 816640 —-a-w- c:\program files\iview361.exe
2001-09-08 19:25 . 2001-09-08 19:25 46 —-a-w- c:\program files\cconfig.ini
2001-02-02 21:59 . 2001-02-02 21:59 23357 —h–w- c:\program files\folder.htt
2000-10-13 11:01 . 2000-10-13 11:01 9322 —-a-w- c:\program files\macros.dat
2000-10-12 05:44 . 2002-05-21 14:55 167936 —-a-w- c:\program files\TIME.EXE
1999-11-20 01:29 . 1999-11-20 01:29 2499 —-a-w- c:\program files\quote.ini
1999-02-27 23:25 . 1999-02-27 23:25 31244 —-a-w- c:\program files\CHEETACHAT.HLP
1999-02-19 12:54 . 1999-02-19 12:54 40960 —-a-w- c:\program files\SSubTmr6.dll
1998-11-08 15:47 . 1998-11-08 15:47 8850 —-a-w- c:\program files\emotions.dat
1998-06-04 19:30 . 2002-07-04 19:53 709120 —-a-w- c:\program files\winzip95.exe
1997-08-13 16:19 . 2002-07-21 14:17 1714 —-a-w- c:\program files\UsingCC.txt
1997-08-13 16:10 . 2002-07-21 14:17 2930 —-a-w- c:\program files\general.txt
1997-08-13 16:09 . 2002-07-21 14:17 1121 —-a-w- c:\program files\tech.txt
1997-08-13 16:08 . 2002-07-21 14:17 3570 —-a-w- c:\program files\install.txt
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\default\Application Data\Google\Update\GoogleUpdate.exe" [2010-08-20 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-12-03 180269]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-05 149280]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2005-01-27 16:17 1381376 ——w- c:\program files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 16:50 155648 —-a-w- c:\windows\SYSTEM32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2004-12-03 19:57 204845 —-a-w- c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WANMiniportService"=2 (0x2)
"Pctspk"=2 (0x2)
"McShield"=3 (0x3)
"AvSynMgr"=2 (0x2)
"Messenger"=2 (0x2)
"InCDsrvR"=2 (0x2)
"InCDsrv"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCHealth"=c:\windows\PCHealth\Support\PCHSchd.exe -s
"PCTVOICE"=pctvoice.exe
"eMachine eBoard"=c:\progra~1\ESOFT\EBOARD\eBoard.exe
"uTOK uSleep"=
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"LoadQM"=loadqm.exe
"CountrySelection"=pctptt.exe
"QuickTime Task"="c:\windows\SYSTEM\QTTASK.EXE" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"SchedulingAgent"=mstask.exe
"SSDPSRV"=c:\windows\SYSTEM\ssdpsrv.exe
"*StateMgr"=c:\windows\System\Restore\StateMgr.exe
"McAfeeVirusScanService"=c:\program files\Network Associates\VirusScan\AVSYNMGR.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R3 PD1030VID;Creative WebCam Pro;c:\windows\system32\DRIVERS\p1030vid.sys [2002-05-20 167673]
R3 Ptserli;PCTEL Serial Device Driver for INTEL;c:\windows\system32\DRIVERS\ptserli.sys [2001-08-17 128286]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-04 13592]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
2001-03-23 21:17 7168 ——w- c:\windows\SYSTEM32\updcrl.exe
.
Contents of the 'Scheduled Tasks' folder
2010-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-688789844-1708537768-1004Core.job
- c:\documents and settings\default\Application Data\Google\Update\GoogleUpdate.exe [2010-08-20 17:40]
2010-09-10 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = 127.0.0.1
Trusted Zone: aol.com\free
DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\default\Application Data\Mozilla\Firefox\Profiles\oltr6zob.default\
FF - plugin: c:\documents and settings\default\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-09-11 23:36
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(360)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2010-09-11 23:42:28
ComboFix-quarantined-files.txt 2010-09-12 04:42
ComboFix2.txt 2010-08-12 19:38
Pre-Run: 3,563,257,856 bytes free
Post-Run: 3,560,931,328 bytes free
- - End Of File - - 33D0752A47FF5952CC0159B77655D5F3
ComboFix 10-09-11.02 - default 09/12/2010 0:24.4.1 - FAT32x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((( Files Created from 2010-08-12 to 2010-09-12 )))))))))))))))))))))))))))))))
.
2010-09-12 05:12 . 2010-09-03 00:58 1534008 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\npchrome_frame.dll
2010-09-12 05:11 . 2010-09-03 00:57 3184184 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\gears.dll
2010-09-12 05:10 . 2010-09-03 00:57 20078648 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\chrome.dll
2010-09-12 05:09 . 2010-09-03 00:57 204344 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\ca.dll
2010-09-12 05:09 . 2010-09-03 00:57 203320 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\bn.dll
2010-09-12 05:09 . 2010-09-03 00:57 237112 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\bg.dll
2010-09-12 05:09 . 2010-09-03 00:57 91192 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\avutil-50.dll
2010-09-12 05:09 . 2010-09-03 00:57 193592 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\avformat-52.dll
2010-09-12 05:09 . 2010-09-03 00:57 1434680 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\avcodec-52.dll
2010-09-12 05:09 . 2010-09-03 00:57 193080 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\ar.dll
2010-09-12 05:09 . 2010-09-03 00:57 107064 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\am.dll
2010-09-10 05:26 . 2010-09-10 05:26 5395512 —-a-w- c:\documents and settings\default\Application Data\Google\Update\Download\{1CDD5048-9203-40C6-BA4C-C5E80EA0822B}\chrome_updater.exe
2010-09-08 15:46 . 2010-09-08 15:46 ——– d—–w- c:\program files\ESET
2010-09-07 15:40 . 2010-09-07 15:40 ——– d—–w- c:\documents and settings\default\Application Data\Avira
2010-09-07 15:40 . 2010-09-07 15:40 ——– d—–w- c:\documents and settings\default\Application Data\Avira
2010-09-07 15:20 . 2010-03-01 15:05 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-09-07 15:20 . 2009-05-11 17:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-09-07 15:20 . 2010-02-16 19:24 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-09-07 15:20 . 2009-05-11 17:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-09-07 15:20 . 2010-09-07 15:20 ——– d—–w- c:\program files\Avira
2010-09-07 15:20 . 2010-09-07 15:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2010-09-06 07:19 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-06 07:18 . 2010-09-06 07:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-09-06 07:18 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-04 03:19 . 2010-09-04 03:19 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-08-29 16:13 . 2008-04-13 18:45 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-08-21 04:45 . 2010-09-09 00:06 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-08-20 22:26 . 2010-09-07 17:46 63488 —-a-w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-08-20 22:25 . 2010-08-20 22:25 52224 —-a-w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-08-20 17:40 . 2010-08-20 17:40 27288 —-a-w- c:\documents and settings\default\Application Data\Google\Update\1.2.183.29\goopdateres_tr.dll
2010-08-20 07:17 . 2010-08-20 07:17 ——– d—–w- c:\documents and settings\default\Application Data\Temp
2010-08-20 07:17 . 2010-08-20 07:17 ——– d—–w- c:\documents and settings\default\Application Data\Temp
2010-08-20 06:46 . 2010-05-21 19:14 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-08-20 06:42 . 2010-08-20 06:42 ——– d—–w- c:\program files\Windows Defender
2010-08-20 06:34 . 2010-09-07 17:45 117760 —-a-w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-08-20 04:31 . 2010-06-24 12:21 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-08-15 17:09 . 2010-09-09 00:12 593 —-a-w- C:\register.bat
2010-08-15 16:23 . 2010-06-18 13:36 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe
2010-08-15 16:18 . 2010-06-14 14:31 744448 ——w- c:\windows\system32\dllcache\helpsvc.exe
2010-08-15 16:07 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll
2010-08-15 15:57 . 2010-08-15 15:57 ——– d—–w- c:\windows\SDOLD2
2010-08-14 18:42 . 2010-08-14 18:42 ——– d—–w- c:\documents and settings\default\Apps
2010-08-14 07:55 . 2010-08-14 07:55 ——– d—–w- c:\program files\Windows Live Safety Center
2010-08-14 05:51 . 2010-09-07 07:13 452104 —-a-w- c:\documents and settings\default\Application Data\Real\Update\setup3.12\setup.exe
2010-08-13 07:07 . 2010-08-13 07:07 ——– d—–w- c:\documents and settings\default\.ehdc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-10 06:30 . 2002-12-10 18:58 3667 —-a-w- c:\program files\i_view32.ini
2010-09-03 00:57 . 2010-09-12 05:11 178744 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\et.dll
2010-09-03 00:57 . 2010-09-12 05:11 207928 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\es.dll
2010-09-03 00:57 . 2010-09-12 05:11 204344 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\es-419.dll
2010-09-03 00:57 . 2010-09-12 05:11 174648 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\en-US.dll
2010-09-03 00:57 . 2010-09-12 05:11 175160 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\en-GB.dll
2010-09-03 00:57 . 2010-09-12 05:11 258616 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\el.dll
2010-09-03 00:57 . 2010-09-12 05:11 169016 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\de.dll
2010-09-03 00:57 . 2010-09-12 05:11 186936 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\da.dll
2010-09-03 00:57 . 2010-09-12 05:11 195128 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\cs.dll
2010-09-03 00:57 . 2010-09-12 05:12 10911800 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\icudt42.dll
2010-09-03 00:57 . 2010-09-12 05:13 89656 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\chrome_launcher.exe
2010-09-02 23:01 . 2010-09-12 05:13 1131576 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Installer\setup.exe
2010-09-02 22:53 . 2010-09-12 05:11 5964752 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\gcswf32.dll
2010-08-18 01:58 . 2010-08-20 17:43 111672 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\rlz.dll
2010-08-18 01:58 . 2010-08-20 17:43 1154616 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\npchrome_frame.dll
2010-08-18 01:58 . 2010-08-20 17:43 1133624 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\nacl64.exe
2010-08-18 01:58 . 2010-08-20 17:43 2158136 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\nacl64.dll
2010-08-18 01:58 . 2010-08-20 17:43 100920 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\zh-TW.dll
2010-08-18 01:58 . 2010-08-20 17:43 100920 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\zh-CN.dll
2010-08-18 01:58 . 2010-08-20 17:43 218168 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\uk.dll
2010-08-18 01:58 . 2010-08-20 17:43 197176 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\vi.dll
2010-08-18 01:58 . 2010-08-20 17:43 189496 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\tr.dll
2010-08-18 01:58 . 2010-08-20 17:43 234040 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\th.dll
2010-08-18 01:58 . 2010-08-20 17:43 228920 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\ta.dll
2010-08-18 01:58 . 2010-08-20 17:43 206392 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\te.dll
2010-08-18 01:58 . 2010-08-20 17:43 138808 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\sw.dll
2010-08-18 01:56 . 2010-08-20 17:43 3184184 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\gears.dll
2010-08-18 01:56 . 2010-08-20 17:43 8760 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\chrome_launcher.exe
2010-08-18 01:56 . 2010-08-20 17:43 17939512 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\chrome.dll
2010-08-18 01:56 . 2010-08-20 17:43 71224 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\avutil-50.dll
2010-08-18 01:56 . 2010-08-20 17:43 151608 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\avformat-52.dll
2010-08-18 01:56 . 2010-08-20 17:43 1186360 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\avcodec-52.dll
2010-08-18 00:26 . 2010-08-20 17:43 5964752 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\gcswf32.dll
2010-08-18 00:00 . 2010-08-20 17:43 1127992 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Installer\setup.exe
2010-08-08 04:45 . 2010-08-08 04:45 ——– d—–w- c:\program files\SpywareBlaster
2010-08-08 04:45 . 2010-08-08 04:45 ——– d—–w- c:\program files\eCleaner
2010-08-08 04:45 . 2010-08-08 04:45 ——– d—–w- c:\program files\CCleaner
2010-08-08 04:44 . 2010-08-08 04:44 ——– d—–w- c:\program files\Ulead Systems
2010-08-08 03:37 . 2010-08-08 03:37 34144 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-07 21:33 . 2010-08-07 21:33 ——– d—–w- c:\program files\Trend Micro
2010-06-30 12:31 . 2003-08-30 17:05 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2004-02-06 23:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2003-08-30 17:06 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2003-08-30 17:05 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2003-08-30 17:03 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2003-08-30 17:33 744448 —-a-w- c:\windows\PCHEALTH\HELPCTR\BINARIES\HelpSvc.exe
2010-06-14 07:41 . 2003-08-30 17:04 1172480 —-a-w- c:\windows\system32\msxml3.dll
2006-12-24 23:56 . 2002-09-03 01:05 19129 —ha-w- c:\program files\I_VIEW32.GID
2006-10-11 23:21 . 2006-09-29 20:12 11177 —ha-w- c:\program files\hpothb07.dat
2006-10-11 23:21 . 2005-05-14 00:48 152081 —ha-w- c:\program files\hpothb07.tif
2006-10-05 20:34 . 2006-10-05 20:34 11996626 —-a-w- c:\program files\Scan0007.tif
2006-10-05 19:33 . 2006-10-05 19:33 1555 —-a-w- c:\program files\ganttproject.jnlp
2006-09-29 20:14 . 2006-09-29 20:14 11996628 —-a-w- c:\program files\Scan0006.tif
2006-09-28 03:32 . 2006-09-28 03:32 11996604 —-a-w- c:\program files\Scan0005.tif
2006-09-28 01:31 . 2006-09-28 01:31 11996604 —-a-w- c:\program files\Scan0004.tif
2006-09-28 01:21 . 2006-09-28 01:21 11996628 —-a-w- c:\program files\Scan0003.tif
2006-09-27 23:36 . 2006-09-27 23:36 11996628 —-a-w- c:\program files\Scan0002.tif
2006-09-27 23:32 . 2006-09-27 23:32 11996604 —-a-w- c:\program files\Scan0001.tif
2006-02-18 22:12 . 2003-10-05 12:55 5120 –sha-w- c:\program files\Thumbs.db
2005-01-11 18:53 . 2004-07-22 21:23 17 —-a-w- c:\program files\stinger.opt
2004-11-18 02:56 . 2002-08-16 01:15 661 —-a-w- c:\program files\i_view32.exe.manifest
2004-11-18 02:56 . 2001-12-23 02:42 765 —-a-w- c:\program files\i_languages.txt
2004-11-18 02:56 . 2001-12-23 02:42 5754 —-a-w- c:\program files\i_plugins.txt
2004-11-18 02:56 . 2001-12-23 02:42 55822 —-a-w- c:\program files\i_changes.txt
2004-11-18 02:56 . 2001-12-23 02:42 432128 —-a-w- c:\program files\i_view32.exe
2004-11-18 02:56 . 2001-12-23 02:42 3940 —-a-w- c:\program files\i_view32.cnt
2004-11-18 02:56 . 2001-12-23 02:42 31744 —-a-w- c:\program files\iv_uninstall.exe
2004-11-18 02:56 . 2001-12-23 02:42 2189 —-a-w- c:\program files\i_about.txt
2004-11-18 02:56 . 2001-12-23 02:42 168929 —-a-w- c:\program files\i_view32.hlp
2004-11-18 02:56 . 2001-12-23 02:42 10579 —-a-w- c:\program files\i_options.txt
2004-07-22 20:59 . 2004-07-22 20:57 800263 —-a-w- c:\program files\stinger.exe
2004-02-28 23:57 . 2004-02-28 23:57 36864 —-a-w- c:\program files\soc. paper.doc
2004-02-27 19:31 . 2004-02-27 01:30 29696 —-a-w- c:\program files\Capital Punishment.doc
2004-02-26 22:41 . 2004-02-26 22:41 10752 —-a-w- c:\program files\abortion paper-work cited.wps
2004-02-26 22:40 . 2004-02-26 22:40 26624 —-a-w- c:\program files\abortion paper-1.wps
2004-02-23 13:54 . 2004-02-23 13:54 1167762 —-a-w- c:\program files\kibler.pdf
2003-06-14 03:04 . 2003-06-14 03:04 487428 —-a-w- c:\program files\nokia.mpeg
2002-11-15 17:55 . 2002-11-15 17:55 456128 —-a-w- c:\program files\PopUpStopper.exe
2002-10-21 03:11 . 2002-10-21 03:11 553687 —-a-w- c:\program files\RegCleaner.exe
2002-08-16 01:14 . 2002-08-16 01:14 827392 —-a-w- c:\program files\iview375.exe
2002-05-29 04:22 . 2002-05-29 04:18 27 —-a-w- c:\program files\alias.dat
2002-05-29 04:20 . 2002-05-29 04:18 27 —-a-w- c:\program files\cfilter.dat
2002-05-29 04:18 . 2002-05-29 04:18 1688 —-a-w- c:\program files\cverinfo.ini
2002-05-29 04:18 . 2002-05-29 04:18 4484 —-a-w- c:\program files\unins000.dat
2002-05-29 04:18 . 2002-02-10 08:00 72748 —-a-w- c:\program files\unins000.exe
2002-05-21 14:55 . 2002-05-21 14:55 0 —-a-w- c:\program files\CUSTDATA.INI
2002-04-26 05:11 . 2002-04-26 05:11 1069056 —-a-w- c:\program files\cstub.exe
2002-04-15 20:34 . 2002-04-15 20:34 172032 —-a-w- c:\program files\cchat.exe
2002-03-25 17:59 . 2002-03-25 17:59 77824 —-a-w- c:\program files\CUpdater.exe
2002-03-23 03:04 . 2002-03-23 03:04 3222744 —-a-w- c:\program files\acdzip.exe
2002-03-20 13:56 . 2002-03-20 13:57 3877 —-a-w- c:\program files\AGBP.csv
2002-03-10 18:17 . 2002-03-10 18:17 877531 —-a-w- c:\program files\aaw.exe
2002-03-10 18:12 . 2002-03-10 18:12 14270 —-a-w- c:\program files\reflist.zip
2002-02-09 14:18 . 2002-02-09 14:18 383 —-a-w- c:\program files\smileys.txt
2002-01-16 02:05 . 2002-01-16 02:05 2654 —-a-w- c:\program files\catlist.dat
2002-01-14 23:30 . 2002-01-14 23:30 21823560 —-a-w- c:\program files\dotnetfx.exe
2001-12-23 02:41 . 2001-12-23 02:41 816640 —-a-w- c:\program files\iview361.exe
2001-09-08 19:25 . 2001-09-08 19:25 46 —-a-w- c:\program files\cconfig.ini
2001-02-02 21:59 . 2001-02-02 21:59 23357 —h–w- c:\program files\folder.htt
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\default\Application Data\Google\Update\GoogleUpdate.exe" [2010-08-20 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-12-03 180269]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-05 149280]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2005-01-27 16:17 1381376 ——w- c:\program files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 16:50 155648 —-a-w- c:\windows\SYSTEM32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2004-12-03 19:57 204845 —-a-w- c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WANMiniportService"=2 (0x2)
"Pctspk"=2 (0x2)
"McShield"=3 (0x3)
"AvSynMgr"=2 (0x2)
"Messenger"=2 (0x2)
"InCDsrvR"=2 (0x2)
"InCDsrv"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCHealth"=c:\windows\PCHealth\Support\PCHSchd.exe -s
"PCTVOICE"=pctvoice.exe
"eMachine eBoard"=c:\progra~1\ESOFT\EBOARD\eBoard.exe
"uTOK uSleep"=
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"LoadQM"=loadqm.exe
"CountrySelection"=pctptt.exe
"QuickTime Task"="c:\windows\SYSTEM\QTTASK.EXE" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"SchedulingAgent"=mstask.exe
"SSDPSRV"=c:\windows\SYSTEM\ssdpsrv.exe
"*StateMgr"=c:\windows\System\Restore\StateMgr.exe
"McAfeeVirusScanService"=c:\program files\Network Associates\VirusScan\AVSYNMGR.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 1:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67656]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/7/2010 10:21 AM 135336]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 PD1030VID;Creative WebCam Pro;c:\windows\SYSTEM32\DRIVERS\p1030vid.sys [3/28/2004 3:25 PM 167673]
S3 Ptserli;PCTEL Serial Device Driver for INTEL;c:\windows\SYSTEM32\DRIVERS\ptserli.sys [8/30/2003 12:24 PM 128286]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
2001-03-23 21:17 7168 ——w- c:\windows\SYSTEM32\updcrl.exe
.
Contents of the 'Scheduled Tasks' folder
2010-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-688789844-1708537768-1004Core.job
- c:\documents and settings\default\Application Data\Google\Update\GoogleUpdate.exe [2010-08-20 17:40]
2010-09-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = 127.0.0.1
Trusted Zone: aol.com\free
DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\default\Application Data\Mozilla\Firefox\Profiles\oltr6zob.default\
FF - plugin: c:\documents and settings\default\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-09-12 00:46
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(412)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(8644)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2010-09-12 00:54:52
ComboFix-quarantined-files.txt 2010-09-12 05:54
ComboFix2.txt 2010-09-12 04:42
ComboFix3.txt 2010-08-12 19:38
Pre-Run: 3,147,005,952 bytes free
Post-Run: 3,144,908,800 bytes free
- - End Of File - - 1CCD24B0B7A2DE8697346DE5D7252291