ComboFix 09-03-15.01 - Owner 2009-
ComboFix 09-03-15.01 - Owner 2009-03-16 12:34:59.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.126.12 [GMT -7:00]
Running from: c:\my download files\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-02-16 to 2009-03-16 )))))))))))))))))))))))))))))))
.
2009-03-16 07:48 . 2009-03-16 07:48 <DIR> d-------- c:\program files\iPod
2009-03-16 07:46 . 2009-03-16 07:49 <DIR> d-------- c:\program files\iTunes
2009-03-16 07:46 . 2009-03-16 07:49 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-16 07:38 . 2009-03-16 07:49 <DIR> d-------- c:\windows\LastGood
2009-03-16 03:29 . 2009-03-16 05:12 <DIR> d-------- C:\music limewire
2009-03-16 03:29 . 2009-03-16 05:36 <DIR> d-------- C:\Incomplete
2009-03-09 03:24 . 2009-03-09 03:24 <DIR> d-------- c:\program files\Cobian Backup 8
2009-03-08 05:31 . 2009-03-08 05:32 <DIR> d-------- c:\program files\ACW
2009-03-07 03:02 . 2009-03-07 03:02 <DIR> d-------- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-03-07 03:01 . 2009-03-16 03:23 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-23 20:24 . 2009-02-23 20:25 <DIR> d-------- c:\program files\Bonjour
2009-02-21 09:04 . 2009-02-21 09:04 12 --a------ c:\documents and settings\Owner\bitpim.dat
2009-02-21 08:49 . 2004-08-04 01:56 90,624 --a------ c:\windows\system32\kswdmcap.ax
2009-02-21 08:49 . 2004-08-04 01:56 61,952 --a------ c:\windows\system32\kstvtune.ax
2009-02-21 08:49 . 2004-08-04 01:56 53,760 --a------ c:\windows\system32\vfwwdm32.dll
2009-02-21 08:49 . 2004-08-04 01:56 43,008 --a------ c:\windows\system32\ksxbar.ax
2009-02-21 08:49 . 2004-08-04 01:56 28,672 --a------ c:\windows\system32\vidcap.ax
2009-02-21 03:48 . 2009-02-21 03:48 <DIR> d-------- c:\program files\SAMSUNG CDMA Modem
2009-02-21 03:47 . 2009-02-21 03:49 <DIR> d-------- c:\program files\QuickLink Mobile
2009-02-21 03:47 . 2009-02-21 03:49 <DIR> d-------- c:\program files\Common Files\Smith Micro Shared
2009-02-21 00:39 . 2009-02-21 00:40 <DIR> d-------- c:\program files\BitPim
2009-02-20 15:15 . 2007-12-04 18:10 16,640 -ra------ c:\windows\system32\drivers\PalmUSBD.sys
2009-02-20 15:05 . 2009-02-20 15:05 <DIR> d-------- c:\documents and settings\Owner\Application Data\Arcsoft
2009-02-20 14:59 . 2009-02-20 14:59 <DIR> d-------- c:\documents and settings\Owner\Application Data\HotSync
2009-02-20 14:59 . 2009-02-20 14:59 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\HotSync
2009-02-20 14:58 . 2009-03-16 03:22 <DIR> d-------- c:\program files\Palm
2009-02-19 21:35 . 2004-03-03 18:02 <DIR> d-------- C:\BigClock
2009-02-16 14:38 . 2009-02-16 14:43 <DIR> d-------- c:\program files\Safari
2009-02-16 14:26 . 2009-02-16 14:26 <DIR> d-------- c:\program files\AVG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-16 14:47 --------- d-----w c:\program files\Common Files\Apple
2009-03-09 08:55 --------- d-----w c:\program files\Trend Micro
2009-03-08 08:04 --------- d-----w c:\program files\Coupons
2009-03-07 09:51 --------- d-----w c:\program files\Lx_cats
2009-03-06 18:12 --------- d-----w c:\program files\LimeWire
2009-03-06 18:12 --------- d-----w c:\program files\Lexmark 1300 Series
2009-03-06 17:26 --------- d-----r c:\program files\Lexmark X1100 Series
2009-02-20 09:13 --------- d---a-w c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-02-16 21:49 --------- d-----w c:\documents and settings\Owner\Application Data\Apple Computer
2009-02-16 20:09 --------- d-----w c:\program files\Common Files\Motive
2009-02-16 20:07 --------- d-----w c:\program files\Common Files\SupportSoft
2009-02-10 00:27 --------- d-----w c:\documents and settings\AMIRA.HOME-FB222EE479.000\Application Data\LimeWire
2009-02-08 17:13 --------- d-----w c:\program files\Alwil Software
2009-02-08 17:11 31,262,848 ----a-w c:\program files\AVAST ANTIVIRUS DOWNLOAD.exe
2009-02-08 09:13 52,736 ----a-w c:\windows\system32\drivers\i8042prt.sys
2009-02-03 07:59 --------- d-----w c:\program files\Broderbund
2009-02-02 04:32 --------- d-----w c:\documents and settings\Owner\Application Data\Broderbund Software
2009-02-02 03:27 --------- d-----w c:\program files\JlgSolera
2009-02-01 22:21 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-29 22:50 --------- d-----w c:\program files\Common Files\Real
2009-01-25 15:54 --------- d-----w c:\program files\Common Files\Adobe
2009-01-25 14:06 --------- d-----w c:\program files\QuickTime
2009-01-25 07:47 --------- d-----w c:\program files\Apple Software Update
2009-01-25 07:46 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Apple
2009-01-25 00:55 --------- d-----w c:\program files\Common Files\Broderbund
2009-01-25 00:43 --------- d-----w c:\program files\Paint.NET
2009-01-25 00:41 --------- d-----w c:\program files\Web Publish
2009-01-21 10:54 --------- d-----w c:\documents and settings\Owner\Application Data\SmartDraw
2009-01-13 22:55 28,549 ----a-w c:\windows\Fonts\sarsapar.zip
2009-01-13 22:51 28,232 ----a-w c:\windows\Fonts\easilyamused.zip
2009-01-13 22:48 11,798 ----a-w c:\windows\Fonts\NegativeSpace1.zip
2009-01-13 21:08 838,158 ----a-w c:\program files\sci GRAPHS setup.exe
2008-07-12 04:32 22,411,048 ----a-w c:\program files\SkypeSetup.exe
2008-06-11 22:38 19,790,584 ----a-w c:\program files\VZMM2_1-DL-SAMSU-Bld9-Juke-002.exe
2008-06-07 09:50 12,664,832 ----a-w c:\program files\BlackBerry Device Manager v4.2 (English).msi
2008-06-02 10:23 4,042,444 ----a-w c:\program files\win ace269i.exe
2008-04-19 08:43 2,733,520 ----a-w c:\program files\ccleansetup205.exe
2007-08-04 07:32 5,149,152 ----a-w c:\program files\rminstallFREEE.exe
2007-08-04 07:26 5,149,152 ----a-w c:\program files\regmechfree.exe
2007-07-30 14:24 4,900,888 ----a-w c:\program files\LimeWireWin.exe
2006-10-29 22:06 454 ----a-w c:\program files\Shortcut to xerox.lnk
2006-10-15 21:32 740 ----a-w c:\program files\LATESTADOBEEEEEEE.exe
2008-10-20 03:46 16,384 --sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
2008-10-20 03:46 16,384 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
2008-10-20 03:46 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
------- Sigcheck -------
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\svchost.exe
2004-08-04 05:00 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\system32\svchost.exe
2004-08-04 05:00 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\system32\dllcache\svchost.exe
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ws2_32.dll
2004-08-04 05:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll
2004-08-04 05:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\dllcache\ws2_32.dll
2006-04-20 05:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 03:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 04:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2004-08-04 05:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys
2006-04-20 04:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys
2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\tcpip.sys
2008-06-20 03:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\dllcache\tcpip.sys
2008-06-20 03:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\drivers\tcpip.sys
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\winlogon.exe
2004-08-04 05:00 502272 01c3346c241652f43aed8e2149881bfe c:\windows\system32\winlogon.exe
2004-08-04 05:00 502272 01c3346c241652f43aed8e2149881bfe c:\windows\system32\dllcache\winlogon.exe
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ndis.sys
2004-08-04 05:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\dllcache\ndis.sys
2004-08-04 05:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ip6fw.sys
2004-08-04 05:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\dllcache\ip6fw.sys
2004-08-04 05:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\services.exe
2004-08-04 05:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\system32\services.exe
2004-08-04 05:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\system32\dllcache\services.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\lsass.exe
2004-08-04 05:00 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\lsass.exe
2004-08-04 05:00 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\dllcache\lsass.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ctfmon.exe
2004-08-04 05:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\ctfmon.exe
2004-08-04 05:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\dllcache\ctfmon.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\userinit.exe
2004-08-04 05:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe
2004-08-04 05:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\dllcache\userinit.exe
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\termsrv.dll
2004-08-04 05:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\termsrv.dll
2004-08-04 05:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\dllcache\termsrv.dll
2008-04-13 17:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\powrprof.dll
2004-08-04 05:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\powrprof.dll
2004-08-04 05:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\dllcache\powrprof.dll
2008-04-13 17:11 110080 0da85218e92526972a821587e6a8bf8f c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\imm32.dll
2004-08-04 05:00 110080 87ca7ce6469577f059297b9d6556d66d c:\windows\system32\imm32.dll
2004-08-04 05:00 110080 87ca7ce6469577f059297b9d6556d66d c:\windows\system32\dllcache\imm32.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-03-09_12.10.25.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-09 10:20:05 1,847,424 ----a-w c:\windows\$hf_mig$\KB958690\SP2QFE\win32k.sys
+ 2009-02-09 11:13:27 1,846,784 ----a-w c:\windows\$hf_mig$\KB958690\SP3GDR\win32k.sys
+ 2009-02-09 11:08:53 1,847,552 ----a-w c:\windows\$hf_mig$\KB958690\SP3QFE\win32k.sys
+ 2008-07-09 07:38:24 17,272 ----a-w c:\windows\$hf_mig$\KB958690\spmsg.dll
+ 2008-07-09 07:38:25 231,288 ----a-w c:\windows\$hf_mig$\KB958690\spuninst.exe
+ 2008-07-09 07:38:24 26,488 ----a-w c:\windows\$hf_mig$\KB958690\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB958690\update\update.exe
+ 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB958690\update\updspapi.dll
+ 2008-12-05 06:41:26 144,896 ----a-w c:\windows\$hf_mig$\KB960225\SP2QFE\schannel.dll
+ 2008-12-05 06:54:55 144,896 ----a-w c:\windows\$hf_mig$\KB960225\SP3GDR\schannel.dll
+ 2008-12-05 06:58:08 144,896 ----a-w c:\windows\$hf_mig$\KB960225\SP3QFE\schannel.dll
+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB960225\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB960225\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB960225\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB960225\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB960225\update\updspapi.dll
+ 2009-03-16 14:51:12 102,400 ----a-r c:\windows\Installer\{C26B06A9-27BB-45B0-9873-9C623EC2BA38}\iTunesIco.exe
+ 2008-04-17 21:12:54 15,464 ----a-w c:\windows\LastGood\system32\DRIVERS\GEARAspiWDM.sys
+ 2008-04-17 21:12:54 107,368 ----a-w c:\windows\LastGood\system32\GEARAspi.dll
- 2007-04-25 14:21:15 144,896 -c--a-w c:\windows\system32\dllcache\schannel.dll
+ 2008-12-05 07:12:45 144,896 -c--a-w c:\windows\system32\dllcache\schannel.dll
- 2008-09-15 11:57:41 1,846,016 -c--a-w c:\windows\system32\dllcache\win32k.sys
+ 2009-02-09 10:19:34 1,846,272 -c--a-w c:\windows\system32\dllcache\win32k.sys
- 2007-06-12 07:51:12 10,834,944 -c--a-w c:\windows\system32\dllcache\wmp.dll
+ 2008-11-12 01:34:42 10,838,016 -c--a-w c:\windows\system32\dllcache\wmp.dll
- 2008-04-17 21:12:54 15,464 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
+ 2009-01-15 19:19:36 23,848 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
+ 2008-04-17 19:12:54 107,368 -c--a-w c:\windows\system32\DRVSTORE\GEARAspiWD_4F4AA3475F1B13A1E8212B6D40B351211BC358CE\x86\GEARAspi.dll
+ 2009-01-15 19:19:36 23,848 -c--a-w c:\windows\system32\DRVSTORE\GEARAspiWD_4F4AA3475F1B13A1E8212B6D40B351211BC358CE\x86\GEARAspiWDM.sys
+ 2009-03-06 06:59:00 36,864 -c--a-w c:\windows\system32\DRVSTORE\usbaapl_AF109929C2381E41FEF454F3FEDAA257A9E85F92\usbaapl.sys
+ 2009-03-06 06:59:00 1,900,544 -c--a-w c:\windows\system32\DRVSTORE\usbaapl_AF109929C2381E41FEF454F3FEDAA257A9E85F92\usbaaplrc.dll
- 2009-02-06 22:57:03 675,360 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-03-11 19:06:28 675,360 ----a-w c:\windows\system32\FNTCACHE.DAT
- 2008-04-17 21:12:54 107,368 ----a-w c:\windows\system32\GEARAspi.dll
+ 2008-04-17 19:12:54 107,368 ----a-w c:\windows\system32\GEARAspi.dll
- 2009-03-09 18:56:47 59,984 ----a-w c:\windows\system32\perfc009.dat
+ 2009-03-15 05:03:22 59,984 ----a-w c:\windows\system32\perfc009.dat
- 2009-03-09 18:56:47 397,890 ----a-w c:\windows\system32\perfh009.dat
+ 2009-03-15 05:03:24 397,890 ----a-w c:\windows\system32\perfh009.dat
- 2007-04-25 14:21:15 144,896 ----a-w c:\windows\system32\schannel.dll
+ 2008-12-05 07:12:45 144,896 ----a-w c:\windows\system32\schannel.dll
- 2008-07-09 07:38:24 17,272 ------w c:\windows\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ------w c:\windows\system32\spmsg.dll
- 2006-10-16 23:10:58 23,856 ----a-w c:\windows\system32\spupdsvc.exe
+ 2007-07-27 16:41:38 26,488 ----a-w c:\windows\system32\spupdsvc.exe
- 2008-09-15 11:57:41 1,846,016 ----a-w c:\windows\system32\win32k.sys
+ 2009-02-09 10:19:34 1,846,272 ----a-w c:\windows\system32\win32k.sys
- 2007-06-12 07:51:12 10,834,944 ----a-w c:\windows\system32\wmp.dll
+ 2008-11-12 01:34:42 10,838,016 ----a-w c:\windows\system32\wmp.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 158208]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{03A80B1D-5C6A-42c2-9DFB-81B6005D8023}"= "c:\program files\Trend Micro\Tmas\sshook.dll" [2006-08-25 77824]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^EPSON Background Monitor.lnk]
backup=c:\windows\pss\EPSON Background Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Event Reminder.lnk]
backup=c:\windows\pss\Event Reminder.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^MediaChecker.lnk]
backup=c:\windows\pss\MediaChecker.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Run Google Web Accelerator.lnk]
backup=c:\windows\pss\Run Google Web Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Trend Micro Anti-Spyware.lnk]
backup=c:\windows\pss\Trend Micro Anti-Spyware.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Alarm Manager.LNK]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Alarm Manager.LNK
backup=c:\windows\pss\Alarm Manager.LNKStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^firefox.lnk]
backup=c:\windows\pss\firefox.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^MEMonitor.lnk]
backup=c:\windows\pss\MEMonitor.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Microsoft Greetings Reminders.lnk]
backup=c:\windows\pss\Microsoft Greetings Reminders.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^yahoodeeneeweenee.url]
backup=c:\windows\pss\yahoodeeneeweenee.urlStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 02:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2004-02-10 11:51 118784 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-05-12 00:12 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2002-11-05 11:34 188416 c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2004-02-10 11:55 155648 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2009-03-12 20:56 342312 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
--------- 2003-08-19 03:43 57344 c:\program files\Lexmark X1100 Series\lxbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdcamon]
--a------ 2007-04-30 01:19 20480 c:\program files\Lexmark 1300 Series\lxdcamon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2009-01-05 17:18 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--------- 2006-10-18 21:05 204288 c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RPSUpdaterR"=3 (0x3)
"MyWebSearchService"=2 (0x2)
"lxdc_device"=3 (0x3)
"lxdcCATSCustConnectService"=3 (0x3)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"EpsonBidirectionalService"=2 (0x2)
"dvpapi"=3 (0x3)
"Bonjour Service"=2 (0x2)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Lexmark 1300 Series\\lxdcamon.exe"=
"c:\\Program Files\\Lexmark 1300 Series\\App4R.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Lexmark 1300 Series\\Diagnostics\\lxdccdw.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdcpswx.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
R3 i740;i740;c:\windows\system32\DRIVERS\i740nt5.sys [2001-08-17 58592]
R4 lxdc_device;lxdc_device;c:\windows\system32\lxdccoms.exe [2007-05-25 537520]
R4 lxdcCATSCustConnectService;lxdcCATSCustConnectService;c:\windows\System32\spool\DRIVERS\W32X86\3\\lxdcserv.exe [2007-05-25 99248]
S2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe [2004-08-04 14336]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - APPLE_MOBILE_DEVICE
*NewlyCreated* - IPOD_SERVICE
*Deregistered* - 6to4
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - Apple Mobile Device
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - CryptSvc
*Deregistered* - CSS DVP
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HidServ
*Deregistered* - HTTP
*Deregistered* - ImapiService
*Deregistered* - IntelIde
*Deregistered* - Ip6Fw
*Deregistered* - IpNat
*Deregistered* - iPod Service
*Deregistered* - IPSec
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LexBceS
*Deregistered* - LmHosts
*Deregistered* - MCSTRM
*Deregistered* - mdmxsdk
*Deregistered* - mnmdd
*Deregistered* - Mouclass
*Deregistered* - MountMgr
*Deregistered* - mr7910
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - MSIServer
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - NwlnkIpx
*Deregistered* - NwlnkNb
*Deregistered* - NwlnkSpx
*Deregistered* - NwSapAgent
*Deregistered* - OMCI
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - RimVSerPort
*Deregistered* - ROOTMODEM
*Deregistered* - RpcLocator
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - StillCam
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - Tcpip6
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - tmcomm
*Deregistered* - tunmp
*Deregistered* - Update
*Deregistered* - upnphost
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WudfPf
*Deregistered* - WudfSvc
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder
2009-03-01 c:\windows\Tasks\CHANGES.job
- c:\program files\Java\jre1.5.0_06\CHANGES [2005-11-10 12:36]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: yahoo.com\us.mc314.mail
TCP: {F573D2CF-FD78-48D9-82CB-225575122902} = 66.51.205.100,66.51.206.100
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-16 12:43:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-1659004503-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2009-03-16 12:53:07
ComboFix-quarantined-files.txt 2009-03-16 19:52:48
ComboFix2.txt 2009-03-09 19:14:34
Pre-Run: 46,979,764,224 bytes free
Post-Run: 47,205,421,056 bytes free
444 --- E O F --- 2009-03-11 18:59:49