ComboFix 07-12-07.5 - wayne 2007-12-07 13:05:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.102 [GMT -6:00]
Running from: C:\Documents and Settings\Administrator.RXENTRY02\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\autorun.inf
C:\Program Files\Common Files\ecurit~1
C:\Program Files\Common Files\ecurit~1\?ecurity\
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\PopSwatr\History\allowed
C:\Program Files\FunWebProducts\PopSwatr\History\notallow
C:\Program Files\FunWebProducts\ScreenSaver\Images\2AD170E8.urr
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\Rqaljyvv
C:\Program Files\Rqaljyvv\zukrvtec.dll
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe.bak
C:\Program Files\smss.exe
C:\Program Files\vision
C:\Program Files\vision\admupdat.exe
C:\Program Files\vision\ANSITERM.exe
C:\Program Files\vision\hostexp.exe
C:\Program Files\vision\HostWiz.exe
C:\Program Files\vision\Keymap.exe
C:\Program Files\vision\MSGPAD.exe
C:\Program Files\vision\ProxyWiz.exe
C:\Program Files\vision\rps.exe
C:\Program Files\vision\system\101.KLT
C:\Program Files\vision\system\102.KLT
C:\Program Files\vision\system\ANSI.DFT
C:\Program Files\vision\system\ANSI.KDB
C:\Program Files\vision\system\ANSIX.dll
C:\Program Files\vision\system\English\Ats.hlp
C:\Program Files\vision\system\English\Cnaccess.hlp
C:\Program Files\vision\system\English\Cnterm.hlp
C:\Program Files\vision\system\English\Cnvca.hlp
C:\Program Files\vision\system\English\Cnvisn.hlp
C:\Program Files\vision\system\English\Common.hlp
C:\Program Files\vision\system\English\Conmon.hlp
C:\Program Files\vision\system\English\Hostexp.hlp
C:\Program Files\vision\system\English\Keymap.hlp
C:\Program Files\vision\system\English\Licts.hlp
C:\Program Files\vision\system\English\Msgpad.hlp
C:\Program Files\vision\system\English\Netcheck.hlp
C:\Program Files\vision\system\English\Rps.hlp
C:\Program Files\vision\system\English\Term.hlp
C:\Program Files\vision\system\English\Userview.hlp
C:\Program Files\vision\system\English\Vcats.hlp
C:\Program Files\vision\system\English\Vision.hlp
C:\Program Files\vision\system\English\Visionts.hlp
C:\Program Files\vision\system\English\Vwc32.hlp
C:\Program Files\vision\system\HOSTFCTL.dll
C:\Program Files\vision\system\LK250.KLT
C:\Program Files\vision\system\PRTCTL.dll
C:\Program Files\vision\system\PrtLocal.vcf
C:\Program Files\vision\system\rifx.exe
C:\Program Files\vision\system\rifxx.dll
C:\Program Files\vision\system\Rpsx.dll
C:\Program Files\vision\system\sni-tate.klt
C:\Program Files\vision\system\UPDTCTL.dll
C:\Program Files\vision\system\Vt420.dft
C:\Program Files\vision\system\Vt420.kdb
C:\Program Files\vision\system\VT420X.dll
C:\Program Files\vision\system\VTICONX.dll
C:\Program Files\vision\system\vwaansi.dll
C:\Program Files\vision\system\vwarps.dll
C:\Program Files\vision\system\vwavt420.dll
C:\Program Files\vision\system\vwawys60.dll
C:\Program Files\vision\system\W60X.dll
C:\Program Files\vision\system\Wyse60.dft
C:\Program Files\vision\system\Wyse60.kdb
C:\Program Files\vision\unixwizd.exe
C:\Program Files\vision\userview.exe
C:\Program Files\vision\V420TERM.exe
C:\Program Files\vision\wy60term.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\abW9
C:\Temp\abW9\tPho.log
C:\temp\tn3
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\ODCTOOLS
C:\WINDOWS\Free Online Dating.ico
C:\WINDOWS\IA
C:\WINDOWS\system32\c1
C:\WINDOWS\system32\d1
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\j2
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\m8
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rMa02yy
C:\WINDOWS\system32\v97
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_CORE
-------\LEGACY_DOMAINSERVICE
-------\core
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-11-07 to 2007-12-07 )))))))))))))))))))))))))))))))
.
2007-12-07 12:49 . 2007-12-07 12:49 <DIR> d-------- C:\Program Files\Sun
2007-12-07 12:49 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-07 12:37 . 2007-12-07 12:38 <DIR> d-------- C:\Documents and Settings\Administrator.RXENTRY02\.SunDownloadManager
2007-12-06 12:42 . 2007-12-07 12:19 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-06 12:42 . 2007-12-06 12:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-06 12:42 . 2007-12-06 12:42 <DIR> d-------- C:\Documents and Settings\Administrator.RXENTRY02\Application Data\SUPERAntiSpyware.com
2007-12-06 12:14 . 2007-12-06 12:14 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-12-06 11:55 . 2007-12-06 12:19 <DIR> d-------- C:\VundoFix Backups
2007-12-06 11:40 . 2007-12-06 11:40 <DIR> d-------- C:\Program Files\SonicWallES
2007-12-06 01:42 . 2007-12-07 12:14 1,276 --a------ C:\rollback.ini
2007-12-05 22:06 . 2007-12-06 11:40 <DIR> d-------- C:\Documents and Settings\Administrator.RXENTRY02\Application Data\MailFrontier
2007-12-05 22:00 . 2007-12-07 13:17 2,863,648 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-05 22:00 . 2007-12-07 13:17 39,140 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-05 21:53 . 2007-12-06 02:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-05 21:53 . 2007-11-14 16:05 75,248 --a------ C:\WINDOWS\zllsputility.exe
2007-12-05 21:53 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-12-05 21:53 . 2007-12-06 23:09 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-12-05 21:51 . 2007-12-07 13:15 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-12-05 21:47 . 2007-12-05 21:47 143 --a------ C:\WINDOWS\system32\mcrh.tmp
2007-12-05 10:42 . 2007-12-06 01:41 807,606 --ahs---- C:\WINDOWS\system32\kgnpxcbl.ini
2007-12-01 13:11 . 2007-12-01 13:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MSN6
2007-12-01 13:11 . 2007-12-01 13:12 <DIR> d-------- C:\Documents and Settings\Administrator.RXENTRY02\Application Data\MSN6
2007-12-01 12:44 . 2007-12-01 12:44 <DIR> d-------- C:\Program Files\Microsoft Easy Assist
2007-12-01 11:20 . 2007-12-01 11:21 <DIR> d-------- C:\OneCareSupportData
2007-12-01 10:56 . 2007-12-01 11:00 <DIR> d-------- C:\Program Files\RegCure
2007-11-28 08:29 . 2007-12-01 11:22 1,459,356 --a------ C:\OneCareSupportData.zip
2007-11-27 19:47 . 2007-09-21 10:35 116,416 --a------ C:\WINDOWS\system32\drivers\msfwhlpr.sys
2007-11-27 19:47 . 2007-09-21 10:35 91,328 --a------ C:\WINDOWS\system32\drivers\msfwdrv.sys
2007-11-27 19:46 . 2007-07-06 16:09 70,928 --a------ C:\WINDOWS\system32\drivers\MpFilter.sys
2007-11-27 19:44 . 2007-03-29 06:56 409,600 --------- C:\WINDOWS\system32\dllcache\qmgr.dll
2007-11-27 19:44 . 2007-03-29 06:56 18,944 --------- C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2007-11-27 19:44 . 2007-03-29 06:56 8,192 --------- C:\WINDOWS\system32\dllcache\bitsprx2.dll
2007-11-27 19:44 . 2007-03-29 06:56 7,168 --------- C:\WINDOWS\system32\dllcache\bitsprx4.dll
2007-11-27 19:44 . 2007-03-29 06:56 7,168 --------- C:\WINDOWS\system32\dllcache\bitsprx3.dll
2007-11-27 19:44 . 2007-03-29 06:56 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll
2007-11-27 18:59 . 2007-11-27 18:59 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-11-27 16:23 . 2007-12-07 13:00 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2007-11-27 15:42 . 2007-12-06 11:40 <DIR> d-------- C:\WINDOWS\system32\tpcwdoia
2007-11-27 15:42 . 2007-11-27 15:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2007-11-27 15:42 . 2007-11-27 15:42 131 --a------ C:\Documents and Settings\Administrator.RXENTRY02\mit.bat
2007-11-27 15:41 . 2007-12-06 11:40 <DIR> d-------- C:\Program Files\kfqrsped
2007-11-27 15:41 . 2007-11-27 15:42 1,149,472 --a------ C:\Install
2007-11-26 10:15 . 2007-03-07 17:51 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2007-11-15 11:50 . 2007-11-15 11:50 <DIR> d-------- C:\Program Files\Ventrilo
2007-11-15 11:50 . 2007-12-06 12:41 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-13 13:33 . 2007-11-13 13:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-11-13 13:32 . 2007-11-13 13:32 <DIR> d-------- C:\Program Files\DivX
2007-11-13 10:30 . 2007-11-13 10:30 <DIR> d-------- C:\Program Files\MySlideShow Plug-ins
2007-11-13 10:30 . 2007-11-13 10:30 <DIR> d-------- C:\Program Files\MySlideShow Gold 2
2007-11-13 10:30 . 2007-11-13 10:30 <DIR> d-------- C:\Program Files\Common Files\Anix Shared
2007-11-13 10:30 . 2007-11-13 10:30 <DIR> d-------- C:\Documents and Settings\Administrator.RXENTRY02\Application Data\Anix Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 18:51 --------- d-----w C:\Program Files\Java
2007-12-06 17:50 --------- d-----w C:\Program Files\QuickTime
2007-12-06 17:40 --------- d-----w C:\Program Files\Virtools Web Player 3.5
2007-12-06 08:05 --------- d-----w C:\Program Files\Trend Micro
2007-12-06 02:16 --------- d-----w C:\Program Files\Compaq
2007-12-01 21:59 --------- d-----w C:\Program Files\Yahoo SiteBuilder
2007-12-01 21:58 524,288 ----a-w C:\Documents and Settings\__sbs_netsetup__\ntuser.dat
2007-12-01 21:58 --------- d-----w C:\Program Files\MySpace
2007-11-28 02:09 --------- d-----w C:\Program Files\Lavasoft
2007-11-27 16:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-27 16:00 --------- d-----w C:\Program Files\Google
2007-11-27 15:59 --------- d-----w C:\Program Files\Yahoo! Games
2007-11-27 15:59 --------- d-----w C:\Program Files\Common Files\AOL
2007-11-27 15:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-11-27 15:55 --------- d---a-w C:\Program Files\Lycos
2007-11-26 16:16 --------- d-----w C:\Program Files\Winamp
2007-11-19 14:11 --------- d-----w C:\Program Files\UI Central
2007-11-14 22:05 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2007-11-13 19:33 --------- d--h--r C:\Documents and Settings\Administrator.RXENTRY02\Application Data\yahoo!
2007-11-07 10:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-20 00:56 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-09-24 23:28 202,240 ----a-w C:\WINDOWS\system32\Dr Pepper Go For More 23.scr
2004-06-22 13:04 94,438 ------w C:\Program Files\hposcu08.inf
2004-06-22 13:04 9,777 ------w C:\Program Files\hpzipr13.inf
2004-06-22 13:04 9,773 ------w C:\Program Files\hpousc08.inf
2004-06-22 13:04 70,656 ------w C:\Program Files\msvcirt.dll
2004-06-22 13:04 7,579 ------w C:\Program Files\hpound08.inf
2004-06-22 13:04 66,431 ------w C:\Program Files\hpoprl04.dat
2004-06-22 13:04 65,420 ------w C:\Program Files\hpoprl05.dat
2004-06-22 13:04 65 ------w C:\Program Files\dxprl.dat
2004-06-22 13:04 6,704 ------w C:\Program Files\hpounp08.inf
2004-06-22 13:04 53,670 ------w C:\Program Files\hposcu08.cat
2004-06-22 13:04 52,349 ------w C:\Program Files\hpzius13.cat
2004-06-22 13:04 52,349 ------w C:\Program Files\HPZius12.cat
2004-06-22 13:04 51,467 ------w C:\Program Files\hpzist13.cat
2004-06-22 13:04 51,467 ------w C:\Program Files\hpzist12.cat
2004-06-22 13:04 51,467 ------w C:\Program Files\hpzipr13.cat
2004-06-22 13:04 51,467 ------w C:\Program Files\HPZipr12.cat
2004-06-22 13:04 51,467 ------w C:\Program Files\hpzid413.cat
2004-06-22 13:04 51,467 ------w C:\Program Files\HPZid412.cat
2004-06-22 13:04 51,026 ------w C:\Program Files\HPOunp08.cat
2004-06-22 13:04 50,615 ------w C:\Program Files\hpzid412.inf
2004-06-22 13:04 5,538 ------w C:\Program Files\hpzist12.inf
2004-06-22 13:04 49,212 ------w C:\Program Files\hpzjvp01.dll
2004-06-22 13:04 458,752 ------w C:\Program Files\tls704d.dll
2004-06-22 13:04 447,400 ------w C:\Program Files\hpoprn08.cat
2004-06-22 13:04 442,425 ------w C:\Program Files\hpzjpp01.dll
2004-06-22 13:04 4,779 ------w C:\Program Files\hpoglu08.inf
2004-06-22 13:04 4,768 ------w C:\Program Files\hpoprl01.dat
2004-06-22 13:04 4,144 ------w C:\Program Files\hpousb08.inf
2004-06-22 13:04 4,132 ------w C:\Program Files\hpzist13.inf
2004-06-22 13:04 4,014 ------w C:\Program Files\hpoprl08.dat
2004-06-22 13:04 399 ------w C:\Program Files\hpzprl01.dat
2004-06-22 13:04 314 ------w C:\Program Files\hpqprl01.dat
2004-06-22 13:04 3,448 ------w C:\Program Files\hpohub08.inf
2004-06-22 13:04 297 ------w C:\Program Files\Readme.html
2004-06-22 13:04 290,873 ------w C:\Program Files\hpzjut01.dll
2004-06-22 13:04 28,722 ------w C:\Program Files\hpzjlog.dll
2004-06-22 13:04 270,336 ------w C:\Program Files\hpzglu10.exe
2004-06-22 13:04 270,336 ------w C:\Program Files\hpzc3212.dll
2004-06-22 13:04 26,768 ------w C:\Program Files\usbhub.sys
2004-06-22 13:04 254,005 ------w C:\Program Files\msvcrt.dll
2004-06-22 13:04 22,636 ------w C:\Program Files\hpzid413.inf
2004-06-22 13:04 22,608 ------w C:\Program Files\usbprint.sys
2004-06-22 13:04 205 ------w C:\Program Files\hpzprl02.dat
2004-06-22 13:04 200,704 ------w C:\Program Files\hpzpnp10.dll
2004-06-22 13:04 20,168 ------w C:\Program Files\hpzius12.inf
2004-06-22 13:04 2,542 ------w C:\Program Files\hpoprl02.dat
2004-06-22 13:04 19,578 ------w C:\Program Files\hpoprl03.dat
2004-06-22 13:04 176,128 ------w C:\Program Files\hpzscr10.dll
2004-06-22 13:04 17,176 ------w C:\Program Files\hpomdl04.dat
2004-06-22 13:04 16,416 ------w C:\Program Files\HPZUCI12.DLL
2004-06-22 13:04 14,845 ------w C:\Program Files\hpoapd01.dat
2004-06-22 13:04 14,815 ------w C:\Program Files\hpzius13.inf
2004-06-22 13:04 137,124 ------w C:\Program Files\hpoprn08.inf
2004-06-22 13:04 12,922 ------w C:\Program Files\hpzipr12.inf
2004-06-22 13:04 12,288 ------w C:\Program Files\usbmon.dll
2004-06-22 13:04 1,980 ------w C:\Program Files\hpoprl07.dat
2004-06-22 13:04 1,479 ------w C:\Program Files\license.txt
2004-06-22 13:04 1,391 ------w C:\Program Files\readme.txt
2004-06-22 13:04 1,073,152 ------w C:\Program Files\Setup.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 21:49]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" []
"MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24]
"Aim6"="C:\Program Files\AIM6\aim6.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-04 19:00]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-04 01:56]
"srmclean"="C:\Cpqs\Scom\srmclean.exe" [2001-07-24 15:34]
"SpywareBot"="C:\Program Files\SpywareBot\SpywareBot.exe" []
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 10:57]
"SetRefresh"="C:\Program Files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 12:01]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" []
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2007-11-19 09:38]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" []
"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 14:45]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32]
"HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 12:38]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 14:18]
"DrvLsnr"="C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe" [2003-05-08 06:34]
"CPQEASYACC"="C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe" []
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 01:56]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\Palm\Hotsync.exe [2004-06-09 14:27:34]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 21:31:38]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 22:06:36]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
Vision Services.lnk - C:\Program Files\Common Files\Vision\vservice.exe [2004-06-10 09:03:46]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"tmlisten"=2 (0x2)
"ntrtscan"=2 (0x2)
"WinDefend"=2 (0x2)
"usnjsvc"=3 (0x3)
"SoundMAX Agent Service (default)"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"MDM"=2 (0x2)
"iPodService"=3 (0x3)
"IDriverT"=3 (0x3)
"DomainService"=2 (0x2)
"Belkin Wireless USB Network Adapter Service"=2 (0x2)
"wuauserv"=2 (0x2)
R1 MSFWHLPR;MSFWHLPR;C:\WINDOWS\system32\DRIVERS\msfwhlpr.sys
R2 Machnm32;Machnm32 Driver;\??\C:\WINDOWS\system32\Machnm32.sys
R2 MSFWDrv;MSFWDrv;C:\WINDOWS\system32\DRIVERS\msfwdrv.sys
R2 msfwsvc;OneCare Firewall;"C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe"
R2 OneCareMP;OneCare AntiSpyware and AntiVirus;"C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe"
R3 MpFilter;Microsoft Malware Protection Driver;C:\WINDOWS\system32\DRIVERS\MpFilter.sys
S3 CTL511Plus;Video Blaster WebCam 3/WebCam Plus (WDM);C:\WINDOWS\system32\DRIVERS\webc3vid.sys
S4 Belkin Wireless USB Network Adapter Service;Belkin Wireless USB Network Adapter;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7a9ddc6f-dc16-11db-a95a-001150bec44a}]
\Shell\AutoRun\command - E:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-11-24 06:11:37 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job"
- C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe
"2007-12-07 19:18:25 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2007-12-06 09:00:12 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-07 13:23:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-07 13:30:46 - machine was rebooted
.
--- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:42:28 PM, on 12/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe"
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Outlook\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Vision Services.lnk = C:\Program Files\Common Files\Vision\vservice.exe
O4 - Global Startup: ZIM SMS Mail.lnk = C:\Program Files\ZIM\SMS Mail\ZIMSMSMail.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) -
http://www.superadblocker.com/activex/sabspx.cab
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 5800 bytes