ComboFix 09-04-04.01 - Tom 2009-04-05 11:10:17.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1535.890 [GMT -5:00]
Running from: c:\documents and settings\Tom\Desktop\ComboFixx.exe
Command switches used :: c:\documents and settings\Tom\Desktop\CFscript.txt
AV: Norton AntiVirus 2005 *On-access scanning disabled* (Outdated)
FW: Norton Internet Worm Protection *enabled*
* Created a new restore point
FILE ::
C:\-468360241
C:\ajtbyh.exe
C:\dmsiacq.exe
c:\documents and settings\Tom\Application Data\wklnhst.dat
C:\gldmo.exe
C:\lxdwn.exe
C:\wicnin.exe
c:\windows\Fsuya.bin
c:\windows\instsp2.exe
c:\windows\system32\drivers\UACd.sys
c:\windows\udusafuza.dll
c:\windows\Uqizoxihuvuwoxu.dat
c:\windows\wmsrary.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\-468360241
C:\ajtbyh.exe
C:\dmsiacq.exe
c:\documents and settings\Tom\Application Data\wklnhst.dat
C:\gldmo.exe
C:\lxdwn.exe
c:\program files\AskSBar
c:\program files\AskSBar\bar\2.bin\A2FFXTBR.JAR
c:\program files\AskSBar\bar\2.bin\A2FFXTBR.MANIFEST
c:\program files\AskSBar\bar\2.bin\A2NTSTBR.JAR
c:\program files\AskSBar\bar\2.bin\A2NTSTBR.MANIFEST
c:\program files\AskSBar\bar\Cache\
0003B71C
c:\program files\AskSBar\bar\Cache\
02D23CC2.bin
c:\program files\AskSBar\bar\Cache\
02D23E0B.bin
c:\program files\AskSBar\bar\Cache\
02D23EC6.bin
c:\program files\AskSBar\bar\Cache\
02D2400E.bin
c:\program files\AskSBar\bar\Cache\
02D24156.bin
c:\program files\AskSBar\bar\Cache\
02D24202.bin
c:\program files\AskSBar\bar\Cache\files.ini
c:\program files\AskSBar\bar\History\search2
c:\program files\AskSBar\bar\Settings\prevcfg2.htm
c:\program files\AskSBar\SrchAstt\2.bin\A2SRCHAS.DLL
c:\program files\SpywareDetector
c:\program files\SpywareDetector\ActiveProtection.dll
c:\program files\SpywareDetector\AntiRootKitDLL.dll
c:\program files\SpywareDetector\CloseAll.exe
c:\program files\SpywareDetector\Data\SD1.DB
c:\program files\SpywareDetector\Data\SD18.DB
c:\program files\SpywareDetector\Data\SD19.DB
c:\program files\SpywareDetector\Data\SD2.DB
c:\program files\SpywareDetector\Data\SD23.DB
c:\program files\SpywareDetector\Data\SD25.DB
c:\program files\SpywareDetector\Data\SD26.DB
c:\program files\SpywareDetector\Data\SD3.DB
c:\program files\SpywareDetector\Data\SD31.DB
c:\program files\SpywareDetector\Data\SD39.DB
c:\program files\SpywareDetector\Data\SD4.DB
c:\program files\SpywareDetector\Data\SD5.DB
c:\program files\SpywareDetector\Data\SD501.DB
c:\program files\SpywareDetector\Data\SD503.DB
c:\program files\SpywareDetector\Data\SD504.DB
c:\program files\SpywareDetector\Data\SD505.DB
c:\program files\SpywareDetector\Data\SD506.DB
c:\program files\SpywareDetector\Data\SD507.DB
c:\program files\SpywareDetector\Data\SD508.DB
c:\program files\SpywareDetector\Data\SD509.DB
c:\program files\SpywareDetector\Data\SD510.DB
c:\program files\SpywareDetector\Data\SD511.DB
c:\program files\SpywareDetector\Data\SD512.DB
c:\program files\SpywareDetector\Data\SD516.DB
c:\program files\SpywareDetector\Data\SD517.DB
c:\program files\SpywareDetector\Data\SD519.DB
c:\program files\SpywareDetector\Data\SD520.DB
c:\program files\SpywareDetector\Data\SD521.DB
c:\program files\SpywareDetector\Data\SD522.DB
c:\program files\SpywareDetector\Data\SD523.DB
c:\program files\SpywareDetector\Data\SD524.DB
c:\program files\SpywareDetector\Data\SD525.DB
c:\program files\SpywareDetector\Data\SD526.DB
c:\program files\SpywareDetector\Data\SD527.DB
c:\program files\SpywareDetector\Data\SD528.DB
c:\program files\SpywareDetector\Data\SD529.DB
c:\program files\SpywareDetector\Data\SD530.DB
c:\program files\SpywareDetector\Data\SD531.DB
c:\program files\SpywareDetector\Data\SD532.DB
c:\program files\SpywareDetector\Data\SD536.DB
c:\program files\SpywareDetector\Data\SD537.DB
c:\program files\SpywareDetector\Data\SD538.DB
c:\program files\SpywareDetector\Data\SD539.DB
c:\program files\SpywareDetector\Data\SD540.DB
c:\program files\SpywareDetector\Data\SD541.DB
c:\program files\SpywareDetector\Data\SD542.DB
c:\program files\SpywareDetector\Data\SD543.DB
c:\program files\SpywareDetector\Data\SD6.DB
c:\program files\SpywareDetector\Data\SD7.DB
c:\program files\SpywareDetector\Data\SD8.DB
c:\program files\SpywareDetector\Data\SDE.DB
c:\program files\SpywareDetector\Data\SDF501.DB
c:\program files\SpywareDetector\Data\SDF502.DB
c:\program files\SpywareDetector\Data\SDF503.DB
c:\program files\SpywareDetector\Data\SDF504.DB
c:\program files\SpywareDetector\Data\SDF505.DB
c:\program files\SpywareDetector\Data\SDF506.DB
c:\program files\SpywareDetector\Data\SDF507.DB
c:\program files\SpywareDetector\Data\SDF508.DB
c:\program files\SpywareDetector\Data\SDF509.DB
c:\program files\SpywareDetector\Data\SDF510.DB
c:\program files\SpywareDetector\Data\SDF512.DB
c:\program files\SpywareDetector\Data\SDF513.DB
c:\program files\SpywareDetector\Data\SDF514.DB
c:\program files\SpywareDetector\Data\SDF515.DB
c:\program files\SpywareDetector\Data\SDF516.DB
c:\program files\SpywareDetector\Data\SDF517.DB
c:\program files\SpywareDetector\Data\SDF518.DB
c:\program files\SpywareDetector\Data\SDF519.DB
c:\program files\SpywareDetector\Data\SDF520.DB
c:\program files\SpywareDetector\Data\SDF521.DB
c:\program files\SpywareDetector\Data\SDF522.DB
c:\program files\SpywareDetector\Data\SDF523.DB
c:\program files\SpywareDetector\Data\SDF524.DB
c:\program files\SpywareDetector\Data\SDF525.DB
c:\program files\SpywareDetector\Data\SDF526.DB
c:\program files\SpywareDetector\Data\SDF527.DB
c:\program files\SpywareDetector\Data\SDF528.DB
c:\program files\SpywareDetector\Data\SDF529.DB
c:\program files\SpywareDetector\Data\SDF530.DB
c:\program files\SpywareDetector\Data\SDF531.DB
c:\program files\SpywareDetector\Data\SDF532.DB
c:\program files\SpywareDetector\Data\SDF533.DB
c:\program files\SpywareDetector\Data\SDF534.DB
c:\program files\SpywareDetector\Data\SDF535.DB
c:\program files\SpywareDetector\Data\SDF536.DB
c:\program files\SpywareDetector\Data\SDF537.DB
c:\program files\SpywareDetector\Data\SDF538.DB
c:\program files\SpywareDetector\Data\SDF539.DB
c:\program files\SpywareDetector\Data\SDF540.DB
c:\program files\SpywareDetector\Data\SDF541.DB
c:\program files\SpywareDetector\Data\SDF542.DB
c:\program files\SpywareDetector\Data\SDF543.DB
c:\program files\SpywareDetector\Data\SDINFO.DB
c:\program files\SpywareDetector\Data\SDK10.DB
c:\program files\SpywareDetector\Data\SDK12.DB
c:\program files\SpywareDetector\Data\SDK13.DB
c:\program files\SpywareDetector\Data\SDK14.DB
c:\program files\SpywareDetector\Data\SDK15.DB
c:\program files\SpywareDetector\Data\SDK16.DB
c:\program files\SpywareDetector\Data\SDK17.DB
c:\program files\SpywareDetector\Data\SDK20.DB
c:\program files\SpywareDetector\Data\SDK21.DB
c:\program files\SpywareDetector\Data\SDK30.DB
c:\program files\SpywareDetector\Data\SDK31.DB
c:\program files\SpywareDetector\Data\SDK32.DB
c:\program files\SpywareDetector\Data\SDK33.DB
c:\program files\SpywareDetector\Data\SDK34.DB
c:\program files\SpywareDetector\Data\SDK35.DB
c:\program files\SpywareDetector\Data\SDk36.DB
c:\program files\SpywareDetector\Data\SDk37.DB
c:\program files\SpywareDetector\Data\SDk38.DB
c:\program files\SpywareDetector\Data\SDK42.DB
c:\program files\SpywareDetector\Data\SDK43.DB
c:\program files\SpywareDetector\Data\SDK9.DB
c:\program files\SpywareDetector\Data\sdn.db
c:\program files\SpywareDetector\Data\SDR1.DB
c:\program files\SpywareDetector\Data\SDR2.DB
c:\program files\SpywareDetector\Data\SDR3.DB
c:\program files\SpywareDetector\Data\SDS1.DB
c:\program files\SpywareDetector\Data\SDS2.DB
c:\program files\SpywareDetector\Data\SDV.DB
c:\program files\SpywareDetector\Data\SDV10.DB
c:\program files\SpywareDetector\Data\SDV11.DB
c:\program files\SpywareDetector\Data\SDv13.DB
c:\program files\SpywareDetector\Data\SDv15.DB
c:\program files\SpywareDetector\Data\SDv16.DB
c:\program files\SpywareDetector\Data\SDv17.DB
c:\program files\SpywareDetector\Data\SDv18.DB
c:\program files\SpywareDetector\Data\SDv19.DB
c:\program files\SpywareDetector\Data\SDv20.DB
c:\program files\SpywareDetector\Data\SDv25.DB
c:\program files\SpywareDetector\Data\SDv30.DB
c:\program files\SpywareDetector\Data\SDv32.DB
c:\program files\SpywareDetector\Data\SDv36.DB
c:\program files\SpywareDetector\Data\SDv37.DB
c:\program files\SpywareDetector\Data\SDV38.DB
c:\program files\SpywareDetector\Data\SDV9.DB
c:\program files\SpywareDetector\Data\SDVS1.DB
c:\program files\SpywareDetector\Data\SDVS2.DB
c:\program files\SpywareDetector\Data\SDVS3.DB
c:\program files\SpywareDetector\Data\SDVS4.DB
c:\program files\SpywareDetector\Data\SDVS5.DB
c:\program files\SpywareDetector\Data\SDVS6.DB
c:\program files\SpywareDetector\Data\SDVS7.DB
c:\program files\SpywareDetector\Data\SDVS8.DB
c:\program files\SpywareDetector\Data\SDWA.DB
c:\program files\SpywareDetector\Data\SDWH.db
c:\program files\SpywareDetector\Data\SDWK.db
c:\program files\SpywareDetector\Data\SDWN.DB
c:\program files\SpywareDetector\Data\SDWS.DB
c:\program files\SpywareDetector\Data\SM1.db
c:\program files\SpywareDetector\Data\SM2.db
c:\program files\SpywareDetector\Data\Worms.ini
c:\program files\SpywareDetector\DisasmEngineDll.dll
c:\program files\SpywareDetector\ExcludeDB.db
c:\program files\SpywareDetector\FileSignature.dll
c:\program files\SpywareDetector\HostDummy.ini
c:\program files\SpywareDetector\hostlistSD
c:\program files\SpywareDetector\HostListSD.ini
c:\program files\SpywareDetector\hosts.backup
c:\program files\SpywareDetector\Infolsp.dll
c:\program files\SpywareDetector\KeyLoggerHandler.dll
c:\program files\SpywareDetector\KeyLoggerScanner.dll
c:\program files\SpywareDetector\KeyLoggerScanner.exe
c:\program files\SpywareDetector\LiveUpdateSD.exe
c:\program files\SpywareDetector\Log.htm
c:\program files\SpywareDetector\Log\ExecSDLog.txt
c:\program files\SpywareDetector\Log\Export.txt
c:\program files\SpywareDetector\Log\MD5SDLog.txt
c:\program files\SpywareDetector\Log\RootKitLog.txt
c:\program files\SpywareDetector\Log\SDLiveupdateLog.txt
c:\program files\SpywareDetector\Log\SDLog.txt
c:\program files\SpywareDetector\Log\SplSpyLog.txt
c:\program files\SpywareDetector\Log\SystemLog.txt
c:\program files\SpywareDetector\Log\VoucherLog.txt
c:\program files\SpywareDetector\MainUI.gif
c:\program files\SpywareDetector\MAxNews.txt
c:\program files\SpywareDetector\News.txt
c:\program files\SpywareDetector\Option.dll
c:\program files\SpywareDetector\RestartTool.DLL
c:\program files\SpywareDetector\RestartTool.exe
c:\program files\SpywareDetector\ScannerExtension.exe
c:\program files\SpywareDetector\SDActiveMonitor.chm
c:\program files\SpywareDetector\SDActiveMonitor.exe
c:\program files\SpywareDetector\SDActMon.sys
c:\program files\SpywareDetector\SDActMon2K.sys
c:\program files\SpywareDetector\SDAntiRtKt.sys
c:\program files\SpywareDetector\SDEarlyDelete.log
c:\program files\SpywareDetector\SDLiveupdate\SDAdvScan.exe
c:\program files\SpywareDetector\SDLiveupdate\SDComplexSpy.exe
c:\program files\SpywareDetector\SDLiveupdate\SDDatabase.exe
c:\program files\SpywareDetector\SDLiveupdate\SDKeylogger.exe
c:\program files\SpywareDetector\SDLiveupdate\SDProduct.exe
c:\program files\SpywareDetector\SDLiveupdate\SDRootkit.exe
c:\program files\SpywareDetector\SDLiveupdate\SDVirus.exe
c:\program files\SpywareDetector\SDLiveupdate\ServerVersion.txt
c:\program files\SpywareDetector\SDMainService.exe
c:\program files\SpywareDetector\SDRemoveDB.db
c:\program files\SpywareDetector\SDRestrictedSites.ini
c:\program files\SpywareDetector\SDService.exe
c:\program files\SpywareDetector\SDSystemtray.chm
c:\program files\SpywareDetector\SDVirusScanner.dll
c:\program files\SpywareDetector\SDWormsToDelete.ini
c:\program files\SpywareDetector\SendReport.exe
c:\program files\SpywareDetector\Setting\blockActivex.reg
c:\program files\SpywareDetector\Setting\CurrentSettings.ini
c:\program files\SpywareDetector\Setting\English_Strings.ini
c:\program files\SpywareDetector\Setting\exe.dat
c:\program files\SpywareDetector\Setting\exefile.dat
c:\program files\SpywareDetector\Setting\Export.ini
c:\program files\SpywareDetector\Setting\HostDummy.ini
c:\program files\SpywareDetector\Setting\hostInsert.ini
c:\program files\SpywareDetector\Setting\Restricted.reg
c:\program files\SpywareDetector\Setting\RootKitWhiteDB.ini
c:\program files\SpywareDetector\Setting\SDWormsToDelete.ini
c:\program files\SpywareDetector\Setting\UnReg.reg
c:\program files\SpywareDetector\Setting\Voucher_English_Strings.ini
c:\program files\SpywareDetector\Setting\vssver.scc
c:\program files\SpywareDetector\Setting\WinsockBkp-Win2K.reg
c:\program files\SpywareDetector\Setting\WinsockBkp-Win98.reg
c:\program files\SpywareDetector\Setting\WinsockBkp-WinME.reg
c:\program files\SpywareDetector\Setting\WinsockBkp-WinVista.reg
c:\program files\SpywareDetector\Setting\WinsockBkp-WinXP.reg
c:\program files\SpywareDetector\Setting\WinsockBkp-WinXPHE.reg
c:\program files\SpywareDetector\Setting\wormcounts.ini
c:\program files\SpywareDetector\SignatureScanner.dll
c:\program files\SpywareDetector\SMTPDll.dll
c:\program files\SpywareDetector\SpecialSpyHandler.dll
c:\program files\SpywareDetector\SpywareDetector.chm
c:\program files\SpywareDetector\SpywareDetector.dll
c:\program files\SpywareDetector\SpywareDetector.exe
c:\program files\SpywareDetector\StartUpTipsDll.dll
c:\program files\SpywareDetector\Tips.txt
c:\program files\SpywareDetector\TrayPopUp.exe
c:\program files\SpywareDetector\ui_bg.jpg
c:\program files\SpywareDetector\unins000.dat
c:\program files\SpywareDetector\unins000.exe
c:\program files\SpywareDetector\UnReg.reg
c:\program files\SpywareDetector\VchReg.dll
c:\program files\SpywareDetector\Verinfo.ini
C:\wicnin.exe
c:\windows\Fsuya.bin
c:\windows\instsp2.exe
c:\windows\system32\drivers\UACd.sys
c:\windows\udusafuza.dll
c:\windows\Uqizoxihuvuwoxu.dat
c:\windows\wmsrary.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FADPU16E
-------\Legacy_SDMAINSVC
-------\Legacy_SDSERVICE
-------\Legacy_XDVA219
-------\Service_Fadpu16E
-------\Service_SDMainSvc
-------\Service_SDService
-------\Service_XDva219
((((((((((((((((((((((((( Files Created from 2009-03-05 to 2009-04-05 )))))))))))))))))))))))))))))))
.
2009-04-04 06:13 . 2009-04-04 06:14 <DIR> d-------- c:\program files\iTunes
2009-04-04 06:13 . 2009-04-04 06:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-04-04 06:10 . 2009-04-04 06:10 <DIR> d-------- c:\program files\Bonjour
2009-04-04 06:08 . 2009-04-04 06:09 <DIR> d-------- c:\program files\QuickTime
2009-03-29 06:08 . 2009-03-29 06:08 <DIR> d-------- c:\program files\Trend Micro
2009-03-28 14:00 . 2009-03-28 14:00 <DIR> d-------- c:\documents and settings\Tom\My desktop
2009-03-28 13:32 . 2009-03-28 13:32 <DIR> d-------- c:\documents and settings\Tom\Application Data\AVS4YOU
2009-03-28 13:32 . 2009-03-28 13:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-03-28 13:29 . 2009-03-28 13:31 <DIR> d-------- c:\program files\Common Files\AVSMedia
2009-03-28 13:29 . 2009-03-28 13:31 <DIR> d-------- c:\program files\AVS4YOU
2009-03-28 09:05 . 2009-03-28 09:05 <DIR> d-------- c:\documents and settings\Tom\Application Data\MSNInstaller
2009-03-28 08:59 . 2009-03-28 08:59 <DIR> d--h----- c:\windows\msdownld.tmp
2009-03-27 23:48 . 2009-04-04 23:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\Google Updater
2009-03-25 07:53 . 2009-03-25 07:53 <DIR> d-------- c:\documents and settings\Tom\Application Data\acccore
2009-03-25 07:47 . 2009-03-25 07:47 <DIR> d-------- c:\documents and settings\All Users\Application Data\acccore
2009-03-25 07:45 . 2009-03-25 07:49 <DIR> d-------- c:\program files\AIM6
2009-03-25 06:07 . 2009-04-05 10:15 <DIR> d-------- c:\documents and settings\Tom\Tracing
2009-03-25 06:06 . 2009-03-25 06:06 <DIR> d-------- c:\program files\Windows Live SkyDrive
2009-03-25 06:06 . 2009-03-25 06:06 <DIR> d-------- c:\program files\Windows Live
2009-03-25 06:06 . 2009-03-25 06:06 <DIR> d-------- c:\program files\Microsoft
2009-03-25 06:02 . 2009-03-25 06:02 <DIR> d-------- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-05 16:07 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-04-05 15:14 --------- d-----w c:\program files\SpiralFrog
2009-04-05 05:32 --------- d-----w c:\documents and settings\Tom\Application Data\FrostWire
2009-04-05 05:04 --------- d-----w c:\program files\Incomplete
2009-04-05 05:04 --------- d-----w c:\program files\FrostWire
2009-04-04 11:13 --------- d-----w c:\program files\iPod
2009-04-04 11:13 --------- d-----w c:\program files\Common Files\Apple
2009-03-31 11:25 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-03-28 09:54 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-28 09:54 --------- d-----w c:\program files\Electronic Arts
2009-03-28 09:52 --------- d-----w c:\program files\Google
2009-03-28 07:03 --------- d-----w c:\program files\Steam
2009-03-25 12:47 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2009-03-25 12:46 --------- d-----w c:\program files\Common Files\AOL
2009-03-06 05:33 --------- d-----w c:\documents and settings\Tom\Application Data\Apple Computer
2009-03-06 04:59 36,864 ----a-w c:\windows\system32\drivers\usbaapl.sys
2009-02-27 11:16 --------- d-----w c:\program files\Free iPod Video Converter
2009-02-27 11:15 --------- d-----w c:\program files\AviSynth 2.5
2009-02-27 10:35 --------- d-----w c:\program files\Cucusoft
2008-11-18 23:11 30 ----a-w c:\documents and settings\Tom\jagex_runescape_preferences.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-04-05_10.20.49.48 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2008-08-01 1103216]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2003-04-14 1491216]
"CurseClient"="c:\program files\Curse\CurseClient.exe" [2008-10-10 4789760]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-01-09 3321856]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-27 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2005-12-06 100056]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-24 49152]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-29 81920]
"SpiralFrog"="c:\program files\SpiralFrog\Spiralfrog.exe" [2007-12-18 163128]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"DVDtoiPodConverter_upgrade"="c:\program files\E-Zsoft\DVDtoiPodConverter\DVDtoiPodConverter.exe" [2008-11-02 900608]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-03-23 58992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-09-24 282624]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 73728]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
--a------ 2004-03-19 23:17 78960 c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2005-03-23 16:34 58992 c:\program files\Common Files\Symantec Shared\CCAPP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 20:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-06-29 00:43 8466432 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-06-29 00:43 81920 c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2009-01-05 16:18 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2003-11-01 04:42 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunKistEM]
--a------ 2004-03-11 17:18 135168 c:\program files\Digital Media Reader\shwiconEM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
--a------ 2005-12-06 16:45 100056 c:\progra~1\SYMNET~1\SNDMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
--a------ 2004-05-18 03:30 543232 c:\windows\zHotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nForce Tray Options]
--a------ 2003-09-03 03:25 73728 c:\windows\system32\sstray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-06-29 00:43 1626112 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowWnd]
--a------ 2003-09-19 18:09 36864 c:\windows\ShowWnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2003-08-15 09:34 57344 c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Blitz 1941 Global\\BlitzClient2.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Trend Micro\\HijackThis\\HijackThis.exe"=
"c:\\Program Files\\SpiralFrog\\Spiralfrog.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\iTunes\\iTunesHelper.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3274:TCP"= 3274:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-06-30 13352]
S3 SDActMon;SDActMon;\??\c:\program files\SpywareDetector\SDActMon.sys --> c:\program files\SpywareDetector\SDActMon.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-03-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-04-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-27 23:48]
2009-03-28 c:\windows\Tasks\Norton AntiVirus - Scan my computer - Tom.job
- c:\progra~1\NORTON~1\Navw32.exe [2005-10-19 13:54]
2009-03-27 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
2008-05-21 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ask.com/?o=101676&l=dis
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
FF - ProfilePath - c:\documents and settings\Tom\Application Data\Mozilla\Firefox\Profiles\nu2737cn.default\
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np32dsw.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npnul32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPSFDMGR.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-05 11:16:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\docume~1\Tom\LOCALS~1\Temp\NEWF.tmp 7529 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1440936148-3481316508-1564428167-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:89,51,ff,54,16,83,7c,db,74,52,7b,1f,ea,66,f6,4b,e2,08,57,85,7a,2e,65,
94,46,d5,44,b2,2c,d6,57,5e,b2,99,ed,35,40,e4,ba,4d,9e,46,82,6e,b2,25,c6,ac,\
"??"=hex:6a,cf,f8,a0,ac,2e,aa,62,23,d2,da,b5,c0,7b,9f,67
[HKEY_USERS\S-1-5-21-1440936148-3481316508-1564428167-1006\Software\SecuROM\License information*]
"datasecu"=hex:fb,be,68,4a,1e,ef,da,93,13,89,07,ab,46,a5,5d,d6,14,a4,91,3c,e1,
99,78,6d,a2,7f,c8,d1,a2,e1,93,08,25,e6,6f,c9,bd,bf,be,b0,20,35,bf,19,e3,ac,\
"rkeysecu"=hex:3a,70,83,d9,1a,bd,0e,1a,ed,c1,d2,a7,fe,a6,18,32
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(628)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Symantec Shared\CCSETMGR.EXE
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Symantec Shared\CCEVTMGR.EXE
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Norton AntiVirus\IWP\NPFMNTOR.EXE
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\system32\slserv.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\windows\system32\msiexec.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2009-04-05 11:24:58 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-05 16:24:44
ComboFix2.txt 2009-04-05 15:22:35
Pre-Run: 44,957,548,544 bytes free
Post-Run: 44,880,457,728 bytes free
551 --- E O F --- 2008-10-24 03:30:59