ComboFix 09-06-17.02 - jeff cohen 06/18/2009 4:13.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.206 [GMT -5:00]
Running from: c:\documents and settings\jeff cohen\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\jeff cohen\Application Data\PCTurbo Pro Free
c:\windows\system32\drivers\SKYNETiqltlwbr.sys
c:\windows\system32\SKYNETcxevmejp.dat
c:\windows\system32\SKYNETktuwykll.dat
c:\windows\system32\SKYNETsntihful.dll
c:\windows\system32\SKYNETxbnmpxft.dll
c:\documents and settings\jeff cohen\Application Data\PCTurbo Pro Free\Logs\update.log
c:\documents and settings\jeff cohen\err.log
c:\documents and settings\jeff cohen\ResErrors.log
c:\windows\system32\drivers\SKYNETiqltlwbr.sys
c:\windows\system32\SKYNETcxevmejp.dat
c:\windows\system32\SKYNETktuwykll.dat
c:\windows\system32\SKYNETsntihful.dll
c:\windows\system32\SKYNETxbnmpxft.dll
F:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETltfqhbos
-------\Legacy_PODMENA
-------\Legacy_PODMENADRV
((((((((((((((((((((((((( Files Created from 2009-05-18 to 2009-06-18 )))))))))))))))))))))))))))))))
.
2009-06-18 04:14 . 2009-06-18 04:15 -------- d-----w- c:\program files\QuickTime
2009-06-18 04:14 . 2009-06-18 04:14 -------- d-----w- c:\documents and settings\jeff cohen\Local Settings\Application Data\Apple
2009-06-18 04:14 . 2009-06-18 04:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-06-16 18:54 . 2009-06-16 18:54 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\BVRP Software
2009-06-16 16:55 . 2009-06-16 16:55 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\DivX
2009-06-12 18:30 . 2009-06-12 22:31 -------- d-----w- c:\documents and settings\All Users\Application Data\94530306
2009-06-12 18:30 . 2009-06-12 22:31 -------- d-----w- c:\documents and settings\All Users\Application Data\14520314
2009-06-08 14:16 . 2009-06-08 15:57 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\vlc
2009-06-08 14:15 . 2009-06-08 14:15 -------- d-----w- c:\program files\VideoLAN
2009-06-01 12:45 . 2009-06-01 12:45 -------- d-----w- c:\program files\MSXML 4.0
2009-05-31 21:02 . 2009-05-31 21:02 3371383 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-31 11:39 . 2009-05-31 11:39 -------- d-----w- c:\documents and settings\jeff cohen\Local Settings\Application Data\PowerDVD
2009-05-31 01:11 . 2004-08-17 00:40 16384 ----a-w- c:\windows\system32\FileOps.exe
2009-05-31 01:11 . 2009-05-31 01:11 -------- d-----w- c:\windows\system32\Adobe
2009-05-31 00:54 . 2009-05-31 00:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Adobe Systems
2009-05-31 00:51 . 2009-05-31 00:51 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2009-05-30 22:20 . 2009-06-01 07:43 -------- d-----w- c:\documents and settings\jeff cohen\Local Settings\Application Data\Ahead
2009-05-30 22:19 . 2009-05-31 11:39 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\Ahead
2009-05-30 22:18 . 2009-05-30 22:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Ahead
2009-05-30 22:16 . 2009-05-30 22:18 -------- d-----w- c:\program files\Common Files\Ahead
2009-05-30 22:16 . 2009-05-30 22:16 -------- d-----w- c:\program files\Nero
2009-05-30 22:16 . 2009-05-30 22:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-18 04:14 . 2007-05-04 17:46 -------- d-----w- c:\program files\Apple Software Update
2009-06-16 17:07 . 2009-04-27 10:21 -------- d-----w- c:\program files\DivX
2009-06-16 16:51 . 2009-04-27 10:21 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-05-31 21:02 . 2009-04-22 06:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-31 11:38 . 2004-08-31 21:55 48808 -c--a-w- c:\documents and settings\jeff cohen\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-31 02:05 . 2004-07-23 06:47 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-31 01:21 . 2004-10-05 19:26 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-28 03:49 . 2009-04-28 11:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Soulseek
2009-05-26 18:20 . 2009-04-22 06:59 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 18:19 . 2009-04-22 06:59 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-11 02:51 . 2009-05-11 02:51 -------- d-----w- c:\program files\Hero Editor
2009-05-11 02:50 . 2009-05-11 02:50 249856 ------w- c:\windows\Setup1.exe
2009-05-11 02:50 . 2009-05-11 02:50 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-05-10 10:48 . 2009-04-23 08:39 -------- d-----w- c:\program files\DAEMON Tools Pro
2009-05-10 10:44 . 2009-05-10 10:40 31361 ----a-w- c:\windows\DIIUnin.dat
2009-05-10 10:40 . 2009-05-10 10:40 94208 ----a-w- c:\windows\DIIUnin.exe
2009-05-10 10:40 . 2009-05-10 10:40 2829 ----a-w- c:\windows\DIIUnin.pif
2009-05-10 10:23 . 2009-05-10 10:23 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2009-05-10 10:20 . 2009-05-10 09:41 -------- d-----w- c:\program files\ATI Technologies
2009-05-10 10:12 . 2009-05-10 10:12 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\ATI
2009-05-10 10:09 . 2009-05-10 10:09 0 ----a-w- c:\windows\ativpsrm.bin
2009-05-10 09:58 . 2009-05-10 09:58 -------- d-----w- c:\program files\MSBuild
2009-05-10 09:58 . 2009-05-10 09:58 -------- d-----w- c:\program files\Reference Assemblies
2009-05-10 05:42 . 2009-05-10 05:42 -------- d-----w- c:\program files\SystemRequirementsLab
2009-05-10 05:42 . 2009-05-10 05:42 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\SystemRequirementsLab
2009-05-10 05:42 . 2009-05-10 05:42 207872 ----a-w- c:\documents and settings\jeff cohen\Application Data\SystemRequirementsLab\SRLProxy_srl_4.dll
2009-05-10 05:42 . 2009-05-10 05:42 207872 ----a-w- c:\documents and settings\jeff cohen\Application Data\SystemRequirementsLab\SRLProxy_srl_3.dll
2009-05-10 05:42 . 2009-05-10 05:42 207872 ----a-w- c:\documents and settings\jeff cohen\Application Data\SystemRequirementsLab\SRLProxy_srl_2.dll
2009-05-10 05:42 . 2009-05-10 05:42 207872 ----a-w- c:\documents and settings\jeff cohen\Application Data\SystemRequirementsLab\SRLProxy_srl_1.dll
2009-05-07 15:32 . 2002-08-29 10:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 10:25 . 2009-04-30 05:48 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\mIRC
2009-05-03 11:50 . 2009-04-23 08:16 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-03 11:50 . 2009-04-23 08:16 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-03 11:50 . 2009-04-23 08:16 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-03 11:50 . 2009-04-23 08:16 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-01 21:03 . 2004-11-22 01:24 120056 ------w- c:\windows\system32\pxcpyi64.exe
2009-05-01 21:03 . 2004-11-22 01:24 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-05-01 21:02 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll
2009-04-29 04:56 . 2006-06-23 16:33 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2009-04-22 08:14 78336 ------w- c:\windows\system32\ieencode.dll
2009-04-28 11:54 . 2009-04-28 11:54 -------- d-----w- c:\program files\SoulseekNS
2009-04-28 11:36 . 2009-04-28 11:36 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-28 11:36 . 2004-07-23 06:45 -------- d-----w- c:\program files\Java
2009-04-28 05:18 . 2009-04-28 05:18 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-04-27 09:19 . 2009-04-27 09:14 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\Winamp
2009-04-27 09:14 . 2009-04-27 09:14 -------- d-----w- c:\program files\Winamp
2009-04-24 10:34 . 2004-05-11 15:02 78699 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-04-23 08:41 . 2009-04-23 08:41 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2009-04-23 08:41 . 2009-04-23 08:41 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\DAEMON Tools Pro
2009-04-23 08:37 . 2004-07-23 06:51 -------- d-----w- c:\program files\Viewpoint
2009-04-23 08:35 . 2009-04-23 08:35 685816 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-04-23 08:21 . 2009-04-23 08:21 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\.BitTornado
2009-04-23 08:16 . 2009-04-23 08:16 -------- d-----w- c:\program files\AVG
2009-04-23 08:16 . 2009-04-23 08:16 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-04-23 08:13 . 2004-07-23 06:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-04-23 08:12 . 2004-07-23 06:50 -------- d-----w- c:\program files\Real
2009-04-22 20:39 . 2009-04-22 20:39 -------- d-----w- c:\program files\BitTornado
2009-04-22 19:11 . 2009-04-22 19:03 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\Smart PC Solutions
2009-04-22 19:03 . 2009-04-22 19:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-04-22 19:03 . 2009-04-22 19:03 -------- d-----w- c:\program files\Smart PC Solutions
2009-04-22 07:26 . 2004-07-23 06:23 -------- d-----w- c:\program files\Dell
2009-04-22 07:25 . 2006-08-08 23:43 -------- d-----w- c:\documents and settings\Guest\Application Data\Gtek
2009-04-22 07:25 . 2004-10-04 00:21 -------- d-----w- c:\program files\FinePixViewer
2009-04-22 07:25 . 2004-08-31 22:32 -------- d-----w- c:\program files\Canon
2009-04-22 07:22 . 2006-04-21 04:37 -------- d-----w- c:\program files\HP
2009-04-22 07:20 . 2004-07-23 06:54 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-04-22 07:20 . 2004-07-23 06:53 -------- d-----w- c:\program files\Jasc Software Inc
2009-04-22 07:19 . 2005-01-27 00:37 -------- d-----w- c:\program files\Mafia
2009-04-22 07:18 . 2006-07-27 04:13 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
2009-04-22 07:17 . 2007-07-31 04:19 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\Move Networks
2009-04-22 07:15 . 2005-05-17 04:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-22 07:14 . 2004-09-29 23:20 -------- d-----w- c:\program files\MSN Messenger
2009-04-22 06:59 . 2009-04-22 06:59 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\Malwarebytes
2009-04-22 06:59 . 2009-04-22 06:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-22 06:52 . 2004-07-23 06:50 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-04-22 06:50 . 2006-06-03 20:38 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-04-22 06:50 . 2004-10-12 04:32 -------- d-----w- c:\program files\Pure Networks
2009-04-22 06:50 . 2004-07-23 06:50 -------- d-----w- c:\program files\Common Files\AOL
2009-04-22 06:45 . 2004-10-06 20:02 -------- d-----w- c:\documents and settings\jeff cohen\Application Data\AOL
2009-04-22 06:32 . 2009-04-22 06:32 8854 ----a-r- c:\documents and settings\jeff cohen\Application Data\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\Uninstall_WD_Diagnos_0AB76F69E7614CFAB9B0A1906B4E9E4B.exe
2009-04-22 06:32 . 2009-04-22 06:32 40960 ----a-r- c:\documents and settings\jeff cohen\Application Data\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\WinDlg.exe_0AB76F69E7614CFAB9B0A1906B4E9E4B_3.exe
2009-04-22 06:32 . 2009-04-22 06:32 10134 ----a-r- c:\documents and settings\jeff cohen\Application Data\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\ARPPRODUCTICON.exe
2009-04-22 06:32 . 2009-04-22 06:32 -------- d-----w- c:\program files\Western Digital Technologies
2009-04-19 22:36 . 2009-04-19 22:36 -------- d-----w- c:\program files\Microsoft
2009-04-17 12:26 . 2003-07-15 21:01 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-03-06 02:16 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-02 20:55 . 2009-04-22 18:50 217088 ----a-w- c:\windows\system32\ConTest.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2005-08-15 18:03 . 2005-08-17 16:26 401408 --sh--r- c:\windows\SYSTEM32\?ti2evxx.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-04 405583]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-03-23 135168]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2002-09-11 368706]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 856064]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-03 1947928]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Kyrmcx"="c:\windows\System32\?ti2evxx.exe" [?]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2009-5-30 25214]
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-03 11:50 11952 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
backup=c:\windows\pss\AOL Companion.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aida
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Registry Cleaner
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TizzleTalk
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\mIRC\\mirc.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [4/23/2009 3:16 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [4/23/2009 3:16 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [4/23/2009 3:16 AM 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [4/23/2009 3:16 AM 298776]
S3 FXDRV;FXDRV;\??\d:\fxdrv.sys --> d:\Fxdrv.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-06-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2004-08-31 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\System32\OOBE\OOBEBALN.EXE [2002-08-29 00:12]
.
- - - - ORPHANS REMOVED - - - -
BHO-{91F69B5E-0DEC-0032-95D9-5A3027102190} - (no file)
HKU-Default-Run-Symantec NetDriver Warning - c:\progra~1\SYMNET~1\SNDWarn.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ask.com/?o=20011&l=dis
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=%s
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: &Search
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {A9DD5FE2-5567-4983-971F-C792375025A6} - hxxp://software.musicnow.com/musicnow/phoenix/4.0.0.34/MusicNow.cab
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-18 04:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(740)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\ati2evxx.exe
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\Intel\Intel Application Accelerator\IAANTmon.exe
c:\windows\SYSTEM32\HPZipm12.exe
c:\windows\SYSTEM32\wdfmgr.exe
c:\windows\wanmpsvc.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\acrobat_sl.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\SYSTEM32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-06-18 4:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-18 09:26
Pre-Run: 46,773,989,376 bytes free
Post-Run: 47,447,138,304 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
282 --- E O F --- 2009-06-11 20:19