new Combofix logs
Here's the logs:
ComboFix 09-05-08.03 - Owner 05/13/2009 13:29.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2942.1810 [GMT -7:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
FW: Norton AntiVirus *enabled*
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\PCenter
c:\program files\PCenter\faq\guide.html
c:\program files\PCenter\faq\images\gimg1.jpg
c:\program files\PCenter\faq\images\gimg10.jpg
c:\program files\PCenter\faq\images\gimg2.jpg
c:\program files\PCenter\faq\images\gimg3.jpg
c:\program files\PCenter\faq\images\gimg4.jpg
c:\program files\PCenter\faq\images\gimg5.jpg
c:\program files\PCenter\faq\images\gimg6.jpg
c:\program files\PCenter\faq\images\gimg7.jpg
c:\program files\PCenter\faq\images\gimg8.jpg
c:\program files\PCenter\faq\images\gimg9.jpg
c:\program files\PCenter\sounds\1.mp3
c:\program files\PCenter\sounds\3.mp3
c:\program files\PCenter\tools\sc\ca.crt
c:\program files\PCenter\tools\sc\libeay32.dll
c:\program files\PCenter\tools\sc\libssl32.dll
c:\program files\PCenter\tools\sc\OemWin2k.inf
c:\program files\PCenter\tools\sc\openvpn.exe
c:\program files\PCenter\tools\sc\tap0801.sys
c:\program files\PCenter\tools\sc\tapinstall.exe
c:\program files\PCenter\uninstall.exe
c:\users\Owner\AppData\Roaming\PCenter
c:\users\Owner\AppData\Roaming\PCenter\dbases\cg.dat
c:\users\Owner\AppData\Roaming\PCenter\dbases\mw.dat
c:\users\Owner\AppData\Roaming\PCenter\dbases\rd.dat
c:\users\Owner\AppData\Roaming\PCenter\dbases\sc.dat
c:\users\Owner\AppData\Roaming\PCenter\dbases\sm.dat
c:\users\Owner\AppData\Roaming\PCenter\dbases\sp.dat
c:\users\Owner\AppData\Roaming\PCenter\keys\cg.key
c:\users\Owner\AppData\Roaming\PCenter\keys\rd.key
c:\users\Owner\AppData\Roaming\PCenter\keys\sc.key
c:\users\Owner\AppData\Roaming\PCenter\keys\sp.key
c:\users\Owner\AppData\Roaming\PCenter\temp\settings.ini
c:\users\Owner\AppData\Roaming\PCenter\temp\spfilter
.
((((((((((((((((((((((((( Files Created from 2009-04-13 to 2009-05-13 )))))))))))))))))))))))))))))))
.
2009-04-24 06:44 . 1998-10-29 23:45 306688 ----a-w c:\windows\IsUninst.exe
2009-04-22 03:15 . 2009-04-22 03:15 194560 ----a-w c:\windows\Word Whomp Whackdown Screen Saver #1.scr
2009-04-22 03:15 . 2009-04-22 03:15 -------- d-----w c:\windows\Word Whomp Whackdown Screen Saver #1 dir
2009-04-19 17:40 . 2009-04-19 17:40 -------- d-----w c:\program files\AC3Filter
2009-04-19 17:35 . 2009-04-23 19:09 -------- d-----w c:\users\Owner\Downloaded Apps
2009-04-16 12:37 . 2008-12-06 04:42 376832 ----a-w c:\windows\system32\winhttp.dll
2009-04-16 12:37 . 2008-06-06 03:27 562176 ----a-w c:\windows\system32\msdtcprx.dll
2009-04-16 12:37 . 2008-06-06 03:27 38912 ----a-w c:\windows\system32\xolehlp.dll
2009-04-16 04:27 . 2009-04-16 04:27 -------- d-----w c:\users\Owner\AppData\Roaming\WildTangentv1002
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-13 01:57 . 2008-03-30 19:29 15950 ----a-w c:\users\Owner\AppData\Roaming\wklnhst.dat
2009-04-27 20:53 . 2008-05-18 01:59 -------- d-----w c:\program files\913D Camera
2009-04-23 04:15 . 2007-11-10 05:53 -------- d-----w c:\program files\HP Games
2009-04-22 03:15 . 2009-04-06 00:05 606848 ----a-w c:\windows\flashax.exe
2009-04-22 03:15 . 2009-04-06 00:05 12288 ----a-w c:\windows\impborl.dll
2009-04-18 14:13 . 2008-07-21 19:51 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-16 23:22 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-04-06 00:05 . 2009-04-06 00:05 194560 ----a-w c:\windows\Club Pogo Badge Screen Saver #1.scr
2009-03-24 00:10 . 2008-03-25 02:02 -------- d-----w c:\program files\DivX
2009-03-24 00:09 . 2009-03-24 00:09 -------- d-----w c:\program files\Common Files\DivX Shared
2009-03-21 08:34 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstor.dat
2009-03-21 08:34 . 2006-11-02 10:25 51200 ----a-w c:\windows\inf\infpub.dat
2009-03-21 08:34 . 2006-11-02 10:25 143360 ----a-w c:\windows\inf\infstrng.dat
2009-03-20 18:29 . 2009-02-07 03:46 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-03-20 18:29 . 2009-02-07 03:46 7386 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-20 18:29 . 2009-02-07 03:46 124464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-20 18:29 . 2009-02-07 03:46 -------- d-----w c:\program files\Symantec
2009-03-17 03:38 . 2009-04-16 12:36 13824 ----a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 12:36 24064 ----a-w c:\windows\system32\amxread.dll
2009-03-03 04:46 . 2009-04-16 12:36 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-16 12:36 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:40 . 2009-04-16 12:36 827392 ----a-w c:\windows\system32\wininet.dll
2009-03-03 04:39 . 2009-04-16 12:36 183296 ----a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-16 12:36 551424 ----a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-16 12:36 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-16 12:36 78336 ----a-w c:\windows\system32\ieencode.dll
2009-03-03 04:37 . 2009-04-16 12:36 98304 ----a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-16 12:36 54784 ----a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-16 12:36 44032 ----a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-16 12:36 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-16 12:36 17408 ----a-w c:\windows\system32\iashost.exe
2009-03-03 02:28 . 2009-04-16 12:36 26624 ----a-w c:\windows\system32\ieUnatt.exe
2009-02-27 11:02 . 2009-02-07 03:46 25136 ----a-r c:\windows\system32\drivers\SymIMV.sys
2009-02-13 08:49 . 2009-04-16 12:36 72704 ----a-w c:\windows\system32\secur32.dll
2009-02-13 08:49 . 2009-04-16 12:36 1255936 ----a-w c:\windows\system32\lsasrv.dll
2008-11-27 07:50 . 2006-11-02 12:50 174 --sha-w c:\program files\desktop.ini
2008-03-23 01:19 . 2008-03-23 01:19 22 --sha-w c:\windows\SMINST\HPCD.sys
2007-11-10 05:06 . 2007-11-10 05:01 8192 --sha-w c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-05-09_22.14.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-01 06:43 . 2009-05-13 12:02 39479 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
+ 2007-11-10 05:28 . 2009-05-13 11:53 50812 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-05-13 11:53 65672 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-03-22 22:58 . 2009-05-13 11:53 10968 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2444741237-3818788396-3830472199-1000_UserData.bin
- 2008-03-22 22:58 . 2009-05-09 21:49 10968 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2444741237-3818788396-3830472199-1000_UserData.bin
- 2008-03-22 22:53 . 2009-05-09 21:58 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-03-22 22:53 . 2009-05-13 20:20 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-03-22 22:53 . 2009-05-09 21:58 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-22 22:53 . 2009-05-13 20:20 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-22 22:53 . 2009-05-13 20:20 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-03-22 22:53 . 2009-05-09 21:58 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-13 20:24 . 2009-05-09 22:24 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-13 20:24 . 2009-03-28 11:37 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-13 20:24 . 2009-03-28 11:37 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-13 20:24 . 2009-05-09 22:24 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-13 20:24 . 2009-05-09 22:24 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-04-13 20:24 . 2009-03-28 11:37 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-05-13 11:51 . 2009-05-13 11:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-09 21:47 . 2009-05-09 21:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-09 21:47 . 2009-05-09 21:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-13 11:51 . 2009-05-13 11:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2006-11-02 10:33 . 2009-05-09 21:52 595446 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-05-13 11:57 595446 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-05-09 21:52 101144 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-05-13 11:57 101144 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:22 . 2009-05-13 12:02 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2006-11-02 10:22 . 2009-05-01 06:44 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-05-13 20:28 . 2009-05-13 20:28 6299648 c:\windows\ERDNT\Hiv-backup\schema.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Power2GoExpress"="c:\program files\CyberLink\Power2Go\Power2GoExpress.exe" [2007-10-18 2503976]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-16 454784]
"PopUpStopperFreeEdition"="c:\program files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe" [2003-04-29 524288]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"<NO NAME>"="c:\program files\Internet Explorer\iexplore.exe" [2009-03-03 636072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\system32\msconfig.exe" [2008-01-19 227840]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-25 185896]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2008-07-24 1195640]
"QuickCare2.2"="c:\program files\Qwest\QuickCare\bin\sprtcmd.exe" [2007-05-04 198184]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-07-07 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-07 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-07 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-10-25 4702208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-10-09 44168]
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish Media Detector.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk
backup=c:\windows\pss\Snapfish Media Detector.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{94185F4F-8608-48D1-991D-806BCD12CB16}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{46CDC510-BBF9-45B8-A4E3-749D3D0BD37E}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{198093D5-5017-4AC7-8A1B-3F6D78423B0B}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{53EE0812-56F1-484B-9D99-82DB516C0CF0}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{6F9B64DB-D3A5-4358-A8C8-F0DEE0A4D92D}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{A8B3DDF2-8C4B-4F7A-AD4D-BD76871A99A5}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{1F772AE8-B359-4949-94C3-F694C5A4B998}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{14C77C92-4377-4EA2-AB1A-9933ED3FEEE7}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{FA100667-34A2-4E98-BE40-BEE15B5E19D0}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{472C0CAA-9108-454F-903B-E85877B57E1A}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{11F28107-5FDF-41BD-A7E2-BECE5EA84CF4}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D9001582-2EB9-4B7D-8D99-8AA6217AFBB3}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{48828088-1BA0-4F93-894B-FB251CBA69D0}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{CB96F9CC-B447-41BF-912B-D49A15E73236}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{04F86912-4363-4CD9-B743-FB13163DDF35}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{7324287F-1A89-47F2-875F-B65644D6B83B}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{DD29E2F4-EAB8-4F04-8898-2318773539C5}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{FA88474A-F418-47B1-AF1C-6AF330D54D47}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\NAV\1005000.086\SymEFA.sys [3/20/2009 11:29 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\NAV\1005000.086\BHDrvx86.sys [3/20/2009 11:29 AM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NAV\1005000.086\cchpx86.sys [3/20/2009 11:29 AM 482352]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090508.002\IDSvix86.sys [5/8/2009 2:10 PM 292912]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe [3/20/2009 11:29 AM 115560]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [7/21/2008 12:51 PM 1153368]
R2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\supportsoft\bin\sprtlisten.exe [1/8/2008 12:02 PM 1213728]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [4/23/2009 4:31 PM 101936]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\System32\drivers\HCW85BDA.sys [11/9/2007 10:36 PM 1129344]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\NAV\1005000.086\symndisv.sys [3/20/2009 11:29 AM 39984]
S3 SQTECH913D;913D Camera;c:\windows\System32\drivers\Capt913D.sys [5/17/2008 6:59 PM 29696]
.
Contents of the 'Scheduled Tasks' folder
2009-05-12 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-07-21 22:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.earthlink.net/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {775879E2-7309-4619-BB02-AADE41F4B690} - hxxp://webgames.d.tmsrv.com/c=c9a62cbbabb730e42a514859f23dce5f/aff=t_05kn1_wg/p/release/playfirst/wg_dreamchronicles/dreamchronicles/dreamweb.1.0.0.9.cab
DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} - hxxp://www.gamehouse.com/games/SpinTopGamesLauncher.cab
DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} - hxxp://www.gamehouse.com/games/JBGamePlayer.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game01.zylom.com/activex/zylomgamesplayer.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-13 13:31
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.5.0.134\diMaster.dll\" /prefetch:1"
.
Completion time: 2009-05-13 13:32
ComboFix-quarantined-files.txt 2009-05-13 20:32
ComboFix2.txt 2009-05-09 22:16
Pre-Run: 197,335,724,032 bytes free
Post-Run: 197,288,529,920 bytes free
238 --- E O F --- 2009-05-01 06:43
ComboFix 09-05-08.03 - Owner 05/13/2009 13:29.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2942.1810 [GMT -7:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
FW: Norton AntiVirus *enabled*
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\PCenter
c:\program files\PCenter\faq\guide.html
c:\program files\PCenter\faq\images\gimg1.jpg
c:\program files\PCenter\faq\images\gimg10.jpg
c:\program files\PCenter\faq\images\gimg2.jpg
c:\program files\PCenter\faq\images\gimg3.jpg
c:\program files\PCenter\faq\images\gimg4.jpg
c:\program files\PCenter\faq\images\gimg5.jpg
c:\program files\PCenter\faq\images\gimg6.jpg
c:\program files\PCenter\faq\images\gimg7.jpg
c:\program files\PCenter\faq\images\gimg8.jpg
c:\program files\PCenter\faq\images\gimg9.jpg
c:\program files\PCenter\sounds\1.mp3
c:\program files\PCenter\sounds\3.mp3
c:\program files\PCenter\tools\sc\ca.crt
c:\program files\PCenter\tools\sc\libeay32.dll
c:\program files\PCenter\tools\sc\libssl32.dll
c:\program files\PCenter\tools\sc\OemWin2k.inf
c:\program files\PCenter\tools\sc\openvpn.exe
c:\program files\PCenter\tools\sc\tap0801.sys
c:\program files\PCenter\tools\sc\tapinstall.exe
c:\program files\PCenter\uninstall.exe
c:\users\Owner\AppData\Roaming\PCenter
c:\users\Owner\AppData\Roaming\PCenter\dbases\cg.dat
c:\users\Owner\AppData\Roaming\PCenter\dbases\mw.dat
c:\users\Owner\AppData\Roaming\PCenter\dbases\rd.dat
c:\users\Owner\AppData\Roaming\PCenter\dbases\sc.dat
c:\users\Owner\AppData\Roaming\PCenter\dbases\sm.dat
c:\users\Owner\AppData\Roaming\PCenter\dbases\sp.dat
c:\users\Owner\AppData\Roaming\PCenter\keys\cg.key
c:\users\Owner\AppData\Roaming\PCenter\keys\rd.key
c:\users\Owner\AppData\Roaming\PCenter\keys\sc.key
c:\users\Owner\AppData\Roaming\PCenter\keys\sp.key
c:\users\Owner\AppData\Roaming\PCenter\temp\settings.ini
c:\users\Owner\AppData\Roaming\PCenter\temp\spfilter
.
((((((((((((((((((((((((( Files Created from 2009-04-13 to 2009-05-13 )))))))))))))))))))))))))))))))
.
2009-04-24 06:44 . 1998-10-29 23:45 306688 ----a-w c:\windows\IsUninst.exe
2009-04-22 03:15 . 2009-04-22 03:15 194560 ----a-w c:\windows\Word Whomp Whackdown Screen Saver #1.scr
2009-04-22 03:15 . 2009-04-22 03:15 -------- d-----w c:\windows\Word Whomp Whackdown Screen Saver #1 dir
2009-04-19 17:40 . 2009-04-19 17:40 -------- d-----w c:\program files\AC3Filter
2009-04-19 17:35 . 2009-04-23 19:09 -------- d-----w c:\users\Owner\Downloaded Apps
2009-04-16 12:37 . 2008-12-06 04:42 376832 ----a-w c:\windows\system32\winhttp.dll
2009-04-16 12:37 . 2008-06-06 03:27 562176 ----a-w c:\windows\system32\msdtcprx.dll
2009-04-16 12:37 . 2008-06-06 03:27 38912 ----a-w c:\windows\system32\xolehlp.dll
2009-04-16 04:27 . 2009-04-16 04:27 -------- d-----w c:\users\Owner\AppData\Roaming\WildTangentv1002
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-13 01:57 . 2008-03-30 19:29 15950 ----a-w c:\users\Owner\AppData\Roaming\wklnhst.dat
2009-04-27 20:53 . 2008-05-18 01:59 -------- d-----w c:\program files\913D Camera
2009-04-23 04:15 . 2007-11-10 05:53 -------- d-----w c:\program files\HP Games
2009-04-22 03:15 . 2009-04-06 00:05 606848 ----a-w c:\windows\flashax.exe
2009-04-22 03:15 . 2009-04-06 00:05 12288 ----a-w c:\windows\impborl.dll
2009-04-18 14:13 . 2008-07-21 19:51 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-16 23:22 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-04-06 00:05 . 2009-04-06 00:05 194560 ----a-w c:\windows\Club Pogo Badge Screen Saver #1.scr
2009-03-24 00:10 . 2008-03-25 02:02 -------- d-----w c:\program files\DivX
2009-03-24 00:09 . 2009-03-24 00:09 -------- d-----w c:\program files\Common Files\DivX Shared
2009-03-21 08:34 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstor.dat
2009-03-21 08:34 . 2006-11-02 10:25 51200 ----a-w c:\windows\inf\infpub.dat
2009-03-21 08:34 . 2006-11-02 10:25 143360 ----a-w c:\windows\inf\infstrng.dat
2009-03-20 18:29 . 2009-02-07 03:46 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-03-20 18:29 . 2009-02-07 03:46 7386 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-20 18:29 . 2009-02-07 03:46 124464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-20 18:29 . 2009-02-07 03:46 -------- d-----w c:\program files\Symantec
2009-03-17 03:38 . 2009-04-16 12:36 13824 ----a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 12:36 24064 ----a-w c:\windows\system32\amxread.dll
2009-03-03 04:46 . 2009-04-16 12:36 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-16 12:36 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:40 . 2009-04-16 12:36 827392 ----a-w c:\windows\system32\wininet.dll
2009-03-03 04:39 . 2009-04-16 12:36 183296 ----a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-16 12:36 551424 ----a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-16 12:36 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-16 12:36 78336 ----a-w c:\windows\system32\ieencode.dll
2009-03-03 04:37 . 2009-04-16 12:36 98304 ----a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-16 12:36 54784 ----a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-16 12:36 44032 ----a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-16 12:36 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-16 12:36 17408 ----a-w c:\windows\system32\iashost.exe
2009-03-03 02:28 . 2009-04-16 12:36 26624 ----a-w c:\windows\system32\ieUnatt.exe
2009-02-27 11:02 . 2009-02-07 03:46 25136 ----a-r c:\windows\system32\drivers\SymIMV.sys
2009-02-13 08:49 . 2009-04-16 12:36 72704 ----a-w c:\windows\system32\secur32.dll
2009-02-13 08:49 . 2009-04-16 12:36 1255936 ----a-w c:\windows\system32\lsasrv.dll
2008-11-27 07:50 . 2006-11-02 12:50 174 --sha-w c:\program files\desktop.ini
2008-03-23 01:19 . 2008-03-23 01:19 22 --sha-w c:\windows\SMINST\HPCD.sys
2007-11-10 05:06 . 2007-11-10 05:01 8192 --sha-w c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-05-09_22.14.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-01 06:43 . 2009-05-13 12:02 39479 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
+ 2007-11-10 05:28 . 2009-05-13 11:53 50812 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-05-13 11:53 65672 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-03-22 22:58 . 2009-05-13 11:53 10968 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2444741237-3818788396-3830472199-1000_UserData.bin
- 2008-03-22 22:58 . 2009-05-09 21:49 10968 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2444741237-3818788396-3830472199-1000_UserData.bin
- 2008-03-22 22:53 . 2009-05-09 21:58 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-03-22 22:53 . 2009-05-13 20:20 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-03-22 22:53 . 2009-05-09 21:58 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-22 22:53 . 2009-05-13 20:20 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-22 22:53 . 2009-05-13 20:20 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-03-22 22:53 . 2009-05-09 21:58 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-13 20:24 . 2009-05-09 22:24 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-13 20:24 . 2009-03-28 11:37 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-13 20:24 . 2009-03-28 11:37 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-13 20:24 . 2009-05-09 22:24 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-13 20:24 . 2009-05-09 22:24 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-04-13 20:24 . 2009-03-28 11:37 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-05-13 11:51 . 2009-05-13 11:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-09 21:47 . 2009-05-09 21:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-09 21:47 . 2009-05-09 21:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-13 11:51 . 2009-05-13 11:51 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2006-11-02 10:33 . 2009-05-09 21:52 595446 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-05-13 11:57 595446 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-05-09 21:52 101144 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-05-13 11:57 101144 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:22 . 2009-05-13 12:02 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2006-11-02 10:22 . 2009-05-01 06:44 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-05-13 20:28 . 2009-05-13 20:28 6299648 c:\windows\ERDNT\Hiv-backup\schema.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Power2GoExpress"="c:\program files\CyberLink\Power2Go\Power2GoExpress.exe" [2007-10-18 2503976]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-16 454784]
"PopUpStopperFreeEdition"="c:\program files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe" [2003-04-29 524288]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"<NO NAME>"="c:\program files\Internet Explorer\iexplore.exe" [2009-03-03 636072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\system32\msconfig.exe" [2008-01-19 227840]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-25 185896]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2008-07-24 1195640]
"QuickCare2.2"="c:\program files\Qwest\QuickCare\bin\sprtcmd.exe" [2007-05-04 198184]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-07-07 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-07 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-07 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-10-25 4702208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-10-09 44168]
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish Media Detector.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk
backup=c:\windows\pss\Snapfish Media Detector.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{94185F4F-8608-48D1-991D-806BCD12CB16}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{46CDC510-BBF9-45B8-A4E3-749D3D0BD37E}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{198093D5-5017-4AC7-8A1B-3F6D78423B0B}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{53EE0812-56F1-484B-9D99-82DB516C0CF0}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{6F9B64DB-D3A5-4358-A8C8-F0DEE0A4D92D}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{A8B3DDF2-8C4B-4F7A-AD4D-BD76871A99A5}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{1F772AE8-B359-4949-94C3-F694C5A4B998}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{14C77C92-4377-4EA2-AB1A-9933ED3FEEE7}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{FA100667-34A2-4E98-BE40-BEE15B5E19D0}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{472C0CAA-9108-454F-903B-E85877B57E1A}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{11F28107-5FDF-41BD-A7E2-BECE5EA84CF4}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D9001582-2EB9-4B7D-8D99-8AA6217AFBB3}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{48828088-1BA0-4F93-894B-FB251CBA69D0}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{CB96F9CC-B447-41BF-912B-D49A15E73236}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{04F86912-4363-4CD9-B743-FB13163DDF35}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{7324287F-1A89-47F2-875F-B65644D6B83B}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{DD29E2F4-EAB8-4F04-8898-2318773539C5}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{FA88474A-F418-47B1-AF1C-6AF330D54D47}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\NAV\1005000.086\SymEFA.sys [3/20/2009 11:29 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\NAV\1005000.086\BHDrvx86.sys [3/20/2009 11:29 AM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NAV\1005000.086\cchpx86.sys [3/20/2009 11:29 AM 482352]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090508.002\IDSvix86.sys [5/8/2009 2:10 PM 292912]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe [3/20/2009 11:29 AM 115560]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [7/21/2008 12:51 PM 1153368]
R2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\supportsoft\bin\sprtlisten.exe [1/8/2008 12:02 PM 1213728]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [4/23/2009 4:31 PM 101936]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\System32\drivers\HCW85BDA.sys [11/9/2007 10:36 PM 1129344]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\NAV\1005000.086\symndisv.sys [3/20/2009 11:29 AM 39984]
S3 SQTECH913D;913D Camera;c:\windows\System32\drivers\Capt913D.sys [5/17/2008 6:59 PM 29696]
.
Contents of the 'Scheduled Tasks' folder
2009-05-12 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-07-21 22:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.earthlink.net/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {775879E2-7309-4619-BB02-AADE41F4B690} - hxxp://webgames.d.tmsrv.com/c=c9a62cbbabb730e42a514859f23dce5f/aff=t_05kn1_wg/p/release/playfirst/wg_dreamchronicles/dreamchronicles/dreamweb.1.0.0.9.cab
DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} - hxxp://www.gamehouse.com/games/SpinTopGamesLauncher.cab
DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} - hxxp://www.gamehouse.com/games/JBGamePlayer.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game01.zylom.com/activex/zylomgamesplayer.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-13 13:31
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.5.0.134\diMaster.dll\" /prefetch:1"
.
Completion time: 2009-05-13 13:32
ComboFix-quarantined-files.txt 2009-05-13 20:32
ComboFix2.txt 2009-05-09 22:16
Pre-Run: 197,335,724,032 bytes free
Post-Run: 197,288,529,920 bytes free
238 --- E O F --- 2009-05-01 06:43
Working on the rest