combofix log
ComboFix 10-01-04.01 - Double J 01/11/2010 7:37.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1982.1124 [GMT -6:00]
Running from: c:\users\Double J\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-12-11 to 2010-01-11 )))))))))))))))))))))))))))))))
.
2010-01-11 13:44 . 2010-01-11 13:44 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-01-11 13:44 . 2010-01-11 13:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-09 19:20 . 2010-01-09 19:20 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-01-09 19:00 . 2010-01-09 19:00 -------- d-----w- C:\_OTM
2010-01-09 01:06 . 2010-01-09 01:06 -------- d-----w- c:\users\Double J\AppData\Roaming\GTek
2010-01-08 17:31 . 2010-01-08 17:31 -------- d-----w- c:\program files\ESET
2010-01-08 15:48 . 2010-01-08 15:48 -------- d-----w- c:\program files\Trend Micro
2010-01-08 15:34 . 2010-01-08 15:34 -------- d-----w- c:\users\Double J\AppData\Roaming\Malwarebytes
2010-01-08 15:34 . 2010-01-07 22:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-08 15:34 . 2010-01-08 15:34 -------- d-----w- c:\programdata\Malwarebytes
2010-01-08 15:34 . 2010-01-07 22:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-08 13:54 . 2010-01-11 13:44 -------- d-----w- c:\users\Double J\AppData\Local\temp
2010-01-04 16:02 . 2010-01-08 15:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-03 22:06 . 2010-01-03 22:06 -------- d-----w- c:\users\Double J\AppData\Local\MigWiz
2010-01-03 15:28 . 2010-01-03 15:28 -------- d-----w- C:\e87c46291dbb65d8e7
2010-01-03 13:29 . 2010-01-03 13:29 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-01-03 13:27 . 2010-01-03 13:27 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-01-03 09:02 . 2010-01-03 09:02 -------- d-----w- c:\programdata\HP Product Assistant
2010-01-03 06:21 . 2010-01-03 06:21 -------- d-----w- c:\users\Double J\AppData\Roaming\AVG8
2009-12-31 21:34 . 2009-12-31 21:34 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-16 13:20 . 2009-12-16 13:20 -------- d-----w- c:\programdata\Norton
2009-12-12 18:19 . 2009-11-09 13:22 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-12 18:19 . 2009-11-09 13:20 31232 ----a-w- c:\windows\system32\httpapi.dll
2009-12-12 18:19 . 2009-11-09 11:04 411136 ----a-w- c:\windows\system32\drivers\http.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-11 02:27 . 2008-03-16 16:23 32530 ----a-w- c:\users\Double J\AppData\Roaming\nvModes.dat
2010-01-10 21:43 . 2008-03-16 16:15 92504 ----a-w- c:\users\Double J\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-09 19:05 . 2007-06-14 18:01 -------- d-----w- c:\programdata\Microsoft Help
2010-01-09 19:03 . 2007-06-14 17:59 -------- d-----w- c:\program files\Microsoft Works
2010-01-08 22:32 . 2007-06-14 17:42 -------- d-----w- c:\programdata\Symantec
2010-01-08 22:32 . 2007-06-14 17:42 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-08 02:17 . 2008-03-26 00:03 -------- d-----w- c:\program files\iWin Games
2010-01-08 01:54 . 2008-03-17 01:48 1356 ----a-w- c:\users\Double J\AppData\Local\d3d9caps.dat
2010-01-03 10:21 . 2007-06-14 17:14 -------- d-----w- c:\program files\Hewlett-Packard
2010-01-03 09:58 . 2007-06-14 19:09 -------- d-----w- c:\programdata\Hewlett-Packard
2010-01-03 09:38 . 2008-03-26 00:07 -------- d-----w- c:\programdata\PopCap Games
2010-01-03 09:36 . 2007-06-14 18:28 -------- d-----w- c:\program files\Yahoo!
2010-01-03 09:30 . 2007-06-14 17:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-03 09:27 . 2007-06-14 18:48 -------- d-----w- c:\program files\Vongo
2010-01-03 09:24 . 2008-03-16 16:04 -------- d-----w- c:\users\Double J\AppData\Roaming\Hewlett-Packard
2009-12-11 21:12 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-11-21 06:40 . 2009-12-10 22:02 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-10 22:02 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-10 22:02 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-10 22:02 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-03 02:42 . 2009-10-12 21:53 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:41 . 2009-12-07 01:34 2048 ----a-w- c:\windows\system32\tzres.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 2153472]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-03-20 1773568]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 3784704]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-03-29 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-21 149280]
"CognizanceTS"="c:\progra~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll" [2003-12-22 17920]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2008-08-02 675840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-02-26 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-26 7770112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-26 81920]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-14 1048392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
c:\users\Double J\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\APSHook.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2006-09-26 00:52 50736 ----a-w- c:\program files\Common Files\AOL\1210902539\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
2007-10-03 21:15 480560 ----a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=""
"FirewallOverride"=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Cognizance [11/9/2008 8:58 PM 21504]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [11/9/2008 8:58 PM 21504]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [6/18/2009 6:48 PM 42480]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker ASChannel
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-ALUAlert - c:\program files\Symantec\LiveUpdate\ALuNotify.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-11 07:44
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\users\DOUBLE~1\AppData\Local\Temp\catchme.dll 53248 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(4716)
c:\windows\system32\APSHook.dll
c:\program files\Bioscrypt\VeriSoft\Bin\ItClient.dll
.
Completion time: 2010-01-11 07:46:43
ComboFix-quarantined-files.txt 2010-01-11 13:46
Pre-Run: 174,361,571,328 bytes free
Post-Run: 174,351,241,216 bytes free
- - End Of File - - F4633D51A571DA4BAF772B584345F4FB