ComboFix 09-03-06.02 - jcartagena 2009-03-09 22:09:58.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1431 [GMT -4:00]
Running from: c:\documents and settings\jcartagena\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\jcartagena\Desktop\CFScript.txt
AV: Norton 360 *On-access scanning enabled* (Updated)
FW: Norton 360 *enabled*
FILE ::
c:\recycler\S-4-2-32-100016085-100004298-100016323-8498.com
c:\windows\ASSE.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\jcartagena\Application Data\uTorrent
c:\documents and settings\jcartagena\Application Data\uTorrent\[SALSA] Gilberto Santa Rosa Discografia.rar.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Akon - Freedom.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Billy Joel.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Bob Marley - Complete Discography From 1967 To 2002 [33 Full Albums] (Mp3 256Kbps).torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Bride Wars 2009 TELESYNC XviD-KingBen (Kingdom-Release).torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Britney Spears.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Daughtry - Daughtry [+Covers][320kbps][DeadPoetRIP]@H33T.com.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Destiny's Child.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\dht.dat
c:\documents and settings\jcartagena\Application Data\uTorrent\dht.dat.old
c:\documents and settings\jcartagena\Application Data\uTorrent\DMX Discography.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Dr. Dre Discography[9 Albums].torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Eminem-Discography-(23_Releases)-h8me.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Gang Starr.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Jay-Z - Brooklyn We Go Hard.mp3.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Jay Z Full Discography + Mixtape Albums + Mixtapes.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Justin Timberlake.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Kanye West - 808's and Heartbreak (2008) [Explicit].torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Katy Perry - One Of The Boys (2008).torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\LL Cool J - Discography (1985-2008).torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Madonna - Complete Discography.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Marc Anthony - El cantante [2007] [www.topetorrent.com].torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Mariah Carey - Discography- The Pirate Bay-.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Michael Jackson - Discography (320kbps).torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Mobb Deep Discography-((InfamousFlip.com)).torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Musiq Soulchild Discography.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\N.W.A - Complete Discography+2CD.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Nasir 'NaS' Jones - Complete Discography.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Pink (4 albums).torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\R. Kelly - Discography.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\resume.dat
c:\documents and settings\jcartagena\Application Data\uTorrent\resume.dat.old
c:\documents and settings\jcartagena\Application Data\uTorrent\rss.dat
c:\documents and settings\jcartagena\Application Data\uTorrent\rss.dat.old
c:\documents and settings\jcartagena\Application Data\uTorrent\Sara Bareilles - Little Voice (2007) - Pop.rar.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\settings.dat
c:\documents and settings\jcartagena\Application Data\uTorrent\settings.dat.old
c:\documents and settings\jcartagena\Application Data\uTorrent\The Dream - Love Hate (2007) - Bajenbob.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\The Very Best of Latin Jazz - Various Artists.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\The.Dark.Knight[2008]DvDrip-aXXo.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\U2 - Discography.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\U2 - No Line On The Horizon [mp3-vbr-2009].torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Vicky Christina Barcelona (2008) DVDSCR Occor avi.torrent
c:\documents and settings\jcartagena\Application Data\uTorrent\Wu-Tang Clan - discography (11 albums + Wu DVDRiP.XViD).torrent
c:\program files\AdWare SpyWare SE
c:\program files\AdWare SpyWare SE\AdWare SpyWare SE.exe
c:\program files\Soulseek
c:\program files\Soulseek\attrstrings.cfg
c:\program files\Soulseek\autoaway.cfg
c:\program files\Soulseek\chatrooms.cfg
c:\program files\Soulseek\chatui.cfg
c:\program files\Soulseek\dlbans.cfg
c:\program files\Soulseek\extensions.cfg
c:\program files\Soulseek\hotlist.cfg
c:\program files\Soulseek\ignores.cfg
c:\program files\Soulseek\login.cfg
c:\program files\Soulseek\pchat.cfg
c:\program files\Soulseek\port.cfg
c:\program files\Soulseek\queue.cfg
c:\program files\Soulseek\queue2.cfg
c:\program files\Soulseek\rcmnd.cfg
c:\program files\Soulseek\save.cfg
c:\program files\Soulseek\search.cfg
c:\program files\Soulseek\shared.cfg
c:\program files\Soulseek\ticker.cfg
c:\program files\Soulseek\transfersview.cfg
c:\program files\Soulseek\ui.cfg
c:\program files\Soulseek\userinfo.cfg
c:\program files\Soulseek\usernotes.cfg
c:\program files\Soulseek\wishlist.cfg
c:\windows\ASSE.dat
.
((((((((((((((((((((((((( Files Created from 2009-02-10 to 2009-03-10 )))))))))))))))))))))))))))))))
.
2009-03-09 03:00 . 2009-03-09 03:00 <DIR> d-------- c:\windows\LastGood
2009-03-08 11:29 . 2009-03-08 11:29 <DIR> d-------- c:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
2009-03-07 16:55 . 2009-03-07 16:55 <DIR> d-------- c:\documents and settings\administrator.LATINLEVEL\help
2009-03-07 09:21 . 2009-03-07 09:21 <DIR> d-------- c:\program files\ERUNT
2009-03-06 22:37 . 2009-03-06 22:37 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-03-06 22:26 . 2009-01-18 17:35 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-03-06 21:30 . 2009-03-06 21:30 <DIR> d-------- c:\program files\Lavasoft
2009-03-06 21:30 . 2009-03-06 21:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-06 21:21 . 2009-03-06 21:30 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-06 19:02 . 2009-03-06 19:37 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-03-06 19:00 . 2009-03-06 19:00 <DIR> d-------- c:\program files\Bazooka Scanner
2009-03-06 18:28 . 2009-03-06 18:28 <DIR> d-------- c:\documents and settings\administrator.LATINLEVEL\Application Data\Ipswitch
2009-03-06 00:09 . 2009-03-06 00:09 <DIR> d-------- c:\program files\DVD Flick
2009-03-06 00:09 . 2004-03-09 00:00 212,240 --a------ c:\windows\system32\richtx32.ocx
2009-03-06 00:09 . 2003-01-26 13:41 40,960 --a------ c:\windows\system32\ssubtmr6.dll
2009-03-06 00:09 . 2007-08-31 18:36 36,864 --a------ c:\windows\system32\trayicon_handler.ocx
2009-03-06 00:09 . 2008-08-31 13:27 28,672 --a------ c:\windows\system32\mousewheel.ocx
2009-03-05 21:30 . 2009-03-05 21:30 <DIR> d-------- c:\documents and settings\jcartagena\System
2009-03-05 21:30 . 2009-03-05 21:50 <DIR> d-------- c:\documents and settings\jcartagena\Application Data\SmartDraw
2009-03-05 21:15 . 2009-03-05 23:36 <DIR> d-------- c:\program files\SmartDraw 2009
2009-03-04 12:09 . 2009-03-04 12:09 <DIR> d-------- c:\documents and settings\msosa\Application Data\Research In Motion
2009-03-03 04:14 . 2009-01-09 15:19 1,089,593 -----c--- c:\windows\system32\dllcache\ntprint.cat
2009-03-02 13:25 . 2009-03-02 13:26 <DIR> d-------- C:\e57f3a77a9a4f97737f3afe19758
2009-03-02 13:19 . 2009-03-02 13:27 <DIR> d-------- C:\aa87e1352427f5d40209eb
2009-03-02 12:10 . 2009-03-02 12:10 <DIR> d-------- c:\documents and settings\msosa\Application Data\Symantec
2009-03-02 11:39 . 2009-03-08 11:29 <DIR> d-------- c:\program files\Symantec
2009-03-02 11:34 . 2009-03-08 11:30 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2009-03-02 11:32 . 2009-03-02 11:32 <DIR> d--hs---- c:\documents and settings\jcartagena\IECompatCache
2009-03-02 11:28 . 2009-03-02 11:28 <DIR> d--hs---- c:\documents and settings\jcartagena\IETldCache
2009-03-02 11:23 . 2009-03-02 12:41 <DIR> d-------- c:\documents and settings\jcartagena\Application Data\Symantec
2009-03-02 11:10 . 2009-03-02 11:50 <DIR> d-------- c:\windows\ie8updates
2009-03-02 11:08 . 2008-04-13 20:11 81,920 --a------ c:\windows\system32\ieencode.dll
2009-03-02 11:04 . 2009-01-11 01:00 79,360 -----c--- c:\windows\system32\dllcache\iecompat.dll
2009-03-02 10:44 . 2009-03-02 10:44 <DIR> d-------- c:\program files\Bonjour
2009-03-02 10:30 . 2009-03-02 10:31 <DIR> d-------- c:\program files\iTunes
2009-03-02 10:30 . 2009-03-02 10:30 <DIR> d-------- c:\program files\iPod
2009-03-02 10:30 . 2009-03-02 10:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-03-02 10:27 . 2009-03-02 10:27 <DIR> d-------- c:\program files\QuickTime
2009-03-02 10:13 . 2009-03-02 10:13 <DIR> d-------- c:\windows\system32\IOSUBSYS
2009-03-02 10:13 . 2009-03-02 10:13 86,908 --ah----- c:\windows\system32\mlfcache.dat
2009-03-02 09:49 . 2009-03-02 09:49 184 --a------ c:\windows\system32\brsvc01a.bsi
2009-03-02 09:49 . 2009-03-02 09:49 30 --a------ c:\windows\system32\brss01a.ini
2009-03-02 09:44 . 2009-03-06 07:52 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-02 09:40 . 2008-10-24 07:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-03-02 09:38 . 2008-09-04 13:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2009-03-02 09:34 . 2008-04-13 15:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2009-03-02 09:34 . 2008-04-13 15:47 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-10 01:54 --------- d-----w c:\program files\Common Files\Adobe
2009-03-10 01:48 --------- d-----w c:\program files\Java
2009-03-08 16:01 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2009-03-08 16:01 0 ----a-w c:\windows\system32\drivers\logiflt.iad
2009-03-08 15:50 --------- d-----w c:\program files\LogMeIn
2009-03-08 15:29 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-03-07 03:30 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-02 17:19 --------- d-----w c:\documents and settings\msosa\Application Data\Apple Computer
2009-03-02 15:26 --------- d-----w c:\program files\Microsoft Silverlight
2009-03-02 15:25 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-02 15:20 --------- d-----w c:\program files\Symantec AntiVirus
2009-03-02 14:36 --------- d-----w c:\program files\Safari
2009-03-02 14:30 --------- d-----w c:\program files\Common Files\Apple
2009-03-02 14:12 --------- d-----w c:\program files\Google
2009-03-02 14:00 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-25 02:55 --------- d-----w c:\program files\Belkin Bulldog Plus
2009-01-05 22:33 3,751,995 ----a-w c:\windows\system32\GPhotos.scr
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-12 16:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
2008-12-12 16:11 61,440 ----a-w c:\windows\system32\dnssd.dll
2008-01-03 01:45 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-07-31 17:21 81,920 ----a-w c:\documents and settings\Administrator\Application Data\ezpinst.exe
2007-07-31 17:21 47,360 ----a-w c:\documents and settings\Administrator\Application Data\pcouffin.sys
2008-09-03 19:14 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090320080904\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-03-08_12.06.49.62 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"H/PC Connection Agent"="c:\progra~1\MI3AA1~1\wcescomm.exe" [2006-06-20 1207080]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-01 68856]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
"DiskeeperSystray"="c:\program files\Executive Software\Diskeeper\DkIcon.exe" [2004-10-04 176216]
"UPS-Status"="c:\program files\Belkin Bulldog Plus\UPS-Status.exe" [2006-11-15 69632]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 63048]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Nitro PDF Printer Monitor"="c:\program files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe" [2008-03-05 210224]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-02-06 177472]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-11-04 615696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-09-19 236016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-18 506712]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-06 148888]
"CTHelper"="CTHELPER.EXE" [2006-12-12 c:\windows\system32\CtHelper.exe]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-12-12 c:\windows\system32\Ctxfihlp.exe]
c:\documents and settings\administrator.LATINLEVEL\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-16 20:35 87352 c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NavLogon]
[BU]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=c:\windows\pss\Windows Desktop Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^jcartagena^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\jcartagena\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
--a------ 2007-01-01 17:22 3739648 c:\program files\Google\Google Talk\googletalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 08:00 33648 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2004-09-13 15:49 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2009-01-06 14:06 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
--a------ 2007-10-25 17:37 2178832 c:\program files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando]
--a------ 2007-11-02 17:36 5223752 c:\program files\Pando Networks\Pando\pando.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2009-01-05 17:18 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-08-01 18:21 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-02-17 47640]
R3 Angel;Angel MPEG Device;c:\windows\system32\drivers\Angel.sys [2007-07-31 376320]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 921936]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [2007-08-03 12856]
S3 bepldr;BCL easyPDF SDK 5 Loader;c:\program files\Common Files\BCL Technologies\NitroPDF5\bepldr.exe [2007-11-15 151552]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4f10458f-3f86-11dc-955f-bc5ae248b5b9}]
\Shell\AutoRun\command - D:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-03-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 17:34]
2008-11-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-03-10 c:\windows\Tasks\SDMsgUpdate (TE).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2008-08-11 07:29]
2009-03-10 c:\windows\Tasks\User_Feed_Synchronization-{609DA143-9038-4A63-A95E-91FC9C1F8B31}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 19:36]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://1010wins.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: microsoft.com\update
DPF: Web-Based Email Tools - hxxp://email.secureserver.net/Download.CAB
DPF: {89242969-422B-46BF-B0D5-6A7B7DC4D0E0} - file:///C:/Documents%20and%20Settings/Administrator/Desktop/NASFinder-050809/html/nafcom.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-09 22:12:02
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1824872524-2195349826-2609249708-1156\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-1824872524-2195349826-2609249708-1156\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000004
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-1824872524-2195349826-2609249708-1156\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000003
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-1824872524-2195349826-2609249708-1156\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000002
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-1824872524-2195349826-2609249708-1156\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\Outlook]
"Name"="Outlook"
"DisplayName"="Microsoft Outlook"
"Param1"="Outlook"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000020
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(764)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-03-09 22:13:40
ComboFix-quarantined-files.txt 2009-03-10 02:13:37
ComboFix2.txt 2009-03-08 16:08:01
Pre-Run: 113,897,533,440 bytes free
Post-Run: 113,928,253,440 bytes free
354 --- E O F --- 2009-03-09 07:00:31