ComboFix log
ComboFix 10-02-16.03 - Glenn 02/18/2010 3:58.6.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.639.340 [GMT -6:00]
Running from: c:\documents and settings\Glenn\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Glenn\Desktop\CFScript.txt
AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
FW: CA Personal Firewall *disabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
FILE ::
"c:\documents and settings\Glenn\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-16155449"
"c:\documents and settings\Glenn\Application Data\Sun\Java\Deployment\cache\6.0\23\40d74897-2d1586a6"
"c:\documents and settings\Glenn\Application Data\Sun\Java\Deployment\cache\6.0\57\4839f1b9-62981ccf"
"d:\data\My Documents\My Music\AGSetup0606.exe"
"d:\data\My Documents\My Music\BS226.exe"
"d:\data\My Documents\My Music\BS227.exe"
"d:\data\My Documents\My Music\bs230.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\data\BearShare
d:\data\BearShare\Extras\Bonzi.ico
d:\data\BearShare\Extras\CasinoOnNet.ico
d:\data\BearShare\Extras\fiveroses.ico
d:\data\BearShare\Extras\goldencomps.ico
d:\data\BearShare\Extras\onluck.ico
d:\data\BearShare\Extras\Sanity.ico
d:\data\BearShare\Extras\sports.ico
d:\data\BearShare\FreePeers.dat
d:\data\BearShare\FreePeers.ini
d:\data\BearShare\History.txt
d:\data\BearShare\Html\images\bsdcbtn.gif
d:\data\BearShare\Html\images\bsdlbtn.gif
d:\data\BearShare\Html\images\bsdnbtn.gif
d:\data\BearShare\Html\images\gfsnbtnb.gif
d:\data\BearShare\Html\images\gfsnbtnw.gif
d:\data\BearShare\Html\images\gwsb.gif
d:\data\BearShare\Html\images\gwsw.gif
d:\data\BearShare\Html\images\p.gif
d:\data\BearShare\Html\images\p0.gif
d:\data\BearShare\Html\images\p1.gif
d:\data\BearShare\Html\images\pb.gif
d:\data\BearShare\Html\images\vssver.scc
d:\data\BearShare\Html\index.htm
d:\data\BearShare\Html\vssver.scc
d:\data\BearShare\INSTALL.LOG
d:\data\BearShare\Log.txt
d:\data\BearShare\Shortcut to Downloads.lnk
d:\data\BearShare\Temp\(NSync) Bye Bye Bye.mp3
d:\data\BearShare\Temp\4841C07.tmp
d:\data\BearShare\Temp\Backstreet's Back! - Backstreet Boys.mp3
d:\data\BearShare\Temp\Britney Spears - Lucky.mp3
d:\data\BearShare\Temp\Christina Aguilera - Come O.mp3
d:\data\BearShare\Temp\City High -- Best Friends.mp3
d:\data\BearShare\Temp\country--Tracy Bird - Watermelon Crawl.mp3
d:\data\BearShare\Temp\Destiny's Child - Bug A Boo.mp3
d:\data\BearShare\Temp\Destiny's Child - Survivor - 06 - Apple Pie A La Mode.mp3
d:\data\BearShare\Temp\destiny's child - temptation.mp3
d:\data\BearShare\Temp\Divas Live 99 - 08 - brandy & faith hill - (everything i do) i do it for you.mp3
d:\data\BearShare\Temp\Dixie Chicks - 05 - Goodbye Earl.mp3
d:\data\BearShare\Temp\Dixie Chicks - Cowboy Take Me Away.mp3
d:\data\BearShare\Temp\Elvis Presley - A Fool Such As I.mp3
d:\data\BearShare\Temp\Elvis Presley - Burning Love.mp3
d:\data\BearShare\Temp\Elvis Presley - Don't.mp3
d:\data\BearShare\Temp\Elvis Presley - Fever.mp3
d:\data\BearShare\Temp\Elvis Presley - Follow That Dream .mp3
d:\data\BearShare\Temp\Elvis Presley - Good Luck Charm.mp3
d:\data\BearShare\Temp\Elvis Presley - I Forgot To Remember To Forget.mp3
d:\data\BearShare\Temp\Elvis Presley - I Want Tou, I Need You, I Love You.mp3
d:\data\BearShare\Temp\Elvis Presley - It's Now Or Never.mp3
d:\data\BearShare\Temp\Elvis Presley - My Way.mp3
d:\data\BearShare\Temp\Elvis Presley - Mystery Train.mp3
d:\data\BearShare\Temp\Elvis Presley - Oh What A Night.mp3
d:\data\BearShare\Temp\Elvis Presley - Only Fools Rush In.mp3
d:\data\BearShare\Temp\Elvis Presley - Shake, Rattle and Roll.mp3
d:\data\BearShare\Temp\Elvis Presley - Stuck On You.mp3
d:\data\BearShare\Temp\Elvis Presley - Teddy Bear.mp3
d:\data\BearShare\Temp\Elvis Presley - Whole Lotta Shakin Goin On.mp3
d:\data\BearShare\Temp\Elvis Presley - You Don't Know Me.mp3
d:\data\BearShare\Temp\Faith Hill - There You'll Be (Pearl Harbor Soundtrack).mp3
d:\data\BearShare\Temp\Faith Hill - There You'll Be.mp3
d:\data\BearShare\Temp\Faith Hill & Brandi - Everything I Do, I Do It For You (SPD).mp3
d:\data\BearShare\Temp\Frank Sinatra - America The Beautiful.mp3
d:\data\BearShare\Temp\George Strait - I Cross My Heart.mp3
d:\data\BearShare\Temp\George Strait & Frank Sinatra - Fly Me To The Moon.mp3
d:\data\BearShare\Temp\I'm Dreaming of a White Christmas - Bing Crosby.mp3
d:\data\BearShare\Temp\Incubus- Wish You Were Here.mp3
d:\data\BearShare\Temp\Incubus - I Wish You Were Here.mp3
d:\data\BearShare\Temp\Ja Rule feat. Christina Milian - Between Me And You (LP Version).mp3
d:\data\BearShare\Temp\Jamie O'Neal_Shiver_01_When I Think About Angels.mp3
d:\data\BearShare\Temp\Jessica Andrews - Who I Am .mp3
d:\data\BearShare\Temp\Jessica Simpson - Where You Are.MP3
d:\data\BearShare\Temp\Jo Dee Messina - Lesson In Leavin'.mp3
d:\data\BearShare\Temp\JODEE MESSINA - LESSONS IN LEAVING.MP3
d:\data\BearShare\Temp\Limp Bisket - Rollin.mp3
d:\data\BearShare\Temp\Limp Bizkit - 06 - Rollin.mp3
d:\data\BearShare\Temp\Limp Bizkit - My Way.mp3
d:\data\BearShare\Temp\Limp Bizkit - Rollin'.mp3
d:\data\BearShare\Temp\Lonestar-Amazed.mp3
d:\data\BearShare\Temp\Mandy More - Candy.mp3
d:\data\BearShare\Temp\Mark Wills - Loving Every Minute.mp3
d:\data\BearShare\Temp\Mark Wills - Permanently - 08 - Permanently.mp3.mp3
d:\data\BearShare\Temp\N'SYNC- Bye Bye Bye.mp3
d:\data\BearShare\Temp\Neal McCoy - Give Me That Wink.mp3
d:\data\BearShare\Temp\Nickelback - How You Remind Me.mp3
d:\data\BearShare\Temp\Nsync-01-Bye bye bye.mp3
d:\data\BearShare\Temp\Nsync-Bye Bye Bye.mp3
d:\data\BearShare\Temp\Nsync - ByeByeBye.mp3
d:\data\BearShare\Temp\NSync - Celebrity - 03 - The Game Is Over.mp3
d:\data\BearShare\Temp\Radiohead - National Anthem.mpg
d:\data\BearShare\Temp\Radiohead -03 STUDIO KID A- The National Anthem.mp3
d:\data\BearShare\Temp\Tim McGraw - I Like It I Love It.mp3
d:\data\BearShare\Temp\Tim McGraw - Indian Outlaw.mp3
d:\data\BearShare\Temp\Toby Keith - Blue Bedroom.mp3
d:\data\BearShare\Temp\Toby Keith - Do I Know You (Bottom Of My Heart).mp3
d:\data\BearShare\Temp\TRACY BIRD - WATERMELON CRAWL -1.mp3
d:\data\BearShare\Temp\Usher- You Remind Me.mp3
d:\data\BearShare\Temp\Usher - Nice and Slow.mp3
d:\data\BearShare\Temp\Usher - U Got It Bad.MP3
d:\data\BearShare\Temp\usher - You Got It Bad..mp3
d:\data\BearShare\Temp\Vitamin C - Graduation (Friends Forever).mp3
d:\data\BearShare\Temp\Walt Disney - I Wanna Be Like You (The Jungle Book).mp3
d:\data\BearShare\UNWISE.EXE
d:\data\BearShare\Webstats.bat
d:\data\BearShare\Webstats.exe
d:\data\BearShare\Webstats.ini
d:\data\My Documents\My Music\AGSetup0606.exe
d:\data\My Documents\My Music\BS226.exe
d:\data\My Documents\My Music\BS227.exe
d:\data\My Documents\My Music\bs230.exe
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\erdnt\cache\userinit.exe
.
original MBR restored successfully !
.
((((((((((((((((((((((((( Files Created from 2010-01-18 to 2010-02-18 )))))))))))))))))))))))))))))))
.
2010-02-14 22:45 . 2010-02-14 22:45 -------- d-----w- c:\program files\Common Files\Java
2010-02-14 22:45 . 2010-02-14 22:45 348160 ----a-w- c:\documents and settings\Glenn\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-1cfc7252-n\msvcr71.dll
2010-02-14 22:45 . 2010-02-14 22:45 503808 ----a-w- c:\documents and settings\Glenn\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-1cfc7252-n\msvcp71.dll
2010-02-14 22:45 . 2010-02-14 22:45 499712 ----a-w- c:\documents and settings\Glenn\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-1cfc7252-n\jmc.dll
2010-02-14 22:45 . 2010-02-14 22:45 61440 ----a-w- c:\documents and settings\Glenn\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6a0f079d-n\decora-sse.dll
2010-02-14 22:45 . 2010-02-14 22:45 12800 ----a-w- c:\documents and settings\Glenn\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6a0f079d-n\decora-d3d.dll
2010-02-14 21:46 . 2010-02-14 21:43 38784 ----a-w- c:\documents and settings\Glenn\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-14 21:46 . 2010-02-14 21:46 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-02-14 21:44 . 2010-02-14 21:43 38784 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-14 21:44 . 2010-02-14 21:44 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-02-14 21:42 . 2010-02-14 21:42 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-02-14 21:42 . 2010-02-14 22:09 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-02-13 23:23 . 2010-02-11 10:59 95360 -c--a-w- c:\windows\system32\dllcache\atapi.sys
2010-02-13 23:23 . 2010-02-11 10:59 95360 ------w- c:\windows\system32\drivers\atapi.sys
2010-02-13 23:23 . 2010-02-13 23:23 -------- d-----w- C:\8b2840f8c1146969fd4ecbf4
2010-01-23 12:36 . 2009-11-21 16:36 470528 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-23 11:34 . 2010-01-23 11:34 -------- d-----w- c:\windows\system32\wbem\Repository
2010-01-23 11:32 . 2010-01-23 11:32 -------- d-----w- c:\program files\iTunes
2010-01-23 11:32 . 2010-01-23 11:32 -------- d-----w- c:\program files\iPod
2010-01-23 11:22 . 2010-02-12 04:25 -------- d-----w- c:\program files\PlaySushi
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-18 10:22 . 2006-08-25 03:42 -------- d-----w- c:\program files\NovaNet-WEB Backup
2010-02-18 10:15 . 2008-07-18 22:52 74346 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2010-02-18 10:15 . 2008-07-18 22:52 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2010-02-18 10:15 . 2008-07-18 22:52 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2010-02-18 10:15 . 2008-07-18 22:52 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2010-02-18 10:15 . 2008-07-18 22:52 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2010-02-18 10:15 . 2008-07-18 22:52 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2010-02-18 10:15 . 2008-07-18 22:52 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2010-02-18 10:15 . 2008-07-18 22:52 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2010-02-14 22:44 . 2009-01-30 14:22 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-14 21:45 . 2006-08-29 01:49 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-12 06:44 . 2008-05-11 18:59 -------- d-----w- c:\program files\Coupons
2010-01-23 11:33 . 2010-01-02 09:53 -------- d-----w- c:\program files\QuickTime
2010-01-23 11:32 . 2010-01-12 02:59 -------- d-----w- c:\program files\iTunes(4)
2010-01-23 11:32 . 2010-01-12 03:00 -------- d-----w- c:\program files\iPod(4)
2010-01-23 11:32 . 2009-06-25 04:22 -------- d-----w- c:\program files\Common Files\Apple
2010-01-23 11:26 . 2009-12-10 08:44 -------- d-----w- c:\program files\QuickTime(3)
2010-01-23 11:25 . 2009-12-10 09:42 -------- d-----w- c:\program files\iPod(3)
2010-01-23 11:25 . 2009-12-10 09:41 -------- d-----w- c:\program files\iTunes(3)
2010-01-23 11:23 . 2009-12-21 20:50 -------- d-----w- c:\program files\QuickTime(4)
2010-01-16 09:27 . 2009-12-22 16:33 1786 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2010-01-06 11:00 . 2009-12-24 00:01 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-02 10:09 . 2009-10-13 13:49 739696 ----a-w- c:\windows\system32\drivers\vetefile.sys
2010-01-02 10:09 . 2010-01-02 10:09 133520 ----a-w- c:\windows\system32\drivers\veteboot.1
2010-01-02 10:09 . 2010-01-02 10:09 133520 ------w- c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\avrtdrv\veteboot.sys
2010-01-02 10:09 . 2008-07-19 05:44 32240 ----a-w- c:\windows\system32\drivers\vetmonnt.sys
2010-01-02 10:09 . 2008-07-19 05:44 21488 ----a-w- c:\windows\system32\drivers\vetfddnt.sys
2010-01-02 10:09 . 2008-07-19 05:44 21104 ----a-w- c:\windows\system32\drivers\vet-rec.sys
2010-01-02 10:09 . 2008-07-19 05:44 26352 ----a-w- c:\windows\system32\drivers\vet-filt.sys
2009-12-31 16:14 . 2006-09-27 17:30 352640 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:42 . 2006-09-27 17:31 662016 ------w- c:\windows\system32\wininet.dll
2009-12-22 05:42 . 2004-08-04 07:56 81920 ------w- c:\windows\system32\ieencode.dll
2009-12-16 12:58 . 2006-09-27 17:31 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2006-09-27 17:31 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:55 . 2006-09-27 17:30 2180352 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:19 . 2006-09-27 17:30 2057728 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 14:41 . 2006-09-27 17:31 453760 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:33 . 2006-09-27 17:31 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 17:33 . 2006-09-27 17:31 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 16:37 . 2006-09-27 17:32 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:37 . 2006-09-27 17:31 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:37 . 2006-09-27 17:31 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:37 . 2001-08-23 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:37 . 2001-08-17 22:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-21 16:36 . 2006-09-27 17:30 470528 ----a-w- c:\windows\AppPatch\aclayers.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-11-02 472632]
"gStart"="c:\garmin\gStart.exe" [2005-07-25 1896448]
"NvMediaCenter"="c:\windows\system32\NVMCTRAY.DLL" [2003-07-28 49152]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-25 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2003-07-28 323584]
"NovaNet-WEB Tray Control"="c:\program files\NovaNet-WEB Backup\TrayControl.exe" [2003-11-25 835584]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-07-31 177392]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2010-01-02 230664]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-08-03 259312]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-08-03 173296]
"cafwc"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-08-03 1193200]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-07-28 4841472]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 18:30 79368 ----a-w- c:\windows\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e\0stera
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [6/24/2008 6:08 PM 93712]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [6/24/2008 6:08 PM 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [6/24/2008 6:08 PM 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [6/24/2008 6:08 PM 115216]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [6/24/2008 6:08 PM 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [6/24/2008 6:08 PM 66576]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [10/18/2007 9:24 AM 1010192]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [10/18/2007 9:24 AM 801296]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [6/24/2008 6:10 PM 281104]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [6/24/2008 6:08 PM 88816]
R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [8/16/2007 8:10 PM 189704]
.
Contents of the 'Scheduled Tasks' folder
2010-02-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-01-10 c:\windows\Tasks\CAAntiSpywareScan_Daily as Glenn at 12 42 AM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-17 02:10]
2010-02-18 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-06 03:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://forums.spybot.info/showthread.php?t=55244&page=2
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - c:\program files\PlaySushi\PSText.dll
LSP: c:\windows\system32\VetRedir.dll
DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} - hxxp://offers.e-centives.com/cif/download/bin/actxcab.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-18 04:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(556)
c:\windows\system32\UmxWnp.Dll
c:\windows\system32\WRLogonNTF.dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
- - - - - - - > 'lsass.exe'(612)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
- - - - - - - > 'explorer.exe'(2664)
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\NovaNet-WEB Backup\BackupClientSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\WgaTray.exe
c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
c:\windows\system32\devldr32.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
c:\program files\CA\CA Internet Security Suite\ccprovsp.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\RUNDLL32.EXE
.
**************************************************************************
.
Completion time: 2010-02-18 04:31:53 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-18 10:31
ComboFix2.txt 2010-02-14 21:27
ComboFix3.txt 2010-02-14 00:06
ComboFix4.txt 2010-02-12 04:47
ComboFix5.txt 2010-02-18 09:13
Pre-Run: 55,251,070,976 bytes free
Post-Run: 54,921,732,096 bytes free
- - End Of File - - 24A0EF0468A8ECAA59ADF28D87829CB9