I had my daughter download and run combofix. She ran it twice because the first time it was accidentally run from the USB flash device and the machine may have still been in safe mode. The second time it was run from C: and the machine was definitely in normal mode. Sorry if this makes anything more difficult to debug.
Note: She is still unable to access the internet and I don't know if that is due to damage to Windows, issues with her ISP or Malware.
----------------------------------------------------------------------------------------------------------------------------------------------------------
ComboFix Run 1:
ComboFix 09-03-31.01 - Compaq_Owner 2009-03-31 19:05:21.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.446.111 [GMT -6:00]
Running from: L:\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Outdated)
FW: Norton 360 *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
K:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-03-01 to 2009-04-01 )))))))))))))))))))))))))))))))
.
2009-03-27 12:47 . 2009-03-27 12:47 <DIR> d-------- c:\program files\Trend Micro
2009-03-26 23:31 . 2009-03-26 23:31 <DIR> d--hs---- c:\windows\ftpcache
2009-03-26 23:31 . 2009-03-26 23:31 917,504 --a------ c:\windows\system32\FLASH.OCX
2009-03-26 21:34 . 2001-08-31 12:00 27,296 --a------ c:\windows\system32\drivers\PERC2.SYS
2009-03-26 21:34 . 2001-08-31 12:00 27,296 --a------ c:\windows\system32\dllcache\perc2.sys
2009-03-26 21:34 . 2001-08-31 12:00 19,072 --a------ c:\windows\system32\drivers\SPARROW.SYS
2009-03-26 21:34 . 2001-08-31 12:00 19,072 --a------ c:\windows\system32\dllcache\sparrow.sys
2009-03-26 21:34 . 2001-08-31 12:00 17,280 --a------ c:\windows\system32\drivers\MRAID35X.SYS
2009-03-26 21:34 . 2001-08-31 12:00 17,280 --a------ c:\windows\system32\dllcache\mraid35x.sys
2009-03-26 21:34 . 2001-08-31 12:00 5,504 --a------ c:\windows\system32\drivers\PERC2HIB.SYS
2009-03-26 21:34 . 2001-08-31 12:00 5,504 --a------ c:\windows\system32\dllcache\perc2hib.sys
2009-03-26 21:33 . 2008-04-13 11:40 34,688 --a------ c:\windows\system32\drivers\lbrtfdc.sys
2009-03-26 21:33 . 2008-04-13 11:40 34,688 --a------ c:\windows\system32\dllcache\lbrtfdc.sys
2009-03-26 21:33 . 2008-04-13 11:41 18,560 --a------ c:\windows\system32\drivers\i2omp.sys
2009-03-26 21:33 . 2008-04-13 11:41 18,560 --a------ c:\windows\system32\dllcache\i2omp.sys
2009-03-26 21:33 . 2001-08-31 12:00 16,000 --a------ c:\windows\system32\drivers\INI910U.SYS
2009-03-26 21:33 . 2001-08-31 12:00 16,000 --a------ c:\windows\system32\dllcache\ini910u.sys
2009-03-26 21:33 . 2008-04-13 11:41 8,576 --a------ c:\windows\system32\drivers\i2omgmt.sys
2009-03-26 21:33 . 2008-04-13 11:41 8,576 --a------ c:\windows\system32\dllcache\i2omgmt.sys
2009-03-26 21:17 . 2004-08-03 22:00 18,304 --a------ c:\windows\system32\drivers\SYMC8XX.SY_
2009-03-26 21:17 . 2004-08-03 22:00 15,864 --a------ c:\windows\system32\drivers\ULTRA.SY_
2009-03-26 21:17 . 2004-08-03 22:00 2,629 --a------ c:\windows\system32\drivers\TOSIDE.SY_
2009-03-26 21:16 . 2004-08-03 22:00 17,923 --a------ c:\windows\system32\drivers\SYM_U3.SY_
2009-03-26 21:16 . 2004-08-03 22:00 16,761 --a------ c:\windows\system32\drivers\SYM_HI.SY_
2009-03-26 21:16 . 2004-08-03 22:00 11,098 --a------ c:\windows\system32\drivers\SPARROW.SY_
2009-03-26 21:16 . 2004-08-03 22:00 8,352 --a------ c:\windows\system32\drivers\SYMC810.SY_
2009-03-26 21:15 . 2004-08-03 22:00 27,359 --a------ c:\windows\system32\drivers\QL1280.SY_
2009-03-26 21:15 . 2004-08-03 22:00 22,855 --a------ c:\windows\system32\drivers\QL1240.SY_
2009-03-26 21:14 . 2004-08-03 22:00 25,938 --a------ c:\windows\system32\drivers\QL12160.SY_
2009-03-26 21:14 . 2004-08-03 22:00 22,761 --a------ c:\windows\system32\drivers\QL1080.SY_
2009-03-26 21:14 . 2004-08-03 22:00 18,888 --a------ c:\windows\system32\drivers\QL10WNT.SY_
2009-03-26 21:12 . 2004-08-03 22:00 9,785 --a------ c:\windows\system32\drivers\MRAID35X.SY_
2009-03-26 21:09 . 2004-08-03 22:00 14,614 --a------ c:\windows\system32\drivers\LBRTFDC.SY_
2009-03-26 21:09 . 2004-08-03 22:00 8,560 --a------ c:\windows\system32\drivers\INI910U.SY_
2009-03-26 21:08 . 2004-08-03 22:00 10,324 --a------ c:\windows\system32\drivers\I2OMP.SY_
2009-03-26 21:08 . 2004-08-03 22:00 4,064 --a------ c:\windows\system32\drivers\I2OMGMT.SY_
2009-03-26 20:58 . 2009-03-26 20:59 <DIR> d-------- c:\program files\PC-Doctor for Windows
2009-03-26 20:56 . 2009-03-26 20:56 <DIR> d-------- c:\program files\directx
2009-03-26 20:53 . 2009-03-26 20:53 <DIR> d-------- c:\program files\Support Tools
2009-03-26 20:49 . 2009-03-26 20:49 <DIR> d-------- c:\program files\Application Compatibility Toolkit
2009-03-26 20:30 . 2009-03-26 20:30 <DIR> d-------- c:\program files\AWS
2009-03-26 20:12 . 2009-03-26 20:12 <DIR> d-------- c:\program files\Common Files\xing shared
2009-03-26 20:01 . 2003-09-10 23:36 21,060 --------- c:\windows\system32\drivers\iviaspi.sys
2009-03-26 20:01 . 2003-09-19 01:47 10,368 --------- c:\windows\system32\drivers\pfc.sys
2009-03-26 20:00 . 2004-12-16 20:07 204,800 --a------ c:\windows\system32\IVIresizeW7.dll
2009-03-26 20:00 . 2004-12-16 20:07 200,704 --a------ c:\windows\system32\IVIresizeA6.dll
2009-03-26 20:00 . 2004-12-16 20:07 192,512 --a------ c:\windows\system32\IVIresizeP6.dll
2009-03-26 20:00 . 2004-12-16 20:07 192,512 --a------ c:\windows\system32\IVIresizeM6.dll
2009-03-26 20:00 . 2004-12-16 20:07 188,416 --a------ c:\windows\system32\IVIresizePX.dll
2009-03-26 20:00 . 2004-12-16 20:07 20,480 --a------ c:\windows\system32\IVIresize.dll
2009-03-26 19:58 . 2009-03-26 20:56 <DIR> d-------- c:\program files\InterVideo
2009-03-26 19:55 . 2009-03-26 19:55 <DIR> d-------- c:\program files\Macrovision Corp
2009-03-26 19:51 . 2009-03-26 19:51 <DIR> d-------- c:\program files\Common Files\Sonic
2009-03-26 19:51 . 2009-03-26 19:51 <DIR> d-------- c:\documents and settings\Compaq_Owner\Application Data\Sonic
2009-03-26 19:48 . 2009-03-26 19:48 <DIR> d-------- c:\program files\Common Files\SureThing Shared
2009-03-26 19:16 . 2009-03-26 19:16 <DIR> d-------- c:\documents and settings\Compaq_Owner\Application Data\InterMute
2009-03-26 19:15 . 2009-03-26 19:15 <DIR> d-------- c:\program files\InterMute
2009-03-26 19:15 . 2009-03-26 19:16 2,158 --a------ c:\windows\system32\ssmute.ini
2009-03-26 16:08 . 2004-01-28 10:11 159,744 -ra------ c:\windows\system32\nvuide.exe
2009-03-26 15:44 . 2002-08-29 14:00 25,952 --a------ c:\windows\system32\drivers\hpn.sys
2009-03-26 15:44 . 2002-08-29 14:00 25,952 --a------ c:\windows\system32\dllcache\hpn.sys
2009-03-26 15:43 . 2001-08-31 12:00 20,192 --a------ c:\windows\system32\drivers\dpti2o.sys
2009-03-26 15:43 . 2001-08-31 12:00 20,192 --a------ c:\windows\system32\dllcache\dpti2o.sys
2009-03-26 15:42 . 2001-08-31 12:00 14,976 --a------ c:\windows\system32\drivers\cpqarray.sys
2009-03-26 15:42 . 2001-08-31 12:00 14,976 --a------ c:\windows\system32\dllcache\cpqarray.sys
2009-03-26 15:42 . 2001-08-31 12:00 14,720 --a------ c:\windows\system32\drivers\dac960nt.sys
2009-03-26 15:42 . 2001-08-31 12:00 14,720 --a------ c:\windows\system32\dllcache\dac960nt.sys
2009-03-26 15:41 . 2001-08-31 12:00 7,680 --a------ c:\windows\system32\drivers\cd20xrnt.sys
2009-03-26 15:41 . 2001-08-31 12:00 7,680 --a------ c:\windows\system32\dllcache\cd20xrnt.sys
2009-03-26 15:41 . 2001-08-17 13:51 6,656 --a------ c:\windows\system32\drivers\cmdide.sys
2009-03-26 15:41 . 2001-08-17 13:51 6,656 --a------ c:\windows\system32\dllcache\cmdide.sys
2009-03-26 15:40 . 2001-08-31 12:00 26,496 --a------ c:\windows\system32\drivers\asc.sys
2009-03-26 15:40 . 2001-08-31 12:00 26,496 --a------ c:\windows\system32\dllcache\asc.sys
2009-03-26 15:40 . 2001-08-31 12:00 22,400 --a------ c:\windows\system32\drivers\asc3350p.sys
2009-03-26 15:40 . 2001-08-31 12:00 22,400 --a------ c:\windows\system32\dllcache\asc3350p.sys
2009-03-26 15:40 . 2001-08-31 12:00 14,848 --a------ c:\windows\system32\drivers\asc3550.sys
2009-03-26 15:40 . 2001-08-31 12:00 14,848 --a------ c:\windows\system32\dllcache\asc3550.sys
2009-03-26 15:40 . 2001-08-31 12:00 12,032 --a------ c:\windows\system32\drivers\amsint.sys
2009-03-26 15:40 . 2001-08-31 12:00 12,032 --a------ c:\windows\system32\dllcache\amsint.sys
2009-03-26 15:39 . 2001-08-31 12:00 56,960 --a------ c:\windows\system32\drivers\aic78xx.sys
2009-03-26 15:39 . 2001-08-31 12:00 56,960 --a------ c:\windows\system32\dllcache\aic78xx.sys
2009-03-26 15:39 . 2001-08-31 12:00 55,168 --a------ c:\windows\system32\drivers\aic78u2.sys
2009-03-26 15:39 . 2001-08-31 12:00 55,168 --a------ c:\windows\system32\dllcache\aic78u2.sys
2009-03-26 15:39 . 2001-08-31 12:00 5,248 --a------ c:\windows\system32\drivers\aliide.sys
2009-03-26 15:39 . 2001-08-31 12:00 5,248 --a------ c:\windows\system32\dllcache\aliide.sys
2009-03-26 15:38 . 2001-08-31 12:00 101,888 --a------ c:\windows\system32\drivers\adpu160m.sys
2009-03-26 15:38 . 2001-08-31 12:00 101,888 --a------ c:\windows\system32\dllcache\adpu160m.sys
2009-03-26 15:38 . 2001-08-31 12:00 12,800 --a------ c:\windows\system32\drivers\aha154x.sys
2009-03-26 15:38 . 2001-08-31 12:00 12,800 --a------ c:\windows\system32\dllcache\aha154x.sys
2009-03-26 15:35 . 2001-08-31 12:00 23,552 --a------ c:\windows\system32\drivers\abp480n5.sys
2009-03-26 15:35 . 2001-08-31 12:00 23,552 --a------ c:\windows\system32\dllcache\abp480n5.sys
2009-03-26 12:06 . 2009-03-30 10:20 <DIR> d-------- c:\program files\Malwarebytes
2009-03-26 12:06 . 2009-03-26 12:06 <DIR> d-------- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2009-03-26 12:06 . 2009-03-26 12:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-26 12:06 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 12:06 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-25 21:50 . 2009-03-25 21:50 <DIR> d-------- c:\documents and settings\Compaq_Owner\Application Data\HPQ
2009-03-25 11:56 . 2009-03-25 11:56 0 --a------ c:\windows\nsreg.dat
2009-03-23 12:06 . 2009-03-23 12:06 7,522,240 --a------ c:\program files\Firefox.exe
2009-03-23 12:02 . 2009-03-23 12:02 <DIR> d-------- c:\documents and settings\Compaq_Owner\Application Data\MSNInstaller
2009-03-02 16:27 . 2009-03-02 16:27 28,365,104 --a------ c:\program files\snagit.exe
2009-03-01 22:25 . 2008-01-13 23:29 <DIR> d-------- c:\documents and settings\Administrator\WINDOWS
2009-03-01 22:25 . 2008-01-13 23:29 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Intuit
2009-03-01 22:25 . 2009-03-01 22:25 <DIR> d-------- c:\documents and settings\Administrator
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-01 01:03 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-03-27 11:43 --------- d-----w c:\program files\WildTangent
2009-03-27 06:14 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-03-27 02:59 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-27 02:58 --------- d-----w c:\program files\Quicken
2009-03-27 02:12 --------- d-----w c:\program files\Common Files\Real
2009-03-27 01:55 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-27 01:48 --------- d-----w c:\program files\Sonic
2009-03-27 01:40 --------- d-----w c:\program files\Symantec
2009-03-25 17:24 --------- d-----w c:\program files\Google
2009-03-23 16:29 --------- d-----w c:\program files\Common Files\Sonic Shared
2009-03-23 16:18 --------- d-----w c:\program files\HP Games
2009-03-23 16:17 --------- d-----w c:\program files\Chill
2009-03-02 22:13 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-02 19:01 --------- d-----w c:\documents and settings\Compaq_Owner\Application Data\ZoomBrowser EX
2009-03-02 19:01 --------- d-----w c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-03-02 17:38 --------- d-----w c:\program files\Norton 360
2009-03-02 02:21 --------- d-----w c:\documents and settings\Compaq_Owner\Application Data\LimeWire
2009-02-25 13:15 --------- d-----w c:\documents and settings\Guest\Application Data\Apple Computer
2009-02-22 17:58 --------- d-----w c:\documents and settings\Compaq_Owner\Application Data\Apple Computer
2009-02-19 23:48 --------- d-----w c:\program files\Lavasoft
2009-02-19 23:48 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-18 05:14 --------- d-----w c:\documents and settings\Compaq_Owner\Application Data\Move Networks
2009-02-09 11:13 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:13 1,846,784 ------w c:\windows\system32\dllcache\win32k.sys
2009-02-04 01:36 --------- d-----w c:\program files\LimeWire
2009-01-28 11:25 60,808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-01-17 04:35 3,594,752 ------w c:\windows\system32\dllcache\mshtml.dll
2008-11-13 00:35 350 ----a-w c:\documents and settings\Compaq_Owner\Application Data\wklnhst.dat
2008-08-06 12:53 15,070,144 ----a-w c:\program files\SpySweeper.exe
2008-01-15 22:27 4,494,664 ----a-w c:\program files\LimeWire.exe
2008-12-19 14:22 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008121920081220\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Weather"="c:\progra~1\AWS\WEATHE~1\Weather.exe" [2004-04-13 851968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"StxTrayMenu"="c:\program files\Seagate\SystemTray\StxMenuMgr.exe" [2007-01-18 190008]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-26 180269]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"thirdintel"="c:\hp\bin\cloaker.exe" [1999-11-07 27136]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-13 169984]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 c:\windows\RTHDCPL.EXE]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 c:\windows\system32\bthprops.cpl]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-04-26 27136]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-07-07 65588]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{FA010552-4A27-4cb1-A1BB-3E2D697F1639}"= "c:\program files\InterMute\SpySubtract\sshook.dll" [2009-03-26 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-01-27 64160]
R2 Seagate Sync Service;Seagate Sync Service;c:\program files\Seagate\Sync\SeaSyncServices.exe [2007-01-18 24120]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-23 101936]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-03-26 38496]
S3 WMP300Nv1;Linksys Wireless-N PCI Adapter WMP300N Driver;c:\windows\system32\drivers\WMP300Nv1.sys [2007-10-17 822400]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
2009-03-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
2009-03-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]
2009-03-23 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2008-04-13 18:12]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKLM-Run-DXDllRegExe - dxdllreg.exe
HKLM-Run-PCDrProfiler - (no file)
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.comcast.net/
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\stuwmk4w.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-31 19:10:40
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-4077673394-3207311990-1865167216-1009\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-03-31 19:21:22
ComboFix-quarantined-files.txt 2009-04-01 01:21:17
Pre-Run: 162,384,642,048 bytes free
Post-Run: 162,534,211,584 bytes free
264 --- E O F --- 2009-03-18 03:55:37
-----------------------------------------------------------------------------------------------------------------------------------------------------
ComboFix Run 2
ComboFix 09-03-31.01 - Compaq_Owner 2009-03-31 19:58:18.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.446.72 [GMT -6:00]
Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Outdated)
FW: Norton 360 *disabled*
.
((((((((((((((((((((((((( Files Created from 2009-03-01 to 2009-04-01 )))))))))))))))))))))))))))))))
.
2009-03-27 12:47 . 2009-03-27 12:47 <DIR> d-------- c:\program files\Trend Micro
2009-03-26 23:31 . 2009-03-26 23:31 <DIR> d--hs---- c:\windows\ftpcache
2009-03-26 23:31 . 2009-03-26 23:31 917,504 --a------ c:\windows\system32\FLASH.OCX
2009-03-26 21:34 . 2001-08-31 12:00 27,296 --a------ c:\windows\system32\drivers\PERC2.SYS
2009-03-26 21:34 . 2001-08-31 12:00 27,296 --a------ c:\windows\system32\dllcache\perc2.sys
2009-03-26 21:34 . 2001-08-31 12:00 19,072 --a------ c:\windows\system32\drivers\SPARROW.SYS
2009-03-26 21:34 . 2001-08-31 12:00 19,072 --a------ c:\windows\system32\dllcache\sparrow.sys
2009-03-26 21:34 . 2001-08-31 12:00 17,280 --a------ c:\windows\system32\drivers\MRAID35X.SYS
2009-03-26 21:34 . 2001-08-31 12:00 17,280 --a------ c:\windows\system32\dllcache\mraid35x.sys
2009-03-26 21:34 . 2001-08-31 12:00 5,504 --a------ c:\windows\system32\drivers\PERC2HIB.SYS
2009-03-26 21:34 . 2001-08-31 12:00 5,504 --a------ c:\windows\system32\dllcache\perc2hib.sys
2009-03-26 21:33 . 2008-04-13 11:40 34,688 --a------ c:\windows\system32\drivers\lbrtfdc.sys
2009-03-26 21:33 . 2008-04-13 11:40 34,688 --a------ c:\windows\system32\dllcache\lbrtfdc.sys
2009-03-26 21:33 . 2008-04-13 11:41 18,560 --a------ c:\windows\system32\drivers\i2omp.sys
2009-03-26 21:33 . 2008-04-13 11:41 18,560 --a------ c:\windows\system32\dllcache\i2omp.sys
2009-03-26 21:33 . 2001-08-31 12:00 16,000 --a------ c:\windows\system32\drivers\INI910U.SYS
2009-03-26 21:33 . 2001-08-31 12:00 16,000 --a------ c:\windows\system32\dllcache\ini910u.sys
2009-03-26 21:33 . 2008-04-13 11:41 8,576 --a------ c:\windows\system32\drivers\i2omgmt.sys
2009-03-26 21:33 . 2008-04-13 11:41 8,576 --a------ c:\windows\system32\dllcache\i2omgmt.sys
2009-03-26 21:17 . 2004-08-03 22:00 18,304 --a------ c:\windows\system32\drivers\SYMC8XX.SY_
2009-03-26 21:17 . 2004-08-03 22:00 15,864 --a------ c:\windows\system32\drivers\ULTRA.SY_
2009-03-26 21:17 . 2004-08-03 22:00 2,629 --a------ c:\windows\system32\drivers\TOSIDE.SY_
2009-03-26 21:16 . 2004-08-03 22:00 17,923 --a------ c:\windows\system32\drivers\SYM_U3.SY_
2009-03-26 21:16 . 2004-08-03 22:00 16,761 --a------ c:\windows\system32\drivers\SYM_HI.SY_
2009-03-26 21:16 . 2004-08-03 22:00 11,098 --a------ c:\windows\system32\drivers\SPARROW.SY_
2009-03-26 21:16 . 2004-08-03 22:00 8,352 --a------ c:\windows\system32\drivers\SYMC810.SY_
2009-03-26 21:15 . 2004-08-03 22:00 27,359 --a------ c:\windows\system32\drivers\QL1280.SY_
2009-03-26 21:15 . 2004-08-03 22:00 22,855 --a------ c:\windows\system32\drivers\QL1240.SY_
2009-03-26 21:14 . 2004-08-03 22:00 25,938 --a------ c:\windows\system32\drivers\QL12160.SY_
2009-03-26 21:14 . 2004-08-03 22:00 22,761 --a------ c:\windows\system32\drivers\QL1080.SY_
2009-03-26 21:14 . 2004-08-03 22:00 18,888 --a------ c:\windows\system32\drivers\QL10WNT.SY_
2009-03-26 21:12 . 2004-08-03 22:00 9,785 --a------ c:\windows\system32\drivers\MRAID35X.SY_
2009-03-26 21:09 . 2004-08-03 22:00 14,614 --a------ c:\windows\system32\drivers\LBRTFDC.SY_
2009-03-26 21:09 . 2004-08-03 22:00 8,560 --a------ c:\windows\system32\drivers\INI910U.SY_
2009-03-26 21:08 . 2004-08-03 22:00 10,324 --a------ c:\windows\system32\drivers\I2OMP.SY_
2009-03-26 21:08 . 2004-08-03 22:00 4,064 --a------ c:\windows\system32\drivers\I2OMGMT.SY_
2009-03-26 20:58 . 2009-03-26 20:59 <DIR> d-------- c:\program files\PC-Doctor for Windows
2009-03-26 20:56 . 2009-03-26 20:56 <DIR> d-------- c:\program files\directx
2009-03-26 20:53 . 2009-03-26 20:53 <DIR> d-------- c:\program files\Support Tools
2009-03-26 20:49 . 2009-03-26 20:49 <DIR> d-------- c:\program files\Application Compatibility Toolkit
2009-03-26 20:30 . 2009-03-26 20:30 <DIR> d-------- c:\program files\AWS
2009-03-26 20:12 . 2009-03-26 20:12 <DIR> d-------- c:\program files\Common Files\xing shared
2009-03-26 20:01 . 2003-09-10 23:36 21,060 --------- c:\windows\system32\drivers\iviaspi.sys
2009-03-26 20:01 . 2003-09-19 01:47 10,368 --------- c:\windows\system32\drivers\pfc.sys
2009-03-26 20:00 . 2004-12-16 20:07 204,800 --a------ c:\windows\system32\IVIresizeW7.dll
2009-03-26 20:00 . 2004-12-16 20:07 200,704 --a------ c:\windows\system32\IVIresizeA6.dll
2009-03-26 20:00 . 2004-12-16 20:07 192,512 --a------ c:\windows\system32\IVIresizeP6.dll
2009-03-26 20:00 . 2004-12-16 20:07 192,512 --a------ c:\windows\system32\IVIresizeM6.dll
2009-03-26 20:00 . 2004-12-16 20:07 188,416 --a------ c:\windows\system32\IVIresizePX.dll
2009-03-26 20:00 . 2004-12-16 20:07 20,480 --a------ c:\windows\system32\IVIresize.dll
2009-03-26 19:58 . 2009-03-26 20:56 <DIR> d-------- c:\program files\InterVideo
2009-03-26 19:55 . 2009-03-26 19:55 <DIR> d-------- c:\program files\Macrovision Corp
2009-03-26 19:51 . 2009-03-26 19:51 <DIR> d-------- c:\program files\Common Files\Sonic
2009-03-26 19:51 . 2009-03-26 19:51 <DIR> d-------- c:\documents and settings\Compaq_Owner\Application Data\Sonic
2009-03-26 19:48 . 2009-03-26 19:48 <DIR> d-------- c:\program files\Common Files\SureThing Shared
2009-03-26 19:16 . 2009-03-26 19:16 <DIR> d-------- c:\documents and settings\Compaq_Owner\Application Data\InterMute
2009-03-26 19:15 . 2009-03-26 19:15 <DIR> d-------- c:\program files\InterMute
2009-03-26 19:15 . 2009-03-26 19:16 2,158 --a------ c:\windows\system32\ssmute.ini
2009-03-26 16:08 . 2004-01-28 10:11 159,744 -ra------ c:\windows\system32\nvuide.exe
2009-03-26 15:44 . 2002-08-29 14:00 25,952 --a------ c:\windows\system32\drivers\hpn.sys
2009-03-26 15:44 . 2002-08-29 14:00 25,952 --a------ c:\windows\system32\dllcache\hpn.sys
2009-03-26 15:43 . 2001-08-31 12:00 20,192 --a------ c:\windows\system32\drivers\dpti2o.sys
2009-03-26 15:43 . 2001-08-31 12:00 20,192 --a------ c:\windows\system32\dllcache\dpti2o.sys
2009-03-26 15:42 . 2001-08-31 12:00 14,976 --a------ c:\windows\system32\drivers\cpqarray.sys
2009-03-26 15:42 . 2001-08-31 12:00 14,976 --a------ c:\windows\system32\dllcache\cpqarray.sys
2009-03-26 15:42 . 2001-08-31 12:00 14,720 --a------ c:\windows\system32\drivers\dac960nt.sys
2009-03-26 15:42 . 2001-08-31 12:00 14,720 --a------ c:\windows\system32\dllcache\dac960nt.sys
2009-03-26 15:41 . 2001-08-31 12:00 7,680 --a------ c:\windows\system32\drivers\cd20xrnt.sys
2009-03-26 15:41 . 2001-08-31 12:00 7,680 --a------ c:\windows\system32\dllcache\cd20xrnt.sys
2009-03-26 15:41 . 2001-08-17 13:51 6,656 --a------ c:\windows\system32\drivers\cmdide.sys
2009-03-26 15:41 . 2001-08-17 13:51 6,656 --a------ c:\windows\system32\dllcache\cmdide.sys
2009-03-26 15:40 . 2001-08-31 12:00 26,496 --a------ c:\windows\system32\drivers\asc.sys
2009-03-26 15:40 . 2001-08-31 12:00 26,496 --a------ c:\windows\system32\dllcache\asc.sys
2009-03-26 15:40 . 2001-08-31 12:00 22,400 --a------ c:\windows\system32\drivers\asc3350p.sys
2009-03-26 15:40 . 2001-08-31 12:00 22,400 --a------ c:\windows\system32\dllcache\asc3350p.sys
2009-03-26 15:40 . 2001-08-31 12:00 14,848 --a------ c:\windows\system32\drivers\asc3550.sys
2009-03-26 15:40 . 2001-08-31 12:00 14,848 --a------ c:\windows\system32\dllcache\asc3550.sys
2009-03-26 15:40 . 2001-08-31 12:00 12,032 --a------ c:\windows\system32\drivers\amsint.sys
2009-03-26 15:40 . 2001-08-31 12:00 12,032 --a------ c:\windows\system32\dllcache\amsint.sys
2009-03-26 15:39 . 2001-08-31 12:00 56,960 --a------ c:\windows\system32\drivers\aic78xx.sys
2009-03-26 15:39 . 2001-08-31 12:00 56,960 --a------ c:\windows\system32\dllcache\aic78xx.sys
2009-03-26 15:39 . 2001-08-31 12:00 55,168 --a------ c:\windows\system32\drivers\aic78u2.sys
2009-03-26 15:39 . 2001-08-31 12:00 55,168 --a------ c:\windows\system32\dllcache\aic78u2.sys
2009-03-26 15:39 . 2001-08-31 12:00 5,248 --a------ c:\windows\system32\drivers\aliide.sys
2009-03-26 15:39 . 2001-08-31 12:00 5,248 --a------ c:\windows\system32\dllcache\aliide.sys
2009-03-26 15:38 . 2001-08-31 12:00 101,888 --a------ c:\windows\system32\drivers\adpu160m.sys
2009-03-26 15:38 . 2001-08-31 12:00 101,888 --a------ c:\windows\system32\dllcache\adpu160m.sys
2009-03-26 15:38 . 2001-08-31 12:00 12,800 --a------ c:\windows\system32\drivers\aha154x.sys
2009-03-26 15:38 . 2001-08-31 12:00 12,800 --a------ c:\windows\system32\dllcache\aha154x.sys
2009-03-26 15:35 . 2001-08-31 12:00 23,552 --a------ c:\windows\system32\drivers\abp480n5.sys
2009-03-26 15:35 . 2001-08-31 12:00 23,552 --a------ c:\windows\system32\dllcache\abp480n5.sys
2009-03-26 12:06 . 2009-03-30 10:20 <DIR> d-------- c:\program files\Malwarebytes
2009-03-26 12:06 . 2009-03-26 12:06 <DIR> d-------- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2009-03-26 12:06 . 2009-03-26 12:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-26 12:06 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 12:06 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-25 21:50 . 2009-03-25 21:50 <DIR> d-------- c:\documents and settings\Compaq_Owner\Application Data\HPQ
2009-03-25 11:56 . 2009-03-25 11:56 0 --a------ c:\windows\nsreg.dat
2009-03-23 12:06 . 2009-03-23 12:06 7,522,240 --a------ c:\program files\Firefox.exe
2009-03-23 12:02 . 2009-03-23 12:02 <DIR> d-------- c:\documents and settings\Compaq_Owner\Application Data\MSNInstaller
2009-03-02 16:27 . 2009-03-02 16:27 28,365,104 --a------ c:\program files\snagit.exe
2009-03-01 22:25 . 2008-01-13 23:29 <DIR> d-------- c:\documents and settings\Administrator\WINDOWS
2009-03-01 22:25 . 2008-01-13 23:29 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Intuit
2009-03-01 22:25 . 2009-03-01 22:25 <DIR> d-------- c:\documents and settings\Administrator
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-01 01:44 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-03-27 11:43 --------- d-----w c:\program files\WildTangent
2009-03-27 06:14 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-03-27 02:59 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-27 02:58 --------- d-----w c:\program files\Quicken
2009-03-27 02:12 --------- d-----w c:\program files\Common Files\Real
2009-03-27 01:55 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-27 01:48 --------- d-----w c:\program files\Sonic
2009-03-27 01:40 --------- d-----w c:\program files\Symantec
2009-03-25 17:24 --------- d-----w c:\program files\Google
2009-03-23 16:29 --------- d-----w c:\program files\Common Files\Sonic Shared
2009-03-23 16:18 --------- d-----w c:\program files\HP Games
2009-03-23 16:17 --------- d-----w c:\program files\Chill
2009-03-02 22:13 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-02 19:01 --------- d-----w c:\documents and settings\Compaq_Owner\Application Data\ZoomBrowser EX
2009-03-02 19:01 --------- d-----w c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-03-02 17:38 --------- d-----w c:\program files\Norton 360
2009-03-02 02:21 --------- d-----w c:\documents and settings\Compaq_Owner\Application Data\LimeWire
2009-02-25 13:15 --------- d-----w c:\documents and settings\Guest\Application Data\Apple Computer
2009-02-22 17:58 --------- d-----w c:\documents and settings\Compaq_Owner\Application Data\Apple Computer
2009-02-19 23:48 --------- d-----w c:\program files\Lavasoft
2009-02-19 23:48 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-18 05:14 --------- d-----w c:\documents and settings\Compaq_Owner\Application Data\Move Networks
2009-02-09 11:13 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:13 1,846,784 ------w c:\windows\system32\dllcache\win32k.sys
2009-02-04 01:36 --------- d-----w c:\program files\LimeWire
2009-01-28 11:25 60,808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-01-17 04:35 3,594,752 ------w c:\windows\system32\dllcache\mshtml.dll
2008-11-13 00:35 350 ----a-w c:\documents and settings\Compaq_Owner\Application Data\wklnhst.dat
2008-08-06 12:53 15,070,144 ----a-w c:\program files\SpySweeper.exe
2008-01-15 22:27 4,494,664 ----a-w c:\program files\LimeWire.exe
2008-12-19 14:22 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008121920081220\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-03-31_19.19.53.07 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-30 21:28:15 1,660 ----a-w c:\windows\bthservsdp.dat
+ 2009-04-01 01:30:16 1,660 ----a-w c:\windows\bthservsdp.dat
- 2009-04-01 00:54:39 53,436 ----a-w c:\windows\system32\perfc009.dat
+ 2009-04-01 01:35:53 53,436 ----a-w c:\windows\system32\perfc009.dat
- 2009-04-01 00:54:39 381,692 ----a-w c:\windows\system32\perfh009.dat
+ 2009-04-01 01:35:53 381,692 ----a-w c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Weather"="c:\progra~1\AWS\WEATHE~1\Weather.exe" [2004-04-13 851968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"StxTrayMenu"="c:\program files\Seagate\SystemTray\StxMenuMgr.exe" [2007-01-18 190008]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-26 180269]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"thirdintel"="c:\hp\bin\cloaker.exe" [1999-11-07 27136]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-13 169984]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 c:\windows\RTHDCPL.EXE]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 c:\windows\system32\bthprops.cpl]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-04-26 27136]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-07-07 65588]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{FA010552-4A27-4cb1-A1BB-3E2D697F1639}"= "c:\program files\InterMute\SpySubtract\sshook.dll" [2009-03-26 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-01-27 64160]
R2 Seagate Sync Service;Seagate Sync Service;c:\program files\Seagate\Sync\SeaSyncServices.exe [2007-01-18 24120]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-23 101936]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-03-26 38496]
S3 WMP300Nv1;Linksys Wireless-N PCI Adapter WMP300N Driver;c:\windows\system32\drivers\WMP300Nv1.sys [2007-10-17 822400]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
2009-03-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
2009-03-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]
2009-03-23 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2008-04-13 18:12]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.comcast.net/
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\stuwmk4w.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-31 20:01:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-4077673394-3207311990-1865167216-1009\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-03-31 20:03:41
ComboFix-quarantined-files.txt 2009-04-01 02:03:37
ComboFix2.txt 2009-04-01 01:52:53
ComboFix3.txt 2009-04-01 01:21:25
Pre-Run: 162,540,216,320 bytes free
Post-Run: 162,524,762,112 bytes free
264 --- E O F --- 2009-03-18 03:55:37