# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3525 (20081015)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=b6a97245f8d78048ab2d2fc2caca0d7a
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-10-15 09:26:28
# local_time=2008-10-15 05:26:28 (-0500, Eastern Daylight Time)
# country="Canada"
# osver=6.0.6001 NT Service Pack 1
# scanned=394457
# found=0
# scan_time=3651
Malwarebytes' Anti-Malware 1.28
Database version: 1274
Windows 6.0.6001 Service Pack 1
15/10/2008 3:59:03 PM
mbam-log-2008-10-15 (15-59-03).txt
Scan type: Quick Scan
Objects scanned: 42775
Time elapsed: 2 minute(s), 29 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{fded8846-95b0-4005-9e39-9f1720b6815e} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphcvmdj0e7fr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:27:51 PM, on 14/10/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Brian\Program Files\DNA\btdna.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conime.exe
C:\hp\kbd\kbd.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SnapfishMediaDetector] C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\yayaAqpn.dll,#1
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Brian\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [lphcvmdj0e7fr] C:\Windows\system32\lphcvmdj0e7fr.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Snapfish Media Detector.lnk = C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O13 - Gopher Prefix:
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1223059842746&h=9d7d1a13d574fad763707a11d3c2445b/&filename=jinstall-6u7-windows-i586-jc.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 8820 bytes
omboFix 08-10-15.05 - Brian 2008-10-15 19:27:47.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1103 [GMT -4:00]
Running from: C:\Users\Brian\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-09-15 to 2008-10-15 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-15 23:26 --------- d-----w C:\Users\Brian\AppData\Roaming\DNA
2008-10-15 23:20 --------- d-----w C:\Users\Brian\AppData\Roaming\LimeWire
2008-10-15 22:05 --------- d-----w C:\ProgramData\Symantec
2008-10-15 21:26 --------- d-----w C:\Program Files\EsetOnlineScanner
2008-10-15 19:54 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-10-15 19:52 --------- d-----w C:\Users\Brian\AppData\Roaming\Malwarebytes
2008-10-15 19:52 --------- d-----w C:\ProgramData\Malwarebytes
2008-10-15 18:56 --------- d-----w C:\Program Files\Windows Mail
2008-10-14 23:17 --------- d-----w C:\Program Files\Trend Micro
2008-10-14 00:42 --------- d-----w C:\Program Files\Norton 360
2008-10-13 22:40 --------- d-----w C:\Users\Brian\AppData\Roaming\BitTorrent
2008-10-13 22:16 --------- d-----w C:\Users\Brian\AppData\Roaming\Symantec
2008-10-13 22:00 0 ----a-w C:\Users\Brian\AppData\Roaming\wklnhst.dat
2008-10-13 22:00 --------- d-----w C:\Users\Brian\AppData\Roaming\Template
2008-10-13 17:58 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2008-10-13 17:58 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2008-10-13 17:58 10,671 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2008-10-13 17:58 --------- d-----w C:\Program Files\Symantec
2008-10-13 17:57 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-10-13 02:09 --------- d-----w C:\Program Files\HP DeskJet 970C Series
2008-10-12 17:42 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-10-12 17:42 --------- d-----w C:\Program Files\Realtek
2008-10-12 15:39 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-10-12 15:19 --------- d-----w C:\ProgramData\Nero
2008-10-12 15:19 --------- d-----w C:\Program Files\Common Files\Nero
2008-10-12 14:52 --------- d-----w C:\Program Files\Nero
2008-10-12 14:13 --------- d-----w C:\Users\Brian\AppData\Roaming\Nero
2008-10-12 13:08 --------- d---a-w C:\Program Files\Common Files\LightScribe
2008-10-11 22:13 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-10-11 22:13 --------- d-----w C:\Program Files\AVS4YOU
2008-10-11 22:02 --------- d-----w C:\Users\Brian\AppData\Roaming\AVS4YOU
2008-10-11 22:02 --------- d-----w C:\ProgramData\AVS4YOU
2008-10-11 13:10 --------- d-----w C:\Users\Brian\AppData\Roaming\muvee Technologies
2008-10-11 13:07 --------- d-----w C:\ProgramData\TEMP
2008-10-10 21:58 --------- d-----w C:\ProgramData\LightScribe
2008-10-10 01:47 --------- d-----w C:\ProgramData\Roxio
2008-10-10 01:46 --------- d-----w C:\Users\Brian\AppData\Roaming\Roxio
2008-10-09 01:23 --------- d-----w C:\Program Files\DNA
2008-10-09 01:23 --------- d-----w C:\Program Files\BitTorrent
2008-10-09 00:50 --------- d-----w C:\Program Files\HP Games
2008-10-09 00:45 --------- d-----w C:\ProgramData\WildTangent
2008-10-09 00:34 --------- d-----w C:\ProgramData\Microsoft Help
2008-10-09 00:34 --------- d-----w C:\Program Files\Microsoft Works
2008-10-08 01:51 --------- d-----w C:\Users\Brian\AppData\Roaming\DivX
2008-10-08 01:51 --------- d-----w C:\Program Files\DivX
2008-10-08 01:20 --------- d-----w C:\Program Files\Real
2008-10-08 01:20 --------- d-----w C:\Program Files\Common Files\Real
2008-10-06 20:59 174 --sha-w C:\Program Files\desktop.ini
2008-10-06 20:51 --------- d-----w C:\Program Files\Windows Sidebar
2008-10-06 20:51 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-10-06 20:51 --------- d-----w C:\Program Files\Windows Journal
2008-10-06 20:51 --------- d-----w C:\Program Files\Windows Defender
2008-10-06 20:51 --------- d-----w C:\Program Files\Windows Collaboration
2008-10-06 20:51 --------- d-----w C:\Program Files\Windows Calendar
2008-10-06 20:05 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-10-06 20:05 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-10-05 23:02 --------- d-----w C:\ProgramData\NVIDIA
2008-10-05 22:42 --------- d-----w C:\Users\Brian\AppData\Roaming\Apple Computer
2008-10-05 22:42 --------- d-----w C:\ProgramData\Apple Computer
2008-10-05 22:42 --------- d-----w C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-05 22:42 --------- d-----w C:\Program Files\iTunes
2008-10-05 22:42 --------- d-----w C:\Program Files\iPod
2008-10-05 22:41 --------- d-----w C:\Program Files\QuickTime
2008-10-05 22:41 --------- d-----w C:\Program Files\Bonjour
2008-10-05 22:40 --------- d-----w C:\Program Files\Common Files\Apple
2008-10-05 22:39 --------- d-----w C:\Program Files\Apple Software Update
2008-10-05 22:38 --------- d-----w C:\ProgramData\Apple
2008-10-05 20:44 269,312 ----a-w C:\Windows\System32\es.dll
2008-10-05 19:18 61,440 ----a-w C:\Windows\System32\winipsec.dll
2008-10-05 19:18 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL
2008-10-05 19:18 28,672 ----a-w C:\Windows\System32\FwRemoteSvr.dll
2008-10-05 19:18 272,896 ----a-w C:\Windows\System32\polstore.dll
2008-10-05 19:07 541,696 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-10-05 19:07 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-10-05 19:07 4,240,384 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-10-05 19:07 28,160 ----a-w C:\Windows\System32\Apphlpdm.dll
2008-10-05 19:07 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-10-05 19:07 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-10-05 19:07 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-10-05 19:07 1,695,744 ----a-w C:\Windows\System32\gameux.dll
2008-10-05 18:47 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-10-05 18:43 303,616 ----a-w C:\Windows\System32\wmpeffects.dll
2008-10-05 18:24 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-10-05 18:23 988,216 ----a-w C:\Windows\System32\winload.exe
2008-10-05 18:23 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-10-05 18:23 615,992 ----a-w C:\Windows\System32\ci.dll
2008-10-05 18:23 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-10-05 18:23 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-10-05 18:23 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-10-05 18:23 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-10-05 18:23 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-10-05 18:23 14,848 ----a-w C:\Windows\System32\srdelayed.exe
2008-10-05 18:18 295,936 ----a-w C:\Windows\System32\gdi32.dll
2008-10-05 18:15 14,848 ----a-w C:\Windows\System32\wshrm.dll
2008-10-05 18:15 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
2008-10-05 18:12 84,480 ----a-w C:\Windows\System32\INETRES.dll
2008-10-05 18:12 738,304 ----a-w C:\Windows\System32\inetcomm.dll
2008-10-05 18:11 1,314,816 ----a-w C:\Windows\System32\quartz.dll
2008-10-05 16:52 --------- d-----w C:\Program Files\Google
2008-10-05 16:07 --------- d-----w C:\Users\Brian\AppData\Roaming\WinBatch
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-03-12 1773568]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-10-05 171448]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"BitTorrent DNA"="C:\Users\Brian\Program Files\DNA\btdna.exe" [2008-10-09 289088]
"LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"SnapfishMediaDetector"="C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe" [2007-03-02 1441792]
"HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-22 92704]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 116072]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 C:\Windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="C:\Windows\SMINST\launcher.exe" [2007-03-07 44168]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Snapfish Media Detector.lnk - C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe [2007-03-02 1441792]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{720CCA31-0130-46C4-B912-ADC9B895E1C4}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{6348283B-EB6D-42FA-82EE-DB90C29B0E3D}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9D620FB8-6652-4E35-9A69-47A4918C58D7}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{7209C481-662A-4AF0-B671-27016496A960}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{95F90EA2-BF90-4FAF-AA4C-400FC48760D3}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{10E8988F-0A6B-4842-82A2-8AC64216BD42}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{31968948-BF02-4692-AA76-F096108ED98E}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{6C0FA126-23AF-4FA4-80EF-7682086127D8}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{C18684B6-4878-4CAA-B6A3-42688BF6A552}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{2140BFFB-9696-4E44-AA2F-088621090DC1}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{C8831D37-2EFF-41EF-AB0D-1D2EC4B0B648}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{A6347F1D-614A-4738-836C-58BD7FEBF89A}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{E5A38A98-EFF9-4B0B-AA66-8D25086CF7AA}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{41D29349-0C80-4744-A85D-94788FAA1515}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20081014.001\IDSvix86.sys [2008-10-08 270384]
R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;C:\Windows\system32\DRIVERS\netr73.sys [2008-02-26 493568]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-01-09 38200]
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2008-10-15 C:\Windows\Tasks\User_Feed_Synchronization-{53B5AB87-A32A-4CA2-9F54-28FCCD8F7E1B}.job
- C:\Windows\system32\msfeedssync.exe [2008-01-19 03:33]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
HKLM-Run-NBKeyScan - C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
ShellExecuteHooks-{FDED8846-95B0-4005-9E39-9F1720B6815E} - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://ca.my.yahoo.com/
R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-15 19:34:35
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-15 19:36:02
ComboFix-quarantined-files.txt 2008-10-15 23:35:58
Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
Post-Run: 238,831,525,888 bytes free
217 --- E O F --- 2008-10-15 22:30:09