ComboFix 09-06-30.03 - Owner 07/01/2009 11:17.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.617 [GMT -4:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\14025934
c:\documents and settings\All Users\Application Data\14025934\14025934.exe
c:\documents and settings\All Users\Application Data\14025934\14025934.glu
c:\documents and settings\All Users\Application Data\14025934\pc14025934cnf
c:\documents and settings\All Users\Application Data\14025934\pc14025934ins
c:\documents and settings\All Users\Application Data\94035926
c:\documents and settings\All Users\Application Data\94035926\94035926.exe
c:\documents and settings\Owner\err.log
c:\documents and settings\Owner\ResErrors.log
C:\EXCEL.EXE
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\drivers\SKYNETwonipxmk.sys
c:\windows\system32\iAlmcoin.dll
c:\windows\system32\mfc45.dll
c:\windows\system32\SKYNEThaodmltw.dll
c:\windows\system32\SKYNEThpjucorm.dat
c:\windows\system32\SKYNETmujnkeih.dat
c:\windows\system32\SKYNETowkmxdqp.dll
c:\windows\winhelp.ini
D:\Autorun.inf
D:\Desktop.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETvkbgoeyf
-------\Legacy_WASFSD
((((((((((((((((((((((((( Files Created from 2009-06-01 to 2009-07-01 )))))))))))))))))))))))))))))))
.
2009-06-27 23:42 . 2008-12-10 16:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-06-27 23:42 . 2009-07-01 14:44 -------- d-----w- c:\program files\Spyware Doctor
2009-06-27 23:42 . 2009-06-27 23:42 -------- d-----w- c:\documents and settings\Owner\Application Data\PC Tools
2009-06-27 23:42 . 2009-06-27 23:42 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-06-26 16:34 . 2009-06-26 16:34 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-06-26 16:34 . 2009-06-26 16:35 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\COMCASTTOOLBAR
2009-06-26 03:49 . 2009-06-26 03:49 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-06-25 16:51 . 1601-01-21 17:33 372777 ----a-w- c:\windows\system32\javactln.exe
2009-06-21 21:34 . 2009-06-21 21:34 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-21 17:12 . 2009-06-21 17:12 -------- d-sh--w- c:\documents and settings\Owner\IETldCache
2009-06-15 03:07 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-15 03:07 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-15 03:06 . 2009-06-15 03:06 -------- d-----w- c:\windows\ie8updates
2009-06-15 03:06 . 2009-05-12 05:11 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-06-15 03:01 . 2009-06-21 16:58 -------- dc-h--w- c:\windows\ie8
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-01 15:00 . 2009-06-27 23:46 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-01 14:52 . 2008-07-15 13:37 -------- d-----w- c:\documents and settings\Owner\Application Data\ComcastToolbar
2009-07-01 14:20 . 2008-05-11 21:21 -------- d-----w- c:\program files\TomTom HOME 2
2009-07-01 14:17 . 2009-07-01 14:04 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-07-01 14:04 . 2009-06-27 23:42 -------- d-----w- c:\program files\Common Files\PC Tools
2009-06-30 19:01 . 2003-08-23 14:25 -------- d-----w- c:\program files\Quicken
2009-06-29 19:48 . 2009-06-29 19:48 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-06-29 19:48 . 2009-06-29 19:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-29 19:48 . 2009-06-29 19:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-29 19:09 . 2009-06-29 19:09 -------- d-----w- c:\program files\Trend Micro
2009-06-26 23:59 . 2008-07-13 23:08 518 ----a-w- c:\documents and settings\Owner\Application Data\iolo\Registry\Last\restore.bat
2009-06-26 03:52 . 2003-11-02 03:05 -------- d-----w- c:\program files\Google
2009-06-22 18:34 . 2008-07-13 23:08 1527 ----a-w- c:\documents and settings\Owner\Application Data\iolo\restore.bat
2009-06-17 15:27 . 2009-06-29 19:48 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 15:27 . 2009-06-29 19:48 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-29 19:40 . 2008-07-13 22:15 940896 ----a-w- c:\windows\system32\Incinerator.dll
2009-05-26 14:50 . 2003-08-23 14:19 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-13 05:15 . 2004-08-24 00:32 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2003-08-08 16:23 345600 ------w- c:\windows\system32\localspl.dll
2009-05-05 17:42 . 2009-05-05 17:42 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-05-05 17:41 . 2008-05-24 01:25 38208 -c--a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe2009-05-05 17:36 . 2009-05-05 17:36 -------- d-----w- c:\documents and settings\Owner\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-04-17 12:26 . 2003-08-08 15:35 1847168 ------w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-06-15 04:40 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-12 18:32 . 2003-11-06 03:15 45056 -c--a-w- c:\windows\NCUNINST.EXE
2009-04-08 04:36 . 2008-05-22 02:10 2815 -c--a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2008\qbbackup.sys
2007-01-02 19:27 . 2007-01-02 19:27 31002 -c--a-w- c:\program files\Quicken.QIF
2004-01-01 22:16 . 2004-01-01 22:16 0 -csha-w- c:\windows\SMINST\HPCD.sys
2003-11-12 23:56 . 2003-11-09 11:50 56 -csh--r- c:\windows\system32\BC2C6383F0.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATI Remote Control"="c:\program files\ATI Multimedia\RemCtrl\ATIRW.exe" [2004-08-27 200704]
"ATI DeviceDetect"="c:\program files\ATI Multimedia\main\ATIDtct.EXE" [2004-12-01 69709]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-29 68856]
"cdloader"="c:\documents and settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2008-12-17 50520]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-12-09 234856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-06-15 114688]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-15 623992]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-15 29744]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2008-02-15 1052672]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-04-29 188728]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"McAfee Backup"="c:\program files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 4838952]
"MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Symantec NetDriver Warning"="c:\progra~1\SYMNET~1\SNDWarn.exe" [2004-10-29 218232]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-02-02 32768]
c:\documents and settings\Default User\Start Menu\Programs\Startup\
AutoTBar.exe [2004-6-14 53248]
c:\documents and settings\Administrator.JIM_MOORE\Start Menu\Programs\Startup\
AutoTBar.exe [2004-6-14 53248]
mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2006-6-22 462848]
WkCalRem.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2002-6-20 24651]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-10-30 282624]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ 'autocheck autochk *'
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ATI CATALYST System Tray.lnk.disabled
backup=c:\windows\pss\ATI CATALYST System Tray.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk.disabled
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Image Transfer.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Image Transfer.lnk.disabled
backup=c:\windows\pss\Image Transfer.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk.disabled
backup=c:\windows\pss\Quicken Scheduled Updates.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk.disabled
backup=c:\windows\pss\Updates from HP.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Online Support Center.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Verizon Online Support Center.lnk.disabled
backup=c:\windows\pss\Verizon Online Support Center.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^HP Organize.lnk.disabled]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\HP Organize.lnk.disabled
backup=c:\windows\pss\HP Organize.lnk.disabledStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk.disabled]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk.disabled
backup=c:\windows\pss\spamsubtract.lnk.disabledStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"x10nets"=3 (0x3)
"MDM"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Juno_uoltray"=c:\program files\Juno6\exec.exe regrun
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe"
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" /background
"NVIEW"=rundll32.exe nview.dll,nViewLoadHook
"spc_w"="c:\program files\JUSearch\juspc.exe" -w
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ATIPTA"=c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
"eMailEncryption"=c:\progra~1\ACCELE~1\VELOZD~1\velozsys.exe runstart
"Microsoft Works Update Detection"=c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
"NvCplDaemon"=RUNDLL32.EXE c:\windows\System32\NvCpl.dll,NvStartup
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"WT GameChannel"=c:\program files\WildTangent\Apps\GameChannel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealOne Player\\realplay.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\WINDOWS\\system32\\wjview.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IMSI\\TCW90\\Program\\FindNews.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\WINDOWS\\system32\\javactln.exe"=