ComboFix 09-09-14.02 - Owner 09/14/2009 19:47.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.631 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\Combo-Fix.exe
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\izonip.bat
c:\documents and settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk
c:\documents and settings\Owner\Local Settings\Application Data\edugi.reg
c:\documents and settings\Owner\Local Settings\Application Data\hubo.inf
c:\documents and settings\Owner\Start Menu\Advanced Virus Remover.lnk
c:\program files\AdvancedVirusRemover
c:\program files\AdvancedVirusRemover\PAVRM.exe
c:\program files\sFX
c:\program files\Windows Police Pro
c:\program files\Windows Police Pro\msvcm80.dll
c:\program files\Windows Police Pro\msvcp80.dll
c:\program files\Windows Police Pro\msvcr80.dll
c:\program files\Windows Police Pro\windows Police Pro.exe
C:\sitkrb.exe
C:\uskwdhpq.exe
c:\windows\010112010146118114.dat
c:\windows\0101120101464849.dat
c:\windows\934fdfg34fgjf23
c:\windows\Fonts\mlog
c:\windows\igykemiha.bat
c:\windows\Install.txt
c:\windows\Installer\6299b30.msi
c:\windows\jestertb.dll
c:\windows\kyqabu.inf
c:\windows\okugyl.dll
c:\windows\ppp3.dat
c:\windows\ppp4.dat
c:\windows\run.log
c:\windows\system32\_004376_.tmp.dll
c:\windows\system32\_004377_.tmp.dll
c:\windows\system32\_004378_.tmp.dll
c:\windows\system32\_004379_.tmp.dll
c:\windows\system32\_004386_.tmp.dll
c:\windows\system32\_004387_.tmp.dll
c:\windows\system32\_004388_.tmp.dll
c:\windows\system32\_004389_.tmp.dll
c:\windows\system32\_004391_.tmp.dll
c:\windows\system32\_004392_.tmp.dll
c:\windows\system32\_004395_.tmp.dll
c:\windows\system32\_004396_.tmp.dll
c:\windows\system32\_004398_.tmp.dll
c:\windows\system32\_004399_.tmp.dll
c:\windows\system32\_004400_.tmp.dll
c:\windows\system32\_004402_.tmp.dll
c:\windows\system32\_004403_.tmp.dll
c:\windows\system32\_004405_.tmp.dll
c:\windows\system32\_004406_.tmp.dll
c:\windows\system32\_004410_.tmp.dll
c:\windows\system32\_004411_.tmp.dll
c:\windows\system32\_004413_.tmp.dll
c:\windows\system32\_004416_.tmp.dll
c:\windows\system32\_004418_.tmp.dll
c:\windows\system32\_004419_.tmp.dll
c:\windows\system32\_004420_.tmp.dll
c:\windows\system32\_004421_.tmp.dll
c:\windows\system32\_004422_.tmp.dll
c:\windows\system32\_004425_.tmp.dll
c:\windows\system32\_004426_.tmp.dll
c:\windows\system32\_004427_.tmp.dll
c:\windows\system32\_004428_.tmp.dll
c:\windows\system32\_004429_.tmp.dll
c:\windows\system32\_004434_.tmp.dll
c:\windows\system32\_004436_.tmp.dll
c:\windows\system32\_004437_.tmp.dll
c:\windows\system32\_004618_.tmp.dll
c:\windows\system32\_004619_.tmp.dll
c:\windows\system32\_004620_.tmp.dll
c:\windows\system32\_004621_.tmp.dll
c:\windows\system32\_004628_.tmp.dll
c:\windows\system32\_004629_.tmp.dll
c:\windows\system32\_004630_.tmp.dll
c:\windows\system32\_004631_.tmp.dll
c:\windows\system32\_004633_.tmp.dll
c:\windows\system32\_004634_.tmp.dll
c:\windows\system32\_004637_.tmp.dll
c:\windows\system32\_004638_.tmp.dll
c:\windows\system32\_004640_.tmp.dll
c:\windows\system32\_004641_.tmp.dll
c:\windows\system32\_004642_.tmp.dll
c:\windows\system32\_004644_.tmp.dll
c:\windows\system32\_004645_.tmp.dll
c:\windows\system32\_004647_.tmp.dll
c:\windows\system32\_004648_.tmp.dll
c:\windows\system32\_004652_.tmp.dll
c:\windows\system32\_004653_.tmp.dll
c:\windows\system32\_004655_.tmp.dll
c:\windows\system32\_004658_.tmp.dll
c:\windows\system32\_004660_.tmp.dll
c:\windows\system32\_004661_.tmp.dll
c:\windows\system32\_004662_.tmp.dll
c:\windows\system32\_004663_.tmp.dll
c:\windows\system32\_004664_.tmp.dll
c:\windows\system32\_004667_.tmp.dll
c:\windows\system32\_004668_.tmp.dll
c:\windows\system32\_004669_.tmp.dll
c:\windows\system32\_004670_.tmp.dll
c:\windows\system32\_004671_.tmp.dll
c:\windows\system32\_004676_.tmp.dll
c:\windows\system32\_004678_.tmp.dll
c:\windows\system32\_004679_.tmp.dll
c:\windows\system32\18467.exe
c:\windows\system32\41.exe
c:\windows\system32\advapi32new.dll
c:\windows\system32\apphelpnew.dll
c:\windows\system32\AVR09.exe
c:\windows\system32\config\systemprofile\Desktop\Advanced Virus Remover.lnk
c:\windows\system32\crypt32new.dll
c:\windows\system32\d3d10core.dll
c:\windows\system32\Data
c:\windows\system32\ddDEsot.dll
c:\windows\system32\drivers\hjgruifbtowdlt.sys
c:\windows\system32\drivers\UACgqqlfgkbdi.sys
c:\windows\system32\dwmapi.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\flashd32.dll
c:\windows\system32\hjgruiauxtkbsm.dll
c:\windows\system32\hjgruijxtqxxor.dll
c:\windows\system32\hjgruikiinigqw.dll
c:\windows\system32\hjgruimnbfvlne.dll
c:\windows\system32\hjgruinfpxmayg.dat
c:\windows\system32\hjgruinvbadsjj.dll
c:\windows\system32\hjgruiqdcblnlw.dat
c:\windows\system32\hjgruiriyusibc.dat
c:\windows\system32\hjgruiubuweciu.dat
c:\windows\system32\Install.txt
c:\windows\system32\kernel32new.dll
c:\windows\system32\msvcrtnew.dll
c:\windows\system32\ntdsapinew.dll
c:\windows\system32\onhelp.htm
c:\windows\system32\powrprofnew.dll
c:\windows\system32\secur32new.dll
c:\windows\system32\sonhelp.htm
c:\windows\system32\sysnet.dat
c:\windows\system32\tapi.nfo
c:\windows\system32\UACptojqfjspx.dll
c:\windows\system32\UACxoopvgvrdwgucwign.dat
c:\windows\system32\UACywqrpentvxoeaejnk.db
c:\windows\system32\user32new.dll
c:\windows\system32\winhelper.dll
c:\windows\system32\winstanew.dll
c:\windows\system32\winupdate.exe
c:\windows\system32\proquota.exe . . . is missing!!
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_hjgruimnwubowl
-------\Legacy_hjgruimnwubowl
-------\Service_UACd.sys
-------\Legacy_UACd.sys
-------\Legacy_6TO4
-------\Legacy_ANTIPPRO2009_100
-------\Legacy_MSNCACHE
-------\Legacy_PCMSTUB
-------\Legacy_SFXDRV
-------\Legacy_SOPIDKC
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Service_6to4
-------\Service_AntipPro2009_100
-------\Service_pcmstub
-------\Service_sFxdrv
((((((((((((((((((((((((( Files Created from 2009-08-15 to 2009-09-15 )))))))))))))))))))))))))))))))
.
2009-09-13 03:15 . 2009-06-17 16:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-13 03:14 . 2009-06-17 16:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-13 03:14 . 2009-09-13 03:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-12 02:37 . 2009-09-12 02:37 -------- d-----w- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-09-12 02:37 . 2009-09-12 02:37 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-09-11 21:32 . 2009-09-11 21:40 -------- d-----w- c:\program files\RegScrubVistaXP
2009-09-11 21:03 . 2009-09-11 21:03 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E}
2009-09-09 13:41 . 2009-09-09 13:41 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Mozilla
2009-09-09 13:07 . 2009-09-09 13:07 2198 ----a-w- C:\eoA7Q.bat
2009-09-09 13:06 . 2009-09-09 13:06 2198 ----a-w- C:\gUzxUvF.bat
2009-09-09 13:06 . 2009-09-09 13:06 2048 ----a-w- C:\khwx.exe
2009-09-09 13:06 . 2009-09-09 13:06 28160 ----a-w- C:\snpprnco.exe
2009-09-09 13:06 . 2009-09-09 13:06 88064 ----a-w- C:\oqnxehuw.exe
2009-09-08 23:29 . 2009-09-08 23:29 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-09-06 01:38 . 2009-09-06 01:39 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Temp
2009-08-24 23:26 . 2009-08-24 23:26 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\PCHealth
2009-08-22 08:01 . 2009-08-22 08:01 -------- d-----w- C:\a38061ec44a40dac19122860
2009-08-21 08:04 . 2009-08-21 08:04 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-21 08:03 . 2009-08-21 08:03 -------- d-----w- c:\program files\MSBuild
2009-08-21 08:03 . 2009-08-21 08:03 -------- d-----w- c:\program files\Reference Assemblies
2009-08-21 08:03 . 2009-08-21 08:03 -------- d-----w- C:\060865e421b441991762161bff15b5
2009-08-21 08:03 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-21 08:03 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-21 08:03 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-21 08:03 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-21 08:03 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-21 08:03 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-21 08:03 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-21 08:00 . 2009-08-21 08:00 -------- d-----w- C:\4c2d92f28c3fd666dfc15b0fa2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-11 21:09 . 2008-09-05 21:18 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-10 00:05 . 2009-01-08 21:33 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-09-09 23:59 . 2009-01-08 21:33 -------- d-----w- c:\program files\NOS
2009-09-08 23:15 . 2009-07-20 01:05 10752 ----a-w- c:\windows\DCEBoot.exe
2009-09-07 00:01 . 2009-01-24 19:47 -------- d-----w- c:\documents and settings\Owner\Application Data\gtk-2.0
2009-08-30 01:00 . 2008-07-21 05:46 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-27 00:18 . 2009-06-19 22:18 -------- d-----w- c:\documents and settings\Owner\Application Data\SystemRequirementsLab
2009-08-26 18:40 . 2008-07-21 18:32 -------- d-----w- c:\documents and settings\Owner\Application Data\AdobeUM
2009-08-24 23:48 . 2008-07-18 19:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-22 14:03 . 2008-07-18 21:14 108304 -c--a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-15 00:59 . 2009-08-15 00:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo
2009-08-15 00:59 . 2009-08-15 00:59 -------- d-----w- c:\documents and settings\Owner\Application Data\Yahoo
2009-08-15 00:58 . 2009-03-26 01:31 -------- d-----w- c:\program files\Yahoo! Games
2009-08-14 21:19 . 2009-07-20 00:27 -------- d-----w- c:\program files\Trend Micro
2009-08-05 09:11 . 2004-08-04 10:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-24 15:58 . 2009-07-24 15:58 -------- d-----w- c:\documents and settings\Owner\Application Data\Canon
2009-07-24 04:02 . 2008-08-09 17:48 -------- d-----w- c:\documents and settings\Owner\Application Data\U3
2009-07-24 03:43 . 2009-07-24 03:43 -------- d-----w- c:\program files\Malwarebytes'Anti-Malware
2009-07-20 00:31 . 2008-07-20 20:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Trend Micro
2009-07-20 00:15 . 2008-08-30 01:45 -------- d-----w- c:\program files\Veoh Networks
2009-07-20 00:13 . 2008-07-19 03:33 -------- d-----w- c:\program files\Real
2009-07-20 00:12 . 2009-04-16 18:18 -------- d-----w- c:\program files\RealArcade
2009-07-20 00:11 . 2009-07-20 00:11 -------- d-----w- c:\documents and settings\Owner\Application Data\MSNInstaller
2009-07-20 00:09 . 2009-02-17 03:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-17 18:55 . 2004-08-04 10:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 14:28 . 2009-07-13 14:28 18456 ----a-w- c:\windows\system32\owyca.pif
2009-07-13 14:28 . 2009-07-13 14:28 18190 ----a-w- c:\program files\Common Files\rupoj._dl
2009-07-13 14:28 . 2009-07-13 14:28 17217 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\isyjybo.bin
2009-07-13 14:28 . 2009-07-13 14:28 16880 ----a-w- c:\program files\Common Files\ovijikoroq.com
2009-07-13 14:28 . 2009-07-13 14:28 16086 ----a-w- c:\windows\wazoguju.pif
2009-07-13 14:28 . 2009-07-13 14:28 16021 ----a-w- c:\documents and settings\All Users\Application Data\ykony.exe
2009-07-13 14:28 . 2009-07-13 14:28 15789 ----a-w- c:\documents and settings\All Users\Application Data\pytynap.sys
2009-07-13 14:28 . 2009-07-13 14:28 13882 ----a-w- c:\program files\Common Files\botukameh.scr
2009-07-13 14:28 . 2009-07-13 14:28 13511 ----a-w- c:\windows\system32\zawibys.exe
2009-07-13 14:28 . 2009-07-13 14:28 12883 ----a-w- c:\windows\piny.sys
2009-07-13 14:28 . 2009-07-13 14:28 12423 ----a-w- c:\windows\jimav.sys
2009-07-13 14:28 . 2009-07-13 14:28 12209 ----a-w- c:\program files\Common Files\ehativu.ban
2009-07-13 07:18 . 2004-08-04 10:00 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2006-03-04 03:33 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 10:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-04 10:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-04-19 19:01 . 2009-04-19 19:00 199 -c--a-w- c:\program files\tutorialState.dat
2008-03-09 13:25 . 2009-02-22 01:49 236 -c-ha-w- c:\program files\Common Files\dx.reg
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-02-29 4670704]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-04-29 3338240]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-02-22 492808]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"basicsmssmenu"="c:\documents and settings\Owner\My Documents\Basics Status\MaxMenuMgrBasics.exe" [2007-10-09 169328]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-10 289064]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2008-07-19 26112]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-10 344064]
"CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-04 61440]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-04-01 995528]
"P17Helper"="P17.dll" - c:\windows\system32\P17.dll [2004-06-10 60928]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-02-22 492808]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Firefly Studios\\Stronghold Crusader\\Stronghold Crusader.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [7/19/2009 7:29 PM 50192]
R2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [7/19/2009 7:29 PM 497008]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2/22/2009 5:56 AM 36368]
R2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [7/19/2009 7:29 PM 677128]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [7/18/2008 2:05 PM 24652]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2/22/2009 5:56 AM 335376]
S3 getPlusHelper;getPlus(R) Helper;c:\windows\System32\svchost.exe -k getPlusHelper [8/4/2004 5:00 AM 14336]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 3:22 PM 34064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2009-09-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-12 00:57]
.
.
------- Supplementary Scan -------
.
uLocal Page =
uStart Page =
hxxp://www.google.commLocal Page =
mStart Page =
hxxp://www.google.comuInternet Settings,ProxyOverride = *.local
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} -
hxxp://download.playfirst.com/play/game/doggiedash/DoggieDash.1.0.0.9.cabFF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0685nnp.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - prefs.js: browser.startup.homepage - furry-paws.com
FF - prefs.js: keyword.URL -
hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101664&gct=&gc=1&q=FF - plugin: c:\documents and settings\All Users\Application Data\RealArcade\npraclient.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npraclient.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)
HKLM-Run-UIUCU - (no file)
HKU-Default-Run-Advanced Virus Remover - c:\program files\AdvancedVirusRemover\PAVRM.exe
ShellExecuteHooks-{38101905-D80F-4788-96F6-986A8186178A} - c:\windows\system32\flashd32.dll
AddRemove-SystemRequirementsLab - c:\program files\SystemRequirementsLab\Uninstall.exe
AddRemove-Win Police Pro - c:\program files\Windows Police Pro\AntiSpyware_Uninstall.exe
AddRemove-{6FE24A8F-3777-B94A-FE11-A559C5EDE14F} - c:\windows\system32\bwryuiiqjs.dll-uninst.exe
AddRemove-{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7} - c:\program files\NOS\bin\getPlus_HelperSvc.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-14 19:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.nbcuni.com
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.nbcuni.com\AdPolicyInfo.sol 111 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.neopets.com
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.neopets.com\UserPrefs.sol 46 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.redorbit.com
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.redorbit.com\VideoPlayer
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.redorbit.com\VideoPlayer\redorbitVideoPlayer.swf
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.redorbit.com\VideoPlayer\redorbitVideoPlayer.swf\Lightningcast.sol 56 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\videos.video-loader.com
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\videos.video-loader.com\preroll
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\videos.video-loader.com\preroll\TV2NPlayer.swf
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\videos.video-loader.com\preroll\TV2NPlayer.swf\tv2nIntegrationPlayer.sol 101 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\vidshadow.vo.llnwd.net
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\vidshadow.vo.llnwd.net\vidshadow.sol 118 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\vizu.com
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\vizu.com\acUserData.sol 5718 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\void.snocap.com
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\void.snocap.com\s
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\void.snocap.com\s\store.swf
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\void.snocap.com\s\store.swf\SharedObjectLock.sol 54 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\void.snocap.com\s\storefront.swf
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\void.snocap.com\s\storefront.swf\SnocapDownloadManager.sol 52 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\vox-static.liverail.com
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\wat.tv
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\wat.tv\images
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\wat.tv\images\v2.5
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\wat.tv\images\v2.5\flash
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\wat.tv\images\v2.5\flash\player.swf
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\wat.tv\images\v2.5\flash\player.swf\watPlayer.sol 60 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#Sharecatchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\webmessenger.yahoo.com\eden_cookie.sol 1311 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.yourfilehost.comc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.yourfilehost.com\flashc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.yourfilehost.com\flash\flvplayer7.swfc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.yourfilehost.com\flash\flvplayer7.swf\UserVolume.sol 55 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.youtube.comc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.youtube.com\soundData.sol 58 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.youtube.com\videostats.sol 199 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\static.twitter.com
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\static.twitter.com\flash
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\static.twitter.com\flash\widgets
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\static.twitter.com\flash\widgets\profile
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\static.twitter.com\flash\widgets\profile\TwitterWidget.swf
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\stuff.pyzam.com
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\stuff.pyzam.com\com.quantserve.sol 74 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.google.com
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.google.com\googleplayer.swf
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.google.com\googleplayer.swf\mediaPlayerUserSettings.sol 94 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.google.com\s
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.google.com\s\4lS77yaJ_k8
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.google.com\s\4lS77yaJ_k8\googleplayer.swf
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.google.com\s\4lS77yaJ_k8\googleplayer.swf\mediaPlayerUserSettings.sol 94 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.google.com\s\ztlPrL9D4z8
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.google.com\s\ztlPrL9D4z8\googleplayer.swf
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.google.com\s\ztlPrL9D4z8\googleplayer.swf\mediaPlayerUserSettings.sol 94 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\video.google.com\videostats.sol 199 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\wp.vizu.com
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\wp.vizu.com\vizuUserData.sol 644 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.funnyhub.comc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.funnyhub.com\com.jeroenwijering.players.sol 66 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.podtech.netc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.podtech.net\podtech-player.sol 263 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.yikers.comc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.yikers.com\flashc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.yikers.com\flash\FLVPlayer.swfc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.yikers.com\flash\FLVPlayer.swf\UserVolume.sol 55 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.guba.comc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.guba.com\fc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.guba.com\f\root.swfc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.guba.com\f\root.swf\guba_video.sol 73 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.happymeal.comc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.he.playlist.comc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.he.playlist.com\com.jeroenwijering.players.sol 66 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.he.playlist.com\mcc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.he.playlist.com\mc\mp3player_new.swfc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.he.playlist.com\mc\mp3player_new.swf\ppl5.sol 49 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.he.playlist.com\playersc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.he.playlist.com\players\642aac:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.he.playlist.com\players\642aa\mp3player.swfc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.he.playlist.com\players\642aa\mp3player.swf\ppl5.sol 49 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.comc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flashc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\7595.29c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\7595.29\HeavyVideoPlayer.swfc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\7595.29\HeavyVideoPlayer.swf\json_data.sol 48 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\7809c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\7809\HeavyVideoPlayer.swfc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\7809\HeavyVideoPlayer.swf\json_data.sol 48 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\7859c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\7859\HeavyVideoPlayer.swfc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\7859\HeavyVideoPlayer.swf\json_data.sol 48 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\7859\hp_video_player.swfc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\7859\hp_video_player.swf\marquee_player_volume.sol 51 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\8042.34c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\8042.34\HeavyVideoPlayer.swfc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\8042.34\HeavyVideoPlayer.swf\json_data.sol 48 bytes
c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\8042.36c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\8042.36\HeavyVideoPlayer.swfc:\documents and settings\Owner\Application Data\Macromedia\Flash Player\#SharedObjects\A3ZJ2DEC\
www.heavy.com\flash\8042.36\HeavyVideoPlayer.swf\json_data.sol 48 bytes