ComboFix 10-05-13.04 - Deb 05/14/2010 13:08:03.1.2 - x86
Microsoft
Windows Vista
Home Premium 6.0.6002.2.1252.1.1033.18.3002.1686 [GMT -5:00]
Running from: c:\users\Deb\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Search Toolbar
c:\program files\Search Toolbar\basis.xml
c:\program files\Search Toolbar\bg.bmp
c:\program files\Search Toolbar\bing_logo.png
c:\program files\Search Toolbar\celebrity.png
c:\program files\Search Toolbar\drop_images.png
c:\program files\Search Toolbar\drop_maps.png
c:\program files\Search Toolbar\drop_news.png
c:\program files\Search Toolbar\drop_videos.png
c:\program files\Search Toolbar\drop_web.png
c:\program files\Search Toolbar\facebook.png
c:\program files\Search Toolbar\favicon.png
c:\program files\Search Toolbar\games.png
c:\program files\Search Toolbar\hotmail.png
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\images.png
c:\program files\Search Toolbar\include.xml
c:\program files\Search Toolbar\info.txt
c:\program files\Search Toolbar\lifestyle.png
c:\program files\Search Toolbar\maps.png
c:\program files\Search Toolbar\messenger.png
c:\program files\Search Toolbar\msn.png
c:\program files\Search Toolbar\news.png
c:\program files\Search Toolbar\SearchToolbar.dll
c:\program files\Search Toolbar\twitter.png
c:\program files\Search Toolbar\uninstall.exe
c:\program files\Search Toolbar\update.exe
c:\program files\Search Toolbar\version.txt
c:\program files\Search Toolbar\video.png
c:\program files\Search Toolbar\videos.png
c:\program files\Search Toolbar\weather.png
c:\program files\Search Toolbar\web.png
c:\users\Deb\AppData\Roaming\02000000b6884f21810C.manifest
c:\users\Deb\AppData\Roaming\02000000b6884f21810O.manifest
c:\users\Deb\AppData\Roaming\02000000b6884f21810P.manifest
c:\users\Deb\AppData\Roaming\02000000b6884f21810S.manifest
c:\users\Deb\SetupDVDDecrypter_3.5.4.0.exe
c:\users\Public\RemoveSGP.exe
c:\users\Public\RemoveSGP0.exe
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\system32\AbaleZip.dll
.
((((((((((((((((((((((((( Files Created from 2010-04-14 to 2010-05-14 )))))))))))))))))))))))))))))))
.
2010-05-14 18:15 . 2010-05-14 18:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-05-14 13:40 . 2010-05-14 13:40 -------- d-----w- C:\_OTL
2010-05-14 12:58 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-14 12:58 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-14 12:58 . 2010-05-14 12:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-14 12:54 . 2010-05-14 12:54 -------- d-----w- c:\users\Deb\AppData\Roaming\HPAppData
2010-05-14 11:37 . 2010-05-14 11:37 310 ----a-w- c:\windows\system32\UnifiedToolbarCleanup.bat
2010-05-13 13:04 . 2010-05-13 13:04 -------- d-----w- c:\program files\Inbox Toolbar
2010-05-12 10:42 . 2010-01-29 15:40 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-10 11:11 . 2010-05-14 11:44 -------- d-----w- c:\programdata\RegCure
2010-05-09 19:25 . 2010-05-09 19:25 -------- d-----w- c:\users\Deb\AppData\Roaming\Malwarebytes
2010-05-09 19:25 . 2010-05-09 19:25 -------- d-----w- c:\programdata\Malwarebytes
2010-05-09 15:31 . 2010-05-09 15:48 -------- d-----w- c:\users\Deb\AppData\Local\clduxrjwe
2010-04-29 17:08 . 2010-04-29 17:08 8851392 ----a-w- c:\users\Deb\AppData\Roaming\Azureus\tmp\AZU6773107062041691641.tmp\Vuze_4.4.0.0a_win32.exe
2010-04-28 02:27 . 2010-04-28 02:27 -------- d-----w- c:\users\Deb\AppData\Local\assembly
2010-04-22 00:30 . 2010-04-22 00:30 -------- d-----w- c:\program files\iPod
2010-04-22 00:30 . 2010-04-22 00:31 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-22 00:30 . 2010-04-22 00:31 -------- d-----w- c:\program files\iTunes
2010-04-22 00:26 . 2010-04-22 00:27 -------- d-----w- c:\program files\QuickTime
2010-04-22 00:19 . 2010-04-22 00:19 -------- d-----w- c:\program files\Bonjour
2010-04-22 00:16 . 2010-04-22 00:16 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-04-19 23:41 . 2010-04-19 23:41 -------- d-----w- c:\users\Deb\AppData\Roaming\Uniblue
2010-04-19 23:41 . 2010-04-19 23:41 -------- d-----w- c:\program files\Uniblue
2010-04-19 23:39 . 2010-04-19 23:40 4071208 ----a-w- c:\users\Deb\registrybooster.exe
2010-04-19 23:36 . 2010-04-19 23:36 3370619 ----a-w- c:\users\Deb\MagicDVDRipper542.exe
2010-04-16 00:33 . 2010-04-16 00:35 -------- d-----w- c:\program files\Common Files\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-14 11:42 . 2010-04-10 12:30 -------- d-----w- c:\users\Deb\AppData\Roaming\NBC Direct
2010-05-14 11:42 . 2010-04-10 12:29 -------- d-----w- c:\programdata\NBC Direct
2010-05-14 11:42 . 2010-04-10 12:30 -------- d-----w- c:\users\Deb\AppData\Roaming\IDM
2010-05-14 11:42 . 2010-04-10 12:29 -------- d---a-w- c:\program files\NBC Direct
2010-05-13 08:02 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-13 08:02 . 2009-04-22 14:57 -------- d-----w- c:\programdata\Microsoft Help
2010-05-11 09:50 . 2009-08-13 02:22 -------- d-----w- c:\program files\Google
2010-05-10 19:36 . 2009-10-18 13:09 -------- d-----w- c:\users\Deb\AppData\Roaming\HpUpdate
2010-05-10 12:03 . 2009-08-08 21:11 76624 ----a-w- c:\users\Deb\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-02 12:50 . 2010-01-06 18:27 -------- d-----w- c:\users\Deb\AppData\Roaming\Azureus
2010-04-22 00:33 . 2009-09-19 21:40 -------- d-----w- c:\users\Deb\AppData\Roaming\Apple Computer
2010-04-22 00:30 . 2009-09-19 21:30 -------- d-----w- c:\program files\Common Files\Apple
2010-04-22 00:13 . 2009-08-19 03:15 -------- d-----w- c:\programdata\Apple
2010-04-15 23:49 . 2010-03-08 01:44 1335048 ----a-w- c:\windows\Help\OEM\scripts\SamsungHDDFW1HC.exe
2010-04-10 12:29 . 2010-04-10 12:29 -------- d-----w- c:\programdata\PMB Files
2010-04-10 12:29 . 2010-04-10 12:29 -------- d-----w- c:\program files\Pando Networks
2010-04-08 21:48 . 2010-04-25 22:13 18184 ----a-w- c:\windows\Help\OEM\scripts\HPHC_BUY_BATTERY.exe
2010-04-08 21:48 . 2010-03-14 21:24 17160 ----a-w- c:\windows\Help\OEM\scripts\HPHCDisableObject.exe
2010-04-06 22:52 . 2010-04-25 22:13 18184 ----a-w- c:\windows\Help\OEM\scripts\HC_Launch.exe
2010-04-02 10:53 . 2010-04-02 10:53 49152 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-04-02 10:53 . 2010-04-02 10:53 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-04-02 10:53 . 2010-04-02 10:53 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-04-02 10:53 . 2010-04-02 10:53 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-04-02 10:53 . 2010-04-02 10:53 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-04-02 10:53 . 2010-04-02 10:53 308808 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-04-02 10:53 . 2010-04-02 10:53 14848 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-04-02 10:53 . 2010-03-14 22:29 40960 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-04-02 10:53 . 2010-03-14 22:29 341600 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-04-02 10:53 . 2009-08-09 20:55 -------- d-----w- c:\program files\Common Files\Real
2010-04-02 10:52 . 2009-08-09 20:55 -------- d-----w- c:\program files\Real
2010-04-02 10:52 . 2010-04-02 10:52 -------- d-----w- c:\program files\Common Files\xing shared
2010-03-30 12:12 . 2010-03-30 12:12 137216 ----a-w- c:\programdata\WorldWinner.com\WorldWinner Games\1.0\shared\fmod.dll
2010-03-30 12:12 . 2010-03-30 12:12 -------- d-----w- c:\programdata\WorldWinner.com
2010-03-30 12:05 . 2010-03-27 18:01 1769240 ----a-w- c:\programdata\WildTangent\My HP Game Console\Downloads\en-us\Installers\SetupGamesClient.exe
2010-03-27 16:11 . 2009-04-22 14:16 -------- d-----w- c:\programdata\WildTangent
2010-03-27 16:06 . 2010-03-27 16:06 -------- d-----w- c:\programdata\Sony Online Entertainment
2010-03-27 16:04 . 2010-03-27 16:04 -------- d-----w- c:\users\Deb\AppData\Roaming\WildTangent
2010-03-25 23:18 . 2010-03-25 23:18 439816 ----a-w- c:\users\Deb\AppData\Roaming\Real\Update\setup3.11\setup.exe
2010-03-25 08:02 . 2010-03-23 21:57 -------- d-----w- c:\program files\Movie Maker 2.6
2010-03-14 22:25 . 2010-03-14 22:25 20841968 ----a-w- c:\users\Deb\RealPlayerSPGold.exe
2010-03-06 21:00 . 2010-03-06 21:00 439816 ----a-w- c:\users\Deb\AppData\Roaming\Real\Update\setup3.10\setup.exe
2010-03-05 14:01 . 2010-04-14 10:10 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-24 23:01 . 2010-03-11 02:54 108544 --s-a-r- c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
2010-02-24 22:59 . 2010-03-11 02:54 179200 --s-a-r- c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
2010-02-23 11:10 . 2010-04-14 10:10 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-23 11:10 . 2010-04-14 10:10 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-02-23 11:10 . 2010-04-14 10:10 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 06:39 . 2010-03-31 10:32 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-31 10:32 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:33 . 2010-03-31 10:32 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 04:55 . 2010-03-31 10:32 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:06 . 2010-03-10 13:01 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-10 13:01 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-10 13:01 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-02-18 14:07 . 2010-04-14 10:10 904576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-18 14:07 . 2010-04-14 10:10 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-18 14:07 . 2010-04-14 10:10 3600776 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-18 13:30 . 2010-04-14 10:10 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-02-18 11:28 . 2010-04-14 10:10 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2009-04-22 14:18 . 2009-04-22 14:09 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{20FEC4E7-F7B7-438B-8191-33D2EFC5EBEA}]
2010-01-22 02:32 614400 ----a-w- c:\program files\Shop to Win 2\ShoppingBHO.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
2010-02-22 22:05 2353176 ----a-w- c:\program files\PageRage\tbPage.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2010-02-24 23:01 194912 ------w- c:\program files\Yontoo Layers Client\YontooIEClient.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9565115d-c7d6-46d3-bd63-b67b481a4368}"= "c:\program files\PageRage\tbPage.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9565115D-C7D6-46D3-BD63-B67B481A4368}"= "c:\program files\PageRage\tbPage.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9565115d-c7d6-46d3-bd63-b67b481a4368}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-09-30 972080]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-13 39408]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-31 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-10 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-10 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-10 145944]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-24 468264]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-07 210216]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2008-11-15 218408]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-02 202256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
c:\users\Deb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2010-04-10 12:29 2937528 ----a-w- c:\program files\Pando Networks\Media Booster\PMB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):70,13,90,20,da,53,ca,01
R2 gupdate1ca1bbd238535f0;Google Update Service (gupdate1ca1bbd238535f0);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-13 133104]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SYMEFA.SYS [2009-08-22 310320]
S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys [2009-08-22 259632]
S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\N360\0308000.029\ccHPx86.sys [2009-08-22 482432]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100505.001\IDSvix86.sys [2009-10-28 343088]
S2 N360;Norton 360;c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe [2009-08-22 117640]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-10-06 365952]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-10-21 102448]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-06-29 112128]
S3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS [2009-08-22 48688]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-21 16896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-05-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-13 02:22]
2010-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-13 02:23]
2010-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-13 02:23]
2010-05-07 c:\windows\Tasks\HPCeeScheduleForDeb.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2009-04-22 18:34]
2010-05-14 c:\windows\Tasks\Norton Security Scan for Deb.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-03-08 05:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fptb-hpd03
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=127.0.0.1:5555
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: CabBuilder - hxxp://www.imgag.com/kiw/toolbar/download/InstallerControl.cab
DPF: {36299202-09EF-4ABF-ADB9-47C599DBE778} - hxxps://www.hpwindows7upgrade.arvato.com/north_america/Endcustomer/HPProdDetect.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
WebBrowser-{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - (no file)
WebBrowser-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
HKLM-Run-hpqSRMon - (no file)
MSConfigStartUp-DirectPlayerCore - c:\program files\NBC Direct\DirectPlayerCore.exe
AddRemove-{F46BF5EA-0B4E-4A41-8C4B-3B127346E30F} - c:\users\Deb\AppData\Local\{8C881E6D-E5A1-4765-AF9A-1AE1E78B41CD}\NBCDirectInstaller.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-14 13:17
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.0.41\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-05-14 13:20:46
ComboFix-quarantined-files.txt 2010-05-14 18:20
Pre-Run: 166,852,853,760 bytes free
Post-Run: 166,979,362,816 bytes free
- - End Of File - - A687618B2B2ECDEE9D98DC20075CBEDE