[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-08-01 266497]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-08 15872]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-03-14 257088]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime Alternative\qttask.exe" [2007-02-16 282624]
"C-Media Mixer"="Mixer.exe" [2002-10-15 c:\windows\mixer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-01-13 44544]
c:\documents and settings\Jason\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk - c:\program files\CreataCard\Gold\FMRemind.exe [2007-12-24 189952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i263_32.drv
"msacm.imc"= imc32.acm
"msacm.l3codecp"= l3codecp.acm
"VIDC.i263"= i263_32.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0smrgdf c:\program files\iolo\System Mechanic Professional 6\
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
Contents of the 'Scheduled Tasks' folder
2009-01-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
2009-04-07 c:\windows\Tasks\At1.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At10.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At11.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At12.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At13.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At14.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At15.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At16.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At17.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At18.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At19.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At2.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At20.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At21.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At22.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At23.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At24.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At25.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At26.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At27.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At28.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At29.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At3.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At30.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At31.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At32.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At33.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At34.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At35.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At36.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At37.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At38.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At39.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At4.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At40.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At41.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At42.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At43.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At44.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At45.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At46.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At47.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At48.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At49.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At5.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At50.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At51.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At52.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At53.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At54.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At55.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At56.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At57.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At58.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At59.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At6.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At60.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At61.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At62.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At63.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At64.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At65.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At66.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At67.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At68.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-10 c:\windows\Tasks\At69.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At7.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At70.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\At71.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At72.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At8.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-07 c:\windows\Tasks\At9.job
- c:\windows\system32\qP0e8DxE.exe [2009-04-07 13:10]
2009-04-11 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-03-10 22:18]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-PC-Checkup - c:\program files\PC Check-up\PCCheckUp.exe
HKU-Default-Run-msnsc - c:\windows\system32\msnsc.exe
HKU-Default-Run-Cognac - c:\windows\TEMP\12.tmp.exe
.
------- Supplementary Scan -------
.
uStart Page =
uSearchMigratedDefaultURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
uDefault_Search_URL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
mStart Page = about:blank
mSearch Bar = 687474703a2f2f7777772e676f6f676c652e636f6d2f
mSearchMigratedDefaultURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
uInternet Settings,ProxyOverride =
mSearchURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
IE: &Webshots Photo Search - c:\program files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
DPF: {96EEC7FF-106A-47F3-90D6-B4BB754AA40E} - hxxps://autxn.paywithpoli.com/ewcustomer/POLiPayOnline.cab
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-11 14:24:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-11 14:27:13 - machine was rebooted [Jason]
ComboFix-quarantined-files.txt 2009-04-11 04:27:01
Pre-Run: 24,436,391,936 bytes free
Post-Run: 24,450,039,808 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
288 --- E O F --- 2009-04-09 10:20:01