Is there a reason this is not visible????
ComboFix 10-06-25.02 - Melissa 06/28/2010 5:39.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2912 [GMT -4]
Running from: c:\documents and settings\Melissa\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Melissa\Desktop\CFscript.txt
AV: Norton 360 *On-access scanning disabled* (Updated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
FW: Norton 360 *disabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-28 )))))))))))))))))))))))))))))))
.
2010-06-26 17:14 . 2010-06-26 17:14 -------- d-----w- c:\program files\ESET
2010-06-14 11:26 . 2010-06-14 11:26 -------- d-----w- c:\documents and settings\Jason\Application Data\Apple Computer
2010-06-13 13:13 . 2010-06-13 13:13 -------- d-----w- c:\program files\iPod
2010-06-13 13:13 . 2010-06-13 13:13 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-13 13:05 . 2010-06-13 13:05 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-06-13 13:04 . 2010-06-13 13:04 -------- d-----w- c:\program files\Bonjour
2010-06-13 12:52 . 2010-06-13 12:52 71992 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-10 04:27 . 2010-05-06 10:41 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-28 09:38 . 2008-07-12 02:08 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-06-28 01:46 . 2009-08-19 16:00 256 ----a-w- c:\windows\system32\pool.bin
2010-06-24 13:19 . 2008-07-12 02:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-06-22 22:54 . 2009-12-28 01:33 -------- d-----w- c:\documents and settings\Melissa\Application Data\ZoomBrowser EX
2010-06-22 20:49 . 2009-12-28 01:32 -------- d-----w- c:\documents and settings\Melissa\Application Data\CameraWindowDC
2010-06-18 11:37 . 2008-09-04 16:48 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-06-14 01:00 . 2009-12-04 03:01 82408 ---ha-w- c:\windows\system32\mlfcache.dat
2010-06-13 13:15 . 2008-04-07 00:05 -------- d-----w- c:\documents and settings\Melissa\Application Data\Apple Computer
2010-06-13 13:13 . 2009-12-04 00:57 -------- d-----w- c:\program files\iTunes
2010-06-13 13:13 . 2009-12-05 01:52 -------- d-----w- c:\program files\Common Files\Apple
2010-06-13 13:10 . 2009-12-04 00:56 -------- d-----w- c:\program files\QuickTime
2010-06-13 12:54 . 2010-04-01 18:09 -------- d-----w- c:\program files\Safari
2010-06-13 12:51 . 2008-04-07 00:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-06-10 13:29 . 2010-01-23 21:49 -------- d-----w- c:\program files\Microsoft Silverlight
2010-05-19 03:14 . 2009-03-15 12:19 -------- d-----w- c:\program files\Roxio Creator 2009
2010-05-19 03:11 . 2008-04-02 13:26 -------- d-----w- c:\program files\Common Files\Roxio Shared
2010-05-19 03:11 . 2008-07-12 02:10 -------- d-----w- c:\program files\Windows Sidebar
2010-05-19 03:11 . 2009-03-14 02:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Roxio
2010-05-15 11:17 . 2010-04-29 00:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-05-13 23:18 . 2010-05-13 23:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-05-13 23:18 . 2010-05-13 23:18 -------- d-----w- c:\documents and settings\Melissa\Application Data\Office Genuine Advantage
2010-05-08 12:05 . 2008-04-19 23:40 -------- d-----w- c:\documents and settings\Melissa\Application Data\gtk-2.0
2010-05-06 10:41 . 2004-08-11 22:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-11 22:00 1851264 ------w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-11 22:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-16 12:33 . 2009-12-05 01:52 41472 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-04-16 12:33 . 2009-12-05 01:52 3003680 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-04-14 21:24 . 2009-11-25 21:43 79488 ----a-w- c:\documents and settings\Melissa\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-04-12 17:39 . 2010-04-29 00:05 1808752 ----a-w- c:\documents and settings\All Users\Application Data\Norton\NUA.exe
2010-04-08 17:20 . 2010-04-08 17:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 17:20 . 2010-04-08 17:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-01 18:08 . 2010-04-01 18:08 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2010-03-31 04:16 . 2010-03-31 04:16 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-03-31 04:10 . 2010-03-31 04:10 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2009-04-01 02:47 . 2008-12-13 02:30 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
.
(((((((((((((((((((((((((((((
SnapShot@2010-06-26_12.40.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-28 09:38 . 2010-06-28 09:38 16384 c:\windows\Temp\Perflib_Perfdata_6e8.dat
+ 2010-06-28 09:39 . 2010-06-28 09:39 16384 c:\windows\Temp\Perflib_Perfdata_360.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PDAV appUpdater"="c:\program files\PDA Verticals Corp\appUpdater\appUpdater.exe" [2008-09-30 274432]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-09-26 2356088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2001-10-06 24576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-14 136600]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-28 137752]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-28 141848]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-26 178712]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-28 162328]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-02 1838592]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"BuildBU"="c:\dell\bldbubg.exe" [2004-02-19 61440]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-08-01 1036288]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-05-14 623888]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-10 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-10 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-01-19 1150976]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2009-01-09 114688]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
c:\documents and settings\Melissa\Start Menu\Programs\Startup\
Monitor My eRooms (V7).lnk - c:\program files\eRoom 7\ERClient7.exe [2009-4-11 153352]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2009-5-13 1701136]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-8-7 24633]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"2051:UDP"= 2051:UDP:Windows Media Format SDK (iexplore.exe)
"2050:UDP"= 2050:UDP:Windows Media Format SDK (iexplore.exe)
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [1/23/2007 3:58 AM 133968]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/18/2008 3:37 PM 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/10/2010 6:13 AM 102448]
S3 AsfAlrt;AsfAlrt Service;c:\windows\system32\drivers\Asfalrt.sys [1/23/2007 3:45 AM 42832]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/12/2008 10:32 PM 23888]
S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;"c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe" --> c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2010-06-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-06-28 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 19:07]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} -
hxxps://eroom.newyorklife.com/eRoomSetup/client.cabDPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} -
hxxps://mycampus.phoenix.edu/secure/PhxStudent15.CABFF - ProfilePath - c:\documents and settings\Melissa\Application Data\Mozilla\Firefox\Profiles\qojqdfgn.default\
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - plugin: c:\documents and settings\Melissa\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\program files\Canon\ZoomBrowser EX\Program\NPCIG.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npeRoom7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
disk not found C:\
please note that you need administrator rights to perform deep scan
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
Completion time: 2010-06-28 05:47:32
ComboFix-quarantined-files.txt 2010-06-28 09:47
ComboFix2.txt 2010-06-28 01:59
ComboFix3.txt 2010-06-26 12:41
ComboFix4.txt 2010-06-26 02:51
ComboFix5.txt 2010-06-28 09:36
Pre-Run: 189,127,458,816 bytes free
Post-Run: 189,116,764,160 bytes free
- - End Of File - - 950C9141733657330A088401467A7A92
Last edited by MLeonardRN on 28th June 2010, 9:56 am; edited 2 times in total