ComboFix 11-10-07.04 - *my*name* 10/07/2011 16:02:25.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.638.231 [GMT -4:00]
Running from: c:\documents and settings\*my*name*\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\*my*name*\g2ax_customer_downloadhelper_win32_x86.exe
c:\documents and settings\*my*name*\GoToAssistDownloadHelper.exe
c:\documents and settings\*my*name*\My Documents\~WRL0004.tmp
c:\documents and settings\*my*name*\My Documents\~WRL0196.tmp
c:\documents and settings\*my*name*\My Documents\~WRL0522.tmp
c:\documents and settings\*my*name*\My Documents\~WRL0650.tmp
c:\documents and settings\*my*name*\My Documents\~WRL0958.tmp
c:\documents and settings\*my*name*\My Documents\~WRL1104.tmp
c:\documents and settings\*my*name*\My Documents\~WRL1311.tmp
c:\documents and settings\*my*name*\My Documents\~WRL1315.tmp
c:\documents and settings\*my*name*\My Documents\~WRL1906.tmp
c:\documents and settings\*my*name*\My Documents\~WRL2206.tmp
c:\documents and settings\*my*name*\My Documents\~WRL2281.tmp
c:\documents and settings\*my*name*\My Documents\~WRL2410.tmp
c:\documents and settings\*my*name*\My Documents\~WRL2454.tmp
c:\documents and settings\*my*name*\My Documents\~WRL2854.tmp
c:\documents and settings\*my*name*\My Documents\~WRL2908.tmp
c:\documents and settings\*my*name*\My Documents\~WRL2985.tmp
c:\documents and settings\*my*name*\My Documents\~WRL2998.tmp
c:\documents and settings\*my*name*\My Documents\~WRL3401.tmp
c:\documents and settings\*my*name*\My Documents\~WRL3406.tmp
c:\documents and settings\*my*name*\My Documents\~WRL3508.tmp
c:\documents and settings\*my*name*\My Documents\~WRL3511.tmp
c:\documents and settings\*my*name*\My Documents\~WRL3642.tmp
c:\documents and settings\*my*name*\My Documents\~WRL3691.tmp
c:\documents and settings\*my*name*\Start Menu\OTL.exe
c:\documents and settings\*my*name*\Start Menu\Programs\Windows XP Recovery
c:\documents and settings\*my*name*\WINDOWS
C:\NORTON~1.EXE
c:\program files\messenger\msmsgsin.exe
c:\windows\system32\config\systemprofile\Application Data\Starware347
c:\windows\system32\config\systemprofile\Application Data\Starware347\BrowserSearch\BrowserSearch.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\BrowserSearch\BrowserSearch.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\EntertainmentMarketingSP\EntertainmentMarketingSPOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\EntertainmentMarketingSP\EntertainmentMarketingSPOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\ErrorSearch\ErrorSearchOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\ErrorSearch\ErrorSearchOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\Games\GamesOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\Games\GamesOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\JokeSearch\JokeSearchOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\JokeSearch\JokeSearchOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\Layouts\PreferencesLayout.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\Layouts\PreferencesLayout.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\Layouts\ToolbarLayout.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\Layouts\ToolbarLayout.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\Manager\ManagerOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\Manager\ManagerOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\Movies\MoviesOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\Movies\MoviesOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\Pranks\PranksOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\Pranks\PranksOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\RelatedSearch\RelatedSearchOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\RelatedSearch\RelatedSearchOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\SearchAssistPlus\SearchAssistPlusOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\SearchAssistPlus\SearchAssistPlusOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\SearchMatch\SearchMatchOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\SearchMatch\SearchMatchOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\Toolbar\TBProductsOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\Toolbar\TBProductsOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\ToolbarLogo\ToolbarLogoOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\ToolbarLogo\ToolbarLogoOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\ToolbarSearch\ToolbarSearchOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\ToolbarSearch\ToolbarSearchOptions.xml.backup
c:\windows\system32\config\systemprofile\Application Data\Starware347\TravelSearch\TravelSearchOptions.xml
c:\windows\system32\config\systemprofile\Application Data\Starware347\TravelSearch\TravelSearchOptions.xml.backup
c:\windows\system32\dumphive.exe
c:\windows\system32\rnaph.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\system
c:\windows\system32\tmp.reg
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Legacy_RPCPATCH
-------\Legacy_RPCTFTPD
.
.
((((((((((((((((((((((((( Files Created from 2011-09-07 to 2011-10-07 )))))))))))))))))))))))))))))))
.
.
2011-10-07 19:51 . 2002-12-19 00:50 167936 ----a-w- c:\windows\system32\LexLog.dll
2011-10-07 18:51 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\hidserv.dll
2011-10-07 18:51 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\dllcache\hidserv.dll
2011-10-07 18:51 . 2001-08-17 17:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2011-10-07 18:51 . 2001-08-17 17:48 12160 ----a-w- c:\windows\system32\dllcache\mouhid.sys
2011-10-07 18:51 . 2008-04-13 18:39 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2011-10-07 18:51 . 2008-04-13 18:39 14592 ----a-w- c:\windows\system32\dllcache\kbdhid.sys
2011-10-07 18:51 . 2008-04-13 18:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2011-10-07 18:51 . 2008-04-13 18:45 10368 ----a-w- c:\windows\system32\dllcache\hidusb.sys
2011-10-07 12:04 . 2011-10-07 12:04 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-07 04:07 . 2011-10-07 04:07 440822 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2011-10-07 02:02 . 2011-10-07 01:11 582656 ----a-w- C:\OTL.com
2011-10-06 15:22 . 2011-10-06 15:22 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\ICS
2011-10-06 14:15 . 2011-09-09 09:12 599040 ------w- c:\windows\system32\dllcache\crypt32.dll
2011-10-06 14:01 . 2011-06-24 14:10 139656 ------w- c:\windows\system32\dllcache\rdpwd.sys
2011-10-06 13:54 . 2011-07-08 14:02 10496 ------w- c:\windows\system32\dllcache\ndistapi.sys
2011-10-06 13:14 . 2010-12-20 17:32 551936 ------w- c:\windows\system32\dllcache\oleaut32.dll
2011-10-06 13:10 . 2011-04-21 13:37 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-10-05 22:13 . 2011-09-18 12:39 134344 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-10-05 22:13 . 2011-09-16 03:55 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2011-10-05 22:13 . 2011-09-16 03:55 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-10-05 22:13 . 2011-10-05 22:13 -------- d-----w- c:\program files\Avira
2011-10-05 22:13 . 2011-10-05 22:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-09 09:12 . 2002-09-23 20:10 599040 ---ha-w- c:\windows\system32\crypt32.dll
2011-07-15 13:29 . 2002-08-29 10:00 456320 ---ha-w- c:\windows\system32\drivers\mrxsmb.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-08-09 417112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-09-23 258512]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-01 18:44 87352 ---ha-w- c:\windows\SYSTEM32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
NvCp1Do REG_SZ C:\sgs.exe
Virscanner REG_SZ c:\windows\smss.exe
AntiVir REG_SZ c:\program files\smss.exe
Msnmsgr.exe REG_SZ c:\lsass.exe
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 8.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 8.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 8.0 Tray Icon.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online Tray Icon.lnk
backup=c:\windows\pss\America Online Tray Icon.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
backup=c:\windows\pss\AOL Companion.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2002-12-17 17:28 684032 ---ha-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-03-09 15:09 63712 ---ha-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CARPService]
2003-01-23 20:06 4608 ---ha-w- c:\windows\SYSTEM32\carpserv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\SYSTEM32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DadApp]
2002-11-01 21:47 208560 ---ha-w- c:\program files\Dell\AccessDirect\DadApp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
2003-04-10 11:52 270336 ---ha-w- c:\program files\Dell AIO Printer A920\dlbkbmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2004-07-19 13:51 306688 ---ha-w- c:\program files\Dell Support\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
2002-07-17 15:18 28672 ---ha-w- c:\windows\SYSTEM32\DSentry.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-10-19 12:59 126976 ---ha-w- c:\windows\SYSTEM32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-10-19 12:59 155648 ---ha-w- c:\windows\SYSTEM32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
2008-07-24 23:46 63048 ---ha-w- c:\program files\LogMeIn\x86\LogMeInSystray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2002-07-16 12:21 28672 ---h--w- c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2002-08-14 22:29 90112 ---ha-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
2002-07-17 16:00 200767 ---ha-w- c:\program files\Microsoft Money\System\mnyexpr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ---ha-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2003-10-07 08:52 77824 ---ha-w- c:\program files\QuickTime\qttask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-04-06 06:27 26105128 ---ha-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-07-12 08:00 132496 ---ha-w- c:\program files\Java\jre1.6.0_02\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2003-05-02 22:15 610304 ---ha-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
2003-05-02 22:21 110592 ---ha-w- c:\program files\Synaptics\SynTP\SynTPLpr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2003-07-25 16:28 151597 ---ha-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2010-08-24 09:38 247144 ---ha-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Verizon_McciTrayApp]
2007-06-06 23:52 936960 ---ha-w- c:\program files\Verizon\McciTrayApp.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 avkmgr;avkmgr;c:\windows\SYSTEM32\DRIVERS\avkmgr.sys [10/5/2011 6:13 PM 36000]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [10/6/2011 12:46 AM 328536]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [10/5/2011 6:13 PM 86224]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 7:46 PM 12856]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [8/24/2010 5:38 AM 92008]
S3 {5C8B2B62-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-A;c:\windows\SYSTEM32\DRIVERS\a311.sys [1/1/1980 1:00 AM 31799]
S3 {5C8B2B65-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-B;c:\windows\SYSTEM32\DRIVERS\a310.sys [1/1/1980 1:00 AM 33335]
S3 BLKWGN;Belkin Wireless G Notebook Card Service;c:\windows\system32\DRIVERS\BLKWGN.sys --> c:\windows\system32\DRIVERS\BLKWGN.sys [?]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\SYSTEM32\DRIVERS\gan_adapter.sys [10/19/2006 11:11 AM 10664]
S3 wlanndi5;wlanndi5 NDIS Protocol Driver;c:\windows\SYSTEM32\wlanndi5.sys [4/21/2004 5:51 PM 16384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-07 c:\windows\Tasks\ASC4_PerformanceMonitor.job
- c:\program files\IObit\Advanced SystemCare 4\PMonitor.exe [2011-10-06 20:40]
.
2003-08-01 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\System32\OOBE\OOBEBALN.EXE [2002-08-29 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/uDefault_Search_URL =
hxxp://www.earthlink.net/partner/more/msie/button/search.htmluInternet Connection Wizard,ShellNext =
hxxp://www.dellnet.com/uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
TCP: DhcpNameServer = 204.186.110.76 216.144.187.37 216.144.187.199
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cabDPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabFF - ProfilePath - c:\documents and settings\*my*name*\Application Data\Mozilla\Firefox\Profiles\1rwdf2qj.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearchFF - prefs.js: browser.search.selectedEngine - iMesh Web Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com/FF - prefs.js: keyword.URL -
hxxp://search.babylon.com/?babsrc=adbartrp&q=FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - Ext: LogMeIn, Inc. Remote Access Plugin:
LogMeInClient@logmein.com - %profile%\extensions\LogMeInClient@logmein.com
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: myBabylon English Toolbar: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - %profile%\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
FF - Ext: HP Smart Web Printing:
smartwebprinting@hp.com - c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF - Ext: HP Smart Web Printing:
smartwebprinting@hp.com - c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{474597C5-AB09-49d6-A4D5-2E8D7341384E} - (no file)
HKU-Default-Run-Virscanner - c:\windows\smss.exe
HKU-Default-Run-AntiVir - c:\program files\smss.exe
HKU-Default-Run-Msnmsgr.exe - c:\lsass.exe
MSConfigStartUp-Advanced SystemCare 3 - c:\program files\IObit\Advanced SystemCare 3\AWC.exe
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-ccRegVfy - c:\program files\Common Files\Symantec Shared\ccRegVfy.exe
MSConfigStartUp-ConMgr - c:\program files\EarthLink 5.0\conmgr.exe
MSConfigStartUp-My Web Search Bar - c:\progra~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL
MSConfigStartUp-MYTffkoXRESS - c:\documents and settings\All Users\Application Data\MYTffkoXRESS.exe
MSConfigStartUp-MyWebSearch Email Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
MSConfigStartUp-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-VerizonServicepoint - c:\program files\Verizon\VSP\VerizonServicepoint.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-10-07 16:32
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(716)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(3448)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\LMIRfsClientNP.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
c:\windows\System32\igfxpph.dll
c:\windows\System32\hccutils.DLL
c:\windows\system32\igfxres.dll
c:\windows\System32\igfxsrvc.dll
c:\windows\System32\igfxdev.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\progra~1\COMMON~1\aol\ACS\acsd.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\System32\logon.scr
.
**************************************************************************
.
Completion time: 2011-10-07 17:33:06 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-07 21:32
.
Pre-Run: 5,071,695,872 bytes free
Post-Run: 5,124,145,152 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - EADE82E39068653563390C3EFDDADBC1