ComboFix 09-02-27.01 - Sriram 2009-02-27 19:02:29.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.348 [GMT -5:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Sriram\Desktop\CFScript.txt AV: Norton AntiVirus *On-access scanning disabled* (Updated) FW: Norton AntiVirus *disabled* * Created a new restore point FILE :: c:\windows\srnlwcdh c:\windows\system32\fasirozi.dll c:\windows\system32\rezizafo.dll . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Sriram\Application Data\cogad c:\windows\srnlwcdh c:\windows\system32\fasirozi.dll c:\windows\system32\rezizafo.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_MRTRATE -------\Legacy_SRNLWCDH -------\Service_srnlwcdh ((((((((((((((((((((((((( Files Created from 2009-01-28 to 2009-02-28 ))))))))))))))))))))))))))))))) . 2009-02-27 13:37 . 2009-02-27 13:19 15,688 --a------ c:\windows\system32\lsdelete.exe 2009-02-27 13:19 . 2009-02-27 13:19 64,160 --a------ c:\windows\system32\drivers\Lbd.sys 2009-02-27 13:17 . 2009-02-27 13:19 d-------- c:\documents and settings\All Users\Application Data\Lavasoft 2009-02-27 13:17 . 2009-02-27 13:18 d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-02-27 13:05 . 2009-02-27 13:05 230 --a------ c:\windows\system32\spupdsvc.inf 2009-02-27 00:00 . 2009-02-26 23:45 102,664 --a------ c:\windows\system32\drivers\tmcomm.sys 2009-02-26 23:45 . 2009-02-27 16:13 d-------- c:\documents and settings\Sriram\.housecall6.6 2009-02-26 08:49 . 2009-02-26 08:49 2,713 ---hs---- c:\windows\system32\pinapoyo.dll 2009-02-23 08:48 . 2009-02-23 08:48 d-------- c:\program files\Trend Micro 2009-02-22 12:35 . 2009-02-23 08:41 2,560 --a------ c:\windows\system32\drivers\mchInjDrv.sys 2009-02-21 14:18 . 2009-02-21 14:18 d-------- c:\documents and settings\Sriram\Application Data\PC Tools 2009-02-21 14:18 . 2008-08-25 12:36 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys 2009-02-21 14:18 . 2008-08-25 12:36 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys 2009-02-21 14:18 . 2008-08-25 12:36 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys 2009-02-21 14:18 . 2008-06-02 16:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys 2009-02-21 13:26 . 2009-02-21 13:26 d-a------ c:\program files\Norton Support 2009-02-21 13:10 . 2009-02-21 13:09 36,272 -ra------ c:\windows\system32\drivers\SymIM.sys 2009-02-21 13:09 . 2009-02-21 13:10 d-------- c:\program files\Symantec 2009-02-21 13:09 . 2009-02-21 13:09 124,464 --a------ c:\windows\system32\drivers\SYMEVENT.SYS 2009-02-21 13:09 . 2009-02-21 13:09 60,808 --a------ c:\windows\system32\S32EVNT1.DLL 2009-02-21 13:09 . 2009-02-21 13:09 10,635 --a------ c:\windows\system32\drivers\SYMEVENT.CAT 2009-02-21 13:09 . 2009-02-21 13:09 806 --a------ c:\windows\system32\drivers\SYMEVENT.INF 2009-02-21 13:08 . 2009-02-21 13:08 d-------- c:\windows\system32\drivers\NAV 2009-02-21 13:08 . 2009-02-21 13:08 d-------- c:\program files\Windows Sidebar 2009-02-21 13:08 . 2009-02-21 13:08 d-------- c:\program files\Norton AntiVirus 2009-02-21 13:08 . 2009-02-21 13:13 d-------- c:\documents and settings\All Users\Application Data\Norton 2009-02-21 13:07 . 2009-02-21 13:07 d-------- c:\program files\NortonInstaller 2009-02-21 12:36 . 2009-02-21 12:36 d-------- c:\documents and settings\All Users\Application Data\NortonInstaller 2009-02-21 12:10 . 2009-02-23 09:36 d-a------ c:\documents and settings\All Users\Application Data\TEMP 2009-02-21 12:09 . 2009-02-22 12:45 d-------- c:\program files\Spyware Doctor 2009-02-21 09:06 . 2009-02-21 09:06 d-------- C:\My Downloads 2009-02-21 09:03 . 2009-02-21 09:03 d-------- c:\documents and settings\Sriram\Application Data\VirusRemover2009 2009-02-21 08:54 . 2009-02-21 08:54 d-------- C:\Cache 2009-02-21 08:50 . 2009-02-21 08:50 25,088 --a------ c:\windows\system32\drivers\linofmof.sys 2009-02-10 15:01 . 2009-02-21 08:57 d-------- c:\program files\CA Yahoo! Anti-Spy . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-28 00:00 --------- d-----w c:\program files\Common Files\Adobe 2009-02-27 23:41 --------- d-----w c:\program files\HP 2009-02-27 23:32 --------- d--h--w c:\program files\InstallShield Installation Information 2009-02-27 23:26 --------- d-----w c:\program files\Skype 2009-02-27 23:21 --------- d-----w c:\program files\Quicken 2009-02-27 23:18 --------- d-----w c:\program files\Palm 2009-02-27 21:27 --------- d-----w c:\program files\Microsoft Money 2009-02-27 21:23 --------- d-----w c:\program files\DivX 2009-02-27 21:22 --------- d-----w c:\program files\Acro Software 2009-02-27 18:17 --------- d-----w c:\program files\Lavasoft 2009-02-27 14:33 --------- d-----w c:\documents and settings\Sriram\Application Data\Lavasoft 2009-02-21 18:14 --------- d-----w c:\program files\Common Files\Symantec Shared 2009-02-21 17:05 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec 2009-02-15 14:46 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion 2009-02-15 14:45 --------- d--h--r c:\documents and settings\All Users\Application Data\yahoo! 2009-02-15 14:45 --------- d-----w c:\program files\Yahoo! 2009-02-11 03:28 --------- d-----w c:\program files\Google 2009-02-10 20:01 --------- d-----w c:\program files\Common Files\Scanner 2008-10-01 23:27 122,880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll 2008-10-12 11:54 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101220081013\index.dat . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ---- Directory of c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800} ---- 2009-02-27 13:18 9022 --a--c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.par 2009-02-27 13:18 90 --a--c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\instance.dat 2009-02-27 13:18 9 --a--c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.lan 2009-02-27 13:18 493 --a--c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.dat 2009-01-18 16:43 578782 --a--c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\mia.lib 2009-01-18 16:43 569856 --a--c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.msi 2009-01-18 16:43 5113482 --a--c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.res 2009-01-18 16:43 2892112 --a--c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe ------- Sigcheck ------- 2004-09-29 13:27 656896 2c07195588d69a067c2afdaa31759295 c:\windows\$hf_mig$\KB834707\SP2QFE\wininet.dll 2005-01-27 12:08 657920 a8eac5330876548e9966a7d13025d196 c:\windows\$hf_mig$\KB867282\SP2QFE\wininet.dll 2005-05-02 15:57 658944 e1e18136f9dd3df1ad9c82193a5898a6 c:\windows\$hf_mig$\KB883939\SP2QFE\wininet.dll 2005-03-10 02:43 657920 c8663b488996e89a84c3d17c1d12b79e c:\windows\$hf_mig$\KB890923\SP2QFE\wininet.dll 2005-09-02 18:53 660480 97a6fd7cafd688cf2c78939ebaf0cd0c c:\windows\$hf_mig$\KB896688\SP2QFE\wininet.dll 2005-07-02 21:09 659456 6e533d155b259eb2363d3e04b5be309f c:\windows\$hf_mig$\KB896727\SP2QFE\wininet.dll 2005-10-20 22:38 661504 af785c4947676a7fc1673fdc5c8d0b5b c:\windows\$hf_mig$\KB905915\SP2QFE\wininet.dll 2006-03-03 22:58 663552 c0845ecbf4f9164e618ee381b79c9032 c:\windows\$hf_mig$\KB912812\SP2QFE\wininet.dll 2006-05-10 00:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll 2006-06-23 06:25 664576 64ce26db72810b30f7855ea51e1df836 c:\windows\$hf_mig$\KB918899\SP2QFE\wininet.dll 2006-09-14 03:31 664576 d207370287cf769aebebf03837784963 c:\windows\$hf_mig$\KB922760\SP2QFE\wininet.dll 2007-03-07 12:40 823296 b8f4db39ca7353752f245379d285c80e c:\windows\$hf_mig$\KB931768-IE7\SP2QFE\wininet.dll 2007-04-25 04:08 823808 431defbb4a3d7b0dc062c1b064623a2f c:\windows\$hf_mig$\KB933566-IE7\SP2QFE\wininet.dll 2007-06-27 09:40 824320 d6ed5e042c5207553e7f5e842918137f c:\windows\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll 2007-08-20 05:02 825344 357d54bf94fe9d6d8505a96b5c2a3bca c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll 2007-10-10 18:47 825344 0e5d918f87efa7d2424d66b499c7eb04 c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll 2007-12-06 21:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll 2008-03-01 08:03 827392 6316c2f0c61271c8abdff7429174879e c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll 2008-04-22 22:35 827392 41546b396a526918da7995a02ea04e51 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll 2008-06-23 11:01 827904 c66402a06b83b036c195242c0c8cf83c c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll 2008-08-26 04:08 827904 77c192fe56a70d7fa0247ba0a6201c32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll 2008-10-16 15:24 827904 0d5b75171ff51775b630a431b6c667e8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll 2008-12-20 18:56 827904 044e0a4e9fe97c0fb9afe9c89e2a82e6 c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll 2005-03-10 03:02 656896 6f018d6319be4f96426ea829b79e05d5 c:\windows\$NtUninstallKB883939$\wininet.dll 2005-07-02 21:11 658432 5b5ff992c0fa762ccf8655fc290e6e52 c:\windows\$NtUninstallKB896688$\wininet.dll 2005-05-02 15:52 657920 1a078af3f85d10ba56444c23b3a18e74 c:\windows\$NtUninstallKB896727$\wininet.dll 2005-09-02 18:52 658432 af61ebb1f550175eff406d545d6ab086 c:\windows\$NtUninstallKB905915$\wininet.dll 2005-10-20 22:39 658432 e7b27b6b6e06ce34ea019fd8b858c613 c:\windows\$NtUninstallKB912812$\wininet.dll 2006-03-03 22:33 658432 1c0979c7a489bee573cd0bf4ad94bb06 c:\windows\$NtUninstallKB916281$\wininet.dll 2006-05-10 00:23 658432 38ab7a56f566d9aaad31812494944824 c:\windows\$NtUninstallKB918899$\wininet.dll 2006-06-23 06:02 658944 2b4db890936430c71419037039502752 c:\windows\$NtUninstallKB922760$\wininet.dll 2007-03-07 12:45 822784 5b35dae6e4886f64d1da58c4e3e01eb9 c:\windows\ie7updates\KB933566-IE7\wininet.dll 2007-10-10 18:56 824832 30c1e0f34ad2972c72a01db5c74ab065 c:\windows\ie7updates\KB944533-IE7\wininet.dll 2008-03-01 08:06 826368 ad21461aef8244edec2ef18e55e1dcf3 c:\windows\ie7updates\KB950759-IE7\wininet.dll 2008-06-23 11:57 826368 8c13d4a7479fa0a026eda8abce82c0ed c:\windows\ie7updates\KB956390-IE7\wininet.dll 2008-04-13 19:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\ServicePackFiles\i386\wininet.dll 2008-10-16 05:37 659456 6f1e4bfd78c4e0d05ff3725d59b72925 c:\windows\SoftwareDistribution\Download\7bc58354ca50aa200544caaef7677c8a\SP2GDR\wininet.dll 2008-10-16 05:20 667648 93c9d0a216498ee14eb9b26119bb95ee c:\windows\SoftwareDistribution\Download\7bc58354ca50aa200544caaef7677c8a\SP2QFE\wininet.dll 2008-10-15 20:00 666112 1576318bf08d28cc61d1278114ad8d5b c:\windows\SoftwareDistribution\Download\7bc58354ca50aa200544caaef7677c8a\SP3GDR\wininet.dll 2008-10-15 20:04 667136 e8fce58a470999350f64c591557f9e42 c:\windows\SoftwareDistribution\Download\7bc58354ca50aa200544caaef7677c8a\SP3QFE\wininet.dll 2006-09-14 03:39 658944 621af3f6174a3f60677f5230e28bcc07 c:\windows\system32\wininet.dll 2006-09-14 03:39 658944 621af3f6174a3f60677f5230e28bcc07 c:\windows\system32\dllcache\wininet.dll . c:\combofix\temp00 ((((((((((((((((((((((((((((( SnapShot@2009-02-27_16.54.44.99 ))))))))))))))))))))))))))))))))))))))))) . + 2009-02-28 00:15:44 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_174.dat + 2009-02-28 00:14:04 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_664.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-23 68856] "Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-06-07 4670968] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] "CLRHost"="c:\blp\API\Office Tools\bbxlcmd.exe" [2008-12-18 102400] "BackupNotify"="c:\program files\HP\Digital Imaging\bin\backupnotify.exe" [2003-06-22 24576] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" [2007-11-28 583048] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-07-15 110592] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-07-15 618496] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-10 136600] "Share-to-Web Namespace Daemon"="c:\program files\HP\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088] "HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-10-01 29744] "Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412] "CamMonitor"="c:\program files\HP\Digital Imaging\Unload\hpqcmon.exe" [2002-10-07 90112] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-11-13 335872] "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-27 509784] "AGRSMMSG"="AGRSMMSG.exe" [2003-11-19 c:\windows\AGRSMMSG.exe] c:\documents and settings\All Users\Start Menu\Programs\Startup\ BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2003-09-12 503869] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.iv31"= c:\windows\system32\ir32_32.dll "vidc.iv32"= c:\windows\system32\ir32_32.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "InoTask"=2 (0x2) "InoRT"=2 (0x2) "InoRPC"=2 (0x2) "SAVScan"=3 (0x3) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\WINDOWS\\system32\\mmc.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"= "c:\\blp\\Wintrv\\wintrv.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\blp\\API\\bbcomm.exe"= R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-27 64160] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1002000.007\SymEFA.sys [2009-02-21 309296] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1002000.007\BHDrvx86.sys [2009-02-21 255536] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1002000.007\cchpx86.sys [2009-02-21 362544] R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090225.002\IDSxpx86.sys [2009-02-27 276344] R1 mchInjDrv;madCodeHook DLL injection driver;c:\windows\system32\drivers\mchInjDrv.sys [2009-02-22 2560] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096] R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe [2009-02-21 115560] R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [2005-05-06 14336] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-26 101936] R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;c:\windows\system32\drivers\wbsd.sys [2004-04-18 26240] S3 GPCCARD;GPCCARD;c:\windows\system32\drivers\gpccard.sys [2006-06-09 82176] S3 GPR400;GEMPLUS GPR400 PCMCIA Smart Card Reader;c:\windows\system32\drivers\gpr400.sys [2004-10-24 17408] S3 GTwinUSB;GTwinUSB;c:\windows\system32\drivers\GTwinUSB.sys [2002-10-04 61776] S4 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2004-10-17 29744] S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-02-21 356920] S4 YahooAUService;Yahoo! Updater;c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392] . Contents of the 'Scheduled Tasks' folder 2009-02-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-27 13:19] 2009-02-27 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/webhp?sourceid=navclient&ie=UTF-8 uSearch Page = hxxp://www.google.com uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uDefault_Search_URL = hxxp://www.google.com/ie uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie mStart Page = hxxp://www.yahoo.com/ mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm Trusted Zone: blackrock.com\citrix.amrs DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - hxxp://download.sidestep.com/get/k00719/sb028.cab FF - ProfilePath - c:\documents and settings\Sriram\Application Data\Mozilla\Firefox\Profiles\fi2xzsde.gayathri\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-27 19:15:01 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????4?0?9?3??????? ?deB???????????????B? ?????? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus] "ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.2.0.7\diMaster.dll\" /prefetch:1" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-2312533393-450040937-3754819232-1007\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . Completion time: 2009-02-27 19:27:04 - machine was rebooted ComboFix-quarantined-files.txt 2009-02-28 00:26:50 ComboFix2.txt 2009-02-27 21:57:50 Pre-Run: 10,344,058,880 bytes free Post-Run: 10,335,330,304 bytes free 286 --- E O F --- 2009-02-12 04:45:12