ComboFix 09-04-18.01 - Owner 04/17/2009 14:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.553 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\windows\system32\drivers\gxvxcuvpinbnaihqnikpiyvvttpqgpefyqhrf.sys
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxcdcbltuotqfjvjclaetlujdxjdqchbdvn.dll
C:\xcrashdump.dat
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_GXVXCSERV.SYS
((((((((((((((((((((((((( Files Created from 2009-03-18 to 2009-04-18 )))))))))))))))))))))))))))))))
.
2009-04-17 04:28 . 2009-04-17 04:28 -------- d-----w c:\documents and settings\Owner\.housecall6.6
2009-04-16 20:08 . 2009-04-16 22:01 -------- d--h--w C:\$AVG8.VAULT$
2009-04-16 19:50 . 2009-04-17 04:23 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-16 19:37 . 2009-04-16 19:37 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-16 19:37 . 2009-04-16 19:37 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-04-16 19:37 . 2009-04-16 19:37 325640 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-16 19:37 . 2009-04-17 18:40 -------- d-----w c:\windows\system32\drivers\Avg
2009-04-16 19:37 . 2009-04-16 19:37 -------- d-----w c:\documents and settings\Owner\Application Data\AVGTOOLBAR
2009-04-16 19:37 . 2009-04-16 19:48 -------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-04-16 19:26 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-16 19:26 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 19:26 . 2009-02-06 10:39 35328 -c----w c:\windows\system32\dllcache\sc.exe
2009-04-16 19:26 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 19:26 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-16 19:26 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 19:26 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 19:26 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 19:26 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 19:26 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 19:24 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-16 19:24 . 2009-03-27 06:58 1203922 -c----w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 19:24 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-16 08:17 . 2009-04-16 08:17 -------- d-----w c:\windows\system32\scripting
2009-04-16 08:17 . 2009-04-16 08:17 -------- d-----w c:\windows\l2schemas
2009-04-16 08:17 . 2009-04-16 08:17 -------- d-----w c:\windows\system32\en
2009-04-16 08:17 . 2009-04-16 08:17 -------- d-----w c:\windows\system32\bits
2009-04-16 08:16 . 2009-04-16 08:16 -------- d-----w c:\windows\ServicePackFiles
2009-04-14 12:12 . 2009-04-14 12:12 -------- d-----w C:\THUNDER_ROAD
2009-04-14 11:51 . 2009-04-14 11:51 -------- d-----w C:\TWOFORTHEROAD
2009-04-14 11:22 . 2009-04-14 11:22 -------- d-----w C:\VERA_CRUZ
2009-04-13 17:26 . 2009-04-13 17:26 -------- d-----w C:\IWAKEUPSCREAMING
2009-04-13 14:38 . 2009-04-13 14:38 -------- d-----w C:\COME_BACK_LITTLE_SHEBA
2009-04-06 10:18 . 2009-04-06 10:18 -------- d-----w C:\STALAG17
2009-04-03 11:45 . 2009-04-03 11:45 -------- d-----w C:\LIFEBOAT
2009-03-26 03:55 . 2009-03-26 03:54 36400 ----a-r c:\windows\system32\drivers\SymIM.sys
2009-03-26 03:54 . 2009-03-26 03:54 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-03-26 03:54 . 2009-03-26 03:54 7386 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-03-26 03:53 . 2009-04-16 19:03 -------- d-----w c:\windows\system32\drivers\NIS
2009-03-26 00:50 . 2009-03-26 00:50 -------- d-----w C:\THE_BATTLING_BUTLER
2009-03-25 23:50 . 2009-03-25 23:50 -------- d-----w c:\documents and settings\All Users\Application Data\PCSettings
2009-03-25 23:27 . 2009-03-25 23:50 -------- d-----w c:\documents and settings\All Users\Application Data\Norton
2009-03-25 23:27 . 2009-03-26 03:53 -------- d-----w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-03-25 23:25 . 2009-03-25 23:25 -------- d-----w c:\documents and settings\All Users\Symantec Temporary Files
2009-03-21 14:06 . 2009-03-21 14:06 989696 -c----w c:\windows\system32\dllcache\kernel32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-17 04:23 . 2009-04-16 19:50 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-16 20:41 . 2006-07-17 03:04 -------- d-----w c:\program files\ARES
2009-04-16 19:37 . 2009-04-16 19:37 -------- d-----w c:\program files\AVG
2009-04-16 19:03 . 2006-04-11 15:37 -------- d-----w c:\program files\Norton Internet Security
2009-04-16 18:47 . 2006-08-15 08:03 -------- d-----w c:\program files\DivX
2009-04-16 18:37 . 2006-02-15 12:45 -------- d-----w c:\documents and settings\Administrator\Application Data\AOL
2009-04-16 18:37 . 2006-02-15 12:30 -------- d-----w c:\program files\Common Files\AOL
2009-04-16 18:37 . 2006-02-15 12:30 -------- d-----w c:\documents and settings\All Users\Application Data\AOL
2009-04-16 17:12 . 2005-01-10 01:26 80432 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-16 08:42 . 2006-05-14 05:15 -------- d-----w c:\program files\Yahoo!
2009-04-16 08:42 . 2006-04-14 23:56 -------- d-----w c:\program files\Plaxo
2009-04-16 08:41 . 2006-02-15 12:10 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-16 08:41 . 2006-02-15 12:10 -------- d-----w c:\program files\CyberLink
2009-04-16 08:20 . 2005-01-10 01:10 86811 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-16 08:14 . 2005-01-09 23:49 250048 --sha-r C:\ntldr
2009-03-27 16:01 . 2006-02-15 12:26 -------- d-----w c:\program files\Common Files\Adobe
2009-03-26 09:58 . 2006-04-11 15:35 -------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-03-26 03:54 . 2006-04-11 15:35 -------- d-----w c:\program files\Symantec
2009-03-26 03:54 . 2006-04-11 15:35 60808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-03-26 03:54 . 2006-04-11 15:35 124464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-26 03:53 . 2009-03-26 03:53 -------- d-----w c:\program files\Windows Sidebar
2009-03-26 03:52 . 2006-04-11 15:35 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-03-25 23:47 . 2006-02-15 12:35 -------- d-----w c:\program files\McAfee
2009-03-25 23:43 . 2006-02-15 12:34 -------- d-----w c:\documents and settings\All Users\Application Data\McAfee.com
2009-03-25 23:27 . 2009-03-25 23:27 -------- d-----w c:\program files\NortonInstaller
2009-03-19 21:53 . 2006-02-15 12:12 -------- d-----w c:\program files\Google
2009-03-06 14:22 . 2005-01-09 23:48 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2005-01-09 23:48 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-23 09:50 . 2007-01-28 02:37 -------- d-----w c:\program files\UltimateBet
2009-02-23 09:47 . 2006-04-28 23:54 -------- d-----w c:\program files\Absolute Poker
2009-02-23 09:43 . 2007-05-27 04:03 -------- d-----w c:\program files\PokerStars
2009-02-20 18:09 . 2005-01-09 23:48 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2005-01-09 23:48 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2005-01-09 23:48 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2005-01-09 23:48 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2005-01-09 23:47 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2005-01-09 23:48 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-08 00:02 . 2004-08-04 05:59 2066048 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:11 . 2005-01-09 23:48 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2005-01-09 23:48 2189056 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2005-01-09 23:48 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:59 . 2005-01-09 23:48 56832 ----a-w c:\windows\system32\secur32.dll
2009-01-20 13:42 . 2007-10-02 10:03 2697 ----a-w C:\Cucu_Video_log.txt
2007-08-16 17:10 . 2007-08-16 17:10 774144 ----a-w c:\program files\RngInterstitial.dll
2007-04-19 19:16 . 2007-04-15 01:47 2034 ----a-w c:\documents and settings\Owner\Application Data\SAS7_000.DAT
2007-03-22 12:00 . 2006-04-05 13:34 2272 ----a-w c:\documents and settings\Owner\Application Data\wklnhst.dat
2006-06-13 00:09 . 2006-06-13 00:09 128 ----a-w c:\documents and settings\Owner\Local Settings\Application Data\fusioncache.dat
2005-01-10 01:26 . 2006-04-04 18:52 13104 ----a-w c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-12-19 19:2006-08-15 08:04 53:37 . c:\program files\mozilla firefox\components\jar50.dll
2008-12-19 19:2006-08-15 08:04 53:37 . c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-19 19:2007-12-14 00:04 53:37 . c:\program files\mozilla firefox\components\myspell.dll
2008-12-19 19:2007-12-14 00:04 53:37 . c:\program files\mozilla firefox\components\spellchk.dll
2008-12-19 19:2006-08-15 08:04 53:38 . c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-19 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-09-18 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 49263]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-01-17 58728]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 155648]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-16 19:37 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
backup=c:\windows\pss\NkbMonitor.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
2008-06-19 17:51 50528 ----a-w c:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2005-06-23 17:31 50776 ----a-w c:\program files\America Online 9.0\Email Removedexe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
2009-04-16 19:37 1932568 ----a-w c:\progra~1\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2008-01-17 16:42 58728 ----a-w c:\program files\Common Files\Symantec Shared\CCAPP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2005-11-03 03:01 50792 ----a-w c:\program files\Common Files\AOL\1140006624\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2008-02-19 18:10 267048 ----a-w c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2005-09-18 16:32 7204864 ----a-w c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-02-01 04:13 385024 ----a-w c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\readericon]
2005-08-27 13:09 139264 ----a-w c:\program files\Digital Media Reader\readericon45G.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2006-02-15 12:30 26112 ----a-w c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-14 06:42 212992 ----a-w c:\windows\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
2005-02-26 01:24 966656 ----a-w c:\windows\Creator\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
2004-12-09 01:57 550912 ----a-w c:\windows\zHotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
2005-01-08 01:07 61952 ----a-w c:\windows\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2005-09-18 16:32 1519616 ----a-w c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2005-09-14 19:38 14820864 ----a-w c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\America Online 9.0\\wEmail Removedexe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1140006624\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\1140006624\\EE\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1140006624\\EE\\aim6.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-26 101936]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-16 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-16 108552]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-16 298264]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
.
Contents of the 'Scheduled Tasks' folder
2009-04-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{E1BACF55-35E1-4E47-9247-2D48660E5545} - (no file)
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-AdobeUpdater - c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-Symantec NetDriver Monitor - c:\progra~1\SYMNET~1\SNDMon.exe
MSConfigStartUp-AOL Spyware Protection - c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
MSConfigStartUp-ares - c:\program files\ARES\Ares.exe
MSConfigStartUp-ares lite - c:\program files\ARES\Ares.exe
MSConfigStartUp-MCAgentExe - c:\progra~1\mcafee.com\agent\McAgent.exe
MSConfigStartUp-MCUpdateExe - c:\progra~1\mcafee.com\agent\mcupdate.exe
MSConfigStartUp-MPFExe - c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
MSConfigStartUp-MSKAGENTEXE - c:\progra~1\McAfee\SPAMKI~1\MskAgent.exe
MSConfigStartUp-MSKDetectorExe - c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe
MSConfigStartUp-OASClnt - c:\program files\McAfee.com\VSO\oasclnt.exe
MSConfigStartUp-PlaxoUpdate - c:\program files\Plaxo\2.11.1.5\PlaxoHelper.exe
MSConfigStartUp-Spyware Doctor - c:\progra~1\SPYWAR~1\swdoctor.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
MSConfigStartUp-Symantec NetDriver Monitor - c:\progra~1\SYMNET~1\SNDMon.exe
MSConfigStartUp-VirusScan Online - c:\progra~1\mcafee.com\vso\mcvsshld.exe
MSConfigStartUp-VSOCheckTask - c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.imdb.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{10F055B8-F443-4adf-948A-EC551E9DBCE4} - c:\documents and settings\Owner\Start Menu\Programs\UltimateBet\UltimateBet.lnk
IE: {{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - c:\program files\PartyGaming\PartyCasino\RunCasino.exe
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\7invx9rj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.Email Removed/aolcom/search?invocationType=tbff50ie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: keyword.URL - hxxp://search.Email Removed/aolcom/search?invocationType=TB50TRFF;homepage=no;search=yesab&query=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-17 14:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-04-17 14:12
ComboFix-quarantined-files.txt 2009-04-17 19:11
ComboFix2.txt 2006-12-10 03:51
Pre-Run: 83,933,872,128 bytes free
Post-Run: 83,890,774,016 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
283 --- E O F --- 2009-04-17 00:25