sidthereal
New Member
Folks,
need some help repairing a friends comp.
Here are some logs:
ComboFix 09-02-12.03 - The Roses 2009-02-14 5:45:01.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1436 [GMT -5:00]
Running from: c:\documents and settings\The Roses\Desktop\ComboFix.exe
AV: PC-cillin Internet Security - Virus Protection *On-access scanning disabled* (Updated)
FW: PC-cillin Internet Security - Firewall *enabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\The Roses\Application Data\.#
c:\documents and settings\The Roses\Application Data\020000008c849112530C.manifest
c:\documents and settings\The Roses\Application Data\020000008c849112530O.manifest
c:\documents and settings\The Roses\Application Data\020000008c849112530P.manifest
c:\documents and settings\The Roses\Application Data\020000008c849112530S.manifest
c:\program files\Gamevance\gamevancelib32.dll
c:\program files\Gamevance\gvtl.dll
c:\windows\GnuHashes.ini
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\x64
----- BITS: Possible infected sites -----
hxxp://updates.smithmicro.com
.
((((((((((((((((((((((((( Files Created from 2009-01-14 to 2009-02-14 )))))))))))))))))))))))))))))))
.
2009-02-12 13:33 . 2009-02-14 05:45 <DIR> d-------- c:\program files\Gamevance
2009-02-12 08:05 . 2009-02-13 07:29 <DIR> d-------- c:\documents and settings\The Roses\Incomplete
2009-02-11 14:06 . 2009-02-11 14:06 <DIR> d-------- C:\spoolerlogs
2009-02-10 09:29 . 2008-06-19 16:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys
2009-02-10 04:48 . 2009-02-10 04:48 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-02-09 17:45 . 2009-02-09 17:45 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-09 17:45 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-09 17:45 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-09 17:36 . 2009-02-09 17:36 <DIR> d-------- C:\!KillBox
2009-02-09 14:25 . 2009-02-09 14:25 <DIR> d-------- C:\rsit
2009-02-09 14:00 . 2009-02-09 14:00 1,529,241 --a------ c:\program files\SDFix(4).exe
2009-02-09 10:35 . 2009-02-09 18:48 <DIR> d-------- c:\program files\EsetOnlineScanner
2009-02-09 10:19 . 2009-02-09 10:19 <DIR> d-------- C:\VundoFix Backups
2009-02-09 10:19 . 2009-02-09 10:19 119,808 --a------ c:\program files\VundoFix(3).exe
2009-02-09 08:10 . 2009-02-09 08:13 <DIR> d-------- c:\documents and settings\The Roses\Application Data\U3
2009-02-09 07:37 . 2009-02-09 07:37 208,480 --a------ c:\program files\cooking-academy-2-world-cuisine_s1_l1_gF2844T1L1_d432980536.exe
2009-02-09 07:19 . 2009-02-09 07:20 16,939,888 --a------ c:\program files\IE8-WindowsXP-x86-ENU.exe
2009-02-09 07:13 . 2009-02-09 07:13 208,480 --a------ c:\program files\bigfishgames_p32790221_s1_l1.exe
2009-02-09 07:03 . 2009-02-09 07:03 119,808 --a------ c:\program files\VundoFix(2).exe
2009-02-09 07:02 . 2009-02-09 07:02 119,808 --a------ c:\program files\VundoFix.exe
2009-02-07 21:10 . 2009-02-08 22:41 1,355 --a------ c:\windows\imsins.BAK
2009-02-07 21:10 . 2009-02-07 21:10 230 --a------ c:\windows\system32\spupdsvc.inf
2009-02-07 20:32 . 2009-02-07 20:32 578,560 --a------ c:\windows\system32\dllcache\user32.dll
2009-02-07 20:23 . 2009-02-07 20:23 1,529,241 --a------ c:\program files\SDFix(3).exe
2009-02-07 20:22 . 2009-02-07 20:22 1,529,241 --a------ c:\program files\SDFix(2).exe
2009-02-07 20:14 . 2009-02-07 20:53 <DIR> d-------- c:\program files\Lavasoft
2009-02-07 20:09 . 2009-02-07 20:13 34,543,112 --a------ c:\program files\Ad-AwareAE(2).exe
2009-02-07 20:08 . 2009-02-07 20:08 0 --a------ c:\program files\Ad-AwareAE.exe
2009-02-07 19:51 . 2009-02-07 19:51 2,737,800 --a------ c:\program files\mbam-setup(2).exe
2009-02-07 19:45 . 2009-02-07 19:45 791,393 --a------ c:\program files\erunt_setup.exe
2009-02-07 19:44 . 2009-02-07 19:44 9,334 --a------ c:\program files\SysRestorePoint_v13.zip
2009-02-07 19:43 . 2009-02-07 19:43 50,688 --a------ c:\program files\ATF_Cleaner.exe
2009-02-07 19:36 . 2009-02-07 19:36 812,344 --a------ c:\program files\HJTInstall(2).exe
2009-02-06 13:51 . 2009-02-06 13:51 3,171,208 --a------ c:\program files\ccsetup216.exe
2009-02-05 15:25 . 2009-02-05 15:26 4,481,095 --a------ c:\program files\iata55_enu.exe
2009-02-05 15:24 . 2009-02-05 15:25 5,750,160 --a------ c:\program files\iata78_enu.exe
2009-02-05 15:23 . 2009-02-05 15:23 206,576 --a------ c:\program files\f6flpy3287.zip
2009-02-05 15:22 . 2009-02-05 15:22 2,953,176 --a------ c:\program files\iata87enu.exe
2009-02-04 17:38 . 2009-02-04 17:38 83,968 --a------ c:\program files\mp3_codec_KB9182625_ENU.exe
2009-02-04 09:44 . 2009-02-04 09:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\SugarGames
2009-02-04 09:37 . 2009-02-04 09:37 <DIR> d-------- c:\program files\Wendy's Wellness
2009-02-02 14:12 . 2008-04-29 16:23 0 --a------ c:\windows\system32\CUSTOM.DICCUSTOM.DIC
2009-02-02 13:58 . 2009-02-02 14:12 <DIR> d-------- c:\documents and settings\The Roses\Application Data\GetRightToGo
2009-02-02 13:58 . 2009-02-02 13:58 366,032 --a------ c:\program files\X12-30247-DLM.exe
2009-01-30 03:23 . 2009-01-30 03:23 <DIR> d-------- c:\program files\Shop-n-Spree
2009-01-27 11:50 . 2009-01-27 11:50 769,112 --a------ c:\program files\SetupGamevance(6).exe
2009-01-27 08:02 . 2009-01-27 08:02 <DIR> d-------- c:\documents and settings\The Roses\Application Data\Mousechief
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-14 10:47 --------- d-----w c:\program files\Dl_cats
2009-02-14 10:43 586,041 ----a-w c:\program files\eudora.log
2009-02-14 10:43 256,348 ----a-w c:\program files\Audit.log
2009-02-14 10:43 13,216 ----a-w c:\program files\eudora.ini
2009-02-14 10:43 13,124 ----a-w c:\program files\Eudora61Stats.xml
2009-02-14 10:43 --------- d-----w c:\program files\Search
2009-02-14 10:38 11,490 ----a-w c:\program files\LinkHistory.dat
2009-02-14 10:35 373,320 ----a-w c:\program files\Out.toc
2009-02-14 10:35 --------- d-----w c:\program files\spool
2009-02-14 10:33 426,948 ----a-w c:\program files\In.toc
2009-02-14 10:10 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-14 10:06 5,828 ----a-w c:\program files\Trash.mbx
2009-02-14 10:06 322 ----a-w c:\program files\Trash.toc
2009-02-14 09:47 675 ----a-w c:\program files\descmap.pce
2009-02-14 09:47 --------- d-----w c:\program files\Embedded
2009-02-14 09:46 4,315,207 ----a-w c:\program files\Out.mbx
2009-02-14 09:46 3,144 ----a-w c:\program files\History.lst
2009-02-14 09:45 92,536 ----a-w c:\program files\Cheerleading.toc
2009-02-14 09:42 23,793,108 ----a-w c:\program files\In.mbx
2009-02-14 09:32 10,240,047 ----a-w c:\program files\eudorlog.old
2009-02-13 22:32 --------- d-----w c:\program files\icons
2009-02-13 22:20 --------- d-----w c:\program files\attach
2009-02-13 22:18 427,166 ----a-w c:\program files\In.toc.001
2009-02-13 22:10 31,568,185 ----a-w c:\program files\In.mbx.001
2009-02-13 21:59 51,552 ----a-w c:\program files\Broader View.toc
2009-02-13 21:59 1,017,104 ----a-w c:\program files\Broader View.mbx
2009-02-13 12:24 --------- d-----w c:\documents and settings\The Roses\Application Data\LimeWire
2009-02-11 17:31 5,990 ----a-w c:\program files\Saved.toc
2009-02-11 17:31 436,464 ----a-w c:\program files\School.mbx
2009-02-11 17:31 15,800 ----a-w c:\program files\School.toc
2009-02-11 17:31 137,778 ----a-w c:\program files\Saved.mbx
2009-02-11 13:14 101,968 ----a-w c:\program files\Dance.mbx
2009-02-11 13:14 1,630 ----a-w c:\program files\Dance.toc
2009-02-10 14:22 2,667,990 ----a-w c:\program files\Cheerleading.mbx
2009-02-10 14:21 746,274 ----a-w c:\program files\SVEYA.mbx
2009-02-10 14:21 469,669 ----a-w c:\program files\PTO.mbx
2009-02-10 14:21 3,156 ----a-w c:\program files\SVE Breakfast Club.toc
2009-02-10 14:21 25,392 ----a-w c:\program files\SVEYA.toc
2009-02-10 14:21 235,277 ----a-w c:\program files\SVE Breakfast Club.mbx
2009-02-10 14:21 22,994 ----a-w c:\program files\PTO.toc
2009-02-10 09:49 --------- d-----w c:\program files\SUPERAntiSpyware
2009-02-09 15:55 546,483 ----a-w c:\program files\JokesMisc.mbx
2009-02-09 15:55 24,302 ----a-w c:\program files\JokesMisc.toc
2009-02-09 12:12 --------- d-----w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-02-09 02:12 2,284 ----a-w c:\program files\Help.toc
2009-02-09 02:12 101,661 ----a-w c:\program files\Help.mbx
2009-02-08 01:51 --------- d-----w c:\program files\Coupons
2009-02-08 01:14 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-08 01:09 1,787,040 ----a-w c:\program files\Ad-AwareAE.exe.part
2009-02-08 01:05 --------- d-----w c:\program files\iWin Games
2009-02-07 13:34 438,502 ----a-w c:\program files\In.toc.002
2009-02-07 13:28 32,421,437 ----a-w c:\program files\In.mbx.002
2009-02-06 18:52 --------- d-----w c:\program files\CCleaner
2009-02-05 20:27 --------- d-----w c:\program files\Intel
2009-02-04 02:51 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-02 22:37 33,942 ----a-w c:\program files\driving-test.html
2009-01-31 00:52 238,373 ----a-w c:\program files\game.swf
2009-01-30 17:06 338,222 ----a-w c:\program files\Out.toc.001
2009-01-30 16:48 7,510,547 ----a-w c:\program files\Out.mbx.001
2009-01-30 16:23 --------- d-----w c:\program files\iWin.com
2009-01-30 13:24 3,347 ----a-w c:\program files\NNdbase.toc
2009-01-30 13:24 12,314 ----a-w c:\program files\NNdbase.txt
2009-01-30 08:24 --------- d-----w c:\documents and settings\The Roses\Application Data\ViquaSoft
2009-01-30 03:10 702,287 ----a-w c:\program files\Soccer Help.mbx
2009-01-30 03:10 500,788 ----a-w c:\program files\Yearbook.mbx
2009-01-30 03:10 28,226 ----a-w c:\program files\Yearbook.toc
2009-01-30 03:10 22,776 ----a-w c:\program files\Soccer Help.toc
2009-01-30 03:06 8,268,118 ----a-w c:\program files\Out.mbx.002
2009-01-30 03:06 667,838 ----a-w c:\program files\Out.toc.002
2009-01-29 15:07 0 ----a-w c:\program files\updateurl.htm
2009-01-27 20:48 --------- d-----w c:\program files\Abbyy FineReader 6.0 Sprint
2009-01-17 21:01 --------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
2009-01-11 15:14 --------- d-----w c:\documents and settings\All Users\Application Data\JollyBear
2009-01-10 05:04 1,848 ----a-w c:\program files\Van Ness Family.toc
2009-01-10 05:03 3,592 ----a-w c:\program files\Neighborhood Watch.toc
2009-01-10 04:51 82,809 ---ha-w c:\program files\Eudora.GID
2009-01-10 02:49 765,016 ----a-w c:\program files\SetupGamevance(5).exe
2009-01-10 02:37 765,016 ----a-w c:\program files\SetupGamevance(4).exe
2009-01-10 02:37 765,016 ----a-w c:\program files\SetupGamevance(3).exe
2009-01-09 13:52 --------- d-----w c:\program files\Chocolate Shop Frenzy
2009-01-01 15:56 --------- d-----w c:\program files\Megaplex Madness - Now Playing
2008-12-30 19:29 --------- d-----w c:\documents and settings\The Roses\Application Data\Bigfish Ashtons Family Resort
2008-12-30 19:14 --------- d-----w c:\documents and settings\All Users\Application Data\Bigfish Ashtons Family Resort
2008-12-29 14:28 --------- d-----w c:\documents and settings\All Users\Application Data\AOL OCP
2008-12-29 14:27 --------- d-----w c:\program files\AIM6
2008-12-29 14:25 --------- d-----w c:\program files\Viewpoint
2008-12-29 14:25 --------- d-----w c:\program files\Common Files\Software Update Utility
2008-12-29 14:25 --------- d-----w c:\program files\Common Files\AOL
2008-12-29 14:25 --------- d-----w c:\program files\AIM Toolbar
2008-12-29 14:25 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-12-29 14:25 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-12-29 14:25 --------- d-----w c:\documents and settings\All Users\Application Data\AIM Toolbar
2008-12-29 14:25 --------- d-----w c:\documents and settings\All Users\Application Data\acccore
2008-12-29 14:21 13,440,584 ----a-w c:\program files\Install_AIM.exe
2008-12-29 13:41 --------- d-----w c:\documents and settings\All Users\Application Data\Sandlot Games
2008-12-29 13:30 --------- d-----w c:\program files\Ashtons - Family Resort
2008-12-29 01:02 --------- d-----w c:\documents and settings\The Roses\Application Data\PlayFirst
2008-12-29 01:02 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-27 14:46 --------- d-----w c:\documents and settings\The Roses\Application Data\Fuzzy Games
2008-12-27 02:29 --------- d-----w c:\documents and settings\All Users\Application Data\Fitn17
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"OE_OEM"="c:\program files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [2006-08-04 321040]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-07-21 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-07-21 86016]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-07-21 81920]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-01-09 1838592]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-24 17920]
"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-11-03 312200]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 304008]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-06-20 69632]
"CamMonitor"="c:\program files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-06 90112]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 106496]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"Gamevance"="c:\program files\Gamevance\gamevance32.exe" [2009-02-12 105472]
"PMX Daemon"="ICO.EXE" [2006-11-08 c:\windows\system32\ico.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-20 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Billminder.lnk - c:\quickenw\BILLMIND.EXE [2008-07-23 36864]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-01-09 24576]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-10-22 972064]
Quicken Startup.lnk - c:\quickenw\QWDLLS.EXE [2008-07-23 36864]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\EuShlExt.dll" [2006-08-17 86016]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\dlcxjswr32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\iWin Games\\iWinGames.exe"=
"c:\\Program Files\\iWin Games\\WebUpdater.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-02-10 28544]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [2008-12-17 78104]
R2 QuickBooksDB18;QuickBooksDB18;c:\progra~1\Intuit\QUICKB~2\QBDBMgrN.exe -hvQuickBooksDB18 --> c:\progra~1\Intuit\QUICKB~2\QBDBMgrN.exe -hvQuickBooksDB18 [?]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2007-11-08 345696]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2007-11-08 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2007-11-08 566872]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-12-29 24652]
R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-01-16 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-01-16 14336]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2007-11-08 280392]
S2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2007-11-08 923216]
S3 atidgllk;atidgllk;c:\dell\Drivers\R169419\atidgllk.sys [2008-10-24 12048]
S3 yeddef;YEDDEF driver;c:\windows\system32\drivers\yeddef.sys [2007-01-26 19200]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0126616-f6aa-11dd-92bf-001cc033e7a2}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-02-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
2009-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Weather - c:\program files\AWS\WeatherBug\Weather.exe
Notify-dc3ceefe530 - c:\windows\System32\dlcxjswr32.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://www.dell.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\The Roses\Application Data\Mozilla\Firefox\Profiles\5rl43nwh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\documents and settings\The Roses\Application Data\Mozilla\Firefox\Profiles\5rl43nwh.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMySrch.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-14 05:47:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(524)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dlcxcoms.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\progra~1\TRENDM~1\INTERN~1\PcCtlCom.exe
c:\windows\system32\pmxmiced.exe
c:\program files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\progra~1\Intuit\QUICKB~2\QBDBMgrN.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\searchindexer.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
c:\windows\system32\msiexec.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
.
**************************************************************************
.
Completion time: 2009-02-14 5:53:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-14 10:53:53
Pre-Run: 455,007,096,832 bytes free
Post-Run: 454,912,999,424 bytes free
359 --- E O F --- 2009-02-12 03:06:32
need some help repairing a friends comp.
Here are some logs:
ComboFix 09-02-12.03 - The Roses 2009-02-14 5:45:01.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1436 [GMT -5:00]
Running from: c:\documents and settings\The Roses\Desktop\ComboFix.exe
AV: PC-cillin Internet Security - Virus Protection *On-access scanning disabled* (Updated)
FW: PC-cillin Internet Security - Firewall *enabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\The Roses\Application Data\.#
c:\documents and settings\The Roses\Application Data\020000008c849112530C.manifest
c:\documents and settings\The Roses\Application Data\020000008c849112530O.manifest
c:\documents and settings\The Roses\Application Data\020000008c849112530P.manifest
c:\documents and settings\The Roses\Application Data\020000008c849112530S.manifest
c:\program files\Gamevance\gamevancelib32.dll
c:\program files\Gamevance\gvtl.dll
c:\windows\GnuHashes.ini
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\x64
----- BITS: Possible infected sites -----
hxxp://updates.smithmicro.com
.
((((((((((((((((((((((((( Files Created from 2009-01-14 to 2009-02-14 )))))))))))))))))))))))))))))))
.
2009-02-12 13:33 . 2009-02-14 05:45 <DIR> d-------- c:\program files\Gamevance
2009-02-12 08:05 . 2009-02-13 07:29 <DIR> d-------- c:\documents and settings\The Roses\Incomplete
2009-02-11 14:06 . 2009-02-11 14:06 <DIR> d-------- C:\spoolerlogs
2009-02-10 09:29 . 2008-06-19 16:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys
2009-02-10 04:48 . 2009-02-10 04:48 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-02-09 17:45 . 2009-02-09 17:45 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-09 17:45 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-09 17:45 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-09 17:36 . 2009-02-09 17:36 <DIR> d-------- C:\!KillBox
2009-02-09 14:25 . 2009-02-09 14:25 <DIR> d-------- C:\rsit
2009-02-09 14:00 . 2009-02-09 14:00 1,529,241 --a------ c:\program files\SDFix(4).exe
2009-02-09 10:35 . 2009-02-09 18:48 <DIR> d-------- c:\program files\EsetOnlineScanner
2009-02-09 10:19 . 2009-02-09 10:19 <DIR> d-------- C:\VundoFix Backups
2009-02-09 10:19 . 2009-02-09 10:19 119,808 --a------ c:\program files\VundoFix(3).exe
2009-02-09 08:10 . 2009-02-09 08:13 <DIR> d-------- c:\documents and settings\The Roses\Application Data\U3
2009-02-09 07:37 . 2009-02-09 07:37 208,480 --a------ c:\program files\cooking-academy-2-world-cuisine_s1_l1_gF2844T1L1_d432980536.exe
2009-02-09 07:19 . 2009-02-09 07:20 16,939,888 --a------ c:\program files\IE8-WindowsXP-x86-ENU.exe
2009-02-09 07:13 . 2009-02-09 07:13 208,480 --a------ c:\program files\bigfishgames_p32790221_s1_l1.exe
2009-02-09 07:03 . 2009-02-09 07:03 119,808 --a------ c:\program files\VundoFix(2).exe
2009-02-09 07:02 . 2009-02-09 07:02 119,808 --a------ c:\program files\VundoFix.exe
2009-02-07 21:10 . 2009-02-08 22:41 1,355 --a------ c:\windows\imsins.BAK
2009-02-07 21:10 . 2009-02-07 21:10 230 --a------ c:\windows\system32\spupdsvc.inf
2009-02-07 20:32 . 2009-02-07 20:32 578,560 --a------ c:\windows\system32\dllcache\user32.dll
2009-02-07 20:23 . 2009-02-07 20:23 1,529,241 --a------ c:\program files\SDFix(3).exe
2009-02-07 20:22 . 2009-02-07 20:22 1,529,241 --a------ c:\program files\SDFix(2).exe
2009-02-07 20:14 . 2009-02-07 20:53 <DIR> d-------- c:\program files\Lavasoft
2009-02-07 20:09 . 2009-02-07 20:13 34,543,112 --a------ c:\program files\Ad-AwareAE(2).exe
2009-02-07 20:08 . 2009-02-07 20:08 0 --a------ c:\program files\Ad-AwareAE.exe
2009-02-07 19:51 . 2009-02-07 19:51 2,737,800 --a------ c:\program files\mbam-setup(2).exe
2009-02-07 19:45 . 2009-02-07 19:45 791,393 --a------ c:\program files\erunt_setup.exe
2009-02-07 19:44 . 2009-02-07 19:44 9,334 --a------ c:\program files\SysRestorePoint_v13.zip
2009-02-07 19:43 . 2009-02-07 19:43 50,688 --a------ c:\program files\ATF_Cleaner.exe
2009-02-07 19:36 . 2009-02-07 19:36 812,344 --a------ c:\program files\HJTInstall(2).exe
2009-02-06 13:51 . 2009-02-06 13:51 3,171,208 --a------ c:\program files\ccsetup216.exe
2009-02-05 15:25 . 2009-02-05 15:26 4,481,095 --a------ c:\program files\iata55_enu.exe
2009-02-05 15:24 . 2009-02-05 15:25 5,750,160 --a------ c:\program files\iata78_enu.exe
2009-02-05 15:23 . 2009-02-05 15:23 206,576 --a------ c:\program files\f6flpy3287.zip
2009-02-05 15:22 . 2009-02-05 15:22 2,953,176 --a------ c:\program files\iata87enu.exe
2009-02-04 17:38 . 2009-02-04 17:38 83,968 --a------ c:\program files\mp3_codec_KB9182625_ENU.exe
2009-02-04 09:44 . 2009-02-04 09:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\SugarGames
2009-02-04 09:37 . 2009-02-04 09:37 <DIR> d-------- c:\program files\Wendy's Wellness
2009-02-02 14:12 . 2008-04-29 16:23 0 --a------ c:\windows\system32\CUSTOM.DICCUSTOM.DIC
2009-02-02 13:58 . 2009-02-02 14:12 <DIR> d-------- c:\documents and settings\The Roses\Application Data\GetRightToGo
2009-02-02 13:58 . 2009-02-02 13:58 366,032 --a------ c:\program files\X12-30247-DLM.exe
2009-01-30 03:23 . 2009-01-30 03:23 <DIR> d-------- c:\program files\Shop-n-Spree
2009-01-27 11:50 . 2009-01-27 11:50 769,112 --a------ c:\program files\SetupGamevance(6).exe
2009-01-27 08:02 . 2009-01-27 08:02 <DIR> d-------- c:\documents and settings\The Roses\Application Data\Mousechief
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-14 10:47 --------- d-----w c:\program files\Dl_cats
2009-02-14 10:43 586,041 ----a-w c:\program files\eudora.log
2009-02-14 10:43 256,348 ----a-w c:\program files\Audit.log
2009-02-14 10:43 13,216 ----a-w c:\program files\eudora.ini
2009-02-14 10:43 13,124 ----a-w c:\program files\Eudora61Stats.xml
2009-02-14 10:43 --------- d-----w c:\program files\Search
2009-02-14 10:38 11,490 ----a-w c:\program files\LinkHistory.dat
2009-02-14 10:35 373,320 ----a-w c:\program files\Out.toc
2009-02-14 10:35 --------- d-----w c:\program files\spool
2009-02-14 10:33 426,948 ----a-w c:\program files\In.toc
2009-02-14 10:10 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-14 10:06 5,828 ----a-w c:\program files\Trash.mbx
2009-02-14 10:06 322 ----a-w c:\program files\Trash.toc
2009-02-14 09:47 675 ----a-w c:\program files\descmap.pce
2009-02-14 09:47 --------- d-----w c:\program files\Embedded
2009-02-14 09:46 4,315,207 ----a-w c:\program files\Out.mbx
2009-02-14 09:46 3,144 ----a-w c:\program files\History.lst
2009-02-14 09:45 92,536 ----a-w c:\program files\Cheerleading.toc
2009-02-14 09:42 23,793,108 ----a-w c:\program files\In.mbx
2009-02-14 09:32 10,240,047 ----a-w c:\program files\eudorlog.old
2009-02-13 22:32 --------- d-----w c:\program files\icons
2009-02-13 22:20 --------- d-----w c:\program files\attach
2009-02-13 22:18 427,166 ----a-w c:\program files\In.toc.001
2009-02-13 22:10 31,568,185 ----a-w c:\program files\In.mbx.001
2009-02-13 21:59 51,552 ----a-w c:\program files\Broader View.toc
2009-02-13 21:59 1,017,104 ----a-w c:\program files\Broader View.mbx
2009-02-13 12:24 --------- d-----w c:\documents and settings\The Roses\Application Data\LimeWire
2009-02-11 17:31 5,990 ----a-w c:\program files\Saved.toc
2009-02-11 17:31 436,464 ----a-w c:\program files\School.mbx
2009-02-11 17:31 15,800 ----a-w c:\program files\School.toc
2009-02-11 17:31 137,778 ----a-w c:\program files\Saved.mbx
2009-02-11 13:14 101,968 ----a-w c:\program files\Dance.mbx
2009-02-11 13:14 1,630 ----a-w c:\program files\Dance.toc
2009-02-10 14:22 2,667,990 ----a-w c:\program files\Cheerleading.mbx
2009-02-10 14:21 746,274 ----a-w c:\program files\SVEYA.mbx
2009-02-10 14:21 469,669 ----a-w c:\program files\PTO.mbx
2009-02-10 14:21 3,156 ----a-w c:\program files\SVE Breakfast Club.toc
2009-02-10 14:21 25,392 ----a-w c:\program files\SVEYA.toc
2009-02-10 14:21 235,277 ----a-w c:\program files\SVE Breakfast Club.mbx
2009-02-10 14:21 22,994 ----a-w c:\program files\PTO.toc
2009-02-10 09:49 --------- d-----w c:\program files\SUPERAntiSpyware
2009-02-09 15:55 546,483 ----a-w c:\program files\JokesMisc.mbx
2009-02-09 15:55 24,302 ----a-w c:\program files\JokesMisc.toc
2009-02-09 12:12 --------- d-----w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-02-09 02:12 2,284 ----a-w c:\program files\Help.toc
2009-02-09 02:12 101,661 ----a-w c:\program files\Help.mbx
2009-02-08 01:51 --------- d-----w c:\program files\Coupons
2009-02-08 01:14 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-08 01:09 1,787,040 ----a-w c:\program files\Ad-AwareAE.exe.part
2009-02-08 01:05 --------- d-----w c:\program files\iWin Games
2009-02-07 13:34 438,502 ----a-w c:\program files\In.toc.002
2009-02-07 13:28 32,421,437 ----a-w c:\program files\In.mbx.002
2009-02-06 18:52 --------- d-----w c:\program files\CCleaner
2009-02-05 20:27 --------- d-----w c:\program files\Intel
2009-02-04 02:51 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-02 22:37 33,942 ----a-w c:\program files\driving-test.html
2009-01-31 00:52 238,373 ----a-w c:\program files\game.swf
2009-01-30 17:06 338,222 ----a-w c:\program files\Out.toc.001
2009-01-30 16:48 7,510,547 ----a-w c:\program files\Out.mbx.001
2009-01-30 16:23 --------- d-----w c:\program files\iWin.com
2009-01-30 13:24 3,347 ----a-w c:\program files\NNdbase.toc
2009-01-30 13:24 12,314 ----a-w c:\program files\NNdbase.txt
2009-01-30 08:24 --------- d-----w c:\documents and settings\The Roses\Application Data\ViquaSoft
2009-01-30 03:10 702,287 ----a-w c:\program files\Soccer Help.mbx
2009-01-30 03:10 500,788 ----a-w c:\program files\Yearbook.mbx
2009-01-30 03:10 28,226 ----a-w c:\program files\Yearbook.toc
2009-01-30 03:10 22,776 ----a-w c:\program files\Soccer Help.toc
2009-01-30 03:06 8,268,118 ----a-w c:\program files\Out.mbx.002
2009-01-30 03:06 667,838 ----a-w c:\program files\Out.toc.002
2009-01-29 15:07 0 ----a-w c:\program files\updateurl.htm
2009-01-27 20:48 --------- d-----w c:\program files\Abbyy FineReader 6.0 Sprint
2009-01-17 21:01 --------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
2009-01-11 15:14 --------- d-----w c:\documents and settings\All Users\Application Data\JollyBear
2009-01-10 05:04 1,848 ----a-w c:\program files\Van Ness Family.toc
2009-01-10 05:03 3,592 ----a-w c:\program files\Neighborhood Watch.toc
2009-01-10 04:51 82,809 ---ha-w c:\program files\Eudora.GID
2009-01-10 02:49 765,016 ----a-w c:\program files\SetupGamevance(5).exe
2009-01-10 02:37 765,016 ----a-w c:\program files\SetupGamevance(4).exe
2009-01-10 02:37 765,016 ----a-w c:\program files\SetupGamevance(3).exe
2009-01-09 13:52 --------- d-----w c:\program files\Chocolate Shop Frenzy
2009-01-01 15:56 --------- d-----w c:\program files\Megaplex Madness - Now Playing
2008-12-30 19:29 --------- d-----w c:\documents and settings\The Roses\Application Data\Bigfish Ashtons Family Resort
2008-12-30 19:14 --------- d-----w c:\documents and settings\All Users\Application Data\Bigfish Ashtons Family Resort
2008-12-29 14:28 --------- d-----w c:\documents and settings\All Users\Application Data\AOL OCP
2008-12-29 14:27 --------- d-----w c:\program files\AIM6
2008-12-29 14:25 --------- d-----w c:\program files\Viewpoint
2008-12-29 14:25 --------- d-----w c:\program files\Common Files\Software Update Utility
2008-12-29 14:25 --------- d-----w c:\program files\Common Files\AOL
2008-12-29 14:25 --------- d-----w c:\program files\AIM Toolbar
2008-12-29 14:25 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-12-29 14:25 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-12-29 14:25 --------- d-----w c:\documents and settings\All Users\Application Data\AIM Toolbar
2008-12-29 14:25 --------- d-----w c:\documents and settings\All Users\Application Data\acccore
2008-12-29 14:21 13,440,584 ----a-w c:\program files\Install_AIM.exe
2008-12-29 13:41 --------- d-----w c:\documents and settings\All Users\Application Data\Sandlot Games
2008-12-29 13:30 --------- d-----w c:\program files\Ashtons - Family Resort
2008-12-29 01:02 --------- d-----w c:\documents and settings\The Roses\Application Data\PlayFirst
2008-12-29 01:02 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-27 14:46 --------- d-----w c:\documents and settings\The Roses\Application Data\Fuzzy Games
2008-12-27 02:29 --------- d-----w c:\documents and settings\All Users\Application Data\Fitn17
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"OE_OEM"="c:\program files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [2006-08-04 321040]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-07-21 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-07-21 86016]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-07-21 81920]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-01-09 1838592]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-24 17920]
"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-11-03 312200]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 304008]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-06-20 69632]
"CamMonitor"="c:\program files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-06 90112]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 106496]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"Gamevance"="c:\program files\Gamevance\gamevance32.exe" [2009-02-12 105472]
"PMX Daemon"="ICO.EXE" [2006-11-08 c:\windows\system32\ico.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-20 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Billminder.lnk - c:\quickenw\BILLMIND.EXE [2008-07-23 36864]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-01-09 24576]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-10-22 972064]
Quicken Startup.lnk - c:\quickenw\QWDLLS.EXE [2008-07-23 36864]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\EuShlExt.dll" [2006-08-17 86016]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\dlcxjswr32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\iWin Games\\iWinGames.exe"=
"c:\\Program Files\\iWin Games\\WebUpdater.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-02-10 28544]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [2008-12-17 78104]
R2 QuickBooksDB18;QuickBooksDB18;c:\progra~1\Intuit\QUICKB~2\QBDBMgrN.exe -hvQuickBooksDB18 --> c:\progra~1\Intuit\QUICKB~2\QBDBMgrN.exe -hvQuickBooksDB18 [?]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2007-11-08 345696]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2007-11-08 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2007-11-08 566872]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-12-29 24652]
R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-01-16 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-01-16 14336]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2007-11-08 280392]
S2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2007-11-08 923216]
S3 atidgllk;atidgllk;c:\dell\Drivers\R169419\atidgllk.sys [2008-10-24 12048]
S3 yeddef;YEDDEF driver;c:\windows\system32\drivers\yeddef.sys [2007-01-26 19200]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0126616-f6aa-11dd-92bf-001cc033e7a2}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-02-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
2009-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Weather - c:\program files\AWS\WeatherBug\Weather.exe
Notify-dc3ceefe530 - c:\windows\System32\dlcxjswr32.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://www.dell.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\The Roses\Application Data\Mozilla\Firefox\Profiles\5rl43nwh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\documents and settings\The Roses\Application Data\Mozilla\Firefox\Profiles\5rl43nwh.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMySrch.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-14 05:47:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(524)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dlcxcoms.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\progra~1\TRENDM~1\INTERN~1\PcCtlCom.exe
c:\windows\system32\pmxmiced.exe
c:\program files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\progra~1\Intuit\QUICKB~2\QBDBMgrN.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\searchindexer.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
c:\windows\system32\msiexec.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
.
**************************************************************************
.
Completion time: 2009-02-14 5:53:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-14 10:53:53
Pre-Run: 455,007,096,832 bytes free
Post-Run: 454,912,999,424 bytes free
359 --- E O F --- 2009-02-12 03:06:32