ComboFix 10-09-29.01 - Jinju 09/29/2010 18:12:08.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.958.437 [GMT -4:00]
Running from: c:\users\Jinju\Desktop\ComboFix.exe
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-29 )))))))))))))))))))))))))))))))
.
2010-09-29 22:28 . 2010-09-29 22:28 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-29 22:28 . 2010-09-29 22:28 -------- d-----w- c:\users\Jinhee\AppData\Local\temp
2010-09-29 22:28 . 2010-09-29 22:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-29 22:07 . 2010-09-29 22:08 -------- d-----w- C:\32788R22FWJFW
2010-09-28 20:44 . 2010-06-22 12:57 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-23 20:19 . 2010-09-23 20:19 1377632 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-09-23 20:19 . 2010-09-23 20:19 598368 ----a-w- c:\programdata\avg9\update\backup\avgsrmx.dll
2010-09-23 20:19 . 2010-09-23 20:19 942432 ----a-w- c:\programdata\avg9\update\backup\avgcfgx.dll
2010-09-23 20:19 . 2010-09-23 20:19 4371296 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-09-23 20:19 . 2010-09-23 20:19 300896 ----a-w- c:\programdata\avg9\update\backup\avgchclx.dll
2010-09-23 20:15 . 2010-09-23 20:15 1690952 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2010-09-23 07:21 . 2010-04-14 17:47 293376 ----a-w- c:\windows\system32\psisdecd.dll
2010-09-23 07:21 . 2010-04-14 17:46 428544 ----a-w- c:\windows\system32\EncDec.dll
2010-09-23 07:18 . 2009-11-08 14:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-09-23 07:18 . 2009-11-08 14:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-09-23 07:18 . 2009-11-08 14:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-09-23 07:18 . 2009-11-08 14:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-09-23 07:18 . 2009-11-08 14:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-09-23 00:17 . 2010-06-11 15:31 274432 ----a-w- c:\windows\system32\schannel.dll
2010-09-23 00:17 . 2008-08-02 01:01 625152 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-09-23 00:17 . 2008-06-26 03:29 565248 ----a-w- c:\windows\system32\emdmgmt.dll
2010-09-23 00:17 . 2008-08-02 03:26 36864 ----a-w- c:\windows\system32\cdd.dll
2010-09-23 00:17 . 2008-06-26 03:29 45056 ----a-w- c:\windows\system32\dataclen.dll
2010-09-23 00:17 . 2008-05-20 02:07 148480 ----a-w- c:\windows\system32\drivers\nwifi.sys
2010-09-23 00:17 . 2010-05-27 19:16 81920 ----a-w- c:\windows\system32\iccvid.dll
2010-09-23 00:17 . 2009-08-24 12:16 378368 ----a-w- c:\windows\system32\winhttp.dll
2010-09-23 00:17 . 2010-04-05 16:07 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-09-23 00:17 . 2010-06-21 13:18 2036736 ----a-w- c:\windows\system32\win32k.sys
2010-09-23 00:08 . 2010-06-08 17:00 3598216 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-09-23 00:08 . 2010-06-08 17:00 3545992 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-09-23 00:07 . 2010-04-16 16:10 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-09-23 00:07 . 2010-06-11 15:30 1257472 ----a-w- c:\windows\system32\msxml3.dll
2010-09-23 00:07 . 2008-09-18 04:56 125952 ----a-w- c:\windows\system32\wersvc.dll
2010-09-23 00:07 . 2008-09-18 04:56 147456 ----a-w- c:\windows\system32\Faultrep.dll
2010-09-23 00:07 . 2010-06-18 14:43 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-09-23 00:07 . 2010-06-18 14:43 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-09-23 00:07 . 2008-05-08 21:59 90112 ----a-w- c:\windows\system32\wshext.dll
2010-09-23 00:07 . 2008-05-08 21:59 155648 ----a-w- c:\windows\system32\wscript.exe
2010-09-23 00:07 . 2008-05-08 21:59 180224 ----a-w- c:\windows\system32\scrobj.dll
2010-09-23 00:07 . 2008-05-08 21:59 172032 ----a-w- c:\windows\system32\scrrun.dll
2010-09-23 00:07 . 2008-05-08 21:58 135168 ----a-w- c:\windows\system32\cscript.exe
2010-09-23 00:03 . 2008-04-05 03:34 15360 ----a-w- c:\windows\system32\pacerprf.dll
2010-09-23 00:03 . 2008-04-05 01:21 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2010-09-23 00:03 . 2010-04-16 16:05 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-09-23 00:03 . 2010-04-16 14:17 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-09-23 00:02 . 2010-06-18 16:43 36352 ----a-w- c:\windows\system32\rtutils.dll
2010-09-23 00:02 . 2010-05-26 14:25 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-09-23 00:02 . 2009-10-19 14:24 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-09-23 00:02 . 2010-05-26 16:16 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-09-23 00:02 . 2009-06-15 15:20 10240 ----a-w- c:\windows\system32\dciman32.dll
2010-09-23 00:00 . 2010-06-16 15:59 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-09-22 23:51 . 2010-08-17 13:32 126464 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-22 23:40 . 2010-04-16 16:10 501760 ----a-w- c:\windows\system32\usp10.dll
2010-09-22 23:34 . 2010-04-05 16:08 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-09-22 23:26 . 2010-05-27 19:16 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-22 23:25 . 2009-10-19 14:27 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-09-22 23:25 . 2010-02-23 11:32 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-09-22 23:25 . 2010-02-23 11:32 78848 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-09-22 23:25 . 2010-02-23 11:32 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-09-22 23:24 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll
2010-09-22 23:24 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll
2010-09-22 23:24 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2010-09-22 23:24 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2010-09-22 23:22 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2010-09-22 23:22 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2010-09-22 23:22 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2010-09-22 23:21 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll
2010-09-22 23:21 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2010-09-22 23:21 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2010-09-22 23:21 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe
2010-09-22 23:21 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE
2010-09-22 23:21 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll
2010-09-22 23:19 . 2009-09-10 17:30 213504 ----a-w- c:\windows\system32\msv1_0.dll
2010-09-22 23:09 . 2008-10-22 03:57 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2010-09-22 04:34 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2010-09-22 04:34 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-09-22 04:34 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2010-09-22 04:34 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2010-09-22 04:34 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2010-09-22 04:25 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
2010-09-22 04:25 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
2010-09-22 04:22 . 2010-02-20 23:39 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-09-22 04:22 . 2010-02-20 23:37 31232 ----a-w- c:\windows\system32\httpapi.dll
2010-09-22 04:22 . 2010-02-20 21:18 411136 ----a-w- c:\windows\system32\drivers\http.sys
2010-09-22 03:59 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-22 03:59 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-22 03:40 . 2010-09-22 03:40 52224 ----a-w- c:\users\Jinju\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-09-22 03:40 . 2010-09-22 03:40 63488 ----a-w- c:\users\Jinju\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-09-22 03:40 . 2010-09-22 03:40 117760 ----a-w- c:\users\Jinju\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-09-21 22:00 . 2010-09-21 22:00 165632 ---ha-w- c:\windows\system32\mlfcache.dat
2010-09-21 22:00 . 2010-09-21 22:00 2788816 ----a-w- c:\users\Jinju\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2010-09-21 11:56 . 2010-09-21 11:56 658184 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-09-21 11:28 . 2010-09-21 11:28 -------- d-----w- c:\programdata\Office Genuine Advantage
2010-09-21 05:37 . 2010-09-21 05:37 2384752 ----a-w- c:\programdata\WildTangent\My HP Game Console\Downloads\en-us\Installers\SetupGamesClient.exe
2010-09-21 05:28 . 2010-09-21 05:29 20519176 ----a-w- c:\programdata\WildTangent\My HP Game Console\Downloads\Installers\SetupGamesClient.exe
2010-09-21 05:08 . 2008-01-19 07:36 1541120 ----a-w- c:\windows\system32\onex.dll
2010-09-21 05:08 . 2008-01-19 07:33 2623488 ----a-w- c:\windows\system32\SLsvc.exe
2010-09-21 05:06 . 2008-01-19 07:36 1013760 ----a-w- c:\windows\system32\wevtsvc.dll
2010-09-21 05:04 . 2008-01-19 07:35 216064 ----a-w- c:\windows\system32\ntprint.dll
2010-09-21 05:03 . 2008-01-19 07:36 242688 ----a-w- c:\windows\system32\pdh.dll
2010-09-21 05:02 . 2008-01-19 07:34 394240 ----a-w- c:\windows\system32\dsquery.dll
2010-09-21 05:01 . 2008-01-19 07:37 1329152 ----a-w- c:\windows\system32\WMSPDMOE.DLL
2010-09-21 05:00 . 2008-01-19 07:33 31744 ----a-w- c:\windows\system32\bitsigd.dll
2010-09-21 04:59 . 2008-01-19 07:33 17408 ----a-w- c:\windows\system32\cfgmgr32.dll
2010-09-21 04:58 . 2008-01-19 07:33 599552 ----a-w- c:\windows\system32\vsp1cln.exe
2010-09-21 04:57 . 2008-01-19 07:34 102400 ----a-w- c:\windows\system32\wbem\mofinstall.dll
2010-09-21 04:57 . 2008-01-19 07:36 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll
2010-09-21 04:57 . 2008-01-19 07:36 742912 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2010-09-21 04:57 . 2008-01-19 07:36 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2010-09-21 04:57 . 2008-01-19 07:36 357888 ----a-w- c:\windows\system32\wbemcomn.dll
2010-09-21 04:57 . 2008-01-19 07:36 264704 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
2010-09-21 04:57 . 2008-01-19 07:34 191488 ----a-w- c:\windows\system32\wbem\mofd.dll
2010-09-21 04:57 . 2008-01-19 07:34 263168 ----a-w- c:\windows\system32\wbem\esscli.dll
2010-09-21 04:56 . 2008-01-19 07:36 139264 ----a-w- c:\windows\system32\SmiInstaller.dll
2010-09-21 04:56 . 2008-01-19 07:36 704512 ----a-w- c:\windows\system32\SmiEngine.dll
2010-09-21 04:56 . 2008-01-19 07:36 218624 ----a-w- c:\windows\system32\wdscore.dll
2010-09-21 04:56 . 2008-01-19 07:33 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2010-09-21 04:54 . 2008-01-19 07:34 246784 ----a-w- c:\windows\system32\drvstore.dll
2010-09-21 04:54 . 2008-01-19 07:35 35328 ----a-w- c:\windows\system32\mspatcha.dll
2010-09-21 04:54 . 2008-01-19 07:34 305152 ----a-w- c:\windows\system32\msdelta.dll
2010-09-21 04:54 . 2008-01-19 07:34 258560 ----a-w- c:\windows\system32\dpx.dll
2010-09-21 04:52 . 2008-10-21 05:25 1645568 ----a-w- c:\windows\system32\connect.dll
2010-09-21 04:51 . 2010-01-25 08:34 511488 ----a-w- c:\windows\system32\RMActivate.exe
2010-09-21 04:51 . 2010-01-25 08:35 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-09-21 04:51 . 2010-01-25 12:48 472576 ----a-w- c:\windows\system32\secproc_isv.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-23 22:55 . 2010-09-23 22:55 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2010-09-23 20:30 . 2008-07-25 21:33 -------- d-----w- c:\users\Jinju\AppData\Roaming\OpenOffice.org2
2010-09-23 07:54 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-09-23 07:26 . 2007-06-29 13:00 -------- d-----w- c:\programdata\Microsoft Help
2010-09-22 00:25 . 2007-09-05 00:50 97936 ----a-w- c:\users\Jinju\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-22 00:16 . 2006-11-02 10:25 86016 ----a-w- c:\windows\Inf\infstor.dat
2010-09-22 00:16 . 2006-11-02 10:25 51200 ----a-w- c:\windows\Inf\infpub.dat
2010-09-22 00:16 . 2006-11-02 10:25 143360 ----a-w- c:\windows\Inf\infstrng.dat
2010-09-22 00:07 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-09-22 00:07 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-09-22 00:07 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-09-22 00:07 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-09-22 00:07 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-09-22 00:07 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-09-22 00:01 . 2006-11-02 10:25 665600 ----a-w- c:\windows\Inf\drvindex.dat
2010-09-21 23:14 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2010-09-21 23:13 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2010-09-21 06:42 . 2007-06-29 12:58 -------- d-----w- c:\program files\Microsoft Works
2010-09-21 06:32 . 2008-08-07 02:45 -------- d-----w- c:\programdata\WildTangent
2010-09-21 06:32 . 2008-03-29 02:28 -------- d-----w- c:\program files\Safari
2010-09-21 06:32 . 2008-08-11 03:25 -------- d-----w- c:\program files\QuickTime
2010-09-21 06:32 . 2007-09-10 01:12 -------- d-----w- c:\program files\NetZero
2010-09-21 06:32 . 2008-08-11 03:29 -------- d-----w- c:\program files\iTunes
2010-09-21 06:32 . 2006-11-30 22:49 -------- d-----w- c:\program files\HP Games
2010-09-21 06:32 . 2008-08-11 03:27 -------- d-----w- c:\program files\Bonjour
2010-09-21 06:29 . 2007-10-22 07:00 -------- d-----w- c:\users\Jinju\AppData\Roaming\Move Networks
2010-09-21 06:29 . 2007-09-10 01:19 -------- d-----w- c:\program files\iPod
2010-09-21 06:29 . 2007-06-29 13:05 -------- d-----w- c:\program files\HP
2010-09-21 03:49 . 2007-09-05 02:36 13025 ----a-w- c:\users\Jinju\AppData\Roaming\nvModes.dat
2010-09-21 03:25 . 2007-10-03 03:09 -------- d-----w- c:\programdata\Viewpoint
2010-09-19 22:45 . 2008-07-08 21:07 -------- d-----w- c:\program files\AVG
2010-09-15 22:51 . 2010-06-27 19:43 -------- d-----w- c:\programdata\WinZip
2010-09-14 04:00 . 2007-11-29 01:09 1356 ----a-w- c:\users\Jinju\AppData\Local\d3d9caps.dat
2010-09-13 13:49 . 2010-02-16 20:17 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-08 00:30 . 2009-05-28 18:37 -------- d-----w- c:\programdata\Motive
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"NetZero_uoltray"="c:\program files\NetZero\exec.exe" [2007-03-07 1629184]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2006-11-21 1474560]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-03-25 50528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-11-24 167936]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744]
"Mouse Suite 98 Daemon"="ICO.EXE" [2006-11-03 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 317152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 472800]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-23 116040]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2006-11-10 46704]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2006-11-18 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-11-18 7753728]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-11-18 81920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
c:\users\Jinju\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MEMonitor.lnk - c:\program files\V CAST Music Manager\MEMonitor.exe [2007-11-2 951640]
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Connections.lnk - c:\program files\HP Connections\6811507\Program\HP Connections.exe [2007-6-29 34520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S4 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys
--- Other Services/Drivers In Memory ---
*Deregistered* - AvgLdx86
.
Contents of the 'Scheduled Tasks' folder
2010-09-29 c:\windows\Tasks\User_Feed_Synchronization-{90EE62B4-9066-4567-B527-472EEF2CA871}.job
- c:\windows\system32\msfeedssync.exe [2010-09-21 07:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/?src=aim
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
IE: Display All Images with Full Quality - c:\program files\NetZero\qsacc\appres.dll/228
IE: Display Image with Full Quality - c:\program files\NetZero\qsacc\appres.dll/227
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: netzero.com
Trusted Zone: netzero.net
FF - ProfilePath - c:\users\Jinju\AppData\Roaming\Mozilla\Firefox\Profiles\w5fweigy.default\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-09-29 18:28
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-09-29 18:33:46
ComboFix-quarantined-files.txt 2010-09-29 22:33
Pre-Run: 73,712,840,704 bytes free
Post-Run: 73,612,976,128 bytes free
- - End Of File - - BAAE23D9312E5BAE78E43F64E6E7ED60