ComboFix 09-08-10.06 - Alex Vivas 08/14/2009 19:12.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1534.1150 [GMT -4:00]
Running from: c:\documents and settings\Alex Vivas\Desktop\Combo-Fix.exe
AV: Eset NOD32 antivirus system 2.51 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AWS\WEATHE~1\MINIBU~1.DLL
c:\program files\Common Files\Real\WeatherBug\MiniBugTransporter.dll
c:\windows\Installer\80d51ab.msp
c:\windows\Installer\94773.msi
c:\windows\system32\cbadd.bak1
c:\windows\system32\cbadd.bak2
c:\windows\system32\cbadd.ini
c:\windows\system32\cbadd.ini2
c:\windows\system32\cbadd.tmp
c:\windows\system32\drivers\MSIVXjfvqyowsrdnaqnpbvyhdqhsboffynrvy.sys
c:\windows\system32\mcrh.tmp
c:\windows\system32\MSIVXcduhokwtmceyjwtxqsbukstqraguopkm.dll
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXvuomqdrmberdtvljuwmqeibswquxpqvd.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_MSIVXserv.sys
-------\Legacy_MSIVXserv.sys
((((((((((((((((((((((((( Files Created from 2009-07-14 to 2009-08-14 )))))))))))))))))))))))))))))))
.
2009-08-14 00:48 . 2009-08-14 00:48 -------- d-----w- c:\program files\Trend Micro
2009-08-12 00:38 . 2008-12-11 12:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-08-12 00:37 . 2009-04-03 15:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-08-12 00:37 . 2008-12-18 16:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-08-12 00:37 . 2009-08-12 00:38 -------- d-----w- c:\program files\Common Files\PC Tools
2009-08-12 00:37 . 2008-12-10 15:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-08-12 00:37 . 2009-08-12 00:38 -------- d-----w- c:\program files\Spyware Doctor
2009-08-12 00:37 . 2009-08-12 00:37 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-08-12 00:37 . 2009-08-12 00:37 -------- d-----w- c:\docume~1\ALEXVI~1\APPLIC~1\PC Tools
2009-08-12 00:13 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-12 00:13 . 2009-08-12 00:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-12 00:13 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-12 00:13 . 2009-08-12 00:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-11 03:47 . 2009-08-11 03:47 -------- d-----w- c:\program files\WebEx
2009-08-11 03:47 . 2009-07-07 18:48 25392 ----a-w- c:\windows\system32\drivers\pnarp.sys
2009-08-11 03:47 . 2009-07-07 18:48 26672 ----a-w- c:\windows\system32\drivers\purendis.sys
2009-08-11 03:46 . 2009-08-11 03:46 -------- d-----w- c:\program files\Common Files\Pure Networks Shared
2009-08-08 18:42 . 2009-05-26 23:50 607472 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-08-06 02:51 . 2009-08-06 02:51 -------- d-----w- c:\documents and settings\Alex Vivas\Local Settings\Application Data\Yahoo
2009-08-06 02:46 . 2009-08-06 02:46 -------- d-----w- c:\docume~1\ALEXVI~1\APPLIC~1\Yahoo!
2009-08-06 02:45 . 2009-08-06 02:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-07-31 05:20 . 2009-07-31 05:20 -------- d-----w- c:\program files\iPod
2009-07-31 05:15 . 2009-07-31 05:15 75040 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-27 05:49 . 2009-07-27 05:49 683801 ----a-w- c:\documents and settings\All Users\Application Data\Last.fm\Client\UninstITW\unins000.exe
2009-07-27 05:49 . 2009-07-27 05:49 184 ----a-w- c:\documents and settings\All Users\Application Data\Last.fm\Client\uninst2.bat
2009-07-27 05:49 . 2009-07-27 05:49 683801 ----a-w- c:\documents and settings\All Users\Application Data\Last.fm\Client\UninstWMP\unins000.exe
2009-07-27 05:49 . 2009-07-27 05:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Last.fm
2009-07-27 05:48 . 2009-07-27 05:48 -------- d-----w- c:\documents and settings\Alex Vivas\Local Settings\Application Data\Last.fm
2009-07-27 05:47 . 2009-07-27 05:48 -------- d-----w- c:\program files\Last.fm
2009-07-18 04:33 . 2009-07-18 04:33 967 ----a-w- c:\windows\ScUnin.pif
2009-07-18 04:33 . 2009-07-18 04:33 94208 ----a-w- c:\windows\ScUnin.exe
2009-07-18 04:33 . 2009-07-18 04:33 12852 ----a-w- c:\windows\scunin.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-14 23:09 . 2008-07-22 02:23 -------- d-----w- c:\docume~1\ALEXVI~1\APPLIC~1\DNA
2009-08-12 17:50 . 2009-04-08 19:20 -------- d-----w- c:\docume~1\ALEXVI~1\APPLIC~1\uTorrent
2009-08-12 08:02 . 2008-07-22 02:23 -------- d-----w- c:\program files\DNA
2009-08-12 07:26 . 2009-02-09 20:19 -------- d---a-w- c:\documents and settings\All Users\Application Data\temp
2009-08-12 03:17 . 2008-06-21 00:36 -------- d-----w- c:\program files\World of Warcraft
2009-08-11 20:50 . 2009-02-02 01:33 256 ----a-w- c:\windows\system32\pool.bin
2009-08-11 19:36 . 2006-08-20 07:21 -------- d-----w- c:\docume~1\ALEXVI~1\APPLIC~1\BitTorrent
2009-08-11 08:04 . 2005-11-19 18:45 86320 ----a-w- c:\documents and settings\Alex Vivas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-11 07:46 . 2007-03-15 04:09 -------- d-----w- c:\program files\Kaspersky Lab
2009-08-11 03:47 . 2009-08-11 03:47 8892928 ----a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2009-08-11 01:51 . 2006-05-28 20:56 -------- d-----w- c:\program files\Steam
2009-08-08 18:42 . 2005-11-22 04:49 -------- d-----w- c:\program files\Yahoo!
2009-08-06 02:50 . 2006-10-12 00:16 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-07-31 05:20 . 2007-07-01 15:52 -------- d-----w- c:\program files\Common Files\Apple
2009-07-18 22:26 . 2006-08-17 23:50 -------- d-----w- c:\program files\Starcraft
2009-07-17 10:34 . 2009-04-01 19:32 -------- d-----w- c:\docume~1\ALEXVI~1\APPLIC~1\dvdcss
2009-07-12 03:30 . 2006-11-11 07:21 -------- d-----w- c:\docume~1\ALEXVI~1\APPLIC~1\Skype
2009-07-12 03:23 . 2008-11-20 02:23 -------- d-----w- c:\docume~1\ALEXVI~1\APPLIC~1\skypePM
2009-07-10 04:14 . 2009-07-10 03:57 -------- d--h--w- c:\docume~1\ALEXVI~1\APPLIC~1\ijjigame
2009-07-10 03:55 . 2009-07-10 03:55 -------- d-----w- c:\documents and settings\All Users\Application Data\ijjigame
2009-07-10 03:50 . 2009-07-10 03:50 -------- d-----w- c:\program files\NHN USA
2009-07-10 03:50 . 2005-10-26 11:57 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-10 02:45 . 2009-07-10 02:45 -------- d-----w- c:\program files\Common Files\INCA Shared
2009-07-10 02:21 . 2009-07-10 02:21 -------- d-----w- c:\program files\Softnyx
2009-06-27 22:35 . 2006-11-26 21:38 -------- d-----w- c:\docume~1\ALEXVI~1\APPLIC~1\Image Zone Express
2009-06-27 08:06 . 2009-06-27 08:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-27 07:46 . 2008-12-03 01:18 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-27 07:46 . 2006-02-07 05:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-26 16:50 . 2004-08-10 17:51 666624 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:50 . 2004-08-10 17:51 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-20 21:04 . 2009-06-20 21:03 -------- d-----w- c:\program files\QuickTime
2009-06-16 14:36 . 2004-08-10 17:51 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-10 17:51 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-05 15:42 . 2009-03-15 23:28 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-05 15:42 . 2008-10-08 04:03 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-03 21:48 . 2009-07-10 03:55 779720 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\PurpleBean.exe
2009-06-03 19:09 . 2004-08-10 17:51 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-27 22:08 . 2009-07-10 03:55 591320 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\ExLauncher.exe
2009-05-26 21:31 . 2009-07-10 03:50 58800 ----a-w- c:\windows\system32\ijjiProcessRestarter.exe
2009-05-21 15:33 . 2008-12-27 01:49 410984 ----a-w- c:\windows\system32\deploytk.dll
2006-03-20 01:29 . 2005-11-26 00:50 104 -csh--r- c:\windows\system32\094F0B04D1.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Free Ram Optimizer"="c:\program files\AceLogix\Free Ram Optimizer\fro.exe" [2003-08-22 57344]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-23 67128]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032]
"AIM"="c:\program files\AIM\aim.exe" [2004-08-10 61440]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-07-10 318272]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-20 114688]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"LVCOMS"="c:\program files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 98304]
"Advanced WindowsCare"="c:\program files\IObit\Advanced WindowsCare V2\Awc.exe" [2006-09-09 890368]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-04 185896]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="f:\music\iTunesHelper.exe" [2009-07-13 292128]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2009-07-07 647216]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-12-19 76304]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-12-19 76304]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-6-10 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-2-23 67128]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-11 809488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-19 04:30 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2006-03-19 17:37 110592 ----a-w- c:\progra~1\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Steam\\SteamApps\\mr_bubblegum\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\SteamApps\\mr_bubblegum\\counter-strike source beta\\hl2.exe"=
"c:\\Program Files\\Java\\jre1.5.0_09\\bin\\javaw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Steam\\SteamApps\\mr_bubblegum\\counter-strike\\hl.exe"=
"c:\\Program Files\\Steam\\SteamApps\\mr_bubblegum\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\mr_bubblegum\\day of defeat source\\hl2.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Java\\jre1.5.0_10\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre1.5.0_11\\bin\\javaw.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Steam\\SteamApps\\mr_bubblegum\\ricochet\\hl.exe"=
"c:\\Program Files\\Steam\\SteamApps\\mr_bubblegum\\deathmatch classic\\hl.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Steam\\SteamApps\\jeffscoloncam\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"f:\\Music\\iTunes.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\left 4 dead\\left4dead.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
"67:UDP"= 67:UDP:DHCP Discovery Service
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [8/11/2009 8:37 PM 130936]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/16/2007 5:03 AM 24652]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PciCon;PciCon;\??\e:\pcicon.sys --> e:\PciCon.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [8/11/2009 8:37 PM 348752]
S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\netusbxp.sys [11/14/2005 5:47 PM 72576]
.
Contents of the 'Scheduled Tasks' folder
2009-08-13 c:\windows\Tasks\Advanced WindowsCare.job
- c:\program files\IObit\Advanced WindowsCare V2\AutoCare.exe [2006-09-19 18:32]
2009-08-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-08-02 c:\windows\Tasks\AwcUpdate.job
- c:\program files\IObit\Advanced WindowsCare V2\AutoUpdate.exe [2006-09-19 05:31]
2009-08-14 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 16:20]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-nmapp - c:\program files\Pure Networks\Network Magic\nmapp.exe
Notify-AtiExtEvent - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=7.0unattached&bm=ho_central
mStart Page = hxxp://www.dell4me.com/mywaybiz
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to AD Black List
IE: Add to Windows &Live Favorites -
http://favorites.liv...m/quickadd.aspxIE: Block All Images from the Same Server
IE: E&xport to Microsoft Office Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Highlight
IE: Open All Links in This Page...
IE: Open In New Avant Browser
IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?bb3627c087864d80ba34bf2a37000c9b
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?bb3627c087864d80ba34bf2a37000c9b
IE: Search
Trusted Zone: imageservr.com\locator.cdn
Trusted Zone: sysprotect.com\scanner
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {02CA9974-B6AC-497E-A371-73580432B0F6} - hxxp://imlive.com/ChatSource/gVideoContol.cab
FF - ProfilePath - c:\docume~1\ALEXVI~1\APPLIC~1\Mozilla\Firefox\Profiles\b29zb4hn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.wowhead.com/
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: f:\music\Mozilla Plugins\npitunes.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-14 19:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2646574709-2709291196-891625016-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(656)
c:\windows\system32\GTGina.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
c:\progra~1\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
.
Completion time: 2009-08-14 19:23
ComboFix-quarantined-files.txt 2009-08-14 23:23
Pre-Run: 22,324,051,968 bytes free
Post-Run: 22,411,550,720 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
325 --- E O F --- 2009-07-28 19:51
~~~~
ok everything above the squiggly lines is what the log says. hopefully this is the right one. it did also make me download a recovery console thing. please respond asap. thank you for your help in this situation.