ComboFix 08-01-11.3 - Kevin Jackie 2008-01-11 22:38:34.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.202 [GMT -5:00]
Running from: C:\Documents and Settings\Kevin Jackie\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Starware347
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\FindIt.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\FindItHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\findithotxp.png
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\finditxp.png
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\Highlight.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\HighlightHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\highlighthotxp.png
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\highlightxp.png
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\jokesearch.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\logo.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\logoxp.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\buttons\pranks.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\contexts\error.xml
C:\Documents and Settings\All Users\Application Data\Starware347\contexts\Related.xml
C:\Documents and Settings\All Users\Application Data\Starware347\contexts\Travel.xml
C:\Documents and Settings\All Users\Application Data\Starware347\EntertainmentMarketingSP\images\active\EntertainmentMarketingSP0.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\Games\images\active\Games0.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\Movies\images\active\Movies0.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\ScreensaversMarketingSitePager\images\active\ScreensaversMarketingSitePager0.bmp
C:\Documents and Settings\All Users\Application Data\Starware347\SimpleUpdate\ProductMessagingConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware347\SimpleUpdate\ProductMessagingConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware347\SimpleUpdate\SimpleUpdateConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware347\SimpleUpdate\SimpleUpdateConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware347\SimpleUpdate\TimerManagerConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware347\SimpleUpdate\TimerManagerConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware347\U0003EFFE.exe
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\BrowserSearch\BrowserSearch.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\BrowserSearch\BrowserSearch.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Configurator\Configurator.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Configurator\Configurator.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\EntertainmentMarketingSP\EntertainmentMarketingSPOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\EntertainmentMarketingSP\EntertainmentMarketingSPOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\ErrorSearch\ErrorSearchOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\ErrorSearch\ErrorSearchOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Games\GamesOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Games\GamesOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\JokeSearch\JokeSearchOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\JokeSearch\JokeSearchOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Layouts\ToolbarLayout.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Layouts\ToolbarLayout.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Manager\ManagerOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Manager\ManagerOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Movies\MoviesOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Movies\MoviesOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Pranks\PranksOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Pranks\PranksOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\RelatedSearch\RelatedSearchOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\RelatedSearch\RelatedSearchOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\SearchAssistPlus\SearchAssistPlusOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\SearchAssistPlus\SearchAssistPlusOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\SearchMatch\SearchMatchOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\SearchMatch\SearchMatchOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Toolbar\TBProductsOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\Toolbar\TBProductsOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\ToolbarLogo\ToolbarLogoOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\ToolbarLogo\ToolbarLogoOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\ToolbarSearch\ToolbarSearchOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\ToolbarSearch\ToolbarSearchOptions.xml.backup
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\TravelSearch\TravelSearchOptions.xml
C:\Documents and Settings\Kevin Jackie\Application Data\Starware347\TravelSearch\TravelSearchOptions.xml.backup
C:\Program Files\Starware347
C:\Program Files\Starware347\brand.bmp
C:\Program Files\Starware347\icons\star_16.ico
C:\Program Files\Starware347\Starware347Config.xml
C:\Program Files\Starware347\Starware347Uninstall.exe
C:\WINDOWS\system32\jpdiixsp.ini
.
((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))
.
2008-01-11 22:36 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-11 22:24 . 2008-01-11 22:24 486,449 --a------ C:\temp\Fixwareout.exe
2008-01-11 22:14 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-01-11 21:47 . 2008-01-11 22:09 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-11 21:47 . 2008-01-11 21:47 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-11 21:47 . 2008-01-11 21:47 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-11 21:47 . 2008-01-11 21:47 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-11 19:34 . 2008-01-11 21:43 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-11 19:34 . 2008-01-11 19:34 <DIR> d-------- C:\Documents and Settings\Kevin Jackie\Application Data\SUPERAntiSpyware.com
2008-01-11 19:34 . 2008-01-11 19:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-11 17:00 . 2008-01-11 17:00 <DIR> d-------- C:\VundoFix Backups
2008-01-11 16:53 . 2008-01-11 16:53 <DIR> d-------- C:\Documents and Settings\Kevin Jackie\Application Data\Grisoft
2008-01-11 16:52 . 2008-01-11 16:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-11 16:52 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-11 16:43 . 2008-01-11 16:43 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-11 13:49 . 2007-03-21 20:33 503,808 --a------ C:\WINDOWS\system32\MSVCP71.DL1
2008-01-11 12:55 . 2008-01-11 12:55 0 --a------ C:\WINDOWS\VPC32.INI
2008-01-11 12:51 . 2008-01-11 12:50 123,619 --a------ C:\WINDOWS\system32\SYMEVNT.386
2008-01-11 12:51 . 2008-01-11 12:50 83,672 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-11 12:51 . 2008-01-11 12:50 73,224 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-11 12:50 . 2008-01-11 12:50 <DIR> d-------- C:\Program Files\Symantec_Client_Security
2008-01-11 12:50 . 2008-01-11 12:51 <DIR> d-------- C:\Program Files\Symantec
2008-01-11 00:52 . 2008-01-11 22:36 <DIR> d-------- C:\temp
2008-01-10 22:56 . 2008-01-10 22:56 <DIR> d-------- C:\Program Files\RealVNC
2008-01-10 22:46 . 2008-01-10 22:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-10 22:45 . 2008-01-11 19:33 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-10 22:35 . 2008-01-11 22:17 <DIR> d-------- C:\temp\Anti-Virus_Anti-Spyware
2008-01-10 20:43 . 2008-01-10 20:43 294 ---hs---- C:\WINDOWS\system32\pkrvogrx.ini
2008-01-10 20:41 . 2008-01-10 20:41 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-01-10 20:38 . 2008-01-10 20:38 <DIR> d---s---- C:\Documents and Settings\Kevin Jackie\UserData
2008-01-10 20:38 . 2008-01-11 00:44 <DIR> d-------- C:\Documents and Settings\Kevin Jackie\Contacts
2007-12-21 19:18 . 2008-01-10 22:33 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-11 18:49 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-11 18:28 --------- d-----w C:\Program Files\SpywareBlaster
2008-01-11 17:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-11 06:06 --------- d-----w C:\Program Files\Microsoft AntiSpyware
2008-01-11 06:03 --------- d-----w C:\Program Files\Norton AntiVirus
2008-01-11 03:46 --------- d-----w C:\Program Files\Lavasoft
2007-12-11 16:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\WildTangent
2007-12-11 16:21 --------- d-----w C:\Program Files\WildGames
2007-12-06 13:18 --------- d-----w C:\Program Files\OpenOffice.org1.1.4
2007-11-30 17:06 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-30 17:06 --------- d-----w C:\Program Files\Windows Live Favorites
2007-11-28 20:29 --------- d-----w C:\Program Files\LimeWire
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2006-12-27 15:31 32 ----a-r C:\Documents and Settings\All Users\hash.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{65e5f63b-c0f3-4ec6-8b7a-754978a7cbcc}]
C:\WINDOWS\system32\onohqqxs.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54 5674352]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-23 11:38 68856]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2006-10-31 14:06 204843]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTPreset"="VTPreset.exe" [2004-02-24 19:17 45056 C:\WINDOWS\system32\VTPreset.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00 132496]
"UADC_3510341195"="C:\Program Files\AdvancedCleaner Free\UADCcw.exe" [ ]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-07-30 11:35 77824]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifdebc]
iifdebc.dll
.
Contents of the 'Scheduled Tasks' folder
"2008-01-12 02:28:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-11 22:52:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
Completion time: 2008-01-11 22:54:39 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-12 03:54:35
.
2007-12-21 22:40:42 --- E O F ---