omboFix 08-02-17.2 - Angie 2008-02-19 22:03:13.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.726 [GMT -6:00]
Running from: C:\Documents and Settings\Angie\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\Angie\Application Data\apphash.dat
C:\Documents and Settings\LocalService\Application Data\Starware
C:\Documents and Settings\LocalService\Application Data\Starware\BrowserSearch\BrowserSearch.xml
C:\Documents and Settings\LocalService\Application Data\Starware\BrowserSearch\BrowserSearch.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\Layouts\PreferencesLayout.xml
C:\Documents and Settings\LocalService\Application Data\Starware\Layouts\PreferencesLayout.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\Layouts\ToolbarLayout.xml
C:\Documents and Settings\LocalService\Application Data\Starware\Layouts\ToolbarLayout.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\Manager\ManagerOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware\Manager\ManagerOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\Reference\ReferenceOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware\Reference\ReferenceOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\Screensavers\ScreensaversOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware\Screensavers\ScreensaversOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\SearchMatch\SearchMatchOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware\SearchMatch\SearchMatchOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\Toolbar\TBProductsOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware\Toolbar\TBProductsOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\TravelSearch\TravelSearchOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware\TravelSearch\TravelSearchOptions.xml.backup
C:\Documents and Settings\LocalService\Application Data\Starware\Weather\AlertArchive.xml
C:\Documents and Settings\LocalService\Application Data\Starware\Weather\WeatherOptions.xml
C:\Documents and Settings\LocalService\Application Data\Starware\Weather\WeatherOptions.xml.backup
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\PopSwatr\History\allowed
C:\Program Files\FunWebProducts\PopSwatr\History\notallow
C:\Program Files\FunWebProducts\ScreenSaver\Images\
0013AF8D.urr
C:\Program Files\FunWebProducts\ScreenSaver\Images\
0083C391.urr
C:\Program Files\FunWebProducts\Shared\1A1B1F84.dat
C:\Program Files\FunWebProducts\Shared\Cache\AvatarSmallBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\FunBuddyIconBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\Helper
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\4.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\4.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\4.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\4.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\5.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\5.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\5.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\5.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\5.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\5.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\5.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\5.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\5.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\5.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\5.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\5.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\5.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\5.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\5.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\5.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\5.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\5.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\5.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\5.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\5.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\5.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\5.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\5.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\5.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\5.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\5.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\5.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\5.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\5.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\5.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\5.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\5.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\5.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\5.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\5.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Cache\
00044FF1.bin
C:\Program Files\MyWebSearch\bar\Cache\
000832A2
C:\Program Files\MyWebSearch\bar\Cache\
000F53C4
C:\Program Files\MyWebSearch\bar\Cache\
002176F4
C:\Program Files\MyWebSearch\bar\Cache\
003ACF5B.bin
C:\Program Files\MyWebSearch\bar\Cache\
0093806F.bin
C:\Program Files\MyWebSearch\bar\Cache\
00B3DED0
C:\Program Files\MyWebSearch\bar\Cache\
00BCAD25.bin
C:\Program Files\MyWebSearch\bar\Cache\
00BCB311.bin
C:\Program Files\MyWebSearch\bar\Cache\
00BCB515.bin
C:\Program Files\MyWebSearch\bar\Cache\
059202E6.bin
C:\Program Files\MyWebSearch\bar\Cache\
05920C6B.bin
C:\Program Files\MyWebSearch\bar\Cache\
05920E8E.bin
C:\Program Files\MyWebSearch\bar\Cache\
05921082.bin
C:\Program Files\MyWebSearch\bar\Cache\
07121355
C:\Program Files\MyWebSearch\bar\Cache\
08CF7CE8
C:\Program Files\MyWebSearch\bar\Cache\
0A4C532B.bin
C:\Program Files\MyWebSearch\bar\Cache\
0A4C5917.bin
C:\Program Files\MyWebSearch\bar\Cache\
0E150521
C:\Program Files\MyWebSearch\bar\Cache\11EA78B8
C:\Program Files\MyWebSearch\bar\Cache\14E2BEE8
C:\Program Files\MyWebSearch\bar\Cache\1C3B26B2.bin
C:\Program Files\MyWebSearch\bar\Cache\1C3B2896.bin
C:\Program Files\MyWebSearch\bar\Cache\1C3B29CF.bin
C:\Program Files\MyWebSearch\bar\Cache\1C3B2B07.bin
C:\Program Files\MyWebSearch\bar\Cache\1C3B2C8E.bin
C:\Program Files\MyWebSearch\bar\Cache\206A9C94
C:\Program Files\MyWebSearch\bar\Cache\234739B6
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\icons\CM.ICO
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
C:\Program Files\MyWebSearch\bar\icons\WB.ICO
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg.htm
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm.bak
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\MyWebSearch\bar\Settings\settings.dat.bak
C:\Program Files\MyWebSearch\bar\Settings\settings.htm
C:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL
C:\Program Files\MyWebSearch\SrchAstt\5.bin\MWSSRCAS.DLL
C:\WINNT\Downloaded Program Files\UERS_0001_N85M0906NetInstaller.exe
C:\WINNT\Downloaded Program Files\UERS_9999_N91S2507NetInstaller.exe
C:\WINNT\system32\f3PSSavr.scr
C:\WINNT\system32\regsvr32.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-20 to 2008-02-20 )))))))))))))))))))))))))))))))
.
2008-02-16 17:43 . 2008-02-16 17:43 145 --a------ C:\Shortcut to CD Drive.lnk
2008-02-15 19:33 . 2008-02-15 19:33 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-11 21:42 . 2008-02-11 21:42 <DIR> d-------- C:\Mouse Suite v1.2
2008-01-23 10:49 . 2008-01-23 10:49 8,192 --ahs---- C:\WINNT\Thumbs.db
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-18 00:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-02-17 14:50 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-16 15:30 --------- d--h--r C:\Documents and Settings\Angie\Application Data\yahoo!
2008-02-16 15:30 --------- d-----w C:\Program Files\Yahoo!
2008-02-16 15:29 --------- d--h--r C:\Documents and Settings\All Users\Application Data\yahoo!
2008-02-16 01:21 --------- d-----w C:\Documents and Settings\Angie\Application Data\OpenOffice.org2
2008-02-15 23:32 --------- d-----w C:\Program Files\Lavasoft
2008-02-15 23:32 --------- d-----w C:\Documents and Settings\Angie\Application Data\Lavasoft
2008-02-15 23:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-14 18:50 --------- d-----w C:\Program Files\World of Warcraft
2008-01-25 22:41 --------- d-----w C:\Documents and Settings\Guest\Application Data\Gtek
2008-01-23 16:42 --------- d-----w C:\Program Files\ydt
2008-01-23 16:42 --------- d-----w C:\Program Files\Sierra On-Line
2008-01-23 16:42 --------- d-----w C:\Program Files\Microsoft Works
2008-01-23 16:42 --------- d-----w C:\Program Files\Microsoft Plus! Digital Media Edition
2008-01-23 16:42 --------- d-----w C:\Program Files\Microsoft Picture It! 9
2008-01-23 16:42 --------- d-----w C:\Program Files\GameHouse
2008-01-23 16:42 --------- d-----w C:\Program Files\Dropheads
2008-01-23 16:42 --------- d-----w C:\Program Files\DivX
2008-01-12 20:53 --------- d-----w C:\Program Files\Toblo
2007-12-18 09:51 179,584 ------w C:\WINNT\system32\dllcache\mrxdav.sys
2007-12-12 21:56 409,600 ----a-w C:\WINNT\system32\wrap_oal.dll
2007-12-12 21:56 114,688 ----a-w C:\WINNT\system32\OpenAL32.dll
2007-12-09 05:23 49,664 ----a-w C:\WINNT\system32\tdlSoUI.dll
2007-12-06 10:05 18,432 ----a-w C:\WINNT\system32\dllcache\iedw.exe
2007-12-04 18:38 550,912 ----a-w C:\WINNT\system32\oleaut32.dll
2007-12-04 18:38 550,912 ------w C:\WINNT\system32\dllcache\oleaut32.dll
2007-05-20 14:11 107,632 ----a-w C:\Documents and Settings\Angie\Application Data\GDIPFONTCACHEV1.DAT
2007-05-03 12:59 10,326 ----a-w C:\Documents and Settings\Angie\Application Data\wklnhst.dat
2007-04-15 14:37 32 ----a-r C:\Documents and Settings\All Users\hash.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 08:59 224248]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16 454784]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gateway Ink Monitor"="C:\Program Files\Gateway\Gateway Ink Monitor\GWInkMonitor.exe" [2003-11-05 12:23 303180]
"Gateway Extended Warranty"="C:\Program Files\Gateway\GWCares\GWCares.exe" [2004-02-08 16:30 73728]
"IgfxTray"="C:\WINNT\system32\igfxtray.exe" [2005-03-10 11:20 155648]
"HotKeysCmds"="C:\WINNT\system32\hkcmd.exe" [2005-03-10 11:16 126976]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-07 06:32 50688]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 15:52 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe" [2005-04-17 12:30 85184]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-12-21 05:20 227328]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-06 08:41 180269]
"NvCplDaemon"="C:\WINNT\system32\NvCpl.dll" [2007-06-28 23:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 23:43 1626112 C:\WINNT\system32\nwiz.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24 286720]
"NvMediaCenter"="C:\WINNT\system32\NvMcTray.dll" [2007-06-28 23:43 81920]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 17:44 271672]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 08:59 224248]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"WheelMouse"="C:\MOUSES~1.2\wh_exec.exe" [2007-02-28 07:42 86016]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2005-03-15 05:33:07 225280]
C:\Documents and Settings\Angie\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2007-02-07 11:37:32 256000]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 07:05:26 29696]
Event Reminder.lnk - C:\Program Files\Broderbund\PrintMaster\PMremind.exe [2004-12-07 01:02:18 331776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
S3 iatmunin;iatmunin;C:\DOCUME~1\Owner\LOCALS~1\Temp\iatmunin.sys []
S3 RIOUNIV;Rio universal USB driver;C:\WINNT\system32\Drivers\RIOUNIV.sys [2003-07-02 11:15]
S3 whfltr2k;WheelMouse USB Lower Filter Driver;C:\WINNT\system32\DRIVERS\whfltr2k.sys [2007-01-25 09:45]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-20 02:37:03 C:\WINNT\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-18 00:00:51 C:\WINNT\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2005-05-11 07:54:34 C:\WINNT\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-19 22:07:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-19 22:08:20
ComboFix-quarantined-files.txt 2008-02-20 04:08:10
.
2008-02-16 05:13:03 --- E O F ---