ComboFix 08-02-25.3 - MERION 2008-02-28 16:56:57.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.249 [GMT -8:00]
Running from: C:\Documents and Settings\MERION\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\b122.exe
C:\WINDOWS\Fonts\'
C:\WINDOWS\system32\aajqetgg.dll
C:\WINDOWS\system32\anfhoabp.ini
C:\WINDOWS\system32\bjjgbilg.dll
C:\WINDOWS\system32\ggteqjaa.ini
C:\WINDOWS\system32\hblxeckn.ini
C:\WINDOWS\system32\icadbfml.dll
C:\WINDOWS\system32\kgkitkef.dll
C:\WINDOWS\system32\khfdbcb.dll
C:\WINDOWS\system32\lacwxddq.dll
C:\WINDOWS\system32\lklicwjq.dll
C:\WINDOWS\system32\llkmp.ini
C:\WINDOWS\system32\llkmp.ini2
C:\WINDOWS\system32\lmfbdaci.ini
C:\WINDOWS\system32\mdauaqyu.ini
C:\WINDOWS\system32\mywpdyuw.dll
C:\WINDOWS\system32\nGpxx18
C:\WINDOWS\system32\nGpxx18\nGpxx182328.exe
C:\WINDOWS\system32\nhymiwxb.dll
C:\WINDOWS\system32\oljwuseh.dll
C:\WINDOWS\system32\pbaohfna.dll
C:\WINDOWS\system32\pviiqfcd.dll
C:\WINDOWS\system32\pxwjmtuh.dll
C:\WINDOWS\system32\qmvlaykf.dll
C:\WINDOWS\system32\qpppo.ini
C:\WINDOWS\system32\qpppo.ini2
C:\WINDOWS\system32\skegdcuv.ini
C:\WINDOWS\system32\sknwjiao.dll
C:\WINDOWS\system32\syepytxk.dll
C:\WINDOWS\system32\tgaipupe.ini
C:\WINDOWS\system32\uiyrittd.dll
C:\WINDOWS\system32\zppwbmyx.dllbox
C:\WINDOWS\timessquare1.dat
----- BITS: Possible infected sites -----
hxxp://77.91.228.184
hxxp://onsafepro.com
.
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-29 )))))))))))))))))))))))))))))))
.
2008-02-27 18:57 . 2008-02-27 18:50 128,625 --a--c--- C:\setup.isn
2008-02-27 18:57 . 2008-02-27 18:50 6,129 --a--c--- C:\
0x0409.ini
2008-02-27 18:57 . 2008-02-27 18:50 2,059 --a--c--- C:\Setup.INI
2008-02-27 18:56 . 2008-02-27 18:56 <DIR> d----c--- C:\Program Files\InstallShield Installation Information
2008-02-27 18:56 . 2008-02-27 18:51 14,248,960 --a--c--- C:\veoh.msi
2008-02-27 18:51 . 2008-02-27 18:51 <DIR> d----c--- C:\Program Files\Veoh Networks
2008-02-23 14:03 . 2008-02-23 14:03 <DIR> d----c--- C:\Program Files\Trend Micro
2008-02-20 11:54 . 2008-02-28 13:09 <DIR> d----c--- C:\Program Files\AIM6
2008-02-20 10:33 . 2008-02-20 10:33 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-02-20 10:14 . 2002-01-05 07:37 344,064 --a--c--- C:\WINDOWS\system32\msvcr70.dll
2008-02-20 10:14 . 2002-01-05 06:18 84,992 --a--c--- C:\WINDOWS\system32\ATL70.DLL
2008-02-20 10:14 . 2001-10-11 11:26 65,536 --a--c--- C:\WINDOWS\system32\YCRWin32.dll
2008-02-08 20:31 . 2008-02-22 12:17 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\SITEguard
2008-02-08 20:28 . 2008-02-08 20:28 <DIR> d----c--- C:\Program Files\Common Files\iS3
2008-02-08 20:28 . 2008-02-24 15:39 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-02-08 20:22 . 2008-02-08 20:22 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-02-08 13:22 . 2008-02-20 09:29 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Avira
2008-02-08 11:23 . 2008-02-08 11:23 <DIR> d----c--- C:\Documents and Settings\MERION\Application Data\SiteAdvisor
2008-02-07 23:11 . 2008-02-08 11:23 14,930 --a--c--- C:\WINDOWS\system32\Config.MPF
2008-02-07 09:16 . 2008-02-08 02:23 <DIR> d-a--c--- C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-06 18:52 . 2008-02-06 18:52 <DIR> d----c--- C:\WINDOWS\system32\Sys
2008-02-06 12:09 . 2008-02-06 12:09 147,456 --a--c--- C:\WINDOWS\system32\vbzip10.dll
2008-02-06 12:06 . 2008-02-06 15:24 <DIR> d----c--- C:\Temp
2008-02-06 08:22 . 2008-02-08 11:50 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-06 08:16 . 2008-02-06 08:16 15,544 --a--c--- C:\WINDOWS\system32\drivers\sbhr.sys
2008-02-06 08:15 . 2008-02-06 08:15 <DIR> d----c--- C:\Documents and Settings\MERION\Application Data\Sunbelt Software
2008-02-06 00:21 . 2008-02-20 14:02 <DIR> d----c--- C:\Program Files\LimeWire
2008-02-05 22:41 . 2005-08-27 02:38 1,435,272 --a--c--- C:\WINDOWS\system32\Flash.ocx
2008-02-05 22:41 . 2003-11-19 14:59 512,688 --a--c--- C:\WINDOWS\system32\XceedCry.dll
2008-02-05 22:41 . 2004-05-11 10:56 423,784 --a--c--- C:\WINDOWS\system32\XceedBkp.dll
2008-02-05 22:41 . 2004-02-05 21:53 389,120 --a--c--- C:\WINDOWS\system32\ACTSKN43.OCX
2008-02-05 22:41 . 2004-01-09 11:54 188,416 --a--c--- C:\WINDOWS\system32\actsplash.ocx
2008-02-05 22:41 . 2004-03-09 00:00 131,856 --a--c--- C:\WINDOWS\system32\MSADODC.ocx
2008-02-05 22:41 . 2000-07-15 06:00 101,888 --a--c--- C:\WINDOWS\system32\VB6STKIT.DLL
2008-02-05 22:41 . 2001-03-28 23:02 89,088 --a--c--- C:\WINDOWS\system32\ProgressBar4.ocx
2008-02-05 22:41 . 1999-01-26 19:36 11,012 --a--c--- C:\WINDOWS\system32\threadapi.tlb
2008-02-05 21:20 . 2008-02-05 21:20 <DIR> d----c--- C:\Documents and Settings\MERION\Application Data\MalwareBot
2008-02-04 15:06 . 2008-02-04 15:06 <DIR> d----c--- C:\Documents and Settings\MERION\Application Data\DivX
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-28 21:09 --------- dc----w C:\Program Files\iTunes
2008-02-27 23:21 --------- dc----w C:\Program Files\Common Files\Adobe
2008-02-25 00:17 --------- dc----w C:\Program Files\Ahead
2008-02-24 23:10 --------- dc----w C:\Documents and Settings\MERION\Application Data\Yahoo!
2008-02-22 08:29 --------- dc----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-02-22 03:11 --------- dc----w C:\Program Files\Common Files\AOL
2008-02-20 20:12 --------- dc----w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-20 20:03 --------- dc----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-02-20 18:32 --------- dc----w C:\Program Files\Yahoo!
2008-02-13 09:08 --------- dc----w C:\Documents and Settings\MERION\Application Data\Canon
2008-02-13 08:59 19,576 -c--a-w C:\Documents and Settings\MERION\Application Data\GDIPFONTCACHEV1.DAT
2008-02-08 19:28 --------- dc-h--w C:\Documents and Settings\MERION\Application Data\Move Networks
2008-02-07 05:21 --------- dc----w C:\Program Files\Common Files\Symantec Shared
2008-02-07 03:30 --------- dc----w C:\Program Files\Symantec
2008-02-07 03:30 --------- dc----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-06 08:04 --------- dc----w C:\Documents and Settings\MERION\Application Data\Aim
2008-02-06 06:26 --------- dc----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-05 03:37 --------- dc----w C:\Program Files\QuickTime
2008-01-22 02:58 --------- dc----w C:\Program Files\AIM
2008-01-18 08:51 --------- dc----w C:\Program Files\DivX
2008-01-16 07:53 --------- dc----w C:\Documents and Settings\All Users\Application Data\Avg7
2008-01-04 21:58 9,464 -c----w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-01-04 21:58 9,336 -c----w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-01-04 21:58 43,528 -c----w C:\WINDOWS\system32\drivers\PxHelp20.sys
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 39,792 2007-10-11 03:51:55 C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
-c--a-w 14,348 2008-02-28 21:07:13 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
-c--a-w 50,736 2006-11-07 15:29:02 C:\Program Files\AIM6\bak\aim6.exe
-c--a-w 14,348 2008-02-28 21:07:13 C:\Program Files\AIM6\aim6.exe
-c--a-w 1,191,936 2006-03-22 01:30:00 C:\Program Files\Canon\MyPrinter\bak\BJMyPrt.exe
-c--a-w 14,348 2008-02-28 21:07:13 C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
-c--a-w 267,064 2007-09-26 21:42:04 C:\Program Files\iTunes\bak\iTunesHelper.exe
-c--a-w 14,348 2008-02-28 21:07:13 C:\Program Files\iTunes\iTunesHelper.exe
-c--a-w 132,496 2007-09-25 08:11:35 C:\Program Files\Java\jre1.6.0_03\bin\bak\jusched.exe
-c--a-w 14,348 2008-02-28 21:07:13 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
-c--a-w 1,694,208 2004-10-13 16:24:37 C:\Program Files\Messenger\bak\msmsgs.exe
-c--a-w 14,348 2008-02-28 21:07:13 C:\Program Files\Messenger\msmsgs.exe
-c--a-w 14,348 2008-02-28 21:07:13 C:\Program Files\QuickTime\bak\qttask.exe
-c--a-w 14,860 2008-02-05 03:35:30 C:\Program Files\QuickTime\qttask.exe
-c--a-w 286,720 2007-06-29 13:24:52 C:\Program Files\QuickTime\bak\bak\qttask.exe
-c--a-w 14,860 2008-02-05 03:35:30 C:\Program Files\QuickTime\qttask.exe
-c--a-w 286,720 2007-06-29 13:24:52 C:\Program Files\QuickTime\bak\bak\qttask.exe
-c--a-w 14,348 2008-02-28 21:07:13 C:\Program Files\QuickTime\bak\qttask.exe
-c--a-w 3,537,968 2008-02-23 05:42:34 C:\Program Files\Veoh Networks\Veoh\bak\VeohClient.exe
-c--a-w 14,348 2008-02-28 21:07:13 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
-c--a-w 129,536 2006-07-22 00:19:46 C:\Program Files\Yahoo!\browser\bak\ybrwicon.exe
-c--a-w 14,348 2008-02-28 21:07:13 C:\Program Files\Yahoo!\browser\ybrwicon.exe
-c--a-w 10 2008-02-12 06:00:57 C:\Program Files\Yahoo!\Messenger\bak\emptygrps.steph_flores510.ini
-c--a-w 10 2008-01-27 05:54:42 C:\Program Files\Yahoo!\Messenger\emptygrps.steph_flores510.ini
----a-w 4,662,776 2006-12-01 05:49:04 C:\Program Files\Yahoo!\Messenger\bak\YahooMessenger.exe
-c--a-w 14,348 2008-02-28 21:07:13 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
-c--a-w 3,442 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\audiblemenu.xml
-c--a-w 752 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\audiblerevoked.xml
-c--a-w 10,071 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\content-tabs.xml
-c--a-w 16,563 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\countries.xml
-c--a-w 892 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\default-plugins.xml
-c--a-w 2,793 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\filters.xml
-c--a-w 6,874 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\games.xml
-c--a-w 15,621 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\imvironments.xml
-c--a-w 859 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\logos.xml
-c--a-w 767 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\marketing.xml
-c--a-w 2,256 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\partner.xml
-c--a-w 1,406 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\revoked-plugins.xml
-c--a-w 1,396 2008-02-12 06:01:11 C:\Program Files\Yahoo!\Messenger\bak\Cache\S6KP6dCkAbZHWGr2dU6rKQ--.ab.xml
-c--a-w 3,832 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\S6KP6dCkAbZHWGr2dU6rKQ--.chatCategories.xml
-c--a-w 128 2008-02-12 06:10:40 C:\Program Files\Yahoo!\Messenger\bak\Cache\S6KP6dCkAbZHWGr2dU6rKQ--.conversationhistory.xml
-c--a-w 0 2008-02-12 06:00:57 C:\Program Files\Yahoo!\Messenger\bak\Cache\S6KP6dCkAbZHWGr2dU6rKQ--.ProfileMap.dat.tmp
-c--a-w 71 2008-02-12 06:10:40 C:\Program Files\Yahoo!\Messenger\bak\Cache\S6KP6dCkAbZHWGr2dU6rKQ--.slotmgr.ini
-c--a-w 1,230 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\safeobjects.xml
-c--a-w 2,629 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\searchbar.xml
-c--a-w 16,726 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\searchcategories.xml
-c--a-w 4,701 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\sidepanel-plugins.xml
-c--a-w 5,814 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\sms.xml
-c--a-w 1,158 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\system.xml
-c--a-w 827 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\urls.xml
-c--a-w 3,173 2008-02-11 08:54:16 C:\Program Files\Yahoo!\Messenger\bak\Cache\userfeedback.xml
-c--a-w 854 2008-02-11 08:54:19 C:\Program Files\Yahoo!\Messenger\bak\Cache\branding\10small_1.png
-c--a-w 407 2008-02-11 08:54:19 C:\Program Files\Yahoo!\Messenger\bak\Cache\branding\11small_1.png
-c--a-w 3,410 2008-02-11 08:54:19 C:\Program Files\Yahoo!\Messenger\bak\Cache\branding\1small_1.png
-c--a-w 857 2008-02-11 08:54:19 C:\Program Files\Yahoo!\Messenger\bak\Cache\branding\2small_1.png
-c--a-w 684 2008-02-11 08:54:19 C:\Program Files\Yahoo!\Messenger\bak\Cache\branding\9small_1.png
-c--a-w 16,122 2008-02-11 08:54:17 C:\Program Files\Yahoo!\Messenger\bak\Cache\SearchBar\sb.swf
-c--a-w 16,053 2007-08-31 00:17:44 C:\Program Files\Yahoo!\Messenger\sb.swf
-c--a-w 1,362 2008-02-11 08:54:17 C:\Program Files\Yahoo!\Messenger\bak\Cache\SearchBar\sb.xml
-c--a-w 1,362 2007-08-31 00:17:44 C:\Program Files\Yahoo!\Messenger\sb.xml
-c--a-w 439 2008-02-11 08:54:20 C:\Program Files\Yahoo!\Messenger\bak\Cache\SearchKeywords\keyword_default_0.xml
-c--a-w 439 2008-02-11 08:54:20 C:\Program Files\Yahoo!\Messenger\bak\Cache\SearchKeywords\keyword_default_1.xml
-c--a-w 440 2008-02-11 08:54:20 C:\Program Files\Yahoo!\Messenger\bak\Cache\SearchKeywords\keyword_default_11.xml
-c--a-w 439 2008-02-11 08:54:20 C:\Program Files\Yahoo!\Messenger\bak\Cache\SearchKeywords\keyword_default_4.xml
-c--a-w 439 2008-02-11 08:54:20 C:\Program Files\Yahoo!\Messenger\bak\Cache\SearchKeywords\keyword_default_5.xml
-c--a-w 439 2008-02-11 08:54:20 C:\Program Files\Yahoo!\Messenger\bak\Cache\SearchKeywords\keyword_default_6.xml
-c--a-w 5,289 2008-02-11 08:54:20 C:\Program Files\Yahoo!\Messenger\bak\Cache\SearchKeywords\keyword_default_7.xml
-c--a-w 171 2008-02-11 08:54:18 C:\Program Files\Yahoo!\Messenger\bak\Games\icons\bg_1.gif
-c--a-w 180 2008-02-11 08:54:18 C:\Program Files\Yahoo!\Messenger\bak\Games\icons\ch_1.gif
-c--a-w 225 2008-02-11 08:54:18 C:\Program Files\Yahoo!\Messenger\bak\Games\icons\ck_1.gif
-c--a-w 178 2008-02-11 08:54:18 C:\Program Files\Yahoo!\Messenger\bak\Games\icons\do_2.gif
-c--a-w 226 2008-02-11 08:54:18 C:\Program Files\Yahoo!\Messenger\bak\Games\icons\lt_1.gif
-c--a-w 1,358 2008-02-11 08:54:18 C:\Program Files\Yahoo!\Messenger\bak\Games\icons\ph_3.gif
-c--a-w 367 2008-02-11 08:54:18 C:\Program Files\Yahoo!\Messenger\bak\Games\icons\pl_1.gif
-c--a-w 354 2008-02-11 08:54:18 C:\Program Files\Yahoo!\Messenger\bak\Games\icons\ttb_1.gif
-c--a-w 198 2008-02-11 08:54:18 C:\Program Files\Yahoo!\Messenger\bak\Games\icons\ww_2.gif
-c--a-w 4,726 2008-02-12 06:01:04 C:\Program Files\Yahoo!\Messenger\bak\logs\billing_MERION.log
-c--a-w 45,822 2008-02-12 06:10:40 C:\Program Files\Yahoo!\Messenger\bak\logs\client_MERION.log
-c--a-w 20,809 2008-02-12 06:10:40 C:\Program Files\Yahoo!\Messenger\bak\logs\GIPS.log
-c--a-w 20,221 2008-02-12 06:10:40 C:\Program Files\Yahoo!\Messenger\bak\logs\network_MERION.log
-c--a-w 4,856 2008-02-12 06:10:39 C:\Program Files\Yahoo!\Messenger\bak\logs\p2pce.log
-c--a-w 147,284 2008-02-12 06:10:39 C:\Program Files\Yahoo!\Messenger\bak\logs\voice.log
-c--a-w 492 2008-02-12 06:10:39 C:\Program Files\Yahoo!\Messenger\bak\logs\YSDP.log
-c--a-w 492 2008-02-12 06:10:39 C:\Program Files\Yahoo!\Messenger\bak\logs\YSIP.log
-c--a-w 133 2008-02-12 06:01:12 C:\Program Files\Yahoo!\Messenger\bak\Profiles\steph_flores510\My Icons\Index.ini
-c--a-w 19,371 2008-02-12 06:01:12 C:\Program Files\Yahoo!\Messenger\bak\Profiles\steph_flores510\My Icons\yptC0.png
----a-w 67,112 2006-08-01 21:35:36 E:\Program Files\AIM\bak\aim.exe
----a-w 14,348 2008-02-28 21:07:13 E:\Program Files\AIM\aim.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10C52A42-DB8B-4ade-AA4A-CED6A8282B85}]
C:\Program Files\Sotfone\1202165738.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7db9a213-6c0a-4456-8572-ad897f25405b}]
C:\WINDOWS\system32\wyonyyey.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C38DEBB7-8D19-48B6-96F8-D05F56F8A153}]
C:\WINDOWS\system32\pmkll.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EC6951DC-FE76-4ADA-BF1C-032443E9AD7B}]
C:\WINDOWS\system32\opppq.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2008-02-28 13:07 14348]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-02-28 13:07 14348]
"AIM"="E:\Program Files\AIM\aim.exe" [2008-02-28 13:07 14348]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-02-28 13:07 14348]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-02-28 13:07 14348]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe" [2002-07-12 00:33 1581056 C:\WINDOWS\mixer.exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [ ]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2008-02-28 13:07 14348]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-02-28 13:07 14348]
"QuickTime Task"="C:\Program Files\QuickTime\bak\qttask.exe" [2008-02-28 13:07 14348]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-28 13:07 14348]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 19:51 583048]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2008-02-28 13:07 14348]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-02-28 13:07 14348]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-03-15 21:35:49 113664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"E:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\bak\\YahooMessenger.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
R2 Pctspk;PCTEL Speaker Phone;C:\WINDOWS\system32\pctspk.exe [2001-08-17 14:36]
R3 Ptserlp;PCTEL Serial Device Driver for PCI;C:\WINDOWS\system32\DRIVERS\ptserlp.sys [2001-08-17 05:28]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-28 11:00:00 C:\WINDOWS\Tasks\MalwareBot Scheduled Scan.job"
- C:\Program Files\MalwareBot\MalwareBot.exe
- C:\Program Files\MalwareBot
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-28 17:06:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Canon\MyPrinter\bak\BJMyPrt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\YTBSDK.exe
.
**************************************************************************
.
Completion time: 2008-02-28 17:12:07 - machine was rebooted [MERION]
ComboFix-quarantined-files.txt 2008-02-29 01:12:04
.
2008-02-13 15:18:05 --- E O F ---