Here is the ComboFix log:
ComboFix 09-03-22.01 - The Kids 2009-03-23 21:52:00.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.958.429 [GMT -4:00]
Running from: c:\users\The Kids\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning enabled* (Updated)
FW: Norton 360 *enabled*
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-02-24 to 2009-03-24 )))))))))))))))))))))))))))))))
.
2009-03-23 20:33 . 2009-03-23 20:33 6,736 --a------ c:\windows\System32\drivers\PROCEXP90.SYS
2009-03-23 16:45 . 2009-03-23 16:44 410,984 --a------ c:\windows\System32\deploytk.dll
2009-03-20 22:34 . 2008-12-15 23:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-20 22:34 . 2009-02-08 23:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-20 22:34 . 2008-11-27 00:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-20 22:34 . 2008-12-16 01:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-20 22:34 . 2008-12-16 01:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-20 22:34 . 2008-12-16 01:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-20 22:31 . 2009-03-20 22:31 <DIR> d-------- c:\program files\CCleaner
2009-03-20 22:04 . 2009-03-20 22:04 <DIR> d-------- c:\users\All Users\SUPERAntiSpyware.com
2009-03-20 22:04 . 2009-03-20 22:04 <DIR> d-------- c:\programdata\SUPERAntiSpyware.com
2009-03-20 22:02 . 2009-03-20 22:02 <DIR> d-------- c:\users\The Kids\AppData\Roaming\SUPERAntiSpyware.com
2009-03-20 22:02 . 2009-03-20 22:02 <DIR> d-------- c:\program files\SUPERAntiSpyware
2009-03-20 13:37 . 2009-03-20 13:37 <DIR> d-------- c:\users\The Kids\AppData\Roaming\Malwarebytes
2009-03-20 13:37 . 2009-03-20 13:37 <DIR> d-------- c:\users\All Users\Malwarebytes
2009-03-20 13:37 . 2009-03-20 13:37 <DIR> d-------- c:\programdata\Malwarebytes
2009-03-20 13:37 . 2009-03-20 13:37 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-20 13:37 . 2009-02-11 10:19 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-03-20 13:37 . 2009-02-11 10:19 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-03-16 20:04 . 2009-03-16 20:04 <DIR> d-------- c:\program files\Lavasoft
2009-03-15 02:02 . 2009-03-23 19:47 <DIR> d-------- c:\users\All Users\avg8
2009-03-15 02:02 . 2009-03-23 19:47 <DIR> d-------- c:\programdata\avg8
2009-03-09 15:28 . 2008-12-05 00:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-03-09 15:28 . 2008-12-05 00:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-03-09 15:28 . 2008-12-05 00:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-03-09 15:28 . 2008-12-05 00:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-03-09 15:28 . 2008-12-05 00:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-03-09 15:12 . 2009-01-14 23:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-03-09 15:12 . 2009-01-15 02:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-03-08 21:45 . 2009-03-08 21:45 <DIR> dr------- c:\windows\System32\config\systemprofile\Music
2009-03-05 16:36 . 2009-03-05 16:36 22,528 --a-s---- c:\windows\System32\drivers\PsSdk30.drv
2009-03-03 02:42 . 2004-05-13 17:37 49,152 --a------ c:\windows\System32\npptools.dll
2009-03-03 02:11 . 2009-03-04 23:09 <DIR> d-------- c:\program files\WinPcap
2009-03-02 15:17 . 2009-03-06 17:24 <DIR> d-------- c:\program files\XBC
2009-02-26 14:46 . 2009-02-26 14:46 42,320 --a------ c:\windows\System32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-03-23 23:43 92,052 ----a-w c:\users\All Users\nvModes.dat
2009-03-23 23:43 92,052 ----a-w c:\programdata\nvModes.dat
2009-03-23 20:44 --------- d-----w c:\program files\Java
2009-03-21 07:22 --------- d-----w c:\program files\Windows Mail
2009-03-21 02:01 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-03-17 00:04 --------- d-----w c:\programdata\Lavasoft
2009-03-09 00:52 --------- d-----w c:\programdata\Xfire
2009-03-06 23:15 --------- d-----w c:\programdata\NCH Swift Sound
2009-03-06 17:23 --------- d-----w c:\users\The Kids\AppData\Roaming\IGN_DLM
2009-03-06 15:03 --------- d-----w c:\users\The Kids\AppData\Roaming\Xfire
2009-03-06 14:59 --------- d-----w c:\program files\Xfire
2009-03-05 21:02 --------- d-----w c:\users\The Kids\AppData\Roaming\Yahoo!
2009-03-05 06:01 --------- d-----w c:\users\The Kids\AppData\Roaming\Skype
2009-03-05 05:09 --------- d-----w c:\users\The Kids\AppData\Roaming\skypePM
2009-03-05 03:04 --------- d-----w c:\users\The Kids\AppData\Roaming\oovooToolbar
2009-03-03 16:23 --------- d-----w c:\program files\Common Files\Adobe
2009-02-27 01:21 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-02-24 03:22 --------- d-----w c:\program files\DivX
2009-02-22 01:44 674,138 ----a-w c:\windows\unins000.exe
2009-02-22 01:44 --------- d-----w c:\program files\livetvbar
2009-02-22 01:44 --------- d-----w c:\program files\Conduit
2009-02-20 16:49 --------- d-----w c:\program files\SystemRequirementsLab
2009-02-20 16:43 --------- d-----w c:\users\The Kids\AppData\Roaming\SystemRequirementsLab
2009-02-19 16:31 96,560 ----a-w c:\windows\system32\drivers\symfw.sys
2009-02-19 16:31 9,844 ----a-w c:\windows\system32\drivers\SymRedir.cat
2009-02-19 16:31 41,008 ----a-w c:\windows\system32\drivers\symndisv.sys
2009-02-19 16:31 38,576 ----a-w c:\windows\system32\drivers\symids.sys
2009-02-19 16:31 24,112 ----a-w c:\windows\system32\drivers\SymIMV.sys
2009-02-19 16:31 22,320 ----a-w c:\windows\system32\drivers\symredrv.sys
2009-02-19 16:31 184,496 ----a-w c:\windows\system32\drivers\symtdi.sys
2009-02-19 16:31 13,616 ----a-w c:\windows\system32\drivers\symdns.sys
2009-02-19 16:31 1,611 ----a-w c:\windows\system32\drivers\SymRedir.inf
2009-02-14 03:29 --------- d-----w c:\users\The Kids\AppData\Roaming\Acreon
2009-02-13 22:16 --------- d-----w c:\users\The Kids\AppData\Roaming\Hamachi
2009-02-13 21:25 --------- d-----w c:\program files\AVG
2009-02-13 21:23 --------- d-----w c:\program files\Common Files\Autodesk Shared
2009-02-13 21:23 --------- d-----w c:\program files\AutoCAD 2009
2009-02-12 22:09 --------- d---a-w c:\programdata\TEMP
2009-02-11 00:52 --------- d-----w c:\program files\Common Files\Adobe AIR
2009-02-10 21:03 --------- d-----w c:\users\The Kids\AppData\Roaming\Azureus
2009-02-10 03:24 --------- d-----w c:\users\The Kids\AppData\Roaming\Audacity
2009-02-04 23:47 --------- d-----w c:\users\The Kids\AppData\Roaming\Ventrilo
2009-02-02 04:11 --------- d-----w c:\program files\Download Manager
2009-01-29 22:04 --------- d-----w c:\program files\Azureus
2009-01-29 21:32 --------- d-----w c:\program files\Sony
2009-01-29 12:01 --------- d-----w c:\program files\Vstplugins
2009-01-29 12:00 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-29 12:00 --------- d-----w c:\program files\u-he
2009-01-29 12:00 --------- d-----w c:\program files\Common Files\Digidesign
2009-01-29 12:00 --------- d-----w c:\program files\Celemony
2009-01-27 21:42 --------- d-----w c:\program files\Bonjour
2009-01-26 20:11 --------- d-----w c:\program files\Image-Line
2009-01-26 19:56 --------- d-----w c:\program files\Outsim
2009-01-25 02:48 --------- d-----w c:\users\The Kids\AppData\Roaming\Acoustica
2009-01-25 02:48 --------- d-----w c:\programdata\Acoustica
2009-01-25 02:48 --------- d-----w c:\program files\Acoustica Shared Effects
2009-01-25 02:48 --------- d-----w c:\program files\Acoustica Mixcraft 4
2009-01-23 14:11 7,728 ----a-w c:\users\The Kids\AppData\Roaming\wklnhst.dat
2008-12-31 01:10 60,322 ----a-w c:\users\The Kids\AppData\Roaming\nvModes.dat
2008-12-30 20:25 174 --sha-w c:\program files\desktop.ini
2008-12-30 10:26 118,784 ----a-w c:\windows\dsdxirmv.exe
2008-12-15 20:55 30 ----a-w c:\users\The Kids\jagex_runescape_preferences.dat
2008-12-09 03:38 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-12-09 03:38 56 ---ha-w c:\programdata\ezsidmv.dat
2008-06-18 14:37 604 ---ha-w c:\program files\STLL Notifier
2008-06-30 17:44 324,976 ----a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2008-12-25 14:15 135,680 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-08-30 14:55 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Lo cal\Microsoft\Windows\History\History.IE5\index.da t
2008-08-30 14:55 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Lo cal\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-08-30 14:55 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Ro aming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ad55c869-668e-457c-b270-0cfb2f61116f}"= "c:\program files\livetvbar\tblive.dll" [2008-07-10 1600024]
[HKEY_CLASSES_ROOT\clsid\{ad55c869-668e-457c-b270-0cfb2f61116f}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-8087-36EE87E26986}]
2008-07-29 15:56 1987544 --a------ c:\progra~1\OOVOOT~1\OOVOOT~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ad55c869-668e-457c-b270-0cfb2f61116f}]
2008-07-10 15:04 1600024 --a------ c:\program files\livetvbar\tblive.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-8087-36EE87E26986}"= "c:\progra~1\OOVOOT~1\OOVOOT~1.DLL" [2008-07-29 1987544]
"{ad55c869-668e-457c-b270-0cfb2f61116f}"= "c:\program files\livetvbar\tblive.dll" [2008-07-10 1600024]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8087-36ee87e26986}]
[HKEY_CLASSES_ROOT\oovooToolbar.OOVOOTOOLBAR]
[HKEY_CLASSES_ROOT\clsid\{ad55c869-668e-457c-b270-0cfb2f61116f}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A057A204-BACC-4D26-8087-36EE87E26986}"= "c:\progra~1\OOVOOT~1\OOVOOT~1.DLL" [2008-07-29 1987544]
"{AD55C869-668E-457C-B270-0CFB2F61116F}"= "c:\program files\livetvbar\tblive.dll" [2008-07-10 1600024]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8087-36ee87e26986}]
[HKEY_CLASSES_ROOT\oovooToolbar.OOVOOTOOLBAR]
[HKEY_CLASSES_ROOT\clsid\{ad55c869-668e-457c-b270-0cfb2f61116f}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 1021224]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-11-24 167936]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 317152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-23 148888]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-05-16 430080]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2008-12-04 92704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-07 44128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~ 1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Wind ows^Start Menu^Programs^Startup^HP Connections.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Connections.lnk
backup=c:\windows\pss\HP Connections.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^The Kids^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hamachi.lnk]
path=c:\users\The Kids\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hamachi.lnk
backup=c:\windows\pss\hamachi.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^The Kids^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Memeo AutoSync Launcher.lnk]
path=c:\users\The Kids\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Memeo AutoSync Launcher.lnk
backup=c:\windows\pss\Memeo AutoSync Launcher.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^The Kids^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\The Kids\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^The Kids^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^WD Anywhere Backup Launcher.lnk]
path=c:\users\The Kids\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WD Anywhere Backup Launcher.lnk
backup=c:\windows\pss\WD Anywhere Backup Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 02:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EKIJ5000StatusMonitor]
--a------ 2008-02-19 01:01 1052672 c:\windows\System32\spool\drivers\w32x86\3\EKIJ500 0MUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-12-25 10:15 1838592 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
--a------ 2006-11-28 19:42 46704 c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-05-08 17:24 54840 c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
--a------ 2006-11-21 20:36 1474560 c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
--a------ 2006-10-18 13:32 472800 c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
--a------ 2008-08-01 14:36 1103216 c:\program files\Download Manager\DLM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
--a------ 2006-03-20 18:34 213936 c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 14:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
--a------ 2008-02-26 10:50 988512 c:\program files\Norton 360\osCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2007-02-20 21:18 366400 c:\program files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-03-14 19:50 233472 c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 11:30 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-06-03 10:11 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-19 03:38 1008184 c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-19 03:33 202240 c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\FirewallRules]
"{95ECDD01-AB84-4195-A36C-29147C571235}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9E02C4F2-DF48-4ADA-B6DF-757714F01315}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{847B4D9A-56A3-49A5-9521-2D7585715908}"= UDP:c:\program files\HP\QuickPlay\QP.exe:QP
"{90528E1E-A1FE-4A81-B793-12DCFBBD3662}"= TCP:c:\program files\HP\QuickPlay\QP.exe:QP
"{090CF6CF-EE2B-41E5-8C78-4E27BDD9A0C7}"= UDP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{6B57F522-FAAD-41A8-B1C1-953062BF9446}"= c:\program files\HP Connections\6811507\Program\HP Connections:HP Connections
"{AB06BDE8-59B8-48EC-BE3A-F47C57907ABE}"= UDP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{81A65DC1-77E6-4167-8E14-4B7FCA87FA72}"= TCP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{EC58DC15-F7C5-434D-85D3-CDAD99FD9AC4}"= UDP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{60DEC888-F219-4253-B879-9DCB9F49D1E6}"= TCP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{69766FF7-C030-44B6-941A-342BD87A0965}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{6B858232-CDA8-4787-BC69-95686C88817A}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{964A17A2-B864-49C4-AE05-C970AF48F245}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{D0E33B3D-1A5D-4264-A998-9D761F9F2B0E}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{E4F8C58C-172C-4E9F-87BD-9C7CCBAA8251}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{0CA0798A-3E2C-4FD7-BEAB-7513E7519FE5}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{1DAEAF7A-EEF0-4055-8982-1FA5DAD6196A}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{6F1A09BD-D58B-4CDC-88C2-525E875426A1}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{A3A9B5E7-66A9-4A88-96BC-0E02506CD669}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{146C74A2-7388-4BB5-A0CD-95DEDF3E8DCB}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{A5A30352-1D7E-4BD5-AE28-B6829E35A2CC}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{EDBE90CE-2F37-4AB7-9B89-5B1A5EF9CC52}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{79084186-ABA1-457E-9479-14E780B29913}"= UDP:c:\program files\Electronic Arts\Battlefield 2142 Demo\BF2142.exe:Battlefield 2
"{68BBC46E-6EE7-49F8-ACB8-EC8F4A1424FB}"= TCP:c:\program files\Electronic Arts\Battlefield 2142 Demo\BF2142.exe:Battlefield 2
"{D3E7D3C0-C187-4DF1-8298-D0EF5B89EFAF}"= UDP:c:\program files\vghd\vghd.exe:VirtuaGirl HD
"{1039C10D-D5F5-4968-A930-DAB140CB2BE4}"= TCP:c:\program files\vghd\vghd.exe:VirtuaGirl HD
"{299A7502-5AA8-4E53-A0E9-379709870F22}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{5F8D0592-F6AC-4366-87DD-CAC189946573}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{FAC59CCB-FED0-4F97-9C66-2DEC7AD5DEFF}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{ABA9249B-CCFC-45E6-A17F-57AD46511A42}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{38B5B822-C472-4C02-B43E-38F7401FE1A1}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D767EED9-C3FA-49EF-8DF2-E916C05B75D7}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{F9D3F265-B097-4274-9092-7E13BD749008}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{731F1C55-7334-4BB0-9344-56FEDC8FE5DA}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{58368A42-4ABA-4119-9807-41FD6CD13F21}"= UDP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{2D750FEF-AF4B-4A07-8C8A-D4C79A0BFA22}"= TCP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{9ABB0E82-030A-45D0-BBC3-E17D50FA2A45}"= UDP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{CD66240A-DB0B-4A2B-A20B-E0141C830BDC}"= TCP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{2C7779A5-C781-4A5D-894A-19E8D8C72AFD}"= UDP:443:ooVoo TCP port 443
"{A32A00D8-8EB5-4F4E-A725-B076DA5A7CA9}"= TCP:443:ooVoo UDP port 443
"{DE78D73F-EED6-47D6-B8D8-0EDE1C9AA55B}"= UDP:37674:ooVoo TCP port 37674
"{9397C10D-74D2-44A6-B22C-612C3CDCAEBB}"= TCP:37674:ooVoo UDP port 37674
"{C42DFEC4-D6A8-4878-9AA0-81E6BA74CBC3}"= TCP:37675:ooVoo UDP port 37675
"{1B1AED2E-91F1-4F23-ACF4-B4803EB803CF}"= UDP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{5C1C1CA3-349B-4581-9BCE-14C763016515}"= TCP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{D37A98E1-883B-4C4A-B60B-E4DBB7C6AE50}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{47CD6B3B-91B1-4FD7-914B-2308F86EBEF9}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{3192CBA8-F5A0-402B-BB7C-2A64D832A0D5}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{01D77EED-A1BF-44D9-B806-E7AEAC3A3DF9}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{49FA375E-BB30-41E4-9004-2C90803EA2E0}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{AA9619A4-0D80-4931-91D3-DAC3716B220C}"= UDP:5353:Adobe CSI CS4
"{EF57A766-9EDA-4A65-B481-3DC66F334A1D}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.ex e:Adobe CSI CS4
"{2CC51998-F44D-4C91-9154-4A98732EDEC1}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.ex e:Adobe CSI CS4
"{1D4441DD-FB46-4D46-AB88-73A1947651BD}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{96FDF893-0B3F-472E-B5BC-0A03E802DD50}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{26848B8C-1DF1-448C-AB1A-5616AD26A554}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{AFF7E2A0-064A-4913-BACC-2C87CBE7D2BF}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1813FD63-0BDA-4B6E-9946-F90BBEF8DAE5}"= UDP:c:\program files\XBC\AppUpdater.exe:XBC 5.1
"{4C2552C1-9F38-4AAC-B560-387F3E72BA88}"= TCP:c:\program files\XBC\AppUpdater.exe:XBC 5.1
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
"c:\\Nexon\\Combat Arms\\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\\Nexon\\Combat Arms\\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsd efs\20090318.001\IDSvix86.sys [2009-03-23 272432]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-02-17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2008-10-30 149352]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-03-31 24652]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [2008-05-16 102400]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-26 101936]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symn disv.sys [2009-02-19 41008]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mo n.sys [2008-01-12 23888]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\System32\drivers\npf.sys [2008-12-23 50704]
S3 PsSdk30;PsSdk30;c:\windows\System32\drivers\PsSdk3 0.drv [2009-03-05 22528]
S3 RDID1009;EDIROL UM-1;c:\windows\System32\drivers\Rdwm1009.sys [2008-12-30 56832]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
S3 XDva190;XDva190;c:\windows\System32\XDva190.sys [2008-09-03 46720]
S4 AutoSyncService;Memeo AutoSync ;c:\program files\Memeo\AutoSync\MemeoService.exe [2007-07-06 31768]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\F]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-2-5-91-100000658-100004814-100013302-2210.com f:\
\shell\Open\command - RECYCLER\S-2-5-91-100000658-100004814-100013302-2210.com f:\
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{45874d27-27fa-11dd-9411-001b2430930b}]
\shell\AutoRun\command - G:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{45874d4e-27fa-11dd-9411-001b2430930b}]
\shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{d17fa6b5-7a0f-11dd-b7f6-001b2430930b}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{d17fa7cc-7a0f-11dd-b7f6-001b2430930b}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-03-23 c:\windows\Tasks\User_Feed_Synchronization-{D358B560-0EF6-4865-B491-8AA1A92023FD}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 03:33]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)
HKCU-Run-AdobeBridge - (no file)
HKLM-RunOnce-<NO NAME> - (no file)
MSConfigStartUp-6c24ff16 - c:\users\THEKID~1\AppData\Local\Temp\stybwsvx.dll
MSConfigStartUp-AntiMalwareProMFCT - c:\program files\AdwarePro\StartApp.exe
MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
MSConfigStartUp-Host Process - c:\users\The Kids\svchost.exe
MSConfigStartUp-MS Juan - c:\users\THEKID~1\AppData\Local\Temp\ccxedxjw.dll
MSConfigStartUp-MSServer - c:\users\THEKID~1\AppData\Local\Temp\mlJApPIb.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT1576177
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion &pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\The Kids\AppData\Roaming\Mozilla\Firefox\Profiles\ykgx ezp7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nptgeqplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\users\The Kids\AppData\Roaming\Mozilla\Firefox\Profiles\ykgx ezp7.default\extensions\iaplayer@instantaction.com \plugins\npiaplayer.dll
.
************************************************** ************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-23 21:57:56
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(2504)
c:\windows\System32\NLSData0009.dll
c:\windows\system32\BatMeter.dll
.
Completion time: 2009-03-23 22:01:50
ComboFix-quarantined-files.txt 2009-03-24 02:01:33
Pre-Run: 24,030,859,264 bytes free
Post-Run: 23,999,025,152 bytes free
396 --- E O F --- 2009-03-21 07:15:32