Here is the Combofix log.
ComboFix 09-03-01.01 - Joe 2009-03-01 18:54:00.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.894.194 [GMT -6:00]
Running from: c:\users\Joe\Desktop\ComboFix.exe
AV: StopSign Antivirus *On-access scanning disabled* (Updated)
FW: StopSign Firewall *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\FunWebProducts
c:\program files\Gamevance\gvtl.dll
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\3.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\3.bin\F3CJPEG.DLL
c:\program files\MyWebSearch\bar\3.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\3.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\3.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\3.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\3.bin\FWPBUDDY.PNG
c:\program files\MyWebSearch\bar\3.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\3.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\3.bin\M3HIGHIN.EXE
c:\program files\MyWebSearch\bar\3.bin\M3HTML.DLL
c:\program files\MyWebSearch\bar\3.bin\M3IDLE.DLL
c:\program files\MyWebSearch\bar\3.bin\M3IMPIPE.EXE
c:\program files\MyWebSearch\bar\3.bin\M3MEDINT.EXE
c:\program files\MyWebSearch\bar\3.bin\M3MSG.DLL
c:\program files\MyWebSearch\bar\3.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\3.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\3.bin\M3PLUGIN.DLL
c:\program files\MyWebSearch\bar\3.bin\M3SKIN.DLL
c:\program files\MyWebSearch\bar\3.bin\M3SKPLAY.EXE
c:\program files\MyWebSearch\bar\3.bin\M3SLSRCH.EXE
c:\program files\MyWebSearch\bar\3.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\3.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\windows\system32\drivers\RKHit.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_MyWebSearchService
-------\Service_RkHit
((((((((((((((((((((((((( Files Created from 2009-02-02 to 2009-03-02 )))))))))))))))))))))))))))))))
.
2009-03-01 18:49 . 2009-03-01 18:49 6,736 --a------ c:\windows\System32\drivers\PROCEXP90.SYS
2009-03-01 18:39 . 2009-03-01 18:39 <DIR> d-------- c:\program files\New Folder
2009-02-27 11:11 . 2009-02-27 11:32 <DIR> d-------- c:\program files\NoAdware
2009-02-27 00:02 . 2009-02-27 00:02 <DIR> d-------- c:\program files\Trend Micro
2009-02-26 23:55 . 2009-02-27 00:00 <DIR> d-------- c:\users\Joe\AppData\Roaming\ErrorFix
2009-02-23 19:03 . 2009-02-23 19:03 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-02-11 12:59 . 2009-02-11 12:59 <DIR> d-------- c:\program files\MFInstall
2009-02-11 12:59 . 2006-10-06 09:35 1,693,696 --a------ c:\windows\System32\ltclr13n.dll
2009-02-11 12:59 . 2006-10-06 09:35 453,120 --a------ c:\windows\System32\ltkrn13n.dll
2009-02-11 12:59 . 2006-10-06 09:35 445,440 --a------ c:\windows\System32\ltimg13n.dll
2009-02-11 12:59 . 2006-10-06 09:35 388,608 --a------ c:\windows\System32\lfcmp13n.dll
2009-02-11 12:59 . 2006-10-06 09:35 265,216 --a------ c:\windows\System32\ltdis13n.dll
2009-02-11 12:59 . 2006-10-06 09:35 246,272 --a------ c:\windows\System32\lfj2k13n.dll
2009-02-11 12:59 . 2006-10-06 09:35 206,848 --a------ c:\windows\System32\ltefx13n.dll
2009-02-11 12:59 . 2006-10-18 14:52 189,976 --a------ c:\windows\System32\mfimgvwr.ocx
2009-02-11 12:59 . 2006-10-06 09:35 154,112 --a------ c:\windows\System32\ltfil13n.dll
2009-02-11 12:59 . 2006-10-06 09:35 142,848 --a------ c:\windows\System32\lftif13n.dll
2009-02-11 12:59 . 2006-10-06 09:35 90,112 --a------ c:\windows\System32\lfjbg13n.dll
2009-02-11 12:59 . 2006-10-06 09:35 73,728 --a------ c:\windows\System32\lffax13n.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-02 00:59 --------- d-----w c:\program files\Gamevance
2009-03-01 16:48 --------- d-----w c:\programdata\Google Updater
2009-02-24 03:28 --------- d-----w c:\programdata\lx_cats
2009-02-19 01:17 --------- d-----w c:\program files\Google
2009-02-05 21:06 51,792 ----a-w c:\windows\system32\drivers\aswMonFlt.sys
2009-01-25 18:36 --------- d-----w c:\program files\MySpace
2009-01-23 03:16 --------- d-----w c:\program files\Common Files\Adobe
2009-01-23 03:14 --------- d-----w c:\program files\Adobe Media Player
2009-01-23 02:59 --------- d-----w c:\program files\Common Files\Macrovision Shared
2009-01-23 02:53 --------- d-----w c:\users\Joe\AppData\Roaming\Download Manager
2009-01-14 19:24 --------- d-----w c:\users\Joe\AppData\Roaming\U3
2008-12-23 07:20 319,456 ----a-w c:\windows\DIFxAPI.dll
2008-08-04 01:14 1,162 ----a-w c:\users\Joe\AppData\Roaming\wklnhst.dat
2008-06-07 23:07 88 --sh--r c:\users\All Users\944A43625F.sys
2008-06-07 23:07 88 --sh--r c:\programdata\944A43625F.sys
2008-06-07 23:07 2,516 --sha-w c:\users\All Users\KGyGaAvL.sys
2008-06-07 23:07 2,516 --sha-w c:\programdata\KGyGaAvL.sys
2008-01-03 23:00 56,912 ----a-w c:\users\Joe\g2mdlhlpx.exe
2006-11-02 12:48 174 --sha-w c:\program files\desktop.ini
2003-08-05 17:41 53,248 ----a-w c:\windows\inf\ap561.exe
2002-11-26 22:24 32,768 ----a-w c:\windows\inf\Remove561.exe
2002-11-22 21:56 118,784 ----a-w c:\windows\inf\ShowBmp.exe
2002-10-30 00:07 36,864 ----a-w c:\windows\inf\Setup8a.exe
2002-10-01 20:43 119,798 ----a-w c:\windows\inf\spca561.sys
2008-12-19 23:02 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-19 23:02 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-19 23:02 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-19 23:02 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-19 23:02 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-09 1232896]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-16 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"SnapfishMediaDetector"="c:\program files\Snapfish Media Detector\SnapfishMediaDetector.exe" [2007-03-02 1441792]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-19 286720]
"SoftwareStation"="c:\program files\eAcceleration\Station\station.exe" [2008-04-15 173392]
"webscan"="c:\program files\Acceleration Software\Anti-Virus\stopsignav.exe" [2007-12-19 771504]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"WinZip E-Mail Companion OEAPI"="c:\program files\WinZip E-Mail Companion\loadwzco.exe" [2007-11-19 75136]
"lxdmmon.exe"="c:\program files\Lexmark 5000 Series\lxdmmon.exe" [2007-07-06 455344]
"lxdmamon"="c:\program files\Lexmark 5000 Series\lxdmamon.exe" [2007-06-01 20480]
"Lexmark 5000 Series Fax Server"="c:\program files\Lexmark 5000 Series\fm3032.exe" [2007-07-06 307888]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 856064]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"DPService"="c:\program files\HP\DVDPlay\DPService.exe" [2007-12-18 90112]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-03-07 44168]
c:\users\Joe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
Snapfish Media Detector.lnk - c:\program files\Snapfish Media Detector\SnapfishMediaDetector.exe [2007-03-02 1441792]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A38BFD50-6D38-4631-B38E-E0E65CE16D35}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5F492DF9-3E76-42E6-973A-8083AE42F792}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C39C9369-DF78-4BA3-B71E-AAEBCCC33157}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{E6281A08-83AE-4E62-8A1A-2C189B8D1BE7}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{21C042E9-8F4D-4046-980E-4F45283AC8F2}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{61D8597E-437D-43DD-89CC-62F487F13081}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{CFE6DE30-FE46-4C60-B0B7-09C12C3214F0}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{B82921CB-E57D-4E9E-AADF-71E261A9A6FC}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{2FA31048-6F8B-4B6D-B4B3-4CA3B2CCA773}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{348A4B28-60FC-450A-A061-3A915E48CE2E}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{A4B950D3-1F4C-40BA-B942-455C74728F8C}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{A9AEACEB-E4A5-4621-A94F-4B63E3E8B84E}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{D3971D83-A194-466E-9D0E-1298F755BED0}"= UDP:c:\windows\System32\lxbkcoms.exe:Lexmark Communications System
"{00C283B4-D6ED-42ED-B4FF-F08451E28971}"= TCP:c:\windows\System32\lxbkcoms.exe:Lexmark Communications System
"{FB9520B7-7325-46C2-B3EA-D51B80D7A5EF}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window
"{CCB51CE6-39B7-47A3-9D98-272E88C27BCE}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window
"{E471E950-0BEC-40E4-AB2A-20F8ACDE4020}"= UDP:c:\windows\System32\lxdmcoms.exe:Lexmark Communications System
"{BF9755C8-1234-4120-BF1E-6D480C2C42B6}"= TCP:c:\windows\System32\lxdmcoms.exe:Lexmark Communications System
"{7FE75FAA-B81E-4106-93A5-45820FEE2E05}"= UDP:c:\program files\Lexmark 5000 Series\lxdmamon.exe:Lexmark Device Monitor
"{9D9BB749-CE0C-45B6-AD57-0A5E92E31FC4}"= TCP:c:\program files\Lexmark 5000 Series\lxdmamon.exe:Lexmark Device Monitor
"{8BCAD5ED-2FEB-4FEF-9859-E86E01FE2D39}"= UDP:c:\program files\Lexmark 5000 Series\frun.exe:Lexmark Productivity Studio
"{1660A0B2-ADD8-4A17-B282-CC466A8610DA}"= TCP:c:\program files\Lexmark 5000 Series\frun.exe:Lexmark Productivity Studio
"{484B5C05-430D-4E2F-B5E1-F352538EB387}"= UDP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{3E6E2D27-5A58-4B50-AEC6-38599D0EA693}"= TCP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{053109D9-9122-4143-9247-E63B5A26CAA4}"= UDP:c:\program files\Lexmark 5000 Series\LXDMFax.exe:Fax software
"{863B3986-8603-4A8E-BDFE-855A781CB52F}"= TCP:c:\program files\Lexmark 5000 Series\LXDMFax.exe:Fax software
"{E8FA639A-470A-424E-8FF7-297FA4849A28}"= UDP:c:\program files\Lexmark 5000 Series\lxdmmon.exe:Printer Device Monitor
"{01CCA309-8034-4BE6-A4B3-99C3DB914CAD}"= TCP:c:\program files\Lexmark 5000 Series\lxdmmon.exe:Printer Device Monitor
"{8CF24E38-677E-4E1F-9C86-32D9BCDE8F53}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{63AE7B04-2D5A-4A99-A867-B688B8DEC491}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C6C16AF6-551D-46F0-94AC-DACEF5ACC943}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{A1D7C3B9-F555-41BA-87BF-F696249A9B39}"= UDP:c:\windows\System32\lxdmcoms.exe:Lexmark Communications System
"{8615819A-C0C2-4697-B603-3C3777E77658}"= TCP:c:\windows\System32\lxdmcoms.exe:Lexmark Communications System
"{7B18DE96-D71D-4EF7-922F-E35C5515D38C}"= UDP:c:\program files\Lexmark 5000 Series\lxdmamon.exe:Lexmark Device Monitor
"{9FF82007-885E-4079-97FE-844434C468E8}"= TCP:c:\program files\Lexmark 5000 Series\lxdmamon.exe:Lexmark Device Monitor
"{AE67E3AF-FA8A-47E3-9B2E-157EFFBABA4B}"= UDP:c:\program files\Lexmark 5000 Series\frun.exe:Lexmark Productivity Studio
"{B1C8980F-4655-44B9-B3AB-23C0E2C85B04}"= TCP:c:\program files\Lexmark 5000 Series\frun.exe:Lexmark Productivity Studio
"{2D9DD8BC-E4E0-4B49-BB39-38D9C1676192}"= UDP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{7F3DD1E0-2B52-460A-84C1-5D927E5A6AE3}"= TCP:c:\program files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:ABBYY FineReader
"{98D410D8-097D-4171-843F-D247090C0D57}"= UDP:c:\program files\Lexmark 5000 Series\LXDMFax.exe:Fax software
"{4111BD43-0E73-47A7-AC5A-C118522AC103}"= TCP:c:\program files\Lexmark 5000 Series\LXDMFax.exe:Fax software
"{983092F6-7B76-463A-8942-8CDC6F80C62C}"= UDP:c:\program files\Lexmark 5000 Series\lxdmmon.exe:Printer Device Monitor
"{945D8BF3-D4E3-40C6-8D11-2FAA9D9E7DDA}"= TCP:c:\program files\Lexmark 5000 Series\lxdmmon.exe:Printer Device Monitor
"{50FA30DC-6484-4B27-A51D-A7D93E636410}"= UDP:c:\program files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe:Adobe Version Cue CS2
"{39601A4F-87CB-4512-977C-E4309A21C49D}"= TCP:c:\program files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe:Adobe Version Cue CS2
"{4BD104C4-1D35-40D8-AAA2-5E569682ECD2}"= c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"TCP Query User{EF2D79BA-FC86-48CE-AC50-CBB56B76C87F}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{BB14F65E-9B74-4FD8-BD05-3795C825FF95}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"{21448E84-A6A6-4967-A388-9CE7CE2C7665}"= c:\program files\HP\DVDPlay\DVDPlay.exe:DVD Play
"{D7C10EE1-DA31-44A8-B95F-8A5D518A4A10}"= c:\program files\HP\DVDPlay\DPService.exe:DVD Play Resident Program
"{6FAE1937-683F-4946-A9F3-BAAC6FBD51FE}"= UDP:5353:Adobe CSI CS4
"{2CF1540E-CD80-4806-AF04-B68A24ED5854}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{7A2A9C9E-016B-465A-B7A5-89480506FE4C}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2008-10-12 114768]
R1 FWCore;FWCore;c:\windows\System32\drivers\fwcore.sys [2008-07-23 58456]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20080111.002\IDSvix86.sys [2008-01-11 180272]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2008-10-12 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2008-10-12 51792]
R2 eac_notifysvc;eAcceleration Notification Service;c:\program files\eAcceleration\Framework\eac_svc.exe [2008-04-17 111952]
R2 eac_productsvc;eAcceleration Product Manager Service;c:\program files\eAcceleration\Framework\eac_productsvc.exe [2008-04-17 263504]
R2 FWService;FWService;c:\program files\eAcceleration\Firewall\FWService.exe -Service --> c:\program files\eAcceleration\Firewall\FWService.exe -Service [?]
R2 lxdm_device;lxdm_device;c:\windows\system32\lxdmcoms.exe -service --> c:\windows\system32\lxdmcoms.exe -service [?]
R2 StopSign Update Manager;StopSign Update Manager;c:\program files\Common Files\eAcceleration\eacsvc.exe [2008-01-08 103760]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;c:\windows\System32\drivers\mr97310v.sys [2006-03-07 111872]
S3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2007-10-30 37936]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{311bd3d1-d524-11dd-bbe1-001bfc520958}]
\shell\AutoRun\command - K:\podcastready.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f418a8e8-e26c-11dd-a4cc-001bfc520958}]
\shell\AutoRun\command - L:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-03-01 c:\windows\Tasks\ErrorFix Scan.job
- c:\program files\ErrorFix\ErrorFix.exe []
2009-03-01 c:\windows\Tasks\ErrorFix Scan.job
- c:\program files\ErrorFix []
2009-03-02 c:\windows\Tasks\ErrorFix Startup.job
- c:\program files\ErrorFix\ErrorFix.exe []
2009-03-02 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-06-25 12:08]
2009-02-19 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-06-25 12:08]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\3.bin\M3PLUGIN.DLL
.
------- Supplementary Scan -------
.
uLocal Page = \blank.htm
uStart Page =
hxxp://www.yahoo.com/mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktopmSearch Bar =
hxxp://us.rd.yahoo.com/customize/ie/def ... earch.htmluInternet Settings,ProxyOverride = *.local
IE: &Search -
http://edits.mywebsearch.com/toolbaredi ... xdm021YYUSIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\users\Joe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} -
hxxp://dlm.tools.akamai.com/dlmanager/v ... .2.4.1.cabFF - ProfilePath - c:\users\Joe\AppData\Roaming\Mozilla\Firefox\Profiles\ophkujvg.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.ask.com/?o=20011&l=disFF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.hideGoButton", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.enabled", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-01 19:11:42
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(5348)
c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\System32\lxdmcoms.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\WUDFHost.exe
c:\program files\eAcceleration\Firewall\FWService.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\windows\System32\rundll32.exe
c:\program files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
c:\program files\eAcceleration\Station\station_bk.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\combofix\hidec.exe
c:\combofix\Catchme.tmp
.
**************************************************************************
.
Completion time: 2009-03-01 19:18:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-02 01:17:10
Pre-Run: 72,651,755,520 bytes free
Post-Run: 91,904,737,280 bytes free
348 --- E O F --- 2009-03-01 16:45:18