Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\Documents and Settings\Administrator\Desktop\installments\Nero-7.5.9.0A_eng.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-3ad601a5-49cfd623.zip\
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5efd1945-70408ee2.zip\
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-4477ad6a.zip\
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-b825669-2b0e2f8d.zip\
C:\Documents and Settings\Administrator\Desktop\installments\Nero-7.5.9.0A_eng.exe
.
((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))
.
2008-02-02 22:41 . 02/02/08 10:41p 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_35c.dat
2008-02-02 19:54 . 02/02/08 07:54p <DIR> d-------- C:\WINNT\system32\Kaspersky Lab
2008-02-02 19:54 . 02/02/08 07:54p <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-02 17:21 . 02/02/08 07:30p <DIR> d-------- C:\col4309
2008-02-02 17:20 . 02/02/08 05:20p 3 --a------ C:\WINNT\Twain001.Mtx
2008-02-02 14:05 . 02/02/08 02:05p <DIR> d-------- C:\Program Files\Trend Micro
2008-01-25 20:03 . 01/25/08 08:05p <DIR> d-------- C:\Program Files\Age Of Wonders
2008-01-20 14:39 . 01/22/08 10:06a 54,156 --ah----- C:\WINNT\QTFont.qfn
2008-01-20 14:39 . 01/20/08 02:39p 1,409 --a------ C:\WINNT\QTFont.for
2008-01-14 03:01 . 01/14/08 03:01a <DIR> d-------- C:\Program Files\MSXML 4.0
2008-01-14 01:11 . 01/17/08 03:08p <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\BitTorrent
2008-01-14 01:10 . 01/14/08 01:10a <DIR> d-------- C:\Program Files\DNA
2008-01-14 01:10 . 01/14/08 01:10a <DIR> d-------- C:\Program Files\BitTorrent
2008-01-14 01:10 . 02/02/08 10:37p <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\DNA
2008-01-13 18:11 . 01/13/08 06:11p <DIR> d-------- C:\Program Files\Photo Viewer
2008-01-13 18:06 . 01/13/08 06:06p <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Share-to-Web Upload Folder
2008-01-13 18:06 . 01/13/08 06:06p 82,380 --a------ C:\WINNT\system32\drivers\AFS2K.SYS
2008-01-13 18:05 . 06/19/03 01:05p 12,592 --a------ C:\WINNT\system32\drivers\usbscan.sys
2008-01-13 18:05 . 06/19/03 01:05p 12,592 --a--c--- C:\WINNT\system32\dllcache\usbscan.sys
2008-01-13 18:04 . 01/13/08 06:04p <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-01-13 17:52 . 01/13/08 05:52p <DIR> d-------- C:\Program Files\Bonjour
2008-01-13 17:50 . 01/13/08 05:50p <DIR> d-------- C:\WINNT\system32\BWKDLogs
2008-01-13 17:49 . 01/13/08 05:49p <DIR> d-------- C:\Program Files\Common Files\Kodak
2008-01-13 17:48 . 01/13/08 05:48p <DIR> d-------- C:\WINNT\system32\color
2008-01-13 17:48 . 01/13/08 05:48p <DIR> d-------- C:\KPCMS
2008-01-13 17:39 . 01/13/08 05:51p <DIR> d-------- C:\Program Files\Kodak
2008-01-13 17:39 . 01/13/08 05:39p <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kodak
2008-01-07 19:24 . 01/07/08 07:24p <DIR> dr------- C:\Program Files\Liquid Entertainment
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-02 23:43 --------- d---a-w C:\Program Files\Steam
2008-02-02 06:27 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AVG7
2008-02-02 01:42 --------- d-----w C:\Program Files\DivX
2008-01-30 03:00 43,520 ----a-w C:\WINNT\system32\CmdLineExt03.dll
2008-01-14 00:06 --------- d-----w C:\Program Files\Hewlett-Packard
2008-01-13 23:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-09 20:37 --------- d-----w C:\Program Files\World of Warcraft
2007-12-26 20:16 --------- d-----w C:\Program Files\iTunes
2007-12-26 20:16 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Apple Computer
2007-12-26 20:15 --------- d-----w C:\Program Files\iPod
2007-12-26 20:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-26 19:27 --------- d-----w C:\Program Files\Common Files\Ahead
2007-12-26 19:26 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Ahead
2007-12-26 19:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2007-12-26 19:20 --------- d-----w C:\Program Files\Nero
2007-12-23 07:22 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2007-12-22 22:55 --------- d--h--w C:\Documents and Settings\Administrator\Application Data\yahoo!
2007-12-21 21:08 --------- d-----w C:\Program Files\Ventrilo
2007-12-21 21:08 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-21 00:51 --------- d-----w C:\Program Files\SystemRequirementsLab
2007-12-21 00:51 --------- d-----w C:\Documents and Settings\Administrator\Application Data\SystemRequirementsLab
2007-12-11 21:54 --------- d-----w C:\Program Files\Yahoo!
2007-12-10 22:04 --------- d-----w C:\Program Files\AIM6
2007-12-10 22:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-10 22:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-12-10 21:56 --------- d-----w C:\Program Files\Common Files\AOL
2004-01-01 20:59 271 ---h--w C:\Program Files\desktop.ini
2004-01-01 20:59 21,952 ---h--w C:\Program Files\folder.htt
1999-12-07 17:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [11/16/06 07:04p 139264]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [08/30/07 04:43p 4670704]
"Steam"="C:\Program Files\Steam\Steam.exe" [01/01/04 12:08a 1266936]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [10/04/07 09:20a 50528]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [01/14/08 01:10a 290112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [06/19/03 01:05p 111376 C:\WINNT\system32\mobsync.exe]
"NvCplDaemon"="C:\WINNT\System32\NvCpl.dll" [03/09/06 03:29p 7561216]
"nwiz"="nwiz.exe" [03/09/06 03:29p 1519616 C:\WINNT\system32\nwiz.exe]
"NvMediaCenter"="C:\WINNT\System32\NvMcTray.dll" [03/09/06 03:29p 86016]
"SoundMax"="C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [04/13/05 02:48a 36975]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [01/12/06 03:40p 155648]
"QuickTime Task"="C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" [10/25/06 06:58p 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [10/30/06 09:36a 256576]
"HPDJ Taskbar Utility"="C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe" [11/19/01 08:27a 196608]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [01/28/08 02:27p 579072]
"Share-to-Web Namespace Daemon"="c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [04/17/02 10:42a 69632]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [10/26/07 01:44p 219136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [06/19/03 01:05p 186640]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
D-Link AirPlus.lnk - C:\Program Files\D-Link AirPlus\AirPlus.exe [2004-01-03 19:44:24 262144]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-06-14 23:11:40 180224]
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 14:12:08 16423]
R1 Avg7RsNT;AVG7 Resident Driver NT;C:\WINNT\system32\Drivers\avg7rsnt.sys [10/23/07 09:13p]
R3 openhci;Microsoft USB Open Host Controller Driver;C:\WINNT\system32\DRIVERS\openhci.sys [06/19/03 01:05p]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-02 22:44:25
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 02/02/2008 22:46:24
ComboFix-quarantined-files.txt 2008-02-03 04:45:34
ComboFix2.txt 2008-02-02 23:45:17
ComboFix3.txt 2008-02-02 22:54:29
.
2008-01-14 09:01:17 --- E O F ---