ComboFix 08-03-07.4 - Omar 2008-03-08 14:15:28.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.961 [GMT -5:00]
Running from: C:\Users\Omar\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Omar\AppData\Local\etxraixi.dat
C:\Users\Omar\AppData\Local\etxraixi.exe
C:\Users\Omar\AppData\Local\etxraixi_nav.dat
C:\Users\Omar\AppData\Local\etxraixi_navps.dat
C:\Windows\rs.txt
C:\Windows\search_res.txt
C:\Windows\system32\install.exe
.
((((((((((((((((((((((((( Files Created from 2008-02-08 to 2008-03-08 )))))))))))))))))))))))))))))))
.
2008-03-08 14:11 . 2008-03-08 14:12 <DIR> d-------- C:\HostsXpert 4.2 - Hosts File Manager
2008-03-08 12:27 . 2008-03-08 12:28 <DIR> d-------- C:\SmitfraudFix
2008-03-08 12:27 . 2008-03-08 12:27 1,303,855 --a------ C:\SmitfraudFix.exe
2008-03-06 18:39 . 2008-03-06 18:39 <DIR> d-------- C:\Windows\Java
2008-03-06 18:39 . 2002-02-18 07:34 313,856 --a------ C:\Windows\System32\dx3j.dll
2008-03-06 18:39 . 2002-02-18 10:22 171,280 --a------ C:\Windows\System32\jit.dll
2008-03-06 18:39 . 2002-02-18 10:22 139,536 --a------ C:\Windows\System32\javaee.dll
2008-03-06 18:39 . 2002-02-18 10:23 46,352 --a------ C:\Windows\setdebug.exe
2008-03-06 18:39 . 2002-02-18 07:55 7,315 --a------ C:\Windows\System32\javasup.vxd
2008-03-06 18:39 . 2002-02-18 07:35 6,550 --a------ C:\Windows\jautoexp.dat
2008-03-06 18:38 . 2008-03-06 18:39 <DIR> d-------- C:\Program Files\Hushmail for Outlook
2008-03-06 18:24 . 2008-03-06 18:24 <DIR> d-------- C:\Deckard
2008-03-03 14:50 . 2008-03-03 14:50 <DIR> d-------- C:\Program Files\SigmaTel
2008-03-03 14:50 . 2006-11-02 12:39 4,931,584 --a------ C:\Windows\System32\stacgui.cpl
2008-03-03 14:50 . 2006-11-02 12:38 1,146,880 --a------ C:\Windows\System32\stlang.dll
2008-03-03 14:50 . 2006-11-02 12:39 520,192 --a------ C:\Windows\System32\stapo.dll
2008-03-03 14:50 . 2006-11-02 12:38 303,104 --a------ C:\Windows\sttray.exe
2008-03-03 14:50 . 2006-11-02 12:39 140,800 --a------ C:\Windows\System32\staco.dll
2008-03-03 14:50 . 2006-11-02 12:39 91,648 --a------ C:\Windows\System32\stcplx.dll
2008-03-03 14:50 . 2006-11-02 12:39 90,112 --a------ C:\Windows\System32\stacsv.exe
2008-03-03 14:44 . 2008-03-03 14:44 <DIR> d-------- C:\dell
2008-03-03 14:39 . 2008-03-03 14:39 <DIR> d-------- C:\pnp
2008-03-03 13:58 . 2008-03-03 14:21 <DIR> d-------- C:\Program Files\Abexo
2008-03-03 13:58 . 2008-03-03 13:58 241 --a------ C:\Windows\Wininit.ini
2008-03-03 10:26 . 2008-03-03 10:26 <DIR> d-------- C:\Program Files\Paradox Interactive
2008-03-02 20:04 . 2008-03-02 20:04 <DIR> d-------- C:\Program Files\AVI MPEG RM WMV Joiner
2008-03-02 10:37 . 2008-03-02 10:37 1,158 --a------ C:\Windows\mozver.dat
2008-03-02 10:34 . 2008-03-02 10:34 <DIR> d-------- C:\Users\Omar\AppData\Roaming\Talkback
2008-03-01 17:38 . 2008-03-01 17:51 <DIR> d-------- C:\Users\Omar\AppData\Roaming\IcoFX
2008-03-01 17:38 . 2008-03-01 17:38 <DIR> d-------- C:\Program Files\IcoFX 1.5
2008-02-29 16:42 . 2008-02-29 16:49 <DIR> d-------- C:\Program Files\Label Wizard
2008-02-28 13:54 . 2007-10-12 15:14 3,734,536 --a------ C:\Windows\System32\d3dx9_36.dll
2008-02-28 13:54 . 2007-10-12 15:14 1,374,232 --a------ C:\Windows\System32\D3DCompiler_36.dll
2008-02-28 13:54 . 2007-10-02 09:56 444,776 --a------ C:\Windows\System32\d3dx10_36.dll
2008-02-28 13:54 . 2007-10-22 03:39 267,272 --a------ C:\Windows\System32\xactengine2_10.dll
2008-02-28 13:54 . 2007-07-20 00:57 267,112 --a------ C:\Windows\System32\xactengine2_9.dll
2008-02-28 13:54 . 2007-10-22 03:37 17,928 --a------ C:\Windows\System32\X3DAudio1_2.dll
2008-02-28 13:53 . 2008-02-28 13:54 <DIR> d--h----- C:\Windows\msdownld.tmp
2008-02-28 13:34 . 2008-02-28 13:34 <DIR> d-------- C:\Program Files\Common Files\Panda Software
2008-02-28 13:34 . 2008-02-28 13:29 178,872 --a------ C:\Windows\System32\drivers\PavProc.sys
2008-02-28 13:34 . 2008-02-28 13:29 38,968 --a------ C:\Windows\System32\drivers\ShlDrv51.sys
2008-02-28 13:29 . 2007-09-28 13:24 46,648 --a------ C:\Windows\System32\drivers\amm8660.sys
2008-02-28 13:22 . 2008-02-28 13:22 <DIR> d-------- C:\Users\All Users\sentinel
2008-02-28 13:22 . 2008-02-28 13:22 <DIR> d-------- C:\ProgramData\sentinel
2008-02-28 13:21 . 2008-02-28 15:57 <DIR> d-------- C:\Windows\System32\PAV
2008-02-28 13:21 . 2007-03-15 18:38 54,832 --a------ C:\Windows\System32\pavcpl.cpl
2008-02-28 13:21 . 2008-02-28 13:21 248 --a------ C:\Windows\System32\PavCPL.dat
2008-02-28 13:20 . 2007-02-15 20:02 50,736 --a------ C:\Windows\System32\avldr.dll
2008-02-28 13:18 . 2008-02-28 13:20 <DIR> d-------- C:\Program Files\Panda Security
2008-02-28 12:43 . 2008-02-28 12:43 <DIR> d-------- C:\Program Files\CapCom
2008-02-26 17:42 . 2008-02-26 17:49 <DIR> d-------- C:\Program Files\YouTube Downloader
2008-02-26 00:49 . 2008-02-26 00:49 <DIR> d-------- C:\Program Files\Sothink SWF Decompiler
2008-02-26 00:49 . 2008-02-26 00:49 <DIR> d-------- C:\Program Files\Common Files\SourceTec
2008-02-22 23:44 . 2008-02-22 23:44 <DIR> d-------- C:\Program Files\iTunes
2008-02-22 23:44 . 2008-02-22 23:44 <DIR> d-------- C:\Program Files\iPod
2008-02-22 23:44 . 2008-03-06 19:00 54,156 --ah----- C:\Windows\QTFont.qfn
2008-02-22 23:44 . 2008-02-22 23:44 1,409 --a------ C:\Windows\QTFont.for
2008-02-17 12:07 . 2008-02-17 12:07 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-02-17 12:07 . 2008-02-17 12:07 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-02-17 12:01 . 2008-02-17 12:01 3,504,696 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-02-17 12:01 . 2008-02-17 12:01 3,470,392 --a------ C:\Windows\System32\ntoskrnl.exe
2008-02-17 12:01 . 2008-02-17 12:01 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-02-17 12:01 . 2008-02-17 12:01 109,624 --a------ C:\Windows\System32\drivers\ataport.sys
2008-02-17 12:01 . 2008-02-17 12:01 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-02-17 12:01 . 2008-02-17 12:01 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-02-17 12:01 . 2008-02-17 12:01 17,464 --a------ C:\Windows\System32\drivers\intelide.sys
2008-02-17 12:01 . 2008-02-17 12:01 15,928 --a------ C:\Windows\System32\drivers\pciide.sys
2008-02-17 12:00 . 2008-02-17 12:00 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-17 12:00 . 2008-02-17 12:00 1,686,528 --a------ C:\Windows\System32\gameux.dll
2008-02-17 12:00 . 2008-02-17 12:00 803,328 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-02-17 12:00 . 2008-02-17 12:00 216,632 --a------ C:\Windows\System32\drivers\netio.sys
2008-02-17 12:00 . 2008-02-17 12:00 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-02-17 12:00 . 2008-02-17 12:00 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-02-17 12:00 . 2008-02-17 12:00 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-02-17 11:56 . 2008-02-17 11:56 1,244,672 --a------ C:\Windows\System32\mcmde.dll
2008-02-17 10:53 . 2007-06-21 01:53 32,768 --a------ C:\Windows\System32\mf (2).dll
2008-02-17 10:41 . 2008-02-17 10:41 <DIR> d-------- C:\Users\All Users\Martau
2008-02-17 10:41 . 2008-02-17 10:41 <DIR> d-------- C:\ProgramData\Martau
2008-02-17 10:39 . 2008-02-17 10:40 <DIR> d-------- C:\Program Files\Total Uninstall 4
2008-02-17 02:27 . 2008-02-17 02:27 <DIR> d-------- C:\Users\All Users\Activision
2008-02-17 02:27 . 2008-02-17 02:27 <DIR> d-------- C:\ProgramData\Activision
2008-02-17 01:47 . 2008-02-17 01:47 <DIR> d-------- C:\Program Files\Traction Software
2008-02-16 09:18 . 2008-02-16 09:18 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-14 17:39 . 2008-03-02 13:39 390 --a------ C:\Windows\ANS2000.INI
2008-02-14 17:39 . 2008-03-02 11:06 20 --ah----- C:\Windows\akebook.ini
2008-02-14 17:39 . 2008-03-02 11:06 4 --ah----- C:\Windows\a3kebook.ini
2008-02-14 13:19 . 2008-02-17 10:51 <DIR> d-------- C:\Users\All Users\Microsoft Games
2008-02-14 13:19 . 2008-02-17 10:51 <DIR> d-------- C:\ProgramData\Microsoft Games
2008-02-14 13:11 . 2008-02-14 13:11 <DIR> d-------- C:\Users\Omar\AppData\Roaming\Microsoft Game Studios
2008-02-11 15:49 . 2008-02-11 15:49 <DIR> d-------- C:\Users\Omar\AppData\Roaming\dvdcss
2008-02-09 22:51 . 2008-02-09 22:51 <DIR> d-------- C:\Program Files\FDRLab
2008-02-09 21:32 . 2008-03-08 14:14 <DIR> d-------- C:\Users\Omar\AppData\Roaming\DNA
2008-02-09 21:32 . 2008-03-08 14:14 <DIR> d-------- C:\Users\Omar\AppData\Roaming\BitTorrent
2008-02-09 21:32 . 2008-02-09 21:32 <DIR> d-------- C:\Program Files\DNA
2008-02-09 21:32 . 2008-02-29 12:05 <DIR> d-------- C:\Program Files\BitTorrent
2008-02-09 18:18 . 2008-02-09 18:18 <DIR> d-------- C:\Users\Omar\AppData\Roaming\JAM Software
2008-02-09 18:15 . 2008-02-09 18:15 <DIR> d-------- C:\Program Files\TreeSize Professional
2008-02-08 09:25 . 2008-02-08 09:30 911 --a------ C:\Windows\STA2.ini
2008-02-08 09:24 . 2008-02-08 09:24 <DIR> d-------- C:\Users\Omar\AppData\Roaming\DAEMON Tools
2008-02-08 09:24 . 2008-02-08 09:24 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-07 00:46 --------- d-----w C:\Users\Omar\AppData\Roaming\Corel
2008-03-06 23:45 --------- d-----w C:\ProgramData\Microsoft Help
2008-03-06 23:39 155,995 ----a-w C:\Windows\Java\Packages\CRJ73PV5.ZIP
2008-03-06 22:43 --------- d-----w C:\Program Files\Java
2008-03-05 19:02 --------- d-----w C:\Program Files\Soldier of Fortune II - Double Helix
2008-03-05 03:14 --------- d-----w C:\Users\Omar\AppData\Roaming\Winamp
2008-03-04 04:49 --------- d-----w C:\Program Files\Magic Video Converter
2008-03-03 23:29 --------- d-----w C:\Program Files\DAEMON Tools Pro
2008-03-03 18:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-03 18:11 --------- d-----w C:\Program Files\Activision
2008-03-03 17:34 --------- d-----w C:\Users\Omar\AppData\Roaming\InstallShield
2008-03-03 17:34 --------- d-----w C:\Program Files\THQ
2008-03-03 17:33 --------- d-----w C:\ProgramData\Media Center Programs
2008-03-03 05:10 3,350 --sha-w C:\Windows\System32\KGyGaAvL.sys
2008-03-03 03:15 --------- d-----w C:\Users\Omar\AppData\Roaming\Vso
2008-02-29 15:01 --------- d-----w C:\Program Files\Star Trek Away Team
2008-02-28 18:12 --------- d-----w C:\ProgramData\McAfee
2008-02-28 17:49 --------- d-----w C:\ProgramData\SiteAdvisor
2008-02-27 00:27 --------- d-----w C:\Program Files\Far Cry
2008-02-25 18:09 --------- d-----w C:\Program Files\Kasparov Chessmate
2008-02-17 17:00 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-17 17:00 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-17 17:00 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-17 17:00 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-17 15:51 --------- d-----w C:\Program Files\Microsoft Games
2008-02-17 07:27 --------- d-----w C:\Users\Omar\AppData\Roaming\Activision
2008-02-17 06:47 --------- d-----w C:\Users\Omar\AppData\Roaming\GetRightToGo
2008-02-16 18:25 --------- d-----w C:\Users\Omar\AppData\Roaming\UseNeXT
2008-02-16 15:33 --------- d-----w C:\Program Files\Xilisoft
2008-02-16 15:33 --------- d-----w C:\Program Files\MSECACHE
2008-02-16 15:28 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-16 14:19 --------- d-----w C:\ProgramData\RoboForm
2008-02-09 23:52 --------- d-----w C:\Users\Omar\AppData\Roaming\Bioshock
2008-01-31 20:15 --------- d-----w C:\ProgramData\Office Genuine Advantage
2008-01-31 05:04 --------- d-----w C:\Program Files\Winamp
2008-01-26 22:56 716,272 ----a-w C:\Windows\system32\drivers\sptd.sys
2008-01-25 05:15 --------- d-----w C:\Program Files\OO Software
2008-01-23 02:00 --------- d-----w C:\Program Files\CCleaner
2008-01-21 04:31 --------- d---a-w C:\ProgramData\TEMP
2008-01-21 02:15 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-01-21 02:08 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-17 11:29 --------- d-----w C:\Program Files\PowerISO
2008-01-17 01:27 --------- d-----w C:\Users\Omar\AppData\Roaming\MultimediaFeed.com
2008-01-17 01:27 --------- d-----w C:\Program Files\MultimediaFeed MP3 Tagger
2008-01-15 14:45 --------- d-----w C:\Program Files\Ubisoft
2008-01-14 19:19 --------- d-----w C:\Users\Omar\AppData\Roaming\Canon
2008-01-10 20:54 131,584 ----a-w C:\Windows\System32\SpoonUninstall.exe
2008-01-10 02:59 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-10 02:59 --------- d-----w C:\Program Files\Windows Mail
2008-01-10 02:54 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-10 02:54 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-01-10 02:53 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-06 20:00 107,832 ----a-w C:\Windows\System32\PnkBstrB.exe
2007-12-17 22:10 98,304 ----a-w C:\Windows\System32\CmdLineExt.dll
2007-12-15 05:15 165,477 ----a-w C:\Windows\Video Cleaner Pro Uninstaller.exe
2007-12-15 01:07 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-15 01:07 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-15 01:07 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-12-09 18:17 21,840 ----atw C:\Windows\System32\SIntfNT.dll
2007-12-09 18:17 17,212 ----atw C:\Windows\System32\SIntf32.dll
2007-12-09 18:17 12,067 ----atw C:\Windows\System32\SIntf16.dll
2007-12-09 02:27 5,020 ----a-w C:\Windows\inf\DataDirect Pervasive .NET Data Provider\
0009\tmp369B.tmp
2007-12-09 02:27 5,020 ----a-w C:\Windows\inf\DataDirect Pervasive .NET Data Provider\
0000\tmp369B.tmp
2007-11-16 17:28 22,328 ----a-w C:\Users\Omar\AppData\Roaming\PnkBstrK.sys
2007-09-13 17:42 17,394 ----a-w C:\Users\Omar\AppData\Roaming\wklnhst.dat
2007-08-29 03:19 174 --sha-w C:\Program Files\desktop.ini
2007-03-24 21:04 94,080 ----a-w C:\Users\Omar\AppData\Roaming\ezplay.sys
2007-03-24 21:04 87,608 ----a-w C:\Users\Omar\AppData\Roaming\ezpinst.exe
2007-03-24 21:04 47,360 ----a-w C:\Users\Omar\AppData\Roaming\pcouffin.sys
2007-04-17 03:19 88 --sh--r C:\Windows\System32\956A9C89ED.sys
2002-04-16 15:27 5 --sha-w C:\Windows\System32\CdI5T.drv
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4516D1E3-BC1A-4B2F-83EC-F4D0302CD5AC}"= "C:\PROGRA~1\CALORI~1\CALORI~1\CKTOOL~1.DLL" [2007-07-26 12:16 103808]
[HKEY_CLASSES_ROOT\clsid\{4516d1e3-bc1a-4b2f-83ec-f4d0302cd5ac}]
[HKEY_CLASSES_ROOT\CKToolbar.CKToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{5394A76B-F52F-4149-8E55-3291DC4563F2}]
[HKEY_CLASSES_ROOT\CKToolbar.CKToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{4516D1E3-BC1A-4B2F-83EC-F4D0302CD5AC}"= C:\PROGRA~1\CALORI~1\CALORI~1\CKTOOL~1.DLL [2007-07-26 12:16 103808]
[HKEY_CLASSES_ROOT\clsid\{4516d1e3-bc1a-4b2f-83ec-f4d0302cd5ac}]
[HKEY_CLASSES_ROOT\CKToolbar.CKToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{5394A76B-F52F-4149-8E55-3291DC4563F2}]
[HKEY_CLASSES_ROOT\CKToolbar.CKToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 21:53 1232896]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 07:35 125440]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 04:40 218032]
"wben"="C:\Program Files\Starfield\Desktop Notifier\wben.exe" [2007-11-06 14:12 312024]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-17 11:51 486856]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-02-09 21:32 290112]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-02-16 09:20 160592]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:36 201728]
"ProvideSupportOperatorConsole[default]"="C:\PROGRA~1\PROVID~1\PROVID~1.exe" [2007-01-29 18:37 3858432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-10-31 22:47 106496]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-10-31 22:44 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"QuickTime Task"="C:\Program Files\VistaCodecPack\QT\QTTask.exe" [2008-01-31 23:13 385024]
"OODefragTray"="C:\Windows\system32\oodtray.exe" [2007-05-11 02:08 2512392]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
"APVXDWIN"="C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.exe" [2007-10-04 15:14 455984]
"SigmatelSysTrayApp"="sttray.exe" [2006-11-02 12:38 303104 C:\Windows\sttray.exe]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Explorer.lnk - C:\Windows\explorer.exe [2007-11-15 10:00:50 2923520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 20:02 50736 C:\Windows\System32\avldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanzarL2007]
C:\Users\Omar\AppData\Local\Temp\{E3361C39-565C-4D19-8982-54ABFB0D56A5}\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2284226963-1265642083-3178862661-1002]
"EnableNotificationsRef"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2284226963-1265642083-3178862661-500]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\FlashFXP\FlashFXP.exe"= C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DAD7A092-D66B-47FC-83E4-D15B32343E56}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{62B8BB02-091B-46FE-9FC6-D0184A547043}"= UDP:11616:uTorrent
"{06D0ED3F-B6BF-4A72-B516-7E96BF6AB647}"= UDP:8535:BitComet 8535 TCP
"{50684BA0-75A1-4AA4-B446-661CAF3022B9}"= TCP:8535:BitComet 8535 UDP
"{D4D7CFE9-D698-44BD-9B19-76EF9755A8DE}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{F6EC1D8C-0C86-488A-977C-E4F6BF473003}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{A7989950-C5CA-4713-8D8B-32BC706842DF}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{72EE87BB-D79A-4149-B7F8-FE300DC88A79}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{8AB5D0A5-5A52-43D3-B29A-E7AF7786A30F}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7ED63EE5-A176-4AF4-A639-DEE3DA617163}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:Age of Empires III - The WarChiefs
"{FF8CD612-FFDF-437B-8F30-6DECAC4C470E}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:Age of Empires III - The WarChiefs
"{B3925807-9785-4B8C-AF31-15B211C342A6}"= UDP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
"{86119683-335F-4899-8C95-713B4790DFE2}"= TCP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
"{30666D0E-5A74-4E89-B3BC-DAB2566DD0AF}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{0E420FE9-19E8-4845-B7FA-4567C65FA918}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{24DA4F2A-7764-4535-B940-A46F7791A2C0}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{0D90B82F-2191-45C5-9397-6BA0C8D3455F}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{4D1FD499-A2F3-4BB2-B02B-383C10ED4E7F}"= UDP:C:\Program Files\Sierra Entertainment\Empire Earth III\EE3.exe:Empire Earth III
"{2A80DD3C-DD6A-4277-B581-51E35C755426}"= TCP:C:\Program Files\Sierra Entertainment\Empire Earth III\EE3.exe:Empire Earth III
"{3E4088EB-BC7F-413F-8E72-EDE3D525FCFE}"= UDP:C:\Program Files\Microsoft Games\Gears of War\Binaries\WarGame-G4WLive.exe:Gears of War
"{45379E43-6597-4249-BF48-595D03606646}"= TCP:C:\Program Files\Microsoft Games\Gears of War\Binaries\WarGame-G4WLive.exe:Gears of War
"{A9DB1FA5-2CF8-4BC8-843B-F827E0EF5F08}"= UDP:C:\Program Files\Eidos\Kane and Lynch Dead Men\kaneandlynch.exe:Kane & Lynch: Dead Men
"{4D70967D-9B68-4E54-B7C3-52F68A0CDB9B}"= TCP:C:\Program Files\Eidos\Kane and Lynch Dead Men\kaneandlynch.exe:Kane & Lynch: Dead Men
"{C477C5F0-E596-4723-A480-AFA1C6BB7EB0}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare
"{2F377628-078B-42BB-B090-052D075D2718}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare
"{8875435B-8A31-4179-90EB-4170F7F42A5A}"= UDP:C:\Program Files\Microsoft Games\Age of Empires II\empires2.exe:Age of Empires II
"{1291AD47-8A61-4BA7-9EF0-28047692935E}"= TCP:C:\Program Files\Microsoft Games\Age of Empires II\empires2.exe:Age of Empires II
"{CA70CD8C-2EEB-4332-BF24-9DD9BEEFF5F1}"= UDP:C:\Program Files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{CC6E18AD-3728-4E3B-8996-A9EA8CF24EB7}"= TCP:C:\Program Files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{F8A16569-7FA5-4EF2-80D8-A05D27DAFE9F}"= UDP:6667:GameSpy IRC
"{63F7D53A-7A18-4D26-8A2B-61F6D1A1ED45}"= UDP:3783:GameSpy (Voice Chat)
"{D567797E-9463-4EEE-99CB-6B36C97DD91C}"= UDP:27900:GameSpy (Master Server UDP HeartBeat)
"{406D4356-70D6-47CD-ACC3-9D5CD2076F0E}"= UDP:28900:28900 (Master Server List Request)
"{A409A4A1-D0EE-4D2E-A81E-2CFA302245FD}"= UDP:29900:GameSpy (GP Connection Manager)
"{3A2699AD-8C90-4755-B543-AF4CE0C6A334}"= UDP:29901:GameSpy (GP Search Manager)
"{DFB9E147-B90B-4ECE-8265-69CE2195BD59}"= UDP:13139:GameSpy (Custom UDP Pings)
"{839D0CA6-F34E-4E18-9190-623E63581029}"= UDP:6515:GameSpy (Dplay UDP)
"{EE3C8CC7-6032-4320-A884-761C5AE57EED}"= UDP:6500:GameSpy (Query Port)
"{B26F43A3-4595-4DCB-B489-08703CDA9A8B}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3y.exe:Age of Empires III - The Asian Dynasties
"{0E1349BB-21EF-4502-A7B9-CC421400E7EB}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3y.exe:Age of Empires III - The Asian Dynasties
"{868A7700-663A-4A9B-A545-B8852320119C}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{52F1F4E7-42B9-43A9-A79D-B8D04A1C80CE}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{ECEA6BE6-C433-4244-AD32-C9541E946459}"= UDP:C:\Program Files\MultimediaFeed MP3 Tagger\MultimediaFeed MP3 Tagger.exe:MultimediaFeed MP3 Tagger
"{865C003A-1D0E-4CC8-8A5D-B33BBEF15A28}"= TCP:C:\Program Files\MultimediaFeed MP3 Tagger\MultimediaFeed MP3 Tagger.exe:MultimediaFeed MP3 Tagger
"{1BC727C3-B2F2-4C57-B049-D7BD29426A58}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{0B580717-F910-4D83-8560-F5E7C29BD0A9}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{C617B230-F8D0-49E4-987F-5CEB1ED460DA}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{70B81EC9-BB8C-461C-B116-E6AF235B0952}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{7289BBCF-1FE7-4072-ADAE-9E2AC5339C7E}"= UDP:C:\Program Files\Microsoft Games\Halo 2\halo2.exe:Halo 2
"{340949F9-6667-4DCE-9E28-EF86A9879AEF}"= TCP:C:\Program Files\Microsoft Games\Halo 2\halo2.exe:Halo 2
"{CE4C43FE-847B-4881-81C4-E1BF817DE663}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{B23FA1C0-377C-4F80-86E6-99172C2BCFED}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\FlashFXP\FlashFXP.exe"= C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3
"C:\WINDOWS\winlogon.exe"= C:\WINDOWS\winlogon.exe
"C:\Program Files\BitTorrent\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 ShldDrv;Panda File Shield Driver;C:\Windows\system32\DRIVERS\ShlDrv51.sys [2008-02-28 13:29]
R2 AmFSM;AmFSM;C:\Windows\system32\DRIVERS\amm8660.sys [2007-09-28 13:24]
R2 atchksrv;Intel® AMT System Status Service;C:\Program Files\Intel\AMT\atchksrv.exe [2006-10-30 19:53]
R2 LMS;Intel® Active Management Technology LMS Service;C:\Program Files\Intel\AMT\LMS.exe [2006-10-30 19:53]
R2 PavProc;Panda Process Protection Driver;C:\Windows\system32\DRIVERS\PavProc.sys [2008-02-28 13:29]
R2 PskSvcRetail;Panda PSK service;"C:\Program Files\Panda Security\Panda Antivirus 2008\PskSvc.exe" [2007-03-21 19:32]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-08-21 21:08]
R3 TPM;TPM;C:\Windows\system32\drivers\tpm.sys [2006-11-02 04:50]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2007-08-31 16:46]
S2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-08-21 21:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{057c59fc-d38d-11dc-86a5-0019d1121e78}]
\shell\AutoRun\command - F:\penumbra_bp_ger.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{386c0fa8-5ad8-11dc-a6e1-0019d1121e78}]
\shell\AutoRun\command - H:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a93e927-9388-11dc-9c31-0019d1121e78}]
\shell\AutoRun\command - F:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5e989fac-930e-11dc-84a7-0019d1121e78}]
\shell\AutoRun\command - E:\AutoRunCD.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6b4a3a94-18fb-11dc-8d8b-0019d1121e78}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ea3d23c4-d01f-11db-bf80-0019d1121e78}]
\shell\AutoRun\command - F:\doNada.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {F8487D71-8722-24E3-AC1E-8BA8B34E8832} /qb
.
Contents of the 'Scheduled Tasks' folder
"2008-02-28 18:10:02 C:\Windows\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-10-30 18:47:23 C:\Windows\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-10-30 18:46:37 C:\Windows\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-08 14:19:35
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-08 14:20:20
ComboFix-quarantined-files.txt 2008-03-08 19:20:18
.
2008-03-02 19:34:30 --- E O F ---