ComboFix 08-03-22.1 - Kunal Goel 2008-03-24 14:13:57.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1445 [GMT 5.5:30]
Running from: C:\Documents and Settings\Kunal Goel\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kunal Goel\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\Fonts\RandFont.dll
C:\WINDOWS\popcinfo.dat
C:\WINDOWS\system32\hncxbxgo.ini
C:\WINDOWS\system32\iesearch.dll
C:\WINDOWS\system32\jmiqhpig.ini
C:\WINDOWS\system32\mgrShell.exe
C:\WINDOWS\system32\mlbfbwmc.ini
C:\WINDOWS\system32\pmkjj.dll
C:\WINDOWS\system32\spoolsv32.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\TEMP\
C:\WINDOWS\Fonts\RandFont.dll
C:\WINDOWS\popcinfo.dat
C:\WINDOWS\system32\hncxbxgo.ini
C:\WINDOWS\system32\jmiqhpig.ini
C:\WINDOWS\system32\mlbfbwmc.ini
.
((((((((((((((((((((((((( Files Created from 2008-02-24 to 2008-03-24 )))))))))))))))))))))))))))))))
.
2008-03-23 13:50 . 2008-03-24 14:18 3,483,680 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-23 13:50 . 2008-03-24 00:36 8,252 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-23 12:43 . 2008-03-23 12:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-03-23 12:43 . 2007-11-14 16:05 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-03-23 12:43 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-03-23 12:42 . 2007-11-14 16:05 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2008-03-23 03:06 . 2008-03-23 12:45 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-03-23 03:05 . 2008-03-23 13:50 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-03-23 03:05 . 2008-03-24 02:45 353,365 --ah----- C:\WINDOWS\system32\vsconfig.xml
2008-03-23 02:48 . 2008-03-24 08:00 <DIR> d-------- C:\Documents and Settings\Kunal Goel\Application Data\AVG7
2008-03-23 02:47 . 2008-03-23 02:47 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-23 02:47 . 2008-03-23 02:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-23 02:47 . 2008-03-23 03:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-03-23 02:29 . 2008-03-23 02:29 <DIR> d-------- C:\Program Files\Zone Labs
2008-03-23 02:23 . 2008-03-24 14:02 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-03-23 02:06 . 2008-03-23 02:06 <DIR> d-------- C:\Documents and Settings\Administrator\Bluetooth Software
2008-03-18 21:08 . 2008-03-18 21:12 2 --a------ C:\1075353495
2008-03-13 06:37 . 2008-03-18 20:57 <DIR> d-------- C:\Program Files\Sega
2008-03-12 12:51 . 2008-03-12 12:51 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-03-12 06:09 . 2008-03-12 06:09 <DIR> d-------- C:\Documents and Settings\Kunal Goel\Application Data\DAEMON Tools
2008-03-09 03:43 . 2008-03-09 03:44 <DIR> d-------- C:\Program Files\Zuma Deluxe
2008-03-08 00:54 . 2008-03-09 17:35 <DIR> d-------- C:\Program Files\Opera
2008-03-07 10:46 . 2008-03-07 10:47 <DIR> d-------- C:\Program Files\Windows Live
2008-03-07 10:46 . 2008-03-07 10:47 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-07 10:46 . 2008-03-07 10:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-03 01:43 . 2008-03-24 02:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-03 01:43 . 2008-03-03 01:43 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-24 08:43 --------- d-----w C:\Documents and Settings\Kunal Goel\Application Data\uTorrent
2008-03-24 00:47 --------- d-----w C:\Documents and Settings\Kunal Goel\Application Data\LimeWire
2008-03-23 13:48 --------- d-----w C:\Program Files\SpywareBlaster
2008-03-23 07:09 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-23 07:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-13 01:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-12 21:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-12 00:39 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-03-08 01:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\WildTangent
2008-03-02 20:40 --------- d-----w C:\Program Files\iTunes
2008-03-02 20:40 --------- d-----w C:\Program Files\iPod
2008-03-02 20:38 --------- d-----w C:\Program Files\QuickTime
2008-02-23 18:54 --------- d-----w C:\Documents and Settings\Kunal Goel\Application Data\Xfire
2008-02-23 18:51 --------- d-----w C:\Documents and Settings\Kunal Goel\Application Data\Hamachi
2008-02-23 18:48 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-02-22 17:26 --------- d-----w C:\Program Files\Xfire
2008-02-18 19:55 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-18 19:39 --------- d-----w C:\Documents and Settings\Kunal Goel\Application Data\AdobeUM
2008-02-02 20:09 --------- d-----w C:\Documents and Settings\Kunal Goel\Application Data\dvdcss
2008-01-31 02:02 54,608 ----a-w C:\WINDOWS\system32\xfcodec.dll
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-14 13:43 0 ----a-w C:\Documents and Settings\Kunal Goel\Application Data\wklnhst.dat
2006-05-28 23:40 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((( snapshot@2008-03-23_10.39.20.70 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-07-19 09:40:28 127,768 ----a-w C:\WINDOWS\system32\drivers\klif.sys
+ 2007-11-14 10:34:46 796,048 ----a-w C:\WINDOWS\system32\libeay32_0.9.6l.dll
- 2005-08-29 13:38:34 83,712 ----a-w C:\WINDOWS\system32\vsdata.dll
+ 2007-11-14 10:34:52 83,432 ----a-w C:\WINDOWS\system32\vsdata.dll
- 2005-08-29 13:38:38 368,256 ----a-w C:\WINDOWS\system32\vsdatant.sys
+ 2007-11-14 10:35:16 394,952 ----a-w C:\WINDOWS\system32\vsdatant.sys
- 2005-08-29 13:38:46 141,056 ----a-w C:\WINDOWS\system32\vsinit.dll
+ 2007-11-14 10:34:52 157,160 ----a-w C:\WINDOWS\system32\vsinit.dll
- 2005-08-29 13:38:54 104,192 ----a-w C:\WINDOWS\system32\vsmonapi.dll
+ 2007-11-14 10:34:52 103,912 ----a-w C:\WINDOWS\system32\vsmonapi.dll
- 2005-08-29 13:38:58 227,072 ----a-w C:\WINDOWS\system32\vspubapi.dll
+ 2007-11-14 10:34:52 275,944 ----a-w C:\WINDOWS\system32\vspubapi.dll
- 2005-08-29 13:39:02 71,424 ----a-w C:\WINDOWS\system32\vsregexp.dll
+ 2007-11-14 10:34:52 71,144 ----a-w C:\WINDOWS\system32\vsregexp.dll
- 2005-08-29 13:39:14 382,720 ----a-w C:\WINDOWS\system32\vsutil.dll
+ 2007-11-14 10:34:54 472,552 ----a-w C:\WINDOWS\system32\vsutil.dll
+ 2007-11-14 10:34:54 46,568 ----a-w C:\WINDOWS\system32\vswmi.dll
- 2005-08-29 13:39:22 100,096 ----a-w C:\WINDOWS\system32\vsxml.dll
+ 2007-11-14 10:34:54 99,816 ----a-w C:\WINDOWS\system32\vsxml.dll
- 2005-08-29 13:39:42 79,616 ----a-w C:\WINDOWS\system32\zlcomm.dll
+ 2007-11-14 10:34:56 83,432 ----a-w C:\WINDOWS\system32\zlcomm.dll
- 2005-08-29 13:39:46 71,424 ----a-w C:\WINDOWS\system32\zlcommdb.dll
+ 2007-11-14 10:34:56 71,144 ----a-w C:\WINDOWS\system32\zlcommdb.dll
+ 2007-11-14 10:34:44 370,208 ----a-w C:\WINDOWS\system32\ZoneLabs\av.dll
+ 2007-05-30 18:33:30 65,248 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\aphish.dat
+ 2006-06-30 09:17:36 21,568 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\avcmhk4.dll
+ 2007-05-30 18:33:16 77,824 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHComm.dll
+ 2007-05-30 18:33:16 110,592 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHrule.dll
+ 2007-05-30 18:33:16 331,776 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHUM.dll
+ 2007-05-30 18:33:16 38,400 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\FSSync.dll
+ 2007-07-19 09:40:32 110,360 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\w2kxp32\kl1.sys
+ 2007-07-19 09:40:32 186,128 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\w2kxp32\klif.sys
+ 2007-05-30 18:33:48 110,360 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\x32\kl1.sys
+ 2007-07-19 09:40:28 127,768 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\x32\klif.sys
+ 2007-05-30 18:33:50 45,056 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\x32\regcat.exe
+ 2006-09-19 17:42:14 208,960 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\inv.dll
+ 2007-09-11 15:39:16 274,432 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\kave.dll
+ 2006-12-19 12:43:52 1,093,632 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\libeay32.dll
+ 2007-05-30 18:33:20 548,864 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcp80.dll
+ 2007-05-30 18:33:20 626,688 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcr80.dll
+ 2007-05-30 18:33:18 184,320 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prloader.dll
+ 2007-05-30 18:33:22 90,112 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prremote.dll
+ 2007-09-11 15:39:16 135,168 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
+ 2006-12-19 12:43:52 200,704 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ssleay32.dll
- 2005-08-29 13:18:28 87,808 ----a-w C:\WINDOWS\system32\ZoneLabs\camupd.dll
+ 2007-11-14 10:34:44 99,816 ----a-w C:\WINDOWS\system32\ZoneLabs\camupd.dll
+ 2007-11-14 10:34:46 128,480 ----a-w C:\WINDOWS\system32\ZoneLabs\fbl.dll
+ 2007-11-14 10:34:46 38,376 ----a-w C:\WINDOWS\system32\ZoneLabs\featuremap.dll
+ 2007-11-14 10:34:46 321,016 ----a-w C:\WINDOWS\system32\ZoneLabs\imsecure.dll
+ 2007-11-14 10:35:18 288,144 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\ConfigWizard.zip.dll
+ 2007-11-14 10:35:18 152,976 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\licenseui.zip.dll
+ 2007-11-14 10:35:18 26,000 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zlsvc.zip.dll
+ 2007-11-14 10:35:18 1,361,296 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zpy.zip.dll
+ 2007-11-14 10:35:20 71,056 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zui.zip.dll
+ 2007-11-14 10:36:34 30,184 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\rpc_server\rpc_server.dll
+ 2007-11-14 10:36:36 30,216 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\vsmon_plugin\vsmon_plugin.dll
- 2005-07-04 17:59:58 689,928 ----a-w C:\WINDOWS\system32\ZoneLabs\qrbase.dll
+ 2007-10-18 14:48:38 714,208 ----a-w C:\WINDOWS\system32\ZoneLabs\qrbase.dll
- 2005-07-04 17:59:58 648,968 ----a-w C:\WINDOWS\system32\ZoneLabs\qrsrecl.dll
+ 2007-10-18 14:48:38 787,936 ----a-w C:\WINDOWS\system32\ZoneLabs\qrsrecl.dll
- 2005-08-29 13:37:52 149,248 ----a-w C:\WINDOWS\system32\ZoneLabs\scheduler.dll
+ 2007-11-14 10:34:48 173,544 ----a-w C:\WINDOWS\system32\ZoneLabs\scheduler.dll
- 2005-08-14 22:59:46 566,294 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
+ 2007-01-11 05:42:08 2,432,259 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
- 2005-07-04 17:59:58 1,382,152 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.dll
+ 2007-10-18 14:48:40 1,500,640 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.dll
+ 2007-10-18 14:48:44 51,176 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.sys
- 2005-08-29 13:38:04 452,352 ----a-w C:\WINDOWS\system32\ZoneLabs\ssleay32.dll
+ 2007-11-14 10:34:50 456,168 ----a-w C:\WINDOWS\system32\ZoneLabs\ssleay32.dll
+ 2007-11-14 10:36:36 214,528 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
+ 2007-11-14 10:36:36 3,266,040 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\imslsp\imslsp.dll
+ 2006-09-04 15:29:14 503,875 ----a-w C:\WINDOWS\system32\ZoneLabs\upd_core.dll
+ 2007-10-11 11:20:32 832,984 ----a-w C:\WINDOWS\system32\ZoneLabs\updating.dll
+ 2007-11-14 10:35:06 144,936 ----a-w C:\WINDOWS\system32\ZoneLabs\updclient.exe
+ 2007-01-11 12:01:06 286,787 ----a-w C:\WINDOWS\system32\ZoneLabs\updtrsdk.dll
- 2005-08-29 13:38:30 104,192 ----a-w C:\WINDOWS\system32\ZoneLabs\vsavpro.dll
+ 2007-11-14 10:34:52 108,008 ----a-w C:\WINDOWS\system32\ZoneLabs\vsavpro.dll
- 2005-08-29 13:38:42 79,616 ----a-w C:\WINDOWS\system32\ZoneLabs\vsdb.dll
+ 2007-11-14 10:34:52 83,432 ----a-w C:\WINDOWS\system32\ZoneLabs\vsdb.dll
- 2005-08-29 13:38:50 1,677,056 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmon.exe
+ 2007-11-14 10:35:06 75,304 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmon.exe
+ 2007-11-14 10:34:52 2,029,032 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmondll.dll
- 2005-08-29 13:39:06 1,124,096 ----a-w C:\WINDOWS\system32\ZoneLabs\vsruledb.dll
+ 2007-11-14 10:34:54 1,361,384 ----a-w C:\WINDOWS\system32\ZoneLabs\vsruledb.dll
- 2005-08-29 13:39:18 239,360 ----a-w C:\WINDOWS\system32\ZoneLabs\vsvault.dll
+ 2007-11-14 10:34:54 239,080 ----a-w C:\WINDOWS\system32\ZoneLabs\vsvault.dll
+ 2007-01-11 05:42:08 2,432,259 ----a-w C:\WINDOWS\system32\ZoneLabs\zlasdbup.dat
- 2005-08-29 13:39:58 177,920 ----a-w C:\WINDOWS\system32\ZoneLabs\zlparser.dll
+ 2007-11-14 10:34:56 177,640 ----a-w C:\WINDOWS\system32\ZoneLabs\zlparser.dll
- 2005-08-29 13:40:02 71,432 ----a-w C:\WINDOWS\system32\ZoneLabs\zlquarantine.dll
+ 2007-11-14 10:34:56 79,344 ----a-w C:\WINDOWS\system32\ZoneLabs\zlquarantine.dll
- 2005-08-29 13:40:14 259,840 ----a-w C:\WINDOWS\system32\ZoneLabs\zlsre.dll
+ 2007-11-14 10:34:58 382,440 ----a-w C:\WINDOWS\system32\ZoneLabs\zlsre.dll
+ 2007-11-14 10:34:58 120,296 ----a-w C:\WINDOWS\system32\ZoneLabs\zlupdate.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 20:30 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-06 19:52 68856]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe" [2006-11-10 04:16 190072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-06 10:26 64512]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-20 02:20 729178]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-08 00:26 409600]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-08-02 03:56 233534]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 23:53 1187840]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 16:45 507904]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-11 10:35 344064]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-23 02:47 579072]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 21:54 1694208]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-08-18 02:18 439872]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-23 02:47 219136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-10 20:30 53760 C:\WINDOWS\system32\narrator.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"PolicyRun"= C:\WINDOWS\system32\spoolsv32.exe
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Kunal Goel^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Documents and Settings\Kunal Goel\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Kunal Goel^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Documents and Settings\Kunal Goel\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-02-14 04:39 486856 C:\Program Files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-02-19 13:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nxpclient]
--a------ 2007-01-11 12:19 192512 C:\Program Files\Airtel\NetXpert Agent\bin\sprtcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2007-08-18 02:18 439872 C:\Program Files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
--a------ 2005-12-13 01:09 94208 C:\Program Files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-31 23:13 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-11-11 02:33 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-07-06 19:52 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 14:36]
S3 iComp;HP Analog TV Tuner;C:\WINDOWS\system32\DRIVERS\p2usbwdm.sys [2006-01-17 13:07]
S3 SE31bus;Sony Ericsson Device 049 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE31bus.sys [2006-05-01 17:26]
S3 SE31mdfl;Sony Ericsson Device 049 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE31mdfl.sys [2006-05-01 17:27]
S3 SE31mdm;Sony Ericsson Device 049 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE31mdm.sys [2006-05-01 17:27]
S3 SE31mgmt;Sony Ericsson Device 049 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE31mgmt.sys [2006-05-01 17:28]
S3 se31nd5;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (NDIS);C:\WINDOWS\system32\DRIVERS\se31nd5.sys [2006-05-01 17:26]
S3 SE31obex;Sony Ericsson Device 049 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE31obex.sys [2006-05-01 17:29]
S3 se31unic;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (WDM);C:\WINDOWS\system32\DRIVERS\se31unic.sys [2006-05-01 17:26]
S3 USB_RNDIS_51;USB Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-10 20:30]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-24 14:18:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe???????????????|?P???? ???B?????????????hLC? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-24 14:19:19
ComboFix-quarantined-files.txt 2008-03-24 08:49:15
ComboFix2.txt 2008-03-23 05:09:36
.
2008-03-12 21:34:25 --- E O F ---