ComboFix.txt:
ComboFix 08-04-18.3 - Boss 2008-04-19 8:31:04.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1946 [GMT -7:00]
Running from: C:\Users\Boss\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Windows\cookies.ini
C:\Windows\system\update.exe
C:\Windows\System32\BIPVCccf.ini
C:\Windows\System32\BIPVCccf.ini2
C:\Windows\System32\CJRsBJjl.ini
C:\Windows\System32\CJRsBJjl.ini2
C:\Windows\system32\ckxegiiw.dll
C:\Windows\system32\cmfgfwky.dll
C:\Windows\System32\dddpxbpg.ini
C:\Windows\system32\eisbdinj.dll
C:\Windows\System32\eywvkxeo.ini
C:\Windows\system32\fccCVPIB.dll
C:\Windows\system32\gpbxpddd.dll
C:\Windows\system32\igytqimu.dll
C:\Windows\system32\irxbvaay.dll
C:\Windows\system32\ixpripeb.dll
C:\Windows\System32\llmWxbeg.ini
C:\Windows\System32\llmWxbeg.ini2
C:\Windows\system32\lokusius.dll
C:\Windows\system32\mcrh.tmp
C:\Windows\system32\mgnwfwtk.dll
C:\Windows\system32\mhiqmjcn.dll
C:\Windows\System32\mlltbqfk.ini
C:\Windows\system32\nrtpvvdi.dll
C:\Windows\system32\opgwrqpg.dll
C:\Windows\system32\palhjgjb.dll
C:\Windows\system32\qhoflpuw.dll
C:\Windows\System32\qiymfbkv.ini
C:\Windows\System32\rdeglkwt.ini
C:\Windows\system32\rkmmdbrm.dll
C:\Windows\system32\sasxcmab.dll
C:\Windows\system32\vkbfmyiq.dll
C:\Windows\System32\vquxspwh.ini
C:\Windows\system32\vtUopNDv.dll
C:\Windows\System32\wvnkskmi.ini
C:\Windows\system32\x64
C:\Windows\System32\ykwfgfmc.ini
----- BITS: Possible infected sites -----
hxxp://theinstalls.com
.
((((((((((((((((((((((((( Files Created from 2008-03-19 to 2008-04-19 )))))))))))))))))))))))))))))))
.
2008-04-17 00:14 . 2008-04-17 01:16 <DIR> d-------- C:\Users\All Users\Kaspersky Lab
2008-04-17 00:14 . 2008-04-17 01:16 <DIR> d-------- C:\ProgramData\Kaspersky Lab
2008-04-16 23:45 . 2008-04-16 23:45 <DIR> d-------- C:\Users\All Users\Kaspersky Lab Setup Files
2008-04-16 23:45 . 2008-04-16 23:45 <DIR> d-------- C:\ProgramData\Kaspersky Lab Setup Files
2008-04-16 23:33 . 2008-04-16 23:22 0 --a------ C:\Windows\System32\MSWINSCK - Copy.OCX
2008-04-16 23:23 . 2008-04-16 23:23 <DIR> d-------- C:\Users\Boss\AppData\Roaming\Bitdefender
2008-04-16 23:22 . 2008-04-17 00:49 <DIR> d-a------ C:\Users\All Users\TEMP
2008-04-16 23:22 . 2008-04-16 23:23 <DIR> d-------- C:\Users\All Users\BitDefender
2008-04-16 23:22 . 2008-04-17 00:49 <DIR> d-a------ C:\ProgramData\TEMP
2008-04-16 23:22 . 2008-04-16 23:23 <DIR> d-------- C:\ProgramData\BitDefender
2008-04-16 23:22 . 2008-04-16 23:33 109,248 --a------ C:\Windows\System32\MSWINSCK.OCX
2008-04-16 22:50 . 2008-04-16 22:50 <DIR> d-------- C:\Program Files\CCleaner
2008-04-16 17:34 . 2008-04-16 17:34 <DIR> d-------- C:\Windows\Content.IE5
2008-04-16 17:33 . 2008-04-16 22:11 691 --a------ C:\Users\Boss\AppData\Roaming\GetValue.vbs
2008-04-16 17:33 . 2008-04-16 22:11 35 --a------ C:\Users\Boss\AppData\Roaming\SetValue.bat
2008-04-16 17:32 . 2007-10-04 00:36 25,600 --a------ C:\Windows\System32\WS2Fix.exe
2008-04-16 17:32 . 2008-04-16 22:11 1,534 --a------ C:\Windows\System32\tmp.reg
2008-04-16 16:56 . 2007-09-06 00:22 289,144 --a------ C:\Windows\System32\VCCLSID.exe
2008-04-16 16:56 . 2006-04-27 17:49 288,417 --a------ C:\Windows\System32\SrchSTS.exe
2008-04-16 16:56 . 2008-04-14 19:28 86,528 --a------ C:\Windows\System32\VACFix.exe
2008-04-16 16:56 . 2008-04-12 13:49 82,432 --a------ C:\Windows\System32\IEDFix.exe
2008-04-16 16:56 . 2003-06-05 21:13 53,248 --a------ C:\Windows\System32\Process.exe
2008-04-16 16:56 . 2004-07-31 18:50 51,200 --a------ C:\Windows\System32\dumphive.exe
2008-04-15 19:16 . 2008-04-16 15:20 1,603,057 ---hs---- C:\Windows\System32\ftkucokj.ini
2008-04-14 15:03 . 2008-04-17 01:16 239,561,283 --a------ C:\Windows\MEMORY.DMP
2008-04-14 15:03 . 2008-04-14 15:03 524,288 --ahs---- C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{993e3e9b-0a6e-11dd-b04c-0019212f80c2}.TMContainer00000000000000000002.regtrans-ms
2008-04-14 15:03 . 2008-04-14 15:03 524,288 --ahs---- C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{993e3e9b-0a6e-11dd-b04c-0019212f80c2}.TMContainer00000000000000000001.regtrans-ms
2008-04-14 15:03 . 2008-04-14 15:03 524,288 --ahs---- C:\Windows\ServiceProfiles\LocalService\ntuser.dat{993e3e9f-0a6e-11dd-b04c-0019212f80c2}.TMContainer00000000000000000002.regtrans-ms
2008-04-14 15:03 . 2008-04-14 15:03 524,288 --ahs---- C:\Windows\ServiceProfiles\LocalService\ntuser.dat{993e3e9f-0a6e-11dd-b04c-0019212f80c2}.TMContainer00000000000000000001.regtrans-ms
2008-04-14 15:03 . 2008-04-14 15:03 65,536 --ahs---- C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{993e3e9b-0a6e-11dd-b04c-0019212f80c2}.TM.blf
2008-04-14 15:03 . 2008-04-14 15:03 65,536 --ahs---- C:\Windows\ServiceProfiles\LocalService\ntuser.dat{993e3e9f-0a6e-11dd-b04c-0019212f80c2}.TM.blf
2008-04-14 14:57 . 2008-04-14 14:58 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-04-14 14:57 . 2008-04-14 14:58 <DIR> d-------- C:\ProgramData\Lavasoft
2008-04-14 14:57 . 2008-04-14 14:57 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-14 14:39 . 2008-04-16 17:03 538 --a------ C:\Windows\wininit.ini
2008-04-14 14:24 . 2008-04-16 16:24 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-04-14 14:24 . 2008-04-16 16:24 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-04-14 14:24 . 2008-04-14 14:24 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-14 06:50 . 2008-04-14 06:50 24,576 --a------ C:\Windows\System32\VundoFixSVC.exe
2008-04-14 06:24 . 2008-04-14 06:50 <DIR> d-------- C:\VundoFix Backups
2008-04-14 02:07 . 2008-04-16 23:09 <DIR> d-------- C:\backups
2008-04-14 02:03 . 2008-04-14 02:04 101,865 --a------ C:\Users\Boss\startuplist.zip
2008-04-14 01:57 . 2005-01-20 13:47 175,616 --a------ C:\Windows\System32\strings.exe
2008-04-14 01:57 . 2006-03-02 23:42 73,728 --a------ C:\Windows\System32\pv.exe
2008-04-14 01:57 . 2005-01-13 21:41 39,184 --a------ C:\Windows\System32\Ntrights.exe
2008-04-14 01:57 . 2005-10-19 18:50 16,384 --a------ C:\Windows\System32\restart.exe
2008-04-14 01:57 . 2005-01-13 21:41 11,254 --a------ C:\Windows\System32\locate.com
2008-04-14 01:56 . 2008-04-14 01:56 <DIR> d-------- C:\l2m
2008-04-13 23:24 . 2008-04-13 23:24 <DIR> d-------- C:\Users\Other.Boss-PC\AppData\Roaming\vlc
2008-04-13 23:04 . 2008-04-13 23:22 2,123,263 ---hs---- C:\Windows\System32\hjqqrnop.ini
2008-04-13 22:36 . 2008-04-13 22:36 <DIR> d-------- C:\Users\Other.Boss-PC\AppData\Roaming\Logitech
2008-04-13 22:22 . 2008-04-13 22:22 <DIR> dr------- C:\Users\Other.Boss-PC\Videos
2008-04-13 22:22 . 2008-04-13 22:22 <DIR> dr------- C:\Users\Other.Boss-PC\Searches
2008-04-13 22:22 . 2008-04-13 22:22 <DIR> dr------- C:\Users\Other.Boss-PC\Saved Games
2008-04-13 22:22 . 2008-04-13 22:22 <DIR> dr------- C:\Users\Other.Boss-PC\Pictures
2008-04-13 22:22 . 2008-04-13 22:22 <DIR> dr------- C:\Users\Other.Boss-PC\Music
2008-04-13 22:22 . 2008-04-13 22:22 <DIR> dr------- C:\Users\Other.Boss-PC\Links
2008-04-13 22:22 . 2008-04-13 22:22 <DIR> dr------- C:\Users\Other.Boss-PC\Downloads
2008-04-13 22:22 . 2008-04-13 22:22 <DIR> dr------- C:\Users\Other.Boss-PC\Documents
2008-04-13 22:22 . 2008-04-13 22:22 <DIR> dr------- C:\Users\Other.Boss-PC\Contacts
2008-04-13 22:22 . 2008-04-13 22:22 <DIR> d-------- C:\Users\Other.Boss-PC\AppData\Roaming\Webroot
2008-04-13 22:22 . 2006-11-02 05:37 <DIR> d-------- C:\Users\Other.Boss-PC\AppData\Roaming\Media Center Programs
2008-04-13 22:22 . 2007-10-28 14:33 <DIR> d--h----- C:\Users\Other.Boss-PC\AppData\Roaming\GTek
2008-04-13 22:22 . 2008-04-13 22:22 <DIR> d--h----- C:\Users\Other.Boss-PC\AppData
2008-04-13 22:22 . 2008-04-13 22:22 <DIR> d-------- C:\Users\Other.Boss-PC
2008-04-13 22:22 . 2008-04-13 22:50 524,288 --ahs---- C:\Users\Other.Boss-PC\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
2008-04-13 22:22 . 2008-04-13 22:50 524,288 --ahs---- C:\Users\Other.Boss-PC\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
2008-04-13 22:22 . 2008-04-19 08:31 262,144 --ah----- C:\Users\Other.Boss-PC\ntuser.dat.LOG1
2008-04-13 22:22 . 2008-04-13 22:50 65,536 --ahs---- C:\Users\Other.Boss-PC\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
2008-04-13 22:22 . 2008-04-13 22:22 0 --ah----- C:\Users\Other.Boss-PC\ntuser.dat.LOG2
2008-04-13 21:20 . 2008-01-04 20:34 163,696 --a------ C:\Windows\System32\drivers\ssidrv.sys
2008-04-13 21:20 . 2008-01-04 20:34 23,920 --a------ C:\Windows\System32\drivers\sskbfd.sys
2008-04-13 21:20 . 2008-01-04 20:34 21,872 --a------ C:\Windows\System32\drivers\sshrmd.sys
2008-04-13 21:20 . 2008-01-04 20:34 20,336 --a------ C:\Windows\System32\drivers\SSFS0BB9.sys
2008-04-13 21:19 . 2008-04-13 21:19 <DIR> d-------- C:\Users\Boss\AppData\Roaming\Webroot
2008-04-13 21:19 . 2008-04-13 21:19 <DIR> d-------- C:\Users\All Users\Webroot
2008-04-13 21:19 . 2008-04-13 21:19 <DIR> d-------- C:\ProgramData\Webroot
2008-04-13 21:19 . 2008-04-13 21:19 <DIR> d-------- C:\Program Files\Webroot
2008-04-13 21:19 . 2008-01-04 20:56 1,526,640 --a------ C:\Windows\WRSetup.dll
2008-04-13 21:04 . 2008-04-13 21:04 <DIR> d-------- C:\Users\Boss\AppData\Roaming\Ubisoft
2008-04-13 20:57 . 2008-04-13 20:57 <DIR> d-------- C:\Users\All Users\Ubisoft
2008-04-13 20:57 . 2008-04-13 20:57 <DIR> d-------- C:\ProgramData\Ubisoft
2008-04-13 20:56 . 2007-10-12 15:14 3,734,536 --a------ C:\Windows\System32\d3dx9_36.dll
2008-04-13 20:56 . 2007-10-12 15:14 1,374,232 --a------ C:\Windows\System32\D3DCompiler_36.dll
2008-04-13 20:56 . 2007-10-02 09:56 444,776 --a------ C:\Windows\System32\d3dx10_36.dll
2008-04-13 20:56 . 2007-10-22 03:39 267,272 --a------ C:\Windows\System32\xactengine2_10.dll
2008-04-13 20:56 . 2007-10-22 03:37 17,928 --a------ C:\Windows\System32\X3DAudio1_2.dll
2008-04-13 20:44 . 2008-04-13 20:44 <DIR> d-------- C:\Program Files\Ubisoft
2008-04-13 20:20 . 2008-04-13 22:51 2,124,379 ---hs---- C:\Windows\System32\mnewvhtl.ini
2008-04-12 15:21 . 2008-04-12 15:21 <DIR> d-------- C:\Users\All Users\Avg7
2008-04-12 15:21 . 2008-04-12 15:21 <DIR> d-------- C:\ProgramData\Avg7
2008-04-12 11:09 . 2008-04-12 11:09 53,768 --a------ C:\Windows\System32\drivers\avgwfp.sys
2008-04-12 05:46 . 2008-04-12 05:46 <DIR> d-------- C:\Program Files\Panda Security
2008-04-12 03:05 . 2008-04-16 16:56 <DIR> d-------- C:\QUARANTINE
2008-04-12 03:04 . 2008-04-12 03:04 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems
2008-04-12 03:04 . 2006-12-19 15:06 1,495,552 --a------ C:\Windows\System32\epoPGPsdk.dll
2008-04-12 00:04 . 2008-04-16 23:31 121 --a------ C:\Windows\bdagent.INI
2008-04-11 23:53 . 2008-04-11 23:53 <DIR> d-------- C:\Program Files\BitDefender
2008-04-11 23:52 . 2008-04-16 23:22 <DIR> d-------- C:\Program Files\Common Files\BitDefender
2008-04-11 22:48 . 2008-04-11 22:48 <DIR> d-------- C:\Program Files\AskPBar
2008-04-11 02:01 . 2008-04-11 02:04 <DIR> d-------- C:\booti2
2008-04-11 01:59 . 2008-04-11 02:11 <DIR> d-------- C:\booti
2008-04-11 00:59 . 2008-04-11 01:39 <DIR> d-------- C:\Windows\BDOSCAN8
2008-04-11 00:21 . 2008-04-11 00:22 <DIR> d-------- C:\Naruto_397[Binktopia]
2008-04-10 23:01 . 2006-11-02 03:23 <DIR> dr------- C:\Users\Other\Videos
2008-04-10 23:01 . 2006-11-02 03:23 <DIR> d-------- C:\Users\Other\Saved Games
2008-04-10 23:01 . 2006-11-02 03:23 <DIR> dr------- C:\Users\Other\Pictures
2008-04-10 23:01 . 2006-11-02 03:23 <DIR> dr------- C:\Users\Other\Music
2008-04-10 23:01 . 2006-11-02 03:23 <DIR> dr------- C:\Users\Other\Links
2008-04-10 23:01 . 2006-11-02 03:23 <DIR> dr------- C:\Users\Other\Downloads
2008-04-10 23:01 . 2008-04-10 23:01 <DIR> dr------- C:\Users\Other\Documents
2008-04-10 23:01 . 2006-11-02 04:18 <DIR> d--h----- C:\Users\Other\AppData
2008-04-10 23:01 . 2008-04-10 23:01 <DIR> d-------- C:\Users\Other
2008-04-10 23:01 . 2008-04-10 23:01 524,288 --ahs---- C:\Users\Other\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
2008-04-10 23:01 . 2008-04-10 23:01 524,288 --ahs---- C:\Users\Other\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
2008-04-10 23:01 . 2008-04-19 08:30 197,632 --ah----- C:\Users\Other\ntuser.dat.LOG1
2008-04-10 23:01 . 2008-04-10 23:01 65,536 --ahs---- C:\Users\Other\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
2008-04-10 23:01 . 2008-04-10 23:01 0 --ah----- C:\Users\Other\ntuser.dat.LOG2
2008-04-10 21:35 . 2008-04-10 21:35 2 --a------ C:\283746077
2008-04-10 21:17 . 2008-04-10 21:17 159,744 --a------ C:\gkpaxt.exe
2008-04-10 21:17 . 2008-04-10 21:17 58,880 --a------ C:\njhxmjb.exe
2008-04-10 21:17 . 55,218 C:\Windows\zeqbqwp.sys
2008-04-10 21:17 . 2008-04-10 21:17 44,544 --a------ C:\ncolyrif.exe
2008-04-10 21:17 . 2008-04-10 21:17 12,800 --a------ C:\cusgi.exe
2008-04-10 21:17 . 2008-04-10 21:17 4,096 --a------ C:\vhyp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-19 15:30 --------- d-s---w C:\Program Files\HLSW
2008-04-18 06:34 --------- d-----w C:\Program Files\Steam
2008-04-17 07:08 --------- d-----w C:\ProgramData\Symantec
2008-04-17 06:52 --------- d-----w C:\Program Files\Symantec
2008-04-17 06:45 --------- d-----w C:\Users\Boss\AppData\Roaming\uTorrent
2008-04-14 21:27 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-14 20:58 0 ----a-w C:\Program Files\New Text Document.txt
2008-04-14 09:03 401,720 ----a-w C:\HijackThis.exe
2008-04-14 03:44 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-12 03:58 --------- d-----w C:\Program Files\Paltalk Messenger
2008-04-11 11:14 --------- d-----w C:\Program Files\AIM
2008-04-09 10:38 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-09 10:24 --------- d-----w C:\Program Files\PowerISO
2008-04-06 22:09 --------- d-----w C:\Users\Boss\AppData\Roaming\LimeWire
2008-04-05 06:57 --------- d-----w C:\Program Files\Common Files\Steam
2008-03-18 16:17 --------- d-----w C:\Program Files\Activision
2008-03-18 04:26 --------- d-----w C:\Program Files\9Dragons
2008-03-14 06:04 46,652 ----a-w C:\Windows\system32\drivers\scdemu.sys
2008-03-13 15:01 --------- d-----w C:\Program Files\Windows Live
2008-03-13 15:00 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-13 14:59 --------- d-----w C:\ProgramData\WLInstaller
2008-03-13 06:00 --------- d-----w C:\Program Files\OGPlanet
2008-02-27 08:51 --------- d-----w C:\Program Files\Warcraft III
2008-01-19 09:28 142 ----a-w C:\Users\Boss\naruto_385.zip
2008-01-19 08:20 96,282,697 ----a-w C:\Users\Boss\rybka.zip
2008-01-19 08:01 5,002,240 ----a-w C:\Users\Boss\Rybka_v2.1c.demo.x64.exe
2008-01-19 08:00 4,681,728 ----a-w C:\Users\Boss\Rybka_v2.1c.demo.w32.exe
2008-01-19 07:53 590,942 ----a-w C:\Users\Boss\rebdec10.zip
2008-01-18 05:33 22,122 ----a-w C:\Users\Boss\shredder.classic.1.2.patch-icu.zip
2008-01-17 08:32 7,755,319 ----a-w C:\Users\Boss\SetupShredderClassic3.exe
2008-01-15 07:36 52,791,359 ----a-w C:\Users\Boss\NXMREQ.zip
2008-01-15 07:36 1,158,444 ----a-w C:\Users\Boss\setup.zip
2008-01-15 06:34 214,016 ----a-w C:\Users\Boss\ChessmasterChallenge-dm.exe
2008-01-14 13:04 1,337,837 ----a-w C:\Users\Boss\ant_stratego_install.exe
2008-01-02 15:32 527,905 ----a-w C:\Users\Boss\KainSetup.exe
2008-01-02 15:32 3,619 ----a-w C:\Users\Boss\cpugrab.zip
2008-01-02 05:01 144 ----a-w C:\Users\Boss\naruto_384.zip
2008-01-02 03:42 6,222,376 ----a-w C:\Users\Boss\DivXWebPlayerInstaller.exe
2007-12-29 07:15 22 ----a-w C:\Users\Boss\naruto_384raw.zip
2007-12-27 17:26 562,744 ----a-w C:\Users\Boss\WinPcap_4_1_beta.exe
2007-12-27 06:34 7,171,783 ----a-w C:\Users\Boss\Pcsx2_0.9.4_Setup.exe
2007-12-22 08:10 128 ----a-w C:\Users\Boss\naruto_383.zip
2007-12-20 11:41 128 ----a-w C:\Users\Boss\naruto_382.zip
2007-12-20 08:56 22 ----a-w C:\Users\Boss\DEVIL.MAY.CRY.3.SE.PLUS4TRN.ASXDOX.ZIP
2007-12-20 08:56 22 ----a-w C:\Users\Boss\DEVIL.MAY.CRY.3.SE.PLUS2TRN.ICARUS.ZIP
2007-12-20 08:39 22 ----a-w C:\Users\Boss\DEVIL.MAY.CRY.3.SE.PLUS9TRN.ASXDOX.ZIP
2007-12-19 05:30 22 ----a-w C:\Users\Boss\Chrono_Trigger_(U).zip
2007-12-19 05:28 22 ----a-w C:\Users\Boss\zsnesw151.zip
2007-12-18 08:36 94,181 ----a-w C:\Users\Boss\FABLE.TLC.PLUS7TRN.DEVIANCE.ZIP
2007-12-18 05:27 22 ----a-w C:\Users\Boss\FABLE.TLC.PLUS10TRN.W0RF.ZIP
2007-12-17 09:25 9,237,432 ----a-w C:\Users\Boss\BearShareV6.exe
2007-12-14 10:48 22 ----a-w C:\Users\Boss\naruto_382raw.zip
2007-12-10 22:06 128 ----a-w C:\Users\Boss\naruto_381.zip
2007-12-10 20:03 5,243,518 ----a-w C:\Users\Boss\shareaza_2.3.0.0.exe
2007-12-10 19:59 2,018,059 ----a-w C:\Users\Boss\aresregular209_installer.exe
2007-12-05 09:06 9,733,451 ----a-w C:\Users\Boss\vlc-0.8.6d-win32.exe
2007-12-05 08:36 742,560 ----a-w C:\Users\Boss\PMFplay_H.264_Decoder.exe
2007-12-01 09:47 128 ----a-w C:\Users\Boss\naruto_380.zip
2007-11-30 05:58 40,951,297 ----a-w C:\Users\Boss\NittoLegendsBeta0991.exe
2007-11-24 23:35 128 ----a-w C:\Users\Boss\naruto_379.zip
2007-11-23 21:19 7,555,823 ----a-w C:\Users\Boss\1320v152S.zip
2007-11-22 10:52 22 ----a-w C:\Users\Boss\MoFunZone.com--crysis_6_trainer.zip
2007-11-22 10:29 22,328 ----a-w C:\Users\Boss\AppData\Roaming\PnkBstrK.sys
2007-11-22 10:18 269,312 ----a-w C:\Users\Boss\DAMN_NFO_Viewer_v2-10-0032-RC3.exe
2007-11-19 09:32 3,238,127 ----a-w C:\Users\Boss\naruto_378.zip
2007-11-18 16:35 4,160,370 ----a-w C:\Users\Boss\Call.Of.Duty.4-KEYGEN.1911.exe
2007-11-18 16:30 1,372,178 ----a-w C:\Users\Boss\Call Of Duty 4 Crackfix and Keygen.zip
2007-11-16 10:20 1,027,090 ----a-w C:\Users\Boss\wowclient-downloader.exe
2007-11-15 03:58 2,732,032 ----a-w C:\Users\Boss\ventrilo-3.0.0-Windows-i386.exe
2007-11-07 02:29 1,110,016 ----a-w C:\Users\Boss\CohUpdater.exe
2007-11-06 03:23 2,010,624 ----a-w C:\Users\Boss\ventrilo-2.3.0-Windows-i386.exe
2007-11-04 10:04 118,739,008 ----a-w C:\Users\Boss\TheWitcherPatch_1.1a.exe
2007-11-03 14:57 1,819,802,137 ----a-w C:\Users\Boss\Rappelz_E4_072007_USA.zip
2007-11-02 11:22 22 ----a-w C:\Users\Boss\TheWitcherv1.1aGoldTrainer.zip
2007-11-02 11:22 170,496 ----a-w C:\Users\Boss\The Witcher 1.1a Promo Trainer.exe
2007-11-02 05:12 23,770,568 ----a-w C:\Users\Boss\DivXInstaller.exe
2007-10-31 06:45 8,506,408 ----a-w C:\Users\Boss\Install_AIM59.exe
2007-10-31 06:32 1,550,866 ----a-w C:\Users\Boss\mirc63.exe
2007-10-31 04:16 223,822 ----a-w C:\Users\Boss\AutoRefresher.zip
2007-10-31 01:18 114,781 ----a-w C:\Users\Boss\crysisdemo-ch.zip
2007-10-30 10:13 67,108,864 ----a-w C:\Users\Boss\Windows XP Ultimate Edition (by Johnny) [October2007-R3.1].exe
2007-10-30 10:11 2,104,776 ----a-w C:\Users\Boss\daemon410-x64.exe
2007-10-30 10:11 1,911,240 ----a-w C:\Users\Boss\daemon410-x86.exe
2007-10-30 07:20 5,741,210 ----a-w C:\Users\Boss\WARCRAFT.3.V1.21A.ENG.BOR0.NOCD.ZIP
2007-10-30 07:13 1,135,893 ----a-w C:\Users\Boss\New Compressed (zipped) Folder.zip
2007-10-30 07:07 53,026,744 ----a-w C:\Users\Boss\War3TFT_121a_English.exe
2007-10-30 00:38 1,206,366 ----a-w C:\Users\Boss\wrar371.exe
2007-10-29 23:39 2,721,721 ----a-w C:\Users\Boss\hlsw_1_2_0_setup.exe
2007-10-29 00:40 24,792,040 ----a-w C:\Users\Boss\7-10_vista32_dd_53254.exe
2007-10-29 00:39 60,816,768 ----a-w C:\Users\Boss\setpoint400.exe
2007-10-28 23:09 22 ----a-w C:\Users\Boss\Batch FLV.zip
2007-10-28 23:07 193,797,819 ----a-w C:\Users\Boss\esfb123.exe
2007-10-28 21:55 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour"="" []
"eRecoveryService"="" []
"MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 02:45 222208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-05-22 15:49 151552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
backup=C:\Windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\Windows\pss\Logitech SetPoint.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PalTalk.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PalTalk.lnk
backup=C:\Windows\pss\PalTalk.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Boss^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\Windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\10e99fb2]
C:\Windows\system32\gpbxpddd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Assist Launcher]
--a------ 2007-02-02 11:05 1261568 C:\Program Files\Acer Assist\launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Empowering Technology Monitor]
--a------ 2007-06-15 16:48 326440 C:\Acer\Empowering Technology\SysMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Product Registration]
--a------ 2007-02-02 12:24 3383296 C:\Program Files\Acer Registration\ACE1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
--a------ 2007-05-22 15:49 151552 C:\Acer\AcerTour\Reminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-03-08 04:38 40048 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
--a------ 2007-02-28 23:06 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
--a------ 2006-08-01 15:35 67112 C:\Program Files\AIM\aim.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apanel]
C:\ACERSW\config\SetApanel.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2007-11-23 09:18 962560 C:\Program Files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_Run]
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bdagent]
--a------ 2008-02-16 17:45 360448 C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-09-20 15:35 202024 C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bitdefender antiphishing helper]
--a------ 2007-10-09 15:46 61440 C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bm13daac2e]
C:\Windows\system32\rkmmdbrm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
c:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCUTRAYICON]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
--a------ 2007-06-29 16:03 36864 C:\Program Files\GameSpy\Comrade\Comrade.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2007-09-18 07:16 171464 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader]
--a------ 2007-04-25 16:33 457216 C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\Windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
--a------ 2007-03-21 13:00 174872 C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\Windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
c:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
--a------ 2007-04-11 15:32 56080 C:\Windows\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfeeUpdaterUI]
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msserver]
C:\Windows\system32\geBurppn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-09-20 09:51 1836328 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NMSSupport]
--a------ 2007-04-06 14:07 439768 C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
c:\Program Files\Norton Internet Security\osCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMMediaSharing]
--a------ 2007-06-21 18:33 204908 C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\Windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-03-14 16:50 233472 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2007-06-20 01:56 4493312 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShStatEXE]
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 2006-11-02 05:35 1196032 C:\Program Files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spysweeper]
--a------ 2008-01-04 20:56 5367664 C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2006-11-10 12:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-03-29 14:59 1271032 c:\program files\steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2007-07-10 15:30 1006264 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
--a------ 2006-11-02 05:34 2159104 C:\Windows\System32\oobefldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\windows updates]
c:\windows\system\Update.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2006-11-02 05:36 201728 C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A5E2F4F9-4ACC-49D9-8E12-34C554A9F1C5}"= C:\Program Files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{CB7A8998-4B1E-4D90-B5D9-67E2D40F82F4}"= C:\Program Files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine
"{D7C7B185-CD7A-4FB4-9C8F-E488FF26D873}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia
"{41DCE02C-9070-4DE4-A4AA-097557D75583}"= C:\Program Files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician
"{9361F589-2C58-4607-9F3E-7EDDFC19A2FB}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician
"{6C205EE7-6E99-49C4-974F-7B80F2BBA6F0}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect
"{5A8AD70F-9DD5-4D8A-9B7C-E626EC865F3A}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service
"{A6F6AFBC-E5E3-4FE5-99E2-7A541B465AFF}"= C:\Program Files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD
"{712344DC-3475-4A33-8CE2-9D00FC463310}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{287BA272-D032-433E-A8A7-6AEDD2FA4BEC}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D0D5264A-98A1-4CDB-B73A-87736FBCEA20}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{3C8ECEDC-D424-4B98-B403-3AF4A394DD2A}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{998EDADF-65F7-4ED7-BD23-D9AAF420769A}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{B1037FA5-CB88-4F8E-A3E5-851189B3BF45}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{9F614491-7339-4FDC-B9EB-6CD48575C958}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv Media Server
"{6D6DCD2A-740B-4E54-B68E-A2BCBB2BEBA0}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv Media Server
"{16AA6F9C-957B-435F-ACF1-C2C50D48B9A2}"= TCP:Profile=Private|Profile=Public|9442:127.0.0.1:Intel® Viiv Media Server Discovery
"{12591F3D-5523-4A1C-A864-560E0A37FBC8}"= TCP:Profile=Private|Profile=Public|1900:LocalSubnet:LocalSubnet:Intel® Viiv Media Server UPnP Discovery
"{C14AB52F-31A8-4107-B71F-15461DFAD792}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe:Crysis_32_sp_demo
"{25857231-D771-4C01-8B58-8A1A2C0D0477}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe:Crysis_32_sp_demo
"TCP Query User{E3044BC8-6061-45DA-BB11-A6D4F25C4F2A}C:\\program files\\bittornado\\btdownloadgui.exe"= UDP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"UDP Query User{8496F8D9-EC27-429A-B88E-DD15C7E85E2C}C:\\program files\\bittornado\\btdownloadgui.exe"= TCP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"{6CA13711-570A-485E-96AB-A896129956F0}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{3C5B1A79-646C-4CBA-AD98-77167144067E}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{777150B1-0CF5-4C3A-A3AA-D0DCA50D683B}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{5BE49B3C-6BD0-4EBC-80CD-C652A572F293}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{7128608F-0F06-4D25-8E22-7F767D2FF67D}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{B4C66867-FD4B-4822-A29C-13FDDA056869}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{3EC75B3C-CE3C-46D9-83D2-4B8D021214F9}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{BF964E2A-A089-4345-87A0-A56C1E7FCDEC}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{8A7C66C0-C5E9-4F0C-8ACB-8AEE5E2F8C7A}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{6E713BA8-F107-4CC3-9AB6-8EB272CD542D}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{E5EDF402-75F4-4E9B-9970-2E8A455DF1FF}"= UDP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
"{F887BB54-0725-4284-B808-AF68A9D8F9FB}"= TCP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
"TCP Query User{B4BD7D29-C84E-4226-8D0E-90ED0494507C}C:\\program files\\ares\\ares.exe"= UDP:C:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{7011DE3F-C482-462C-A5CE-55FB6DC58654}C:\\program files\\ares\\ares.exe"= TCP:C:\program files\ares\ares.exe:Ares p2p for windows
"{A0006030-C83C-44C1-BD85-9CDD309BEC4C}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare
"{5D013D89-BC1B-437F-ACA3-61288C803E03}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare
"{5ADD0E4A-93B4-4A76-B13C-CABFCE8006BA}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{4B899C01-B222-4B88-A766-7DC5448E592A}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{DD810CF9-628D-48A1-8C7F-A078C7A970D7}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{017FDD7E-5BDF-41B4-9CCB-E3ECEC565734}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{B3C8C70A-BB7D-4505-959D-4BD0921E695B}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{D1F3C5CC-4740-440F-BEE0-E1B3C1DE3AE3}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{53E5F994-E9BE-437D-BC25-DBD73DDB8EC4}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
"DisabledInterfaces"= {550542C4-3186-48D4-9701-CE8FC3FD0832}
R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-04-25 16:34]
R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-04-25 16:34]
R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-04-25 16:34]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;"C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe" [2007-06-21 18:33]
R2 DQLWinService;DQLWinService;"C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe" [2007-02-12 10:46]
R2 eDataSecurity Service;eDataSecurity Service;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-04-25 16:34]
R2 nmsunidr;UniDriver for NMS;C:\Windows\system32\DRIVERS\nmsunidr.sys [2007-02-18 20:34]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-09-28 20:13]
R3 IntelDH;IntelDH Driver;C:\Windows\system32\Drivers\IntelDH.sys [2007-10-28 14:33]
S3 DHTRACE;Intel® DHTrace Controller;C:\Program Files\Common Files\Intel\IntelDH\bin\DHTraceController.exe [2007-04-06 14:08]
S3 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20061025.029\IDSvix86.sys [2006-11-20 21:42]
S3 IntelDHSvcConf;IntelDHSvcConf;"C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe" [2007-04-06 14:08]
S3 NMSCore;Intel® NMSCore;"C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe" [2007-04-06 14:07]
S3 NPF;NetGroup Packet Filter Driver;C:\Windows\system32\drivers\npf.sys [2007-06-21 13:55]
S3 QualityManager;Intel® Quality Manager;"C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe" [2007-04-06 14:10]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-04-04 22:03]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\shell\autorun\command - J:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5eff3f94-86d1-11dc-8b87-0019212f80c2}]
\shell\autorun\command - K:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd405468-98b9-11dc-9911-0019212f80c2}]
\shell\AutoRun\command - N:\autorun.exe
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-19 08:34:57
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\Ati2evxx.exe
C:\Windows\System32\audiodg.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Windows\System32\Ati2evxx.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Windows\System32\WUDFHost.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-04-19 8:37:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-19 15:37:13
Pre-Run: 60,419,825,664 bytes free
Post-Run: 60,364,607,488 bytes free
523 --- E O F --- 2007-10-28 21:52:25
---
My HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:39:07 AM, on 4/19/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16546)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - C:\Program Files\Moyea\FLV Downloader\MoyeaCth.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\.DEFAULT\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {2d8ed06d-3c30-438b-96ae-4d110fdc1fb8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoft...s/as2stubie.cabO23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: COM Host (comHost) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (file missing)
O23 - Service: Intel® DHTrace Controller (DHTRACE) - Intel® Corporation - C:\Program Files\Common Files\Intel\IntelDH\bin\DHTraceController.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IntelDHSvcConf - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Unknown owner - c:\Program Files\Norton Internet Security\isPwdSvc.exe (file missing)
O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (livesrv) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Intel® Viiv Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Intel® NMSCore (NMSCore) - Intel® Corporation - C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe
O23 - Service: Intel® Quality Manager (QualityManager) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe
O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe (file missing)
O23 - Service: BitDefender Virus Shield (vsserv) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: VundoFix Service (vundofixsvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
O23 - Service: Webroot Spy Sweeper Engine (webrootspysweeperservice) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: BitDefender Communicator (xcomm) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 8605 bytes