ComboFix 08-05-15.2 - tony 2008-05-15 16:20:52.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2127 [GMT -7:00]
Running from: C:\Users\tony\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\ProgramData\Microsoft\Windows\Start Menu\Online Security Guide.url
C:\ProgramData\Microsoft\Windows\Start Menu\Security Troubleshooting.url
C:\Windows\cookies.ini
C:\Windows\dat.txt
C:\Windows\Downloaded Program Files\setup.inf
C:\Windows\search_res.txt
C:\Windows\system32\aWOHBuRl.dll
C:\Windows\system32\euxakgjo.ini
C:\Windows\system32\jusched.exe
C:\Windows\System32\lRuBHOWa.ini
C:\Windows\System32\lRuBHOWa.ini2
C:\Windows\system32\qwxqslrd.ini
C:\Windows\system32\xwdemyfq.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-15 to 2008-05-15 )))))))))))))))))))))))))))))))
.
2008-05-15 12:53 . 2008-05-15 12:53 <DIR> d-------- C:\Users\All Users\Avg7
2008-05-15 12:53 . 2008-05-15 12:53 <DIR> d-------- C:\ProgramData\Avg7
2008-05-15 12:51 . 2007-11-27 22:45 91,200 --a------ C:\Windows\System32\drivers\msfwdrv.sys
2008-05-15 12:51 . 2007-11-27 22:44 37,440 --a------ C:\Windows\System32\drivers\msfwhlpr.sys
2008-05-15 12:50 . 2008-05-15 12:51 <DIR> d----c--- C:\Windows\System32\DRVSTORE
2008-05-15 12:50 . 2007-07-06 15:09 70,928 --a------ C:\Windows\System32\drivers\MpFilter.sys
2008-05-15 12:43 . 2008-05-15 15:43 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-05-15 12:04 . 2008-05-15 12:43 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-05-15 11:44 . 2008-05-15 11:44 691 --a------ C:\Users\tony\AppData\Roaming\GetValue.vbs
2008-05-15 11:44 . 2008-05-15 11:44 35 --a------ C:\Users\tony\AppData\Roaming\SetValue.bat
2008-05-15 04:11 . 2008-05-15 04:11 91,840 --a------ C:\Windows\System32\drlsqxwq.dll
2008-05-14 16:19 . 2008-05-14 16:19 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-07 04:01 . 2008-05-07 04:01 54,156 --ah----- C:\Windows\QTFont.qfn
2008-05-07 04:01 . 2008-05-07 04:01 1,409 --a------ C:\Windows\QTFont.for
2008-05-06 12:37 . 2008-05-06 12:37 <DIR> d-------- C:\Program Files\Turbine
2008-05-06 12:21 . 2007-01-03 19:20 1,732 --a------ C:\Windows\System32\drivers\nvphy.bin
2008-05-05 04:45 . 2008-05-05 04:45 <DIR> d-------- C:\Users\tony\AppData\Roaming\Petroglyph
2008-05-05 04:44 . 2008-05-05 04:44 <DIR> d-------- C:\Users\tony\AppData\Roaming\LucasArts
2008-05-05 04:22 . 2008-05-05 04:22 <DIR> d-------- C:\Program Files\LucasArts
2008-04-28 08:07 . 2008-04-28 08:07 <DIR> d-------- C:\Program Files\THQ
2008-04-27 05:30 . 2003-07-20 20:17 5,174 --a------ C:\Windows\System32\nppt9x.vxd
2008-04-27 05:30 . 2005-01-04 11:43 4,682 --a------ C:\Windows\System32\npptNT2.sys
2008-04-27 03:36 . 2008-04-27 03:36 <DIR> d-------- C:\Windows\System32\SolidStateNetworks
2008-04-27 03:36 . 2008-04-27 03:36 <DIR> d-------- C:\Windows\System32\AcclaimGames
2008-04-23 15:39 . 2008-04-23 15:39 <DIR> d-------- C:\perflogs
2008-04-15 04:03 . 2008-04-15 04:03 <DIR> d-------- C:\Program Files\iPod
2008-04-15 04:02 . 2008-04-15 04:02 <DIR> d-------- C:\Program Files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-15 19:53 --------- d-----w C:\ProgramData\Grisoft
2008-05-15 19:50 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2008-05-15 18:57 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-15 18:47 1,750 ----a-w C:\Windows\System32\tmp.reg
2008-05-15 18:15 --------- d-----w C:\Users\tony\AppData\Roaming\uTorrent
2008-05-13 22:02 334 ----a-w C:\Users\tony\AppData\Roaming\wklnhst.dat
2008-05-13 17:42 --------- d-----w C:\Program Files\World of Warcraft
2008-05-07 05:22 --------- d-----w C:\ProgramData\Roxio
2008-05-06 19:32 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-06 19:28 --------- d-----w C:\ProgramData\Symantec
2008-05-06 11:35 --------- d-----w C:\Program Files\Microsoft Games
2008-05-06 10:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-05 11:44 98,304 ----a-w C:\Windows\System32\CmdLineExt.dll
2008-04-19 06:56 --------- d-----w C:\Users\tony\AppData\Roaming\DivX
2008-04-19 06:55 --------- d-----w C:\Program Files\DivX
2008-04-17 19:33 --------- d-----w C:\Program Files\Google
2008-04-17 19:33 --------- d-----w C:\Program Files\free-downloads.net
2008-04-17 19:33 --------- d-----w C:\Program Files\Conduit
2008-04-17 19:25 --------- d--h--w C:\ProgramData\yahoo!
2008-04-17 19:25 --------- d-----w C:\Program Files\Yahoo!
2008-04-15 11:03 --------- d-----w C:\Program Files\iTunes
2008-04-14 00:17 --------- d-----w C:\Program Files\Activision
2008-04-13 10:21 --------- d-----w C:\Program Files\Windows Mail
2008-04-08 20:45 --------- d-----w C:\Users\tony\AppData\Roaming\Template
2008-04-05 08:35 --------- d-----w C:\Users\tony\AppData\Roaming\WildTangent
2008-04-05 08:35 --------- d-----w C:\ProgramData\WildTangent
2008-03-31 21:25 831,488 ----a-w C:\Windows\System32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w C:\Windows\System32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w C:\Windows\System32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w C:\Windows\System32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w C:\Windows\System32\DivX.dll
2008-03-31 21:25 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-03-31 00:55 --------- d---a-w C:\ProgramData\TEMP
2008-03-28 22:03 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-03-26 05:02 --------- d-----w C:\Program Files\Alcohol Soft
2008-03-26 04:10 717,296 ----a-w C:\Windows\system32\drivers\sptd.sys
2008-03-26 04:10 --------- d-----w C:\Users\tony\AppData\Roaming\DAEMON Tools
2008-03-25 10:32 --------- d-----w C:\Program Files\EA GAMES
2008-03-25 06:59 --------- d-----w C:\Users\tony\AppData\Roaming\Uniblue
2008-03-21 20:30 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\Windows\System32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\Windows\System32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\Windows\System32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\Windows\System32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\Windows\System32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2008-03-20 07:17 --------- d-----w C:\ProgramData\HipSoft
2008-03-20 07:17 --------- d-----w C:\Program Files\MSN Games
2008-03-20 07:13 --------- d-----w C:\Program Files\Trymedia
2008-03-20 07:12 --------- d-----w C:\Program Files\Hexacto Games
2008-02-29 22:33 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-29 22:30 3,505,720 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-29 22:30 3,471,928 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-29 22:29 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-29 22:29 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-29 22:29 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-29 22:29 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-29 22:29 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-29 22:29 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-02-29 22:29 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-29 22:29 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-29 22:29 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-29 22:29 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-29 22:27 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:14 2,028,544 ----a-w C:\Windows\System32\win32k.sys
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
2007-12-09 04:36 174 --sha-w C:\Program Files\desktop.ini
2008-02-08 15:53 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-02-08 15:53 32,768 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-02-08 15:53 16,384 --sha-w C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 05:34 2159104 C:\Windows\System32\oobefldr.dll]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 05:35 125440]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-04-01 18:35 3587120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 16:32 56080 C:\Windows\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 16:32 56080 C:\Windows\KHALMNPR.Exe]
"MSConfig"="C:\Windows\System32\msconfig.exe" [2006-11-02 02:45 222208]
"94cfff19"="C:\Windows\system32\drlsqxwq.dll" [2008-05-15 04:11 91840]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2008-04-21 10:23 67112]
"MSServer"="C:\Windows\system32\opnmMDSk.dll" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{240A2128-ACD4-4124-87AF-527124CAAC38}"= C:\Windows\system32\opnmMDSk.dll [ ]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\Windows\pss\Logitech Desktop Messenger.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\Windows\pss\Logitech SetPoint.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish Media Detector.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snapfish Media Detector.lnk
backup=C:\Windows\pss\Snapfish Media Detector.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
c:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
--a------ 2007-05-24 13:13 71176 c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-16 23:11 49152 c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
--a------ 2007-06-01 13:40 1783400 C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a------ 2007-04-18 08:01 65536 c:\hp\support\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
c:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
--a------ 2006-12-08 09:16 65536 C:\HP\KBD\KbdStub.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
--a------ 2007-04-11 16:32 56080 C:\Windows\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
--a------ 2007-04-11 16:32 56080 C:\Windows\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2001-07-09 02:50 155648 C:\Windows\system32\\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-04-12 10:07 8429568 C:\Windows\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-04-12 10:07 81920 C:\Windows\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2007-04-12 10:07 86016 C:\Windows\system32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OsdMaestro]
--a------ 2007-02-15 04:59 118784 C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2007-09-19 07:50 4702208 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2006-11-10 13:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateReg]
--a------ 2007-04-07 02:56 54936 C:\Windows\system32\jureg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
--a------ 2008-01-29 18:38 583048 C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-01-07 05:26 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{90823AD4-A2F1-486D-8EA7-9E2C01DE83B2}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{4AE50274-27D8-4966-87D5-6311AA99B027}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{AD0E426E-AB2A-4962-AE9B-768675D72A51}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{BA8C0E53-1F52-47C1-8971-885FFD426EE4}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{E7BCF2CF-8A5A-459D-A68B-F732A469DAB3}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{CBF53917-2CFE-4BF8-8EAA-BD1A70250085}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{5FF21C31-34D7-405D-89FB-BFA0F3473E61}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{1417D978-292D-4887-9C26-506D84B76ACA}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{BE0C9981-2F6F-404B-AE2B-D0C7CD90EB80}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{D48F7633-B102-481C-9B01-C28897AC2131}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{03AB03BA-C05E-46A5-BCB2-7B4C2FF80D3A}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{7B7A7088-0572-419D-8C68-1856025B6EC5}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{7023C575-7AD7-4A35-9482-6A49661CA82E}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{DE4E10A8-1875-4181-A56C-A75BD4032C62}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{699F8FD1-5B98-4FFF-84B1-5F3731297558}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8A788319-A014-4F57-A449-82F6D75DF4D5}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{038064AD-0DCA-4B53-8BE7-61C4C3A663B4}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{9C3FDDF4-4B99-4C4E-86DA-EE5FF7B3D9AD}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{19170A32-CE90-4B7E-A9A1-01C9EA9A0DD6}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{5CF6A1D4-E327-4870-BCC6-B473936ACA0A}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{551A51BC-3745-48C1-8742-2DEFD9992EC0}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{66535925-4583-4A13-A88A-72F9CAC06987}"= UDP:C:\Program Files\Sierra Entertainment\Empire Earth III\EE3.exe:Empire Earth III
"{2134CEC8-E7D8-4C14-8DF2-15D97D963EC4}"= TCP:C:\Program Files\Sierra Entertainment\Empire Earth III\EE3.exe:Empire Earth III
"{5F005CCF-990E-449C-9C42-64CF4B0674B9}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{D8EFDF9C-4466-4F56-9CEB-A3669AF54B81}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{617C8D80-F401-49C2-A94D-308E524D33B1}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{E07E6E4F-5347-4A67-B79C-7871D72C718D}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{2C48458D-FA29-4381-B8D8-E0CEB8F39D75}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{DE1D8190-A30A-4B47-A0FB-9D76C3535755}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{B8D45649-84EE-4B43-9503-79A0CC81E301}"= Disabled:UDP:10169:SolidNetworkManager
"{83B5918B-BDA3-44D5-BC29-1E625F4F2CD5}"= Disabled:TCP:10169:SolidNetworkManager
"{4FDD67C7-B4D5-44BA-8A9D-F5DF63264FFC}"= UDP:C:\Program Files\LucasArts\Star Wars Empire at War\GameData\sweaw.exe:Star Wars: Empire at War
"{DE9E5BE5-FBD4-44DE-A7FF-7EF96D720AC0}"= TCP:C:\Program Files\LucasArts\Star Wars Empire at War\GameData\sweaw.exe:Star Wars: Empire at War
"{99138FFE-7EDD-4025-BDC4-98B694E7979B}"= Disabled:UDP:C:\Program Files\Rhapsody\rhapsody.exe:Rhapsody Media Player
"{FFC8C3B8-E80B-41AE-8A1C-FB308520C1DC}"= Disabled:TCP:C:\Program Files\Rhapsody\rhapsody.exe:Rhapsody Media Player
"TCP Query User{43E97B80-F5C7-40DA-ADF7-D31F72C2EF84}C:\\program files\\turbine\\asheron's call - throne of destiny\\aclauncher.exe"= UDP:C:\program files\turbine\asheron's call - throne of destiny\aclauncher.exe:AC Launcher
"UDP Query User{A0A6B0C0-ECE9-4A26-AE6D-82FC2662D7AA}C:\\program files\\turbine\\asheron's call - throne of destiny\\aclauncher.exe"= TCP:C:\program files\turbine\asheron's call - throne of destiny\aclauncher.exe:AC Launcher
"TCP Query User{213C11E7-0D8A-428E-A760-177ECC30B793}C:\\program files\\turbine\\asheron's call - throne of destiny\\acclient.exe"= UDP:C:\program files\turbine\asheron's call - throne of destiny\acclient.exe:acclient
"UDP Query User{F692FD66-4E7D-45A2-AA7D-3A1F8E131D64}C:\\program files\\turbine\\asheron's call - throne of destiny\\acclient.exe"= TCP:C:\program files\turbine\asheron's call - throne of destiny\acclient.exe:acclient
"TCP Query User{2422DF67-11FE-42C5-A2BE-76A29F43DFB9}C:\\program files\\itunes\\itunes.exe"= UDP:C:\program files\itunes\itunes.exe:iTunes
"UDP Query User{AC7CC5AF-C334-4ABE-A5F4-F4BE862D7630}C:\\program files\\itunes\\itunes.exe"= TCP:C:\program files\itunes\itunes.exe:iTunes
"{880783EB-C9E1-456C-8D1C-2F64BC8B5BF1}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{1D9FB783-FB48-4BA2-8B3A-4B3BA7897FB1}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{CBFA7E25-6DC5-45AF-B738-A24276392289}C:\\program files\\thq\\dawn of war demo\\w40k.exe"= UDP:C:\program files\thq\dawn of war demo\w40k.exe:W40K
"UDP Query User{213E6379-D9BE-4E2A-BFA3-C2DA61D023A6}C:\\program files\\thq\\dawn of war demo\\w40k.exe"= TCP:C:\program files\thq\dawn of war demo\w40k.exe:W40K
"TCP Query User{08D6BA70-71A2-4AAD-9EB4-F17ACF85332A}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"UDP Query User{4892427C-08C1-4BCA-85FA-840031E39A31}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"{DE5391DA-89CD-4D86-9484-486478D37484}"= UDP:63331:Windows Live OneCare
"{A72028F9-D41F-4AE4-8990-993F3C481AC9}"= UDP:63331:Windows Live OneCare
"{5E1F0CB7-006C-458F-BFAE-D558AF909D0C}"= UDP:63331:Windows Live OneCare
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-28 09:44]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-09-29 04:13]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb939525-faea-11dc-a73a-001d60b5b8c8}]
\shell\AutoRun\command - K:\Autorun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-15 16:25:49
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\Explorer.exe
-> C:\Windows\system32\drlsqxwq.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\Windows\System32\Ati2evxx.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Windows\System32\wbem\WMIADAP.exe
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
.
**************************************************************************
.
Completion time: 2008-05-15 16:30:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-15 23:30:24
Pre-Run: 174,586,675,200 bytes free
Post-Run: 174,872,154,112 bytes free
343 --- E O F --- 2008-05-06 19:21:41