Here ya are
ComboFix 08-05-19.4 - Ken 2008-05-21 8:08:13.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1205 [GMT -4:00]
Running from: C:\Users\Ken\Desktop\ComboFix.exe
Command switches used :: C:\Users\Ken\Desktop\CFScript.txt.txt
* Created a new restore point
FILE ::
C:\Windows\exnk.exe
C:\Windows\vbksrofa.dll
E:\autorun.exe
E:\setup.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\exnk.exe
C:\Windows\vbksrofa.dll
E:\autorun.exe . . . . failed to delete
E:\setup.exe . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-04-21 to 2008-05-21 )))))))))))))))))))))))))))))))
.
2008-05-19 16:45 . 2008-05-19 16:45 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-19 16:25 . 2008-05-19 16:25 <DIR> d-------- C:\VundoFix Backups
2008-05-19 13:29 . 2008-05-19 13:29 62 --a------ C:\Windows\wininit.ini
2008-05-19 07:22 . 2008-05-19 21:31 <DIR> d----c--- C:\Windows\System32\DRVSTORE
2008-05-18 23:47 . 2008-05-19 20:39 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-05-17 17:04 . 2008-05-19 08:07 <DIR> d-------- C:\Users\All Users\Symantec
2008-05-17 17:04 . 2008-05-19 08:07 <DIR> d-------- C:\ProgramData\Symantec
2008-05-17 17:04 . 2008-05-19 08:10 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-05-17 12:21 . 2008-05-17 12:21 <DIR> d-------- C:\Windows\solcache
2008-05-17 12:20 . 2008-05-19 13:29 <DIR> d-------- C:\SIERRA
2008-05-17 12:20 . 2008-05-17 12:22 408 --a------ C:\Windows\SIERRA.INI
2008-05-17 11:21 . 2008-05-17 11:21 <DIR> d-------- C:\Users\Ken\AppData\Roaming\DAEMON Tools
2008-05-17 11:21 . 2008-05-17 11:21 717,296 --a------ C:\Windows\System32\drivers\sptd.sys
2008-05-10 23:58 . 2008-05-10 23:58 <DIR> d-------- C:\Program Files\iTunes
2008-05-10 23:58 . 2008-05-10 23:58 <DIR> d-------- C:\Program Files\iPod
2008-05-10 23:57 . 2008-05-10 23:57 <DIR> d-------- C:\Program Files\QuickTime
2008-05-10 23:54 . 2008-05-10 23:54 <DIR> d-------- C:\Program Files\Apple Software Update
2008-05-10 00:12 . 2008-05-10 00:12 <DIR> d--h----- C:\Users\All Users\{0E8E33D8-193A-414A-A909-0F101A142D26}
2008-05-10 00:12 . 2008-05-10 00:12 <DIR> d--h----- C:\ProgramData\{0E8E33D8-193A-414A-A909-0F101A142D26}
2008-05-10 00:04 . 2008-05-10 00:04 <DIR> d-------- C:\Program Files\Stardock Games
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-20 04:12 --------- d-----w C:\Program Files\Steam
2008-05-20 01:30 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2008-05-20 00:37 --------- d-----w C:\Program Files\BitComet
2008-05-19 20:24 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-19 11:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-16 02:05 --------- d-----w C:\Program Files\Trillian
2008-05-04 23:55 43,520 ----a-w C:\Windows\System32\CmdLineExt03.dll
2008-05-04 22:53 22,328 ----a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-05-04 22:52 107,832 ----a-w C:\Windows\System32\PnkBstrB.exe
2008-05-04 03:27 --------- d-----w C:\Program Files\Common Files\Steam
2008-05-03 11:20 --------- d-----w C:\Program Files\MySpace
2008-05-03 11:19 --------- d-----w C:\ProgramData\Dragon's Eye Productions
2008-05-03 11:16 --------- d-----w C:\Program Files\zMUD
2008-04-24 13:04 66,872 ----a-w C:\Windows\System32\PnkBstrA.exe
2008-04-24 12:55 22,328 ----a-w C:\Users\Ken\AppData\Roaming\PnkBstrK.sys
2008-04-15 18:44 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-06 19:36 --------- d-----w C:\Program Files\Common Files\INCA Shared
2008-03-25 12:16 --------- d-----w C:\Program Files\Mediatwins software
2008-03-25 12:12 --------- d-----w C:\Program Files\DivX
2008-03-22 11:39 --------- d-----w C:\Users\Ken\AppData\Roaming\Codemasters
2008-03-22 11:38 --------- d-----w C:\Program Files\AGEIA Technologies
2008-03-22 11:37 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-21 02:05 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-02-21 02:05 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-02-21 02:05 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-02-21 02:04 823,296 ----a-w C:\Windows\System32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\Windows\System32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\Windows\System32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\Windows\System32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\Windows\System32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\Windows\System32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\Windows\System32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\Windows\System32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\Windows\System32\dtu100.dll
2008-02-21 02:03 156,992 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-02-21 02:03 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2007-09-04 11:07 174 --sha-w C:\Program Files\desktop.ini
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((( snapshot@2008-05-20_ 0.09.51.50 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-20 04:04:37 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-05-21 12:10:25 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-05-20 04:04:38 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-05-21 12:10:25 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-05-20 04:04:38 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-05-21 12:10:25 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-05-20 04:06:54 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-05-21 12:12:45 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-05-20 04:06:54 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-05-21 12:12:45 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2008-05-20 01:39:28 103,818 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-05-20 04:11:28 103,818 ----a-w C:\Windows\System32\perfc009.dat
- 2008-05-20 01:39:28 618,410 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-05-20 04:11:29 618,410 ----a-w C:\Windows\System32\perfh009.dat
- 2008-05-20 01:35:27 9,412 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3145862903-2119528392-1372316911-1000_UserData.bin
+ 2008-05-20 04:08:25 9,658 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3145862903-2119528392-1372316911-1000_UserData.bin
- 2008-05-20 01:35:27 67,522 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-05-20 04:08:24 67,678 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 13:57 1103480]
"EA Core"="C:\Program Files\Electronic Arts\EADM\Core.exe" [2007-12-04 06:57 2494464]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 08:35 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-02 08:34 1004136]
"RtHDVCpl"="RtHDVCpl.exe" [2007-11-14 16:50 4706304 C:\Windows\RtHDVCpl.exe]
"CHotkey"="zHotkey.exe" [2006-11-07 17:08 547840 C:\Windows\zHotkey.exe]
"ShowWnd"="ShowWnd.exe" [2005-01-27 12:13 36864 C:\Windows\ShowWnd.exe]
"ModPS2"="ModPS2Key.exe" [2006-11-07 17:34 53248 C:\Windows\ModPS2Key.exe]
"BigFix"="c:\program files\Bigfix\bigfix.exe" [2006-11-16 19:04 2348584]
"PivotSoftware"="C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe" [2007-02-09 12:17 694008]
"DT GWY"="C:\Program Files\Gateway\EzTune\DTHtml.exe" [2007-03-20 10:10 281600]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2007-01-12 17:48 275800]
"VX3000"="C:\Windows\vVX3000.exe" [2006-12-05 15:39 707360]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-12-11 18:06 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-12-11 18:06 8530464]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-12-11 18:06 81920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-09 10:23:40 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3145862903-2119528392-1372316911-1000]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D4B49E7C-6997-4DDC-88E4-5DF72E3588E3}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{160B30FC-5DB1-4315-86AC-4540BF3DA13C}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{93F1E7DC-02DD-4C9F-9485-5549F03FC478}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{67AAD4A0-AACE-4B07-94EA-1B33ABC4E41E}"= UDP:C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{D76C23E0-5ADF-418B-BF29-C90EFFE20DDE}"= TCP:C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{D0DDFD64-4294-4DC0-9306-9E3E83D39000}"= UDP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"{B760F881-E47C-4B0B-ABAB-9A2AE2625E6B}"= TCP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"{D1C66E24-55DD-41A1-91A7-15BDF306A526}"= UDP:C:\Program Files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{C5BA6D06-159E-4FD7-B7E3-52EFE21C84D6}"= TCP:C:\Program Files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{AC540FD1-318B-467F-9AF8-4BDA5E3E4F90}"= UDP:C:\Program Files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{A4F0F5BD-AE84-4512-A7FC-AF1A7B67F9FC}"= TCP:C:\Program Files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{79743885-8347-44C8-892E-BE61D90D3DE2}"= UDP:C:\Program Files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)
"{42212ED8-6F9A-4AF6-9679-204964B7262D}"= TCP:C:\Program Files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)
"{67864E10-A43F-4519-A459-3465C3E4E396}"= UDP:C:\Program Files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)
"{D0C9D30F-B505-4C17-9238-1B735EB126CD}"= TCP:C:\Program Files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)
"TCP Query User{EAD31D02-77C7-43F9-8600-436EA1F052C3}C:\\program files\\electronic arts\\battlefield 2142\\bf2142pace.exe"= UDP:C:\program files\electronic arts\battlefield 2142\bf2142pace.exe:BF2142Pace
"UDP Query User{B78D2E95-CE4D-45B6-B88C-C27B8137DDFD}C:\\program files\\electronic arts\\battlefield 2142\\bf2142pace.exe"= TCP:C:\program files\electronic arts\battlefield 2142\bf2142pace.exe:BF2142Pace
"{0DA6F617-A7DC-4A74-AC2A-12437DF55BED}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{E0722CEB-85D7-4CD1-AEBE-DE02F3B07873}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{10E2067F-CA5B-41C1-BADA-E607B11BE67B}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{71E7148D-ABF9-4AA0-A719-55EF5F9E4A9D}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{BD83E689-CE56-4671-A2B7-373630E3C2AB}"= UDP:C:\Program Files\BitTorrent_DNA\dna.exe:BitTorrent DNA
"{F292CC18-1F08-401C-8E67-F19A6C293DE7}"= TCP:C:\Program Files\BitTorrent_DNA\dna.exe:BitTorrent DNA
"TCP Query User{E6EDA244-9D55-489E-BC4E-52114219BD36}C:\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{44DD7D3C-39EC-4181-A141-B2DA9E3B1A5A}C:\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\program files\bittorrent\bittorrent.exe:bittorrent
"{7F0C979F-6989-4028-B270-4CCC468B1222}"= UDP:C:\Program Files\Download Manager\DLM.exe:Download Manager
"{A0D600FC-DBE5-4C93-ACFF-D6E493E2DFA4}"= TCP:C:\Program Files\Download Manager\DLM.exe:Download Manager
"{9C6DE3DC-1F4C-4DD2-9BE4-FBDC09A861A7}"= UDP:C:\Program Files\Sierra\FEAR\FEAR.exe:FEAR
"{47533822-8F64-4C76-9BB0-01A603A19D76}"= TCP:C:\Program Files\Sierra\FEAR\FEAR.exe:FEAR
"TCP Query User{BB623170-9543-4E01-891A-462F047BC024}C:\\program files\\steam\\steam.exe"= UDP:C:\program files\steam\steam.exe:Steam
"UDP Query User{D52D6B41-471E-4DC9-BB0F-9E1AA74F68E4}C:\\program files\\steam\\steam.exe"= TCP:C:\program files\steam\steam.exe:Steam
"TCP Query User{7E566D8E-BB52-40E6-8621-C04A200E169A}C:\\program files\\steam\\steamapps\\takaraprg\\team fortress 2\\hl2.exe"= UDP:C:\program files\steam\steamapps\takaraprg\team fortress 2\hl2.exe:hl2
"UDP Query User{E3CF1ABC-F7EB-4486-8E26-19CA292AB652}C:\\program files\\steam\\steamapps\\takaraprg\\team fortress 2\\hl2.exe"= TCP:C:\program files\steam\steamapps\takaraprg\team fortress 2\hl2.exe:hl2
"TCP Query User{064D470B-52DF-413F-A277-8C46915D857E}C:\\program files\\trillian\\trillian.exe"= UDP:C:\program files\trillian\trillian.exe:Trillian
"UDP Query User{08008E7F-A144-4F3F-8E8E-0FABF885A32D}C:\\program files\\trillian\\trillian.exe"= TCP:C:\program files\trillian\trillian.exe:Trillian
"{3D84B296-805E-4F28-805B-D7349255BF34}"= UDP:16641:BitComet 16641 TCP
"{91B3D533-AE86-4608-8F58-B4563B417666}"= TCP:16641:BitComet 16641 UDP
"TCP Query User{43B2D94C-436B-478E-A9A3-24A1973DCD5A}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{60A1F8A5-3A29-4A72-9141-5E44337A55FA}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{A7F19581-0D6F-4224-ABDC-0EA5A06F9B2D}"= UDP:C:\Program Files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{2450B6EA-1603-449A-89C8-5EA209F2EC5D}"= TCP:C:\Program Files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"TCP Query User{71E62E96-92D1-4C58-B572-FA95C1A0784E}C:\\program files\\steam\\steamapps\\takaraprg\\source sdk base\\hl2.exe"= UDP:C:\program files\steam\steamapps\takaraprg\source sdk base\hl2.exe:hl2
"UDP Query User{13E91D7A-7A41-4251-B4DB-B2FC59839E8B}C:\\program files\\steam\\steamapps\\takaraprg\\source sdk base\\hl2.exe"= TCP:C:\program files\steam\steamapps\takaraprg\source sdk base\hl2.exe:hl2
"TCP Query User{B8CECA7A-ECB9-4B81-8721-D1DA4C98E97E}C:\\program files\\firaxis games\\sid meier's civilization 4\\civilization4.exe"= UDP:C:\program files\firaxis games\sid meier's civilization 4\civilization4.exe:Sid Meier's Civilization 4
"UDP Query User{61A24B57-D925-452C-9448-AE97B2A40DD5}C:\\program files\\firaxis games\\sid meier's civilization 4\\civilization4.exe"= TCP:C:\program files\firaxis games\sid meier's civilization 4\civilization4.exe:Sid Meier's Civilization 4
"TCP Query User{58A23DF3-AEE6-4512-A245-0A91606BF0E9}C:\\program files\\steam\\steamapps\\common\\universe at war earth assault\\uawea.exe"= UDP:C:\program files\steam\steamapps\common\universe at war earth assault\uawea.exe:Universe at War: Earth Assault Application
"UDP Query User{A5CE6537-0D94-45ED-BA39-A3743E42C094}C:\\program files\\steam\\steamapps\\common\\universe at war earth assault\\uawea.exe"= TCP:C:\program files\steam\steamapps\common\universe at war earth assault\uawea.exe:Universe at War: Earth Assault Application
"{5425BF3A-89A6-465A-97FA-527CC521FEA0}"= UDP:C:\Program Files\Microsoft Games\Gears of War\Binaries\WarGame-G4WLive.exe:Gears of War
"{7FB55202-612B-47DD-BEFC-CB34A792AAC9}"= TCP:C:\Program Files\Microsoft Games\Gears of War\Binaries\WarGame-G4WLive.exe:Gears of War
"{70DCDADC-9DF3-48DB-80FE-E16A3B409853}"= UDP:C:\Program Files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"{73152E71-050C-4E0E-AF6B-1DF885DAD162}"= TCP:C:\Program Files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"{34FD7DEE-66A5-40FA-A3E8-FFCFED7161DB}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{00925067-0FE4-4787-8A0E-228F18BEB959}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-01-04 14:13]
R3 AVer88xHD;AVerMedia 23888 AvStream Video Capture;C:\Windows\system32\drivers\AVer88xHD.sys [2007-04-08 23:47]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-01-09 13:00]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 03:30]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-05-09 13:48]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-21 08:13:17
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Windows\TEMP\TMP0000002843E52F7FFA1FCF23 524288 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\Explorer.exe
-> C:\Program Files\Portrait Displays\Pivot Software\winphook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Windows\System32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\Windows\System32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\wbem\WMIADAP.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-05-21 8:16:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-21 12:16:00
ComboFix2.txt 2008-05-21 11:14:33
ComboFix3.txt 2008-05-20 04:10:34
Pre-Run: 336,694,214,656 bytes free
Post-Run: 337,293,467,648 bytes free
269 --- E O F --- 2008-05-21 11:10:56
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:20:35 AM, on 5/21/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\zHotkey.exe
C:\Windows\ModPS2Key.exe
C:\Program Files\Portrait Displays\Pivot Software\wpCtrl.exe
C:\Program Files\Gateway\EzTune\dthtml.exe
C:\Windows\vVX3000.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Windows\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.gateway.c...h...TP&M=GM5472R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.gateway.c...h...TP&M=GM5472R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [ModPS2] ModPS2Key.exe
O4 - HKLM\..\Run: [BigFix] c:\program files\Bigfix\bigfix.exe /atstartup
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe"
O4 - HKLM\..\Run: [DT GWY] C:\Program Files\Gateway\EzTune\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX3000] C:\Windows\vVX3000.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) -
http://cdn.scan.onec...s/wlscctrl2.cabO23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 5852 bytes