Here's the combofix log:
ComboFix 08-06-05.3 - MOE 2008-06-08 14:15:51.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.248 [GMT -4:00]
Running from: C:\Documents and Settings\MOE\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((( Files Created from 2008-05-08 to 2008-06-08 )))))))))))))))))))))))))))))))
.
2008-06-07 14:27 . 2008-06-07 14:27 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-06-07 14:27 . 2008-06-07 14:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-06 21:34 . 2008-06-06 21:34 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-06-06 18:16 . 2008-06-06 18:17 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-06 18:16 . 2008-06-05 16:04 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-06 18:16 . 2008-06-05 16:04 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-06 17:47 . 2008-06-06 17:47 <DIR> d-------- C:\Documents and Settings\MOE\New Folder
2008-06-06 17:37 . 2008-06-06 17:37 <DIR> d-------- C:\Documents and Settings\MOE\Application Data\LimeWire
2008-06-06 17:37 . 2008-06-06 17:37 <DIR> d-------- C:\Documents and Settings\HAMDA & HASSAN\Application Data\LimeWire
2008-06-06 16:59 . 2008-06-06 16:59 <DIR> d-------- C:\Documents and Settings\MOE\Application Data\Malwarebytes
2008-06-06 16:59 . 2008-06-06 16:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-06 07:37 . 2008-06-06 07:37 <DIR> d-------- C:\industry_files
2008-06-06 07:37 . 2008-06-06 07:37 45,111 --a------ C:\industry.htm
2008-06-06 07:36 . 2008-06-06 07:36 <DIR> d-------- C:\reasons_files
2008-06-06 07:36 . 2008-06-06 07:36 20,358 --a------ C:\reasons.htm
2008-06-06 07:35 . 2008-06-06 07:35 <DIR> d-------- C:\population_files
2008-06-06 07:35 . 2008-06-06 07:35 <DIR> d-------- C:\invest_files
2008-06-06 07:35 . 2008-06-06 07:35 41,502 --a------ C:\population.htm
2008-06-06 07:35 . 2008-06-06 07:35 23,334 --a------ C:\invest.htm
2008-06-06 07:33 . 2008-06-06 07:33 <DIR> d-------- C:\Age_distribution_files
2008-06-06 07:33 . 2008-06-06 07:33 42,072 --a------ C:\Age_distribution.htm
2008-06-05 18:23 . 2008-06-05 18:23 347 --ahs---- C:\WINDOWS\system32\svFeNXyb.ini
2008-06-05 17:11 . 2008-06-05 17:11 <DIR> d-------- C:\Deckard
2008-06-01 20:27 . 2008-06-01 20:27 <DIR> d-------- C:\Program Files\Aspose
2008-06-01 11:15 . 2008-06-01 11:15 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-28 23:01 . 2008-05-28 23:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-28 21:07 . 2008-05-28 23:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-28 20:56 . 2008-05-28 20:56 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-28 20:56 . 2008-05-28 21:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-28 20:14 . 2008-05-28 20:14 <DIR> d-------- C:\!KillBox
2008-05-28 19:47 . 2008-05-28 19:47 <DIR> d-------- C:\Documents and Settings\MOE\Application Data\Uniblue
2008-05-28 19:26 . 2008-05-28 19:32 <DIR> d-------- C:\Program Files\Security Task Manager
2008-05-28 19:26 . 2008-05-28 19:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-05-21 16:01 . 2008-05-21 16:01 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2008-05-21 16:00 . 2008-05-21 16:01 <DIR> d-------- C:\Documents and Settings\MOE\Application Data\U3
2008-05-18 17:44 . 2008-05-18 17:50 <DIR> d-------- C:\Program Files\Microsoft Bootvis
2008-05-18 17:18 . 2008-05-18 17:19 <DIR> d-------- C:\Program Files\CachemanXP
2008-05-18 16:21 . 2008-05-18 16:21 <DIR> d-------- C:\WINDOWS\system32\IOSUBSYS
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\system32\lsdelete.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-01 15:20 --------- d-----w C:\Program Files\mIRC
2008-05-30 19:52 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-29 03:01 --------- d-----w C:\Program Files\Lavasoft
2008-05-25 17:26 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-18 20:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-18 20:10 --------- d-----w C:\Program Files\ChessBase
2008-05-18 20:10 --------- d-----w C:\Documents and Settings\MOE\Application Data\ChessBase
2008-05-17 15:34 --------- d-----w C:\Documents and Settings\HAMDA & HASSAN\Application Data\MEGAUPLOADTOOLBAR
2008-05-15 20:49 --------- d-----w C:\Program Files\ShredderChess
2008-05-09 23:05 --------- d-----w C:\Documents and Settings\MOE\Application Data\Yahoo!
2008-05-09 23:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-05-03 19:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-05-03 19:46 --------- d-----w C:\Program Files\Yahoo!
2008-04-29 15:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 15:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 15:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-27 01:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-26 14:53 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-24 13:03 20,240 ----a-w C:\Documents and Settings\HASSAN\Application Data\GDIPFONTCACHEV1.DAT
2008-04-22 23:25 --------- d-----w C:\Documents and Settings\HAMDA & HASSAN\Application Data\Hamachi
2008-04-22 20:01 --------- d-----w C:\Documents and Settings\MOE\Application Data\Hamachi
2008-04-21 14:26 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-04-19 20:50 --------- d-----w C:\Program Files\Bookup
2008-04-17 01:03 --------- d-----w C:\Program Files\Arena
2008-04-14 11:48 19,456 -c--a-w C:\Documents and Settings\MOE\Application Data\GDIPFONTCACHEV1.DAT
2008-04-09 11:41 --------- d-----w C:\Documents and Settings\MOE\Application Data\Internet Chess Club
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-01-06 16:30 77 ----a-w C:\Documents and Settings\MOE\3289.bat
2008-01-05 21:17 77 ----a-w C:\Documents and Settings\MOE\2091.bat
2008-01-05 10:46 77 ----a-w C:\Documents and Settings\MOE\4743.bat
2008-01-05 04:26 77 ----a-w C:\Documents and Settings\MOE\8540.bat
2008-01-04 21:17 77 ----a-w C:\Documents and Settings\MOE\5392.bat
2008-01-04 16:10 77 ----a-w C:\Documents and Settings\MOE\3685.bat
2008-01-04 02:17 77 ----a-w C:\Documents and Settings\MOE\3004.bat
2008-01-03 23:20 77 ----a-w C:\Documents and Settings\MOE\2485.bat
2008-01-03 19:38 77 ----a-w C:\Documents and Settings\MOE\3090.bat
2008-01-03 01:00 77 ----a-w C:\Documents and Settings\MOE\6339.bat
2008-01-02 15:31 77 ----a-w C:\Documents and Settings\MOE\2779.bat
2008-01-02 04:22 249 ----a-w C:\Documents and Settings\MOE\4299.bat
2008-01-01 16:22 77 ----a-w C:\Documents and Settings\MOE\8192.bat
2008-01-01 04:53 249 ----a-w C:\Documents and Settings\MOE\6407.bat
2008-01-01 03:03 77 ----a-w C:\Documents and Settings\MOE\9181.bat
2008-01-01 03:02 249 ----a-w C:\Documents and Settings\MOE\2240.bat
2007-12-31 23:32 77 ----a-w C:\Documents and Settings\MOE\7081.bat
2007-12-31 23:31 249 ----a-w C:\Documents and Settings\MOE\4334.bat
2007-12-31 18:48 77 ----a-w C:\Documents and Settings\MOE\8717.bat
2007-12-31 15:31 77 ----a-w C:\Documents and Settings\MOE\2391.bat
2007-12-31 15:30 249 ----a-w C:\Documents and Settings\MOE\8664.bat
2007-12-30 22:41 77 ----a-w C:\Documents and Settings\MOE\6444.bat
2007-12-30 22:40 249 ----a-w C:\Documents and Settings\MOE\5502.bat
2007-12-30 19:53 77 ----a-w C:\Documents and Settings\MOE\3536.bat
2007-12-30 19:53 249 ----a-w C:\Documents and Settings\MOE\9136.bat
2007-12-30 19:09 77 ----a-w C:\Documents and Settings\MOE\5050.bat
2007-12-30 19:09 249 ----a-w C:\Documents and Settings\MOE\6435.bat
2007-12-30 15:25 77 ----a-w C:\Documents and Settings\MOE\4543.bat
2007-12-30 15:24 249 ----a-w C:\Documents and Settings\MOE\7344.bat
2007-12-30 04:49 77 ----a-w C:\Documents and Settings\MOE\2766.bat
2007-12-30 04:49 249 ----a-w C:\Documents and Settings\MOE\7934.bat
2007-12-30 04:43 77 ----a-w C:\Documents and Settings\MOE\6463.bat
2007-12-30 04:43 249 ----a-w C:\Documents and Settings\MOE\3097.bat
2007-12-30 03:39 249 ----a-w C:\Documents and Settings\MOE\4425.bat
2007-12-30 01:45 249 ----a-w C:\Documents and Settings\MOE\4170.bat
2007-12-29 13:44 77 ----a-w C:\Documents and Settings\MOE\8442.bat
2007-10-25 22:17 78,184 -c--a-w C:\Documents and Settings\HAMDA & HASSAN\Application Data\GDIPFONTCACHEV1.DAT
2007-01-27 22:33 524,300 -c--a-w C:\Documents and Settings\MOE\Application Data\position.bin
2005-05-12 01:10 66,576 -c--a-w C:\Documents and Settings\Guest\Application Data\GDIPFONTCACHEV1.DAT
2005-03-11 00:06 66,576 -c--a-w C:\Documents and Settings\ANYONE ELSE\Application Data\GDIPFONTCACHEV1.DAT
2007-08-09 18:08 8,784 ----a-w C:\Program Files\mozilla firefox\plugins\ractrlkeyhook.dll
2007-08-09 18:10 245,408 ----a-w C:\Program Files\mozilla firefox\plugins\unicows.dll
2007-05-19 23:30 168 --sh--r C:\WINDOWS\system32\8A66670798.sys
2007-03-31 18:20 56 --sh--r C:\WINDOWS\system32\980767668A.sys
2007-06-12 03:07 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2005-07-29 21:24 472 --sha-r C:\WINDOWS\TU9FIA\no6IKE.vbs
.
((((((((((((((((((((((((((((( snapshot@2008-06-05_17.07.48.56 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-05 20:55:18 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-08 14:21:52 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-05-08 20:38:23 407,004 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat
+ 2008-06-06 21:38:11 213,488 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"Free Registry Fix"="C:\Program Files\Promosoft Corporation\Free Registry Fix\regfix.exe" [ ]
"Uniblue SpeedUpMyPC"="C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-02 20:58 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-11-15 18:46 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= jl_mjpg2.drv
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Fantastic Flame Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Fantastic Flame Agent.lnk
backup=C:\WINDOWS\pss\Fantastic Flame Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^palstart.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\palstart.exe
backup=C:\WINDOWS\pss\palstart.exeCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^MOE^Start Menu^Programs^Startup^Morpheus.lnk]
path=C:\Documents and Settings\MOE\Start Menu\Programs\Startup\Morpheus.lnk
backup=C:\WINDOWS\pss\Morpheus.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^MOE^Start Menu^Programs^Startup^PalNetaware.lnk]
path=C:\Documents and Settings\MOE\Start Menu\Programs\Startup\PalNetaware.lnk
backup=C:\WINDOWS\pss\PalNetaware.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
--a------ 2004-04-08 10:56 496752 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
C:\Program Files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
--a------ 2007-02-27 17:04 262184 C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDElbyCDFL]
C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 08:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Freedom]
C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasServ]
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Host Process]
C:\WINDOWS\Fonts\svchost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2002-10-16 02:05 114688 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\I&F Viewer toolbar]
--a------ 2006-10-27 21:34 65536 C:\Program Files\Photo Toolkit\ivbar\phototoolkitmem.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2002-10-16 02:18 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-06-10 10:44 249856 c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-06-10 11:44 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-09-07 16:55 267064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
--a------ 2003-08-19 06:43 57344 C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
--a------ 2005-03-09 20:10 11776 C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
--a------ 2005-03-09 20:10 110592 C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
-ra------ 2001-07-09 06:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
C:\Program Files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
--a------ 2002-10-23 13:15 86016 c:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 06:24 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rqx1evùõš/‚²‘ÆßfÏNC:]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rqx1evùõš/‚²‘ÆßfÏNC:\Program Files]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rqx1evùõš/‚²‘ÆßfÏNC:\Program Files\ISTsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rqx1evùõš/‚²‘ÆßfÏNC:\Program Files\ISTsvc\istsvc.exe]
C:\WINDOWS\bdubyd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Simpleology 1.0]
C:\Program Files\Simpleology\Wimiki\wimiki.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SNM]
C:\Program Files\SpyNoMore\SNM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2003-04-24 16:53 54784 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
C:\Program Files\Spyware Doctor\swdoctor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2006-10-12 04:10 49263 C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-02-02 20:58 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Kh'þ9Óœ÷3rÅWC:]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Kh'þ9Óœ÷3rÅWC:\Program Files]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Kh'þ9Óœ÷3rÅWC:\Program Files\ISTsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Kh'þ9Óœ÷3rÅWC:\Program Files\ISTsvc\istsvc.exe]
C:\WINDOWS\bdubyd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SvcProc"=2 (0x2)
"MDM"=2 (0x2)
"LexBceS"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"AOL ACS"=2 (0x2)
"gusvc"=3 (0x3)
"SDhelper"=2 (0x2)
"usnjsvc"=3 (0x3)
"NetSvc"=3 (0x3)
"AntiVirService"=2 (0x2)
"AntiVirScheduler"=2 (0x2)
"GoogleDesktopManager"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"DomainService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"LogMeIn GUI"="D:\x86\LogMeInSystray.exe"
"LSA Shellu"=C:\Documents and Settings\MOE\lsass.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Arena\\Timeseal.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MSN Messenger\\msrr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"21847:TCP"= 21847:TCP:BitComet 21847 TCP
"21847:UDP"= 21847:UDP:BitComet 21847 UDP
"56979:TCP"= 56979:TCP:AresChatServer
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-08-03 15:09]
R3 iANSMiniport;Intel® Advanced Network Services Virtual Adapter;C:\WINDOWS\system32\DRIVERS\ianswxp.sys [2002-10-09 23:21]
S2 CachemanXPService;CachemanXP;C:\PROGRA~1\CACHEM~1\CachemanXP.exe [2008-04-30 19:54]
S2 LMIInfo;LogMeIn Kernel Information Provider;D:\x86\RaInfo.sys []
S3 iANSProtocol;Intel® Advanced Network Services Protocol;C:\WINDOWS\system32\DRIVERS\ianswxp.sys [2002-10-09 23:21]
S3 JL2005;JL2005A Toy Camera;C:\WINDOWS\system32\Drivers\toywdm.sys [2004-06-04 14:21]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2002-10-16 03:11]
S3 SE31bus;Sony Ericsson Device 049 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE31bus.sys [2006-05-01 14:56]
S3 SE31mdfl;Sony Ericsson Device 049 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE31mdfl.sys [2006-05-01 14:57]
S3 SE31mdm;Sony Ericsson Device 049 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE31mdm.sys [2006-05-01 14:57]
S3 SE31mgmt;Sony Ericsson Device 049 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE31mgmt.sys [2006-05-01 14:58]
S3 se31nd5;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (NDIS);C:\WINDOWS\system32\DRIVERS\se31nd5.sys [2006-05-01 07:56]
S3 SE31obex;Sony Ericsson Device 049 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE31obex.sys [2006-05-01 14:59]
S3 se31unic;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (WDM);C:\WINDOWS\system32\DRIVERS\se31unic.sys [2006-05-01 14:56]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-06 00:03:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-06 22:00:08 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2008-05-30 20:13:13 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-05-28 23:47:54 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-08 14:17:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-08 14:24:30
ComboFix-quarantined-files.txt 2008-06-08 18:24:28
ComboFix2.txt 2008-06-08 18:13:54
ComboFix3.txt 2008-06-06 22:37:26
ComboFix4.txt 2008-06-06 22:10:53
ComboFix5.txt 2008-06-06 20:53:58
Pre-Run: 52,841,558,016 bytes free
Post-Run: 52,827,451,392 bytes free
342 --- E O F --- 2008-05-28 03:38:03