Ok Ran everything, got no errors on startup and it was a bit faster than normal. If that ends up being it I'm gonna have to ban the kids from playing on my comp
ComboFix 08-06-20.4 - Mine 2008-06-24 19:23:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1411 [GMT -4:00]
Running from: C:\Documents and Settings\Mine\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Mine\Application Data\inst.exe
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-05-24 to 2008-06-24 )))))))))))))))))))))))))))))))
.
2008-06-24 19:20 . 2008-06-24 19:20 <DIR> d-------- C:\_OTMoveIt
2008-06-24 15:18 . 2008-06-24 15:18 <DIR> d-------- C:\VundoFix Backups
2008-06-24 15:04 . 2008-06-24 15:05 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-24 15:04 . 2008-06-24 15:04 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-06-24 15:04 . 2008-06-24 15:04 <DIR> d-------- C:\Documents and Settings\Mine\Application Data\Malwarebytes
2008-06-24 15:04 . 2008-06-24 15:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-24 15:04 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-24 15:04 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-24 14:36 . 2008-06-24 14:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-24 13:32 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-06-23 23:04 . 2008-06-23 23:04 <DIR> d-------- C:\WINDOWS\Fitness Frenzy
2008-06-23 23:04 . 2008-06-23 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Fitn17
2008-06-23 20:35 . 2008-06-24 13:50 <DIR> d-------- C:\Program Files\Switlle
2008-06-23 00:07 . 2008-06-23 00:07 <DIR> d-------- C:\Documents and Settings\Mine\Application Data\Leadertech
2008-06-23 00:05 . 2008-06-23 00:05 <DIR> d-------- C:\Program Files\NovaLogic
2008-06-22 23:33 . 2008-06-22 23:55 588 --a------ C:\WINDOWS\_delis43.ini
2008-06-22 20:08 . 2008-06-22 20:12 <DIR> d-------- C:\temp\CheetahAudio
2008-06-22 17:09 . 2008-06-22 20:08 <DIR> d-------- C:\temp
2008-06-22 17:04 . 2008-06-22 17:04 <DIR> d-------- C:\Program Files\ABBYY FineReader 6.0
2008-06-22 17:04 . 2008-06-22 17:04 <DIR> d-------- C:\Program Files\ABBYY FineReader 5.0 Sprint
2008-06-22 17:01 . 2008-06-22 17:07 215 --a------ C:\WINDOWS\lexstat.ini
2008-06-22 17:01 . 2008-06-22 17:01 76 --a------ C:\WINDOWS\dellstat.ini
2008-06-22 17:00 . 2008-06-22 17:00 <DIR> d-------- C:\Program Files\Lexmark 1200 Series
2008-06-22 17:00 . 2001-08-17 22:36 87,040 --a------ C:\WINDOWS\system32\wiafbdrv.dll
2008-06-22 17:00 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-06-21 18:50 . 2008-06-21 18:50 896 --a------ C:\WINDOWS\system32\history.aaw
2008-06-20 22:06 . 2008-06-20 22:06 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-06-20 14:22 . 2008-06-20 04:37 102,400 --a------ C:\WINDOWS\system32\Font.exe
2008-06-20 14:21 . 2007-07-30 14:44 3,518,464 --a------ C:\WINDOWS\system32\cdintf300.dll
2008-06-20 14:21 . 2007-06-28 14:09 1,843,200 --a------ C:\WINDOWS\system32\acXMLParser.dll
2008-06-20 14:17 . 2008-06-20 14:17 <DIR> d-------- C:\Program Files\Intuit
2008-06-20 14:17 . 2008-06-20 14:19 <DIR> d-------- C:\Program Files\Common Files\Intuit
2008-06-20 14:17 . 2008-06-21 19:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Intuit
2008-06-20 14:15 . 2008-06-20 14:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\COMMON FILES
2008-06-20 13:35 . 2008-06-23 21:25 <DIR> d-------- C:\Program Files\FitDay
2008-06-19 15:27 . 2008-06-19 15:27 <DIR> d-------- C:\Program Files\Vision Video Games
2008-06-19 11:19 . 2008-06-19 11:19 <DIR> d-------- C:\WINDOWS\Build in Time
2008-06-18 15:08 . 2008-06-18 15:08 <DIR> d-------- C:\Documents and Settings\Mine\Application Data\InstallShield
2008-06-17 22:12 . 2008-06-17 22:12 <DIR> d-------- C:\Program Files\SEGA
2008-06-17 12:33 . 2008-06-17 12:33 <DIR> d-------- C:\Documents and Settings\Mine\Application Data\Texture Maker
2008-06-17 12:32 . 2008-06-17 12:43 <DIR> d-------- C:\Program Files\Texture Maker
2008-06-17 10:52 . 2008-06-24 14:07 20 --a------ C:\WINDOWS\system32\PDBootState
2008-06-17 10:43 . 2008-06-17 10:43 <DIR> d-------- C:\Program Files\Raxco
2008-06-17 10:43 . 2008-06-17 10:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Raxco
2008-06-17 10:43 . 2008-04-10 12:08 71,184 -ra------ C:\WINDOWS\system32\drivers\DefragFS.sys
2008-06-14 23:00 . 2008-06-18 15:09 <DIR> d-------- C:\Program Files\Frets on Fire
2008-06-14 22:59 . 2008-06-24 16:06 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-13 21:26 . 2008-06-13 21:26 <DIR> d-------- C:\Program Files\IObit
2008-06-13 20:57 . 2008-06-13 20:57 0 ---hs---- C:\WINDOWS\S02897D68.tmp
2008-06-13 20:56 . 2008-06-24 13:59 <DIR> d-------- C:\Program Files\Elaborate Bytes
2008-06-13 17:08 . 2008-06-24 13:59 <DIR> d-------- C:\Program Files\Trillian
2008-06-13 16:33 . 2008-06-13 16:33 0 --a------ C:\WINDOWS\WB.ini
2008-06-13 06:49 . 2008-06-13 06:49 <DIR> d-------- C:\Program Files\Ubisoft
2008-06-13 06:23 . 2008-06-13 06:23 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-06-13 06:23 . 2008-06-13 06:32 <DIR> d-------- C:\Program Files\GameShadow
2008-06-13 06:03 . 2008-06-13 06:03 <DIR> d-------- C:\Program Files\Download Manager
2008-06-13 06:03 . 2008-06-13 06:43 <DIR> d-------- C:\Documents and Settings\Mine\Application Data\IGN_DLM
2008-06-13 04:10 . 2008-06-13 04:12 <DIR> d--h----- C:\Program Files\Zero G Registry
2008-06-13 04:09 . 2008-06-13 04:09 <DIR> d--h----- C:\Documents and Settings\Mine\InstallAnywhere
2008-06-13 03:58 . 2008-06-13 03:59 <DIR> d-------- C:\Program Files\QuickTime
2008-06-13 03:58 . 2008-06-13 03:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-13 03:57 . 2008-06-13 03:57 <DIR> d-------- C:\Program Files\Apple Software Update
2008-06-13 03:57 . 2008-06-13 03:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-06-12 20:28 . 2008-06-12 20:28 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-06-12 20:24 . 2008-06-12 20:24 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-06-12 06:09 . 2008-06-12 06:09 27 --a------ C:\WINDOWS\SDAddressBox1633cb8581916.ini
2008-06-12 06:04 . 2008-06-12 06:09 27 --a------ C:\WINDOWS\SDAddressBox16827d0561119.ini
2008-06-12 06:02 . 2008-06-12 06:02 7,852 --a------ C:\WINDOWS\system32\mcdmsg7.dll
2008-06-12 05:44 . 2007-07-11 15:06 42,672 --a------ C:\WINDOWS\system32\wbsys.dll
2008-06-12 05:42 . 2008-06-12 05:42 <DIR> d-------- C:\Program Files\Stardock
2008-06-12 05:42 . 2008-06-12 05:59 <DIR> d-------- C:\Program Files\Common Files\Stardock
2008-06-12 05:42 . 2002-02-15 15:02 1,326,080 --a------ C:\WINDOWS\system32\vcl60.bpl
2008-06-12 05:42 . 2002-02-15 15:02 676,352 --a------ C:\WINDOWS\system32\rtl60.bpl
2008-06-12 05:29 . 2008-06-12 06:28 <DIR> d-------- C:\Program Files\VSO
2008-06-12 05:29 . 2008-06-12 06:28 <DIR> d-------- C:\Documents and Settings\Mine\Application Data\Vso
2008-06-12 05:29 . 2006-09-29 11:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll
2008-06-12 05:29 . 2006-09-29 11:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll
2008-06-12 05:29 . 2006-09-29 11:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll
2008-06-12 05:29 . 2008-06-12 05:29 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-06-12 05:29 . 2008-06-12 06:28 47,360 --a------ C:\Documents and Settings\Mine\Application Data\pcouffin.sys
2008-06-11 14:01 . 2008-06-11 14:01 <DIR> d-------- C:\Documents and Settings\Mine\Application Data\Windows Desktop Search
2008-06-11 14:01 . 2008-06-11 14:01 1,912 --a------ C:\bar.emf
2008-06-11 13:57 . 2008-06-11 13:57 <DIR> d-------- C:\Program Files\Windows Desktop Search
2008-06-11 13:56 . 2006-09-15 08:36 192,000 --------- C:\WINDOWS\system32\dllcache\offfilt.dll
2008-06-11 13:56 . 2006-09-15 08:36 98,304 --------- C:\WINDOWS\system32\dllcache\nlhtml.dll
2008-06-11 13:56 . 2006-09-15 08:36 29,696 --------- C:\WINDOWS\system32\dllcache\mimefilt.dll
2008-06-10 22:35 . 2008-06-10 22:35 663 --a------ C:\WINDOWS\eReg.dat
2008-06-10 22:07 . 2008-06-17 18:13 <DIR> d-------- C:\Program Files\Total War
2008-06-10 22:02 . 1998-10-29 15:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-06-10 21:54 . 2008-06-10 21:54 <DIR> d-------- C:\Program Files\MagicISO
2008-06-10 21:51 . 2008-06-10 21:51 <DIR> d-------- C:\Program Files\PowerISO
2008-06-10 21:51 . 2004-04-30 09:37 160,640 --a------ C:\WINDOWS\system32\drivers\a347bus.sys
2008-06-10 21:51 . 2004-04-30 09:33 5,248 --a------ C:\WINDOWS\system32\drivers\a347scsi.sys
2008-06-10 21:50 . 2008-06-10 21:50 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-06-10 21:44 . 2008-06-10 21:44 <DIR> d-------- C:\Program Files\Collectorz.com
2008-06-10 21:42 . 2008-06-10 21:42 <DIR> d-------- C:\Program Files\CoffeeCup Software
2008-06-10 21:42 . 2006-01-27 01:56 938,272 --a------ C:\WINDOWS\system32\wodFtpDLX.OCX
2008-06-10 21:39 . 2005-11-14 05:23 1,228,800 --a------ C:\WINDOWS\system32\FoxBurner.ocx
2008-06-10 21:39 . 2007-07-31 12:57 1,164,728 --a------ C:\WINDOWS\system32\NMSDVDXU.dll
2008-06-10 21:39 . 2004-02-08 15:53 856,064 --a------ C:\WINDOWS\system32\mpgfiltr.ax
2008-06-10 21:39 . 2005-01-19 00:44 454,656 --a------ C:\WINDOWS\system32\FoxDVDImager.ocx
2008-06-10 21:39 . 2002-03-25 03:03 380,928 --a------ C:\WINDOWS\system32\CDRipperX.ocx
2008-06-10 21:39 . 2007-04-06 00:08 196,608 --a------ C:\WINDOWS\system32\VideoEdit.ocx
2008-06-10 21:39 . 2003-08-19 04:31 81,920 --a------ C:\WINDOWS\system32\viscomwave.dll
2008-06-10 21:38 . 2008-06-10 21:38 <DIR> d-------- C:\Program Files\Cheetah Burner
2008-06-10 21:38 . 2003-12-17 16:00 1,208,320 --a------ C:\WINDOWS\system32\PTxSCP.ocx
2008-06-10 21:38 . 2000-05-22 22:58 608,448 --a------ C:\WINDOWS\system32\comctl32.ocx
2008-06-10 21:38 . 2005-01-19 00:18 323,584 --a------ C:\WINDOWS\system32\FoxImager.dll
2008-06-10 21:38 . 1998-06-18 00:00 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL
2008-06-10 21:16 . 2008-06-10 21:16 <DIR> d-------- C:\Program Files\Alien Skin
2008-06-10 20:43 . 2008-06-10 20:43 <DIR> d-------- C:\Program Files\Bonjour
2008-06-10 20:15 . 2008-06-10 20:15 <DIR> d-------- C:\Program Files\Screensaver Factory 4 Enterprise
2008-06-10 20:15 . 2008-06-10 20:15 <DIR> d-------- C:\Documents and Settings\Mine\Application Data\Blumentals
2008-06-10 19:49 . 2008-06-10 19:49 162 --a------ C:\WINDOWS\ODBC.INI
2008-06-10 19:46 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-06-10 19:44 . 2008-06-10 19:44 <DIR> d-------- C:\Program Files\Microsoft Works
2008-06-10 19:41 . 2008-06-10 19:41 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-06-10 19:38 . 2008-06-10 19:38 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-06-10 19:37 . 2008-06-10 19:42 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-06-10 18:45 . 2008-06-12 20:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-10 18:44 . 2008-06-10 18:44 <DIR> dr-h----- C:\MSOCache
2008-06-10 18:32 . 2008-06-10 18:32 <DIR> d-------- C:\Program Files\Codemasters
2008-06-10 18:29 . 2008-06-10 18:29 <DIR> d-------- C:\Documents and Settings\Mine\Application Data\Likno
2008-06-10 18:28 . 2008-06-10 18:29 <DIR> d-------- C:\Program Files\AllWebMenus4
2008-06-10 18:28 . 1998-04-24 01:00 368,912 --a------ C:\WINDOWS\system32\vbar332.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-15 03:40 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-10 18:13 --------- d-----w C:\Program Files\RocketDock
2008-06-10 11:52 --------- d-----w C:\Documents and Settings\Mine\Application Data\Media Player Classic
2008-06-10 11:32 --------- d-----w C:\Program Files\XP Codec Pack
2008-06-10 11:27 --------- d-----w C:\Documents and Settings\Mine\Application Data\Talkback
2008-06-10 11:22 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-06-10 11:16 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-08 12:14 203,008 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-03 02:46 6,554,496 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-04-29 15:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 15:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 15:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 21:56 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 19:03 152872]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40 1421824]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-09-02 13:58 495616]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 17:57 1103480]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2008-06-10 14:10 219952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"BrStsWnd"="C:\Program Files\Brownie\BrstsWnd.exe" [2007-07-31 20:37 815104]
"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-02-15 16:10 57344]
"P17Helper"="P17.dll" [2005-05-02 23:38 64512 C:\WINDOWS\system32\P17.dll]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 14:49 36352]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 22:46 624248]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"Lexmark 1200 Series"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 01:22 57344]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-04-22 23:35 124928 C:\WINDOWS\system32\advpack.dll]
"ShowDeskFix"="regsvr32" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-09-11 08:38:44 972064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"= 1 (0x1)
"HideRunAsVerb"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 15:39 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 2008-06-12 05:48 229376 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Intuit\\QuickBooks Enterprise Solutions 8.0\\QBDBMgrN.exe"=
R2 PD91Agent;PD91Agent;"C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe" [2008-04-16 13:00]
S3 PD91Engine;PD91Engine;"C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe" [2008-04-16 13:00]
.
Contents of the 'Scheduled Tasks' folder
"2008-06-15 05:00:01 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-06-10 19:08:55 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-24 19:27:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\RocketDock\RocketDock.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\Program Files\McAfee\VirusScan\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\searchindexer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\searchprotocolhost.exe
C:\WINDOWS\system32\searchfilterhost.exe
.
**************************************************************************
.
Completion time: 2008-06-24 19:32:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-24 23:31:49
Pre-Run: 102,833,864,704 bytes free
Post-Run: 102,738,042,880 bytes free
289 --- E O F --- 2008-06-13 00:33:06
____________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:39:30 PM, on 6/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe Autorun
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0EC4C9E3-EC6A-11CF-8E3B-444553540000} (WaveTab Control) - file:///G:/setup/RiffLick.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) -
http://www.fileplane...C_2.3.6.108.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 8.0\HelpAsyncPluggableProtocol.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Uninterruptible Power Supply (UPS) - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
--
End of file - 10321 bytes