than the Combofix log
ComboFix 08-08-14.05 - Mike 2008-08-15 20:38:24.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1555 [GMT 2:00]
Running from: C:\Documents and Settings\Mike\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mike\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\byXrsRJa.dll
C:\WINDOWS\system32\dnhaytpw.ini
C:\WINDOWS\system32\fccdEVPI.dll
C:\WINDOWS\system32\IPVEdccf.ini
C:\WINDOWS\system32\IPVEdccf.ini2
C:\WINDOWS\system32\tuvVLcyw.dll
C:\WINDOWS\system32\wptyahnd.dll
----- BITS: Possible infected sites -----
http://pornotube8.net.
((((((((((((((((((((((((( Files Created from 2008-07-15 to 2008-08-15 )))))))))))))))))))))))))))))))
.
2008-08-15 13:38 . 2008-08-15 13:38 <DIR> d-------- C:\Program Files\Lavasoft
2008-08-15 13:38 . 2008-08-15 13:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-14 22:47 . 2008-08-15 18:48 2,402 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-14 21:19 . 2008-08-14 21:19 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-14 20:54 . 2008-08-14 20:58 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-08-14 20:54 . 2008-08-14 20:54 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-08-14 20:54 . 2008-08-14 20:54 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\PC Tools
2008-08-14 20:54 . 2008-08-14 20:58 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-14 20:54 . 2008-08-14 20:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-08-14 20:54 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-08-14 20:54 . 2007-02-23 00:09 83,536 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-08-14 20:54 . 2007-02-25 23:45 59,472 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-08-14 20:54 . 2007-02-19 18:13 52,304 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-08-14 20:54 . 2007-02-19 18:13 39,248 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
2008-08-14 20:54 . 2007-02-23 07:13 26,064 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-08-14 20:10 . 2008-08-14 20:10 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\MAGIX
2008-08-14 20:10 . 2001-05-11 13:18 420,240 --a------ C:\WINDOWS\system32\mpg4c32.dll
2008-08-14 20:10 . 2001-05-16 17:54 309,616 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2008-08-14 20:10 . 2001-03-26 04:41 245,760 --a------ C:\WINDOWS\system32\mp4sds32.ax
2008-08-14 20:10 . 2008-08-14 20:10 28 --a------ C:\WINDOWS\Robota.INI
2008-08-14 20:09 . 2008-08-14 20:19 <DIR> d-------- C:\Program Files\MAGIX
2008-08-14 20:09 . 2008-08-14 20:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MAGIX
2008-08-14 20:08 . 2008-08-14 20:19 <DIR> d-------- C:\WINDOWS\system32\MAGIX
2008-08-14 20:08 . 2008-04-15 16:14 700,416 --a------ C:\WINDOWS\system32\mgxoschk.dll
2008-08-14 20:08 . 2008-08-14 20:10 5,937 --a------ C:\WINDOWS\mgxoschk.ini
2008-08-14 18:13 . 2005-05-18 11:52 1,212,416 --a------ C:\WINDOWS\system32\NCTAudioInformation2.dll
2008-08-14 18:13 . 2005-04-04 17:21 602,112 --a------ C:\WINDOWS\system32\NCTAudioTransform2.dll
2008-08-14 18:13 . 2005-03-28 15:54 479,232 --a------ C:\WINDOWS\system32\NCTAudioVisualization2.dll
2008-08-14 18:13 . 2005-04-25 13:01 458,752 --a------ C:\WINDOWS\system32\NCTAudioRecord2.dll
2008-08-14 18:13 . 2005-04-25 13:01 458,752 --a------ C:\WINDOWS\system32\NCTAudioPlayer2.dll
2008-08-14 18:13 . 2005-03-28 15:52 417,792 --a------ C:\WINDOWS\system32\NCTTextToAudio2.dll
2008-08-14 18:13 . 2005-02-24 11:51 348,160 --a------ C:\WINDOWS\system32\NCTWMAFile2.dll
2008-08-14 18:13 . 2006-03-23 12:56 113,486 --a------ C:\WINDOWS\system32\NCTWMAProfiles.prx
2008-08-14 18:12 . 2008-08-14 18:14 <DIR> d-------- C:\Program Files\Free Sound Recorder
2008-08-14 18:12 . 2005-05-17 12:37 1,986,560 --a------ C:\WINDOWS\system32\NCTAudioFile2.dll
2008-08-14 18:12 . 2005-04-15 12:08 880,640 --a------ C:\WINDOWS\system32\NCTAudioEditor2.dll
2008-08-14 18:12 . 2004-11-04 13:31 835,584 --a------ C:\WINDOWS\system32\NCTAudioCDGrabber2.dll
2008-08-14 18:12 . 2002-01-05 16:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-08-14 17:51 . 2008-08-14 17:51 <DIR> d-------- C:\Program Files\NCH Software
2008-08-14 17:50 . 2008-08-14 17:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-08-14 17:48 . 2008-08-14 18:14 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-08-14 17:48 . 2008-08-14 18:13 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\NCH Swift Sound
2008-08-14 17:48 . 2008-08-14 17:48 27,136 --a------ C:\WINDOWS\system32\drivers\nchssvad.sys
2008-08-12 22:39 . 2008-08-12 22:46 <DIR> d-------- C:\Program Files\PhotoScape
2008-08-12 21:28 . 2008-08-12 21:28 <DIR> d-------- C:\Program Files\Jasc Software Inc
2008-08-12 21:28 . 2008-08-12 21:28 <DIR> d-------- C:\Program Files\Common Files\Jasc Software Inc
2008-08-12 21:28 . 2008-08-12 21:28 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\Jasc Software Inc
2008-08-12 21:28 . 2008-08-12 21:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-08-11 23:52 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-08-11 23:52 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-08-11 23:52 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-08-11 23:52 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-08-11 22:36 . 2008-08-11 22:36 <DIR> d-------- C:\Program Files\Red Kawa
2008-08-11 22:36 . 2008-08-11 22:36 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-08-10 23:16 . 2008-08-10 23:16 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-10 16:57 . 2008-08-15 14:02 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\AdobeUM
2008-08-10 14:00 . 2008-08-10 15:06 <DIR> d-------- C:\Program Files\Cossacks
2008-08-10 14:00 . 2002-04-22 13:30 4,284,416 -ra------ C:\WINDOWS\uncsetup.exe
2008-08-10 14:00 . 2008-08-10 14:00 53,248 --a------ C:\WINDOWS\system32\unrar.dll
2008-08-10 02:46 . 2008-08-10 02:46 <DIR> d-------- C:\Program Files\Logitech
2008-08-10 02:46 . 2008-08-10 02:50 <DIR> d-------- C:\Program Files\Common Files\LogiShrd
2008-08-10 02:46 . 2008-08-10 02:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-08-10 02:46 . 2008-08-10 02:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logishrd
2008-08-09 19:42 . 2008-08-15 17:51 941 --a------ C:\WINDOWS\system32\%LocalXml%
2008-08-09 01:10 . 2008-08-09 03:12 <DIR> d-------- C:\Program Files\9Dragons
2008-08-09 00:35 . 2008-08-09 00:35 74,081 --a------ C:\FRUITYLOOPS.STUDIO.PRODUCER.EDITION.XXL.V8.0.0.EXE
2008-08-09 00:33 . 2008-08-09 00:33 <DIR> d-------- C:\Program Files\VstPlugins
2008-08-09 00:33 . 2008-08-09 00:33 <DIR> d-------- C:\Program Files\ASIO4ALL v2
2008-08-09 00:33 . 2002-07-08 00:14 1,294,336 --a------ C:\WINDOWS\system32\vorbis.acm
2008-08-09 00:33 . 2006-06-20 10:56 225,280 --a------ C:\WINDOWS\system32\rewire.dll
2008-08-09 00:32 . 2008-08-09 00:32 <DIR> d-------- C:\Program Files\Outsim
2008-08-09 00:31 . 2008-08-14 18:06 <DIR> d-------- C:\Program Files\Image-Line
2008-08-08 23:54 . 2008-08-08 23:54 4,096 --a------ C:\WINDOWS\system32\crash
2008-08-08 23:47 . 2008-08-08 23:55 <DIR> d-------- C:\Program Files\ATITool
2008-08-07 22:51 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-08-07 22:51 . 2004-08-03 23:08 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-08-07 22:50 . 2008-08-07 22:50 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-08-07 22:50 . 2008-08-07 22:50 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-08-07 22:49 . 2008-08-07 22:51 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\PC Suite
2008-08-07 22:49 . 2008-08-07 22:51 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\Nokia
2008-08-07 22:49 . 2008-08-07 22:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Suite
2008-08-07 22:48 . 2008-08-07 22:48 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-08-07 22:48 . 2008-08-07 22:48 <DIR> d-------- C:\Program Files\Nokia
2008-08-07 22:48 . 2008-08-07 22:48 <DIR> d-------- C:\Program Files\DIFX
2008-08-07 22:48 . 2008-08-07 22:48 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-08-07 22:48 . 2008-08-07 22:48 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-08-07 22:48 . 2008-05-07 07:39 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-08-07 22:48 . 2008-05-07 07:38 659,968 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-08-07 22:48 . 2008-05-07 07:38 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2008-08-07 22:48 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-08-07 22:48 . 2008-05-07 07:38 20,864 --a------ C:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-08-07 22:48 . 2008-05-07 07:38 17,536 --a------ C:\WINDOWS\system32\drivers\ccdcmb.sys
2008-08-07 22:48 . 2008-05-07 07:38 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
2008-08-07 22:48 . 2008-06-06 09:24 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-08-07 22:47 . 2008-08-07 22:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Installations
2008-08-07 21:35 . 2008-08-07 21:35 <DIR> d-------- C:\Program Files\Belarc
2008-08-07 21:35 . 2008-02-27 13:49 3,840 --a------ C:\WINDOWS\system32\drivers\BANTExt.sys
2008-08-07 21:15 . 2008-08-07 21:15 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-08-07 21:15 . 2008-08-10 20:26 162,008 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-08-07 21:15 . 2008-08-10 20:26 111,928 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-08-07 21:15 . 2008-08-07 21:15 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-08-07 21:08 . 2008-08-07 21:08 <DIR> d--h----- C:\WINDOWS\PIF
2008-08-07 21:00 . 2008-08-07 21:14 <DIR> d-------- C:\Program Files\WarRock
2008-08-07 21:00 . 2008-08-07 21:00 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\InstallShield
2008-08-07 19:08 . 2008-08-15 19:37 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\OpenOffice.org2
2008-08-07 19:06 . 2008-08-07 19:06 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-08-07 00:02 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-08-07 00:02 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-08-07 00:02 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-08-06 00:00 . 2008-08-06 00:00 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\vlc
2008-08-05 23:01 . 2008-08-05 23:01 <DIR> d-------- C:\Program Files\VideoLAN
2008-08-05 22:59 . 2008-08-05 22:59 <DIR> d-------- C:\Nexon
2008-08-05 22:59 . 2008-08-05 22:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NexonUS
2008-08-05 22:05 . 2008-08-05 22:05 <DIR> d-------- C:\WINDOWS\Sun
2008-08-05 21:48 . 2008-08-05 21:48 <DIR> d-------- C:\Program Files\QuickTime
2008-08-05 21:48 . 2008-08-05 21:48 <DIR> d-------- C:\Program Files\iTunes
2008-08-05 21:48 . 2008-08-05 21:48 <DIR> d-------- C:\Program Files\iPod
2008-08-05 21:48 . 2008-08-05 21:48 <DIR> d-------- C:\Program Files\Bonjour
2008-08-05 21:48 . 2008-08-11 23:53 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\Apple Computer
2008-08-05 21:47 . 2008-08-05 21:47 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-08-05 21:47 . 2008-08-05 21:47 <DIR> d-------- C:\Program Files\Apple Software Update
2008-08-05 21:47 . 2008-08-05 21:47 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\FileSubmit
2008-08-05 21:47 . 2008-08-05 21:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-05 21:47 . 2008-08-05 21:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-08-05 21:47 . 2008-07-22 20:32 32,000 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-10 12:57 28,400 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2008-08-04 21:45 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-04 21:44 --------- d-----w C:\Program Files\Java
2008-08-04 21:44 --------- d-----w C:\Program Files\Common Files\Java
2008-07-04 06:33 3,230,720 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-07-04 02:28 53,248 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-06-20 10:44 360,960 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:32 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 16:00 1249280]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-06-18 14:31 1122816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0\bin\jusched.exe" [2008-08-04 23:44 36972]
"nTrayFw"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-07-18 17:08 270336]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 20:42 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 10:47 289064]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 16:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 16:37 2178832]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 18:21 201992]
"SoundMan"="SOUNDMAN.EXE" [2005-12-14 19:06 577536 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
C:\Documents and Settings\Mike\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 16:41:28 393216]
RK Launcher.lnk - C:\Documents and Settings\Mike\Desktop\RK_Launcher_041_Beta_Nightly\RKLauncher.exe [2008-08-05 22:07:16 708608]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispSettingPage"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"C:\Nexon\Combat Arms\CombatArms.exe"= C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Nexon\Combat Arms\Engine.exe"= C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 18:29]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 14:00]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 19:02]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 20:07]
R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\sis163u.sys [2005-06-20 09:12]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 15:18]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-08-05 21:41]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2008-08-15 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe [2008-01-08 13:31]
2008-08-05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\59z0sdd4.default\
FF -: plugin - C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJPI150.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPOJI610.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-15 20:56:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.bin
.
**************************************************************************
.
Completion time: 2008-08-15 21:00:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-15 19:00:43
Pre-Run: 132,911,583,232 bytes free
Post-Run: 132,993,507,328 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
289 --- E O F --- 2008-08-13 22:51:02