This is the fixwareout log
Username "Owner" - 2008-09-14 13:22:51 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdbca.exe"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.115.77 85.255.112.159" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{53BF5ECF-6CF8-42A4-A278-EBD7DA2C8C61}
"nameserver"="85.255.115.77,85.255.112.159" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{DBFF62AE-D80D-43CE-84EE-FE2E9198C0E2}
"nameserver"="85.255.115.77,85.255.112.159" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{2D5C8792-1B13-41D5-AAB6-51483AA699BD}
"DhcpNameServer"="85.255.115.77,85.255.112.159" <Value cleared.
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="C:\\HP\\KBD\\KBD.EXE"
"addbb32.exe"="C:\\WINDOWS\\system32\\addbb32.exe"
"v0zGjJ"="C:\\documents and settings\\owner\\local settings\\temp\\v0zGjJ.exe"
"winws.exe"="C:\\WINDOWS\\system32\\winws.exe"
"wLXi"="C:\\documents and settings\\owner\\local settings\\temp\\wLXi.exe"
"mswn32.exe"="C:\\WINDOWS\\system32\\mswn32.exe"
"netij32.exe"="C:\\WINDOWS\\system32\\netij32.exe"
"javaed.exe"="C:\\WINDOWS\\system32\\javaed.exe"
"KIiSvib"="C:\\documents and settings\\owner\\local settings\\temp\\KIiSvib.exe"
"AlcxMonitor"="ALCXMNTR.EXE"
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"sdknw.exe"="C:\\WINDOWS\\system32\\sdknw.exe"
"LTMSG"="LTMSG.exe 7"
"PS2"="C:\\WINDOWS\\system32\\ps2.exe"
"eeypkf"="c:\\windows\\system32\\tasgpc.exe"
"YLive.exe"="C:\\PROGRA~1\\Yahoo!\\ASSIST~1\\YLive.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"ISUSPM Startup"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"IMEKRMIG6.1"="C:\\WINDOWS\\ime\\imkr6_1\\IMEKRMIG.EXE"
"MSPY2002"="\"C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe\" /SYNC"
"PHIME2002ASync"="\"C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE\" /SYNC"
"PHIME2002A"="\"C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE\" /IMEName"
"{a8f70898-2302-f331-85c0-8feafc52bd03}"="C:\\WINDOWS\\System32\\Rundll32.exe \"C:\\WINDOWS\\system32\\vbsutiuvuk.dll\" DllStart"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"lphcvflj0eta5"="C:\\WINDOWS\\system32\\lphcvflj0eta5.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeper.exe\" /0"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_9 -reboot 1"
....
Hosts file was reset, If you use a custom hosts file please replace it...
C:\WINDOWS\System32\AUTOEXEC.NT missing
~~~~~ End report ~~~~~
llllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
llllllllllllllllllllll
This is the combofix log
ComboFix 08-09-13.05 - Owner 2008-09-14 13:54:27.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.193 [GMT -4:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\Owner\LOCALS~1\Temp\tmp1.tmp
C:\Documents and Settings\Owner\cookies\
[email protected][3].txt
C:\Documents and Settings\Owner\cookies\
[email protected][1].txt
C:\Documents and Settings\Owner\cookies\
[email protected][1].txt
C:\Documents and Settings\Owner\cookies\owner@turn[2].txt
C:\Documents and Settings\Owner\cookies\
[email protected][2].txt
C:\Program Files\Mozilla Firefox\components\nsBrowserGal.dll
C:\Program Files\yahoo!\assist~1
C:\Program Files\yahoo!\assist~1\Assist\CoolBar\prodef.ini
C:\Program Files\yahoo!\assist~1\Assist\CoolBar\profile.ini
C:\Program Files\yahoo!\assist~1\Assist\Images\adkiller.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\alert.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\alertnew.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\anitvirus.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\assist.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\clear.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\custheme.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\daoyan3.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\gouwu.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\hilight.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\iefix.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\logo.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\music.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\musiclink.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\musictop.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\picture.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\search.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\searchtop.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\settings.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\Thumbs.db
C:\Program Files\yahoo!\assist~1\Assist\Images\yphtb.bmp
C:\Program Files\yahoo!\assist~1\Assist\Images\yrss.bmp
C:\Program Files\yahoo!\assist~1\Assist\profile\1.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\10.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\11.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\13.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\14.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\15.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\16.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\17.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\18.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\19.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\20.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\22.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\23.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\3.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\6.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\7.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\8.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\9.gif
C:\Program Files\yahoo!\assist~1\Assist\profile\profile.xml
C:\Program Files\yahoo!\assist~1\Assist\SearchBar\prodef.ini
C:\Program Files\yahoo!\assist~1\Assist\SearchBar\profile.ini
C:\Program Files\yahoo!\assist~1\Assist\SecurityBar\prodef.ini
C:\Program Files\yahoo!\assist~1\Assist\SecurityBar\profile.ini
C:\Program Files\yahoo!\assist~1\Assist\Update\filter.ini
C:\Program Files\yahoo!\assist~1\Shell\ysp.exe
C:\Program Files\yahoo!\assist~1\yal01.dat
C:\Program Files\yahoo!\assist~1\yalive.dll
C:\Program Files\yahoo!\assist~1\yalive.dll.1.log
C:\Program Files\yahoo!\assist~1\yalive.dll.2.log
C:\Program Files\yahoo!\assist~1\yalive.ini
C:\Program Files\yahoo!\assist~1\yalive3.ini
C:\Program Files\yahoo!\assist~1\yalliveex.dll
C:\Program Files\yahoo!\assist~1\yalvsw.ini
C:\Program Files\yahoo!\assist~1\yalvsw3.ini
C:\Program Files\yahoo!\assist~1\yhelper.dll
C:\Program Files\yahoo!\assist~1\yhelperup.dll
C:\Program Files\yahoo!\assist~1\ylive.exe
C:\Program Files\yahoo!\assist~1\ynotifier.dll
C:\Program Files\yahoo!\assist~1\yscrblock.dll
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\phcvflj0eta5.bmp
C:\WINDOWS\Sysvxd.exe
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CNSMINKP
-------\Legacy_XPROTECTOR
-------\Service_CnsMinKP
-------\Service_XPROTECTOR
((((((((((((((((((((((((( Files Created from 2008-08-14 to 2008-09-14 )))))))))))))))))))))))))))))))
.
2008-09-14 13:22 . 2008-09-14 13:29 <DIR> d-------- C:\fixwareout
2008-09-14 00:46 . 2008-09-14 00:46 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-25 01:01 . 2008-08-25 01:01 <DIR> d-------- C:\Program Files\Alwil Software
2008-08-20 22:31 . 2008-08-20 22:31 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-08-17 00:31 . 2008-08-23 17:24 <DIR> d-------- C:\Program Files\SpeedFan
2008-08-17 00:31 . 2008-08-17 00:31 45 --a------ C:\WINDOWS\system32\initdebug.nfo
2008-08-16 01:32 . 2008-08-25 00:45 <DIR> d-------- C:\Program Files\PC Tools AntiVirus
2008-08-16 01:32 . 2008-08-16 01:32 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-08-16 01:32 . 2006-11-24 10:19 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-08-14 12:05 . 2008-08-14 12:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-08-14 12:05 . 2007-10-30 05:25 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-08-14 12:05 . 2007-10-30 05:25 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-08-14 12:04 . 2007-10-30 05:22 970,752 -ra------ C:\WINDOWS\system32\hpotiop6.dll
2008-08-14 12:04 . 2007-10-30 05:22 729,088 -ra------ C:\WINDOWS\system32\hpowiax8.dll
2008-08-14 12:04 . 2007-10-30 05:25 372,736 -ra------ C:\WINDOWS\system32\hppldcoi.dll
2008-08-14 12:04 . 2007-10-30 05:25 309,760 -ra------ C:\WINDOWS\system32\difxapi.dll
2008-08-14 12:04 . 2007-10-30 05:22 303,104 -ra------ C:\WINDOWS\system32\hpovst14.dll
2008-08-14 12:04 . 2008-02-11 23:49 271,704 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-08-14 12:04 . 2008-02-07 10:26 118,272 --a------ C:\WINDOWS\system32\hpz3l5mu.dll
2008-08-14 12:04 . 2007-10-30 05:25 21,568 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-08-14 12:04 . 2004-08-04 00:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-08-14 12:04 . 2004-08-04 00:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-14 17:57 --------- d-----w C:\Program Files\Yahoo!
2008-09-07 16:50 --------- d-----w C:\Program Files\Java
2008-08-25 04:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-23 23:15 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-15 19:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-08-08 05:46 --------- d-----w C:\Program Files\PCDownloader
2008-08-08 05:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-08-06 00:37 --------- d-----w C:\Program Files\DivX
2008-07-30 04:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-30 04:14 --------- d-----w C:\Program Files\Logitech
2008-07-30 04:13 --------- d-----w C:\Program Files\Common Files\Logitech
2008-07-30 03:52 --------- d-----w C:\Program Files\Quicken
2008-07-29 14:06 --------- d-----w C:\Program Files\Apple Software Update
2008-07-23 16:50 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-07-23 16:50 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-07-23 16:50 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-01-05 18:21 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2006-03-18 12:55 396 ----a-w C:\Program Files\INSTALL.LOG
2006-02-10 01:05 72 ----a-w C:\Program Files\UnInst.log
2006-01-26 05:58 264 ----a-w C:\Program Files\patch_malaysia_eng_openbeta.cfg
2005-12-04 19:59 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2005-11-19 04:56 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2004-12-03 23:39 4 ----a-w C:\Program Files\index.tmp
2004-06-23 18:55 20,480 ----a-w C:\Program Files\ProcManager.exe
2005-01-19 16:32 3,547 --sha-w C:\WINDOWS\cikpw.dat
2005-04-09 02:10 4,080 --sha-w C:\WINDOWS\system32\ateb_3pacsenur.dat
2005-01-13 22:06 3,537 --sha-w C:\WINDOWS\system32\owgvb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" [2007-10-01 3567928]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 61440]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-08-20 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-08-20 118784]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 98304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-03-12 180269]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 286720]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2003-08-16 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2003-08-15 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2003-08-15 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2003-08-15 455168]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 C:\WINDOWS\ALCXMNTR.EXE]
"LTMSG"="LTMSG.exe" [2004-12-09 C:\WINDOWS\ltmsg.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 557056]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^V CAST Music Monitor.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\V CAST Music Monitor.lnk
backup=C:\WINDOWS\pss\V CAST Music Monitor.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2004-08-20 16:51 118784 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
--a------ 2003-08-21 07:15 483328 C:\WINDOWS\system32\hphmon05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
--a------ 2003-08-21 07:23 49152 c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a------ 1998-05-07 20:04 52736 c:\WINDOWS\system\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-09-26 14:42 267064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 06:24 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a------ 2003-11-03 20:50 221184 C:\WINDOWS\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2004-01-26 06:24 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-03-12 01:53 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2003-08-19 12:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
--a------ 2007-11-13 16:48 3411968 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 14:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTMSG]
--a------ 2004-12-09 15:37 40960 C:\WINDOWS\ltmsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"C:\\Program Files\\Blitz 1941 Global\\BlitzClient2.exe"=
"C:\\StubInstaller.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\ijji\\ENGLISH\\u_gbound.exe"=
"C:\\ijji\\ENGLISH\\u_gunz.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support
"27297:TCP"= 27297:TCP:BitComet 27297 TCP
"27297:UDP"= 27297:UDP:BitComet 27297 UDP
"9842:TCP"= 9842:TCP:SolidNetworkManager
"9842:UDP"= 9842:UDP:SolidNetworkManager
"62998:TCP"= 62998:TCP:SolidNetworkManager
"62998:UDP"= 62998:UDP:SolidNetworkManager
"30151:TCP"= 30151:TCP:SolidNetworkManager
"30151:UDP"= 30151:UDP:SolidNetworkManager
"11815:TCP"= 11815:TCP:BitComet 11815 TCP
"11815:UDP"= 11815:UDP:BitComet 11815 UDP
"45010:TCP"= 45010:TCP:*:Disabled:SolidNetworkManager
"45010:UDP"= 45010:UDP:*:Disabled:SolidNetworkManager
"6112:TCP"= 6112:TCP:warcraft 3 customgames
R0 hkssnizl;hkssnizl;C:\WINDOWS\system32\DRIVERS\hkssnizl.sys [2007-07-11 11192]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 npkcmsvc;npkcmsvc;C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 80528]
R2 UMAXPCLS;Print Port Scanner Driver;C:\WINDOWS\system32\DRIVERS\umaxpcls.sys [2001-08-17 22912]
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys [ ]
S3 npkycryp;npkycryp;C:\Nexon\Mabinogi\npkycryp.sys [ ]
S3 vcddev;VCD VNC Virtual Network Adapter;C:\WINDOWS\system32\DRIVERS\vcdvnic.sys [2006-03-09 13312]
S3 XDva030;XDva030;C:\WINDOWS\system32\XDva030.sys [ ]
S3 XDva037;XDva037;C:\WINDOWS\system32\XDva037.sys [ ]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-addbb32.exe - C:\WINDOWS\system32\addbb32.exe
HKLM-Run-v0zGjJ - C:\documents and settings\owner\local settings\temp\v0zGjJ.exe
HKLM-Run-winws.exe - C:\WINDOWS\system32\winws.exe
HKLM-Run-wLXi - C:\documents and settings\owner\local settings\temp\wLXi.exe
HKLM-Run-mswn32.exe - C:\WINDOWS\system32\mswn32.exe
HKLM-Run-netij32.exe - C:\WINDOWS\system32\netij32.exe
HKLM-Run-javaed.exe - C:\WINDOWS\system32\javaed.exe
HKLM-Run-KIiSvib - C:\documents and settings\owner\local settings\temp\KIiSvib.exe
HKLM-Run-ViewMgr - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
HKLM-Run-sdknw.exe - C:\WINDOWS\system32\sdknw.exe
HKLM-Run-eeypkf - c:\windows\system32\tasgpc.exe
HKLM-Run-ISUSPM Startup - C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
HKLM-Run-{a8f70898-2302-f331-85c0-8feafc52bd03} - C:\WINDOWS\system32\vbsutiuvuk.dll
HKLM-Run-lphcvflj0eta5 - C:\WINDOWS\system32\lphcvflj0eta5.exe
Notify-winstart - winstart.dll
MSConfigStartUp-eMuleAutoStart - C:\Program Files\eMule\emule.exe
MSConfigStartUp-LDM - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
MSConfigStartUp-LogitechVideoTray - C:\Program Files\Logitech\Video\LogiTray.exe
MSConfigStartUp-MsnMsgr - C:\Program Files\MSN Messenger\MsnMsgr.Exe
MSConfigStartUp-PostSetupCheck - C:\WINDOWS\system32\cpmsky.dll
MSConfigStartUp-Skype - C:\Program Files\Skype\Phone\Skype.exe
MSConfigStartUp-VTTimer - VTTimer.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w4xqhzt5.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.atcomet.com/b/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-14 14:20:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\taskmgr.exe
.
**************************************************************************
.
Completion time: 2008-09-14 14:32:10 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-09-14 18:31:20
Pre-Run: 21,750,607,872 bytes free
Post-Run: 34,247,680,000 bytes free
325 --- E O F --- 2008-09-14 18:02:41
Edited by ulti, 14 September 2008 - 01:26 PM.