ComboFix 08-10-30.04 - Pinga 2008-10-29 16:44:24.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.570 [GMT -7:00]
Running from: C:\Documents and Settings\Pinga\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\system32\ahptksla.dll
C:\WINDOWS\system32\btiifpxc.dll
C:\WINDOWS\system32\cxpfiitb.ini
C:\WINDOWS\system32\fcwtshno.ini
C:\WINDOWS\system32\FNVGOnnn.ini
C:\WINDOWS\system32\FNVGOnnn.ini2
C:\WINDOWS\system32\hcepbork.ini
C:\WINDOWS\system32\hdjrfqex.ini
C:\WINDOWS\system32\kdvzqb.dll
C:\WINDOWS\system32\nnnOGVNF.dll
C:\WINDOWS\system32\nxcqauvt.dll
C:\WINDOWS\system32\pvognx(2).dll
C:\WINDOWS\system32\servers.ini
C:\WINDOWS\system32\tcpanrep.dll
C:\WINDOWS\system32\tmyxrg.dll
C:\WINDOWS\system32\tvuaqcxn.ini
C:\WINDOWS\system32\umfyslsv.dll
C:\WINDOWS\system32\zoonwe.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_COMCSVC
-------\Legacy_NETDDEC
-------\Service_COMCSVC
-------\Service_COMSS
-------\Service_NETDDEC
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.
2008-10-29 06:49 . 2008-10-29 06:49 <DIR> d-------- C:\rsit
2008-10-28 17:54 . 2008-10-28 17:54 <DIR> d-------- C:\Lop SD
2008-10-26 10:49 . 2008-10-26 10:49 95 --a------ C:\WINDOWS\wininit.ini
2008-10-26 10:28 . 2008-10-26 10:26 35,888 -ra------ C:\WINDOWS\system32\drivers\SymIM.sys
2008-10-26 10:27 . 2008-10-26 10:27 <DIR> d-------- C:\Program Files\Symantec
2008-10-26 10:27 . 2008-10-26 10:31 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-10-26 10:27 . 2008-10-26 10:27 124,464 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-10-26 10:27 . 2008-10-26 10:27 60,808 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-10-26 10:27 . 2008-10-26 10:27 10,635 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-10-26 10:27 . 2008-10-26 10:27 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-10-26 10:26 . 2008-10-26 10:26 <DIR> d-------- C:\WINDOWS\system32\drivers\NAV
2008-10-26 10:25 . 2008-10-26 10:26 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-10-26 10:25 . 2008-10-26 10:25 <DIR> d-------- C:\Program Files\NortonInstaller
2008-10-26 10:25 . 2008-10-26 10:26 <DIR> d-------- C:\Program Files\Norton AntiVirus
2008-10-26 10:25 . 2008-10-26 10:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-10-26 10:25 . 2008-10-26 10:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Norton
2008-10-26 09:56 . 2008-10-26 10:13 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-26 09:56 . 2008-10-26 11:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-26 09:53 . 2008-10-26 09:53 <DIR> d-------- C:\Program Files\Lavasoft
2008-10-17 18:32 . 2007-05-01 16:01 63,588 -ra------ C:\WINDOWS\system32\SaiD80C0.pr0
2008-10-17 17:35 . 2008-10-17 17:35 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_xusb21_01001.Wdf
2008-10-17 17:33 . 2008-09-05 09:00 18,944 --a------ C:\WINDOWS\system32\drivers\SiLib.sys
2008-10-17 17:33 . 2008-09-05 09:00 14,848 --a------ C:\WINDOWS\system32\drivers\SiUSBXp.sys
2008-10-17 17:31 . 2008-10-17 17:33 <DIR> d-------- C:\WINDOWS\system32\Silabs
2008-10-17 17:31 . 2008-10-26 14:57 <DIR> d-------- C:\Program Files\XIM 360
2008-10-17 17:31 . 2008-10-17 17:31 <DIR> d-------- C:\Program Files\DIFX
2008-10-17 16:46 . 2007-02-26 18:15 1,421,216 --a------ C:\WINDOWS\system32\WdfCoInstaller01001.dll
2008-10-17 16:46 . 2007-02-26 18:15 61,984 --a------ C:\WINDOWS\system32\drivers\xusb21.sys
2008-10-17 16:45 . 2008-10-17 16:45 <DIR> d-------- C:\Program Files\Microsoft Xbox 360 Accessories
2008-10-17 16:45 . 2006-09-28 16:04 68,888 --a------ C:\WINDOWS\system32\xinput1_3.dll
2008-10-17 13:19 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-10-17 13:19 . 2004-08-04 00:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-10-17 13:17 . 2004-08-03 22:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-10-17 13:17 . 2004-08-03 22:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-10-17 13:14 . 2008-10-17 13:14 <DIR> d-------- C:\Program Files\Saitek
2008-10-17 13:14 . 2008-10-17 13:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Saitek
2008-10-17 13:10 . 2008-10-17 13:11 <DIR> d-------- C:\Program Files\Common Files\Logishrd
2008-10-17 13:10 . 2008-05-02 02:38 301,656 --a------ C:\WINDOWS\system32\BtCoreIf.dll
2008-10-17 13:04 . 2008-10-17 13:04 <DIR> d-------- C:\Program Files\Common Files\LogiShared
2008-10-17 13:04 . 2008-10-17 13:04 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\Logitech
2008-10-17 13:04 . 2008-10-17 13:04 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\Leadertech
2008-10-17 13:03 . 2008-10-17 13:03 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-17 13:03 . 2008-10-17 13:03 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-10-17 13:03 . 2008-10-17 13:03 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-10-17 13:02 . 2008-10-17 13:02 <DIR> d-------- C:\Program Files\Logitech
2008-10-17 13:02 . 2008-10-17 13:10 <DIR> d-------- C:\Program Files\Common Files\Logitech
2008-10-17 13:02 . 2008-10-17 13:02 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\InstallShield
2008-10-17 13:02 . 2008-10-17 13:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-10-17 13:02 . 2007-06-22 12:34 1,419,232 --a------ C:\WINDOWS\system32\WdfCoInstaller01005.dll
2008-10-17 13:02 . 2008-05-02 02:39 170,512 --a------ C:\WINDOWS\system32\kemutb.dll
2008-10-17 13:02 . 2008-05-02 02:39 145,936 --a------ C:\WINDOWS\system32\KemUtil.dll
2008-10-17 13:02 . 2008-05-02 02:40 117,264 --a------ C:\WINDOWS\system32\KemWnd.dll
2008-10-17 13:02 . 2008-05-02 02:40 84,496 --a------ C:\WINDOWS\system32\KemXML.dll
2008-10-17 13:02 . 2008-02-29 03:12 76,304 --a------ C:\WINDOWS\KHALMNPR.Exe
2008-10-17 13:02 . 2008-02-29 03:13 36,880 --a------ C:\WINDOWS\system32\drivers\LMouFilt.Sys
2008-10-17 13:02 . 2008-02-29 03:13 35,344 --a------ C:\WINDOWS\system32\drivers\LHidFilt.Sys
2008-10-17 13:02 . 2008-02-29 03:13 28,944 --a------ C:\WINDOWS\system32\drivers\LUsbFilt.sys
2008-10-17 13:02 . 2008-02-29 03:12 20,240 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.sys
2008-10-17 13:01 . 2008-10-17 13:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-10-16 15:40 . 2008-10-16 15:42 <DIR> d-------- C:\Program Files\AltBinz
2008-10-16 15:03 . 2008-10-16 15:22 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\SuperNZB
2008-10-16 15:02 . 2008-10-16 15:02 <DIR> d-------- C:\Program Files\SuperNZB
2008-10-16 14:53 . 2008-10-16 14:53 <DIR> d-------- C:\WINDOWS\system32\sounds
2008-10-16 14:53 . 2008-10-16 14:53 <DIR> d-------- C:\WINDOWS\system32\logs
2008-10-16 14:53 . 2008-10-16 14:53 <DIR> d-------- C:\WINDOWS\system32\download
2008-10-16 14:53 . 2008-10-16 14:53 <DIR> d-------- C:\WINDOWS\system32\channels
2008-10-13 22:12 . 2008-10-13 22:12 <DIR> d-------- C:\Program Files\ImgBurn
2008-10-12 16:56 . 2004-08-04 05:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-10-12 14:39 . 2008-10-12 14:39 <DIR> d-------- C:\Program Files\iTunes
2008-10-12 14:39 . 2008-10-12 14:39 <DIR> d-------- C:\Program Files\iPod
2008-10-12 14:39 . 2008-10-12 14:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-12 14:23 . 2008-10-12 14:23 <DIR> d-------- C:\Program Files\Safari
2008-10-11 17:15 . 2008-10-11 17:15 <DIR> d-------- C:\Program Files\uTorrent
2008-10-09 12:17 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-10-09 12:17 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-09-20 20:09 . 2008-09-20 20:10 <DIR> d-------- C:\Program Files\Macromedia
2008-09-20 20:09 . 2008-09-20 20:12 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2008-09-20 20:07 . 2008-09-20 20:07 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-09-20 20:05 . 2008-09-20 20:20 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\AdobeAUM
2008-09-20 19:59 . 2008-10-17 13:10 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-09-20 19:51 . 2008-09-20 19:51 <DIR> d-------- C:\WINDOWS\Sun
2008-09-20 19:51 . 2008-09-20 19:51 <DIR> d-------- C:\Program Files\Sun
2008-09-20 19:50 . 2008-09-20 19:50 <DIR> d-------- C:\Program Files\Java
2008-09-20 19:50 . 2008-09-20 19:50 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-09-20 19:50 . 2008-09-20 19:50 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-20 19:49 . 2008-09-20 20:07 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-09-17 06:16 . 2008-09-17 06:16 549,159 -rahs---- C:\Program Files\Norton2009Reset.exe
2008-09-10 09:38 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-09-08 20:00 . 2008-09-08 20:00 <DIR> d-------- C:\Program Files\FirefoxPortable
2008-09-08 11:11 . 2008-10-25 23:24 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-09-08 10:05 . 2008-10-24 18:29 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\Apple Computer
2008-09-08 10:04 . 2008-09-08 10:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-08 10:03 . 2008-10-17 17:31 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-09-08 10:03 . 2008-10-12 14:38 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-09-08 10:03 . 2008-10-12 22:40 <DIR> d-------- C:\Program Files\Apple Software Update
2008-09-08 10:03 . 2008-09-08 10:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-09-08 09:57 . 2008-09-08 10:01 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\ImgBurn
2008-09-08 09:44 . 2008-09-08 09:44 <DIR> d-------- C:\Program Files\vso
2008-09-08 09:44 . 2008-09-08 09:45 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\Vso
2008-09-08 09:44 . 2008-09-08 09:44 81,920 --a------ C:\Documents and Settings\Pinga\Application Data\ezpinst.exe
2008-09-08 09:44 . 2008-09-08 09:44 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-09-08 09:44 . 2008-09-08 09:44 47,360 --a------ C:\Documents and Settings\Pinga\Application Data\pcouffin.sys
2008-09-08 09:44 . 2008-10-27 10:54 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-09-08 09:39 . 2008-09-08 12:09 <DIR> d-------- C:\Program Files\Trillian Pro
2008-09-08 09:37 . 2008-09-08 09:37 <DIR> d-------- C:\Program Files\SourceTec
2008-09-08 09:37 . 2008-09-08 09:37 <DIR> d-------- C:\Program Files\Common Files\SourceTec
2008-09-08 09:12 . 2008-10-30 16:38 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-08 08:36 . 2008-06-13 06:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-09-08 08:36 . 2008-06-13 06:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-07 23:22 . 2008-09-07 23:22 <DIR> d-------- C:\Program Files\TechSmith
2008-09-07 23:22 . 2008-09-07 23:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TechSmith
2008-09-07 23:21 . 2008-09-07 23:21 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-07 23:19 . 2008-09-07 23:19 <DIR> d-------- C:\Program Files\RipIt4Me
2008-09-07 23:18 . 2008-09-07 23:19 <DIR> d-------- C:\Program Files\DVD Decrypter
2008-09-07 23:17 . 2008-09-07 23:18 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\RipIt4Me
2008-09-07 23:16 . 2008-09-07 23:16 <DIR> d-------- C:\Program Files\RADVideo
2008-09-07 23:16 . 2008-09-07 23:16 <DIR> d-------- C:\Program Files\Qwix101
2008-09-07 23:14 . 2008-09-07 23:14 2,023,424 --a------ C:\WINDOWS\system32\mirc.exe
2008-09-07 23:14 . 2008-09-07 23:14 234,909 --a------ C:\WINDOWS\system32\mirc.hlp
2008-09-07 23:14 . 2008-09-07 23:14 68,925 --a------ C:\WINDOWS\system32\ircintro.hlp
2008-09-07 23:14 . 2008-10-16 16:46 5,393 --a------ C:\WINDOWS\system32\mirc.ini
2008-09-07 23:14 . 2008-09-07 23:14 2,568 --a------ C:\WINDOWS\system32\popups.ini
2008-09-07 23:14 . 2008-10-16 16:46 355 --a------ C:\WINDOWS\system32\urls.ini
2008-09-07 23:14 . 2008-09-07 23:14 287 --a------ C:\WINDOWS\system32\aliases.ini
2008-09-07 23:10 . 2008-09-07 23:10 <DIR> d-------- C:\Program Files\Lavavo Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-26 17:51 44,880 ----a-w C:\WINDOWS\system32\es32.dll
2008-09-07 19:39 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-29 17:18 87,336 ----a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 16:53 61,440 ----a-w C:\WINDOWS\system32\dnssd.dll
2008-07-19 05:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="C:\Documents and Settings\Pinga\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-07 133104]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-20 144792]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-10-17 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^uTorrent.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\uTorrent.exe.lnk
backup=C:\WINDOWS\pss\uTorrent.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2004-12-14 02:12 483328 C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-10-01 12:57 111936 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2005-05-19 06:47 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo 820 Series]
--a------ 2002-04-10 03:00 74240 C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S0EIC1.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-09-07 13:35 133104 C:\Documents and Settings\Pinga\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 18:57 289576 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X5100 Series]
--a------ 2003-03-04 07:49 86100 C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProfilerU]
--a------ 2007-10-02 10:10 233472 C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiMfd]
--a------ 2007-10-02 10:10 131072 C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-09-16 12:16 1833296 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
--a------ 2008-02-29 03:12 76304 C:\WINDOWS\KHALMNPR.Exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\mirc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"1206:TCP"= 1206:TCP:WindowsAutoupdate
"1853:TCP"= 1853:TCP:WindowsAutoupdate
"53:TCP"= 53:TCP:Dns
R0 SymEFA;Symantec Extended File Attributes;C:\WINDOWS\system32\drivers\NAV\1000000.07D\SYMEFA.SYS [2008-10-26 309296]
R1 BHDrvx86;Symantec Heuristics Driver;C:\WINDOWS\system32\drivers\NAV\1000000.07D\BHDrvx86.sys [2008-10-26 254512]
R1 ccHP;Symantec Hash Provider;C:\WINDOWS\system32\drivers\NAV\1000000.07D\ccHPx86.sys [2008-10-26 362544]
R1 IDSxpx86;IDSxpx86;C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20081027.007\IDSxpx86.sys [2008-10-26 274808]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-09-20 147456]
R2 Norton AntiVirus;Norton AntiVirus;C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe /s Norton AntiVirus /m C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\diMaster.dll [ ]
R3 SaiH80C0;SaiH80C0;C:\WINDOWS\system32\DRIVERS\SaiH80C0.sys [2007-05-01 132232]
R3 SIUSBXP;SIUSBXP;C:\WINDOWS\system32\drivers\SiUSBXp.sys [2008-09-05 14848]
S2 .norton2009Reset;Norton2009 Reset;C:\Program Files\Norton2009Reset.exe [2008-09-17 549159]
.
Contents of the 'Scheduled Tasks' folder
2008-10-25 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-10-29 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\Pinga\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-07 13:35]
.
- - - - ORPHANS REMOVED - - - -
BHO-{FD417378-F411-4B77-BBEE-4893BB670D4C} - C:\WINDOWS\system32\yayvUNde.dll
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
ShellExecuteHooks-{FD417378-F411-4B77-BBEE-4893BB670D4C} - C:\WINDOWS\system32\yayvUNde.dll
.
------- Supplementary Scan -------
.
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-30 16:48:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2008-10-30 16:52:18 - machine was rebooted [Pinga]
ComboFix-quarantined-files.txt 2008-10-30 23:52:13
Pre-Run: 320,453,111,808 bytes free
Post-Run: 320,443,830,272 bytes free
308 --- E O F --- 2008-09-22 23:26:58
ComboFix 08-10-30.04 - Pinga 2008-10-29 16:44:24.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.570 [GMT -7:00]
Running from: C:\Documents and Settings\Pinga\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\system32\ahptksla.dll
C:\WINDOWS\system32\btiifpxc.dll
C:\WINDOWS\system32\cxpfiitb.ini
C:\WINDOWS\system32\fcwtshno.ini
C:\WINDOWS\system32\FNVGOnnn.ini
C:\WINDOWS\system32\FNVGOnnn.ini2
C:\WINDOWS\system32\hcepbork.ini
C:\WINDOWS\system32\hdjrfqex.ini
C:\WINDOWS\system32\kdvzqb.dll
C:\WINDOWS\system32\nnnOGVNF.dll
C:\WINDOWS\system32\nxcqauvt.dll
C:\WINDOWS\system32\pvognx(2).dll
C:\WINDOWS\system32\servers.ini
C:\WINDOWS\system32\tcpanrep.dll
C:\WINDOWS\system32\tmyxrg.dll
C:\WINDOWS\system32\tvuaqcxn.ini
C:\WINDOWS\system32\umfyslsv.dll
C:\WINDOWS\system32\zoonwe.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_COMCSVC
-------\Legacy_NETDDEC
-------\Service_COMCSVC
-------\Service_COMSS
-------\Service_NETDDEC
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.
2008-10-29 06:49 . 2008-10-29 06:49 <DIR> d-------- C:\rsit
2008-10-28 17:54 . 2008-10-28 17:54 <DIR> d-------- C:\Lop SD
2008-10-26 10:49 . 2008-10-26 10:49 95 --a------ C:\WINDOWS\wininit.ini
2008-10-26 10:28 . 2008-10-26 10:26 35,888 -ra------ C:\WINDOWS\system32\drivers\SymIM.sys
2008-10-26 10:27 . 2008-10-26 10:27 <DIR> d-------- C:\Program Files\Symantec
2008-10-26 10:27 . 2008-10-26 10:31 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-10-26 10:27 . 2008-10-26 10:27 124,464 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-10-26 10:27 . 2008-10-26 10:27 60,808 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-10-26 10:27 . 2008-10-26 10:27 10,635 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-10-26 10:27 . 2008-10-26 10:27 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-10-26 10:26 . 2008-10-26 10:26 <DIR> d-------- C:\WINDOWS\system32\drivers\NAV
2008-10-26 10:25 . 2008-10-26 10:26 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-10-26 10:25 . 2008-10-26 10:25 <DIR> d-------- C:\Program Files\NortonInstaller
2008-10-26 10:25 . 2008-10-26 10:26 <DIR> d-------- C:\Program Files\Norton AntiVirus
2008-10-26 10:25 . 2008-10-26 10:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-10-26 10:25 . 2008-10-26 10:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Norton
2008-10-26 09:56 . 2008-10-26 10:13 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-26 09:56 . 2008-10-26 11:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-26 09:53 . 2008-10-26 09:53 <DIR> d-------- C:\Program Files\Lavasoft
2008-10-17 18:32 . 2007-05-01 16:01 63,588 -ra------ C:\WINDOWS\system32\SaiD80C0.pr0
2008-10-17 17:35 . 2008-10-17 17:35 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_xusb21_01001.Wdf
2008-10-17 17:33 . 2008-09-05 09:00 18,944 --a------ C:\WINDOWS\system32\drivers\SiLib.sys
2008-10-17 17:33 . 2008-09-05 09:00 14,848 --a------ C:\WINDOWS\system32\drivers\SiUSBXp.sys
2008-10-17 17:31 . 2008-10-17 17:33 <DIR> d-------- C:\WINDOWS\system32\Silabs
2008-10-17 17:31 . 2008-10-26 14:57 <DIR> d-------- C:\Program Files\XIM 360
2008-10-17 17:31 . 2008-10-17 17:31 <DIR> d-------- C:\Program Files\DIFX
2008-10-17 16:46 . 2007-02-26 18:15 1,421,216 --a------ C:\WINDOWS\system32\WdfCoInstaller01001.dll
2008-10-17 16:46 . 2007-02-26 18:15 61,984 --a------ C:\WINDOWS\system32\drivers\xusb21.sys
2008-10-17 16:45 . 2008-10-17 16:45 <DIR> d-------- C:\Program Files\Microsoft Xbox 360 Accessories
2008-10-17 16:45 . 2006-09-28 16:04 68,888 --a------ C:\WINDOWS\system32\xinput1_3.dll
2008-10-17 13:19 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-10-17 13:19 . 2004-08-04 00:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-10-17 13:17 . 2004-08-03 22:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-10-17 13:17 . 2004-08-03 22:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-10-17 13:14 . 2008-10-17 13:14 <DIR> d-------- C:\Program Files\Saitek
2008-10-17 13:14 . 2008-10-17 13:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Saitek
2008-10-17 13:10 . 2008-10-17 13:11 <DIR> d-------- C:\Program Files\Common Files\Logishrd
2008-10-17 13:10 . 2008-05-02 02:38 301,656 --a------ C:\WINDOWS\system32\BtCoreIf.dll
2008-10-17 13:04 . 2008-10-17 13:04 <DIR> d-------- C:\Program Files\Common Files\LogiShared
2008-10-17 13:04 . 2008-10-17 13:04 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\Logitech
2008-10-17 13:04 . 2008-10-17 13:04 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\Leadertech
2008-10-17 13:03 . 2008-10-17 13:03 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-17 13:03 . 2008-10-17 13:03 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-10-17 13:03 . 2008-10-17 13:03 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-10-17 13:02 . 2008-10-17 13:02 <DIR> d-------- C:\Program Files\Logitech
2008-10-17 13:02 . 2008-10-17 13:10 <DIR> d-------- C:\Program Files\Common Files\Logitech
2008-10-17 13:02 . 2008-10-17 13:02 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\InstallShield
2008-10-17 13:02 . 2008-10-17 13:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-10-17 13:02 . 2007-06-22 12:34 1,419,232 --a------ C:\WINDOWS\system32\WdfCoInstaller01005.dll
2008-10-17 13:02 . 2008-05-02 02:39 170,512 --a------ C:\WINDOWS\system32\kemutb.dll
2008-10-17 13:02 . 2008-05-02 02:39 145,936 --a------ C:\WINDOWS\system32\KemUtil.dll
2008-10-17 13:02 . 2008-05-02 02:40 117,264 --a------ C:\WINDOWS\system32\KemWnd.dll
2008-10-17 13:02 . 2008-05-02 02:40 84,496 --a------ C:\WINDOWS\system32\KemXML.dll
2008-10-17 13:02 . 2008-02-29 03:12 76,304 --a------ C:\WINDOWS\KHALMNPR.Exe
2008-10-17 13:02 . 2008-02-29 03:13 36,880 --a------ C:\WINDOWS\system32\drivers\LMouFilt.Sys
2008-10-17 13:02 . 2008-02-29 03:13 35,344 --a------ C:\WINDOWS\system32\drivers\LHidFilt.Sys
2008-10-17 13:02 . 2008-02-29 03:13 28,944 --a------ C:\WINDOWS\system32\drivers\LUsbFilt.sys
2008-10-17 13:02 . 2008-02-29 03:12 20,240 --a------ C:\WINDOWS\system32\drivers\L8042Kbd.sys
2008-10-17 13:01 . 2008-10-17 13:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-10-16 15:40 . 2008-10-16 15:42 <DIR> d-------- C:\Program Files\AltBinz
2008-10-16 15:03 . 2008-10-16 15:22 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\SuperNZB
2008-10-16 15:02 . 2008-10-16 15:02 <DIR> d-------- C:\Program Files\SuperNZB
2008-10-16 14:53 . 2008-10-16 14:53 <DIR> d-------- C:\WINDOWS\system32\sounds
2008-10-16 14:53 . 2008-10-16 14:53 <DIR> d-------- C:\WINDOWS\system32\logs
2008-10-16 14:53 . 2008-10-16 14:53 <DIR> d-------- C:\WINDOWS\system32\download
2008-10-16 14:53 . 2008-10-16 14:53 <DIR> d-------- C:\WINDOWS\system32\channels
2008-10-13 22:12 . 2008-10-13 22:12 <DIR> d-------- C:\Program Files\ImgBurn
2008-10-12 16:56 . 2004-08-04 05:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-10-12 14:39 . 2008-10-12 14:39 <DIR> d-------- C:\Program Files\iTunes
2008-10-12 14:39 . 2008-10-12 14:39 <DIR> d-------- C:\Program Files\iPod
2008-10-12 14:39 . 2008-10-12 14:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-12 14:23 . 2008-10-12 14:23 <DIR> d-------- C:\Program Files\Safari
2008-10-11 17:15 . 2008-10-11 17:15 <DIR> d-------- C:\Program Files\uTorrent
2008-10-09 12:17 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-10-09 12:17 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-09-20 20:09 . 2008-09-20 20:10 <DIR> d-------- C:\Program Files\Macromedia
2008-09-20 20:09 . 2008-09-20 20:12 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2008-09-20 20:07 . 2008-09-20 20:07 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-09-20 20:05 . 2008-09-20 20:20 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\AdobeAUM
2008-09-20 19:59 . 2008-10-17 13:10 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-09-20 19:51 . 2008-09-20 19:51 <DIR> d-------- C:\WINDOWS\Sun
2008-09-20 19:51 . 2008-09-20 19:51 <DIR> d-------- C:\Program Files\Sun
2008-09-20 19:50 . 2008-09-20 19:50 <DIR> d-------- C:\Program Files\Java
2008-09-20 19:50 . 2008-09-20 19:50 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-09-20 19:50 . 2008-09-20 19:50 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-20 19:49 . 2008-09-20 20:07 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-09-17 06:16 . 2008-09-17 06:16 549,159 -rahs---- C:\Program Files\Norton2009Reset.exe
2008-09-10 09:38 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-09-08 20:00 . 2008-09-08 20:00 <DIR> d-------- C:\Program Files\FirefoxPortable
2008-09-08 11:11 . 2008-10-25 23:24 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-09-08 10:05 . 2008-10-24 18:29 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\Apple Computer
2008-09-08 10:04 . 2008-09-08 10:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-08 10:03 . 2008-10-17 17:31 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-09-08 10:03 . 2008-10-12 14:38 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-09-08 10:03 . 2008-10-12 22:40 <DIR> d-------- C:\Program Files\Apple Software Update
2008-09-08 10:03 . 2008-09-08 10:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-09-08 09:57 . 2008-09-08 10:01 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\ImgBurn
2008-09-08 09:44 . 2008-09-08 09:44 <DIR> d-------- C:\Program Files\vso
2008-09-08 09:44 . 2008-09-08 09:45 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\Vso
2008-09-08 09:44 . 2008-09-08 09:44 81,920 --a------ C:\Documents and Settings\Pinga\Application Data\ezpinst.exe
2008-09-08 09:44 . 2008-09-08 09:44 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-09-08 09:44 . 2008-09-08 09:44 47,360 --a------ C:\Documents and Settings\Pinga\Application Data\pcouffin.sys
2008-09-08 09:44 . 2008-10-27 10:54 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-09-08 09:39 . 2008-09-08 12:09 <DIR> d-------- C:\Program Files\Trillian Pro
2008-09-08 09:37 . 2008-09-08 09:37 <DIR> d-------- C:\Program Files\SourceTec
2008-09-08 09:37 . 2008-09-08 09:37 <DIR> d-------- C:\Program Files\Common Files\SourceTec
2008-09-08 09:12 . 2008-10-30 16:38 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-08 08:36 . 2008-06-13 06:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-09-08 08:36 . 2008-06-13 06:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-07 23:22 . 2008-09-07 23:22 <DIR> d-------- C:\Program Files\TechSmith
2008-09-07 23:22 . 2008-09-07 23:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TechSmith
2008-09-07 23:21 . 2008-09-07 23:21 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-07 23:19 . 2008-09-07 23:19 <DIR> d-------- C:\Program Files\RipIt4Me
2008-09-07 23:18 . 2008-09-07 23:19 <DIR> d-------- C:\Program Files\DVD Decrypter
2008-09-07 23:17 . 2008-09-07 23:18 <DIR> d-------- C:\Documents and Settings\Pinga\Application Data\RipIt4Me
2008-09-07 23:16 . 2008-09-07 23:16 <DIR> d-------- C:\Program Files\RADVideo
2008-09-07 23:16 . 2008-09-07 23:16 <DIR> d-------- C:\Program Files\Qwix101
2008-09-07 23:14 . 2008-09-07 23:14 2,023,424 --a------ C:\WINDOWS\system32\mirc.exe
2008-09-07 23:14 . 2008-09-07 23:14 234,909 --a------ C:\WINDOWS\system32\mirc.hlp
2008-09-07 23:14 . 2008-09-07 23:14 68,925 --a------ C:\WINDOWS\system32\ircintro.hlp
2008-09-07 23:14 . 2008-10-16 16:46 5,393 --a------ C:\WINDOWS\system32\mirc.ini
2008-09-07 23:14 . 2008-09-07 23:14 2,568 --a------ C:\WINDOWS\system32\popups.ini
2008-09-07 23:14 . 2008-10-16 16:46 355 --a------ C:\WINDOWS\system32\urls.ini
2008-09-07 23:14 . 2008-09-07 23:14 287 --a------ C:\WINDOWS\system32\aliases.ini
2008-09-07 23:10 . 2008-09-07 23:10 <DIR> d-------- C:\Program Files\Lavavo Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-26 17:51 44,880 ----a-w C:\WINDOWS\system32\es32.dll
2008-09-07 19:39 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-29 17:18 87,336 ----a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 16:53 61,440 ----a-w C:\WINDOWS\system32\dnssd.dll
2008-07-19 05:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="C:\Documents and Settings\Pinga\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-07 133104]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-20 144792]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-10-17 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^uTorrent.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\uTorrent.exe.lnk
backup=C:\WINDOWS\pss\uTorrent.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2004-12-14 02:12 483328 C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-10-01 12:57 111936 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2005-05-19 06:47 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo 820 Series]
--a------ 2002-04-10 03:00 74240 C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S0EIC1.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-09-07 13:35 133104 C:\Documents and Settings\Pinga\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 18:57 289576 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X5100 Series]
--a------ 2003-03-04 07:49 86100 C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProfilerU]
--a------ 2007-10-02 10:10 233472 C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiMfd]
--a------ 2007-10-02 10:10 131072 C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-09-16 12:16 1833296 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
--a------ 2008-02-29 03:12 76304 C:\WINDOWS\KHALMNPR.Exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\mirc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"1206:TCP"= 1206:TCP:WindowsAutoupdate
"1853:TCP"= 1853:TCP:WindowsAutoupdate
"53:TCP"= 53:TCP:Dns
R0 SymEFA;Symantec Extended File Attributes;C:\WINDOWS\system32\drivers\NAV\1000000.07D\SYMEFA.SYS [2008-10-26 309296]
R1 BHDrvx86;Symantec Heuristics Driver;C:\WINDOWS\system32\drivers\NAV\1000000.07D\BHDrvx86.sys [2008-10-26 254512]
R1 ccHP;Symantec Hash Provider;C:\WINDOWS\system32\drivers\NAV\1000000.07D\ccHPx86.sys [2008-10-26 362544]
R1 IDSxpx86;IDSxpx86;C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20081027.007\IDSxpx86.sys [2008-10-26 274808]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-09-20 147456]
R2 Norton AntiVirus;Norton AntiVirus;C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe /s Norton AntiVirus /m C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\diMaster.dll [ ]
R3 SaiH80C0;SaiH80C0;C:\WINDOWS\system32\DRIVERS\SaiH80C0.sys [2007-05-01 132232]
R3 SIUSBXP;SIUSBXP;C:\WINDOWS\system32\drivers\SiUSBXp.sys [2008-09-05 14848]
S2 .norton2009Reset;Norton2009 Reset;C:\Program Files\Norton2009Reset.exe [2008-09-17 549159]
.
Contents of the 'Scheduled Tasks' folder
2008-10-25 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-10-29 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\Pinga\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-07 13:35]
.
- - - - ORPHANS REMOVED - - - -
BHO-{FD417378-F411-4B77-BBEE-4893BB670D4C} - C:\WINDOWS\system32\yayvUNde.dll
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
ShellExecuteHooks-{FD417378-F411-4B77-BBEE-4893BB670D4C} - C:\WINDOWS\system32\yayvUNde.dll
.
------- Supplementary Scan -------
.
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-30 16:48:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
C:\Program Files\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2008-10-30 16:52:18 - machine was rebooted [Pinga]
ComboFix-quarantined-files.txt 2008-10-30 23:52:13
Pre-Run: 320,453,111,808 bytes free
Post-Run: 320,443,830,272 bytes free
308 --- E O F --- 2008-09-22 23:26:58