ComboFix 07-08-30.3 - "Administrator" 2007-09-02 18:23:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.243 [GMT -4:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ADMINI~1\APPLIC~1\microsoft\internet explorer\quick launch\intern~1.lnk
C:\DOCUME~1\ADMINI~1\APPLIC~1\ymante~1
C:\Program Files\Common Files\mantec~1
C:\Program Files\winpop
C:\WINDOWS\msresearch1.dat
((((((((((((((((((((((((( Files Created from 2007-08-02 to 2007-09-02 )))))))))))))))))))))))))))))))
2007-09-02 18:23 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-09-02 02:55 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-09-02 02:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-02 02:20 <DIR> d-------- C:\DOCUME~1\ADMINI~1\.housecall6.6
2007-09-01 12:21 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-08-26 03:14 82,248 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-08-26 03:14 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-26 03:14 57,672 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-08-26 03:14 40,264 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-08-26 03:14 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-08-26 03:14 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-08-26 03:14 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\PC Tools
2007-08-25 02:00 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Yahoo!
2007-08-25 01:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
2007-08-25 01:53 <DIR> d-------- C:\Program Files\Yahoo!
2007-08-22 01:05 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
2007-08-16 19:36 <DIR> d-------- C:\Program Files\Lavasoft
2007-08-16 19:36 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-08-16 19:34 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-08-16 16:01 <DIR> d-------- C:\Program Files\Viewpoint
2007-08-16 16:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-08-16 16:01 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\acccore
2007-08-16 16:00 <DIR> d-------- C:\Program Files\Common Files\AOL
2007-08-16 16:00 <DIR> d-------- C:\Program Files\AIM6
2007-08-14 01:15 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
2007-08-11 23:29 <DIR> d-------- C:\WINDOWS\twain_32
2007-08-11 23:29 <DIR> d-------- C:\Program Files\Common Files\Logitech
2007-08-11 23:28 <DIR> d-------- C:\Program Files\Logitech
2007-08-02 02:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\.purple
2007-08-02 02:07 <DIR> d-------- C:\Program Files\Pidgin
2007-08-02 02:07 <DIR> d-------- C:\Program Files\Common Files\GTK
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-09-01 12:51 --------- d-------- C:\Program Files\MSN Messenger
2007-09-01 12:23 --------- d-------- C:\Program Files\Notepad++
2007-09-01 12:23 --------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Notepad++
2007-08-19 23:00 --------- d-------- C:\Program Files\Google
2007-08-17 03:45 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-16 20:04 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-08-16 20:04 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-16 19:36 --------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
2007-08-16 16:07 --------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Viewpoint
2007-08-16 16:01 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
2007-08-16 16:01 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-08-16 16:00 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
2007-08-11 23:29 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-03 00:57 --------- d-------- C:\Program Files\DivX
2007-08-02 02:14 --------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\.purple
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-26 19:06 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-07-26 19:06 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-07-19 14:36 --------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
2007-07-18 07:44 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-07-12 04:54 107864 --a------ C:\WINDOWS\system32\tsccvid.dll
2007-07-11 03:11 --------- d-------- C:\Program Files\Recuva
2007-07-09 15:07 36624 --------- C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-07-09 15:07 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-07-09 15:07 2560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-07-09 15:07 2432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-07-09 15:07 129784 --------- C:\WINDOWS\system32\pxafs.dll
2007-07-09 15:07 118520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-07-09 15:07 116472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-07-09 15:05 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-07-09 15:05 593920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2007-07-09 15:05 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-07-09 15:05 53248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2007-07-09 15:05 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-07-09 15:05 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-07-09 15:05 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-07-09 15:05 196608 --a------ C:\WINDOWS\system32\dtu100.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 18:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2005-08-31 21:27]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"PcSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1140464654\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Access]
C:\Program Files\Media Access\MediaAccK.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\Msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
S3 DIGIRPS;Digi PortServer Driver;C:\WINDOWS\system32\DRIVERS\digirlpt.sys
S4 VFILT;Outpost Firewall Kernel Driver;\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\2000\FILTNT.SYS
*Newly Created Service* - CATCHME
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-09-02 18:25:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-09-02 18:26:18
C:\ComboFix-quarantined-files.txt ... 2007-09-02 18:25
--- E O F ---