Here is the ComboFix log: (the OTScanIt log is attached)ComboFix 08-05-12.1 - Andrew 2008-05-13 9:45:56.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.541 [GMT -4:00]
Running from: C:\Documents and Settings\Andrew\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Andrew\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\system32\gbyjasqm.dll
C:\WINDOWS\TEMP\win14.exe
E:\LaunchU3.exe
E:\start.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\gbyjasqm.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-13 to 2008-05-13 )))))))))))))))))))))))))))))))
.
2008-05-13 00:09 . 2008-05-13 00:09 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-13 00:08 . 2008-05-13 00:08 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-13 00:08 . 2008-05-13 00:08 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-13 00:08 . 2008-05-13 00:08 <DIR> d-------- C:\Documents and Settings\Andrew\Application Data\Malwarebytes
2008-05-13 00:08 . 2008-05-13 00:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-13 00:08 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-13 00:08 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-12 22:25 . 2008-05-12 22:25 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-12 22:25 . 2008-05-12 22:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-12 21:43 . 2008-05-12 22:24 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-05-12 16:21 . 2008-05-12 16:21 <DIR> d-------- C:\Program Files\Panda Security
2008-05-12 08:42 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-05-11 23:28 . 2008-05-11 23:28 84 --a------ C:\WINDOWS\system32\ikhcore.cfg
2008-05-11 23:15 . 2008-05-12 23:34 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-11 23:15 . 2008-05-12 23:34 <DIR> d-------- C:\Documents and Settings\Andrew\Application Data\SUPERAntiSpyware.com
2008-05-11 23:15 . 2008-05-11 23:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-11 22:33 . 2008-05-12 22:12 <DIR> d-------- C:\VundoFix Backups
2008-05-11 19:07 . 2008-05-13 00:21 <DIR> d-------- C:\Program Files\Starcraft
2008-05-09 21:59 . 2008-05-09 21:59 203,776 --a------ C:\WINDOWS\system32\clrviddc.dll
2008-05-09 21:49 . 2008-05-09 21:49 <DIR> d-------- C:\Program Files\Real
2008-05-09 21:49 . 2008-05-09 21:49 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-05-09 21:43 . 2008-05-09 21:43 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-09 21:43 . 2008-05-09 21:43 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-09 21:39 . 2008-05-09 21:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-05-09 21:33 . 2008-05-09 21:33 <DIR> d-------- C:\Documents and Settings\Andrew\Application Data\Media Player Classic
2008-05-08 23:29 . 2008-05-08 23:34 <DIR> d-------- C:\Documents and Settings\Andrew\Application Data\U3
2008-05-06 20:23 . 2008-05-09 19:58 <DIR> d-------- C:\Documents and Settings\Andrew\Application Data\Microsoft Games
2008-05-03 14:04 . 2008-05-03 14:04 18,620 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-04-27 17:16 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-04-27 17:16 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-04-27 17:16 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-04-27 17:16 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-04-26 11:05 . 2008-04-26 11:11 <DIR> d-------- C:\Program Files\GoldWave
2008-04-25 23:37 . 2008-04-25 23:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GRETECH
2008-04-25 23:36 . 2008-04-25 23:36 <DIR> d-------- C:\Program Files\GomPlayer
2008-04-25 23:36 . 2008-04-25 23:36 <DIR> d-------- C:\Documents and Settings\Andrew\Application Data\GRETECH
2008-04-25 23:25 . 2008-04-25 23:25 <DIR> d-------- C:\Program Files\Adobe Media Player
2008-04-25 18:17 . 2006-12-07 00:14 2,330,624 -----c--- C:\WINDOWS\system32\dllcache\wmvcore.dll
2008-04-24 21:08 . 2008-04-24 21:08 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-04-24 21:08 . 2008-04-24 21:08 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-04-24 19:48 . 2008-05-09 20:38 <DIR> d-------- C:\Documents and Settings\Andrew\Incomplete
2008-04-24 19:47 . 2008-04-25 00:47 <DIR> d-------- C:\Program Files\MP3 Rocket
2008-04-24 19:47 . 2008-04-25 00:50 <DIR> d-------- C:\Documents and Settings\Andrew\Application Data\MP3Rocket
2008-04-22 22:03 . 2008-04-24 21:15 <DIR> d-------- C:\Program Files\MediaMonkey
2008-04-22 21:33 . 2007-03-07 19:51 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-04-22 01:49 . 2008-04-22 01:49 <DIR> d-------- C:\Documents and Settings\Andrew\.thumbnails
2008-04-22 01:48 . 2008-04-22 18:48 <DIR> d-------- C:\Documents and Settings\Andrew\.gimp-2.4
2008-04-20 18:43 . 2008-05-09 19:04 <DIR> d-------- C:\Westwood
2008-04-14 22:39 . 2008-04-14 22:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-04-14 22:39 . 2008-02-15 10:21 12,608 --a------ C:\WINDOWS\system32\drivers\TfKbMon.sys
2008-04-14 22:37 . 2008-04-14 22:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-13 23:05 . 2008-04-13 23:05 <DIR> d-------- C:\Program Files\CodeBlocks
2008-04-13 23:05 . 2008-04-28 11:05 <DIR> d-------- C:\Documents and Settings\Andrew\Application Data\codeblocks
2008-04-13 17:45 . 2008-04-13 17:45 <DIR> d-------- C:\Program Files\TrueCrypt
2008-04-13 17:45 . 2008-04-13 17:45 223,424 --a------ C:\WINDOWS\system32\drivers\truecrypt.sys
2008-04-13 17:44 . 2008-04-14 19:15 <DIR> d-------- C:\Documents and Settings\Andrew\Application Data\TrueCrypt
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-13 13:46 --------- d-----w C:\Documents and Settings\Andrew\Application Data\.purple
2008-05-13 12:52 --------- d-----w C:\Documents and Settings\Andrew\Application Data\OpenOffice.org2
2008-05-12 03:30 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-12 02:19 --------- d-----w C:\Program Files\Google
2008-05-10 01:49 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-05-10 01:49 --------- d-----w C:\Program Files\Common Files\Real
2008-05-05 23:22 --------- d-----w C:\Documents and Settings\Andrew\Application Data\FileZilla
2008-05-03 18:04 --------- d-----w C:\Program Files\Picasa2
2008-04-26 03:06 --------- d-----w C:\Program Files\MediaCoder
2008-04-23 04:14 --------- d-----w C:\Documents and Settings\Andrew\Application Data\gtk-2.0
2008-04-23 00:26 --------- d-----w C:\Program Files\FileZilla FTP Client
2008-04-07 03:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-01 18:14 --------- d-----w C:\Program Files\Common Files\Taxman
2008-04-01 18:08 --------- d-----w C:\Program Files\StudioTax 2007
2008-03-29 19:09 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-03-29 19:08 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-03-29 19:07 --------- d-----w C:\Program Files\Java
2008-03-29 15:00 --------- d-----w C:\Documents and Settings\Andrew\Application Data\InstallShield
2008-03-23 01:20 17,801 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-03-21 16:58 --------- d-----w C:\Program Files\Graph
2008-03-19 23:41 --------- d-----w C:\Program Files\Pidgin
2008-03-19 22:29 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-14 03:49 --------- d-----w C:\Program Files\MultiDesk
2008-03-13 04:17 --------- d-----w C:\Program Files\Motorola
2008-03-12 06:01 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2007-08-09 17:08 8,784 ----a-w C:\Program Files\mozilla firefox\plugins\ractrlkeyhook.dll
2007-08-09 17:10 245,408 ----a-w C:\Program Files\mozilla firefox\plugins\unicows.dll
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\
0678ae36fb2ce581bec948b8531de8\SP2QFE\acadproc.dll
2006-10-04 10:05 39424 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP18\A0000715.dll
C:\
0678ae36fb2ce581bec948b8531de8\spmsg.dll
2005-10-12 19:12 14048 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP18\A0000712.dll
C:\
0678ae36fb2ce581bec948b8531de8\spuninst.exe
2005-10-12 19:12 213216 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP18\A0000722.exe
C:\
0678ae36fb2ce581bec948b8531de8\update\spcustom.dll
2005-10-12 19:12 22752 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP18\A0000711.dll
C:\
0678ae36fb2ce581bec948b8531de8\update\update.exe
2005-10-12 19:12 716000 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP18\A0000723.exe
C:\
0678ae36fb2ce581bec948b8531de8\update\updspapi.dll
2005-10-12 19:12 371424 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP18\A0000713.dll
C:\
0c4241a1b3e22144a82af0af55\admparse.dll
2007-08-13 19:39 71680 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000510.dll
C:\
0c4241a1b3e22144a82af0af55\advpack.dll
2007-08-13 19:39 123904 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000509.dll
C:\
0c4241a1b3e22144a82af0af55\browseui.dll
2006-09-23 14:12 1022976 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000508.dll
C:\
0c4241a1b3e22144a82af0af55\corpol.dll
2007-08-13 19:42 17408 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000507.dll
C:\
0c4241a1b3e22144a82af0af55\custsat.dll
2007-08-13 19:54 33792 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000506.dll
C:\
0c4241a1b3e22144a82af0af55\dxtmsft.dll
2007-08-13 19:35 346624 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000505.dll
C:\
0c4241a1b3e22144a82af0af55\dxtrans.dll
2007-08-13 19:35 214528 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000504.dll
C:\
0c4241a1b3e22144a82af0af55\extmgr.dll
2007-08-13 19:54 131584 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000503.dll
C:\
0c4241a1b3e22144a82af0af55\hmmapi.dll
2007-08-13 19:18 60416 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000502.dll
C:\
0c4241a1b3e22144a82af0af55\icardie.dll
2007-08-13 19:36 61952 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000501.dll
C:\
0c4241a1b3e22144a82af0af55\ie4uinit.exe
2007-08-13 19:39 54784 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000463.exe
C:\
0c4241a1b3e22144a82af0af55\ieakeng.dll
2007-08-13 19:39 152064 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000500.dll
C:\
0c4241a1b3e22144a82af0af55\ieaksie.dll
2007-08-13 19:39 229376 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000499.dll
C:\
0c4241a1b3e22144a82af0af55\ieakui.dll
2007-08-13 18:56 161792 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000498.dll
C:\
0c4241a1b3e22144a82af0af55\ieapfltr.dll
2007-07-11 13:27 383488 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000497.dll
C:\
0c4241a1b3e22144a82af0af55\iedkcs32.dll
2007-08-13 19:39 382976 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000496.dll
C:\
0c4241a1b3e22144a82af0af55\iedw.exe
2007-08-13 19:44 69120 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000462.exe
C:\
0c4241a1b3e22144a82af0af55\ieencode.dll
2007-08-13 19:45 78336 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000495.dll
C:\
0c4241a1b3e22144a82af0af55\ieframe.dll
2007-08-13 19:54 6049280 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000494.dll
C:\
0c4241a1b3e22144a82af0af55\iepeers.dll
2007-08-13 19:54 191488 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000493.dll
C:\
0c4241a1b3e22144a82af0af55\ieproxy.dll
2007-08-13 19:54 287744 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000492.dll
C:\
0c4241a1b3e22144a82af0af55\iernonce.dll
2007-08-13 19:39 43008 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000491.dll
C:\
0c4241a1b3e22144a82af0af55\iertutil.dll
2007-08-13 19:34 266752 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000490.dll
C:\
0c4241a1b3e22144a82af0af55\iesetup.dll
2007-08-13 19:39 55296 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000489.dll
C:\
0c4241a1b3e22144a82af0af55\ieudinit.exe
2007-08-13 19:39 13312 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000461.exe
C:\
0c4241a1b3e22144a82af0af55\ieui.dll
2007-08-13 19:54 180736 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000488.dll
C:\
0c4241a1b3e22144a82af0af55\iexplore.exe
2007-08-13 19:43 622080 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000460.exe
C:\
0c4241a1b3e22144a82af0af55\imgutil.dll
2007-08-13 19:36 36352 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000487.dll
C:\
0c4241a1b3e22144a82af0af55\inseng.dll
2007-08-13 19:39 92672 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000486.dll
C:\
0c4241a1b3e22144a82af0af55\jscript.dll
2007-08-13 19:38 491520 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000485.dll
C:\
0c4241a1b3e22144a82af0af55\jsproxy.dll
2007-08-13 19:54 27136 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000484.dll
C:\
0c4241a1b3e22144a82af0af55\licmgr10.dll
2007-08-13 19:44 40960 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000483.dll
C:\
0c4241a1b3e22144a82af0af55\msfeeds.dll
2007-08-13 19:54 458752 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000482.dll
C:\
0c4241a1b3e22144a82af0af55\msfeedsbs.dll
2007-08-13 19:54 50688 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000481.dll
C:\
0c4241a1b3e22144a82af0af55\msfeedssync.exe
2007-08-13 19:36 12288 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000459.exe
C:\
0c4241a1b3e22144a82af0af55\mshta.exe
2007-08-13 19:32 45568 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000458.exe
C:\
0c4241a1b3e22144a82af0af55\mshtml.dll
2007-08-13 19:54 3578368 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000480.dll
C:\
0c4241a1b3e22144a82af0af55\mshtmled.dll
2007-08-13 19:54 475648 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000479.dll
C:\
0c4241a1b3e22144a82af0af55\mshtmler.dll
2007-08-13 19:01 48128 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000478.dll
C:\
0c4241a1b3e22144a82af0af55\msls31.dll
2007-08-13 19:54 156160 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000477.dll
C:\
0c4241a1b3e22144a82af0af55\msrating.dll
2007-08-13 19:44 192000 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000476.dll
C:\
0c4241a1b3e22144a82af0af55\mstime.dll
2007-08-13 19:54 670720 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000475.dll
C:\
0c4241a1b3e22144a82af0af55\occache.dll
2007-08-13 19:44 101376 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000474.dll
C:\
0c4241a1b3e22144a82af0af55\pngfilt.dll
2007-08-13 19:36 44544 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000473.dll
C:\
0c4241a1b3e22144a82af0af55\shdocvw.dll
2006-09-23 14:12 1497088 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000472.dll
C:\
0c4241a1b3e22144a82af0af55\shlwapi.dll
2006-09-23 14:12 474112 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000471.dll
C:\
0c4241a1b3e22144a82af0af55\spmsg.dll
2006-09-06 18:43 14048 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000470.dll
C:\
0c4241a1b3e22144a82af0af55\spuninst.exe
2006-09-06 18:43 213216 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000457.exe
C:\
0c4241a1b3e22144a82af0af55\spupdsvc.exe
2006-09-06 18:43 22752 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000456.exe
C:\
0c4241a1b3e22144a82af0af55\update\idndl.exe
2006-09-06 18:42 589672 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000440.exe
C:\
0c4241a1b3e22144a82af0af55\update\iecustom.dll
2007-08-13 19:54 32960 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000443.dll
C:\
0c4241a1b3e22144a82af0af55\update\iereseticons.exe
2007-08-13 19:52 66048 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000439.exe
C:\
0c4241a1b3e22144a82af0af55\update\iesetup.exe
2007-08-13 19:54 1084096 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000438.exe
C:\
0c4241a1b3e22144a82af0af55\update\legitlibm.dll
2007-02-12 17:10 635696 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000442.dll
C:\
0c4241a1b3e22144a82af0af55\update\nlsdl.exe
2006-09-06 18:42 498016 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000437.exe
C:\
0c4241a1b3e22144a82af0af55\update\update.exe
2006-09-06 18:43 716000 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000436.exe
C:\
0c4241a1b3e22144a82af0af55\update\updspapi.dll
2006-09-06 18:43 371424 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000441.dll
C:\
0c4241a1b3e22144a82af0af55\update\xmllitesetup.exe
2006-09-06 18:43 536888 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000435.exe
C:\
0c4241a1b3e22144a82af0af55\url.dll
2007-08-13 19:44 105984 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000469.dll
C:\
0c4241a1b3e22144a82af0af55\urlmon.dll
2007-08-13 19:54 1162240 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000468.dll
C:\
0c4241a1b3e22144a82af0af55\vbscript.dll
2007-08-13 19:54 413696 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000467.dll
C:\
0c4241a1b3e22144a82af0af55\vgx.dll
2007-08-13 19:54 765952 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000466.dll
C:\
0c4241a1b3e22144a82af0af55\webcheck.dll
2007-08-13 19:54 231424 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000465.dll
C:\
0c4241a1b3e22144a82af0af55\winfxdocobj.exe
2007-08-13 19:45 206336 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000455.exe
C:\
0c4241a1b3e22144a82af0af55\wininet.dll
2007-08-13 19:54 818688 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP11\A0000464.dll
C:\
0f6d565df9dbcd5ca524652a4a032f50\commonfiles\hdaprop.dll
2005-01-07 18:07 25088 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000191.dll
C:\
0f6d565df9dbcd5ca524652a4a032f50\commonfiles\hdashcut.exe
2005-01-07 18:07 61952 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000189.exe
C:\
0f6d565df9dbcd5ca524652a4a032f50\commonfiles\hdaudbus.sys
2005-01-07 18:07 138752 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000186.sys
C:\
0f6d565df9dbcd5ca524652a4a032f50\commonfiles\hdaudio.sys
2005-01-07 18:07 145920 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000185.sys
C:\
0f6d565df9dbcd5ca524652a4a032f50\commonfiles\hdaudres.dll
2005-01-07 18:07 5120 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000190.dll
C:\
0f6d565df9dbcd5ca524652a4a032f50\sprecovr.exe
2004-11-18 11:43 27360 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000194.exe
C:\
0f6d565df9dbcd5ca524652a4a032f50\spuninst.exe
2004-11-18 11:44 209632 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000193.exe
C:\
0f6d565df9dbcd5ca524652a4a032f50\spupdsvc.exe
2004-11-18 11:42 22752 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000192.exe
C:\
0f6d565df9dbcd5ca524652a4a032f50\update\spcustom.dll
2004-11-18 11:47 22752 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000183.dll
C:\
0f6d565df9dbcd5ca524652a4a032f50\update\spmsg.dll
2004-11-18 11:41 14048 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000182.dll
C:\
0f6d565df9dbcd5ca524652a4a032f50\update\update.exe
2004-11-18 11:46 717024 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000180.exe
C:\
0f6d565df9dbcd5ca524652a4a032f50\update\updspapi.dll
2004-11-18 11:45 371936 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000181.dll
C:\
0f6d565df9dbcd5ca524652a4a032f50\winxpsp2\portcls.sys
2004-03-16 11:58 136960 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP3\A0000177.sys
C:\578585eaac08e0c5dc8f5498f7c55d70\update\update.exe
2006-05-16 19:11 716000 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP18\A0000787.exe
C:\578585eaac08e0c5dc8f5498f7c55d70\update\updspapi.dll
2006-05-16 19:11 371424 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP18\A0000788.dll
C:\c67a4c6badc9d788341e8e724d68cb\spmsg.dll
2006-09-16 02:05 14640 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000615.dll
C:\c67a4c6badc9d788341e8e724d68cb\spuninst.exe
2006-09-16 02:05 221488 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000609.exe
C:\c67a4c6badc9d788341e8e724d68cb\spupdsvc.exe
2006-09-16 02:05 23856 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000608.exe
C:\c67a4c6badc9d788341e8e724d68cb\update\update.exe
2006-09-16 02:05 742192 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000600.exe
C:\c67a4c6badc9d788341e8e724d68cb\update\updspapi.dll
2006-09-16 02:05 379184 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000602.dll
C:\c67a4c6badc9d788341e8e724d68cb\update\wudfcustom.dll
2006-09-28 20:01 58368 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000601.dll
C:\c67a4c6badc9d788341e8e724d68cb\wudfcoinstaller.dll
2006-09-28 21:13 95344 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000614.dll
C:\c67a4c6badc9d788341e8e724d68cb\wudfcustom.dll
2006-09-28 20:01 58368 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000613.dll
C:\c67a4c6badc9d788341e8e724d68cb\wudfhost.exe
2006-09-28 19:56 146432 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000607.exe
C:\c67a4c6badc9d788341e8e724d68cb\wudfpf.sys
2006-09-28 19:55 77568 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000605.sys
C:\c67a4c6badc9d788341e8e724d68cb\wudfplatform.dll
2006-09-28 19:56 165376 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000612.dll
C:\c67a4c6badc9d788341e8e724d68cb\wudfrd.sys
2006-09-28 20:00 82944 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000604.sys
C:\c67a4c6badc9d788341e8e724d68cb\wudfsvc.dll
2006-09-28 19:56 55808 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000611.dll
C:\c67a4c6badc9d788341e8e724d68cb\wudfx.dll
2006-09-28 19:56 316416 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP16\A0000610.dll
C:\c7f7008582edcad7b40a29e7f421d537\nlsdl.dll
2006-06-28 18:59 24576 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP8\A0000344.dll
C:\c7f7008582edcad7b40a29e7f421d537\spmsg.dll
2006-05-24 13:32 14048 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP8\A0000343.dll
C:\c7f7008582edcad7b40a29e7f421d537\spuninst.exe
2006-05-24 13:32 213216 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP8\A0000342.exe
C:\c7f7008582edcad7b40a29e7f421d537\spupdsvc.exe
2006-05-24 13:32 22752 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP8\A0000341.exe
C:\c7f7008582edcad7b40a29e7f421d537\update\spcustom.dll
2006-05-24 13:32 22752 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP8\A0000339.dll
C:\c7f7008582edcad7b40a29e7f421d537\update\update.exe
2006-05-24 13:32 716000 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP8\A0000337.exe
C:\c7f7008582edcad7b40a29e7f421d537\update\updspapi.dll
2006-05-24 13:32 371424 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP8\A0000338.dll
2006-10-20 14:45 4110518 C:\cabs\D20003-003-001\ISSetup.dll
2006-10-20 15:45 4110518 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP35\A0002653.dll
2006-10-20 14:45 4110518 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP56\A0004207.dll
2006-10-20 14:45 2185018 C:\cabs\D20003-003-001\setup.exe
2006-10-20 15:45 2185018 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP35\A0002654.exe
2006-10-20 14:45 2185018 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP56\A0004208.exe
2004-03-23 11:45 28672 C:\cabs\D20003-003-001\Windows\tiinst\cttib1.dll
2004-03-23 12:45 28672 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP35\A0002657.dll
2004-03-23 11:45 28672 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP56\A0004211.dll
2005-11-17 15:46 337320 C:\cabs\D20003-003-001\Windows\tiinst\difxapi.dll
2005-11-17 16:46 337320 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP35\A0002658.dll
2005-11-17 15:46 337320 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP56\A0004212.dll
2006-04-06 15:49 88192 C:\cabs\D20003-003-001\Windows\tiinst\gtipci21.sys
2006-04-06 16:49 88192 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP35\A0002661.sys
2006-04-06 15:49 88192 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP56\A0004215.sys
2006-07-06 13:44 168448 C:\cabs\D20003-003-001\Windows\tiinst\tifm21.sys
2006-07-06 14:44 168448 {593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP35\A0002664.sys
{593F298F-B7D6-4A3D-A260-6D
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 15:44 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 17:20 1024000]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-09-29 12:39 151552]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-09-18 15:58 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-09-18 15:57 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-09-18 15:58 118784]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 12:55 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 12:56 602182]
"SigmatelSysTrayApp"="stsystra.exe" [2005-12-27 11:20 413696 C:\WINDOWS\stsystra.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
--a------ 2006-09-27 18:26 573440 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"=
"C:\\Westwood\\RA2 fake\\GAME.EXE"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh
S0 TfFsMon;TfFsMon;C:\WINDOWS\system32\drivers\TfFsMon.sys []
S0 TfSysMon;TfSysMon;C:\WINDOWS\system32\drivers\TfSysMon.sys []
S3 portio;portio;C:\Program Files\Zinf\portio.sys []
S3 TfNetMon;TfNetMon;C:\WINDOWS\system32\drivers\TfNetMon.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-05-13 03:28:17 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-13 09:46:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-13 9:48:23
ComboFix-quarantined-files.txt 2008-05-13 13:48:16
ComboFix2.txt 2008-05-13 12:53:57
Pre-Run: 132,595,765,248 bytes free
Post-Run: 132,583,739,392 bytes free
410 --- E O F --- 2008-04-25 22:17:51