ComboFix 08-12-13.03 - User 2008-12-14 11:03:30.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.629 [GMT -5:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Install.txt
c:\windows\system32\comsa32.sys
c:\windows\system32\Install.txt
c:\windows\system32\mabidwe.exe
c:\windows\system32\soxpeca.exe
c:\windows\system32\tpszxyd.sys
c:\windows\system32\udxfytw.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AFISICX
-------\Legacy_MABIDWE
-------\Legacy_NOYTCYR
-------\Legacy_ROYTCTM
-------\Legacy_SOXPECA
-------\Legacy_TDYDOWKC
-------\Legacy_WSLDOEKD
-------\Service_afisicx
-------\Service_mabidwe
-------\Service_noytcyr
-------\Service_roytctm
-------\Service_soxpeca
-------\Service_tdydowkc
-------\Service_wsldoekd
((((((((((((((((((((((((( Files Created from 2008-11-14 to 2008-12-14 )))))))))))))))))))))))))))))))
.
2008-12-14 10:40 . 2008-12-14 10:40 <DIR> d-------- c:\program files\Zone Labs
2008-12-14 09:20 . 2008-12-14 10:41 <DIR> d-------- C:\RECYCLER(2)
2008-12-12 17:32 . 2008-12-12 17:32 <DIR> d-------- c:\program files\AviSynth 2.5
2008-12-12 17:31 . 2008-12-12 17:31 <DIR> d-------- c:\program files\eRightSoft
2008-12-11 18:17 . 2008-12-11 18:57 59,392 --a------ c:\windows\system32\msnioed.exe
2008-12-11 15:12 . 2008-12-11 15:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\MailFrontier
2008-12-05 17:21 . 2008-12-05 17:21 <DIR> d-------- C:\_OTMoveIt
2008-12-03 18:39 . 2008-12-03 18:40 <DIR> d-------- c:\windows\ERUNT
2008-12-03 18:37 . 2008-12-14 10:42 <DIR> d-------- c:\documents and settings\Administrator.ELVIS-COMP-
2008-12-03 18:20 . 2008-12-03 20:53 <DIR> d-------- C:\SDFix
2008-12-02 19:47 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuapi.dll.mui
2008-12-02 19:44 . 2008-12-02 19:44 <DIR> d-------- c:\program files\ERUNT
2008-12-02 19:19 . 2008-12-04 20:16 <DIR> d-------- C:\rsit
2008-12-02 19:19 . 2008-12-02 19:27 <DIR> d-------- c:\program files\trend micro
2008-12-01 20:24 . 2008-12-06 19:35 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-01 20:24 . 2008-12-01 20:24 <DIR> d-------- c:\documents and settings\User\Application Data\Malwarebytes
2008-12-01 20:24 . 2008-12-01 20:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-01 20:24 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-01 20:24 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-25 13:02 . 2008-11-25 13:02 <DIR> d-------- c:\program files\microsoft frontpage
2008-11-24 14:32 . 2008-11-24 14:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avg8
2008-11-22 19:15 . 2008-11-22 20:54 <DIR> d--h----- C:\$AVG8.VAULT$
2008-11-22 18:49 . 2008-11-22 18:49 <DIR> d-------- c:\program files\IObit
2008-11-22 18:43 . 2008-11-22 18:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-22 18:31 . 2008-11-22 18:31 62 ---hs---- c:\windows\system32\@#$#.htm
2008-11-19 18:54 . 2008-11-10 05:43 410,984 --a------ c:\windows\system32\deploytk.dll
2008-11-19 00:09 . 2008-11-19 00:09 <DIR> d-------- c:\documents and settings\User\Application Data\Ubisoft
2008-11-19 00:09 . 2008-11-19 00:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\Ubisoft
2008-11-17 22:28 . 2008-12-01 19:42 7,875 --a------ C:\xp_emergencyutil.zip
2008-11-15 21:46 . 2008-11-15 21:46 <DIR> d-------- c:\program files\Ventrilo
2008-11-15 21:46 . 2008-11-15 21:46 262 --a------ c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2008-11-15 21:45 . 2008-11-22 18:42 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-14 13:17 . 2008-11-14 13:18 <DIR> d-------- c:\program files\iTunes
2008-11-14 13:17 . 2008-11-14 13:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-12 23:37 --------- d-----w c:\documents and settings\User\Application Data\Move Networks
2008-12-12 00:09 --------- d-----w c:\program files\Warcraft III
2008-12-10 23:14 --------- d-----w c:\documents and settings\User\Application Data\uTorrent
2008-12-07 22:44 --------- d-----w c:\program files\Java
2008-12-03 01:17 --------- d-----w c:\program files\Microsoft Silverlight
2008-12-02 02:08 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-22 23:43 --------- d-----w c:\program files\Lavasoft
2008-11-22 23:43 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-19 19:46 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-16 02:46 --------- d-----w c:\documents and settings\User\Application Data\Ventrilo
2008-11-15 21:22 --------- d-----w c:\program files\World of Warcraft
2008-11-14 18:17 --------- d-----w c:\program files\iPod
2008-11-14 17:51 --------- d-----w c:\program files\Safari
2008-11-08 05:26 --------- d-----w c:\program files\Guild Wars
2008-11-04 06:06 --------- d-----w c:\program files\StepMania
2008-10-29 02:47 --------- d-----w c:\program files\LimeWirepr
2008-10-25 10:39 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-10-18 19:28 --------- d-----w c:\documents and settings\All Users\Application Data\Blizzard
2008-10-17 21:18 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-16 22:57 32 -c--a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2005-07-31 16:34 139 ---ha-w c:\program files\Desktop.ini
2005-03-11 01:51 32 -c--a-r c:\documents and settings\All Users\hash.dat
2004-10-13 16:24 1,694,208 --sha-w c:\windows\FlyakiteOSX\Backup\msmsgs.exe
2005-02-19 22:32 56 --sha-r c:\windows\system32\88105EFAED.sys
.
((((((((((((((((((((((((((((( snapshot@2008-12-05_17.32.19.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-14 02:45:45 21,061,632 ----a-w c:\windows\ERDNT\12-13-2008\Users\
00000001\ntuser.dat
+ 2008-12-14 02:45:45 1,773,568 ----a-w c:\windows\ERDNT\12-13-2008\Users\
00000002\UsrClass.dat
+ 2005-10-20 17:02:28 163,328 ----a-w c:\windows\ERDNT\2008-12-14\ERDNT.EXE
+ 2008-12-14 15:53:18 21,061,632 ----a-w c:\windows\ERDNT\2008-12-14\Users\
00000001\ntuser.dat
+ 2008-12-14 15:53:18 1,773,568 ----a-w c:\windows\ERDNT\2008-12-14\Users\
00000002\UsrClass.dat
+ 2005-10-20 17:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\12-10-2008\ERDNT.EXE
+ 2008-12-10 19:29:12 21,061,632 ----a-w c:\windows\ERDNT\AutoBackup\12-10-2008\Users\
00000001\ntuser.dat
+ 2008-12-10 19:29:12 1,773,568 ----a-w c:\windows\ERDNT\AutoBackup\12-10-2008\Users\
00000002\UsrClass.dat
+ 2005-10-20 17:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\12-11-2008\ERDNT.EXE
+ 2008-12-11 18:22:20 21,061,632 ----a-w c:\windows\ERDNT\AutoBackup\12-11-2008\Users\
00000001\ntuser.dat
+ 2008-12-11 18:22:21 1,773,568 ----a-w c:\windows\ERDNT\AutoBackup\12-11-2008\Users\
00000002\UsrClass.dat
+ 2008-12-12 22:13:39 21,061,632 ----a-w c:\windows\ERDNT\AutoBackup\12-12-2008\Users\
00000001\ntuser.dat
+ 2008-12-12 22:13:40 1,773,568 ----a-w c:\windows\ERDNT\AutoBackup\12-12-2008\Users\
00000002\UsrClass.dat
+ 2008-12-14 02:20:48 21,061,632 ----a-w c:\windows\ERDNT\AutoBackup\12-13-2008\Users\
00000001\ntuser.dat
+ 2008-12-14 02:20:48 1,773,568 ----a-w c:\windows\ERDNT\AutoBackup\12-13-2008\Users\
00000002\UsrClass.dat
+ 2008-12-14 13:30:49 21,061,632 ----a-w c:\windows\ERDNT\AutoBackup\12-14-2008\Users\
00000001\ntuser.dat
+ 2008-12-14 13:30:50 1,773,568 ----a-w c:\windows\ERDNT\AutoBackup\12-14-2008\Users\
00000002\UsrClass.dat
+ 2005-10-20 17:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\12-6-2008\ERDNT.EXE
+ 2008-12-06 05:17:26 21,061,632 ----a-w c:\windows\ERDNT\AutoBackup\12-6-2008\Users\
00000001\ntuser.dat
+ 2008-12-06 05:17:27 1,773,568 ----a-w c:\windows\ERDNT\AutoBackup\12-6-2008\Users\
00000002\UsrClass.dat
+ 2005-10-20 17:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\12-7-2008\ERDNT.EXE
+ 2008-12-07 13:06:02 21,061,632 ----a-w c:\windows\ERDNT\AutoBackup\12-7-2008\Users\
00000001\ntuser.dat
+ 2008-12-07 13:06:03 1,773,568 ----a-w c:\windows\ERDNT\AutoBackup\12-7-2008\Users\
00000002\UsrClass.dat
+ 2005-10-20 17:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\12-8-2008\ERDNT.EXE
+ 2008-12-08 19:35:34 21,061,632 ----a-w c:\windows\ERDNT\AutoBackup\12-8-2008\Users\
00000001\ntuser.dat
+ 2008-12-08 19:35:35 1,773,568 ----a-w c:\windows\ERDNT\AutoBackup\12-8-2008\Users\
00000002\UsrClass.dat
+ 2005-10-20 17:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\12-9-2008\ERDNT.EXE
+ 2008-12-09 19:27:16 21,061,632 ----a-w c:\windows\ERDNT\AutoBackup\12-9-2008\Users\
00000001\ntuser.dat
+ 2008-12-09 19:27:16 1,773,568 ----a-w c:\windows\ERDNT\AutoBackup\12-9-2008\Users\
00000002\UsrClass.dat
+ 2005-10-20 17:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2008-12-05\ERDNT.EXE
+ 2008-12-06 04:41:38 21,061,632 ----a-w c:\windows\ERDNT\AutoBackup\2008-12-05\Users\
00000001\ntuser.dat
+ 2008-12-06 04:41:39 1,773,568 ----a-w c:\windows\ERDNT\AutoBackup\2008-12-05\Users\
00000002\UsrClass.dat
+ 2008-12-12 00:26:49 21,061,632 ----a-w c:\windows\ERDNT\AutoBackup\2008-12-11\Users\
00000001\ntuser.dat
+ 2008-12-12 00:26:50 1,773,568 ----a-w c:\windows\ERDNT\AutoBackup\2008-12-11\Users\
00000002\UsrClass.dat
+ 2005-10-20 17:02:28 163,328 ----a-w c:\windows\ERDNT\AutoBackup\2008-12-14\ERDNT.EXE
+ 2008-12-14 15:46:28 21,061,632 ----a-w c:\windows\ERDNT\AutoBackup\2008-12-14\Users\
00000001\ntuser.dat
+ 2008-12-14 15:46:29 1,773,568 ----a-w c:\windows\ERDNT\AutoBackup\2008-12-14\Users\
00000002\UsrClass.dat
+ 2008-12-12 00:31:42 507,904 ----a-w c:\windows\ERDNT\Hiv-backup(2)\Users(2)\
00000001(2)\ntuser.dat
+ 2008-12-12 00:31:42 1,224,704 ----a-w c:\windows\ERDNT\Hiv-backup(2)\Users(2)\
00000002(2)\UsrClass.dat
+ 2008-12-12 00:31:44 21,061,632 ----a-w c:\windows\ERDNT\Hiv-backup(2)\Users(2)\
00000003(2)\ntuser.dat
+ 2008-12-12 00:31:44 1,773,568 ----a-w c:\windows\ERDNT\Hiv-backup(2)\Users(2)\
00000004(2)\UsrClass.dat
+ 2008-12-12 00:31:44 491,520 ----a-w c:\windows\ERDNT\Hiv-backup(2)\Users(2)\
00000005(2)\ntuser.dat
+ 2008-12-12 00:31:45 1,224,704 ----a-w c:\windows\ERDNT\Hiv-backup(2)\Users(2)\
00000006(2)\UsrClass.dat
- 2008-11-19 23:54:28 148,888 ----a-w c:\windows\FlyakiteOSX\Backup\javaws.exe
+ 2008-11-10 10:43:39 148,888 ----a-w c:\windows\FlyakiteOSX\Backup\javaws.exe
- 2008-12-04 23:14:34 32,768 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-14 15:55:23 32,768 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-04 23:14:34 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-14 15:55:23 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-11 18:35:56 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008120120081208\index.dat
+ 2008-12-12 00:01:45 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008121120081212\index.dat
+ 2008-12-14 15:55:23 114,688 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-11-22 23:20:37 1,552,152 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-14 16:09:12 1,552,152 ----a-w c:\windows\system32\FNTCACHE.DAT
- 2008-11-19 23:54:28 144,792 ----a-w c:\windows\system32\java.exe
+ 2008-11-10 10:43:37 144,792 ----a-w c:\windows\system32\java.exe
- 2008-11-19 23:54:28 144,792 ----a-w c:\windows\system32\javaw.exe
+ 2008-11-10 10:43:38 144,792 ----a-w c:\windows\system32\javaw.exe
- 2008-11-19 23:54:28 136,600 ----a-w c:\windows\system32\javaws.exe
+ 2008-11-10 10:43:39 136,600 ----a-w c:\windows\system32\javaws.exe
- 2008-07-15 17:14:35 4,996 -c--a-w c:\windows\system32\Restore\rstrlog.dat
+ 2008-12-14 15:43:07 664,964 -c--a-w c:\windows\system32\Restore\rstrlog.dat
- 2006-02-27 03:06:20 4,212 -c-h--w c:\windows\system32\zllictbl.dat
+ 2008-12-11 23:08:00 4,212 -c-h--w c:\windows\system32\zllictbl.dat
+ 2008-12-14 16:09:22 16,384 ----atw c:\windows\temp\Perflib_Perfdata_1e0.dat
+ 2008-12-14 16:09:21 16,384 ----atw c:\windows\temp\Perflib_Perfdata_2b4.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2004-10-25 1118208]
"UberIcon"="c:\program files\UberIcon\UberIcon Manager.exe" [2006-02-23 188416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\Smtray.exe" [2002-06-26 90112]
"DeadAIM"="c:\progra~1\AIM\\DeadAIM.ocm" [2003-06-19 116224]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]
"razer"="c:\program files\Razer\Copperhead\razerhid.exe" [2005-10-08 155648]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2007-12-13 2051096]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2007-12-13 2095640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-02 94208]
"System Files Updater"="c:\windows\FlyakiteOSX\Tools\System Files Updater.exe" [2006-02-25 118485]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
c:\documents and settings\User\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Transparent Windows.lnk - c:\documents and settings\User\Application Data\Microsoft\Installer\{3105352A-DA47-473F-9D85-3867FE9EDF35}\_609D529CCA3C1366DBDAE8.exe [2008-05-04 10134]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.wmv3"= c:\progra~1\COMBIN~1\Filters\wmv9vcm.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LimeWire 4.0.8.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MiniEYE-MiniREAD Launch.lnk]
backup=c:\windows\pss\MiniEYE-MiniREAD Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Online Account Setup.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Online.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^User^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIMWDInstallFilename]
--a--c--- 2004-01-12 14:29 102400 c:\progra~1\AIM\AIMWDI~1.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a--c--- 2004-08-04 02:56 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
--a------ 2003-06-19 01:38 116224 c:\program files\AIM\DeadAIM.ocm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
--a--c--- 2001-08-23 07:00 44032 c:\windows\ime\imkr6_1\imekrmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a--c--- 2004-08-04 00:31 208952 c:\windows\ime\imjp8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a--c--- 2005-08-11 14:30 249856 c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a--c--- 2005-08-11 14:30 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 18:57 289576 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 11:24 1686016 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a--c--- 2007-01-19 11:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
--a--c--- 2002-08-28 20:39 59392 c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
-ra--c--- 2001-07-09 05:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
-ra--c--- 2001-07-09 05:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-05-02 21:46 13529088 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
--a------ 2007-09-04 18:25 81920 c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-05-02 21:46 94208 c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a--c--- 2002-08-28 20:39 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a--c--- 2002-08-28 20:39 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
-----c--- 2003-10-31 18:42 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
--a------ 2002-06-26 16:36 90112 c:\program files\Analog Devices\SoundMAX\SMTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP]
--a--c--- 2004-10-25 14:36 1118208 c:\program files\TGTSoft\StyleXP\StyleXP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2007-07-12 03:00 132496 c:\program files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-03-04 15:07 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
--a--c--- 2005-03-04 11:01 88209 c:\windows\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-05-02 21:46 1630208 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"wuauserv"=2 (0x2)
"NVSvc"=2 (0x2)
"Netlogon"=3 (0x3)
"navapsvc"=2 (0x2)
"MSSQLServerADHelper"=3 (0x3)
"MSSQL$SONY_MEDIAMGR"=3 (0x3)
"LmHosts"=2 (0x2)
"LiveUpdate"=3 (0x3)
"iPodService"=3 (0x3)
"ImapiService"=3 (0x3)
"IDriverT"=3 (0x3)
"clr_optimization_v2.0.50727_32"=3 (0x3)
"CiSvc"=3 (0x3)
"Automatic LiveUpdate Scheduler"=2 (0x2)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"aspnet_state"=3 (0x3)
"AppMgmt"=3 (0x3)
"Apache"=2 (0x2)
"ALG"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"usnjsvc"=3 (0x3)
"rpcapd"=3 (0x3)
"Pctspk"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"npkcsvc"=2 (0x2)
"MDM"=2 (0x2)
"mabidwe"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWirepr\\LimeWire.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Warcraft III\\war3.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16785:TCP"= 16785:TCP:BitComet 16785 TCP
"16785:UDP"= 16785:UDP:BitComet 16785 UDP
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
R3 Razerlow;Razer Copperhead Driver;c:\windows\system32\Drivers\Razerlow.sys [2007-04-25 19020]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
S3 uisp;Freescale USB JW32 driver;c:\windows\system32\Drivers\usbicp.sys [2007-04-25 162900]
S3 VGAUTI;VGAUTI;\??\c:\windows\system32\DRIVERS\VGAUTI.sys [2005-06-19 37880]
S3 XDva202;XDva202;\??\c:\windows\system32\XDva202.sys []
.
Contents of the 'Scheduled Tasks' folder
2008-11-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-12-13 c:\windows\Tasks\CAAntiSpywareScan_Daily as User at 7 16 PM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe []
2008-12-08 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-10-22 10:13]
2007-11-24 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-10-22 10:13]
2007-11-24 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe []
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-New - c:\progra~1\NEWDOT~1\NEWDOT~2.DLL
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mSearch Bar =
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &Google Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: >>> FREE PORN GALLERIES <<< - java script:{document.location='http://sexmaxx.com/freegalleries.htm';}
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: Download ALL with IDA - c:\program files\IDA\idaieall.htm
IE: Download with IDA - c:\program files\IDA\idaie.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
IE: {{28D44DAC-D1FC-4d4f-BB1B-ADF037C8DDBC}
IE: {{28D44DAC-D1FC-4d4f-BB1B-ADF037C8DDBC} - -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-14 11:09:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(780)
c:\windows\system32\cscui.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
c:\program files\Razer\Copperhead\razertra.exe
c:\program files\Razer\Copperhead\razerofa.exe
c:\program files\Transparent Windows\Transparent.exe
.
**************************************************************************
.
Completion time: 2008-12-14 11:16:41 - machine was rebooted [User]
ComboFix-quarantined-files.txt 2008-12-14 16:16:19
ComboFix2.txt 2008-12-12 00:32:09
ComboFix3.txt 2008-12-06 04:46:22
ComboFix4.txt 2008-12-05 22:34:06
Pre-Run: 25,540,911,104 bytes free
Post-Run: 25,492,180,992 bytes free
393 --- E O F --- 2008-08-28 06:08:32