ComboFix 08-06-30.2 - Joel 2008-07-08 19:10:46.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1083 [GMT -5:00]
Running from: C:\Documents and Settings\Joel\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Joel\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\axrfgvek.dll
C:\WINDOWS\kgqfweltbnk.dll
C:\WINDOWS\mrvtdpqe.exe
C:\WINDOWS\nqgpedlr.dll
C:\WINDOWS\okmdepgb.dll
C:\WINDOWS\system32\nnnOETKE.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\kgqfweltbnk.dll
C:\WINDOWS\nqgpedlr.dll
C:\WINDOWS\okmdepgb.dll
C:\WINDOWS\resources\RomSetup.dll
C:\WINDOWS\resources\VoidUnknown.dll
C:\WINDOWS\system32\egntbmff.dll
C:\WINDOWS\system32\FgQBayxx.ini
C:\WINDOWS\system32\FgQBayxx.ini2
C:\WINDOWS\system32\nnnOETKE.dll
C:\WINDOWS\system32\xxyaBQgF.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_uisp
((((((((((((((((((((((((( Files Created from 2008-06-09 to 2008-07-09 )))))))))))))))))))))))))))))))
.
2008-07-02 13:09 . 2008-07-02 13:09 <DIR> d-------- C:\Program Files\nanoPEG for WinTV
2008-07-02 13:09 . 2006-12-28 13:12 290,816 --a------ C:\WINDOWS\system32\hcwzblast.dll
2008-07-02 13:09 . 2007-03-28 07:16 90,175 --a------ C:\WINDOWS\system32\hcwblast.ocx
2008-07-02 13:09 . 2007-03-28 07:15 65,603 --a------ C:\WINDOWS\system32\hcwIRblast.dll
2008-07-02 13:09 . 2005-07-28 13:33 40,960 --a------ C:\WINDOWS\system32\GButton.ocx
2008-07-02 13:09 . 2004-10-06 14:03 248 --a------ C:\WINDOWS\HCWBlast.ini
2008-07-02 13:08 . 2007-02-19 16:30 46,488 --a------ C:\WINDOWS\system32\HCWTVServer.tlb
2008-07-02 13:07 . 2007-06-01 11:01 397,312 --a------ C:\WINDOWS\system32\HCWChMgr.ocx
2008-07-02 13:07 . 2006-07-21 15:07 176,197 --a------ C:\WINDOWS\system32\hcwmux.ax
2008-07-02 13:07 . 2007-05-01 12:13 168,007 --a------ C:\WINDOWS\system32\HCWPsiParser.ax
2008-07-02 13:07 . 2007-04-02 16:27 159,744 --a------ C:\WINDOWS\system32\hcwChDB.dll
2008-07-02 13:07 . 2006-10-12 11:28 139,264 --a------ C:\WINDOWS\system32\hcwdvbsubtitles.ax
2008-07-02 13:07 . 2004-09-10 15:58 94,208 --a------ C:\WINDOWS\system32\hcwsstereo.ax
2008-07-02 13:07 . 2006-04-06 13:46 65,536 --a------ C:\WINDOWS\system32\hcwNowNext.ax
2008-07-02 13:07 . 2006-03-28 17:38 57,344 --a------ C:\WINDOWS\system32\HCWdlace.ax
2008-07-02 13:07 . 2006-09-13 11:13 23,304 --a------ C:\WINDOWS\system32\HcwChDB.tlb
2008-07-02 08:40 . 2008-07-02 08:40 <DIR> d-------- C:\Documents and Settings\Joel\Application Data\Malwarebytes
2008-07-02 08:40 . 2008-07-02 08:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-02 08:40 . 2008-06-28 14:23 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-02 08:40 . 2008-06-28 14:23 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-02 08:18 . 2008-07-02 08:25 <DIR> d-------- C:\WINDOWS\system32\734914
2008-07-02 08:18 . 2008-07-02 08:53 28,288 --------- C:\WINDOWS\system32\xxyxWQKC.dll
2008-07-02 08:05 . 2008-07-02 08:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-07-02 03:00 . 2008-07-02 03:00 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-07-01 22:47 . 2008-07-08 18:41 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-07-01 17:05 . 2008-07-01 22:32 94,208 --a------ C:\WINDOWS\system32\31.tmp
2008-07-01 16:34 . 2008-07-01 16:34 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-07-01 16:26 . 2008-07-01 16:30 94,208 --a------ C:\WINDOWS\system32\F.tmp
2008-07-01 16:12 . 2008-07-01 16:12 <DIR> d-------- C:\Documents and Settings\Joel\Application Data\Nero
2008-07-01 16:05 . 2008-07-01 16:08 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-07-01 16:05 . 2008-07-01 16:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-06-27 14:03 . 2008-07-01 11:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WholeSecurity
2008-06-18 15:39 . 2008-06-18 15:39 <DIR> d-------- C:\Program Files\Common Files\eSellerate
2008-06-18 15:38 . 2008-06-18 15:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Findley Designs
2008-06-11 00:46 . 2008-06-13 06:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 00:46 . 2008-05-08 09:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-10 10:14 . 2008-06-10 10:16 <DIR> d-------- C:\Documents and Settings\Joel\Application Data\rockbox.org
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-09 00:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-07-08 23:31 --------- d-----w C:\Program Files\RaidenFTPD
2008-07-08 19:37 --------- d-----w C:\Documents and Settings\Joel\Application Data\uTorrent
2008-07-02 18:08 --------- d-----w C:\Program Files\WinTV
2008-07-02 13:55 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-01 20:16 --------- d-----w C:\Program Files\Common Files\Ahead
2008-06-30 15:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-06-28 18:46 --------- d-----w C:\Program Files\Safari
2008-06-27 19:03 --------- d-----w C:\Program Files\PayPal
2008-06-26 18:22 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-06-26 12:34 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-06-19 18:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-13 11:05 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 13:01 --------- d-----w C:\Program Files\Coupons
2008-05-21 14:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-14 14:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-14 13:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-14 13:30 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-05-14 13:30 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-14 13:30 10,563 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-05-14 13:30 --------- d-----w C:\Program Files\Symantec
2008-05-09 14:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-04-14 00:12 69,120 ----a-w C:\WINDOWS\notepad.exe
2008-04-14 00:12 50,688 ----a-w C:\WINDOWS\twain_32.dll
2008-04-14 00:12 34,816 ----a-w C:\WINDOWS\Help\sniffpol.dll
2008-04-14 00:12 33,280 ----a-w C:\WINDOWS\Help\sstub.dll
2008-04-14 00:12 32,866 ------w C:\WINDOWS\slrundll.exe
2008-04-14 00:12 283,648 ----a-w C:\WINDOWS\winhlp32.exe
2008-04-14 00:12 279,040 ----a-w C:\WINDOWS\Help\tshoot.dll
2008-04-14 00:12 146,432 ----a-w C:\WINDOWS\regedit.exe
2008-04-14 00:12 10,752 ----a-w C:\WINDOWS\hh.exe
2008-04-14 00:12 1,033,728 ----a-w C:\WINDOWS\explorer.exe
2008-04-14 00:11 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
2008-04-14 00:11 39,424 ----a-w C:\WINDOWS\AppPatch\acadproc.dll
2008-04-14 00:11 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll
2008-04-14 00:11 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll
2008-04-14 00:11 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll
2008-04-14 00:11 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll
2007-12-13 12:56 81,920 ----a-w C:\Documents and Settings\Joel\Application Data\ezpinst.exe
2007-12-13 12:56 47,360 ----a-w C:\Documents and Settings\Joel\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((( snapshot@2008-07-02_ 7.26.39.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-02 12:11:08 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-09 00:23:15 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2006-05-08 14:54:42 69,632 ----a-w C:\WINDOWS\system32\3DES.dll
+ 2006-01-25 22:38:22 69,632 ----a-w C:\WINDOWS\system32\3DES.dll
- 2004-10-14 16:53:06 90,190 ----a-w C:\WINDOWS\system32\Bt848WST.DLL
+ 2004-01-26 19:49:00 90,190 ----a-w C:\WINDOWS\system32\Bt848WST.DLL
+ 2008-04-14 00:11:56 47,616 -c--a-w C:\WINDOWS\system32\dllcache\iyuv_32.dll
+ 2008-04-13 19:16:36 141,056 -c--a-w C:\WINDOWS\system32\dllcache\ks.sys
+ 2008-04-14 00:12:02 16,896 -c--a-w C:\WINDOWS\system32\dllcache\msyuv.dll
+ 2008-04-14 00:12:08 53,760 -c--a-w C:\WINDOWS\system32\dllcache\vfwwdm32.dll
- 2007-02-06 18:27:02 185,728 ----a-r C:\WINDOWS\system32\drivers\hcwPP2.sys
+ 2006-08-15 20:18:10 177,152 ----a-w C:\WINDOWS\system32\drivers\hcwPP2.sys
- 1999-04-27 06:26:10 11,264 ----a-w C:\WINDOWS\system32\hcwhook.dll
+ 1999-04-27 21:26:10 11,264 ----a-w C:\WINDOWS\system32\hcwhook.dll
- 2005-12-22 22:13:56 94,264 ----a-w C:\WINDOWS\system32\hcwi2c32.dll
+ 2007-01-19 16:34:58 98,360 ----a-w C:\WINDOWS\system32\hcwi2c32.dll
- 2006-01-20 14:42:20 229,432 ----a-w C:\WINDOWS\system32\hcwpnp32.dll
+ 2007-04-12 16:49:46 258,104 ----a-w C:\WINDOWS\system32\hcwpnp32.dll
- 2001-07-19 14:44:06 393,216 ----a-w C:\WINDOWS\system32\hcwsnbd9.dll
+ 2001-07-19 13:44:06 393,216 ----a-w C:\WINDOWS\system32\hcwsnbd9.dll
- 2003-11-07 18:45:18 106,559 ----a-w C:\WINDOWS\system32\hcwTVDlg.dll
+ 2003-11-07 17:45:18 106,559 ----a-w C:\WINDOWS\system32\hcwTVDlg.dll
- 2006-04-21 21:37:54 639,049 ----a-w C:\WINDOWS\system32\hcwtvwnd.dll
+ 2007-06-01 15:59:26 749,641 ----a-w C:\WINDOWS\system32\hcwtvwnd.dll
- 2004-06-08 06:03:40 36,921 ----a-w C:\WINDOWS\system32\hcwutl32.dll
+ 2004-06-08 05:03:40 36,921 ----a-w C:\WINDOWS\system32\hcwutl32.dll
- 2006-07-21 19:50:32 66,048 ----a-r C:\WINDOWS\system32\hcwXDS.dll
+ 2006-07-21 19:50:34 66,048 ----a-w C:\WINDOWS\system32\hcwXDS.dll
- 2008-04-14 00:11:55 47,616 ----a-w C:\WINDOWS\system32\iyuv_32.dll
+ 2008-04-14 00:11:56 47,616 ----a-w C:\WINDOWS\system32\iyuv_32.dll
- 2008-03-25 01:21:00 2,889,088 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2008-03-25 03:21:18 2,889,088 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
- 2008-03-25 01:21:00 218,496 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-03-25 03:21:20 218,496 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-07-02 14:24:44 70,264 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
- 2008-04-14 00:12:45 294,912 ----a-w C:\WINDOWS\system32\msh263.drv
+ 2008-04-14 00:12:46 294,912 ----a-w C:\WINDOWS\system32\msh263.drv
- 2008-04-14 00:12:01 16,896 ----a-w C:\WINDOWS\system32\msyuv.dll
+ 2008-04-14 00:12:02 16,896 ----a-w C:\WINDOWS\system32\msyuv.dll
- 2008-05-21 13:18:24 71,966 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-07-02 13:41:25 71,966 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-05-21 13:18:25 442,860 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-07-02 13:41:25 442,860 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-02-06 18:27:02 185,728 ----a-r C:\WINDOWS\system32\ReinstallBackups\
0031\DriverFiles\DriverA2\hcwPP2.sys
+ 2006-07-21 19:50:32 66,048 ----a-r C:\WINDOWS\system32\ReinstallBackups\
0031\DriverFiles\DriverA2\hcwXDS.dll
+ 2008-04-14 00:11:55 47,616 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0031\DriverFiles\i386\iyuv_32.dll
+ 2008-04-13 19:16:36 141,056 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0031\DriverFiles\i386\ks.sys
+ 2008-04-14 00:11:56 4,096 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0031\DriverFiles\i386\ksuser.dll
+ 2008-04-14 00:12:45 294,912 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0031\DriverFiles\i386\msh263.drv
+ 2008-04-14 00:12:01 16,896 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0031\DriverFiles\i386\msyuv.dll
+ 2001-08-18 03:36:34 8,192 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0031\DriverFiles\i386\tsbyuv.dll
+ 2008-04-14 00:12:08 53,760 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0031\DriverFiles\i386\vfwwdm32.dll
- 2008-07-02 12:12:08 16,384 --sha-w C:\WINDOWS\Temp\Cookies\index.dat
+ 2008-07-09 00:24:26 16,384 --sha-w C:\WINDOWS\Temp\Cookies\index.dat
- 2008-07-02 12:12:08 16,384 --sha-w C:\WINDOWS\Temp\History\History.IE5\index.dat
+ 2008-07-09 00:24:26 16,384 --sha-w C:\WINDOWS\Temp\History\History.IE5\index.dat
+ 2008-07-09 00:24:00 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_9e4.dat
+ 2008-07-09 00:27:45 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_cfc.dat
- 2008-07-02 12:12:08 32,768 --sha-w C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-09 00:24:26 32,768 --sha-w C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2005-09-23 06:35:10 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0ee63867\vcomp.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
"Orb"="H:\Orb\bin\OrbTray.exe" [2008-05-13 20:29 507904]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 18:07 1828136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 17:12 131072]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 10:12 90112]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 16:22 3739648]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 18:08 813912]
"OSSelectorReinstall"="C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe" [2006-04-12 16:15 1261475]
"RemoteControl"="h:\PowerDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="H:\Itunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-01 01:25 115560]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2008-04-28 17:14 570664]
"NBKeyScan"="H:\Ahead\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 17:29 2221352]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="H:\Picasa2\PicasaMediaDetector.exe" [2007-09-27 20:17 443968]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 03:18 437160]
C:\Documents and Settings\Joel\Start Menu\Programs\Startup\
No-IP Duct.lnk - H:\No-IP\DUC20.exe [2007-03-05 13:48:02 1172992]
r.exe.lnk - C:\Program Files\RaidenFTPD\r.exe [2007-02-19 10:01:08 4763648]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoStart IR.lnk - H:\WinTV\Ir.exe [2007-10-24 16:57:40 106551]
Logitech SetPoint.lnk - H:\Logitech\SetPoint\SetPoint.exe [2007-07-25 07:43:50 692224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antvirus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
backup=C:\WINDOWS\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Joel^Start Menu^Programs^Startup^palmOne Registration.lnk]
path=C:\Documents and Settings\Joel\Start Menu\Programs\Startup\palmOne Registration.lnk
backup=C:\WINDOWS\pss\palmOne Registration.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 H:\Itunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
--a------ 2007-03-14 17:52 3770024 H:\TomTom HOME\TomTomHOME.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"H:\\utorrent.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Symantec AntiVirus\\Rtvscan.exe"=
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"I:\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"=
"I:\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"=
"H:\\Joost\\xulrunner\\tvprunner.exe"=
"C:\\Program Files\\kontiki\\KService.exe"=
"H:\\FlashFXP\\FlashFXP.exe"=
"H:\\Itunes\\iTunes.exe"=
"C:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"H:\\Orb\\bin\\Orb.exe"=
"H:\\Orb\\bin\\OrbTray.exe"=
"H:\\Orb\\bin\\OrbStreamerClient.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R3 HauppaugeTVServer;HauppaugeTVServer;C:\PROGRA~1\WinTV\HCWTVS~1.EXE [2007-02-20 15:11]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2007-05-29 13:55]
S3 PsSdk30;PsSdk30;C:\WINDOWS\system32\Drivers\PsSdk30.drv []
S3 SIUSBXP;SIUSBXP;C:\WINDOWS\system32\drivers\SiUSBXp.sys [2007-03-01 13:11]
S3 ultradfg;ultradfg;C:\WINDOWS\system32\DRIVERS\ultradfg.sys [2007-12-05 01:27]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4021c7ee-c0e4-11db-bdb1-005056c00008}]
\Shell\AutoRun\command - L:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{55a810a2-d635-11db-b854-000129d2ec15}]
\Shell\AutoRun\command - G:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{60b359ca-d0b5-11db-b851-000129d2ec15}]
\Shell\AutoRun\command - L:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E555}]
F:\SlySoft\AnyDVD 6.3.0.0\AnyDVD leftover killer 1.3.exe -M
.
Contents of the 'Scheduled Tasks' folder
"2008-07-05 02:34:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-09 00:26:43 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-08 19:25:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdk30]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\PsSdk30.drv"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Symantec AntiVirus\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
H:\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec AntiVirus\SmcGui.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
H:\AVG Anti-Spyware 7.5\guard.exe
H:\iPod Access for Windows\iPAHelper.exe
C:\Program Files\kontiki\KService.exe
H:\Ahead\Nero\Nero8\Nero BackItUp\NBService.exe
H:\Orb\bin\OrbMediaService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
H:\Orb\bin\Orb.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
C:\PROGRA~1\WinTV\HCBE33~1.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-07-08 19:42:41 - machine was rebooted [Joel]
ComboFix-quarantined-files.txt 2008-07-09 00:42:29
ComboFix2.txt 2008-07-02 12:28:10
Pre-Run: 1,457,459,200 bytes free
Post-Run: 1,444,724,736 bytes free
329 --- E O F --- 2008-07-02 08:00:26