ComboFix 08-07-23.5 - User 2008-07-31 19:23:34.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.585 [GMT 1:00]
Running from: C:\Documents and Settings\User\Desktop\Shortcuts\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-31 )))))))))))))))))))))))))))))))
.
2008-07-30 20:06 . 2008-07-30 20:06 244 --ah----- C:\sqmnoopt00.sqm
2008-07-30 20:06 . 2008-07-30 20:06 232 --ah----- C:\sqmdata00.sqm
2008-07-30 12:41 . 2008-07-31 09:26 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-07-30 09:22 . 2008-07-30 09:22 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2008-07-29 20:19 . 2008-07-29 20:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-07-29 20:19 . 2008-07-29 20:17 159,880 --a------ C:\WINDOWS\system32\drivers\pctfw2.sys
2008-07-29 20:17 . 2008-07-29 20:19 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-07-29 20:06 . 2008-07-31 09:04 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-07-29 20:06 . 2008-07-29 20:06 <DIR> d-------- C:\Documents and Settings\User\Application Data\PC Tools
2008-07-29 20:06 . 2007-12-10 13:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-07-29 20:06 . 2007-12-10 13:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-07-29 20:06 . 2008-02-01 11:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-07-29 20:06 . 2007-12-10 13:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-07-29 19:03 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-29 18:54 . 2008-07-29 18:54 <DIR> d-------- C:\Documents and Settings\Admin
2008-07-29 18:51 . 2008-07-29 18:51 <DIR> d--h----- C:\WINDOWS\PIF
2008-07-29 18:49 . 2008-07-29 19:03 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-29 18:49 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-29 18:25 . 2008-07-29 18:25 <DIR> d-------- C:\Program Files\uTorrent
2008-07-29 18:25 . 2008-07-31 19:06 <DIR> d-------- C:\Documents and Settings\User\Application Data\uTorrent
2008-07-29 15:14 . 2008-07-29 15:14 <DIR> d-------- C:\temp_dvd
2008-07-29 15:13 . 2008-07-29 15:14 <DIR> d-------- C:\Program Files\Dvd-cloner
2008-07-29 12:49 . 2008-07-29 12:49 <DIR> d-------- C:\WINDOWS\World Mosaics
2008-07-29 12:49 . 2008-07-29 12:49 <DIR> d-------- C:\Program Files\World Mosaics
2008-07-29 12:49 . 2008-07-29 12:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Fugazo
2008-07-29 08:23 . 2008-07-29 08:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SpinTop Games
2008-07-28 19:22 . 2008-07-28 19:49 207 --a------ C:\WINDOWS\maketorrent.ini
2008-07-28 10:24 . 2008-07-28 10:24 <DIR> d-------- C:\Program Files\DVDFab 5
2008-07-28 09:03 . 2008-07-28 09:03 <DIR> d-------- C:\Program Files\Common Files\Oberon Media
2008-07-28 08:38 . 2008-07-28 08:38 <DIR> d-------- C:\Program Files\Sun
2008-07-28 08:38 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-28 08:36 . 2008-07-28 08:36 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-26 20:59 . 2008-07-26 21:02 <DIR> d-------- C:\Program Files\Mystery PI The Vegas Heist
2008-07-26 17:42 . 2008-05-28 14:53 <DIR> d-------- C:\Program Files\XoftSpySE
2008-07-26 16:58 . 2008-07-26 16:58 <DIR> d-------- C:\Program Files\Google
2008-07-26 14:15 . 2008-07-29 16:02 <DIR> d-------- C:\GAMES
2008-07-26 14:07 . 2008-07-29 10:23 <DIR> d-------- C:\Program Files\Mystery Case Files Prime Suspects
2008-07-26 13:36 . 2008-07-26 16:35 <DIR> d-------- C:\Program Files\Tradewinds Legends
2008-07-26 13:27 . 2008-07-26 13:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GameHouse
2008-07-26 13:02 . 2008-07-27 09:44 <DIR> d-------- C:\Program Files\Gold Rush Treasure Hunt
2008-07-25 18:50 . 2008-07-25 18:50 <DIR> d-------- C:\WINDOWS\Tradewinds Caravans
2008-07-25 18:50 . 2008-07-25 18:50 <DIR> d-------- C:\Program Files\Tradewinds Caravans
2008-07-24 19:52 . 2008-07-24 19:52 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-24 19:04 . 2008-07-24 19:04 <DIR> d-------- C:\WINDOWS\Discovery A Seek And Find Adventure
2008-07-24 19:04 . 2008-07-24 19:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MumboJumbo
2008-07-24 18:51 . 2008-07-24 18:56 <DIR> d-------- C:\Program Files\PopCap Games
2008-07-24 18:08 . 2008-07-24 18:08 <DIR> d-------- C:\Documents and Settings\User\Application Data\Malwarebytes
2008-07-24 18:08 . 2008-07-24 18:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-24 16:31 . 2008-07-24 16:31 <DIR> d-------- C:\Documents and Settings\User\Saved Games
2008-07-24 16:31 . 2008-07-26 14:10 <DIR> d-------- C:\Documents and Settings\User\Application Data\Flood Light Games
2008-07-24 16:31 . 2008-07-26 14:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Flood Light Games
2008-07-24 16:30 . 2008-07-24 16:30 <DIR> d-------- C:\WINDOWS\Women's Murder Club - Death in Scarlet
2008-07-23 23:11 . 2008-07-24 08:25 <DIR> d-------- C:\Documents and Settings\User\Application Data\TweakNow PowerPack
2008-07-23 19:58 . 2008-07-23 19:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hot Lava Games
2008-07-23 19:57 . 2008-07-23 19:57 <DIR> d-------- C:\WINDOWS\Little Farm
2008-07-23 19:57 . 2008-07-24 11:35 <DIR> d-------- C:\Program Files\Little Farm
2008-07-23 11:00 . 2008-07-26 09:03 <DIR> d-------- C:\Documents and Settings\User\Application Data\Registry Booster
2008-07-23 09:38 . 2008-07-23 09:38 <DIR> d-------- C:\Documents and Settings\User\Application Data\Desktop Mechanic
2008-07-22 16:24 . 2008-07-22 16:24 <DIR> d-------- C:\Documents and Settings\User\Application Data\Nero
2008-07-22 16:19 . 2008-07-22 16:21 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-07-22 15:10 . 2008-07-22 15:10 <DIR> d-------- C:\WINDOWS\Build in Time
2008-07-21 16:48 . 2008-07-21 16:48 <DIR> d-------- C:\Documents and Settings\User\Application Data\Canneverbe_Limited
2008-07-21 16:31 . 2008-07-21 16:35 <DIR> d-------- C:\Documents and Settings\User\Application Data\AudioMoves
2008-07-21 13:21 . 2008-07-21 13:21 <DIR> d-------- C:\Program Files\BitDefender
2008-07-21 13:21 . 2008-07-21 13:21 <DIR> d-------- C:\Documents and Settings\User\Application Data\Bitdefender
2008-07-21 13:21 . 2008-07-21 13:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-07-21 13:19 . 2008-07-21 13:21 <DIR> d-------- C:\Program Files\Common Files\BitDefender
2008-07-21 12:41 . 2008-07-21 12:41 <DIR> d-------- C:\Documents and Settings\User\WINDOWS
2008-07-21 12:41 . 2008-07-28 10:38 <DIR> d-------- C:\Documents and Settings\User\Application Data\Vso
2008-07-21 12:41 . 2008-07-23 11:16 <DIR> d-------- C:\Documents and Settings\User\Application Data\Uniblue
2008-07-21 12:41 . 2008-07-24 18:35 <DIR> d-------- C:\Documents and Settings\User\Application Data\Lavasoft
2008-07-21 12:41 . 2008-07-21 12:41 <DIR> d-------- C:\Documents and Settings\User\Application Data\DMCache
2008-07-21 12:39 . 2008-07-31 19:15 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-21 12:39 . 2008-07-21 12:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-21 08:47 . 2008-07-21 12:42 <DIR> d-------- C:\Documents and Settings\User\Application Data\MagicDVDCreator
2008-07-19 13:59 . 2004-10-12 14:40 2,255,360 --a------ C:\WINDOWS\system32\libavcodec.dll
2008-07-19 13:59 . 2004-10-12 14:46 1,761,280 --a------ C:\WINDOWS\system32\ffdshow.ax
2008-07-19 13:59 . 2004-10-05 16:16 395,776 --a------ C:\WINDOWS\system32\libmplayer.dll
2008-07-19 13:59 . 2004-10-12 14:42 262,144 --a------ C:\WINDOWS\system32\TomsMoComp_ff.dll
2008-07-19 13:59 . 2003-04-03 00:17 172,032 --a------ C:\WINDOWS\system32\ac3filter.ax
2008-07-19 13:59 . 2004-10-04 01:50 112,640 --a------ C:\WINDOWS\system32\libmpeg2_ff.dll
2008-07-19 12:31 . 2008-07-19 12:31 81,920 --a------ C:\Documents and Settings\User\Application Data\ezpinst.exe
2008-07-19 10:42 . 2008-07-26 09:13 <DIR> d-------- C:\Program Files\Unlocker
2008-07-19 10:42 . 2008-07-29 20:19 <DIR> d-------- C:\Documents and Settings\User\Application Data\Desktopicon
2008-07-18 09:52 . 2008-07-18 09:52 <DIR> d--h----- C:\WINDOWS\Icons
2008-07-17 19:59 . 2008-07-17 19:59 <DIR> d-------- C:\Documents and Settings\User\Application Data\CyberLink
2008-07-17 19:41 . 2008-07-31 19:27 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2008-07-17 18:24 . 2008-07-17 18:24 <DIR> d-------- C:\Documents and Settings\User\Application Data\Thunderbird
2008-07-17 18:24 . 2008-07-17 18:24 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-17 17:26 . 2008-07-28 10:25 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-07-17 17:26 . 2008-07-28 10:25 47,360 --a------ C:\Documents and Settings\User\Application Data\pcouffin.sys
2008-07-17 15:46 . 2008-07-31 19:23 121 --a------ C:\WINDOWS\bdagent.INI
2008-07-17 14:59 . 2008-07-17 22:03 <DIR> d-------- C:\Program Files\Your Uninstaller 2008
2008-07-17 14:59 . 2008-07-17 14:59 <DIR> d-------- C:\Documents and Settings\User\Application Data\URSoft
2008-07-17 13:44 . 2008-07-17 14:21 <DIR> d-------- C:\Program Files\Yahoo!
2008-07-17 13:28 . 2008-07-17 13:28 42 --a------ C:\WINDOWS\system32\AK083E209605E394C.lie
2008-07-16 17:35 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-07-16 17:35 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-07-16 17:35 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-07-16 16:35 . 2002-03-04 13:27 1,140,472 --a------ C:\WINDOWS\system32\IGUltraGrid20.ocx
2008-07-16 16:35 . 2001-07-28 13:50 265,753 --a------ C:\WINDOWS\system32\AS-Exp2.ocx
2008-07-16 16:35 . 2001-04-20 02:28 28,672 --a------ C:\WINDOWS\system32\systray.ocx
2008-07-16 16:35 . 2006-05-31 15:38 10,752 --a------ C:\WINDOWS\system32\md5.dll
2008-07-16 13:14 . 2008-07-21 12:12 <DIR> d-------- C:\Webshots Data
2008-07-15 23:03 . 2008-07-15 23:03 0 --a------ C:\WINDOWS\system32\SDRemoveDB.db
2008-07-15 23:02 . 2008-07-16 13:12 63 --a------ C:\WINDOWS\system\SysSD.dll
2008-07-15 15:07 . 2008-07-15 22:45 <DIR> d-------- C:\Documents and Settings\User\Application Data\TmpRecentIcons
2008-07-15 13:18 . 2008-07-28 10:42 67 --a------ C:\WINDOWS\Easy DVD Creator.INI
2008-07-14 12:23 . 2008-07-14 12:23 <DIR> d-------- C:\WINDOWS\Sun
2008-07-14 12:19 . 2008-07-14 12:19 <DIR> d-------- C:\Garmin
2008-07-12 13:09 . 2008-07-16 16:49 <DIR> d-------- C:\Program Files\Virtual Villagers - The Secret City
2008-07-12 13:09 . 2008-07-12 13:09 <DIR> d-------- C:\Program Files\bfgclient
2008-07-12 13:09 . 2008-07-12 13:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
2008-07-12 12:06 . 2008-07-12 12:06 <DIR> d-------- C:\Program Files\PrintParade Studio
2008-07-12 12:06 . 2008-07-12 12:06 <DIR> d-------- C:\Documents and Settings\User\Application Data\Printparade
2008-07-12 12:06 . 2003-06-25 11:17 374,272 --a------ C:\WINDOWS\system32\Dav3_32.dll
2008-07-12 12:06 . 2003-06-24 13:35 143,360 --a------ C:\WINDOWS\system32\leon3_32.dll
2008-07-11 11:20 . 2008-07-11 11:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-07-10 17:40 . 2008-07-15 11:48 <DIR> d-------- C:\Downloads
2008-07-10 13:13 . 2008-07-16 16:49 <DIR> d-------- C:\Program Files\Mario Worlds
2008-07-06 13:15 . 2008-07-06 13:15 <DIR> d-------- C:\Documents and Settings\User\Application Data\PlanetPlayMore
2008-07-06 13:14 . 2008-07-07 18:35 <DIR> d-------- C:\Program Files\Tropicabana
2008-07-04 12:11 . 2008-07-04 12:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-07-04 12:07 . 2008-07-22 16:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-07-04 08:48 . 2008-07-04 12:28 <DIR> d-------- C:\Program Files\Flash Slideshow Maker Professional
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-31 12:53 0 ----a-w C:\Program Files\temp01
2008-07-21 13:18 86,792 ----a-w C:\WINDOWS\system32\drivers\bdfndisf.sys
2008-06-24 11:40 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-06-24 11:23 507,904 ----a-w C:\WINDOWS\system32\winlogon.exe
2008-06-24 10:54 --------- d-----w C:\Program Files\microsoft frontpage
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 11:05 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-16 10:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-09 10:53 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
2008-05-09 10:53 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
2008-05-09 10:53 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
2008-05-09 10:53 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
2008-05-07 09:07 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 05:42 74,752 ----a-w C:\WINDOWS\system32\storprop.dll
2008-04-14 05:42 74,240 ----a-w C:\WINDOWS\system32\usbui.dll
2008-04-14 05:42 4,274,816 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2008-04-14 04:55 1,804 ----a-w C:\WINDOWS\system32\Dcache.bin
2008-04-14 04:51 52,736 ----a-w C:\WINDOWS\system32\wzcsapi.dll
2008-04-14 04:51 52,224 ----a-w C:\WINDOWS\system32\dmutil.dll
2008-04-14 04:51 483,840 ----a-w C:\WINDOWS\system32\wzcsvc.dll
2008-04-14 04:51 47,616 ----a-w C:\WINDOWS\system32\iyuv_32.dll
2008-04-14 04:51 47,104 ----a-w C:\WINDOWS\system32\cnbjmon.dll
2008-04-14 04:51 35,328 ----a-w C:\WINDOWS\system32\pid.dll
2008-04-14 04:51 294,912 ----a-w C:\WINDOWS\system32\msh263.drv
2008-04-14 04:51 23,552 ----a-w C:\WINDOWS\system32\wdmaud.drv
2008-04-14 04:51 20,992 ----a-w C:\WINDOWS\system32\hid.dll
2008-04-14 04:51 2,065,792 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-14 04:51 16,896 ----a-w C:\WINDOWS\system32\msyuv.dll
2008-04-14 04:51 15,360 ----a-w C:\WINDOWS\system32\pjlmon.dll
2008-04-14 04:46 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 04:43 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 04:43 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 04:43 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 04:43 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 04:41 98,304 ----a-w C:\WINDOWS\system32\actxprxy.dll
2008-04-14 04:40 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 04:40 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 04:40 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-14 01:30 103,424 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-14 00:00 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 23:57 2,188,928 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 23:15 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 23:05 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll
2008-04-13 23:01 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll
2008-04-13 23:00 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-13 22:45 76,800 ----a-w C:\WINDOWS\system32\msshavmsg.dll
2008-04-13 22:09 438,784 ----a-w C:\WINDOWS\system32\xpob2res.dll
2008-04-13 22:09 2,897,920 ----a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-13 22:09 187,392 ----a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-13 22:08 306,176 ----a-w C:\WINDOWS\system32\slbcsp.dll
2008-04-13 22:08 169,984 ----a-w C:\WINDOWS\system32\sccbase.dll
2008-04-13 22:08 101,888 ----a-w C:\WINDOWS\system32\gpkcsp.dll
2008-04-13 22:07 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-13 22:07 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll
2008-04-13 21:57 79,872 ----a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-13 21:56 94,208 ----a-w C:\WINDOWS\system32\odbcint.dll
2008-04-13 21:56 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-13 21:56 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dLL
2008-04-13 21:54 20,480 ----a-w C:\WINDOWS\system32\msorc32r.dll
2008-04-13 21:51 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-13 21:39 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-13 21:33 63,488 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-13 21:33 549,376 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-13 21:24 68,768 ----a-w C:\WINDOWS\system32\mmsystem.dll
2008-04-13 21:24 53,840 ----a-w C:\WINDOWS\system32\dosx.exe
2008-04-13 21:24 5,120 ----a-w C:\WINDOWS\system32\winnls.dll
2008-04-13 21:23 92,224 ----a-w C:\WINDOWS\system32\krnl386.exe
2008-04-13 21:22 3,338 ----a-w C:\WINDOWS\system32\redir.exe
2008-04-13 21:20 42,537 ----a-w C:\WINDOWS\system32\keyboard.sys
2008-04-13 21:19 35,648 ----a-w C:\WINDOWS\system32\ntio411.sys
2008-04-13 21:19 35,424 ----a-w C:\WINDOWS\system32\ntio412.sys
2008-04-13 21:19 34,560 ----a-w C:\WINDOWS\system32\ntio804.sys
2008-04-13 21:19 34,560 ----a-w C:\WINDOWS\system32\ntio404.sys
2008-04-13 21:19 33,840 ----a-w C:\WINDOWS\system32\ntio.sys
2008-04-13 21:18 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-04-13 21:15 216,064 ----a-w C:\WINDOWS\system32\moricons.dll
2008-04-13 20:53 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll
2008-04-13 20:52 48,128 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-13 20:09 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
.
------- Sigcheck -------
2008-06-24 12:23 507904 c2d1429e210a032d36bb24493214e584 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-25 14:02 185896]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 09:53 570664]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 09:31 2221352]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
C:\Documents and Settings\User\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2008-06-25 14:42:29 63064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"mW[íµˆÖ¾`=µú¾˜v%S8’ÿÙêé>grl>Ý\†Ð=ŸàÛ±Þ"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13549:TCP"= 13549:TCP:ut1
"13549:UDP"= 13549:UDP:ut1
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-09 13:41]
R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2008-07-29 20:17]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-09 13:41]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2008-04-14 05:42]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-07-21 14:18]
S2 ioloFileInfoList;iolo FileInfoList Service;C:\Program Files\iolo\common\lib\ioloServiceManager.exe []
S2 ioloSystemService;iolo System Service;C:\Program Files\iolo\common\lib\ioloServiceManager.exe []
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-07-03 08:47]
S4 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe []
S4 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe []
S4 FreezeScreenSaver;FreezeScreenSaver;C:\WINDOWS\system32\FreezeScreenSaver.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-07-31 18:00:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-07-31 16:09:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-31 16:00:01 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2008-07-27 07:54:09 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page =
hxxp://www.google.comR0 -: HKLM-Main,Start Page =
hxxp://www.google.comO8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-31 19:26:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-07-31 19:29:19
ComboFix-quarantined-files.txt 2008-07-31 18:28:15
Pre-Run: 49,776,209,920 bytes free
Post-Run: 49,852,096,512 bytes free
313 --- E O F --- 2008-07-28 07:47:30
This is the Combofix File