I realize that uTorrent is a P2P sharing program, but I need it for something I'm doing today. I will remove it after I'm finished.
ComboFix 08-12-18.01 - Jimmy 2008-12-21 13:57:34.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1195 [GMT -5:00]
Running from: c:\documents and settings\Jimmy\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jimmy\Desktop\cfscript.txt
* Created a new restore point
FILE ::
c:\windows\system32\msnetwk.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\DNA
c:\program files\DNA\btdna.exe
c:\program files\DNA\DNAcpl.cpl
c:\program files\DNA\plugins\npbtdna.dll
c:\program files\LimeWire
c:\program files\LimeWire\hs_err_pid216.log
c:\program files\LimeWire\hs_err_pid2348.log
c:\program files\LimeWire\hs_err_pid3524.log
c:\program files\LimeWire\limewire.m3u
c:\program files\LimeWire\Playlist 1.m3u
c:\program files\LimeWire\soilwork.m3u
c:\windows\system32\msnetwk.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MS_NTSVR
-------\Service_MS NtSvr
((((((((((((((((((((((((( Files Created from 2008-11-21 to 2008-12-21 )))))))))))))))))))))))))))))))
.
2008-12-21 11:29 . 2008-12-21 14:01 <DIR> d-------- c:\program files\PeerGuardian2
2008-12-21 11:17 . 2008-12-21 11:17 <DIR> d-------- c:\program files\uTorrent
2008-12-21 11:17 . 2008-12-21 13:55 <DIR> d-------- c:\documents and settings\Jimmy\Application Data\uTorrent
2008-12-20 17:01 . 2008-12-17 17:49 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-18 16:39 . 2008-12-19 16:28 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-18 16:39 . 2008-12-18 16:39 1,409 --a------ c:\windows\QTFont.for
2008-12-17 17:49 . 2008-12-17 17:49 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-16 18:34 . 2007-12-11 09:37 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Roxio
2008-12-16 18:34 . 2007-12-11 09:15 <DIR> d-------- c:\documents and settings\Administrator\Application Data\InstallShield
2008-12-16 18:34 . 2008-12-16 18:34 <DIR> d-------- c:\documents and settings\Administrator
2008-12-13 10:27 . 2008-12-13 10:27 <DIR> d-------- c:\program files\Common Files\Thraex Software
2008-12-10 17:10 . 2008-12-10 17:10 <DIR> d-------- C:\VundoFix Backups
2008-12-08 17:00 . 2008-12-08 17:00 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\HPAppData
2008-11-29 12:23 . 2008-11-29 12:23 <DIR> d-------- c:\program files\GodzHellClient
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-21 19:04 --------- d-----w c:\program files\Steam
2008-12-21 16:27 31 ----a-w c:\documents and settings\Jimmy\jagex_runescape_preferences.dat
2008-12-20 22:01 --------- d-----w c:\program files\Java
2008-12-19 02:15 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-15 21:18 --------- d-----w c:\program files\World of Warcraft
2008-12-09 23:41 --------- d-----w c:\program files\Trend Micro
2008-12-04 18:41 --------- d-----w c:\program files\AV Vcs 6.0 DIAMOND
2008-11-23 15:48 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2008-11-12 21:23 --------- d-----w c:\program files\MSBuild
2008-11-12 21:20 --------- d-----w c:\program files\Reference Assemblies
2008-11-12 21:17 --------- d-----w c:\documents and settings\Jimmy\Application Data\Sony Setup
2008-11-12 20:54 --------- d-----w c:\documents and settings\Jimmy\Application Data\gtk-2.0
2008-11-04 04:32 --------- d-----w c:\documents and settings\All Users\Application Data\SwiftKit
2008-11-03 21:41 --------- d-----w c:\program files\Microsoft Silverlight
2008-11-02 23:24 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2008-11-02 23:24 --------- d-----w c:\program files\Windows Live
2008-11-02 23:22 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-02 23:21 2,400,784 ----a-w C:\WLinstaller.exe
2008-11-01 17:05 --------- d-----w c:\program files\HyCam2
2008-11-01 17:04 668,488 ----a-w C:\HC2Setup.exe
2008-10-28 21:35 --------- d-----w c:\documents and settings\Jimmy\Application Data\Sony
2008-10-28 21:34 --------- d-----w c:\program files\Vstplugins
2008-10-28 21:34 --------- d-----w c:\documents and settings\All Users\Application Data\Sony
2008-10-28 21:33 --------- d-----w c:\program files\Sony
2008-10-28 21:31 147,544,835 ----a-w C:\vegas70e_enu.exe
2008-10-25 21:28 --------- d-----w c:\documents and settings\All Users\Application Data\Blizzard
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 20:40 --------- d-----w c:\program files\Panda Security
2008-10-23 00:30 --------- d-----w c:\program files\RegCleaner
2008-10-23 00:18 553,687 ----a-w C:\regcleaner.exe
2008-10-22 22:48 --------- d-----w c:\documents and settings\NetworkService\Application Data\Skype
2008-10-22 20:55 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-22 20:39 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-10-22 20:37 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-22 20:34 --------- d-----w c:\program files\Lavasoft
2008-10-22 20:34 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-10-22 19:42 --------- d-----w c:\program files\Common Files\Logishrd
2008-10-22 00:44 --------- d-----w c:\program files\Common Files\SureThing Shared
2008-10-22 00:38 --------- d-----w c:\program files\Windows Live Safety Center
2008-10-22 00:37 --------- d-----w c:\program files\Common Files\AOL
2008-10-22 00:30 --------- d-----w c:\program files\CCleaner
2008-10-22 00:27 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-10-22 00:27 --------- d-----w c:\documents and settings\Jimmy\Application Data\Malwarebytes
2008-10-22 00:27 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-10-22 00:20 --------- d-----w c:\documents and settings\All Users\Application Data\WholeSecurity
2008-10-21 01:00 --------- d-----w c:\documents and settings\NetworkService\Application Data\HPAppData
2008-10-07 20:43 61,588 -c--a-w c:\windows\BricoPackUninst.cmd
2008-10-07 20:43 5,417 -c--a-w c:\windows\BricoPackFoldersDelete.cmd
2008-10-02 23:40 7,127,451 ----a-w C:\Zip.zip
2008-07-22 14:35 0 -csh--w c:\program files\desktoq.ini
2005-12-03 04:58 1,982,464 ----a-w c:\program files\Vistab2.msstyles
2008-07-22 14:25 14,080 --sha-w c:\windows\system32\mssjfilejf.dll
2008-07-22 14:25 20,192 --sha-w c:\windows\system32\vcrxfileju.dll
.
------- Sigcheck -------
2007-06-13 05:23 975360 9784e0719124e4a23989aef9e7ca02d6 c:\windows\explorer.exe
2007-06-13 06:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2008-04-13 19:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
2007-06-13 05:23 975360 9784e0719124e4a23989aef9e7ca02d6 c:\windows\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-12-18_20.02.17.42 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-19 00:18:39 101,991 ----a-w c:\windows\.jagex_cache_32\loginapplet\cache-1272026540.dat
+ 2008-12-20 01:30:16 101,991 ----a-w c:\windows\.jagex_cache_32\loginapplet\cache-1272026540.dat
- 2008-12-18 21:07:33 315,392 ----a-w c:\windows\.jagex_cache_32\runescape\jogl.dll
+ 2008-12-21 16:27:42 315,392 ----a-w c:\windows\.jagex_cache_32\runescape\jogl.dll
- 2008-12-18 21:07:33 20,480 ----a-w c:\windows\.jagex_cache_32\runescape\jogl_awt.dll
+ 2008-12-21 16:27:42 20,480 ----a-w c:\windows\.jagex_cache_32\runescape\jogl_awt.dll
- 2008-11-13 02:11:33 20,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-12-19 02:16:00 20,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-11-13 02:11:32 184,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-12-19 02:15:59 184,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2008-11-13 02:11:33 217,864 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2008-12-19 02:16:00 217,864 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2008-11-13 02:11:33 18,704 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-12-19 02:16:00 18,704 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-11-13 02:11:33 35,088 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-12-19 02:16:00 35,088 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-11-13 02:11:32 922,384 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-12-19 02:16:00 922,384 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2008-11-13 02:11:33 888,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-12-19 02:16:00 888,080 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-11-13 02:11:32 1,172,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-12-19 02:15:59 1,172,240 ----a-r c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-08-20 05:33:19 1,024,000 ----a-w c:\windows\system32\browseui.dll
+ 2008-10-16 10:20:52 1,024,000 ----a-w c:\windows\system32\browseui.dll
- 2008-08-20 05:33:17 151,040 ----a-w c:\windows\system32\cdfview.dll
+ 2008-10-16 10:20:42 151,040 ----a-w c:\windows\system32\cdfview.dll
- 2008-08-20 05:33:18 1,054,208 ----a-w c:\windows\system32\danim.dll
+ 2008-10-16 10:20:45 1,054,208 ----a-w c:\windows\system32\danim.dll
- 2008-08-20 05:33:19 1,024,000 ----a-w c:\windows\system32\dllcache\browseui.dll
+ 2008-10-16 10:20:52 1,024,000 ----a-w c:\windows\system32\dllcache\browseui.dll
- 2008-08-20 05:33:17 151,040 ------w c:\windows\system32\dllcache\cdfview.dll
+ 2008-10-16 10:20:42 151,040 ------w c:\windows\system32\dllcache\cdfview.dll
- 2008-08-20 05:33:18 1,054,208 ------w c:\windows\system32\dllcache\danim.dll
+ 2008-10-16 10:20:45 1,054,208 ------w c:\windows\system32\dllcache\danim.dll
- 2008-08-20 05:33:18 357,888 ------w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-10-16 10:20:45 357,888 ------w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-20 05:33:18 205,312 ------w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-10-16 10:20:45 205,312 ------w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-20 05:33:18 55,808 ------w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-16 10:20:46 55,808 ------w c:\windows\system32\dllcache\extmgr.dll
- 2008-02-20 06:51:05 282,624 ------w c:\windows\system32\dllcache\gdi32.dll
+ 2008-10-23 13:01:36 283,648 ------w c:\windows\system32\dllcache\gdi32.dll
- 2008-08-19 09:38:57 18,432 ------w c:\windows\system32\dllcache\iedw.exe
+ 2008-10-15 14:18:21 18,432 ------w c:\windows\system32\dllcache\iedw.exe
- 2008-08-20 05:33:18 251,904 ------w c:\windows\system32\dllcache\iepeers.dll
+ 2008-10-16 10:20:46 251,904 ------w c:\windows\system32\dllcache\iepeers.dll
- 2008-08-20 05:33:18 96,256 ------w c:\windows\system32\dllcache\inseng.dll
+ 2008-10-16 10:20:46 96,256 ------w c:\windows\system32\dllcache\inseng.dll
- 2008-08-20 05:33:19 16,384 ------w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-16 10:20:50 16,384 ------w c:\windows\system32\dllcache\jsproxy.dll
- 2005-01-28 19:44:28 96,768 ----a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-06-10 10:52:04 96,768 ----a-w c:\windows\system32\dllcache\logagent.exe
- 2008-08-20 05:33:20 3,067,392 ----a-w c:\windows\system32\dllcache\mshtml.dll
+ 2008-12-12 17:27:54 3,067,392 ----a-w c:\windows\system32\dllcache\mshtml.dll
- 2008-08-20 05:33:19 449,024 ------w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-10-16 10:20:50 449,024 ------w c:\windows\system32\dllcache\mshtmled.dll
- 2008-08-20 05:33:18 146,432 ------w c:\windows\system32\dllcache\msrating.dll
+ 2008-10-16 10:20:46 146,432 ------w c:\windows\system32\dllcache\msrating.dll
- 2008-08-20 05:33:18 532,480 ------w c:\windows\system32\dllcache\mstime.dll
+ 2008-10-16 10:20:46 532,480 ------w c:\windows\system32\dllcache\mstime.dll
- 2008-08-20 05:33:18 39,424 ------w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-10-16 10:20:46 39,424 ------w c:\windows\system32\dllcache\pngfilt.dll
- 2008-08-20 05:33:19 1,499,136 ----a-w c:\windows\system32\dllcache\shdocvw.dll
+ 2008-10-16 10:20:48 1,499,136 ----a-w c:\windows\system32\dllcache\shdocvw.dll
- 2008-08-20 05:33:19 474,112 ----a-w c:\windows\system32\dllcache\shlwapi.dll
+ 2008-10-16 10:20:51 474,112 ----a-w c:\windows\system32\dllcache\shlwapi.dll
- 2006-08-21 15:52:08 246,814 ------w c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-03 10:15:47 247,326 ------w c:\windows\system32\dllcache\strmdll.dll
- 2008-08-20 05:33:19 619,008 ----a-w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 10:20:53 619,008 ----a-w c:\windows\system32\dllcache\urlmon.dll
- 2008-08-20 05:33:19 667,648 ----a-w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 10:20:49 667,648 ----a-w c:\windows\system32\dllcache\wininet.dll
- 2005-01-28 19:44:28 1,027,072 ----a-w c:\windows\system32\dllcache\wmnetmgr.dll
+ 2008-06-10 11:28:36 1,028,096 ----a-w c:\windows\system32\dllcache\WMNetmgr.dll
- 2006-12-07 05:29:34 2,374,472 ----a-w c:\windows\system32\dllcache\wmvcore.dll
+ 2008-06-10 12:07:24 2,376,760 ----a-w c:\windows\system32\dllcache\WMVCore.dll
- 2008-08-20 05:33:18 357,888 ----a-w c:\windows\system32\dxtmsft.dll
+ 2008-10-16 10:20:45 357,888 ----a-w c:\windows\system32\dxtmsft.dll
- 2008-08-20 05:33:18 205,312 ----a-w c:\windows\system32\dxtrans.dll
+ 2008-10-16 10:20:45 205,312 ----a-w c:\windows\system32\dxtrans.dll
- 2008-08-20 05:33:18 55,808 ----a-w c:\windows\system32\extmgr.dll
+ 2008-10-16 10:20:46 55,808 ----a-w c:\windows\system32\extmgr.dll
- 2008-02-20 06:51:05 282,624 ----a-w c:\windows\system32\gdi32.dll
+ 2008-10-23 13:01:36 283,648 ----a-w c:\windows\system32\gdi32.dll
- 2008-08-20 05:33:18 251,904 ----a-w c:\windows\system32\iepeers.dll
+ 2008-10-16 10:20:46 251,904 ----a-w c:\windows\system32\iepeers.dll
- 2008-08-20 05:33:18 96,256 ----a-w c:\windows\system32\inseng.dll
+ 2008-10-16 10:20:46 96,256 ----a-w c:\windows\system32\inseng.dll
- 2008-08-20 05:33:19 16,384 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-10-16 10:20:50 16,384 ----a-w c:\windows\system32\jsproxy.dll
- 2005-01-28 19:44:28 96,768 ----a-w c:\windows\system32\logagent.exe
+ 2008-06-10 10:52:04 96,768 ----a-w c:\windows\system32\logagent.exe
+ 2008-12-09 20:24:38 17,593,280 ----a-w c:\windows\system32\MRT.exe
- 2008-08-20 05:33:20 3,067,392 ----a-w c:\windows\system32\mshtml.dll
+ 2008-12-12 17:27:54 3,067,392 ----a-w c:\windows\system32\mshtml.dll
- 2008-08-20 05:33:19 449,024 ----a-w c:\windows\system32\mshtmled.dll
+ 2008-10-16 10:20:50 449,024 ----a-w c:\windows\system32\mshtmled.dll
- 2008-08-20 05:33:18 146,432 ----a-w c:\windows\system32\msrating.dll
+ 2008-10-16 10:20:46 146,432 ----a-w c:\windows\system32\msrating.dll
- 2008-08-20 05:33:18 532,480 ----a-w c:\windows\system32\mstime.dll
+ 2008-10-16 10:20:46 532,480 ----a-w c:\windows\system32\mstime.dll
- 2008-12-15 20:58:50 79,675 ----a-w c:\windows\system32\nvModes.dat
+ 2008-12-20 01:26:34 79,675 ----a-w c:\windows\system32\nvModes.dat
- 2008-08-20 05:33:18 39,424 ----a-w c:\windows\system32\pngfilt.dll
+ 2008-10-16 10:20:46 39,424 ----a-w c:\windows\system32\pngfilt.dll
- 2008-08-20 05:33:19 1,499,136 ----a-w c:\windows\system32\shdocvw.dll
+ 2008-10-16 10:20:48 1,499,136 ----a-w c:\windows\system32\shdocvw.dll
- 2008-08-20 05:33:19 474,112 ----a-w c:\windows\system32\shlwapi.dll
+ 2008-10-16 10:20:51 474,112 ----a-w c:\windows\system32\shlwapi.dll
- 2008-07-08 13:02:01 17,272 ----a-w c:\windows\system32\spmsg.dll
+ 2007-07-27 14:41:40 16,760 ------w c:\windows\system32\spmsg.dll
- 2006-08-21 15:52:08 246,814 ----a-w c:\windows\system32\strmdll.dll
+ 2008-10-03 10:15:47 247,326 ----a-w c:\windows\system32\strmdll.dll
- 2008-07-14 11:09:18 62,976 ----a-w c:\windows\system32\tzchange.exe
+ 2008-10-22 09:47:07 62,976 ----a-w c:\windows\system32\tzchange.exe
- 2008-08-20 05:33:19 619,008 ----a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 10:20:53 619,008 ----a-w c:\windows\system32\urlmon.dll
- 2008-08-20 05:33:19 667,648 ----a-w c:\windows\system32\wininet.dll
+ 2008-10-16 10:20:49 667,648 ----a-w c:\windows\system32\wininet.dll
- 2005-01-28 19:44:28 1,027,072 ----a-w c:\windows\system32\wmnetmgr.dll
+ 2008-06-10 11:28:36 1,028,096 ----a-w c:\windows\system32\WMNetmgr.dll
- 2006-12-07 05:29:34 2,374,472 ----a-w c:\windows\system32\wmvcore.dll
+ 2008-06-10 12:07:24 2,376,760 ----a-w c:\windows\system32\WMVCore.dll
- 2008-08-19 09:20:32 351,744 ----a-w c:\windows\system32\xpsp3res.dll
+ 2008-10-15 14:00:41 351,744 ----a-w c:\windows\system32\xpsp3res.dll
+ 2008-12-21 19:03:41 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_7c4.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Steam"="c:\program files\steam\steam.exe" [2008-12-11 1410296]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
"Google Update"="c:\documents and settings\Jimmy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-21 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-09 851968]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-06 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-06 81920]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-07-03 1228800]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-05-09 1392640]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-10 385024]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"nwiz"="nwiz.exe" [2007-06-06 c:\windows\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2007-06-06 c:\windows\system32\nvhotkey.dll]
c:\documents and settings\Jimmy\Start Menu\Programs\Startup\
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]
TransBar.lnk - c:\windows\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-06-01 65536]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-11 50688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifcAsrQ]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\SteamApps\\pishockj\\counter-strike source\\hl2.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"c:\\SRCDS\\srcds.exe"=
"c:\\Program Files\\Steam\\SteamApps\\pishockj\\source dedicated server\\srcds.exe"=
"c:\\Program Files\\Steam\\SteamApps\\pishockj\\counter-strike\\hl.exe"=
"c:\\Program Files\\Steam\\SteamApps\\pishockj\\zombie panic! source\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\jimmyjhp\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\pishockj\\age of chivalry\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\pishockj\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\pishockj\\insurgency\\hl2.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-10-23 28544]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2007-11-08 345696]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2007-11-08 923216]
R2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2007-11-08 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2007-11-08 566872]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2007-12-25 24652]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\DRIVERS\TM_CFW.sys [2007-11-08 280392]
S3 XDva143;XDva143;\??\c:\windows\system32\XDva143.sys []
S3 XDva186;XDva186;\??\c:\windows\system32\XDva186.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2008-06-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
2008-12-21 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\Jimmy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-21 13:51]
2008-12-21 c:\windows\Tasks\SDMsgUpdate (TE).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2007-09-26 08:53]
.
- - - - ORPHANS REMOVED - - - -
BHO-{1B93547F-5CE9-4E60-B3B8-15AE6B6F93B7} - (no file)
BHO-{1D03BF11-3729-4CDF-8C1A-4B0AFD45326A} - (no file)
BHO-{467B24BD-D8BF-453F-9DB2-B58CF8EC364F} - (no file)
BHO-{55af58ab-9339-400d-9c9c-1a83e921e47f} - (no file)
BHO-{5a4627ce-385a-4f3a-8a1e-8a80a3406117} - (no file)
BHO-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - (no file)
BHO-{90F5A359-914F-40CF-B406-082EA7F8744D} - (no file)
BHO-{B3AA6D76-A5DA-4C05-9DC1-E061E0E4528C} - (no file)
BHO-{B5F009B0-1266-4AF5-B6D5-E35FEC70E4BB} - (no file)
BHO-{E0EF78AE-5534-40FC-866D-419739FEA10C} - (no file)
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_05\bin\jusched.exe
HKLM-Run-hamukuboye - c:\windows\system32\yehifuni.dll
HKLM-Run-<NO NAME> - (no file)
.
------- Supplementary Scan -------
.
mStart Page =
hxxp://www.comcast.net/mWindow Title = Windows Internet Explorer provided by Comcast
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {EC46BC7F-E5D7-4F5B-A70B-3C2C37C1861C} = 68.87.64.146,68.87.75.194
c:\program files\Common Files\supportsoft\bin\tgctlsi.dll - c:\windows\Downloaded Program Files\sprtexternal.dll
O16 -: {42D06124-98A2-47EC-8098-3778B58CE7D5}
hxxps://actsvr.comcastonline.com/techto ... ntrols.cabc:\windows\Downloaded Program Files\sprtexternal.inf
FF - ProfilePath - c:\documents and settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\3mkdxskb.default\
FF - prefs.js: browser.search.selectedEngine - Zybez Item Database
FF - prefs.js: browser.startup.homepage -
hxxp://www.zybez.net/FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
ATTENTION: FIREFOX POLICES IS IN FORCE c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("general.useragent.vendorComment", "ax");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("security.xpconnect.activex.global.hosting_flags", 9);
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("security.classID.allowByDefault", false);
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6BF52A52-394A-11D3-B153-00C04F79FAA6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID22D6F312-B0F6-11D0-94AB-0080C74C7E95", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.rights.version", 3);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.rights.3.shown", false);
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-21 14:04:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(988)
c:\windows\System32\BCMLogon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\TRENDM~1\INTERN~1\PcCtlCom.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
.
**************************************************************************
.
Completion time: 2008-12-21 14:08:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-21 19:08:34
ComboFix2.txt 2008-12-19 01:02:51
Pre-Run: 22,627,061,760 bytes free
Post-Run: 22,617,231,360 bytes free
401 --- E O F --- 2008-12-19 02:16:03