Combofix log.
ComboFix 08-02.05.3 - Rick 2008-02-07 17:07:16.1 - NTFSx86
Microsoft Windows Vista Business 6.0.6000.0.1252.1.1033.18.1264 [GMT -8:00]
Running from: C:\Users\Rick\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\drivers\atapii.sys
C:\Windows\system32\drivers\core.cache.dsk
C:\Windows\system32\drivers\iSightFTT.sys
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Users\Rick\AppData\Roaming\macromedia\Flash Player\#SharedObjects\4MWZSTZW\www.broadcaster.com
C:\Users\Rick\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Users\Rick\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Windows\system32\drivers\atapii.sys
C:\Windows\system32\drivers\core.cache.dsk
C:\Windows\system32\drivers\iSightFTT.sys
----- BITS: Possible infected sites -----
hxxp://www.download.windowsupdate.com
hxxp://j+|C̛v+@J:NGD_DQ{zZOmO̢\}&\Hǯ@WU Client Download S-1-5-18@x`l@\???? 6VwoQZCDHM6VwoQZCDHMXu(yh(yh(yh(yhoV2vZOmO̢GD_DQ{zGD_DQ{zGD_DQ{z+@J:Nj+|C̛vate.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_ISIGHTFTT
-------\iSightFTT
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-06 17:06 . 2008-02-06 17:06 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-05 20:43 . 2008-02-05 20:43 <DIR> d-------- C:\Windows\PCHEALTH
2008-02-05 16:39 . 2008-02-05 16:39 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-05 16:39 . 2008-02-05 16:39 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-04 20:03 . 2008-02-04 20:03 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-04 18:57 . 2008-02-05 18:54 <DIR> d-------- C:\Program Files\StarWarsGalaxies
2008-02-03 21:08 . 2008-02-04 19:39 <DIR> d-------- C:\Downloads
2008-02-03 21:01 . 2008-02-03 21:01 <DIR> d-------- C:\$WINDOWS.~BT
2008-02-03 08:14 . 2008-02-03 08:14 <DIR> d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-02-03 08:14 . 2008-02-03 08:14 <DIR> d-------- C:\ProgramData\SUPERAntiSpyware.com
2008-02-03 08:13 . 2008-02-04 20:11 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-02 17:53 . 2008-02-02 17:53 <DIR> d-------- C:\Windows\McAfee.com
2008-02-02 13:02 . 2008-02-02 13:02 0 --a------ C:\Windows\nsreg.dat
2008-02-01 19:01 . 2008-02-05 16:39 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-02-01 19:01 . 2008-02-05 16:39 <DIR> d-------- C:\ProgramData\Lavasoft
2008-02-01 18:21 . 2008-02-01 18:21 <DIR> dr------- C:\Windows\System32\config\systemprofile\Contacts
2008-02-01 18:10 . 2008-02-07 17:12 7,418 --a------ C:\Windows\System32\Config.MPF
2008-02-01 18:09 . 2008-02-01 19:05 <DIR> d-------- C:\Users\Rick\AppData\Roaming\SiteAdvisor
2008-02-01 18:09 . 2008-02-01 18:09 <DIR> d-------- C:\Users\All Users\SiteAdvisor
2008-02-01 18:09 . 2008-02-01 18:09 <DIR> d-------- C:\ProgramData\SiteAdvisor
2008-02-01 18:09 . 2008-02-03 08:03 <DIR> d-------- C:\Program Files\SiteAdvisor
2008-02-01 18:08 . 2007-07-21 09:08 40,488 --a------ C:\Windows\System32\drivers\mfesmfk.sys
2008-02-01 18:08 . 2007-07-21 09:08 35,240 --a------ C:\Windows\System32\drivers\mfebopk.sys
2008-02-01 18:08 . 2007-07-24 12:02 33,800 --a------ C:\Windows\System32\drivers\mferkdk.sys
2008-02-01 18:07 . 2008-02-01 18:07 <DIR> d-------- C:\Program Files\McAfee.com
2008-02-01 18:07 . 2008-02-06 17:29 <DIR> d-------- C:\Program Files\McAfee
2008-02-01 18:07 . 2008-02-01 18:24 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-02-01 18:07 . 2007-07-21 09:08 201,288 --a------ C:\Windows\System32\drivers\mfehidk.sys
2008-02-01 18:07 . 2007-07-13 09:21 125,728 --a------ C:\Windows\System32\drivers\Mpfp.sys
2008-02-01 18:07 . 2007-07-24 07:40 79,304 --a------ C:\Windows\System32\drivers\mfeavfk.sys
2008-02-01 17:55 . 2008-02-01 18:10 <DIR> d-------- C:\Users\All Users\McAfee
2008-02-01 17:55 . 2008-02-01 18:10 <DIR> d-------- C:\ProgramData\McAfee
2008-02-01 17:50 . 2008-02-01 17:50 <DIR> d-------- C:\Users\All Users\Avg7
2008-02-01 17:50 . 2008-02-01 17:50 <DIR> d-------- C:\ProgramData\Avg7
2008-01-29 16:29 . 2008-02-07 17:16 54,156 --ah----- C:\Windows\QTFont.qfn
2008-01-29 16:29 . 2008-01-29 16:29 1,409 --a------ C:\Windows\QTFont.for
2008-01-28 18:43 . 2008-01-28 18:43 <DIR> d-------- C:\Program Files\iTunes
2008-01-28 18:43 . 2008-01-28 18:43 <DIR> d-------- C:\Program Files\iPod
2008-01-28 18:42 . 2008-01-28 18:43 <DIR> d-------- C:\Program Files\QuickTime
2008-01-28 18:39 . 2008-01-28 18:39 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-01-28 18:37 . 2008-01-28 18:37 <DIR> d-------- C:\Program Files\Apple Software Update
2008-01-26 11:52 . 2008-01-26 11:52 <DIR> d-------- C:\Program Files\Common Files\Steam
2008-01-24 12:09 . 2008-01-24 12:14 <DIR> d-------- C:\Program Files\Windows Live
2008-01-24 12:09 . 2008-01-24 12:13 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-24 12:08 . 2008-01-24 12:08 <DIR> d-------- C:\Users\All Users\WLInstaller
2008-01-24 12:08 . 2008-01-24 12:08 <DIR> d-------- C:\ProgramData\WLInstaller
2008-01-24 07:38 . 2008-01-24 07:39 <DIR> d-------- C:\Program Files\Yahoo!
2008-01-21 12:26 . 2008-01-21 12:26 <DIR> d-------- C:\Users\Rick\AppData\Roaming\skypePM
2008-01-21 12:26 . 2008-01-21 12:39 <DIR> d-------- C:\Users\Rick\AppData\Roaming\Skype
2008-01-21 12:26 . 2008-01-21 12:26 32 --a------ C:\Users\All Users\ezsid.dat
2008-01-21 12:26 . 2008-01-21 12:26 32 --a------ C:\ProgramData\ezsid.dat
2008-01-21 12:25 . 2008-01-21 12:25 <DIR> d-------- C:\Users\All Users\Skype
2008-01-21 12:25 . 2008-01-21 12:25 <DIR> d-------- C:\ProgramData\Skype
2008-01-21 12:25 . 2008-01-21 20:17 <DIR> d-------- C:\Program Files\Skype
2008-01-21 12:25 . 2008-01-21 12:25 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-01-19 22:45 . 2008-01-19 22:45 205,824 --a------ C:\Windows\System32\msoeacct.dll
2008-01-19 22:45 . 2008-01-19 22:45 87,040 --a------ C:\Windows\System32\msoert2.dll
2008-01-19 22:45 . 2008-01-19 22:45 39,424 --a------ C:\Windows\System32\ACCTRES.dll
2008-01-19 22:42 . 2008-01-19 22:42 376,320 --a------ C:\Windows\System32\winsrv.dll
2008-01-19 22:42 . 2008-01-19 22:42 49,664 --a------ C:\Windows\System32\csrsrv.dll
2008-01-19 22:40 . 2008-01-19 22:40 802,816 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-01-19 22:40 . 2008-01-19 22:40 216,760 --a------ C:\Windows\System32\drivers\netio.sys
2008-01-19 22:40 . 2008-01-19 22:40 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-01-19 22:40 . 2008-01-19 22:40 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-01-19 22:40 . 2008-01-19 22:40 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-01-19 22:39 . 2008-01-19 22:39 414,208 --a------ C:\Windows\System32\msscp.dll
2008-01-19 22:39 . 2008-01-19 22:39 374,456 --a------ C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-01-19 22:38 . 2008-01-19 22:38 8,147,968 --a------ C:\Windows\System32\wmploc.DLL
2008-01-19 22:38 . 2008-01-19 22:38 356,864 --a------ C:\Windows\System32\MediaMetadataHandler.dll
2008-01-19 22:38 . 2008-01-19 22:38 7,680 --a------ C:\Windows\System32\spwmp.dll
2008-01-19 22:38 . 2008-01-19 22:38 4,096 --a------ C:\Windows\System32\msdxm.ocx
2008-01-19 22:38 . 2008-01-19 22:38 4,096 --a------ C:\Windows\System32\dxmasf.dll
2008-01-19 22:37 . 2008-01-19 22:37 396,800 --a------ C:\Windows\System32\MPSSVC.dll
2008-01-19 22:37 . 2008-01-19 22:37 392,192 --a------ C:\Windows\System32\FirewallAPI.dll
2008-01-19 22:37 . 2008-01-19 22:37 178,688 --a------ C:\Windows\System32\iphlpsvc.dll
2008-01-19 22:37 . 2008-01-19 22:37 86,016 --a------ C:\Windows\System32\icfupgd.dll
2008-01-19 22:37 . 2008-01-19 22:37 63,488 --a------ C:\Windows\System32\drivers\mpsdrv.sys
2008-01-19 22:37 . 2008-01-19 22:37 61,952 --a------ C:\Windows\System32\cmifw.dll
2008-01-19 22:37 . 2008-01-19 22:37 23,040 --a------ C:\Windows\System32\drivers\tunnel.sys
2008-01-19 22:37 . 2008-01-19 22:37 16,896 --a------ C:\Windows\System32\wfapigp.dll
2008-01-19 22:37 . 2008-01-19 22:37 15,360 --a------ C:\Windows\System32\drivers\TUNMP.SYS
2008-01-19 22:34 . 2008-01-19 22:34 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-19 22:34 . 2008-01-19 22:34 1,686,016 --a------ C:\Windows\System32\gameux.dll
2008-01-19 22:34 . 2008-01-19 22:34 104,448 --a------ C:\Windows\System32\DWWIN.EXE
2008-01-19 22:33 . 2008-01-19 22:33 1,191,936 --a------ C:\Windows\System32\msxml3.dll
2008-01-19 22:33 . 2008-01-19 22:33 229,888 --a------ C:\Windows\System32\msshsq.dll
2008-01-19 22:33 . 2008-01-19 22:33 2,048 --a------ C:\Windows\System32\msxml3r.dll
2008-01-19 22:32 . 2008-01-19 22:32 224,768 --a------ C:\Windows\System32\drivers\usbport.sys
2008-01-19 22:32 . 2008-01-19 22:32 192,000 --a------ C:\Windows\System32\drivers\usbhub.sys
2008-01-19 22:32 . 2008-01-19 22:32 73,216 --a------ C:\Windows\System32\drivers\usbccgp.sys
2008-01-19 22:32 . 2008-01-19 22:32 38,400 --a------ C:\Windows\System32\drivers\usbehci.sys
2008-01-19 22:32 . 2008-01-19 22:32 23,040 --a------ C:\Windows\System32\drivers\usbuhci.sys
2008-01-19 22:32 . 2008-01-19 22:32 8,704 --a------ C:\Windows\System32\hcrstco.dll
2008-01-19 22:32 . 2008-01-19 22:32 8,704 --a------ C:\Windows\System32\hccoin.dll
2008-01-19 22:32 . 2008-01-19 22:32 5,888 --a------ C:\Windows\System32\drivers\usbd.sys
2008-01-19 22:30 . 2008-01-19 22:30 1,327,104 --a------ C:\Windows\System32\quartz.dll
2008-01-19 22:29 . 2008-01-19 22:29 223,232 --a------ C:\Windows\System32\WMASF.DLL
2008-01-19 22:29 . 2008-01-19 22:29 9,728 --a------ C:\Windows\System32\LAPRXY.DLL
2008-01-19 22:29 . 2008-01-19 22:29 2,048 --a------ C:\Windows\System32\asferror.dll
2008-01-19 22:25 . 2008-01-19 22:25 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-07 01:08 --------- d-----w C:\Program Files\Java
2008-02-06 04:51 --------- d-----w C:\ProgramData\Microsoft Help
2008-01-29 02:44 --------- d-----w C:\Users\Rick\AppData\Roaming\Apple Computer
2008-01-29 02:43 --------- d-----w C:\ProgramData\Apple Computer
2008-01-24 15:35 --------- d-----w C:\Program Files\Common Files\Logitech
2008-01-24 04:54 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-24 01:13 --------- d-----w C:\Users\Rick\AppData\Roaming\Juniper Networks
2008-01-21 19:50 --------- d-----w C:\Program Files\Google
2008-01-20 07:00 174 --sha-w C:\Program Files\desktop.ini
2008-01-20 06:55 --------- d-----w C:\Program Files\Windows Mail
2008-01-20 06:55 --------- d-----w C:\Program Files\Windows Defender
2008-01-20 06:55 --------- d-----w C:\Program Files\Windows Calendar
2008-01-20 06:54 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-20 06:46 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys
2008-01-20 06:46 619,008 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
2008-01-20 06:46 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys
2008-01-20 06:46 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
2008-01-20 06:46 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
2008-01-20 06:44 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2008-01-20 06:44 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2008-01-20 06:44 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2008-01-20 06:44 2,923,520 ----a-w C:\Windows\explorer.exe
2008-01-20 06:44 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
2008-01-20 06:34 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-20 06:34 449,024 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-20 06:34 2,143,744 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-20 06:34 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-01-20 06:26 320,000 ----a-w C:\Windows\system32\drivers\csc.sys
2008-01-20 06:23 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-01-20 05:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-20 05:43 --------- d-----w C:\ProgramData\Symantec
2008-01-20 05:28 --------- d-----w C:\Program Files\Realtek
2008-01-20 04:35 641 ----a-w C:\Windows\system32\drivers\stwrte.log
2008-01-20 03:24 484 ----a-w C:\Windows\system32\drivers\sthdae.log
2008-01-19 16:12 --------- d-----w C:\Users\Rick\AppData\Roaming\Zylom
2008-01-19 16:12 --------- d-----w C:\Users\Rick\AppData\Roaming\Xfire
2008-01-19 16:12 --------- d-----w C:\Users\Rick\AppData\Roaming\U3
2008-01-19 16:12 --------- d-----w C:\Users\Rick\AppData\Roaming\teamspeak2
2008-01-19 16:12 --------- d-----w C:\Users\Rick\AppData\Roaming\Nero
2008-01-19 16:12 --------- d-----w C:\Users\Rick\AppData\Roaming\NCH Swift Sound
2008-01-19 16:12 --------- d-----w C:\Users\Rick\AppData\Roaming\LimeWire
2008-01-19 16:12 --------- d-----w C:\Users\Rick\AppData\Roaming\CoffeeCup Software
2008-01-19 16:03 --------- d-----w C:\Program Files\Zylom Games
2008-01-19 16:03 --------- d-----w C:\Program Files\Xvid
2008-01-19 16:03 --------- d-----w C:\Program Files\Xfire
2008-01-19 16:03 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-01-19 16:03 --------- d-----w C:\Program Files\Trillian
2008-01-19 16:03 --------- d-----w C:\Program Files\Teamspeak2_RC2
2008-01-19 16:02 --------- d-----w C:\Program Files\Sony
2008-01-19 16:02 --------- d-----w C:\Program Files\Real
2008-01-19 16:02 --------- d-----w C:\Program Files\Nero
2008-01-19 16:02 --------- d-----w C:\Program Files\NCH Swift Sound
2008-01-19 16:02 --------- d-----w C:\Program Files\MSXML 6.0
2008-01-19 16:02 --------- d-----w C:\Program Files\MSBuild
2008-01-19 16:02 --------- d-----w C:\Program Files\Microsoft.NET
2008-01-19 16:02 --------- d-----w C:\Program Files\Microsoft Works
2008-01-19 16:02 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-01-19 16:01 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2008-01-19 16:01 --------- d-----w C:\Program Files\microsoft frontpage
2008-01-19 16:01 --------- d-----w C:\Program Files\Mahjong Fortuna 2 Deluxe
2008-01-19 16:01 --------- d-----w C:\Program Files\Juniper Networks
2008-01-19 16:01 --------- d-----w C:\Program Files\IrfanView
2008-01-19 16:01 --------- d-----w C:\Program Files\Intel
2008-01-19 16:01 --------- d-----w C:\Program Files\HWiNFO32
2008-01-19 16:01 --------- d-----w C:\Program Files\Common Files\xing shared
2008-01-19 16:01 --------- d-----w C:\Program Files\Common Files\Real
2008-01-19 16:01 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-19 16:01 --------- d-----w C:\Program Files\Common Files\Canon
2008-01-19 16:01 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-01-19 16:01 --------- d-----w C:\Program Files\Canon
2008-01-19 16:01 --------- d-----w C:\Program Files\BitComet
2008-01-19 16:00 --------- d-sh--w C:\ProgramData\DRM
2008-01-19 16:00 --------- d-----w C:\ProgramData\Zylom
2008-01-19 16:00 --------- d-----w C:\ProgramData\Yahoo!
2008-01-19 16:00 --------- d-----w C:\ProgramData\Viewpoint
2008-01-19 16:00 --------- d-----w C:\ProgramData\PopCap
2008-01-19 16:00 --------- d-----w C:\ProgramData\Nero
2008-01-19 16:00 --------- d-----w C:\ProgramData\NCH Swift Sound
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-11-02 01:45 8704]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2007-06-21 15:12 36640]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-07-22 20:29 1160480]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-19 22:41 1006264]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-08 00:58 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"SigmatelSysTrayApp"="sttray.exe" [2007-10-08 20:59 303104 C:\Windows\sttray.exe]
"RecordPadRun"="C:\Program Files\NCH Swift Sound\RecordPad\recordpad.exe" [ ]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [ ]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [ ]
"IRW"="C:\Windows\system32\IRW.exe" [2007-10-08 20:56 147456]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 14:52 849280]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2006-11-02 01:44 989696 C:\Windows\System32\bthprops.cpl]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"Apple_KbdMgr"="C:\Program Files\Boot Camp\KbdMgr.exe" [2007-10-08 22:06 419120]
"AppleTime"="C:\WINDOWS\system32\AppleTime.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"DelayShred"="c:\program files\mcafee\mshr\ShrCL.exe" [2007-07-25 15:10 111904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"DisableCAD"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Windows Desktop Search.lnk
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"CoolSwitch"=C:\WINDOWS\system32\taskswitch.exe
R1 NEOFLTR_600_12141;Juniper Networks TDI Filter Driver (NEOFLTR_600_12141);C:\WINDOWS\system32\Drivers\NEOFLTR_600_12141.SYS [2007-10-02 15:51]
R2 HWiNFO32;HWiNFO32 Kernel Driver;C:\Program Files\HWiNFO32\HWiNFO32.SYS [2007-09-14 13:15]
R2 KeyAgent;KeyAgent;C:\Windows\system32\drivers\KeyAgent.sys [2007-10-08 20:56]
R2 MacHALDriver;Mac HAL;C:\Windows\system32\drivers\MacHALDriver.sys [2007-10-08 20:56]
R3 aapltp;Apple Trackpad;C:\Windows\system32\DRIVERS\aapltp.sys [2007-10-08 20:56]
R3 applebt;Apple Built-in Bluetooth;C:\Windows\system32\DRIVERS\applebt.sys [2007-10-08 20:56]
R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2007-10-08 20:56]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-10-08 20:55]
R3 IRRemoteFlt;IR Receiver Filter Driver;C:\Windows\system32\DRIVERS\IRFilter.sys [2007-10-08 20:56]
R3 KeyMagic;USB Keyboard HID Filter;C:\Windows\system32\DRIVERS\KeyMagic.sys [2007-10-08 20:56]
S3 aapltctp;Apple Trackpad Enabler;C:\Windows\system32\DRIVERS\aapltctp.sys [2007-10-08 20:56]
S3 BthKicker;Apple Bluetooth Device Driver;C:\Windows\system32\DRIVERS\BthKicker.sys [2007-10-08 20:56]
S3 IFXTPM;IFXTPM;C:\Windows\system32\DRIVERS\IFXTPM.SYS [2005-10-10 14:46]
S3 iSightUpdate;iSight Update Driver;C:\Windows\system32\DRIVERS\iSightUP.sys [2007-10-08 20:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
WudfServiceGroup REG_MULTI_SZ WUDFSvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a1d892d2-c6a5-11dc-a144-806e6f6e6963}]
\shell\AutoRun\command - D:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-02 02:24:48 C:\Windows\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-02-02 02:24:48 C:\Windows\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-07 17:16:23
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\AppleOSSMgr.exe
C:\Windows\system32\AppleTimeSrv.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-02-07 17:19:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-08 01:19:00
.
2008-02-06 04:51:54 --- E O F ---