ComboFix 08-10-07.06 - krazyCarl 2008-10-07 22:25:21.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.634 [GMT -6:00]
Running from: C:\Documents and Settings\krazyCarl\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\krazyCarl\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\{05fef975-5cf1-2df2-d70f-7dd437e6d660}.dll
C:\WINDOWS\system32\iolo.ini
C:\WINDOWS\system32\ioloBootDefrag.cfg
C:\windows\system32\rmwnw64m.exe
C:\WINDOWS\system32\xnnkiqlpgou.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\iolo
C:\Program Files\iolo\Common\Lib\is-7BT6H.tmp
C:\Program Files\iolo\Common\Lib\is-9TSUS.tmp
C:\Program Files\iolo\Common\Lib\is-B8JKT.tmp
C:\Program Files\iolo\Common\Lib\is-P7JPQ.tmp
C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\is-QADQR.tmp
C:\Program Files\iolo\System Mechanic Professional 7\is-A1B6K.tmp
C:\SDFix
C:\SDFix\Add_DBFix_RunOnce_key.inf
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\Cghtme.exe
C:\SDFix\apps\clb1.txt
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\DBFix.inf
C:\SDFix\apps\download.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.inf
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBeep.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FixComponents.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixSchedule.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\grep.exe
C:\SDFix\apps\HaxdFix.reg
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\HPFix3.reg
C:\SDFix\apps\HPFix4.reg
C:\SDFix\apps\HPFix5.reg
C:\SDFix\apps\HPFix6.reg
C:\SDFix\apps\HPFix7.reg
C:\SDFix\apps\HPFix8.reg
C:\SDFix\apps\HPFix9.reg
C:\SDFix\apps\Installed.txt
C:\SDFix\apps\isadmin.exe
C:\SDFix\apps\leg2.txt
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\moveex.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\NewFolder.zip
C:\SDFix\apps\NewFolder\FIXLM.reg
C:\SDFix\apps\NewFolder\FixPath.exe
C:\SDFix\apps\NewFolder\FixRedir.reg
C:\SDFix\apps\NewFolder\FixSchedule.reg
C:\SDFix\apps\NewFolder\FixWebCheck.reg
C:\SDFix\apps\NewFolder\fixXP.reg
C:\SDFix\apps\NewFolder\FixXPsp2.reg
C:\SDFix\apps\NewFolder\grep.exe
C:\SDFix\apps\NewFolder\HaxdFix.reg
C:\SDFix\apps\NewFolder\HPFix2.reg
C:\SDFix\apps\Process.exe
C:\SDFix\apps\procs.exe
C:\SDFix\apps\procs.zip
C:\SDFix\apps\psservice.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\regedit.exe
C:\SDFix\apps\Replace\w2k\AUTOEXEC.NT
C:\SDFix\apps\Replace\w2k\beep.sys
C:\SDFix\apps\Replace\w2k\command.com
C:\SDFix\apps\Replace\w2k\command.PIF
C:\SDFix\apps\Replace\w2k\CONFIG.NT
C:\SDFix\apps\Replace\w2k\null.sys
C:\SDFix\apps\Replace\xp\AUTOEXEC.NT
C:\SDFix\apps\Replace\xp\beep.sys
C:\SDFix\apps\Replace\xp\command.com
C:\SDFix\apps\Replace\xp\command.PIF
C:\SDFix\apps\Replace\xp\CONFIG.NT
C:\SDFix\apps\Replace\xp\null.sys
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\RestartIt!.zip
C:\SDFix\apps\Restore_SafeBoot_Windows2000.reg
C:\SDFix\apps\Restore_SafeBoot_WindowsXP.reg
C:\SDFix\apps\Restore_SafeBoot_WindowsXP_SP2.reg
C:\SDFix\apps\Restore_SafeBoot_WindowsXP_SP3.reg
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\sed.exe
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\srv2bk.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\Swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\vfind.exe
C:\SDFix\apps\WINMSG.EXE
C:\SDFix\apps\winsec.reg
C:\SDFix\apps\zip.exe
C:\SDFix\backups\backupreg.zip
C:\SDFix\backups\catchme.log
C:\SDFix\backups\HOSTS
C:\SDFix\backups_old\backupreg.zip
C:\SDFix\backups_old\backups.zip
C:\SDFix\backups_old\catchme.log
C:\SDFix\backups_old\HOSTS
C:\SDFix\catchme.exe
C:\SDFix\DBFix.bat
C:\SDFix\dummy.sys
C:\SDFix\Report.txt
C:\SDFix\Report_old_1.txt
C:\SDFix\Report2.txt
C:\SDFix\RunThis.bat
C:\SDFix\SDFIX_ReadMe_Online.url
C:\SDFix\VirusAlertRepair.inf
C:\SDFix\W2K_VirusAlert_Repair.inf
C:\SDFix\XP_VirusAlert_Repair.inf
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\iolo.ini
C:\WINDOWS\system32\ioloBootDefrag.cfg
.
((((((((((((((((((((((((( Files Created from 2008-09-08 to 2008-10-08 )))))))))))))))))))))))))))))))
.
2008-09-27 18:31 . 2008-09-27 18:33 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-27 18:31 . 2008-09-27 18:31 <DIR> d-------- C:\Documents and Settings\krazyCarl\Application Data\Malwarebytes
2008-09-27 18:31 . 2008-09-27 18:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-27 18:31 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-27 18:31 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-27 18:11 . 2008-09-27 18:11 578,560 --a--c--- C:\WINDOWS\system32\dllcache\user32.dll
2008-09-27 18:09 . 2008-09-27 18:09 <DIR> d-------- C:\WINDOWS\ERUNT
2008-09-26 12:30 . 2008-09-26 12:30 186,368 --a------ C:\Documents and Settings\All Users\mQeVS.exe
2008-09-25 19:59 . 2008-09-27 17:59 <DIR> d-------- C:\stop the spammin
2008-09-25 19:59 . 2008-09-25 19:59 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-25 19:58 . 2008-09-25 19:58 <DIR> d-------- C:\Spybot search and destroy
2008-09-20 16:55 . 2008-09-20 16:55 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-09-20 16:55 . 2008-09-20 16:55 <DIR> d-------- C:\WINDOWS\system32\en
2008-09-20 16:55 . 2008-09-20 16:55 <DIR> d-------- C:\WINDOWS\system32\bits
2008-09-20 16:55 . 2008-09-20 16:55 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-20 16:48 . 2008-09-20 16:48 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-09-18 15:08 . 2007-04-17 03:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-09-18 15:08 . 2007-03-07 23:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-09-18 15:08 . 2008-06-23 10:57 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-09-18 15:08 . 2008-06-23 10:57 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-09-18 15:08 . 2008-06-23 10:57 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-09-18 15:08 . 2008-06-23 10:57 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-09-18 15:08 . 2008-06-23 10:57 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-09-18 15:08 . 2008-06-23 03:20 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-09-18 15:07 . 2008-06-23 10:57 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-09-18 11:42 . 2008-09-18 11:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-09-18 11:41 . 2008-09-18 11:41 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-16 20:14 . 2008-09-16 20:16 <DIR> d-------- C:\Program Files\VirtualDJ
2008-09-15 21:58 . 2008-09-15 21:58 <DIR> d-------- C:\Program Files\Vstplugins
2008-09-15 21:53 . 2008-09-15 21:53 <DIR> d-------- C:\Documents and Settings\krazyCarl\Application Data\Publish Providers
2008-09-15 21:53 . 2008-09-15 21:53 <DIR> d-------- C:\Documents and Settings\krazyCarl\Application Data\NetMedia Providers
2008-09-15 21:50 . 2008-09-15 21:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sony
2008-09-15 21:48 . 1998-10-29 15:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-09-15 21:48 . 2002-12-17 16:23 33,340 --------- C:\WINDOWS\system32\dbmsqlgc.dll
2008-09-15 21:48 . 2002-10-20 14:05 24,576 --------- C:\WINDOWS\system32\dbmsgnet.dll
2008-09-15 21:46 . 2008-09-15 21:46 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-09-15 21:35 . 2008-09-15 21:35 <DIR> d-------- C:\Program Files\Audacity
2008-09-15 21:17 . 2008-09-15 21:18 44 --a------ C:\WINDOWS\SMWizard.INI
2008-09-15 21:12 . 2008-09-28 13:04 <DIR> d--h----- C:\$AVG8.VAULT$
2008-09-15 21:10 . 2008-09-15 21:10 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-15 21:10 . 2008-09-15 21:10 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-15 21:10 . 2008-09-15 21:10 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-09-15 21:10 . 2008-09-15 21:10 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-09-15 21:09 . 2008-10-07 14:34 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-09-15 21:09 . 2008-09-15 21:09 <DIR> d-------- C:\Program Files\AVG
2008-09-15 21:09 . 2008-09-15 21:35 <DIR> d-------- C:\Documents and Settings\krazyCarl\Application Data\AVGTOOLBAR
2008-09-15 21:09 . 2008-09-15 21:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-09-15 15:14 . 2008-09-15 15:14 <DIR> d-------- C:\WINDOWS\Sun
2008-09-14 18:24 . 2008-09-14 18:24 <DIR> d-------- C:\Documents and Settings\krazyCarl\Application Data\Lavasoft
2008-09-14 18:24 . 2008-10-05 16:52 <DIR> d-------- C:\Ad-Aware SE Plus
2008-09-13 22:13 . 2008-09-13 22:13 9,662 --a------ C:\WINDOWS\system32\pinkip.ico
2008-09-13 15:41 . 2008-09-13 15:41 <DIR> d-------- C:\Program Files\DivX
2008-09-12 20:46 . 2008-09-12 20:46 <DIR> d-------- C:\Documents and Settings\krazyCarl\Application Data\Sony Setup
2008-09-12 20:35 . 2008-09-15 21:53 <DIR> d-------- C:\Documents and Settings\krazyCarl\Application Data\Sony
2008-09-12 20:33 . 2008-09-15 21:43 <DIR> d-------- C:\Program Files\Sony
2008-09-12 20:33 . 2001-10-19 15:40 1,683,792 --a------ C:\WINDOWS\system32\wmvcore2.dll
2008-09-12 20:33 . 2001-10-19 15:40 665,424 --a------ C:\WINDOWS\system32\wmv8dmoe.dll
2008-09-12 20:33 . 2002-10-09 13:21 566,272 --a------ C:\WINDOWS\system32\wmvdmoe.dll
2008-09-12 20:33 . 2001-10-19 15:40 438,608 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2008-09-12 20:33 . 2001-10-19 03:05 285,184 --a------ C:\WINDOWS\system32\wmidx2.ocx
2008-09-12 20:33 . 2008-09-12 20:33 156,910 --a------ C:\WINDOWS\WMSysPr8.prx
2008-09-12 20:31 . 2008-09-15 21:41 <DIR> d-------- C:\Program Files\Sony Setup
2008-09-12 00:07 . 2004-08-03 22:41 404,990 --------- C:\WINDOWS\system32\drivers\slntamr.sys
2008-09-12 00:07 . 2004-08-03 22:41 129,535 --------- C:\WINDOWS\system32\drivers\slnt7554.sys
2008-09-12 00:07 . 2004-08-03 22:41 95,424 --------- C:\WINDOWS\system32\drivers\slnthal.sys
2008-09-12 00:07 . 2008-04-13 18:12 73,796 --------- C:\WINDOWS\system32\slserv.exe
2008-09-12 00:07 . 2008-04-13 18:12 32,866 --------- C:\WINDOWS\system32\slrundll.exe
2008-09-12 00:07 . 2008-04-13 18:12 32,866 --------- C:\WINDOWS\slrundll.exe
2008-09-12 00:07 . 2008-04-13 18:12 20,992 --------- C:\WINDOWS\system32\spupdwxp.exe
2008-09-12 00:07 . 2004-08-03 22:41 13,240 --------- C:\WINDOWS\system32\drivers\slwdmsup.sys
2008-09-12 00:07 . 2008-04-13 18:12 7,680 --a------ C:\WINDOWS\system32\spdwnwxp.exe
2008-09-12 00:07 . 2008-04-13 12:36 5,888 --------- C:\WINDOWS\system32\drivers\smbali.sys
2008-09-12 00:05 . 2008-04-13 18:12 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2008-09-12 00:04 . 2008-04-13 18:11 397,312 --------- C:\WINDOWS\system32\mmcex.dll
2008-09-12 00:04 . 2008-04-13 18:11 184,320 --------- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-09-12 00:04 . 2008-04-13 18:11 106,496 --------- C:\WINDOWS\system32\mmcfxcommon.dll
2008-09-12 00:04 . 2008-04-13 18:11 86,016 --------- C:\WINDOWS\system32\mdmxsdk.dll
2008-09-12 00:04 . 2008-04-13 18:12 33,792 --------- C:\WINDOWS\system32\mmcperf.exe
2008-09-12 00:04 . 2004-08-03 22:41 11,868 --------- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2008-09-12 00:03 . 2008-04-13 18:11 61,440 --------- C:\WINDOWS\system32\kmsvc.dll
2008-09-12 00:03 . 2008-04-13 18:11 37,376 --------- C:\WINDOWS\system32\l2gpstore.dll
2008-09-12 00:03 . 2008-04-13 18:12 10,752 --------- C:\WINDOWS\system32\smtpapi.dll
2008-09-12 00:03 . 2008-04-13 18:12 9,728 --------- C:\WINDOWS\system32\rwnh.dll
2008-09-12 00:03 . 2008-04-13 18:09 6,144 --------- C:\WINDOWS\system32\kbdpash.dll
2008-09-12 00:03 . 2008-04-13 18:09 6,144 --------- C:\WINDOWS\system32\kbdnepr.dll
2008-09-12 00:03 . 2008-04-13 18:09 6,144 --------- C:\WINDOWS\system32\kbdiultn.dll
2008-09-12 00:03 . 2008-04-13 18:09 6,144 --------- C:\WINDOWS\system32\kbdbhc.dll
2008-09-12 00:03 . 2007-06-20 23:52 974 --------- C:\WINDOWS\system32\pid.inf
2008-09-12 00:01 . 2008-04-13 18:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-09-11 03:02 . 2008-09-11 03:02 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-09-10 19:18 . 2008-06-13 05:05 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-09-10 19:18 . 2008-06-13 05:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-10 19:17 . 2008-05-08 08:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-09-10 19:17 . 2006-03-20 21:23 23,040 --------- C:\WINDOWS\kb913800.exe
2008-09-10 19:16 . 2008-04-11 13:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-09-10 14:08 . 2008-09-10 14:08 <DIR> d--hs---- C:\Documents and Settings\krazyCarl\UserData
2008-09-10 00:31 . 2008-09-16 19:23 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-09-09 21:07 . 2008-09-09 21:07 <DIR> d-------- C:\Documents and Settings\krazyCarl\Application Data\Apple Computer
2008-09-09 21:06 . 2008-09-09 21:06 <DIR> d-------- C:\Program Files\iPod
2008-09-09 21:06 . 2008-04-17 13:12 107,368 --a------ C:\WINDOWS\system32\GEARAspi.dll
2008-09-09 21:06 . 2008-04-17 13:12 15,464 --a------ C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-09-09 21:05 . 2008-09-09 21:06 <DIR> d-------- C:\Program Files\iTunes
2008-09-09 21:05 . 2008-09-09 21:05 <DIR> d-------- C:\Program Files\Bonjour
2008-09-09 21:05 . 2008-09-09 21:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-09 21:03 . 2008-09-09 21:04 <DIR> d-------- C:\Program Files\QuickTime
2008-09-09 21:03 . 2008-09-09 21:03 <DIR> d-------- C:\Program Files\Apple Software Update
2008-09-09 21:03 . 2008-09-09 21:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-09 21:02 . 2008-09-09 21:02 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-09-09 21:02 . 2008-09-09 21:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-09-09 19:03 . 2008-09-12 21:16 <DIR> d-------- C:\Program Files\Three Rings Design
2008-09-09 18:48 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-09-09 18:48 . 2008-09-09 18:48 376 --a------ C:\WINDOWS\ODBC.INI
2008-09-09 18:46 . 2008-09-09 18:46 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-09-09 18:45 . 2008-09-09 18:45 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-09-09 18:43 . 2008-09-09 18:43 <DIR> d-------- C:\Program Files\Microsoft Works
2008-09-09 18:42 . 2008-09-09 18:45 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-09-09 18:42 . 2008-09-09 18:42 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-09-09 18:40 . 2008-09-09 18:40 <DIR> d-------- C:\Program Files\NeroInstall.bak
2008-09-09 18:39 . 2008-09-09 18:39 <DIR> d-------- C:\Documents and Settings\krazyCarl\Application Data\Nero
2008-09-09 18:29 . 2008-09-09 18:29 <DIR> d-------- C:\Program Files\Nero
2008-09-09 18:29 . 2008-09-09 18:37 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-09-09 18:29 . 2008-09-09 18:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-09-09 18:25 . 2005-09-20 10:31 135,168 --a------ C:\WINDOWS\system32\igfxres.dll
2008-09-09 18:19 . 2006-05-26 22:35 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-09-09 18:14 . 2008-09-22 00:03 <DIR> d--h----- C:\WINDOWS\$hf_mig$
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-16 03:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-10 00:19 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-06 00:05 --------- d-----w C:\Program Files\PC Wizard 2008
2008-09-05 23:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-05 23:18 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-05 23:12 --------- d-----w C:\Program Files\Windows Plus
2008-08-29 16:18 87,336 ----a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 15:53 61,440 ----a-w C:\WINDOWS\system32\dnssd.dll
2008-07-23 16:48 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-07-19 04:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 04:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 04:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 04:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 04:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 04:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 04:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 04:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
.
((((((((((((((((((((((((((((( snapshot@2008-10-03_15.38.31.03 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-28 00:10:07 2,514,944 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\NTUSER.DAT
+ 2008-10-07 05:45:11 471,040 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\NTUSER.DAT
- 2008-09-28 00:10:07 155,648 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-10-07 05:45:11 8,192 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"AWMON"="C:\Ad-Aware SE Plus\Ad-Watch.exe" [2008-09-14 517632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 114688]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-08 289576]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 74308]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-09-15 12936]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-15 97928]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-15 875288]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-15 231704]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-09-15 76040]
R2 sprtlisten;SupportSoft Listener Service;C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe [2008-01-08 1213728]
S3 BCM42XX;Broadcom iLine10 Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\bcm42xx5.sys [2001-08-17 54271]
S3 BCM44X2;BCM 10/100 Ethernet Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\BCM4E5.SYS [2001-08-17 26568]
S3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\CBTNDIS5.SYS [2003-07-16 17142]
S3 wind502u;Motorola Wireless USB Adapter WU830G Windows Driver;C:\WINDOWS\system32\DRIVERS\wind502u.sys [ ]
.
Contents of the 'Scheduled Tasks' folder
2008-10-02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-07 22:28:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-07 22:30:49
ComboFix-quarantined-files.txt 2008-10-08 04:30:12
ComboFix2.txt 2008-10-05 23:30:50
ComboFix3.txt 2008-10-03 21:39:22
Pre-Run: 71,089,913,856 bytes free
Post-Run: 71,122,186,240 bytes free
368 --- E O F --- 2008-09-22 07:06:57
and hijackthis....
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:32:12 PM, on 10/7/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wpabaln.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\internet explorer\iexplore.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.myspace.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://go.divx.com/plugin/DivXBrowserPlugin.cabO16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) -
http://h20270.www2.hp.com/ediags/gmn2/inst...ctDetection.cabO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SupportSoft Listener Service (sprtlisten) - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
--
End of file - 6776 bytes