ComboFix 08-07-07.3 - Frederik 2008-07-08 19:12:11.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.549 [GMT 2:00]
Running from: C:\Documents and Settings\Frederik\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\icon.ico
C:\WINDOWS\system32\pskill.exe
G:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-06-08 to 2008-07-08 )))))))))))))))))))))))))))))))
.
2008-07-08 15:26 . 2008-07-08 15:26 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-08 15:26 . 2008-07-08 15:26 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\SUPERAntiSpyware.com
2008-07-08 15:26 . 2008-07-08 15:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-07 14:47 . 2008-07-08 10:09 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-07 14:47 . 2008-07-07 14:47 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-07 14:37 . 2008-07-07 14:39 <DIR> d-------- C:\Program Files\Common Files\Corel
2008-07-06 19:26 . 2008-07-06 19:26 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-07-02 18:28 . 2008-07-02 18:28 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\SoundSpectrum
2008-07-02 18:27 . 2008-07-02 18:27 <DIR> d-------- C:\Program Files\SoundSpectrum
2008-07-02 10:33 . 2008-07-02 11:47 <DIR> d-------- C:\Program Files\Groove Games
2008-07-02 00:13 . 2008-07-02 00:13 <DIR> d-------- C:\VundoFix Backups
2008-07-01 12:03 . 2008-07-01 12:03 103 --a------ C:\ioSpecial.ini
2008-06-29 23:49 . 2000-01-24 05:01 2,023,424 --a------ C:\WINDOWS\system32\vcl50.bpl
2008-06-29 23:49 . 2000-08-07 05:01 1,497,088 --a------ C:\WINDOWS\system32\cc3250mt.dll
2008-06-29 23:49 . 2000-01-24 05:01 248,832 --a------ C:\WINDOWS\system32\vclx50.bpl
2008-06-29 23:49 . 2000-01-31 05:00 25,600 --a------ C:\WINDOWS\system32\borlndmm.dll
2008-06-27 23:49 . 2008-06-28 08:02 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\skypePM
2008-06-27 23:49 . 2008-06-27 23:49 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-06-27 23:48 . 2008-06-27 23:48 <DIR> d-------- C:\Program Files\Skype
2008-06-27 23:48 . 2008-06-27 23:48 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-06-27 23:48 . 2008-06-28 11:14 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\Skype
2008-06-27 23:47 . 2008-06-27 23:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-06-27 17:40 . 2008-06-27 17:46 <DIR> d-------- C:\Program Files\XP Smoker
2008-06-27 16:37 . 2008-07-07 12:44 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\McAfee
2008-06-26 19:55 . 2008-06-26 19:58 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\Winamp
2008-06-26 18:14 . 2008-06-26 19:47 <DIR> d-------- C:\Program Files\Turbo Searcher
2008-06-26 18:14 . 2008-06-26 19:45 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\TS_STD
2008-06-23 21:58 . 2008-06-23 21:58 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\MixMeister Technology
2008-06-23 21:57 . 2008-06-23 21:58 <DIR> d-------- C:\Program Files\MixMeister Fusion + Video
2008-06-23 16:21 . 2008-06-23 16:21 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\XemiComputers
2008-06-23 16:21 . 2008-06-23 16:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\XemiComputers
2008-06-22 21:59 . 2008-06-22 22:17 <DIR> d-------- C:\Program Files\AoA Audio Extractor
2008-06-22 21:24 . 2008-06-22 21:28 <DIR> d-------- C:\Movavi files
2008-06-22 21:19 . 2008-06-22 21:19 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\dvdcss
2008-06-22 21:17 . 2004-07-19 18:41 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2008-06-22 21:17 . 2004-07-19 18:41 16,512 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-06-22 18:29 . 2008-06-22 20:06 <DIR> d-------- C:\Program Files\fbquick
2008-06-22 18:29 . 2008-06-22 18:29 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\gnupg
2008-06-22 15:05 . 2008-06-22 15:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SRS Labs
2008-06-22 15:05 . 2007-07-26 09:25 47,360 -ra------ C:\WINDOWS\system32\drivers\Surroundhp_kern_i386.sys
2008-06-22 15:05 . 2007-07-26 09:25 47,104 -ra------ C:\WINDOWS\system32\drivers\tshd4_kern_i386.sys
2008-06-22 15:05 . 2007-07-26 09:25 42,112 -ra------ C:\WINDOWS\system32\drivers\csiidecoder_kern_i386.sys
2008-06-22 15:05 . 2007-07-26 09:25 39,808 -ra------ C:\WINDOWS\system32\drivers\SRS_SSCFilter_i386.sys
2008-06-22 15:05 . 2007-07-26 09:25 32,000 -ra------ C:\WINDOWS\system32\drivers\wowhd_kern_i386.sys
2008-06-22 12:43 . 2008-06-22 12:43 <DIR> d-------- C:\Program Files\Common Files\DFX
2008-06-22 12:43 . 2008-06-22 12:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DFX
2008-06-22 02:06 . 2008-07-08 18:51 <DIR> d--hs---- C:\temp
2008-06-22 00:26 . 2008-06-18 02:32 35,709 --a------ C:\Program Files\Common Files\Stardock Keygen.exe
2008-06-21 16:47 . 2008-06-21 17:23 <DIR> d-------- C:\Program Files\MediaMonkey
2008-06-20 13:41 . 2008-06-20 13:41 <DIR> d-------- C:\Program Files\R4
2008-06-20 13:40 . 2008-06-22 02:15 <DIR> d-------- C:\Program Files\Superscape
2008-06-20 13:40 . 1997-10-27 14:53 241,664 --a------ C:\WINDOWS\system32\HDK3CTNT.DLL
2008-06-20 13:40 . 1994-08-24 00:00 188,960 --a------ C:\WINDOWS\system32\WINGDE.DLL
2008-06-20 13:40 . 1997-08-27 20:34 172,544 --a------ C:\WINDOWS\system32\HDK3ANIM.DLL
2008-06-20 13:40 . 1994-09-21 00:00 92,208 --a------ C:\WINDOWS\system32\WING.DLL
2008-06-20 13:40 . 1999-08-10 10:32 53,248 --a------ C:\WINDOWS\system32\SCLVideo.ax
2008-06-20 13:40 . 1999-08-10 10:32 40,960 --a------ C:\WINDOWS\system32\SCLAudio.ax
2008-06-20 13:40 . 1994-09-21 00:00 12,800 --a------ C:\WINDOWS\system32\WING32.DLL
2008-06-20 13:40 . 1994-09-21 00:00 6,736 --a------ C:\WINDOWS\system32\WINGDIB.DRV
2008-06-20 13:40 . 1994-09-02 00:00 5,195 --a------ C:\WINDOWS\system32\DVA.386
2008-06-20 13:40 . 1994-09-21 00:00 5,024 --a------ C:\WINDOWS\system32\WINGPAL.WND
2008-06-20 13:28 . 2008-06-22 02:16 <DIR> d-------- C:\Program Files\MP3 Remix
2008-06-18 18:50 . 2008-06-19 11:38 <DIR> d-------- C:\Program Files\ReaConverter 5.5 Pro
2008-06-17 00:07 . 2008-06-17 00:07 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\SiteAdvisor
2008-06-16 19:16 . 2008-06-25 22:41 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-06-16 17:58 . 2003-06-25 16:05 266,360 --a------ C:\WINDOWS\system32\TweakUI.exe
2008-06-16 17:58 . 2002-06-21 15:09 160,217 --a------ C:\WINDOWS\system32\PowerToysLicense.rtf
2008-06-16 17:13 . 2008-06-16 17:13 <DIR> d-------- C:\Program Files\J River
2008-06-14 10:24 . 2008-06-14 10:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\My Movies
2008-06-14 10:12 . 2008-06-14 10:21 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-06-14 10:07 . 2008-07-02 10:24 <DIR> d-------- C:\Downloads
2008-06-14 00:26 . 2008-06-14 00:26 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\Movie Label
2008-06-11 08:28 . 2008-06-13 15:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 08:28 . 2008-06-13 15:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-10 08:19 . 2008-06-10 15:04 <DIR> d-------- C:\Documents and Settings\Frederik\Application Data\UseNeXT
2008-06-08 11:45 . 2008-06-08 11:45 495,104 --a------ C:\WINDOWS\system32\mp3tsshx.dll
2008-06-08 11:44 . 2008-06-08 11:44 <DIR> d-------- C:\Program Files\Magnus Brading
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-08 17:16 71,464,992 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-08 17:15 3,738,400 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-08 17:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-08 17:03 --------- d-----w C:\Program Files\Winamp Toolbar
2008-07-08 16:50 842,684 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-08 16:50 357,404 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-08 13:25 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-08 12:42 2,724 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-07-08 12:35 --------- d-----w C:\Program Files\Warcraft III
2008-07-08 01:13 --------- d-----w C:\Program Files\McAfee
2008-07-07 22:55 --------- d-----w C:\Documents and Settings\Frederik\Application Data\uTorrent
2008-07-07 12:37 --------- d-----w C:\Program Files\Corel
2008-07-07 10:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-07-02 08:26 --------- d-----w C:\Documents and Settings\Frederik\Application Data\Free Download Manager
2008-06-30 10:20 --------- d-----w C:\Program Files\Winamp
2008-06-29 09:34 --------- d-----w C:\Documents and Settings\Frederik\Application Data\DVD Profiler
2008-06-29 09:24 --------- d-----w C:\Program Files\DVD Profiler
2008-06-28 04:55 --------- d-----w C:\Program Files\uTorrent
2008-06-27 15:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-27 15:40 32,658 ----a-w C:\WINDOWS\system32\tcpipbak.reg
2008-06-23 19:56 --------- d-----w C:\Program Files\Diablo II
2008-06-22 20:17 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-22 00:14 --------- d-----w C:\Program Files\Yahoo!
2008-06-21 23:33 --------- d-----w C:\Program Files\Samurize
2008-06-21 13:52 --------- d-----w C:\Program Files\TagRename
2008-06-17 11:22 --------- d-----w C:\Program Files\Steam
2008-06-16 17:14 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
2008-06-16 17:14 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
2008-06-16 17:14 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
2008-06-16 15:25 --------- d-----w C:\Documents and Settings\Frederik\Application Data\J River
2008-06-14 08:17 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-06 17:25 94,208 ----a-w C:\WINDOWS\DIIUnin.exe
2008-06-06 17:25 2,829 ----a-w C:\WINDOWS\DIIUnin.pif
2008-06-06 15:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-06 15:30 --------- d--h--r C:\Documents and Settings\Frederik\Application Data\SecuROM
2008-06-06 15:21 --------- d-----w C:\Program Files\CAPCOM
2008-06-06 14:39 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-06-06 14:20 --------- d-----w C:\Program Files\THQ
2008-06-05 18:01 --------- d-----w C:\Program Files\QuickTime
2008-06-04 21:21 606,848 ----a-w C:\WINDOWS\flashax.exe
2008-06-04 21:21 12,288 ----a-w C:\WINDOWS\impborl.dll
2008-06-04 10:42 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2008-06-04 10:28 25,416 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys
2008-06-02 22:51 --------- d-----w C:\Program Files\Google
2008-06-02 22:48 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-02 22:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-06-02 22:36 --------- d-----w C:\Documents and Settings\Frederik\Application Data\Thinstall
2008-06-02 16:07 --------- d-----w C:\Documents and Settings\Frederik\Application Data\MediaMan
2008-06-01 21:03 --------- d-----w C:\Documents and Settings\Frederik\Application Data\Shareaza
2008-05-30 12:22 --------- d-----w C:\Program Files\AgeOfCastles_at
2008-05-29 14:23 --------- d-----w C:\Documents and Settings\Frederik\Application Data\Command & Conquer 3 Kane's Wrath
2008-05-29 11:15 2,275,840 ----a-w C:\WINDOWS\system32\TUKernel.exe
2008-05-29 10:28 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-05-29 10:26 354,560 ----a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-05-29 10:26 --------- d-----w C:\Documents and Settings\Frederik\Application Data\TuneUp Software
2008-05-29 10:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-05-28 16:35 --------- d-----w C:\Program Files\Last.fm
2008-05-27 05:25 --------- d-----w C:\Program Files\Stardock
2008-05-26 20:25 --------- d-----w C:\Program Files\YourWare Solutions
2008-05-26 20:21 --------- d-----w C:\Program Files\VistaCodecPack
2008-05-26 20:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-26 20:09 --------- d-----w C:\Program Files\SopCast
2008-05-26 20:09 --------- d-----w C:\Program Files\Common Files\Stardock
2008-05-26 20:05 --------- d-----w C:\Program Files\Call of Duty
2008-05-26 20:03 --------- d-----w C:\Documents and Settings\Frederik\Application Data\GetRight
2008-05-26 20:02 --------- d-----w C:\Program Files\Windows Sidebar
2008-05-26 19:49 --------- d-----w C:\Documents and Settings\Frederik\Application Data\GetRightToGo
2008-05-23 07:56 --------- d-----w C:\Program Files\SiteAdvisor
2008-05-22 21:13 --------- d--h--w C:\Documents and Settings\All Users\Application Data\{C86EF2C8-8BA2-48C3-9A30-EB3E1E22E2B5}
2008-05-19 20:56 --------- d-----w C:\Documents and Settings\Frederik\Application Data\Azureus
2008-05-19 20:24 --------- d-----w C:\Program Files\PC Drivers HeadQuarters
2008-05-11 14:02 --------- d-----w C:\Documents and Settings\Frederik\Application Data\yooPlugs
2008-05-11 13:03 --------- d-----w C:\Program Files\MovieTrack
2008-05-10 18:41 --------- d-----w C:\Documents and Settings\Frederik\Application Data\Realtime Soft
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-04 08:23 0 ----a-r C:\logwmemory.bin
2008-04-29 21:04 78,952 ----a-w C:\Documents and Settings\Frederik\Application Data\GDIPFONTCACHEV1.DAT
2008-04-21 06:56 666,624 ----a-w C:\WINDOWS\system32\wininet.dll
2004-07-10 14:12 2,238 ----a-w C:\Program Files\Songs Recycle.ico
.
------- Sigcheck -------
2007-12-13 10:09 1656832 c58f0e4dae57c0dc304ecc3683958e4c C:\WINDOWS\explorer.exe
2007-06-13 13:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-07-05 22:09 1655808 b40eb7c75c2ceaab5328a3bf0209a430 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-12-13 10:09 1656832 c58f0e4dae57c0dc304ecc3683958e4c C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 13:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 13:04 59392]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-16 20:39 7323648]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47 31016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 20:12 582992]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-11-30 06:42 1164576]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 14:59 4838952]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 12:22 20480]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 14:19 282624 C:\WINDOWS\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 18:35 1294336]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"<NO NAME>"= 1
"NoCommonGroups"= 0 (0x0)
"LockTaskbar"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoFavoritesMenu"= 1 (0x1)
"NoNetworkConnections"= 1 (0x1)
"NoSMMyDocs"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoStartMenuMyMusic"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 11 (0xb)
"NoInstrumentation"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsp_lmwl]
2007-02-21 22:21 43376 C:\WINDOWS\system32\fsp_lmwl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-03-28 10:55 1271032 C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Free Download Manager\\fdm.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Steam\\steamapps\\fuzzi714\\counter-strike\\hl.exe"=
"C:\\Program Files\\Steam\\steamapps\\fuzzi714\\condition zero\\hl.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Shareaza Applications\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\VALVe\\Counter-Strike Source\\hl2.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\McAfee\\MSC\\mcuimgr.exe"=
"C:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=
R1 hwinterface;hwinterface;C:\WINDOWS\system32\Drivers\hwinterface.sys [2008-04-03 23:32]
R2 LmpcService;Lock My PC Service;C:\Program Files\Lock My PC 4\LmpcServ.exe [2007-03-18 13:51]
R2 MSSQL$MYMOVIES;SQL Server (MYMOVIES);c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2007-02-10 15:29]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-10 13:00]
R3 dsnpfd;DeskSoft Service;C:\WINDOWS\system32\DRIVERS\dsnpfd.sys [2007-11-09 19:33]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
R3 LMPC4;LMPC4;C:\WINDOWS\system32\drivers\LMPC4.sys [2007-02-21 22:21]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2006-11-20 15:48]
S2 Messager;Messager;c:\temp\svchost.exe []
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-29 12:26]
S3 UltraMonMirror;UltraMonMirror;C:\WINDOWS\system32\DRIVERS\UltraMonMirror.sys []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34981f5a-f131-11dc-98ed-000fb5cc51a9}]
\Shell\AutoRun\command - H:\ClickMe.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-07-08 17:00:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-06-27 17:52:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-14 23:00:00 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-06-30 23:20:02 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-08 19:15:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
McAfee Backup = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-08 19:17:28
ComboFix-quarantined-files.txt 2008-07-08 17:17:00
Pre-Run: 155,004,940,288 bytes free
Post-Run: 155,248,173,056 bytes free
299 --- E O F --- 2008-07-08 01:03:04