Hi there, just to point out that that before the log was created it said (the system cannot find the file temp04) this may or may not mean anything but thought i would let you know. Also it told me to write this down ( c:\windows\system32\drivers\kbiwkmmqlhxlxu.sys) also this may not mean anything but thought i would include it.
This is the combifix file,,,
ComboFix 09-08-31.04 - Family 01/09/2009 18:31.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2046.1526 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\802.11g USB Wireless Network Utility .lnk
c:\documents and settings\Family\Application Data\inst.exe
c:\recycler\S-1-5-21-1644407709-2911996522-2064524667-500
c:\windows\Installer\2484a0.msp
c:\windows\Installer\2484ab.msp
c:\windows\Installer\2484b7.msp
c:\windows\Installer\WMEncoder.msi
c:\windows\kb913800.exe
c:\windows\run.log
c:\windows\system32\drivers\kbiwkmmqlhxlxu.sys
c:\windows\system32\kbiwkmbmqegvpx.dat
c:\windows\system32\kbiwkmhnunupkc.dat
c:\windows\system32\kbiwkmmvvmlkte.dll
c:\windows\system32\kbiwkmxeyrxvxu.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_kbiwkmparmyyxr
((((((((((((((((((((((((( Files Created from 2009-08-01 to 2009-09-01 )))))))))))))))))))))))))))))))
.
2009-09-01 17:19 . 2009-09-01 17:24 ——– d-s—w- C:\ComboFix
2009-09-01 14:43 . 2009-09-01 14:43 0 —-a-w- c:\documents and settings\Family\settings.dat
2009-09-01 14:27 . 2009-09-01 14:29 ——– d—–w- c:\program files\Common Files\ParetoLogic
2009-09-01 12:51 . 2009-09-01 12:51 ——– d—–w- c:\program files\GameTracker
2009-09-01 12:51 . 2009-09-01 13:30 ——– d—–w- c:\documents and settings\Family\Application Data\GameTracker
2009-09-01 12:36 . 2009-09-01 12:36 ——– d—–w- c:\program files\ERUNT
2009-08-31 21:22 . 2009-08-31 21:22 ——– d—–w- c:\program files\Trend Micro
2009-08-31 11:14 . 2009-08-31 11:14 ——– d—–w- c:\documents and settings\All Users\Application Data\F-Secure
2009-08-31 10:42 . 2009-08-31 10:42 3942047 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-30 11:22 . 2001-05-16 16:54 309616 —-a-w- c:\windows\system32\wmv8dmod.dll
2009-08-30 11:22 . 2001-05-11 12:18 420240 —-a-w- c:\windows\system32\mpg4c32.dll
2009-08-29 15:13 . 2009-08-29 15:13 ——– d—–w- c:\windows\Google Earth Pro 4.2
2009-08-29 12:08 . 2009-08-29 12:08 ——– d—–w- c:\program files\AskBarDis
2009-08-28 15:50 . 2009-08-28 15:50 ——– d—–w- c:\program files\NVIDIA Corporation
2009-08-28 15:49 . 2009-08-28 15:49 151552 —-a-w- c:\windows\system32\nvRegDev.dll
2009-08-28 12:13 . 2009-08-28 12:13 15872 —-a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C9.exe
2009-08-28 12:13 . 2009-09-01 17:15 ——– d—–w- c:\program files\Steam
2009-08-27 13:47 . 2009-08-27 13:47 ——– d—–w- c:\program files\Common Files\Macrovision Shared
2009-08-26 21:07 . 2009-09-01 17:15 ——– d—–w- c:\program files\Winflip
2009-08-26 15:01 . 2009-08-26 15:01 ——– d—–w- c:\program files\Adobe Media Player
2009-08-26 11:06 . 2009-08-30 11:29 ——– d–h–w- C:\$AVG8.VAULT$
2009-08-25 17:30 . 2009-08-25 17:30 ——– d—–w- c:\documents and settings\Family\Library
2009-08-25 17:30 . 2009-08-25 17:30 ——– d—–w- c:\documents and settings\Family\Application Data\com.adobe.ExMan
2009-08-25 17:09 . 2009-08-25 17:09 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-08-25 16:09 . 2009-08-25 16:09 ——– d—–w- c:\program files\Belarc
2009-08-25 16:09 . 2008-03-06 10:51 3840 —-a-w- c:\windows\system32\drivers\BANTExt.sys
2009-08-21 15:05 . 2009-08-25 21:19 ——– d—–w- c:\documents and settings\All Users\Application Data\TrackMania
2009-08-21 15:02 . 2009-08-21 15:03 ——– d—–w- c:\program files\TmNationsForever
2009-08-20 13:41 . 2009-08-20 15:37 ——– d—–w- c:\documents and settings\Family\Application Data\MegaplexMadnessSummerBlockbuster
2009-08-19 21:20 . 2009-08-30 11:14 ——– d—–w- c:\program files\Codemasters
2009-08-19 21:20 . 1999-04-23 21:22 151552 —-a-w- c:\windows\system32\MSOSS.DLL
2009-08-19 21:18 . 2009-08-19 21:18 ——– d—–w- C:\Colin Mcrae Rally
2009-08-19 13:36 . 2009-08-19 13:36 ——– d—–w- c:\program files\Common Files\EasyInfo
2009-08-18 20:36 . 2008-03-21 12:57 14640 ——w- c:\windows\system32\spmsgXP_2k3.dll
2009-08-18 20:35 . 2009-08-21 13:22 ——– d-sh–w- c:\documents and settings\Family\Phone Browser
2009-08-18 20:33 . 2009-08-18 20:05 33773208 —-a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng_web.exe
2009-08-18 20:33 . 2009-08-18 20:33 95232 —-a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-08-18 20:33 . 2009-08-18 20:33 8192 —-a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-08-18 20:33 . 2009-08-18 20:33 61440 —-a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-08-18 20:33 . 2009-08-18 20:33 10240 —-a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-08-18 20:33 . 2009-08-18 20:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Installations
2009-08-18 17:30 . 2009-08-18 17:30 ——– d—–w- c:\documents and settings\All Users\Application Data\FreshGames
2009-08-18 17:29 . 2009-08-18 17:29 ——– d—–w- c:\program files\Ranch Rush
2009-08-18 17:29 . 2009-08-18 17:29 ——– d—–w- c:\windows\Ranch Rush
2009-08-17 20:19 . 2009-08-17 20:25 ——– d—–w- c:\documents and settings\Family\Application Data\Peace Craft
2009-08-17 16:32 . 2009-08-17 16:32 ——– d—–w- c:\program files\Regseeker
2009-08-16 20:36 . 2009-08-28 11:59 ——– d—–w- c:\documents and settings\Family\Application Data\vlc
2009-08-16 20:33 . 2009-08-16 20:33 ——– d—–w- c:\program files\VideoLAN
2009-08-13 16:58 . 2006-11-02 11:16 1268224 —-a-w- c:\windows\d3d10.dll
2009-08-13 12:34 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-11 15:04 . 2009-08-11 15:04 ——– d—–w- c:\program files\EA GAMES
2009-08-11 12:34 . 2009-08-11 12:37 ——– d—–w- c:\program files\DAEMON Tools Pro
2009-08-11 12:34 . 2009-08-11 12:34 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2009-08-11 12:18 . 2009-08-11 12:18 ——– d—–w- c:\documents and settings\Family\Application Data\DAEMON Tools Pro
2009-08-11 12:08 . 2009-08-11 12:08 ——– d—–w- c:\program files\Conduit
2009-08-11 12:08 . 2009-08-11 12:08 ——– d—–w- c:\documents and settings\Family\Local Settings\Application Data\free-downloads.net
2009-08-11 12:08 . 2009-08-11 12:08 ——– d—–w- c:\documents and settings\Family\Local Settings\Application Data\Conduit
2009-08-11 12:08 . 2009-08-11 12:08 ——– d—–w- c:\program files\Alcohol Soft
2009-08-09 19:56 . 2009-08-09 19:56 2560 —-a-w- c:\windows\_MSRSTRT.EXE
2009-08-09 19:45 . 2007-07-11 13:06 42672 ——w- c:\windows\system32\wbsys.dll
2009-08-09 19:45 . 2009-08-09 19:45 ——– d—–w- c:\program files\Stardock
2009-08-09 13:31 . 2009-08-09 13:31 ——– d—–w- c:\program files\Veetle
2009-08-05 20:25 . 2009-08-05 20:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Trymedia
2009-08-05 20:23 . 2009-08-05 20:23 ——– d—–w- c:\program files\BFG
2009-08-05 19:21 . 2009-08-05 19:21 ——– d—–w- c:\program files\Anders Kjersem
2009-08-04 20:55 . 2009-08-04 20:55 ——– d—–w- c:\program files\Burger Shop 2
2009-08-04 00:19 . 2009-08-04 00:19 ——– d—–w- c:\documents and settings\Family\Local Settings\Application Data\Aspyr
2009-08-04 00:15 . 2009-08-04 00:15 ——– d—–w- c:\program files\MSXML 6.0
2009-08-04 00:04 . 2009-08-04 00:04 ——– d—–w- c:\program files\Aspyr
2009-08-03 23:48 . 2009-08-03 23:49 ——– d—–w- C:\guitar hero iso
2009-08-03 19:34 . 2009-08-03 19:34 ——– d–h–w- c:\windows\PIF
2009-08-03 15:45 . 2008-09-04 20:17 447752 —-a-w- c:\windows\system32\vp6vfw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-01 17:38 . 2009-06-04 20:41 ——– d—–w- c:\documents and settings\LocalService\Application Data\GameTracker
2009-09-01 13:29 . 2009-05-07 17:31 189104 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-09-01 12:54 . 2009-05-07 17:32 139584 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-01 12:15 . 2009-05-15 18:52 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-08-31 10:43 . 2009-05-29 16:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-30 18:07 . 2009-05-26 15:52 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-30 17:55 . 2009-05-08 17:41 ——– d—–w- c:\documents and settings\Family\Application Data\Azureus
2009-08-30 14:56 . 2009-05-26 15:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-30 11:14 . 2009-06-12 15:35 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-29 15:05 . 2009-08-29 15:05 889809 —-a-w- c:\windows\system32\xa.tmp
2009-08-29 12:08 . 2009-05-08 17:40 ——– d—–w- c:\program files\Vuze
2009-08-28 19:12 . 2009-05-09 13:18 ——– d—–w- c:\documents and settings\Family\Application Data\Vso
2009-08-27 23:16 . 2009-07-25 19:42 ——– d—–w- c:\program files\PKR
2009-08-27 14:03 . 2009-05-06 22:19 74120 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-27 13:56 . 2009-05-06 22:33 ——– d—–w- c:\program files\Common Files\Adobe
2009-08-22 09:00 . 2009-05-07 16:10 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-22 09:00 . 2009-05-07 16:10 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-22 09:00 . 2009-05-07 16:10 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-21 15:00 . 2009-06-11 17:42 ——– d—–w- c:\program files\Games
2009-08-21 13:24 . 2009-08-21 13:24 4548 —-a-w- c:\windows\system32\PerfStringBackup.TMP
2009-08-21 13:23 . 2009-08-21 13:23 0 —ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2009-08-21 13:23 . 2009-08-21 13:23 0 —ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2009-08-21 13:23 . 2009-08-18 20:34 ——– d—–w- c:\documents and settings\Family\Application Data\PC Suite
2009-08-21 13:22 . 2009-08-18 20:34 ——– d—–w- c:\documents and settings\Family\Application Data\Nokia
2009-08-21 13:22 . 2009-08-18 20:34 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Suite
2009-08-20 15:40 . 2009-05-19 15:28 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-20 12:40 . 2009-05-19 15:12 ——– d—–w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-08-20 10:36 . 2009-05-19 17:01 ——– d—–w- c:\program files\Nanny Mania 2 - Goes to Hollywood
2009-08-19 16:21 . 2009-06-12 15:35 ——– d—–w- c:\documents and settings\All Users\Application Data\BVRP Software
2009-08-18 20:36 . 2009-08-18 20:36 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-08-18 20:36 . 2009-08-18 20:36 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-08-18 20:34 . 2009-08-18 20:34 ——– d—–w- c:\program files\DIFX
2009-08-18 20:34 . 2009-08-18 20:34 ——– d—–w- c:\program files\Common Files\PCSuite
2009-08-18 20:34 . 2009-08-18 20:34 ——– d—–w- c:\program files\Common Files\Nokia
2009-08-18 20:34 . 2009-08-18 20:34 ——– d—–w- c:\program files\Nokia
2009-08-18 20:34 . 2009-08-18 20:34 ——– d—–w- c:\program files\PC Connectivity Solution
2009-08-11 12:19 . 2009-05-23 15:10 722416 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-08-09 19:35 . 2009-05-13 18:09 ——– d—–w- c:\program files\PeerGuardian2
2009-08-08 19:30 . 2009-05-07 17:21 ——– d—–w- c:\program files\Activision
2009-08-08 19:10 . 2009-07-18 15:28 ——– d—–w- c:\program files\Microsoft Games for Windows - LIVE
2009-08-05 09:01 . 2004-09-10 13:57 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 12:36 . 2009-05-29 16:42 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 12:36 . 2009-05-29 16:42 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-01 19:43 . 2009-08-01 19:42 ——– d—–w- c:\program files\Farmer Jane
2009-08-01 09:37 . 2009-08-01 09:37 ——– d—–w- c:\program files\My Kingdom for the Princess
2009-08-01 09:10 . 2009-07-28 18:57 ——– d—–w- c:\documents and settings\Family\Application Data\IDM
2009-07-31 19:10 . 2009-07-31 19:10 ——– d—–w- c:\program files\Rockstar Games
2009-07-31 17:07 . 2009-07-31 17:07 ——– d—–w- c:\documents and settings\All Users\Application Data\GoBit Games
2009-07-31 16:51 . 2009-07-28 18:57 ——– d—–w- c:\documents and settings\Family\Application Data\DMCache
2009-07-31 11:16 . 2009-07-10 16:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-07-28 16:21 . 2009-07-28 16:21 ——– d—–w- c:\program files\CCleaner
2009-07-28 15:54 . 2009-06-11 17:45 ——– d—–w- c:\documents and settings\Family\Application Data\PlayFirst
2009-07-28 15:54 . 2009-06-11 17:45 ——– d—–w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-07-28 15:00 . 2009-07-28 14:59 ——– d—–w- c:\program files\DinerTown Tycoon
2009-07-26 22:48 . 2009-07-26 22:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Sandlot Games
2009-07-26 22:47 . 2009-07-26 22:47 ——– d—–w- c:\documents and settings\Family\Application Data\Sandlot Games
2009-07-26 21:46 . 2009-07-26 21:46 ——– d—–w- c:\documents and settings\Family\Application Data\EleFun Games
2009-07-26 16:08 . 2009-07-26 16:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Fugazo
2009-07-26 16:07 . 2009-07-26 14:44 ——– d—–w- c:\program files\Cooking Academy 2 - World Cuisine
2009-07-26 13:36 . 2009-07-26 13:36 ——– d—–w- c:\documents and settings\Family\Application Data\CupcakeCafe
2009-07-26 13:07 . 2009-05-19 15:13 ——– d—–w- c:\program files\bfgclient
2009-07-24 20:45 . 2009-07-24 20:45 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-07-24 12:48 . 2009-07-24 12:48 ——– d—–w- c:\program files\SEGA
2009-07-23 15:33 . 2009-07-23 15:33 ——– d—–w- c:\program files\GFI
2009-07-19 11:38 . 2009-07-19 11:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Activision
2009-07-18 00:42 . 2009-05-07 16:07 ——– d—–w- c:\program files\PartyGaming
2009-07-17 19:01 . 2004-09-10 13:56 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-16 13:08 . 2009-05-22 12:46 510 —-a-w- c:\documents and settings\Family\Application Data\wklnhst.dat
2009-07-13 22:43 . 2004-09-10 13:58 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 16:29 . 2009-07-10 16:29 ——– d—–w- c:\program files\AGEIA Technologies
2009-07-10 16:29 . 2009-05-22 11:41 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-07-05 11:23 . 2009-07-05 11:23 ——– d—–w- c:\program files\THQ
2009-06-26 11:12 . 2009-06-26 11:12 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2009-06-26 11:10 . 2009-05-07 17:32 22328 —-a-w- c:\documents and settings\Family\Application Data\PnkBstrK.sys
2009-06-26 11:10 . 2009-05-07 17:32 22328 —-a-w- c:\documents and settings\Family\Application Data\PnkBstrK.sys
2009-06-26 11:10 . 2009-06-26 11:10 2250024 —-a-w- c:\windows\system32\pbsvc.exe
2009-06-25 08:25 . 2004-09-10 13:57 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-09-10 13:57 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-09-10 13:57 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-09-10 13:57 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-09-10 13:57 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-09-10 13:57 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-09-10 13:57 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-09-10 13:57 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-09-10 13:57 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 15:35 . 2009-06-12 15:35 24192 —-a-w- c:\documents and settings\Family\usbsermptxp.sys
2009-06-12 15:35 . 2009-06-12 15:35 22768 —-a-w- c:\documents and settings\Family\usbsermpt.sys
2009-06-12 12:31 . 2004-09-10 13:57 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-09-10 13:57 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-09-10 13:56 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 08:19 . 2004-09-10 14:30 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-09-10 13:57 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2004-09-10 13:57 1291264 —-a-w- c:\windows\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 11:47 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
2009-05-04 10:56 398776 —-a-w- c:\program files\BearShare Applications\BearShare\BearShareIEHelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-18 630784]
"Anders Kjersem: TransBar"="c:\program files\Anders Kjersem\TransBar\TransBar.exe" [2002-05-18 29696]
"Steam"="c:\program files\steam\steam.exe" [2009-08-28 1217784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-22 2007832]
"LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Family\Start Menu\Programs\Startup\
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-3-18 630784]
WinFlip.lnk - c:\program files\Winflip\WinFlip.exe [2009-8-26 483328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-22 09:00 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^Family^Start Menu^Programs^Startup^TransBar.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^Family^Start Menu^Programs^Startup^UberIcon.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^Family^Start Menu^Programs^Startup^WinFlip.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^Family^Start Menu^Programs^Startup^Y'z Shadow.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UleadBurningHelper"=2 (0x2)
"gupdate1c9d3c98a12cbc"=2 (0x2)
"AOL ACS"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AOL 9.0\\aol.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"c:\\Program Files\\TmNationsForever\\TmForever.exe"=
"c:\\Program Files\\Steam\\SteamApps\\destroyer59771\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15739:TCP"= 15739:TCP:azureus
"15739:UDP"= 15739:UDP:azureus
"5353:TCP"= 5353:TCP:*:Disabled:Adobe CSI CS4
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [26/05/2009 21:30 21144]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [07/05/2009 17:10 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [07/05/2009 17:10 108552]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [29/08/2009 13:08 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [29/08/2009 13:08 234888]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [07/05/2009 17:10 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [07/05/2009 17:10 297752]
R2 GS In-Game Service;GS In-Game Service;c:\program files\GameTracker\GSInGameService.exe [01/09/2009 13:51 1612128]
R3 3xHybrid;ASUSTek SAA713x PCI Card;c:\windows\system32\drivers\3xHybrid.sys [06/05/2009 23:15 882688]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [06/05/2009 23:59 332928]
R3 X10Hid;X10 Hid Device;c:\windows\system32\drivers\x10hid.sys [06/05/2009 23:17 7040]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [15/05/2009 19:20 1684736]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S4 gupdate1c9d3c98a12cbc;Google Update Service (gupdate1c9d3c98a12cbc);c:\program files\Google\Update\GoogleUpdate.exe [13/05/2009 13:47 133104]
.
Contents of the 'Scheduled Tasks' folder
2009-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-13 12:47]
2009-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-13 12:47]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{ecdee021-0d17-467f-a1ff-c7a115230949} - (no file)
BHO-{d56d7a88-9574-4acc-8ac8-dd7d34f4a1c1} - (no file)
BHO-{ecdee021-0d17-467f-a1ff-c7a115230949} - (no file)
Toolbar-{ecdee021-0d17-467f-a1ff-c7a115230949} - (no file)
HKLM-Run-Windows Center - iexplorer.exe
MSConfigStartUp-2 - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.bearshare.com/
uInternet Connection Wizard,ShellNext = hxxp://www1.partypoker.com/pam_images/installer/omn.htm?pid=Poker&bid;=Party&lid;=en&sid;=1
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
FF - ProfilePath - c:\documents and settings\Family\Application Data\Mozilla\Firefox\Profiles\905ajkym.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/firefox
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJPI150_04.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npnul32.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-01 18:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kbiwkmparmyyxr]
"imagepath"="\systemroot\system32\drivers\kbiwkmmqlhxlxu.sys"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\.Default\Software\Stardock\WindowBlinds]
@DACL=(02 0000)
[HKEY_USERS\.Default\Software\Stardock\WindowBlinds\WB5.ini\WBLiteFX]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-21-1065087527-3504542235-3153624688-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{42D710F1-6427-E855-8F16-9103CC5EB3BA}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"hanaeoeomgiknhhg"=hex:61,61,00,7c
"janaeoeomgiknhhgippb"=hex:63,61,6f,63,61,69,00,7c
"pafabmhplddiaockilgnldmngioapcai"=hex:64,61,63,64,6d,6f,6f,6a,00,00
[HKEY_USERS\S-1-5-21-1065087527-3504542235-3153624688-1005\Software\Skype\Phone\UI]
@DACL=(02 0000)
@SACL=
"Installed"=dword:00000001
[HKEY_LOCAL_MACHINE\software\America Online\ACS\Clients]
@DACL=(02 0000)
@SACL=
"1"="c:\\Program Files\\AOL 9.0"
[HKEY_LOCAL_MACHINE\software\America Online\ACS\Languages]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\ATI Technologies Inc.\ATI Drivers]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\British Telecom Plc\Internet from BT]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\CyberLink\PowerDVD\6.0]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\CyberLink\PowerDVD\BuildInfo]
@DACL=(02 0000)
@SACL=
"SR_No"="DVD060502-01"
"Setup"="060407"
"RC"="050802(GM)"
"Help"="050824(GM)"
"Readme"="050630(GM)"
"Skin"="041220"
"OlReg"="050621v2"
"RegRC"="050810v2"
"TrialDialog RC"="050908"
"Ver"="6.00.2003e"
"Utility"="1905"
"UI"="2003e_NP"
"UI98"="2003e_NP"
"DShow"="2003c"
"AVSetting"="3128"
"CPXM"="2207"
"Other"="1328"
"CL264"="-"
"Pou"="1423b"
"TrialDialog"="050906_PowerDVD"
[HKEY_LOCAL_MACHINE\software\CyberLink\PowerDVD\UserReg]
@DACL=(02 0000)
@SACL=
"SR_No"="DVD060502-01"
"Prod_Name"="PowerDVD"
"Prod_Ver"="6.0"
"CustomerNO"="300"
"Hardware"="Desktop PC"
"Channel"="OEM"
"RegVType"="OEM 2CH"
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IEHomePageInfo\RegBackup]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IMAGING_USE_ART]
@DACL=(02 0000)
@SACL=
@=""
"waol.exe"=dword:00000001
"cs.exe"=dword:00000001
"wm.exe"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\services]
@DACL=(02 0000)
@SACL=
"NoServices"=dword:00000000
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\ShimInclusionList\firefox.exe]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\UIPlugins\{875FD3CE-E284-467B-BDF4-00D1007C4F08}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="res://Od2QueueListManager.dll/RT_STRING/#102"
"Description"="res://Od2QueueListManager.dll/RT_STRING/#103"
"Capabilities"=dword:40000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\KnownDeviceClasses]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\KnownDevices]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\On Demand Distribution\Music Manager]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Realtek Semiconductor Corp.\Realtek High Definition Audio Driver]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Symantec\CCPD-LC]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Symantec\Shared Technology]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Ulead Systems\Ulead VideoStudio SE\9.0\Installer]
@DACL=(02 0000)
@SACL=
"ProductName"="Ulead VideoStudio %s"
"ProgramGroupName"="Ulead VideoStudio 9.0 SE DVD"
"Specially"="SE DVD"
"ProductVersion"="9.00.0100"
"Product Version"="9.00.0100"
"Product Build"="SE DVD"
"snLanguage"="11"
"szLanguage"="English"
"Serial Number"="781A2-89000-99933113"
"Path"="c:\\Program Files\\Ulead Systems\\Ulead VideoStudio 9.0 SE DVD"
"DDR_Path"="c:\\Program Files\\Ulead Systems\\Ulead VideoStudio 9.0 SE DVD\\DDR21"
"ProjectNumber"="130202890.510100000"
[HKEY_LOCAL_MACHINE\software\Ulead Systems\Ulead VideoStudio SE\9.0\Preference]
@DACL=(02 0000)
@SACL=
"TV System"=dword:00000000
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kbiwkmparmyyxr]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\kbiwkmmqlhxlxu.sys"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1000)
c:\windows\system32\Ati2evxx.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(3796)
c:\windows\system32\SHDOCVW.dll
c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
c:\program files\Winflip\WFHook.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
c:\progra~1\COMMON~1\X10\Common\X10nets.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\dllhost.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2009-09-01 18:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-01 17:44
Pre-Run: 197,779,636,224 bytes free
Post-Run: 197,688,479,744 bytes free
519 — E O F — 2009-08-18 16:55