HI
Answering your question.
I press ok
The results of
Combofix
ComboFix 07-08-30.3 - "Abdul_2" 09/05/2007 13:12:54.2 - NTFSx86
framedyn.dll is missing
((((((((((((((((((((((((( Files Created from 2007-08-05 to 2007-09-05 )))))))))))))))))))))))))))))))
No new files created in this timespan
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
11/23/2001 07:08 AM 712704 -ra------ C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
09/05/2007 02:05 AM --------- d-------- C:\DOCUME~1\ABDUL_2\APPLIC~1\Talkback
09/05/2007 01:04 PM 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
09/05/2007 01:04 PM 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
09/05/2007 01:04 PM 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
09/05/2007 01:04 PM 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
09/04/2007 05:04 PM --------- d-------- C:\DOCUME~1\ABDUL_2\APPLIC~1\SlipStream
09/04/2007 04:15 PM --------- d-------- C:\DOCUME~1\ABDUL_2\APPLIC~1\Real
09/04/2007 02:47 AM 82061 --a------ C:\WINDOWS\system32\drivers\klick.dat
09/04/2007 02:47 AM 81549 --a------ C:\WINDOWS\system32\drivers\klin.dat
09/04/2007 02:31 AM --------- d-------- C:\Program Files\Kaspersky Lab
09/02/2007 10:36 PM --------- d-------- C:\Program Files\TurboFTP
09/02/2007 10:36 PM --------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\TurboFTP
09/01/2007 04:48 PM --------- d-------- C:\Program Files\LeapFTP
09/01/2007 03:45 PM 114688 --a------ C:\WINDOWS\system32\msmsg3sp.dll
09/01/2007 03:45 PM --------- d-------- C:\Program Files\Common Files\FileStream Scheduler
08/30/2007 09:16 PM --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
08/30/2007 08:08 PM --------- d-------- C:\Program Files\JAP
08/30/2007 04:47 PM --------- d-------- C:\Program Files\Trend Micro
08/29/2007 11:35 PM --------- d-------- C:\Program Files\NoAdware5.0
08/29/2007 10:40 PM --------- d-------- C:\Program Files\RegCure
08/25/2007 10:04 PM --------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\WinRAR
08/22/2007 07:00 PM --------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\PC Tools
08/22/2007 05:42 PM --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
08/22/2007 05:24 PM --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab Setup Files
08/19/2007 12:14 AM --------- d-------- C:\Program Files\McAfee.com
08/19/2007 12:14 AM --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
08/19/2007 12:08 AM 9 -r-hs---- C:\Program Files\Desktop_.ini
08/19/2007 02:51 AM --------- d-------- C:\Program Files\Power Email Harvester
08/15/2007 03:57 PM --------- d-------- C:\Program Files\iZone Internet Turbo
08/15/2007 01:46 AM --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
08/14/2007 01:06 PM --------- d-------- C:\Program Files\Hide IP Platinum
07/30/2007 07:19 PM 92504 --a------ C:\WINDOWS\system32\cdm.dll
07/30/2007 07:19 PM 549720 --a------ C:\WINDOWS\system32\wuapi.dll
07/30/2007 07:19 PM 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
07/30/2007 07:19 PM 43352 --a------ C:\WINDOWS\system32\wups2.dll
07/30/2007 07:19 PM 325976 --a------ C:\WINDOWS\system32\wucltui.dll
07/30/2007 07:19 PM 203096 --a------ C:\WINDOWS\system32\wuweb.dll
07/30/2007 07:19 PM 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
07/30/2007 07:18 PM 33624 --a------ C:\WINDOWS\system32\wups.dll
06/28/2007 12:51 PM 206088 --a------ C:\WINDOWS\system32\klogon.dll
06/17/2007 12:11 AM 51200 --a------ C:\WINDOWS\nircmd.exe
06/14/2007 06:14 PM 114688 --a------ C:\WINDOWS\sliprt.dll
((((((((((((((((((((((((((((( snapshot_Fri 08-31-2007_173642.04 )))))))))))))))))))))))))))))))))))))))))
----a-w 60,928 2002-08-16 12:15:52 C:\WINDOWS\unleap.exe
----a-w 32,768 2007-09-03 23:40:06 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
----a-w 32,768 2007-09-03 23:40:06 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
----a-w 32,768 2007-09-03 23:45:18 C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
----a-w 186,640 2007-06-27 14:31:58 C:\WINDOWS\system32\drivers\klif.sys
----a-w 36,352 2004-08-03 19:59:56 C:\WINDOWS\system32\drivers\disk.sys
----a-w 26,496 2004-08-03 20:08:48 C:\WINDOWS\system32\drivers\USBSTOR.SYS
----a-w 110,360 2007-04-28 13:51:02 C:\WINDOWS\system32\drivers\kl1.sys
----a-w 22,457 2007-06-28 09:50:52 C:\WINDOWS\system32\drivers\klop.dat
----a-w 12,160 2001-08-17 10:48:00 C:\WINDOWS\system32\drivers\mouhid.sys
----a-w 23,040 2004-08-03 19:58:34 C:\WINDOWS\system32\drivers\mouclass.sys
----a-w 36,864 2003-08-01 08:00:16 C:\WINDOWS\system32\ActiveScan\certdll.dll
----a-w 110,592 2007-03-29 06:20:50 C:\WINDOWS\system32\ActiveScan\as.dll
----a-w 96,256 2005-06-03 11:03:18 C:\WINDOWS\system32\ActiveScan\asmdat.dll
----a-w 4,608 2006-02-16 15:20:20 C:\WINDOWS\system32\ActiveScan\memvfile.dll
----a-w 139,264 2004-05-04 12:01:02 C:\WINDOWS\system32\ActiveScan\pavaleas.dll
----a-w 45,056 2006-07-14 10:04:10 C:\WINDOWS\system32\ActiveScan\pavdr.exe
----a-w 159,832 2006-04-10 07:50:02 C:\WINDOWS\system32\ActiveScan\pavexcom.dll
----a-w 180,224 2006-02-16 15:35:38 C:\WINDOWS\system32\ActiveScan\pavoe.dll
----a-w 122,880 2006-10-05 13:15:38 C:\WINDOWS\system32\ActiveScan\pavpz.dll
----a-w 8,704 2006-06-30 11:13:38 C:\WINDOWS\system32\ActiveScan\pfdnnt.exe
----a-w 49,152 2004-02-04 11:08:42 C:\WINDOWS\system32\ActiveScan\port32.dll
----a-w 10,752 2006-08-17 08:38:14 C:\WINDOWS\system32\ActiveScan\pskalloc.dll
----a-w 61,440 2006-09-04 08:49:54 C:\WINDOWS\system32\ActiveScan\pskas.dll
----a-w 233,472 2006-10-05 13:15:26 C:\WINDOWS\system32\ActiveScan\ascontrol.dll
----a-w 94,208 2006-02-14 10:05:38 C:\WINDOWS\system32\ActiveScan\pavinas.dll
----a-w 1,388,544 2006-08-23 10:06:08 C:\WINDOWS\system32\ActiveScan\pskahk.dll
----a-w 33,624 2007-07-30 16:18:40 C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.381\wups.dll
----a-w 43,352 2007-07-30 16:19:12 C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.0.6000.381\wups2.dll
----a-w 16,384 2007-09-04 18:59:46 C:\WINDOWS\temp\Perflib_Perfdata_7f8.dat
----a-w 163,328 2007-03-13 07:57:12 C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
----a-w 23,040 2005-12-31 21:00:00 C:\WINDOWS\LastGood\system32\DRIVERS\mouclass.sys
----a-w 12,160 2005-12-31 21:00:00 C:\WINDOWS\LastGood\system32\DRIVERS\mouhid.sys
----a-w 141,424 2006-08-24 05:28:54 C:\WINDOWS\Downloaded Program Files\asinst.dll
----a-w 213,216 2005-10-12 23:12:26 C:\WINDOWS\SoftwareDistribution\Download\b54528191e99a817679c5ba3ee641572\spuninst.exe
----a-w 14,048 2005-10-12 23:12:26 C:\WINDOWS\SoftwareDistribution\Download\b54528191e99a817679c5ba3ee641572\spmsg.dll
----a-w 716,000 2005-10-12 23:12:30 C:\WINDOWS\SoftwareDistribution\Download\b54528191e99a817679c5ba3ee641572\update\update.exe
----a-w 22,752 2005-10-12 23:12:26 C:\WINDOWS\SoftwareDistribution\Download\b54528191e99a817679c5ba3ee641572\update\spcustom.dll
----a-w 371,424 2005-10-12 23:12:34 C:\WINDOWS\SoftwareDistribution\Download\b54528191e99a817679c5ba3ee641572\update\updspapi.dll
------w 1,287,680 2005-12-31 21:00:00 C:\WINDOWS\SoftwareDistribution\Download\b54528191e99a817679c5ba3ee641572\backup\sp2gdr\quartz.dll
------w 1,287,680 2005-12-31 21:00:00 C:\WINDOWS\SoftwareDistribution\Download\b54528191e99a817679c5ba3ee641572\backup\sp2qfe\quartz.dll
----a-w 14,048 2005-02-24 17:35:06 C:\WINDOWS\SoftwareDistribution\Download\aebb83db003f77a45671fd2c1557da38\spmsg.dll
----a-w 209,632 2005-02-24 17:35:06 C:\WINDOWS\SoftwareDistribution\Download\aebb83db003f77a45671fd2c1557da38\spuninst.exe
----a-w 718,048 2005-02-24 17:35:06 C:\WINDOWS\SoftwareDistribution\Download\aebb83db003f77a45671fd2c1557da38\update\update.exe
----a-w 371,936 2005-02-24 17:35:08 C:\WINDOWS\SoftwareDistribution\Download\aebb83db003f77a45671fd2c1557da38\update\updspapi.dll
----a-w 22,240 2005-02-24 17:35:06 C:\WINDOWS\SoftwareDistribution\Download\aebb83db003f77a45671fd2c1557da38\update\spcustom.dll
----a-w 30,720 2005-08-22 15:01:30 C:\WINDOWS\SoftwareDistribution\Download\aebb83db003f77a45671fd2c1557da38\update\arpidfix.exe
------w 118,272 2005-12-31 21:00:00 C:\WINDOWS\SoftwareDistribution\Download\aebb83db003f77a45671fd2c1557da38\backup\sp2gdr\umpnpmgr.dll
------w 118,272 2005-12-31 21:00:00 C:\WINDOWS\SoftwareDistribution\Download\aebb83db003f77a45671fd2c1557da38\backup\sp2qfe\umpnpmgr.dll
----a-w 13,536 2005-06-28 07:20:24 C:\WINDOWS\SoftwareDistribution\Download\1e354442629d28d789283ed99200860a\spmsg.dll
----a-w 5,537,792 2007-04-30 05:20:24 C:\WINDOWS\SoftwareDistribution\Download\1e354442629d28d789283ed99200860a\wmp.dll
----a-w 213,216 2005-06-28 07:23:26 C:\WINDOWS\SoftwareDistribution\Download\1e354442629d28d789283ed99200860a\spuninst.exe
----a-w 22,752 2005-06-28 07:21:34 C:\WINDOWS\SoftwareDistribution\Download\1e354442629d28d789283ed99200860a\spupdsvc.exe
----a-w 371,424 2005-06-28 07:23:54 C:\WINDOWS\SoftwareDistribution\Download\1e354442629d28d789283ed99200860a\update\updspapi.dll
----a-w 716,000 2005-06-28 07:24:52 C:\WINDOWS\SoftwareDistribution\Download\1e354442629d28d789283ed99200860a\update\update.exe
----a-w 213,216 2005-10-12 23:16:50 C:\WINDOWS\SoftwareDistribution\Download\d1c98689cdcd0ea9312780ffc77a2cbe\spuninst.exe
----a-w 14,048 2005-10-12 23:16:50 C:\WINDOWS\SoftwareDistribution\Download\d1c98689cdcd0ea9312780ffc77a2cbe\spmsg.dll
----a-w 716,000 2005-10-12 23:16:52 C:\WINDOWS\SoftwareDistribution\Download\d1c98689cdcd0ea9312780ffc77a2cbe\update\update.exe
----a-w 22,752 2005-10-12 23:16:50 C:\WINDOWS\SoftwareDistribution\Download\d1c98689cdcd0ea9312780ffc77a2cbe\update\spcustom.dll
----a-w 371,424 2005-10-12 23:16:56 C:\WINDOWS\SoftwareDistribution\Download\d1c98689cdcd0ea9312780ffc77a2cbe\update\updspapi.dll
------w 262,400 2005-12-31 21:00:00 C:\WINDOWS\SoftwareDistribution\Download\d1c98689cdcd0ea9312780ffc77a2cbe\backup\sp2gdr\http.sys
------w 263,040 2004-08-03 20:00:14 C:\WINDOWS\SoftwareDistribution\Download\d1c98689cdcd0ea9312780ffc77a2cbe\backup\sp2qfe\http.sys
----a-w 213,216 2006-01-19 19:29:20 C:\WINDOWS\SoftwareDistribution\Download\393673217fc83f2b990ca70aa98f1df8\spuninst.exe
----a-w 14,048 2006-01-19 19:29:20 C:\WINDOWS\SoftwareDistribution\Download\393673217fc83f2b990ca70aa98f1df8\spmsg.dll
----a-w 716,000 2006-01-19 19:29:20 C:\WINDOWS\SoftwareDistribution\Download\393673217fc83f2b990ca70aa98f1df8\update\update.exe
----a-w 22,752 2006-01-19 19:29:20 C:\WINDOWS\SoftwareDistribution\Download\393673217fc83f2b990ca70aa98f1df8\update\spcustom.dll
----a-w 371,424 2006-01-19 19:29:20 C:\WINDOWS\SoftwareDistribution\Download\393673217fc83f2b990ca70aa98f1df8\update\updspapi.dll
------w 144,896 2005-12-31 21:00:00 C:\WINDOWS\SoftwareDistribution\Download\393673217fc83f2b990ca70aa98f1df8\backup\sp2gdr\schannel.dll
------w 144,896 2005-12-31 21:00:00 C:\WINDOWS\SoftwareDistribution\Download\393673217fc83f2b990ca70aa98f1df8\backup\sp2qfe\schannel.dll
----a-w 213,216 2005-10-12 23:16:50 C:\WINDOWS\SoftwareDistribution\Download\4387300ca1dcf29784a47c30e67cb637\spuninst.exe
----a-w 14,048 2005-10-12 23:16:50 C:\WINDOWS\SoftwareDistribution\Download\4387300ca1dcf29784a47c30e67cb637\spmsg.dll
----a-w 716,000 2005-10-12 23:16:52 C:\WINDOWS\SoftwareDistribution\Download\4387300ca1dcf29784a47c30e67cb637\update\update.exe
----a-w 22,752 2005-10-12 23:16:50 C:\WINDOWS\SoftwareDistribution\Download\4387300ca1dcf29784a47c30e67cb637\update\spcustom.dll
----a-w 371,424 2005-10-12 23:16:56 C:\WINDOWS\SoftwareDistribution\Download\4387300ca1dcf29784a47c30e67cb637\update\updspapi.dll
------w 41,984 2005-12-31 21:00:00 C:\WINDOWS\SoftwareDistribution\Download\4387300ca1dcf29784a47c30e67cb637\backup\sp2gdr\agentdp2.dll
------w 256,512 2005-12-31 21:00:00 C:\WINDOWS\SoftwareDistribution\Download\4387300ca1dcf29784a47c30e67cb637\backup\sp2gdr\agentsvr.exe
----a-w 7,168 2004-10-14 08:34:52 C:\WINDOWS\SoftwareDistribution\Download\adc42e4e6905251cac80b18a8dccd42a\spmsg.dll
----a-w 169,984 2004-10-14 08:36:18 C:\WINDOWS\SoftwareDistribution\Download\adc42e4e6905251cac80b18a8dccd42a\spuninst.exe
----a-w 654,848 2004-10-14 08:34:54 C:\WINDOWS\SoftwareDistribution\Download\adc42e4e6905251cac80b18a8dccd42a\update\update.exe
----a-w 21,504 2004-10-14 08:36:16 C:\WINDOWS\SoftwareDistribution\Download\adc42e4e6905251cac80b18a8dccd42a\update\spcustom.dll
----a-w 32,768 2007-08-21 12:24:56 C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
----a-w 32,768 2007-08-21 12:24:56 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
----a-w 16,384 2007-08-21 12:24:56 C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
----a-w 36,352 2005-12-31 21:00:00 C:\WINDOWS\system32\drivers\disk.sys
----a-w 23,040 2005-12-31 21:00:00 C:\WINDOWS\system32\drivers\mouclass.sys
----a-w 26,496 2005-12-31 21:00:00 C:\WINDOWS\system32\drivers\usbstor.sys
----a-w 12,160 2005-12-31 21:00:00 C:\WINDOWS\system32\drivers\mouhid.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [06/28/2007 12:51 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [06/30/2004 03:55 PM]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [01/01/2006 12:00 AM]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [03/27/2007 03:58 PM]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"tscuninstall"=%systemroot%\system32\tscupgrd.exe
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
"WinAVX"=C:\WINDOWS\system32\WinAvXX.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"=0 (0x0)
"SynchronousUserGroupPolicy"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsHistory"=00000000
"MaxRecentDocs"=10 (0xa)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoControlPanel"=1 (0x1)
"NoWindowsUpdate"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Abdul^Start Menu^Programs^Startup^system.exe]
path=C:\Documents and Settings\Abdul\Start Menu\Programs\Startup\system.exe
backup=C:\WINDOWS\pss\system.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^system.exe]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\system.exe
backup=C:\WINDOWS\pss\system.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^autorun.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
backup=C:\WINDOWS\pss\autorun.exeCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^iZone Internet Turbo.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\iZone Internet Turbo.lnk
backup=C:\WINDOWS\pss\iZone Internet Turbo.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalStart.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalStart.lnk
backup=C:\WINDOWS\pss\PalStart.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\12Voip]
"C:\Program Files\12Voip.com\12Voip\12Voip.exe" -nosplash -minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
"C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CleanUp]
C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio]
RunDll32 cmicnfg.cpl,CMICtrlWnd
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hide IP Platinum]
C:\Program Files\Hide IP Platinum\hideippla.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
D:\hp\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
D:\Program Files\Internet Download Manager\IDMan.exe /onboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.2]
msime80.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LowRateVoip]
"C:\Program Files\LowRateVoip\LowRateVoip.exe" -nosplash -minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McRegWiz]
c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsServer]
msfir80.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
C:\Program Files\McAfee.com\VSO\oasclnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeekmoOE]
C:\Program Files\Seekmo\bin\10.0.341.0\OEAddOn.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeekmoSA]
"C:\Program Files\Seekmo\bin\10.0.341.0\SeekmoSA.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
C:\WINDOWS\system32\keyhook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SlipStream]
"C:\Program Files\iZone Internet Turbo\iZonecore.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\svcshare]
C:\WINDOWS\system32\drivers\spoclsv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
"C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAVX]
C:\WINDOWS\system32\WinAvXX.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"ServiceLayer"=3 (0x3)
"Pml Driver HPZ12"=2 (0x2)
"MDM"=2 (0x2)
"xmlprov"=3 (0x3)
"WmiApSrv"=3 (0x3)
"Wmi"=3 (0x3)
"winmgmt"=2 (0x2)
"WebClient"=2 (0x2)
"W32Time"=2 (0x2)
"VSS"=3 (0x3)
"usprserv"=3 (0x3)
"UPS"=3 (0x3)
"upnphost"=3 (0x3)
"TrkWks"=2 (0x2)
"TermService"=3 (0x3)
"TapiSrv"=3 (0x3)
"SysmonLog"=3 (0x3)
"SwPrv"=3 (0x3)
"stisvc"=2 (0x2)
"SSDPSRV"=3 (0x3)
"Spooler"=2 (0x2)
"ShellHWDetection"=2 (0x2)
"SharedAccess"=2 (0x2)
"seclogon"=2 (0x2)
"SCardSvr"=3 (0x3)
"SamSs"=2 (0x2)
"RSVP"=3 (0x3)
"RemoteRegistry"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"ProtectedStorage"=2 (0x2)
"PolicyAgent"=2 (0x2)
"PlugPlay"=2 (0x2)
"NtmsSvc"=3 (0x3)
"NtLmSsp"=3 (0x3)
"NOD32krn"=2 (0x2)
"Nla"=3 (0x3)
"Netman"=3 (0x3)
"Netlogon"=3 (0x3)
"MSIServer"=3 (0x3)
"MSDTC"=3 (0x3)
"mnmsrvc"=3 (0x3)
"LmHosts"=2 (0x2)
"lanmanworkstation"=2 (0x2)
"lanmanserver"=2 (0x2)
"ImapiService"=3 (0x3)
"HTTPFilter"=3 (0x3)
"EventSystem"=3 (0x3)
"Eventlog"=2 (0x2)
"Dnscache"=2 (0x2)
"dmserver"=2 (0x2)
"dmadmin"=3 (0x3)
"Dhcp"=2 (0x2)
"CryptSvc"=2 (0x2)
"COMSysApp"=3 (0x3)
"Browser"=2 (0x2)
"BITS"=3 (0x3)
"AudioSrv"=2 (0x2)
"AppMgmt"=3 (0x3)
"ALG"=3 (0x3)
"AVP"=2 (0x2)
"SDhelper"=2 (0x2)
"mcupdmgr.exe"=3 (0x3)
Contents of the 'Scheduled Tasks' folder
2007-08-28 01:42:36 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
2007-08-29 19:41:40 C:\WINDOWS\Tasks\RegCure.job - C:\Program Files\RegCure\RegCure.exe
2007-08-29 19:41:42 C:\WINDOWS\Tasks\RegCure Program Check.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-05 13:22:18
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Altap = 63
LongClock = 63
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Altap = 63
LongClock = 63
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\AntiVirScheduler]
"ImagePath"="\"C:\Program Files\AntiVir PersonalEdition Classic\sched.exe\""
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\AntiVirService]
"ImagePath"="\"C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe\""
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\avgio]
"ImagePath"="\??\C:\Program Files\AntiVir PersonalEdition Classic\avgio.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\avgntflt]
"ImagePath"="\??\C:\Program Files\AntiVir PersonalEdition Classic\avgntflt.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\avipbb]
"ImagePath"="system32\DRIVERS\avipbb.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\ssmdrv]
"ImagePath"="system32\DRIVERS\ssmdrv.sys"
Completion time: 09/05/2007 13:24:32
C:\ComboFix-quarantined-files.txt ... 09/05/2007 01:24 PM
C:\ComboFix2.txt ... 08/31/2007 05:37 PM
--- E O F ---
Edited by The killer, 05 September 2007 - 04:38 AM.