Here are the logs:
ComboFix 07-11-19.3 - Steve 2007-11-25 21:11:37.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1545 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\dat.txt
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\rs.txt
.
((((((((((((((((((((((((( Files Created from 2007-10-25 to 2007-11-25 )))))))))))))))))))))))))))))))
.
2007-11-25 13:36 3,582 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-25 13:36 0 –a—— C:\WINDOWS\system32\tmp.txt
2007-11-25 13:32 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2007-11-25 13:32 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-11-25 13:32 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-11-25 13:32 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2007-11-25 12:53 d——– C:\Program Files\Trend Micro
2007-11-25 11:47 d——– C:\Program Files\Common Files\Nokia
2007-11-25 11:37 d——– C:\Documents and Settings\Pip\Application Data\Leadertech
2007-11-24 14:20 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-24 13:58 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-18 21:03 d——– C:\Documents and Settings\Administrator\Application Data\toshiba
2007-11-18 21:03 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2007-11-18 21:03 d——– C:\Documents and Settings\Administrator\Application Data\AdobeUM
2007-11-17 23:08 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-17 23:08 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-17 23:08 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-17 23:08 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-11-17 23:06 d——– C:\Program Files\Spyware Doctor
2007-11-17 23:06 d——– C:\Documents and Settings\Steve\Application Data\PC Tools
2007-11-17 20:31 286,720 –a—— C:\WINDOWS\rmvgor.dll
2007-11-17 20:31 114,688 –a—— C:\WINDOWS\nethop.exe
2007-11-11 22:21 d——– C:\Documents and Settings\Steve\Application Data\wsInspector
2007-11-11 14:25 d——– C:\Program Files\Startup Inspector for Windows
2007-11-01 12:53 d——– C:\Documents and Settings\Steve\Application Data\PC Suite
2007-11-01 12:22 d——– C:\Documents and Settings\Pip\Application Data\Datalayer
2007-11-01 12:20 d——– C:\Documents and Settings\Pip\Application Data\AdobeAUM
2007-11-01 12:17 d——– C:\Program Files\Common Files\PCSuite
2007-11-01 12:17 127,488 –a—— C:\WINDOWS\system32\drivers\nmwcd.sys
2007-11-01 12:17 13,312 –a—— C:\WINDOWS\system32\drivers\nmwcdcj.sys
2007-11-01 12:17 8,704 –a—— C:\WINDOWS\system32\drivers\nmwcdc.sys
2007-11-01 12:01 d——– C:\Documents and Settings\Pip\Phone Browser
2007-11-01 11:18 d——– C:\Documents and Settings\Pip\Application Data\Nokia
2007-11-01 11:10 d——– C:\Program Files\DIFX
2007-11-01 11:09 d——– C:\Program Files\Nokia
2007-11-01 11:07 d——– C:\Documents and Settings\Pip\Application Data\PC Suite
2007-11-01 11:07 d——– C:\Documents and Settings\All Users\Application Data\PC Suite
2007-11-01 11:07 d——– C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-10-31 17:13 d——– C:\Program Files\Opera
2007-10-31 17:00 230 –a—— C:\WINDOWS\system32\spupdsvc.inf
2007-10-30 18:53 d——– C:\Program Files\Windows Live Favorites
2007-10-30 18:52 d——– C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-10-30 18:51 d——– C:\Program Files\Windows Live Toolbar
2007-10-30 16:57 6,058,496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-30 16:57 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-10-30 16:57 991,232 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-10-30 16:57 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-30 16:57 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-30 16:57 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-30 16:57 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-30 16:57 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-30 16:57 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-26 20:47 d——– C:\Documents and Settings\Steve\Application Data\Media Player Classic
2007-10-26 20:45 d——– C:\Program Files\Combined Community Codec Pack
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-25 20:06 ——— d—–w C:\Documents and Settings\Steve\Application Data\Microgaming
2007-11-25 16:09 ——— d—–w C:\Program Files\PokerStars
2007-11-24 16:14 ——— d—–w C:\Documents and Settings\Steve\Application Data\toshiba
2007-11-24 14:03 ——— d—–w C:\Program Files\McAfee
2007-11-24 02:51 ——— d—–w C:\Documents and Settings\Steve\Application Data\StumbleUpon
2007-11-18 23:42 ——— d—–w C:\Documents and Settings\Steve\Application Data\Skype
2007-11-18 14:49 ——— d—–w C:\Documents and Settings\Pip\Application Data\StumbleUpon
2007-11-14 22:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-12 16:30 ——— d—–w C:\Program Files\Common Files\McAfee
2007-11-03 18:41 ——— d—–w C:\Program Files\Java
2007-11-01 18:57 ——— d—–w C:\Program Files\Full Tilt Poker
2007-11-01 17:54 ——— d—–w C:\Program Files\William Hill Poker
2007-10-30 15:31 ——— d—–w C:\Program Files\MansionPoker
2007-10-30 15:30 ——— d—–w C:\Program Files\Bodog Poker
2007-10-30 15:17 ——— d—–w C:\Program Files\PartyGaming
2007-10-30 12:53 ——— d—–w C:\Program Files\PKR
2007-10-26 15:59 ——— d—–w C:\Documents and Settings\Steve\Application Data\LimeWire
2007-10-25 19:00 ——— d—–w C:\Program Files\TexasCalculatem
2007-10-25 14:02 ——— d—–w C:\Program Files\EmpirePokerMaster
2007-10-18 23:27 ——— d—–w C:\Program Files\LimeWire
2007-10-18 22:30 ——— d—–w C:\Documents and Settings\Steve\Application Data\BearShare
2007-09-30 14:32 ——— d—–w C:\Program Files\GalaPoker
2007-09-29 13:50 ——— d—–w C:\Program Files\StumbleUpon
2007-09-17 19:40 109,568 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-09-17 19:40 108,544 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-05-29 02:31 348,160 ——w C:\Documents and Settings\Steve\msvcr71.dll
2007-05-29 02:28 9,216 ——w C:\Documents and Settings\Steve\plds4.dll
2007-05-29 02:28 7,680 ——w C:\Documents and Settings\Steve\xpcom.dll
2007-05-29 02:28 6,459,392 ——w C:\Documents and Settings\Steve\xul.dll
2007-05-29 02:28 376,832 ——w C:\Documents and Settings\Steve\softokn3.dll
2007-05-29 02:28 372,736 ——w C:\Documents and Settings\Steve\nss3.dll
2007-05-29 02:28 233,472 ——w C:\Documents and Settings\Steve\nssckbi.dll
2007-05-29 02:28 13,312 ——w C:\Documents and Settings\Steve\plc4.dll
2007-05-29 02:28 118,784 ——w C:\Documents and Settings\Steve\ssl3.dll
2007-05-29 02:28 110,592 ——w C:\Documents and Settings\Steve\smime3.dll
2007-05-29 02:27 425,984 ——w C:\Documents and Settings\Steve\js3250.dll
2007-05-29 02:27 37,888 ——w C:\Documents and Settings\Steve\gksvggdiplus.dll
2007-05-29 02:27 159,744 ——w C:\Documents and Settings\Steve\nspr4.dll
2007-05-29 01:42 90,112 ——w C:\Documents and Settings\Steve\DirectXTest.exe
2007-05-29 01:42 1,257,472 ——w C:\Documents and Settings\Steve\DXTest.dll
2007-05-29 00:46 557,568 ——w C:\Documents and Settings\Steve\EscapeToNorrath.exe
2007-05-29 00:32 60,416 ——w C:\Documents and Settings\Steve\DSETUP.dll
2007-05-29 00:32 258,352 ——w C:\Documents and Settings\Steve\unicows.dll
2007-05-29 00:00 307,200 ——w C:\Documents and Settings\Steve\OptionsEditor.exe
2007-05-28 23:56 1,298,432 ——w C:\Documents and Settings\Steve\EQGraphicsDX9.dll
2007-05-28 22:50 1,296 ——w C:\Documents and Settings\Steve\load2_switches.dat
2007-05-28 22:48 901,120 ——w C:\Documents and Settings\Steve\EQGfx_Dx8.dll
2007-05-28 22:47 160,256 ——w C:\Documents and Settings\Steve\dpvs.dll
2007-05-28 22:45 974,848 ——w C:\Documents and Settings\Steve\eqmain.dll
2007-05-28 22:37 349,696 ——w C:\Documents and Settings\Steve\mss32.dll
2007-05-28 22:25 81,920 ——w C:\Documents and Settings\Steve\eaxman.dll
2007-05-28 21:59 3,604,480 ——w C:\Documents and Settings\Steve\eqgame.exe
2007-05-28 21:54 95,232 ——w C:\Documents and Settings\Steve\smackw32.dll
2007-05-28 21:29 249,856 ——w C:\Documents and Settings\Steve\installerconfig.exe
2007-05-28 21:29 1,421,312 ——w C:\Documents and Settings\Steve\TestEverQuest.exe
2007-05-28 21:28 217,088 ——w C:\Documents and Settings\Steve\Win32Bitmap.dll
2007-05-28 21:28 1,417,216 —-a-w C:\Documents and Settings\Steve\EverQuest.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6BA27973-068D-4F85-BE84-1251E0B20FD3}"= C:\WINDOWS\jokwmp.dll [ ]
[HKEY_CLASSES_ROOT\clsid\{6ba27973-068d-4f85-be84-1251e0b20fd3}]
[HKEY_CLASSES_ROOT\jokwmp.ToolBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{83AFF385-2051-4ADA-8001-549F0A671402}]
[HKEY_CLASSES_ROOT\jokwmp.ToolBar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-30 15:46]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-21 05:00 C:\WINDOWS\agrsmmsg.exe]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2004-08-06 14:14]
"NDSTray.exe"="NDSTray.exe" []
"CeEPOWER"="C:\Program Files\TOSHIBA\Power Management\CePMTray.exe" [2004-08-18 09:21]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-07-20 00:04]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 12:00 C:\WINDOWS\system32\bthprops.cpl]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 17:16]
"workflow"="D:\installs\workflow.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-19 22:41]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 20:10]
"EPSON Stylus D88 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABE.exe" [2005-01-27 04:00]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 12:59]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"rmvgor"= {B589957C-4765-4862-8896-A2AE7E6BA6D5} - C:\WINDOWS\rmvgor.dll [2007-11-17 16:31 286720]
"sapnet"= {45528DF1-8F15-46A9-9977-8D2788365912} - C:\WINDOWS\sapnet.dll [ ]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TrayMin200.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TrayMin200.exe.lnk
backup=C:\WINDOWS\pss\TrayMin200.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 23:46 57344 –a—— C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDogPath]
C:\WINDOWS\VM_STI.EXE Philips SPC 200NC PC Camera
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzButton]
2004-07-07 15:25 712704 –a—— C:\Program Files\EzButton\EzButton.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 12:39 1289000 –a—— C:\Program Files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MBkLogOnHook]
2007-01-08 10:22 20480 –a—— C:\Program Files\McAfee\MBK\LogOnHook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PadTouch]
2004-02-12 10:02 1019904 –a—— C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2007-06-15 23:15 366400 –a—— C:\Program Files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PKR Pal]
C:\Program Files\PKR\pkrpal.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
2004-04-27 08:02 118784 –a—— C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe /startoptions
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPNF]
2004-07-28 15:23 53248 –a—— C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoomingHook]
2004-07-14 15:07 24576 –a—— c:\WINDOWS\System32\ZoomingHook.exe
R1 SrvcEKIOMngr;SrvcEKIOMngr;C:\WINDOWS\system32\Drivers\EKIoMngr.sys
R1 SrvcEPECioctl;SrvcEPECioctl;C:\WINDOWS\system32\Drivers\ECioctl.sys
R1 SrvcEPIOMngr;SrvcEPIOMngr;C:\WINDOWS\system32\Drivers\EPIoMngr.sys
R1 SrvcSSIOMngr;SrvcSSIOMngr;C:\WINDOWS\system32\Drivers\SSIoMngr.sys
R1 SrvcTPIOMngr;SrvcTPIOMngr;C:\WINDOWS\system32\Drivers\TPIoMngr.sys
R2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys
R3 Bonifay;Bonifay;C:\WINDOWS\system32\DRIVERS\Bonifay.sys
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys
R3 EMSCR;EMSCR;C:\WINDOWS\system32\DRIVERS\EMS7SK.sys
R3 EPOWER;Compal E-POWER Driver;C:\WINDOWS\system32\Drivers\hkdrv.sys
R3 ESDCR;ESDCR;C:\WINDOWS\system32\DRIVERS\ESD7SK.sys
R3 ESMCR;ESMCR;C:\WINDOWS\system32\DRIVERS\ESM7SK.sys
S2 0258951195913067mcinstcleanup;McAfee Application Installer Cleanup (0258951195913067);C:\WINDOWS\TEMP\
025895~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service
S3 Gonzales;Gonzales;C:\WINDOWS\system32\DRIVERS\Gonzales.sys
S3 o1394bul;o1394bul;\??\C:\DOCUME~1\Steve\LOCALS~1\Temp\o1394bul.sys
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys
S3 w550bus;Sony Ericsson W550 driver (WDM);C:\WINDOWS\system32\DRIVERS\w550bus.sys
S3 w550mdfl;Sony Ericsson W550 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w550mdfl.sys
S3 w550mdm;Sony Ericsson W550 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\w550mdm.sys
S3 w550mgmt;Sony Ericsson W550 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\w550mgmt.sys
S3 w550obex;Sony Ericsson W550 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\w550obex.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\NokiaInstaller.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-11-25 20:41:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2007-08-15 01:07:49 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2007-08-06 18:41:26 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2005-04-18 17:26:23 C:\WINDOWS\Tasks\Registration reminder 2.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2005-04-18 17:26:24 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-25 21:15:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-25 21:16:59
.
— E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:21:11, on 25/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\system32\RAMASST.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: The jokwmp - {6BA27973-068D-4F85-BE84-1251E0B20FD3} - C:\WINDOWS\jokwmp.dll (file missing)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [workflow] D:\installs\workflow.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [EPSON Stylus D88 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABE.EXE /P23 "EPSON Stylus D88 Series" /O5 "LPT1:" /M "Stylus D88"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Steve\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Steve\Desktop\WH GBP Casino.lnk (file missing)
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PacificPoker - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - C:\PROGRA~1\PACIFI~1\pacificpoker.exe
O9 - Extra button: Poker 333 - {9A315457-791D-4dec-AFB0-9E7ACFF4B506} - C:\Program Files\piggspeakMPP\MPPoker.exe
O9 - Extra button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDPoker\casino.exe
O9 - Extra 'Tools' menuitem: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDPoker\casino.exe
O9 - Extra button: Gnuf Poker - {A99C8F70-4D5B-482c-8854-05BC0BB8B182} - C:\Program Files\Gnuf\Poker\MPPoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - http://www.williamhillcasino.com (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - http://www.williamhillcasino.com (file missing) (HKCU)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: rmvgor - {B589957C-4765-4862-8896-A2AE7E6BA6D5} - C:\WINDOWS\rmvgor.dll
O21 - SSODL: sapnet - {45528DF1-8F15-46A9-9977-8D2788365912} - C:\WINDOWS\sapnet.dll (file missing)
O23 - Service: McAfee Application Installer Cleanup (0258951195913067) (0258951195913067mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\025895~1.EXE (file missing)
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
–
End of file - 12466 bytes
Thanks for your help,
Steve