ok here are the two logs you requested….
combofix
ComboFix 08-02-25.3 - mom 2008-02-26 18:14:10.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.159 [GMT -8:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\mom\Desktop\CFScript.txt
FILE ::
C:\Users\mom\AppData\Local\Temp\hgday.dll
C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll
C:\Windows\system32\msconfig.exe
C:\Windows\wusa.lock
C:\Windows\xmljacodec.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\f24a1aca0b9794bd2211db
C:\f24a1aca0b9794bd2211db\Windows6.0-KB943899-v2-x86-pkgProperties.txt
C:\f24a1aca0b9794bd2211db\Windows6.0-KB943899-v2-x86.cab
C:\f24a1aca0b9794bd2211db\Windows6.0-KB943899-v2-x86.xml
C:\f24a1aca0b9794bd2211db\WSUSSCAN.cab
C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll
C:\Windows\wusa.lock
C:\Windows\xmljacodec.dll
C:\Windows\system32\msconfig.exe . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-01-27 to 2008-02-27 )))))))))))))))))))))))))))))))
.
2008-02-26 17:29 . 2008-02-26 17:29 d——– C:\Users\All Users\SUPERAntiSpyware.com
2008-02-26 17:29 . 2008-02-26 17:29 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-02-26 17:28 . 2008-02-26 17:28 d——– C:\Users\mom\AppData\Roaming\SUPERAntiSpyware.com
2008-02-26 17:28 . 2008-02-26 17:28 d——– C:\Program Files\SUPERAntiSpyware
2008-02-26 03:11 . 2008-02-26 03:11 d——– C:\Users\mom\AppData\Roaming\PC Tools
2008-02-26 03:11 . 2008-02-26 03:34 d——– C:\Program Files\Spyware Doctor
2008-02-26 03:11 . 2007-12-10 14:53 81,288 –a—— C:\Windows\System32\drivers\iksyssec.sys
2008-02-26 03:11 . 2007-12-10 14:53 66,952 –a—— C:\Windows\System32\drivers\iksysflt.sys
2008-02-26 03:11 . 2008-02-01 12:55 42,376 –a—— C:\Windows\System32\drivers\ikfilesec.sys
2008-02-26 03:11 . 2007-12-10 14:53 29,576 –a—— C:\Windows\System32\drivers\kcom.sys
2008-02-25 17:22 . 2008-02-25 17:26 d——– C:\Program Files\SpywareBlaster
2008-02-25 17:18 . 2008-02-25 17:18 d——– C:\ie-spyad
2008-02-25 16:27 . 2008-02-26 13:03 d——– C:\temp
2008-02-25 16:16 . 2008-02-25 16:16 d——– C:\Users\mom\AppData\Roaming\Grisoft
2008-02-25 16:16 . 2007-05-30 04:10 10,872 –a—— C:\Windows\System32\drivers\AvgAsCln.sys
2008-02-25 16:15 . 2008-02-26 17:16 246 –a—— C:\Windows\Lexstat.ini
2008-02-25 16:13 . 2008-02-25 16:18 d——– C:\Program Files\Lexmark X1100 Series
2008-02-25 16:12 . 2008-02-25 16:12 d——– C:\drivers
2008-02-25 16:11 . 2008-02-25 16:12 36,487,088 –a—— C:\Users\mom\cjrX1100EN.exe
2008-02-25 11:50 . 2007-07-26 17:07 621,056 –a—— C:\Windows\System32\drivers\dxgkrnl.sys
2008-02-25 11:50 . 2007-07-26 18:17 36,864 –a—— C:\Windows\System32\cdd.dll
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\Users\All Users\HP
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\ProgramData\HP
2008-02-25 05:42 . 2008-02-25 05:43 d——– C:\Program Files\HP
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\Program Files\Common Files\HP
2008-02-25 05:42 . 2008-02-25 05:43 102,364 –a—— C:\Windows\hpqins13.dat
2008-02-25 05:06 . 2008-02-25 05:08 125 –a—— C:\ioSpecial.ini
2008-02-24 15:11 . 2008-02-25 04:54 d——– C:\Program Files\BuildALot_at
2008-02-24 08:52 . 2008-02-24 08:52 d——– C:\Program Files\ReflexiveArcade
2008-02-24 08:09 . 2008-02-24 08:09 d——– C:\Program Files\Agatha Christie - Peril at End House
2008-02-24 05:07 . 2008-02-24 05:07 d——– C:\Program Files\Mystery Case Files - Prime Suspects
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\Users\mom\AppData\Roaming\Oberon Games
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\Users\All Users\Oberon Games
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\ProgramData\Oberon Games
2008-02-22 22:09 . 2008-02-22 22:09 d——– C:\Users\mom\AppData\Roaming\Magic Seeds
2008-02-22 12:13 . 2008-02-22 12:13 d——– C:\Users\All Users\HipSoft
2008-02-22 12:13 . 2008-02-22 12:13 d——– C:\ProgramData\HipSoft
2008-02-22 10:07 . 2008-02-22 10:07 d——– C:\Program Files\bfgclient
2008-02-22 10:07 . 2008-02-22 10:21 d——– C:\BigFishGamesCache
2008-02-20 22:09 . 2008-02-20 22:09 d——– C:\Users\All Users\BVRP Software
2008-02-20 22:09 . 2008-02-20 22:09 d——– C:\ProgramData\BVRP Software
2008-02-20 22:04 . 2008-02-20 22:04 dr-hs—- C:\_Backup.RC
2008-02-20 22:04 . 2008-02-20 23:43 d–h—– C:\_Backup
2008-02-20 22:00 . 2008-02-24 15:23 d——– C:\Users\mom\AppData\Roaming\Avanquest
2008-02-20 22:00 . 2008-02-20 22:00 d——– C:\Users\All Users\Avanquest
2008-02-20 22:00 . 2008-02-20 22:00 d——– C:\ProgramData\Avanquest
2008-02-20 21:59 . 2008-02-20 21:59 d——– C:\Program Files\Avanquest
2008-02-20 21:55 . 2008-02-26 17:27 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-19 21:18 . 2007-03-06 18:51 543,232 –a—— C:\Windows\System32\FWPUCLNT.DLL
2008-02-19 21:18 . 2007-03-06 18:51 416,768 –a—— C:\Windows\System32\IKEEXT.DLL
2008-02-19 21:18 . 2007-03-06 18:51 317,440 –a—— C:\Windows\System32\BFE.DLL
2008-02-19 21:18 . 2007-03-06 18:08 84,992 –a—— C:\Windows\System32\drivers\FWPKCLNT.SYS
2008-02-19 21:17 . 2008-02-19 21:17 d——– C:\Users\mom\AppData\Roaming\Sammsoft
2008-02-19 21:16 . 2008-02-19 22:25 d——– C:\Program Files\Advanced Registry Optimizer
2008-02-19 21:09 . 2008-02-19 21:09 d——– C:\Users\All Users\Grisoft
2008-02-19 21:09 . 2008-02-19 21:09 d——– C:\ProgramData\Grisoft
2008-02-19 21:06 . 2008-02-19 21:06 1,420 –a—— C:\Windows\wininit.ini
2008-02-19 20:25 . 2008-02-19 22:34 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-02-19 20:25 . 2008-02-19 22:34 d——– C:\ProgramData\Spybot - Search & Destroy
2008-02-19 20:25 . 2008-02-19 21:12 d——– C:\Program Files\Trend Micro
2008-02-19 20:25 . 2008-02-19 22:35 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-19 20:12 . 2008-02-19 20:12 d——– C:\kav
2008-02-19 19:37 . 2008-02-19 19:37 3,764 –a—— C:\Windows\System32\tmp.reg
2008-02-19 19:36 . 2008-02-19 19:41 d——– C:\Windows\System32\SmitfraudFix
2008-02-19 05:33 . 2008-02-19 05:37 d——– C:\Users\mom\.housecall6.6
2008-02-18 23:00 . 2008-02-25 04:53 d——– C:\Program Files\AdwareAlert
2008-02-18 22:51 . 2008-02-18 22:51 d——– C:\Program Files\Enigma Software Group
2008-02-17 11:52 . 2008-02-17 11:52 d——– C:\Users\mom\AppData\Roaming\PCF-VLC
2008-02-16 21:34 . 2008-02-26 17:52 dr——- C:\Windows\System32\config\systemprofile\Documents
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Users\All Users\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\ProgramData\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Program Files\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Program Files\Common Files\Authentium
2008-02-16 21:23 . 2007-04-04 17:15 839,880 –a—— C:\Windows\System32\drivers\css-dvp.sys
2008-02-16 21:23 . 2007-03-06 13:24 55,296 –a—— C:\Windows\System32\drivers\rp_skt32.sys
2008-02-16 21:23 . 2007-04-05 14:52 48,384 –a—— C:\Windows\System32\drivers\rp_pkt32.sys
2008-02-16 21:22 . 2008-02-19 23:02 d——– C:\Program Files\Common Files\Scanner
2008-02-16 21:22 . 2008-02-16 21:22 d——– C:\Program Files\CA
2008-02-16 21:20 . 2008-02-16 21:20 d——– C:\Users\mom\AppData\Roaming\InstallShield
2008-02-15 21:09 . 2008-01-09 21:50 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2008-02-15 18:38 . 2008-02-15 18:38 d——– C:\Users\mom\AppData\Roaming\Template
2008-02-15 18:37 . 2008-02-22 21:53 90 –a—— C:\Users\mom\AppData\Roaming\wklnhst.dat
2008-02-15 17:00 . 2008-02-15 17:00 d——– C:\Users\All Users\Macrovision
2008-02-15 17:00 . 2008-02-15 17:00 d——– C:\ProgramData\Macrovision
2008-02-15 16:58 . 2008-02-15 16:58 d——– C:\Program Files\Common Files\Macromedia Shared
2008-02-15 16:55 . 2008-02-15 16:55 d——– C:\Program Files\Common Files\Macromedia
2008-02-15 16:53 . 2008-02-15 16:53 d——– C:\Program Files\Macromedia
2008-02-14 06:02 . 2008-02-14 06:02 d——– C:\Users\mom\AppData\Roaming\Participatory Culture Foundation
2008-02-14 06:01 . 2008-02-14 06:01 d——– C:\Users\All Users\Participatory Culture Foundation
2008-02-14 06:01 . 2008-02-14 06:01 d——– C:\ProgramData\Participatory Culture Foundation
2008-02-14 06:00 . 2008-02-14 06:00 d——– C:\My Documents
2008-02-13 18:05 . 2008-02-13 18:05 194,560 –a—— C:\Windows\System32\WebClnt.dll
2008-02-13 18:05 . 2008-02-13 18:05 110,080 –a—— C:\Windows\System32\drivers\mrxdav.sys
2008-02-13 18:01 . 2008-02-13 18:01 3,505,720 –a—— C:\Windows\System32\ntkrnlpa.exe
2008-02-13 18:01 . 2008-02-13 18:01 3,471,928 –a—— C:\Windows\System32\ntoskrnl.exe
2008-02-13 18:01 . 2008-02-13 18:01 154,624 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-02-13 18:01 . 2008-02-13 18:01 109,624 –a—— C:\Windows\System32\drivers\ataport.sys
2008-02-13 18:01 . 2008-02-13 18:01 45,112 –a—— C:\Windows\System32\drivers\pciidex.sys
2008-02-13 18:01 . 2008-02-13 18:01 21,560 –a—— C:\Windows\System32\drivers\atapi.sys
2008-02-13 18:01 . 2008-02-13 18:01 15,928 –a—— C:\Windows\System32\drivers\pciide.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 13:05 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-14 02:04 54,784 —-a-w C:\Windows\system32\drivers\i8042prt.sys
2008-02-14 02:04 495,160 —-a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-02-14 02:04 35,384 —-a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-02-14 02:04 35,384 —-a-w C:\Windows\system32\drivers\kbdclass.sys
2008-02-14 02:04 34,360 —-a-w C:\Windows\system32\drivers\mouclass.sys
2008-02-14 02:04 19,968 —-a-w C:\Windows\system32\drivers\sermouse.sys
2008-02-14 02:04 15,872 —-a-w C:\Windows\system32\drivers\mouhid.sys
2008-02-13 20:00 537,600 —-a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 20:00 449,536 —-a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 20:00 2,144,256 —-a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 20:00 173,056 —-a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 19:57 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-02 17:15 ——— d—–w C:\Users\mom\AppData\Roaming\.wyzo
2008-02-02 16:04 ——— d—–w C:\Users\mom\AppData\Roaming\.BitTornado
2008-02-02 15:44 ——— d—–w C:\Program Files\eSobi
2008-02-01 23:04 ——— d—–w C:\Program Files\Microsoft Games
2008-02-01 11:31 174 –sha-w C:\Program Files\desktop.ini
2008-02-01 11:28 ——— d—–w C:\Program Files\Windows Mail
2008-02-01 11:28 ——— d—–w C:\Program Files\Windows Calendar
2008-02-01 11:27 ——— d—–w C:\Program Files\Windows Sidebar
2008-02-01 11:27 ——— d—–w C:\Program Files\Windows Defender
2008-02-01 11:19 70,144 —-a-w C:\Windows\system32\drivers\pacer.sys
2008-02-01 11:19 61,952 —-a-w C:\Windows\system32\drivers\wanarp.sys
2008-02-01 11:19 48,640 —-a-w C:\Windows\system32\drivers\ndproxy.sys
2008-02-01 11:19 20,480 —-a-w C:\Windows\system32\drivers\ndistapi.sys
2008-02-01 11:17 258,232 —-a-w C:\Windows\system32\drivers\acpi.sys
2008-02-01 11:17 2,923,520 —-a-w C:\Windows\explorer.exe
2008-02-01 11:12 63,488 —-a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-02-01 11:12 23,040 —-a-w C:\Windows\system32\drivers\tunnel.sys
2008-02-01 11:12 15,360 —-a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-02-01 08:25 ——— d—–w C:\ProgramData\eSobi
2008-02-01 07:40 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-01 07:39 ——— d—–w C:\ProgramData\Symantec
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-01 03:04 1232896]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16 454784]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-31 23:32 68856]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 04:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 04:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 03:04 4423680 C:\Windows\RtHDVCpl.exe]
"Acer Empowering Technology Monitor"="C:\Acer\Empowering Technology\SysMonitor.exe" [2007-01-24 09:27 319488]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 23:04 464168]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-02-02 00:37 630784]
"Acer Product Registration"="C:\Program Files\Acer Registration\ACE1.exe" [2007-02-02 11:24 3383296]
"Acer Assist Launcher"="C:\Program Files\Acer Assist\launcher.exe" [2007-02-02 10:05 1261568]
"Setresolution"="C:\ACERSW\config\1440x900.cmd" [2007-10-11 11:15 198]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ISW.exe"="C:\Program Files\AT&T;\Internet Security Wizard\ISW.exe" [2007-05-03 13:12 2061816]
"AT&T; Internet Security Suite"="C:\Program Files\AT&T;\AT&T; Internet Security Suite\Rps.exe" [2007-06-28 16:09 310000]
"-FreedomNeedsReboot"="C:\Program Files\AT&T;\AT&T; Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 16:09 13552]
"VirusScannerPro"="C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe" [2007-09-11 02:32 173312]
"hpqSRMon"="C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 16:31 80896]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25 6731312]
"lxbkbmgr.exe"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2007-04-26 12:02 74672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-04-16 17:09:28 528384]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PCM Media Sharing.lnk]
backup=C:\Windows\pss\PCM Media Sharing.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2007-10-02 14:45 67488 C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blubster]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LimeShop]
javaw -cp C:\Program Files\LimeShop\System\Code Main lp: C:\Program Files\LimeShop
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2008-01-31 23:32 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{ED1E9675-5C5C-4552-8979-8FFBD704C996}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C5A6A6A0-D297-4AA6-9383-21A16C3F9929}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C0B04953-9D63-4886-9FEE-B20972592777}"= C:\Program Files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live|Desc=Acer Arcade Live
"{64C52DD3-2977-4C34-BDA1-8FD96179DF00}"= C:\Program Files\Acer Arcade Live\SlideShow DVD\Component\CLSLDVD.exe:SlideShow DVD workprocess|Desc=SlideShow DVD workprocess
"{F42A10AE-D383-4A78-9E05-64BBC84376C5}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\ARAWP.exe:DV Magician ARA workprocess|Desc=DV Magician ARA workprocess
"{A0E22BD1-9D17-41A4-BF50-419B503C50D0}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\DVAX2Process.exe:DV Magician AVAX workprocess|Desc=DV Magician AVAX workprocess
"{E59634F8-1C07-40AC-84E1-E301FBC238EE}"= C:\Program Files\Acer Arcade Live\Acer DVDivine\DVDivine.exe:DVDivine|Desc=DVDivine
"{DFFF3429-DA90-43DB-898C-FAEEFE3F39E2}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia\HomeMedia.exe:HomeMedia|Desc=HomeMedia
"{5F06C73B-3B46-4ED5-983C-2880071833B2}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\HomeMedia Connect.exe:HomeMedia Connect|Desc=HomeMedia Connect
"{1955E669-BE1F-4C13-B854-FB32F2900974}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:HomeMedia Connect Service|Desc=HomeMedia Connect Service
"{A8757501-B402-4C19-AD10-EA4697A9512B}"= C:\Program Files\Acer Arcade Live\Acer VideoMagician\VideoMagician.exe:VideoMagician|Desc=VideoMagician
"{9234C2B8-F04E-4204-A09F-3FCCBFA126AE}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B2B007CA-B0EE-4273-9F70-DC3EA7ABA9ED}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B456AA34-D9D2-4AA1-B344-8B09EAECC6B8}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{0C714E48-AC34-4FD8-9B2A-59D42C53B5D7}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{46815E3A-9CC6-45F8-A148-A9473F8E7769}C:\program files\windows sidebar\sidebar.exe"= UDP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar|Desc=Windows Sidebar
"UDP Query User{0866C7EE-A71E-4654-8CA1-0E1F5CE3E61B}C:\program files\windows sidebar\sidebar.exe"= TCP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar|Desc=Windows Sidebar
"TCP Query User{5465F7B4-AB26-4F4D-933A-FF89AF66E9CB}C:\program files\ares destiny powered by advantage\ares.exe"= UDP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"UDP Query User{977F1337-B2E4-45C8-BD56-64A89A48894E}C:\program files\ares destiny powered by advantage\ares.exe"= TCP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"{94AA03C4-97DD-4A17-AC0E-944B0071DAD9}"= UDP:C:\Program Files\Blubster\Blubster.exe:Blubster
"{B1C11E30-1213-4486-BBA4-EC18397A5EC4}"= TCP:C:\Program Files\Blubster\Blubster.exe:Blubster
"{FFCAA06D-B93F-4761-95C2-ED89CD2E1795}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires III
"{F44736BC-EC14-4700-B298-7914E0856207}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires III
"{D7709ABE-C477-4DC0-B614-9683BC741823}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:Age of Empires III - The WarChiefs
"{1E358188-B5AE-4DC6-8C6E-319E3BB034B0}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:Age of Empires III - The WarChiefs
"TCP Query User{B2D87FF7-832C-49FE-BD9E-89ACD040F655}C:\program files\streamcast\morpheus\morpheus.exe"= UDP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"UDP Query User{F6A71D3E-5BA8-4449-8DDB-23D0DF2A9708}C:\program files\streamcast\morpheus\morpheus.exe"= TCP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"TCP Query User{EC8CE942-D080-4BA8-AE3B-0F834E4969CC}C:\windows\system32\javaw.exe"= UDP:C:\windows\system32\javaw.exe:Java™ Platform SE binary|Desc=Java™ Platform SE binary
"UDP Query User{F3285B82-9AA8-438E-8AD8-14ECE6877D4D}C:\windows\system32\javaw.exe"= TCP:C:\windows\system32\javaw.exe:Java™ Platform SE binary|Desc=Java™ Platform SE binary
"{5780BA34-CFE2-423E-B53C-D00E62E549CF}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{0A80E1F4-015B-4A63-BDCA-AA0349472A0F}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{53213690-2F90-48B7-88C0-0EC426C28D83}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{26BDE5B8-667C-4659-BD7E-1B40D4A2FC4B}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{FA80AA46-E4BC-4AF2-AE1F-48DE47BA08DF}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{8CA99614-5EA4-4858-A86D-078ED9E34859}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{8CDEA102-A4A2-46C9-9926-BB6C7A327CF1}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{A51AE3A2-2ED8-40AB-90EE-17AF90D79C16}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"TCP Query User{2A015A47-5926-4EC6-B4F2-7A271F2EB118}C:\program files\ares ultra\ares ultra.exe"= Disabled:UDP:C:\program files\ares ultra\ares ultra.exe:Ares Ultra p2p for windows|Desc=Ares Ultra p2p for windows
"UDP Query User{2ADF9AAE-7C9D-4D54-8F66-BFDD44542910}C:\program files\ares ultra\ares ultra.exe"= Disabled:TCP:C:\program files\ares ultra\ares ultra.exe:Ares Ultra p2p for windows|Desc=Ares Ultra p2p for windows
"TCP Query User{D51C1380-4F13-455B-BAEC-A8957567347F}C:\program files\bittornado\btdownloadgui.exe"= UDP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"UDP Query User{915AC283-DB84-4A06-AACC-531197D15028}C:\program files\bittornado\btdownloadgui.exe"= TCP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"TCP Query User{05AF3670-5012-41C7-BE3B-90E8B91D6618}C:\program files\utorrent\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"UDP Query User{519F3CCD-78C9-4D71-8241-8545D5E28844}C:\program files\utorrent\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"TCP Query User{06B02AE2-9D81-4A20-9FB9-E497EA8FD740}C:\program files\wyzo\wyzo.exe"= UDP:C:\program files\wyzo\wyzo.exe:Wyzo|Desc=Wyzo
"UDP Query User{1B57D6E7-155E-4450-8365-27D8D5548C34}C:\program files\wyzo\wyzo.exe"= TCP:C:\program files\wyzo\wyzo.exe:Wyzo|Desc=Wyzo
"TCP Query User{4C971860-1839-4552-B334-9CC70301ABCB}C:\program files\bittornado\btdownloadgui.exe"= UDP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"UDP Query User{6C063307-082D-4B83-B397-D4950890871E}C:\program files\bittornado\btdownloadgui.exe"= TCP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"TCP Query User{B733EB0A-5624-4DA0-94FE-BE4CBEDA5950}C:\program files\azureus\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"UDP Query User{63641DF6-E896-4EB4-BD1B-5693B1BBB4AC}C:\program files\azureus\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"TCP Query User{979A8622-97BB-4327-893C-1E933B2DD82F}C:\program files\ares destiny powered by advantage\ares.exe"= UDP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"UDP Query User{9984BA5E-7108-492F-A1CE-E82DEA8DA5BD}C:\program files\ares destiny powered by advantage\ares.exe"= TCP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"TCP Query User{3CCD6E95-EB20-413A-A1D8-4B11C7DE15CC}C:\program files\streamcast\morpheus\morpheus.exe"= UDP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"UDP Query User{FDC9E13B-2EDC-4F19-9A6C-F7019E1EE034}C:\program files\streamcast\morpheus\morpheus.exe"= TCP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"{1EA8CC77-0C78-4A5F-9358-00995778259E}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{0515436C-451C-4970-B3FA-617E20EE7E95}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"TCP Query User{47A29E79-4ED1-48A0-941D-F8C203508FE4}C:\program files\utorrent\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"UDP Query User{05A0B5DF-7D19-41C8-A704-EDB7FF9561E3}C:\program files\utorrent\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"{35656831-0F96-4AE7-84B7-80ABD02C2A59}"= UDP:52555:utor1
"{E7FC6750-7D3B-4B3A-900B-E7EBE5BD0494}"= UDP:C:\Windows\System32\lxbkcoms.exe:Lexmark Communications System
"{B11A941D-BACA-4B0E-AEF7-8CAB19B0B5F7}"= TCP:C:\Windows\System32\lxbkcoms.exe:Lexmark Communications System
"{0E690F73-7BE2-42B3-8E93-9149D1DA9C14}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window
"{0F122DF0-5137-4336-9DD4-FC51C50AC9A0}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-29 19:22]
R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-02-06 23:04]
R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-02-06 23:04]
R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-02-06 23:04]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;"C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe" [2007-04-04 17:54]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 14:46]
R2 AdwareAlertSrv;AdwareAlert Scanning Engine;"C:\Program Files\AdwareAlert\AdwareAlert.srv.exe" [2008-02-14 13:27]
R2 eDataSecurity Service;eDataSecurity Service;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-02-06 23:04]
R2 lxbk_device;lxbk_device;C:\Windows\system32\lxbkcoms.exe [2007-04-26 12:01]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-03-14 06:04]
R3 KFilter;KFilter;C:\PROGRA~1\AVANQU~1\SYSTEM~1\KFilter.sys [2007-09-11 02:32]
R3 MailScan;MailScan;C:\PROGRA~1\AVANQU~1\SYSTEM~1\MailScan.sys [2007-09-11 02:32]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-03-22 18:12]
S3 Radialpoint Security Services;AT&T; Internet Security Suite;C:\Windows\system32\dllhost.exe [2006-11-02 01:45]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6818ae31-d20c-11dc-8e7b-001c2552ea58}]
\shell\AutoRun\command - LinksysConnectPC.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5783dde-d202-11dc-8197-001c2552ea58}]
\shell\AutoRun\command - K:\RCAMemoryMgr.exe
\shell\Manage your videos\command - K:\RCAMemoryMgr.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-26 18:19:27
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\AT&T;\AT&T; Internet Security Suite\Fws.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Windows\system32\WUDFHost.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\mxtask.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\Program Files\Avanquest\SystemSuite\MemCheck.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2008-02-26 18:22:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-27 02:22:38
ComboFix2.txt 2008-02-27 01:45:22
.
2008-02-17 01:05:47 — E O F —
and hijack
ComboFix 08-02-25.3 - mom 2008-02-26 18:14:10.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.159 [GMT -8:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\mom\Desktop\CFScript.txt
FILE ::
C:\Users\mom\AppData\Local\Temp\hgday.dll
C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll
C:\Windows\system32\msconfig.exe
C:\Windows\wusa.lock
C:\Windows\xmljacodec.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\f24a1aca0b9794bd2211db
C:\f24a1aca0b9794bd2211db\Windows6.0-KB943899-v2-x86-pkgProperties.txt
C:\f24a1aca0b9794bd2211db\Windows6.0-KB943899-v2-x86.cab
C:\f24a1aca0b9794bd2211db\Windows6.0-KB943899-v2-x86.xml
C:\f24a1aca0b9794bd2211db\WSUSSCAN.cab
C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll
C:\Windows\wusa.lock
C:\Windows\xmljacodec.dll
C:\Windows\system32\msconfig.exe . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-01-27 to 2008-02-27 )))))))))))))))))))))))))))))))
.
2008-02-26 17:29 . 2008-02-26 17:29 d——– C:\Users\All Users\SUPERAntiSpyware.com
2008-02-26 17:29 . 2008-02-26 17:29 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-02-26 17:28 . 2008-02-26 17:28 d——– C:\Users\mom\AppData\Roaming\SUPERAntiSpyware.com
2008-02-26 17:28 . 2008-02-26 17:28 d——– C:\Program Files\SUPERAntiSpyware
2008-02-26 03:11 . 2008-02-26 03:11 d——– C:\Users\mom\AppData\Roaming\PC Tools
2008-02-26 03:11 . 2008-02-26 03:34 d——– C:\Program Files\Spyware Doctor
2008-02-26 03:11 . 2007-12-10 14:53 81,288 –a—— C:\Windows\System32\drivers\iksyssec.sys
2008-02-26 03:11 . 2007-12-10 14:53 66,952 –a—— C:\Windows\System32\drivers\iksysflt.sys
2008-02-26 03:11 . 2008-02-01 12:55 42,376 –a—— C:\Windows\System32\drivers\ikfilesec.sys
2008-02-26 03:11 . 2007-12-10 14:53 29,576 –a—— C:\Windows\System32\drivers\kcom.sys
2008-02-25 17:22 . 2008-02-25 17:26 d——– C:\Program Files\SpywareBlaster
2008-02-25 17:18 . 2008-02-25 17:18 d——– C:\ie-spyad
2008-02-25 16:27 . 2008-02-26 13:03 d——– C:\temp
2008-02-25 16:16 . 2008-02-25 16:16 d——– C:\Users\mom\AppData\Roaming\Grisoft
2008-02-25 16:16 . 2007-05-30 04:10 10,872 –a—— C:\Windows\System32\drivers\AvgAsCln.sys
2008-02-25 16:15 . 2008-02-26 17:16 246 –a—— C:\Windows\Lexstat.ini
2008-02-25 16:13 . 2008-02-25 16:18 d——– C:\Program Files\Lexmark X1100 Series
2008-02-25 16:12 . 2008-02-25 16:12 d——– C:\drivers
2008-02-25 16:11 . 2008-02-25 16:12 36,487,088 –a—— C:\Users\mom\cjrX1100EN.exe
2008-02-25 11:50 . 2007-07-26 17:07 621,056 –a—— C:\Windows\System32\drivers\dxgkrnl.sys
2008-02-25 11:50 . 2007-07-26 18:17 36,864 –a—— C:\Windows\System32\cdd.dll
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\Users\All Users\HP
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\ProgramData\HP
2008-02-25 05:42 . 2008-02-25 05:43 d——– C:\Program Files\HP
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\Program Files\Common Files\HP
2008-02-25 05:42 . 2008-02-25 05:43 102,364 –a—— C:\Windows\hpqins13.dat
2008-02-25 05:06 . 2008-02-25 05:08 125 –a—— C:\ioSpecial.ini
2008-02-24 15:11 . 2008-02-25 04:54 d——– C:\Program Files\BuildALot_at
2008-02-24 08:52 . 2008-02-24 08:52 d——– C:\Program Files\ReflexiveArcade
2008-02-24 08:09 . 2008-02-24 08:09 d——– C:\Program Files\Agatha Christie - Peril at End House
2008-02-24 05:07 . 2008-02-24 05:07 d——– C:\Program Files\Mystery Case Files - Prime Suspects
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\Users\mom\AppData\Roaming\Oberon Games
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\Users\All Users\Oberon Games
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\ProgramData\Oberon Games
2008-02-22 22:09 . 2008-02-22 22:09 d——– C:\Users\mom\AppData\Roaming\Magic Seeds
2008-02-22 12:13 . 2008-02-22 12:13 d——– C:\Users\All Users\HipSoft
2008-02-22 12:13 . 2008-02-22 12:13 d——– C:\ProgramData\HipSoft
2008-02-22 10:07 . 2008-02-22 10:07 d——– C:\Program Files\bfgclient
2008-02-22 10:07 . 2008-02-22 10:21 d——– C:\BigFishGamesCache
2008-02-20 22:09 . 2008-02-20 22:09 d——– C:\Users\All Users\BVRP Software
2008-02-20 22:09 . 2008-02-20 22:09 d——– C:\ProgramData\BVRP Software
2008-02-20 22:04 . 2008-02-20 22:04 dr-hs—- C:\_Backup.RC
2008-02-20 22:04 . 2008-02-20 23:43 d–h—– C:\_Backup
2008-02-20 22:00 . 2008-02-24 15:23 d——– C:\Users\mom\AppData\Roaming\Avanquest
2008-02-20 22:00 . 2008-02-20 22:00 d——– C:\Users\All Users\Avanquest
2008-02-20 22:00 . 2008-02-20 22:00 d——– C:\ProgramData\Avanquest
2008-02-20 21:59 . 2008-02-20 21:59 d——– C:\Program Files\Avanquest
2008-02-20 21:55 . 2008-02-26 17:27 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-19 21:18 . 2007-03-06 18:51 543,232 –a—— C:\Windows\System32\FWPUCLNT.DLL
2008-02-19 21:18 . 2007-03-06 18:51 416,768 –a—— C:\Windows\System32\IKEEXT.DLL
2008-02-19 21:18 . 2007-03-06 18:51 317,440 –a—— C:\Windows\System32\BFE.DLL
2008-02-19 21:18 . 2007-03-06 18:08 84,992 –a—— C:\Windows\System32\drivers\FWPKCLNT.SYS
2008-02-19 21:17 . 2008-02-19 21:17 d——– C:\Users\mom\AppData\Roaming\Sammsoft
2008-02-19 21:16 . 2008-02-19 22:25 d——– C:\Program Files\Advanced Registry Optimizer
2008-02-19 21:09 . 2008-02-19 21:09 d——– C:\Users\All Users\Grisoft
2008-02-19 21:09 . 2008-02-19 21:09 d——– C:\ProgramData\Grisoft
2008-02-19 21:06 . 2008-02-19 21:06 1,420 –a—— C:\Windows\wininit.ini
2008-02-19 20:25 . 2008-02-19 22:34 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-02-19 20:25 . 2008-02-19 22:34 d——– C:\ProgramData\Spybot - Search & Destroy
2008-02-19 20:25 . 2008-02-19 21:12 d——– C:\Program Files\Trend Micro
2008-02-19 20:25 . 2008-02-19 22:35 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-19 20:12 . 2008-02-19 20:12 d——– C:\kav
2008-02-19 19:37 . 2008-02-19 19:37 3,764 –a—— C:\Windows\System32\tmp.reg
2008-02-19 19:36 . 2008-02-19 19:41 d——– C:\Windows\System32\SmitfraudFix
2008-02-19 05:33 . 2008-02-19 05:37 d——– C:\Users\mom\.housecall6.6
2008-02-18 23:00 . 2008-02-25 04:53 d——– C:\Program Files\AdwareAlert
2008-02-18 22:51 . 2008-02-18 22:51 d——– C:\Program Files\Enigma Software Group
2008-02-17 11:52 . 2008-02-17 11:52 d——– C:\Users\mom\AppData\Roaming\PCF-VLC
2008-02-16 21:34 . 2008-02-26 17:52 dr——- C:\Windows\System32\config\systemprofile\Documents
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Users\All Users\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\ProgramData\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Program Files\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Program Files\Common Files\Authentium
2008-02-16 21:23 . 2007-04-04 17:15 839,880 –a—— C:\Windows\System32\drivers\css-dvp.sys
2008-02-16 21:23 . 2007-03-06 13:24 55,296 –a—— C:\Windows\System32\drivers\rp_skt32.sys
2008-02-16 21:23 . 2007-04-05 14:52 48,384 –a—— C:\Windows\System32\drivers\rp_pkt32.sys
2008-02-16 21:22 . 2008-02-19 23:02 d——– C:\Program Files\Common Files\Scanner
2008-02-16 21:22 . 2008-02-16 21:22 d——– C:\Program Files\CA
2008-02-16 21:20 . 2008-02-16 21:20 d——– C:\Users\mom\AppData\Roaming\InstallShield
2008-02-15 21:09 . 2008-01-09 21:50 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2008-02-15 18:38 . 2008-02-15 18:38 d——– C:\Users\mom\AppData\Roaming\Template
2008-02-15 18:37 . 2008-02-22 21:53 90 –a—— C:\Users\mom\AppData\Roaming\wklnhst.dat
2008-02-15 17:00 . 2008-02-15 17:00 d——– C:\Users\All Users\Macrovision
2008-02-15 17:00 . 2008-02-15 17:00 d——– C:\ProgramData\Macrovision
2008-02-15 16:58 . 2008-02-15 16:58 d——– C:\Program Files\Common Files\Macromedia Shared
2008-02-15 16:55 . 2008-02-15 16:55 d——– C:\Program Files\Common Files\Macromedia
2008-02-15 16:53 . 2008-02-15 16:53 d——– C:\Program Files\Macromedia
2008-02-14 06:02 . 2008-02-14 06:02 d——– C:\Users\mom\AppData\Roaming\Participatory Culture Foundation
2008-02-14 06:01 . 2008-02-14 06:01 d——– C:\Users\All Users\Participatory Culture Foundation
2008-02-14 06:01 . 2008-02-14 06:01 d——– C:\ProgramData\Participatory Culture Foundation
2008-02-14 06:00 . 2008-02-14 06:00 d——– C:\My Documents
2008-02-13 18:05 . 2008-02-13 18:05 194,560 –a—— C:\Windows\System32\WebClnt.dll
2008-02-13 18:05 . 2008-02-13 18:05 110,080 –a—— C:\Windows\System32\drivers\mrxdav.sys
2008-02-13 18:01 . 2008-02-13 18:01 3,505,720 –a—— C:\Windows\System32\ntkrnlpa.exe
2008-02-13 18:01 . 2008-02-13 18:01 3,471,928 –a—— C:\Windows\System32\ntoskrnl.exe
2008-02-13 18:01 . 2008-02-13 18:01 154,624 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-02-13 18:01 . 2008-02-13 18:01 109,624 –a—— C:\Windows\System32\drivers\ataport.sys
2008-02-13 18:01 . 2008-02-13 18:01 45,112 –a—— C:\Windows\System32\drivers\pciidex.sys
2008-02-13 18:01 . 2008-02-13 18:01 21,560 –a—— C:\Windows\System32\drivers\atapi.sys
2008-02-13 18:01 . 2008-02-13 18:01 15,928 –a—— C:\Windows\System32\drivers\pciide.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 13:05 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-14 02:04 54,784 —-a-w C:\Windows\system32\drivers\i8042prt.sys
2008-02-14 02:04 495,160 —-a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-02-14 02:04 35,384 —-a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-02-14 02:04 35,384 —-a-w C:\Windows\system32\drivers\kbdclass.sys
2008-02-14 02:04 34,360 —-a-w C:\Windows\system32\drivers\mouclass.sys
2008-02-14 02:04 19,968 —-a-w C:\Windows\system32\drivers\sermouse.sys
2008-02-14 02:04 15,872 —-a-w C:\Windows\system32\drivers\mouhid.sys
2008-02-13 20:00 537,600 —-a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 20:00 449,536 —-a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 20:00 2,144,256 —-a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 20:00 173,056 —-a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 19:57 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-02 17:15 ——— d—–w C:\Users\mom\AppData\Roaming\.wyzo
2008-02-02 16:04 ——— d—–w C:\Users\mom\AppData\Roaming\.BitTornado
2008-02-02 15:44 ——— d—–w C:\Program Files\eSobi
2008-02-01 23:04 ——— d—–w C:\Program Files\Microsoft Games
2008-02-01 11:31 174 –sha-w C:\Program Files\desktop.ini
2008-02-01 11:28 ——— d—–w C:\Program Files\Windows Mail
2008-02-01 11:28 ——— d—–w C:\Program Files\Windows Calendar
2008-02-01 11:27 ——— d—–w C:\Program Files\Windows Sidebar
2008-02-01 11:27 ——— d—–w C:\Program Files\Windows Defender
2008-02-01 11:19 70,144 —-a-w C:\Windows\system32\drivers\pacer.sys
2008-02-01 11:19 61,952 —-a-w C:\Windows\system32\drivers\wanarp.sys
2008-02-01 11:19 48,640 —-a-w C:\Windows\system32\drivers\ndproxy.sys
2008-02-01 11:19 20,480 —-a-w C:\Windows\system32\drivers\ndistapi.sys
2008-02-01 11:17 258,232 —-a-w C:\Windows\system32\drivers\acpi.sys
2008-02-01 11:17 2,923,520 —-a-w C:\Windows\explorer.exe
2008-02-01 11:12 63,488 —-a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-02-01 11:12 23,040 —-a-w C:\Windows\system32\drivers\tunnel.sys
2008-02-01 11:12 15,360 —-a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-02-01 08:25 ——— d—–w C:\ProgramData\eSobi
2008-02-01 07:40 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-01 07:39 ——— d—–w C:\ProgramData\Symantec
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-01 03:04 1232896]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16 454784]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-31 23:32 68856]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 04:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 04:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 03:04 4423680 C:\Windows\RtHDVCpl.exe]
"Acer Empowering Technology Monitor"="C:\Acer\Empowering Technology\SysMonitor.exe" [2007-01-24 09:27 319488]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 23:04 464168]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-02-02 00:37 630784]
"Acer Product Registration"="C:\Program Files\Acer Registration\ACE1.exe" [2007-02-02 11:24 3383296]
"Acer Assist Launcher"="C:\Program Files\Acer Assist\launcher.exe" [2007-02-02 10:05 1261568]
"Setresolution"="C:\ACERSW\config\1440x900.cmd" [2007-10-11 11:15 198]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ISW.exe"="C:\Program Files\AT&T;\Internet Security Wizard\ISW.exe" [2007-05-03 13:12 2061816]
"AT&T; Internet Security Suite"="C:\Program Files\AT&T;\AT&T; Internet Security Suite\Rps.exe" [2007-06-28 16:09 310000]
"-FreedomNeedsReboot"="C:\Program Files\AT&T;\AT&T; Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 16:09 13552]
"VirusScannerPro"="C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe" [2007-09-11 02:32 173312]
"hpqSRMon"="C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 16:31 80896]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25 6731312]
"lxbkbmgr.exe"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2007-04-26 12:02 74672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-04-16 17:09:28 528384]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PCM Media Sharing.lnk]
backup=C:\Windows\pss\PCM Media Sharing.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2007-10-02 14:45 67488 C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blubster]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LimeShop]
javaw -cp C:\Program Files\LimeShop\System\Code Main lp: C:\Program Files\LimeShop
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2008-01-31 23:32 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{ED1E9675-5C5C-4552-8979-8FFBD704C996}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C5A6A6A0-D297-4AA6-9383-21A16C3F9929}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C0B04953-9D63-4886-9FEE-B20972592777}"= C:\Program Files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live|Desc=Acer Arcade Live
"{64C52DD3-2977-4C34-BDA1-8FD96179DF00}"= C:\Program Files\Acer Arcade Live\SlideShow DVD\Component\CLSLDVD.exe:SlideShow DVD workprocess|Desc=SlideShow DVD workprocess
"{F42A10AE-D383-4A78-9E05-64BBC84376C5}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\ARAWP.exe:DV Magician ARA workprocess|Desc=DV Magician ARA workprocess
"{A0E22BD1-9D17-41A4-BF50-419B503C50D0}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\DVAX2Process.exe:DV Magician AVAX workprocess|Desc=DV Magician AVAX workprocess
"{E59634F8-1C07-40AC-84E1-E301FBC238EE}"= C:\Program Files\Acer Arcade Live\Acer DVDivine\DVDivine.exe:DVDivine|Desc=DVDivine
"{DFFF3429-DA90-43DB-898C-FAEEFE3F39E2}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia\HomeMedia.exe:HomeMedia|Desc=HomeMedia
"{5F06C73B-3B46-4ED5-983C-2880071833B2}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\HomeMedia Connect.exe:HomeMedia Connect|Desc=HomeMedia Connect
"{1955E669-BE1F-4C13-B854-FB32F2900974}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:HomeMedia Connect Service|Desc=HomeMedia Connect Service
"{A8757501-B402-4C19-AD10-EA4697A9512B}"= C:\Program Files\Acer Arcade Live\Acer VideoMagician\VideoMagician.exe:VideoMagician|Desc=VideoMagician
"{9234C2B8-F04E-4204-A09F-3FCCBFA126AE}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B2B007CA-B0EE-4273-9F70-DC3EA7ABA9ED}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B456AA34-D9D2-4AA1-B344-8B09EAECC6B8}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{0C714E48-AC34-4FD8-9B2A-59D42C53B5D7}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{46815E3A-9CC6-45F8-A148-A9473F8E7769}C:\program files\windows sidebar\sidebar.exe"= UDP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar|Desc=Windows Sidebar
"UDP Query User{0866C7EE-A71E-4654-8CA1-0E1F5CE3E61B}C:\program files\windows sidebar\sidebar.exe"= TCP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar|Desc=Windows Sidebar
"TCP Query User{5465F7B4-AB26-4F4D-933A-FF89AF66E9CB}C:\program files\ares destiny powered by advantage\ares.exe"= UDP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"UDP Query User{977F1337-B2E4-45C8-BD56-64A89A48894E}C:\program files\ares destiny powered by advantage\ares.exe"= TCP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"{94AA03C4-97DD-4A17-AC0E-944B0071DAD9}"= UDP:C:\Program Files\Blubster\Blubster.exe:Blubster
"{B1C11E30-1213-4486-BBA4-EC18397A5EC4}"= TCP:C:\Program Files\Blubster\Blubster.exe:Blubster
"{FFCAA06D-B93F-4761-95C2-ED89CD2E1795}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires III
"{F44736BC-EC14-4700-B298-7914E0856207}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires III
"{D7709ABE-C477-4DC0-B614-9683BC741823}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:Age of Empires III - The WarChiefs
"{1E358188-B5AE-4DC6-8C6E-319E3BB034B0}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:Age of Empires III - The WarChiefs
"TCP Query User{B2D87FF7-832C-49FE-BD9E-89ACD040F655}C:\program files\streamcast\morpheus\morpheus.exe"= UDP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"UDP Query User{F6A71D3E-5BA8-4449-8DDB-23D0DF2A9708}C:\program files\streamcast\morpheus\morpheus.exe"= TCP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"TCP Query User{EC8CE942-D080-4BA8-AE3B-0F834E4969CC}C:\windows\system32\javaw.exe"= UDP:C:\windows\system32\javaw.exe:Java™ Platform SE binary|Desc=Java™ Platform SE binary
"UDP Query User{F3285B82-9AA8-438E-8AD8-14ECE6877D4D}C:\windows\system32\javaw.exe"= TCP:C:\windows\system32\javaw.exe:Java™ Platform SE binary|Desc=Java™ Platform SE binary
"{5780BA34-CFE2-423E-B53C-D00E62E549CF}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{0A80E1F4-015B-4A63-BDCA-AA0349472A0F}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{53213690-2F90-48B7-88C0-0EC426C28D83}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{26BDE5B8-667C-4659-BD7E-1B40D4A2FC4B}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{FA80AA46-E4BC-4AF2-AE1F-48DE47BA08DF}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{8CA99614-5EA4-4858-A86D-078ED9E34859}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{8CDEA102-A4A2-46C9-9926-BB6C7A327CF1}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{A51AE3A2-2ED8-40AB-90EE-17AF90D79C16}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"TCP Query User{2A015A47-5926-4EC6-B4F2-7A271F2EB118}C:\program files\ares ultra\ares ultra.exe"= Disabled:UDP:C:\program files\ares ultra\ares ultra.exe:Ares Ultra p2p for windows|Desc=Ares Ultra p2p for windows
"UDP Query User{2ADF9AAE-7C9D-4D54-8F66-BFDD44542910}C:\program files\ares ultra\ares ultra.exe"= Disabled:TCP:C:\program files\ares ultra\ares ultra.exe:Ares Ultra p2p for windows|Desc=Ares Ultra p2p for windows
"TCP Query User{D51C1380-4F13-455B-BAEC-A8957567347F}C:\program files\bittornado\btdownloadgui.exe"= UDP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"UDP Query User{915AC283-DB84-4A06-AACC-531197D15028}C:\program files\bittornado\btdownloadgui.exe"= TCP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"TCP Query User{05AF3670-5012-41C7-BE3B-90E8B91D6618}C:\program files\utorrent\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"UDP Query User{519F3CCD-78C9-4D71-8241-8545D5E28844}C:\program files\utorrent\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"TCP Query User{06B02AE2-9D81-4A20-9FB9-E497EA8FD740}C:\program files\wyzo\wyzo.exe"= UDP:C:\program files\wyzo\wyzo.exe:Wyzo|Desc=Wyzo
"UDP Query User{1B57D6E7-155E-4450-8365-27D8D5548C34}C:\program files\wyzo\wyzo.exe"= TCP:C:\program files\wyzo\wyzo.exe:Wyzo|Desc=Wyzo
"TCP Query User{4C971860-1839-4552-B334-9CC70301ABCB}C:\program files\bittornado\btdownloadgui.exe"= UDP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"UDP Query User{6C063307-082D-4B83-B397-D4950890871E}C:\program files\bittornado\btdownloadgui.exe"= TCP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"TCP Query User{B733EB0A-5624-4DA0-94FE-BE4CBEDA5950}C:\program files\azureus\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"UDP Query User{63641DF6-E896-4EB4-BD1B-5693B1BBB4AC}C:\program files\azureus\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"TCP Query User{979A8622-97BB-4327-893C-1E933B2DD82F}C:\program files\ares destiny powered by advantage\ares.exe"= UDP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"UDP Query User{9984BA5E-7108-492F-A1CE-E82DEA8DA5BD}C:\program files\ares destiny powered by advantage\ares.exe"= TCP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"TCP Query User{3CCD6E95-EB20-413A-A1D8-4B11C7DE15CC}C:\program files\streamcast\morpheus\morpheus.exe"= UDP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"UDP Query User{FDC9E13B-2EDC-4F19-9A6C-F7019E1EE034}C:\program files\streamcast\morpheus\morpheus.exe"= TCP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"{1EA8CC77-0C78-4A5F-9358-00995778259E}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{0515436C-451C-4970-B3FA-617E20EE7E95}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"TCP Query User{47A29E79-4ED1-48A0-941D-F8C203508FE4}C:\program files\utorrent\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"UDP Query User{05A0B5DF-7D19-41C8-A704-EDB7FF9561E3}C:\program files\utorrent\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"{35656831-0F96-4AE7-84B7-80ABD02C2A59}"= UDP:52555:utor1
"{E7FC6750-7D3B-4B3A-900B-E7EBE5BD0494}"= UDP:C:\Windows\System32\lxbkcoms.exe:Lexmark Communications System
"{B11A941D-BACA-4B0E-AEF7-8CAB19B0B5F7}"= TCP:C:\Windows\System32\lxbkcoms.exe:Lexmark Communications System
"{0E690F73-7BE2-42B3-8E93-9149D1DA9C14}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window
"{0F122DF0-5137-4336-9DD4-FC51C50AC9A0}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-29 19:22]
R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-02-06 23:04]
R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-02-06 23:04]
R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-02-06 23:04]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;"C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe" [2007-04-04 17:54]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 14:46]
R2 AdwareAlertSrv;AdwareAlert Scanning Engine;"C:\Program Files\AdwareAlert\AdwareAlert.srv.exe" [2008-02-14 13:27]
R2 eDataSecurity Service;eDataSecurity Service;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-02-06 23:04]
R2 lxbk_device;lxbk_device;C:\Windows\system32\lxbkcoms.exe [2007-04-26 12:01]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-03-14 06:04]
R3 KFilter;KFilter;C:\PROGRA~1\AVANQU~1\SYSTEM~1\KFilter.sys [2007-09-11 02:32]
R3 MailScan;MailScan;C:\PROGRA~1\AVANQU~1\SYSTEM~1\MailScan.sys [2007-09-11 02:32]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-03-22 18:12]
S3 Radialpoint Security Services;AT&T; Internet Security Suite;C:\Windows\system32\dllhost.exe [2006-11-02 01:45]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6818ae31-d20c-11dc-8e7b-001c2552ea58}]
\shell\AutoRun\command - LinksysConnectPC.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5783dde-d202-11dc-8197-001c2552ea58}]
\shell\AutoRun\command - K:\RCAMemoryMgr.exe
\shell\Manage your videos\command - K:\RCAMemoryMgr.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-26 18:19:27
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\AT&T;\AT&T; Internet Security Suite\Fws.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Windows\system32\WUDFHost.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\mxtask.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\Program Files\Avanquest\SystemSuite\MemCheck.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2008-02-26 18:22:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-27 02:22:38
ComboFix2.txt 2008-02-27 01:45:22
.
2008-02-17 01:05:47 — E O F —