Done with everything. I think it's my fault downloading from torrent while fixing this machine. I just wanted to have ad-aware for protection. Sorry for that. Anyway, here are the new logs.
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
ComboFix 08-04-22.5 - Bondoc 2008-04-27 14:09:03.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.550 [GMT 8:00]
Running from: D:\Installers\Malware Utils\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\upkithuj.ini
.
((((((((((((((((((((((((( Files Created from 2008-03-27 to 2008-04-27 )))))))))))))))))))))))))))))))
.
2008-04-26 22:15 . 2008-04-26 22:15 <DIR> d-------- C:\_OTMoveIt
2008-04-26 16:33 . 2008-04-26 19:22 109,776 --a------ C:\WINDOWS\BMd3fd8e8f.xml
2008-04-26 15:54 . 2008-04-26 16:51 <DIR> d-------- C:\Program Files\Ad-Aware 2007
2008-04-26 15:54 . 2008-04-26 16:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-26 11:23 . 2008-04-26 11:23 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-26 11:23 . 2008-04-26 11:23 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-25 22:55 . 2008-04-25 22:55 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-25 22:55 . 2008-04-25 22:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-25 17:48 . 2008-04-25 17:48 <DIR> d-------- C:\Program Files\Malwarebytes
2008-04-25 17:48 . 2008-04-25 17:48 <DIR> d-------- C:\Documents and Settings\Bondoc\Application Data\Malwarebytes
2008-04-25 17:48 . 2008-04-25 17:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-25 14:10 . 2008-04-25 14:16 <DIR> d-------- C:\Program Files\SimCity 4 Deluxe
2008-04-25 14:10 . 2008-04-25 14:10 530 --a------ C:\WINDOWS\eReg.dat
2008-04-23 18:58 . 2008-04-26 22:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-04-22 20:25 . 2008-04-22 20:25 <DIR> d-------- C:\Program Files\FileZilla FTP
2008-04-22 20:25 . 2008-04-23 14:17 <DIR> d-------- C:\Documents and Settings\Bondoc\Application Data\FileZilla
2008-04-22 20:22 . 2008-04-22 20:22 <DIR> d-------- C:\Program Files\WinSCP
2008-04-22 20:00 . 2008-04-22 20:00 138 -r-hs---- C:\WINDOWS\mainms.vpi
2008-04-15 07:08 . 2007-12-18 01:16 65,536 --a------ C:\npkimi.dll
2008-04-15 02:07 . 2008-04-17 23:25 <DIR> d-------- C:\Program Files\Veoh
2008-04-14 23:17 . 2008-04-14 23:17 <DIR> d-------- C:\Program Files\Uniblue
2008-04-14 23:17 . 2008-04-14 23:17 <DIR> d-------- C:\Documents and Settings\Bondoc\Application Data\Uniblue
2008-04-14 18:10 . 2008-04-14 18:10 <DIR> d-------- C:\Program Files\SmartFTP
2008-04-14 16:33 . 2008-04-15 02:11 <DIR> d-------- C:\Documents and Settings\Bondoc\Application Data\MegauploadToolbar
2008-04-13 23:55 . 2008-04-13 23:55 <DIR> d-------- C:\Documents and Settings\Bondoc\Application Data\Meridian93
2008-04-13 23:03 . 2008-04-14 23:48 <DIR> d-------- C:\Program Files\Garena
2008-04-13 23:03 . 2008-04-13 23:03 <DIR> d-------- C:\Documents and Settings\Bondoc\Application Data\InstallShield
2008-04-13 23:03 . 2006-03-14 02:26 53,248 --a------ C:\WINDOWS\system32\ImageOle.dll
2008-04-13 22:37 . 2008-04-16 03:56 <DIR> d-------- C:\Program Files\Magic Farm
2008-04-13 18:24 . 2008-04-13 18:25 <DIR> d-------- C:\Program Files\Safari
2008-04-13 16:51 . 2008-04-13 16:51 <DIR> d-------- C:\Documents and Settings\Bondoc\Application Data\Jane s Hotel Family Hero
2008-04-07 13:26 . 2008-04-07 13:29 <DIR> d-------- C:\Program Files\J2ME-Polish
2008-04-07 01:33 . 2008-04-07 01:33 <DIR> d-------- C:\Documents and Settings\Bondoc\workspace
2008-04-05 21:43 . 2008-04-05 21:43 72 --a------ C:\WINDOWS\MediaManager.INI
2008-04-03 20:48 . 2008-04-03 20:49 11,024 --a------ C:\WINDOWS\system32\productregistry
2008-04-03 20:47 . 2008-04-03 20:47 <DIR> d-------- C:\Sun
2008-03-29 21:39 . 2008-03-29 21:47 <DIR> d-------- C:\Program Files\QuickTime
2008-03-29 21:39 . 2008-03-29 21:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 06:13 --------- d-----w C:\Program Files\cFosSpeed
2008-04-26 14:41 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-26 14:01 --------- d-----w C:\Program Files\Warcraft III
2008-04-26 10:00 --------- d-----w C:\Program Files\Navigator 9
2008-04-26 07:58 --------- d-----w C:\Documents and Settings\Bondoc\Application Data\uTorrent
2008-04-25 14:58 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-23 15:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-04-23 13:08 --------- d-----w C:\Documents and Settings\Bondoc\Application Data\LimeWire
2008-04-23 11:05 --------- d-----w C:\Program Files\Google
2008-04-21 11:39 --------- d-----w C:\Program Files\Norton SystemWorks
2008-04-14 23:08 --------- d-----w C:\Program Files\Imikimi
2008-04-14 18:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-14 13:48 --------- d-----w C:\Program Files\PPLive
2008-04-14 10:08 --------- d-----w C:\Program Files\SmartFTP Client 2.0
2008-04-13 19:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-13 15:03 --------- d-----w C:\Program Files\GG E-Sports Platform
2008-04-13 05:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-03 06:23 --------- d-----w C:\Program Files\Counter Strike
2008-03-31 05:37 --------- d-----w C:\Documents and Settings\Bondoc\Application Data\Wildfire
2008-03-29 13:43 --------- d-----w C:\Documents and Settings\Bondoc\Application Data\Apple Computer
2008-03-29 07:50 --------- d-----r C:\Program Files\TypingMaster
2008-03-29 04:48 --------- d-----w C:\Program Files\Bonjour
2008-03-28 13:09 --------- d-----w C:\Program Files\Neuber TaskMngr
2008-03-21 08:56 --------- d-----w C:\Documents and Settings\Bondoc\Application Data\Netscape
2008-03-20 10:14 --------- d-----w C:\Program Files\Opera
2008-03-20 09:58 --------- d-----w C:\Program Files\Apple Software Update
2008-03-20 09:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-03-20 09:43 --------- d-----w C:\Program Files\PremiumSoft
2008-03-06 13:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-06 13:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-06 13:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2007-12-22 19:23 3,928,264 ----a-w C:\Program Files\FLV PlayerRCATSetup.exe
2007-12-22 19:05 411,248 ----a-w C:\Program Files\FLV PlayerRCSetup.exe
2007-09-12 02:19 8,784 ----a-w C:\Program Files\mozilla firefox\plugins\ractrlkeyhook.dll
2007-09-12 02:22 245,408 ----a-w C:\Program Files\mozilla firefox\plugins\unicows.dll
.
((((((((((((((((((((((((((((( snapshot@2008-04-25_ 5.44.47.65 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-24 21:38:51 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-27 06:13:17 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-26 07:55:15 1,038,336 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe
+ 2008-04-26 07:55:15 178,688 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe
+ 2008-04-26 07:55:15 171,008 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe
+ 2008-04-26 07:55:15 8,704 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe
+ 2007-07-11 09:37:26 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
+ 2007-08-07 08:58:08 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
+ 2007-08-07 08:56:58 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
+ 2005-05-24 04:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 07:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 07:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2007-12-14 07:32:52 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
+ 2008-04-27 06:13:31 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_1d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2007-11-24 20:24 267592 --a------ C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL" [2007-11-24 20:24 267592]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2007-11-24 20:24 267592]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30 517768]
"cFosSpeed"="C:\Program Files\cFosSpeed\cFosSpeed.exe" [2007-07-09 17:10 838608]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59 115816]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 11 (0xb)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoRun"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=
backup=C:\WINDOWS\pss\Adobe Acrobat Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Bondoc^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Bondoc^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
--a------ 2008-01-11 19:54 623992 C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-05-16 09:27 153136 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 2004-08-04 00:56 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMd3fd8e8f]
C:\WINDOWS\system32\rskmtbth.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2007-01-09 22:59 115816 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\d0cebd13]
C:\WINDOWS\system32\juhtikpu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 00:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2006-02-19 02:41 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2007-05-15 15:55 1057328 C:\Program Files\Nero\Nero 7\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-14 00:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Save and Restore]
--a------ 2007-03-26 15:45 1582696 C:\PROGRA~1\NORTON~1\NSR\Agent\NSRTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSRKey]
--a------ 2007-03-26 15:45 1582696 C:\PROGRA~1\NORTON~1\NSR\Agent\NSRTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSWosCheck]
--a------ 2007-12-03 01:41 25472 C:\Program Files\Norton SystemWorks\osCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
--a------ 2006-09-06 10:22 26248 C:\Program Files\Norton AntiVirus\osCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2007-01-20 15:09 200704 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-02-16 10:54 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecurDisc]
--a------ 2007-05-15 15:55 1628208 C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-r------- 2006-11-17 05:42 577536 C:\WINDOWS\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]
--a------ 2007-05-16 10:45 8975904 C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
--a------ 2005-03-08 03:33 53248 C:\WINDOWS\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XDc]
--a------ 2006-10-03 12:09 1383478 C:\Program Files\Xtreme Desktop\xdc\startxdc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo Messenger]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-07-16 15:17 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Warcraft III\\war3.exe"=
"C:\\Program Files\\Python\\pythonw.exe"=
"C:\\Program Files\\DAP\\DAP.exe"=
"\\\\ZEIT\\DATA (D)\\Programs\\PerfectWorld\\launcher\\Launcher.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Programs\\Xampp\\mysql\\bin\\mysqld.exe"=
"D:\\Programs\\Xampp\\apache\\bin\\apache.exe"=
"C:\\Documents and Settings\\Bondoc\\.netbeans\\5.5\\emulators\\wtk22_win\\emulator\\wtk22\\bin\\emulator.exe"=
"C:\\Program Files\\Java\\jdk1.6.0\\jre\\bin\\java.exe"=
"C:\\Documents and Settings\\Bondoc\\.netbeans\\5.5\\emulators\\wtk22_win\\emulator\\wtk22\\bin\\zayit.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\PPLive\\PPLive.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\Counter Strike\\hl.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Java\\jdk1.6.0\\jre\\bin\\javaw.exe"=
"C:\\Program Files\\Java\\jdk1.6.0\\bin\\java.exe"=
"C:\\WINDOWS\\system32\\javaw.exe"=
"D:\\SunWTK\\bin\\emulator.exe"=
"D:\\SunWTK\\bin\\zayit.exe"=
"C:\\Program Files\\Garena\\Garena.exe"=
"C:\\Program Files\\SmartFTP\\SmartFTP.exe"=
"C:\\Program Files\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\WinSCP\\WinSCP.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6119:TCP"= 6119:TCP:war3port
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 20:22]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-10-18 17:39]
R2 Norton Save and Restore;Norton Save and Restore;C:\PROGRA~1\NORTON~1\NSR\Agent\VProSvc.exe [2007-03-26 15:45]
R2 NvNdis;NVIDIA NDIS IO Control Driver;C:\WINDOWS\system32\Drivers\NvNdis.sys [2004-12-13 09:44]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2005-08-03 05:10]
S3 SetupNTGLM7X;SetupNTGLM7X;E:\NTGLM7X.sys []
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 07:01]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command -
\Shell\explore\Command -
\Shell\open\Command -
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command -
\Shell\explore\Command -
\Shell\open\Command -
.
Contents of the 'Scheduled Tasks' folder
"2008-04-24 09:39:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-25 13:16:21 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Bondoc.job"
- C:\PROGRA~1\NORTON~2\Navw32.exeh/TASK:
"2008-04-21 11:39:29 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Norton SystemWorks\OBC.exe
"2008-04-24 15:17:02 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-04-14 15:17:44 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-27 14:14:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\cFosSpeed\spd.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
.
**************************************************************************
.
Completion time: 2008-04-27 14:19:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-27 06:19:53
ComboFix2.txt 2008-04-25 18:27:12
ComboFix3.txt 2008-04-25 18:18:28
ComboFix4.txt 2008-04-25 09:31:45
ComboFix5.txt 2008-04-24 21:45:11
Pre-Run: 9,095,933,952 bytes free
Post-Run: 9,044,525,056 bytes free
315 --- E O F --- 2008-04-13 19:12:21