The Computer is running great in terms of speed. Discover Games has all of a sudden popped up with start-up, its cool to delete that right? I would also like to get rid of a lot of the programs that start with windows that I dont need.
ComboFix 08-04-29.5 - HP_Administrator 2008-05-04 19:54:21.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.572 [GMT -4:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt
* Created a new restore point
FILE ::
H:\I386\APPS\APP16614\src\CompaqPresario_Spring06.exe
H:\I386\APPS\APP16614\src\HPPavillion_Spring06.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
H:\I386\APPS\APP16614\src\CompaqPresario_Spring06.exe
H:\I386\APPS\APP16614\src\HPPavillion_Spring06.exe
.
((((((((((((((((((((((((( Files Created from 2008-04-04 to 2008-05-04 )))))))))))))))))))))))))))))))
.
2008-05-03 11:16 . 2008-05-03 11:16 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-03 11:16 . 2008-05-03 11:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-29 21:57 . 2008-04-29 21:57 13,942 --a------ C:\WINDOWS\system32\iphone-011.ico
2008-04-29 13:57 . 2008-04-29 13:57 9,662 --a------ C:\WINDOWS\system32\iphone-6y.ico
2008-04-29 01:13 . 2008-04-29 01:13 9,662 --a------ C:\WINDOWS\system32\vaio3-011.ico
2008-04-28 22:09 . 2008-04-28 22:09 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-28 20:37 . 2008-04-28 20:38 <DIR> d-------- C:\Program Files\Panda Security
2008-04-28 18:21 . 2008-04-28 18:29 <DIR> d--hs---- C:\Documents and Settings\HP_Administrator\!
2008-04-27 18:52 . 2008-04-27 18:53 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2008-04-25 14:55 . 2008-04-25 14:55 664 --a------ C:\WINDOWS\system32\d3d9caps.tmp
2008-04-24 13:07 . 2008-04-24 13:07 <DIR> d-------- C:\Documents and Settings\Smilez\Application Data\ATI
2008-04-23 16:30 . 2008-04-23 16:30 <DIR> d-------- C:\Documents and Settings\Erin\Application Data\ATI
2008-04-23 10:21 . 2008-04-23 10:21 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\ATI
2008-04-23 10:21 . 2008-04-23 10:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-04-23 10:16 . 2008-04-23 10:17 <DIR> d-------- C:\Program Files\ATI Technologies
2008-04-22 21:53 . 2008-04-22 21:53 <DIR> d-------- C:\Documents and Settings\Smilez\music
2008-04-21 19:19 . 2008-04-27 12:43 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-21 19:19 . 2008-04-21 19:19 22,328 --a------ C:\Documents and Settings\HP_Administrator\Application Data\PnkBstrK.sys
2008-04-21 19:18 . 2008-04-27 12:43 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-04-21 19:18 . 2008-04-22 09:35 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-04-21 14:33 . 2008-04-21 14:33 <DIR> d-------- C:\Program Files\Download Manager
2008-04-21 14:33 . 2008-04-21 19:25 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\IGN_DLM
2008-04-20 23:58 . 2008-04-20 23:58 <DIR> dr-h----- C:\Documents and Settings\Smilez\Application Data\SecuROM
2008-04-20 20:15 . 2008-03-28 21:05 593,920 --a------ C:\WINDOWS\system32\ati2sgag.exe
2008-04-20 18:09 . 2008-04-20 18:09 <DIR> d-------- C:\ProgramData
2008-04-20 15:09 . 2008-04-20 15:09 7,252 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-18 11:20 . 2008-04-18 11:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SimCity Societies
2008-04-18 10:50 . 2008-04-20 22:04 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-04-18 10:38 . 2008-04-23 10:41 <DIR> d-------- C:\Program Files\Electronic Arts
2008-04-16 12:10 . 2007-05-31 19:30 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2008-04-16 12:10 . 2007-10-22 03:37 17,928 --a------ C:\WINDOWS\system32\X3DAudio1_2.dll
2008-04-16 12:09 . 2008-04-21 19:18 321 --a------ C:\WINDOWS\game.ini
2008-04-16 12:05 . 2008-04-21 19:04 <DIR> d-------- C:\Program Files\Activision
2008-04-16 11:16 . 2008-04-16 11:16 <DIR> d-------- C:\Documents and Settings\All Users\temp
2008-04-16 11:16 . 2008-04-16 11:16 <DIR> d-------- C:\Documents and Settings\All Users\Gamespot
2008-04-16 10:21 . 2008-04-16 10:21 <DIR> d-------- C:\Program Files\Brad Smith
2008-04-16 10:21 . 2008-04-16 10:21 286,720 --------- C:\WINDOWS\SETUP1.EXE
2008-04-16 10:21 . 2008-04-16 10:21 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2008-04-15 15:08 . 2008-04-15 15:08 <DIR> d-------- C:\Documents and Settings\Smilez\Application Data\HPQ
2008-04-15 15:04 . 2008-04-15 15:04 <DIR> d-------- C:\Documents and Settings\Smilez\Application Data\Grisoft
2008-04-15 15:04 . 2008-04-15 15:04 <DIR> d-------- C:\Documents and Settings\Smilez\Application Data\AVG7
2008-04-15 15:03 . 2007-02-20 00:42 <DIR> d-------- C:\Documents and Settings\Smilez\WINDOWS
2008-04-15 15:03 . 2007-02-20 00:45 <DIR> d-------- C:\Documents and Settings\Smilez\Application Data\Intuit
2008-04-15 15:03 . 2008-04-23 01:09 <DIR> d-------- C:\Documents and Settings\Smilez
2008-04-15 15:03 . 2008-05-04 19:47 1,024 --ah----- C:\Documents and Settings\Smilez\ntuser.dat.LOG
2008-04-14 17:04 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-04-14 17:04 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2008-04-14 17:04 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2008-04-14 17:04 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2008-04-14 17:04 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2008-04-14 17:04 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2008-04-14 14:21 . 2008-04-16 11:16 <DIR> d-------- C:\Program Files\GameSpot
2008-04-07 19:44 . 2008-04-07 19:44 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\acccore
2008-04-07 19:43 . 2008-04-07 19:43 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-04-07 19:43 . 2008-04-07 19:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-04-07 19:43 . 2008-04-07 19:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-04-07 19:42 . 2008-04-07 19:43 <DIR> d-------- C:\Program Files\AIM6
2008-04-07 19:42 . 2008-04-07 20:21 365 --ah----- C:\IPH.PH
2008-04-05 13:26 . 2008-04-29 09:59 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\LimeWire
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-04 23:51 --------- d-----w C:\Program Files\DISC
2008-05-04 15:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2008-05-03 03:12 --------- d-----w C:\Program Files\MINITAB 14 Student
2008-05-02 16:09 --------- d-----w C:\Program Files\QuickTime
2008-05-02 16:09 --------- d-----w C:\Program Files\iTunes
2008-05-02 16:09 --------- d-----w C:\Program Files\HP DigitalMedia Archive
2008-04-29 02:22 --------- d-----w C:\Program Files\WildTangent
2008-04-29 02:22 --------- d-----w C:\Program Files\HP Games
2008-04-29 02:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\WildTangent
2008-04-28 23:35 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\AVG7
2008-04-21 23:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-20 22:43 --------- d-----w C:\Program Files\PeerGuardian2
2008-04-18 04:13 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Azureus
2008-04-14 18:21 6,078 ----a-w C:\Program Files\install.log
2008-04-07 23:43 --------- d-----w C:\Program Files\Viewpoint
2008-04-07 23:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-04-01 17:36 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\gtk-2.0
2008-04-01 17:34 --------- d-----w C:\Program Files\GIMP-2.0
2008-03-29 10:21 2,873,856 ----a-w C:\WINDOWS\system32\dllcache\ati2mtag.sys
2008-03-29 08:40 167,936 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-03-29 08:05 372,736 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-03-29 08:04 299,008 ----a-w C:\WINDOWS\system32\dllcache\ati2dvag.dll
2008-03-29 08:04 299,008 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-03-29 07:56 172,032 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-03-29 07:55 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-03-29 07:55 126,976 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-03-29 07:54 536,576 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-03-29 07:44 3,176,480 ----a-w C:\WINDOWS\system32\dllcache\ati3duag.dll
2008-03-29 07:44 3,176,480 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-03-29 07:36 1,765,120 ----a-w C:\WINDOWS\system32\dllcache\ativvaxx.dll
2008-03-29 07:36 1,765,120 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-03-29 07:21 393,216 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-03-29 07:13 520,192 ----a-w C:\WINDOWS\system32\dllcache\ati2cqag.dll
2008-03-29 07:13 520,192 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-03-29 06:21 2,873,856 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-03-29 05:19 9,801,728 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-03-29 03:56 126,976 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-03-29 03:55 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-03-29 03:52 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-03-29 03:39 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-03-29 03:24 46,080 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-03-29 03:23 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-03-29 03:19 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-03-29 03:18 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-03-28 15:47 --------- d-----w C:\Program Files\Netflix
2008-03-26 17:32 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Vso
2008-03-26 14:57 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-03-26 14:57 47,360 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\pcouffin.sys
2008-03-24 00:24 --------- d-----w C:\Program Files\World of Warcraft
2008-03-19 20:03 --------- d-----w C:\Documents and Settings\Guest\Application Data\Cakewalk
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-18 17:07 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Cakewalk
2008-03-18 17:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Cakewalk
2008-03-18 17:03 --------- d-----w C:\Program Files\Cakewalk
2008-03-18 16:11 --------- d-----w C:\Program Files\PowerISO
2008-03-18 03:43 --------- d-----w C:\Program Files\Azureus
2008-03-14 06:04 46,652 ----a-w C:\WINDOWS\system32\drivers\scdemu.sys
2008-03-05 20:03 479,752 ----a-w C:\WINDOWS\system32\XAudio2_0.dll
2008-03-05 20:03 238,088 ----a-w C:\WINDOWS\system32\xactengine3_0.dll
2008-03-05 20:00 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_3.dll
2008-03-05 19:56 3,786,760 ----a-w C:\WINDOWS\system32\D3DX9_37.dll
2008-03-05 19:56 1,420,824 ----a-w C:\WINDOWS\system32\D3DCompiler_37.dll
2008-03-01 22:36 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ----a-w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 05:44 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-02-06 03:07 462,864 ----a-w C:\WINDOWS\system32\d3dx10_37.dll
2007-07-10 03:07 81,920 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\ezpinst.exe
2007-05-07 22:29 0 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2006-10-03 07:43 2,402,550 ----a-w C:\WINDOWS\inf\SET11C9.tmp
2004-08-09 21:00 1,431,144 ----a-w C:\WINDOWS\inf\SET122F.tmp
.
((((((((((((((((((((((((((((( snapshot@2008-05-01_12.59.30.56 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-01 16:42:23 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-04 15:05:07 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2004-12-14 10:23:44 663,552 ----a-w C:\WINDOWS\CREATOR\Remind_XP.exe
+ 2004-12-14 03:23:44 663,552 ----a-w C:\WINDOWS\CREATOR\Remind_XP.exe
- 2005-09-30 05:01:14 67,584 ----a-w C:\WINDOWS\ehome\ehtray.exe
+ 2005-08-06 04:56:34 64,512 ----a-w C:\WINDOWS\ehome\ehtray.exe
- 2005-07-23 06:14:00 237,568 ----a-w C:\WINDOWS\SMINST\Recguard.exe
+ 2005-07-22 23:14:00 237,568 ----a-w C:\WINDOWS\SMINST\RECGUARD.EXE
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"EA Core"="C:\Program Files\Electronic Arts\EADM\Core.exe" [2007-12-04 05:57 2494464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-06 00:56 64512]
"ftutil2"="ftutil2.dll" [2004-06-08 00:05 106496 C:\WINDOWS\system32\ftutil2.dll]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-14 06:05 16239616 C:\WINDOWS\RTHDCPL.EXE]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 23:13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 23:17 118784]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-21 19:59 143360]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 03:19 77312 C:\WINDOWS\arpwrmsg.exe]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 06:05 90112]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 19:14 237568]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 19:34 249856]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 03:11 49152]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-19 03:07 579584]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-03-12 23:43 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-02-19 17:29 180269]
"DigidesignMMERefresh"="C:\Program Files\Digidesign\Drivers\MMERefresh.exe" [2006-11-14 01:05 61440]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-03-14 19:50 233472]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-04 23:13 219136]
C:\Documents and Settings\Erin\Start Menu\Programs\Startup\
PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-08-01 00:58:52 27136]
C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-08-01 00:58:52 27136]
C:\Documents and Settings\Smilez\Start Menu\Programs\Startup\
PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-08-01 00:58:52 27136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 04:15:54 65588]
Updates From HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2007-02-20 00:49:58 36903]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\DISC\\DISCover.exe"=
"C:\\Program Files\\DISC\\DiscStreamHub.exe"=
"C:\\Program Files\\DISC\\myFTP.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 23:41]
R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys [2004-03-12 23:41]
R0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys [2006-11-13 22:38]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
S3 MAFW;MAFW;C:\WINDOWS\system32\DRIVERS\mafw.sys []
S3 PL-40R;CASIO USB MIDI;C:\WINDOWS\system32\Drivers\pl40rwdm.sys [2004-10-01 03:08]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-04 20:01:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-04 20:18:14
ComboFix-quarantined-files.txt 2008-05-05 00:18:10
ComboFix2.txt 2008-05-03 15:11:40
ComboFix3.txt 2008-05-02 16:26:54
ComboFix4.txt 2008-05-01 17:00:14
Pre-Run: 18,239,049,728 bytes free
Post-Run: 18,464,104,448 bytes free
270 --- E O F --- 2008-04-09 07:03:47
HijackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:47:53 PM, on 5/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\D-Tools\daemon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Electronic Arts\EADM\Core.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.h...a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.h...a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.h...a...&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://appldnld.appl...ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) -
http://www.fileplane...C_2.3.6.108.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.systemreq.../sysreqlab2.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 9345 bytes