Hi peku!
I followed your detailed instructions to the letter and I am sending you the 4 files you requested. I hope this did the trick.and thanks soooo much for your technical assistance in advance!!!!!
********************************************************************************
**************************
SDFix: Version 1.193
Run by [removed] on Mon 06/16/2008 at 09:34
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default HomePage Value
Restoring Default Desktop Components Value
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-16 09:40:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\1152163973\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1152163973\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Steam\\steamapps\\eiji82\\counter-strike\\hl.exe"="C:\\Program Files\\Steam\\steamapps\\eiji82\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1152163973\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1152163973\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe:*:Disabled:McAfee Network Agent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Sun 16 Mar 2008 31 A..H. — "C:\WINDOWS\uccspecc.sys"
Wed 22 Jun 2005 45,568 A.SHR — "C:\WINDOWS\system32\cygz.dll"
Mon 16 Jun 2008 561 A.SH. — "C:\WINDOWS\system32\mmf.sys"
Sat 23 Sep 2006 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 14 Jun 2008 20,487 A.SHR — "C:\Program Files\McAfee\MQC\MRU.bak"
Sat 14 Jun 2008 265 A.SHR — "C:\Program Files\McAfee\MQC\qcconf.bak"
Wed 3 Jan 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Mon 13 Nov 2006 319,456 A..H. — "C:\Program Files\Common Files\Motorola Shared\MotPCSDrivers\difxapi.dll"
Thu 12 Jun 2008 250,029 …HR — "C:\WINDOWS\system32\drivers\etc\Hosts.bak"
Finished!
********************************************************************************
*************************************
HijackThis log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:52, on 2008-06-16
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Hewlett-Packard\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Hewlett-Packard\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O3 - Toolbar: rtsplgob - {C075D7A0-956E-4AF8-B5EC-8FFA98C53940} - (no file)
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AtiPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: &Search; - ?p=ZU
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/…b?1154270380515
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu…b?1184385592515
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: jkkJbxyX - jkkJbxyX.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 10879 bytes
UNINSTALL LIST
*************************************************************
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
32 Bit HP CIO Components Installer
Ad-Aware
Adobe Flash Player 9 ActiveX
Adobe Flash Player Plugin
Adobe Reader 8.1.2
Adobe® Photoshop® Album Starter Edition 3.2
AIM 6
Apple Mobile Device Support
Apple Software Update
ATI Control Panel
ATI Display Driver
ATI HYDRAVISION
Avanquest update
Battle.net
BitLord 1.1
BlackBerry Desktop Software 4.2
BlackBerry Desktop Software 4.2
CCleaner (remove only)
DVDFab Platinum 4.0.5.5 by Dr.Pc Putte - Team RES
GdiplusUpgrade
getPlus®_dll
GOM Player
Half-Life: Counter-Strike
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows Media Player 11 (KB939683)
HP Deskjet 3740
HP Photo and Imaging 1.0 - PSC 2000 Series
HP Photo and Imaging 1.0 - PSC 2000 Series
HP Photo and Imaging 1.0 - PSC 2000 Series Drivers
hp psc 2100 series
HP Smart Web Printing
HP Software Update
HP Update
HPSSupply
iPod for Windows 2006-06-28
iTunes
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 3
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java DB 10.3.1.4
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 5
Java™ SE Development Kit 6 Update 5
Java™ SE Runtime Environment 6 Update 1
LimeWire 4.16.7
LiveUpdate Notice (Symantec Corporation)
McAfee SecurityCenter
Memorex exPressit Label Design Studio
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Ultimate 2007
Microsoft Office Ultimate 2007
Microsoft Office Word MUI (English) 2007
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MONOPOLY HERE & NOW EDITION
Motorola Driver Installation
Motorola Phone Tools
Mozilla Firefox (2.0.0.14)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Nero Suite
Norton 360
QuickTime
Readiris 7.5
RealArcade
Realtek AC'97 Audio
RegCure 1.5.0.0
Roxio Media Manager
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Excel 2007 (KB946974)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB951808)
Security Update for Microsoft Office Word 2007 (KB950113)
Security Update for Office 2007 (KB947801)
Security Update for Outlook 2007 (KB946983)
Security Update for Visio 2007 (KB947590)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
SiS 900 PCI Fast Ethernet Adapter Driver
SiS VGA Utilities
SiSAGP driver
Steam
Symantec KB-DocID:2003093015493306
Symantec Technical Support Web Controls
Update for Office 2007 (KB946691)
Update for Outlook 2007 Junk Email Filter (kb950378)
Viewpoint Media Player
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
World of Warcraft
Yahtzee Download Edition
********************************************************************************
**************************
ComboFix.txt
ComboFix 08-06-15.4 - me 2008-06-16 11:01:04.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1035 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-16 to 2008-06-16 )))))))))))))))))))))))))))))))
.
2008-06-16 09:29 . 2008-06-16 09:30 d—-c— C:\WINDOWS\ERUNT
2008-06-16 09:22 . 2007-11-20 15:11 d—-c— C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-06-16 09:21 . 2008-06-16 09:22 d—-c— C:\Documents and Settings\Administrator
2008-06-16 09:18 . 2008-06-16 09:45 d—-c— C:\SDFix
2008-06-14 18:34 . 2008-06-14 18:34 2,688 –a–c— C:\WINDOWS\system32\settings.aaw
2008-06-14 18:34 . 2008-06-14 18:34 704 –a–c— C:\WINDOWS\system32\history.aaw
2008-06-14 15:44 . 2008-06-14 15:48 4,400 –a–c— C:\WINDOWS\system32\tmp.reg
2008-06-14 14:39 . 2008-06-14 14:39 d—-c— C:\Program Files\Trend Micro
2008-06-14 13:18 . 2008-06-14 13:36 d——– C:\Documents and Settings\me\Application Data\SUPERAntiSpyware.com
2008-06-14 13:18 . 2008-06-14 13:18 d—-c— C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-14 13:04 . 2008-06-14 13:08 d—-c— C:\WINDOWS\system32\URTTemp
2008-06-14 10:26 . 2006-03-03 08:07 143,360 –a–c— C:\WINDOWS\system32\dunzip32.dll
2008-06-14 10:26 . 2008-06-16 10:32 5,135 –a–c— C:\WINDOWS\system32\Config.MPF
2008-06-14 10:24 . 2008-06-14 10:24 d—-c— C:\Program Files\McAfee.com
2008-06-14 10:24 . 2007-11-22 06:44 201,320 –a–c— C:\WINDOWS\system32\drivers\mfehidk.sys
2008-06-14 10:24 . 2007-07-13 06:20 113,952 –a–c— C:\WINDOWS\system32\drivers\Mpfp.sys
2008-06-14 10:24 . 2007-11-22 06:44 79,304 –a–c— C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-06-14 10:24 . 2007-12-02 12:51 40,488 –a–c— C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-06-14 10:24 . 2007-11-22 06:44 35,240 –a–c— C:\WINDOWS\system32\drivers\mfebopk.sys
2008-06-14 10:24 . 2007-11-22 06:44 33,832 –a–c— C:\WINDOWS\system32\drivers\mferkdk.sys
2008-06-14 10:23 . 2008-06-14 12:15 d—-c— C:\Program Files\McAfee
2008-06-14 10:23 . 2008-06-14 10:24 d—-c— C:\Program Files\Common Files\McAfee
2008-06-14 10:21 . 2008-06-14 10:26 d—-c— C:\Documents and Settings\All Users\Application Data\McAfee
2008-06-13 16:31 . 2008-06-14 13:36 d—-c— C:\Program Files\Common Files\Wise Installation Wizard
2008-06-12 23:15 . 2008-06-14 01:51 d–h-c— C:\$AVG8.VAULT$
2008-06-12 23:10 . 2008-06-12 23:10 d—-c— C:\Program Files\AVG
2008-06-12 23:10 . 2008-06-12 23:10 d——– C:\Documents and Settings\me\Application Data\AVGTOOLBAR
2008-06-12 23:10 . 2008-06-14 10:01 d—-c— C:\Documents and Settings\All Users\Application Data\avg8
2008-06-12 20:40 . 2008-06-12 20:40 d—-c— C:\CCleaner
2008-06-11 18:47 . 2008-06-12 22:11 d—-c— C:\N360_BACKUP
2008-06-11 08:38 . 2008-04-14 07:30 272,128 —–c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 08:38 . 2008-05-08 09:02 203,136 —–c— C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-18 20:15 . 2008-05-18 20:15 d—-c— C:\Logs
2008-05-18 18:29 . 2008-06-08 10:53 d—-c— C:\World of Warcraft
2008-05-18 18:29 . 2008-05-18 19:15 d—-c— C:\Program Files\Common Files\Blizzard Entertainment
2008-05-16 11:58 . 2008-05-16 11:58 12,632 –a–c— C:\WINDOWS\system32\lsdelete.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-16 02:22 ——— dc—-w C:\Program Files\Steam
2008-06-14 18:35 ——— dc–a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-14 15:13 ——— dc—-w C:\Program Files\Common Files\Symantec Shared
2008-06-14 15:12 ——— dc—-w C:\Program Files\Spybot - Search & Destroy
2008-06-14 15:12 ——— dc—-w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-14 15:10 ——— dc—-w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-14 15:09 ——— dc—-w C:\Program Files\Norton 360
2008-06-13 21:32 15,648 -c–a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-06-13 21:32 15,648 -c–a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-06-13 21:32 12,960 -c–a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2008-06-13 21:32 ——— dc—-w C:\Program Files\Lavasoft
2008-06-13 21:32 ——— dc—-w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-11 12:19 ——— d—–w C:\Documents and Settings\me\Application Data\Vso
2008-05-21 12:20 ——— dc—-w C:\Program Files\Viewpoint
2008-05-21 12:20 ——— dc—-w C:\Program Files\AIM6
2008-05-21 12:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-21 12:19 ——— dc—-w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-05-21 12:19 ——— dc—-w C:\Documents and Settings\All Users\Application Data\AOL
2008-05-15 22:06 ——— dc—-w C:\Program Files\LimeWire
2008-05-15 04:44 ——— d—–w C:\Documents and Settings\me\Application Data\Research In Motion
2008-05-15 04:31 ——— dc—-w C:\Program Files\Common Files\Research In Motion
2008-05-15 04:31 ——— d—–w C:\Documents and Settings\me\Application Data\Blackberry Desktop
2008-05-15 04:30 ——— dc—-w C:\Program Files\Research In Motion
2008-05-14 08:02 ——— dc—-w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-14 04:51 86,528 -c–a-w C:\WINDOWS\bnetunin.exe
2008-05-12 14:26 ——— dc—-w C:\Program Files\DivX
2008-05-12 14:26 ——— d—–w C:\Documents and Settings\me\Application Data\Viewpoint
2008-05-12 05:18 ——— dc—-w C:\Documents and Settings\All Users\Application Data\GRETECH
2008-05-12 05:18 ——— d—–w C:\Documents and Settings\me\Application Data\GRETECH
2008-05-12 05:17 ——— dc—-w C:\Program Files\GRETECH
2008-05-11 16:49 ——— dc—-w C:\Documents and Settings\All Users\Application Data\HP
2008-05-08 14:02 203,136 -c–a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:12 1,288,192 -c–a-w C:\WINDOWS\system32\quartz.dll
2008-04-26 22:22 ——— dc—-w C:\Program Files\iTunes
2008-04-26 22:22 ——— dc—-w C:\Program Files\iPod
2008-04-26 22:21 ——— dc—-w C:\Program Files\QuickTime
2008-04-26 22:16 ——— dc—-w C:\Program Files\Apple Software Update
2008-04-25 22:12 ——— dc—-w C:\Program Files\Common Files\Adobe
2008-04-25 21:57 ——— dc—-w C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-04-25 21:46 ——— dc—-w C:\Program Files\Common Files\Adobe Systems Shared
2008-04-23 04:16 826,368 -c–a-w C:\WINDOWS\system32\wininet.dll
2008-04-21 15:25 ——— dc—-w C:\Program Files\RegCure
2008-04-14 10:42 985,088 -c–a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 10:42 11,264 -c–a-w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 10:41 423,936 -c–a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 -c–a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 329,728 -c–a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 -c–a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 -c–a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 299,520 -c–a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 00:13 12,168 -c–a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:11 997,376 -c–a-w C:\WINDOWS\system32\msgina.dll
2008-04-14 00:10 53,279 -c–a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 -c–a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 -c–a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 21:00 103,424 -c–a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-13 19:30 1,845,632 -c–a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:24 2,145,280 -c–a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 18:44 17,664 -c–a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:35 24,064 -c–a-w C:\WINDOWS\system32\pidgen.dll
2008-04-13 18:31 7,424 -c–a-w C:\WINDOWS\system32\kd1394.dll
2008-04-13 18:31 2,023,936 -c–a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 18:30 61,440 -c–a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-13 18:14 76,800 -c—-w C:\WINDOWS\system32\msshavmsg.dll
2008-04-13 17:39 438,784 -c–a-w C:\WINDOWS\system32\xpob2res.dll
2008-04-13 17:39 2,897,920 -c–a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-13 17:39 187,392 -c–a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-13 17:37 208,384 -c–a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-13 17:37 138,752 -c–a-w C:\WINDOWS\system32\dssenh.dll
2008-04-13 17:27 79,872 -c—-w C:\WINDOWS\system32\msxml6r.dll
2008-04-13 17:26 94,208 -c–a-w C:\WINDOWS\system32\odbcint.dll
2008-04-13 17:26 12,288 -c–a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-13 17:26 12,288 -c–a-w C:\WINDOWS\system32\mscpx32r.dll
2008-04-13 17:24 20,480 -c–a-w C:\WINDOWS\system32\msorc32r.dll
2008-04-13 17:21 733,696 -c–a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-13 17:09 4,096 -c–a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-13 17:03 63,488 -c–a-w C:\WINDOWS\system32\browselc.dll
2008-04-13 17:03 549,376 -c–a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-13 16:48 1,647,616 -c–a-w C:\WINDOWS\system32\winbrand.dll
2008-04-13 16:45 216,064 -c–a-w C:\WINDOWS\system32\moricons.dll
2008-04-13 16:23 48,128 -c–a-w C:\WINDOWS\system32\msprivs.dll
2008-04-13 16:22 48,128 -c–a-w C:\WINDOWS\system32\inetres.dll
2008-04-13 15:39 884,736 -c–a-w C:\WINDOWS\system32\msimsg.dll
2008-02-04 22:08 47,360 -c–a-w C:\Documents and Settings\me\Application Data\pcouffin.sys
2006-12-22 06:33 92,064 -c–a-w C:\Documents and Settings\me\mqdmmdm.sys
2006-12-22 06:33 9,232 -c–a-w C:\Documents and Settings\me\mqdmmdfl.sys
2006-12-22 06:33 79,328 -c–a-w C:\Documents and Settings\me\mqdmserd.sys
2006-12-22 06:33 66,656 -c–a-w C:\Documents and Settings\me\mqdmbus.sys
2006-12-22 06:33 6,208 -c–a-w C:\Documents and Settings\me\mqdmcmnt.sys
2006-12-22 06:33 5,936 -c–a-w C:\Documents and Settings\me\mqdmwhnt.sys
2006-12-22 06:33 4,048 -c–a-w C:\Documents and Settings\me\mqdmcr.sys
2006-12-22 06:33 25,600 -c–a-w C:\Documents and Settings\me\usbsermptxp.sys
2006-12-22 06:33 22,768 -c–a-w C:\Documents and Settings\me\usbsermpt.sys
2006-08-10 04:10 81,920 —-a-w C:\Documents and Settings\me\Application Data\ezpinst.exe
2005-06-22 05:37 45,568 -csha-r C:\WINDOWS\system32\cygz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 05:40 218032]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Share-to-Web Namespace Daemon"="C:\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 04:19 69632]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"AtiPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-01 21:05 339968]
"SiSPower"="SiSPower.dll" [2005-04-11 22:31 49152 C:\WINDOWS\system32\SiSPower.dll]
"SoundMan"="SOUNDMAN.EXE" [2005-03-24 08:20 77824 C:\WINDOWS\SOUNDMAN.EXE]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38 241664]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 10:46 172032]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 08:00 33648]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-04-23 12:43 228088]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkJbxyX]
jkkJbxyX.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winaq75.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winey66.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winlx04.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winom54.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winot50.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winou44.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winpn64.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winvu51.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\1152163973\\ee\\aim6.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Steam\\steamapps\\eiji82\\counter-strike\\hl.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1152163973\\ee\\aolsoftware.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2007-03-21 17:58]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-04 11:43]
S0 Winom54;Winom54;C:\WINDOWS\system32\Drivers\Winom54.sys []
S0 Winot50;Winot50;C:\WINDOWS\system32\Drivers\Winot50.sys []
S3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-03 17:31]
S3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2001-09-26 21:32]
S3 Winey66;Winey66;C:\WINDOWS\System32\drivers\Winey66.sys []
S3 Winou44;Winou44;C:\WINDOWS\System32\drivers\Winou44.sys []
S3 Winpn64;Winpn64;C:\WINDOWS\System32\drivers\Winpn64.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
"2008-06-10 02:00:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-15 06:09:42 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-06-14 15:24:07 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-06-16 15:30:37 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-06-12 21:09:08 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-06-16 08:00:01 C:\WINDOWS\Tasks\SpyHunter Scanner.job"
- C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-16 11:02:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-16 11:03:20
ComboFix-quarantined-files.txt 2008-06-16 16:03:05
ComboFix2.txt 2008-06-16 15:34:35
Pre-Run: 135,458,828,288 bytes free
Post-Run: 135,449,366,528 bytes free
258 — E O F — 2008-06-15 23:08:24
I also removed Norton, Spy Hunter and others I had on the system. Awaiting your response to the scans.
Thanks,
Ryan