Well I ran the CFscript and went off to work, and when I come back I have no internet connection. It was sending out packets but wouldn't recieve any, so I went on another computer and looked online for solution, and none of them seemed to work out for my comptuer..my guess is that it could've been combofix since it occured right after the CFscript or just quinicdental. I have everything set to "obtain automatically" and all the settings are set the same as this one so I really don't know. also when I try to repiar it , it comes back with "cannot renew IP"
heres the logs:
Logfile of Trend Micro
HijackThis v2.0.2Scan saved at 9:42:31 PM, on 9/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Spybot - Search & Destroy\SDFiles.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.gateway.com/g/startpage.html?Ch…DTP&M=W3622
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Spare Backup] "C:\Program Files\Spare Backup\SpareBackup.exe" /silent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
–
End of file - 4307 bytes
ComboFix 08-09-19.13 - Owner 2008-09-20 12:21:24.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFscript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\exsv.exe
C:\WINDOWS\system32\
00setup.exe
C:\WINDOWS\system32\12.tmp
C:\WINDOWS\system32\16.tmp
C:\WINDOWS\system32\6F.tmp
C:\WINDOWS\system32\70.tmp
C:\WINDOWS\system32\71.tmp
C:\WINDOWS\system32\72.tmp
C:\WINDOWS\system32\73.tmp
C:\WINDOWS\system32\dplx.sys
C:\WINDOWS\system32\imod3.dll
C:\WINDOWS\system32\k86.bin
C:\WINDOWS\system32\nxg.bin
C:\WINDOWS\system32\tdssadw.dll
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\tdsslog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdssserf.dll
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job
C:\WINDOWS\vmgspntbqvm.dll
C:\WINDOWS\wininit.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DIFxAPI.dll
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\GEARAspiWDM.inf
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\gearaspiwdmx86.cat
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspi.dll
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspiWDM.sys
C:\Documents and Settings\Owner\Application Data\AdwareAlert
C:\Documents and Settings\Owner\Application Data\AdwareAlert\Log\2008 Sep 17 - 10_30_38 AM_796.log
C:\Documents and Settings\Owner\Application Data\AdwareAlert\rs.dat
C:\Documents and Settings\Owner\Application Data\AdwareAlert\Settings\ScanResults.pie
C:\WINDOWS\exsv.exe
C:\WINDOWS\system32\
00setup.exe
C:\WINDOWS\system32\12.tmp
C:\WINDOWS\system32\16.tmp
C:\WINDOWS\system32\6F.tmp
C:\WINDOWS\system32\71.tmp
C:\WINDOWS\system32\73.tmp
C:\WINDOWS\system32\dwave.sys
C:\WINDOWS\system32\imod3.dll
C:\WINDOWS\system32\k86.bin
C:\WINDOWS\system32\nxg.bin
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job
C:\WINDOWS\vmgspntbqvm.dll
C:\WINDOWS\wininit.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_DPLX
——-\Legacy_TDSSSERV
——-\Service_dplx
——-\Service_TDSSserv
((((((((((((((((((((((((( Files Created from 2008-08-20 to 2008-09-20 )))))))))))))))))))))))))))))))
.
2008-09-19 09:23 . 2008-09-19 09:25 d——– C:\Program Files\Spybot - Search & Destroy
2008-09-19 09:23 . 2008-09-19 10:47 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-19 08:23 . 2008-09-20 05:33 d–h—– C:\$AVG8.VAULT$
2008-09-19 08:13 . 2008-09-19 08:24 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\AVGTOOLBAR
2008-09-19 08:11 . 2008-09-20 04:06 d——– C:\WINDOWS\system32\drivers\Avg
2008-09-19 08:11 . 2008-09-19 08:11 d——– C:\Program Files\AVG
2008-09-19 08:11 . 2008-09-19 09:15 d——– C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
2008-09-19 08:11 . 2008-09-19 11:13 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-09-19 08:11 . 2008-09-19 08:11 97,928 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-19 08:11 . 2008-09-19 08:11 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-19 08:11 . 2008-09-19 08:11 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-09-19 07:44 . 2008-09-19 07:44 0 –a—— C:\WINDOWS\nsreg.dat
2008-09-17 15:33 . 2008-09-17 15:33 d——– C:\Program Files\Microsoft Silverlight
2008-09-17 15:19 . 2008-09-17 15:19 d——– C:\Program Files\Windows Media Components
2008-09-17 15:14 . 2008-09-17 15:15 d——– C:\Documents and Settings\Owner\Application Data\Ventrilo
2008-09-17 15:14 . 2008-09-19 09:05 d——– C:\Documents and Settings\Owner\Application Data\Hamachi
2008-09-17 15:06 . 2008-09-17 15:06 d——– C:\Program Files\Xilisoft
2008-09-17 15:06 . 2008-09-17 15:06 d——– C:\Program Files\Trend Micro
2008-09-17 15:04 . 2008-09-17 15:05 d——– C:\Program Files\Warcraft III
2008-09-17 14:25 . 2008-09-17 15:35 d——– C:\Program Files\Beston
2008-09-17 14:20 . 2008-09-17 14:35 137,472 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-09-17 14:20 . 2008-09-17 14:35 111,928 –a—— C:\WINDOWS\system32\PnkBstrB.exe
2008-09-17 14:19 . 2008-09-17 14:19 66,872 –a—— C:\WINDOWS\system32\PnkBstrA.exe
2008-09-17 12:40 . 2008-09-17 12:40 d——– C:\Program Files\Lavasoft
2008-09-17 12:40 . 2008-09-17 12:40 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-09-17 12:40 . 2008-09-17 12:40 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-17 08:56 . 2008-09-17 14:11 d——– C:\Documents and Settings\Owner\Application Data\Apple Computer
2008-09-17 08:55 . 2008-04-17 13:12 107,368 –a—— C:\WINDOWS\system32\GEARAspi.dll
2008-09-17 08:55 . 2008-04-17 13:12 15,464 –a—— C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-09-17 08:54 . 2008-09-17 15:42 d——– C:\Program Files\iTunes
2008-09-17 08:54 . 2008-09-17 14:28 d——– C:\Program Files\iPod
2008-09-17 08:53 . 2008-09-17 08:53 d——– C:\Program Files\Bonjour
2008-09-17 08:51 . 2008-09-17 08:53 d——– C:\Program Files\QuickTime
2008-09-17 08:51 . 2008-09-17 08:54 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-17 08:50 . 2008-09-17 08:50 d——– C:\Program Files\Apple Software Update
2008-09-17 08:49 . 2008-09-17 08:52 d——– C:\Program Files\Common Files\Apple
2008-09-17 08:48 . 2008-09-17 08:48 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-09-17 08:38 . 2008-09-17 08:38 d——– C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-09-17 08:36 . 2008-09-17 08:36 d——– C:\Program Files\River Past
2008-09-17 08:36 . 2008-09-17 08:36 d——– C:\Program Files\Common Files\River Past
2008-09-17 08:36 . 2008-09-17 09:44 d——– C:\Documents and Settings\Owner\Application Data\River Past G5
2008-09-17 08:36 . 2008-09-17 09:44 d——– C:\Documents and Settings\All Users\Application Data\River Past G5
2008-09-17 08:36 . 2008-09-17 08:36 164,872 –a—— C:\WINDOWS\Crazi Video Uninstaller.exe
2008-09-17 08:29 . 2008-09-17 10:05 d——– C:\Documents and Settings\Owner\Incomplete
2008-09-17 08:28 . 2008-09-17 10:05 d——– C:\Program Files\LimeWire
2008-09-17 08:28 . 2008-09-17 10:16 d——– C:\Documents and Settings\Owner\Application Data\LimeWire
2008-09-17 03:00 . 2008-09-17 03:00 d——– C:\Program Files\MSXML 4.0
2008-09-16 01:30 . 2008-09-20 04:07 d——– C:\Documents and Settings\Owner\Shared
2008-09-16 01:27 . 2008-09-16 11:29 d——– C:\WINDOWS\system32\CatRoot_bak
2008-09-16 01:27 . 2008-06-13 09:10 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-09-16 01:27 . 2008-06-13 09:10 272,128 —–c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-16 01:26 . 2008-05-01 10:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-16 01:26 . 2008-06-23 12:57 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-09-16 01:23 . 2004-08-04 15:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-09-16 01:22 . 2006-07-01 01:30 d——– C:\WINDOWS\system32\config\systemprofile\WINDOWS
2008-09-16 01:22 . 2008-09-16 00:59 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\Spare Backup
2008-09-16 01:22 . 2008-09-16 00:56 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\SampleView
2008-09-16 01:22 . 2006-07-01 01:30 d——– C:\Documents and Settings\Default User\WINDOWS
2008-09-16 01:03 . 2008-09-16 01:03 8,192 –a—— C:\WINDOWS\REGLOCS.OLD
2008-09-16 00:59 . 2008-09-16 00:59 333 –a—— C:\WINDOWS\system32\$ncsp$.inf
2008-09-16 00:59 . 2008-09-16 00:59 0 –a—— C:\WINDOWS\system32\Gateway_W3622_3.1_0000.MRK
2008-09-16 00:58 . 2008-09-16 00:58 940,794 –a—— C:\WINDOWS\system32\LoopyMusic.wav
2008-09-16 00:58 . 2008-09-16 00:58 146,650 –a—— C:\WINDOWS\system32\BuzzingBee.wav
2008-09-16 00:57 . 2006-10-06 00:09 155,648 –a—— C:\WINDOWS\system32\igfxres.dll
2008-09-16 00:56 . 2008-09-16 00:56 d——– C:\Documents and Settings\Owner\Application Data\SampleView
2008-09-16 00:54 . 2006-12-19 17:52 8,453,632 –a–c— C:\WINDOWS\system32\dllcache\shell32.dll
2008-09-16 00:54 . 2006-12-19 17:52 134,656 –a–c— C:\WINDOWS\system32\dllcache\shsvcs.dll
2008-09-16 00:52 . 2006-11-27 10:54 539,136 –a–c— C:\WINDOWS\system32\dllcache\msftedit.dll
2008-09-16 00:52 . 2006-11-27 10:54 433,152 –a–c— C:\WINDOWS\system32\dllcache\riched20.dll
2008-09-16 00:51 . 2006-08-21 05:14 128,896 –a–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-09-16 00:51 . 2006-08-21 05:14 30,720 –a–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2008-09-16 00:51 . 2006-08-21 08:21 16,896 –a–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2008-09-16 00:50 . 2006-06-22 01:06 1,435,648 –a–c— C:\WINDOWS\system32\dllcache\query.dll
2008-09-16 00:50 . 2008-05-08 08:28 202,752 –a–c— C:\WINDOWS\system32\dllcache\rmcast.sys
2008-09-16 00:50 . 2006-06-22 01:06 69,120 –a–c— C:\WINDOWS\system32\dllcache\ciodm.dll
2008-09-16 00:49 . 2006-04-21 02:12 332,800 –a–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-09-16 00:49 . 2006-06-22 06:47 181,248 –a–c— C:\WINDOWS\system32\dllcache\rasmans.dll
2008-09-16 00:49 . 2008-06-20 13:41 148,992 –a–c— C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-09-16 00:49 . 2006-05-19 08:59 111,616 –a–c— C:\WINDOWS\system32\dllcache\dhcpcsvc.dll
2008-09-16 00:49 . 2006-05-19 08:59 94,720 –a–c— C:\WINDOWS\system32\dllcache\iphlpapi.dll
2008-09-16 00:48 . 2004-09-03 19:07 28,672 –a—— C:\WINDOWS\system32\Marker32.exe
2008-09-16 00:47 . 2008-09-16 00:47 d——– C:\Program Files\Spare Backup
2008-09-16 00:47 . 2008-09-16 00:47 d——– C:\Program Files\Microsoft WSE
2008-09-16 00:47 . 2008-09-20 04:36 d——– C:\Documents and Settings\Owner\Application Data\Spare Backup
2008-09-16 00:46 . 2008-09-16 00:46 d——– C:\McAfee
2008-09-16 00:46 . 2007-04-23 06:14 364,160 –a–c— C:\WINDOWS\system32\dllcache\update.sys
2008-09-16 00:44 . 2007-02-28 05:55 2,182,144 –a–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-09-16 00:44 . 2007-02-28 05:53 2,137,600 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-09-16 00:44 . 2007-02-28 05:15 2,017,280 –a–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-09-16 00:44 . 2007-03-17 09:43 292,864 –a–c— C:\WINDOWS\system32\dllcache\winsrv.dll
2008-09-16 00:44 . 2007-02-05 16:17 185,344 –a–c— C:\WINDOWS\system32\dllcache\upnphost.dll
2008-09-16 00:44 . 2007-03-09 09:58 57,344 –a–c— C:\WINDOWS\system32\dllcache\agentdpv.dll
2008-09-16 00:43 . 2008-09-16 01:34 d——– C:\Program Files\BigFix
2008-09-16 00:43 . 2007-03-08 09:47 1,843,584 –a–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-09-16 00:43 . 2007-03-08 11:36 577,536 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-09-16 00:43 . 2007-03-08 11:36 281,600 –a–c— C:\WINDOWS\system32\dllcache\gdi32.dll
2008-09-16 00:43 . 2007-03-08 11:36 40,960 –a–c— C:\WINDOWS\system32\dllcache\mf3216.dll
2008-09-16 00:43 . 2006-11-16 19:05 11,816 –a—— C:\WINDOWS\BigFixClientOverride.dll
2008-09-16 00:42 . 2008-09-16 11:18 d——– C:\Program Files\eMachines Games
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\Program Files\NetZero
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\google
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\Documents and Settings\All Users\Application Data\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2008-09-16 00:41 . 2006-02-01 06:54 94,208 –a—— C:\WINDOWS\system32\BAE.dll
2008-09-16 00:39 . 2008-09-16 11:19 d——– C:\Program Files\Java
2008-09-16 00:39 . 2008-09-16 11:44 d——– C:\Program Files\Google
2008-09-16 00:39 . 2008-09-16 00:39 d——– C:\Program Files\Common Files\Java
2008-09-16 00:39 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-16 00:39 . 2008-09-16 00:39 0 –a—— C:\WINDOWS\system32\drivers\Gateway_W3622_3.1_0000.MRK
2008-09-16 00:38 . 2008-09-16 00:38 d–h—– C:\WINDOWS\msdownld.tmp
2008-09-16 00:38 . 2006-10-26 22:56 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2008-09-16 00:37 . 2008-09-16 00:37 d——– C:\Program Files\Microsoft.NET
2008-09-16 00:37 . 2008-09-16 00:40 d——– C:\Program Files\Microsoft Works
2008-09-16 00:36 . 2008-09-16 00:36 d——– C:\WINDOWS\SHELLNEW
2008-09-16 00:35 . 2008-09-16 00:35 dr-h—– C:\MSOCache
2008-09-16 00:35 . 2008-09-16 00:38 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-16 00:34 . 2001-03-08 21:30 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2008-09-16 00:33 . 2008-09-16 00:34 d——– C:\Program Files\CyberLink
2008-09-16 00:33 . 2003-03-18 23:14 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-09-16 00:33 . 2003-02-21 07:42 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-09-16 00:32 . 2008-09-16 00:33 d——– C:\Program Files\Common Files\Adobe
2008-09-16 00:31 . 2008-09-17 15:19 d——– C:\Program Files\Windows Media Connect 2
2008-09-16 00:31 . 2006-10-04 10:06 1,197,294 –a–c— C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-09-16 00:31 . 2006-10-04 10:06 764,868 –a–c— C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-09-16 00:31 . 2006-10-04 10:06 217,118 –a–c— C:\WINDOWS\system32\dllcache\apphelp.sdb
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-18 07:54 ——— d—–w C:\Program Files\Diablo II
2008-09-17 19:15 ——— d—–w C:\Program Files\Ventrilo
2008-09-17 18:55 ——— d—–w C:\Program Files\Q3Ademo
2008-09-17 18:20 ——— d—–w C:\Program Files\Wolfenstein - Enemy Territory
2008-09-15 23:05 ——— d—–w C:\Program Files\Starcraft
2008-08-12 06:05 ——— d—–w C:\Program Files\Rockstar Games
2008-08-08 00:10 ——— d—–w C:\Program Files\EA GAMES
.
——- Sigcheck ——-
2004-08-04 15:00 1039872 6beed988649566e49c3fb63dec564c3c C:\WINDOWS\explorer.exe
2008-04-13 20:12 1041408 6ce19208891e9dc85b46ec32ea3fa3e9 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\explorer.exe
2008-04-13 20:12 23040 7994d694ec2fb339baff2e50925e62cf C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ctfmon.exe
2004-08-04 15:00 23040 8f95a0995a14394008f0415fa5aceaac C:\WINDOWS\system32\ctfmon.exe
2008-04-13 20:12 33792 66f69cf680ee53f7751ab7bd8490c797 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\userinit.exe
2004-08-04 15:00 32256 72eadc55ba014923295f84aba5361d50 C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((( snapshot@2008-09-20_ 4.40.07.89 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 00:02:28 174,592 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-21 00:02:28 163,328 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2008-09-20 08:33:53 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-20 16:30:13 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-20 08:33:53 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-20 16:30:13 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-20 08:33:53 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-20 16:30:13 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DIFxAPI.dll
2008-04-17 13:12 319456 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002161.dll
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
2008-07-04 13:35 54632 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002162.exe
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspi.dll
2008-04-17 13:12 107368 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002165.dll
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspiWDM.sys
2008-04-17 13:12 15464 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002166.sys
2008-09-16 00:30 57344 C:\Documents and Settings\Owner\Application Data\Microsoft\Installer\{15377C3E-9655-400F-B441-E69F0A6BEAFE}\NewShortcut3_15377C3E9655400FB441E69F0A6BEAFE.EXE
2008-09-16 00:30 57344 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002208.EXE
2007-01-08 18:46 656984 C:\McAfee\Install.exe
2007-01-08 18:46 656984 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002278.exe
2008-09-19 08:11 540440 C:\Program Files\AVG\AVG8\aAvgApi.exe
2008-09-19 08:11 540440 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002062.exe
2008-09-19 08:11 875288 C:\Program Files\AVG\AVG8\avgemc.exe
2008-09-19 08:11 875288 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002181.exe
2008-09-19 08:11 287000 C:\Program Files\AVG\AVG8\avgrsx.exe
2008-09-19 08:11 287000 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002180.exe
2008-09-19 08:11 2813720 C:\Program Files\AVG\AVG8\avgui.exe
2008-09-19 08:11 2813720 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002206.exe
2008-09-19 08:11 641304 C:\Program Files\AVG\AVG8\avgupd.exe
2008-09-19 08:11 641304 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002056.exe
2008-09-19 08:11 222488 C:\Program Files\AVG\AVG8\fixcfg.exe
2008-09-19 08:11 222488 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002057.exe
2008-09-19 08:11 2546968 C:\Program Files\AVG\AVG8\setup.exe
2008-09-19 08:11 2546968 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002234.exe
2003-07-23 14:32 2347008 C:\Program Files\Beston\EZPhoto Browser 2.1\EZPhotoBrowser2.exe
2003-07-23 14:32 2347008 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002235.exe
2003-06-26 03:46 4497408 C:\Program Files\Beston\EZPhoto Tools 2.1\EZPhotoTools2.exe
2003-06-26 03:46 4497408 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002236.exe
2003-07-07 13:39 1953792 C:\Program Files\Beston\EZShowtime MMS 1.1\Showtime1.exe
2003-07-07 13:39 1953792 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002237.exe
2003-06-21 00:28 266240 C:\Program Files\Beston\EZSuite For Video Chat Kit\EZSuite-VideoChatKit.exe
2003-06-21 00:28 266240 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002238.exe
2001-05-11 05:17 200704 C:\Program Files\Beston\EZSuite For Video Chat Kit\OnlineReg.exe
2001-05-11 05:17 200704 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002239.exe
2002-03-11 04:08 484100 C:\Program Files\Beston\EZVideo Mail 2.1\demo.exe
2002-03-11 04:08 484100 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002240.exe
2003-07-07 13:26 1273856 C:\Program Files\Beston\EZVideo Mail 2.1\EZVMail2.exe
2003-07-07 13:26 1273856 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002241.exe
2004-08-04 15:00 47616 C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe
2004-08-04 15:00 47616 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002230.exe
2005-06-14 23:42 65536 C:\Program Files\CyberLink\Power2Go\CLDMA.exe
2005-06-14 23:42 65536 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002245.exe
2006-11-13 22:49 360448 C:\Program Files\CyberLink\Power2Go\OLRSubmission\OLRSubmission.exe
2006-11-13 22:49 360448 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002242.exe
2006-11-23 00:45 2129920 C:\Program Files\CyberLink\Power2Go\Power2Go.exe
2006-11-23 00:45 2129920 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002243.exe
2006-11-23 00:42 2478080 C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe
2006-11-23 00:42 2478080 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002244.exe
2008-05-27 21:44 192512 C:\Program Files\Diablo II\D2VidTst.exe
2008-05-27 21:44 192512 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002246.exe
2008-06-28 22:14 45056 C:\Program Files\Diablo II\Diablo II.exe
2008-06-28 22:14 45056 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002203.exe
2004-10-19 15:04 5656576 C:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe
2004-10-19 15:04 5656576 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002247.exe
2004-01-22 12:36 376832 C:\Program Files\EA GAMES\Battlefield 1942\DedicatedServer.exe
2004-01-22 12:36 376832 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002250.exe
2002-07-17 16:28 790528 C:\Program Files\EA GAMES\Battlefield 1942\eReg\Battlefield 1942_eReg.exe
2002-07-17 16:28 790528 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002249.exe
2003-09-11 11:35 634880 C:\Program Files\EA GAMES\Battlefield 1942\eReg\Battlefield 1942_EZ.exe
2003-09-11 11:35 634880 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002248.exe
2002-12-13 04:35 790528 C:\Program Files\EA GAMES\Battlefield 1942\Mods\XPack1\eReg\Battlefield 1942 The Road to Rome_eReg.exe
2002-12-13 04:35 790528 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002254.exe
2003-09-11 11:35 634880 C:\Program Files\EA GAMES\Battlefield 1942\Mods\XPack1\eReg\Battlefield 1942 The Road to Rome_EZ.exe
2003-09-11 11:35 634880 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002253.exe
2003-07-02 16:52 450560 C:\Program Files\EA GAMES\Battlefield 1942\Mods\XPack2\eReg\Battlefield 1942 Secret Weapons of WWII_eReg.exe
2003-07-02 16:52 450560 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002252.exe
2003-07-02 16:55 634880 C:\Program Files\EA GAMES\Battlefield 1942\Mods\XPack2\eReg\Battlefield 1942 Secret Weapons of WWII_EZ.exe
2003-07-02 16:55 634880 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002251.exe
2004-09-23 12:24 9696256 C:\Program Files\EA GAMES\Battlefield Vietnam\bfvietnam.exe
2004-09-23 12:24 9696256 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002255.exe
2004-09-06 12:25 3809280 C:\Program Files\EA GAMES\Battlefield Vietnam\DedicatedServer.exe
2004-09-06 12:25 3809280 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002258.exe
2004-02-13 11:49 634880 C:\Program Files\EA GAMES\Battlefield Vietnam\eReg\Battlefield Vietnam TM_EZ.exe
2004-02-13 11:49 634880 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002256.exe
2003-10-29 13:51 450560 C:\Program Files\EA GAMES\Battlefield Vietnam\eReg\Battlefield Vietnam_eReg.exe
2003-10-29 13:51 450560 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002257.exe
2003-08-30 20:16 450560 C:\Program Files\EA GAMES\Command & Conquer Generals Zero Hour\support\Command and Conquer Generals Zero Hour_eReg.exe
2003-08-30 20:16 450560 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002263.exe
2003-08-30 20:16 77824 C:\Program Files\EA GAMES\Command & Conquer Generals Zero Hour\support\go_ez.exe
2003-08-30 20:16 77824 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002262.exe
2003-01-12 17:15 790528 C:\Program Files\EA GAMES\Command and Conquer Generals\support\Generals_eReg.exe
2003-01-12 17:15 790528 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002261.exe
2003-01-12 14:13 77824 C:\Program Files\EA GAMES\Command and Conquer Generals\support\go_ez.exe
2003-01-12 14:13 77824 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002260.exe
2007-06-26 18:48 1394464 C:\Program Files\eMachines Games\eMachines Game Console\GameConsole.exe
2007-06-26 18:48 1394464 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002264.exe
2008-06-23 05:20 633344 C:\Program Files\Internet Explorer\iexplore.exe
2008-06-23 05:20 633344 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002060.exe
2008-05-14 15:17 2682216 C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
2008-05-14 15:17 2682216 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002274.exe
2008-04-29 12:26 1238880 C:\Program Files\Lavasoft\Ad-Aware\lsupdatemanager.exe
2008-04-29 12:26 1238880 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002275.exe
2008-05-12 13:45 468312 C:\Program Files\Lavasoft\Ad-Aware\threatwork.exe
2008-05-12 13:45 468312 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002276.exe
2004-08-04 15:00 3563008 C:\Program Files\Movie Maker\moviemk.exe
2004-08-04 15:00 3563008 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002218.exe
2008-07-02 21:52 307712 C:\Program Files\Mozilla Firefox\firefox.exe
2008-07-02 21:52 307712 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002061.exe
2008-07-02 21:52 307712 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002205.exe
2004-08-04 15:00 50257 C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe
2004-08-04 15:00 50257 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002265.exe
2004-08-04 15:00 50255 C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe
2004-08-04 15:00 50255 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002266.exe
2004-08-04 15:00 50253 C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe
2004-08-04 15:00 50253 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002267.exe
2004-08-04 15:00 50254 C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exe
2004-08-04 15:00 50254 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002268.exe
2004-08-04 15:00 50253 C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe
2004-08-04 15:00 50253 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002269.exe
2004-08-04 15:00 68096 C:\Program Files\Outlook Express\msimn.exe
2004-08-04 15:00 68096 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002160.exe
1999-11-29 16:47 872505 C:\Program Files\Q3Ademo\quake3.exe
1999-11-29 16:47 872505 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002201.exe
2008-09-06 15:09 7685424 C:\Program Files\QuickTime\QuickTimePlayer.exe
2008-09-06 15:09 7685424 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002070.exe
2008-08-29 19:55 339968 C:\Program Files\River Past\Crazi Video\CraziVideo.exe
2008-08-29 19:55 339968 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002289.exe
2006-01-29 11:48 623616 C:\Program Files\ShoqBox Buddy\ShoqBox Buddy.exe
2006-01-29 11:48 623616 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002291.exe
2008-07-07 09:37 966656 C:\Program Files\Spybot - Search & Destroy\SDShred.exe
2008-07-07 09:37 966656 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002295.exe
2008-07-07 09:42 1429840 C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe
2008-07-07 09:42 1429840 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002297.exe
2008-07-07 09:42 4891472 C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
2008-07-07 09:42 4891472 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002200.exe
2008-09-19 09:23 696200 C:\Program Files\Spybot - Search & Destroy\unins000.exe
2008-09-19 09:23 696200 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002296.exe
2008-01-10 16:23 1228800 C:\Program Files\Starcraft\StarCraft.exe
2008-01-10 16:23 1228800 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002298.exe
2008-01-10 16:23 1024000 C:\Program Files\Starcraft\StarEdit.exe
2008-01-10 16:23 1024000 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002299.exe
2008-09-17 15:06 404480 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
2008-09-17 15:06 404480 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002202.exe
2007-11-17 15:58 1396736 C:\Program Files\Ventrilo\Ventrilo.exe
2007-11-17 15:58 1396736 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002199.exe
2006-10-19 00:46 71680 C:\Program Files\Windows Media Player\wmplayer.exe
2006-10-19 00:46 71680 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002071.exe
2004-08-04 15:00 222208 C:\Program Files\Windows NT\Accessories\wordpad.exe
2004-08-04 15:00 222208 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002222.exe
2004-08-04 15:00 35840 C:\Program Files\Windows NT\hypertrm.exe
2004-08-04 15:00 35840 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002224.exe
2004-08-04 15:00 288768 C:\Program Files\Windows NT\Pinball\PINBALL.EXE
2004-08-04 15:00 288768 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002271.EXE
2003-05-27 15:44 1405000 C:\Program Files\Wolfenstein - Enemy Territory\ET.exe
2003-05-27 15:44 1405000 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002196.exe
2008-09-03 22:21 61440 C:\Program Files\Xilisoft\AVI to DVD Converter\AVI to DVD Converter.exe
2008-09-03 22:21 61440 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002195.exe
2008-09-17 15:06 68334 C:\Program Files\Xilisoft\AVI to DVD Converter\Uninstall.exe
2008-09-17 15:06 68334 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002209.exe
2008-09-17 08:36 164872 C:\WINDOWS\Crazi Video Uninstaller.exe
2008-09-17 08:36 164872 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002290.exe
2004-08-04 15:00 1039872 C:\WINDOWS\explorer.exe
2004-08-04 15:00 1039872 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002186.exe
C:\WINDOWS\exsv.exe
2008-09-16 18:34 135168 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002168.exe
2008-09-17 08:50 27136 C:\WINDOWS\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
2008-09-17 08:50 27136 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002212.exe
2008-09-16 00:40 73728 C:\WINDOWS\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_630CEEA9B210_4765_A2B1_FC24596048D7.exe
2008-09-16 00:40 73728 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002286.exe
2008-09-16 00:40 192512 C:\WINDOWS\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_9FA356B1395F_4530_8CB3_946ED0B3291E.exe
2008-09-16 00:40 192512 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002287.exe
2008-09-16 00:40 73728 C:\WINDOWS\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_B8B1511D9331_467C_9B1B_E8204012E95B.exe
2008-09-16 00:40 73728 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002288.exe
2008-09-16 00:40 17534 C:\WINDOWS\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\gtngstrtd.exe
2008-09-16 00:40 17534 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002285.exe
2008-09-16 00:38 20240 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
2008-09-16 00:38 20240 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002283.exe
2008-09-16 00:38 184080 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
2008-09-16 00:38 184080 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002280.exe
2008-09-16 00:38 217864 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
2008-09-16 00:38 217864 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002282.exe
2008-09-16 00:38 35088 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
2008-09-16 00:38 35088 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002284.exe
2008-09-16 00:38 922384 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
2008-09-16 00:38 922384 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002281.exe
2008-09-16 00:38 888080 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
2008-09-16 00:38 888080 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002259.exe
2008-09-16 00:38 1172240 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
2008-09-16 00:38 1172240 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002279.exe
2008-09-16 00:47 65536 C:\WINDOWS\Installer\{A57C6094-FC5A-4DEC-B1E0-1B2F48EEE8F4}\SpareBackup.exe_A57C6094FC5A4DECB1E01B2F48EEE8F4.exe
2008-09-16 00:47 65536 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002292.exe
2008-09-16 00:47 2238 C:\WINDOWS\Installer\{A57C6094-FC5A-4DEC-B1E0-1B2F48EEE8F4}\Sparebackup.url_A57C6094FC5A4DECB1E01B2F48EEE8F4.exe
2008-09-16 00:47 2238 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002294.exe
2008-09-16 00:47 2238 C:\WINDOWS\Installer\{A57C6094-FC5A-4DEC-B1E0-1B2F48EEE8F4}\WebAccess.url_A57C6094FC5A4DECB1E01B2F48EEE8F4.exe
2008-09-16 00:47 2238 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002293.exe
2008-09-16 00:33 295606 C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A80000000002}\SC_Reader.exe
2008-09-16 00:33 295606 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002300.exe
2003-02-21 17:24 57344 C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
2003-02-21 17:24 57344 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002233.exe
2005-09-27 03:34 177664 C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe
2005-09-27 03:34 177664 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002213.exe
2004-08-04 15:00 154112 C:\WINDOWS\regedit.exe
2004-08-04 15:00 154112 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002120.exe
2006-07-21 19:14 94208 C:\WINDOWS\SoundMan.exe
2006-07-21 19:14 94208 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002117.exe
C:\WINDOWS\system32\
00setup.exe
2008-09-18 10:28 18432 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002067.exe
2004-08-04 15:00 191488 C:\WINDOWS\system32\accwiz.exe
2004-08-04 15:00 191488 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002223.exe
2004-08-04 15:00 18944 C:\WINDOWS\system32\attrib.exe
2004-08-04 15:00 18944 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002078.exe
2004-08-04 15:00 122368 C:\WINDOWS\system32\calc.exe
2004-08-04 15:00 122368 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002221.exe
2004-08-04 15:00 71680 C:\WINDOWS\system32\cleanmgr.exe
2004-08-04 15:00 71680 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002229.exe
2004-08-04 15:00 396288 C:\WINDOWS\system32\cmd.exe
2004-08-04 15:00 396288 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002076.exe
2004-08-04 15:00 396288 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002189.exe
2004-08-04 15:00 21504 C:\WINDOWS\system32\convert.exe
2004-08-04 15:00 21504 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002068.exe
2004-08-04 15:00 16896 C:\WINDOWS\system32\find.exe
2004-08-04 15:00 16896 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002077.exe
2004-08-04 15:00 34816 C:\WINDOWS\system32\findstr.exe
2004-08-04 15:00 34816 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002079.exe
2004-08-04 15:00 34816 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002190.exe
2004-08-04 15:00 47104 C:\WINDOWS\system32\grpconv.exe
2004-08-04 15:00 47104 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002074.exe
2006-10-06 00:10 102400 C:\WINDOWS\system32\igfxpers.exe
2006-10-06 00:10 102400 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002210.exe
C:\WINDOWS\system32\imod3.dll
2008-09-18 10:28 5136 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002169.dll
2006-10-17 14:56 53248 C:\WINDOWS\system32\mshta.exe
2006-10-17 14:56 53248 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002065.exe
2005-03-22 01:00 86528 C:\WINDOWS\system32\msiexec.exe
2005-03-22 01:00 86528 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002277.exe
2004-08-04 15:00 415232 C:\WINDOWS\system32\mstsc.exe
2004-08-04 15:00 415232 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002225.exe
2004-08-04 15:00 76800 C:\WINDOWS\system32\notepad.exe
2004-08-04 15:00 76800 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002066.exe
2001-08-18 08:36 1143296 C:\WINDOWS\system32\ntbackup.exe
2001-08-18 08:36 1143296 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002228.exe
2007-02-28 04:15 2059392 C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 04:15 2059392 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002301.exe
2007-02-28 05:55 2182144 C:\WINDOWS\system32\ntoskrnl.exe
2007-02-28 05:55 2182144 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002159.exe
2007-02-28 05:55 2182144 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002302.exe
2004-08-04 15:00 40960 C:\WINDOWS\system32\odbcad32.exe
2004-08-04 15:00 40960 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002232.exe
2004-08-04 15:00 25600 C:\WINDOWS\system32\ping.exe
2004-08-04 15:00 25600 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002080.exe
2004-08-04 15:00 388096 C:\WINDOWS\system32\Restore\rstrui.exe
2004-08-04 15:00 388096 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002231.exe
2004-08-04 15:00 27648 C:\WINDOWS\system32\route.exe
2004-08-04 15:00 27648 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002124.exe
2004-08-04 15:00 40960 C:\WINDOWS\system32\rundll32.exe
2004-08-04 15:00 40960 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002072.exe
2004-08-04 15:00 40960 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002187.exe
2004-08-04 15:00 22016 C:\WINDOWS\system32\runonce.exe
2004-08-04 15:00 22016 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002073.exe
2004-08-04 15:00 139264 C:\WINDOWS\system32\sndrec32.exe
2004-08-04 15:00 139264 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002226.exe
2004-08-04 15:00 146432 C:\WINDOWS\system32\sndvol32.exe
2004-08-04 15:00 146432 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002227.exe
2004-08-04 15:00 64512 C:\WINDOWS\system32\sol.exe
2004-08-04 15:00 64512 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002272.exe
2004-08-04 15:00 31232 C:\WINDOWS\system32\sort.exe
2004-08-04 15:00 31232 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002081.exe
2004-08-04 15:00 31232 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002191.exe
2004-08-04 15:00 546304 C:\WINDOWS\system32\spider.exe
2004-08-04 15:00 546304 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002273.exe
C:\WINDOWS\system32\tdssinit.dll
2008-09-19 11:35 53285 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002167.dll
2004-08-04 15:00 32256 C:\WINDOWS\system32\userinit.exe
2004-08-04 15:00 32256 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002185.exe
2006-03-17 03:38 36352 C:\WINDOWS\system32\verclsid.exe
2006-03-17 03:38 36352 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002075.exe
2006-03-17 03:38 36352 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002207.exe
2004-08-04 15:00 225792 C:\WINDOWS\system32\wbem\wmiprvse.exe
2004-08-04 15:00 225792 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002183.exe
2004-08-04 15:00 127488 C:\WINDOWS\system32\winmine.exe
2004-08-04 15:00 127488 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002270.exe
2008-07-18 22:10 53448 C:\WINDOWS\system32\wuauclt.exe
2008-07-18 22:10 53448 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002182.exe
2004-08-04 15:00 39936 C:\WINDOWS\system32\wupdmgr.exe
2004-08-04 15:00 39936 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002211.exe
C:\WINDOWS\vmgspntbqvm.dll
2008-09-16 18:34 372736 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002170.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\River Past\\Crazi Video\\CraziVideo.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;C:\WINDOWS\system32\DRIVERS\el575nd5.sys [2001-08-17 22:10]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-09-19 08:11]
S2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-19 08:11]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-19 08:11]
S2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-09-19 08:11]
.
Contents of the 'Scheduled Tasks' folder
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-20 12:37:29
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Completion time: 2008-09-20 12:41:09 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-09-20 16:41:06
ComboFix2.txt 2008-09-20 08:40:34
Pre-Run: 39,181,025,280 bytes free
Post-Run: 39,014,985,728 bytes free
569 — E O F — 2008-09-17 07:00:22