And the end:
Sorry about the 3 replys, I couldnt get it to fit right... I've put virustotal on the end, to save an extra post
Heres the rest:
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\repair
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\Provisioning
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\PeerNet
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\pchealth
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\mui
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\msapps
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\msagent
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\Media
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\java
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\ime
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\Help
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\ehome
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\Driver Cache
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\Debug
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\Cursors
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\Connection Wizard
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\Config
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\AppPatch
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\addins
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS\.
2006-11-30 00:52 <DIR> d-------- C:\WINDOWS
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
"Xzqebrpy"="C:\\WINDOWS\\system32\\?dobe\\l?ass.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"RTHDCPL"="RTHDCPL.EXE"
"SkyTel"="SkyTel.EXE"
"Alcmtr"="ALCMTR.EXE"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
"itype"="\"C:\\Program Files\\Microsoft IntelliType Pro\\itype.exe\""
"IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\ipoint.exe\""
"{B4BDA421-08A2-1033-0910-06011006002c}"="\"C:\\Program Files\\Common Files\\{B4BDA421-08A2-1033-0910-06011006002c}\\Update.exe\" mc-110-12-0000137"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"{B4BDA421-08A2-1033-0910-060110060001}"="\"C:\\Program Files\\Common Files\\{B4BDA421-08A2-1033-0910-060110060001}\\Update.exe\" mc-110-12-0000137"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,ea,00,00,00,00,00,00,00,16,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Completion time: 06-12-19 20:42:24.51
C:\ComboFix.txt ... 06-12-19 20:42
-----
Virustotal
-----
STATUS: FINISHEDComplete scanning result of "svchosts.exe", received in VirusTotal at 12.19.2006, 21:59:34 (CET).
Antivirus Version Update Result
AntiVir 7.3.0.19 12.19.2006 no virus found
Authentium 4.93.8 12.19.2006 no virus found
Avast 4.7.892.0 12.19.2006 no virus found
AVG 386 12.19.2006 no virus found
BitDefender 7.2 12.19.2006 no virus found
CAT-QuickHeal 8.00 12.19.2006 no virus found
ClamAV devel-20060426 12.19.2006 no virus found
DrWeb 4.33 12.19.2006 no virus found
eSafe 7.0.14.0 12.19.2006 no virus found
eTrust-InoculateIT 23.73.89 12.19.2006 no virus found
eTrust-Vet 30.3.3262 12.19.2006 no virus found
Ewido 4.0 12.19.2006 no virus found
Fortinet 2.82.0.0 12.19.2006 no virus found
F-Prot 3.16f 12.15.2006 no virus found
F-Prot4 4.2.1.29 12.19.2006 no virus found
Ikarus T3.1.0.27 12.19.2006 no virus found
Kaspersky 4.0.2.24 12.19.2006 no virus found
McAfee 4922 12.19.2006 no virus found
Microsoft 1.1904 12.19.2006 no virus found
NOD32v2 1929 12.19.2006 no virus found
Norman 5.80.02 12.19.2006 W32/Softomate.EH.dropper
Panda 9.0.0.4 12.19.2006 Adware/Mytoolbar
Prevx1 V2 12.19.2006 Trojan.SystemPoser
Sophos 4.12.0 12.18.2006 no virus found
Sunbelt 2.2.907.0 12.18.2006 no virus found
TheHacker 6.0.3.134 12.18.2006 no virus found
UNA 1.83 12.19.2006 no virus found
VBA32 3.11.1 12.19.2006 no virus found
VirusBuster 4.3.19:9 12.19.2006 no virus found
Aditional Information
File size: 36864 bytes
MD5: 3fe5755470a1c9c223ac25944c0161fd
SHA1: 36c92adc1ca2ee0211124187cb2678c008b85958
norman sandbox: [ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO:
ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* File length: 36864 bytes.
[ Changes to filesystem ]
* Deletes file C:WINDOWS{837F873E-0000-1044--popo0000}.
* Creates directory C:WINDOWS{837F873E-0000-1044--popo0000}.
* Creates file C:WINDOWS{837F873E-0000-1044--popo0000}directorexe.lzma.
* Creates file C:WINDOWS{837F873E-0000-1044--popo0000}Update.exe.
* Deletes file C:WINDOWS{837F873E-0000-1044--popo0000}directorexe.lzma.
* Deletes file C:WINDOWS{837F873E-0000-1044--popo0000}directordll.lzma.
[ Changes to registry ]
* Creates key "HKLMSoftwareHARDWAREDESCRIPTIONSystemCentralProcessor
Prevx info:
http://fileinfo.prevx.com/fileinfo.asp?PXC=6f6363243327