ComboFix Log
ComboFix 08-05-27.4 - Owner 2008-05-28 16:29:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.554 [GMT -4:00]
Running from: F:\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\byXRijhh.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-28 )))))))))))))))))))))))))))))))
.
2008-05-26 23:00 . 2008-05-26 23:00 <DIR> d-------- C:\Program Files\UltraSurf
2008-05-26 23:00 . 2008-05-26 23:05 <DIR> d-------- C:\Program Files\Pocket Tanks Deluxe 1.3
2008-05-26 18:09 . 2008-05-26 18:09 <DIR> d-------- C:\VundoFix Backups
2008-05-26 11:20 . 2007-05-31 08:44 740,442 --a------ C:\WINDOWS\system32\divx.dll
2008-05-26 11:20 . 2007-07-29 17:51 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-05-26 11:20 . 2007-07-10 18:10 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-05-26 11:00 . 2008-05-26 11:00 <DIR> d-------- C:\Program Files\CCleaner
2008-05-22 16:52 . 2008-05-22 16:52 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN\Application Data\AdobeUM
2008-05-21 22:21 . 2008-05-21 22:21 139 --a------ C:\WINDOWS\wininit.ini
2008-05-21 21:32 . 2004-03-29 04:06 90,464 --a------ C:\WINDOWS\system32\drivers\MarvinBus.sys
2008-05-21 21:32 . 2002-03-19 10:29 14,165 --a------ C:\WINDOWS\system32\drivers\Pclepci.sys
2008-05-21 21:29 . 2002-01-05 04:48 974,848 --a------ C:\WINDOWS\system32\MFC70.DLL
2008-05-21 21:28 . 2008-05-21 21:30 <DIR> d-------- C:\Program Files\Pinnacle
2008-05-21 21:28 . 2008-05-21 21:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle
2008-05-21 16:07 . 2008-05-21 16:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-05-20 13:39 . 2008-05-20 13:39 18,816 --a------ C:\WINDOWS\system32\drivers\dvd43llh.sys
2008-05-20 13:38 . 2008-05-20 22:18 181 --a------ C:\WINDOWS\system32\sam.ini
2008-05-20 13:24 . 2008-05-20 13:24 <DIR> d-------- C:\New Folder
2008-05-17 10:09 . 2008-05-17 10:09 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-16 19:51 . 2008-05-21 21:11 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN\Application Data\Apple Computer
2008-05-16 19:51 . 2008-05-28 16:36 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-16 19:51 . 2008-05-16 19:51 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-16 19:50 . 2008-05-16 19:51 <DIR> d-------- C:\Program Files\iTunes
2008-05-16 19:50 . 2008-05-16 19:50 <DIR> d-------- C:\Program Files\iPod
2008-05-16 19:46 . 2008-05-16 19:46 <DIR> d-------- C:\Program Files\QuickTime
2008-05-16 19:46 . 2008-05-16 19:46 <DIR> d-------- C:\Program Files\Bonjour
2008-05-16 19:46 . 2008-05-16 19:46 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN\Application Data\Media Player Classic
2008-05-16 19:46 . 2008-05-16 19:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-16 19:45 . 2008-05-16 19:45 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-05-16 19:45 . 2008-05-16 19:45 <DIR> d-------- C:\Program Files\Apple Software Update
2008-05-16 19:45 . 2008-05-16 19:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-05-16 17:04 . 2008-05-16 19:50 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN\Application Data\McAfee.com Personal Firewall
2008-05-16 17:04 . 2008-05-16 17:04 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
2008-05-15 22:24 . 2008-05-21 21:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-15 21:38 . 2008-05-15 21:38 <DIR> d-------- C:\Program Files\ZUMA
2008-05-15 21:38 . 2008-05-15 21:38 <DIR> d-------- C:\Program Files\Windows Defender
2008-05-15 21:37 . 2008-05-15 21:37 <DIR> d-------- C:\Program Files\Webroot
2008-05-15 21:37 . 2008-05-15 21:37 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-15 21:37 . 2008-05-15 21:37 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-05-15 21:36 . 2008-05-15 21:36 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-05-15 21:35 . 2008-05-15 21:35 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-05-15 21:35 . 2008-05-15 21:35 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-05-15 21:35 . 2008-05-15 21:35 <DIR> d-------- C:\Program Files\MSBuild
2008-05-15 21:34 . 2008-05-15 21:35 <DIR> d-------- C:\Program Files\Motorola Phone Tools
2008-05-15 21:32 . 2008-05-15 21:32 <DIR> d-------- C:\Program Files\Microsoft Web Designer Tools
2008-05-15 21:22 . 2008-05-15 21:32 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-05-15 21:22 . 2008-05-15 21:22 <DIR> d-------- C:\Program Files\Microsoft Visual Studio .NET 2003
2008-05-15 21:22 . 2008-05-15 21:22 <DIR> d-------- C:\Program Files\Microsoft Synchronization Services
2008-05-15 21:22 . 2008-05-15 21:22 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-05-15 21:18 . 2008-05-15 21:21 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-05-15 21:17 . 2008-05-15 21:17 <DIR> d-------- C:\Program Files\Microsoft Small Business
2008-05-15 21:17 . 2008-05-15 21:17 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-05-15 21:13 . 2008-05-15 21:13 <DIR> d-------- C:\Program Files\Microsoft SDKs
2008-05-15 21:08 . 2008-05-15 21:08 <DIR> d-------- C:\Program Files\MagicISO
2008-05-15 21:08 . 2008-05-26 11:21 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-05-15 21:06 . 2008-05-15 21:06 <DIR> d-------- C:\Program Files\GGE909 PC Recoil Pad
2008-05-15 21:00 . 2008-05-15 21:00 <DIR> d-------- C:\Program Files\Game Elements
2008-05-15 21:00 . 2008-05-15 21:00 <DIR> d-------- C:\Program Files\Free DVD MP3 Ripper
2008-05-15 21:00 . 2008-05-20 13:39 <DIR> d-------- C:\Program Files\dvd43
2008-05-15 21:00 . 2008-05-15 21:00 <DIR> d-------- C:\Program Files\Datel
2008-05-15 21:00 . 2008-05-15 21:00 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-05-15 20:55 . 2008-05-15 20:55 <DIR> d-------- C:\Program Files\CMAK
2008-05-15 20:55 . 2008-05-15 20:55 <DIR> d-------- C:\Program Files\Avanquest update
2008-05-15 20:55 . 2008-05-15 20:55 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-05-15 20:54 . 2008-05-15 20:54 <DIR> d-------- C:\Program Files\ADMIN TOOLS
2008-05-15 20:54 . 2008-05-15 20:54 <DIR> d-------- C:\Program Files\activePDF
2008-05-15 19:14 . 2008-05-15 19:14 0 --a------ C:\Documents and Settings\Owner.NON-POLITICIAN\Application Data\wklnhst.dat
2008-05-15 18:05 . 2008-05-15 18:05 <DIR> d-------- C:\Program Files\Audacity
2008-05-15 18:03 . 2008-05-15 18:03 <DIR> d-------- C:\Program Files\Windows Resource Kits
2008-05-15 17:58 . 2008-05-15 17:59 <DIR> d-------- C:\Program Files\Samurize
2008-05-15 17:57 . 2008-05-15 17:57 <DIR> d-------- C:\Program Files\Rainlendar
2008-05-15 17:57 . 2008-05-15 21:01 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN\Application Data\Rainlendar
2008-05-15 01:05 . 2008-05-21 21:09 26 --a------ C:\WINDOWS\popcinfo.dat
2008-05-15 00:18 . 2008-05-21 16:07 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN\Application Data\PlayFirst
2008-05-14 22:37 . 2008-05-14 22:37 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN\Application Data\WildTangent
2008-05-14 21:03 . 2008-05-14 21:03 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN\Application Data\CyberLink
2008-05-14 20:32 . 2006-10-04 10:06 1,197,294 --a--c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-05-14 20:32 . 2006-10-04 10:06 764,868 --a--c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-05-14 20:32 . 2006-10-04 10:06 217,118 --a--c--- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-05-14 20:31 . 2008-05-14 20:31 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-05-14 20:30 . 2008-05-14 20:30 <DIR> d-------- C:\80c8ec2e7307d5f604
2008-05-14 20:29 . 2008-05-14 20:29 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-05-14 20:29 . 2008-05-14 20:30 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-05-14 20:17 . 2008-05-14 20:17 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-05-14 20:05 . 2008-05-14 09:59 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN\WINDOWS
2008-05-14 20:05 . 2008-05-14 10:44 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN\Application Data\You've Got Pictures Screensaver
2008-05-14 20:05 . 2008-05-14 10:46 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN\Application Data\SampleView
2008-05-14 20:05 . 2008-05-14 10:56 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN\Application Data\Intel
2008-05-14 20:05 . 2008-05-26 22:52 <DIR> d-------- C:\Documents and Settings\Owner.NON-POLITICIAN
2008-05-14 20:04 . 2008-05-14 09:59 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\WINDOWS
2008-05-14 20:04 . 2008-05-14 10:44 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\You've Got Pictures Screensaver
2008-05-14 20:04 . 2008-05-14 10:46 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\SampleView
2008-05-14 11:09 . 2008-05-14 11:09 8,192 --a------ C:\WINDOWS\REGLOCS.OLD
2008-05-14 11:04 . 2008-05-14 11:04 333 --a------ C:\WINDOWS\system32\$ncsp$.inf
2008-05-14 11:04 . 2008-05-14 11:04 0 --a------ C:\WINDOWS\system32\Gateway_MX6956_Rev.1_T3A6A41004121.MRK
2008-05-14 11:03 . 2006-03-23 15:12 139,264 --a------ C:\WINDOWS\system32\igfxres.dll
2008-05-14 11:02 . 2008-05-17 09:48 34,400 --a------ C:\WINDOWS\system32\Status.MPF
2008-05-14 10:57 . 2006-04-21 02:12 332,800 --a--c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-05-14 10:57 . 2006-06-22 06:47 181,248 --a--c--- C:\WINDOWS\system32\dllcache\rasmans.dll
2008-05-14 10:57 . 2006-05-19 08:59 148,480 --a--c--- C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-05-14 10:57 . 2006-05-19 08:59 111,616 --a--c--- C:\WINDOWS\system32\dllcache\dhcpcsvc.dll
2008-05-14 10:57 . 2006-05-19 08:59 94,720 --a--c--- C:\WINDOWS\system32\dllcache\iphlpapi.dll
2008-05-14 10:56 . 2008-05-14 10:56 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel
2008-05-14 10:55 . 2008-05-16 19:45 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-05-14 10:55 . 2008-05-14 10:56 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Intel
2008-05-14 10:55 . 2008-05-14 10:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Intel
2008-05-14 10:55 . 2008-05-14 10:55 21,275 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2008-05-14 10:54 . 2008-05-14 10:54 <DIR> d-------- C:\Program Files\McAfee
2008-05-14 10:54 . 2008-05-16 19:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
2008-05-14 10:54 . 2008-05-14 10:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-05-14 10:54 . 2008-05-14 10:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-05-14 10:52 . 2008-05-14 10:52 <DIR> d-------- C:\Program Files\gtw_logo
2008-05-14 10:52 . 2008-05-14 20:04 <DIR> d-------- C:\Documents and Settings\Owner
2008-05-14 10:52 . 2006-02-06 15:24 1,239,209 --a------ C:\WINDOWS\system32\gtw_logo.scr
2008-05-14 10:52 . 2003-07-03 18:48 23,552 --a------ C:\WINDOWS\system32\jesterss.dll
2008-05-14 10:52 . 2006-04-21 12:50 1,150 --a------ C:\WINDOWS\system32\gtw.ico
2008-05-14 10:49 . 2008-05-14 10:49 <DIR> d-------- C:\WINDOWS\tiinst
2008-05-14 10:47 . 2008-05-14 10:47 <DIR> d-------- C:\Program Files\Motorola
2008-05-14 10:46 . 2008-05-14 10:46 <DIR> d-------- C:\Program Files\SigmaTel
2008-05-14 10:46 . 2008-05-14 10:46 <DIR> d-------- C:\Program Files\Microsoft Money 2006
2008-05-14 10:46 . 2008-05-14 10:46 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2008-05-14 10:46 . 2006-06-15 18:28 1,179,784 --a------ C:\WINDOWS\system32\drivers\sthda.sys
2008-05-14 10:46 . 2006-06-15 18:24 217,088 --a------ C:\WINDOWS\system32\stacapi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-14 14:43 8,552 ----a-w C:\WINDOWS\system32\drivers\asctrm.sys
2008-05-14 13:59 --------- d-----w C:\Program Files\Windows Plus
2008-05-14 13:59 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-14 13:59 --------- d-----w C:\Program Files\Common Files\New Boundary
2008-05-14 13:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Prism Deploy
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-05-20 12:34 171448]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 19:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 23:56 64512]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-14 10:33 169984]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 10:47 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 10:47 688218]
"HostManager"="C:\Program Files\Common Files\AOL\1210776190\EE\AOLHostManager.exe" [2004-11-03 17:03 125528]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 20:42 79448]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 15:30 139264]
"SigmatelSysTrayApp"="stsystra.exe" [2005-12-27 13:20 413696 C:\WINDOWS\stsystra.exe]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-05-23 22:22 573440]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 15:17 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 15:13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 15:17 118784]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 14:55 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 14:56 602182]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 14:18 267048]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 19:16 1121792]
"pccguide.exe"="C:\Program Files\Trend Micro\Antivirus\pccguide.exe" [2004-02-17 18:51 950337]
"PCClient.exe"="C:\Program Files\Trend Micro\Antivirus\PCClient.exe" [2004-02-17 18:51 634949]
"TM Outbreak Agent"="C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" [2004-02-17 18:50 290816]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [2007-11-20 16:40 731136]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2004-03-10 16:26 406016]
C:\Documents and Settings\Owner.NON-POLITICIAN\Start Menu\Programs\Startup\
Spybot - S&D.lnk - C:\Program Files\Spybot - Search & Destroy\SDMain.exe [2008-04-07 17:55:32 414544]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2008-05-14 10:37:34 2168360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll
"msacm.ac3filter"= ac3filter.acm
"msacm.divxa32"= divxa32.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1210776190\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
.
Contents of the 'Scheduled Tasks' folder
"2008-05-16 23:45:55 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-15 00:04:47 C:\WINDOWS\Tasks\ISP signup reminder 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2008-05-28 20:38:58 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-28 16:36:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\COMMON~1\AOL\121077~1\EE\AOLServiceHost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopMail.exe
.
**************************************************************************
.
Completion time: 2008-05-28 16:42:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-28 20:41:59
Pre-Run: 51,723,718,656 bytes free
Post-Run: 51,820,269,568 bytes free
275