PDA

View Full Version : Virtumonde, MyWay, MyWebSearch



Fred of Kings Lynn
2008-09-15, 19:09
Hello,
I used a BT Torrent a little while back not knowing much about what's it all about. Things started to go wrong pretty quickly, so I deleted all the programmes I could find that were related to them.

Internet explorer and Firefox started doing things on there own, i.e. down loading web pages and asking permission to install virus software. Google would not work, nor Altavista or Ebay.

I have the latest version on McAfee Security Suite. - Out of the blue McAfee would let me know it has stopped a virus called VUNDO. After a while I knew I needed more help, a friend highly recommended, SPYBOT. Spybot recognised 35 trojens and deleted nearly all of them bar ones called Virtumonde and MyWeb, MyWebSearch pups. I have followed the instructions and allowed Spybot to run and start up, but these files and more seem to re- appear.

There is also a Windows Security Alert, say automatic updates is off, I can not seem to change this.

Please help me.


Fred of Kings Lynn, Norfolk, United Kingdom

Fred of Kings Lynn
2008-09-16, 00:25
Hello,
I used a BT Torrent a little while back not knowing much about what's it all about. Things started to go wrong pretty quickly, so I deleted all the programmes I could find that were related to them.

Internet explorer and Firefox started doing things on there own, i.e. down loading web pages and asking permission to install virus software. Google would not work, nor Altavista or Ebay.

I have the latest version on McAfee Security Suite. - Out of the blue McAfee would let me know it has stopped a virus called VUNDO. After a while I knew I needed more help, a friend highly recommended, SPYBOT. Spybot recognised 35 trojens and deleted nearly all of them bar ones called Virtumonde and MyWeb, MyWebSearch pups. I have followed the instructions and allowed Spybot to run and start up, but these files and more seem to re- appear.

There is also a Windows Security Alert, say automatic updates is off, I can not seem to change this.

Please help me.


Fred of Kings Lynn, Norfolk, United Kingdom

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:17:17, on 15/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\cidaemon.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tiscali
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.co.uk/"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CNetscape_UK.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [McAfee Backup] "C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe"
O4 - HKLM\..\Run: [1cc111c4] rundll32.exe "C:\WINDOWS\system32\txusgqsx.dll",b
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3662] command /c del "C:\WINDOWS\system32\bwcasgdk.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC500] cmd /c del "C:\WINDOWS\system32\bwcasgdk.dll_old"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB820] command /c del "C:\WINDOWS\system32\bwcasgdk.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7650] cmd /c del "C:\WINDOWS\system32\bwcasgdk.dll_old"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{865FD82A-61A9-40E1-B551-DB3C7F08964C}: NameServer = 212.139.132.10 212.139.132.11
O20 - AppInit_DLLs: ragrma.dll ijcmni.dll
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O24 - Desktop Component 0: (no name) - http://news.bbc.co.uk/

--
End of file - 9195 bytes

Shaba
2008-09-20, 12:02
Hi Fred of Kings Lynn

To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.

You will now be presented with a screen similar to the one below:

http://img.bleepingcomputer.com/tutorials/hijackthis/uninstall-man.jpg

5. Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.

Fred of Kings Lynn
2008-09-20, 13:32
Thank you for your assistance.
When I press the SAVE LIST button, the whole programme closes and nothing else happens. Have tried this several times, I can not even copy and paste the list.

Shaba
2008-09-20, 14:18
Thank you for information.

Then we'll use this:

Download random's system information tool (RSIT) by random/random from here (http://images.malwareremoval.com/random/RSIT.exe) and save it to your desktop.
Double click on RSIT.exe to run RSIT.
Click Continue at the disclaimer screen.
Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

Fred of Kings Lynn
2008-09-20, 16:57
Logfile of random's system information tool 1.02 (written by random/random)
Run by Owner at 2008-09-20 14:51:50
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 5 GB (24%) free of 20 GB
Total RAM: 383 MB (29% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:52:07, on 20/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\cidaemon.exe
c:\PROGRA~1\mcafee\msc\mcshell.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Owner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tiscali
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.co.uk/"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CNetscape_UK.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: (no name) - {4849B01B-0C40-428A-A885-185F11CACCC6} - C:\WINDOWS\system32\urqOFwuV.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [McAfee Backup] "C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe"
O4 - HKLM\..\Run: [1cc111c4] rundll32.exe "C:\WINDOWS\system32\mycnytnb.dll",b
O4 - HKLM\..\Run: [BM1ff22258] Rundll32.exe "C:\WINDOWS\system32\qkqaqslw.dll",s
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{865FD82A-61A9-40E1-B551-DB3C7F08964C}: NameServer = 212.139.132.37 212.139.132.36
O20 - AppInit_DLLs: ragrma.dll ttrxyk.dll
O20 - Winlogon Notify: wvUljKAT - wvUljKAT.dll (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O24 - Desktop Component 0: (no name) - http://news.bbc.co.uk/

--
End of file - 9391 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Disk Cleanup.job
C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job
C:\WINDOWS\tasks\XoftSpySE 2.job
C:\WINDOWS\tasks\XoftSpySE.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{089FD14D-132B-48FC-8861-0048AE113215}]
C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4849B01B-0C40-428A-A885-185F11CACCC6}]
C:\WINDOWS\system32\urqOFwuV.dll [2008-09-09 237056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-07-07 1562448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-08-04 343112]
{0BF43445-2F28-4351-9252-17FE6E806AA0} - McAfee SiteAdvisor - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]
{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - Ask Toolbar - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2008-09-09 262144]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"adiras"=adiras.exe []
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"EEventManager"=C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2005-04-08 102400]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2008-07-11 641208]
"SiteAdvisor"=C:\Program Files\SiteAdvisor\6172\SiteAdv.exe [2007-08-24 36640]
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe [2008-06-13 1176808]
"McAfee Backup"=C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe [2008-07-10 5129504]
"1cc111c4"=C:\WINDOWS\system32\mycnytnb.dll [2008-09-19 88064]
"BM1ff22258"=C:\WINDOWS\system32\qkqaqslw.dll [2008-09-19 97280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Spybot - Search & Destroy"=C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe [2008-07-07 4891472]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-08-18 1832272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus COLOR 580]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_AICN03.EXE /P22 EPSON Stylus COLOR 580 /O6 USB001 /M Stylus COLOR 580 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\System32\NeroCheck.exe [2001-07-09 155648]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
EPSON Background Monitor.lnk - C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="ragrma.dll ttrxyk.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvUljKAT]
wvUljKAT.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\urqOFwuV

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispCPL"=0
"NoDispAppearancePage"=0
"NoDispSettingsPage"=0
"NoDispScrSavPage"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoActiveDesktop"=0
"NoViewContextMenu"=0
"NoWinKeys"=0
"NoFileAssociate"=0
"NoFolderOptions"=0
"NoFind"=0
"NoRun"=0
"NoClose"=0
"NoCommonGroups"=0
"NoSimpleStartMenu"=0
"HideClock"=0
"StartMenuLogoff"=0
"NoTrayContextMenu"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\fxsclnt.exe"="C:\WINDOWS\system32\fxsclnt.exe:*:Disabled:Microsoft Fax Console"
"C:\Program Files\ws ftp tiscali\WS_FTP95.exe"="C:\Program Files\ws ftp tiscali\WS_FTP95.exe:*:Enabled:WS_FTP 95"
"C:\Program Files\Abacast\Abaclient.exe"="C:\Program Files\Abacast\Abaclient.exe:*:Enabled:Abaclient"
"C:\Program Files\Netscape\Netscape\Netscp.exe"="C:\Program Files\Netscape\Netscape\Netscp.exe:*:Enabled:Netscp"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\WINDOWS\system32\mpxa.exe"="C:\WINDOWS\system32\mpxa.exe:*:Disabled:mpxa"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b3ab410-5bbe-11dd-88c4-4d6564696130}]
shell\AutoRun\command - G:\InstallTomTomHOME.exe


======List of files/folders created in the last 1 months======

2008-09-20 14:51:50 ----D---- C:\rsit
2008-09-20 14:43:27 ----A---- C:\WINDOWS\system32\mcrh.tmp
2008-09-19 17:10:29 ----SH---- C:\WINDOWS\system32\bntyncym.ini
2008-09-19 17:10:29 ----A---- C:\WINDOWS\system32\mycnytnb.dll
2008-09-19 17:07:28 ----A---- C:\WINDOWS\system32\fotchwkr.dll
2008-09-19 17:01:28 ----A---- C:\WINDOWS\system32\qkqaqslw.dll
2008-09-19 16:52:34 ----SH---- C:\WINDOWS\system32\dkvtvfui.ini
2008-09-19 16:49:28 ----A---- C:\WINDOWS\system32\skwgfl.dll
2008-09-19 16:49:27 ----A---- C:\WINDOWS\system32\wlwebiqc.dll
2008-09-19 16:49:11 ----A---- C:\WINDOWS\pskt.ini
2008-09-19 16:49:09 ----A---- C:\WINDOWS\system32\lssxmytt.dll
2008-09-18 16:34:34 ----A---- C:\WINDOWS\system32\ihjedy.dll
2008-09-18 16:34:31 ----A---- C:\WINDOWS\system32\bgqvvwiq.dll
2008-09-18 16:31:31 ----SH---- C:\WINDOWS\system32\jqtqrkvs.ini
2008-09-18 16:28:31 ----A---- C:\WINDOWS\system32\qbtmatry.dll
2008-09-18 15:37:32 ----A---- C:\WINDOWS\system32\gjdofe.dll
2008-09-18 15:37:31 ----A---- C:\WINDOWS\system32\haakyota.dll
2008-09-18 15:34:33 ----SH---- C:\WINDOWS\system32\lrouswmc.ini
2008-09-17 15:35:12 ----A---- C:\WINDOWS\system32\gxormo.dll
2008-09-17 15:35:12 ----A---- C:\WINDOWS\system32\bdtkxnry.dll
2008-09-17 15:32:24 ----SH---- C:\WINDOWS\system32\igpyvsyv.ini
2008-09-16 15:34:26 ----A---- C:\WINDOWS\system32\ydoykanq.dll
2008-09-16 15:34:26 ----A---- C:\WINDOWS\system32\xbqgdz.dll
2008-09-16 15:31:26 ----SH---- C:\WINDOWS\system32\wtvtggdl.ini
2008-09-15 22:16:20 ----D---- C:\Program Files\Trend Micro
2008-09-15 15:34:38 ----A---- C:\WINDOWS\wininit.ini
2008-09-15 15:26:37 ----SH---- C:\WINDOWS\system32\xsqgsuxt.ini
2008-09-15 14:21:06 ----SH---- C:\WINDOWS\system32\riqemavm.ini
2008-09-14 09:45:42 ----SH---- C:\WINDOWS\system32\esvfxbqv.ini
2008-09-14 09:06:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\getuname.dll
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\charmap.exe
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\calc.exe
2008-09-14 08:14:49 ----D---- C:\Program Files\MSN
2008-09-13 02:20:14 ----D---- C:\Program Files\XoftSpySE
2008-09-11 21:00:46 ----D---- C:\Program Files\process Explorer
2008-09-10 13:28:48 ----A---- C:\WINDOWS\cookies.ini
2008-09-10 11:12:58 ----SH---- C:\WINDOWS\system32\waohvrpw.ini
2008-09-09 17:55:11 ----D---- C:\Documents and Settings\Owner\Application Data\Nero
2008-09-09 17:49:55 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2008-09-09 17:36:01 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2008-09-09 17:36:00 ----D---- C:\Program Files\Common Files\Nero
2008-09-09 17:10:59 ----A---- C:\WINDOWS\BM1ff22258.txt
2008-09-09 16:57:28 ----A---- C:\WINDOWS\system32\17e2d5ba-.txt
2008-09-09 16:53:13 ----ASH---- C:\WINDOWS\system32\VuwFOqru.ini2
2008-09-09 16:52:51 ----ASH---- C:\WINDOWS\system32\VuwFOqru.ini
2008-09-09 16:52:20 ----A---- C:\WINDOWS\system32\urqOFwuV.dll
2008-09-09 12:18:29 ----D---- C:\Documents and Settings\All Users\Application Data\Azureus
2008-09-09 12:18:22 ----D---- C:\Documents and Settings\Owner\Application Data\Azureus
2008-09-09 12:18:02 ----D---- C:\Program Files\AskSBar
2008-09-08 02:00:20 ----D---- C:\Documents and Settings\Owner\Application Data\DivX
2008-09-01 13:43:26 ----A---- C:\WINDOWS\system32\XceedZip.dll
2008-09-01 12:56:43 ----D---- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-01 09:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2008-09-01 09:10:19 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2008-09-01 09:09:32 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-31 11:46:12 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-08-31 11:46:05 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2008-08-31 11:44:06 ----D---- C:\Program Files\Windows Media Connect 2
2008-08-31 11:43:37 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2008-08-31 11:40:48 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2008-08-31 11:39:29 ----D---- C:\WINDOWS\system32\LogFiles
2008-08-31 11:39:14 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2008-08-31 03:13:29 ----D---- C:\Program Files\7-Zip
2008-08-31 02:45:11 ----SHD---- C:\Config.Msi
2008-08-30 11:49:39 ----D---- C:\Documents and Settings\Owner\Application Data\.BitTornado
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxssend.exe
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsroute.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsperf.ini
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsclntR.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxscfgwz.dll
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaws.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaw.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\java.exe
2008-08-24 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-08-23 03:07:59 ----D---- C:\WINDOWS\Prefetch
2008-08-23 02:12:26 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-08-23 02:12:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-08-23 02:11:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-08-23 02:11:38 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-08-23 02:11:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-23 02:11:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-08-23 02:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-08-23 02:10:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-08-23 02:10:21 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-08-23 02:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-08-23 01:59:25 ----D---- C:\WINDOWS\system32\scripting
2008-08-23 01:59:22 ----D---- C:\WINDOWS\l2schemas
2008-08-23 01:59:19 ----D---- C:\WINDOWS\system32\en
2008-08-22 01:10:31 ----N---- C:\WINDOWS\system32\wmphoto.dll
2008-08-22 01:10:24 ----N---- C:\WINDOWS\system32\wlanapi.dll
2008-08-22 01:10:22 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-22 01:10:22 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2008-08-22 01:10:03 ----N---- C:\WINDOWS\system32\tspkg.dll
2008-08-22 01:10:03 ----N---- C:\WINDOWS\system32\tsgqec.dll
2008-08-22 01:09:37 ----N---- C:\WINDOWS\system32\setupn.exe
2008-08-22 01:09:28 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2008-08-22 01:09:24 ----N---- C:\WINDOWS\system32\rasqec.dll
2008-08-22 01:09:23 ----N---- C:\WINDOWS\system32\qutil.dll
2008-08-22 01:09:21 ----N---- C:\WINDOWS\system32\qcliprov.dll
2008-08-22 01:09:20 ----N---- C:\WINDOWS\system32\qagentrt.dll
2008-08-22 01:09:20 ----N---- C:\WINDOWS\system32\qagent.dll
2008-08-22 01:09:17 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-22 01:09:11 ----N---- C:\WINDOWS\system32\onex.dll
2008-08-22 01:08:52 ----N---- C:\WINDOWS\system32\napstat.exe
2008-08-22 01:08:52 ----N---- C:\WINDOWS\system32\napmontr.dll
2008-08-22 01:08:52 ----N---- C:\WINDOWS\system32\napipsec.dll
2008-08-22 01:08:44 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2008-08-22 01:08:44 ----N---- C:\WINDOWS\system32\mssha.dll
2008-08-22 01:08:17 ----N---- C:\WINDOWS\system32\mmcperf.exe
2008-08-22 01:08:16 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-22 01:08:16 ----N---- C:\WINDOWS\system32\mmcex.dll
2008-08-22 01:08:16 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-22 01:07:59 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2008-08-22 01:07:58 ----N---- C:\WINDOWS\system32\kmsvc.dll
2008-08-22 01:07:55 ----N---- C:\WINDOWS\system32\kbdpash.dll
2008-08-22 01:07:55 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2008-08-22 01:07:55 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2008-08-22 01:07:54 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eapsvc.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eapqec.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eappprxy.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eapphost.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eappgnui.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eappcfg.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eapolqec.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3ui.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3svc.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3msm.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3api.dll
2008-08-22 01:07:01 ----N---- C:\WINDOWS\system32\dimsroam.dll
2008-08-22 01:07:01 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2008-08-22 01:07:00 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2008-08-22 01:06:54 ----N---- C:\WINDOWS\system32\credssp.dll
2008-08-22 01:06:37 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2008-08-22 01:06:36 ----N---- C:\WINDOWS\system32\azroles.dll
2008-08-22 01:06:16 ----N---- C:\WINDOWS\system32\aaclient.dll

======List of files/folders modified in the last 1 months======

2008-09-20 14:51:55 ----D---- C:\WINDOWS\Temp
2008-09-20 14:47:58 ----D---- C:\WINDOWS\system32
2008-09-19 18:23:12 ----D---- C:\WINDOWS
2008-09-19 18:17:50 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-09-19 17:00:04 ----D---- C:\Program Files\Mozilla Thunderbird
2008-09-19 12:19:51 ----D---- C:\WINDOWS\system32\FxsTmp
2008-09-19 12:17:52 ----AC---- C:\WINDOWS\ModemLog_Generic 56K HCF Data Fax Modem.txt
2008-09-17 20:20:19 ----D---- C:\WINDOWS\system32\CatRoot2
2008-09-15 22:16:20 ----RD---- C:\Program Files
2008-09-15 22:12:31 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-09-15 16:27:38 ----SHD---- C:\System Volume Information
2008-09-15 16:27:38 ----D---- C:\WINDOWS\system32\Restore
2008-09-14 17:43:59 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-14 13:02:05 ----D---- C:\WINDOWS\security
2008-09-14 08:27:31 ----D---- C:\Program Files\Mozilla Firefox
2008-09-14 08:16:15 ----A---- C:\WINDOWS\imsins.BAK
2008-09-14 08:15:23 ----D---- C:\Program Files\Online Services
2008-09-14 08:15:06 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-09-14 08:15:06 ----D---- C:\WINDOWS\Cursors
2008-09-14 08:15:00 ----D---- C:\WINDOWS\Help
2008-09-14 08:14:58 ----D---- C:\WINDOWS\system32\wbem
2008-09-13 21:30:31 ----D---- C:\Program Files\Windows NT
2008-09-13 02:20:47 ----SD---- C:\WINDOWS\Tasks
2008-09-12 08:23:11 ----D---- C:\WINDOWS\system32\drivers
2008-09-12 02:08:23 ----HD---- C:\WINDOWS\inf
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Minidump
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Debug
2008-09-12 02:08:22 ----SHD---- C:\WINDOWS\Installer
2008-09-11 02:53:23 ----D---- C:\WINDOWS\system32\en-US
2008-09-11 02:53:23 ----D---- C:\Program Files\Internet Explorer
2008-09-11 02:23:24 ----D---- C:\WINDOWS\system32\CatRoot
2008-09-11 01:39:45 ----D---- C:\Program Files\Common Files
2008-09-11 01:38:54 ----RSD---- C:\WINDOWS\Fonts
2008-09-10 14:00:35 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-10 13:59:15 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-09-10 10:58:11 ----D---- C:\WINDOWS\system32\config
2008-09-10 10:57:42 ----D---- C:\WINDOWS\Registration
2008-09-09 17:15:04 ----D---- C:\WINDOWS\WinSxS
2008-09-08 01:57:54 ----D---- C:\Program Files\ws ftp tiscali
2008-09-02 17:00:33 ----D---- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-09-01 13:11:40 ----HD---- C:\Program Files\InstallShield Installation Information
2008-09-01 12:58:22 ----RSD---- C:\WINDOWS\assembly
2008-08-31 20:21:10 ----AC---- C:\WINDOWS\NeroDigital.ini
2008-08-31 11:50:23 ----D---- C:\Program Files\Windows Media Player
2008-08-31 11:44:45 ----AC---- C:\WINDOWS\win.ini
2008-08-31 02:45:12 ----D---- C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-28 09:48:14 ----D---- C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-08-27 18:16:44 ----D---- C:\WINDOWS\system32\Adobe
2008-08-27 18:16:19 ----D---- C:\Documents and Settings\Owner\Application Data\Adobe
2008-08-27 09:00:26 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-08-26 22:33:21 ----D---- C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-08-26 10:26:22 ----D---- C:\WINDOWS\addins
2008-08-26 10:17:39 ----D---- C:\Program Files\McAfee
2008-08-24 23:22:04 ----D---- C:\Program Files\Java
2008-08-23 12:46:51 ----HD---- C:\WINDOWS\$hf_mig$
2008-08-23 08:03:46 ----AC---- C:\WINDOWS\OEWABLog.txt
2008-08-23 03:08:39 ----AC---- C:\WINDOWS\setuplog.txt
2008-08-23 03:07:19 ----D---- C:\WINDOWS\system32\Setup
2008-08-23 03:07:19 ----D---- C:\WINDOWS\AppPatch
2008-08-23 02:10:05 ----D---- C:\Program Files\Messenger
2008-08-23 02:00:05 ----D---- C:\WINDOWS\ServicePackFiles
2008-08-23 02:00:00 ----D---- C:\WINDOWS\network diagnostic
2008-08-23 01:59:59 ----D---- C:\WINDOWS\ime
2008-08-23 01:59:28 ----D---- C:\WINDOWS\system32\usmt
2008-08-23 01:59:18 ----D---- C:\WINDOWS\system32\bits
2008-08-23 01:59:18 ----D---- C:\WINDOWS\peernet
2008-08-23 01:59:18 ----D---- C:\Program Files\Movie Maker
2008-08-23 01:52:28 ----D---- C:\WINDOWS\system32\npp
2008-08-23 01:52:25 ----D---- C:\WINDOWS\msagent
2008-08-23 01:52:22 ----D---- C:\WINDOWS\srchasst
2008-08-23 01:52:16 ----D---- C:\Program Files\NetMeeting
2008-08-23 01:52:13 ----D---- C:\WINDOWS\system32\Com
2008-08-23 01:52:07 ----D---- C:\Program Files\Outlook Express
2008-08-23 01:52:01 ----D---- C:\Program Files\Common Files\System
2008-08-23 01:51:25 ----D---- C:\WINDOWS\system32\oobe
2008-08-23 01:51:22 ----D---- C:\WINDOWS\system
2008-08-23 01:45:21 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-08-23 01:44:38 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-08-23 01:33:05 ----D---- C:\WINDOWS\EHome
2008-08-22 18:12:04 ----AC---- C:\WINDOWS\CDSEDB01.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ATMhelpr;ATMhelpr; C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 4064]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2008-07-23 9464]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2002-12-17 241152]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2008-06-27 207656]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2008-06-02 120136]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2004-04-08 143834]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2002-12-17 206464]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-18 12032]
R3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2004-03-02 127065]
R3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2004-08-04 327040]
R3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2004-04-08 25898]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704]
R3 HCF_MSFT;HCF_MSFT; C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys [2001-08-17 907456]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2008-06-27 79240]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2008-06-27 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2008-06-27 40488]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NeroCd2k;NeroCd2k; C:\WINDOWS\system32\drivers\NeroCd2k.sys [2001-04-16 44227]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2008-07-23 9336]
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2004-03-02 50007]
S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GT680x;GrandTechICNameNT; C:\WINDOWS\System32\Drivers\gt680x.sys [2001-11-08 18120]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 ICAM3NT5;Intel USB Video Camera III; C:\WINDOWS\System32\Drivers\Icam3.sys [2001-08-17 141056]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2008-06-20 34152]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2004-04-08 30630]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2006-03-30 96341]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [2002-01-30 77824]
R2 EPSONStatusAgent2;EPSON Printer Status Agent2; C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe [2001-10-25 90112]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-08-23 79136]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-06-21 792184]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-07-18 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2008-07-09 358736]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2008-06-20 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2008-07-09 25416]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2008-04-14 33280]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2008-06-20 605512]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MBackMonitor;MBackMonitor; C:\Program Files\McAfee\MBK\MBackMonitor.exe [2008-07-10 66848]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2008-06-20 361800]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------


info.txt logfile of random's system information tool 1.02 2008-09-20 14:52:20

======Uninstall list======

-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
7-Zip 4.57-->"C:\Program Files\7-Zip\Uninstall.exe"
Abacast Client-->C:\PROGRA~1\Abacast\UNWISE.EXE C:\PROGRA~1\Abacast\client.LOG
ABBYY FineReader 6.0 Sprint-->MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
ABClassroom-->C:\WINDOWS\ST5UNST.EXE -n "c:\Documents and Settings\All Users\Documents\ST5UNST.LOG"
Adobe Download Manager 2.0 (Remove Only)-->"C:\Program Files\Common Files\Adobe\ESD\uninst.exe"
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe PhotoDeluxe 2.0-->C:\WINDOWS\uninst.exe -f"C:\Program Files\PhotoDeluxe 2.0\DeIsL1.isu"
Adobe Reader 7.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Adobe Type Manager 4.0-->C:\WINDOWS\uninst.exe -f"C:\Program Files\Adobe Type Manager\DeIsL2.isu" -c"C:\Program Files\Adobe Type Manager\UNINST.DLL"
Apple Software Update-->MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
Ask Toolbar-->rundll32 C:\PROGRA~1\AskSBar\bar\1.bin\AskSBar.dll,O
Canon Camera Access Library-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\CAL\Uninst.ini"
Canon Camera Support Core Library-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\CSCLIB\Uninst.ini"
Canon Camera Window DC_DV 5 for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC\Uninst.ini"
Canon Camera Window DC_DV 6 for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC6\Uninst.ini"
Canon Camera Window MC 6 for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowMC\Uninst.ini"
Canon G.726 WMP-Decoder-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\G726Decoder\G726DecUnInstall.ini"
CANON iMAGE GATEWAY Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\CRWUnInstall.ini"
Canon Internet Library for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\CIGUnInstall.ini"
Canon MovieEdit Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\MVWUninst.ini"
Canon RAW Image Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\RAW Image Task\Uninst.ini"
Canon RemoteCapture Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\RemoteCaptureTask DC\Uninst.ini"
Canon Utilities EOS Utility-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\EOS Utility\Uninst.ini"
Canon Utilities PhotoStitch-->"C:\Program Files\Common Files\Canon\UIW\1.1.0.0\Uninst.exe" "C:\Program Files\Canon\PhotoStitch\Uninst.ini"
Canon Utilities ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.2.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\Uninst.ini"
Easy CD Creator 5 Basic-->MsiExec.exe /I{609F7AC8-C510-11D4-A788-009027ABA5D0}
EasyCleaner-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F5346614-B7C4-4E94-826A-E2363155233D}\setup.exe" -l0x9 -removeonly
EPSON Attach To Email-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x9 -UnInstall
EPSON Event Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{48F22622-1CC2-4A83-9C1E-644DD96F832D}\Setup.exe" -l0x9 -u
EPSON File Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x9 UNINST
EPSON Image Clip Palette-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{314F6D08-A8B7-11D8-8446-0050BA1D384D}\Setup.exe" -l0x9 -u
EPSON Printer Software-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /r
EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x9 -u
EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
EPSON Status Monitor 2-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{87C51198-5A95-4577-9F47-B953D862FA90}
FreeRIP v3.05-->"C:\Program Files\FreeRIP3\unins000.exe"
Graph paper printer-->C:\Documents and Settings\Owner\My Documents\plumbing\Uninstal.exe
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Ipswitch WS_FTP LE-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3A31EEE-7C65-4EE6-BB0D-5549FD2D67B9}\setup.exe" -l0x9
J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
J2SE Runtime Environment 5.0 Update 8-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150080}
Java 2 Runtime Environment, SE v1.4.2_06-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142060}
Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
Macromedia Flash Player 8-->MsiExec.exe /X{6815FCDD-401D-481E-BA88-31B4754C2B46}
Macromedia Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~2\Install.log
McAfee SecurityCenter-->C:\Program Files\McAfee\MSC\mcuninst.exe
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Data Access Components KB870669-->C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2003 Web Components-->MsiExec.exe /I{90A40409-6000-11D3-8CFE-0150048383C9}
Microsoft PowerPoint Viewer 97-->C:\Program Files\PowerPoint Viewer\setup\setup.exe
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Works 6.0-->MsiExec.exe /I{F8D0829C-9C6F-11D3-8080-00C04FA329AA}
Mozilla Thunderbird (2.0.0.16)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Nero - Burning Rom-->MsiExec.exe /X{A4D7B764-4140-11D4-88EB-0050DA3579C0}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Netscape (7.0)-->C:\WINDOWS\NSUninst.exe /ua "7.0 (en)"
Netscape Browser (remove only)-->"C:\Program Files\Netscape\Netscape Browser\NSUninst.exe"
OpenOffice.org 2.2-->MsiExec.exe /I{A1C8D94A-4303-4489-B585-4B6E6CD408CB}
PCGenius FunStation-->C:\Program Files\DEAMM\PcGeniusFunStation\SYSTEM\AUTORUN_.EXE /UNINSTAL
PCGeniusCD-->C:\Program Files\DEAMM\PcGeniusCD\SYSTEM\AUTORUN_.EXE /UNINSTAL
Perf3490P_3590P User's Guide-->C:\Program Files\EPSON\TPMANUAL\Perf3490P_3590P\USE_G\DOCUNINS.EXE
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
Presto! BizCard 4.1 Eng-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\NewSoft\BizCard 4.1 Eng\Uninst.isu" -c"C:\WINDOWS\StiRegstEng.dll"
Print Shop Premier 5.0-->C:\WINDOWS\uninst.exe -f"c:\program files\print shop\Print Shop Premier 5.0\DeIsL1.isu" -c"c:\program files\print shop\Print Shop Premier 5.0\psfinst.dll"
QuickTime-->MsiExec.exe /I{5B09BD67-4C99-46A1-8161-B7208CE18121}
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
SAGEM F@st 800-840-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}\setup.exe" -l0x9
Security Update for Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
TomTom HOME-->C:\Program Files\TomTom HOME 2\Uninstall TomTom HOME.exe
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
VC_MergeModuleToMSI-->MsiExec.exe /I{900A92BA-19EF-4A34-86CF-7B6C85BDD971}
Viewpoint Media Player (Remove Only)-->C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinHTTrack Website Copier 3.33-->"C:\Program Files\WinHTTrack\unins000.exe"
Worcester - Spare Parts Catalog-->C:\WINDOWS\uninstpso.exe tpso-20070706021332
XoftSpySE-->C:\Program Files\XoftSpySE\uninstall.exe
xpTuner LE V1.05-->"C:\Program Files\xpTuner\unins000.exe"
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\unyt.exe
YoPoW 2.9.1-->C:\Documents and Settings\Owner\My Documents\thumbnail album creator\guestbook generator\YoPoW\Uninstall.exe

======Security center information======

AV: McAfee VirusScan
FW: McAfee Personal Firewall

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Adaptec Shared\System;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 1 Stepping 2, GenuineIntel
"PROCESSOR_REVISION"=0102
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip

-----------------EOF-----------------

Shaba
2008-09-20, 17:02
We will continue with ComboFix. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New HijackThis log.

A word of warning: Please do not run ComboFix on your own. This tool is not a toy and not for everyday use.

Fred of Kings Lynn
2008-09-20, 18:34
Thank you

ComboFix 08-09-19.10 - Owner 2008-09-20 15:42:01.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.86 [GMT 1:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Guest\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\BM1ff22258.txt
C:\WINDOWS\BM1ff22258.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.dll
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bntyncym.ini
C:\WINDOWS\system32\dkvtvfui.ini
C:\WINDOWS\system32\esvfxbqv.ini
C:\WINDOWS\system32\igpyvsyv.ini
C:\WINDOWS\system32\jqtqrkvs.ini
C:\WINDOWS\system32\lrouswmc.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\riqemavm.ini
C:\WINDOWS\system32\VuwFOqru.ini
C:\WINDOWS\system32\waohvrpw.ini
C:\WINDOWS\system32\wtvtggdl.ini
C:\WINDOWS\system32\xsqgsuxt.ini

.
((((((((((((((((((((((((( Files Created from 2008-08-20 to 2008-09-20 )))))))))))))))))))))))))))))))
.

2008-09-20 16:03 . 2008-09-20 16:08 742,246 --ahs---- C:\WINDOWS\system32\VuwFOqru.ini
2008-09-20 16:03 . 2008-09-20 16:04 294 ---hs---- C:\WINDOWS\system32\bntyncym.ini
2008-09-20 14:51 . 2008-09-20 14:52 <DIR> d-------- C:\rsit
2008-09-19 17:10 . 2008-09-19 17:10 88,064 --a------ C:\WINDOWS\system32\mycnytnb.dll
2008-09-19 17:07 . 2008-09-19 17:07 112,640 --a------ C:\WINDOWS\system32\fotchwkr.dll
2008-09-19 17:01 . 2008-09-19 17:01 97,280 --a------ C:\WINDOWS\system32\qkqaqslw.dll
2008-09-19 16:49 . 2008-09-19 16:49 112,640 --a------ C:\WINDOWS\system32\wlwebiqc.dll
2008-09-19 16:49 . 2008-09-19 16:49 112,640 --a------ C:\WINDOWS\system32\skwgfl.dll
2008-09-19 16:49 . 2008-09-19 16:49 99,328 --a------ C:\WINDOWS\system32\lssxmytt.dll
2008-09-18 16:34 . 2008-09-18 16:34 112,640 --a------ C:\WINDOWS\system32\ihjedy.dll
2008-09-18 16:34 . 2008-09-18 16:34 112,640 --a------ C:\WINDOWS\system32\bgqvvwiq.dll
2008-09-18 16:28 . 2008-09-18 16:28 99,328 --a------ C:\WINDOWS\system32\qbtmatry.dll
2008-09-18 15:37 . 2008-09-18 15:37 112,640 --a------ C:\WINDOWS\system32\haakyota.dll
2008-09-18 15:37 . 2008-09-18 15:37 112,640 --a------ C:\WINDOWS\system32\gjdofe.dll
2008-09-17 15:35 . 2008-09-17 15:35 112,128 --a------ C:\WINDOWS\system32\gxormo.dll
2008-09-17 15:35 . 2008-09-17 15:35 112,128 --a------ C:\WINDOWS\system32\bdtkxnry.dll
2008-09-16 15:34 . 2008-09-16 15:34 112,128 --a------ C:\WINDOWS\system32\ydoykanq.dll
2008-09-16 15:34 . 2008-09-16 15:34 112,128 --a------ C:\WINDOWS\system32\xbqgdz.dll
2008-09-15 22:16 . 2008-09-15 22:16 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-15 15:34 . 2008-09-18 07:02 150 --a------ C:\WINDOWS\wininit.ini
2008-09-14 09:06 . 2008-09-14 09:19 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-14 08:14 . 2001-08-18 13:00 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2008-09-13 02:20 . 2008-09-13 02:20 <DIR> d-------- C:\Program Files\XoftSpySE
2008-09-11 21:00 . 2008-09-11 21:01 <DIR> d-------- C:\Program Files\process Explorer
2008-09-09 17:55 . 2008-09-09 17:55 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Nero
2008-09-09 17:36 . 2008-09-10 10:57 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-09-09 17:36 . 2008-09-10 10:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-09-09 16:53 . 2008-09-20 16:07 742,246 --ahs---- C:\WINDOWS\system32\VuwFOqru.ini2
2008-09-09 16:52 . 2008-09-09 16:52 237,056 --a------ C:\WINDOWS\system32\urqOFwuV.dll
2008-09-09 12:18 . 2008-09-09 12:18 <DIR> d-------- C:\Program Files\AskSBar
2008-09-09 12:18 . 2008-09-12 02:08 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Azureus
2008-09-09 12:18 . 2008-09-09 12:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-09-08 02:00 . 2008-09-10 10:56 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\DivX
2008-09-08 01:56 . 2008-07-23 17:50 43,528 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-09-01 13:43 . 2007-09-02 20:56 1,686,016 --a------ C:\WINDOWS\system32\clinetsuitex6.ocx
2008-09-01 13:43 . 2004-06-14 14:56 427,864 --a------ C:\WINDOWS\system32\XceedZip.dll
2008-09-01 12:56 . 2008-09-01 12:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-08-31 12:24 . 2000-05-19 17:56 81,920 --a------ C:\WINDOWS\system32\mbmouse.ocx
2008-08-31 12:24 . 2007-08-31 18:36 36,864 --a------ C:\WINDOWS\system32\trayicon_handler.ocx
2008-08-31 11:44 . 2008-08-31 11:44 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-08-31 11:39 . 2008-08-31 11:39 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-08-31 11:39 . 2008-08-31 11:41 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-08-31 03:13 . 2008-08-31 03:13 <DIR> d-------- C:\Program Files\7-Zip
2008-08-30 11:49 . 2008-08-30 11:49 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\.BitTornado
2008-08-26 10:26 . 2001-08-18 13:00 132,608 --a------ C:\WINDOWS\system32\fxsclntR.dll
2008-08-26 10:26 . 2001-08-18 13:00 132,608 --a--c--- C:\WINDOWS\system32\dllcache\fxsclntr.dll
2008-08-26 10:26 . 2001-08-18 13:00 111,104 --a------ C:\WINDOWS\system32\fxscfgwz.dll
2008-08-26 10:26 . 2001-08-18 13:00 111,104 --a--c--- C:\WINDOWS\system32\dllcache\fxscfgwz.dll
2008-08-26 10:26 . 2001-08-18 13:00 31,744 --a------ C:\WINDOWS\system32\fxsroute.dll
2008-08-26 10:26 . 2001-08-18 13:00 31,744 --a--c--- C:\WINDOWS\system32\dllcache\fxsroute.dll
2008-08-26 10:26 . 2001-08-18 13:00 11,264 --a------ C:\WINDOWS\system32\fxssend.exe
2008-08-26 10:26 . 2001-08-18 13:00 11,264 --a--c--- C:\WINDOWS\system32\dllcache\fxssend.exe
2008-08-26 10:26 . 2001-08-18 13:00 1,793 --a------ C:\WINDOWS\system32\fxsperf.ini
2008-08-26 10:26 . 2001-08-18 13:00 1,361 --a------ C:\WINDOWS\system32\fxscount.h
2008-08-23 01:59 . 2008-08-23 01:59 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-23 01:59 . 2008-08-23 01:59 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-23 01:59 . 2008-08-23 01:59 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-22 01:10 . 2008-04-14 01:12 712,704 --------- C:\WINDOWS\system32\windowscodecs.dll
2008-08-22 01:10 . 2008-04-14 01:12 346,112 --------- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-22 01:10 . 2008-04-14 01:12 276,992 --------- C:\WINDOWS\system32\wmphoto.dll
2008-08-22 01:10 . 2008-04-14 01:12 69,120 --------- C:\WINDOWS\system32\wlanapi.dll
2008-08-22 01:10 . 2008-04-14 01:12 53,248 --------- C:\WINDOWS\system32\tsgqec.dll
2008-08-22 01:10 . 2008-04-14 01:12 50,688 --------- C:\WINDOWS\system32\tspkg.dll
2008-08-22 01:09 . 2008-04-14 01:12 412,160 --------- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-22 01:09 . 2008-04-14 01:12 291,328 --------- C:\WINDOWS\system32\qagentrt.dll
2008-08-22 01:09 . 2008-04-14 01:12 290,304 --------- C:\WINDOWS\system32\rhttpaa.dll
2008-08-22 01:09 . 2008-04-14 01:12 150,528 --------- C:\WINDOWS\system32\qagent.dll
2008-08-22 01:09 . 2008-04-14 01:12 144,384 --------- C:\WINDOWS\system32\onex.dll
2008-08-22 01:09 . 2008-04-14 01:12 76,800 --------- C:\WINDOWS\system32\qutil.dll
2008-08-22 01:09 . 2008-04-14 01:12 62,464 --------- C:\WINDOWS\system32\qcliprov.dll
2008-08-22 01:09 . 2008-04-14 01:12 61,952 --------- C:\WINDOWS\system32\rasqec.dll
2008-08-22 01:09 . 2008-04-14 01:12 32,768 --------- C:\WINDOWS\system32\setupn.exe
2008-08-22 01:09 . 2008-04-13 19:40 10,240 --------- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-08-22 01:07 . 2008-04-14 01:11 650,752 --------- C:\WINDOWS\system32\dot3ui.dll
2008-08-22 01:06 . 2008-04-14 01:11 233,472 --------- C:\WINDOWS\system32\azroles.dll
2008-08-22 01:06 . 2008-04-14 01:11 136,192 --------- C:\WINDOWS\system32\aaclient.dll
2008-08-22 01:06 . 2008-04-14 01:11 12,800 --------- C:\WINDOWS\system32\credssp.dll
2008-08-22 01:06 . 2008-04-14 01:11 7,168 --------- C:\WINDOWS\system32\bitsprx4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-19 16:00 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-09-14 16:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-10 13:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-08 00:57 --------- d-----w C:\Program Files\ws ftp tiscali
2008-09-02 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-09-01 12:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-31 01:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-28 08:48 --------- d-----w C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-08-26 21:33 --------- d-----w C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-08-26 09:17 --------- d-----w C:\Program Files\McAfee
2008-08-24 22:22 --------- d-----w C:\Program Files\Java
2008-07-27 09:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\TomTom
2008-07-25 08:34 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-07-23 16:50 9,464 -c----w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-07-23 16:50 9,336 -c----w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 -c--a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 -c--a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-09-09 66912]

[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"EEventManager"="C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2005-04-08 102400]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2008-07-11 641208]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 36640]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2008-06-13 1176808]
"1cc111c4"="C:\WINDOWS\system32\mycnytnb.dll" [2008-09-19 88064]
"BM1ff22258"="C:\WINDOWS\system32\qkqaqslw.dll" [2008-09-19 97280]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-06-18 962660]
EPSON Background Monitor.lnk - C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe [1999-06-07 233984]
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-13 24633]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWinKeys"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=ragrma.dll ttrxyk.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\urqOFwuV

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
---hs---- 2008-04-14 01:12 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a--c--- 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\ws ftp tiscali\\WS_FTP95.exe"=
"C:\\Program Files\\Abacast\\Abaclient.exe"=
"C:\\Program Files\\Netscape\\Netscape\\Netscp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R1 ATMhelpr;ATMhelpr;C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 4064]
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2004-08-04 327040]
R3 NeroCd2k;NeroCd2k;C:\WINDOWS\system32\drivers\NeroCd2k.sys [2001-04-16 44227]
S3 ati2mpaa;ati2mpaa;C:\WINDOWS\system32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
S3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS\system32\Drivers\Icam3.sys [2001-08-17 141056]
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b3ab410-5bbe-11dd-88c4-4d6564696130}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-adiras - adiras.exe
Notify-wvUljKAT - wvUljKAT.dll
MSConfigStartUp-EPSON Stylus COLOR 580 - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_AICN03.EXE


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\q27p3c28.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-GB.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-GB:official
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPMySrch.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 16:03:31
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\SiteAdvisor\6172\saHook.dll
-> C:\WINDOWS\system32\mycnytnb.dll
-> C:\WINDOWS\system32\qkqaqslw.dll
-> C:\WINDOWS\system32\urqOFwuV.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\WINDOWS\system32\snmp.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-09-20 16:15:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-20 15:14:59

Pre-Run: 4,804,542,464 bytes free
Post-Run: 4,839,981,056 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

272 --- E O F --- 2008-09-01 08:10:56







Logfile of random's system information tool 1.02 (written by random/random)
Run by Owner at 2008-09-20 16:24:57
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 5 GB (24%) free of 20 GB
Total RAM: 383 MB (27% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:25:10, on 20/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Owner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.co.uk/"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CNetscape_UK.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: (no name) - {42FEA74B-6462-49F6-959A-2BFD0628CE3E} - C:\WINDOWS\system32\urqOFwuV.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [1cc111c4] rundll32.exe "C:\WINDOWS\system32\mycnytnb.dll",b
O4 - HKLM\..\Run: [BM1ff22258] Rundll32.exe "C:\WINDOWS\system32\qkqaqslw.dll",s
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O20 - AppInit_DLLs: ragrma.dll ttrxyk.dll
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O24 - Desktop Component 0: (no name) - http://news.bbc.co.uk/

--
End of file - 8416 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Disk Cleanup.job
C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job
C:\WINDOWS\tasks\XoftSpySE 2.job
C:\WINDOWS\tasks\XoftSpySE.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{089FD14D-132B-48FC-8861-0048AE113215}]
C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{42FEA74B-6462-49F6-959A-2BFD0628CE3E}]
C:\WINDOWS\system32\urqOFwuV.dll [2008-09-09 237056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-07-07 1562448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-08-04 343112]
{0BF43445-2F28-4351-9252-17FE6E806AA0} - McAfee SiteAdvisor - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]
{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - Ask Toolbar - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2008-09-09 262144]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"EEventManager"=C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2005-04-08 102400]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2008-07-11 641208]
"SiteAdvisor"=C:\Program Files\SiteAdvisor\6172\SiteAdv.exe [2007-08-24 36640]
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe [2008-06-13 1176808]
"1cc111c4"=C:\WINDOWS\system32\mycnytnb.dll [2008-09-19 88064]
"BM1ff22258"=C:\WINDOWS\system32\qkqaqslw.dll [2008-09-19 97280]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-08-18 1832272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\System32\NeroCheck.exe [2001-07-09 155648]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
EPSON Background Monitor.lnk - C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="ragrma.dll ttrxyk.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\urqOFwuV

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoWinKeys"=0
"NoFileAssociate"=0
"NoCommonGroups"=0
"NoSimpleStartMenu"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\fxsclnt.exe"="C:\WINDOWS\system32\fxsclnt.exe:*:Disabled:Microsoft Fax Console"
"C:\Program Files\ws ftp tiscali\WS_FTP95.exe"="C:\Program Files\ws ftp tiscali\WS_FTP95.exe:*:Enabled:WS_FTP 95"
"C:\Program Files\Abacast\Abaclient.exe"="C:\Program Files\Abacast\Abaclient.exe:*:Enabled:Abaclient"
"C:\Program Files\Netscape\Netscape\Netscp.exe"="C:\Program Files\Netscape\Netscape\Netscp.exe:*:Enabled:Netscp"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b3ab410-5bbe-11dd-88c4-4d6564696130}]
shell\AutoRun\command - G:\InstallTomTomHOME.exe


======List of files/folders created in the last 1 months======

2008-09-20 16:15:28 ----A---- C:\ComboFix.txt
2008-09-20 16:15:06 ----A---- C:\WINDOWS\pskt.ini
2008-09-20 16:05:07 ----A---- C:\WINDOWS\BM1ff22258.txt
2008-09-20 16:03:44 ----SH---- C:\WINDOWS\system32\bntyncym.ini
2008-09-20 16:03:43 ----ASH---- C:\WINDOWS\system32\VuwFOqru.ini
2008-09-20 15:41:44 ----A---- C:\Boot.bak
2008-09-20 15:41:32 ----D---- C:\cmdcons
2008-09-20 15:38:36 ----D---- C:\WINDOWS\erdnt
2008-09-20 15:35:43 ----D---- C:\QooBox
2008-09-20 15:34:44 ----A---- C:\WINDOWS\zip.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\swreg.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\sed.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\Nircmd.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\grep.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\VFind.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\swxcacls.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\SWSC.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\fdsv.exe
2008-09-20 14:51:50 ----D---- C:\rsit
2008-09-19 17:10:29 ----A---- C:\WINDOWS\system32\mycnytnb.dll
2008-09-19 17:07:28 ----A---- C:\WINDOWS\system32\fotchwkr.dll
2008-09-19 17:01:28 ----A---- C:\WINDOWS\system32\qkqaqslw.dll
2008-09-19 16:49:28 ----A---- C:\WINDOWS\system32\skwgfl.dll
2008-09-19 16:49:27 ----A---- C:\WINDOWS\system32\wlwebiqc.dll
2008-09-19 16:49:09 ----A---- C:\WINDOWS\system32\lssxmytt.dll
2008-09-18 16:34:34 ----A---- C:\WINDOWS\system32\ihjedy.dll
2008-09-18 16:34:31 ----A---- C:\WINDOWS\system32\bgqvvwiq.dll
2008-09-18 16:28:31 ----A---- C:\WINDOWS\system32\qbtmatry.dll
2008-09-18 15:37:32 ----A---- C:\WINDOWS\system32\gjdofe.dll
2008-09-18 15:37:31 ----A---- C:\WINDOWS\system32\haakyota.dll
2008-09-17 15:35:12 ----A---- C:\WINDOWS\system32\gxormo.dll
2008-09-17 15:35:12 ----A---- C:\WINDOWS\system32\bdtkxnry.dll
2008-09-16 15:34:26 ----A---- C:\WINDOWS\system32\ydoykanq.dll
2008-09-16 15:34:26 ----A---- C:\WINDOWS\system32\xbqgdz.dll
2008-09-15 22:16:20 ----D---- C:\Program Files\Trend Micro
2008-09-15 15:34:38 ----A---- C:\WINDOWS\wininit.ini
2008-09-14 09:06:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\getuname.dll
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\charmap.exe
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\calc.exe
2008-09-14 08:14:49 ----D---- C:\Program Files\MSN
2008-09-13 02:20:14 ----D---- C:\Program Files\XoftSpySE
2008-09-11 21:00:46 ----D---- C:\Program Files\process Explorer
2008-09-09 17:55:11 ----D---- C:\Documents and Settings\Owner\Application Data\Nero
2008-09-09 17:49:55 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2008-09-09 17:36:01 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2008-09-09 17:36:00 ----D---- C:\Program Files\Common Files\Nero
2008-09-09 16:57:28 ----A---- C:\WINDOWS\system32\17e2d5ba-.txt
2008-09-09 16:53:13 ----ASH---- C:\WINDOWS\system32\VuwFOqru.ini2
2008-09-09 16:52:20 ----A---- C:\WINDOWS\system32\urqOFwuV.dll
2008-09-09 12:18:29 ----D---- C:\Documents and Settings\All Users\Application Data\Azureus
2008-09-09 12:18:22 ----D---- C:\Documents and Settings\Owner\Application Data\Azureus
2008-09-09 12:18:02 ----D---- C:\Program Files\AskSBar
2008-09-08 02:00:20 ----D---- C:\Documents and Settings\Owner\Application Data\DivX
2008-09-01 13:43:26 ----A---- C:\WINDOWS\system32\XceedZip.dll
2008-09-01 12:56:43 ----D---- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-01 09:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2008-09-01 09:10:19 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2008-09-01 09:09:32 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-31 11:46:12 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-08-31 11:46:05 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2008-08-31 11:44:06 ----D---- C:\Program Files\Windows Media Connect 2
2008-08-31 11:43:37 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2008-08-31 11:40:48 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2008-08-31 11:39:29 ----D---- C:\WINDOWS\system32\LogFiles
2008-08-31 11:39:14 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2008-08-31 03:13:29 ----D---- C:\Program Files\7-Zip
2008-08-31 02:45:11 ----SHD---- C:\Config.Msi
2008-08-30 11:49:39 ----D---- C:\Documents and Settings\Owner\Application Data\.BitTornado
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxssend.exe
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsroute.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsperf.ini
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsclntR.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxscfgwz.dll
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaws.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaw.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\java.exe
2008-08-24 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-08-23 03:07:59 ----D---- C:\WINDOWS\Prefetch
2008-08-23 02:12:26 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-08-23 02:12:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-08-23 02:11:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-08-23 02:11:38 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-08-23 02:11:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-23 02:11:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-08-23 02:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-08-23 02:10:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-08-23 02:10:21 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-08-23 02:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-08-23 01:59:25 ----D---- C:\WINDOWS\system32\scripting
2008-08-23 01:59:22 ----D---- C:\WINDOWS\l2schemas
2008-08-23 01:59:19 ----D---- C:\WINDOWS\system32\en
2008-08-22 01:10:31 ----N---- C:\WINDOWS\system32\wmphoto.dll
2008-08-22 01:10:24 ----N---- C:\WINDOWS\system32\wlanapi.dll
2008-08-22 01:10:22 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-22 01:10:22 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2008-08-22 01:10:03 ----N---- C:\WINDOWS\system32\tspkg.dll
2008-08-22 01:10:03 ----N---- C:\WINDOWS\system32\tsgqec.dll
2008-08-22 01:09:37 ----N---- C:\WINDOWS\system32\setupn.exe
2008-08-22 01:09:28 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2008-08-22 01:09:24 ----N---- C:\WINDOWS\system32\rasqec.dll
2008-08-22 01:09:23 ----N---- C:\WINDOWS\system32\qutil.dll
2008-08-22 01:09:21 ----N---- C:\WINDOWS\system32\qcliprov.dll
2008-08-22 01:09:20 ----N---- C:\WINDOWS\system32\qagentrt.dll
2008-08-22 01:09:20 ----N---- C:\WINDOWS\system32\qagent.dll
2008-08-22 01:09:17 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-22 01:09:11 ----N---- C:\WINDOWS\system32\onex.dll
2008-08-22 01:08:52 ----N---- C:\WINDOWS\system32\napstat.exe
2008-08-22 01:08:52 ----N---- C:\WINDOWS\system32\napmontr.dll
2008-08-22 01:08:52 ----N---- C:\WINDOWS\system32\napipsec.dll
2008-08-22 01:08:44 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2008-08-22 01:08:44 ----N---- C:\WINDOWS\system32\mssha.dll
2008-08-22 01:08:17 ----N---- C:\WINDOWS\system32\mmcperf.exe
2008-08-22 01:08:16 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-22 01:08:16 ----N---- C:\WINDOWS\system32\mmcex.dll
2008-08-22 01:08:16 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-22 01:07:59 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2008-08-22 01:07:58 ----N---- C:\WINDOWS\system32\kmsvc.dll
2008-08-22 01:07:55 ----N---- C:\WINDOWS\system32\kbdpash.dll
2008-08-22 01:07:55 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2008-08-22 01:07:55 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2008-08-22 01:07:54 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eapsvc.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eapqec.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eappprxy.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eapphost.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eappgnui.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eappcfg.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2008-08-22 01:07:13 ----N---- C:\WINDOWS\system32\eapolqec.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3ui.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3svc.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3msm.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2008-08-22 01:07:06 ----N---- C:\WINDOWS\system32\dot3api.dll
2008-08-22 01:07:01 ----N---- C:\WINDOWS\system32\dimsroam.dll
2008-08-22 01:07:01 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2008-08-22 01:07:00 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2008-08-22 01:06:54 ----N---- C:\WINDOWS\system32\credssp.dll
2008-08-22 01:06:37 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2008-08-22 01:06:36 ----N---- C:\WINDOWS\system32\azroles.dll
2008-08-22 01:06:16 ----N---- C:\WINDOWS\system32\aaclient.dll

======List of files/folders modified in the last 1 months======

2008-09-20 16:25:05 ----D---- C:\WINDOWS\Temp
2008-09-20 16:22:15 ----D---- C:\WINDOWS\system32
2008-09-20 16:21:09 ----AC---- C:\WINDOWS\ModemLog_Generic 56K HCF Data Fax Modem.txt
2008-09-20 16:18:07 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-09-20 16:15:56 ----D---- C:\WINDOWS\system32\drivers
2008-09-20 16:15:44 ----D---- C:\WINDOWS
2008-09-20 16:12:15 ----D---- C:\WINDOWS\system32\CatRoot2
2008-09-20 16:03:14 ----A---- C:\WINDOWS\system.ini
2008-09-20 15:52:31 ----D---- C:\WINDOWS\system32\config
2008-09-20 15:48:13 ----D---- C:\Program Files\Common Files
2008-09-20 15:48:12 ----D---- C:\WINDOWS\AppPatch
2008-09-20 15:42:40 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-09-20 15:41:44 ----RASH---- C:\boot.ini
2008-09-19 17:00:04 ----D---- C:\Program Files\Mozilla Thunderbird
2008-09-19 12:19:51 ----D---- C:\WINDOWS\system32\FxsTmp
2008-09-15 22:16:20 ----RD---- C:\Program Files
2008-09-15 22:12:31 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-09-15 16:27:38 ----SHD---- C:\System Volume Information
2008-09-15 16:27:38 ----D---- C:\WINDOWS\system32\Restore
2008-09-14 17:43:59 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-14 13:02:05 ----D---- C:\WINDOWS\security
2008-09-14 08:27:31 ----D---- C:\Program Files\Mozilla Firefox
2008-09-14 08:16:15 ----A---- C:\WINDOWS\imsins.BAK
2008-09-14 08:15:23 ----D---- C:\Program Files\Online Services
2008-09-14 08:15:06 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-09-14 08:15:06 ----D---- C:\WINDOWS\Cursors
2008-09-14 08:15:00 ----D---- C:\WINDOWS\Help
2008-09-14 08:14:58 ----D---- C:\WINDOWS\system32\wbem
2008-09-13 21:30:31 ----D---- C:\Program Files\Windows NT
2008-09-13 02:20:47 ----SD---- C:\WINDOWS\Tasks
2008-09-12 02:08:23 ----HD---- C:\WINDOWS\inf
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Minidump
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Debug
2008-09-12 02:08:22 ----SHD---- C:\WINDOWS\Installer
2008-09-11 02:53:23 ----D---- C:\WINDOWS\system32\en-US
2008-09-11 02:53:23 ----D---- C:\Program Files\Internet Explorer
2008-09-11 02:23:24 ----D---- C:\WINDOWS\system32\CatRoot
2008-09-11 01:38:54 ----RSD---- C:\WINDOWS\Fonts
2008-09-10 14:00:35 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-10 10:57:42 ----D---- C:\WINDOWS\Registration
2008-09-09 17:15:04 ----D---- C:\WINDOWS\WinSxS
2008-09-08 01:57:54 ----D---- C:\Program Files\ws ftp tiscali
2008-09-02 17:00:33 ----D---- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-09-01 13:11:40 ----HD---- C:\Program Files\InstallShield Installation Information
2008-09-01 12:58:22 ----RSD---- C:\WINDOWS\assembly
2008-08-31 20:21:10 ----AC---- C:\WINDOWS\NeroDigital.ini
2008-08-31 11:50:23 ----D---- C:\Program Files\Windows Media Player
2008-08-31 11:44:45 ----AC---- C:\WINDOWS\win.ini
2008-08-31 02:45:12 ----D---- C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-28 09:48:14 ----D---- C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-08-27 18:16:44 ----D---- C:\WINDOWS\system32\Adobe
2008-08-27 18:16:19 ----D---- C:\Documents and Settings\Owner\Application Data\Adobe
2008-08-27 09:00:26 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-08-26 22:33:21 ----D---- C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-08-26 10:26:22 ----D---- C:\WINDOWS\addins
2008-08-26 10:17:39 ----D---- C:\Program Files\McAfee
2008-08-24 23:22:04 ----D---- C:\Program Files\Java
2008-08-23 12:46:51 ----HD---- C:\WINDOWS\$hf_mig$
2008-08-23 08:03:46 ----AC---- C:\WINDOWS\OEWABLog.txt
2008-08-23 03:08:39 ----AC---- C:\WINDOWS\setuplog.txt
2008-08-23 03:07:19 ----D---- C:\WINDOWS\system32\Setup
2008-08-23 02:10:05 ----D---- C:\Program Files\Messenger
2008-08-23 02:00:05 ----D---- C:\WINDOWS\ServicePackFiles
2008-08-23 02:00:00 ----D---- C:\WINDOWS\network diagnostic
2008-08-23 01:59:59 ----D---- C:\WINDOWS\ime
2008-08-23 01:59:28 ----D---- C:\WINDOWS\system32\usmt
2008-08-23 01:59:18 ----D---- C:\WINDOWS\system32\bits
2008-08-23 01:59:18 ----D---- C:\WINDOWS\peernet
2008-08-23 01:59:18 ----D---- C:\Program Files\Movie Maker
2008-08-23 01:52:28 ----D---- C:\WINDOWS\system32\npp
2008-08-23 01:52:25 ----D---- C:\WINDOWS\msagent
2008-08-23 01:52:22 ----D---- C:\WINDOWS\srchasst
2008-08-23 01:52:16 ----D---- C:\Program Files\NetMeeting
2008-08-23 01:52:13 ----D---- C:\WINDOWS\system32\Com
2008-08-23 01:52:07 ----D---- C:\Program Files\Outlook Express
2008-08-23 01:52:01 ----D---- C:\Program Files\Common Files\System
2008-08-23 01:51:25 ----D---- C:\WINDOWS\system32\oobe
2008-08-23 01:51:22 ----D---- C:\WINDOWS\system
2008-08-23 01:45:21 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-08-23 01:44:38 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-08-23 01:33:05 ----D---- C:\WINDOWS\EHome
2008-08-22 18:12:04 ----AC---- C:\WINDOWS\CDSEDB01.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ATMhelpr;ATMhelpr; C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 4064]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2008-07-23 9464]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2002-12-17 241152]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2008-06-27 207656]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2008-06-02 120136]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2004-04-08 143834]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2002-12-17 206464]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-18 12032]
R3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2004-03-02 127065]
R3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2004-08-04 327040]
R3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2004-04-08 25898]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704]
R3 HCF_MSFT;HCF_MSFT; C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys [2001-08-17 907456]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2008-06-27 79240]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2008-06-27 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2008-06-27 40488]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NeroCd2k;NeroCd2k; C:\WINDOWS\system32\drivers\NeroCd2k.sys [2001-04-16 44227]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2008-07-23 9336]
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2004-03-02 50007]
S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GT680x;GrandTechICNameNT; C:\WINDOWS\System32\Drivers\gt680x.sys [2001-11-08 18120]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 ICAM3NT5;Intel USB Video Camera III; C:\WINDOWS\System32\Drivers\Icam3.sys [2001-08-17 141056]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2008-06-20 34152]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2004-04-08 30630]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2006-03-30 96341]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [2002-01-30 77824]
R2 EPSONStatusAgent2;EPSON Printer Status Agent2; C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe [2001-10-25 90112]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-08-23 79136]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-06-21 792184]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-07-18 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2008-07-09 358736]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2008-06-20 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2008-07-09 25416]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2008-04-14 33280]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2008-06-20 605512]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MBackMonitor;MBackMonitor; C:\Program Files\McAfee\MBK\MBackMonitor.exe [2008-07-10 66848]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2008-06-20 361800]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------

Shaba
2008-09-20, 18:42
We need first to disable TeaTimer that it doesn't interfere with fixes. You can re-enable it when you're clean again:

1. Run Spybot-S&D in Advanced Mode.
2. If it is not already set to do this Go to the Mode menu select "Advanced Mode"
3. On the left hand side, Click on Tools
4. Then click on the Resident Icon in the List
5. Uncheck "Resident TeaTimer" and OK any prompts.
6. Restart your computer.

Open notepad and copy/paste the text in the codebox below into it:


File::
C:\WINDOWS\system32\VuwFOqru.ini
C:\WINDOWS\system32\bntyncym.ini
C:\WINDOWS\system32\mycnytnb.dll
C:\WINDOWS\system32\fotchwkr.dll
C:\WINDOWS\system32\qkqaqslw.dll
C:\WINDOWS\system32\wlwebiqc.dll
C:\WINDOWS\system32\skwgfl.dll
C:\WINDOWS\system32\lssxmytt.dll
C:\WINDOWS\system32\ihjedy.dll
C:\WINDOWS\system32\bgqvvwiq.dll
C:\WINDOWS\system32\qbtmatry.dll
C:\WINDOWS\system32\haakyota.dll
C:\WINDOWS\system32\gjdofe.dll
C:\WINDOWS\system32\gxormo.dll
C:\WINDOWS\system32\bdtkxnry.dll
C:\WINDOWS\system32\ydoykanq.dll
C:\WINDOWS\system32\xbqgdz.dll
C:\WINDOWS\system32\VuwFOqru.ini2
C:\WINDOWS\system32\urqOFwuV.dll

Folder::
C:\Program Files\AskSBar
C:\Documents and Settings\Owner\Application Data\Azureus
C:\Documents and Settings\All Users\Application Data\Azureus

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"=-

[-HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"1cc111c4"=-
"BM1ff22258"=-

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00


Save this as "CFScript"

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

Fred of Kings Lynn
2008-09-20, 21:26
It probably took an hour to complete this last combofix including reboot.
There was no processes called findstre, find,sed or swreg in the task manager prcesses



ComboFix 08-09-19.10 - Owner 2008-09-20 18:25:58.2 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


FILE ::
C:\WINDOWS\system32\bdtkxnry.dll
C:\WINDOWS\system32\bgqvvwiq.dll
C:\WINDOWS\system32\bntyncym.ini
C:\WINDOWS\system32\fotchwkr.dll
C:\WINDOWS\system32\gjdofe.dll
C:\WINDOWS\system32\gxormo.dll
C:\WINDOWS\system32\haakyota.dll
C:\WINDOWS\system32\ihjedy.dll
C:\WINDOWS\system32\lssxmytt.dll
C:\WINDOWS\system32\mycnytnb.dll
C:\WINDOWS\system32\qbtmatry.dll
C:\WINDOWS\system32\qkqaqslw.dll
C:\WINDOWS\system32\skwgfl.dll
C:\WINDOWS\system32\urqOFwuV.dll
C:\WINDOWS\system32\VuwFOqru.ini
C:\WINDOWS\system32\VuwFOqru.ini2
C:\WINDOWS\system32\wlwebiqc.dll
C:\WINDOWS\system32\xbqgdz.dll
C:\WINDOWS\system32\ydoykanq.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Azureus
C:\Documents and Settings\All Users\Application Data\Azureus\azCID.txt
C:\Documents and Settings\Owner\Application Data\Azureus\.certs
C:\Documents and Settings\Owner\Application Data\Azureus\.keystore
C:\Documents and Settings\Owner\Application Data\Azureus\.lock
C:\Documents and Settings\Owner\Application Data\Azureus\active\cache.dat
C:\Documents and Settings\Owner\Application Data\Azureus\azureus.config
C:\Documents and Settings\Owner\Application Data\Azureus\azureus.statistics
C:\Documents and Settings\Owner\Application Data\Azureus\dht\addresses.dat
C:\Documents and Settings\Owner\Application Data\Azureus\dht\contacts.dat
C:\Documents and Settings\Owner\Application Data\Azureus\dht\diverse.dat
C:\Documents and Settings\Owner\Application Data\Azureus\dht\general.dat
C:\Documents and Settings\Owner\Application Data\Azureus\dht\version.dat
C:\Documents and Settings\Owner\Application Data\Azureus\downloads.config
C:\Documents and Settings\Owner\Application Data\Azureus\friends.config
C:\Documents and Settings\Owner\Application Data\Azureus\ipfilter.cache
C:\Documents and Settings\Owner\Application Data\Azureus\logs\alerts_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\AutoSpeed_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\debug_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\Friends_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\MetaSearch_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\NetStatus_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\seltrace_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\SpeedMan_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\thread_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\v3.ads_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\v3.CMsgr_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\v3.emp_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\v3.Friends_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\v3.MD_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\v3.PMsgr_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\logs\v3.Stream_1.log
C:\Documents and Settings\Owner\Application Data\Azureus\metasearch.config
C:\Documents and Settings\Owner\Application Data\Azureus\net\pm_9105.dat
C:\Documents and Settings\Owner\Application Data\Azureus\net\pm_default.dat
C:\Documents and Settings\Owner\Application Data\Azureus\tables.config
C:\Documents and Settings\Owner\Application Data\Azureus\timingstats.dat
C:\Documents and Settings\Owner\Application Data\Azureus\tracker.config
C:\Documents and Settings\Owner\Application Data\Azureus\unsentdata.config
C:\Documents and Settings\Owner\Application Data\Azureus\v3.Friends.dat
C:\Documents and Settings\Owner\Application Data\Azureus\VuzeActivities.config
C:\Program Files\AskSBar
C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.JAR
C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.MANIFEST
C:\Program Files\AskSBar\bar\1.bin\A2HIGHIN.EXE
C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.JAR
C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.MANIFEST
C:\Program Files\AskSBar\bar\1.bin\A2PLUGIN.DLL
C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
C:\Program Files\AskSBar\bar\1.bin\NPASKSBR.DLL
C:\Program Files\AskSBar\bar\1.bin\V2RSSMNU.DLL
C:\Program Files\AskSBar\bar\Cache\003746A8
C:\Program Files\AskSBar\bar\Cache\05A203E5.bin
C:\Program Files\AskSBar\bar\Cache\05A20B2C.bin
C:\Program Files\AskSBar\bar\Cache\05A210D8.bin
C:\Program Files\AskSBar\bar\Cache\05A21937.bin
C:\Program Files\AskSBar\bar\Cache\05A21EC5.bin
C:\Program Files\AskSBar\bar\Cache\05A22196.bin
C:\Program Files\AskSBar\bar\Cache\files.ini
C:\Program Files\AskSBar\bar\History\search2
C:\Program Files\AskSBar\bar\Settings\prevcfg2.htm
C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
C:\WINDOWS\BM1ff22258.txt
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bdtkxnry.dll
C:\WINDOWS\system32\bgqvvwiq.dll
C:\WINDOWS\system32\bntyncym.ini
C:\WINDOWS\system32\fotchwkr.dll
C:\WINDOWS\system32\gjdofe.dll
C:\WINDOWS\system32\gxormo.dll
C:\WINDOWS\system32\haakyota.dll
C:\WINDOWS\system32\ihjedy.dll
C:\WINDOWS\system32\lssxmytt.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mycnytnb.dll
C:\WINDOWS\system32\qbtmatry.dll
C:\WINDOWS\system32\qkqaqslw.dll
C:\WINDOWS\system32\skwgfl.dll
C:\WINDOWS\system32\urqOFwuV.dll
C:\WINDOWS\system32\VuwFOqru.ini
C:\WINDOWS\system32\VuwFOqru.ini2
C:\WINDOWS\system32\wlwebiqc.dll
C:\WINDOWS\system32\xbqgdz.dll
C:\WINDOWS\system32\ydoykanq.dll

.
((((((((((((((((((((((((( Files Created from 2008-08-20 to 2008-09-20 )))))))))))))))))))))))))))))))
.

2008-09-20 16:15 . 2008-09-20 16:15 0 --a------ C:\WINDOWS\BM1ff22258.xml
2008-09-20 14:51 . 2008-09-20 14:52 <DIR> d-------- C:\rsit
2008-09-15 22:16 . 2008-09-15 22:16 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-15 15:34 . 2008-09-18 07:02 150 --a------ C:\WINDOWS\wininit.ini
2008-09-14 09:06 . 2008-09-14 09:19 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-14 08:14 . 2001-08-18 13:00 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2008-09-13 02:20 . 2008-09-13 02:20 <DIR> d-------- C:\Program Files\XoftSpySE
2008-09-11 21:00 . 2008-09-11 21:01 <DIR> d-------- C:\Program Files\process Explorer
2008-09-09 17:55 . 2008-09-09 17:55 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Nero
2008-09-09 17:36 . 2008-09-10 10:57 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-09-09 17:36 . 2008-09-10 10:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-09-09 12:18 . 2008-09-20 18:56 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Azureus
2008-09-08 02:00 . 2008-09-10 10:56 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\DivX
2008-09-08 01:56 . 2008-07-23 17:50 43,528 --a------ C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-09-01 13:43 . 2007-09-02 20:56 1,686,016 --a------ C:\WINDOWS\system32\clinetsuitex6.ocx
2008-09-01 13:43 . 2004-06-14 14:56 427,864 --a------ C:\WINDOWS\system32\XceedZip.dll
2008-09-01 12:56 . 2008-09-01 12:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-08-31 12:24 . 2000-05-19 17:56 81,920 --a------ C:\WINDOWS\system32\mbmouse.ocx
2008-08-31 12:24 . 2007-08-31 18:36 36,864 --a------ C:\WINDOWS\system32\trayicon_handler.ocx
2008-08-31 11:44 . 2008-08-31 11:44 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-08-31 11:39 . 2008-08-31 11:39 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-08-31 11:39 . 2008-08-31 11:41 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-08-31 03:13 . 2008-08-31 03:13 <DIR> d-------- C:\Program Files\7-Zip
2008-08-30 11:49 . 2008-08-30 11:49 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\.BitTornado
2008-08-26 10:26 . 2001-08-18 13:00 132,608 --a------ C:\WINDOWS\system32\fxsclntR.dll
2008-08-26 10:26 . 2001-08-18 13:00 132,608 --a--c--- C:\WINDOWS\system32\dllcache\fxsclntr.dll
2008-08-26 10:26 . 2001-08-18 13:00 111,104 --a------ C:\WINDOWS\system32\fxscfgwz.dll
2008-08-26 10:26 . 2001-08-18 13:00 111,104 --a--c--- C:\WINDOWS\system32\dllcache\fxscfgwz.dll
2008-08-26 10:26 . 2001-08-18 13:00 31,744 --a------ C:\WINDOWS\system32\fxsroute.dll
2008-08-26 10:26 . 2001-08-18 13:00 31,744 --a--c--- C:\WINDOWS\system32\dllcache\fxsroute.dll
2008-08-26 10:26 . 2001-08-18 13:00 11,264 --a------ C:\WINDOWS\system32\fxssend.exe
2008-08-26 10:26 . 2001-08-18 13:00 11,264 --a--c--- C:\WINDOWS\system32\dllcache\fxssend.exe
2008-08-26 10:26 . 2001-08-18 13:00 1,793 --a------ C:\WINDOWS\system32\fxsperf.ini
2008-08-26 10:26 . 2001-08-18 13:00 1,361 --a------ C:\WINDOWS\system32\fxscount.h
2008-08-23 01:59 . 2008-08-23 01:59 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-23 01:59 . 2008-08-23 01:59 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-23 01:59 . 2008-08-23 01:59 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-22 01:10 . 2008-04-14 01:12 712,704 --a------ C:\WINDOWS\system32\windowscodecs.dll
2008-08-22 01:10 . 2008-04-14 01:12 346,112 --a------ C:\WINDOWS\system32\windowscodecsext.dll
2008-08-22 01:10 . 2008-04-14 01:12 276,992 --a------ C:\WINDOWS\system32\wmphoto.dll
2008-08-22 01:10 . 2008-04-14 01:12 69,120 --a------ C:\WINDOWS\system32\wlanapi.dll
2008-08-22 01:10 . 2008-04-14 01:12 53,248 --a------ C:\WINDOWS\system32\tsgqec.dll
2008-08-22 01:10 . 2008-04-14 01:12 50,688 --a------ C:\WINDOWS\system32\tspkg.dll
2008-08-22 01:09 . 2008-04-14 01:12 412,160 --a------ C:\WINDOWS\system32\photometadatahandler.dll
2008-08-22 01:09 . 2008-04-14 01:12 291,328 --a------ C:\WINDOWS\system32\qagentrt.dll
2008-08-22 01:09 . 2008-04-14 01:12 290,304 --a------ C:\WINDOWS\system32\rhttpaa.dll
2008-08-22 01:09 . 2008-04-14 01:12 150,528 --a------ C:\WINDOWS\system32\qagent.dll
2008-08-22 01:09 . 2008-04-14 01:12 144,384 --a------ C:\WINDOWS\system32\onex.dll
2008-08-22 01:09 . 2008-04-14 01:12 76,800 --a------ C:\WINDOWS\system32\qutil.dll
2008-08-22 01:09 . 2008-04-14 01:12 62,464 --a------ C:\WINDOWS\system32\qcliprov.dll
2008-08-22 01:09 . 2008-04-14 01:12 61,952 --a------ C:\WINDOWS\system32\rasqec.dll
2008-08-22 01:09 . 2008-04-14 01:12 32,768 --a------ C:\WINDOWS\system32\setupn.exe
2008-08-22 01:09 . 2008-04-13 19:40 10,240 --a------ C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-08-22 01:07 . 2008-04-14 01:11 650,752 --a------ C:\WINDOWS\system32\dot3ui.dll
2008-08-22 01:06 . 2008-04-14 01:11 233,472 --a------ C:\WINDOWS\system32\azroles.dll
2008-08-22 01:06 . 2008-04-14 01:11 136,192 --a------ C:\WINDOWS\system32\aaclient.dll
2008-08-22 01:06 . 2008-04-14 01:11 12,800 --a------ C:\WINDOWS\system32\credssp.dll
2008-08-22 01:06 . 2008-04-14 01:11 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-20 16:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-19 16:00 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-09-10 13:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-08 00:57 --------- d-----w C:\Program Files\ws ftp tiscali
2008-09-02 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-09-01 12:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-31 01:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-28 08:48 --------- d-----w C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-08-26 21:33 --------- d-----w C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-08-26 09:17 --------- d-----w C:\Program Files\McAfee
2008-08-24 22:22 --------- d-----w C:\Program Files\Java
2008-07-27 09:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\TomTom
2008-07-23 16:50 9,464 -c--a-w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-07-23 16:50 9,336 -c--a-w C:\WINDOWS\system32\drivers\cdr4_xp.sys
.

((((((((((((((((((((((((((((( snapshot@2008-09-20_16.12.52.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-20 17:57:10 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_690.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"EEventManager"="C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2005-04-08 102400]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2008-07-11 641208]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 36640]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2008-06-13 1176808]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-06-18 962660]
EPSON Background Monitor.lnk - C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe [1999-06-07 233984]
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-13 24633]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWinKeys"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
---hs---- 2008-04-14 01:12 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a--c--- 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\ws ftp tiscali\\WS_FTP95.exe"=
"C:\\Program Files\\Abacast\\Abaclient.exe"=
"C:\\Program Files\\Netscape\\Netscape\\Netscp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R1 ATMhelpr;ATMhelpr;C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 4064]
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2004-08-04 327040]
R3 NeroCd2k;NeroCd2k;C:\WINDOWS\system32\drivers\NeroCd2k.sys [2001-04-16 44227]
S3 ati2mpaa;ati2mpaa;C:\WINDOWS\system32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
S3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS\system32\Drivers\Icam3.sys [2001-08-17 141056]
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b3ab410-5bbe-11dd-88c4-4d6564696130}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

BHO-{8465F367-02EB-4E99-AF75-CCDD2A7B27E0} - C:\WINDOWS\system32\urqOFwuV.dll



**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 19:02:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\SiteAdvisor\6172\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\WINDOWS\system32\snmp.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
.
**************************************************************************
.
Completion time: 2008-09-20 19:14:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-20 18:14:23
ComboFix2.txt 2008-09-20 15:15:28

Pre-Run: 4,856,127,488 bytes free
Post-Run: 4,838,334,464 bytes free

294 --- E O F --- 2008-09-01 08:10:56








Logfile of random's system information tool 1.02 (written by random/random)
Run by Owner at 2008-09-20 19:22:32
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 5 GB (23%) free of 20 GB
Total RAM: 383 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:22:49, on 20/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Owner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.co.uk/"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CNetscape_UK.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (file missing)
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{865FD82A-61A9-40E1-B551-DB3C7F08964C}: NameServer = 212.139.132.10 212.139.132.11
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O24 - Desktop Component 0: (no name) - http://news.bbc.co.uk/

--
End of file - 7944 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Disk Cleanup.job
C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job
C:\WINDOWS\tasks\XoftSpySE 2.job
C:\WINDOWS\tasks\XoftSpySE.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{089FD14D-132B-48FC-8861-0048AE113215}]
C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-07-07 1562448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-08-04 343112]
{0BF43445-2F28-4351-9252-17FE6E806AA0} - McAfee SiteAdvisor - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]
{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - Ask Toolbar - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"EEventManager"=C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2005-04-08 102400]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2008-07-11 641208]
"SiteAdvisor"=C:\Program Files\SiteAdvisor\6172\SiteAdv.exe [2007-08-24 36640]
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe [2008-06-13 1176808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\System32\NeroCheck.exe [2001-07-09 155648]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
EPSON Background Monitor.lnk - C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoWinKeys"=0
"NoFileAssociate"=0
"NoCommonGroups"=0
"NoSimpleStartMenu"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\fxsclnt.exe"="C:\WINDOWS\system32\fxsclnt.exe:*:Disabled:Microsoft Fax Console"
"C:\Program Files\ws ftp tiscali\WS_FTP95.exe"="C:\Program Files\ws ftp tiscali\WS_FTP95.exe:*:Enabled:WS_FTP 95"
"C:\Program Files\Abacast\Abaclient.exe"="C:\Program Files\Abacast\Abaclient.exe:*:Enabled:Abaclient"
"C:\Program Files\Netscape\Netscape\Netscp.exe"="C:\Program Files\Netscape\Netscape\Netscp.exe:*:Enabled:Netscp"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b3ab410-5bbe-11dd-88c4-4d6564696130}]
shell\AutoRun\command - G:\InstallTomTomHOME.exe


======List of files/folders created in the last 1 months======

2008-09-20 19:14:44 ----SHD---- C:\RECYCLER
2008-09-20 19:14:41 ----A---- C:\ComboFix.txt
2008-09-20 15:41:44 ----A---- C:\Boot.bak
2008-09-20 15:41:32 ----D---- C:\cmdcons
2008-09-20 15:38:36 ----D---- C:\WINDOWS\erdnt
2008-09-20 15:35:43 ----D---- C:\QooBox
2008-09-20 15:34:44 ----A---- C:\WINDOWS\zip.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\swreg.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\sed.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\Nircmd.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\grep.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\VFind.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\swxcacls.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\SWSC.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\fdsv.exe
2008-09-20 14:51:50 ----D---- C:\rsit
2008-09-15 22:16:20 ----D---- C:\Program Files\Trend Micro
2008-09-15 15:34:38 ----A---- C:\WINDOWS\wininit.ini
2008-09-14 09:06:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\getuname.dll
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\charmap.exe
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\calc.exe
2008-09-14 08:14:49 ----D---- C:\Program Files\MSN
2008-09-13 02:20:14 ----D---- C:\Program Files\XoftSpySE
2008-09-11 21:00:46 ----D---- C:\Program Files\process Explorer
2008-09-09 17:55:11 ----D---- C:\Documents and Settings\Owner\Application Data\Nero
2008-09-09 17:49:55 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2008-09-09 17:36:01 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2008-09-09 17:36:00 ----D---- C:\Program Files\Common Files\Nero
2008-09-09 16:57:28 ----A---- C:\WINDOWS\system32\17e2d5ba-.txt
2008-09-09 12:18:22 ----D---- C:\Documents and Settings\Owner\Application Data\Azureus
2008-09-08 02:00:20 ----D---- C:\Documents and Settings\Owner\Application Data\DivX
2008-09-01 13:43:26 ----A---- C:\WINDOWS\system32\XceedZip.dll
2008-09-01 12:56:43 ----D---- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-01 09:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2008-09-01 09:10:19 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2008-09-01 09:09:32 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-31 11:46:12 ----A---- C:\WINDOWS\system32\spmsg.dll
2008-08-31 11:46:05 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2008-08-31 11:44:06 ----D---- C:\Program Files\Windows Media Connect 2
2008-08-31 11:43:37 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2008-08-31 11:40:48 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2008-08-31 11:39:29 ----D---- C:\WINDOWS\system32\LogFiles
2008-08-31 11:39:14 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2008-08-31 03:13:29 ----D---- C:\Program Files\7-Zip
2008-08-31 02:45:11 ----SHD---- C:\Config.Msi
2008-08-30 11:49:39 ----D---- C:\Documents and Settings\Owner\Application Data\.BitTornado
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxssend.exe
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsroute.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsperf.ini
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsclntR.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxscfgwz.dll
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaws.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaw.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\java.exe
2008-08-24 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-08-23 03:07:59 ----D---- C:\WINDOWS\Prefetch
2008-08-23 02:12:26 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-08-23 02:12:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-08-23 02:11:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-08-23 02:11:38 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-08-23 02:11:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-23 02:11:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-08-23 02:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-08-23 02:10:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-08-23 02:10:21 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-08-23 02:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-08-23 01:59:25 ----D---- C:\WINDOWS\system32\scripting
2008-08-23 01:59:22 ----D---- C:\WINDOWS\l2schemas
2008-08-23 01:59:19 ----D---- C:\WINDOWS\system32\en
2008-08-22 01:10:31 ----A---- C:\WINDOWS\system32\wmphoto.dll
2008-08-22 01:10:24 ----A---- C:\WINDOWS\system32\wlanapi.dll
2008-08-22 01:10:22 ----A---- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-22 01:10:22 ----A---- C:\WINDOWS\system32\windowscodecs.dll
2008-08-22 01:10:03 ----A---- C:\WINDOWS\system32\tspkg.dll
2008-08-22 01:10:03 ----A---- C:\WINDOWS\system32\tsgqec.dll
2008-08-22 01:09:37 ----A---- C:\WINDOWS\system32\setupn.exe
2008-08-22 01:09:28 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2008-08-22 01:09:24 ----A---- C:\WINDOWS\system32\rasqec.dll
2008-08-22 01:09:23 ----A---- C:\WINDOWS\system32\qutil.dll
2008-08-22 01:09:21 ----A---- C:\WINDOWS\system32\qcliprov.dll
2008-08-22 01:09:20 ----A---- C:\WINDOWS\system32\qagentrt.dll
2008-08-22 01:09:20 ----A---- C:\WINDOWS\system32\qagent.dll
2008-08-22 01:09:17 ----A---- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-22 01:09:11 ----A---- C:\WINDOWS\system32\onex.dll
2008-08-22 01:08:52 ----A---- C:\WINDOWS\system32\napstat.exe
2008-08-22 01:08:52 ----A---- C:\WINDOWS\system32\napmontr.dll
2008-08-22 01:08:52 ----A---- C:\WINDOWS\system32\napipsec.dll
2008-08-22 01:08:44 ----A---- C:\WINDOWS\system32\msshavmsg.dll
2008-08-22 01:08:44 ----A---- C:\WINDOWS\system32\mssha.dll
2008-08-22 01:08:17 ----A---- C:\WINDOWS\system32\mmcperf.exe
2008-08-22 01:08:16 ----A---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-22 01:08:16 ----A---- C:\WINDOWS\system32\mmcex.dll
2008-08-22 01:08:16 ----A---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-22 01:07:59 ----A---- C:\WINDOWS\system32\l2gpstore.dll
2008-08-22 01:07:58 ----A---- C:\WINDOWS\system32\kmsvc.dll
2008-08-22 01:07:55 ----A---- C:\WINDOWS\system32\kbdpash.dll
2008-08-22 01:07:55 ----A---- C:\WINDOWS\system32\kbdnepr.dll
2008-08-22 01:07:55 ----A---- C:\WINDOWS\system32\kbdiultn.dll
2008-08-22 01:07:54 ----A---- C:\WINDOWS\system32\kbdbhc.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapsvc.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapqec.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eappprxy.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapphost.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eappgnui.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eappcfg.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapp3hst.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapolqec.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3ui.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3svc.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3msm.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3dlg.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3cfg.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3api.dll
2008-08-22 01:07:01 ----A---- C:\WINDOWS\system32\dimsroam.dll
2008-08-22 01:07:01 ----A---- C:\WINDOWS\system32\dimsntfy.dll
2008-08-22 01:07:00 ----A---- C:\WINDOWS\system32\dhcpqec.dll
2008-08-22 01:06:54 ----A---- C:\WINDOWS\system32\credssp.dll
2008-08-22 01:06:37 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2008-08-22 01:06:36 ----A---- C:\WINDOWS\system32\azroles.dll
2008-08-22 01:06:16 ----A---- C:\WINDOWS\system32\aaclient.dll

======List of files/folders modified in the last 1 months======

2008-09-20 19:22:36 ----D---- C:\WINDOWS\Temp
2008-09-20 19:15:38 ----D---- C:\WINDOWS\system32
2008-09-20 19:15:37 ----D---- C:\WINDOWS\system32\drivers
2008-09-20 19:13:10 ----D---- C:\WINDOWS\system32\CatRoot2
2008-09-20 19:02:35 ----D---- C:\WINDOWS
2008-09-20 19:02:35 ----A---- C:\WINDOWS\system.ini
2008-09-20 18:57:16 ----AC---- C:\WINDOWS\ModemLog_Generic 56K HCF Data Fax Modem.txt
2008-09-20 18:55:28 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-09-20 18:54:12 ----D---- C:\WINDOWS\system32\config
2008-09-20 18:37:45 ----D---- C:\Program Files\Common Files
2008-09-20 18:37:43 ----D---- C:\WINDOWS\AppPatch
2008-09-20 18:28:02 ----RD---- C:\Program Files
2008-09-20 17:08:28 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 15:42:40 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-09-20 15:41:44 ----RASH---- C:\boot.ini
2008-09-19 17:00:04 ----D---- C:\Program Files\Mozilla Thunderbird
2008-09-19 12:19:51 ----D---- C:\WINDOWS\system32\FxsTmp
2008-09-15 22:12:31 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-09-15 16:27:38 ----SHD---- C:\System Volume Information
2008-09-15 16:27:38 ----D---- C:\WINDOWS\system32\Restore
2008-09-14 13:02:05 ----D---- C:\WINDOWS\security
2008-09-14 08:27:31 ----D---- C:\Program Files\Mozilla Firefox
2008-09-14 08:16:15 ----A---- C:\WINDOWS\imsins.BAK
2008-09-14 08:15:23 ----D---- C:\Program Files\Online Services
2008-09-14 08:15:06 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-09-14 08:15:06 ----D---- C:\WINDOWS\Cursors
2008-09-14 08:15:00 ----D---- C:\WINDOWS\Help
2008-09-14 08:14:58 ----D---- C:\WINDOWS\system32\wbem
2008-09-13 21:30:31 ----D---- C:\Program Files\Windows NT
2008-09-13 02:20:47 ----SD---- C:\WINDOWS\Tasks
2008-09-12 02:08:23 ----HD---- C:\WINDOWS\inf
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Minidump
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Debug
2008-09-12 02:08:22 ----SHD---- C:\WINDOWS\Installer
2008-09-11 02:53:23 ----D---- C:\WINDOWS\system32\en-US
2008-09-11 02:53:23 ----D---- C:\Program Files\Internet Explorer
2008-09-11 02:23:24 ----D---- C:\WINDOWS\system32\CatRoot
2008-09-11 01:38:54 ----RSD---- C:\WINDOWS\Fonts
2008-09-10 14:00:35 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-10 10:57:42 ----D---- C:\WINDOWS\Registration
2008-09-09 17:15:04 ----D---- C:\WINDOWS\WinSxS
2008-09-08 01:57:54 ----D---- C:\Program Files\ws ftp tiscali
2008-09-02 17:00:33 ----D---- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-09-01 13:11:40 ----HD---- C:\Program Files\InstallShield Installation Information
2008-09-01 12:58:22 ----RSD---- C:\WINDOWS\assembly
2008-08-31 20:21:10 ----AC---- C:\WINDOWS\NeroDigital.ini
2008-08-31 11:50:23 ----D---- C:\Program Files\Windows Media Player
2008-08-31 11:44:45 ----AC---- C:\WINDOWS\win.ini
2008-08-31 02:45:12 ----D---- C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-28 09:48:14 ----D---- C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-08-27 18:16:44 ----D---- C:\WINDOWS\system32\Adobe
2008-08-27 18:16:19 ----D---- C:\Documents and Settings\Owner\Application Data\Adobe
2008-08-27 09:00:26 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-08-26 22:33:21 ----D---- C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-08-26 10:26:22 ----D---- C:\WINDOWS\addins
2008-08-26 10:17:39 ----D---- C:\Program Files\McAfee
2008-08-24 23:22:04 ----D---- C:\Program Files\Java
2008-08-23 12:46:51 ----HD---- C:\WINDOWS\$hf_mig$
2008-08-23 08:03:46 ----AC---- C:\WINDOWS\OEWABLog.txt
2008-08-23 03:08:39 ----AC---- C:\WINDOWS\setuplog.txt
2008-08-23 03:07:19 ----D---- C:\WINDOWS\system32\Setup
2008-08-23 02:10:05 ----D---- C:\Program Files\Messenger
2008-08-23 02:00:05 ----D---- C:\WINDOWS\ServicePackFiles
2008-08-23 02:00:00 ----D---- C:\WINDOWS\network diagnostic
2008-08-23 01:59:59 ----D---- C:\WINDOWS\ime
2008-08-23 01:59:28 ----D---- C:\WINDOWS\system32\usmt
2008-08-23 01:59:18 ----D---- C:\WINDOWS\system32\bits
2008-08-23 01:59:18 ----D---- C:\WINDOWS\peernet
2008-08-23 01:59:18 ----D---- C:\Program Files\Movie Maker
2008-08-23 01:52:28 ----D---- C:\WINDOWS\system32\npp
2008-08-23 01:52:25 ----D---- C:\WINDOWS\msagent
2008-08-23 01:52:22 ----D---- C:\WINDOWS\srchasst
2008-08-23 01:52:16 ----D---- C:\Program Files\NetMeeting
2008-08-23 01:52:13 ----D---- C:\WINDOWS\system32\Com
2008-08-23 01:52:07 ----D---- C:\Program Files\Outlook Express
2008-08-23 01:52:01 ----D---- C:\Program Files\Common Files\System
2008-08-23 01:51:25 ----D---- C:\WINDOWS\system32\oobe
2008-08-23 01:51:22 ----D---- C:\WINDOWS\system
2008-08-23 01:45:21 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-08-23 01:44:38 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-08-23 01:33:05 ----D---- C:\WINDOWS\EHome
2008-08-22 18:12:04 ----AC---- C:\WINDOWS\CDSEDB01.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ATMhelpr;ATMhelpr; C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 4064]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2008-07-23 9464]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2002-12-17 241152]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2008-06-27 207656]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2008-06-02 120136]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2004-04-08 143834]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2002-12-17 206464]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-18 12032]
R3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2004-03-02 127065]
R3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2004-08-04 327040]
R3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
R3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2004-04-08 25898]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704]
R3 HCF_MSFT;HCF_MSFT; C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys [2001-08-17 907456]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2008-06-27 79240]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2008-06-27 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2008-06-27 40488]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NeroCd2k;NeroCd2k; C:\WINDOWS\system32\drivers\NeroCd2k.sys [2001-04-16 44227]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2008-07-23 9336]
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2004-03-02 50007]
S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GT680x;GrandTechICNameNT; C:\WINDOWS\System32\Drivers\gt680x.sys [2001-11-08 18120]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 ICAM3NT5;Intel USB Video Camera III; C:\WINDOWS\System32\Drivers\Icam3.sys [2001-08-17 141056]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2008-06-20 34152]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2004-04-08 30630]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2006-03-30 96341]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [2002-01-30 77824]
R2 EPSONStatusAgent2;EPSON Printer Status Agent2; C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe [2001-10-25 90112]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-08-23 79136]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-06-21 792184]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-07-18 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2008-07-09 358736]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2008-06-20 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2008-07-09 25416]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2008-04-14 33280]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2008-06-20 605512]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MBackMonitor;MBackMonitor; C:\Program Files\McAfee\MBK\MBackMonitor.exe [2008-07-10 66848]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2008-06-20 361800]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------

Shaba
2008-09-20, 21:46
Second round is needed:

Open notepad and copy/paste the text in the codebox below into it:


File::
C:\WINDOWS\BM1ff22258.xml

Folder::
C:\Documents and Settings\Owner\Application Data\Azureus
C:\Documents and Settings\Owner\Application Data\.BitTornado


Save this as "CFScript"

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

Fred of Kings Lynn
2008-09-21, 05:47
ComboFix 08-09-19.10 - Owner 2008-09-21 3:17:53.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.119 [GMT 1:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


FILE ::
C:\WINDOWS\BM1ff22258.xml
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Owner\Application Data\.BitTornado
C:\Documents and Settings\Owner\Application Data\.BitTornado\config.gui.ini
C:\Documents and Settings\Owner\Application Data\.BitTornado\datacache\5a24915cc000fe9ab6f7184c7310d5664efc10bd
C:\Documents and Settings\Owner\Application Data\.BitTornado\datacache\76c09604bcdd6a0ef4bc5f5a6c6da676da95895a
C:\Documents and Settings\Owner\Application Data\.BitTornado\datacache\b2a10e4aad57fe464d42d080618c3728f599ec95
C:\Documents and Settings\Owner\Application Data\.BitTornado\datacache\e57aab6ae9be31560fa98059a67e74053baa1a48
C:\Documents and Settings\Owner\Application Data\.BitTornado\datacache\f55fdd16b7c45bd2b0a119247677e9c0f522084a
C:\Documents and Settings\Owner\Application Data\.BitTornado\icons\alloc.gif
C:\Documents and Settings\Owner\Application Data\.BitTornado\icons\black.ico
C:\Documents and Settings\Owner\Application Data\.BitTornado\icons\black1.ico
C:\Documents and Settings\Owner\Application Data\.BitTornado\icons\blue.ico
C:\Documents and Settings\Owner\Application Data\.BitTornado\icons\green.ico
C:\Documents and Settings\Owner\Application Data\.BitTornado\icons\green1.ico
C:\Documents and Settings\Owner\Application Data\.BitTornado\icons\icon_bt.ico
C:\Documents and Settings\Owner\Application Data\.BitTornado\icons\icon_done.ico
C:\Documents and Settings\Owner\Application Data\.BitTornado\icons\red.ico
C:\Documents and Settings\Owner\Application Data\.BitTornado\icons\white.ico
C:\Documents and Settings\Owner\Application Data\.BitTornado\icons\yellow.ico
C:\Documents and Settings\Owner\Application Data\.BitTornado\icons\yellow1.ico
C:\Documents and Settings\Owner\Application Data\Azureus
C:\WINDOWS\BM1ff22258.xml

.
((((((((((((((((((((((((( Files Created from 2008-08-21 to 2008-09-21 )))))))))))))))))))))))))))))))
.

2008-09-20 14:51 . 2008-09-20 14:52 <DIR> d-------- C:\rsit
2008-09-15 22:16 . 2008-09-15 22:16 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-15 15:34 . 2008-09-18 07:02 150 --a------ C:\WINDOWS\wininit.ini
2008-09-14 09:06 . 2008-09-14 09:19 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-14 08:14 . 2001-08-18 13:00 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2008-09-13 02:20 . 2008-09-13 02:20 <DIR> d-------- C:\Program Files\XoftSpySE
2008-09-11 21:00 . 2008-09-11 21:01 <DIR> d-------- C:\Program Files\process Explorer
2008-09-09 17:55 . 2008-09-09 17:55 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Nero
2008-09-09 17:36 . 2008-09-10 10:57 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-09-09 17:36 . 2008-09-10 10:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-09-08 02:00 . 2008-09-10 10:56 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\DivX
2008-09-08 01:56 . 2008-07-23 17:50 43,528 --a------ C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-09-01 13:43 . 2007-09-02 20:56 1,686,016 --a------ C:\WINDOWS\system32\clinetsuitex6.ocx
2008-09-01 13:43 . 2004-06-14 14:56 427,864 --a------ C:\WINDOWS\system32\XceedZip.dll
2008-09-01 12:56 . 2008-09-01 12:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-08-31 12:24 . 2000-05-19 17:56 81,920 --a------ C:\WINDOWS\system32\mbmouse.ocx
2008-08-31 12:24 . 2007-08-31 18:36 36,864 --a------ C:\WINDOWS\system32\trayicon_handler.ocx
2008-08-31 11:44 . 2008-08-31 11:44 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-08-31 11:39 . 2008-08-31 11:39 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-08-31 11:39 . 2008-08-31 11:41 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-08-31 03:13 . 2008-08-31 03:13 <DIR> d-------- C:\Program Files\7-Zip
2008-08-26 10:26 . 2001-08-18 13:00 132,608 --a------ C:\WINDOWS\system32\fxsclntR.dll
2008-08-26 10:26 . 2001-08-18 13:00 132,608 --a--c--- C:\WINDOWS\system32\dllcache\fxsclntr.dll
2008-08-26 10:26 . 2001-08-18 13:00 111,104 --a------ C:\WINDOWS\system32\fxscfgwz.dll
2008-08-26 10:26 . 2001-08-18 13:00 111,104 --a--c--- C:\WINDOWS\system32\dllcache\fxscfgwz.dll
2008-08-26 10:26 . 2001-08-18 13:00 31,744 --a------ C:\WINDOWS\system32\fxsroute.dll
2008-08-26 10:26 . 2001-08-18 13:00 31,744 --a--c--- C:\WINDOWS\system32\dllcache\fxsroute.dll
2008-08-26 10:26 . 2001-08-18 13:00 11,264 --a------ C:\WINDOWS\system32\fxssend.exe
2008-08-26 10:26 . 2001-08-18 13:00 11,264 --a--c--- C:\WINDOWS\system32\dllcache\fxssend.exe
2008-08-26 10:26 . 2001-08-18 13:00 1,793 --a------ C:\WINDOWS\system32\fxsperf.ini
2008-08-26 10:26 . 2001-08-18 13:00 1,361 --a------ C:\WINDOWS\system32\fxscount.h
2008-08-23 01:59 . 2008-08-23 01:59 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-23 01:59 . 2008-08-23 01:59 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-23 01:59 . 2008-08-23 01:59 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-22 01:10 . 2008-04-14 01:12 712,704 --a------ C:\WINDOWS\system32\windowscodecs.dll
2008-08-22 01:10 . 2008-04-14 01:12 346,112 --a------ C:\WINDOWS\system32\windowscodecsext.dll
2008-08-22 01:10 . 2008-04-14 01:12 276,992 --a------ C:\WINDOWS\system32\wmphoto.dll
2008-08-22 01:10 . 2008-04-14 01:12 69,120 --a------ C:\WINDOWS\system32\wlanapi.dll
2008-08-22 01:10 . 2008-04-14 01:12 53,248 --a------ C:\WINDOWS\system32\tsgqec.dll
2008-08-22 01:10 . 2008-04-14 01:12 50,688 --a------ C:\WINDOWS\system32\tspkg.dll
2008-08-22 01:09 . 2008-04-14 01:12 412,160 --a------ C:\WINDOWS\system32\photometadatahandler.dll
2008-08-22 01:09 . 2008-04-14 01:12 291,328 --a------ C:\WINDOWS\system32\qagentrt.dll
2008-08-22 01:09 . 2008-04-14 01:12 290,304 --a------ C:\WINDOWS\system32\rhttpaa.dll
2008-08-22 01:09 . 2008-04-14 01:12 150,528 --a------ C:\WINDOWS\system32\qagent.dll
2008-08-22 01:09 . 2008-04-14 01:12 144,384 --a------ C:\WINDOWS\system32\onex.dll
2008-08-22 01:09 . 2008-04-14 01:12 76,800 --a------ C:\WINDOWS\system32\qutil.dll
2008-08-22 01:09 . 2008-04-14 01:12 62,464 --a------ C:\WINDOWS\system32\qcliprov.dll
2008-08-22 01:09 . 2008-04-14 01:12 61,952 --a------ C:\WINDOWS\system32\rasqec.dll
2008-08-22 01:09 . 2008-04-14 01:12 32,768 --a------ C:\WINDOWS\system32\setupn.exe
2008-08-22 01:09 . 2008-04-13 19:40 10,240 --a------ C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-08-22 01:07 . 2008-04-14 01:11 650,752 --a------ C:\WINDOWS\system32\dot3ui.dll
2008-08-22 01:06 . 2008-04-14 01:11 233,472 --a------ C:\WINDOWS\system32\azroles.dll
2008-08-22 01:06 . 2008-04-14 01:11 136,192 --a------ C:\WINDOWS\system32\aaclient.dll
2008-08-22 01:06 . 2008-04-14 01:11 12,800 --a------ C:\WINDOWS\system32\credssp.dll
2008-08-22 01:06 . 2008-04-14 01:11 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-20 16:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-19 16:00 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-09-10 13:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-08 00:57 --------- d-----w C:\Program Files\ws ftp tiscali
2008-09-02 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-09-01 12:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-31 01:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-28 08:48 --------- d-----w C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-08-26 21:33 --------- d-----w C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-08-26 09:17 --------- d-----w C:\Program Files\McAfee
2008-08-24 22:22 --------- d-----w C:\Program Files\Java
2008-07-27 09:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\TomTom
2008-07-25 08:34 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-07-23 16:50 9,464 -c--a-w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-07-23 16:50 9,336 -c--a-w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 -c--a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 -c--a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.

((((((((((((((((((((((((((((( snapshot@2008-09-20_16.12.52.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-20 13:44:01 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-20 22:46:42 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-20 13:44:01 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-20 22:46:42 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-20 17:57:10 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_690.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"EEventManager"="C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2005-04-08 102400]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2008-07-11 641208]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 36640]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2008-06-13 1176808]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-06-18 962660]
EPSON Background Monitor.lnk - C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe [1999-06-07 233984]
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-13 24633]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWinKeys"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
---hs---- 2008-04-14 01:12 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a--c--- 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\ws ftp tiscali\\WS_FTP95.exe"=
"C:\\Program Files\\Abacast\\Abaclient.exe"=
"C:\\Program Files\\Netscape\\Netscape\\Netscp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R1 ATMhelpr;ATMhelpr;C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 4064]
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2004-08-04 327040]
R3 NeroCd2k;NeroCd2k;C:\WINDOWS\system32\drivers\NeroCd2k.sys [2001-04-16 44227]
S3 ati2mpaa;ati2mpaa;C:\WINDOWS\system32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
S3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS\system32\Drivers\Icam3.sys [2001-08-17 141056]
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b3ab410-5bbe-11dd-88c4-4d6564696130}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-21 03:24:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\DOCUME~1\Owner\LOCALS~1\Temp\RGIBF.tmp

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2008-09-21 3:30:23
ComboFix-quarantined-files.txt 2008-09-21 02:30:15
ComboFix2.txt 2008-09-20 18:14:41
ComboFix3.txt 2008-09-20 15:15:28

Pre-Run: 4,761,423,872 bytes free
Post-Run: 4,749,377,536 bytes free

204 --- E O F --- 2008-09-01 08:10:56





Logfile of random's system information tool 1.02 (written by random/random)
Run by Owner at 2008-09-21 03:38:36
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 5 GB (23%) free of 20 GB
Total RAM: 383 MB (24% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:38:46, on 21/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Canon\CAL\CALMAIN.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Owner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.co.uk/"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CNetscape_UK.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (file missing)
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O24 - Desktop Component 0: (no name) - http://news.bbc.co.uk/

--
End of file - 7806 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Disk Cleanup.job
C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job
C:\WINDOWS\tasks\XoftSpySE 2.job
C:\WINDOWS\tasks\XoftSpySE.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{089FD14D-132B-48FC-8861-0048AE113215}]
C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-07-07 1562448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-08-04 343112]
{0BF43445-2F28-4351-9252-17FE6E806AA0} - McAfee SiteAdvisor - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]
{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - Ask Toolbar - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"EEventManager"=C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2005-04-08 102400]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2008-07-11 641208]
"SiteAdvisor"=C:\Program Files\SiteAdvisor\6172\SiteAdv.exe [2007-08-24 36640]
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe [2008-06-13 1176808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\System32\NeroCheck.exe [2001-07-09 155648]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
EPSON Background Monitor.lnk - C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoWinKeys"=0
"NoFileAssociate"=0
"NoCommonGroups"=0
"NoSimpleStartMenu"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\fxsclnt.exe"="C:\WINDOWS\system32\fxsclnt.exe:*:Disabled:Microsoft Fax Console"
"C:\Program Files\ws ftp tiscali\WS_FTP95.exe"="C:\Program Files\ws ftp tiscali\WS_FTP95.exe:*:Enabled:WS_FTP 95"
"C:\Program Files\Abacast\Abaclient.exe"="C:\Program Files\Abacast\Abaclient.exe:*:Enabled:Abaclient"
"C:\Program Files\Netscape\Netscape\Netscp.exe"="C:\Program Files\Netscape\Netscape\Netscp.exe:*:Enabled:Netscp"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b3ab410-5bbe-11dd-88c4-4d6564696130}]
shell\AutoRun\command - G:\InstallTomTomHOME.exe


======List of files/folders created in the last 1 months======

2008-09-21 03:30:25 ----A---- C:\ComboFix.txt
2008-09-20 19:14:44 ----SHD---- C:\RECYCLER
2008-09-20 15:41:44 ----A---- C:\Boot.bak
2008-09-20 15:41:32 ----D---- C:\cmdcons
2008-09-20 15:38:36 ----D---- C:\WINDOWS\erdnt
2008-09-20 15:35:43 ----D---- C:\QooBox
2008-09-20 15:34:44 ----A---- C:\WINDOWS\zip.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\swreg.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\sed.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\Nircmd.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\grep.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\VFind.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\swxcacls.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\SWSC.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\fdsv.exe
2008-09-20 14:51:50 ----D---- C:\rsit
2008-09-15 22:16:20 ----D---- C:\Program Files\Trend Micro
2008-09-15 15:34:38 ----A---- C:\WINDOWS\wininit.ini
2008-09-14 09:06:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\getuname.dll
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\charmap.exe
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\calc.exe
2008-09-14 08:14:49 ----D---- C:\Program Files\MSN
2008-09-13 02:20:14 ----D---- C:\Program Files\XoftSpySE
2008-09-11 21:00:46 ----D---- C:\Program Files\process Explorer
2008-09-09 17:55:11 ----D---- C:\Documents and Settings\Owner\Application Data\Nero
2008-09-09 17:49:55 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2008-09-09 17:36:01 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2008-09-09 17:36:00 ----D---- C:\Program Files\Common Files\Nero
2008-09-09 16:57:28 ----A---- C:\WINDOWS\system32\17e2d5ba-.txt
2008-09-08 02:00:20 ----D---- C:\Documents and Settings\Owner\Application Data\DivX
2008-09-01 13:43:26 ----A---- C:\WINDOWS\system32\XceedZip.dll
2008-09-01 12:56:43 ----D---- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-01 09:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2008-09-01 09:10:19 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2008-09-01 09:09:32 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-31 11:46:12 ----A---- C:\WINDOWS\system32\spmsg.dll
2008-08-31 11:46:05 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2008-08-31 11:44:06 ----D---- C:\Program Files\Windows Media Connect 2
2008-08-31 11:43:37 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2008-08-31 11:40:48 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2008-08-31 11:39:29 ----D---- C:\WINDOWS\system32\LogFiles
2008-08-31 11:39:14 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2008-08-31 03:13:29 ----D---- C:\Program Files\7-Zip
2008-08-31 02:45:11 ----SHD---- C:\Config.Msi
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxssend.exe
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsroute.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsperf.ini
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsclntR.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxscfgwz.dll
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaws.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaw.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\java.exe
2008-08-24 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-08-23 03:07:59 ----D---- C:\WINDOWS\Prefetch
2008-08-23 02:12:26 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-08-23 02:12:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-08-23 02:11:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-08-23 02:11:38 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-08-23 02:11:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-23 02:11:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-08-23 02:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-08-23 02:10:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-08-23 02:10:21 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-08-23 02:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-08-23 01:59:25 ----D---- C:\WINDOWS\system32\scripting
2008-08-23 01:59:22 ----D---- C:\WINDOWS\l2schemas
2008-08-23 01:59:19 ----D---- C:\WINDOWS\system32\en
2008-08-22 01:10:31 ----A---- C:\WINDOWS\system32\wmphoto.dll
2008-08-22 01:10:24 ----A---- C:\WINDOWS\system32\wlanapi.dll
2008-08-22 01:10:22 ----A---- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-22 01:10:22 ----A---- C:\WINDOWS\system32\windowscodecs.dll
2008-08-22 01:10:03 ----A---- C:\WINDOWS\system32\tspkg.dll
2008-08-22 01:10:03 ----A---- C:\WINDOWS\system32\tsgqec.dll
2008-08-22 01:09:37 ----A---- C:\WINDOWS\system32\setupn.exe
2008-08-22 01:09:28 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2008-08-22 01:09:24 ----A---- C:\WINDOWS\system32\rasqec.dll
2008-08-22 01:09:23 ----A---- C:\WINDOWS\system32\qutil.dll
2008-08-22 01:09:21 ----A---- C:\WINDOWS\system32\qcliprov.dll
2008-08-22 01:09:20 ----A---- C:\WINDOWS\system32\qagentrt.dll
2008-08-22 01:09:20 ----A---- C:\WINDOWS\system32\qagent.dll
2008-08-22 01:09:17 ----A---- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-22 01:09:11 ----A---- C:\WINDOWS\system32\onex.dll
2008-08-22 01:08:52 ----A---- C:\WINDOWS\system32\napstat.exe
2008-08-22 01:08:52 ----A---- C:\WINDOWS\system32\napmontr.dll
2008-08-22 01:08:52 ----A---- C:\WINDOWS\system32\napipsec.dll
2008-08-22 01:08:44 ----A---- C:\WINDOWS\system32\msshavmsg.dll
2008-08-22 01:08:44 ----A---- C:\WINDOWS\system32\mssha.dll
2008-08-22 01:08:17 ----A---- C:\WINDOWS\system32\mmcperf.exe
2008-08-22 01:08:16 ----A---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-22 01:08:16 ----A---- C:\WINDOWS\system32\mmcex.dll
2008-08-22 01:08:16 ----A---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-22 01:07:59 ----A---- C:\WINDOWS\system32\l2gpstore.dll
2008-08-22 01:07:58 ----A---- C:\WINDOWS\system32\kmsvc.dll
2008-08-22 01:07:55 ----A---- C:\WINDOWS\system32\kbdpash.dll
2008-08-22 01:07:55 ----A---- C:\WINDOWS\system32\kbdnepr.dll
2008-08-22 01:07:55 ----A---- C:\WINDOWS\system32\kbdiultn.dll
2008-08-22 01:07:54 ----A---- C:\WINDOWS\system32\kbdbhc.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapsvc.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapqec.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eappprxy.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapphost.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eappgnui.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eappcfg.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapp3hst.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapolqec.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3ui.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3svc.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3msm.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3dlg.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3cfg.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3api.dll
2008-08-22 01:07:01 ----A---- C:\WINDOWS\system32\dimsroam.dll
2008-08-22 01:07:01 ----A---- C:\WINDOWS\system32\dimsntfy.dll
2008-08-22 01:07:00 ----A---- C:\WINDOWS\system32\dhcpqec.dll
2008-08-22 01:06:54 ----A---- C:\WINDOWS\system32\credssp.dll
2008-08-22 01:06:37 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2008-08-22 01:06:36 ----A---- C:\WINDOWS\system32\azroles.dll
2008-08-22 01:06:16 ----A---- C:\WINDOWS\system32\aaclient.dll

======List of files/folders modified in the last 1 months======

2008-09-21 03:38:42 ----D---- C:\WINDOWS\Temp
2008-09-21 03:33:55 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-09-21 03:31:15 ----D---- C:\WINDOWS\system32
2008-09-21 03:24:33 ----D---- C:\WINDOWS
2008-09-21 03:24:33 ----A---- C:\WINDOWS\system.ini
2008-09-21 03:22:28 ----D---- C:\WINDOWS\system32\drivers
2008-09-21 03:22:27 ----D---- C:\WINDOWS\AppPatch
2008-09-21 03:22:27 ----D---- C:\Program Files\Common Files
2008-09-20 19:13:10 ----D---- C:\WINDOWS\system32\CatRoot2
2008-09-20 18:57:16 ----AC---- C:\WINDOWS\ModemLog_Generic 56K HCF Data Fax Modem.txt
2008-09-20 18:54:12 ----D---- C:\WINDOWS\system32\config
2008-09-20 18:28:02 ----RD---- C:\Program Files
2008-09-20 17:08:28 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 15:42:40 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-09-20 15:41:44 ----RASH---- C:\boot.ini
2008-09-19 17:00:04 ----D---- C:\Program Files\Mozilla Thunderbird
2008-09-19 12:19:51 ----D---- C:\WINDOWS\system32\FxsTmp
2008-09-15 22:12:31 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-09-15 16:27:38 ----SHD---- C:\System Volume Information
2008-09-15 16:27:38 ----D---- C:\WINDOWS\system32\Restore
2008-09-14 13:02:05 ----D---- C:\WINDOWS\security
2008-09-14 08:27:31 ----D---- C:\Program Files\Mozilla Firefox
2008-09-14 08:16:15 ----A---- C:\WINDOWS\imsins.BAK
2008-09-14 08:15:23 ----D---- C:\Program Files\Online Services
2008-09-14 08:15:06 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-09-14 08:15:06 ----D---- C:\WINDOWS\Cursors
2008-09-14 08:15:00 ----D---- C:\WINDOWS\Help
2008-09-14 08:14:58 ----D---- C:\WINDOWS\system32\wbem
2008-09-13 21:30:31 ----D---- C:\Program Files\Windows NT
2008-09-13 02:20:47 ----SD---- C:\WINDOWS\Tasks
2008-09-12 02:08:23 ----HD---- C:\WINDOWS\inf
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Minidump
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Debug
2008-09-12 02:08:22 ----SHD---- C:\WINDOWS\Installer
2008-09-11 02:53:23 ----D---- C:\WINDOWS\system32\en-US
2008-09-11 02:53:23 ----D---- C:\Program Files\Internet Explorer
2008-09-11 02:23:24 ----D---- C:\WINDOWS\system32\CatRoot
2008-09-11 01:38:54 ----RSD---- C:\WINDOWS\Fonts
2008-09-10 14:00:35 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-10 10:57:42 ----D---- C:\WINDOWS\Registration
2008-09-09 17:15:04 ----D---- C:\WINDOWS\WinSxS
2008-09-08 01:57:54 ----D---- C:\Program Files\ws ftp tiscali
2008-09-02 17:00:33 ----D---- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-09-01 13:11:40 ----HD---- C:\Program Files\InstallShield Installation Information
2008-09-01 12:58:22 ----RSD---- C:\WINDOWS\assembly
2008-08-31 20:21:10 ----AC---- C:\WINDOWS\NeroDigital.ini
2008-08-31 11:50:23 ----D---- C:\Program Files\Windows Media Player
2008-08-31 11:44:45 ----AC---- C:\WINDOWS\win.ini
2008-08-31 02:45:12 ----D---- C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-28 09:48:14 ----D---- C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-08-27 18:16:44 ----D---- C:\WINDOWS\system32\Adobe
2008-08-27 18:16:19 ----D---- C:\Documents and Settings\Owner\Application Data\Adobe
2008-08-27 09:00:26 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-08-26 22:33:21 ----D---- C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-08-26 10:26:22 ----D---- C:\WINDOWS\addins
2008-08-26 10:17:39 ----D---- C:\Program Files\McAfee
2008-08-24 23:22:04 ----D---- C:\Program Files\Java
2008-08-23 12:46:51 ----HD---- C:\WINDOWS\$hf_mig$
2008-08-23 08:03:46 ----AC---- C:\WINDOWS\OEWABLog.txt
2008-08-23 03:08:39 ----AC---- C:\WINDOWS\setuplog.txt
2008-08-23 03:07:19 ----D---- C:\WINDOWS\system32\Setup
2008-08-23 02:10:05 ----D---- C:\Program Files\Messenger
2008-08-23 02:00:05 ----D---- C:\WINDOWS\ServicePackFiles
2008-08-23 02:00:00 ----D---- C:\WINDOWS\network diagnostic
2008-08-23 01:59:59 ----D---- C:\WINDOWS\ime
2008-08-23 01:59:28 ----D---- C:\WINDOWS\system32\usmt
2008-08-23 01:59:18 ----D---- C:\WINDOWS\system32\bits
2008-08-23 01:59:18 ----D---- C:\WINDOWS\peernet
2008-08-23 01:59:18 ----D---- C:\Program Files\Movie Maker
2008-08-23 01:52:28 ----D---- C:\WINDOWS\system32\npp
2008-08-23 01:52:25 ----D---- C:\WINDOWS\msagent
2008-08-23 01:52:22 ----D---- C:\WINDOWS\srchasst
2008-08-23 01:52:16 ----D---- C:\Program Files\NetMeeting
2008-08-23 01:52:13 ----D---- C:\WINDOWS\system32\Com
2008-08-23 01:52:07 ----D---- C:\Program Files\Outlook Express
2008-08-23 01:52:01 ----D---- C:\Program Files\Common Files\System
2008-08-23 01:51:25 ----D---- C:\WINDOWS\system32\oobe
2008-08-23 01:51:22 ----D---- C:\WINDOWS\system
2008-08-23 01:45:21 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-08-23 01:44:38 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-08-23 01:33:05 ----D---- C:\WINDOWS\EHome
2008-08-22 18:12:04 ----AC---- C:\WINDOWS\CDSEDB01.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ATMhelpr;ATMhelpr; C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 4064]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2008-07-23 9464]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2002-12-17 241152]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2008-06-27 207656]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2008-06-02 120136]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2004-04-08 143834]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2002-12-17 206464]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-18 12032]
R3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2004-03-02 127065]
R3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2004-08-04 327040]
R3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2004-04-08 25898]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704]
R3 HCF_MSFT;HCF_MSFT; C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys [2001-08-17 907456]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2008-06-27 79240]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2008-06-27 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2008-06-27 40488]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NeroCd2k;NeroCd2k; C:\WINDOWS\system32\drivers\NeroCd2k.sys [2001-04-16 44227]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2008-07-23 9336]
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2004-03-02 50007]
S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GT680x;GrandTechICNameNT; C:\WINDOWS\System32\Drivers\gt680x.sys [2001-11-08 18120]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 ICAM3NT5;Intel USB Video Camera III; C:\WINDOWS\System32\Drivers\Icam3.sys [2001-08-17 141056]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2008-06-20 34152]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2004-04-08 30630]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2006-03-30 96341]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [2002-01-30 77824]
R2 EPSONStatusAgent2;EPSON Printer Status Agent2; C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe [2001-10-25 90112]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-08-23 79136]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-06-21 792184]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-07-18 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2008-07-09 358736]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2008-06-20 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2008-07-09 25416]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2008-04-14 33280]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2008-06-20 605512]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MBackMonitor;MBackMonitor; C:\Program Files\McAfee\MBK\MBackMonitor.exe [2008-07-10 66848]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2008-06-20 361800]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------

Shaba
2008-09-21, 12:37
Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply along with a fresh HijackThis log.

If you need a tutorial, see here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif)

Fred of Kings Lynn
2008-09-21, 20:46
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Sunday, September 21, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Sunday, September 21, 2008 10:23:16
Records in database: 1247045
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 96157
Threat name: 7
Infected objects: 9
Suspicious objects: 14
Duration of the scan: 04:51:20


File name / Threat name / Threats count
C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\83hp3al7.slt\Mail\pop.tiscali.co.uk\Inbox Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\5iknb6nu.default\Mail\pop.tiscali.co.uk\Inbox Suspicious: Trojan-Spy.HTML.Fraud.gen 3
C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\5iknb6nu.default\Mail\pop.tiscali.co.uk\McAfee Anti-Spam Suspicious: Trojan-Spy.HTML.Fraud.gen 10
C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\5iknb6nu.default\Mail\pop3.tiscali.co.uk\McAfee Anti-Spam Infected: Trojan-Downloader.Win32.Obitel.b 1
C:\Program Files\Mozilla Firefox\plugins\NPMySrch.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i 1
C:\Program Files\MySearch\bar\1.bin\NPMYSRCH.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i 1
C:\Program Files\MySearch\bar\1.bin\S4PLUGIN.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as 1
C:\Program Files\Netscape\Netscape Browser\plugins\NPMySrch.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i 1
C:\QooBox\Quarantine\C\WINDOWS\system32\lssxmytt.dll.vir Infected: Trojan.Win32.Monder.pnd 1
C:\QooBox\Quarantine\C\WINDOWS\system32\mycnytnb.dll.vir Infected: Trojan.Win32.Monder.pnn 1
C:\QooBox\Quarantine\C\WINDOWS\system32\qbtmatry.dll.vir Infected: Trojan.Win32.Monder.pnd 1
C:\QooBox\Quarantine\C\WINDOWS\system32\qkqaqslw.dll.vir Infected: Trojan.Win32.Monder.pno 1

The selected area was scanned.



Logfile of random's system information tool 1.02 (written by random/random)
Run by Owner at 2008-09-21 18:41:28
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 4 GB (23%) free of 20 GB
Total RAM: 383 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:41:39, on 21/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Owner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.co.uk/"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CNetscape_UK.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (file missing)
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{865FD82A-61A9-40E1-B551-DB3C7F08964C}: NameServer = 212.139.132.37 212.139.132.36
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O24 - Desktop Component 0: (no name) - http://news.bbc.co.uk/

--
End of file - 7766 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Disk Cleanup.job
C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{089FD14D-132B-48FC-8861-0048AE113215}]
C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-07-07 1562448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-08-04 343112]
{0BF43445-2F28-4351-9252-17FE6E806AA0} - McAfee SiteAdvisor - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]
{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - Ask Toolbar - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"EEventManager"=C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2005-04-08 102400]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2008-07-11 641208]
"SiteAdvisor"=C:\Program Files\SiteAdvisor\6172\SiteAdv.exe [2007-08-24 36640]
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe [2008-06-13 1176808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\System32\NeroCheck.exe [2001-07-09 155648]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
EPSON Background Monitor.lnk - C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoWinKeys"=0
"NoFileAssociate"=0
"NoCommonGroups"=0
"NoSimpleStartMenu"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\fxsclnt.exe"="C:\WINDOWS\system32\fxsclnt.exe:*:Disabled:Microsoft Fax Console"
"C:\Program Files\ws ftp tiscali\WS_FTP95.exe"="C:\Program Files\ws ftp tiscali\WS_FTP95.exe:*:Enabled:WS_FTP 95"
"C:\Program Files\Abacast\Abaclient.exe"="C:\Program Files\Abacast\Abaclient.exe:*:Enabled:Abaclient"
"C:\Program Files\Netscape\Netscape\Netscp.exe"="C:\Program Files\Netscape\Netscape\Netscp.exe:*:Enabled:Netscp"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b3ab410-5bbe-11dd-88c4-4d6564696130}]
shell\AutoRun\command - G:\InstallTomTomHOME.exe


======List of files/folders created in the last 1 months======

2008-09-21 04:05:55 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-09-21 04:04:16 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-21 03:30:25 ----A---- C:\ComboFix.txt
2008-09-20 19:14:44 ----SHD---- C:\RECYCLER
2008-09-20 15:41:44 ----A---- C:\Boot.bak
2008-09-20 15:41:32 ----D---- C:\cmdcons
2008-09-20 15:38:36 ----D---- C:\WINDOWS\erdnt
2008-09-20 15:35:43 ----D---- C:\QooBox
2008-09-20 15:34:44 ----A---- C:\WINDOWS\zip.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\swreg.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\sed.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\Nircmd.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\grep.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\VFind.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\swxcacls.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\SWSC.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\fdsv.exe
2008-09-20 14:51:50 ----D---- C:\rsit
2008-09-15 22:16:20 ----D---- C:\Program Files\Trend Micro
2008-09-15 15:34:38 ----A---- C:\WINDOWS\wininit.ini
2008-09-14 09:06:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\getuname.dll
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\charmap.exe
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\calc.exe
2008-09-14 08:14:49 ----D---- C:\Program Files\MSN
2008-09-11 21:00:46 ----D---- C:\Program Files\process Explorer
2008-09-09 17:55:11 ----D---- C:\Documents and Settings\Owner\Application Data\Nero
2008-09-09 17:49:55 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2008-09-09 17:36:01 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2008-09-09 17:36:00 ----D---- C:\Program Files\Common Files\Nero
2008-09-09 16:57:28 ----A---- C:\WINDOWS\system32\17e2d5ba-.txt
2008-09-08 02:00:20 ----D---- C:\Documents and Settings\Owner\Application Data\DivX
2008-09-01 13:43:26 ----A---- C:\WINDOWS\system32\XceedZip.dll
2008-09-01 12:56:43 ----D---- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-01 09:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2008-09-01 09:10:19 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2008-09-01 09:09:32 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-31 11:46:12 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-08-31 11:46:05 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2008-08-31 11:44:06 ----D---- C:\Program Files\Windows Media Connect 2
2008-08-31 11:43:37 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2008-08-31 11:40:48 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2008-08-31 11:39:29 ----D---- C:\WINDOWS\system32\LogFiles
2008-08-31 11:39:14 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2008-08-31 03:13:29 ----D---- C:\Program Files\7-Zip
2008-08-31 02:45:11 ----SHD---- C:\Config.Msi
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxssend.exe
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsroute.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsperf.ini
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsclntR.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxscfgwz.dll
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaws.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaw.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\java.exe
2008-08-24 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-08-23 03:07:59 ----D---- C:\WINDOWS\Prefetch
2008-08-23 02:12:26 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-08-23 02:12:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-08-23 02:11:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-08-23 02:11:38 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-08-23 02:11:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-23 02:11:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-08-23 02:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-08-23 02:10:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-08-23 02:10:21 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-08-23 02:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-08-23 01:59:25 ----D---- C:\WINDOWS\system32\scripting
2008-08-23 01:59:22 ----D---- C:\WINDOWS\l2schemas
2008-08-23 01:59:19 ----D---- C:\WINDOWS\system32\en
2008-08-22 01:10:31 ----A---- C:\WINDOWS\system32\wmphoto.dll
2008-08-22 01:10:24 ----A---- C:\WINDOWS\system32\wlanapi.dll
2008-08-22 01:10:22 ----A---- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-22 01:10:22 ----A---- C:\WINDOWS\system32\windowscodecs.dll
2008-08-22 01:10:03 ----A---- C:\WINDOWS\system32\tspkg.dll
2008-08-22 01:10:03 ----A---- C:\WINDOWS\system32\tsgqec.dll
2008-08-22 01:09:37 ----A---- C:\WINDOWS\system32\setupn.exe
2008-08-22 01:09:28 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2008-08-22 01:09:24 ----A---- C:\WINDOWS\system32\rasqec.dll
2008-08-22 01:09:23 ----A---- C:\WINDOWS\system32\qutil.dll
2008-08-22 01:09:21 ----A---- C:\WINDOWS\system32\qcliprov.dll
2008-08-22 01:09:20 ----A---- C:\WINDOWS\system32\qagentrt.dll
2008-08-22 01:09:20 ----A---- C:\WINDOWS\system32\qagent.dll
2008-08-22 01:09:17 ----A---- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-22 01:09:11 ----A---- C:\WINDOWS\system32\onex.dll
2008-08-22 01:08:52 ----A---- C:\WINDOWS\system32\napstat.exe
2008-08-22 01:08:52 ----A---- C:\WINDOWS\system32\napmontr.dll
2008-08-22 01:08:52 ----A---- C:\WINDOWS\system32\napipsec.dll
2008-08-22 01:08:44 ----A---- C:\WINDOWS\system32\msshavmsg.dll
2008-08-22 01:08:44 ----A---- C:\WINDOWS\system32\mssha.dll
2008-08-22 01:08:17 ----A---- C:\WINDOWS\system32\mmcperf.exe
2008-08-22 01:08:16 ----A---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-22 01:08:16 ----A---- C:\WINDOWS\system32\mmcex.dll
2008-08-22 01:08:16 ----A---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-22 01:07:59 ----A---- C:\WINDOWS\system32\l2gpstore.dll
2008-08-22 01:07:58 ----A---- C:\WINDOWS\system32\kmsvc.dll
2008-08-22 01:07:55 ----A---- C:\WINDOWS\system32\kbdpash.dll
2008-08-22 01:07:55 ----A---- C:\WINDOWS\system32\kbdnepr.dll
2008-08-22 01:07:55 ----A---- C:\WINDOWS\system32\kbdiultn.dll
2008-08-22 01:07:54 ----A---- C:\WINDOWS\system32\kbdbhc.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapsvc.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapqec.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eappprxy.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapphost.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eappgnui.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eappcfg.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapp3hst.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapolqec.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3ui.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3svc.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3msm.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3dlg.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3cfg.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3api.dll
2008-08-22 01:07:01 ----A---- C:\WINDOWS\system32\dimsroam.dll
2008-08-22 01:07:01 ----A---- C:\WINDOWS\system32\dimsntfy.dll
2008-08-22 01:07:00 ----A---- C:\WINDOWS\system32\dhcpqec.dll
2008-08-22 01:06:54 ----A---- C:\WINDOWS\system32\credssp.dll
2008-08-22 01:06:37 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2008-08-22 01:06:36 ----A---- C:\WINDOWS\system32\azroles.dll
2008-08-22 01:06:16 ----A---- C:\WINDOWS\system32\aaclient.dll

======List of files/folders modified in the last 1 months======

2008-09-21 17:43:49 ----D---- C:\WINDOWS\Temp
2008-09-21 11:40:05 ----D---- C:\Documents and Settings\Owner\Application Data\SiteAdvisor
2008-09-21 09:50:38 ----D---- C:\WINDOWS\Help
2008-09-21 09:37:53 ----D---- C:\WINDOWS\system32\FxsTmp
2008-09-21 09:35:05 ----AC---- C:\WINDOWS\ModemLog_Generic 56K HCF Data Fax Modem.txt
2008-09-21 09:30:02 ----D---- C:\Program Files\Mozilla Thunderbird
2008-09-21 08:39:24 ----D---- C:\WINDOWS
2008-09-21 04:09:17 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-09-21 04:06:52 ----HD---- C:\WINDOWS\inf
2008-09-21 04:06:49 ----D---- C:\WINDOWS\system32
2008-09-21 04:06:46 ----D---- C:\WINDOWS\system32\CatRoot
2008-09-21 04:06:45 ----D---- C:\WINDOWS\system32\CatRoot2
2008-09-21 04:05:57 ----D---- C:\WINDOWS\WinSxS
2008-09-21 04:04:28 ----A---- C:\WINDOWS\imsins.BAK
2008-09-21 03:48:41 ----RD---- C:\Program Files
2008-09-21 03:48:40 ----SD---- C:\WINDOWS\Tasks
2008-09-21 03:24:33 ----A---- C:\WINDOWS\system.ini
2008-09-21 03:22:28 ----D---- C:\WINDOWS\system32\drivers
2008-09-21 03:22:27 ----D---- C:\WINDOWS\AppPatch
2008-09-21 03:22:27 ----D---- C:\Program Files\Common Files
2008-09-20 18:54:12 ----D---- C:\WINDOWS\system32\config
2008-09-20 17:08:28 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 15:42:40 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-09-20 15:41:44 ----RASH---- C:\boot.ini
2008-09-15 22:12:31 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-09-15 16:27:38 ----SHD---- C:\System Volume Information
2008-09-15 16:27:38 ----D---- C:\WINDOWS\system32\Restore
2008-09-14 13:02:05 ----D---- C:\WINDOWS\security
2008-09-14 08:27:31 ----D---- C:\Program Files\Mozilla Firefox
2008-09-14 08:15:23 ----D---- C:\Program Files\Online Services
2008-09-14 08:15:06 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-09-14 08:15:06 ----D---- C:\WINDOWS\Cursors
2008-09-14 08:14:58 ----D---- C:\WINDOWS\system32\wbem
2008-09-13 21:30:31 ----D---- C:\Program Files\Windows NT
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Minidump
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Debug
2008-09-12 02:08:22 ----SHD---- C:\WINDOWS\Installer
2008-09-11 02:53:23 ----D---- C:\WINDOWS\system32\en-US
2008-09-11 02:53:23 ----D---- C:\Program Files\Internet Explorer
2008-09-11 01:38:54 ----RSD---- C:\WINDOWS\Fonts
2008-09-10 14:00:35 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-10 10:57:42 ----D---- C:\WINDOWS\Registration
2008-09-08 01:57:54 ----D---- C:\Program Files\ws ftp tiscali
2008-09-02 17:00:33 ----D---- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-09-01 13:11:40 ----HD---- C:\Program Files\InstallShield Installation Information
2008-09-01 12:58:22 ----RSD---- C:\WINDOWS\assembly
2008-08-31 20:21:10 ----AC---- C:\WINDOWS\NeroDigital.ini
2008-08-31 11:50:23 ----D---- C:\Program Files\Windows Media Player
2008-08-31 11:44:45 ----AC---- C:\WINDOWS\win.ini
2008-08-31 02:45:12 ----D---- C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-28 09:48:14 ----D---- C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-08-27 18:16:44 ----D---- C:\WINDOWS\system32\Adobe
2008-08-27 18:16:19 ----D---- C:\Documents and Settings\Owner\Application Data\Adobe
2008-08-27 09:00:26 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-08-26 22:33:21 ----D---- C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-08-26 21:28:12 ----AC---- C:\WINDOWS\system32\MRT.exe
2008-08-26 10:26:22 ----D---- C:\WINDOWS\addins
2008-08-26 10:17:39 ----D---- C:\Program Files\McAfee
2008-08-24 23:22:04 ----D---- C:\Program Files\Java
2008-08-23 12:46:51 ----HD---- C:\WINDOWS\$hf_mig$
2008-08-23 08:03:46 ----AC---- C:\WINDOWS\OEWABLog.txt
2008-08-23 03:08:39 ----AC---- C:\WINDOWS\setuplog.txt
2008-08-23 03:07:19 ----D---- C:\WINDOWS\system32\Setup
2008-08-23 02:10:05 ----D---- C:\Program Files\Messenger
2008-08-23 02:00:05 ----D---- C:\WINDOWS\ServicePackFiles
2008-08-23 02:00:00 ----D---- C:\WINDOWS\network diagnostic
2008-08-23 01:59:59 ----D---- C:\WINDOWS\ime
2008-08-23 01:59:28 ----D---- C:\WINDOWS\system32\usmt
2008-08-23 01:59:18 ----D---- C:\WINDOWS\system32\bits
2008-08-23 01:59:18 ----D---- C:\WINDOWS\peernet
2008-08-23 01:59:18 ----D---- C:\Program Files\Movie Maker
2008-08-23 01:52:28 ----D---- C:\WINDOWS\system32\npp
2008-08-23 01:52:25 ----D---- C:\WINDOWS\msagent
2008-08-23 01:52:22 ----D---- C:\WINDOWS\srchasst
2008-08-23 01:52:16 ----D---- C:\Program Files\NetMeeting
2008-08-23 01:52:13 ----D---- C:\WINDOWS\system32\Com
2008-08-23 01:52:07 ----D---- C:\Program Files\Outlook Express
2008-08-23 01:52:01 ----D---- C:\Program Files\Common Files\System
2008-08-23 01:51:25 ----D---- C:\WINDOWS\system32\oobe
2008-08-23 01:51:22 ----D---- C:\WINDOWS\system
2008-08-23 01:45:21 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-08-23 01:44:38 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-08-23 01:33:05 ----D---- C:\WINDOWS\EHome
2008-08-22 18:12:04 ----AC---- C:\WINDOWS\CDSEDB01.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ATMhelpr;ATMhelpr; C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 4064]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2008-07-23 9464]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2002-12-17 241152]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2008-06-27 207656]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2008-06-02 120136]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2004-04-08 143834]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2002-12-17 206464]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-18 12032]
R3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2004-03-02 127065]
R3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2004-08-04 327040]
R3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2004-04-08 25898]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704]
R3 HCF_MSFT;HCF_MSFT; C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys [2001-08-17 907456]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2008-06-27 79240]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2008-06-27 35240]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NeroCd2k;NeroCd2k; C:\WINDOWS\system32\drivers\NeroCd2k.sys [2001-04-16 44227]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2008-07-23 9336]
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2004-03-02 50007]
S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GT680x;GrandTechICNameNT; C:\WINDOWS\System32\Drivers\gt680x.sys [2001-11-08 18120]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 ICAM3NT5;Intel USB Video Camera III; C:\WINDOWS\System32\Drivers\Icam3.sys [2001-08-17 141056]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2008-06-20 34152]
S3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2008-06-27 40488]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2004-04-08 30630]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2006-03-30 96341]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [2002-01-30 77824]
R2 EPSONStatusAgent2;EPSON Printer Status Agent2; C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe [2001-10-25 90112]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-08-23 79136]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-06-21 792184]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-07-18 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2008-07-09 358736]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2008-06-20 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2008-07-09 25416]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2008-04-14 33280]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MBackMonitor;MBackMonitor; C:\Program Files\McAfee\MBK\MBackMonitor.exe [2008-07-10 66848]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2008-06-20 361800]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2008-06-20 605512]

-----------------EOF-----------------

Shaba
2008-09-21, 20:52
Empty McAfee Anti-Spam in tiscali inbox.

Delete these:

C:\Program Files\Mozilla Firefox\plugins\NPMySrch.dll
C:\Program Files\MySearch
C:\Program Files\Netscape\Netscape Browser\plugins\NPMySrch.dll

Empty this folder:

C:\QooBox\Quarantine

Empty Recycle Bin.

Still problems?

Fred of Kings Lynn
2008-09-21, 22:27
Hello Shaba,
Thank you for all your help.

I thought a system re-start would be the ideal way to go forward.

On closing down I got these two messages:

"Access violation at address 694c5405. Read at address 694c5405"

and

"Access violation at address 00470A21 in module "Tea Timer.exe" Read at address 00000010"


On re-starting the system I received these two messages:

"Error loading C:windows\System32\9kqaqslw.dll"
The specified module could not be found.

and

"Error loading C:windows\System32\Mycnytnb.dll"
The specified module could not be found.


I clicked through all notification boxes on closing down and restarting.

Shaba
2008-09-21, 22:33
Looks like TeaTimer put back some entries which was not purpose.

Please post a fresh HijackThis log.

Fred of Kings Lynn
2008-09-21, 22:45
Logfile of random's system information tool 1.02 (written by random/random)
Run by Owner at 2008-09-21 20:41:37
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 4 GB (23%) free of 20 GB
Total RAM: 383 MB (19% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:41:48, on 21/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Owner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.co.uk/"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CNetscape_UK.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: (no name) - {42FEA74B-6462-49F6-959A-2BFD0628CE3E} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (file missing)
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [1cc111c4] rundll32.exe "C:\WINDOWS\system32\mycnytnb.dll",b
O4 - HKLM\..\Run: [BM1ff22258] Rundll32.exe "C:\WINDOWS\system32\qkqaqslw.dll",s
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{865FD82A-61A9-40E1-B551-DB3C7F08964C}: NameServer = 212.139.132.8 212.139.132.9
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O24 - Desktop Component 0: (no name) - http://news.bbc.co.uk/

--
End of file - 8291 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Disk Cleanup.job
C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{089FD14D-132B-48FC-8861-0048AE113215}]
C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{42FEA74B-6462-49F6-959A-2BFD0628CE3E}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-07-07 1562448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-08-04 343112]
{0BF43445-2F28-4351-9252-17FE6E806AA0} - McAfee SiteAdvisor - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]
{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - Ask Toolbar - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"EEventManager"=C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2005-04-08 102400]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2008-07-11 641208]
"SiteAdvisor"=C:\Program Files\SiteAdvisor\6172\SiteAdv.exe [2007-08-24 36640]
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe [2008-06-13 1176808]
"1cc111c4"=C:\WINDOWS\system32\mycnytnb.dll []
"BM1ff22258"=C:\WINDOWS\system32\qkqaqslw.dll []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-08-18 1832272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\System32\NeroCheck.exe [2001-07-09 155648]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
EPSON Background Monitor.lnk - C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoWinKeys"=0
"NoFileAssociate"=0
"NoCommonGroups"=0
"NoSimpleStartMenu"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\fxsclnt.exe"="C:\WINDOWS\system32\fxsclnt.exe:*:Disabled:Microsoft Fax Console"
"C:\Program Files\ws ftp tiscali\WS_FTP95.exe"="C:\Program Files\ws ftp tiscali\WS_FTP95.exe:*:Enabled:WS_FTP 95"
"C:\Program Files\Abacast\Abaclient.exe"="C:\Program Files\Abacast\Abaclient.exe:*:Enabled:Abaclient"
"C:\Program Files\Netscape\Netscape\Netscp.exe"="C:\Program Files\Netscape\Netscape\Netscp.exe:*:Enabled:Netscp"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b3ab410-5bbe-11dd-88c4-4d6564696130}]
shell\AutoRun\command - G:\InstallTomTomHOME.exe


======List of files/folders created in the last 1 months======

2008-09-21 04:05:55 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-09-21 04:04:16 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-21 03:30:25 ----A---- C:\ComboFix.txt
2008-09-20 19:14:44 ----SHD---- C:\RECYCLER
2008-09-20 15:41:44 ----A---- C:\Boot.bak
2008-09-20 15:41:32 ----D---- C:\cmdcons
2008-09-20 15:38:36 ----D---- C:\WINDOWS\erdnt
2008-09-20 15:35:43 ----D---- C:\QooBox
2008-09-20 15:34:44 ----A---- C:\WINDOWS\zip.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\swreg.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\sed.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\Nircmd.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\grep.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\VFind.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\swxcacls.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\SWSC.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\fdsv.exe
2008-09-20 14:51:50 ----D---- C:\rsit
2008-09-15 22:16:20 ----D---- C:\Program Files\Trend Micro
2008-09-15 15:34:38 ----A---- C:\WINDOWS\wininit.ini
2008-09-14 09:06:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\getuname.dll
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\charmap.exe
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\calc.exe
2008-09-14 08:14:49 ----D---- C:\Program Files\MSN
2008-09-11 21:00:46 ----D---- C:\Program Files\process Explorer
2008-09-09 17:55:11 ----D---- C:\Documents and Settings\Owner\Application Data\Nero
2008-09-09 17:49:55 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2008-09-09 17:36:01 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2008-09-09 17:36:00 ----D---- C:\Program Files\Common Files\Nero
2008-09-09 16:57:28 ----A---- C:\WINDOWS\system32\17e2d5ba-.txt
2008-09-08 02:00:20 ----D---- C:\Documents and Settings\Owner\Application Data\DivX
2008-09-01 13:43:26 ----A---- C:\WINDOWS\system32\XceedZip.dll
2008-09-01 12:56:43 ----D---- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-01 09:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2008-09-01 09:10:19 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2008-09-01 09:09:32 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-31 11:46:12 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-08-31 11:46:05 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2008-08-31 11:44:06 ----D---- C:\Program Files\Windows Media Connect 2
2008-08-31 11:43:37 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2008-08-31 11:40:48 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2008-08-31 11:39:29 ----D---- C:\WINDOWS\system32\LogFiles
2008-08-31 11:39:14 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2008-08-31 03:13:29 ----D---- C:\Program Files\7-Zip
2008-08-31 02:45:11 ----SHD---- C:\Config.Msi
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxssend.exe
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsroute.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsperf.ini
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsclntR.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxscfgwz.dll
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaws.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaw.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\java.exe
2008-08-24 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-08-23 03:07:59 ----D---- C:\WINDOWS\Prefetch
2008-08-23 02:12:26 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-08-23 02:12:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-08-23 02:11:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-08-23 02:11:38 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-08-23 02:11:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-23 02:11:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-08-23 02:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-08-23 02:10:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-08-23 02:10:21 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-08-23 02:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-08-23 01:59:25 ----D---- C:\WINDOWS\system32\scripting
2008-08-23 01:59:22 ----D---- C:\WINDOWS\l2schemas
2008-08-23 01:59:19 ----D---- C:\WINDOWS\system32\en
2008-08-22 01:10:31 ----A---- C:\WINDOWS\system32\wmphoto.dll
2008-08-22 01:10:24 ----A---- C:\WINDOWS\system32\wlanapi.dll
2008-08-22 01:10:22 ----A---- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-22 01:10:22 ----A---- C:\WINDOWS\system32\windowscodecs.dll
2008-08-22 01:10:03 ----A---- C:\WINDOWS\system32\tspkg.dll
2008-08-22 01:10:03 ----A---- C:\WINDOWS\system32\tsgqec.dll
2008-08-22 01:09:37 ----A---- C:\WINDOWS\system32\setupn.exe
2008-08-22 01:09:28 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2008-08-22 01:09:24 ----A---- C:\WINDOWS\system32\rasqec.dll
2008-08-22 01:09:23 ----A---- C:\WINDOWS\system32\qutil.dll
2008-08-22 01:09:21 ----A---- C:\WINDOWS\system32\qcliprov.dll
2008-08-22 01:09:20 ----A---- C:\WINDOWS\system32\qagentrt.dll
2008-08-22 01:09:20 ----A---- C:\WINDOWS\system32\qagent.dll
2008-08-22 01:09:17 ----A---- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-22 01:09:11 ----A---- C:\WINDOWS\system32\onex.dll
2008-08-22 01:08:52 ----A---- C:\WINDOWS\system32\napstat.exe
2008-08-22 01:08:52 ----A---- C:\WINDOWS\system32\napmontr.dll
2008-08-22 01:08:52 ----A---- C:\WINDOWS\system32\napipsec.dll
2008-08-22 01:08:44 ----A---- C:\WINDOWS\system32\msshavmsg.dll
2008-08-22 01:08:44 ----A---- C:\WINDOWS\system32\mssha.dll
2008-08-22 01:08:17 ----A---- C:\WINDOWS\system32\mmcperf.exe
2008-08-22 01:08:16 ----A---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-22 01:08:16 ----A---- C:\WINDOWS\system32\mmcex.dll
2008-08-22 01:08:16 ----A---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-22 01:07:59 ----A---- C:\WINDOWS\system32\l2gpstore.dll
2008-08-22 01:07:58 ----A---- C:\WINDOWS\system32\kmsvc.dll
2008-08-22 01:07:55 ----A---- C:\WINDOWS\system32\kbdpash.dll
2008-08-22 01:07:55 ----A---- C:\WINDOWS\system32\kbdnepr.dll
2008-08-22 01:07:55 ----A---- C:\WINDOWS\system32\kbdiultn.dll
2008-08-22 01:07:54 ----A---- C:\WINDOWS\system32\kbdbhc.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapsvc.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapqec.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eappprxy.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapphost.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eappgnui.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eappcfg.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapp3hst.dll
2008-08-22 01:07:13 ----A---- C:\WINDOWS\system32\eapolqec.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3ui.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3svc.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3msm.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3dlg.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3cfg.dll
2008-08-22 01:07:06 ----A---- C:\WINDOWS\system32\dot3api.dll
2008-08-22 01:07:01 ----A---- C:\WINDOWS\system32\dimsroam.dll
2008-08-22 01:07:01 ----A---- C:\WINDOWS\system32\dimsntfy.dll
2008-08-22 01:07:00 ----A---- C:\WINDOWS\system32\dhcpqec.dll
2008-08-22 01:06:54 ----A---- C:\WINDOWS\system32\credssp.dll
2008-08-22 01:06:37 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2008-08-22 01:06:36 ----A---- C:\WINDOWS\system32\azroles.dll
2008-08-22 01:06:16 ----A---- C:\WINDOWS\system32\aaclient.dll

======List of files/folders modified in the last 1 months======

2008-09-21 20:41:44 ----D---- C:\WINDOWS\Temp
2008-09-21 19:42:18 ----AC---- C:\WINDOWS\ModemLog_Generic 56K HCF Data Fax Modem.txt
2008-09-21 19:39:13 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-09-21 18:58:51 ----RD---- C:\Program Files
2008-09-21 18:51:05 ----D---- C:\Program Files\Mozilla Thunderbird
2008-09-21 11:40:05 ----D---- C:\Documents and Settings\Owner\Application Data\SiteAdvisor
2008-09-21 09:50:38 ----D---- C:\WINDOWS\Help
2008-09-21 09:37:53 ----D---- C:\WINDOWS\system32\FxsTmp
2008-09-21 08:39:24 ----D---- C:\WINDOWS
2008-09-21 04:06:52 ----HD---- C:\WINDOWS\inf
2008-09-21 04:06:49 ----D---- C:\WINDOWS\system32
2008-09-21 04:06:46 ----D---- C:\WINDOWS\system32\CatRoot
2008-09-21 04:06:45 ----D---- C:\WINDOWS\system32\CatRoot2
2008-09-21 04:05:57 ----D---- C:\WINDOWS\WinSxS
2008-09-21 04:04:28 ----A---- C:\WINDOWS\imsins.BAK
2008-09-21 03:48:40 ----SD---- C:\WINDOWS\Tasks
2008-09-21 03:24:33 ----A---- C:\WINDOWS\system.ini
2008-09-21 03:22:28 ----D---- C:\WINDOWS\system32\drivers
2008-09-21 03:22:27 ----D---- C:\WINDOWS\AppPatch
2008-09-21 03:22:27 ----D---- C:\Program Files\Common Files
2008-09-20 18:54:12 ----D---- C:\WINDOWS\system32\config
2008-09-20 17:08:28 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 15:42:40 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-09-20 15:41:44 ----RASH---- C:\boot.ini
2008-09-15 22:12:31 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-09-15 16:27:38 ----SHD---- C:\System Volume Information
2008-09-15 16:27:38 ----D---- C:\WINDOWS\system32\Restore
2008-09-14 13:02:05 ----D---- C:\WINDOWS\security
2008-09-14 08:27:31 ----D---- C:\Program Files\Mozilla Firefox
2008-09-14 08:15:23 ----D---- C:\Program Files\Online Services
2008-09-14 08:15:06 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-09-14 08:15:06 ----D---- C:\WINDOWS\Cursors
2008-09-14 08:14:58 ----D---- C:\WINDOWS\system32\wbem
2008-09-13 21:30:31 ----D---- C:\Program Files\Windows NT
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Minidump
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Debug
2008-09-12 02:08:22 ----SHD---- C:\WINDOWS\Installer
2008-09-11 02:53:23 ----D---- C:\WINDOWS\system32\en-US
2008-09-11 02:53:23 ----D---- C:\Program Files\Internet Explorer
2008-09-11 01:38:54 ----RSD---- C:\WINDOWS\Fonts
2008-09-10 14:00:35 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-10 10:57:42 ----D---- C:\WINDOWS\Registration
2008-09-08 01:57:54 ----D---- C:\Program Files\ws ftp tiscali
2008-09-02 17:00:33 ----D---- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-09-01 13:11:40 ----HD---- C:\Program Files\InstallShield Installation Information
2008-09-01 12:58:22 ----RSD---- C:\WINDOWS\assembly
2008-08-31 20:21:10 ----AC---- C:\WINDOWS\NeroDigital.ini
2008-08-31 11:50:23 ----D---- C:\Program Files\Windows Media Player
2008-08-31 11:44:45 ----AC---- C:\WINDOWS\win.ini
2008-08-31 02:45:12 ----D---- C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-28 09:48:14 ----D---- C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-08-27 18:16:44 ----D---- C:\WINDOWS\system32\Adobe
2008-08-27 18:16:19 ----D---- C:\Documents and Settings\Owner\Application Data\Adobe
2008-08-27 09:00:26 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-08-26 22:33:21 ----D---- C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-08-26 21:28:12 ----AC---- C:\WINDOWS\system32\MRT.exe
2008-08-26 10:26:22 ----D---- C:\WINDOWS\addins
2008-08-26 10:17:39 ----D---- C:\Program Files\McAfee
2008-08-24 23:22:04 ----D---- C:\Program Files\Java
2008-08-23 12:46:51 ----HD---- C:\WINDOWS\$hf_mig$
2008-08-23 08:03:46 ----AC---- C:\WINDOWS\OEWABLog.txt
2008-08-23 03:08:39 ----AC---- C:\WINDOWS\setuplog.txt
2008-08-23 03:07:19 ----D---- C:\WINDOWS\system32\Setup
2008-08-23 02:10:05 ----D---- C:\Program Files\Messenger
2008-08-23 02:00:05 ----D---- C:\WINDOWS\ServicePackFiles
2008-08-23 02:00:00 ----D---- C:\WINDOWS\network diagnostic
2008-08-23 01:59:59 ----D---- C:\WINDOWS\ime
2008-08-23 01:59:28 ----D---- C:\WINDOWS\system32\usmt
2008-08-23 01:59:18 ----D---- C:\WINDOWS\system32\bits
2008-08-23 01:59:18 ----D---- C:\WINDOWS\peernet
2008-08-23 01:59:18 ----D---- C:\Program Files\Movie Maker
2008-08-23 01:52:28 ----D---- C:\WINDOWS\system32\npp
2008-08-23 01:52:25 ----D---- C:\WINDOWS\msagent
2008-08-23 01:52:22 ----D---- C:\WINDOWS\srchasst
2008-08-23 01:52:16 ----D---- C:\Program Files\NetMeeting
2008-08-23 01:52:13 ----D---- C:\WINDOWS\system32\Com
2008-08-23 01:52:07 ----D---- C:\Program Files\Outlook Express
2008-08-23 01:52:01 ----D---- C:\Program Files\Common Files\System
2008-08-23 01:51:25 ----D---- C:\WINDOWS\system32\oobe
2008-08-23 01:51:22 ----D---- C:\WINDOWS\system
2008-08-23 01:45:21 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-08-23 01:44:38 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-08-23 01:33:05 ----D---- C:\WINDOWS\EHome
2008-08-22 18:12:04 ----AC---- C:\WINDOWS\CDSEDB01.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ATMhelpr;ATMhelpr; C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 4064]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2008-07-23 9464]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2002-12-17 241152]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2008-06-27 207656]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2008-06-02 120136]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2004-04-08 143834]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2002-12-17 206464]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-18 12032]
R3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2004-03-02 127065]
R3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2004-08-04 327040]
R3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2004-04-08 25898]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704]
R3 HCF_MSFT;HCF_MSFT; C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys [2001-08-17 907456]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2008-06-27 79240]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2008-06-27 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2008-06-27 40488]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NeroCd2k;NeroCd2k; C:\WINDOWS\system32\drivers\NeroCd2k.sys [2001-04-16 44227]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2008-07-23 9336]
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2004-03-02 50007]
S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GT680x;GrandTechICNameNT; C:\WINDOWS\System32\Drivers\gt680x.sys [2001-11-08 18120]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 ICAM3NT5;Intel USB Video Camera III; C:\WINDOWS\System32\Drivers\Icam3.sys [2001-08-17 141056]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2008-06-20 34152]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2004-04-08 30630]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2006-03-30 96341]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [2002-01-30 77824]
R2 EPSONStatusAgent2;EPSON Printer Status Agent2; C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe [2001-10-25 90112]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-08-23 79136]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-06-21 792184]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-07-18 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2008-07-09 358736]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2008-06-20 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2008-07-09 25416]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2008-04-14 33280]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2008-06-20 605512]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MBackMonitor;MBackMonitor; C:\Program Files\McAfee\MBK\MBackMonitor.exe [2008-07-10 66848]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2008-06-20 361800]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------

Shaba
2008-09-22, 11:39
Yes, it did.

We need first to disable TeaTimer that it doesn't interfere with fixes. You can re-enable it when you're clean again:

1. Run Spybot-S&D in Advanced Mode.
2. If it is not already set to do this Go to the Mode menu select "Advanced Mode"
3. On the left hand side, Click on Tools
4. Then click on the Resident Icon in the List
5. Uncheck "Resident TeaTimer" and OK any prompts.
6. Restart your computer.

Download ResetTeaTimer.bat to the Desktop
http://downloads.subratam.org/ResetTeaTimer.bat
Double click ResetTeaTimer.bat to remove all entries set by TeaTimer (and preventing TeaTimer to restore them upon reactivation).

Open HijackThis, click do a system scan only and checkmark these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
O2 - BHO: (no name) - {42FEA74B-6462-49F6-959A-2BFD0628CE3E} - (no file)
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (file missing)
O4 - HKLM\..\Run: [1cc111c4] rundll32.exe "C:\WINDOWS\system32\mycnytnb.dll",b
O4 - HKLM\..\Run: [BM1ff22258] Rundll32.exe "C:\WINDOWS\system32\qkqaqslw.dll",s

Close all windows including browser and press fix checked.

Reboot.

Re-enable TeaTimer.

Post back a fresh HijackThis log.

Fred of Kings Lynn
2008-09-22, 12:46
Hello Shaba,
Thank you for all your help and patience.


Logfile of random's system information tool 1.02 (written by random/random)
Run by Owner at 2008-09-22 10:37:34
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 4 GB (23%) free of 20 GB
Total RAM: 383 MB (19% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:37:45, on 22/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Owner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.co.uk/"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CNetscape_UK.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{865FD82A-61A9-40E1-B551-DB3C7F08964C}: NameServer = 212.139.132.10 212.139.132.11
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O24 - Desktop Component 0: (no name) - http://news.bbc.co.uk/

--
End of file - 7935 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Disk Cleanup.job
C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{089FD14D-132B-48FC-8861-0048AE113215}]
C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-07-07 1562448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-08-04 343112]
{0BF43445-2F28-4351-9252-17FE6E806AA0} - McAfee SiteAdvisor - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"EEventManager"=C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2005-04-08 102400]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2008-07-11 641208]
"SiteAdvisor"=C:\Program Files\SiteAdvisor\6172\SiteAdv.exe [2007-08-24 36640]
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe [2008-06-13 1176808]
"UserFaultCheck"=C:\WINDOWS\system32\dumprep 0 -u []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-08-18 1832272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\System32\NeroCheck.exe [2001-07-09 155648]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
EPSON Background Monitor.lnk - C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoWinKeys"=0
"NoFileAssociate"=0
"NoCommonGroups"=0
"NoSimpleStartMenu"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\fxsclnt.exe"="C:\WINDOWS\system32\fxsclnt.exe:*:Disabled:Microsoft Fax Console"
"C:\Program Files\ws ftp tiscali\WS_FTP95.exe"="C:\Program Files\ws ftp tiscali\WS_FTP95.exe:*:Enabled:WS_FTP 95"
"C:\Program Files\Abacast\Abaclient.exe"="C:\Program Files\Abacast\Abaclient.exe:*:Enabled:Abaclient"
"C:\Program Files\Netscape\Netscape\Netscp.exe"="C:\Program Files\Netscape\Netscape\Netscp.exe:*:Enabled:Netscp"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b3ab410-5bbe-11dd-88c4-4d6564696130}]
shell\AutoRun\command - G:\InstallTomTomHOME.exe


======List of files/folders created in the last 1 months======

2008-09-21 04:05:55 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-09-21 04:04:16 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-21 03:30:25 ----A---- C:\ComboFix.txt
2008-09-20 19:14:44 ----SHD---- C:\RECYCLER
2008-09-20 15:41:44 ----A---- C:\Boot.bak
2008-09-20 15:41:32 ----D---- C:\cmdcons
2008-09-20 15:38:36 ----D---- C:\WINDOWS\erdnt
2008-09-20 15:35:43 ----D---- C:\QooBox
2008-09-20 15:34:44 ----A---- C:\WINDOWS\zip.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\swreg.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\sed.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\Nircmd.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\grep.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\VFind.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\swxcacls.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\SWSC.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\fdsv.exe
2008-09-20 14:51:50 ----D---- C:\rsit
2008-09-15 22:16:20 ----D---- C:\Program Files\Trend Micro
2008-09-15 15:34:38 ----A---- C:\WINDOWS\wininit.ini
2008-09-14 09:06:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\getuname.dll
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\charmap.exe
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\calc.exe
2008-09-14 08:14:49 ----D---- C:\Program Files\MSN
2008-09-11 21:00:46 ----D---- C:\Program Files\process Explorer
2008-09-09 17:55:11 ----D---- C:\Documents and Settings\Owner\Application Data\Nero
2008-09-09 17:49:55 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2008-09-09 17:36:01 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2008-09-09 17:36:00 ----D---- C:\Program Files\Common Files\Nero
2008-09-09 16:57:28 ----A---- C:\WINDOWS\system32\17e2d5ba-.txt
2008-09-08 02:00:20 ----D---- C:\Documents and Settings\Owner\Application Data\DivX
2008-09-01 13:43:26 ----A---- C:\WINDOWS\system32\XceedZip.dll
2008-09-01 12:56:43 ----D---- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-01 09:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2008-09-01 09:10:19 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2008-09-01 09:09:32 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-31 11:46:12 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-08-31 11:46:05 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2008-08-31 11:44:06 ----D---- C:\Program Files\Windows Media Connect 2
2008-08-31 11:43:37 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2008-08-31 11:40:48 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2008-08-31 11:39:29 ----D---- C:\WINDOWS\system32\LogFiles
2008-08-31 11:39:14 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2008-08-31 03:13:29 ----D---- C:\Program Files\7-Zip
2008-08-31 02:45:11 ----SHD---- C:\Config.Msi
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxssend.exe
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsroute.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsperf.ini
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsclntR.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxscfgwz.dll
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaws.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaw.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\java.exe
2008-08-24 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-08-23 03:07:59 ----D---- C:\WINDOWS\Prefetch
2008-08-23 02:12:26 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-08-23 02:12:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-08-23 02:11:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-08-23 02:11:38 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-08-23 02:11:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-23 02:11:09 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-08-23 02:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-08-23 02:10:35 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-08-23 02:10:21 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-08-23 02:10:02 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-08-23 01:59:25 ----D---- C:\WINDOWS\system32\scripting
2008-08-23 01:59:22 ----D---- C:\WINDOWS\l2schemas
2008-08-23 01:59:19 ----D---- C:\WINDOWS\system32\en

======List of files/folders modified in the last 1 months======

2008-09-22 10:37:41 ----D---- C:\WINDOWS\Temp
2008-09-22 10:30:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-09-22 10:08:31 ----AC---- C:\WINDOWS\ModemLog_Generic 56K HCF Data Fax Modem.txt
2008-09-21 18:58:51 ----RD---- C:\Program Files
2008-09-21 18:51:05 ----D---- C:\Program Files\Mozilla Thunderbird
2008-09-21 11:40:05 ----D---- C:\Documents and Settings\Owner\Application Data\SiteAdvisor
2008-09-21 09:50:38 ----D---- C:\WINDOWS\Help
2008-09-21 09:37:53 ----D---- C:\WINDOWS\system32\FxsTmp
2008-09-21 08:39:24 ----D---- C:\WINDOWS
2008-09-21 04:06:52 ----HD---- C:\WINDOWS\inf
2008-09-21 04:06:49 ----D---- C:\WINDOWS\system32
2008-09-21 04:06:46 ----D---- C:\WINDOWS\system32\CatRoot
2008-09-21 04:06:45 ----D---- C:\WINDOWS\system32\CatRoot2
2008-09-21 04:05:57 ----D---- C:\WINDOWS\WinSxS
2008-09-21 04:04:28 ----A---- C:\WINDOWS\imsins.BAK
2008-09-21 03:48:40 ----SD---- C:\WINDOWS\Tasks
2008-09-21 03:24:33 ----A---- C:\WINDOWS\system.ini
2008-09-21 03:22:28 ----D---- C:\WINDOWS\system32\drivers
2008-09-21 03:22:27 ----D---- C:\WINDOWS\AppPatch
2008-09-21 03:22:27 ----D---- C:\Program Files\Common Files
2008-09-20 18:54:12 ----D---- C:\WINDOWS\system32\config
2008-09-20 17:08:28 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 15:42:40 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-09-20 15:41:44 ----RASH---- C:\boot.ini
2008-09-15 22:12:31 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-09-15 16:27:38 ----SHD---- C:\System Volume Information
2008-09-15 16:27:38 ----D---- C:\WINDOWS\system32\Restore
2008-09-14 13:02:05 ----D---- C:\WINDOWS\security
2008-09-14 08:27:31 ----D---- C:\Program Files\Mozilla Firefox
2008-09-14 08:15:23 ----D---- C:\Program Files\Online Services
2008-09-14 08:15:06 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-09-14 08:15:06 ----D---- C:\WINDOWS\Cursors
2008-09-14 08:14:58 ----D---- C:\WINDOWS\system32\wbem
2008-09-13 21:30:31 ----D---- C:\Program Files\Windows NT
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Minidump
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Debug
2008-09-12 02:08:22 ----SHD---- C:\WINDOWS\Installer
2008-09-11 02:53:23 ----D---- C:\WINDOWS\system32\en-US
2008-09-11 02:53:23 ----D---- C:\Program Files\Internet Explorer
2008-09-11 01:38:54 ----RSD---- C:\WINDOWS\Fonts
2008-09-10 14:00:35 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-10 10:57:42 ----D---- C:\WINDOWS\Registration
2008-09-08 01:57:54 ----D---- C:\Program Files\ws ftp tiscali
2008-09-02 17:00:33 ----D---- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-09-01 13:11:40 ----HD---- C:\Program Files\InstallShield Installation Information
2008-09-01 12:58:22 ----RSD---- C:\WINDOWS\assembly
2008-08-31 20:21:10 ----AC---- C:\WINDOWS\NeroDigital.ini
2008-08-31 11:50:23 ----D---- C:\Program Files\Windows Media Player
2008-08-31 11:44:45 ----AC---- C:\WINDOWS\win.ini
2008-08-31 02:45:12 ----D---- C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-28 09:48:14 ----D---- C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-08-27 18:16:44 ----D---- C:\WINDOWS\system32\Adobe
2008-08-27 18:16:19 ----D---- C:\Documents and Settings\Owner\Application Data\Adobe
2008-08-27 09:00:26 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-08-26 22:33:21 ----D---- C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-08-26 21:28:12 ----AC---- C:\WINDOWS\system32\MRT.exe
2008-08-26 10:26:22 ----D---- C:\WINDOWS\addins
2008-08-26 10:17:39 ----D---- C:\Program Files\McAfee
2008-08-24 23:22:04 ----D---- C:\Program Files\Java
2008-08-23 12:46:51 ----HD---- C:\WINDOWS\$hf_mig$
2008-08-23 08:03:46 ----AC---- C:\WINDOWS\OEWABLog.txt
2008-08-23 03:08:39 ----AC---- C:\WINDOWS\setuplog.txt
2008-08-23 03:07:19 ----D---- C:\WINDOWS\system32\Setup
2008-08-23 02:10:05 ----D---- C:\Program Files\Messenger
2008-08-23 02:00:05 ----D---- C:\WINDOWS\ServicePackFiles
2008-08-23 02:00:00 ----D---- C:\WINDOWS\network diagnostic
2008-08-23 01:59:59 ----D---- C:\WINDOWS\ime
2008-08-23 01:59:28 ----D---- C:\WINDOWS\system32\usmt
2008-08-23 01:59:18 ----D---- C:\WINDOWS\system32\bits
2008-08-23 01:59:18 ----D---- C:\WINDOWS\peernet
2008-08-23 01:59:18 ----D---- C:\Program Files\Movie Maker
2008-08-23 01:52:28 ----D---- C:\WINDOWS\system32\npp
2008-08-23 01:52:25 ----D---- C:\WINDOWS\msagent
2008-08-23 01:52:22 ----D---- C:\WINDOWS\srchasst
2008-08-23 01:52:16 ----D---- C:\Program Files\NetMeeting
2008-08-23 01:52:13 ----D---- C:\WINDOWS\system32\Com
2008-08-23 01:52:07 ----D---- C:\Program Files\Outlook Express
2008-08-23 01:52:01 ----D---- C:\Program Files\Common Files\System
2008-08-23 01:51:25 ----D---- C:\WINDOWS\system32\oobe
2008-08-23 01:51:22 ----D---- C:\WINDOWS\system
2008-08-23 01:45:21 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-08-23 01:44:38 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-08-23 01:33:05 ----D---- C:\WINDOWS\EHome

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ATMhelpr;ATMhelpr; C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 4064]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2008-07-23 9464]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2002-12-17 241152]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2008-06-27 207656]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2008-06-02 120136]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2004-04-08 143834]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2002-12-17 206464]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-18 12032]
R3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2004-03-02 127065]
R3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2004-08-04 327040]
R3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2004-04-08 25898]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704]
R3 HCF_MSFT;HCF_MSFT; C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys [2001-08-17 907456]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2008-06-27 79240]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2008-06-27 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2008-06-27 40488]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NeroCd2k;NeroCd2k; C:\WINDOWS\system32\drivers\NeroCd2k.sys [2001-04-16 44227]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2008-07-23 9336]
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2004-03-02 50007]
S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GT680x;GrandTechICNameNT; C:\WINDOWS\System32\Drivers\gt680x.sys [2001-11-08 18120]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 ICAM3NT5;Intel USB Video Camera III; C:\WINDOWS\System32\Drivers\Icam3.sys [2001-08-17 141056]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2008-06-20 34152]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2004-04-08 30630]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2006-03-30 96341]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [2002-01-30 77824]
R2 EPSONStatusAgent2;EPSON Printer Status Agent2; C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe [2001-10-25 90112]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-08-23 79136]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-06-21 792184]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-07-18 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2008-07-09 358736]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2008-06-20 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2008-07-09 25416]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2008-04-14 33280]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2008-06-20 605512]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MBackMonitor;MBackMonitor; C:\Program Files\McAfee\MBK\MBackMonitor.exe [2008-07-10 66848]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2008-06-20 361800]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------

Shaba
2008-09-22, 15:11
Now it looks better :)

Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply along with a fresh HijackThis log.

If you need a tutorial, see here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif)

Fred of Kings Lynn
2008-09-23, 06:26
Hello Shaba,

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, September 23, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, September 22, 2008 19:45:04
Records in database: 1250911
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 102533
Threat name: 2
Infected objects: 1
Suspicious objects: 14
Duration of the scan: 04:50:02


File name / Threat name / Threats count
C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\83hp3al7.slt\Mail\pop.tiscali.co.uk\Inbox Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\5iknb6nu.default\Mail\pop.tiscali.co.uk\Inbox Suspicious: Trojan-Spy.HTML.Fraud.gen 3
C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\5iknb6nu.default\Mail\pop.tiscali.co.uk\McAfee Anti-Spam Suspicious: Trojan-Spy.HTML.Fraud.gen 10
C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\5iknb6nu.default\Mail\pop3.tiscali.co.uk\McAfee Anti-Spam Infected: Trojan-Downloader.Win32.Obitel.b 1

The selected area was scanned.

-----------------------------------------------------------------------------------------------

Logfile of random's system information tool 1.02 (written by random/random)
Run by Owner at 2008-09-23 04:09:41
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 4 GB (22%) free of 20 GB
Total RAM: 383 MB (35% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:09:55, on 23/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Owner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.co.uk/"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CNetscape_UK.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\83hp3al7.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{865FD82A-61A9-40E1-B551-DB3C7F08964C}: NameServer = 212.139.132.36 212.139.132.37
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O24 - Desktop Component 0: (no name) - http://news.bbc.co.uk/

--
End of file - 7904 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Disk Cleanup.job
C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{089FD14D-132B-48FC-8861-0048AE113215}]
C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-07-07 1562448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-08-04 343112]
{0BF43445-2F28-4351-9252-17FE6E806AA0} - McAfee SiteAdvisor - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"EEventManager"=C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2005-04-08 102400]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2008-07-11 641208]
"SiteAdvisor"=C:\Program Files\SiteAdvisor\6172\SiteAdv.exe [2007-08-24 36640]
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe [2008-06-13 1176808]
"UserFaultCheck"=C:\WINDOWS\system32\dumprep 0 -u []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-08-18 1832272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\System32\NeroCheck.exe [2001-07-09 155648]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
EPSON Background Monitor.lnk - C:\Program Files\Common Files\EPSON\EBAPI\STMS.exe
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoWinKeys"=0
"NoFileAssociate"=0
"NoCommonGroups"=0
"NoSimpleStartMenu"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\fxsclnt.exe"="C:\WINDOWS\system32\fxsclnt.exe:*:Disabled:Microsoft Fax Console"
"C:\Program Files\ws ftp tiscali\WS_FTP95.exe"="C:\Program Files\ws ftp tiscali\WS_FTP95.exe:*:Enabled:WS_FTP 95"
"C:\Program Files\Abacast\Abaclient.exe"="C:\Program Files\Abacast\Abaclient.exe:*:Enabled:Abaclient"
"C:\Program Files\Netscape\Netscape\Netscp.exe"="C:\Program Files\Netscape\Netscape\Netscp.exe:*:Enabled:Netscp"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b3ab410-5bbe-11dd-88c4-4d6564696130}]
shell\AutoRun\command - G:\InstallTomTomHOME.exe


======List of files/folders created in the last 1 months======

2008-09-21 04:05:55 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-09-21 04:04:16 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-21 03:30:25 ----A---- C:\ComboFix.txt
2008-09-20 19:14:44 ----SHD---- C:\RECYCLER
2008-09-20 15:41:44 ----A---- C:\Boot.bak
2008-09-20 15:41:32 ----D---- C:\cmdcons
2008-09-20 15:38:36 ----D---- C:\WINDOWS\erdnt
2008-09-20 15:35:43 ----D---- C:\QooBox
2008-09-20 15:34:44 ----A---- C:\WINDOWS\zip.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\swreg.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\sed.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\Nircmd.exe
2008-09-20 15:34:44 ----A---- C:\WINDOWS\grep.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\VFind.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\swxcacls.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\SWSC.exe
2008-09-20 15:34:43 ----A---- C:\WINDOWS\fdsv.exe
2008-09-20 14:51:50 ----D---- C:\rsit
2008-09-15 22:16:20 ----D---- C:\Program Files\Trend Micro
2008-09-15 15:34:38 ----A---- C:\WINDOWS\wininit.ini
2008-09-14 09:06:50 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\getuname.dll
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\charmap.exe
2008-09-14 08:14:59 ----A---- C:\WINDOWS\system32\calc.exe
2008-09-14 08:14:49 ----D---- C:\Program Files\MSN
2008-09-11 21:00:46 ----D---- C:\Program Files\process Explorer
2008-09-09 17:55:11 ----D---- C:\Documents and Settings\Owner\Application Data\Nero
2008-09-09 17:49:55 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
2008-09-09 17:36:01 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2008-09-09 17:36:00 ----D---- C:\Program Files\Common Files\Nero
2008-09-09 16:57:28 ----A---- C:\WINDOWS\system32\17e2d5ba-.txt
2008-09-08 02:00:20 ----D---- C:\Documents and Settings\Owner\Application Data\DivX
2008-09-01 13:43:26 ----A---- C:\WINDOWS\system32\XceedZip.dll
2008-09-01 12:56:43 ----D---- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-01 09:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2008-09-01 09:10:19 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2008-09-01 09:09:32 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-08-31 11:46:12 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-08-31 11:46:05 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2008-08-31 11:44:06 ----D---- C:\Program Files\Windows Media Connect 2
2008-08-31 11:43:37 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2008-08-31 11:40:48 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2008-08-31 11:39:29 ----D---- C:\WINDOWS\system32\LogFiles
2008-08-31 11:39:14 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2008-08-31 03:13:29 ----D---- C:\Program Files\7-Zip
2008-08-31 02:45:11 ----SHD---- C:\Config.Msi
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxssend.exe
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsroute.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsperf.ini
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxsclntR.dll
2008-08-26 10:26:22 ----A---- C:\WINDOWS\system32\fxscfgwz.dll
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaws.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\javaw.exe
2008-08-24 23:22:10 ----A---- C:\WINDOWS\system32\java.exe
2008-08-24 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$

======List of files/folders modified in the last 1 months======

2008-09-23 04:09:51 ----D---- C:\WINDOWS\Temp
2008-09-23 03:34:29 ----D---- C:\WINDOWS\Prefetch
2008-09-23 02:41:55 ----D---- C:\Program Files\Mozilla Thunderbird
2008-09-22 16:59:07 ----D---- C:\WINDOWS\system32\CatRoot2
2008-09-22 10:30:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-09-22 10:08:31 ----AC---- C:\WINDOWS\ModemLog_Generic 56K HCF Data Fax Modem.txt
2008-09-21 18:58:51 ----RD---- C:\Program Files
2008-09-21 11:40:05 ----D---- C:\Documents and Settings\Owner\Application Data\SiteAdvisor
2008-09-21 09:50:38 ----D---- C:\WINDOWS\Help
2008-09-21 09:37:53 ----D---- C:\WINDOWS\system32\FxsTmp
2008-09-21 08:39:24 ----D---- C:\WINDOWS
2008-09-21 04:06:52 ----HD---- C:\WINDOWS\inf
2008-09-21 04:06:49 ----D---- C:\WINDOWS\system32
2008-09-21 04:06:46 ----D---- C:\WINDOWS\system32\CatRoot
2008-09-21 04:05:57 ----D---- C:\WINDOWS\WinSxS
2008-09-21 04:04:28 ----A---- C:\WINDOWS\imsins.BAK
2008-09-21 03:48:40 ----SD---- C:\WINDOWS\Tasks
2008-09-21 03:24:33 ----A---- C:\WINDOWS\system.ini
2008-09-21 03:22:28 ----D---- C:\WINDOWS\system32\drivers
2008-09-21 03:22:27 ----D---- C:\WINDOWS\AppPatch
2008-09-21 03:22:27 ----D---- C:\Program Files\Common Files
2008-09-20 18:54:12 ----D---- C:\WINDOWS\system32\config
2008-09-20 17:08:28 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 15:42:40 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-09-20 15:41:44 ----RASH---- C:\boot.ini
2008-09-15 22:12:31 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-09-15 16:27:38 ----SHD---- C:\System Volume Information
2008-09-15 16:27:38 ----D---- C:\WINDOWS\system32\Restore
2008-09-14 13:02:05 ----D---- C:\WINDOWS\security
2008-09-14 08:27:31 ----D---- C:\Program Files\Mozilla Firefox
2008-09-14 08:15:23 ----D---- C:\Program Files\Online Services
2008-09-14 08:15:06 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-09-14 08:15:06 ----D---- C:\WINDOWS\Cursors
2008-09-14 08:14:58 ----D---- C:\WINDOWS\system32\wbem
2008-09-13 21:30:31 ----D---- C:\Program Files\Windows NT
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Minidump
2008-09-12 02:08:23 ----D---- C:\WINDOWS\Debug
2008-09-12 02:08:22 ----SHD---- C:\WINDOWS\Installer
2008-09-11 02:53:23 ----D---- C:\WINDOWS\system32\en-US
2008-09-11 02:53:23 ----D---- C:\Program Files\Internet Explorer
2008-09-11 01:38:54 ----RSD---- C:\WINDOWS\Fonts
2008-09-10 14:00:35 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-10 10:57:42 ----D---- C:\WINDOWS\Registration
2008-09-08 01:57:54 ----D---- C:\Program Files\ws ftp tiscali
2008-09-02 17:00:33 ----D---- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-09-01 13:11:40 ----HD---- C:\Program Files\InstallShield Installation Information
2008-09-01 12:58:22 ----RSD---- C:\WINDOWS\assembly
2008-08-31 20:21:10 ----AC---- C:\WINDOWS\NeroDigital.ini
2008-08-31 11:50:23 ----D---- C:\Program Files\Windows Media Player
2008-08-31 11:44:45 ----AC---- C:\WINDOWS\win.ini
2008-08-31 02:45:12 ----D---- C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-28 09:48:14 ----D---- C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-08-27 18:16:44 ----D---- C:\WINDOWS\system32\Adobe
2008-08-27 18:16:19 ----D---- C:\Documents and Settings\Owner\Application Data\Adobe
2008-08-27 09:00:26 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-08-26 22:33:21 ----D---- C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-08-26 21:28:12 ----AC---- C:\WINDOWS\system32\MRT.exe
2008-08-26 10:26:22 ----D---- C:\WINDOWS\addins
2008-08-26 10:17:39 ----D---- C:\Program Files\McAfee
2008-08-24 23:22:04 ----D---- C:\Program Files\Java

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ATMhelpr;ATMhelpr; C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 4064]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2008-07-23 9464]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2002-12-17 241152]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2008-06-27 207656]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2008-06-02 120136]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2004-04-08 143834]
R1 UdfReadr_xp;UdfReadr_xp; C:\WINDOWS\system32\drivers\UdfReadr_xp.sys [2002-12-17 206464]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-18 12032]
R3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2004-03-02 127065]
R3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2004-08-04 327040]
R3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2004-04-08 25898]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704]
R3 HCF_MSFT;HCF_MSFT; C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys [2001-08-17 907456]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2008-06-27 79240]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2008-06-27 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2008-06-27 40488]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NeroCd2k;NeroCd2k; C:\WINDOWS\system32\drivers\NeroCd2k.sys [2001-04-16 44227]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2008-07-23 9336]
S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2004-03-02 50007]
S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GT680x;GrandTechICNameNT; C:\WINDOWS\System32\Drivers\gt680x.sys [2001-11-08 18120]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 ICAM3NT5;Intel USB Video Camera III; C:\WINDOWS\System32\Drivers\Icam3.sys [2001-08-17 141056]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2008-06-20 34152]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2004-04-08 30630]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2006-03-30 96341]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [2002-01-30 77824]
R2 EPSONStatusAgent2;EPSON Printer Status Agent2; C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe [2001-10-25 90112]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-08-23 79136]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-06-21 792184]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-07-18 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2008-07-09 358736]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2008-06-20 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2008-07-09 25416]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2008-04-14 33280]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2008-06-20 605512]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MBackMonitor;MBackMonitor; C:\Program Files\McAfee\MBK\MBackMonitor.exe [2008-07-10 66848]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2008-06-20 361800]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]

-----------------EOF-----------------


I opened the hidden files and deleted everything in these two inbox locations

C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\83hp3al7.slt\Mail\pop.tiscali.co.uk\Inbox Suspicious: Trojan-Spy.HTML.Fraud.gen 1

C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\5iknb6nu.default\Mail\pop.tiscali.co.uk\Inbox Suspicious: Trojan-Spy.HTML.Fraud.gen 3



The following two paths , In the properties dialog box: Type of Files = Files
20 MB fize file C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\5iknb6nu.default\Mail\pop.tiscali.co.uk\McAfee Anti-Spam Suspicious: Trojan-Spy.HTML.Fraud.gen 10

609 KB fize file C:\Documents and Settings\Owner\Application Data\Thunderbird\Profiles\5iknb6nu.default\Mail\pop3.tiscali.co.uk\McAfee Anti-Spam Infected: Trojan-Downloader.Win32.Obitel.b 1



There is also another file in each of the destinations with the same name, Type of File = msf, File sizes are very small, about 2KB

I have not deleted any of these without further assitance.

I am using Thunderbird as my email client. From within the program there is nothing in the McAfee Anti-Spam tab folders.
- I have noticed that just recently spam emails have not been placed in this tab folder, but left in the inbox.

Shaba
2008-09-23, 15:51
Then there could be some error in McAfee AntiSpam settings.

"There is also another file in each of the destinations with the same name, Type of File = msf, File sizes are very small, about 2KB

I have not deleted any of these without further assitance."

Please leave them alone, they are Thunderbird Mail Summary Files :)

Still problems?

Fred of Kings Lynn
2008-09-23, 16:32
Dear Shaba,
Thank you for all your help and patience.
I do not know how I would have managed without you.
All seems to be working fine now.
I will go through McAfee and Thunderbird Anti-Spam to see if there is any fixes I can make.
I will of course be making a donation, and will keep in touch with the Safer Networking Forums.
Very best wishes,
Freddy

Shaba
2008-09-23, 16:36
Great :)

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Now lets uninstall ComboFix:

Click START then RUN
Now type Combofix /u in the runbox and click OK

Next we remove all used tools.

You can delete RSIT.

Please download OTCleanIt (http://download.bleepingcomputer.com/oldtimer/OTCleanIt.exe) and save it to desktop.

Double-click OTCleanIt.exe.
Click the CleanUp! button.
Select Yes when the "Begin cleanup Process?" prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTCleanIt attempting to contact the internet, please allow it to do so.

Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html)

Re-enable system restore with instructions from tutorial above

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt

Change the Download unsigned ActiveX controls to Disable

Change the Initialize and script ActiveX controls not marked as safe to Disable

Change the Installation of desktop items to Prompt

Change the Launching programs and files in an IFRAME to Prompt

Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com (http://www.windowsupdate.com) regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
totally free but for real-time protection you will have to pay a small one-time fee. Tutorial on installing & using this product can be found below:

Malwarebytes' Anti-Malware Setup Guide (http://www.bfccomputers.com/forum/index.php?showtopic=1644)

Malwarebytes' Anti-Malware Scanning Guide (http://www.bfccomputers.com/forum/index.php?showtopic=1645)


Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/tutorials/tutorial49.html)


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer. See also a hosts file tutorial here (http://malwareremoval.com/forum/viewtopic.php?t=22187)
Winpatrol (http://www.winpatrol.com/) <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

Stand Up and Be Counted ---> Malware Complaints (http://www.malwarecomplaints.info/index.php) <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place (http://forums.spybot.info/showthread.php?t=279)

Happy surfing and stay clean! :bigthumb:

Shaba
2008-09-25, 12:08
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.