HJT Log is here:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:15:51 PM, on 5/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\System32\DeltTray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [M-Audio Delta Taskbar Icon] C:\WINDOWS\System32\DeltTray.exe
O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [java_sun] Java (Sun)
O16 - DPF: {0eb0e74a-2a76-4ab3-a7fb-9bd8c29f7f75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {215b8138-a3cf-44c5-803f-8226143cfc0a} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD LT 2000i\AcDcToday.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred Control) - file://C:\Program Files\AutoCAD LT 2000i\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD LT 2000i\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{4F973571-084D-491D-B0C7-D0F00251A94C}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{900EF8A5-909B-4E81-9E8C-7FD24E854AB3}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{4F973571-084D-491D-B0C7-D0F00251A94C}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
--
End of file - 4034 bytes
ComboFix log is here:
ComboFix 08-05-01.3 - Dave 2008-05-04 14:58:19.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.772 [GMT -5:00]
Running from: C:\Documents and Settings\Dave\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dave\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\-666500985
C:\DOCUME~1\Dave\LOCALS~1\Temp\csrssc.exe
C:\kbvxxo.exe
C:\mxuxc.exe
C:\WINDOWS\knxsrgte.exe
C:\WINDOWS\qvlbodmnlks.dll
C:\WINDOWS\svorbmke.exe
C:\WINDOWS\system32\jfiehayd.dll
C:\WINDOWS\system32\kzq5re.sys
C:\WINDOWS\tdomgafw.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\-666500985
C:\DOCUME~1\Dave\LOCALS~1\Temp\csrssc.exe
C:\kbvxxo.exe
C:\mxuxc.exe
C:\WINDOWS\knxsrgte.exe
C:\WINDOWS\qvlbodmnlks.dll
C:\WINDOWS\svorbmke.exe
C:\WINDOWS\system32\jfiehayd.dll
C:\WINDOWS\system32\kzq5re.sys
C:\WINDOWS\tdomgafw.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_kzq5re
((((((((((((((((((((((((( Files Created from 2008-04-04 to 2008-05-04 )))))))))))))))))))))))))))))))
.
2008-05-03 22:10 . 2008-05-04 13:56 <DIR> d-------- C:\WINDOWS\system32\382077
2008-05-03 22:08 . 2008-05-03 22:08 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-03 22:08 . 2008-05-03 22:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-03 22:01 . 2008-05-03 22:01 396,288 --a------ C:\Program Files\HijackThis.exe
2008-05-03 19:00 . 2008-05-03 19:00 <DIR> d-------- C:\WINDOWS\Sun
2008-05-03 18:59 . 2008-05-03 18:59 <DIR> d-------- C:\Program Files\Java
2008-05-03 18:59 . 2008-05-03 18:59 <DIR> d-------- C:\Program Files\Common Files\Java
2008-05-03 18:59 . 2005-04-13 03:48 49,265 --a------ C:\WINDOWS\system32\jpicpl32.cpl
2008-05-03 18:29 . 2008-05-03 18:40 <DIR> d-------- C:\Documents and Settings\Dave\.housecall6.6
2008-05-03 16:46 . 2008-05-03 17:42 573 --a------ C:\WINDOWS\wininit.ini
2008-05-03 16:07 . 2008-05-03 16:07 <DIR> d---s---- C:\Documents and Settings\Dave\UserData
2008-05-03 15:38 . 2008-05-03 15:39 <DIR> d-------- C:\VSTPlugIns
2008-05-03 15:21 . 2008-05-03 15:21 <DIR> d-------- C:\Program Files\DirectiXer
2008-05-03 14:31 . 2008-05-03 14:33 <DIR> d-------- C:\Program Files\Audacity
2008-05-03 14:17 . 2000-11-27 04:02 163,840 -ra------ C:\WINDOWS\system32\rddP1009.dat
2008-05-03 14:17 . 2000-11-27 04:04 42,860 -ra------ C:\WINDOWS\system32\drivers\rdwm1009.sys
2008-05-03 14:17 . 2000-11-27 04:03 25,291 -ra------ C:\WINDOWS\system32\rddv1009.dll
2008-05-03 14:09 . 2008-05-03 14:09 <DIR> d-------- C:\Documents and Settings\Dave\WINDOWS
2008-05-03 14:06 . 2008-05-03 14:06 <DIR> d-------- C:\Program Files\FruityloopsExpress
2008-05-03 14:05 . 2008-05-03 14:05 <DIR> d-------- C:\Program Files\Tutorials
2008-05-03 14:05 . 2008-05-03 14:05 118,784 --a------ C:\WINDOWS\dsdxirmv.exe
2008-05-03 14:04 . 2008-05-03 14:06 <DIR> d-------- C:\Program Files\Sample Content
2008-05-03 14:04 . 2008-05-03 14:04 <DIR> d-------- C:\Program Files\Drum Styles
2008-05-03 14:04 . 2008-05-03 14:04 <DIR> d-------- C:\Program Files\Cakewalk
2008-05-03 14:04 . 2008-05-03 15:56 <DIR> d-------- C:\Cakewalk Projects
2008-05-03 14:04 . 2001-07-06 01:00 7,262,208 --a------ C:\Program Files\CWHS.EXE
2008-05-03 14:04 . 2001-07-06 01:00 2,240,512 --a------ C:\Program Files\cw10hyph.dll
2008-05-03 14:04 . 2001-07-06 01:00 794,624 --a------ C:\Program Files\cw10aud.dll
2008-05-03 14:04 . 2001-07-06 01:00 524,800 --a------ C:\Program Files\rnco3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 487,936 --a------ C:\Program Files\rmme3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 487,936 --a------ C:\Program Files\rmbe3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 430,080 --a------ C:\Program Files\cj609lib.dll
2008-05-03 14:04 . 2001-07-06 01:00 410,112 --a------ C:\Program Files\encn3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 352,768 --a------ C:\Program Files\pngu3263.dll
2008-05-03 14:04 . 2001-07-06 01:00 321,024 --a------ C:\Program Files\rmto3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 273,408 --a------ C:\Program Files\pncrt.dll
2008-05-03 14:04 . 2001-07-06 01:00 272,896 --a------ C:\Program Files\erv23260.dll
2008-05-03 14:04 . 2001-07-06 01:00 200,704 --a------ C:\Program Files\automation.dll
2008-05-03 14:04 . 2001-01-05 17:51 162,304 --a------ C:\Program Files\UNWISE.EXE
2008-05-03 14:04 . 2001-07-06 01:00 110,592 --a------ C:\Program Files\cwdxpx1.dll
2008-05-03 14:04 . 2001-07-06 01:00 94,208 --a------ C:\Program Files\erv13260.dll
2008-05-03 14:04 . 2001-07-06 01:00 84,992 --a------ C:\Program Files\14_43260.dll
2008-05-03 14:04 . 2001-07-06 01:00 81,920 --a------ C:\Program Files\raencode.dll
2008-05-03 14:04 . 2001-07-06 01:00 81,408 --a------ C:\Program Files\ednt3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 60,416 --a------ C:\Program Files\espr3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 52,736 --a------ C:\Program Files\rv203260.dll
2008-05-03 14:04 . 2001-07-06 01:00 45,184 --a------ C:\Program Files\cw10sq16.dll
2008-05-03 14:04 . 2001-07-06 01:00 45,056 --a------ C:\Program Files\cw10sq32.dll
2008-05-03 14:04 . 2001-07-06 01:00 45,056 --a------ C:\Program Files\28_83260.dll
2008-05-03 14:04 . 2001-07-06 01:00 41,984 --a------ C:\Program Files\sdpp3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 30,720 --a------ C:\Program Files\auth3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 30,208 --a------ C:\Program Files\rn5a3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 28,672 --a------ C:\Program Files\rv103260.dll
2008-05-03 14:04 . 2001-07-06 01:00 25,600 --a------ C:\Program Files\basc3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 24,576 --a------ C:\Program Files\cook3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 23,552 --a------ C:\Program Files\cokr3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 21,504 --a------ C:\Program Files\enlv3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 20,480 --a------ C:\Program Files\dnet3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 20,480 --a------ C:\Program Files\cw10sq16thk.dll
2008-05-03 14:04 . 2001-07-06 01:00 20,480 --a------ C:\Program Files\cw10dx16thk.dll
2008-05-03 14:04 . 2001-07-06 01:00 16,896 --a------ C:\Program Files\sipr3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 11,264 --a------ C:\Program Files\pnrs3260.dll
2008-05-03 14:04 . 2001-07-06 01:00 9,312 --a------ C:\Program Files\cw10dx16.dll
2008-05-03 14:04 . 2001-07-06 01:00 6 --a------ C:\Program Files\gmsystem.syx
2008-05-03 14:03 . 2008-05-03 14:04 <DIR> d-------- C:\Program Files\MusicLab
2008-05-03 14:00 . 2008-05-03 14:00 <DIR> d-------- C:\WINDOWS\PrimoPDF4
2008-05-03 14:00 . 2008-05-03 14:00 <DIR> d-------- C:\Program Files\activePDF
2008-05-03 14:00 . 2006-12-11 15:12 176,235 --a------ C:\WINDOWS\system32\Primomonnt.dll
2008-05-03 12:47 . 2008-05-03 12:47 <DIR> d-------- C:\Documents and Settings\Dave\Application Data\Autodesk
2008-05-03 12:25 . 2008-05-04 13:56 <DIR> d-------- C:\Documents and Settings\Dave
2008-05-03 12:25 . 2008-05-04 14:59 94,208 --ah----- C:\Documents and Settings\Dave\ntuser.dat.LOG
2008-05-03 11:50 . 2008-05-03 11:50 <DIR> d-------- C:\WINDOWS\occache
2008-05-03 11:50 . 2008-05-03 11:50 <DIR> d-------- C:\Program Files\WexTech
2008-05-03 11:50 . 2008-05-03 11:50 <DIR> d-------- C:\Program Files\Common Files\WexTech Shared
2008-05-03 11:50 . 2008-05-03 11:50 <DIR> d-------- C:\Program Files\Common Files\LHSPF
2008-05-03 11:50 . 2008-05-03 11:50 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared
2008-05-03 11:50 . 1999-06-03 12:05 170,496 --a------ C:\WINDOWS\system32\awrtl30.dll
2008-05-03 11:50 . 1998-08-04 11:22 111,616 --a------ C:\WINDOWS\system32\Ltih30tb.dll
2008-05-03 11:02 . 2008-05-03 11:02 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Autodesk
2008-05-03 10:56 . 2008-05-03 10:56 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2008-05-03 10:40 . 2008-05-03 10:40 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-03 10:40 . 2008-05-03 10:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-03 10:33 . 2008-05-03 10:33 35,262 --a------ C:\WINDOWS\Administrator.acl
2008-05-03 10:10 . 2008-05-04 10:00 872,448 --ah----- C:\ffastun0.ffx
2008-05-03 10:10 . 2008-05-04 10:00 151,552 --ah----- C:\ffastun.ffo
2008-05-03 10:10 . 2008-05-04 10:00 4,717 --ah----- C:\ffastun.ffa
2008-05-03 10:09 . 2008-05-03 10:09 <DIR> d-------- C:\WINDOWS\SendTo
2008-05-03 10:09 . 2008-05-04 10:00 352,256 --ah----- C:\ffastun.ffl
2008-05-03 10:09 . 2008-05-03 10:09 69,632 --a------ C:\WINDOWS\system32\system.mdw
2008-05-03 10:09 . 2008-05-03 10:09 6,209 --a------ C:\WINDOWS\system32\mapisvc.inf
2008-05-03 10:09 . 2008-05-03 10:09 611 --a------ C:\WINDOWS\ODBC.INI
2008-05-03 10:09 . 2008-05-03 10:09 22 --a------ C:\WINDOWS\exchng.ini
2008-05-03 10:08 . 2008-05-03 10:09 <DIR> d-------- C:\WINDOWS\forms
2008-05-03 10:08 . 2008-05-03 10:08 <DIR> d-------- C:\Program Files\Windows Messaging
2008-05-03 10:05 . 2008-05-03 11:51 <DIR> d-------- C:\Program Files\AutoCAD LT 2000i
2008-05-03 10:05 . 2008-05-03 10:05 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-05-03 10:02 . 2008-05-03 12:55 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-05-03 10:01 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-04-30 21:42 . 2008-04-30 21:42 <DIR> d-------- C:\Program Files\M-Audio
2008-04-30 21:42 . 2008-05-03 14:05 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-04-30 21:42 . 2008-05-03 14:04 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-04-30 21:42 . 2006-05-01 16:46 2,405,806 --a------ C:\WINDOWS\system32\pcifmdio.dll
2008-04-30 21:42 . 2004-09-10 00:45 1,122,304 --a------ C:\WINDOWS\system32\deltapnl.exe
2008-04-30 21:42 . 2005-10-06 21:31 292,992 --a------ C:\WINDOWS\system32\drivers\delta.sys
2008-04-30 21:42 . 2004-08-27 06:43 56,320 --a------ C:\WINDOWS\system32\DeltTray.exe
2008-04-30 21:42 . 2004-09-10 00:45 44,032 --a------ C:\WINDOWS\system32\deltapnl.dll
2008-04-30 21:42 . 2005-10-06 21:31 20,480 --a------ C:\WINDOWS\system32\deltasio.dll
2008-04-30 21:42 . 2004-08-13 20:06 5,120 --a------ C:\WINDOWS\system32\DeltaCPL.cpl
2008-04-30 21:32 . 2008-05-03 20:22 1,024 --ah----- C:\Documents and Settings\All Users\NTUSER.DAT.LOG
2008-04-30 17:26 . 2004-08-04 06:15 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2008-04-30 17:26 . 2004-08-04 06:15 145,792 --a--c--- C:\WINDOWS\system32\dllcache\portcls.sys
2008-04-30 17:26 . 2004-08-04 06:08 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-04-30 17:26 . 2004-08-04 06:08 60,288 --a--c--- C:\WINDOWS\system32\dllcache\drmk.sys
2008-04-30 17:26 . 2004-08-04 00:58 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2008-04-30 17:26 . 2004-08-04 00:58 7,552 --a--c--- C:\WINDOWS\system32\dllcache\mskssrv.sys
2008-04-30 17:26 . 2004-08-04 00:58 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2008-04-30 17:26 . 2004-08-04 00:58 5,376 --a--c--- C:\WINDOWS\system32\dllcache\mspclock.sys
2008-04-30 17:26 . 2004-08-04 00:58 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2008-04-30 17:26 . 2004-08-04 00:58 4,992 --a--c--- C:\WINDOWS\system32\dllcache\mspqm.sys
2008-04-30 17:25 . 2008-04-30 17:25 <DIR> d-------- C:\Program Files\CONEXANT
2008-04-30 17:23 . 2005-09-20 08:43 2,310,144 --a------ C:\WINDOWS\system32\iglicd32.dll
2008-04-30 16:30 . 2008-05-04 13:51 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT.LOG
2008-04-30 16:30 . 2008-04-30 16:30 61 --a------ C:\WINDOWS\smscfg.ini
2008-04-30 16:28 . 2005-09-20 08:31 135,168 --a------ C:\WINDOWS\system32\igfxres.dll
2008-04-30 16:28 . 2008-04-30 21:32 1,024 --ah----- C:\Documents and Settings\Default User\ntuser.dat.LOG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-04 19:00 4,968 ----a-w C:\Program Files\hijackthis.log
2008-05-03 20:56 1,469 ----a-w C:\Program Files\AUD.INI
2008-05-03 20:56 1,409 ----a-w C:\Program Files\TTSNOTE.FOR
2008-05-03 19:26 140 ----a-w C:\Program Files\TTSSEQ.INI
2008-05-03 19:11 5,592 ----a-w C:\Program Files\WaveProf.Txt
2008-05-03 19:06 23,311 ----a-w C:\Program Files\INSTALL.LOG
2008-05-03 19:05 57,436 ----a-w C:\Program Files\cakewalk.ini
2001-07-06 16:22 1,532,865 ----a-w C:\Program Files\cwhs.chm
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\WINDOWS\system32\382077 ----
((((((((((((((((((((((((((((( snapshot@2008-05-04_13.58.59.07 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-04 18:58:13 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-04 19:59:31 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 08:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 08:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 08:36 114688]
"M-Audio Delta Taskbar Icon"="C:\WINDOWS\System32\DeltTray.exe" [2004-08-27 06:43 56320]
"DeltTray"="DeltTray.exe" [2004-08-27 06:43 56320 C:\WINDOWS\system32\DeltTray.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48 36975]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-05-03 10:02:47 113664]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1997-07-11 111376]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-07-11 51984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi2"= rddv1009.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
R0 a320raid;a320raid;C:\WINDOWS\system32\DRIVERS\a320raid.sys [2005-02-17 23:05]
R0 aac;PERC 320/DC SCSI RAID Miniport Driver;C:\WINDOWS\system32\DRIVERS\aac.sys [2004-04-07 17:14]
R0 aarich;aarich;C:\WINDOWS\system32\DRIVERS\aarich.sys [2005-05-17 21:12]
R0 megasas;DELL PERC RAID Driver;C:\WINDOWS\system32\drivers\megasas.sys [2006-04-18 12:51]
R2 RVIEG01;VSC Engine;C:\Program Files\Cakewalk\Shared Dxi\Roland\RVIEg01.sys [2001-04-13 19:16]
S3 RD1009;Roland UM-1 USB Driver;C:\WINDOWS\system32\Drivers\rdwm1009.sys [2000-11-27 04:04]
S4 vmscsi;vmscsi;C:\WINDOWS\system32\drivers\vmscsi.sys [2003-02-24 13:02]
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-04 14:59:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-05-04 15:00:26 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-04 20:00:23
ComboFix2.txt 2008-05-04 18:59:10
Pre-Run: 153,531,351,040 bytes free
Post-Run: 153,523,027,968 bytes free
233