ComboFix 08-02-24.4 - Owner 2008-02-24 21:58:59.2 - NTFSx86
Running from: C:\Users\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Users\Owner\Desktop\CFScript.txt
.
((((((((((((((((((((((((( Files Created from 2008-01-24 to 2008-02-24 )))))))))))))))))))))))))))))))
.
2008-02-24 21:35 . 2008-02-24 21:35 524,288 --ahs---- C:\ntuser.dat{76969094-e307-11dc-b6f1-0050bfa9a130}.TMContainer00000000000000000002.regtrans-ms
2008-02-24 21:35 . 2008-02-24 21:35 524,288 --ahs---- C:\ntuser.dat{76969094-e307-11dc-b6f1-0050bfa9a130}.TMContainer00000000000000000001.regtrans-ms
2008-02-24 21:35 . 2008-02-24 21:35 65,536 --ahs---- C:\ntuser.dat{76969094-e307-11dc-b6f1-0050bfa9a130}.TM.blf
2008-02-24 21:34 . 2008-02-24 21:35 524,288 --ahs---- C:\ntuser.dat{76969090-e307-11dc-b6f1-0050bfa9a130}.TMContainer00000000000000000002.regtrans-ms
2008-02-24 21:34 . 2008-02-24 21:35 524,288 --ahs---- C:\ntuser.dat{76969090-e307-11dc-b6f1-0050bfa9a130}.TMContainer00000000000000000001.regtrans-ms
2008-02-24 21:34 . 2008-02-24 21:35 65,536 --ahs---- C:\ntuser.dat{76969090-e307-11dc-b6f1-0050bfa9a130}.TM.blf
2008-02-21 18:52 . 2008-02-24 21:35 262,144 --a------ C:\ntuser.dat
2008-02-21 18:52 . 2008-02-24 21:35 5,120 --ah----- C:\ntuser.dat.LOG1
2008-02-21 18:52 . 2008-02-24 21:34 0 --ah----- C:\ntuser.dat.LOG2
2008-02-21 17:24 . 2008-02-21 17:24 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-21 12:16 . 2008-02-21 12:17 186,199,970 --a------ C:\SYM_REGISTRY_BACKUP.reg
2008-02-20 21:36 . 2008-02-20 21:37 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-02-20 21:36 . 2008-02-20 21:37 <DIR> d-------- C:\ProgramData\Lavasoft
2008-02-20 21:36 . 2008-02-20 21:36 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-20 18:04 . 2008-02-20 18:04 2,598 --a------ C:\Windows\wininit.ini
2008-02-20 17:40 . 2008-02-20 18:07 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-02-20 17:40 . 2008-02-20 18:07 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-02-20 17:40 . 2008-02-20 17:41 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-17 18:26 . 2008-02-17 18:26 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-16 17:40 . 2008-02-24 21:10 <DIR> d-------- C:\Users\Owner\Tracing
2008-02-16 17:34 . 2008-02-16 17:34 <DIR> d-------- C:\Program Files\Windows Live
2008-02-16 12:36 . 2008-02-17 14:23 <DIR> d-------- C:\Users\Owner\Incomplete
2008-02-16 12:29 . 2008-02-16 18:49 <DIR> d-------- C:\Users\Owner\AppData\Roaming\LimeWire
2008-02-16 12:28 . 2008-02-16 14:02 <DIR> d-------- C:\Program Files\LimeWire
2008-02-16 11:28 . 2008-02-16 11:28 <DIR> d-------- C:\Program Files\FDRLab
2008-02-16 00:21 . 2008-02-16 00:21 <DIR> d-------- C:\Windows\PCHEALTH
2008-02-15 23:29 . 2008-02-15 23:29 306,432 --a------ C:\Windows\System32\TuneUpDefragService.exe
2008-02-15 23:29 . 2007-12-20 12:41 29,440 --a------ C:\Windows\System32\uxtuneup.dll
2008-02-15 23:24 . 2006-12-20 08:03 229,888 --a------ C:\Windows\System32\msshsq.dll
2008-02-15 18:50 . 2008-02-21 19:05 <DIR> d-------- C:\Users\Owner\AppData\Roaming\Winamp
2008-02-13 22:24 . 2008-02-13 22:24 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-02-13 22:24 . 2008-02-13 22:24 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-02-13 22:23 . 2008-02-13 22:23 613,888 --a------ C:\Windows\System32\wpd_ci.dll
2008-02-13 22:23 . 2008-02-13 22:23 260,096 --a------ C:\Windows\System32\dpx.dll
2008-02-13 22:23 . 2008-02-13 22:23 224,824 --a------ C:\Windows\System32\clfs.sys
2008-02-13 22:23 . 2008-02-13 22:23 221,696 --a------ C:\Windows\System32\umpnpmgr.dll
2008-02-13 22:23 . 2008-02-13 22:23 101,888 --a------ C:\Windows\System32\drvinst.exe
2008-02-13 22:23 . 2008-02-13 22:23 19,456 --a------ C:\Windows\System32\cfgmgr32.dll
2008-02-13 22:23 . 2008-02-13 22:23 6,656 --a------ C:\Windows\System32\kbd106n.dll
2008-02-13 22:20 . 2008-02-13 22:20 3,504,696 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-02-13 22:20 . 2008-02-13 22:20 3,470,392 --a------ C:\Windows\System32\ntoskrnl.exe
2008-02-13 22:20 . 2008-02-13 22:20 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-02-13 22:20 . 2008-02-13 22:20 109,624 --a------ C:\Windows\System32\drivers\ataport.sys
2008-02-13 22:20 . 2008-02-13 22:20 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-02-13 22:20 . 2008-02-13 22:20 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-02-13 22:20 . 2008-02-13 22:20 17,464 --a------ C:\Windows\System32\drivers\intelide.sys
2008-02-13 22:19 . 2008-02-13 22:19 803,328 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-02-13 22:19 . 2008-02-13 22:19 216,632 --a------ C:\Windows\System32\drivers\netio.sys
2008-02-13 22:19 . 2008-02-13 22:19 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-02-13 22:19 . 2008-02-13 22:19 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-02-13 22:19 . 2008-02-13 22:19 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-02-13 22:18 . 2008-02-13 22:18 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-13 22:18 . 2008-02-13 22:18 1,686,528 --a------ C:\Windows\System32\gameux.dll
2008-02-06 19:13 . 2008-02-06 19:13 <DIR> d-------- C:\Program Files\OpenAL
2008-02-06 19:11 . 2008-02-06 19:11 <DIR> d-------- C:\Windows\System32\xlive
2008-01-30 10:11 . 2008-01-30 10:11 764,416 --a------ C:\Windows\System32\drivers\athr.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 15:04 --------- d-----w C:\Users\Owner\AppData\Roaming\dvdcss
2008-02-21 06:16 --------- d-----w C:\Program Files\DAEMON Tools
2008-02-20 19:34 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-17 16:33 --------- d-----w C:\Program Files\Java
2008-02-16 15:38 --------- d-----w C:\Program Files\MSN Messenger
2008-02-16 11:59 --------- d-----w C:\ProgramData\Symantec
2008-02-16 11:59 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-16 10:13 --------- d-----w C:\Program Files\Winamp
2008-02-16 07:18 47,360 ----a-w C:\Users\Owner\AppData\Roaming\pcouffin.sys
2008-02-16 07:18 --------- d-----w C:\Users\Owner\AppData\Roaming\Vso
2008-02-15 22:29 --------- d-----w C:\ProgramData\Microsoft Help
2008-02-15 21:29 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-02-15 18:39 --------- d-----w C:\Program Files\Google
2008-02-13 20:22 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys
2008-02-13 20:22 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-02-13 20:22 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-02-13 20:22 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys
2008-02-13 20:22 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys
2008-02-13 20:22 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys
2008-02-13 20:22 15,872 ----a-w C:\Windows\system32\drivers\mouhid.sys
2008-02-13 20:18 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 20:18 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 20:18 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 20:18 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 20:15 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-01-27 07:46 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-01-27 07:46 --------- d-----w C:\Program Files\AutoCAD 2007
2008-01-27 07:14 --------- d-----w C:\Program Files\Glovebox
2008-01-27 07:13 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-23 16:45 --------- d-----w C:\Users\Owner\AppData\Roaming\fretsonfire
2008-01-23 15:11 47,360 ----a-w C:\Windows\system32\drivers\pcouffin.sys
2008-01-23 15:11 --------- d-----w C:\Program Files\VSO
2008-01-21 10:56 --------- d-----w C:\Program Files\vghd
2008-01-21 10:54 --------- d-----w C:\Users\Owner\AppData\Roaming\vghd
2008-01-15 06:32 --------- d-----w C:\Program Files\Common Files\Nero
2008-01-13 16:13 --------- d-----w C:\Program Files\DaemonTools_WhenUSave_Installer
2008-01-13 15:15 --------- d-----w C:\Program Files\ESET
2008-01-13 14:34 --------- d-----w C:\Program Files\BYTE@HAND
2008-01-13 07:37 --------- d-----w C:\ProgramData\Eset
2008-01-12 09:55 --------- d-----w C:\Program Files\Microsoft Synchronization Services
2008-01-12 09:55 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-01-12 09:54 --------- d-----w C:\ProgramData\LogiShrd
2008-01-12 09:51 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-01-12 09:50 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-01-12 09:46 --------- d-----w C:\Program Files\Common Files\Logitech
2008-01-12 09:46 --------- d-----w C:\Program Files\Common Files\Logishrd
2008-01-12 09:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-12 09:45 --------- d-----w C:\ProgramData\Logitech
2008-01-10 17:14 --------- d-----w C:\ProgramData\Creative
2008-01-10 17:06 --------- d-----w C:\Users\Owner\AppData\Roaming\Creative
2008-01-10 16:56 --------- d--h--w C:\Program Files\Creative Installation Information
2008-01-10 16:56 --------- d-----w C:\Program Files\Creative
2008-01-10 16:52 --------- d-----w C:\Program Files\Common Files\Creative
2008-01-10 07:37 --------- d-----w C:\Program Files\Windows Mail
2008-01-10 07:33 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-10 07:33 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-01-10 07:32 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-09 14:10 --------- d-----w C:\Program Files\PCI Audio Applications
2008-01-09 06:56 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-01-08 20:43 --------- d-----w C:\Program Files\Reallusion
2008-01-06 08:09 174 --sha-w C:\Program Files\desktop.ini
2008-01-06 08:02 --------- d-----w C:\Program Files\Windows Calendar
2008-01-06 08:01 --------- d-----w C:\Program Files\Windows Defender
2008-01-05 18:16 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys
2008-01-05 18:16 619,008 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
2008-01-05 18:16 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys
2008-01-05 18:16 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
2008-01-05 18:16 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
2008-01-05 18:14 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2008-01-05 18:14 2,923,520 ----a-w C:\Windows\explorer.exe
2008-01-05 18:07 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-01-05 18:07 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys
2008-01-05 18:07 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-01-05 18:03 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2008-01-05 18:03 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2008-01-05 18:03 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2008-01-05 18:03 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2008-01-05 18:03 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2008-01-05 17:58 320,000 ----a-w C:\Windows\system32\drivers\csc.sys
2008-01-05 17:56 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
2008-01-05 17:55 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2008-01-05 17:55 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2008-01-05 17:55 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2008-01-05 17:55 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2008-01-05 17:54 12,800 ----a-w C:\Windows\system32\drivers\fs_rec.sys
2008-01-05 12:24 --------- d-----w C:\Program Files\ZyDAS Technology Corporation
2008-01-05 12:24 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-01-05 12:24 --------- d-----w C:\Program Files\Windows Live Favorites
2008-01-05 12:24 --------- d-----w C:\Program Files\WinAVIVideoConverter
2008-01-05 12:24 --------- d-----w C:\Program Files\Winamp Remote
2008-01-05 12:24 --------- d-----w C:\Program Files\Weather Add-in for Windows Live Toolbar
2008-01-05 12:24 --------- d-----w C:\Program Files\Vimicro
2008-01-05 12:23 --------- d-----w C:\Program Files\VideoLAN
2008-01-05 12:22 --------- d-----w C:\Program Files\Team17 Software Ltd
2008-01-05 12:22 --------- d-----w C:\Program Files\SMC
2008-01-05 12:22 --------- d-----w C:\Program Files\SlySoft
2008-01-05 12:21 --------- d-----w C:\Program Files\sixteen tons entertainment
2008-01-05 12:21 --------- d-----w C:\Program Files\Sierra Entertainment
2008-01-05 12:20 --------- d-----w C:\Program Files\Sierra
2008-01-05 12:20 --------- d-----w C:\Program Files\Sidesk
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 09:32 1232896]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-11-02 11:45 8704]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-01-19 14:26 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-10-09 02:36 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-10-09 02:36 8534560]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-10-09 02:36 81920]
"P17RunE"="P17RunE.dll" [2007-04-09 03:40 14848 C:\Windows\System32\P17RunE.dll]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 03:10 55824 C:\Windows\KHALMNPR.Exe]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 08:21 1443072]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-06-27 23:02:17 784912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"C-Media Mixer"=Mixer.exe /startup
"Windows Mobile-based device management"=%windir%\WindowsMobile\wmdSync.exe
"Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
"UpdReg"=C:\Windows\UpdReg.EXE
"VolPanel"="C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe"= %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
"%windir%\system32\sessmgr.exe"= %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\Program Files\MSN Messenger\livecall.exe"= C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
"C:\Program Files\MSN Messenger\msnmsgr.exe"= C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\GloballyOpenPorts\List]
"137:UDP"= 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"139:TCP"= 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"445:TCP"= 445:TCP:*:Enabled:@xpsp2res.dll,-22005