ComboFix 08-02-25.2 - Owner 2008-02-24 21:40:23.4 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-01-25 to 2008-02-25 )))))))))))))))))))))))))))))))
.
2008-02-24 14:26 . 2008-02-24 14:26 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-02-24 14:26 . 2008-02-24 14:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-24 14:25 . 2008-02-24 14:26 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-02-24 12:47 . 2008-02-24 13:17 <DIR> d-------- C:\VundoFix Backups
2008-02-23 13:56 . 2008-02-23 13:56 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-23 10:34 . 2008-02-24 10:20 15,360 --a--c--- C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-02-23 10:34 . 2008-02-24 10:20 15,360 --a------ C:\WINDOWS\system32\ctfmon.exe
2008-02-21 20:22 . 2008-02-23 20:34 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-02-17 14:06 . 2008-02-17 14:06 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-17 14:06 . 2008-02-17 14:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-15 20:40 . 2008-02-17 22:04 476 --a------ C:\WINDOWS\wininit.ini
2008-02-15 20:06 . 2008-02-15 19:56 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-15 20:06 . 2008-02-15 20:06 3,444 --a------ C:\WINDOWS\unins000.dat
2008-02-15 15:24 . 2008-02-15 15:25 2,094 --ahs---- C:\WINDOWS\system32\gebgemvv.ini
2008-02-15 15:18 . 2008-02-24 10:19 157,341 --a------ C:\WINDOWS\BM7383503f.xml
2008-02-15 15:18 . 2008-02-24 12:44 22 --a------ C:\WINDOWS\pskt.ini
2008-02-13 15:27 . 2008-02-15 14:53 1,373,515 --ahs---- C:\WINDOWS\system32\dwlbxjfq.ini
2008-02-07 19:22 . 2008-02-07 19:27 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Intuit
2008-02-07 19:20 . 2008-02-07 19:20 <DIR> d-------- C:\Program Files\Common Files\AnswerWorks 4.0
2008-02-07 19:18 . 2008-02-07 19:18 <DIR> d-------- C:\Program Files\Common Files\Intuit
2008-02-07 19:18 . 2008-02-07 19:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Intuit
2008-02-07 19:18 . 2007-10-22 18:58 1,721,712 --a------ C:\WINDOWS\system32\InetClnt.dll
2008-02-07 19:08 . 2008-02-07 19:08 <DIR> d-------- C:\Program Files\TurboTax
2008-02-03 08:57 . 2008-02-03 10:47 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-02-01 21:04 . 2008-02-01 21:05 1,741,284 --ahs---- C:\WINDOWS\system32\murjhrjq.ini
2008-02-01 09:07 . 2008-02-01 09:07 0 --a------ C:\WINDOWS\system32\scrwjxgd.tmp
2008-02-01 09:06 . 2008-02-01 09:07 1,707,104 --ahs---- C:\WINDOWS\system32\scrwjxgd.ini
2008-01-31 21:10 . 2008-01-31 21:10 1,719,767 --ahs---- C:\WINDOWS\system32\tcfqvwlf.ini
2008-01-31 21:06 . 2008-01-31 21:07 1,961,288 --ahs---- C:\WINDOWS\system32\rxdhlufi.ini
2008-01-31 09:09 . 2008-01-31 16:00 1,707,044 --ahs---- C:\WINDOWS\system32\impyrvot.ini
2008-01-31 09:03 . 2008-01-31 09:04 1,725,849 --ahs---- C:\WINDOWS\system32\conlbuwo.ini
2008-01-30 21:05 . 2008-01-30 21:05 1,721,568 --ahs---- C:\WINDOWS\system32\wlbgiali.ini
2008-01-29 17:30 . 2008-01-31 16:00 1,964,520 --ahs---- C:\WINDOWS\system32\wgtqxlop.ini
2008-01-28 19:03 . 2008-01-28 19:03 <DIR> d-------- C:\WINDOWS\system32\bak
2008-01-28 09:47 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-01-27 20:18 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-01-27 20:17 . 2008-01-27 20:17 <DIR> d-------- C:\Program Files\Common Files\Java
2008-01-27 20:13 . 2008-01-27 20:13 <DIR> d-------- C:\Program Files\SDM
2008-01-27 19:22 . 2008-01-27 19:22 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-27 19:00 . 2007-07-08 21:01 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-01-27 19:00 . 2007-07-08 21:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver
2008-01-27 19:00 . 2007-12-17 21:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-01-27 19:00 . 2007-07-08 21:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AOL
2008-01-27 09:26 . 2008-01-27 15:01 586 --ahs---- C:\WINDOWS\system32\gyflbydn.ini
2008-01-27 09:23 . 2008-01-27 09:23 294 --ahs---- C:\WINDOWS\system32\vwfoojqm.ini
2008-01-26 09:29 . 2008-01-26 18:02 466 --ahs---- C:\WINDOWS\system32\qwjlrleh.ini
2008-01-26 09:23 . 2008-01-26 09:23 294 --ahs---- C:\WINDOWS\system32\wqaqtmdy.ini
2008-01-25 21:24 . 2008-01-26 09:35 466 --ahs---- C:\WINDOWS\system32\imkhfurx.ini
2008-01-25 21:21 . 2008-01-25 21:21 294 --ahs---- C:\WINDOWS\system32\cxsvknup.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 18:20 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-24 04:35 15,360 ----a-w C:\WINDOWS\system32\ctfmon .exe
2008-02-22 04:22 --------- d-----w C:\Program Files\MSN Messenger
2008-02-16 04:39 --------- d-----w C:\Program Files\Free Offers from Freeze.com
2008-02-16 04:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-16 01:05 --------- d-----w C:\Program Files\McAfee
2008-02-08 03:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-07 23:11 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2008-01-28 07:33 169,984 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
2008-01-28 04:18 --------- d-----w C:\Program Files\Java
2008-01-19 03:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-19 03:48 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-01-11 03:36 --------- d-----w C:\Program Files\RcvSystem
2008-01-05 19:23 --------- d-----w C:\Documents and Settings\Owner\Application Data\SiteAdvisor
2008-01-04 19:00 --------- d-----w C:\Program Files\Common Files\Webroot Shared
2008-01-04 19:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Webroot
2008-01-02 20:39 --------- d-----w C:\Documents and Settings\britney.FILBERT\Application Data\SiteAdvisor
2008-01-01 23:37 --------- d-----w C:\Program Files\SiteAdvisor
2008-01-01 16:12 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-12-31 01:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-31 01:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2007-12-31 01:29 --------- d-----w C:\Program Files\Common Files\McAfee
2007-12-31 01:24 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-31 01:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-31 01:03 --------- d-----w C:\Program Files\Yahoo!
2007-12-29 23:59 --------- d-----w C:\Program Files\QuickTime
2007-12-23 18:54 46,512 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-11-27 07:04 74,703 ----a-w C:\WINDOWS\system32\mfc45.dll
2007-11-26 22:47 194,888 ----a-w C:\WINDOWS\Unwash6.exe
2007-11-26 02:49 46,512 ----a-w C:\Documents and Settings\britney.FILBERT\Application Data\GDIPFONTCACHEV1.DAT
.
Code:
<pre>
----a-w 115,816 2007-12-29 17:39:32 C:\Program Files\Common Files\Symantec Shared\ccApp .exe
----a-w 68,856 2007-12-29 17:39:46 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
----a-w 270,648 2007-12-22 18:55:30 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 144,784 2008-01-28 04:57:19 C:\Program Files\Java\jre1.6.0_04\bin\jusched .exe
----a-w 582,992 2008-01-30 02:05:10 C:\Program Files\McAfee.com\Agent\mcagent .exe
----a-w 1,694,208 2007-12-28 05:32:54 C:\Program Files\Messenger\msmsgs .exe
----a-w 5,674,352 2008-01-29 02:38:02 C:\Program Files\MSN Messenger\MsnMsgr .Exe
----a-w 5,674,352 2008-01-31 03:43:29 C:\Program Files\MSN Messenger\bak\msnmsgr .exe
----a-w 282,624 2007-12-30 06:01:00 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:01 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:02 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:03 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:04 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:05 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:07 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:08 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:09 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:11 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:13 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:14 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:16 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:17 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:19 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:20 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:21 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:22 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:23 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:25 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2007-12-30 06:01:27 C:\Program Files\QuickTime\qttask .exe
----a-w 2,097,488 2008-02-24 04:35:39 C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
----a-w 1,206,600 2008-01-28 09:19:06 C:\Program Files\Webroot\Washer\wwDisp .exe
----a-w 169,984 2008-01-28 07:33:35 C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
----a-w 15,360 2008-02-24 04:35:35 C:\WINDOWS\system32\ctfmon .exe
</pre>
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{03818d58-854e-4681-bde0-8f5cb63c98aa}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06e33a7a-900e-4a4d-8e10-64894c5a6101}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{07b1a70d-299a-427f-af53-b0d58f8c3236}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{24130fc5-3284-4e8d-98f6-ea01b6984d16}]
C:\WINDOWS\system32\fmkqeyft.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2F551E36-B34E-4342-944B-2B980E432716}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{432B2330-2008-4E26-A237-594C54126615}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{48A16FEE-F943-403C-9F92-DECF55BCD820}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{552B86A7-D89C-4136-B589-81B5BE1B1D44}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{59C3B40A-92FE-4975-A5DF-BE51F45E7CCD}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{64960885-0409-41E1-80CB-457BB2D6896F}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A02C47F-60E3-4E2F-93B4-B4CE658B8C59}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6E548D91-0D0F-4A48-9216-49C00191E207}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6FF5EB0C-94F1-415A-AB9F-FB2D6C86184B}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79e40ab3-e068-4553-8839-b701acec1de7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91587F08-C5C4-4286-A90C-20DD8A78A4B2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97812B21-D87C-47BC-974E-2B30A46C0F59}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{98450F23-A8F3-48E6-9F48-ADEA0FAA4C54}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9c6d2a88-9e99-40b0-9e4a-29b4c8ea5fb4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9E726B90-5DD7-4A24-9326-7A5067CBED64}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A337763C-B6CE-4FC3-BB9E-BC97F3751856}]
C:\WINDOWS\system32\vtutt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8352918-FFBA-4425-9FC0-EBF39236F6DE}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B82802EF-5E7B-4FAF-B4E9-9CF807226EC0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C36E56FB-3064-434B-B07C-6CE9A1E85E7C}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E733331C-DCDC-48A2-B81B-9BE1D5CAFC75}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F1CB876D-4022-43B1-9156-6758C4132136}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F25A0899-F659-4B48-A012-0BC251DEB91F}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F8A643C4-4D76-44DA-BCE1-4E8B9B7F73EE}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-24 10:20 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-09-18 07:32 7204864]
"70b063a3"="C:\WINDOWS\system32\thantoom.dll" [ ]
"BM7383503f"="C:\WINDOWS\system32\mifvpspf.dll" [ ]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\70b063a3]
C:\WINDOWS\system32\udeiwkeb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
--a------ 2004-10-18 16:42 79448 C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cleanup]
C:\DOCUME~1\Owner\LOCALS~1\Temp\200779174123_mcappins.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2004-11-03 13:03 125528 C:\Program Files\Common Files\AOL\1183959268\EE\AOLHostManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-29 23:00 270648 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\vtutt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
--a------ 2008-01-31 21:23 582992 C:\Program Files\McAfee.com\Agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msci]
C:\DOCUME~1\Owner\LOCALS~1\Temp\200779174121_mcinfo.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-09-18 07:32 7204864 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2005-09-18 07:32 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-09-18 07:32 1519616 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
%WINDIR%\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
%WINDIR%\Creator\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 19:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2005-09-26 14:07 90112 C:\WINDOWS\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-01 04:32 144784 C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunKistEM]
--a------ 2004-11-15 14:04 135168 C:\Program Files\Digital Media Reader\shwiconem.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave]
C:\Program Files\Save\Save.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Window Washer]
C:\Program Files\Webroot\Washer\wwDisp.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
R2 SonyIEx;SonyIEx;C:\WINDOWS\system32\SonyIEx.exe [2005-05-30 10:48]
R2 wwEngineSvc;Window Washer Engine;C:\Program Files\Webroot\Washer\WasherSvc.exe [2007-11-26 14:47]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-22 06:33:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-15 09:39:53 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-02-01 09:00:23 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-24 21:44:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-24 21:45:12
ComboFix-quarantined-files.txt 2008-02-25 05:45:02
ComboFix2.txt 2008-02-25 05:09:36
ComboFix3.txt 2008-02-25 00:30:26
ComboFix4.txt 2008-01-28 05:01:11
.
2008-02-13 11:06:04 --- E O F ---