ComboFix 08-10-04.07 - Administrator 2008-10-05 12:27:31.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.877 [GMT -4:00]
Running from: E:\ComboFix.exe
Command switches used :: E:\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\DUMP82eb.tmp
C:\WINDOWS\DUMP9078.tmp
C:\WINDOWS\DUMP9c6e.tmp
C:\WINDOWS\system32\10.tmp
C:\WINDOWS\system32\11.tmp
C:\WINDOWS\system32\12.tmp
C:\WINDOWS\system32\13.tmp
C:\WINDOWS\system32\14.tmp
C:\WINDOWS\system32\15.tmp
C:\WINDOWS\system32\16.tmp
C:\WINDOWS\system32\17.tmp
C:\WINDOWS\system32\18.tmp
C:\WINDOWS\system32\19.tmp
C:\WINDOWS\system32\1A.tmp
C:\WINDOWS\system32\1B.tmp
C:\WINDOWS\system32\1C.tmp
C:\WINDOWS\system32\1D.tmp
C:\WINDOWS\system32\1Dr.dll
C:\WINDOWS\system32\1E.tmp
C:\WINDOWS\system32\1F.tmp
C:\WINDOWS\system32\2.tmp
C:\WINDOWS\system32\20.tmp
C:\WINDOWS\system32\21.tmp
C:\WINDOWS\system32\22.tmp
C:\WINDOWS\system32\23.tmp
C:\WINDOWS\system32\24.tmp
C:\WINDOWS\system32\25.tmp
C:\WINDOWS\system32\26.tmp
C:\WINDOWS\system32\27.tmp
C:\WINDOWS\system32\28.tmp
C:\WINDOWS\system32\29.tmp
C:\WINDOWS\system32\2A.tmp
C:\WINDOWS\system32\2B.tmp
C:\WINDOWS\system32\2C.tmp
C:\WINDOWS\system32\2D.tmp
C:\WINDOWS\system32\2E.tmp
C:\WINDOWS\system32\2F.tmp
C:\WINDOWS\system32\30.tmp
C:\WINDOWS\system32\31.tmp
C:\WINDOWS\system32\32.tmp
C:\WINDOWS\system32\33.tmp
C:\WINDOWS\system32\34.tmp
C:\WINDOWS\system32\35.tmp
C:\WINDOWS\system32\36.tmp
C:\WINDOWS\system32\37.tmp
C:\WINDOWS\system32\38.tmp
C:\WINDOWS\system32\39.tmp
C:\WINDOWS\system32\3A.tmp
C:\WINDOWS\system32\3B.tmp
C:\WINDOWS\system32\3C.tmp
C:\WINDOWS\system32\3D.tmp
C:\WINDOWS\system32\3E.tmp
C:\WINDOWS\system32\3F.tmp
C:\WINDOWS\system32\4.tmp
C:\WINDOWS\system32\40.tmp
C:\WINDOWS\system32\41.tmp
C:\WINDOWS\system32\42.tmp
C:\WINDOWS\system32\43.tmp
C:\WINDOWS\system32\44.tmp
C:\WINDOWS\system32\45.tmp
C:\WINDOWS\system32\46.tmp
C:\WINDOWS\system32\47.tmp
C:\WINDOWS\system32\48.tmp
C:\WINDOWS\system32\49.tmp
C:\WINDOWS\system32\4A.tmp
C:\WINDOWS\system32\4B.tmp
C:\WINDOWS\system32\4C.tmp
C:\WINDOWS\system32\4D.tmp
C:\WINDOWS\system32\4E.tmp
C:\WINDOWS\system32\4F.tmp
C:\WINDOWS\system32\5.tmp
C:\WINDOWS\system32\50.tmp
C:\WINDOWS\system32\51.tmp
C:\WINDOWS\system32\52.tmp
C:\WINDOWS\system32\53.tmp
C:\WINDOWS\system32\55.tmp
C:\WINDOWS\system32\57.tmp
C:\WINDOWS\system32\58.tmp
C:\WINDOWS\system32\58c.dll
C:\WINDOWS\system32\598619786.dat
C:\WINDOWS\system32\5F.tmp
C:\WINDOWS\system32\60.tmp
C:\WINDOWS\system32\61.tmp
C:\WINDOWS\system32\66.tmp
C:\WINDOWS\system32\67.tmp
C:\WINDOWS\system32\68.tmp
C:\WINDOWS\system32\69.tmp
C:\WINDOWS\system32\6A.tmp
C:\WINDOWS\system32\7B.tmp
C:\WINDOWS\system32\7C.tmp
C:\WINDOWS\system32\7D.tmp
C:\WINDOWS\system32\7E.tmp
C:\WINDOWS\system32\7F.tmp
C:\WINDOWS\system32\8.tmp
C:\WINDOWS\system32\9.tmp
C:\WINDOWS\system32\AF.tmp
C:\WINDOWS\system32\B.tmp
C:\WINDOWS\system32\B0.tmp
C:\WINDOWS\system32\B1.tmp
C:\WINDOWS\system32\B2.tmp
C:\WINDOWS\system32\B3.tmp
C:\WINDOWS\system32\C3.tmp
C:\WINDOWS\system32\C4.tmp
C:\WINDOWS\system32\C5.tmp
C:\WINDOWS\system32\C6.tmp
C:\WINDOWS\system32\C7.tmp
C:\WINDOWS\system32\C8.tmp
C:\WINDOWS\system32\D.tmp
C:\WINDOWS\system32\drivers\ati1ttxxx.sys
C:\WINDOWS\system32\drivers\cjvwgp.sys
C:\WINDOWS\system32\drivers\NUWNNTWO.sys
C:\WINDOWS\system32\drivers\uhktyh.sys
C:\WINDOWS\system32\drivers\xlrp.sys
C:\WINDOWS\system32\dswiuwsf.tmp
C:\WINDOWS\system32\FPapli.exe
C:\WINDOWS\system32\Jamster.ico
C:\WINDOWS\system32\netrp.sys
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\system32\ZoneAlarmIconUS.ico
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\VundoFix Backups
C:\WINDOWS\DUMP82eb.tmp
C:\WINDOWS\DUMP9078.tmp
C:\WINDOWS\DUMP9c6e.tmp
C:\WINDOWS\system32\10.tmp
C:\WINDOWS\system32\11.tmp
C:\WINDOWS\system32\12.tmp
C:\WINDOWS\system32\13.tmp
C:\WINDOWS\system32\14.tmp
C:\WINDOWS\system32\15.tmp
C:\WINDOWS\system32\16.tmp
C:\WINDOWS\system32\17.tmp
C:\WINDOWS\system32\18.tmp
C:\WINDOWS\system32\19.tmp
C:\WINDOWS\system32\1A.tmp
C:\WINDOWS\system32\1B.tmp
C:\WINDOWS\system32\1C.tmp
C:\WINDOWS\system32\1D.tmp
C:\WINDOWS\system32\1Dr.dll
C:\WINDOWS\system32\1E.tmp
C:\WINDOWS\system32\1F.tmp
C:\WINDOWS\system32\2.tmp
C:\WINDOWS\system32\20.tmp
C:\WINDOWS\system32\21.tmp
C:\WINDOWS\system32\22.tmp
C:\WINDOWS\system32\23.tmp
C:\WINDOWS\system32\24.tmp
C:\WINDOWS\system32\25.tmp
C:\WINDOWS\system32\26.tmp
C:\WINDOWS\system32\27.tmp
C:\WINDOWS\system32\28.tmp
C:\WINDOWS\system32\29.tmp
C:\WINDOWS\system32\2A.tmp
C:\WINDOWS\system32\2B.tmp
C:\WINDOWS\system32\2C.tmp
C:\WINDOWS\system32\2D.tmp
C:\WINDOWS\system32\2E.tmp
C:\WINDOWS\system32\2F.tmp
C:\WINDOWS\system32\30.tmp
C:\WINDOWS\system32\31.tmp
C:\WINDOWS\system32\32.tmp
C:\WINDOWS\system32\33.tmp
C:\WINDOWS\system32\34.tmp
C:\WINDOWS\system32\35.tmp
C:\WINDOWS\system32\36.tmp
C:\WINDOWS\system32\37.tmp
C:\WINDOWS\system32\38.tmp
C:\WINDOWS\system32\39.tmp
C:\WINDOWS\system32\3A.tmp
C:\WINDOWS\system32\3B.tmp
C:\WINDOWS\system32\3C.tmp
C:\WINDOWS\system32\3D.tmp
C:\WINDOWS\system32\3E.tmp
C:\WINDOWS\system32\3F.tmp
C:\WINDOWS\system32\4.tmp
C:\WINDOWS\system32\40.tmp
C:\WINDOWS\system32\41.tmp
C:\WINDOWS\system32\42.tmp
C:\WINDOWS\system32\43.tmp
C:\WINDOWS\system32\44.tmp
C:\WINDOWS\system32\45.tmp
C:\WINDOWS\system32\46.tmp
C:\WINDOWS\system32\47.tmp
C:\WINDOWS\system32\48.tmp
C:\WINDOWS\system32\49.tmp
C:\WINDOWS\system32\4A.tmp
C:\WINDOWS\system32\4B.tmp
C:\WINDOWS\system32\4C.tmp
C:\WINDOWS\system32\4D.tmp
C:\WINDOWS\system32\4E.tmp
C:\WINDOWS\system32\4F.tmp
C:\WINDOWS\system32\5.tmp
C:\WINDOWS\system32\50.tmp
C:\WINDOWS\system32\51.tmp
C:\WINDOWS\system32\52.tmp
C:\WINDOWS\system32\53.tmp
C:\WINDOWS\system32\55.tmp
C:\WINDOWS\system32\57.tmp
C:\WINDOWS\system32\58.tmp
C:\WINDOWS\system32\58c.dll
C:\WINDOWS\system32\598619786.dat
C:\WINDOWS\system32\5F.tmp
C:\WINDOWS\system32\60.tmp
C:\WINDOWS\system32\61.tmp
C:\WINDOWS\system32\66.tmp
C:\WINDOWS\system32\67.tmp
C:\WINDOWS\system32\68.tmp
C:\WINDOWS\system32\69.tmp
C:\WINDOWS\system32\6A.tmp
C:\WINDOWS\system32\7B.tmp
C:\WINDOWS\system32\7C.tmp
C:\WINDOWS\system32\7D.tmp
C:\WINDOWS\system32\7E.tmp
C:\WINDOWS\system32\7F.tmp
C:\WINDOWS\system32\8.tmp
C:\WINDOWS\system32\9.tmp
C:\WINDOWS\system32\AF.tmp
C:\WINDOWS\system32\B.tmp
C:\WINDOWS\system32\B0.tmp
C:\WINDOWS\system32\B1.tmp
C:\WINDOWS\system32\B2.tmp
C:\WINDOWS\system32\B3.tmp
C:\WINDOWS\system32\C3.tmp
C:\WINDOWS\system32\C4.tmp
C:\WINDOWS\system32\C5.tmp
C:\WINDOWS\system32\C6.tmp
C:\WINDOWS\system32\C7.tmp
C:\WINDOWS\system32\C8.tmp
C:\WINDOWS\system32\D.tmp
C:\WINDOWS\system32\drivers\ati1ttxxx.sys
C:\WINDOWS\system32\dswiuwsf.tmp
C:\WINDOWS\system32\FPapli.exe
C:\WINDOWS\system32\inf
C:\WINDOWS\system32\Jamster.ico
C:\WINDOWS\system32\netrp.sys
C:\WINDOWS\system32\np5
C:\WINDOWS\system32\np5\sfeth112.exe
C:\WINDOWS\system32\p
C:\WINDOWS\system32\p\xerd2140.exe
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\system32\ZoneAlarmIconUS.ico
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ATI1TTXXX
-------\Legacy_NUWNNTWO
-------\Service_ati1ttxxx
-------\Service_fvac
-------\Service_hwqud
-------\Service_NUWNNTWO
-------\Service_xeljap
((((((((((((((((((((((((( Files Created from 2008-09-05 to 2008-10-05 )))))))))))))))))))))))))))))))
.
2008-09-26 21:29 . 2008-09-26 21:30 186,368 --a------ C:\WINDOWS\system32\65.tmp
2008-09-26 21:29 . 2008-09-26 21:29 186,368 --a------ C:\WINDOWS\system32\5B.tmp
2008-09-26 21:29 . 2008-09-26 21:29 78,848 --a------ C:\WINDOWS\system32\64.tmp
2008-09-26 21:29 . 2008-09-26 21:29 78,848 --a------ C:\WINDOWS\system32\5A.tmp
2008-09-26 21:29 . 2008-09-26 21:29 41,984 --a------ C:\WINDOWS\system32\62.tmp
2008-09-26 21:29 . 2008-09-26 21:29 41,984 --a------ C:\WINDOWS\system32\56.tmp
2008-09-26 21:29 . 2008-09-26 21:29 37,032 --a------ C:\WINDOWS\system32\63.tmp
2008-09-26 21:29 . 2008-09-26 21:29 37,032 --a------ C:\WINDOWS\system32\59.tmp
2008-09-26 21:29 . 2008-09-26 21:29 176 --a------ C:\WINDOWS\system32\5E.tmp
2008-09-26 21:29 . 2008-09-26 21:29 176 --a------ C:\WINDOWS\system32\54.tmp
2008-09-26 21:29 . 2008-09-26 21:29 18 --a------ C:\WINDOWS\system32\5C.tmp
2008-09-26 10:38 . 2008-09-26 10:38 <DIR> d-------- C:\WINDOWS\Sun
2008-09-26 10:28 . 2008-09-26 10:28 <DIR> d-------- C:\Program Files\Sun
2008-09-26 10:28 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-26 10:27 . 2008-09-26 10:27 <DIR> d-------- C:\Program Files\Common Files\Java
2008-09-20 03:40 . 2008-09-20 03:41 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-20 03:40 . 2008-09-20 03:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-20 03:40 . 2008-09-20 03:40 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-09-20 03:40 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-20 03:40 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-19 21:45 . 2008-09-20 11:30 <DIR> d-------- C:\WINDOWS\system32\ES
2008-09-19 21:45 . 2008-09-19 21:45 <DIR> d-------- C:\Temp\mtc2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-26 14:28 --------- d-----w C:\Program Files\Java
2008-09-25 22:09 --------- d-----w C:\Program Files\TalkPCR
2008-09-20 07:20 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-29 12:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-14 23:33 --------- d-----w C:\Program Files\LandAirSea Systems
2008-07-06 15:10 348,160 ----a-w C:\WINDOWS\MSVCR71.DLL
2008-07-06 15:10 1,060,864 ----a-w C:\WINDOWS\MFC71.DLL
2008-07-06 15:09 40,960 ----a-w C:\WINDOWS\SimTestDll.dll
.
------- Sigcheck -------
2005-03-13 21:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2006-04-20 08:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 12:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 06:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 07:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 07:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 06:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 17:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
2005-03-13 20:55 359808 0e66b538096a6529d1ac66e78eb0d5c8 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 07:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 15:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2007-10-30 13:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 15:20 361344 accf5a9a1ffaa490f33dba1c632b95e1 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2008-06-20 07:51 361600 9425b72f40257b45d45d24773273dad0 C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 07:51 361600 9425b72f40257b45d45d24773273dad0 C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 20:12 1041408 b0d52f609df94a72b4af3edf477c7c2e C:\WINDOWS\explorer.exe
2007-06-13 07:26 1040896 4580e16e92bb88da525a51e1b03b42e2 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 06:23 1040896 3225f4663de4cb04858403af116aef98 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 17:00 1039872 8fe830fbff9363952ed533a4022f5291 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2008-04-13 20:12 1041408 c074c20ff2cd9560706244ff3aad5724 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2004-08-04 17:00 23040 8cbacd9f0d3d6942fe10d134ed7ed764 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 20:12 23040 1f00a2901ffc1ba48321c06b5f2195f9 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-13 20:12 23040 d6cdc4fa4980a746a548be5d456ae7e4 C:\WINDOWS\system32\ctfmon.exe
2005-06-10 20:17 65536 ce3605a5b02be13080ad6fc62b00327a C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 19:53 65536 292419cc59317cc6ced2666a9ffcdde3 C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 17:00 65536 53832404a4ae49aea8ad515644b979bc C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2008-04-13 20:12 65536 30721bc166cf511848d7340e167170f3 C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-13 20:12 65536 c09cccb28b2a6307ef7e76e9c97b0e78 C:\WINDOWS\system32\spoolsv.exe
2004-08-04 17:00 32256 37bcdc79f48a0c7a83b48f31d6423247 C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2008-04-13 20:12 33792 cdb8fe37d770759da584fa4a3c585666 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2008-04-13 20:12 33792 0d931ad3b3aa2bae592d3ed2d6392aea C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRunOnce"="C:\util\prunonce\PRunOnce.exe" [2004-08-06 118784]
"Panasonic HotKey Manager"="C:\Program Files\Panasonic\HotKey Appendix\HKEYAPP.EXE" [2005-06-13 983040]
"PCinfo"="C:\Program Files\Panasonic\PCINFO\SetDiag.exe" [2005-06-14 53248]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 393216]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 163840]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-20 C:\WINDOWS\AGRSMMSG.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WLAN network adaptor Wireless LAN Configuration.lnk - C:\WINDOWS\system32\wlansta.exe [2006-05-10 155719]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 14:27 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.NTN1"= nuvision.ax
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Panasonic Hand Writing.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Panasonic Hand Writing.lnk
backup=C:\WINDOWS\pss\Panasonic Hand Writing.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-13 20:12 1702912 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--------- 2006-05-20 11:49 290816 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2007-06-13 09:16 536576 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--------- 2002-04-26 13:53 19968 C:\Program Files\Winamp\winampa.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\FreeFTP\\FreeFTP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R0 GPSFilter;Panasonic GPS Filter Service;C:\WINDOWS\system32\DRIVERS\gpsfilter.sys [2005-09-26 10112]
R2 brecal;Panasonic Battery Recalibration Driver;C:\Program Files\Panasonic\BRECAL\Brecal.sys [2004-11-15 7168]
R2 pcinfo;Panasonic PC Info. Viewer Driver;C:\Program Files\Panasonic\PCINFO\pcinfo.sys [2004-11-04 7168]
R2 SDKEY;Panasonic SD Misc. Function Driver;C:\Program Files\Panasonic\SDKEY\SDKEY.SYS [2005-04-21 8192]
R3 FIDMOU;Fujitsu touchpad;C:\WINDOWS\system32\DRIVERS\Fidmou.sys [2005-04-18 23463]
R3 HOTKEY;Panasonic Hotkey Driver;C:\WINDOWS\system32\DRIVERS\HOTKEY.SYS [2003-03-17 9216]
R3 vidcap;vidcap;C:\WINDOWS\system32\DRIVERS\vidcap.sys [2006-12-27 9006]
S2 USBHSB;GeneLink File Transfer Driver;C:\WINDOWS\system32\Drivers\usbhsb.sys [2001-12-17 18690]
S2 VRDVC20;Sony VRD-VC20 [Video Capture];C:\WINDOWS\system32\Drivers\VRDVC20X.SYS [2004-11-09 04:02 31104]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\NSNDIS5.SYS [2004-03-23 17280]
S3 NuVision;Hauppauge WinTV USB Pro (NTSC);C:\WINDOWS\system32\DRIVERS\NUVision.sys [2005-07-08 260144]
S3 s125bus;Sony Ericsson Device 125 driver (WDM);C:\WINDOWS\system32\DRIVERS\s125bus.sys [2007-04-24 83336]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s125mdfl.sys [2007-04-24 15112]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s125mdm.sys [2007-04-24 108680]
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s125mgmt.sys [2007-04-24 100488]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s125obex.sys [2007-04-24 98696]
S3 WLAN;IEEE 802.11b WLAN network adaptor Driver;C:\WINDOWS\system32\DRIVERS\WLANNDS.sys [2003-10-17 651776]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-05 12:32:26
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-10-05 12:37:08 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2008-10-05 16:37:02
ComboFix2.txt 2008-10-05 15:13:26
ComboFix3.txt 2008-10-05 01:31:15
ComboFix4.txt 2008-09-22 00:53:25
ComboFix5.txt 2008-10-05 16:26:22
Pre-Run: 30,733,098,496 bytes free
Post-Run: 30,684,529,664 bytes free
417 --- E O F --- 2008-09-11 03:34:02
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.877 [GMT -4:00]
Running from: E:\ComboFix.exe
Command switches used :: E:\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\DUMP82eb.tmp
C:\WINDOWS\DUMP9078.tmp
C:\WINDOWS\DUMP9c6e.tmp
C:\WINDOWS\system32\10.tmp
C:\WINDOWS\system32\11.tmp
C:\WINDOWS\system32\12.tmp
C:\WINDOWS\system32\13.tmp
C:\WINDOWS\system32\14.tmp
C:\WINDOWS\system32\15.tmp
C:\WINDOWS\system32\16.tmp
C:\WINDOWS\system32\17.tmp
C:\WINDOWS\system32\18.tmp
C:\WINDOWS\system32\19.tmp
C:\WINDOWS\system32\1A.tmp
C:\WINDOWS\system32\1B.tmp
C:\WINDOWS\system32\1C.tmp
C:\WINDOWS\system32\1D.tmp
C:\WINDOWS\system32\1Dr.dll
C:\WINDOWS\system32\1E.tmp
C:\WINDOWS\system32\1F.tmp
C:\WINDOWS\system32\2.tmp
C:\WINDOWS\system32\20.tmp
C:\WINDOWS\system32\21.tmp
C:\WINDOWS\system32\22.tmp
C:\WINDOWS\system32\23.tmp
C:\WINDOWS\system32\24.tmp
C:\WINDOWS\system32\25.tmp
C:\WINDOWS\system32\26.tmp
C:\WINDOWS\system32\27.tmp
C:\WINDOWS\system32\28.tmp
C:\WINDOWS\system32\29.tmp
C:\WINDOWS\system32\2A.tmp
C:\WINDOWS\system32\2B.tmp
C:\WINDOWS\system32\2C.tmp
C:\WINDOWS\system32\2D.tmp
C:\WINDOWS\system32\2E.tmp
C:\WINDOWS\system32\2F.tmp
C:\WINDOWS\system32\30.tmp
C:\WINDOWS\system32\31.tmp
C:\WINDOWS\system32\32.tmp
C:\WINDOWS\system32\33.tmp
C:\WINDOWS\system32\34.tmp
C:\WINDOWS\system32\35.tmp
C:\WINDOWS\system32\36.tmp
C:\WINDOWS\system32\37.tmp
C:\WINDOWS\system32\38.tmp
C:\WINDOWS\system32\39.tmp
C:\WINDOWS\system32\3A.tmp
C:\WINDOWS\system32\3B.tmp
C:\WINDOWS\system32\3C.tmp
C:\WINDOWS\system32\3D.tmp
C:\WINDOWS\system32\3E.tmp
C:\WINDOWS\system32\3F.tmp
C:\WINDOWS\system32\4.tmp
C:\WINDOWS\system32\40.tmp
C:\WINDOWS\system32\41.tmp
C:\WINDOWS\system32\42.tmp
C:\WINDOWS\system32\43.tmp
C:\WINDOWS\system32\44.tmp
C:\WINDOWS\system32\45.tmp
C:\WINDOWS\system32\46.tmp
C:\WINDOWS\system32\47.tmp
C:\WINDOWS\system32\48.tmp
C:\WINDOWS\system32\49.tmp
C:\WINDOWS\system32\4A.tmp
C:\WINDOWS\system32\4B.tmp
C:\WINDOWS\system32\4C.tmp
C:\WINDOWS\system32\4D.tmp
C:\WINDOWS\system32\4E.tmp
C:\WINDOWS\system32\4F.tmp
C:\WINDOWS\system32\5.tmp
C:\WINDOWS\system32\50.tmp
C:\WINDOWS\system32\51.tmp
C:\WINDOWS\system32\52.tmp
C:\WINDOWS\system32\53.tmp
C:\WINDOWS\system32\55.tmp
C:\WINDOWS\system32\57.tmp
C:\WINDOWS\system32\58.tmp
C:\WINDOWS\system32\58c.dll
C:\WINDOWS\system32\598619786.dat
C:\WINDOWS\system32\5F.tmp
C:\WINDOWS\system32\60.tmp
C:\WINDOWS\system32\61.tmp
C:\WINDOWS\system32\66.tmp
C:\WINDOWS\system32\67.tmp
C:\WINDOWS\system32\68.tmp
C:\WINDOWS\system32\69.tmp
C:\WINDOWS\system32\6A.tmp
C:\WINDOWS\system32\7B.tmp
C:\WINDOWS\system32\7C.tmp
C:\WINDOWS\system32\7D.tmp
C:\WINDOWS\system32\7E.tmp
C:\WINDOWS\system32\7F.tmp
C:\WINDOWS\system32\8.tmp
C:\WINDOWS\system32\9.tmp
C:\WINDOWS\system32\AF.tmp
C:\WINDOWS\system32\B.tmp
C:\WINDOWS\system32\B0.tmp
C:\WINDOWS\system32\B1.tmp
C:\WINDOWS\system32\B2.tmp
C:\WINDOWS\system32\B3.tmp
C:\WINDOWS\system32\C3.tmp
C:\WINDOWS\system32\C4.tmp
C:\WINDOWS\system32\C5.tmp
C:\WINDOWS\system32\C6.tmp
C:\WINDOWS\system32\C7.tmp
C:\WINDOWS\system32\C8.tmp
C:\WINDOWS\system32\D.tmp
C:\WINDOWS\system32\drivers\ati1ttxxx.sys
C:\WINDOWS\system32\drivers\cjvwgp.sys
C:\WINDOWS\system32\drivers\NUWNNTWO.sys
C:\WINDOWS\system32\drivers\uhktyh.sys
C:\WINDOWS\system32\drivers\xlrp.sys
C:\WINDOWS\system32\dswiuwsf.tmp
C:\WINDOWS\system32\FPapli.exe
C:\WINDOWS\system32\Jamster.ico
C:\WINDOWS\system32\netrp.sys
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\system32\ZoneAlarmIconUS.ico
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\VundoFix Backups
C:\WINDOWS\DUMP82eb.tmp
C:\WINDOWS\DUMP9078.tmp
C:\WINDOWS\DUMP9c6e.tmp
C:\WINDOWS\system32\10.tmp
C:\WINDOWS\system32\11.tmp
C:\WINDOWS\system32\12.tmp
C:\WINDOWS\system32\13.tmp
C:\WINDOWS\system32\14.tmp
C:\WINDOWS\system32\15.tmp
C:\WINDOWS\system32\16.tmp
C:\WINDOWS\system32\17.tmp
C:\WINDOWS\system32\18.tmp
C:\WINDOWS\system32\19.tmp
C:\WINDOWS\system32\1A.tmp
C:\WINDOWS\system32\1B.tmp
C:\WINDOWS\system32\1C.tmp
C:\WINDOWS\system32\1D.tmp
C:\WINDOWS\system32\1Dr.dll
C:\WINDOWS\system32\1E.tmp
C:\WINDOWS\system32\1F.tmp
C:\WINDOWS\system32\2.tmp
C:\WINDOWS\system32\20.tmp
C:\WINDOWS\system32\21.tmp
C:\WINDOWS\system32\22.tmp
C:\WINDOWS\system32\23.tmp
C:\WINDOWS\system32\24.tmp
C:\WINDOWS\system32\25.tmp
C:\WINDOWS\system32\26.tmp
C:\WINDOWS\system32\27.tmp
C:\WINDOWS\system32\28.tmp
C:\WINDOWS\system32\29.tmp
C:\WINDOWS\system32\2A.tmp
C:\WINDOWS\system32\2B.tmp
C:\WINDOWS\system32\2C.tmp
C:\WINDOWS\system32\2D.tmp
C:\WINDOWS\system32\2E.tmp
C:\WINDOWS\system32\2F.tmp
C:\WINDOWS\system32\30.tmp
C:\WINDOWS\system32\31.tmp
C:\WINDOWS\system32\32.tmp
C:\WINDOWS\system32\33.tmp
C:\WINDOWS\system32\34.tmp
C:\WINDOWS\system32\35.tmp
C:\WINDOWS\system32\36.tmp
C:\WINDOWS\system32\37.tmp
C:\WINDOWS\system32\38.tmp
C:\WINDOWS\system32\39.tmp
C:\WINDOWS\system32\3A.tmp
C:\WINDOWS\system32\3B.tmp
C:\WINDOWS\system32\3C.tmp
C:\WINDOWS\system32\3D.tmp
C:\WINDOWS\system32\3E.tmp
C:\WINDOWS\system32\3F.tmp
C:\WINDOWS\system32\4.tmp
C:\WINDOWS\system32\40.tmp
C:\WINDOWS\system32\41.tmp
C:\WINDOWS\system32\42.tmp
C:\WINDOWS\system32\43.tmp
C:\WINDOWS\system32\44.tmp
C:\WINDOWS\system32\45.tmp
C:\WINDOWS\system32\46.tmp
C:\WINDOWS\system32\47.tmp
C:\WINDOWS\system32\48.tmp
C:\WINDOWS\system32\49.tmp
C:\WINDOWS\system32\4A.tmp
C:\WINDOWS\system32\4B.tmp
C:\WINDOWS\system32\4C.tmp
C:\WINDOWS\system32\4D.tmp
C:\WINDOWS\system32\4E.tmp
C:\WINDOWS\system32\4F.tmp
C:\WINDOWS\system32\5.tmp
C:\WINDOWS\system32\50.tmp
C:\WINDOWS\system32\51.tmp
C:\WINDOWS\system32\52.tmp
C:\WINDOWS\system32\53.tmp
C:\WINDOWS\system32\55.tmp
C:\WINDOWS\system32\57.tmp
C:\WINDOWS\system32\58.tmp
C:\WINDOWS\system32\58c.dll
C:\WINDOWS\system32\598619786.dat
C:\WINDOWS\system32\5F.tmp
C:\WINDOWS\system32\60.tmp
C:\WINDOWS\system32\61.tmp
C:\WINDOWS\system32\66.tmp
C:\WINDOWS\system32\67.tmp
C:\WINDOWS\system32\68.tmp
C:\WINDOWS\system32\69.tmp
C:\WINDOWS\system32\6A.tmp
C:\WINDOWS\system32\7B.tmp
C:\WINDOWS\system32\7C.tmp
C:\WINDOWS\system32\7D.tmp
C:\WINDOWS\system32\7E.tmp
C:\WINDOWS\system32\7F.tmp
C:\WINDOWS\system32\8.tmp
C:\WINDOWS\system32\9.tmp
C:\WINDOWS\system32\AF.tmp
C:\WINDOWS\system32\B.tmp
C:\WINDOWS\system32\B0.tmp
C:\WINDOWS\system32\B1.tmp
C:\WINDOWS\system32\B2.tmp
C:\WINDOWS\system32\B3.tmp
C:\WINDOWS\system32\C3.tmp
C:\WINDOWS\system32\C4.tmp
C:\WINDOWS\system32\C5.tmp
C:\WINDOWS\system32\C6.tmp
C:\WINDOWS\system32\C7.tmp
C:\WINDOWS\system32\C8.tmp
C:\WINDOWS\system32\D.tmp
C:\WINDOWS\system32\drivers\ati1ttxxx.sys
C:\WINDOWS\system32\dswiuwsf.tmp
C:\WINDOWS\system32\FPapli.exe
C:\WINDOWS\system32\inf
C:\WINDOWS\system32\Jamster.ico
C:\WINDOWS\system32\netrp.sys
C:\WINDOWS\system32\np5
C:\WINDOWS\system32\np5\sfeth112.exe
C:\WINDOWS\system32\p
C:\WINDOWS\system32\p\xerd2140.exe
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\system32\ZoneAlarmIconUS.ico
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ATI1TTXXX
-------\Legacy_NUWNNTWO
-------\Service_ati1ttxxx
-------\Service_fvac
-------\Service_hwqud
-------\Service_NUWNNTWO
-------\Service_xeljap
((((((((((((((((((((((((( Files Created from 2008-09-05 to 2008-10-05 )))))))))))))))))))))))))))))))
.
2008-09-26 21:29 . 2008-09-26 21:30 186,368 --a------ C:\WINDOWS\system32\65.tmp
2008-09-26 21:29 . 2008-09-26 21:29 186,368 --a------ C:\WINDOWS\system32\5B.tmp
2008-09-26 21:29 . 2008-09-26 21:29 78,848 --a------ C:\WINDOWS\system32\64.tmp
2008-09-26 21:29 . 2008-09-26 21:29 78,848 --a------ C:\WINDOWS\system32\5A.tmp
2008-09-26 21:29 . 2008-09-26 21:29 41,984 --a------ C:\WINDOWS\system32\62.tmp
2008-09-26 21:29 . 2008-09-26 21:29 41,984 --a------ C:\WINDOWS\system32\56.tmp
2008-09-26 21:29 . 2008-09-26 21:29 37,032 --a------ C:\WINDOWS\system32\63.tmp
2008-09-26 21:29 . 2008-09-26 21:29 37,032 --a------ C:\WINDOWS\system32\59.tmp
2008-09-26 21:29 . 2008-09-26 21:29 176 --a------ C:\WINDOWS\system32\5E.tmp
2008-09-26 21:29 . 2008-09-26 21:29 176 --a------ C:\WINDOWS\system32\54.tmp
2008-09-26 21:29 . 2008-09-26 21:29 18 --a------ C:\WINDOWS\system32\5C.tmp
2008-09-26 10:38 . 2008-09-26 10:38 <DIR> d-------- C:\WINDOWS\Sun
2008-09-26 10:28 . 2008-09-26 10:28 <DIR> d-------- C:\Program Files\Sun
2008-09-26 10:28 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-26 10:27 . 2008-09-26 10:27 <DIR> d-------- C:\Program Files\Common Files\Java
2008-09-20 03:40 . 2008-09-20 03:41 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-20 03:40 . 2008-09-20 03:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-20 03:40 . 2008-09-20 03:40 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-09-20 03:40 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-20 03:40 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-19 21:45 . 2008-09-20 11:30 <DIR> d-------- C:\WINDOWS\system32\ES
2008-09-19 21:45 . 2008-09-19 21:45 <DIR> d-------- C:\Temp\mtc2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-26 14:28 --------- d-----w C:\Program Files\Java
2008-09-25 22:09 --------- d-----w C:\Program Files\TalkPCR
2008-09-20 07:20 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-29 12:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-14 23:33 --------- d-----w C:\Program Files\LandAirSea Systems
2008-07-06 15:10 348,160 ----a-w C:\WINDOWS\MSVCR71.DLL
2008-07-06 15:10 1,060,864 ----a-w C:\WINDOWS\MFC71.DLL
2008-07-06 15:09 40,960 ----a-w C:\WINDOWS\SimTestDll.dll
.
------- Sigcheck -------
2005-03-13 21:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2006-04-20 08:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 12:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 06:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 07:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 07:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 06:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 17:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
2005-03-13 20:55 359808 0e66b538096a6529d1ac66e78eb0d5c8 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 07:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 15:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2007-10-30 13:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 15:20 361344 accf5a9a1ffaa490f33dba1c632b95e1 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2008-06-20 07:51 361600 9425b72f40257b45d45d24773273dad0 C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 07:51 361600 9425b72f40257b45d45d24773273dad0 C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 20:12 1041408 b0d52f609df94a72b4af3edf477c7c2e C:\WINDOWS\explorer.exe
2007-06-13 07:26 1040896 4580e16e92bb88da525a51e1b03b42e2 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 06:23 1040896 3225f4663de4cb04858403af116aef98 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 17:00 1039872 8fe830fbff9363952ed533a4022f5291 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2008-04-13 20:12 1041408 c074c20ff2cd9560706244ff3aad5724 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2004-08-04 17:00 23040 8cbacd9f0d3d6942fe10d134ed7ed764 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 20:12 23040 1f00a2901ffc1ba48321c06b5f2195f9 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-13 20:12 23040 d6cdc4fa4980a746a548be5d456ae7e4 C:\WINDOWS\system32\ctfmon.exe
2005-06-10 20:17 65536 ce3605a5b02be13080ad6fc62b00327a C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 19:53 65536 292419cc59317cc6ced2666a9ffcdde3 C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 17:00 65536 53832404a4ae49aea8ad515644b979bc C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2008-04-13 20:12 65536 30721bc166cf511848d7340e167170f3 C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-13 20:12 65536 c09cccb28b2a6307ef7e76e9c97b0e78 C:\WINDOWS\system32\spoolsv.exe
2004-08-04 17:00 32256 37bcdc79f48a0c7a83b48f31d6423247 C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2008-04-13 20:12 33792 cdb8fe37d770759da584fa4a3c585666 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2008-04-13 20:12 33792 0d931ad3b3aa2bae592d3ed2d6392aea C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRunOnce"="C:\util\prunonce\PRunOnce.exe" [2004-08-06 118784]
"Panasonic HotKey Manager"="C:\Program Files\Panasonic\HotKey Appendix\HKEYAPP.EXE" [2005-06-13 983040]
"PCinfo"="C:\Program Files\Panasonic\PCINFO\SetDiag.exe" [2005-06-14 53248]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 393216]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 163840]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-20 C:\WINDOWS\AGRSMMSG.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WLAN network adaptor Wireless LAN Configuration.lnk - C:\WINDOWS\system32\wlansta.exe [2006-05-10 155719]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 14:27 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.NTN1"= nuvision.ax
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Panasonic Hand Writing.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Panasonic Hand Writing.lnk
backup=C:\WINDOWS\pss\Panasonic Hand Writing.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-13 20:12 1702912 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--------- 2006-05-20 11:49 290816 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2007-06-13 09:16 536576 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--------- 2002-04-26 13:53 19968 C:\Program Files\Winamp\winampa.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\FreeFTP\\FreeFTP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R0 GPSFilter;Panasonic GPS Filter Service;C:\WINDOWS\system32\DRIVERS\gpsfilter.sys [2005-09-26 10112]
R2 brecal;Panasonic Battery Recalibration Driver;C:\Program Files\Panasonic\BRECAL\Brecal.sys [2004-11-15 7168]
R2 pcinfo;Panasonic PC Info. Viewer Driver;C:\Program Files\Panasonic\PCINFO\pcinfo.sys [2004-11-04 7168]
R2 SDKEY;Panasonic SD Misc. Function Driver;C:\Program Files\Panasonic\SDKEY\SDKEY.SYS [2005-04-21 8192]
R3 FIDMOU;Fujitsu touchpad;C:\WINDOWS\system32\DRIVERS\Fidmou.sys [2005-04-18 23463]
R3 HOTKEY;Panasonic Hotkey Driver;C:\WINDOWS\system32\DRIVERS\HOTKEY.SYS [2003-03-17 9216]
R3 vidcap;vidcap;C:\WINDOWS\system32\DRIVERS\vidcap.sys [2006-12-27 9006]
S2 USBHSB;GeneLink File Transfer Driver;C:\WINDOWS\system32\Drivers\usbhsb.sys [2001-12-17 18690]
S2 VRDVC20;Sony VRD-VC20 [Video Capture];C:\WINDOWS\system32\Drivers\VRDVC20X.SYS [2004-11-09 04:02 31104]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\NSNDIS5.SYS [2004-03-23 17280]
S3 NuVision;Hauppauge WinTV USB Pro (NTSC);C:\WINDOWS\system32\DRIVERS\NUVision.sys [2005-07-08 260144]
S3 s125bus;Sony Ericsson Device 125 driver (WDM);C:\WINDOWS\system32\DRIVERS\s125bus.sys [2007-04-24 83336]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s125mdfl.sys [2007-04-24 15112]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s125mdm.sys [2007-04-24 108680]
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s125mgmt.sys [2007-04-24 100488]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s125obex.sys [2007-04-24 98696]
S3 WLAN;IEEE 802.11b WLAN network adaptor Driver;C:\WINDOWS\system32\DRIVERS\WLANNDS.sys [2003-10-17 651776]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-05 12:32:26
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-10-05 12:37:08 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2008-10-05 16:37:02
ComboFix2.txt 2008-10-05 15:13:26
ComboFix3.txt 2008-10-05 01:31:15
ComboFix4.txt 2008-09-22 00:53:25
ComboFix5.txt 2008-10-05 16:26:22
Pre-Run: 30,733,098,496 bytes free
Post-Run: 30,684,529,664 bytes free
417 --- E O F --- 2008-09-11 03:34:02