ComboFix 08-06-06.4 - Phill 2008-06-07 0:16:14.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1835 [GMT 1:00]
Running from: C:\Documents and Settings\Phill\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Phill\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\urqRIcbA.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMe7b08195.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\AbcIRqru.ini
C:\WINDOWS\system32\AbcIRqru.ini2
C:\WINDOWS\system32\bodlcyah.dll
C:\WINDOWS\system32\fxflovxt.ini
C:\WINDOWS\system32\kfrmrctk.dll
C:\WINDOWS\system32\txvolfxf.dll
C:\WINDOWS\system32\urqRIcbA.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-06 to 2008-06-06 )))))))))))))))))))))))))))))))
.
2008-06-05 15:46 . 2008-06-05 15:46 <DIR> d-------- C:\WINDOWS\Sun
2008-06-05 15:46 . 2008-06-05 15:46 <DIR> d-------- C:\Program Files\Java
2008-06-05 15:46 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-05 15:45 . 2008-06-05 15:45 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-05 15:38 . 2008-06-05 15:39 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-06-05 15:38 . 2005-04-15 19:58 1,071,088 --a------ C:\WINDOWS\system32\MSCOMCTL.OCX
2008-06-05 15:38 . 2005-08-25 18:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2008-06-05 15:38 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-06-05 13:18 . 2008-06-05 13:18 <DIR> d-------- C:\Documents and Settings\Administrator
2008-06-04 18:28 . 2008-06-04 18:28 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-06-04 18:28 . 2008-06-04 18:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-04 18:15 . 2008-06-04 18:15 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-04 02:36 . 2008-06-05 14:00 326 --a------ C:\WINDOWS\wininit.ini
2008-06-04 01:25 . 2008-06-04 01:25 <DIR> d-------- C:\Documents and Settings\Phill\Application Data\Nokia Multimedia Player
2008-06-04 01:07 . 2008-06-04 01:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nokia
2008-06-04 00:54 . 2008-04-13 19:45 26,112 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-06-04 00:54 . 2008-04-13 19:45 26,112 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-06-04 00:49 . 2008-06-04 00:49 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-04 00:49 . 2008-06-04 00:49 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-06-04 00:47 . 2008-06-04 00:56 <DIR> d-------- C:\Documents and Settings\Phill\Application Data\PC Suite
2008-06-04 00:47 . 2008-06-04 00:54 <DIR> d-------- C:\Documents and Settings\Phill\Application Data\Nokia
2008-06-04 00:47 . 2008-06-04 00:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Suite
2008-06-04 00:46 . 2008-06-04 00:46 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-06-04 00:46 . 2008-06-04 01:07 <DIR> d-------- C:\Program Files\Nokia
2008-06-04 00:46 . 2008-06-04 00:46 <DIR> d-------- C:\Program Files\DIFX
2008-06-04 00:46 . 2008-06-04 00:46 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-06-04 00:46 . 2008-06-04 01:05 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-06-04 00:46 . 2007-11-29 10:33 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-06-04 00:46 . 2007-11-29 10:39 95,744 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-06-04 00:46 . 2008-02-01 15:17 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2008-06-04 00:46 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-06-04 00:46 . 2007-11-29 10:39 19,328 --a------ C:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-06-04 00:46 . 2007-11-29 10:39 16,896 --a------ C:\WINDOWS\system32\drivers\ccdcmb.sys
2008-06-04 00:46 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
2008-06-04 00:46 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-06-04 00:45 . 2008-06-04 01:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Installations
2008-06-01 01:32 . 2008-06-01 01:32 <DIR> d-------- C:\Program Files\Kontiki
2008-06-01 01:32 . 2008-06-01 01:32 <DIR> d-------- C:\logs3
2008-06-01 01:32 . 2008-06-07 00:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kontiki
2008-05-31 02:04 . 2008-05-31 02:06 <DIR> d-------- C:\Temp
2008-05-30 20:20 . 2008-05-30 20:20 <DIR> d-------- C:\Documents and Settings\Phill\Application Data\dvdcss
2008-05-29 23:14 . 2008-05-29 23:14 <DIR> d-------- C:\Documents and Settings\Phill\Application Data\HiYo
2008-05-23 20:30 . 2008-05-23 20:30 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-05-23 20:30 . 2008-05-23 20:30 <DIR> d-------- C:\WINDOWS\system32\en
2008-05-23 20:30 . 2008-05-23 20:30 <DIR> d-------- C:\WINDOWS\l2schemas
2008-05-23 19:05 . 2008-04-14 01:11 233,472 --a------ C:\WINDOWS\system32\azroles.dll
2008-05-23 19:05 . 2008-04-14 01:11 12,800 --a------ C:\WINDOWS\system32\credssp.dll
2008-05-23 19:05 . 2008-04-14 01:11 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll
2008-05-21 16:32 . 2008-05-21 16:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-05-21 16:31 . 2008-05-21 16:31 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-05-21 16:31 . 2008-05-21 16:33 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-05-16 05:05 . 2008-05-16 05:04 691,545 --a------ C:\WINDOWS\unins000.exe
2008-05-16 05:05 . 2008-05-16 05:05 2,539 --a------ C:\WINDOWS\unins000.dat
2008-05-16 04:47 . 2008-05-16 04:47 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-16 04:47 . 2008-05-16 04:47 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-16 04:47 . 2008-05-16 04:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-16 03:21 . 2008-05-17 02:25 120 --a------ C:\drmHeader.bin
2008-05-16 01:45 . 2008-05-16 01:48 <DIR> d-------- C:\Program Files\Thoosje Sidebar V2.3
2008-05-16 01:38 . 2008-05-16 01:38 <DIR> d-------- C:\Program Files\CCleaner
2008-05-13 22:45 . 2008-05-13 22:45 1,024 --a------ C:\.rnd
2008-05-13 22:44 . 2008-06-01 01:32 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-05-13 22:44 . 2004-12-16 16:34 405,504 --a------ C:\WINDOWS\system32\CapabilityTable.exe
2008-05-13 22:44 . 2004-12-16 16:32 176,128 --a------ C:\WINDOWS\system32\nvuide.exe
2008-05-13 22:44 . 2004-12-01 02:30 3,507 --a------ C:\WINDOWS\system32\nvide.nvu
2008-05-13 22:43 . 2005-02-14 16:39 176,128 --a------ C:\WINDOWS\system32\nvusmb.exe
2008-05-13 22:43 . 2005-02-14 16:39 176,128 --a------ C:\WINDOWS\system32\nvunrm.exe
2008-05-13 22:43 . 2005-02-08 13:26 3,596 --a------ C:\WINDOWS\system32\nvnrm.nvu
2008-05-13 22:43 . 2004-11-10 10:35 1,231 --a------ C:\WINDOWS\system32\nvsmb.nvu
2008-05-13 22:41 . 2006-08-01 15:02 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-05-13 22:41 . 2004-07-01 15:02 584 --a------ C:\WINDOWS\system32\drivers\alcxinit.dat
2008-05-13 22:40 . 2008-05-13 22:40 <DIR> d-------- C:\Program Files\Realtek Sound Manager
2008-05-13 22:40 . 2008-05-13 22:40 <DIR> d-------- C:\Program Files\Realtek AC97
2008-05-13 22:40 . 2008-05-13 22:40 <DIR> d-------- C:\Program Files\AvRack
2008-05-13 22:40 . 2006-11-17 05:40 18,804,736 --a------ C:\WINDOWS\system32\alsndmgr.cpl
2008-05-13 22:40 . 2006-08-10 07:27 10,528,768 --a------ C:\WINDOWS\system32\RTLCPL.exe
2008-05-13 22:40 . 2006-11-23 17:11 4,025,088 --a------ C:\WINDOWS\system32\drivers\alcxwdm.sys
2008-05-13 22:40 . 2006-11-17 05:42 577,536 --a------ C:\WINDOWS\soundman.exe
2008-05-13 22:40 . 2006-07-31 11:19 315,392 --a------ C:\WINDOWS\alcupd.exe
2008-05-13 22:40 . 2006-07-31 11:27 217,088 --a------ C:\WINDOWS\Alcrmv.exe
2008-05-13 22:40 . 2006-10-18 02:53 147,456 --a------ C:\WINDOWS\system32\RtlCPAPI.dll
2008-05-13 22:40 . 2002-02-05 13:54 141,016 --a------ C:\WINDOWS\system32\alsndmgr.wav
2008-05-13 22:40 . 2001-07-06 00:19 164 --a------ C:\WINDOWS\avrack.ini
2008-05-11 01:12 . 2008-05-17 22:11 <DIR> d-------- C:\Program Files\Google
2008-05-10 23:02 . 2008-05-10 23:02 <DIR> d-------- C:\Documents and Settings\Phill\Application Data\TVU Networks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-06 22:20 --------- d-----w C:\Documents and Settings\Phill\Application Data\SiteAdvisor
2008-06-06 16:29 --------- d-----w C:\Documents and Settings\Phill\Application Data\uTorrent
2008-06-03 23:43 --------- d-----w C:\Documents and Settings\Phill\Application Data\Orbit
2008-06-03 02:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-22 21:12 --------- d-----w C:\Program Files\SiteAdvisor
2008-05-19 22:04 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-16 21:29 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-13 21:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-12 05:01 --------- d-----w C:\Program Files\SecondLife
2008-05-04 09:56 --------- d-----w C:\Program Files\ffdshow
2008-04-30 02:48 --------- d-----w C:\Program Files\Common Files\Vbox
2008-04-30 02:47 --------- d-----w C:\Program Files\Macromedia
2008-04-30 02:47 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-30 02:38 --------- d-----w C:\Documents and Settings\Phill\Application Data\vlc
2008-04-30 02:33 --------- d-----w C:\Program Files\VideoLAN
2008-04-30 02:29 --------- d-----w C:\Program Files\Real Alternative
2008-04-30 02:26 --------- d-----w C:\Documents and Settings\Phill\Application Data\Media Player Classic
2008-04-29 23:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-04-29 11:21 --------- d-----w C:\Program Files\Orbitdownloader
2008-04-29 10:34 --------- d-----w C:\Documents and Settings\Phill\Application Data\DivX
2008-04-29 10:18 --------- d-----w C:\Program Files\DivX
2008-04-29 04:20 --------- d-----w C:\Program Files\AviSynth 2.5
2008-04-29 01:25 --------- d-----w C:\Program Files\HyCam2
2008-04-29 01:18 --------- d-----w C:\Program Files\MSXML 6.0
2008-04-29 00:53 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-29 00:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-04-29 00:50 --------- d-----w C:\Program Files\MSBuild
2008-04-29 00:49 --------- d-----w C:\Program Files\McAfee
2008-04-29 00:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-04-29 00:47 --------- d-----w C:\Program Files\Common Files\McAfee
2008-04-29 00:46 --------- d-----w C:\Program Files\Reference Assemblies
2008-04-29 00:46 --------- d-----w C:\Program Files\McAfee.com
2008-04-29 00:37 --------- d-----w C:\Program Files\Windows Live
2008-04-29 00:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-29 00:34 --------- d-----w C:\Program Files\iTunes
2008-04-29 00:34 --------- d-----w C:\Documents and Settings\Phill\Application Data\Apple Computer
2008-04-29 00:33 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-29 00:33 --------- d-----w C:\Program Files\QuickTime
2008-04-29 00:33 --------- d-----w C:\Program Files\iPod
2008-04-29 00:33 --------- d-----w C:\Program Files\Bonjour
2008-04-29 00:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-29 00:32 --------- d-----w C:\Program Files\Common Files\Apple
2008-04-29 00:32 --------- d-----w C:\Program Files\Apple Software Update
2008-04-29 00:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-04-28 23:40 --------- d-----w C:\Documents and Settings\Phill\Application Data\SmartFTP
2008-04-28 23:39 --------- d-----w C:\Program Files\SmartFTP Client 3.0 Setup Files
2008-04-28 23:39 --------- d-----w C:\Program Files\SmartFTP Client
2008-04-28 23:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-28 23:34 --------- d--h--r C:\Documents and Settings\Phill\Application Data\yahoo!
2008-04-28 23:34 --------- d-----w C:\Program Files\Yahoo!
2008-04-28 23:24 --------- d-----w C:\Program Files\TVUPlayer
2008-04-28 23:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-04-28 22:34 --------- d-----w C:\Program Files\Creative
2008-04-28 22:31 --------- d-----w C:\Documents and Settings\Phill\Application Data\SecondLife
2008-04-28 22:26 --------- d-----w C:\Program Files\DVD-lab_PRO_2.23
2008-04-28 22:20 --------- d-----w C:\Program Files\Diskeeper Corporation
2008-04-28 22:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation
2008-04-28 22:18 --------- d-----w C:\Program Files\MKVtoolnix
2008-04-28 22:08 --------- d-----w C:\Documents and Settings\Phill\Application Data\Megaupload
2008-04-28 22:07 --------- d-----w C:\Program Files\Megaupload
2008-04-28 22:07 --------- d-----w C:\Documents and Settings\Phill\Application Data\InstallShield
2008-04-28 22:06 --------- d-----w C:\Program Files\uTorrent
2008-04-28 22:04 --------- d-----w C:\Program Files\Magic Music Editor
2008-04-28 22:02 --------- d-----w C:\Program Files\Movie Joiner
2008-04-28 21:40 --------- d-----w C:\Program Files\Pegasys Inc
2008-04-28 21:30 --------- d-----w C:\Program Files\Common Files\Ahead
2008-04-28 21:30 --------- d-----w C:\Documents and Settings\Phill\Application Data\Ahead
2008-04-28 21:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-04-28 21:29 --------- d-----w C:\Program Files\Nero
2008-04-28 21:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-04-28 21:20 --------- d-----w C:\Program Files\Replay Media Catcher
2008-04-28 21:17 --------- d-----w C:\Program Files\Gabest
2008-04-28 21:16 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-04-28 20:57 20,747 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-04-28 20:57 --------- d-----w C:\Program Files\Sitecom
2008-04-28 20:13 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-28 20:12 558,142 ----a-w C:\WINDOWS\java\Packages\OVHNBNFH.ZIP
2008-04-28 20:12 155,995 ----a-w C:\WINDOWS\java\Packages\RN7BJBLB.ZIP
2008-04-14 00:13 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 00:13 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 00:13 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 00:13 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 00:11 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
2008-04-13 19:28 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 19:21 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 19:20 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 19:20 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 19:20 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 19:19 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 19:19 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 19:19 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 19:19 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 19:19 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 19:18 52,480 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 19:17 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 19:17 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 19:17 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 19:16 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 19:16 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 19:15 64,512 ----a-w C:\WINDOWS\system32\drivers\serial.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-06_23.09.30.71 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-06 21:59:08 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-06 23:18:33 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2007-07-30 18:19:36 549,720 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
- 2008-04-14 00:12:41 111,104 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
+ 2007-07-30 18:19:16 53,080 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
- 2008-04-14 00:12:11 1,135,616 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
+ 2007-07-30 18:19:42 1,712,984 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
- 2008-04-14 00:12:11 112,640 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
+ 2007-07-30 18:19:32 325,976 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
- 2008-04-14 00:12:11 32,256 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
+ 2007-07-30 18:18:40 33,624 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
+ 2007-07-30 18:19:28 203,096 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
+ 2007-07-30 18:18:40 33,624 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.381\wups.dll
- 2008-04-14 00:12:10 430,592 ----a-w C:\WINDOWS\system32\wuapi.dll
+ 2007-07-30 18:19:36 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
- 2008-04-14 00:12:41 111,104 ----a-w C:\WINDOWS\system32\wuauclt.exe
+ 2007-07-30 18:19:16 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
- 2008-04-14 00:12:11 1,135,616 ----a-w C:\WINDOWS\system32\wuaueng.dll
+ 2007-07-30 18:19:42 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
- 2008-04-14 00:12:11 112,640 ----a-w C:\WINDOWS\system32\wucltui.dll
+ 2007-07-30 18:19:32 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
- 2008-04-14 00:12:11 32,256 ----a-w C:\WINDOWS\system32\wups.dll
+ 2007-07-30 18:18:40 33,624 ----a-w C:\WINDOWS\system32\wups.dll
- 2008-04-14 00:12:11 120,320 ----a-w C:\WINDOWS\system32\wuweb.dll
+ 2007-07-30 18:19:28 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
+ 2008-06-06 23:18:47 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_6d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{adbbc51a-124e-4a85-b181-3961e0aeed1a}]
C:\WINDOWS\system32\kfrmrctk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EA2E0B78-7413-4EBF-8E14-8AFE8209ED07}]
C:\WINDOWS\system32\urqRIcbA.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 01:12 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 19:03 152872]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 18:41 1232896]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 12:53 1079808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 06:31 208952]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2002-08-29 13:00 455168]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2002-08-29 13:00 455168]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2007-10-04 17:14 8491008]
"nwiz"="nwiz.exe" [2007-10-04 17:14 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2007-10-04 17:14 81920]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"P17Helper"="P17.dll" [2005-05-03 19:38 64512 C:\WINDOWS\system32\P17.dll]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2007-08-24 22:57 36640]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 05:42 577536 C:\WINDOWS\soundman.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"BMe7b08195"="C:\WINDOWS\system32\bodlcyah.dll" [ ]
"e483b209"="C:\WINDOWS\system32\txvolfxf.dll" [ ]
"combofix"="C:\WINDOWS\system32\CF3855.exe" [2008-04-14 01:12 389120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 01:12 15360]
C:\Documents and Settings\Phill\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [3/16/2005 7:16:50 PM 113664]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Sitecom Wireless Utility.lnk - C:\Program Files\Sitecom\Sitecom WL-151 Wireless LAN Card\Installer\WLANUTL.exe [4/28/2008 9:57:15 PM 909312]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"46884:TCP"= 46884:TCP:uTorrent
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;C:\WINDOWS\system32\DRIVERS\nvcchflt.sys [2005-02-11 18:11]
S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53]
S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39]
S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-19 07:54:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-29 00:46:49 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-06-01 00:00:06 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-07 00:23:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Kontiki\KService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
.
**************************************************************************
.
Completion time: 2008-06-07 0:32:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-06 23:32:08
ComboFix2.txt 2008-06-06 22:10:55
Pre-Run: 85,118,140,416 bytes free
Post-Run: 85,161,934,848 bytes free
364 --- E O F --- 2008-05-19 22:04:58
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, June 07, 2008 2:56:19 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 3 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 7/06/2008
Kaspersky Anti-Virus database records: 835736
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 90000
Number of viruses found: 4
Number of infected objects: 21
Number of suspicious objects: 0
Duration of the scan process: 01:23:47
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Kontiki\error.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{1232F79B-B44B-4A59-8374-C544B00C5295}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{223B1B2F-C0C0-425F-A7E4-4FE1EAD789A4}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{B70AC1FD-9374-4C48-AEC9-00978916236F}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\MSKWMDB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\settingsdb.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR3.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Quarantine\7d867117182320.bup Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Phill\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Ahead\Nero Home\is2.db Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Microsoft\Messenger\dekared2004@hotmail.com\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Microsoft\Messenger\dekared2004@hotmail.com\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Microsoft\Messenger\dekared2004@hotmail.com\SharingMetadata\Working\database_3CE4_83F8_E483_B2A6\dfsr.db Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Microsoft\Messenger\dekared2004@hotmail.com\SharingMetadata\Working\database_3CE4_83F8_E483_B2A6\fsr.log Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Microsoft\Messenger\dekared2004@hotmail.com\SharingMetadata\Working\database_3CE4_83F8_E483_B2A6\fsrtmp.log Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Microsoft\Messenger\dekared2004@hotmail.com\SharingMetadata\Working\database_3CE4_83F8_E483_B2A6\tmp.edb Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Microsoft\Windows Live Contacts\dekared2004@hotmail.com\real\members.stg Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Application Data\Microsoft\Windows Live Contacts\dekared2004@hotmail.com\shadow\members.stg Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\History\History.IE5\MSHist012008060720080608\index.dat Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Temp\Perflib_Perfdata_298.dat Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Temp\~DF5171.tmp Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Temp\~DF517F.tmp Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Temp\~DF6F5B.tmp Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Temp\~DF6F7B.tmp Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Temp\~DF7FAF.tmp Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Temp\~DF7FC0.tmp Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Temp\~DFD30.tmp Object is locked skipped
C:\Documents and Settings\Phill\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Phill\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Phill\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Phill\UserData\index.dat Object is locked skipped
C:\Media\downloads\Big.Brother.UK.S09.D002b.Daily.XviD.PDTV.[ramp].avi Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\billing_Phill.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\client_Phill.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\network_Phill.log Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\flrvgesb.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\fraxxsil.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\kgioxcpt.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\nibcwgqr.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\nnnliffD.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ohmegeke.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\uqafaojq.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\urqRIcbA.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ybe skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\vckmygvq.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.yba skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\wnuyuera.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{82AEDFBD-601F-4935-A452-F1EBC8AD43EF}\RP208\A0043230.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{82AEDFBD-601F-4935-A452-F1EBC8AD43EF}\RP210\A0043265.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{82AEDFBD-601F-4935-A452-F1EBC8AD43EF}\RP210\A0043266.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{82AEDFBD-601F-4935-A452-F1EBC8AD43EF}\RP210\A0043267.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{82AEDFBD-601F-4935-A452-F1EBC8AD43EF}\RP210\A0043268.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{82AEDFBD-601F-4935-A452-F1EBC8AD43EF}\RP210\A0043269.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped
C:\System Volume Information\_restore{82AEDFBD-601F-4935-A452-F1EBC8AD43EF}\RP210\A0043270.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{82AEDFBD-601F-4935-A452-F1EBC8AD43EF}\RP210\A0043271.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{82AEDFBD-601F-4935-A452-F1EBC8AD43EF}\RP210\A0043272.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yba skipped
C:\System Volume Information\_restore{82AEDFBD-601F-4935-A452-F1EBC8AD43EF}\RP210\A0043273.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{82AEDFBD-601F-4935-A452-F1EBC8AD43EF}\RP212\A0043352.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ybe skipped
C:\System Volume Information\_restore{82AEDFBD-601F-4935-A452-F1EBC8AD43EF}\RP213\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{A00E2C10-B5F2-4A54-A38C-623A7C6ECB61}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\mcafee_onbWvLyzoCB5azq Object is locked skipped
C:\WINDOWS\Temp\mcmsc_mHatZZMGujFFK8f Object is locked skipped
C:\WINDOWS\Temp\mcmsc_mmVgealKNMhOAhq Object is locked skipped
C:\WINDOWS\Temp\mcmsc_mVoIv7axH44gDfQ Object is locked skipped
C:\WINDOWS\Temp\mcmsc_Qclwso2sjrl3fP2 Object is locked skipped
C:\WINDOWS\Temp\mcmsc_VWAdmhZgrvIvXbK Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_6d0.dat Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_df8.dat Object is locked skipped
C:\WINDOWS\Temp\sqlite_DbZGnEJTuKusGuA Object is locked skipped
C:\WINDOWS\Temp\sqlite_DrzQhrnlIPknp7u Object is locked skipped
C:\WINDOWS\Temp\sqlite_WJh1GYt9ADdO42a Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:57:18, on 07/06/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Sitecom\Sitecom WL-151 Wireless LAN Card\Installer\WLANUTL.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Sitecom Wireless Utility.lnk = C:\Program Files\Sitecom\Sitecom WL-151 Wireless LAN Card\Installer\WLANUTL.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1209416905460
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1209431273906
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
--
End of file - 10512 bytes