Hi Blade,
here is the fresh RSIT log:
Logfile of random's system information tool 1.06 (written by random/random)
Run by paul at 2009-11-22 19:45:29
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 22 GB (29%) free of 78 GB
Total RAM: 255 MB (19% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:45:45 PM, on 11/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\TEMP\nnju.exe
C:\WINDOWS\TEMP\wphgta.exe
C:\WINDOWS\TEMP\winmbudpk.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\EDIMAX\Common\RaUI.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Documents and Settings\paul\Desktop\RSIT.exe
C:\Program Files\trend micro\paul.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Wireless Utility.lnk = C:\Program Files\EDIMAX\Common\RaUI.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - D:\Program Files\a-squared Free\a2service.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
--
End of file - 6680 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\RegCure Program Check.job
C:\WINDOWS\tasks\RegCure.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2009-07-31 909040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-11-21 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-11-21 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll [2009-07-31 159472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2009-07-31 909040]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"=C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe [2009-02-23 185584]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-09-05 491520]
"LogitechQuickCamRibbon"=C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2009-05-08 2854160]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 109424]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 1004920]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-10-28 215328]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-11-21 218912]
"WinPatrol"=C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [2009-10-11 320832]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Search Protection"=C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe [2009-02-23 185584]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1768960]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
C:\WINDOWS\FixCamera.exe [2007-07-11 20480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2std]
C:\WINDOWS\vsnp2std.exe [2007-05-10 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\Core\smax4pnp.exe [2004-10-14 1482752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnp2std]
C:\WINDOWS\tsnp2std.exe [2007-05-12 344064]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Wireless Utility.lnk - C:\Program Files\EDIMAX\Common\RaUI.exe
C:\Documents and Settings\paul\Start Menu\Programs\Startup
OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
"DisableRegistryTools"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\Program Files\Analog Devices\Core\smax4pnp.exe"="C:\Program Files\Analog Devices\Core\smax4pnp.exe:*:Enabled:ipsec"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Adobe\Adobe Bridge CS3\Bridge.exe"="C:\Program Files\Adobe\Adobe Bridge CS3\Bridge.exe:*:Enabled:Adobe Bridge CS3"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Logitech\Logitech Vid\Vid.exe"="C:\Program Files\Logitech\Logitech Vid\Vid.exe:*:Enabled:Logitech Vid"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:ipsec"
"C:\Program Files\QuickTime\QTTask.exe"="C:\Program Files\QuickTime\QTTask.exe:*:Enabled:ipsec"
"C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\dmremote.exe"="C:\WINDOWS\system32\dmremote.exe:*:Enabled:ipsec"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\wscntfy.exe"="C:\WINDOWS\system32\wscntfy.exe:*:Enabled:ipsec"
"C:\Documents and Settings\paul\Application Data\mjusbsp\cdloader2.exe"="C:\Documents and Settings\paul\Application Data\mjusbsp\cdloader2.exe:*:Enabled:ipsec"
"C:\Program Files\Java\jre6\bin\jusched.exe"="C:\Program Files\Java\jre6\bin\jusched.exe:*:Enabled:ipsec"
"C:\Documents and Settings\paul\Application Data\mjusbsp\magicJack.exe"="C:\Documents and Settings\paul\Application Data\mjusbsp\magicJack.exe:*:Enabled:magicJack"
"C:\Program Files\iTunes\iTunesHelper.exe"="C:\Program Files\iTunes\iTunesHelper.exe:*:Enabled:ipsec"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe"="C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe:*:Enabled:ipsec"
"C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe"="C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe:*:Enabled:ipsec"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"D:\Program Files\RegCure\RegCure.exe"="d:\Program Files\RegCure\RegCure.exe:*:Enabled:ipsec"
"C:\WINDOWS\PEV.exe"="C:\WINDOWS\PEV.exe:*:Enabled:ipsec"
"C:\Program Files\OpenOffice.org 3\program\soffice.bin"="C:\Program Files\OpenOffice.org 3\program\soffice.bin:*:Enabled:ipsec"
"C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe"="C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe:*:Enabled:ipsec"
"C:\Program Files\OpenOffice.org 3\program\soffice.exe"="C:\Program Files\OpenOffice.org 3\program\soffice.exe:*:Enabled:ipsec"
"C:\DOCUME~1\paul\LOCALS~1\Temp\hkre.exe"="C:\DOCUME~1\paul\LOCALS~1\Temp\hkre.exe:*:Enabled:ipsec"
"C:\DOCUME~1\paul\LOCALS~1\Temp\winkrxfpw.exe"="C:\DOCUME~1\paul\LOCALS~1\Temp\winkrxfpw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\paul\LOCALS~1\Temp\opou.exe"="C:\DOCUME~1\paul\LOCALS~1\Temp\opou.exe:*:Enabled:ipsec"
"C:\DOCUME~1\paul\LOCALS~1\Temp\ddoqjd.exe"="C:\DOCUME~1\paul\LOCALS~1\Temp\ddoqjd.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\eiak.exe"="C:\WINDOWS\TEMP\eiak.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winlfsy.exe"="C:\WINDOWS\TEMP\winlfsy.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\fmchb.exe"="C:\WINDOWS\TEMP\fmchb.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winhnqhba.exe"="C:\WINDOWS\TEMP\winhnqhba.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winvngq.exe"="C:\WINDOWS\TEMP\winvngq.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\gueh.exe"="C:\WINDOWS\TEMP\gueh.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winceoi.exe"="C:\WINDOWS\TEMP\winceoi.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winjkkjyv.exe"="C:\WINDOWS\TEMP\winjkkjyv.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winnxts.exe"="C:\WINDOWS\TEMP\winnxts.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winogabgl.exe"="C:\WINDOWS\TEMP\winogabgl.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winjisqt.exe"="C:\WINDOWS\TEMP\winjisqt.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wingpcvek.exe"="C:\WINDOWS\TEMP\wingpcvek.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\jxsv.exe"="C:\WINDOWS\TEMP\jxsv.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\vlwdck.exe"="C:\WINDOWS\TEMP\vlwdck.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winnrnvfa.exe"="C:\WINDOWS\TEMP\winnrnvfa.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\pwxc.exe"="C:\WINDOWS\TEMP\pwxc.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winjwpu.exe"="C:\WINDOWS\TEMP\winjwpu.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winamwlu.exe"="C:\WINDOWS\TEMP\winamwlu.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\oaww.exe"="C:\WINDOWS\TEMP\oaww.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winqgkcqt.exe"="C:\WINDOWS\TEMP\winqgkcqt.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winsoxfe.exe"="C:\WINDOWS\TEMP\winsoxfe.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winiuqpm.exe"="C:\WINDOWS\TEMP\winiuqpm.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\rvuc.exe"="C:\WINDOWS\TEMP\rvuc.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\xhiq.exe"="C:\WINDOWS\TEMP\xhiq.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\rcptfx.exe"="C:\WINDOWS\TEMP\rcptfx.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winfiyxj.exe"="C:\WINDOWS\TEMP\winfiyxj.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wineuti.exe"="C:\WINDOWS\TEMP\wineuti.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\jwaadd.exe"="C:\WINDOWS\TEMP\jwaadd.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\rifdk.exe"="C:\WINDOWS\TEMP\rifdk.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winfski.exe"="C:\WINDOWS\TEMP\winfski.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winjxdxux.exe"="C:\WINDOWS\TEMP\winjxdxux.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winfdxsv.exe"="C:\WINDOWS\TEMP\winfdxsv.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\fxxcvx.exe"="C:\WINDOWS\TEMP\fxxcvx.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winaqrkd.exe"="C:\WINDOWS\TEMP\winaqrkd.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winrnue.exe"="C:\WINDOWS\TEMP\winrnue.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wincbad.exe"="C:\WINDOWS\TEMP\wincbad.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winrdojwq.exe"="C:\WINDOWS\TEMP\winrdojwq.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wineymkgu.exe"="C:\WINDOWS\TEMP\wineymkgu.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winiufjn.exe"="C:\WINDOWS\TEMP\winiufjn.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winyqparl.exe"="C:\WINDOWS\TEMP\winyqparl.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\fbof.exe"="C:\WINDOWS\TEMP\fbof.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\qvfwal.exe"="C:\WINDOWS\TEMP\qvfwal.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\lnilbm.exe"="C:\WINDOWS\TEMP\lnilbm.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\kdwj.exe"="C:\WINDOWS\TEMP\kdwj.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winotejw.exe"="C:\WINDOWS\TEMP\winotejw.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winwnfb.exe"="C:\WINDOWS\TEMP\winwnfb.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winkpvas.exe"="C:\WINDOWS\TEMP\winkpvas.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winuhok.exe"="C:\WINDOWS\TEMP\winuhok.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winacmbvk.exe"="C:\WINDOWS\TEMP\winacmbvk.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winowey.exe"="C:\WINDOWS\TEMP\winowey.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winrdeuek.exe"="C:\WINDOWS\TEMP\winrdeuek.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\sumu.exe"="C:\WINDOWS\TEMP\sumu.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\rhcnys.exe"="C:\WINDOWS\TEMP\rhcnys.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winafhfhg.exe"="C:\WINDOWS\TEMP\winafhfhg.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\oxwcw.exe"="C:\WINDOWS\TEMP\oxwcw.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winlnknmk.exe"="C:\WINDOWS\TEMP\winlnknmk.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winowxqa.exe"="C:\WINDOWS\TEMP\winowxqa.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\yrakp.exe"="C:\WINDOWS\TEMP\yrakp.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winaylld.exe"="C:\WINDOWS\TEMP\winaylld.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wintyury.exe"="C:\WINDOWS\TEMP\wintyury.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winyfmjrh.exe"="C:\WINDOWS\TEMP\winyfmjrh.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winwdfaq.exe"="C:\WINDOWS\TEMP\winwdfaq.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winddwsv.exe"="C:\WINDOWS\TEMP\winddwsv.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\shkdv.exe"="C:\WINDOWS\TEMP\shkdv.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\nnju.exe"="C:\WINDOWS\TEMP\nnju.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wphgta.exe"="C:\WINDOWS\TEMP\wphgta.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winmbudpk.exe"="C:\WINDOWS\TEMP\winmbudpk.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\winhwstst.exe"="C:\WINDOWS\TEMP\winhwstst.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\wingnmhu.exe"="C:\WINDOWS\TEMP\wingnmhu.exe:*:Enabled:ipsec"
"C:\WINDOWS\TEMP\windfkjq.exe"="C:\WINDOWS\TEMP\windfkjq.exe:*:Enabled:ipsec"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2009-11-22 19:04:18 ----D---- C:\Documents and Settings\paul\Application Data\WinPatrol
2009-11-22 19:04:07 ----D---- C:\Program Files\BillP Studios
2009-11-21 13:58:37 ----A---- C:\WINDOWS\system32\javaws.exe
2009-11-21 13:58:37 ----A---- C:\WINDOWS\system32\javaw.exe
2009-11-21 13:58:37 ----A---- C:\WINDOWS\system32\java.exe
2009-11-21 12:52:59 ----D---- C:\WINDOWS\temp
2009-11-21 12:52:56 ----A---- C:\ComboFix.txt
2009-11-18 20:11:59 ----A---- C:\Boot.bak
2009-11-18 20:11:53 ----RASHD---- C:\cmdcons
2009-11-18 20:07:33 ----A---- C:\WINDOWS\PEV.exe
2009-11-18 20:07:33 ----A---- C:\WINDOWS\NIRCMD.exe
2009-11-18 20:07:33 ----A---- C:\WINDOWS\MBR.exe
2009-11-18 20:07:32 ----A---- C:\WINDOWS\zip.exe
2009-11-18 20:07:32 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-11-18 20:07:32 ----A---- C:\WINDOWS\SWSC.exe
2009-11-18 20:07:32 ----A---- C:\WINDOWS\SWREG.exe
2009-11-18 20:07:32 ----A---- C:\WINDOWS\sed.exe
2009-11-18 20:07:32 ----A---- C:\WINDOWS\grep.exe
2009-11-18 20:03:30 ----D---- C:\Qoobox
2009-11-17 20:05:01 ----D---- C:\rsit
2009-11-14 07:18:18 ----A---- C:\WINDOWS\system32\tmp.txt
2009-11-14 07:18:06 ----A---- C:\rapport.txt
2009-11-12 07:39:12 ----D---- C:\WINDOWS\ERDNT
2009-11-12 07:31:31 ----D---- C:\Program Files\Trend Micro
2009-11-11 22:10:14 ----A---- C:\WINDOWS\rootkitno.ini
2009-11-11 22:06:45 ----D---- C:\WINDOWS\Minidump
2009-11-11 21:49:28 ----A---- C:\WINDOWS\system32\PARTIZAN.TXT
2009-11-11 21:48:01 ----D---- C:\RootkitNO
2009-11-11 21:35:21 ----D---- C:\Documents and Settings\paul\Application Data\Help
2009-11-11 21:33:19 ----RASHOT---- C:\WINDOWS\winstart.bat
2009-11-11 21:05:25 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2009-11-11 20:11:01 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-10 17:25:05 ----D---- C:\Documents and Settings\paul\Application Data\mjusbsp
2009-11-10 07:39:43 ----D---- C:\Program Files\iPod
2009-11-10 07:39:21 ----D---- C:\Program Files\iTunes
2009-11-08 23:01:08 ----D---- C:\WINDOWS\.jagex_cache_32
2009-11-07 10:54:52 ----A---- C:\sqlite3.dll
2009-10-29 22:35:48 ----A---- C:\SharePod.exe
2009-10-29 22:07:58 ----A---- C:\Readme.txt
======List of files/folders modified in the last 1 months======
2009-11-22 19:04:07 ----RD---- C:\Program Files
2009-11-22 18:26:43 ----D---- C:\Program Files\Mozilla Firefox
2009-11-22 16:51:26 ----D---- C:\WINDOWS\Prefetch
2009-11-22 05:35:59 ----D---- C:\WINDOWS\system32\drivers
2009-11-22 05:35:11 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-11-21 13:58:37 ----D---- C:\WINDOWS\system32
2009-11-21 13:58:21 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-11-21 13:58:20 ----SHD---- C:\WINDOWS\Installer
2009-11-21 13:58:16 ----D---- C:\Program Files\Java
2009-11-21 12:52:59 ----D---- C:\WINDOWS
2009-11-21 12:48:40 ----D---- C:\WINDOWS\system32\CatRoot2
2009-11-21 12:41:37 ----A---- C:\WINDOWS\system.ini
2009-11-21 12:39:27 ----D---- C:\WINDOWS\system32\config
2009-11-21 12:34:01 ----D---- C:\WINDOWS\AppPatch
2009-11-21 12:33:57 ----D---- C:\Program Files\Common Files
2009-11-19 05:53:51 ----HD---- C:\WINDOWS\inf
2009-11-18 21:08:18 ----D---- C:\WINDOWS\repair
2009-11-18 20:37:47 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-11-18 20:11:59 ----RASH---- C:\boot.ini
2009-11-17 20:33:33 ----SD---- C:\Documents and Settings\paul\Application Data\Microsoft
2009-11-14 07:42:20 ----SD---- C:\WINDOWS\Tasks
2009-11-11 13:35:53 ----HD---- C:\WINDOWS\$hf_mig$
2009-11-10 21:28:08 ----D---- C:\Documents and Settings
2009-11-10 07:39:41 ----D---- C:\Program Files\Common Files\Apple
2009-11-10 07:33:10 ----D---- C:\WINDOWS\WinSxS
2009-11-08 05:07:39 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-11-08 05:07:04 ----D---- C:\Documents and Settings\paul\Application Data\Adobe
2009-11-08 05:03:23 ----D---- C:\Program Files\Common Files\Adobe
2009-11-08 05:02:34 ----D---- C:\Program Files\Adobe
2009-11-07 10:25:56 ----D---- C:\Documents and Settings\paul\Application Data\LimeWire
2009-11-06 18:43:06 ----D---- C:\Program Files\RedSnow
2009-11-06 03:01:01 ----A---- C:\WINDOWS\imsins.BAK
2009-11-06 01:36:21 ----A---- C:\WINDOWS\system32\MRT.exe
2009-10-30 16:43:20 ----D---- C:\Documents and Settings\paul\Application Data\Skype
2009-10-30 16:39:20 ----D---- C:\Documents and Settings\paul\Application Data\skypePM
2009-10-24 13:15:07 ----D---- C:\Program Files\Xvid
2009-10-23 03:00:50 ----D---- C:\Program Files\Internet Explorer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-08-04 21361]
R3 asc3360pr;asc3360pr; \??\C:\WINDOWS\system32\drivers\nqokln.sys []
R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2003-03-04 145408]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys [2009-04-30 25624]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-04-14 1897408]
R3 RT73;RT73 USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\rt73.sys [2008-01-15 459520]
R3 senfilt;senfilt; C:\WINDOWS\system32\drivers\senfilt.sys [2004-09-17 732928]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2005-01-27 260352]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\WINDOWS\system32\DRIVERS\LV302V32.SYS [2009-04-30 2687512]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD); C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2007-08-31 12212864]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2free;a-squared Free Service; D:\Program Files\a-squared Free\a2service.exe [2007-06-26 224888]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-11-21 153376]
R2 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-04-30 227864]
R2 YahooAUService;Yahoo! Updater; C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-10 602392]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-10-28 545568]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-08-05 732672]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NetSvc;Intel NCS NetService; C:\Program Files\Intel\NCS\Sync\NetSvc.exe [2003-03-03 221184]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 991232]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Combofix log:
ComboFix 09-11-18.07 - paul 11/21/2009 12:28.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.255.112 [GMT 8:00]
Running from: c:\documents and settings\paul\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\paul\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2009-10-21 to 2009-11-21 )))))))))))))))))))))))))))))))
.
2009-11-19 11:19 . 2009-11-19 11:19 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-11-18 12:37 . 2008-04-14 12:00 96512 -c--a-w- c:\windows\system32\dllcache\atapi.sys
2009-11-18 12:37 . 2008-04-14 12:00 96512 ------w- c:\windows\system32\drivers\atapi.sys
2009-11-17 20:52 . 2009-11-17 20:53 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Adobe
2009-11-17 12:05 . 2009-11-17 12:05 -------- d-----w- C:\rsit
2009-11-15 05:24 . 2009-11-15 05:24 -------- d-sh--w- c:\documents and settings\Guest\PrivacIE
2009-11-15 05:24 . 2009-11-15 05:24 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\AskToolbar
2009-11-14 20:16 . 2009-11-14 20:16 1 ----a-w- c:\documents and settings\Guest\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-14 20:14 . 2009-11-14 20:14 -------- d-----w- c:\documents and settings\Guest\Application Data\OpenOffice.org
2009-11-11 23:31 . 2009-11-19 13:45 -------- d-----w- c:\program files\Trend Micro
2009-11-11 13:48 . 2009-11-11 13:48 -------- d-----w- C:\RootkitNO
2009-11-11 13:35 . 2009-11-11 13:35 -------- d-----w- c:\documents and settings\paul\Local Settings\Application Data\Help
2009-11-11 13:33 . 2009-11-11 13:33 2 --shatr- c:\windows\winstart.bat
2009-11-11 13:32 . 2008-12-22 07:56 12752 ----a-w- c:\windows\system32\drivers\UnHackMeDrv.sys
2009-11-11 12:11 . 2009-11-21 04:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-10 17:20 . 2009-11-10 17:20 -------- d-sh--w- c:\documents and settings\Guest\IETldCache
2009-11-10 13:31 . 2009-11-10 13:31 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Yahoo
2009-11-10 13:29 . 2009-11-10 13:29 16504 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-10 12:00 . 2009-08-01 16:16 6326232 ---ha-w- c:\documents and settings\paul\Application Data\mjusbsp\in00000\setup.exe
2009-11-10 12:00 . 2009-08-01 16:16 6330328 ---ha-w- c:\documents and settings\paul\Application Data\mjusbsp\Upgrade\setup1.exe
2009-11-10 12:00 . 2009-08-01 16:12 798232 ---ha-w- c:\documents and settings\paul\Application Data\mjusbsp\Upgrade\install1.exe
2009-11-10 11:57 . 2009-11-10 12:00 7690776 ---h--w- c:\documents and settings\paul\Application Data\mjusbsp\ar00000\upgrade.exe
2009-11-10 09:25 . 2009-11-10 12:00 -------- d-----w- c:\documents and settings\paul\Application Data\mjusbsp
2009-11-09 23:39 . 2009-11-09 23:39 -------- d-----w- c:\program files\iPod
2009-11-09 23:39 . 2009-11-09 23:40 -------- d-----w- c:\program files\iTunes
2009-11-09 23:19 . 2009-11-09 23:19 152872 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-08 15:01 . 2009-11-08 15:01 -------- d-----w- c:\windows\.jagex_cache_32
2009-11-07 02:54 . 2009-11-07 02:54 504038 ----a-w- C:\sqlite3.dll
2009-10-29 14:35 . 2009-10-29 14:35 5595136 ----a-w- C:\SharePod.exe
2009-10-29 09:55 . 2009-10-29 09:55 152576 ----a-w- c:\documents and settings\paul\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-23 15:05 . 2009-10-23 15:05 -------- d-----w- c:\documents and settings\paul\Local Settings\Application Data\Identities
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-19 12:41 . 2009-08-26 23:21 1 ----a-w- c:\documents and settings\paul\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-17 12:33 . 2009-11-17 12:33 2015 ---h--r- c:\windows\system32\drivers\hosts
2009-11-15 05:24 . 2009-11-10 13:28 -------- d--h--r- c:\documents and settings\Guest\Application Data\yahoo!
2009-11-09 23:39 . 2009-09-10 22:55 -------- d-----w- c:\program files\Common Files\Apple
2009-11-07 21:03 . 2009-08-04 07:05 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-07 02:25 . 2009-08-06 12:08 -------- d-----w- c:\documents and settings\paul\Application Data\LimeWire
2009-11-06 10:43 . 2009-10-06 02:27 -------- d-----w- c:\program files\RedSnow
2009-10-30 08:43 . 2009-08-06 08:32 -------- d-----w- c:\documents and settings\paul\Application Data\Skype
2009-10-30 08:39 . 2009-08-06 08:35 -------- d-----w- c:\documents and settings\paul\Application Data\skypePM
2009-10-29 09:58 . 2009-08-05 06:59 -------- d-----w- c:\program files\Java
2009-10-24 05:15 . 2009-08-27 12:22 -------- d-----w- c:\program files\Xvid
2009-10-14 02:56 . 2009-10-14 02:56 -------- d-----w- c:\documents and settings\paul\Application Data\SharePod
2009-10-11 09:22 . 2009-10-06 01:38 -------- d-----w- c:\documents and settings\paul\Application Data\DivX
2009-10-06 01:26 . 2009-10-06 01:25 -------- d-----w- c:\program files\DivX
2009-10-06 01:25 . 2009-10-06 01:25 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-10-03 08:27 . 2009-10-03 08:27 -------- d-----w- c:\program files\RedSnow iTouch Jailbreak
2009-10-03 07:03 . 2009-10-03 07:03 -------- d-----w- c:\program files\hi join
2009-10-03 07:01 . 2009-08-04 02:36 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-10-03 03:54 . 2009-08-05 05:54 16504 ----a-w- c:\documents and settings\paul\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-03 03:44 . 2009-10-03 03:44 -------- d-----w- c:\program files\MSBuild
2009-10-03 03:44 . 2009-10-03 03:44 -------- d-----w- c:\program files\Reference Assemblies
2009-10-02 23:38 . 2009-09-10 23:04 -------- d-----w- c:\documents and settings\paul\Application Data\Apple Computer
2009-09-26 02:04 . 2009-08-06 22:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-09-25 02:13 . 2009-09-22 04:01 -------- d-----w- c:\documents and settings\All Users\Application Data\LogiShrd
2009-09-11 14:18 . 2008-04-14 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2008-04-14 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2008-04-14 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-28 11:42 . 2009-09-10 22:56 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-28 11:42 . 2009-09-10 22:56 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-26 08:00 . 2008-04-14 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-07-14 00:16 . 2009-07-14 00:16 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-07-14 00:16 . 2009-07-14 00:16 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-11-18_12.24.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-21 04:25 . 2009-11-21 04:25 16384 c:\windows\temp\Perflib_Perfdata_954.dat
+ 2009-11-21 04:40 . 2009-04-30 08:01 109080 c:\windows\temp\logishrd\LVPrcInj01.dll
- 2009-11-18 12:23 . 2009-04-30 08:01 109080 c:\windows\temp\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 185584]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1768960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 185584]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 491520]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-05-08 2854160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-02 109424]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 1004920]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-28 215328]
c:\documents and settings\Guest\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 457728]
c:\documents and settings\paul\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 457728]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Wireless Utility.lnk - c:\program files\EDIMAX\Common\RaUI.exe [2009-8-4 786432]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Adobe\\Adobe Bridge CS3\\Bridge.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\QuickTime\\QTTask.exe"=
"c:\\Program Files\\Yahoo!\\Search Protection\\SearchProtection.exe"=
"c:\\WINDOWS\\system32\\dmremote.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\Documents and Settings\\paul\\Application Data\\mjusbsp\\cdloader2.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\jusched.exe"=
"c:\\Documents and Settings\\paul\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\iTunes\\iTunesHelper.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\ymsgr_tray.exe"=
"c:\\Program Files\\Logitech\\Logitech WebCam Software\\LWS.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\RegCure\\RegCure.exe"= d:\\Program Files\\RegCure\\RegCure.exe
"c:\\WINDOWS\\PEV.exe"=
"c:\\Program Files\\OpenOffice.org 3\\program\\soffice.bin"=
"c:\\Program Files\\Common Files\\LogiShrd\\LVMVFM\\LVPrcSrv.exe"=
"c:\\Program Files\\OpenOffice.org 3\\program\\soffice.exe"=
"c:\\DOCUME~1\\paul\\LOCALS~1\\Temp\\hkre.exe"=
"c:\\DOCUME~1\\paul\\LOCALS~1\\Temp\\winkrxfpw.exe"=
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ASC3360PR
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-11-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 04:34]
2009-11-21 c:\windows\Tasks\RegCure Program Check.job
- d:\program files\RegCure\RegCure.exe [2008-04-21 12:46]
2009-11-19 c:\windows\Tasks\RegCure.job
- d:\program files\RegCure\RegCure.exe [2008-04-21 12:46]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.daemon-search.com/startpage
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
http://www.yahoo.com
FF - ProfilePath - c:\documents and settings\paul\Application Data\Mozilla\Firefox\Profiles\5uoghj58.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.ph/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-21 12:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4028)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
d:\program files\a-squared Free\a2service.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wscntfy.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\iPod\bin\iPodService.exe
c:\docume~1\paul\LOCALS~1\Temp\hkre.exe
c:\docume~1\paul\LOCALS~1\Temp\winkrxfpw.exe
.
**************************************************************************
.
Completion time: 2009-11-21 12:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-21 04:52
ComboFix2.txt 2009-11-19 13:42
ComboFix3.txt 2009-11-18 13:09
Pre-Run: 23,076,749,312 bytes free
Post-Run: 22,965,518,336 bytes free
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - BA06D15BE1E2610E4C09FDB03CC03D44