ComboFix 08-07-11.1 - Stebow 2008-07-12 13:46:10.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1021 [GMT 1:00]
Running from: C:\Documents and Settings\Stebow\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\Stebow\Application Data\inst.exe
C:\Program Files\PCHealthCenter
C:\Program Files\PCHealthCenter\
0.gif
C:\Program Files\PCHealthCenter\1.gif
C:\Program Files\PCHealthCenter\2.gif
C:\Program Files\PCHealthCenter\3.gif
C:\Program Files\PCHealthCenter\sex1.ico
C:\Program Files\PCHealthCenter\sex2.ico
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\clbinit.dll
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\FNqYayay.ini
C:\WINDOWS\system32\FNqYayay.ini2
C:\WINDOWS\system32\lebjbwag.ini
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\rndtyblm.ini
C:\WINDOWS\system32\shmivcxy.ini
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\system32\wqpclibx.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CLBDRIVER
-------\Service_clbdriver
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-06-12 to 2008-07-12 )))))))))))))))))))))))))))))))
.
2008-07-10 07:43 . 2008-07-10 07:43 <DIR> d-------- C:\Program Files\Microsoft IntelliPoint
2008-07-10 07:43 . 2007-08-21 01:13 21,760 --a------ C:\WINDOWS\system32\drivers\point32.sys
2008-07-10 07:08 . 2005-05-03 18:43 69,632 --a------ C:\WINDOWS\Alcmtr.exe
2008-07-05 00:40 . 2008-07-05 00:40 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-07-05 00:16 . 2008-07-05 00:16 <DIR> d-------- C:\Program Files\Sygate
2008-07-05 00:16 . 2004-10-15 18:32 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2008-07-05 00:16 . 2004-10-15 18:17 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2008-07-05 00:16 . 2004-10-15 18:18 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2008-07-05 00:16 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg6n.sys
2008-07-05 00:16 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg5n.sys
2008-07-05 00:16 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg4n.sys
2008-07-05 00:16 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2008-07-04 08:07 . 2008-07-04 08:07 95 --a------ C:\WINDOWS\wininit.ini
2008-07-04 07:03 . 2008-07-10 07:50 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-04 06:44 . 2008-07-04 06:44 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-07-04 04:00 . 2008-07-04 04:00 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\TeamViewer
2008-07-04 03:56 . 2008-07-04 03:56 <DIR> d-------- C:\Documents and Settings\Stebow\temp
2008-07-04 03:56 . 2008-07-04 03:56 <DIR> d-------- C:\Documents and Settings\Stebow\Application Data\TeamViewer
2008-07-04 03:06 . 2008-07-04 03:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-04 02:56 . 2008-07-04 02:56 <DIR> d-------- C:\Program Files\Microsoft Easy Assist
2008-07-04 00:03 . 2008-07-04 00:03 <DIR> d-------- C:\Program Files\CCleaner
2008-07-02 01:02 . 2008-07-10 07:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-01 23:55 . 2006-03-15 13:00 4,224 --a------ C:\WINDOWS\system32\beep.sys
2008-07-01 23:49 . 2008-07-10 04:46 <DIR> d-------- C:\Program Files\a-squared Free
2008-07-01 21:32 . 2008-07-01 21:32 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-07-01 20:57 . 2008-07-01 21:35 <DIR> d-------- C:\Documents and Settings\Stebow\.housecall6.6
2008-07-01 20:40 . 2008-07-01 20:54 <DIR> d-------- C:\Documents and Settings\Stebow\Application Data\HouseCall 6.6
2008-07-01 00:26 . 2008-07-12 13:06 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-06-30 19:51 . 2008-06-30 19:51 <DIR> d-------- C:\Program Files\NeroInstall.bak
2008-06-30 19:50 . 2008-06-30 19:50 <DIR> d-------- C:\Documents and Settings\Stebow\Application Data\Nero
2008-06-30 19:48 . 2008-06-30 19:48 <DIR> d-------- C:\Program Files\Nero
2008-06-30 19:48 . 2008-06-30 19:49 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-06-30 19:48 . 2008-06-30 19:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-06-30 18:20 . 2008-07-12 13:29 <DIR> d-------- C:\Documents and Settings\Stebow\Application Data\uTorrent
2008-06-30 18:05 . 2008-07-08 23:58 <DIR> d-------- C:\Documents and Settings\Stebow\Application Data\dvdcss
2008-06-30 17:30 . 2008-07-01 00:26 <DIR> d-------- C:\Documents and Settings\Stebow\Application Data\DivX
2008-06-30 17:28 . 2008-06-30 17:28 <DIR> d-------- C:\Program Files\DivX
2008-06-30 17:28 . 2008-05-22 23:22 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2008-06-26 21:10 . 2008-06-26 21:10 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-06-20 16:20 . 2008-06-23 03:55 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-06-20 14:28 . 2008-06-21 17:01 <DIR> d-------- C:\Program Files\RegScrubXP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-12 12:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-12 12:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-11 02:26 --------- d-----w C:\Documents and Settings\Stebow\Application Data\Xfire
2008-07-11 01:30 --------- d-----w C:\Program Files\Xfire
2008-07-11 01:24 --------- d-----w C:\Program Files\Ventrilo
2008-07-10 06:50 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-10 04:52 --------- d-----w C:\Documents and Settings\Stebow\Application Data\Vso
2008-07-10 02:34 137,472 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-10 00:24 --------- d-----w C:\Program Files\Wolfenstein - Enemy Territory
2008-07-03 23:11 163,712 ----a-w C:\WINDOWS\system32\drivers\vidstub.sys
2008-07-02 21:50 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-30 22:00 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-06-10 19:15 --------- d-----w C:\Program Files\ET Patch Selector
2008-06-10 19:14 1,386,496 ----a-w C:\WINDOWS\msvbvm60.dll
2008-06-06 11:44 --------- d-----w C:\Program Files\PCPitstop
2008-06-06 01:58 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-06-06 01:58 47,360 ----a-w C:\Documents and Settings\Stebow\Application Data\pcouffin.sys
2008-06-06 01:58 --------- d-----w C:\Program Files\VSO
2008-06-05 21:14 --------- d-----w C:\Documents and Settings\Stebow\Application Data\Nokia Multimedia Player
2008-06-05 21:12 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-05 21:12 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-06-05 21:12 --------- d-----w C:\Documents and Settings\Stebow\Application Data\PC Suite
2008-06-05 21:12 --------- d-----w C:\Documents and Settings\Stebow\Application Data\Nokia
2008-06-05 21:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-06-05 21:07 --------- d-----w C:\Program Files\Nokia
2008-06-05 21:07 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-06-05 21:07 --------- d-----w C:\Program Files\Common Files\Nokia
2008-06-05 21:06 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-06-05 21:06 --------- d-----w C:\Program Files\DIFX
2008-06-05 21:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-06-03 17:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\PCPitstop
2008-06-03 15:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\vsosdk
2008-06-02 17:10 4,752,384 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-05-30 22:40 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Xfire
2008-05-28 22:00 --------- d-----w C:\Documents and Settings\Stebow\Application Data\Image Zone Express
2008-05-28 13:52 16,862,720 ----a-w C:\WINDOWS\RTHDCPL.exe
2008-05-26 01:09 --------- d-----w C:\Documents and Settings\Stebow\Application Data\GSC
2008-05-25 14:50 --------- d-----w C:\Program Files\GSC
2008-05-24 18:45 --------- d-----w C:\Program Files\MagicISO
2008-05-24 18:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-21 23:06 --------- d-----w C:\Program Files\MagicDisc
2008-05-21 17:20 --------- d-----w C:\Program Files\Skype
2008-05-21 17:15 --------- d-----w C:\Documents and Settings\Stebow\Application Data\Skype
2008-05-21 17:13 --------- d-----w C:\Documents and Settings\Stebow\Application Data\skypePM
2008-05-19 01:10 --------- d-----w C:\Documents and Settings\Stebow\Application Data\Ventrilo
2008-05-18 23:37 --------- d-----w C:\Program Files\Common Files\Skype
2008-05-18 23:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-05-15 18:08 1,008,362,079 ----a-w C:\Program Files\Wolfenstein - Enemy Territory.rar
2008-05-13 23:59 --------- d-----w C:\Documents and Settings\Stebow\Application Data\HP
2008-05-13 23:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-05-13 23:46 --------- d-----w C:\Program Files\HP
2008-05-13 23:46 --------- d-----w C:\Program Files\Common Files\HP
2008-05-13 23:45 --------- d-----w C:\Program Files\Hewlett-Packard
2008-05-13 23:44 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-05-13 22:12 --------- d-----w C:\Program Files\Java
2008-05-13 22:11 --------- d-----w C:\Program Files\Common Files\Java
2008-05-13 21:52 --------- d-----w C:\Program Files\Sun
2008-05-13 00:57 --------- d-----w C:\Program Files\TalkTalk
2008-04-26 19:37 286,720 ----a-w C:\WINDOWS\iun506.exe
2008-04-24 09:26 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-04-14 04:42 69,120 ----a-w C:\WINDOWS\notepad.exe
2008-04-14 04:42 50,688 ----a-w C:\WINDOWS\twain_32.dll
2008-04-14 04:42 34,816 ----a-w C:\WINDOWS\Help\sniffpol.dll
2008-04-14 04:42 33,280 ----a-w C:\WINDOWS\Help\sstub.dll
2008-04-14 04:42 32,866 ------w C:\WINDOWS\slrundll.exe
2008-04-14 04:42 283,648 ----a-w C:\WINDOWS\winhlp32.exe
2008-04-14 04:42 279,040 ----a-w C:\WINDOWS\Help\tshoot.dll
2008-04-14 04:42 146,432 ----a-w C:\WINDOWS\regedit.exe
2008-04-14 04:42 10,752 ----a-w C:\WINDOWS\hh.exe
2008-04-14 04:42 1,033,728 ----a-w C:\WINDOWS\explorer.exe
2008-04-14 04:41 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
2008-04-14 04:41 39,424 ----a-w C:\WINDOWS\AppPatch\acadproc.dll
2008-04-14 04:41 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll
2008-04-14 04:41 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll
2008-04-14 04:41 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll
2008-04-14 04:41 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll
.
------- Sigcheck -------
2007-12-07 03:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2008-02-16 10:32 666112 bb1eacd6ab47e78ebca02eb781550d55 C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\wininet.dll
2008-03-01 14:03 827392 6316c2f0c61271c8abdff7429174879e C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
2006-03-15 13:00 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\$NtUninstallKB947864$\wininet.dll
2007-12-07 03:21 824832 806d274c9a6c3aaea5eae8e4af841e04 C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll
2008-04-14 05:42 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\ServicePackFiles\i386\wininet.dll
2008-03-01 14:06 826368 ad21461aef8244edec2ef18e55e1dcf3 C:\WINDOWS\SoftwareDistribution\Download\4dcb1f965c037cafb3a5ed4c71a998b8\SP2GDR\wininet.dll
2008-03-01 14:03 827392 6316c2f0c61271c8abdff7429174879e C:\WINDOWS\SoftwareDistribution\Download\4dcb1f965c037cafb3a5ed4c71a998b8\SP2QFE\wininet.dll
2007-12-07 03:21 824832 806d274c9a6c3aaea5eae8e4af841e04 C:\WINDOWS\SoftwareDistribution\Download\e5a204b08ee9dd0f7a20547e61486b27\SP2GDR\wininet.dll
2007-12-07 03:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 C:\WINDOWS\SoftwareDistribution\Download\e5a204b08ee9dd0f7a20547e61486b27\SP2QFE\wininet.dll
2008-02-16 09:59 659456 0c690e77c0e924c45b4d7045b182fff1 C:\WINDOWS\system32\wininet.dll
2008-02-16 09:59 659456 0c690e77c0e924c45b4d7045b182fff1 C:\WINDOWS\system32\dllcache\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"BitComet"="C:\Program Files\BitLord\BitLord.exe" [2005-05-07 01:47 2224128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 12:01 1037736]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-28 14:52 16862720 C:\WINDOWS\RTHDCPL.exe]
C:\Documents and Settings\Stebow\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [4/30/2008 12:46:24 AM 3450608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Stebow^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Documents and Settings\Stebow\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
--a------ 2005-05-07 01:47 2224128 C:\Program Files\BitLord\BitLord.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
--a------ 2007-02-26 01:01 437160 c:\PROGRA~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2008-02-15 12:46 159744 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2008-02-28 17:07 1828136 C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2008-02-18 16:29 2221352 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
--a------ 2008-03-26 18:41 1232896 C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
--a------ 2008-04-16 12:53 1079808 C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
--a------ 2008-02-15 12:46 131072 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-04-23 17:45 22058792 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-05-03 18:43 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2008-05-28 14:52 16862720 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=2 (0x2)
"SupportSoft RemoteAssist"=3 (0x3)
"RSVP"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"mnmsrvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\TalkTalk\\agent\\bin\\bcont.exe"=
"C:\\Program Files\\Common Files\\SupportSoft\\bin\\tgsrvc.exe"=
"C:\\Program Files\\TalkTalk\\bin\\sprtcmd.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\TalkTalk\\agent\\bin\\bcont_nm.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 00:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 00:16]
R2 sprtsvc_TalkTalk;SupportSoft Sprocket Service (TalkTalk);C:\Program Files\TalkTalk\bin\sprtsvc.exe [2007-10-12 08:33]
R2 tgsrvc_TalkTalk;SupportSoft Repair Service (TalkTalk);C:\Program Files\Common Files\Supportsoft\bin\tgsrvc.exe [2007-08-02 13:42]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l151x86.sys [2008-02-24 14:27]
.
- - - - ORPHANS REMOVED - - - -
Notify-awtqoMee - awtqoMee.dll
MSConfigStartUp-antispy - C:\Program Files\IEAntiVirus\ANTIVIR.exe
MSConfigStartUp-Jigsaw - C:\DOCUME~1\Stebow\LOCALS~1\Temp\3913574.exe
MSConfigStartUp-uTorrent - C:\Program Files\uTorrent\uTorrent.exe
MSConfigStartUp-POINTER - point32.exe
MSConfigStartUp-Windows Sound - svdhost.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-12 13:49:40
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\vsdatant]
"ImagePath"=""
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Sygate\SPF\Smc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\scardsvr.exe
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\locator.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-07-12 13:51:24 - machine was rebooted [Stebow]
ComboFix-quarantined-files.txt 2008-07-12 12:51:21
Pre-Run: 370,774,786,048 bytes free
Post-Run: 370,757,218,304 bytes free
305 --- E O F --- 2008-05-06 18:44:50