Virus Total Results:
AhnLab-V3 2008.4.24.0 2008.04.24 -
AntiVir 7.8.0.8 2008.04.23 -
Authentium 4.93.8 2008.04.22 -
Avast 4.8.1169.0 2008.04.24 -
AVG 7.5.0.516 2008.04.23 -
BitDefender 7.2 2008.04.24 -
CAT-QuickHeal 9.50 2008.04.23 -
ClamAV 0.92.1 2008.04.24 -
DrWeb 4.44.0.09170 2008.04.23 -
eSafe 7.0.15.0 2008.04.21 -
eTrust-Vet 31.3.5730 2008.04.23 -
Ewido 4.0 2008.04.23 -
F-Prot 4.4.2.54 2008.04.23 -
F-Secure 6.70.13260.0 2008.04.24 -
FileAdvisor 1 2008.04.24 -
Fortinet 3.14.0.0 2008.04.23 -
Ikarus T3.1.1.26 2008.04.24 -
Kaspersky 7.0.0.125 2008.04.24 -
McAfee 5279 2008.04.23 -
Microsoft 1.3408 2008.04.22 -
NOD32v2 3049 2008.04.24 -
Norman 5.80.02 2008.04.23 -
Panda 9.0.0.4 2008.04.23 -
Prevx1 V2 2008.04.24 -
Rising 20.41.22.00 2008.04.23 -
Sophos 4.28.0 2008.04.23 -
Sunbelt 3.0.1056.0 2008.04.17 -
Symantec 10 2008.04.24 -
TheHacker 6.2.92.290 2008.04.24 -
VBA32 3.12.6.4 2008.04.16 -
VirusBuster 4.3.26:9 2008.04.23 -
Webwasher-Gateway 6.6.2 2008.04.24 -
Additional information
File size: 153 bytes
MD5...: 5096b05d206dbb4e2785fa5cd5254f96
SHA1..: 8a85f1af6b2c70931595b44d4b945cabfa7215ac
SHA256: 42d7e7a981f02d2b4efbd92334c817f963e569c2b466912f8c300ccf1cf23861
SHA512: d2d712bffd7d5e3ed4b71d60d4bf303061e2eb8bb7acada21c6617dd1bea41a3
408fd58057934adb9b62311fe61f717db956e681280eff88b1145acbfd40d3bd
PEiD..: -
PEInfo: -
ComboFix Results:
ComboFix 08-04-22.5 - Kenda 2008-04-23 20:52:34.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1362 [GMT -5:00]
Running from: C:\Documents and Settings\Kenda\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kenda\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\dpevflbg.dll
C:\WINDOWS\olgdqarf.exe
C:\WINDOWS\qnmargolbve.dll
C:\WINDOWS\system32\irxhklug.ini
C:\WINDOWS\system32\lyxiochc.ini
C:\WINDOWS\vadokmxt.dll
C:\WINDOWS\wdpoefan.dll
C:\WINDOWS\wxvgsdbq.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Kenda\Favorites\Error Cleaner.url
C:\Documents and Settings\Kenda\Favorites\Privacy Protector.url
C:\Documents and Settings\Kenda\Favorites\Spyware&Malware Protection.url
C:\WINDOWS\dpevflbg.dll
C:\WINDOWS\olgdqarf.exe
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\qnmargolbve.dll
C:\WINDOWS\system32\irxhklug.ini
C:\WINDOWS\system32\lyxiochc.ini
C:\WINDOWS\vadokmxt.dll
C:\WINDOWS\wdpoefan.dll
C:\WINDOWS\wxvgsdbq.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-24 to 2008-04-24 )))))))))))))))))))))))))))))))
.
2008-04-23 20:43 . 2008-04-23 20:47 <DIR> d-------- C:\Malware Info
2008-04-21 15:49 . 2008-04-21 15:49 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-04-21 15:20 . 2006-11-07 21:01 66,048 --a------ C:\WINDOWS\ieResetIcons.exe
2008-04-21 14:09 . 2008-04-21 14:09 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-04-21 13:34 . 2008-04-21 13:43 118,784 --a------ C:\WINDOWS\SeaMonkeyUninstall.exe
2008-04-21 13:33 . 2008-04-21 13:43 118,784 --a------ C:\WINDOWS\GREUninstall.exe
2008-04-21 12:58 . 2008-02-21 11:47 91,008 --a------ C:\WINDOWS\system32\drivers\SysPlant.sys
2008-04-21 12:54 . 2008-04-21 12:57 136,496 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-04-21 12:54 . 2008-04-21 12:57 60,808 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-04-21 12:54 . 2008-04-21 12:57 10,652 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-04-21 12:54 . 2008-04-21 12:57 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-04-21 12:51 . 2008-04-21 12:51 <DIR> d-------- C:\Program Files\Symantec Client Security
2008-04-20 23:56 . 2008-04-20 23:56 <DIR> d-------- C:\Documents and Settings\Pastor\Application Data\TmpRecentIcons
2008-04-20 23:09 . 2008-04-20 23:09 153 --a------ C:\DelUS.bat
2008-04-20 22:15 . 2008-04-20 22:15 <DIR> d-------- C:\Documents and Settings\Kenda\Application Data\TmpRecentIcons
2008-04-20 21:11 . 2008-04-20 21:28 <DIR> d-------- C:\Documents and Settings\Kenda\Application Data\GeoVid
2008-04-20 21:09 . 2008-04-20 21:09 <DIR> d-------- C:\Program Files\Common Files\GeoVid
2008-04-20 21:09 . 2005-06-07 16:11 60,416 --a------ C:\WINDOWS\system32\dsetup.dll
2008-04-17 19:43 . 2008-04-17 19:43 <DIR> d-------- C:\Program Files\Apple Software Update
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-24 01:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-04-21 19:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-21 19:06 --------- d-----w C:\Program Files\Common Files\Real
2008-04-21 19:03 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-04-21 18:32 --------- d-----w C:\Program Files\mozilla.org
2008-04-21 18:27 --------- d-----w C:\Program Files\Free Surfer
2008-04-21 18:23 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-21 18:10 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-04-21 18:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-21 17:57 --------- d-----w C:\Program Files\Symantec
2008-04-21 16:56 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-04-21 04:36 --------- d-----w C:\Program Files\Yahoo!
2008-04-21 04:13 --------- d-----w C:\Program Files\Sonic
2008-04-21 04:03 --------- d-----w C:\Program Files\Toshiba
2008-04-03 05:25 --------- d-----w C:\Program Files\iTunes
2008-04-03 05:24 --------- d-----w C:\Program Files\iPod
2008-04-03 05:22 --------- d-----w C:\Program Files\QuickTime
2008-03-25 21:15 50,536 ----a-w C:\WINDOWS\system32\drivers\WpsHelper.sys
2008-03-22 17:22 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-12 08:28 --------- d-----w C:\Program Files\Netflix
2008-02-26 16:56 --------- d-----w C:\Program Files\Google
2008-02-26 15:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo
2008-02-26 15:13 --------- d--h--r C:\Documents and Settings\Kenda\Application Data\yahoo!
2008-02-26 04:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-02-26 04:44 --------- d-----w C:\Program Files\Pure Networks
2008-02-26 04:33 --------- d-----w C:\Program Files\Kodak
2008-02-26 04:33 --------- d-----w C:\Program Files\Common Files\aolshare
2008-02-26 04:30 --------- d-----w C:\Program Files\Plaxo
2008-02-26 04:29 --------- d-----w C:\Program Files\Rhapsody
2008-02-26 04:28 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-21 16:47 91,632 ----a-w C:\WINDOWS\system32\nts.dll
2008-02-21 16:47 89,088 ----a-w C:\WINDOWS\system32\atl71.dll
2008-02-21 16:47 83,440 ----a-w C:\WINDOWS\system32\pds.dll
2008-02-21 16:47 83,384 ----a-w C:\WINDOWS\system32\loc32vc0.dll
2008-02-21 16:47 48,000 ----a-w C:\WINDOWS\system32\FwsVpn.dll
2008-02-21 16:47 46,584 ----a-w C:\WINDOWS\system32\msgsys.dll
2008-02-21 16:47 34,288 ----a-w C:\WINDOWS\system32\cba.dll
2008-02-21 16:47 329,088 ----a-w C:\WINDOWS\system32\sysfer.dll
2008-02-21 16:47 107,904 ----a-w C:\WINDOWS\system32\SymVPN.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-12 13:27 1,301,304 ----a-w C:\Program Files\WindowsXP-KB917021-v3-x86-ENU.exe
2008-01-29 17:02 107,368 ----a-w C:\WINDOWS\system32\GEARAspi.dll
2007-03-05 23:25 66 ----a-w C:\Documents and Settings\Kenda\Application Data\wklnhst.dat
2003-11-03 04:52 301,321 ----a-w C:\Documents and Settings\All Users\Office 2003 Editions 60 Day Trial.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3E8C3B94-97F8-491E-8F60-657A41FF5A91}]
C:\WINDOWS\system32\urqQgddC.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1BACF55-35E1-4E47-9247-2D48660E5545}]
C:\Program Files\Zango\bin\10.1.181.0\HostIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{E1BACF55-35E1-4E47-9247-2D48660E5545}"= "C:\Program Files\Zango\bin\10.1.181.0\HostIE.dll" [ ]
"{838B6BFB-94D5-4C3F-851C-EEBF6108BDA8}"= "C:\WINDOWS\dpevflbg.dll" [ ]
[HKEY_CLASSES_ROOT\clsid\{e1bacf55-35e1-4e47-9247-2d48660e5545}]
[HKEY_CLASSES_ROOT\HostIE.Bho.1]
[HKEY_CLASSES_ROOT\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}]
[HKEY_CLASSES_ROOT\HostIE.Bho]
[HKEY_CLASSES_ROOT\clsid\{838b6bfb-94d5-4c3f-851c-eebf6108bda8}]
[HKEY_CLASSES_ROOT\dpevflbg.1]
[HKEY_CLASSES_ROOT\TypeLib\{85368D78-B064-4F3D-A500-F74B9A7BDBD6}]
[HKEY_CLASSES_ROOT\dpevflbg]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 02:32 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 14:27 385024]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2005-04-12 18:18 184320]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-12 18:17 88358 C:\WINDOWS\agrsmmsg.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-30 18:46 192512]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-11-30 15:06 53248]
"TOSHIBA Accessibility"="C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe" [2005-03-08 17:27 24576]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-04-20 17:56 28672 C:\WINDOWS\system32\TCtrlIOHook.exe]
"TFncKy"="TFncKy.exe" []
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2005-04-28 22:08 675840]
"TPSMain"="TPSMain.exe" [2004-12-28 18:02 270336 C:\WINDOWS\system32\TPSMain.exe]
"SVPWUTIL"="C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2005-02-26 09:59 65536]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 16:03 1077301]
"ZoomingHook"="ZoomingHook.exe" [2004-05-01 15:41 24576 C:\WINDOWS\system32\ZoomingHook.exe]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-15 18:51 122880]
"HWSetup"="C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-12-24 12:07 28672]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2005-04-05 18:25 73728]
"NDSTray.exe"="NDSTray.exe" []
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 19:37 151552]
"CFSServ.exe"="CFSServ.exe" []
"DIGStream"="C:\Program Files\DIGStream\digstream.exe" [2005-10-31 12:05 278528]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [2005-10-31 12:18 101888]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 19:50 212992]
"DXDllRegExe"="dxdllreg.exe" []
"Notebook Maximizer"="C:\Program Files\Notebook Maximizer\maximizer_startup.exe" [2006-05-04 17:59 40960]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59 124520]
"VSOCheckTask"="c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [ ]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [ ]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [ ]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\McAgent.exe" [ ]
"HostManager"="C:\Program Files\Common Files\AOL\1137174404\ee\AOLSoftware.exe" [2006-05-09 19:24 50760]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-01-13 09:47 131072]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-01-13 09:47 163840]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-01-13 09:46 135168]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-21 11:47 115560]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-21 14:02 185896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingC2834"="cmd /c del C:\WINDOWS\system32\urqQgddC.dll_old" [ ]
"GrpConv"="grpconv -o" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-08-18 19:37:12 155648]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 23:07:32 81920]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"vadokmxt"= {07014DC1-2D76-44FD-B717-90F6488BC821} - C:\WINDOWS\vadokmxt.dll [ ]
"wdpoefan"= {DE8ACE17-319D-47D8-B2EA-78E031DA91E7} - C:\WINDOWS\wdpoefan.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-10-15 14:27 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnnKAPH]
pmnnKAPH.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.scg726"= scg726.acm
"msacm.alf2cd"= alf2cd.acm
"vidc.dvsd"= mcdvd_32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antvirus]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1137174404\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Symantec Client Security\\Symantec AntiVirus\\Smc.exe"=
"C:\\Program Files\\Symantec Client Security\\Symantec AntiVirus\\SNAC.EXE"=
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-15 22:38]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-02-21 11:47]
S3 dwusbdnt;dwusbdnt;C:\WINDOWS\system32\DRIVERS\dwusbdnt.sys [2002-05-24 12:52]
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-03-24 18:36]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-22 20:01:59 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-01-17 16:34:19 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1137515435.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe0/#Hewlett-Packard#hp psc 1300 series#1137515435
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-23 20:54:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-23 20:54:54
ComboFix-quarantined-files.txt 2008-04-24 01:54:46
ComboFix2.txt 2008-04-23 21:00:14
Pre-Run: 21,510,348,800 bytes free
Post-Run: 21,494,689,792 bytes free
266 --- E O F --- 2008-04-23 09:40:34