First of all on my C: drive ComboFix isn't in a folder called "ComboFix", it's in a folder called "Qoobox" which threw me for a few mins, lol.
Contents of c:\Qoobox\ComboFix3.txt:-
ComboFix 08-11-06.01 - Kelly 2008-11-07 14:14:07.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.344 [GMT 0:00]
Running from: c:\documents and settings\Kelly\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kelly\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk1.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk2.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk23.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk24.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk25.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk26.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk27.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk28.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk49.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk50.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk51.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk52.zip
c:\documents and settings\Kelly\Desktop\requested-files[2008-11-05_15_04].cab
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[10].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[11].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[12].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[9].exe
c:\windows\system32\tmpacj1.exe
c:\windows\system32\tmpxr_12757299320.bk
c:\windows\system32\tmpxr_258801703886.bk
c:\windows\system32\tmpxr_29906868557.bk
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk1.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk2.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk23.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk24.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk25.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk26.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk27.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk28.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk49.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk50.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk51.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk52.zip
c:\documents and settings\Kelly\Desktop\requested-files[2008-11-05_15_04].cab
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[10].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[11].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[12].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[9].exe
c:\windows\system32\tmpacj1.exe
c:\windows\system32\tmpxr_12757299320.bk
c:\windows\system32\tmpxr_258801703886.bk
c:\windows\system32\tmpxr_29906868557.bk
.
--------------- FCopy ---------------
c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\svchost.exe --> c:\windows\system32\svchost.exe
c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\svchost.exe --> c:\windows\system32\dllcache\svchost.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DHCPSRV
-------\Service_dhcpsrv
((((((((((((((((((((((((( Files Created from 2008-10-07 to 2008-11-07 )))))))))))))))))))))))))))))))
.
2008-11-07 14:19 . 2008-11-07 14:19 <DIR> d-------- c:\windows\systum32
2008-11-07 14:19 . 2008-11-07 14:19 <DIR> d-------- c:\windows\systmm32
2008-11-07 14:19 . 2008-11-07 14:19 <DIR> d-------- c:\windows\system32\dri~ers
2008-11-07 14:19 . 2008-11-07 14:19 <DIR> d-------- c:\windows\{ystem32
2008-11-07 14:14 . 2008-04-14 00:12 14,336 --a--c--- c:\windows\system32\dllcache\svchost.exe
2008-11-06 14:43 . 2008-11-06 15:26 <DIR> d-------- c:\program files\EsetOnlineScanner
2008-11-04 14:40 . 2008-11-04 14:41 <DIR> d-------- C:\rsit
2008-10-30 14:18 . 2008-10-30 14:18 <DIR> d-------- c:\program files\Lavasoft
2008-10-30 14:18 . 2008-10-30 14:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-10-30 14:16 . 2008-10-30 14:16 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-10-29 12:48 . 2008-10-29 12:48 <DIR> d-------- c:\documents and settings\Kelly\Application Data\InstallShield
2008-10-28 13:58 . 2008-10-28 13:58 <DIR> d-------- c:\windows\Sun
2008-10-28 13:55 . 2008-10-28 13:55 <DIR> d-------- c:\program files\Java
2008-10-28 13:55 . 2008-10-28 13:55 410,976 --a------ c:\windows\system32\deploytk.dll
2008-10-28 13:55 . 2008-10-28 13:55 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-10-28 13:51 . 2008-10-28 13:51 0 --a------ c:\windows\nsreg.dat
2008-10-28 13:13 . 2008-11-04 14:41 <DIR> d-------- c:\program files\Trend Micro
2008-10-28 10:25 . 2008-10-28 10:25 16 --a------ c:\windows\system\cmicnfg.ini
2008-10-27 18:25 . 2008-10-30 15:47 <DIR> d--h----- C:\$AVG8.VAULT$
2008-10-27 18:12 . 2008-10-27 18:12 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys
2008-10-27 18:12 . 2008-10-27 18:12 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-10-27 18:11 . 2008-10-29 09:18 <DIR> d-------- c:\windows\system32\drivers\Avg
2008-10-27 18:11 . 2008-10-27 18:11 <DIR> d-------- c:\program files\AVG
2008-10-27 18:11 . 2008-10-30 14:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2008-10-27 18:11 . 2008-10-27 18:11 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-10-27 17:49 . 2008-10-27 17:49 459 --a------ c:\windows\wininit.ini
2008-10-27 16:04 . 2008-10-27 16:10 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-10-27 16:04 . 2008-10-29 13:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-27 16:00 . 2008-10-27 16:00 <DIR> d---s---- c:\documents and settings\Administrator\UserData
2008-10-27 15:59 . 2008-10-27 18:12 <DIR> d-------- c:\documents and settings\Administrator
2008-10-27 15:45 . 2008-10-27 15:45 <DIR> d-------- c:\windows\system32\LogFiles
2008-10-16 16:10 . 2008-10-16 16:22 <DIR> d-------- c:\program files\Microsoft Windows OneCare Live
2008-10-16 09:24 . 2008-10-16 09:24 <DIR> d-------- c:\program files\ParetoLogic
2008-10-16 09:24 . 2008-10-16 09:24 <DIR> d-------- c:\program files\Common Files\ParetoLogic
2008-10-16 09:24 . 2008-10-16 09:24 <DIR> d-------- c:\documents and settings\Kelly\Application Data\ParetoLogic
2008-10-16 09:24 . 2008-10-16 09:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\ParetoLogic
2008-10-16 09:24 . 2008-10-16 09:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations
2008-10-15 18:09 . 2007-04-19 20:33 11,634 --------- c:\windows\hpomdl11.dat.temp
2008-10-15 18:04 . 2008-05-25 14:37 117,949 --------- c:\windows\hpoins11.dat.temp
2008-10-15 18:04 . 2007-04-19 20:33 11,634 --------- c:\windows\hpomdl11.dat
2008-10-14 16:29 . 2008-10-29 09:14 <DIR> d-------- c:\windows\system32\1024
2008-10-14 16:29 . 2008-10-14 16:29 108,336 --a------ c:\windows\system32\MSWINSCK.OCX
2008-10-11 10:58 . 2008-10-11 10:58 221 --a------ c:\windows\NCLogConfig.ini
2008-10-07 18:36 . 2008-11-04 21:27 <DIR> d--hs---- C:\temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-29 12:46 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-15 17:59 --------- d-----w c:\program files\Common Files\HP
2008-10-11 10:58 --------- d-----w c:\documents and settings\Kelly\Application Data\HP
2008-10-05 12:27 --------- d-----w c:\documents and settings\Kelly\Application Data\Virgin Broadband
2008-10-05 12:24 31,517 ----a-w c:\documents and settings\All Users\Application Data\Firewall.dat
2008-10-05 12:24 3,728 ----a-w c:\documents and settings\All Users\Application Data\AdBlocker.dat
2008-10-05 12:24 276 ----a-w c:\documents and settings\Kelly\Application Data\Privacy.dat
2008-10-05 12:24 242 ----a-w c:\documents and settings\All Users\Application Data\Spyware.dat
2008-10-05 12:24 210 ----a-w c:\documents and settings\All Users\Application Data\Freedom.dat
2008-10-05 12:02 283 ----a-w c:\documents and settings\All Users\Application Data\ActivationInfo.dat
2008-10-05 12:02 2,977 ----a-w c:\documents and settings\All Users\Application Data\Services.dat
2008-10-05 12:01 18,326 ----a-w c:\documents and settings\All Users\Application Data\PartnerConfig.dat
2008-03-18 18:16 861 ----a-w c:\documents and settings\All Users\Application Data\Virus.dat
2008-03-18 18:16 133 ----a-w c:\documents and settings\All Users\Application Data\AvQuarantine.dat
2006-10-17 10:11 13,487 ----a-w c:\documents and settings\All Users\Application Data\AdManager.dat
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\system32\1024 ----
2008-10-16 10:51 1332 --a------ c:\windows\system32\1024\a
((((((((((((((((((((((((((((( snapshot@2008-11-04_21.55.26.21 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-04 21:45:50 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-11-07 13:46:48 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-11-04 21:45:50 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-07 13:46:48 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-11-04 21:45:50 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-07 13:46:48 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-10-29 09:08:04 2,620 ----a-w c:\windows\system32\d3d9caps.dat
+ 2008-11-05 16:23:54 2,620 ----a-w c:\windows\system32\d3d9caps.dat
+ 2007-07-27 15:49:02 196,683 ----a-w c:\windows\system32\lnod32apiA.dll
+ 2007-07-27 15:49:02 225,355 ----a-w c:\windows\system32\lnod32apiW.dll
+ 2005-12-05 20:25:22 139,264 ----a-w c:\windows\system32\lnod32umc.dll
+ 2005-12-05 13:37:10 106,496 ----a-w c:\windows\system32\lnod32upd.dll
+ 2007-08-02 18:11:28 253,952 ----a-w c:\windows\system32\OnlineScannerDLLA.dll
+ 2007-08-02 18:11:14 241,664 ----a-w c:\windows\system32\OnlineScannerDLLW.dll
+ 2007-08-06 13:17:40 19,456 ----a-w c:\windows\system32\OnlineScannerLang.dll
+ 2007-06-13 11:10:34 77,824 ----a-w c:\windows\system32\OnlineScannerUninstaller.exe
+ 2004-12-07 11:11:34 258,352 ----a-w c:\windows\system32\unicows.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-02-20 356352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 376912]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [BU]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-19 286720]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-10-27 1234712]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-28 136600]
"Cmaudio"="cmicnfg.cpl" [BU]
"PCTVOICE"="pctspk.exe" [2008-03-13 c:\windows\system32\pctspk.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-10-27 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-10-27 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-10-27 76040]
R2 JavaQuickStarterService;Java Quick Starter;c:\program files\Java\jre6\bin\jqs.exe [2008-10-28 152984]
R2 usbdisk;usbdisk;c:\windows\system32\usbdisk.sys [2006-02-28 2176]
S3 s217bus;Sony Ericsson Device 217 driver (WDM);c:\windows\system32\DRIVERS\s217bus.sys [2007-11-02 83496]
S3 s217mdfl;Sony Ericsson Device 217 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s217mdfl.sys [2007-11-02 15016]
S3 s217mdm;Sony Ericsson Device 217 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s217mdm.sys [2007-11-02 109992]
S3 s217mgmt;Sony Ericsson Device 217 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s217mgmt.sys [2007-11-02 103976]
S3 s217nd5;Sony Ericsson Device 217 USB Ethernet Emulation SEMC217 (NDIS);c:\windows\system32\DRIVERS\s217nd5.sys [2007-11-02 24872]
S3 s217obex;Sony Ericsson Device 217 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s217obex.sys [2007-11-02 100008]
S3 s217unic;Sony Ericsson Device 217 USB Ethernet Emulation SEMC217 (WDM);c:\windows\system32\DRIVERS\s217unic.sys [2007-11-02 105896]
Start Pending2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-10-27 875288]
.
Contents of the 'Scheduled Tasks' folder
2008-07-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
2008-10-28 c:\windows\Tasks\ParetoLogic Registration.job
- c:\windows\system32\rundll32.exe [2006-02-28 12:00]
2008-10-16 c:\windows\Tasks\ParetoLogic Update.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2007-09-18 23:55]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-07 14:19:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: c:\windows\system32\winlogon.exe
-> c:\windows\system32\tsd32.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\MSI\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-11-07 14:23:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-07 14:23:50
ComboFix2.txt 2008-11-04 21:57:02
Pre-Run: 30,692,745,216 bytes free
Post-Run: 30,775,767,040 bytes free
234 --- E O F --- 2008-09-18 07:38:26
Contents of C:\Qoobox\COmboFix-quarantined-files.txt:-
2006-02-28 12:00:00 A------- 282 C:\Qoobox\Quarantine\C\WINDOWS\Install.txt.vir
2006-02-28 12:00:00 A------- 282 C:\Qoobox\Quarantine\C\WINDOWS\system32\Install.txt.vir
2006-02-28 12:00:00 A------- 14,336 C:\Qoobox\Quarantine\C\WINDOWS\system32\svchost.exe.vir
2006-02-28 12:00:00 A------- 45,568 C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_12757299320.bk.vir
2006-02-28 12:00:00 A------- 45,568 C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_258801703886.bk.vir
2006-02-28 12:00:00 A------- 45,568 C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_29906868557.bk.vir
2006-02-28 12:00:00 A------- 46,080 C:\Qoobox\Quarantine\C\WINDOWS\system32\mabidwe.exe.vir
2008-09-22 12:34:34 A------- 896 C:\Qoobox\Quarantine\C\WINDOWS\tawisys.ini.vir
2008-09-22 12:34:34 A------- 33,280 C:\Qoobox\Quarantine\C\WINDOWS\system32\inf\svchoct.exe.vir
2008-09-22 12:35:20 A------- 177 C:\Qoobox\Quarantine\C\WINDOWS\system32\mywfhit.ini.vir
2008-10-14 16:37:48 A------- 1,785 C:\Qoobox\Quarantine\C\WINDOWS\IE4 Error Log.txt.vir
2008-10-16 10:51:43 A------- 1,332 C:\Qoobox\Quarantine\C\WINDOWS\system32\1024\a.vir
2008-10-16 11:19:51 A------- 160 C:\Qoobox\Quarantine\C\AutoRun.inf.vir
2008-10-19 10:09:31 A------- 197,632 C:\Qoobox\Quarantine\C\temp\svchost.exe.vir
2008-10-20 16:01:27 A------- 591,360 C:\Qoobox\Quarantine\C\WINDOWS\system32\service.exe.vir
2008-10-20 16:01:39 A------- 92 C:\Qoobox\Quarantine\C\WINDOWS\system32\Deleteme.bat.vir
2008-10-20 19:10:40 A------- 25,088 C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[9].exe.vir
2008-10-20 19:44:20 A------- 25,088 C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[10].exe.vir
2008-10-21 08:01:31 A------- 25,088 C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[11].exe.vir
2008-10-21 09:58:43 A------- 25,088 C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[12].exe.vir
2008-10-27 17:06:36 A------- 45,513 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk2.zip.vir
2008-10-27 17:06:36 A------- 46,541 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk1.zip.vir
2008-10-27 17:06:40 A------- 46,544 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk23.zip.vir
2008-10-27 17:06:41 A------- 46,036 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk26.zip.vir
2008-10-27 17:06:41 A------- 46,545 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk24.zip.vir
2008-10-27 17:06:41 A------- 46,545 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk25.zip.vir
2008-10-28 12:50:19 A------- 46,538 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk28.zip.vir
2008-10-28 12:50:19 A------- 46,541 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk27.zip.vir
2008-10-28 12:50:23 A------- 47,056 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk50.zip.vir
2008-10-28 12:50:23 A------- 47,057 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk49.zip.vir
2008-10-28 12:50:23 A------- 47,568 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk51.zip.vir
2008-10-28 12:50:24 A------- 46,036 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk52.zip.vir
2008-10-28 16:51:56 A------- 388,608 C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpacj1.exe.vir
2008-10-29 09:14:42 A------- 701 C:\Qoobox\Quarantine\C\WINDOWS\system32\mywfhit.ini.tmp.vir
2008-11-04 21:09:05 A------- 486 C:\Qoobox\Quarantine\catchme.log
2008-11-04 21:29:26 A------- 15,410 C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2008-11-04 21:29:49 A------- 816 C:\Qoobox\Quarantine\Registry_backups\Legacy_AFISICX.reg.dat
2008-11-04 21:29:49 A------- 816 C:\Qoobox\Quarantine\Registry_backups\Legacy_MABIDWE.reg.dat
2008-11-04 21:29:49 A------- 816 C:\Qoobox\Quarantine\Registry_backups\Legacy_NOYTCYR.reg.dat
2008-11-04 21:29:49 A------- 816 C:\Qoobox\Quarantine\Registry_backups\Legacy_ROYTCTM.reg.dat
2008-11-04 21:29:49 A------- 816 C:\Qoobox\Quarantine\Registry_backups\Legacy_SOXPECA.reg.dat
2008-11-04 21:29:49 A------- 822 C:\Qoobox\Quarantine\Registry_backups\Legacy_SEIUCTOL.reg.dat
2008-11-04 21:29:49 A------- 824 C:\Qoobox\Quarantine\Registry_backups\Legacy_TDYDOWKC.reg.dat
2008-11-04 21:29:49 A------- 824 C:\Qoobox\Quarantine\Registry_backups\Legacy_WSLDOEKD.reg.dat
2008-11-04 21:29:50 A------- 5,400 C:\Qoobox\Quarantine\Registry_backups\Service_seiuctol.reg.dat
2008-11-04 21:41:48 A------- 2 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-CFSServ.exe.reg.dat
2008-11-04 21:41:48 A------- 2 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-NDSTray.exe.reg.dat
2008-11-04 21:41:48 A------- 2 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TFncKy.reg.dat
2008-11-04 21:41:55 A------- 122 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-yt8a.reg.dat
2008-11-04 21:41:55 A------- 181 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-ISUSPM.reg.dat
2008-11-04 21:41:56 A------- 125 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-Cmaudio.reg.dat
2008-11-04 21:41:58 A------- 193 C:\Qoobox\Quarantine\Registry_backups\HKLM-Explorer_Run-minyust.reg.dat
2008-11-05 15:04:49 A------- 8,076 C:\Qoobox\Quarantine\C\Documents and Settings\Kelly\Desktop\requested-files[2008-11-05_15_04].cab.vir
2008-11-07 14:14:05 AC------ 14,336 C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache\svchost.exe.vir
2008-11-07 14:15:58 A------- 806 C:\Qoobox\Quarantine\Registry_backups\Legacy_DHCPSRV.reg.dat
2008-11-07 14:15:58 A------- 2,656 C:\Qoobox\Quarantine\Registry_backups\Service_dhcpsrv.reg.dat
Contents of c:\Qoobox\ComboFix3.txt:-
ComboFix 08-11-06.01 - Kelly 2008-11-07 14:14:07.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.344 [GMT 0:00]
Running from: c:\documents and settings\Kelly\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kelly\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk1.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk2.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk23.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk24.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk25.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk26.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk27.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk28.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk49.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk50.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk51.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk52.zip
c:\documents and settings\Kelly\Desktop\requested-files[2008-11-05_15_04].cab
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[10].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[11].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[12].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[9].exe
c:\windows\system32\tmpacj1.exe
c:\windows\system32\tmpxr_12757299320.bk
c:\windows\system32\tmpxr_258801703886.bk
c:\windows\system32\tmpxr_29906868557.bk
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk1.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk2.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk23.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk24.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk25.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk26.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk27.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk28.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk49.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk50.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk51.zip
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk52.zip
c:\documents and settings\Kelly\Desktop\requested-files[2008-11-05_15_04].cab
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[10].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[11].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[12].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[9].exe
c:\windows\system32\tmpacj1.exe
c:\windows\system32\tmpxr_12757299320.bk
c:\windows\system32\tmpxr_258801703886.bk
c:\windows\system32\tmpxr_29906868557.bk
.
--------------- FCopy ---------------
c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\svchost.exe --> c:\windows\system32\svchost.exe
c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\svchost.exe --> c:\windows\system32\dllcache\svchost.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DHCPSRV
-------\Service_dhcpsrv
((((((((((((((((((((((((( Files Created from 2008-10-07 to 2008-11-07 )))))))))))))))))))))))))))))))
.
2008-11-07 14:19 . 2008-11-07 14:19 <DIR> d-------- c:\windows\systum32
2008-11-07 14:19 . 2008-11-07 14:19 <DIR> d-------- c:\windows\systmm32
2008-11-07 14:19 . 2008-11-07 14:19 <DIR> d-------- c:\windows\system32\dri~ers
2008-11-07 14:19 . 2008-11-07 14:19 <DIR> d-------- c:\windows\{ystem32
2008-11-07 14:14 . 2008-04-14 00:12 14,336 --a--c--- c:\windows\system32\dllcache\svchost.exe
2008-11-06 14:43 . 2008-11-06 15:26 <DIR> d-------- c:\program files\EsetOnlineScanner
2008-11-04 14:40 . 2008-11-04 14:41 <DIR> d-------- C:\rsit
2008-10-30 14:18 . 2008-10-30 14:18 <DIR> d-------- c:\program files\Lavasoft
2008-10-30 14:18 . 2008-10-30 14:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-10-30 14:16 . 2008-10-30 14:16 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-10-29 12:48 . 2008-10-29 12:48 <DIR> d-------- c:\documents and settings\Kelly\Application Data\InstallShield
2008-10-28 13:58 . 2008-10-28 13:58 <DIR> d-------- c:\windows\Sun
2008-10-28 13:55 . 2008-10-28 13:55 <DIR> d-------- c:\program files\Java
2008-10-28 13:55 . 2008-10-28 13:55 410,976 --a------ c:\windows\system32\deploytk.dll
2008-10-28 13:55 . 2008-10-28 13:55 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-10-28 13:51 . 2008-10-28 13:51 0 --a------ c:\windows\nsreg.dat
2008-10-28 13:13 . 2008-11-04 14:41 <DIR> d-------- c:\program files\Trend Micro
2008-10-28 10:25 . 2008-10-28 10:25 16 --a------ c:\windows\system\cmicnfg.ini
2008-10-27 18:25 . 2008-10-30 15:47 <DIR> d--h----- C:\$AVG8.VAULT$
2008-10-27 18:12 . 2008-10-27 18:12 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys
2008-10-27 18:12 . 2008-10-27 18:12 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-10-27 18:11 . 2008-10-29 09:18 <DIR> d-------- c:\windows\system32\drivers\Avg
2008-10-27 18:11 . 2008-10-27 18:11 <DIR> d-------- c:\program files\AVG
2008-10-27 18:11 . 2008-10-30 14:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2008-10-27 18:11 . 2008-10-27 18:11 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-10-27 17:49 . 2008-10-27 17:49 459 --a------ c:\windows\wininit.ini
2008-10-27 16:04 . 2008-10-27 16:10 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-10-27 16:04 . 2008-10-29 13:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-27 16:00 . 2008-10-27 16:00 <DIR> d---s---- c:\documents and settings\Administrator\UserData
2008-10-27 15:59 . 2008-10-27 18:12 <DIR> d-------- c:\documents and settings\Administrator
2008-10-27 15:45 . 2008-10-27 15:45 <DIR> d-------- c:\windows\system32\LogFiles
2008-10-16 16:10 . 2008-10-16 16:22 <DIR> d-------- c:\program files\Microsoft Windows OneCare Live
2008-10-16 09:24 . 2008-10-16 09:24 <DIR> d-------- c:\program files\ParetoLogic
2008-10-16 09:24 . 2008-10-16 09:24 <DIR> d-------- c:\program files\Common Files\ParetoLogic
2008-10-16 09:24 . 2008-10-16 09:24 <DIR> d-------- c:\documents and settings\Kelly\Application Data\ParetoLogic
2008-10-16 09:24 . 2008-10-16 09:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\ParetoLogic
2008-10-16 09:24 . 2008-10-16 09:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations
2008-10-15 18:09 . 2007-04-19 20:33 11,634 --------- c:\windows\hpomdl11.dat.temp
2008-10-15 18:04 . 2008-05-25 14:37 117,949 --------- c:\windows\hpoins11.dat.temp
2008-10-15 18:04 . 2007-04-19 20:33 11,634 --------- c:\windows\hpomdl11.dat
2008-10-14 16:29 . 2008-10-29 09:14 <DIR> d-------- c:\windows\system32\1024
2008-10-14 16:29 . 2008-10-14 16:29 108,336 --a------ c:\windows\system32\MSWINSCK.OCX
2008-10-11 10:58 . 2008-10-11 10:58 221 --a------ c:\windows\NCLogConfig.ini
2008-10-07 18:36 . 2008-11-04 21:27 <DIR> d--hs---- C:\temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-29 12:46 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-15 17:59 --------- d-----w c:\program files\Common Files\HP
2008-10-11 10:58 --------- d-----w c:\documents and settings\Kelly\Application Data\HP
2008-10-05 12:27 --------- d-----w c:\documents and settings\Kelly\Application Data\Virgin Broadband
2008-10-05 12:24 31,517 ----a-w c:\documents and settings\All Users\Application Data\Firewall.dat
2008-10-05 12:24 3,728 ----a-w c:\documents and settings\All Users\Application Data\AdBlocker.dat
2008-10-05 12:24 276 ----a-w c:\documents and settings\Kelly\Application Data\Privacy.dat
2008-10-05 12:24 242 ----a-w c:\documents and settings\All Users\Application Data\Spyware.dat
2008-10-05 12:24 210 ----a-w c:\documents and settings\All Users\Application Data\Freedom.dat
2008-10-05 12:02 283 ----a-w c:\documents and settings\All Users\Application Data\ActivationInfo.dat
2008-10-05 12:02 2,977 ----a-w c:\documents and settings\All Users\Application Data\Services.dat
2008-10-05 12:01 18,326 ----a-w c:\documents and settings\All Users\Application Data\PartnerConfig.dat
2008-03-18 18:16 861 ----a-w c:\documents and settings\All Users\Application Data\Virus.dat
2008-03-18 18:16 133 ----a-w c:\documents and settings\All Users\Application Data\AvQuarantine.dat
2006-10-17 10:11 13,487 ----a-w c:\documents and settings\All Users\Application Data\AdManager.dat
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\system32\1024 ----
2008-10-16 10:51 1332 --a------ c:\windows\system32\1024\a
((((((((((((((((((((((((((((( snapshot@2008-11-04_21.55.26.21 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-04 21:45:50 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-11-07 13:46:48 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-11-04 21:45:50 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-07 13:46:48 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-11-04 21:45:50 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-07 13:46:48 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-10-29 09:08:04 2,620 ----a-w c:\windows\system32\d3d9caps.dat
+ 2008-11-05 16:23:54 2,620 ----a-w c:\windows\system32\d3d9caps.dat
+ 2007-07-27 15:49:02 196,683 ----a-w c:\windows\system32\lnod32apiA.dll
+ 2007-07-27 15:49:02 225,355 ----a-w c:\windows\system32\lnod32apiW.dll
+ 2005-12-05 20:25:22 139,264 ----a-w c:\windows\system32\lnod32umc.dll
+ 2005-12-05 13:37:10 106,496 ----a-w c:\windows\system32\lnod32upd.dll
+ 2007-08-02 18:11:28 253,952 ----a-w c:\windows\system32\OnlineScannerDLLA.dll
+ 2007-08-02 18:11:14 241,664 ----a-w c:\windows\system32\OnlineScannerDLLW.dll
+ 2007-08-06 13:17:40 19,456 ----a-w c:\windows\system32\OnlineScannerLang.dll
+ 2007-06-13 11:10:34 77,824 ----a-w c:\windows\system32\OnlineScannerUninstaller.exe
+ 2004-12-07 11:11:34 258,352 ----a-w c:\windows\system32\unicows.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-02-20 356352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 376912]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [BU]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-19 286720]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-10-27 1234712]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-28 136600]
"Cmaudio"="cmicnfg.cpl" [BU]
"PCTVOICE"="pctspk.exe" [2008-03-13 c:\windows\system32\pctspk.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-10-27 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-10-27 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-10-27 76040]
R2 JavaQuickStarterService;Java Quick Starter;c:\program files\Java\jre6\bin\jqs.exe [2008-10-28 152984]
R2 usbdisk;usbdisk;c:\windows\system32\usbdisk.sys [2006-02-28 2176]
S3 s217bus;Sony Ericsson Device 217 driver (WDM);c:\windows\system32\DRIVERS\s217bus.sys [2007-11-02 83496]
S3 s217mdfl;Sony Ericsson Device 217 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s217mdfl.sys [2007-11-02 15016]
S3 s217mdm;Sony Ericsson Device 217 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s217mdm.sys [2007-11-02 109992]
S3 s217mgmt;Sony Ericsson Device 217 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s217mgmt.sys [2007-11-02 103976]
S3 s217nd5;Sony Ericsson Device 217 USB Ethernet Emulation SEMC217 (NDIS);c:\windows\system32\DRIVERS\s217nd5.sys [2007-11-02 24872]
S3 s217obex;Sony Ericsson Device 217 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s217obex.sys [2007-11-02 100008]
S3 s217unic;Sony Ericsson Device 217 USB Ethernet Emulation SEMC217 (WDM);c:\windows\system32\DRIVERS\s217unic.sys [2007-11-02 105896]
Start Pending2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-10-27 875288]
.
Contents of the 'Scheduled Tasks' folder
2008-07-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
2008-10-28 c:\windows\Tasks\ParetoLogic Registration.job
- c:\windows\system32\rundll32.exe [2006-02-28 12:00]
2008-10-16 c:\windows\Tasks\ParetoLogic Update.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2007-09-18 23:55]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-07 14:19:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: c:\windows\system32\winlogon.exe
-> c:\windows\system32\tsd32.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\MSI\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-11-07 14:23:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-07 14:23:50
ComboFix2.txt 2008-11-04 21:57:02
Pre-Run: 30,692,745,216 bytes free
Post-Run: 30,775,767,040 bytes free
234 --- E O F --- 2008-09-18 07:38:26
Contents of C:\Qoobox\COmboFix-quarantined-files.txt:-
2006-02-28 12:00:00 A------- 282 C:\Qoobox\Quarantine\C\WINDOWS\Install.txt.vir
2006-02-28 12:00:00 A------- 282 C:\Qoobox\Quarantine\C\WINDOWS\system32\Install.txt.vir
2006-02-28 12:00:00 A------- 14,336 C:\Qoobox\Quarantine\C\WINDOWS\system32\svchost.exe.vir
2006-02-28 12:00:00 A------- 45,568 C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_12757299320.bk.vir
2006-02-28 12:00:00 A------- 45,568 C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_258801703886.bk.vir
2006-02-28 12:00:00 A------- 45,568 C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_29906868557.bk.vir
2006-02-28 12:00:00 A------- 46,080 C:\Qoobox\Quarantine\C\WINDOWS\system32\mabidwe.exe.vir
2008-09-22 12:34:34 A------- 896 C:\Qoobox\Quarantine\C\WINDOWS\tawisys.ini.vir
2008-09-22 12:34:34 A------- 33,280 C:\Qoobox\Quarantine\C\WINDOWS\system32\inf\svchoct.exe.vir
2008-09-22 12:35:20 A------- 177 C:\Qoobox\Quarantine\C\WINDOWS\system32\mywfhit.ini.vir
2008-10-14 16:37:48 A------- 1,785 C:\Qoobox\Quarantine\C\WINDOWS\IE4 Error Log.txt.vir
2008-10-16 10:51:43 A------- 1,332 C:\Qoobox\Quarantine\C\WINDOWS\system32\1024\a.vir
2008-10-16 11:19:51 A------- 160 C:\Qoobox\Quarantine\C\AutoRun.inf.vir
2008-10-19 10:09:31 A------- 197,632 C:\Qoobox\Quarantine\C\temp\svchost.exe.vir
2008-10-20 16:01:27 A------- 591,360 C:\Qoobox\Quarantine\C\WINDOWS\system32\service.exe.vir
2008-10-20 16:01:39 A------- 92 C:\Qoobox\Quarantine\C\WINDOWS\system32\Deleteme.bat.vir
2008-10-20 19:10:40 A------- 25,088 C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[9].exe.vir
2008-10-20 19:44:20 A------- 25,088 C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[10].exe.vir
2008-10-21 08:01:31 A------- 25,088 C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[11].exe.vir
2008-10-21 09:58:43 A------- 25,088 C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XQ27EDWS\Cracked[12].exe.vir
2008-10-27 17:06:36 A------- 45,513 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk2.zip.vir
2008-10-27 17:06:36 A------- 46,541 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk1.zip.vir
2008-10-27 17:06:40 A------- 46,544 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk23.zip.vir
2008-10-27 17:06:41 A------- 46,036 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk26.zip.vir
2008-10-27 17:06:41 A------- 46,545 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk24.zip.vir
2008-10-27 17:06:41 A------- 46,545 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk25.zip.vir
2008-10-28 12:50:19 A------- 46,538 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk28.zip.vir
2008-10-28 12:50:19 A------- 46,541 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk27.zip.vir
2008-10-28 12:50:23 A------- 47,056 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk50.zip.vir
2008-10-28 12:50:23 A------- 47,057 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk49.zip.vir
2008-10-28 12:50:23 A------- 47,568 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk51.zip.vir
2008-10-28 12:50:24 A------- 46,036 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfrtk52.zip.vir
2008-10-28 16:51:56 A------- 388,608 C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpacj1.exe.vir
2008-10-29 09:14:42 A------- 701 C:\Qoobox\Quarantine\C\WINDOWS\system32\mywfhit.ini.tmp.vir
2008-11-04 21:09:05 A------- 486 C:\Qoobox\Quarantine\catchme.log
2008-11-04 21:29:26 A------- 15,410 C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2008-11-04 21:29:49 A------- 816 C:\Qoobox\Quarantine\Registry_backups\Legacy_AFISICX.reg.dat
2008-11-04 21:29:49 A------- 816 C:\Qoobox\Quarantine\Registry_backups\Legacy_MABIDWE.reg.dat
2008-11-04 21:29:49 A------- 816 C:\Qoobox\Quarantine\Registry_backups\Legacy_NOYTCYR.reg.dat
2008-11-04 21:29:49 A------- 816 C:\Qoobox\Quarantine\Registry_backups\Legacy_ROYTCTM.reg.dat
2008-11-04 21:29:49 A------- 816 C:\Qoobox\Quarantine\Registry_backups\Legacy_SOXPECA.reg.dat
2008-11-04 21:29:49 A------- 822 C:\Qoobox\Quarantine\Registry_backups\Legacy_SEIUCTOL.reg.dat
2008-11-04 21:29:49 A------- 824 C:\Qoobox\Quarantine\Registry_backups\Legacy_TDYDOWKC.reg.dat
2008-11-04 21:29:49 A------- 824 C:\Qoobox\Quarantine\Registry_backups\Legacy_WSLDOEKD.reg.dat
2008-11-04 21:29:50 A------- 5,400 C:\Qoobox\Quarantine\Registry_backups\Service_seiuctol.reg.dat
2008-11-04 21:41:48 A------- 2 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-CFSServ.exe.reg.dat
2008-11-04 21:41:48 A------- 2 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-NDSTray.exe.reg.dat
2008-11-04 21:41:48 A------- 2 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TFncKy.reg.dat
2008-11-04 21:41:55 A------- 122 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-yt8a.reg.dat
2008-11-04 21:41:55 A------- 181 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-ISUSPM.reg.dat
2008-11-04 21:41:56 A------- 125 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-Cmaudio.reg.dat
2008-11-04 21:41:58 A------- 193 C:\Qoobox\Quarantine\Registry_backups\HKLM-Explorer_Run-minyust.reg.dat
2008-11-05 15:04:49 A------- 8,076 C:\Qoobox\Quarantine\C\Documents and Settings\Kelly\Desktop\requested-files[2008-11-05_15_04].cab.vir
2008-11-07 14:14:05 AC------ 14,336 C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache\svchost.exe.vir
2008-11-07 14:15:58 A------- 806 C:\Qoobox\Quarantine\Registry_backups\Legacy_DHCPSRV.reg.dat
2008-11-07 14:15:58 A------- 2,656 C:\Qoobox\Quarantine\Registry_backups\Service_dhcpsrv.reg.dat