ComboFix 08-04-11.5 - Gary 2008-04-12 12:30:48.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.584 [GMT -4:00]
Running from: C:\Documents and Settings\Gary\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Gary\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Program Files\Trend Micro\HijackThis\backups\backup-20080411-133327-958.dll
C:\WINDOWS\system32\anxuqrpd.dll
C:\WINDOWS\system32\fodivmlq.exe
C:\WINDOWS\system32\mxynapwx.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Trend Micro\HijackThis\backups\backup-20080411-133327-958.dll
C:\VundoFix Backups
C:\WINDOWS\system32\anxuqrpd.dll
C:\WINDOWS\system32\fodivmlq.exe
C:\WINDOWS\system32\mxynapwx.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-12 to 2008-04-12 )))))))))))))))))))))))))))))))
.
2008-04-11 22:20 . 2008-04-11 22:20 50 --a------ C:\WINDOWS\qwimp.ini
2008-04-11 16:30 . 2008-04-11 16:30 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-04-11 00:35 . 2008-04-11 00:35 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-11 00:35 . 2008-04-11 00:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-10 03:49 . 2008-04-10 03:49 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-10 03:00 . 2008-04-11 01:30 153 --a------ C:\WINDOWS\wininit.ini
2008-04-10 02:01 . 2008-04-10 02:01 <DIR> d-------- C:\WINDOWS\resources
2008-04-10 01:48 . 2008-04-10 01:56 3,064 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-10 01:47 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-04-10 01:47 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-04-10 01:47 . 2008-03-29 00:19 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-10 01:47 . 2008-04-08 22:44 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-10 01:47 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-04-10 01:47 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-10 01:47 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-10 01:24 . 2008-04-10 01:24 98,304 --a------ C:\WINDOWS\system32\livulode.exe
2008-04-10 01:18 . 2008-04-10 01:18 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-04-10 00:33 . 2008-03-06 21:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-04-10 00:33 . 2008-03-06 21:32 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-04-10 00:33 . 2008-03-06 21:32 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-04-09 23:43 . 2008-04-09 23:43 2,591 --a------ C:\Program Files\instaler.exe
2008-04-09 22:44 . 2008-04-09 22:44 45,056 --a------ C:\WINDOWS\NCUNINST.EXE
2008-04-09 22:43 . 2008-04-09 22:43 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2008-04-09 22:43 . 2008-04-09 22:43 52 --a------ C:\WINDOWS\intuprof.ini
2008-04-09 22:41 . 2008-04-11 22:20 783 --a------ C:\WINDOWS\QUICKEN.INI
2008-04-09 22:40 . 2008-04-09 22:40 <DIR> d-------- C:\Program Files\Common Files\Intuit
2008-04-09 22:39 . 2008-04-11 22:20 <DIR> d-------- C:\Program Files\Quicken
2008-04-07 23:39 . 2008-04-10 01:37 <DIR> d-------- C:\Program Files\Cadsoft
2008-04-07 23:39 . 2008-04-07 23:39 0 --a------ C:\WINDOWS\system32\_r_a_p_.tmp
2008-04-06 19:45 . 2008-04-06 19:45 <DIR> d-------- C:\Documents and Settings\Taylor\Application Data\Yahoo!
2008-04-03 23:44 . 2008-04-03 23:44 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-04-03 22:33 . 2008-04-10 00:30 <DIR> d-------- C:\Program Files\Symantec
2008-04-03 22:33 . 2008-04-10 00:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-03 22:33 . 2008-04-03 23:36 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-04-03 22:33 . 2008-04-03 23:36 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-04-03 22:33 . 2008-04-03 23:36 10,740 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-04-03 22:33 . 2008-04-03 23:36 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-04-03 22:32 . 2008-04-11 21:35 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-04-03 16:42 . 2008-04-06 09:57 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Yahoo!
2008-04-03 16:38 . 2008-04-03 16:39 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\AVG7
2008-04-01 18:05 . 2008-04-03 21:43 <DIR> d-------- C:\Documents and Settings\Carissa\Application Data\Yahoo!
2008-04-01 18:03 . 2008-04-01 18:03 <DIR> d-------- C:\Documents and Settings\Carissa\Application Data\Apple Computer
2008-04-01 18:02 . 2008-04-03 21:29 <DIR> d-------- C:\Documents and Settings\Carissa\Application Data\AVG7
2008-03-31 21:12 . 2008-03-31 21:12 <DIR> d-------- C:\WINDOWS\Sun
2008-03-31 21:11 . 2008-03-31 21:11 <DIR> d-------- C:\Program Files\Java
2008-03-31 21:11 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-31 21:07 . 2008-03-31 21:07 <DIR> d-------- C:\Program Files\Common Files\Java
2008-03-31 21:02 . 2008-03-31 21:09 <DIR> d-------- C:\Documents and Settings\Gary\Application Data\Yahoo!
2008-03-31 20:57 . 2008-04-11 20:22 6,944 --a------ C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2008-03-31 20:56 . 2008-03-31 20:56 <DIR> d-------- C:\Program Files\Common Files\SureThing Shared
2008-03-31 20:56 . 2008-03-31 20:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\YAHOO
2008-03-31 20:52 . 2004-10-25 15:18 131,072 --a------ C:\WINDOWS\system32\ypclsp.dll
2008-03-31 20:52 . 2003-05-19 16:07 86,016 --a------ C:\WINDOWS\system32\YPcservice.exe
2008-03-31 20:20 . 2008-03-31 20:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-03-31 20:19 . 2008-04-03 22:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\yahoo!
2008-03-31 20:18 . 2002-01-05 07:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-03-31 20:18 . 2002-01-05 06:18 84,992 --a------ C:\WINDOWS\system32\ATL70.DLL
2008-03-31 20:18 . 2001-10-11 11:26 65,536 --a------ C:\WINDOWS\system32\YCRWin32.dll
2008-03-27 01:56 . 2008-03-27 02:02 <DIR> d-------- C:\Documents and Settings\Gary\Application Data\parentalcontrol
2008-03-27 01:37 . 2008-03-27 01:38 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-27 01:37 . 2008-03-27 01:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-27 01:15 . 2008-03-27 01:15 <DIR> d-------- C:\Documents and Settings\Gary\Application Data\GTek
2008-03-27 01:15 . 2008-03-27 01:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Gtek
2008-03-27 00:05 . 2008-04-03 17:36 <DIR> d-------- C:\Documents and Settings\Gary\Application Data\AVG7
2008-03-27 00:04 . 2008-03-27 00:04 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-27 00:04 . 2008-04-03 22:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-03-26 22:23 . 2008-03-27 01:30 <DIR> d-------- C:\Program Files\Google
2008-03-26 22:23 . 2008-04-12 12:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-03-26 22:01 . 2008-03-26 22:01 <DIR> d--hs---- C:\Documents and Settings\Gary\UserData
2008-03-24 14:08 . 2008-03-24 14:08 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-03-24 11:11 . 2008-04-09 17:48 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\AdobeUM
2008-03-20 22:12 . 2008-03-20 22:12 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Ahead
2008-03-19 22:59 . 2008-03-19 23:03 2,048 --a------ C:\WINDOWS\system32\win32xml.TX1
2008-03-19 22:49 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-03-19 22:30 . 2008-03-19 22:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
2008-03-19 22:23 . 2008-03-31 20:57 <DIR> d-------- C:\Program Files\Yahoo!
2008-03-19 22:23 . 2008-03-19 22:25 <DIR> d-------- C:\Program Files\Rogers
2008-03-15 23:26 . 2008-03-15 23:26 <DIR> d-------- C:\Documents and Settings\Gary\Application Data\Ahead
2008-03-15 23:26 . 2008-03-26 07:53 116 --a------ C:\WINDOWS\NeroDigital.ini
2008-03-15 23:25 . 2008-03-15 23:25 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2008-03-15 23:22 . 2008-03-15 23:22 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-03-15 23:22 . 2001-07-09 12:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-03-15 23:21 . 2005-07-06 11:12 2,973,696 --------- C:\WINDOWS\UNNeroVision.exe
2008-03-15 23:21 . 2005-10-24 10:23 192,817 --------- C:\WINDOWS\UNNeroVision.cfg
2008-03-15 23:21 . 2002-02-21 18:56 24,576 --a------ C:\WINDOWS\system32\msxml3a.dll
2008-03-15 23:20 . 2008-03-15 23:20 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-03-15 23:20 . 2008-03-15 23:22 <DIR> d-------- C:\Program Files\Ahead
2008-03-15 23:20 . 2008-03-15 23:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-03-15 23:20 . 2004-07-26 18:16 1,568,768 --a------ C:\WINDOWS\system32\ImagX7.dll
2008-03-15 23:20 . 2004-07-26 18:16 476,320 --a------ C:\WINDOWS\system32\ImagXpr7.dll
2008-03-15 23:20 . 2004-07-26 18:16 471,040 --a------ C:\WINDOWS\system32\ImagXRA7.dll
2008-03-15 23:20 . 2004-07-09 10:43 364,544 --a------ C:\WINDOWS\system32\TwnLib4.dll
2008-03-15 23:20 . 2004-07-26 18:16 262,144 --a------ C:\WINDOWS\system32\ImagXR7.dll
2008-03-15 23:20 . 2000-06-26 12:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-03-15 23:20 . 2001-06-26 09:15 38,912 --a------ C:\WINDOWS\system32\picn20.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-11 03:31 --------- d-----w C:\Program Files\Dell
2008-04-10 05:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-20 02:43 --------- d-----w C:\Program Files\UFile 2007
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-12 01:18 5 ----a-w C:\WINDOWS\system32\drivers\DELL_LAT_D600.MRK
2008-02-12 01:18 5 ----a-w C:\WINDOWS\system32\drivers\1028_DELL_LAT_D600.MRK
2008-02-12 01:17 --------- d-----w C:\Documents and Settings\Gary\Application Data\InstallShield
2008-02-12 01:13 --------- d-----w C:\Program Files\Intel
2008-02-12 01:13 --------- d-----w C:\Program Files\Apoint
2008-02-12 01:12 --------- d-----w C:\Program Files\ATI Technologies
2008-02-12 01:10 --------- d-----w C:\Program Files\CONEXANT
2008-02-12 01:09 --------- d-----w C:\Program Files\SigmaTel
2008-02-12 01:08 --------- d-----w C:\Program Files\Modem Helper
2008-02-12 01:08 --------- d-----w C:\Program Files\Digital Line Detect
2008-02-12 01:07 --------- d-----w C:\Program Files\Broadcom Advanced Control Suite
2008-02-12 01:07 --------- d-----w C:\Program Files\Broadcom
2008-02-12 01:06 --------- d-----w C:\Program Files\Common Files\InstallShield
.
((((((((((((((((((((((((((((( snapshot@2008-04-11_20.25.19.45 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-11-11 05:52:50 237,568 ----a-w C:\WINDOWS\system32\ati2cqag.dll
+ 2004-06-11 01:25:26 229,376 ----a-w C:\WINDOWS\system32\ati2cqag.dll
- 2005-11-11 06:49:44 252,416 ----a-w C:\WINDOWS\system32\ati2dvag.dll
+ 2004-06-11 02:57:24 207,360 ----a-w C:\WINDOWS\system32\ati2dvag.dll
- 2005-11-11 06:44:24 40,960 ----a-w C:\WINDOWS\system32\ati2edxx.dll
+ 2004-06-11 02:46:52 30,720 ----a-w C:\WINDOWS\system32\ati2edxx.dll
- 2005-11-11 06:44:14 47,616 ----a-w C:\WINDOWS\system32\ati2evxx.dll
+ 2004-06-11 02:46:34 86,016 ----a-w C:\WINDOWS\system32\ati2evxx.dll
- 2005-11-11 06:43:12 389,120 ----a-w C:\WINDOWS\system32\ati2evxx.exe
+ 2004-06-11 02:44:56 376,832 ----a-w C:\WINDOWS\system32\ati2evxx.exe
- 2005-11-11 06:44:30 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
+ 2004-06-11 02:47:00 65,536 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
- 2005-11-11 06:35:36 2,516,992 ----a-w C:\WINDOWS\system32\ati3duag.dll
+ 2004-06-11 02:31:30 2,155,680 ----a-w C:\WINDOWS\system32\ati3duag.dll
- 2005-11-11 06:42:48 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
+ 2004-06-11 02:44:28 81,920 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
- 2005-11-11 08:56:48 258,048 ----a-w C:\WINDOWS\system32\ATIDEMGR.dll
+ 2004-06-11 05:27:12 131,072 ----a-w C:\WINDOWS\system32\ATIDEMGR.dll
- 2005-11-11 09:34:30 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
+ 2004-06-11 05:54:10 294,912 ----a-w C:\WINDOWS\system32\atiiiexx.dll
- 2005-11-11 07:04:28 4,956,160 ----a-w C:\WINDOWS\system32\atioglxx.dll
+ 2004-06-11 03:43:20 6,524,928 ----a-w C:\WINDOWS\system32\atioglxx.dll
- 2005-11-11 06:44:48 110,592 ----a-w C:\WINDOWS\system32\atipdlxx.dll
+ 2004-06-11 02:47:28 118,784 ----a-w C:\WINDOWS\system32\atipdlxx.dll
- 2005-11-11 05:58:04 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
+ 2004-06-11 01:35:48 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
- 2005-11-11 06:29:52 1,090,240 ----a-w C:\WINDOWS\system32\ativvaxx.dll
+ 2004-06-11 01:51:36 518,240 ----a-w C:\WINDOWS\system32\ativvaxx.dll
- 2005-11-11 06:49:24 1,406,464 -c--a-w C:\WINDOWS\system32\dllcache\ati2mtag.sys
+ 2004-06-11 02:57:04 746,496 -c--a-w C:\WINDOWS\system32\dllcache\ati2mtag.sys
- 2005-11-11 06:49:24 1,406,464 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
+ 2004-06-11 02:57:04 746,496 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
- 2005-11-11 06:44:36 73,728 ----a-w C:\WINDOWS\system32\Oemdspif.dll
+ 2004-06-11 02:47:12 102,400 ----a-w C:\WINDOWS\system32\Oemdspif.dll
+ 2005-11-11 05:52:50 237,568 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\ati2cqag.dll
+ 2005-11-11 06:49:44 252,416 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\ati2dvag.dll
+ 2005-11-11 06:44:24 40,960 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\ati2edxx.dll
+ 2005-11-11 05:57:20 40,960 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\ati2erec.dll
+ 2005-11-11 06:44:14 47,616 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\ati2evxx.dll
+ 2005-11-11 06:43:12 389,120 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\ati2evxx.exe
+ 2005-11-11 06:44:30 26,112 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\Ati2mdxx.exe
+ 2005-11-11 06:49:24 1,406,464 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\ati2mtag.sys
+ 2005-11-11 06:35:36 2,516,992 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\ati3duag.dll
+ 2005-11-11 06:42:48 53,248 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\ATIDDC.DLL
+ 2005-11-11 08:56:48 258,048 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\ATIDEMGR.dll
+ 2005-09-14 18:13:38 104,376 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\atiicdxx.dat
+ 2005-11-11 09:34:30 307,200 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\atiiiexx.dll
+ 2005-11-11 06:17:06 151,552 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\atikvmag.dll
+ 2005-11-11 08:09:44 6,684,672 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\atioglx1.dll
+ 2005-11-11 07:04:28 4,956,160 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\atioglxx.dll
+ 2005-11-11 06:44:48 110,592 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\atipdlxx.dll
+ 2005-11-11 05:58:04 17,408 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\atitvo32.dll
+ 2001-11-09 19:01:04 24,064 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\ativcoxx.dll
+ 2005-11-11 06:29:52 1,090,240 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\ativvaxx.dll
+ 2005-11-11 06:44:36 73,728 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0001\DriverFiles\Oemdspif.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 08:00 15360]
"RogersAgent"="c:\Program Files\Rogers\SelfHealing\rogersagent.exe" [2007-04-23 16:51 478968]
"SHS"="C:\Program Files\Rogers\SelfHealing\SHS.exe" [2007-10-12 16:30 5166392]
"Update Manager"="C:\Program Files\Rogers\Update Manager\UpdateManager.exe" [2007-10-12 16:30 136504]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-26 22:23 68856]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-09-12 14:04 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2005-12-09 02:30 35328]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 03:46 57344]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 19:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 07:22 267048]
"bascstray"="BascsTray.exe" []
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 21:10 339968]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 18:13 176128]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2006-06-29 16:13 1032192]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2007-03-16 22:10 1392640]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-10-26 15:42 509224]
"YPC"="C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe" [2005-06-03 16:32 352256]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 01:59 115816]
"osCheck"="C:\PROGRA~1\Symantec\osCheck.exe" [2007-01-14 03:11 771704]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 02:05:26 29696]
Billminder.lnk - C:\Program Files\Quicken\billmind.exe [2002-11-19 20:03:48 36864]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-02-11 21:08:52 24576]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-03-26 22:23:37 124400]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2002-11-19 20:04:06 53248]
Quicken Startup.lnk - C:\Program Files\Quicken\QWDLLS.EXE [2002-11-19 20:04:10 36864]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-01-19 23:51:46 118784]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2007-08-17 13:20:06 54512]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2005-04-22 01:58]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-04-03 21:27:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-04 03:23:20 C:\WINDOWS\Tasks\Norton Security Online - Run Full System Scan - Gary.job"
- C:\PROGRA~1\Symantec\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-12 12:32:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-04-12 12:33:11
ComboFix-quarantined-files.txt 2008-04-12 16:32:54
ComboFix2.txt 2008-04-12 00:25:51
Pre-Run: 63,913,345,024 bytes free
Post-Run: 63,903,412,224 bytes free
.
2008-04-09 21:52:24 --- E O F ---