ComboFix 08-05-29.1 - Owner 2008-06-01 16:33:28.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.306 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\Documents and Settings\Owner\Desktop\Gaming Stuffs\OdinMS\MapleStory\OdinMS.exe
C:\Nexon\MapleStory\localhost.exe
C:\Nexon\MapleStory\MapleCrusade.exe
C:\Program Files\eMule\Incoming\Technitium MAC Address Changer 4.0.zip
c:\Program Files\HP\Digital Imaging\Unload\HpqCmon.exe
c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Mozilla Firefox\MapleCrusade.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Owner\Desktop\Gaming Stuffs\OdinMS\MapleStory\OdinMS.exe
C:\Nexon\MapleStory\localhost.exe
C:\Nexon\MapleStory\MapleCrusade.exe
C:\Program Files\eMule\Incoming\Technitium MAC Address Changer 4.0.zip
C:\Program Files\eMule\Incoming\Technitium MAC Address Changer 4.0.zip\
c:\Program Files\HP\Digital Imaging\Unload\HpqCmon.exe
C:\Program Files\Mozilla Firefox\MapleCrusade.exe
C:\WINDOWS\system32\drivers\downld
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
((((((((((((((((((((((((( Files Created from 2008-05-01 to 2008-06-01 )))))))))))))))))))))))))))))))
.
2008-05-29 03:44 . 2008-05-29 03:52 <DIR> d-------- C:\Soldat
2008-05-29 03:26 . 2008-05-29 03:26 <DIR> d-------- C:\Program Files\CCleaner
2008-05-28 01:59 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-28 01:59 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-27 10:06 . 2008-05-27 10:16 249,856 --------- C:\WINDOWS\Setup1.exe
2008-05-27 09:58 . 2000-07-15 00:00 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2008-05-27 09:58 . 2008-05-27 09:58 1,347 --a------ C:\WINDOWS\ST6UNST.001
2008-05-27 09:57 . 2008-05-27 10:16 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2008-05-27 09:57 . 2008-05-27 09:57 342 --a------ C:\WINDOWS\ST6UNST.000
2008-05-16 03:40 . 2008-05-17 17:16 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\DivX
2008-05-16 03:40 . 2008-05-12 20:53 120,056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-05-16 03:40 . 2008-05-12 20:53 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2008-05-16 03:39 . 2008-05-16 03:40 <DIR> d-------- C:\Program Files\DivX
2008-05-14 09:18 . 2008-05-14 09:18 <DIR> d-------- C:\WINDOWS\Applian FLV Player
2008-05-14 09:18 . 2008-05-14 09:18 <DIR> d-------- C:\Program Files\FLV Player
2008-05-13 13:51 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-05-13 13:51 . 2001-08-17 14:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-05-12 20:53 . 2008-05-12 20:53 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-05-12 20:53 . 2008-05-12 20:53 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2008-05-12 20:53 . 2008-05-12 20:53 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2008-05-12 20:51 . 2008-05-12 20:51 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-05-12 20:51 . 2008-05-12 20:51 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2008-05-12 20:49 . 2008-05-12 20:49 630,784 --a------ C:\WINDOWS\system32\divxdec.ax
2008-05-12 20:49 . 2008-05-12 20:49 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
2008-05-12 20:49 . 2008-05-12 20:49 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-12 20:49 . 2008-05-12 20:49 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-08 03:57 . 2008-05-12 16:33 <DIR> d-------- C:\Program Files\World of Warcraft
2008-05-07 04:20 . 2008-05-07 04:20 <DIR> d-------- C:\Logs
2008-05-06 20:25 . 2008-05-06 20:25 32 --ahs---- C:\WINDOWS\system32\{E7022AC0-C745-4CB7-8691-2A3DED902CA6}.dat
2008-05-06 20:25 . 2008-05-06 20:25 32 --ahs---- C:\WINDOWS\{BECC9981-C01D-4114-9BFF-6F1F16D4E9D9}.dat
2008-05-06 20:22 . 2008-05-06 20:27 <DIR> d-------- C:\Program Files\Norton Personal Firewall
2008-05-06 20:22 . 2008-05-06 20:22 14 --a------ C:\WINDOWS\system32\SR2.dat
2008-05-06 20:04 . 2008-05-08 04:00 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-05-02 01:37 . 2008-06-01 16:15 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\skypePM
2008-05-02 01:37 . 2008-05-02 01:37 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-05-02 01:06 . 2008-05-02 01:06 <DIR> d-------- C:\Program Files\Skype
2008-05-02 01:06 . 2008-05-02 01:06 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-05-02 01:06 . 2008-06-01 16:15 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Skype
2008-05-02 01:06 . 2008-05-02 01:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-05-01 03:45 . 2008-05-01 03:45 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-05-01 03:45 . 2003-07-20 13:17 5,174 --a------ C:\WINDOWS\system32\nppt9x.vxd
2008-05-01 03:45 . 2005-01-04 04:43 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
2008-05-01 01:31 . 2008-05-28 19:22 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Hamachi
2008-05-01 01:30 . 2008-05-01 01:30 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-28 23:51 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-28 23:49 --------- d-----w C:\Program Files\SpywareBlaster
2008-05-28 07:00 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-05-27 16:54 --------- d-----w C:\Program Files\Norton AntiVirus
2008-05-27 15:22 --------- d-----w C:\Program Files\eMule
2008-05-27 15:02 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-22 22:19 --------- d-----w C:\Program Files\Easy Internet signup
2008-05-12 07:28 --------- d-----w C:\Documents and Settings\Owner\Application Data\Winamp
2008-05-07 01:24 --------- d-----w C:\Program Files\Symantec
2008-05-07 01:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-01 03:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-04-30 21:40 --------- d-----w C:\Program Files\InterActual
2008-04-29 03:26 --------- d-----w C:\Program Files\SpywareGuard
2008-04-27 17:10 28,256 ----a-w C:\WINDOWS\system32\drivers\MxlW2k.sys
2008-04-27 14:41 --------- d-----w C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-04-27 14:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-27 14:21 --------- d-----w C:\Documents and Settings\Owner\Application Data\Motive
2008-04-26 22:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-26 21:59 --------- d-----w C:\Program Files\MSXML 4.0
2008-04-25 11:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-25 10:12 --------- d-----w C:\Program Files\Safer Networking
2008-04-24 20:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-24 19:21 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-04-23 14:10 --------- d-----w C:\Program Files\BitLord
2008-04-23 11:40 0 ----a-r C:\logwmemory.bin
2008-04-23 11:40 --------- d-----w C:\Documents and Settings\Owner\Application Data\Soldat
2008-04-23 11:35 --------- d-----w C:\Program Files\MSN Messenger
2008-04-23 11:30 --------- d-----w C:\Program Files\Viewpoint
2008-04-23 11:30 --------- d-----w C:\Program Files\AIM6
2008-04-23 11:30 --------- d-----w C:\Documents and Settings\Owner\Application Data\acccore
2008-04-23 11:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-04-23 11:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-04-23 11:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-04-23 11:28 --------- d-----w C:\Program Files\Common Files\AOL
2008-04-23 11:12 --------- d-----w C:\Program Files\Winamp
2008-04-23 10:23 --------- d-----w C:\Documents and Settings\Owner\Application Data\Nexon
2008-04-23 08:55 --------- d-----w C:\Program Files\Unlocker
2008-04-23 04:54 --------- d-----w C:\Documents and Settings\Owner\Application Data\.clamwin
2008-04-23 04:52 --------- d-----w C:\Program Files\ClamWin
2008-04-23 01:46 --------- d-----w C:\Documents and Settings\Owner\Application Data\Yahoo!
2008-04-23 01:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-23 00:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-23 00:32 --------- d-----w C:\Program Files\Yahoo!
2008-04-23 00:21 3,884 ----a-w C:\WINDOWS\viassary-hp.reg
2008-04-23 00:14 4,158 --sha-r C:\WINDOWS\system32\drivers\HP_DQ174A-ABA A410N_YC_Pavi_QMXK349_E41NAheBLU4_4_IMS-6577_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.02_T031031_WXH1_L409_M504_J123_7Intel_8Celeron_92.8_111063044_N10EC8139_P_Z11C1044C_K_A808624C5_U808624C2_G80862562.MRK
2008-04-23 00:10 --------- d-----w C:\Program Files\ArcSoft
2008-04-23 00:09 --------- d-----w C:\Program Files\Multimedia Card Reader
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Program Files\eMule\Incoming ----
2008-05-27 10:22 667521 --a------ C:\Program Files\eMule\Incoming\Technitium MAC Address Changer 4.0.zip
2008-05-18 05:04 16896 --ahs---- C:\Program Files\eMule\Incoming\Thumbs.db
2008-05-17 19:56 215022644 --a------ C:\Program Files\eMule\Incoming\Animal Sex - Zoofilia Dog Brutal.avi
2008-05-16 22:02 65376256 --a------ C:\Program Files\eMule\Incoming\Animal - Dog - Caes Do Sexo (Excellent Fuck And Cum Inside Cunt).avi
2008-05-16 21:35 8614900 --a------ C:\Program Files\eMule\Incoming\Zoo Animal Sex - Teenage Girl Fucked By Her Dog - 1.mpeg
2008-05-14 18:13 44847900 --a------ C:\Program Files\eMule\Incoming\Petlust Animal Beastiality - Black Pony Horse Fucks Woman Hard Doggie Style (4m18S).mpg
((((((((((((((((((((((((((((( snapshot@2008-05-30_ 9.19.28.75 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 02:45:19 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB915865\update\update.exe
+ 2005-10-12 23:12:28 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB915865\update\update.exe
+ 2008-02-26 11:48:44 297,984 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\SP2QFE\msctf.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB932823-v3\update\updspapi.dll
- 2008-05-30 14:14:01 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-01 21:37:45 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2007-08-14 02:52:06 66,048 -c--a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
+ 2007-08-13 23:52:06 66,048 -c--a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
- 2004-08-04 07:56:41 35,328 ------w C:\WINDOWS\system32\corpol.dll
+ 2007-08-13 23:42:54 17,408 ----a-w C:\WINDOWS\system32\corpol.dll
+ 2008-02-26 11:59:50 294,912 -c----w C:\WINDOWS\system32\dllcache\msctf.dll
- 2008-02-22 10:00:51 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2007-08-13 23:39:10 13,312 ----a-w C:\WINDOWS\system32\ieudinit.exe
- 2004-08-04 07:56:42 294,400 ----a-w C:\WINDOWS\system32\msctf.dll
+ 2008-02-26 11:59:50 294,912 ----a-w C:\WINDOWS\system32\msctf.dll
- 2006-09-07 01:43:16 22,752 ----a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2006-09-06 22:43:16 22,752 ----a-w C:\WINDOWS\system32\spupdsvc.exe
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\23f7ceac0c43a07ec2743f7a\idndl.dll
2006-06-29 08:05 26112 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP172\A0013373.dll
C:\23f7ceac0c43a07ec2743f7a\normaliz.dll
2006-06-29 08:05 23552 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP172\A0013372.dll
C:\23f7ceac0c43a07ec2743f7a\spmsg.dll
2006-05-25 10:29 14048 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP172\A0013371.dll
C:\23f7ceac0c43a07ec2743f7a\spuninst.exe
2006-05-25 10:29 213216 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP172\A0013370.exe
C:\23f7ceac0c43a07ec2743f7a\spupdsvc.exe
2006-05-25 10:29 22752 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP172\A0013369.exe
C:\23f7ceac0c43a07ec2743f7a\update\spcustom.dll
2006-05-25 10:29 22752 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP172\A0013367.dll
C:\23f7ceac0c43a07ec2743f7a\update\update.exe
2006-05-25 10:29 716000 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP172\A0013365.exe
C:\23f7ceac0c43a07ec2743f7a\update\updspapi.dll
2006-05-25 10:29 371424 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP172\A0013366.dll
C:\721b268685871161c33d36\nlsdl.dll
2006-06-28 17:59 24576 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP171\A0013354.dll
C:\721b268685871161c33d36\spmsg.dll
2006-05-24 12:32 14048 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP171\A0013353.dll
C:\721b268685871161c33d36\spuninst.exe
2006-05-24 12:32 213216 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP171\A0013352.exe
C:\721b268685871161c33d36\spupdsvc.exe
2006-05-24 12:32 22752 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP171\A0013351.exe
C:\721b268685871161c33d36\update\spcustom.dll
2006-05-24 12:32 22752 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP171\A0013349.dll
C:\721b268685871161c33d36\update\update.exe
2006-05-24 12:32 716000 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP171\A0013347.exe
C:\721b268685871161c33d36\update\updspapi.dll
2006-05-24 12:32 371424 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP171\A0013348.dll
C:\8996d1c1c61811f28a5b\SP2GDR\xmllite.dll
2006-07-14 10:51 121856 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP170\A0013329.dll
C:\8996d1c1c61811f28a5b\SP2QFE\xmllite.dll
2006-07-14 10:52 121856 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP170\A0013328.dll
C:\8996d1c1c61811f28a5b\spmsg.dll
2005-10-12 18:12 14048 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP170\A0013327.dll
C:\8996d1c1c61811f28a5b\spuninst.exe
2005-10-12 18:12 213216 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP170\A0013334.exe
C:\8996d1c1c61811f28a5b\update\spcustom.dll
2005-10-12 18:12 22752 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP170\A0013324.dll
C:\8996d1c1c61811f28a5b\update\update.exe
2005-10-12 18:12 716000 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP170\A0013335.exe
C:\8996d1c1c61811f28a5b\update\updspapi.dll
2005-10-12 18:12 371424 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP170\A0013330.dll
C:\Combo-Fix\Combobatch.bat
2000-08-31 08:00 7414 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP174\A0013496.bat
2008-06-01 16:36 7504 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP174\A0013505.bat
C:\Combo-Fix\Comspec.bat
2000-08-31 08:00 149 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013483.bat
C:\Combo-Fix\Disclaimer.bat
{CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP166\A0012127.batC:\WINDOWS\inf\_000000_.tmp.dll
2008-03-27 22:49 705 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP168\A0013282.dll
2008-06-01 16:36 65096 C:\Combo-Fix\Lang.bat
2000-08-31 08:00 65098 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP174\A0013497.bat
C:\Combo-Fix\List-C.bat
2000-08-31 08:00 200169 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP174\A0013495.bat
C:\Combo-Fix\restore_pt.vbs
2000-08-31 08:00 232 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP174\A0013489.vbs
C:\dfafd4ba2f6f078ef441921851170327\admparse.dll
2007-08-13 18:39 71680 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013465.dll
C:\dfafd4ba2f6f078ef441921851170327\advpack.dll
2007-08-13 18:39 123904 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013464.dll
C:\dfafd4ba2f6f078ef441921851170327\browseui.dll
2006-09-23 13:12 1022976 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013463.dll
C:\dfafd4ba2f6f078ef441921851170327\corpol.dll
2007-08-13 18:42 17408 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013462.dll
C:\dfafd4ba2f6f078ef441921851170327\custsat.dll
2007-08-13 18:54 33792 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013461.dll
C:\dfafd4ba2f6f078ef441921851170327\dxtmsft.dll
2007-08-13 18:35 346624 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013460.dll
C:\dfafd4ba2f6f078ef441921851170327\dxtrans.dll
2007-08-13 18:35 214528 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013459.dll
C:\dfafd4ba2f6f078ef441921851170327\extmgr.dll
2007-08-13 18:54 131584 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013458.dll
C:\dfafd4ba2f6f078ef441921851170327\hmmapi.dll
2007-08-13 18:18 60416 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013457.dll
C:\dfafd4ba2f6f078ef441921851170327\icardie.dll
2007-08-13 18:36 61952 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013456.dll
C:\dfafd4ba2f6f078ef441921851170327\ie4uinit.exe
2007-08-13 18:39 54784 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013418.exe
C:\dfafd4ba2f6f078ef441921851170327\ieakeng.dll
2007-08-13 18:39 152064 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013455.dll
C:\dfafd4ba2f6f078ef441921851170327\ieaksie.dll
2007-08-13 18:39 229376 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013454.dll
C:\dfafd4ba2f6f078ef441921851170327\ieakui.dll
2007-08-13 17:56 161792 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013453.dll
C:\dfafd4ba2f6f078ef441921851170327\ieapfltr.dll
2007-07-11 12:27 383488 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013452.dll
C:\dfafd4ba2f6f078ef441921851170327\iedkcs32.dll
2007-08-13 18:39 382976 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013451.dll
C:\dfafd4ba2f6f078ef441921851170327\iedw.exe
2007-08-13 18:44 69120 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013417.exe
C:\dfafd4ba2f6f078ef441921851170327\ieencode.dll
2007-08-13 18:45 78336 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013450.dll
C:\dfafd4ba2f6f078ef441921851170327\ieframe.dll
2007-08-13 18:54 6049280 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013449.dll
C:\dfafd4ba2f6f078ef441921851170327\iepeers.dll
2007-08-13 18:54 191488 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013448.dll
C:\dfafd4ba2f6f078ef441921851170327\ieproxy.dll
2007-08-13 18:54 287744 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013447.dll
C:\dfafd4ba2f6f078ef441921851170327\iernonce.dll
2007-08-13 18:39 43008 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013446.dll
C:\dfafd4ba2f6f078ef441921851170327\iertutil.dll
2007-08-13 18:34 266752 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013445.dll
C:\dfafd4ba2f6f078ef441921851170327\iesetup.dll
2007-08-13 18:39 55296 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013444.dll
C:\dfafd4ba2f6f078ef441921851170327\ieudinit.exe
2007-08-13 18:39 13312 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013416.exe
C:\dfafd4ba2f6f078ef441921851170327\ieui.dll
2007-08-13 18:54 180736 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013443.dll
C:\dfafd4ba2f6f078ef441921851170327\iexplore.exe
2007-08-13 18:43 622080 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013415.exe
C:\dfafd4ba2f6f078ef441921851170327\imgutil.dll
2007-08-13 18:36 36352 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013442.dll
C:\dfafd4ba2f6f078ef441921851170327\inseng.dll
2007-08-13 18:39 92672 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013441.dll
C:\dfafd4ba2f6f078ef441921851170327\jscript.dll
2007-08-13 18:38 491520 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013440.dll
C:\dfafd4ba2f6f078ef441921851170327\jsproxy.dll
2007-08-13 18:54 27136 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013439.dll
C:\dfafd4ba2f6f078ef441921851170327\licmgr10.dll
2007-08-13 18:44 40960 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013438.dll
C:\dfafd4ba2f6f078ef441921851170327\msfeeds.dll
2007-08-13 18:54 458752 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013437.dll
C:\dfafd4ba2f6f078ef441921851170327\msfeedsbs.dll
2007-08-13 18:54 50688 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013436.dll
C:\dfafd4ba2f6f078ef441921851170327\msfeedssync.exe
2007-08-13 18:36 12288 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013414.exe
C:\dfafd4ba2f6f078ef441921851170327\mshta.exe
2007-08-13 18:32 45568 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013413.exe
C:\dfafd4ba2f6f078ef441921851170327\mshtml.dll
2007-08-13 18:54 3578368 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013435.dll
C:\dfafd4ba2f6f078ef441921851170327\mshtmled.dll
2007-08-13 18:54 475648 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013434.dll
C:\dfafd4ba2f6f078ef441921851170327\mshtmler.dll
2007-08-13 18:01 48128 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013433.dll
C:\dfafd4ba2f6f078ef441921851170327\msls31.dll
2007-08-13 18:54 156160 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013432.dll
C:\dfafd4ba2f6f078ef441921851170327\msrating.dll
2007-08-13 18:44 192000 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013431.dll
C:\dfafd4ba2f6f078ef441921851170327\mstime.dll
2007-08-13 18:54 670720 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013430.dll
C:\dfafd4ba2f6f078ef441921851170327\occache.dll
2007-08-13 18:44 101376 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013429.dll
C:\dfafd4ba2f6f078ef441921851170327\pngfilt.dll
2007-08-13 18:36 44544 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013428.dll
C:\dfafd4ba2f6f078ef441921851170327\shdocvw.dll
2006-09-23 13:12 1497088 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013427.dll
C:\dfafd4ba2f6f078ef441921851170327\shlwapi.dll
2006-09-23 13:12 474112 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013426.dll
C:\dfafd4ba2f6f078ef441921851170327\spmsg.dll
2006-09-06 17:43 14048 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013425.dll
C:\dfafd4ba2f6f078ef441921851170327\spuninst.exe
2006-09-06 17:43 213216 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013412.exe
C:\dfafd4ba2f6f078ef441921851170327\spupdsvc.exe
2006-09-06 17:43 22752 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013411.exe
C:\dfafd4ba2f6f078ef441921851170327\update\idndl.exe
2006-09-06 17:42 589672 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013395.exe
C:\dfafd4ba2f6f078ef441921851170327\update\iecustom.dll
2007-08-13 18:54 32960 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013398.dll
C:\dfafd4ba2f6f078ef441921851170327\update\iereseticons.exe
2007-08-13 18:52 66048 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013394.exe
C:\dfafd4ba2f6f078ef441921851170327\update\iesetup.exe
2007-08-13 18:54 1084096 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013393.exe
C:\dfafd4ba2f6f078ef441921851170327\update\legitlibm.dll
2007-02-12 16:10 635696 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013397.dll
C:\dfafd4ba2f6f078ef441921851170327\update\nlsdl.exe
2006-09-06 17:42 498016 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013392.exe
C:\dfafd4ba2f6f078ef441921851170327\update\update.exe
2006-09-06 17:43 716000 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013391.exe
C:\dfafd4ba2f6f078ef441921851170327\update\updspapi.dll
2006-09-06 17:43 371424 {CD53596A-5812-49DB-AF84-A72B9BECDE4F}\RP173\A0013396.dll
C:\dfafd4ba2f6f078ef441921851170327\update\xmllitesetup.exe
{CD53596A-5812-49DB-AF84-A
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 19:43 4670704]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2004-10-13 11:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-03-25 15:21 50528]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-23 20:45 22058792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04 52736]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-02 11:59 126976]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [ ]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-05-23 04:55 483328]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 22:02 61440]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 10:01 110592]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2003-10-10 23:58 151597]
"AutoTKit"="C:\hp\bin\AUTOTKIT.EXE" [2003-06-18 21:19 53248]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 23:42 212992]
"VTTimer"="VTTimer.exe" []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-05-30 09:10 70816]
"LTMSG"="LTMSG.exe" [2003-07-14 19:52 40960 C:\WINDOWS\ltmsg.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 18:57 81920]
"Sunkist2k"="C:\Program Files\Multimedia Card Reader\shwicon2k.exe" [2003-08-14 22:11 139264]
"mmtask"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2003-07-23 18:37 53248]
"ClamWin"="C:\Program Files\ClamWin\bin\ClamTray.exe" [2008-05-30 09:10 77824]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-03-01 00:10 15872]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 15:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-11-02 12:03 155648]
"ccRegVfy"="c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-11-14 19:29 59072]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 13:49 36352]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2003-10-14 00:24:52 557056]
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 22:05:35 360448]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 10:20:40 233472]
Norton Personal Firewall.lnk - C:\Program Files\Norton Personal Firewall\nisfirst.exe [2002-11-15 12:48:14 644744]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-07-30 06:49:48 57344]
Updates from HP.lnk - C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe [2003-10-11 00:26:40 16384]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Updates from HP\\137903\\Program\\BackWeb-137903.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-31 01:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exeh/task:
"2008-04-25 06:29:47 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-01 16:38:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Unlocker\UnlockerHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2008-06-01 16:43:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-01 21:43:45
ComboFix2.txt 2008-05-30 14:22:25
ComboFix3.txt 2008-04-27 00:07:41
Pre-Run: 89,606,701,056 bytes free
Post-Run: 89,592,696,832 bytes free
428 --- E O F --- 2008-05-31 08:07:19