OK, now here is the combofix file.
Shaba, Please note the following:
Before it finalized the log, it popped up a window that said:
"Cannot export APIsvc: Error writing the file. There may be a disk or file system error."
Anyways...here it is.
and...Thanks.
ComboFix 08-09-03.02 - steveo 2008-09-03 21:19:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2541 [GMT -5:00]
Running from: C:\Documents and Settings\steveo\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\steveo\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Alex\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\Guest\Cookies\guest@2o7[1].txt
C:\Documents and Settings\Guest\Cookies\guest@ad.yieldmanager[2].txt
C:\Documents and Settings\Guest\Cookies\guest@advertising[1].txt
C:\Documents and Settings\Guest\Cookies\guest@edge.ru4[2].txt
C:\Documents and Settings\Guest\Cookies\guest@ehg-nestleusainc.hitbox[1].txt
C:\Documents and Settings\New Account\Desktop\Vista Antivirus 2008.lnk
C:\Documents and Settings\steveo\Application Data\FunWebProducts
C:\Documents and Settings\steveo\Application Data\FunWebProducts\Data\steveo\avatar.dat
C:\Documents and Settings\steveo\Application Data\inst.exe
C:\Documents and Settings\steveo\Application Data\macromedia\Flash Player\#SharedObjects\7PNL64M3\bin.clearspring.com
C:\Documents and Settings\steveo\Application Data\macromedia\Flash Player\#SharedObjects\7PNL64M3\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\steveo\Application Data\macromedia\Flash Player\#SharedObjects\7PNL64M3\interclick.com
C:\Documents and Settings\steveo\Application Data\macromedia\Flash Player\#SharedObjects\7PNL64M3\interclick.com\ud.sol
C:\Documents and Settings\steveo\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\steveo\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\steveo\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\steveo\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\steveo\Cookies\steveo@adserver[2].txt
C:\Documents and Settings\steveo\Cookies\steveo@clicktorrent[1].txt
C:\Documents and Settings\steveo\Cookies\steveo@hb.pcworld[2].txt
C:\Documents and Settings\steveo\Cookies\steveo@indextools[1].txt
C:\Documents and Settings\steveo\Cookies\steveo@my.clearchannelradio[1].txt
C:\Documents and Settings\steveo\Cookies\steveo@track.bestbuy[1].txt
C:\Documents and Settings\steveo\Cookies\steveo@vendorweb.citibank[2].txt
C:\Documents and Settings\steveo\Cookies\steveo@webr.harley-davidson[1].txt
C:\Documents and Settings\steveo\Cookies\steveo@www.selfstoragebay[2].txt
C:\Documents and Settings\steveo\Cookies\steveo@www.webschwab[2].txt
C:\Program Files\VAV
C:\WINDOWS\BM7393421d.txt
C:\WINDOWS\BM7393421d.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.dll
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\actskn43.ocx
C:\WINDOWS\system32\afecpfey.ini
C:\WINDOWS\system32\ajanxplc.ini
C:\WINDOWS\system32\baouqrsr.dll
C:\WINDOWS\system32\bdyybn.dll
C:\WINDOWS\system32\bobjmher.ini
C:\WINDOWS\system32\cciagkgy.dll
C:\WINDOWS\system32\ckbxjdpa.dll
C:\WINDOWS\system32\cmcskmcx.dll
C:\WINDOWS\system32\cyclpj.dll
C:\WINDOWS\system32\ddcDvwUO.dll
C:\WINDOWS\system32\dgdkkejt.ini
C:\WINDOWS\system32\dxsegrfl.dll
C:\WINDOWS\system32\efcCsrpM.dll
C:\WINDOWS\system32\eMmmlnmp.ini
C:\WINDOWS\system32\eMmmlnmp.ini2
C:\WINDOWS\system32\epkcgcgq.ini
C:\WINDOWS\system32\etqdmhra.ini
C:\WINDOWS\system32\eycfewgm.ini
C:\WINDOWS\system32\fchtchgg.dll
C:\WINDOWS\system32\fcksneok.ini
C:\WINDOWS\system32\fgknradn.ini
C:\WINDOWS\system32\fkdfdguq.ini
C:\WINDOWS\system32\fndpokgq.ini
C:\WINDOWS\system32\fukbwhni.ini
C:\WINDOWS\system32\fxortdxf.ini
C:\WINDOWS\system32\gkjgtaed.dll
C:\WINDOWS\system32\glycmxwd.ini
C:\WINDOWS\system32\hajoryur.ini
C:\WINDOWS\system32\hcskru.dll
C:\WINDOWS\system32\hvkkfpht.ini
C:\WINDOWS\system32\ihOpAcdd.ini
C:\WINDOWS\system32\ihOpAcdd.ini2
C:\WINDOWS\system32\iilbcxrd.ini
C:\WINDOWS\system32\ilacbwov.dll
C:\WINDOWS\system32\jangbh.dll
C:\WINDOWS\system32\jaxixlcc.ini
C:\WINDOWS\system32\jdmhbxcx.ini
C:\WINDOWS\system32\jjjlm.bak1
C:\WINDOWS\system32\jjjlm.bak2
C:\WINDOWS\system32\jjjlm.ini
C:\WINDOWS\system32\jjjlm.ini2
C:\WINDOWS\system32\jjjlm.tmp
C:\WINDOWS\system32\jkpxwhnc.ini
C:\WINDOWS\system32\jwdovsrc.ini
C:\WINDOWS\system32\kkashi.dll
C:\WINDOWS\system32\kmscvbdr.ini
C:\WINDOWS\system32\lbesqvxx.ini
C:\WINDOWS\system32\lfuqungm.ini
C:\WINDOWS\system32\llekdymt.ini
C:\WINDOWS\system32\lsfnaxpg.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MprsCcfe.ini
C:\WINDOWS\system32\MprsCcfe.ini2
C:\WINDOWS\system32\mqxgspbw.dll
C:\WINDOWS\system32\nhesnuiq.dll
C:\WINDOWS\system32\nhvnvxwx.ini
C:\WINDOWS\system32\niegaxot.ini
C:\WINDOWS\system32\njvpffba.ini
C:\WINDOWS\system32\nyrphleb.ini
C:\WINDOWS\system32\oclmphsm.dll
C:\WINDOWS\system32\ofpiknvl.dll
C:\WINDOWS\system32\ohgfjgfw.ini
C:\WINDOWS\system32\peqdnwiu.ini
C:\WINDOWS\system32\pnbfmvjm.dll
C:\WINDOWS\system32\pzirfw.dll
C:\WINDOWS\system32\qejceoei.ini
C:\WINDOWS\system32\qoppufkm.ini
C:\WINDOWS\system32\qxhfbtax.ini
C:\WINDOWS\system32\rbhczy.dll
C:\WINDOWS\system32\rehmjbob.dll
C:\WINDOWS\system32\rifhuloo.ini
C:\WINDOWS\system32\rmbgxvqs.dll
C:\WINDOWS\system32\rndhsaix.ini
C:\WINDOWS\system32\sbdqgoxy.ini
C:\WINDOWS\system32\sDNWxyxx.ini
C:\WINDOWS\system32\sDNWxyxx.ini2
C:\WINDOWS\system32\siscppng.dll
C:\WINDOWS\system32\sqvxgbmr.ini
C:\WINDOWS\system32\svsffe.dll
C:\WINDOWS\system32\sykxjpfy.ini
C:\WINDOWS\system32\uacjphiw.ini
C:\WINDOWS\system32\ucvdsuhv.dll
C:\WINDOWS\system32\uotgusmu.ini
C:\WINDOWS\system32\UvCIkUvw.ini
C:\WINDOWS\system32\UvCIkUvw.ini2
C:\WINDOWS\system32\vfsaopeg.dll
C:\WINDOWS\system32\vtnirb.dll
C:\WINDOWS\system32\wbyhkjau.ini
C:\WINDOWS\system32\WGfhPXbc.ini
C:\WINDOWS\system32\WGfhPXbc.ini2
C:\WINDOWS\system32\wghycqxo.dll
C:\WINDOWS\system32\wmwwknar.ini
C:\WINDOWS\system32\wnsapisv.exe
C:\WINDOWS\system32\wtbibrua.ini
C:\WINDOWS\system32\xcmkscmc.ini
C:\WINDOWS\system32\yefpcefa.dll
C:\WINDOWS\system32\yimrybqn.dll
C:\WINDOWS\system32\yqbyfiml.dll
C:\WINDOWS\system32\zxdnt3d.cfg
E:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2008-08-04 to 2008-09-04 )))))))))))))))))))))))))))))))
.
2008-08-12 22:38 . 2008-08-12 22:38 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-08-12 22:24 . 2008-08-12 22:24 <DIR> d-------- C:\Documents and Settings\steveo\Application Data\ATI
2008-08-12 22:20 . 2008-08-12 22:20 <DIR> d-------- C:\ATI
2008-08-12 22:12 . 2008-08-12 22:12 <DIR> d-------- C:\Documents and Settings\New Account\Application Data\ATI
2008-08-12 22:12 . 2008-08-12 22:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-08-12 21:44 . 2008-08-12 21:44 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-08-12 21:20 . 2008-08-12 21:20 <DIR> d-------- C:\Program Files\Common Files\ATI Technologies
2008-08-12 21:18 . 2008-01-22 14:42 593,920 --a------ C:\WINDOWS\system32\ati2sgag.exe
2008-08-12 21:18 . 2008-01-22 15:39 307,200 -ra------ C:\WINDOWS\system32\atiiiexx.dll
2008-08-12 21:18 . 2008-01-08 02:34 11,942 -ra------ C:\WINDOWS\atiogl.xml
2008-08-12 21:17 . 2008-01-22 15:14 3,107,788 -ra------ C:\WINDOWS\system32\ativvaxx.dat
2008-08-12 21:17 . 2008-01-22 15:14 3,107,788 -ra------ C:\WINDOWS\system32\ativva5x.dat
2008-08-12 21:17 . 2008-01-22 15:14 887,724 -ra------ C:\WINDOWS\system32\ativva6x.dat
2008-08-12 21:17 . 2008-01-22 15:44 368,640 -ra------ C:\WINDOWS\system32\ATIDEMGX.dll
2008-08-12 21:17 . 2008-01-07 09:43 165,782 -ra------ C:\WINDOWS\system32\atiicdxx.dat
2008-08-12 21:17 . 2007-08-31 09:20 7,167 -ra------ C:\WINDOWS\system32\atifglpf.xml
2008-08-12 21:15 . 2008-08-12 21:35 <DIR> d-------- C:\Program Files\ATI Technologies
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-03 15:06 --------- d-----w C:\Program Files\Quicken
2008-09-01 16:10 10,752 ----a-w C:\WINDOWS\DCEBoot.exe
2008-08-25 15:29 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-24 13:08 --------- d-----w C:\Program Files\Trend Micro
2008-08-13 03:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
2008-08-13 03:30 --------- d-----w C:\Program Files\Oberon Media
2008-08-13 02:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-12 12:51 --------- d-----w C:\Program Files\RegCure
2008-08-12 12:47 --------- d-----w C:\Program Files\oldlimewirefiles
2008-08-12 00:27 --------- d-----w C:\Program Files\Video Strip Poker Supreme
2008-07-28 01:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-27 13:27 --------- d-----w C:\Documents and Settings\steveo\Application Data\Uniblue
2008-07-24 00:11 --------- d-----w C:\Documents and Settings\New Account\Application Data\vlc
2008-07-24 00:06 --------- d-----w C:\Documents and Settings\New Account\Application Data\DivX
2008-07-22 11:49 --------- d-----w C:\Documents and Settings\New Account\Application Data\Intuit
2008-07-22 04:53 --------- d-----w C:\Documents and Settings\New Account\Application Data\Gtek
2008-07-21 21:15 --------- d-----w C:\Program Files\Star Defender 3
2008-07-20 18:46 --------- d-----w C:\Documents and Settings\steveo\Application Data\Wildfire
2008-07-19 00:08 36,368 ----a-w C:\WINDOWS\system32\drivers\tmpreflt.sys
2008-07-19 00:08 205,328 ----a-w C:\WINDOWS\system32\drivers\tmxpflt.sys
2008-07-18 23:51 1,195,448 ----a-w C:\WINDOWS\system32\drivers\vsapint.sys
2008-07-15 12:59 --------- d-----w C:\Program Files\Apple Software Update
2008-03-01 12:47 79,320 ----a-w C:\Documents and Settings\steveo\Application Data\GDIPFONTCACHEV1.DAT
2007-05-11 14:39 47,360 ----a-w C:\Documents and Settings\steveo\Application Data\pcouffin.sys
2007-01-24 02:58 313 ----a-w C:\Documents and Settings\steveo\Application Data\bbbconfig.dat
2006-11-23 14:22 78,072 ----a-w C:\Documents and Settings\steve\Application Data\GDIPFONTCACHEV1.DAT
2006-10-06 02:21 81,920 ----a-w C:\Documents and Settings\steve\Application Data\ezpinst.exe
2006-10-06 02:21 47,360 ----a-w C:\Documents and Settings\steve\Application Data\pcouffin.sys
2005-01-21 00:53 45,056 ------r C:\Program Files\SetAttrib.exe
2004-11-30 07:23 40,960 ------r C:\Program Files\delete.exe
2004-10-01 20:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2002-05-31 19:15 49,152 ----a-w C:\Program Files\owcsetup.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-13 68856]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe" [2008-03-28 413696]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Symantec Network Driver Update Warning"="C:\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE" [2004-04-30 91256]
C:\Documents and Settings\steveo\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-06-11 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2005-11-23 03:47 53248 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWlgn.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^earthlink dsl5.lnk]
backup=C:\WINDOWS\pss\earthlink dsl5.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EarthLink WebLife Backup.lnk]
backup=C:\WINDOWS\pss\EarthLink WebLife Backup.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDrive2
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 02:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyLinkAdvisor]
--a------ 2006-10-30 12:01 392832 C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--------- 2006-03-16 03:00 1397760 C:\Program Files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchPDeviceConn]
--a------ 2005-07-05 20:41 299008 C:\Program Files\Philips\Philips Device Transfer Pop-up\PDeviceConn.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
--a------ 2007-05-09 00:29 249856 C:\Program Files\lg_fwupdate\fwupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXBLKsk]
--a------ 2003-03-26 04:10 294912 C:\PROGRA~1\Lexmark\PHOTOC~1\lxblksk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaLifeService]
--------- 2005-06-03 18:09 110739 C:\Program Files\Logitech\MediaLife\MediaLifeService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryCardManager]
--a------ 2003-04-28 18:29 122880 C:\Program Files\Lexmark\Lexmark Photo Center\MemoryCardManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 12:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pccguide.exe]
--a------ 2007-01-23 01:26 3429904 C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2003-03-11 11:58 593920 C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2003-03-11 11:45 774144 C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-06-13 19:04 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
--a------ 2005-11-03 14:58 28160 C:\WINDOWS\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Themes"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Documents and Settings\\steveo\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\TVAnts\\Tvants.exe"=
"C:\\Program Files\\TVU Player\\TVUPlayer.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Harman Pro\\System Architect 1.60\\SystemArchitect.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2799:UDP"= 2799:UDP:Altova License Metering Port (UDP)
"2799:TCP"= 2799:TCP:Altova License Metering Port (TCP)
R0 SSHIPSEC;SSHIPSEC;C:\WINDOWS\system32\DRIVERS\sshipsec.sys [2002-10-07 370014]
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2001-11-21 11889]
R2 IOPort;IOPort;C:\WINDOWS\System32\DRIVERS\IOPORT.SYS [1998-11-27 6144]
R2 Par1284;Par1284;C:\Program Files\Roland CutChoice\Program\Par1284.sys [2001-09-05 47328]
R2 SSHIPM;SSH Sentinel;C:\Program Files\SSH Communications Security\SSH Sentinel\sshipm.exe [2002-10-07 2076751]
R2 SSHMONITOR;SSH Sentinel Monitor;C:\Program Files\SSH Communications Security\SSH Sentinel\sshmonitor.exe [2002-10-07 98402]
R3 sshvnic;SSH Virtual Network Adapter (sshvnic);C:\WINDOWS\system32\DRIVERS\sshvnic5.sys [2002-10-07 6241]
S3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2002-08-28 36224]
S3 GPCIEnu1;GPCIEnu1;C:\WINDOWS\system32\GPCIEnum.sys [2006-08-06 7626]
S3 WLNR;WLNR;C:\WINDOWS\system32\DRIVERS\WLNR.sys [ ]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
BHO-{3AC960D0-4EE6-4F61-8EDA-1066320B1459} - C:\WINDOWS\system32\wvUkICvU.dll
BHO-{D7DE6CDC-824C-432A-A61A-270A694A6D8A} - C:\WINDOWS\system32\xxyxWNDs.dll
BHO-{EAE5E139-2120-4522-8D85-1B58C052FC2C} - C:\WINDOWS\system32\cbXPhfGW.dll
BHO-{FC199917-15BB-41EC-82DA-BD4EEECA4748} - C:\WINDOWS\system32\ddcApOhi.dll
HKCU-Run-Uniblue RegistryBooster 2 - C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
HKLM-Run-70a07181 - C:\WINDOWS\system32\yefpcefa.dll
HKLM-Run-BM7393421d - C:\WINDOWS\system32\ofpiknvl.dll
MSConfigStartUp-NvCplDaemon - C:\WINDOWS\system32\NvCpl.dll
MSConfigStartUp-NvMediaCenter - C:\WINDOWS\system32\NvMcTray.dll
MSConfigStartUp-Logitech BT Wizard - LBTWiz.exe
MSConfigStartUp-nwiz - nwiz.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie
R0 -: HKLM-Main,Default_Search_URL = hxxp://www.google.com/ie
R1 -: HKCU-Internet Settings,ProxyServer = walledgarden.mchsd.com:8000
R1 -: HKCU-Internet Settings,ProxyOverride = *.mchsd.com
R0 -: HKCU-Search,SearchAssistant = hxxp://www.google.com/ie
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
R0 -: HKLM-Search,SearchAssistant = hxxp://www.google.com/ie
O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 -: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java - C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-03 21:37:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidServ]
"ServiceDll"="%SystemRoot%\System32\hidserv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HidUsb]
"ImagePath"="System32\DRIVERS\hidusb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hpn]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hpt3xx]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTP]
"ImagePath"="System32\Drivers\HTTP.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HTTPFilter]
"ServiceDll"="%SystemRoot%\System32\w3ssl.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omgmt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i2omp]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i8042prt]
"ImagePath"="System32\DRIVERS\i8042prt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IDriverT]
"ImagePath"="\"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Imapi]
"ImagePath"="System32\DRIVERS\imapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ImapiService]
"ImagePath"="%systemroot%\system32\imapi.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\InCDfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\InCDPass]
"ImagePath"="System32\DRIVERS\InCDPass.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\InCDrec]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\incdrm]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\InCDsrv]
"ImagePath"="C:\Program Files\Ahead\InCD\InCDsrv.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\inetaccs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ini910u]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Inport]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IntelIde]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\intelppm]
"ImagePath"="System32\DRIVERS\intelppm.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IOPort]
"ImagePath"="\??\C:\WINDOWS\System32\DRIVERS\IOPORT.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ip6Fw]
"ImagePath"="system32\drivers\ip6fw.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpFilterDriver]
"ImagePath"="System32\DRIVERS\ipfltdrv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpInIp]
"ImagePath"="System32\DRIVERS\ipinip.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IpNat]
"ImagePath"="System32\DRIVERS\ipnat.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iPod Service]
"ImagePath"="\"C:\Program Files\iPod\bin\iPodService.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IPSec]
"ImagePath"="System32\DRIVERS\ipsec.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IRENUM]
"ImagePath"="System32\DRIVERS\irenum.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ISAPISearch]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\isapnp]
"ImagePath"="System32\DRIVERS\isapnp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Kbdclass]
"ImagePath"="System32\DRIVERS\kbdclass.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kbdhid]
"ImagePath"="system32\DRIVERS\kbdhid.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kbfilter]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kmixer]
"ImagePath"="system32\drivers\kmixer.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KSecDD]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\L8042Kbd]
"ImagePath"="system32\DRIVERS\L8042Kbd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\L8042mou]
"ImagePath"="system32\DRIVERS\L8042mou.Sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanserver]
"ServiceDll"="%SystemRoot%\System32\srvsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lanmanworkstation]
"ServiceDll"="%SystemRoot%\System32\wkssvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lbrtfdc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LBTServ]
"ImagePath"="C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ldap]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LexBceS]
"ImagePath"="C:\WINDOWS\system32\LEXBCES.EXE"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LHidKe]
"ImagePath"="system32\DRIVERS\LHidKE.Sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LicenseService]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LightScribeService]
"ImagePath"="\"C:\Program Files\Common Files\LightScribe\LSSrvc.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LmHosts]
"ServiceDll"="%SystemRoot%\System32\lmhsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LMouKE]
"ImagePath"="system32\DRIVERS\LMouKE.Sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MDM]
"ImagePath"="\"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Messenger]
"ServiceDll"="%SystemRoot%\System32\msgsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MidiSyn]
"ImagePath"="system32\drivers\MidiSyn.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmdd]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mnmsrvc]
"ImagePath"="C:\WINDOWS\System32\mnmsrvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Modem]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Mouclass]
"ImagePath"="System32\DRIVERS\mouclass.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mouhid]
"ImagePath"="System32\DRIVERS\mouhid.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MountMgr]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mraid35x]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mrtRate]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MRxDAV]
"ImagePath"="System32\DRIVERS\mrxdav.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MRxSmb]
"ImagePath"="System32\DRIVERS\mrxsmb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSDTC]
"ImagePath"="C:\WINDOWS\System32\msdtc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSDV]
"ImagePath"="System32\DRIVERS\msdv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Msfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSIServer]
"ImagePath"="%systemroot%\system32\msiexec.exe /V"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSKSSRV]
"ImagePath"="system32\drivers\MSKSSRV.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSPCLOCK]
"ImagePath"="system32\drivers\MSPCLOCK.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSPQM]
"ImagePath"="system32\drivers\MSPQM.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mssmbios]
"ImagePath"="System32\DRIVERS\mssmbios.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSTEE]
"ImagePath"="system32\drivers\MSTEE.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Mup]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NABTSFEC]
"ImagePath"="System32\DRIVERS\NABTSFEC.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NDIS]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisIP]
"ImagePath"="System32\DRIVERS\NdisIP.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisTapi]
"ImagePath"="System32\DRIVERS\ndistapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ndisuio]
"ImagePath"="System32\DRIVERS\ndisuio.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NdisWan]
"ImagePath"="System32\DRIVERS\ndiswan.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NDProxy]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetBIOS]
"ImagePath"="System32\DRIVERS\netbios.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetBT]
"ImagePath"="System32\DRIVERS\netbt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDE]
"ImagePath"="%SystemRoot%\system32\netdde.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NetDDEdsdm]
"ImagePath"="%SystemRoot%\system32\netdde.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netlogon]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Netman]
"ServiceDll"="%SystemRoot%\System32\netman.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIC1394]
"ImagePath"="System32\DRIVERS\nic1394.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Nla]
"ServiceDll"="%SystemRoot%\System32\mswsock.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nm]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Npfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ntfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtLmSsp]
"ImagePath"="%SystemRoot%\System32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc]
"ServiceDll"="%SystemRoot%\system32\ntmssvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Null]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkFlt]
"ImagePath"="System32\DRIVERS\nwlnkflt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkFwd]
"ImagePath"="System32\DRIVERS\nwlnkfwd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkIpx]
"ImagePath"="System32\DRIVERS\nwlnkipx.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkNb]
"ImagePath"="System32\DRIVERS\nwlnknb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NwlnkSpx]
"ImagePath"="System32\DRIVERS\nwlnkspx.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ohci1394]
"ImagePath"="System32\DRIVERS\ohci1394.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ose]
"ImagePath"="\"C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Par1284]
"ImagePath"="\??\C:\Program Files\Roland CutChoice\Program\Par1284.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Parport]
"ImagePath"="System32\DRIVERS\parport.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PartMgr]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ParVdm]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PcCtlCom]
"ImagePath"="C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCI]
"ImagePath"="System32\DRIVERS\pci.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCIDump]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCIIde]
"ImagePath"="System32\DRIVERS\pciide.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Pcmcia]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Pcouffin]
"ImagePath"="System32\Drivers\Pcouffin.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PcScnSrv]
"ImagePath"="\"C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDCOMP]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDFRAME]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDRELI]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PDRFRAME]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\perc2]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\perc2hib]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfDisk]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfNet]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfOS]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PerfProc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pfc]
"ImagePath"="system32\drivers\pfc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PlugPlay]
"ImagePath"="%SystemRoot%\system32\services.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PMEM]
"ImagePath"="\??\C:\WINDOWS\System32\drivers\pmemnt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Point32]
"ImagePath"="system32\DRIVERS\point32.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PolicyAgent]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PptpMiniport]
"ImagePath"="System32\DRIVERS\raspptp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Processor]
"ImagePath"="System32\DRIVERS\processr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ProtectedStorage]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSched]
"ImagePath"="System32\DRIVERS\psched.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ptilink]
"ImagePath"="System32\DRIVERS\ptilink.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PxHelp20]
"ImagePath"="System32\Drivers\PxHelp20.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1080]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ql10wnt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql12160]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1240]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ql1280]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasAcd]
"ImagePath"="System32\DRIVERS\rasacd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasAuto]
"ServiceDll"="%SystemRoot%\System32\rasauto.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Rasl2tp]
"ImagePath"="System32\DRIVERS\rasl2tp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasMan]
"ServiceDll"="%SystemRoot%\System32\rasmans.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RasPppoe]
"ImagePath"="System32\DRIVERS\raspppoe.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Raspti]
"ImagePath"="System32\DRIVERS\raspti.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Rdbss]
"ImagePath"="System32\DRIVERS\rdbss.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPCDD]
"ImagePath"="System32\DRIVERS\RDPCDD.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPDD]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rdpdr]
"ImagePath"="System32\DRIVERS\rdpdr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPNP]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDPWD]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Rdr]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RDSessMgr]
"ImagePath"="C:\WINDOWS\system32\sessmgr.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\redbook]
"ImagePath"="System32\DRIVERS\redbook.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RemoteAccess]
"ServiceDll"="%SystemRoot%\System32\mprdim.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RemoteRegistry]
"ServiceDll"="%SystemRoot%\system32\regsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RpcLocator]
"ImagePath"="%SystemRoot%\System32\locator.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RpcSs]
"ServiceDll"="%SystemRoot%\System32\rpcss.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RSVP]
"ImagePath"="%SystemRoot%\System32\rsvp.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SamSs]
"ImagePath"="%SystemRoot%\system32\lsass.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SansaService]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SCardSvr]
"ImagePath"="%SystemRoot%\System32\SCardSvr.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Schedule]
"ServiceDll"="%SystemRoot%\system32\schedsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ScsiPort]
"ImagePath"="%SystemRoot%\system32\drivers\scsiport.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SDDMI2]
"ImagePath"="\??\C:\WINDOWS\system32\DDMI2.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Secdrv]
"ImagePath"="System32\DRIVERS\secdrv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seclogon]
"ServiceDll"="%SystemRoot%\System32\seclogon.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SENS]
"ServiceDll"="%SystemRoot%\system32\sens.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\serenum]
"ImagePath"="System32\DRIVERS\serenum.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Serial]
"ImagePath"="System32\DRIVERS\serial.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sf]
"ImagePath"="system32\drivers\sf.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sfloppy]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess]
"ServiceDll"="%SystemRoot%\System32\ipnathlp.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ShellHWDetection]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Simbad]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SLIP]
"ImagePath"="System32\DRIVERS\SLIP.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SMBios]
"ImagePath"="System32\DRIVERS\SMBios.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\smwdm]
"ImagePath"="system32\drivers\smwdm.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SoundMAX Agent Service (default)]
"ImagePath"="C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sparrow]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\splitter]
"ImagePath"="system32\drivers\splitter.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Spooler]
"ImagePath"="%SystemRoot%\system32\spoolsv.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sptd]
"ImagePath"="System32\Drivers\sptd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sr]
"ImagePath"="System32\DRIVERS\sr.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\srservice]
"ServiceDll"="C:\WINDOWS\System32\srsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Srv]
"ImagePath"="System32\DRIVERS\srv.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SSDPSRV]
"ServiceDll"="%SystemRoot%\System32\ssdpsrv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SSHIPM]
"ImagePath"="\"C:\Program Files\SSH Communications Security\SSH Sentinel\sshipm.exe\" -d"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SSHIPSEC]
"IMAGEPATH"="System32\DRIVERS\sshipsec.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SSHMONITOR]
"ImagePath"="C:\Program Files\SSH Communications Security\SSH Sentinel\sshmonitor.exe -d"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sshvnic]
"ImagePath"="System32\DRIVERS\sshvnic5.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\StillCam]
"ImagePath"="System32\DRIVERS\serscan.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\stisvc]
"ServiceDll"="%SystemRoot%\system32\wiaservc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\streamip]
"ImagePath"="System32\DRIVERS\StreamIP.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\swenum]
"ImagePath"="System32\DRIVERS\swenum.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\swmidi]
"ImagePath"="system32\drivers\swmidi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SwPrv]
"ImagePath"="C:\WINDOWS\System32\dllhost.exe /Processid:{20653BA3-BBDD-4A50-9C76-84E98FDEEF6E}"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\swwd]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Symantec Core LC]
"ImagePath"="C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\symc810]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\symc8xx]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\symlcbrd]
"ImagePath"="\??\C:\WINDOWS\System32\drivers\symlcbrd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sym_hi]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sym_u3]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sysaudio]
"ImagePath"="system32\drivers\sysaudio.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SysmonLog]
"ImagePath"="%SystemRoot%\system32\smlogsvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TapiSrv]
"ServiceDll"="%SystemRoot%\System32\tapisrv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip]
"ImagePath"="System32\DRIVERS\tcpip.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDPIPE]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDTCP]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TermDD]
"ImagePath"="System32\DRIVERS\termdd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TermService]
"ServiceDll"="%SystemRoot%\System32\termsrv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Themes]
"ServiceDll"="%SystemRoot%\System32\shsvcs.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TlntSvr]
"ImagePath"="C:\WINDOWS\System32\tlntsvr.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tmcfw]
"ImagePath"="system32\DRIVERS\TM_CFW.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tmcomm]
"ImagePath"="\??\C:\WINDOWS\system32\drivers\tmcomm.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tmmbd]
"ImagePath"="system32\DRIVERS\tm_mbd_c.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tmntsrv]
"ImagePath"="C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TmPfw]
"ImagePath"="C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tmpreflt]
"ImagePath"="system32\DRIVERS\tmpreflt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tmproxy]
"ImagePath"="C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tmtdi]
"ImagePath"="system32\DRIVERS\tmtdi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tmxpflt]
"ImagePath"="system32\DRIVERS\tmxpflt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TosIde]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TrkWks]
"ServiceDll"="%SystemRoot%\system32\trkwks.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TSDDD]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TVICHW32]
"ImagePath"="\??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Udfs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ultra]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Update]
"ImagePath"="System32\DRIVERS\update.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\upnphost]
"ServiceDll"="%SystemRoot%\System32\upnphost.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UPS]
"ImagePath"="%SystemRoot%\System32\ups.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\USBAAPL]
"ImagePath"="System32\Drivers\usbaapl.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbccgp]
"ImagePath"="System32\DRIVERS\usbccgp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbehci]
"ImagePath"="system32\DRIVERS\usbehci.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbhub]
"ImagePath"="System32\DRIVERS\usbhub.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbprint]
"ImagePath"="System32\DRIVERS\usbprint.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbscan]
"ImagePath"="System32\DRIVERS\usbscan.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\USBSTOR]
"ImagePath"="System32\DRIVERS\USBSTOR.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usbuhci]
"ImagePath"="System32\DRIVERS\usbuhci.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\usnjsvc]
"ImagePath"="\"C:\Program Files\Windows Live\Messenger\usnsvc.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VgaSave]
"ImagePath"="\SystemRoot\System32\drivers\vga.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ViaIde]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VolSnap]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsapint]
"ImagePath"="system32\DRIVERS\vsapint.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VSS]
"ImagePath"="%SystemRoot%\System32\vssvc.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VxD]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\W32Time]
"ServiceDll"="%systemroot%\system32\w32time.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\W3SVC]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Wanarp]
"ImagePath"="System32\DRIVERS\wanarp.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WDICA]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wdmaud]
"ImagePath"="system32\drivers\wdmaud.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WebClient]
"ServiceDll"="%SystemRoot%\System32\webclnt.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\winmgmt]
"ServiceDll"="%SystemRoot%\system32\wbem\WMIsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Winsock]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinSock2]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinTrust]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WLNR]
"ImagePath"="System32\DRIVERS\WLNR.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WLSetupSvc]
"ImagePath"="\"C:\Program Files\Windows Live\installer\WLSetupSvc.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmdmPmSN]
"ServiceDll"="C:\WINDOWS\system32\MsPMSNSv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Wmi]
"ServiceDll"="%SystemRoot%\System32\advapi32.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmiApRpl]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WmiApSrv]
"ImagePath"="C:\WINDOWS\System32\wbem\wmiapsrv.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WMPNetworkSvc]
"ImagePath"="\"C:\Program Files\Windows Media Player\WMPNetwk.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WpdUsb]
"ImagePath"="System32\Drivers\wpdusb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wscsvc]
"ServiceDll"="%SYSTEMROOT%\system32\wscsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WSTCODEC]
"ImagePath"="System32\DRIVERS\WSTCODEC.SYS"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wuauserv]
"ServiceDll"="C:\WINDOWS\system32\wuauserv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfPf]
"ImagePath"="system32\DRIVERS\WudfPf.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfRd]
"ImagePath"="system32\DRIVERS\wudfrd.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WudfSvc]
"ServiceDll"="%SystemRoot%\System32\WUDFSvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WZCSVC]
"ServiceDll"="%SystemRoot%\System32\wzcsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xmlprov]
"ServiceDll"="%SystemRoot%\System32\xmlprov.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{1C131E5A-DDAD-4FD0-AE6E-2FE9D4C67A87}]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{3E9B45AD-9F74-4129-AC5C-4406E224FE5C}]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{4B515309-8097-4B9E-A99C-DAB3155E61F5}]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{53FB8111-60CE-4DAB-BAFB-1563743C4C1F}]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{78B39095-6CB3-40B6-A8C7-5BBA97780181}]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{9C4CADFA-6D1A-417E-89E7-8A3F722E23A8}]
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
.
**************************************************************************
.
Completion time: 2008-09-03 21:51:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-04 02:51:13
Pre-Run: 5,318,754,304 bytes free
Post-Run: 6,079,987,712 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
845 --- E O F --- 2008-09-04 02:50:18