Logs as requested
ComboFix 08-08-28.04 - Computer 2008-08-29 20:18:45.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1648 [GMT 1:00]
Running from: C:\Documents and Settings\Computer\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Computer\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
FILE ::
C:\WINDOWS\system32\levtjrfs.dll
C:\WINDOWS\system32\msxml71.dll
.
/wow section - STAGE 45
pv: No matching processes found
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
/wow section - STAGE 46
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
The process cannot access the file because it is being used by another process.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Computer\Application Data\uTorrent
C:\Documents and Settings\Computer\Application Data\uTorrent\(Wifey - Xxx) Wifeysworld Swallow Compilation.avi.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\[DVD_MUSIC_VIDEO] GEORGE_MICHAEL---TWENTY_FIVE_DVD1 by Zaelous_Inquisitor90.ISO.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\
0010 - Allie.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\33_private_XXX_Videos_Amateur.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\44_echte_private_piss_Videos_Amateur.rar.1.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\44_echte_private_piss_Videos_Amateur.rar.2.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\44_echte_private_piss_Videos_Amateur.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\50_private_Amateur_Videos_echt.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\63_private_Amateur_Videos_Amateur.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\85_Spanner_Voyeur_Videos_echt.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\A Time To Remember 1976-1980.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Abby Winters - Girls In Love.avi.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\alicia-solo.wmv.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Amy Winehouse Live In London-I Told You I Was Trouble(DVDRIP).torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Amy_Winehouse-Back_To_Black_(Deluxe_Edition)-2CD-2007-UKP.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Anal Fisting And Pissing End Of Violation Of Audrey Hollander.avi.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Anchors Aweigh.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Audrey.Hollander.and.Angelique.Morreau.Fisting.wmv.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Back.To.School.Special.[English].XXX.DVDRip.XviD-[
WwW.TorrentesX.CoM].torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Barbra Streisand - Duets [2002][CD+3Vids+Covers].torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Barbra Streisand - Live In Concert 2006.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Barely Legal Innocence 7 XXX [DVDRiP][Teen-Over-18].
www.lokotorrents.com.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Barely Legal School Girls 2 XXX DVDRip 2006.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Barely Legal School Girls 2.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Barely.Legal.Straight.To.Anal.[English].XXX.DVDRip.XVID-[
WwW.TorrentesX.CoM].avi.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Birth place of dance Vol.1 (the best dance classics) 2007.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Bookworm Bitches - Cytherea - 7 squirting orgasms!.wmv.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Bookworm Bitches.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Cannabis - Cooking With Marijuana - The Gourmet Menu By Chef Hans.avi.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Classic Euphoria cd3 With covers(NiTrO).torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Daniella Rush & Meridian-fist & piss.mpg.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\David Bowie-The Rise And Fall Of Ziggy Stardust And The Spiders From Mars(Darkside_RG).torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\David Bowie - The Rise And Fall Of Ziggy Stardust And The Spiders From Mars - 06-11-07 - Pn Pass.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\david bowie.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\David Icke- Was He Right.divx.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\dht.dat
C:\Documents and Settings\Computer\Application Data\uTorrent\DJ Tiesto - Adagio for Strings Video. live.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\DJ Tiesto - Best and New 2005.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Duffy - Mercy [192kbps][Youtuberip].mp3.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Duffy - Rockferry.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Edinburgh.Military.Tattoo.2008.WS.PDTV.XviD-COUNCiL.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Floorfillers Anthems-3CD-2007 seeded by
www.p2p-world.dl.am.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Floorfillers Anthems [2007] ( Zaion RG ).torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Flowers Squirt Shower 4 XXX DVDRip 2006.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\For All Who Hate The Red Scum Manchester City F.C. - Boys in Blue.torrent.mp3.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Frauen_im_Suff_Teil_1_120_min_deutsch.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\GATECRASHER IMMORTAL WITH TRACK NAMES ETC FIXED.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Gilmour_OAI.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Girls Aloud-The Sound Of-Greatest Hits (withcovers) a DHZ.Inc Release.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Great Magic Tricks - Maths.Numbers.zip.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Hacking for Dummies.pdf.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Hacking Wireless Networks for Dummies.pdf.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Harry Potter Audiobooks read by Jim Dale (Chaptered, ready for iPod).torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Hash1s_38_Of_The_Greatest_Hash1_Singles_Of_All_Time.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\How To Do Everything With Your iPod (mcgraw-hill).pdf.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\ImTOO DVD To iPod Converter.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Internal_Explosions_6_Teen_Porn_XXX.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Japanese Teen Great Anal.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Jenaveve Jolie and Sativa Rose - Sweet Cream Pies - by Bomkia.avi.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Johnny Cash - Man In Black (The Very Best Of).torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Justin Timberlake - Future Sex-Love Sounds (2006) - R&B.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Kasabian - Kasabian.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Kirsty MacColl - Tropical Brainstorm (Bonus Tracks) Japan.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Lily Thai - Peter North.avi.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Mamma Mia PFD ENG XviD.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\maria_dea-solo.wmv.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Mark Ronson - Version.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Microsoft Office XP PRO (word, excel, powerpoint, outlook, access, frontpage, Publisher 2003).torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\MILFS Night Out.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Ministry Of Sound - Annual 2008 3CD[EAC-@320 MP3](oan).torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Ministry of Sound Anthems 1991-2008.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Ministry Of Sound The Annual 2008.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Morrissey-Vauxhall And I(Darkside_RG).torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Now Thats What i Call Music 65 A DHZ.Inc Pre release.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Now_Thats_What_I_Call_Music_64-2CD-2006.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Oasis - Stop The Clocks (2006) - Rock [
www.torrentazos.com].rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Only PCTools -~mininova.org~-.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Paul McKenna - Easy Weight Loss & Quit Smoking Now .rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Paul Simon-The Paul Simon Anthology(Darkside_RG).torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Pink Floyd - Animals.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Pirates.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Playing With Cytherea XXX [DVDRIP][Hardcore][
www.sexotorrent.com].torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\PrivateSwingerparty_Amateur.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Raymond Briggs, The Snowman & Father Christmas.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Razorlight - Razorlight [2006][CD+Vid+Cov]192Kbps.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Razorlight - Up All Night (Darkside_RG).torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\resume.dat
C:\Documents and Settings\Computer\Application Data\uTorrent\resume.dat.old
C:\Documents and Settings\Computer\Application Data\uTorrent\ROD STEWART-STILL THE SAME GREAT ROCK CLASSICS OF OUR TIME.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Roger Waters.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\rss.dat
C:\Documents and Settings\Computer\Application Data\uTorrent\SapphicErotica.Angelique.&.Catherine.XXX.[SiteRip][GoldenPirates].torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Scissor Sisters - Ta-Dah (2006) - Pop [
www.torrentazos.com].rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\settings.dat
C:\Documents and Settings\Computer\Application Data\uTorrent\settings.dat.old
C:\Documents and Settings\Computer\Application Data\uTorrent\Sexy.Beast.avi.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Shameless Season 1.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Shameless Season 2.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Shameless Season 3.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Snow.Cake.2006.LiMiTED.DVDRiP.XviD-HLS[
www.moviex.info].torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Snow_Patrol-Eyes_Open-2006-FM.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Sophie and Sandy - Christmas Fisting.avi.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Squirting 101 - teaches how to make a girl squirt!.mpg.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\stop smoking forever.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Take That - Beautiful World [2006][CD+SkidVid+Cov].torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Teagan.Sexual.Freak.2.[English].XXX.DVDRip.XviD-[
WwW.TorrentesX.CoM].avi.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\TeagansJuices_scene_1.wmv.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Teen - Self ass fist.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Teeny-Päärchen gestohlenes Video erste Sexerfahrungen.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The Anthems.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The Art And Science Of Cooking With Cannabis.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The Best Christmas Album In The World Ever [2CD] [
www.pctorrent.com].torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The Kooks - Inside in, Inside out.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The Perry Como Christmas Album [Compilation].torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The Simpsons 2007.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The Simpsons Movie (2007) [Eng] [DVDrip].torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The Smiths Best 1.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The Smiths Best 2.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The Zutons - Tired Of Hangin' Around A DHZ.Inc release.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The.Departed.TELECINE.XViD-PUKKA[
www.moviex.info].torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The.Queen.PROPER.DVDSCR.XviD-MoF[
www.moviex.info].torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The.Simpsons.Movie.DVDSCR.DVDR-mVs.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\The_Who-Endless_Wire-2006-MP3.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Tiesto - Elements Of Life (limited Edition).torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Tom Petty & The Heartbreakers-22 cd.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Tom Petty & The Heartbreakers - 2005 - Live in Concert Soundstage (Discs 1&2) XviD.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Total-Privat_Total-Pervers_(Andrea_Dalton).zip.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\totalaudioconveter.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Two_Very Cute_Teens(Hot_Lesbian_Sceenes)_This_time_in_privacy_of_their_rooms_learning_fisting_SY1.wmv.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\utorrent.lng
C:\Documents and Settings\Computer\Application Data\uTorrent\Va_Pop Party 4(withcovers) a DHZ.Inc Release.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\We All Scream For Ass Cream.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\We Were Dead Before the Ship Even Sank.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Who (The) - Quadrophenia (1973) @ 320.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\wifeys world.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Wigan Pier 55.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\WinAVI.Video.Converter.v7.7.Incl.Keymaker-CORE.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Windows 98 Second Edition English.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\World.Trade.Center.2006.TS.Internal.XViD-GRuNTZ[
www.moviex.info].torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\World.Trade.Center.2006.TS.XviD.Proper-NoGrp.zip.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\
www.hornywhores.net_MILF.Squirters.9.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Xilisoft PSP iPOD CD to MOV MP3 WAV MPEG WMA AVI RM Video Audio Converter Ripper.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Xvision Youtube Video Player Downloader v1.0 - BEAN.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\XXX Amateur Porn - Screaming Moaning Squirting Homemade Anal Sex.rar.torrent
C:\Documents and Settings\Computer\Application Data\uTorrent\Zutons - Tired Of Hanging Around [2006][CD+Vid+Cov].torrent
C:\Program Files\uTorrent
C:\Program Files\uTorrent\4602-utorrent.e353.dmp
C:\WINDOWS\system32\levtjrfs.dll
C:\WINDOWS\system32\msxml71.dll
C:\WINDOWS\system32\sfrjtvel.ini
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-29 )))))))))))))))))))))))))))))))
.
2008-08-29 20:08 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-29 20:07 . 2008-08-29 20:07 <DIR> d-------- C:\Program Files\Common Files\Java
2008-08-28 00:17 . 2008-08-28 00:17 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-27 17:47 . 2008-08-27 17:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Documents
2008-08-27 16:34 . 2008-08-27 16:34 189 --a------ C:\WINDOWS\wininit.ini
2008-08-27 15:57 . 2008-08-27 16:00 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-27 15:57 . 2008-08-28 22:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-12 09:16 . 2008-07-23 17:50 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2008-08-12 09:16 . 2008-07-23 17:50 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-08-12 09:16 . 2008-07-23 17:50 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-08-10 21:04 . 2008-08-10 21:03 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-08-10 21:04 . 2008-08-10 21:03 299,392 --a------ C:\WINDOWS\system32\imon.dll
2008-08-10 21:04 . 2008-08-10 21:03 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-29 19:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-08-29 19:08 --------- d-----w C:\Program Files\Java
2008-08-27 13:17 --------- d-----w C:\Program Files\ESET
2008-08-16 09:20 --------- d-----w C:\Program Files\BKE v2.2
2008-08-12 08:17 --------- d-----w C:\Program Files\DivX
2008-07-27 19:22 --------- d-----w C:\Program Files\V+ Application
2008-07-27 19:19 1,167,360 ------w C:\WINDOWS\Setup1.exe
2008-07-27 19:18 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-07-27 18:28 --------- d-----w C:\Program Files\Conduit
2008-07-26 20:01 --------- d-----w C:\Program Files\Lavasoft
2008-07-26 20:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-26 20:00 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-26 19:58 --------- d-----w C:\Documents and Settings\Computer\Application Data\Lavasoft
2008-07-25 19:15 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-07-25 19:15 --------- d-----w C:\Program Files\Common Files\Nokia
2008-07-25 19:14 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-07-25 19:13 --------- d-----w C:\Program Files\Nokia
2008-07-25 19:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-07-23 16:50 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-07-11 15:51 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-07-10 09:11 --------- d-----w C:\Documents and Settings\Computer\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-07-09 03:53 --------- d-----w C:\Program Files\NOS
2008-07-09 03:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\NOS
2008-07-08 19:37 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-07-08 19:35 --------- d-----w C:\Program Files\Common Files\Adobe
.
------- Sigcheck -------
2004-08-04 05:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe
2004-08-04 05:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\dllcache\svchost.exe
2005-03-02 19:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 16:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-04 05:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 19:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2007-03-08 16:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\user32.dll
2007-03-08 16:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\dllcache\user32.dll
2004-08-04 05:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll
2004-08-04 05:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\dllcache\ws2_32.dll
2004-08-04 05:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe
2004-08-04 05:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\dllcache\winlogon.exe
2004-08-04 04:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\dllcache\ndis.sys
2004-08-04 04:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys
2004-08-04 04:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\dllcache\ip6fw.sys
2004-08-04 04:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
2004-08-04 05:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\services.exe
2004-08-04 05:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\dllcache\services.exe
2004-08-04 05:56 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\lsass.exe
2004-08-04 05:56 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\dllcache\lsass.exe
2004-08-04 05:56 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\ctfmon.exe
2004-08-04 05:56 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\dllcache\ctfmon.exe
2004-08-04 05:56 24576 39b1ffb03c2296323832acbae50d2aff C:\WINDOWS\system32\userinit.exe
2004-08-04 05:56 24576 39b1ffb03c2296323832acbae50d2aff C:\WINDOWS\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((( snapshot@2008-08-29_ 0.30.58.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-11-10 11:27:06 49,248 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 00:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2005-11-10 11:27:16 49,250 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 00:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2005-11-10 13:03:54 127,078 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-06-10 01:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetIcon"="C:\Program Files\SMSC\Seticon.exe" [2003-07-29 18:33 40960]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-10 04:06 7311360]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-08-10 21:03 950664]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"SoundMan"="SOUNDMAN.EXE" [2005-06-20 14:42 77824 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:56 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\btbb_McciTrayApp]
--------- 2007-05-23 12:52 936960 C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link AirPlus G]
--a------ 2004-07-09 15:07 1249280 C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--------- 2006-03-23 17:06 1398272 C:\Program Files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
--a------ 2008-03-26 18:41 1232896 C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
--a------ 2008-04-16 12:53 1079808 C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-06-21 12:09 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2005-08-31 17:11 2478080 C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
--a------ 2006-07-21 16:19 129536 C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Real\\RealPlayer\\trueplay.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\Ahead\\Nero MediaHome\\NeroMediaHome.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
R2 MAC_MOT;MAC_MOT;C:\WINDOWS\system32\drivers\MAC_MOT.sys [2003-05-28 04:55]
R2 PAR1284;PAR1284;C:\WINDOWS\system32\drivers\PAR1284.sys [2002-03-20 13:46]
R3 INFUSB;INFUSB;C:\WINDOWS\system32\drivers\infusb.sys [2002-09-30 16:16]
S3 imhidusb;Immersion's HID USB Driver;C:\WINDOWS\system32\drivers\imhidusb.sys []
S3 ZD1201U;ZyDAS ZD1201 IEEE 802.11b Wireless LAN Driver (USB);C:\WINDOWS\system32\DRIVERS\zd1201u.sys []
S3 ZDNDIS5;ZDNDIS5 Protocol Driver;C:\WINDOWS\system32\ZDNDIS5.SYS [2002-10-30 12:43]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EDC12331-E47A-B81E-D43B-74C9E78B5193}]
C:\WINDOWS\system32:lpr.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-29 21:41:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Kontiki\KService.exe
C:\Program Files\ESET\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\update\update.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-08-29 21:47:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-29 20:46:54
ComboFix2.txt 2008-08-28 23:31:35
Pre-Run: 50,466,332,672 bytes free
Post-Run: 50,446,217,216 bytes free
341 --- E O F --- 2008-08-14 21:28:45
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:54, on 29/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\SMSC\Seticon.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\update\update.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://uk.red.clientapps.yahoo.com/...b/*http://uk.docs.yahoo.com/info/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://uk.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SetIcon] C:\Program Files\SMSC\Seticon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1166226399125
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
--
End of file - 6130 bytes