Combo Fix log
"Compaq_Owner" - 2007-07-13 9:08:09 - ComboFix 07-07-13.8 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\qmopt.dll
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_LANMANDRV
((((((((((((((((((((((((( Files Created from 2007-06-13 to 2007-07-13 )))))))))))))))))))))))))))))))
2007-07-13 09:04 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-12 16:18 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\APPLIC~1\Filehand
2007-07-10 08:48 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-07-10 08:48 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-09 07:58 <DIR> d-------- C:\Program Files\Trend Micro
2007-07-08 17:17 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\.thinupload
2007-07-07 18:05 <DIR> d-------- C:\WINDOWS\McAfee.com
2007-07-07 12:22 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\APPLIC~1\.clamwin
2007-07-07 11:15 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-07 11:10 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\APPLIC~1\SpywareBot
2007-07-06 19:47 <DIR> d-------- C:\Program Files\ClamWin
2007-07-06 19:47 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\.clamwin
2007-07-06 18:01 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\APPLIC~1\WholeSecurity
2007-07-06 17:57 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\.housecall6.6
2007-07-06 17:51 109 --ahs---- C:\WINDOWS\system32\1480663414.dat
2007-07-06 17:26 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\APPLIC~1\My Battle for Middle-earth(tm) II Files
2007-07-05 22:00 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\APPLIC~1\Opera
2007-07-05 20:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\espionServerData
2007-07-05 19:56 20,640 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-07-05 19:56 109,568 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-07-05 19:56 108,544 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-06-25 17:26 <DIR> d-------- C:\Program Files\InfraRecorder
2007-06-21 12:36 <DIR> d-------- C:\Program Files\eMusic Download Manager
2007-06-19 13:24 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2007-06-14 12:53 <DIR> d-------- C:\Program Files\netbeans-5.5.1
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-13 12:53:31 -------- d-----w C:\DOCUME~1\COMPAQ~1\APPLIC~1\Launchy
2007-07-12 20:11:59 -------- d-----w C:\DOCUME~1\COMPAQ~1\APPLIC~1\OpenOffice.org2
2007-07-08 00:25:00 664 ----a-w C:\WINDOWS\system32\d3d9caps.dat
2007-07-07 16:22:16 -------- d-----w C:\DOCUME~1\COMPAQ~1\APPLIC~1\.clamwin
2007-07-06 00:30:50 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-07-05 17:56:35 -------- d-----w C:\DOCUME~1\COMPAQ~1\APPLIC~1\gtk-2.0
2007-06-22 18:44:51 -------- d-----w C:\Program Files\Google
2007-06-21 16:36:31 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-19 17:24:13 6,904 -c--a-w C:\WINDOWS\mozver.dat
2007-06-16 15:28:07 -------- d-----w C:\DOCUME~1\COMPAQ~1\APPLIC~1\My Battle for Middle-earth Files
2007-06-15 19:40:50 -------- d-----w C:\Program Files\Mozilla Thunderbird
2007-06-14 01:38:40 -------- d-----w C:\DOCUME~1\COMPAQ~1\APPLIC~1\VMware
2007-06-12 11:56:47 -------- d-----w C:\Program Files\CCleaner
2007-06-08 14:45:09 -------- d-----w C:\Program Files\OpenOffice.org 2.2
2007-06-08 14:44:03 -------- d-----w C:\Program Files\OpenOffice.org 2.1
2007-06-07 18:49:20 -------- d--h--w C:\Program Files\Zero G Registry
2007-06-07 18:49:20 -------- d-----w C:\Program Files\WordCorr
2007-06-04 13:39:25 -------- d-----w C:\Program Files\Inno Setup 5
2007-06-02 13:55:55 -------- d-----w C:\DOCUME~1\COMPAQ~1\APPLIC~1\CmapTools
2007-06-01 12:42:16 -------- d-----w C:\Program Files\Scribus 1.3.3.7
2007-05-31 14:44:28 -------- d-----w C:\Program Files\IHMC CmapTools
2007-05-30 21:44:11 -------- d-----w C:\Program Files\Common Files\VMware
2007-05-30 21:43:36 -------- d-----w C:\Program Files\VMware
2007-05-25 20:03:12 -------- d-----w C:\Program Files\Windows Media Bonus Pack for Windows XP
2007-05-24 20:03:11 -------- d-----w C:\Program Files\Microsoft ActiveSync
2007-05-23 14:08:08 768 ----a-w C:\WINDOWS\system32\d3d8caps.dat
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-13 07:21:14 271,360 ----a-w C:\WINDOWS\system32\mscoree.dll
2007-04-13 00:05:04 5,120 ----a-r C:\WINDOWS\system32\vnetinst.dll
2007-04-13 00:05:04 37,888 ----a-w C:\WINDOWS\system32\vmnetbridge.dll
2007-04-13 00:05:04 364,631 ----a-w C:\WINDOWS\system32\vnetlib.dll
2007-04-13 00:05:04 135,168 ----a-w C:\WINDOWS\system32\vmnat.exe
2007-04-13 00:05:04 106,496 ----a-w C:\WINDOWS\system32\vmnetdhcp.exe
2007-03-15 19:26:30 943,488 ----a-w C:\Program Files\Bginfo.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-10-22 23:08 62080 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-07-12 16:32]
"ClamWin"="C:\Program Files\ClamWin\bin\ClamTray.exe" [2007-05-27 20:48]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-07-12 08:49]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6dd8cd0f-17e4-11db-9c66-0015f2ab0e95}]
AutoRun\command- K:\PStart.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f4d397e4-ca5f-11da-98f8-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
Contents of the 'Scheduled Tasks' folder
2007-07-08 07:00:00 C:\WINDOWS\tasks\SpywareBot Scheduled Scan.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-13 09:11:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-13 9:13:36 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-13 09:13
--- E O F ---