Hello Shaba,
ComboFix 08-01-16.3 - Owner 2008-01-16 20:06:50.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.623 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\My Documents\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\bipudihu.dll
C:\WINDOWS\dmlurgjc.dll
C:\WINDOWS\edeliraf.dll
C:\WINDOWS\olmdijuv.dll
C:\WINDOWS\vulmrglu.dll
C:\WINDOWS\xkbincru.dll
C:\WINDOWS\yhwpaxyh.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\bicekglt
C:\WINDOWS\bicekglt\1.png
C:\WINDOWS\bicekglt\2.png
C:\WINDOWS\bicekglt\3.png
C:\WINDOWS\bicekglt\4.png
C:\WINDOWS\bicekglt\5.png
C:\WINDOWS\bicekglt\6.png
C:\WINDOWS\bicekglt\7.png
C:\WINDOWS\bicekglt\8.png
C:\WINDOWS\bicekglt\9.png
C:\WINDOWS\bicekglt\bottom-rc.gif
C:\WINDOWS\bicekglt\config.png
C:\WINDOWS\bicekglt\content.png
C:\WINDOWS\bicekglt\download.gif
C:\WINDOWS\bicekglt\frame-bg.gif
C:\WINDOWS\bicekglt\frame-bottom-left.gif
C:\WINDOWS\bicekglt\frame-h1bg.gif
C:\WINDOWS\bicekglt\head.png
C:\WINDOWS\bicekglt\icon.png
C:\WINDOWS\bicekglt\index.html
C:\WINDOWS\bicekglt\main.css
C:\WINDOWS\bicekglt\memory-prots.png
C:\WINDOWS\bicekglt\net.png
C:\WINDOWS\bicekglt\pc-mag.gif
C:\WINDOWS\bicekglt\pc.gif
C:\WINDOWS\bicekglt\poloska1.png
C:\WINDOWS\bicekglt\poloska2.png
C:\WINDOWS\bicekglt\poloska3.png
C:\WINDOWS\bicekglt\promo1.html
C:\WINDOWS\bicekglt\promo10.html
C:\WINDOWS\bicekglt\promo11.html
C:\WINDOWS\bicekglt\promo12.html
C:\WINDOWS\bicekglt\promo13.html
C:\WINDOWS\bicekglt\promo14.html
C:\WINDOWS\bicekglt\promo15.html
C:\WINDOWS\bicekglt\promo16.html
C:\WINDOWS\bicekglt\promo17.html
C:\WINDOWS\bicekglt\promo18.html
C:\WINDOWS\bicekglt\promo2.html
C:\WINDOWS\bicekglt\promo3.html
C:\WINDOWS\bicekglt\promo4.html
C:\WINDOWS\bicekglt\promo5.html
C:\WINDOWS\bicekglt\promo6.html
C:\WINDOWS\bicekglt\promo7.html
C:\WINDOWS\bicekglt\promo8.html
C:\WINDOWS\bicekglt\promo9.html
C:\WINDOWS\bicekglt\reg.png
C:\WINDOWS\bicekglt\repair.png
C:\WINDOWS\bicekglt\scr-1.png
C:\WINDOWS\bicekglt\scr-2.png
C:\WINDOWS\bicekglt\start.png
C:\WINDOWS\bicekglt\styles.css
C:\WINDOWS\bicekglt\top-rc.gif
C:\WINDOWS\bicekglt\vline.gif
C:\WINDOWS\bicekglt\wp.png
C:\WINDOWS\bipudihu.dll
C:\WINDOWS\dmlurgjc.dll
C:\WINDOWS\edeliraf.dll
C:\WINDOWS\olmdijuv.dll
C:\WINDOWS\rgahdope
C:\WINDOWS\rgahdope\1.png
C:\WINDOWS\rgahdope\2.png
C:\WINDOWS\rgahdope\3.png
C:\WINDOWS\rgahdope\4.png
C:\WINDOWS\rgahdope\5.png
C:\WINDOWS\rgahdope\6.png
C:\WINDOWS\rgahdope\7.png
C:\WINDOWS\rgahdope\8.png
C:\WINDOWS\rgahdope\9.png
C:\WINDOWS\rgahdope\bottom-rc.gif
C:\WINDOWS\rgahdope\config.png
C:\WINDOWS\rgahdope\content.png
C:\WINDOWS\rgahdope\download.gif
C:\WINDOWS\rgahdope\frame-bg.gif
C:\WINDOWS\rgahdope\frame-bottom-left.gif
C:\WINDOWS\rgahdope\frame-h1bg.gif
C:\WINDOWS\rgahdope\head.png
C:\WINDOWS\rgahdope\icon.png
C:\WINDOWS\rgahdope\index.html
C:\WINDOWS\rgahdope\main.css
C:\WINDOWS\rgahdope\memory-prots.png
C:\WINDOWS\rgahdope\net.png
C:\WINDOWS\rgahdope\pc-mag.gif
C:\WINDOWS\rgahdope\pc.gif
C:\WINDOWS\rgahdope\poloska1.png
C:\WINDOWS\rgahdope\poloska2.png
C:\WINDOWS\rgahdope\poloska3.png
C:\WINDOWS\rgahdope\promo1.html
C:\WINDOWS\rgahdope\promo10.html
C:\WINDOWS\rgahdope\promo11.html
C:\WINDOWS\rgahdope\promo12.html
C:\WINDOWS\rgahdope\promo13.html
C:\WINDOWS\rgahdope\promo14.html
C:\WINDOWS\rgahdope\promo15.html
C:\WINDOWS\rgahdope\promo16.html
C:\WINDOWS\rgahdope\promo17.html
C:\WINDOWS\rgahdope\promo18.html
C:\WINDOWS\rgahdope\promo2.html
C:\WINDOWS\rgahdope\promo3.html
C:\WINDOWS\rgahdope\promo4.html
C:\WINDOWS\rgahdope\promo5.html
C:\WINDOWS\rgahdope\promo6.html
C:\WINDOWS\rgahdope\promo7.html
C:\WINDOWS\rgahdope\promo8.html
C:\WINDOWS\rgahdope\promo9.html
C:\WINDOWS\rgahdope\reg.png
C:\WINDOWS\rgahdope\repair.png
C:\WINDOWS\rgahdope\scr-1.png
C:\WINDOWS\rgahdope\scr-2.png
C:\WINDOWS\rgahdope\start.png
C:\WINDOWS\rgahdope\styles.css
C:\WINDOWS\rgahdope\top-rc.gif
C:\WINDOWS\rgahdope\vline.gif
C:\WINDOWS\rgahdope\wp.png
C:\WINDOWS\rvpqqcki
C:\WINDOWS\rvpqqcki\1.png
C:\WINDOWS\rvpqqcki\2.png
C:\WINDOWS\rvpqqcki\3.png
C:\WINDOWS\rvpqqcki\4.png
C:\WINDOWS\rvpqqcki\5.png
C:\WINDOWS\rvpqqcki\6.png
C:\WINDOWS\rvpqqcki\7.png
C:\WINDOWS\rvpqqcki\8.png
C:\WINDOWS\rvpqqcki\9.png
C:\WINDOWS\rvpqqcki\bottom-rc.gif
C:\WINDOWS\rvpqqcki\config.png
C:\WINDOWS\rvpqqcki\content.png
C:\WINDOWS\rvpqqcki\download.gif
C:\WINDOWS\rvpqqcki\frame-bg.gif
C:\WINDOWS\rvpqqcki\frame-bottom-left.gif
C:\WINDOWS\rvpqqcki\frame-h1bg.gif
C:\WINDOWS\rvpqqcki\head.png
C:\WINDOWS\rvpqqcki\icon.png
C:\WINDOWS\rvpqqcki\index.html
C:\WINDOWS\rvpqqcki\main.css
C:\WINDOWS\rvpqqcki\memory-prots.png
C:\WINDOWS\rvpqqcki\net.png
C:\WINDOWS\rvpqqcki\pc-mag.gif
C:\WINDOWS\rvpqqcki\pc.gif
C:\WINDOWS\rvpqqcki\poloska1.png
C:\WINDOWS\rvpqqcki\poloska2.png
C:\WINDOWS\rvpqqcki\poloska3.png
C:\WINDOWS\rvpqqcki\promo1.html
C:\WINDOWS\rvpqqcki\promo10.html
C:\WINDOWS\rvpqqcki\promo11.html
C:\WINDOWS\rvpqqcki\promo12.html
C:\WINDOWS\rvpqqcki\promo13.html
C:\WINDOWS\rvpqqcki\promo14.html
C:\WINDOWS\rvpqqcki\promo15.html
C:\WINDOWS\rvpqqcki\promo16.html
C:\WINDOWS\rvpqqcki\promo17.html
C:\WINDOWS\rvpqqcki\promo18.html
C:\WINDOWS\rvpqqcki\promo2.html
C:\WINDOWS\rvpqqcki\promo3.html
C:\WINDOWS\rvpqqcki\promo4.html
C:\WINDOWS\rvpqqcki\promo5.html
C:\WINDOWS\rvpqqcki\promo6.html
C:\WINDOWS\rvpqqcki\promo7.html
C:\WINDOWS\rvpqqcki\promo8.html
C:\WINDOWS\rvpqqcki\promo9.html
C:\WINDOWS\rvpqqcki\reg.png
C:\WINDOWS\rvpqqcki\repair.png
C:\WINDOWS\rvpqqcki\scr-1.png
C:\WINDOWS\rvpqqcki\scr-2.png
C:\WINDOWS\rvpqqcki\start.png
C:\WINDOWS\rvpqqcki\styles.css
C:\WINDOWS\rvpqqcki\top-rc.gif
C:\WINDOWS\rvpqqcki\vline.gif
C:\WINDOWS\rvpqqcki\wp.png
C:\WINDOWS\sgekiopr
C:\WINDOWS\sgekiopr\1.png
C:\WINDOWS\sgekiopr\2.png
C:\WINDOWS\sgekiopr\3.png
C:\WINDOWS\sgekiopr\4.png
C:\WINDOWS\sgekiopr\5.png
C:\WINDOWS\sgekiopr\6.png
C:\WINDOWS\sgekiopr\7.png
C:\WINDOWS\sgekiopr\8.png
C:\WINDOWS\sgekiopr\9.png
C:\WINDOWS\sgekiopr\bottom-rc.gif
C:\WINDOWS\sgekiopr\config.png
C:\WINDOWS\sgekiopr\content.png
C:\WINDOWS\sgekiopr\download.gif
C:\WINDOWS\sgekiopr\frame-bg.gif
C:\WINDOWS\sgekiopr\frame-bottom-left.gif
C:\WINDOWS\sgekiopr\frame-h1bg.gif
C:\WINDOWS\sgekiopr\head.png
C:\WINDOWS\sgekiopr\icon.png
C:\WINDOWS\sgekiopr\indexwp.html
C:\WINDOWS\sgekiopr\main.css
C:\WINDOWS\sgekiopr\memory-prots.png
C:\WINDOWS\sgekiopr\net.png
C:\WINDOWS\sgekiopr\pc-mag.gif
C:\WINDOWS\sgekiopr\pc.gif
C:\WINDOWS\sgekiopr\poloska1.png
C:\WINDOWS\sgekiopr\poloska2.png
C:\WINDOWS\sgekiopr\poloska3.png
C:\WINDOWS\sgekiopr\promowp1.html
C:\WINDOWS\sgekiopr\promowp2.html
C:\WINDOWS\sgekiopr\promowp3.html
C:\WINDOWS\sgekiopr\promowp4.html
C:\WINDOWS\sgekiopr\promowp5.html
C:\WINDOWS\sgekiopr\reg.png
C:\WINDOWS\sgekiopr\repair.png
C:\WINDOWS\sgekiopr\scr-1.png
C:\WINDOWS\sgekiopr\scr-2.png
C:\WINDOWS\sgekiopr\start.png
C:\WINDOWS\sgekiopr\styles.css
C:\WINDOWS\sgekiopr\Thumbs.db
C:\WINDOWS\sgekiopr\top-rc.gif
C:\WINDOWS\sgekiopr\vline.gif
C:\WINDOWS\sgekiopr\wp.png
C:\WINDOWS\srsnrvoo
C:\WINDOWS\srsnrvoo\1.png
C:\WINDOWS\srsnrvoo\2.png
C:\WINDOWS\srsnrvoo\3.png
C:\WINDOWS\srsnrvoo\4.png
C:\WINDOWS\srsnrvoo\5.png
C:\WINDOWS\srsnrvoo\6.png
C:\WINDOWS\srsnrvoo\7.png
C:\WINDOWS\srsnrvoo\8.png
C:\WINDOWS\srsnrvoo\9.png
C:\WINDOWS\srsnrvoo\bottom-rc.gif
C:\WINDOWS\srsnrvoo\config.png
C:\WINDOWS\srsnrvoo\content.png
C:\WINDOWS\srsnrvoo\download.gif
C:\WINDOWS\srsnrvoo\frame-bg.gif
C:\WINDOWS\srsnrvoo\frame-bottom-left.gif
C:\WINDOWS\srsnrvoo\frame-h1bg.gif
C:\WINDOWS\srsnrvoo\head.png
C:\WINDOWS\srsnrvoo\icon.png
C:\WINDOWS\srsnrvoo\index.html
C:\WINDOWS\srsnrvoo\main.css
C:\WINDOWS\srsnrvoo\memory-prots.png
C:\WINDOWS\srsnrvoo\net.png
C:\WINDOWS\srsnrvoo\pc-mag.gif
C:\WINDOWS\srsnrvoo\pc.gif
C:\WINDOWS\srsnrvoo\poloska1.png
C:\WINDOWS\srsnrvoo\poloska2.png
C:\WINDOWS\srsnrvoo\poloska3.png
C:\WINDOWS\srsnrvoo\promo1.html
C:\WINDOWS\srsnrvoo\promo10.html
C:\WINDOWS\srsnrvoo\promo11.html
C:\WINDOWS\srsnrvoo\promo12.html
C:\WINDOWS\srsnrvoo\promo13.html
C:\WINDOWS\srsnrvoo\promo14.html
C:\WINDOWS\srsnrvoo\promo15.html
C:\WINDOWS\srsnrvoo\promo16.html
C:\WINDOWS\srsnrvoo\promo17.html
C:\WINDOWS\srsnrvoo\promo18.html
C:\WINDOWS\srsnrvoo\promo2.html
C:\WINDOWS\srsnrvoo\promo3.html
C:\WINDOWS\srsnrvoo\promo4.html
C:\WINDOWS\srsnrvoo\promo5.html
C:\WINDOWS\srsnrvoo\promo6.html
C:\WINDOWS\srsnrvoo\promo7.html
C:\WINDOWS\srsnrvoo\promo8.html
C:\WINDOWS\srsnrvoo\promo9.html
C:\WINDOWS\srsnrvoo\reg.png
C:\WINDOWS\srsnrvoo\repair.png
C:\WINDOWS\srsnrvoo\scr-1.png
C:\WINDOWS\srsnrvoo\scr-2.png
C:\WINDOWS\srsnrvoo\start.png
C:\WINDOWS\srsnrvoo\styles.css
C:\WINDOWS\srsnrvoo\top-rc.gif
C:\WINDOWS\srsnrvoo\vline.gif
C:\WINDOWS\srsnrvoo\wp.png
C:\WINDOWS\vfluwsse
C:\WINDOWS\vfluwsse\1.png
C:\WINDOWS\vfluwsse\2.png
C:\WINDOWS\vfluwsse\3.png
C:\WINDOWS\vfluwsse\4.png
C:\WINDOWS\vfluwsse\5.png
C:\WINDOWS\vfluwsse\6.png
C:\WINDOWS\vfluwsse\7.png
C:\WINDOWS\vfluwsse\8.png
C:\WINDOWS\vfluwsse\9.png
C:\WINDOWS\vfluwsse\bottom-rc.gif
C:\WINDOWS\vfluwsse\config.png
C:\WINDOWS\vfluwsse\content.png
C:\WINDOWS\vfluwsse\download.gif
C:\WINDOWS\vfluwsse\frame-bg.gif
C:\WINDOWS\vfluwsse\frame-bottom-left.gif
C:\WINDOWS\vfluwsse\frame-h1bg.gif
C:\WINDOWS\vfluwsse\head.png
C:\WINDOWS\vfluwsse\icon.png
C:\WINDOWS\vfluwsse\index.html
C:\WINDOWS\vfluwsse\main.css
C:\WINDOWS\vfluwsse\memory-prots.png
C:\WINDOWS\vfluwsse\net.png
C:\WINDOWS\vfluwsse\pc-mag.gif
C:\WINDOWS\vfluwsse\pc.gif
C:\WINDOWS\vfluwsse\poloska1.png
C:\WINDOWS\vfluwsse\poloska2.png
C:\WINDOWS\vfluwsse\poloska3.png
C:\WINDOWS\vfluwsse\promo1.html
C:\WINDOWS\vfluwsse\promo10.html
C:\WINDOWS\vfluwsse\promo11.html
C:\WINDOWS\vfluwsse\promo12.html
C:\WINDOWS\vfluwsse\promo13.html
C:\WINDOWS\vfluwsse\promo14.html
C:\WINDOWS\vfluwsse\promo15.html
C:\WINDOWS\vfluwsse\promo16.html
C:\WINDOWS\vfluwsse\promo17.html
C:\WINDOWS\vfluwsse\promo18.html
C:\WINDOWS\vfluwsse\promo2.html
C:\WINDOWS\vfluwsse\promo3.html
C:\WINDOWS\vfluwsse\promo4.html
C:\WINDOWS\vfluwsse\promo5.html
C:\WINDOWS\vfluwsse\promo6.html
C:\WINDOWS\vfluwsse\promo7.html
C:\WINDOWS\vfluwsse\promo8.html
C:\WINDOWS\vfluwsse\promo9.html
C:\WINDOWS\vfluwsse\reg.png
C:\WINDOWS\vfluwsse\repair.png
C:\WINDOWS\vfluwsse\scr-1.png
C:\WINDOWS\vfluwsse\scr-2.png
C:\WINDOWS\vfluwsse\start.png
C:\WINDOWS\vfluwsse\styles.css
C:\WINDOWS\vfluwsse\top-rc.gif
C:\WINDOWS\vfluwsse\vline.gif
C:\WINDOWS\vfluwsse\wp.png
C:\WINDOWS\vulmrglu.dll
C:\WINDOWS\xkbincru.dll
C:\WINDOWS\yhwpaxyh.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-17 to 2008-01-17 )))))))))))))))))))))))))))))))
.
2008-01-14 22:51 . 2008-01-16 20:11 4,180,768 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-14 22:51 . 2008-01-16 08:07 56,324 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-14 22:51 . 2008-01-16 20:11 24,608 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-14 22:51 . 2008-01-16 08:07 2,732 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-14 22:46 . 2008-01-14 22:46 <DIR> d-------- C:\KAV
2008-01-09 21:56 . 1999-12-21 07:58 21,312 --a------ C:\WINDOWS\choice.exe
2008-01-09 21:54 . 2008-01-09 21:54 <DIR> d-------- C:\ie-spyad
2008-01-03 18:14 . 2008-01-03 18:14 <DIR> d-------- C:\Program Files\SopCast
2007-12-28 12:45 . 2007-12-28 12:45 <DIR> d-------- C:\Documents and Settings\Owner\LimeWire Store Purchased
2007-12-28 12:45 . 2008-01-14 22:12 <DIR> d-------- C:\Documents and Settings\Owner\LimeWire Saved
2007-12-28 12:44 . 2007-12-28 12:44 <DIR> d-------- C:\Program Files\LimeWire
2007-12-23 13:20 . 2007-12-23 13:20 <DIR> d-------- C:\Program Files\Common Files\Napster Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-17 00:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-15 03:12 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2007-12-23 18:20 --------- d-----w C:\Program Files\Napster
2007-12-23 18:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Napster
2007-12-23 02:43 --------- d-----w C:\Program Files\McAfee
2007-12-20 07:52 --------- d-----w C:\Program Files\SiteAdvisor
2007-12-14 04:38 --------- d-----w C:\Program Files\QuickTime
2007-12-12 01:27 --------- d-----w C:\Documents and Settings\Owner\Application Data\SiteAdvisor
2007-12-12 00:01 --------- d-----w C:\Documents and Settings\Mom\Application Data\SiteAdvisor
2007-11-28 11:04 --------- d-----w C:\Program Files\Trend Micro
2007-11-21 01:18 --------- d--h--r C:\Documents and Settings\Owner\Application Data\yahoo!
2007-11-21 01:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 22:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-04-18 23:36 13,368,951 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_04_18_17_18_05_full.dmp.zip
2007-04-12 13:02 23,131,556 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_04_12_06_11_20_full.dmp.zip
2006-08-26 01:02 0 ----a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot@2008-01-15_21.24.21.31 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-16 02:20:05 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-17 01:06:16 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-16 02:20:05 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-17 01:06:16 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-16 02:20:05 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\ntuser.dat
+ 2008-01-17 01:06:16 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\ntuser.dat
- 2008-01-16 02:20:05 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-17 01:06:16 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-16 02:20:06 6,287,360 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\ntuser.dat
+ 2008-01-17 01:06:16 6,287,360 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\ntuser.dat
- 2008-01-16 02:20:06 208,896 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-17 01:06:16 208,896 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
- 2008-01-16 01:39:20 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-01-17 00:38:22 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-01-16 01:39:20 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-01-17 00:38:22 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-01-16 01:39:20 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-17 00:38:22 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2086306-1dd1-11b2-b55d-d394c3f9dbe2}]
C:\WINDOWS\vulmrglu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4c1ab76-1dd1-11b2-b402-b095bbbc78c0}]
C:\WINDOWS\dmlurgjc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 05:01 32768]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 09:47 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 09:47 688218]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 14:30 139264]
"SigmatelSysTrayApp"="stsystra.exe" [2005-12-26 20:20 413696 C:\WINDOWS\stsystra.exe]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [ ]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [ ]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 14:18 241664]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 10:24 49152]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2005-07-22 21:33 176128]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-03 10:25 185784]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42 267064]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2007-08-24 16:57 36640]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 10:56 286720]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" []
S3 PRISM_USB;Linksys Wireless-B USB Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\LSPMUSBX.sys [2004-07-26 13:32]
S3 ProcObsrv;Process creation detector.;C:\Program Files\Questionmark\QS\ProcObsrv.sys []
.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 07:04:47 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2007-12-01 06:00:04 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-16 20:11:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-16 20:12:26
ComboFix-quarantined-files.txt 2008-01-17 01:12:24
ComboFix2.txt 2008-01-16 02:24:47
ComboFix3.txt 2007-11-28 11:57:45
.
2008-01-09 01:33:49 --- E O F ---