Joined
·
21 Posts
ComboFix 08-02-15.2 - Tony 2008-02-21 2:37:34.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.152 [GMT -5:00]
Running from: C:\Documents and Settings\Tony\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tony\Desktop\CFScript.txt
* Created a new restore point
FILE
G:\3g08.bat
.
((((((((((((((((((((((((( Files Created from 2008-01-21 to 2008-02-21 )))))))))))))))))))))))))))))))
.
2008-02-17 15:27 . 2008-02-17 16:00 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\skypePM
2008-02-17 15:27 . 2008-02-17 15:27 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-17 15:22 . 2008-02-21 01:58 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\Skype
2008-02-17 15:21 . 2008-02-17 15:21 <DIR> d-------- C:\Program Files\Skype
2008-02-17 15:21 . 2008-02-17 15:21 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-02-17 15:21 . 2008-02-17 15:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-02-17 12:08 . 2008-02-17 12:08 244 --ah----- C:\sqmnoopt16.sqm
2008-02-17 12:08 . 2008-02-17 12:08 232 --ah----- C:\sqmdata16.sqm
2008-02-17 12:07 . 2008-02-17 12:07 244 --ah----- C:\sqmnoopt15.sqm
2008-02-17 12:07 . 2008-02-17 12:07 232 --ah----- C:\sqmdata15.sqm
2008-02-16 19:01 . 2008-02-16 19:01 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\vlc
2008-02-16 17:39 . 2008-02-16 17:39 244 --ah----- C:\sqmnoopt14.sqm
2008-02-16 17:39 . 2008-02-16 17:39 232 --ah----- C:\sqmdata14.sqm
2008-02-16 17:26 . 2008-02-16 17:26 244 --ah----- C:\sqmnoopt13.sqm
2008-02-16 17:26 . 2008-02-16 17:26 232 --ah----- C:\sqmdata13.sqm
2008-02-16 16:31 . 2008-02-16 16:31 244 --ah----- C:\sqmnoopt12.sqm
2008-02-16 16:31 . 2008-02-16 16:31 232 --ah----- C:\sqmdata12.sqm
2008-02-16 12:07 . 2008-02-16 12:07 244 --ah----- C:\sqmnoopt11.sqm
2008-02-16 12:07 . 2008-02-16 12:07 232 --ah----- C:\sqmdata11.sqm
2008-02-15 18:10 . 2008-02-15 18:10 <DIR> d-------- C:\Deckard
2008-02-15 18:04 . 2008-02-15 18:04 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-02-15 18:04 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-02-15 16:59 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\RkPavProc.sys
2008-02-15 16:45 . 2008-02-15 17:29 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-02-15 16:45 . 2008-02-15 16:47 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-02-15 16:45 . 2008-02-15 16:47 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-15 16:45 . 2008-02-15 16:47 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-02-15 02:27 . 2008-02-15 02:29 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-02-15 00:55 . 2008-02-15 00:55 <DIR> d-------- C:\Program Files\CCleaner
2008-02-15 00:25 . 2008-02-15 00:25 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-14 22:54 . 2008-02-14 22:54 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-02-12 16:12 . 2008-02-12 16:12 <DIR> d-------- C:\Program Files\Alwil Software
2008-02-12 16:12 . 2007-12-04 08:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-02-12 16:12 . 2004-01-09 04:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-02-12 16:12 . 2007-12-04 07:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-02-12 16:12 . 2007-12-04 09:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-12 16:12 . 2007-12-04 09:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-02-12 16:12 . 2007-12-04 09:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-12 16:12 . 2007-12-04 09:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-12 16:12 . 2007-12-04 09:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-02-12 15:52 . 2008-02-12 15:52 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\Grisoft
2008-02-12 15:51 . 2008-02-12 15:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-12 15:51 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-12 15:40 . 2008-02-15 17:18 <DIR> d-------- C:\Program Files\Windows Defender
2008-02-12 14:56 . 2008-02-12 14:56 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\Uniblue
2008-02-12 01:28 . 2008-02-15 01:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-12 01:24 . 2008-02-15 01:54 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-02-12 01:20 . 2008-02-12 01:20 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\Symantec
2008-02-12 01:00 . 2008-02-15 17:15 <DIR> d-------- C:\Program Files\D-Tools
2008-02-12 01:00 . 2004-08-22 16:31 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2008-02-12 01:00 . 2004-08-22 16:31 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2008-02-12 00:58 . 2008-02-12 00:58 <DIR> d-------- C:\Program Files\VideoLAN
2008-02-11 23:39 . 2008-02-15 00:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-11 20:59 . 2008-02-11 20:59 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\Kingsoft
2008-02-11 20:59 . 2008-02-11 21:00 66 --a------ C:\WINDOWS\xdict.INI
2008-02-11 20:34 . 2008-02-11 20:34 <DIR> d-------- C:\Program Files\Kingsoft
2008-02-11 20:34 . 2008-02-11 20:34 <DIR> d-------- C:\Program Files\Common Files\KingSoft
2008-02-11 20:34 . 2002-11-28 03:34 2,986,038 --a------ C:\WINDOWS\CIBAH.BMP
2008-02-11 01:12 . 2008-02-11 01:12 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\Move Networks
2008-02-01 02:35 . 2008-02-01 02:35 244 --ah----- C:\sqmnoopt10.sqm
2008-02-01 02:35 . 2008-02-01 02:35 232 --ah----- C:\sqmdata10.sqm
2008-02-01 00:18 . 2008-02-01 00:18 244 --ah----- C:\sqmnoopt09.sqm
2008-02-01 00:18 . 2008-02-01 00:18 232 --ah----- C:\sqmdata09.sqm
2008-02-01 00:15 . 2008-02-01 00:15 244 --ah----- C:\sqmnoopt08.sqm
2008-02-01 00:15 . 2008-02-01 00:15 232 --ah----- C:\sqmdata08.sqm
2008-01-31 10:49 . 2008-01-31 10:49 <DIR> d-------- C:\Program Files\iPod
2008-01-31 01:40 . 2008-01-31 01:40 244 --ah----- C:\sqmnoopt07.sqm
2008-01-31 01:40 . 2008-01-31 01:40 232 --ah----- C:\sqmdata07.sqm
2008-01-31 01:35 . 2008-01-31 01:35 244 --ah----- C:\sqmnoopt06.sqm
2008-01-31 01:35 . 2008-01-31 01:35 232 --ah----- C:\sqmdata06.sqm
2008-01-30 12:54 . 2008-01-30 12:54 244 --ah----- C:\sqmnoopt05.sqm
2008-01-30 12:54 . 2008-01-30 12:54 232 --ah----- C:\sqmdata05.sqm
2008-01-30 00:00 . 2008-01-30 00:00 244 --ah----- C:\sqmnoopt04.sqm
2008-01-30 00:00 . 2008-01-30 00:00 232 --ah----- C:\sqmdata04.sqm
2008-01-29 23:29 . 2008-01-29 23:29 244 --ah----- C:\sqmnoopt03.sqm
2008-01-29 23:29 . 2008-01-29 23:29 232 --ah----- C:\sqmdata03.sqm
2008-01-29 23:26 . 2008-01-29 23:26 244 --ah----- C:\sqmnoopt02.sqm
2008-01-29 23:26 . 2008-01-29 23:26 232 --ah----- C:\sqmdata02.sqm
2008-01-28 03:25 . 2008-01-28 03:25 244 --ah----- C:\sqmnoopt01.sqm
2008-01-28 03:25 . 2008-01-28 03:25 232 --ah----- C:\sqmdata01.sqm
2008-01-24 00:33 . 2008-01-24 00:33 <DIR> d--h----- C:\BJPrinter
2008-01-24 00:33 . 2002-11-09 08:00 88,576 --a------ C:\WINDOWS\system32\CNMLM4o.DLL
2008-01-24 00:33 . 2002-10-03 18:23 73,728 -ra------ C:\WINDOWS\system32\CNMCP4o.exe
2008-01-24 00:33 . 2002-11-09 08:00 5,632 --a------ C:\WINDOWS\system32\CNMVS4o.DLL
2008-01-24 00:29 . 2008-01-24 00:33 <DIR> d-------- C:\Temp\i70_2KXP_v163
2008-01-24 00:29 . 2008-01-24 00:33 <DIR> d-------- C:\Temp\Canon_i70_2KXP_v163
2008-01-24 00:29 . 2008-01-24 00:29 <DIR> d-------- C:\Temp
2008-01-24 00:20 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-01-24 00:20 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-01-23 00:53 . 2008-01-23 00:53 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\DivX
2008-01-23 00:52 . 2008-01-23 00:52 <DIR> d-------- C:\Program Files\DivX
2008-01-23 00:45 . 2001-05-11 13:18 420,240 --a------ C:\WINDOWS\system32\mpg4c32.dll
2008-01-23 00:45 . 2001-05-16 17:54 309,616 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2008-01-23 00:45 . 2001-03-26 04:41 245,760 --a------ C:\WINDOWS\system32\mp4sds32.ax
2008-01-22 11:20 . 2008-01-22 11:20 <DIR> d-------- C:\Program Files\Xvid
2008-01-22 11:20 . 2007-06-28 18:52 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-01-22 11:20 . 2007-06-28 18:54 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-01-22 11:20 . 2007-06-28 18:55 77,824 --a------ C:\WINDOWS\system32\xvid.ax
2008-01-21 23:42 . 2008-01-21 23:42 <DIR> d-------- C:\Program Files\Gabest
2008-01-21 23:24 . 2008-01-21 23:24 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\BSplayer Pro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-15 22:16 --------- d-----w C:\Program Files\Launch Manager
2008-02-15 22:15 --------- d-----w C:\Program Files\iTunes
2008-02-15 22:15 --------- d-----w C:\Program Files\Google
2008-02-15 22:13 --------- d-----w C:\Program Files\Arcade
2008-02-12 01:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-03 20:55 --------- d-----w C:\Documents and Settings\Tony\Application Data\Apple Computer
2008-01-31 15:47 --------- d-----w C:\Program Files\QuickTime
2008-01-21 18:17 --------- d-----w C:\Program Files\BitSpirit
2008-01-19 06:24 --------- d-s---w C:\Documents and Settings\All Users\Application Data\Memeo
2008-01-18 05:56 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-18 05:50 --------- d-----w C:\Program Files\Microsoft.NET
2008-01-17 02:39 --------- d-----w C:\Documents and Settings\Tony\Application Data\BitSpirit
2008-01-15 05:16 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-15 02:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-15 02:01 --------- d-----w C:\Program Files\Common Files\Apple
2008-01-15 02:01 --------- d-----w C:\Program Files\Apple Software Update
2008-01-15 02:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-01-14 08:58 --------- d-----w C:\Program Files\Windows Journal Viewer
2008-01-14 07:34 --------- d-----w C:\Program Files\Logitech
2008-01-14 07:34 --------- d-----w C:\Program Files\Common Files\Logitech
2008-01-14 05:46 --------- d-----w C:\Program Files\Western Digital
2008-01-14 05:46 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-14 05:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-01-14 05:41 --------- d-----w C:\Program Files\Western Digital Technologies
2008-01-14 05:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-14 04:55 --------- d-----w C:\Program Files\MSXML 4.0
2008-01-14 04:30 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-01-14 04:10 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-14 04:10 --------- d-----w C:\Program Files\Windows Live
2008-01-14 04:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-14 01:18 --------- d-----w C:\Program Files\Phoenix Technologies Ltd
2008-01-14 01:17 --------- d-----w C:\Program Files\Synaptics
2008-01-14 01:16 --------- d-----w C:\Program Files\sisagp
2008-01-14 01:16 --------- d-----w C:\Program Files\SiS VGA Utilities V3.65f
2008-01-14 01:14 --------- d-----w C:\Program Files\Realtek AC97
2008-01-14 01:09 --------- d-----w C:\Program Files\CyberLink
2008-01-14 01:06 --------- d-----w C:\Program Files\WIDCOMM
2008-01-14 01:05 17,801 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-01-14 00:30 --------- d-----w C:\Program Files\microsoft frontpage
2008-01-04 21:59 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-01-04 21:58 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-01-04 21:58 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-01-04 21:58 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-01-04 21:58 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-01-04 21:58 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-01-04 21:58 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-01-04 21:58 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-01-04 21:58 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-01-04 21:58 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-01-04 21:57 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-01-04 21:57 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-01-04 21:57 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-01-04 21:57 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-01-04 21:57 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-01-04 21:57 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-01-04 21:57 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-01-04 21:57 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-01-04 21:57 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-01-04 21:57 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-01-04 21:57 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-01-04 21:57 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-01-04 21:56 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-01-04 21:56 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2006-10-03 07:43 2,402,550 ----a-w C:\WINDOWS\inf\SET337.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 14:44 196608]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-02-12 02:19 287040]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 17:22 21898024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-08 10:50 88363 C:\WINDOWS\AGRSMMSG.exe]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]
"PCMService"="C:\Program Files\Arcade\PCMService.exe" [2005-03-09 18:59 49152]
"LManager"="C:\Program Files\Launch Manager\QtZgAcer.EXE" [2005-02-23 11:04 315392]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 16:22 577536 C:\WINDOWS\soundman.exe]
"SiSPower"="SiSPower.dll" [2005-02-25 19:35 49152 C:\WINDOWS\system32\SiSPower.dll]
"SiS Windows KeyHook"="C:\WINDOWS\system32\keyhook.exe" [2005-03-04 13:13 32768]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 14:44 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 14:43 688218]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 07:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 07:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 07:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 07:00 455168]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [ ]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 17:32 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 15:24 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 15:14 217088]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05 81920]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-05-25 15:38:42 565309]
Powerword 2003.lnk - C:\Program Files\Kingsoft\Powerword 2003\XDICT.EXE [2008-02-11 20:34:32 823296]
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2008-01-13 20:16:09 331776]
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 16:43]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cef68e81-c25f-11dc-bd5e-00c09fb89fe6}]
\Shell\AutoRun\command - wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-22 00:48:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-21 06:59:22 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-21 02:40:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\Kingsoft\Powerword 2003\Cjktl32.dll
.
Completion time: 2008-02-21 2:41:01
ComboFix-quarantined-files.txt 2008-02-21 07:40:44
ComboFix2.txt 2008-02-21 06:48:34
ComboFix3.txt 2008-02-17 22:25:22
ComboFix4.txt 2008-02-15 06:12:44
.
2008-02-15 07:32:40 --- E O F ---
Kaspersky is coming along (slowly) 26%...
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.152 [GMT -5:00]
Running from: C:\Documents and Settings\Tony\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tony\Desktop\CFScript.txt
* Created a new restore point
FILE
G:\3g08.bat
.
((((((((((((((((((((((((( Files Created from 2008-01-21 to 2008-02-21 )))))))))))))))))))))))))))))))
.
2008-02-17 15:27 . 2008-02-17 16:00 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\skypePM
2008-02-17 15:27 . 2008-02-17 15:27 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-17 15:22 . 2008-02-21 01:58 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\Skype
2008-02-17 15:21 . 2008-02-17 15:21 <DIR> d-------- C:\Program Files\Skype
2008-02-17 15:21 . 2008-02-17 15:21 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-02-17 15:21 . 2008-02-17 15:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-02-17 12:08 . 2008-02-17 12:08 244 --ah----- C:\sqmnoopt16.sqm
2008-02-17 12:08 . 2008-02-17 12:08 232 --ah----- C:\sqmdata16.sqm
2008-02-17 12:07 . 2008-02-17 12:07 244 --ah----- C:\sqmnoopt15.sqm
2008-02-17 12:07 . 2008-02-17 12:07 232 --ah----- C:\sqmdata15.sqm
2008-02-16 19:01 . 2008-02-16 19:01 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\vlc
2008-02-16 17:39 . 2008-02-16 17:39 244 --ah----- C:\sqmnoopt14.sqm
2008-02-16 17:39 . 2008-02-16 17:39 232 --ah----- C:\sqmdata14.sqm
2008-02-16 17:26 . 2008-02-16 17:26 244 --ah----- C:\sqmnoopt13.sqm
2008-02-16 17:26 . 2008-02-16 17:26 232 --ah----- C:\sqmdata13.sqm
2008-02-16 16:31 . 2008-02-16 16:31 244 --ah----- C:\sqmnoopt12.sqm
2008-02-16 16:31 . 2008-02-16 16:31 232 --ah----- C:\sqmdata12.sqm
2008-02-16 12:07 . 2008-02-16 12:07 244 --ah----- C:\sqmnoopt11.sqm
2008-02-16 12:07 . 2008-02-16 12:07 232 --ah----- C:\sqmdata11.sqm
2008-02-15 18:10 . 2008-02-15 18:10 <DIR> d-------- C:\Deckard
2008-02-15 18:04 . 2008-02-15 18:04 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-02-15 18:04 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-02-15 16:59 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\RkPavProc.sys
2008-02-15 16:45 . 2008-02-15 17:29 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-02-15 16:45 . 2008-02-15 16:47 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-02-15 16:45 . 2008-02-15 16:47 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-15 16:45 . 2008-02-15 16:47 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-02-15 02:27 . 2008-02-15 02:29 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-02-15 00:55 . 2008-02-15 00:55 <DIR> d-------- C:\Program Files\CCleaner
2008-02-15 00:25 . 2008-02-15 00:25 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-14 22:54 . 2008-02-14 22:54 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-02-12 16:12 . 2008-02-12 16:12 <DIR> d-------- C:\Program Files\Alwil Software
2008-02-12 16:12 . 2007-12-04 08:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-02-12 16:12 . 2004-01-09 04:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-02-12 16:12 . 2007-12-04 07:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-02-12 16:12 . 2007-12-04 09:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-12 16:12 . 2007-12-04 09:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-02-12 16:12 . 2007-12-04 09:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-12 16:12 . 2007-12-04 09:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-12 16:12 . 2007-12-04 09:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-02-12 15:52 . 2008-02-12 15:52 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\Grisoft
2008-02-12 15:51 . 2008-02-12 15:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-12 15:51 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-12 15:40 . 2008-02-15 17:18 <DIR> d-------- C:\Program Files\Windows Defender
2008-02-12 14:56 . 2008-02-12 14:56 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\Uniblue
2008-02-12 01:28 . 2008-02-15 01:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-12 01:24 . 2008-02-15 01:54 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-02-12 01:20 . 2008-02-12 01:20 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\Symantec
2008-02-12 01:00 . 2008-02-15 17:15 <DIR> d-------- C:\Program Files\D-Tools
2008-02-12 01:00 . 2004-08-22 16:31 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2008-02-12 01:00 . 2004-08-22 16:31 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2008-02-12 00:58 . 2008-02-12 00:58 <DIR> d-------- C:\Program Files\VideoLAN
2008-02-11 23:39 . 2008-02-15 00:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-11 20:59 . 2008-02-11 20:59 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\Kingsoft
2008-02-11 20:59 . 2008-02-11 21:00 66 --a------ C:\WINDOWS\xdict.INI
2008-02-11 20:34 . 2008-02-11 20:34 <DIR> d-------- C:\Program Files\Kingsoft
2008-02-11 20:34 . 2008-02-11 20:34 <DIR> d-------- C:\Program Files\Common Files\KingSoft
2008-02-11 20:34 . 2002-11-28 03:34 2,986,038 --a------ C:\WINDOWS\CIBAH.BMP
2008-02-11 01:12 . 2008-02-11 01:12 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\Move Networks
2008-02-01 02:35 . 2008-02-01 02:35 244 --ah----- C:\sqmnoopt10.sqm
2008-02-01 02:35 . 2008-02-01 02:35 232 --ah----- C:\sqmdata10.sqm
2008-02-01 00:18 . 2008-02-01 00:18 244 --ah----- C:\sqmnoopt09.sqm
2008-02-01 00:18 . 2008-02-01 00:18 232 --ah----- C:\sqmdata09.sqm
2008-02-01 00:15 . 2008-02-01 00:15 244 --ah----- C:\sqmnoopt08.sqm
2008-02-01 00:15 . 2008-02-01 00:15 232 --ah----- C:\sqmdata08.sqm
2008-01-31 10:49 . 2008-01-31 10:49 <DIR> d-------- C:\Program Files\iPod
2008-01-31 01:40 . 2008-01-31 01:40 244 --ah----- C:\sqmnoopt07.sqm
2008-01-31 01:40 . 2008-01-31 01:40 232 --ah----- C:\sqmdata07.sqm
2008-01-31 01:35 . 2008-01-31 01:35 244 --ah----- C:\sqmnoopt06.sqm
2008-01-31 01:35 . 2008-01-31 01:35 232 --ah----- C:\sqmdata06.sqm
2008-01-30 12:54 . 2008-01-30 12:54 244 --ah----- C:\sqmnoopt05.sqm
2008-01-30 12:54 . 2008-01-30 12:54 232 --ah----- C:\sqmdata05.sqm
2008-01-30 00:00 . 2008-01-30 00:00 244 --ah----- C:\sqmnoopt04.sqm
2008-01-30 00:00 . 2008-01-30 00:00 232 --ah----- C:\sqmdata04.sqm
2008-01-29 23:29 . 2008-01-29 23:29 244 --ah----- C:\sqmnoopt03.sqm
2008-01-29 23:29 . 2008-01-29 23:29 232 --ah----- C:\sqmdata03.sqm
2008-01-29 23:26 . 2008-01-29 23:26 244 --ah----- C:\sqmnoopt02.sqm
2008-01-29 23:26 . 2008-01-29 23:26 232 --ah----- C:\sqmdata02.sqm
2008-01-28 03:25 . 2008-01-28 03:25 244 --ah----- C:\sqmnoopt01.sqm
2008-01-28 03:25 . 2008-01-28 03:25 232 --ah----- C:\sqmdata01.sqm
2008-01-24 00:33 . 2008-01-24 00:33 <DIR> d--h----- C:\BJPrinter
2008-01-24 00:33 . 2002-11-09 08:00 88,576 --a------ C:\WINDOWS\system32\CNMLM4o.DLL
2008-01-24 00:33 . 2002-10-03 18:23 73,728 -ra------ C:\WINDOWS\system32\CNMCP4o.exe
2008-01-24 00:33 . 2002-11-09 08:00 5,632 --a------ C:\WINDOWS\system32\CNMVS4o.DLL
2008-01-24 00:29 . 2008-01-24 00:33 <DIR> d-------- C:\Temp\i70_2KXP_v163
2008-01-24 00:29 . 2008-01-24 00:33 <DIR> d-------- C:\Temp\Canon_i70_2KXP_v163
2008-01-24 00:29 . 2008-01-24 00:29 <DIR> d-------- C:\Temp
2008-01-24 00:20 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-01-24 00:20 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-01-23 00:53 . 2008-01-23 00:53 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\DivX
2008-01-23 00:52 . 2008-01-23 00:52 <DIR> d-------- C:\Program Files\DivX
2008-01-23 00:45 . 2001-05-11 13:18 420,240 --a------ C:\WINDOWS\system32\mpg4c32.dll
2008-01-23 00:45 . 2001-05-16 17:54 309,616 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2008-01-23 00:45 . 2001-03-26 04:41 245,760 --a------ C:\WINDOWS\system32\mp4sds32.ax
2008-01-22 11:20 . 2008-01-22 11:20 <DIR> d-------- C:\Program Files\Xvid
2008-01-22 11:20 . 2007-06-28 18:52 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-01-22 11:20 . 2007-06-28 18:54 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-01-22 11:20 . 2007-06-28 18:55 77,824 --a------ C:\WINDOWS\system32\xvid.ax
2008-01-21 23:42 . 2008-01-21 23:42 <DIR> d-------- C:\Program Files\Gabest
2008-01-21 23:24 . 2008-01-21 23:24 <DIR> d-------- C:\Documents and Settings\Tony\Application Data\BSplayer Pro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-15 22:16 --------- d-----w C:\Program Files\Launch Manager
2008-02-15 22:15 --------- d-----w C:\Program Files\iTunes
2008-02-15 22:15 --------- d-----w C:\Program Files\Google
2008-02-15 22:13 --------- d-----w C:\Program Files\Arcade
2008-02-12 01:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-03 20:55 --------- d-----w C:\Documents and Settings\Tony\Application Data\Apple Computer
2008-01-31 15:47 --------- d-----w C:\Program Files\QuickTime
2008-01-21 18:17 --------- d-----w C:\Program Files\BitSpirit
2008-01-19 06:24 --------- d-s---w C:\Documents and Settings\All Users\Application Data\Memeo
2008-01-18 05:56 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-18 05:50 --------- d-----w C:\Program Files\Microsoft.NET
2008-01-17 02:39 --------- d-----w C:\Documents and Settings\Tony\Application Data\BitSpirit
2008-01-15 05:16 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-15 02:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-15 02:01 --------- d-----w C:\Program Files\Common Files\Apple
2008-01-15 02:01 --------- d-----w C:\Program Files\Apple Software Update
2008-01-15 02:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-01-14 08:58 --------- d-----w C:\Program Files\Windows Journal Viewer
2008-01-14 07:34 --------- d-----w C:\Program Files\Logitech
2008-01-14 07:34 --------- d-----w C:\Program Files\Common Files\Logitech
2008-01-14 05:46 --------- d-----w C:\Program Files\Western Digital
2008-01-14 05:46 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-14 05:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-01-14 05:41 --------- d-----w C:\Program Files\Western Digital Technologies
2008-01-14 05:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-14 04:55 --------- d-----w C:\Program Files\MSXML 4.0
2008-01-14 04:30 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-01-14 04:10 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-14 04:10 --------- d-----w C:\Program Files\Windows Live
2008-01-14 04:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-14 01:18 --------- d-----w C:\Program Files\Phoenix Technologies Ltd
2008-01-14 01:17 --------- d-----w C:\Program Files\Synaptics
2008-01-14 01:16 --------- d-----w C:\Program Files\sisagp
2008-01-14 01:16 --------- d-----w C:\Program Files\SiS VGA Utilities V3.65f
2008-01-14 01:14 --------- d-----w C:\Program Files\Realtek AC97
2008-01-14 01:09 --------- d-----w C:\Program Files\CyberLink
2008-01-14 01:06 --------- d-----w C:\Program Files\WIDCOMM
2008-01-14 01:05 17,801 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-01-14 00:30 --------- d-----w C:\Program Files\microsoft frontpage
2008-01-04 21:59 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-01-04 21:58 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-01-04 21:58 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-01-04 21:58 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-01-04 21:58 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-01-04 21:58 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-01-04 21:58 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-01-04 21:58 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-01-04 21:58 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-01-04 21:58 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-01-04 21:57 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-01-04 21:57 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-01-04 21:57 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-01-04 21:57 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-01-04 21:57 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-01-04 21:57 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-01-04 21:57 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-01-04 21:57 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-01-04 21:57 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-01-04 21:57 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-01-04 21:57 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-01-04 21:57 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-01-04 21:56 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-01-04 21:56 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2006-10-03 07:43 2,402,550 ----a-w C:\WINDOWS\inf\SET337.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 14:44 196608]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-02-12 02:19 287040]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 17:22 21898024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-08 10:50 88363 C:\WINDOWS\AGRSMMSG.exe]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]
"PCMService"="C:\Program Files\Arcade\PCMService.exe" [2005-03-09 18:59 49152]
"LManager"="C:\Program Files\Launch Manager\QtZgAcer.EXE" [2005-02-23 11:04 315392]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 16:22 577536 C:\WINDOWS\soundman.exe]
"SiSPower"="SiSPower.dll" [2005-02-25 19:35 49152 C:\WINDOWS\system32\SiSPower.dll]
"SiS Windows KeyHook"="C:\WINDOWS\system32\keyhook.exe" [2005-03-04 13:13 32768]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 14:44 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 14:43 688218]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 07:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 07:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 07:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 07:00 455168]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [ ]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 17:32 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 15:24 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 15:14 217088]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05 81920]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-05-25 15:38:42 565309]
Powerword 2003.lnk - C:\Program Files\Kingsoft\Powerword 2003\XDICT.EXE [2008-02-11 20:34:32 823296]
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2008-01-13 20:16:09 331776]
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 16:43]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cef68e81-c25f-11dc-bd5e-00c09fb89fe6}]
\Shell\AutoRun\command - wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-22 00:48:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-21 06:59:22 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-21 02:40:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\Kingsoft\Powerword 2003\Cjktl32.dll
.
Completion time: 2008-02-21 2:41:01
ComboFix-quarantined-files.txt 2008-02-21 07:40:44
ComboFix2.txt 2008-02-21 06:48:34
ComboFix3.txt 2008-02-17 22:25:22
ComboFix4.txt 2008-02-15 06:12:44
.
2008-02-15 07:32:40 --- E O F ---
Kaspersky is coming along (slowly) 26%...