combo log
ComboFix 08-05-09.1 - Peter D Martin 2008-05-13 21:03:23.9 - NTFSx86
Running from: C:\Documents and Settings\Peter D Martin\Desktop\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\rs.txt
.
((((((((((((((((((((((((( Files Created from 2008-04-13 to 2008-05-13 )))))))))))))))))))))))))))))))
.
2008-05-13 20:23 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-05-12 17:06 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-12 17:06 . 2008-05-13 20:23 5,516 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-10 00:15 . 2008-05-10 00:15 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-08 22:56 . 2008-05-08 22:56 63 --a------ C:\WINDOWS\system32\41beda43
2008-05-08 22:54 . 2008-05-10 20:25 <DIR> d-------- C:\Documents and Settings\Peter D Martin\Application Data\TmpRecentIcons
2008-05-08 20:59 . 2008-05-08 20:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adsl Software Limited
2008-05-08 19:37 . 2008-05-08 19:37 <DIR> d-------- C:\My Videos
2008-05-06 19:36 . 2008-05-06 19:36 <DIR> d-------- C:\Program Files\Veoh Networks
2008-05-04 21:11 . 2008-05-04 21:11 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-05-04 21:07 . 2006-08-21 10:14 128,896 --a--c--- C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-05-04 21:07 . 2006-08-21 10:14 23,040 --a--c--- C:\WINDOWS\system32\dllcache\fltmc.exe
2008-05-04 21:07 . 2006-08-21 13:21 16,896 --a--c--- C:\WINDOWS\system32\dllcache\fltlib.dll
2008-05-04 17:31 . 2007-07-09 14:09 584,192 --a--c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-05-04 14:04 . 2008-05-13 20:56 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-04 14:04 . 2008-05-04 14:04 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-04 13:49 . 2008-05-04 13:51 <DIR> d-------- C:\Program Files\iTunes
2008-05-04 13:20 . 2008-05-04 13:20 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-05-03 22:25 . 2008-05-03 22:25 <DIR> d-------- C:\Program Files\Bonjour
2008-05-03 22:04 . 2008-05-03 22:13 <DIR> d-------- C:\Program Files\QuickTime
2008-05-03 21:27 . 2008-02-18 11:16 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2008-05-03 21:24 . 2008-05-03 21:24 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-05-03 20:02 . 2004-08-04 06:41 404,990 --a------ C:\WINDOWS\system32\drivers\slntamr.sys
2008-05-03 20:01 . 2004-08-04 08:56 4,274,816 --a------ C:\WINDOWS\system32\nv4_disp.dll
2008-05-03 20:00 . 2004-08-04 08:56 380,416 --a------ C:\WINDOWS\system32\irprops.cpl
2008-05-03 19:59 . 2004-08-04 06:41 1,041,536 --a------ C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-05-03 19:58 . 2004-08-04 08:56 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2008-05-03 19:30 . 2004-08-04 08:56 351,232 --a------ C:\WINDOWS\system32\winhttp.dll
2008-05-03 19:30 . 2004-08-04 08:56 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2008-05-02 19:46 . 2007-07-30 19:19 216,408 --a------ C:\WINDOWS\system32\wuaucpl.cpl
2008-05-02 19:09 . 2007-04-19 11:36 48,384 --a------ C:\WINDOWS\system32\drivers\rp_pkt32.sys
2008-05-02 19:08 . 2008-05-02 19:08 <DIR> d-------- C:\Program Files\Common Files\Authentium
2008-05-02 19:07 . 2008-05-02 19:07 <DIR> d-------- C:\Program Files\Raxco
2008-05-02 19:07 . 2008-05-02 19:26 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-05-02 19:07 . 2008-05-02 19:07 <DIR> d-------- C:\Program Files\CA
2008-05-02 19:07 . 2008-05-02 19:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Raxco
2008-05-02 19:00 . 2008-05-02 19:00 <DIR> d-------- C:\Documents and Settings\Peter D Martin\Application Data\InstallShield
2008-05-02 18:55 . 2008-05-02 19:06 <DIR> d-------- C:\Program Files\Virgin Broadband
2008-05-02 11:09 . 2003-03-31 21:00 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2008-05-02 08:16 . 2008-05-02 08:16 <DIR> d-------- C:\Documents and Settings\Peter D Martin\Application Data\Virgin Broadband
2008-05-02 08:16 . 2008-05-02 19:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Virgin Broadband
2008-05-01 08:55 . 2004-06-17 21:48 159,744 --a------ C:\WINDOWS\system32\igfxres.dll
2008-05-01 08:43 . 2004-08-04 06:31 482,304 --a--c--- C:\WINDOWS\system32\dllcache\pintlgnt.ime
2008-05-01 08:42 . 2003-03-31 21:00 10,096,640 --a--c--- C:\WINDOWS\system32\dllcache\hwxcht.dll
2008-05-01 08:41 . 2004-08-04 06:31 480,256 --a--c--- C:\WINDOWS\system32\dllcache\cintsetp.exe
2008-05-01 08:40 . 2001-08-17 22:36 2,134,528 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_smtpsnap.dll
2008-05-01 08:40 . 2001-08-17 22:36 175,104 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_smtpadm.dll
2008-05-01 08:36 . 2004-08-04 08:56 48,128 --a------ C:\WINDOWS\system32\inetres.dll
2008-05-01 08:36 . 2008-05-01 08:36 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-05-01 08:36 . 2008-05-01 08:36 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-05-01 08:36 . 2008-05-01 08:36 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-05-01 08:36 . 2008-05-01 08:36 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-05-01 08:36 . 2008-05-01 08:36 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-05-01 08:35 . 2007-08-21 07:15 683,520 --a------ C:\WINDOWS\system32\inetcomm.dll
2008-05-01 08:35 . 2004-08-04 08:56 382,464 --a------ C:\WINDOWS\system32\qmgr.dll
2008-05-01 08:35 . 2004-08-04 08:56 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll
2008-05-01 08:35 . 2004-08-04 08:56 239,104 --a------ C:\WINDOWS\system32\srrstr.dll
2008-05-01 08:35 . 2004-08-04 08:56 105,984 --a------ C:\WINDOWS\system32\msoert2.dll
2008-05-01 08:35 . 2003-03-31 21:00 73,728 --a--c--- C:\WINDOWS\system32\dllcache\icwtutor.exe
2008-05-01 08:35 . 2003-03-31 21:00 61,440 --a--c--- C:\WINDOWS\system32\dllcache\icwres.dll
2008-05-01 08:35 . 2003-03-31 21:00 40,960 --a--c--- C:\WINDOWS\system32\dllcache\trialoc.dll
2008-05-01 08:21 . 2003-03-31 21:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-05-01 08:21 . 2003-03-31 21:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-05-01 08:21 . 2003-03-31 21:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-05-01 08:21 . 2003-03-31 21:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-05-01 08:20 . 2003-03-31 21:00 1,086,182 -ra------ C:\WINDOWS\SET265.tmp
2008-05-01 08:20 . 2003-03-31 21:00 797,189 --a--c--- C:\WINDOWS\system32\dllcache\NT5IIS.CAT
2008-05-01 08:20 . 2003-03-31 21:00 399,645 --a--c--- C:\WINDOWS\system32\dllcache\MAPIMIG.CAT
2008-05-01 08:20 . 2003-03-31 21:00 37,484 --a--c--- C:\WINDOWS\system32\dllcache\MW770.CAT
2008-05-01 08:20 . 2003-03-31 21:00 13,608 -ra------ C:\WINDOWS\SET271.tmp
2008-05-01 08:20 . 2003-03-31 21:00 13,472 --a--c--- C:\WINDOWS\system32\dllcache\HPCRDP.CAT
2008-05-01 08:20 . 2003-03-31 21:00 8,574 --a--c--- C:\WINDOWS\system32\dllcache\IASNT4.CAT
2008-05-01 08:20 . 2002-05-28 19:54 7,029 --a--c--- C:\WINDOWS\system32\dllcache\OEMBIOS.CAT
2008-04-21 19:29 . 2008-04-21 19:29 <DIR> d-------- C:\WINDOWS\New Folder
2008-04-21 19:29 . 2008-04-21 19:29 8,704 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-04-21 19:24 . 2003-05-03 12:51 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-04-21 19:24 . 2003-05-03 11:59 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2008-04-21 19:24 . 2003-05-03 12:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-04-21 19:24 . 2008-04-21 19:24 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-21 19:24 . 2008-05-10 21:17 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-04-18 15:37 . 2008-04-18 15:44 62,706 --a------ C:\WINDOWS\setupapi.old
2008-04-16 17:36 . 2008-05-02 20:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-04-13 18:52 . 2008-04-13 18:52 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-13 18:52 . 2008-04-13 18:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-13 10:56 . 2008-04-13 10:56 <DIR> d-------- C:\b5972bbf697fdead40e53f083c0a
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-04 18:58 --------- d-----w C:\Documents and Settings\Peter D Martin\Application Data\Apple Computer
2008-05-04 12:50 --------- d-----w C:\Program Files\iPod
2008-05-02 18:34 53,192 ----a-w C:\WINDOWS\system32\drivers\rp_skt32.sys
2008-05-02 18:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-10 15:39 --------- d-----w C:\Program Files\Hewlett-Packard
2008-04-03 16:50 --------- d-----w C:\Program Files\Enigma Software Group
2008-04-02 15:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-01 16:38 --------- d-----w C:\Documents and Settings\Peter D Martin\Application Data\Audacity
2008-03-28 22:19 86,528 ----a-w C:\WINDOWS\system32\VACFix.exe
2008-03-26 07:50 82,432 ----a-w C:\WINDOWS\system32\IEDFix.exe
2008-03-19 22:44 --------- d-----w C:\Program Files\Google
2008-03-19 21:42 --------- d-----w C:\Program Files\Panicware
2008-03-19 21:25 --------- d-----w C:\Program Files\EPSON
2008-03-19 21:23 --------- d-----w C:\Program Files\IKEA HomePlanner
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-18 20:33 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-14 16:09 --------- d-----w C:\Program Files\Canon
2008-03-14 16:07 248 ----a-w C:\UnInstall.dat
2008-03-14 16:05 --------- d-----w C:\Program Files\DivX
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 08:59 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2006-11-19 20:50 78,424 ----a-w C:\Documents and Settings\Lorna Hubbard\Application Data\GDIPFONTCACHEV1.DAT
2005-03-15 17:44 0 ----a-w C:\Documents and Settings\Peter D Martin\Application Data\wklnhst.dat
2005-12-06 19:31 56 --sh--r C:\WINDOWS\system32\1607371D5C.sys
2006-01-16 17:58 1,994 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-05-10_21.52.58.82 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-10 20:38:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-13 19:56:30 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2004-07-15 00:49:16 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW2308\_aspnet_isapi.dll
+ 2004-07-14 23:32:22 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW2308\_CORPerfMonExt.dll
+ 2004-07-14 23:24:30 282,624 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW2308\_fusion.dll
+ 2004-07-14 23:25:06 315,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW2308\_mscorjit.dll
+ 2004-07-15 13:29:02 2,138,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW2308\_mscorlib.dll
+ 2003-02-20 21:09:18 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW2308\_mscorsn.dll
+ 2004-07-14 23:26:52 2,510,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW2308\_mscorsvr.dll
+ 2004-07-14 23:28:34 2,502,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW2308\_mscorwks.dll
+ 2003-02-21 06:42:22 348,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW2308\_msvcr71.dll
+ 2004-07-14 23:34:50 94,208 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW2308\_PerfCounter.dll
+ 2004-07-15 00:49:16 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3816\_aspnet_isapi.dll
+ 2004-07-14 23:32:22 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3816\_CORPerfMonExt.dll
+ 2004-07-14 23:24:30 282,624 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3816\_fusion.dll
+ 2004-07-14 23:25:06 315,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3816\_mscorjit.dll
+ 2004-07-15 13:29:02 2,138,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3816\_mscorlib.dll
+ 2003-02-20 21:09:18 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3816\_mscorsn.dll
+ 2004-07-14 23:26:52 2,510,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3816\_mscorsvr.dll
+ 2004-07-14 23:28:34 2,502,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3816\_mscorwks.dll
+ 2003-02-21 06:42:22 348,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3816\_msvcr71.dll
+ 2004-07-14 23:34:50 94,208 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW3816\_PerfCounter.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1D33427A-2A9F-48DA-B4CC-819902B6A2C2}]
C:\WINDOWS\qvlbodmnqse.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4F6DD2F9-A353-484A-B35E-C4ED0211097F}"= "C:\WINDOWS\mkrndofl.dll" [ ]
[HKEY_CLASSES_ROOT\clsid\{4f6dd2f9-a353-484a-b35e-c4ed0211097f}]
[HKEY_CLASSES_ROOT\mkrndofl.1]
[HKEY_CLASSES_ROOT\TypeLib\{0C160D60-88B7-42DF-8B36-F0EB59EEE1EC}]
[HKEY_CLASSES_ROOT\mkrndofl]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe" [ ]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 22:22 3739648]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-29 18:02 68856]
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" [2005-03-17 12:10 536576]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-04-18 14:30 3628080]
"MalWarrior"="C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\MalWarrior 2008\Malwarrior.exe" [2008-05-10 20:44 1026560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-06-17 21:48 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-06-17 21:43 118784]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48 36975]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01 110592]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-26 18:15 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-26 18:15 536576]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 17:28 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38 241664]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [ ]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-05-22 19:55 483328]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2004-04-30 10:32 208958]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-05-27 20:28 278528]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-10 00:11 50688]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-03-22 23:15 26112]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"Easy-PrintToolBox"="C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.exe" [2004-01-14 02:10 409600]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-12-24 03:33 188416]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-12-14 02:06 495616]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-15 17:05 1838592]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 17:16 376912]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 06:31 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2003-03-31 08:00 44032]
"Broadbandadvisor.exe"="C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2007-08-07 18:49 2061552]
"PCguard"="C:\Program Files\Virgin Broadband\PCguard\Rps.exe" [2007-09-05 14:10 310000]
"-FreedomNeedsReboot"="C:\Program Files\Virgin Broadband\PCguard\ZkRunOnceR.exe" [2007-09-05 14:10 13552]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 08:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-29 18:02 68856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="C:\WINDOWS\System32\Macromed\Flash\NPSWF32_FlashUtil.exe" [2007-06-11 21:34 190696]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-04 06:59 44544]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"wetkadmr"= {FC82C371-41B2-408F-ABE7-3C5558439226} - C:\WINDOWS\wetkadmr.dll [ ]
"tdomgafw"= {1EDBC2B6-A4B9-4E61-A4B4-DC7CDB86BA80} - C:\WINDOWS\tdomgafw.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOLService"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
.
Contents of the 'Scheduled Tasks' folder
"2008-03-24 23:18:36 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-13 21:10:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????6?4?1?0??????? ???B???????????????B? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-13 21:14:15
ComboFix-quarantined-files.txt 2008-05-13 20:14:05
ComboFix2.txt 2008-05-10 20:54:00
Pre-Run: 10,817,732,608 bytes free
Post-Run: 10,802,827,264 bytes free
247 --- E O F --- 2008-05-13 19:42:39