ComboFix 08-05-21.3 - Jeremy 2008-05-22 16:24:19.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1471 [GMT -4:00]
Running from: C:\Documents and Settings\Jeremy\My Documents\My Received Files\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\install.exe
C:\WINDOWS\system32\_000005_.tmp.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-22 to 2008-05-22 )))))))))))))))))))))))))))))))
.
2008-05-22 05:23 . 2008-05-22 05:23 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-05-22 05:13 . 2008-04-26 16:14 42,672 --------- C:\WINDOWS\system32\wbsys.dll
2008-05-22 04:45 . 2008-05-22 05:05 <DIR> d-------- C:\Program Files\Stardock
2008-05-22 01:01 . 2008-05-22 01:01 1,224 --a------ C:\WINDOWS\system32\msexcr.ini
2008-05-20 21:16 . 2008-05-20 21:16 <DIR> d-------- C:\Program Files\Intel Corporation
2008-05-18 03:01 . 2008-05-18 03:01 <DIR> d-------- C:\WINDOWS\system32\windows media
2008-05-18 02:52 . 2008-05-18 02:52 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-05-18 02:49 . 2007-04-18 12:12 2,854,400 --a------ C:\WINDOWS\system32\SET5E0.tmp
2008-05-16 22:11 . 2008-05-16 22:11 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-16 22:11 . 2008-05-16 22:11 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-16 19:19 . 2008-05-16 19:19 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\HP
2008-05-16 18:46 . 2007-01-23 15:46 438,272 -ra------ C:\WINDOWS\system32\hpg400co.dll
2008-05-16 18:46 . 2004-08-04 00:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-05-16 18:46 . 2004-08-04 00:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-05-16 18:44 . 2008-05-16 18:44 <DIR> d-------- C:\Program Files\Common Files\Sonic Shared
2008-05-16 18:44 . 2008-05-16 18:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sonic
2008-05-16 18:41 . 2008-05-16 18:43 <DIR> d-------- C:\Program Files\Common Files\HP
2008-05-16 18:40 . 2008-05-16 18:40 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-05-16 18:40 . 2008-05-16 18:40 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-05-16 18:38 . 2008-05-16 18:41 <DIR> d-------- C:\Program Files\HP
2008-05-16 18:36 . 2008-05-16 18:46 100,887 --a------ C:\WINDOWS\hpgins17.dat
2008-05-16 18:36 . 2007-01-23 04:25 284 --------- C:\WINDOWS\hpgmdl17.dat
2008-05-15 20:41 . 2008-05-15 20:42 <DIR> d-------- C:\Program Files\Wisdom-soft AutoScreenRecorder 3 Pro
2008-05-15 18:57 . 2008-05-15 12:18 57,344 --a------ C:\WINDOWS\system32\pfkipmysr.exe
2008-05-13 21:29 . 2008-05-13 21:29 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-05-11 22:05 . 2008-05-11 22:05 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\MPEG Streamclip
2008-05-11 05:33 . 2008-05-11 05:34 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\DVD Flick
2008-05-11 05:33 . 2004-03-09 00:00 662,288 --a------ C:\WINDOWS\system32\mscomct2.ocx
2008-05-11 05:33 . 2004-03-09 00:00 212,240 --a------ C:\WINDOWS\system32\richtx32.ocx
2008-05-11 05:33 . 2000-05-19 17:56 81,920 --a------ C:\WINDOWS\system32\mbmouse.ocx
2008-05-11 05:33 . 2000-11-05 15:27 36,864 --a------ C:\WINDOWS\system32\trayicon.ocx
2008-05-11 05:07 . 2008-05-11 05:13 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\AVSMedia
2008-05-11 05:07 . 2008-05-11 05:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-05-11 05:06 . 2008-05-11 21:04 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2008-05-11 04:37 . 2008-05-11 04:37 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\Pegasys Inc
2008-05-11 04:34 . 2008-05-11 04:34 145,504 --a------ C:\WINDOWS\system32\bgsvcgen.exe
2008-05-11 04:34 . 2008-05-11 04:34 59,488 --a------ C:\WINDOWS\system32\GenSvcInst.exe
2008-05-11 04:34 . 2008-05-11 04:34 33,408 --a------ C:\WINDOWS\system32\drivers\CDRBSDRV.SYS
2008-05-11 00:56 . 2008-05-22 06:13 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-11 00:56 . 2008-05-11 00:56 <DIR> d-------- C:\Program Files\AVG
2008-05-11 00:56 . 2008-05-16 04:07 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\AVGTOOLBAR
2008-05-11 00:56 . 2008-05-11 00:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-11 00:56 . 2008-05-11 00:56 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-11 00:56 . 2008-05-11 00:56 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-10 22:20 . 2008-05-13 23:19 <DIR> d-------- C:\WINDOWS\system32\temp
2008-05-10 21:21 . 2008-05-10 21:21 <DIR> d-------- C:\Program Files\Burn4Free Toolbar
2008-05-10 21:21 . 2008-05-10 22:21 <DIR> d-------- C:\Program Files\Burn4Free
2008-05-10 21:21 . 2008-05-10 21:21 232,077 --a------ C:\WINDOWS\Burn4Free_Toolbar_Uninstaller_7906.exe
2008-05-10 03:20 . 2008-05-10 03:20 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-10 02:49 . 2008-05-10 02:49 <DIR> d-------- C:\Program Files\Common Files\InterVideo
2008-05-10 02:49 . 2008-05-10 02:51 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\Ulead Systems
2008-05-10 02:48 . 2008-05-10 02:48 <DIR> d-------- C:\Program Files\Windows Media Components
2008-05-10 02:48 . 2008-05-10 02:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-05-10 00:17 . 2008-05-10 00:28 26 --a------ C:\WINDOWS\dvdSanta.INI
2008-05-09 23:27 . 2008-05-09 23:27 <DIR> d-------- C:\TempDVD
2008-05-09 23:27 . 2008-05-11 04:55 <DIR> d-------- C:\Program Files\dvdSanta
2008-05-09 18:05 . 2008-05-09 18:05 <DIR> d-------- C:\Program Files\DVD-RAM
2008-05-09 18:05 . 2008-05-09 18:05 405,504 --a------ C:\WINDOWS\system32\DVDTool.exe
2008-05-09 18:05 . 2008-05-09 18:05 233,472 --a------ C:\WINDOWS\system32\DVDTools.dll
2008-05-09 18:05 . 2008-05-09 18:05 155,648 --a------ C:\WINDOWS\system32\RAMASST.exe
2008-05-09 18:05 . 2008-05-09 18:05 135,168 --a------ C:\WINDOWS\system32\DVDMenu.dll
2008-05-09 18:05 . 2008-05-09 18:05 110,592 --a------ C:\WINDOWS\system32\DVDRAMSV.exe
2008-05-09 18:05 . 2008-05-09 18:05 102,384 --a------ C:\WINDOWS\system32\drivers\meiudf.sys
2008-05-09 04:59 . 2008-05-09 04:59 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\Ahead
2008-05-09 04:58 . 2008-05-10 20:01 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-05-07 15:31 . 2008-05-07 19:22 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\Move Networks
2008-05-03 03:35 . 2008-05-03 03:36 <DIR> d-------- C:\MyBackup
2008-05-03 03:34 . 2008-05-03 03:37 <DIR> d-------- C:\Program Files\Premium Booster
2008-05-02 23:07 . 2008-05-09 23:17 <DIR> d-------- C:\Program Files\ASUS
2008-05-02 23:07 . 2006-01-11 04:50 24,576 -ra------ C:\WINDOWS\system32\AsIO.dll
2008-05-02 23:07 . 2006-10-19 15:12 12,664 -ra------ C:\WINDOWS\system32\drivers\AsIO.sys
2008-05-02 23:06 . 2008-05-02 23:06 <DIR> dr------- C:\WINDOWS\AsDmiHtm
2008-05-02 23:02 . 2008-05-02 23:02 <DIR> d-------- C:\Program Files\CCleaner
2008-05-02 01:34 . 2008-05-15 16:49 107,832 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-05-02 01:34 . 2008-05-02 01:34 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-05-02 01:34 . 2008-05-15 16:49 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-30 23:49 . 2008-05-01 22:44 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-30 21:50 . 2008-04-30 22:06 <DIR> d-------- C:\Program Files\iCall
2008-04-29 21:22 . 2008-04-29 21:22 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\ATI
2008-04-29 21:22 . 2008-04-29 21:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-04-29 21:15 . 2008-04-29 21:15 <DIR> d-------- C:\Program Files\Common Files\ATI Technologies
2008-04-29 21:14 . 2008-04-29 21:18 <DIR> d-------- C:\Program Files\ATI Technologies
2008-04-29 21:14 . 2007-06-29 21:05 520,192 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-04-29 21:11 . 2007-06-26 21:30 3,107,788 -ra------ C:\WINDOWS\system32\ativvaxx.dat
2008-04-29 21:11 . 2007-06-26 21:30 3,107,788 -ra------ C:\WINDOWS\system32\ativva5x.dat
2008-04-29 21:11 . 2007-06-26 21:30 972,072 -ra------ C:\WINDOWS\system32\ativva6x.dat
2008-04-29 21:11 . 2007-06-26 21:59 344,064 -ra------ C:\WINDOWS\system32\ATIDEMGX.dll
2008-04-29 21:11 . 2007-06-26 21:56 307,200 -ra------ C:\WINDOWS\system32\atiiiexx.dll
2008-04-29 21:11 . 2007-06-05 13:40 149,278 -ra------ C:\WINDOWS\system32\atiicdxx.dat
2008-04-29 21:11 . 2007-04-11 21:33 7,069 -ra------ C:\WINDOWS\system32\atifglpf.xml
2008-04-29 19:58 . 2008-04-29 19:58 <DIR> d-------- C:\ATI
2008-04-29 06:18 . 2008-04-29 06:18 <DIR> dr-h----- C:\Documents and Settings\Jeremy\Application Data\SecuROM
2008-04-29 06:18 . 2008-04-29 06:18 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-04-29 06:17 . 2008-04-29 06:17 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-04-29 06:11 . 2008-04-29 06:11 22,328 --a------ C:\Documents and Settings\Jeremy\Application Data\PnkBstrK.sys
2008-04-29 06:04 . 2008-04-29 06:04 <DIR> d-------- C:\Program Files\Activision
2008-04-29 05:53 . 2004-08-04 01:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-04-29 05:53 . 2004-08-04 01:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-04-29 05:53 . 2004-08-04 01:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-04-29 05:53 . 2004-08-04 01:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-04-29 05:53 . 2004-08-04 02:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-04-29 05:53 . 2004-08-04 02:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-04-29 00:41 . 2008-04-29 06:17 <DIR> d-------- C:\Documents and Settings\Jeremy\Application Data\GetRightToGo
2008-04-28 19:15 . 2008-02-28 13:26 1,414,440 --a------ C:\WINDOWS\system32\ShellManager310E2D762.dll
2008-04-28 19:14 . 2008-04-28 19:14 0 --a------ C:\WINDOWS\Irremote.ini
2008-04-24 13:21 . 2008-05-20 21:29 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-04-24 13:21 . 2008-04-24 13:21 <DIR> d-------- C:\AeriaGames
2008-04-22 05:59 . 2008-05-09 23:14 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-04-22 05:53 . 2008-04-22 05:53 4 --a------ C:\WINDOWS\msoffice.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-22 09:57 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 2
2008-05-21 02:03 --------- d-----w C:\Documents and Settings\Jeremy\Application Data\Xfire
2008-05-20 06:14 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-20 06:13 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-05-20 06:05 --------- d-----w C:\Program Files\Xfire
2008-05-11 00:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-05-09 08:58 --------- d-----w C:\Program Files\Nero
2008-04-29 23:58 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-28 23:15 --------- d-----w C:\Program Files\Common Files\Nero
2008-04-22 09:54 --------- d-----w C:\Program Files\Common Files\AOL
2008-04-22 09:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-04-22 09:53 --------- d-----w C:\Documents and Settings\Jeremy\Application Data\AOL
2008-04-21 05:49 --------- d-----w C:\Program Files\NeroInstall.bak
2008-04-21 05:48 --------- d-----w C:\Documents and Settings\Jeremy\Application Data\Nero
2008-04-17 04:40 1,049,662 ----a-w C:\WINDOWS\Prison Tycoon 3 Uninstaller.exe
2008-04-15 02:14 --------- d-----w C:\Program Files\ValuSoft
2008-04-15 02:14 --------- d-----w C:\Program Files\Common Files\Thraex Software
2008-04-14 21:26 --------- d-----w C:\Documents and Settings\Jeremy\Application Data\LimeWire
2008-04-11 07:22 1,882,904 ----a-w C:\WINDOWS\system32\AutoPartNt.exe
2008-04-11 07:19 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Acronis
2008-04-11 07:16 441,760 ----a-w C:\WINDOWS\system32\drivers\timntr.sys
2008-04-11 07:16 44,384 ----a-w C:\WINDOWS\system32\drivers\tifsfilt.sys
2008-04-11 07:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Acronis
2008-04-11 07:15 368,544 ----a-w C:\WINDOWS\system32\drivers\tdrpman.sys
2008-04-11 07:15 129,248 ----a-w C:\WINDOWS\system32\drivers\snapman.sys
2008-04-11 07:15 --------- d-----w C:\Program Files\Acronis
2008-04-10 22:46 --------- d-----w C:\Program Files\Java
2008-04-10 22:45 --------- d-----w C:\Program Files\Common Files\Java
2008-04-04 05:02 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-04-04 01:39 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Xfire
2008-04-02 19:39 --------- d-----w C:\Program Files\LocalCooling
2008-04-02 19:38 --------- d-----w C:\Program Files\ImgBurn
2008-03-29 03:24 46,080 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-24 04:12 --------- d-----w C:\Documents and Settings\Jeremy\Application Data\vlc
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-08 20:27 155,995 ----a-w C:\WINDOWS\java\Packages\UY9BN5VH.ZIP
2008-03-05 20:03 479,752 ----a-w C:\WINDOWS\system32\XAudio2_0.dll
2008-03-05 20:03 238,088 ----a-w C:\WINDOWS\system32\xactengine3_0.dll
2008-03-05 20:00 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_3.dll
2008-03-05 19:56 3,786,760 ----a-w C:\WINDOWS\system32\D3DX9_37.dll
2008-03-05 19:56 1,420,824 ----a-w C:\WINDOWS\system32\D3DCompiler_37.dll
2008-03-01 22:36 3,591,680 ----a-w C:\WINDOWS\system32\SET697.tmp
2008-02-29 04:14 223,744 ----a-w C:\WINDOWS\system32\b4fm.dll
2008-02-25 07:20 4,608 ----a-w C:\WINDOWS\system32\w95inf32.dll
2008-02-25 07:20 2,272 ----a-w C:\WINDOWS\system32\w95inf16.dll
2008-02-24 18:39 5,832 ----a-w C:\Program Files\install.log
2007-12-09 04:10 620 -c--a-w C:\Program Files\JohnDeere.cfg
2006-05-30 01:25 73,727 -c--a-w C:\Program Files\irrm-installer.bat
2006-05-30 01:16 132,199 -c--a-w C:\Program Files\irrm-9x.bat
2006-05-30 00:57 104 -c--a-w C:\Program Files\irrm-reg.reg
2006-04-11 20:14 4,793 -c--a-w C:\Program Files\ReadMe.txt
2005-10-01 18:00 75,264 ----a-w C:\Program Files\irrm-uha.exe
2005-07-23 00:59 2,319,568 ----a-w C:\Program Files\d3dx9_27.dll
2005-07-14 15:06 847,920 ----a-w C:\Program Files\Python22.dll
2005-07-12 20:58 74,573 -c--a-w C:\Program Files\JD.cfl
2005-07-12 20:58 5,191 -c--a-w C:\Program Files\DebugWindow.gib
2005-07-12 20:58 155,648 ----a-w C:\Program Files\boost_python.dll
2005-07-12 20:58 1,378 -c--a-w C:\Program Files\ProfilerWindow.gib
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-11 00:56 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D187A56B-A33F-4CBE-9D77-459FC0BAE012}]
2008-05-10 21:21 806912 --a------ C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll" [2008-05-10 21:21 806912]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-11 00:56 2050816]
[HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-11 00:56 2050816]
"{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll [2008-05-10 21:21 806912]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"AsusStartupHelp"="C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe" [2006-11-15 02:25 363008]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-11 00:56 1177368]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
C:\Documents and Settings\Jeremy\Start Menu\Programs\Startup\
pfkipmysr.lnk - C:\WINDOWS\system32\pfkipmysr.exe [2008-05-15 18:57:55 57344]
Xfire.lnk - C:\Program Files\Xfire\xfire.exe [2008-05-13 21:29:28 3007824]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 07:56:20 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= ir41_32.dll
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RAMASST.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk
backup=C:\WINDOWS\pss\RAMASST.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-ra------ 2005-05-04 14:43 69632 C:\WINDOWS\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 14:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
C:\Program Files\AOL 9.1\AOL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 03:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1200484601\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2006-02-19 02:41 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LocalCooling]
C:\Program Files\LocalCooling\localcooling.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2007-10-19 21:16 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-ra------ 2007-01-31 14:54 16116224 C:\WINDOWS\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-ra------ 2006-05-17 14:04 2879488 C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
--a------ 2005-03-08 05:33 53248 C:\WINDOWS\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires\\Empires.exe"=
"C:\\Nexon\\MapleStory\\MapleStory.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\ftp.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP
xpsp2res.dll,-22009
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-18 17:22]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-11 00:56]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-11 00:56]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2008-02-26 05:54]
S2 npkcmsvc;npkcmsvc;C:\Nexon\Mabinogi\npkcmsvc.exe []
S3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-04 01:31]
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;C:\DOCUME~1\Jeremy\LOCALS~1\Temp\Rar$EX28.547\IlvMoney1105.sys []
S3 tap0801;Smarthide TAP driver;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2007-10-12 09:07]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-22 16:25:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-22 16:25:48
ComboFix-quarantined-files.txt 2008-05-22 20:25:46
Pre-Run: 458,896,551,936 bytes free
Post-Run: 458,903,277,568 bytes free
319
PS.. Does this mean AVG is worthless or is this something that anti-viruses can't detect?