codeman0013
Active Member
ComboFix 08-02.05.3 - David McCoy 2008-02-07 19:19:53.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.178 [GMT -6:00]
Running from: C:\Documents and Settings\David McCoy\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\David McCoy\Application Data\Dxcdmns.dll
C:\Documents and Settings\David McCoy\Application Data\Dxcknwrd.dll
C:\install.exe
C:\Program Files\Common Files\{08E31~1
C:\Program Files\Common Files\{38E31~1
C:\Program Files\FunWebProducts
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\outlook
C:\Program Files\outlook\p.zip
C:\Program Files\winupdate
C:\Program Files\winupdates
C:\Program Files\winupdates\a.zip
C:\WINDOWS\system32\drivers\core.cache.dsk
.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-07 18:40 . 2007-10-10 17:47 6,067,200 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2008-02-07 18:40 . 2007-06-30 21:31 2,455,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2008-02-07 18:40 . 2007-06-30 21:36 991,232 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2008-02-07 18:40 . 2007-10-10 17:47 459,264 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2008-02-07 18:40 . 2007-10-10 17:47 383,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2008-02-07 18:40 . 2007-10-10 17:47 267,776 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2008-02-07 18:40 . 2007-10-10 17:47 63,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2008-02-07 18:40 . 2007-10-10 17:47 52,224 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2008-02-07 18:40 . 2007-10-10 02:16 13,824 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2008-02-06 22:52 . 2001-08-17 22:37 99,865 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xlog.exe
2008-02-06 22:52 . 2001-08-18 07:00 28,288 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xjis.nls
2008-02-06 22:52 . 2004-08-04 00:29 19,455 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wvchntxx.sys
2008-02-06 22:52 . 2001-08-17 12:11 16,970 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xem336n5.sys
2008-02-06 22:52 . 2004-08-04 00:29 12,063 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wsiintxx.sys
2008-02-06 22:52 . 2004-08-04 02:56 8,192 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wshirda.dll
2008-02-06 22:51 . 2004-08-04 00:31 154,624 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wlluc48.sys
2008-02-06 22:51 . 2001-08-17 12:12 34,890 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wlandrv2.sys
2008-02-06 22:51 . 2004-08-04 01:07 8,832 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wmiacpi.sys
2008-02-06 22:49 . 2001-08-17 13:28 794,654 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\usr1801.sys
2008-02-06 22:48 . 2001-08-17 12:18 285,760 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\stlnata.sys
2008-02-06 22:47 . 2001-08-17 14:56 252,032 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\sis300iv.dll
2008-02-06 22:46 . 2001-08-17 22:36 386,560 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\sgiul50.dll
2008-02-06 22:45 . 2001-08-17 13:28 899,146 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\r2mdkxga.sys
2008-02-06 22:44 . 2004-08-04 02:56 363,520 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\psisdecd.dll
2008-02-06 22:43 . 2001-08-17 14:05 351,616 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ovcodek2.sys
2008-02-06 22:42 . 2001-08-17 12:50 198,144 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\nv3.sys
2008-02-06 22:41 . 2001-08-18 07:00 1,875,968 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\msir3jp.lex
2008-02-06 22:40 . 2001-08-17 13:28 802,683 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ltsm.sys
2008-02-06 22:39 . 2001-08-18 07:00 1,158,818 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\korwbrkr.lex
2008-02-06 22:38 . 2001-08-18 07:00 471,102 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\imskdic.dll
2008-02-06 22:37 . 2001-08-18 07:00 10,129,408 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hwxkor.dll
2008-02-06 22:36 . 2001-08-18 07:00 13,463,552 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hwxjpn.dll
2008-02-06 22:35 . 2001-08-17 14:56 1,733,120 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\g400d.dll
2008-02-06 22:34 . 2001-08-17 13:28 634,134 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\el656ct5.sys
2008-02-06 22:33 . 2001-08-17 12:14 952,007 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\diwan.sys
2008-02-06 22:32 . 2001-08-17 12:13 980,034 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cicap.sys
2008-02-06 22:31 . 2001-08-18 07:00 1,677,824 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\chsbrkr.dll
2008-02-06 22:30 . 2001-08-17 13:28 871,388 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bcmdm.sys
2008-02-06 22:29 . 2001-08-17 12:19 747,392 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\adm8830.sys
2008-02-06 22:28 . 2001-08-17 13:28 762,780 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\3cwmcru.sys
2008-02-06 22:28 . 2001-08-17 14:56 66,048 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\s3legacy.dll
2008-02-06 22:28 . 2004-08-04 01:10 53,248 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\1394bus.sys
2008-02-06 22:28 . 2001-08-17 14:06 11,264 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\1394vdbg.sys
2008-02-06 22:19 . 2008-02-06 22:19 <DIR> d-------- C:\Program Files\CCleaner
2008-02-06 22:06 . 2008-02-06 22:19 <DIR> d-------- C:\Documents and Settings\Joel Conley\Programs
2008-02-06 21:50 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-02-06 21:46 . 2008-02-06 21:46 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-06 21:22 . 2008-02-06 21:22 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\TeamViewer
2008-02-06 19:15 . 2008-02-06 19:15 <DIR> dr-h----- C:\Documents and Settings\David McCoy\Application Data\yahoo!
2008-02-06 18:21 . 2008-02-06 18:21 <DIR> d-------- C:\Documents and Settings\David McCoy\Application Data\TeamViewer
2008-02-06 18:18 . 2008-02-06 18:22 <DIR> d-------- C:\Program Files\TeamViewer3
2008-02-06 18:17 . 2008-02-06 18:17 <DIR> d-------- C:\Documents and Settings\David McCoy\temp
2008-01-20 12:30 . 2008-01-20 12:30 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-20 12:30 . 2008-01-20 12:30 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 00:28 --------- d-----w C:\Documents and Settings\David McCoy\Application Data\AVG7
2008-02-07 04:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-07 04:01 --------- d-----w C:\Program Files\Dell
2008-02-07 03:57 --------- d-----w C:\Program Files\CardRecovery
2008-02-07 03:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-07 03:52 --------- d-----w C:\Program Files\DivX
2008-02-07 03:50 --------- d-----w C:\Program Files\Java
2008-02-07 03:41 --------- d-----w C:\Program Files\Symantec
2008-02-07 03:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-07 03:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-07 03:22 --------- d-----w C:\Program Files\McAfee
2008-02-07 03:21 --------- d-----w C:\Program Files\Windows Desktop Search
2008-02-07 03:21 --------- d-----w C:\Program Files\WebIQ
2008-02-07 03:21 --------- d-----w C:\Program Files\Virtools
2008-02-07 03:11 --------- d-----w C:\Program Files\Virtual Laguna Beach
2008-02-07 03:04 --------- d-----w C:\Program Files\Norton Password Manager
2008-02-07 03:03 --------- d-----w C:\Program Files\Yahoo!
2008-02-07 03:02 --------- d-----w C:\Program Files\Opera
2008-02-07 03:00 --------- d-----w C:\Program Files\PartyGaming
2008-02-07 02:59 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-02-07 02:56 --------- d-----w C:\Program Files\Common Files\Real
2008-02-07 02:55 --------- d-----w C:\Program Files\mozilla.org
2008-02-07 02:33 --------- d-----w C:\Program Files\Styler
2008-02-07 02:27 --------- d-----w C:\Program Files\VideoLAN
2008-02-07 02:25 --------- d-----w C:\Program Files\Viewpoint
2008-02-07 02:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-07 01:16 --------- d-----w C:\Program Files\Common Files\Scanner
2008-02-07 01:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-02-06 23:48 --------- d-----w C:\Program Files\McFunSoft Video Solution
2008-02-06 23:43 --------- d-----w C:\Documents and Settings\David McCoy\Application Data\McAfee
2008-02-06 23:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-02-04 02:26 --------- d-----w C:\Documents and Settings\Beth McCoy\Application Data\AVG7
2007-05-18 16:27 25,214 -c--a-w C:\Program Files\B.ico
2007-05-18 16:27 25,214 -c--a-w C:\Program Files\A.ico
2006-07-28 05:22 123,296 -c--a-w C:\Documents and Settings\David McCoy\Application Data\GDIPFONTCACHEV1.DAT
2003-03-02 01:33 32 -csha-w C:\WINDOWS\{234FC75B-0B3A-45DB-B10F-5DFA4B745408}.dat
2003-03-02 01:33 32 -csha-w C:\WINDOWS\SYSTEM32\{EEB70268-39EB-434F-AF8F-D784960261B1}.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Procs]
@={51D8EAB2-A055-487F-BBE0-DFB79DD0E76D}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 09:20 50528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-20 12:18 579072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
"washindex"="C:\Program Files\Cookie Washer\washidx.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [ ]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [ ]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-03 19:04 219136]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"{08E312F2-0891-1033-1207-010322060001}"= "C:\Program Files\Common Files\{08E312F2-0891-1033-1207-010322060001}\Update.exe" mc-110-12-0000140
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Launchpad.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launchpad.lnk
backup=C:\WINDOWS\pss\Launchpad.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MMSYSTRAY_NAME.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MMSYSTRAY_NAME.lnk
backup=C:\WINDOWS\pss\MMSYSTRAY_NAME.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MVP Media Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MVP Media Monitor.lnk
backup=C:\WINDOWS\pss\MVP Media Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^David McCoy^Start Menu^Programs^Startup^Camio Viewer 3.2.lnk]
path=C:\Documents and Settings\David McCoy\Start Menu\Programs\Startup\Camio Viewer 3.2.lnk
backup=C:\WINDOWS\pss\Camio Viewer 3.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0000811163604555mcinstcleanup]
C:\WINDOWS\TEMP\000081~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0048841163555854mcinstcleanup]
C:\WINDOWS\TEMP\004884~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0097661163446971mcinstcleanup]
C:\WINDOWS\TEMP\009766~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0128021163879378mcinstcleanup]
C:\WINDOWS\TEMP\012802~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0139371163779382mcinstcleanup]
C:\WINDOWS\TEMP\013937~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0324641163965674mcinstcleanup]
C:\WINDOWS\TEMP\032464~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcctMgr]
C:\Program Files\Norton Password Manager\AcctMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AccuWeatherDesktopAlerts]
--------- 2004-11-19 20:40 249856 C:\Program Files\AccuWeatherDesktopAlerts\AccuWeatherDesktopAlerts.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AHQInit]
--a------ 2001-03-27 19:00 102400 C:\Program Files\Creative\SBLive\Program\AHQInit.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
--a------ 2004-07-08 10:07 78960 C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ashMaiSv]
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_CC]
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 01:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellTouch]
C:\WINDOWS\DELLMMKB.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Disc Detector]
--a------ 1999-08-30 01:55 189952 C:\Program Files\Creative\ShareDLL\CtNotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fkzihmt]
C:\WINDOWS\fkzihmt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2002-01-08 10:24 401496 C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2005-01-12 14:54 241664 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-16 23:11 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a--c--- 2004-04-06 04:28 172032 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\irkf]
C:\PROGRA~1\COMMON~1\irkf\irkfm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-04-27 10:25 257088 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]
--a------ 2006-03-16 01:07 57344 C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mirabilis ICQ]
C:\Program Files\ICQ\icq.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-08-11 19:43 1519616 C:\WINDOWS\SYSTEM32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\outlook]
C:\Program Files\outlook\outlook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\POINTER]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray]
--a--c--- 2000-06-14 16:55 36864 C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-04-27 08:41 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioAudioCentral]
--a------ 2003-06-23 21:12 319488 C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
--a--c--- 2003-06-25 00:18 868352 C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
--a------ 2003-05-01 18:44 65536 C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
C:\Program Files\SiteAdvisor\6009\SiteAdv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
--a------ 2007-10-01 16:40 5367608 C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
C:\Program Files\Spyware Doctor\swdoctor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TCASUTIEXE]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--a------ 2000-05-11 01:00 90112 C:\WINDOWS\Updreg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WT GameChannel]
C:\Program Files\WildTangent\Apps\GameChannel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XBHOUB]
C:\WINDOWS\XBHOUB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XeroxScannerDaemon]
--a------ 2001-08-17 22:37 27648 C:\Program Files\Xerox\NWWia\XrxFTPLt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
R2 Nhksrv;Netropa NHK Server;C:\WINDOWS\Nhksrv.exe [2001-08-06 13:41]
R2 tcaicchg;tcaicchg;C:\WINDOWS\System32\tcaicchg.sys [2000-06-06 18:08]
R2 TCAITDI;TCAITDI Protocol;C:\WINDOWS\system32\DRIVERS\TCAITDI.sys [2001-09-04 11:22]
R2 TeamViewer;TeamViewer 3;"C:\Program Files\TeamViewer3\TeamViewer_Host.exe" [2008-01-28 03:12]
R3 Msikbd2k;DellTouch;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2000-10-03 15:18]
S2 ousbehci;NEC PCI to USB Enhanced Host Controller;C:\WINDOWS\system32\Drivers\ousbehci.sys [2002-04-01 01:39]
S3 ATICXCAP;ATI TV Wonder Pro A/V Capture;C:\WINDOWS\system32\drivers\aticxcap.sys [2006-06-21 15:22]
S3 ATICXTUN;ATI TV Wonder 200 Tuner (Philips 1236 MK3);C:\WINDOWS\system32\drivers\aticxtun.sys [2006-06-21 15:22]
S3 ATICXXBR;ATI TV Wonder 200 A/V Crossbar;C:\WINDOWS\system32\drivers\aticxxbr.sys [2006-06-21 15:22]
S3 banshee;banshee;C:\WINDOWS\system32\DRIVERS\banshee.sys [2001-08-17 12:48]
S3 DCamUSBUVT;ICM532A;C:\WINDOWS\system32\Drivers\usbuvt.sys []
S3 EraserUtilDrv10614;EraserUtilDrv10614;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10614.sys []
S3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;C:\WINDOWS\system32\DRIVERS\ousb2hub.sys [2002-04-01 01:39]
S4 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2001-08-17 13:52]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d875419-9e81-11db-854d-806d6172696f}]
\Shell\AutoRun\command - H:\Setupx.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{92e65f86-b222-11d9-9b46-00038a000015}]
\Shell\AutoRun\command - JDSecure\Windows\JDSecure20.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{07CDEFFF-22A7-2DEC-0302-070001080100}]
C:\WINDOWS\system32\Run32Dll.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-03-13 20:08:48 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
disk not found C:\
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Aim6 = "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp??
scanning hidden files ...
disk not found C:\
**************************************************************************
.
Completion time: 2008-02-07 19:24:43
ComboFix-quarantined-files.txt 2008-02-08 01:23:46
.
2008-02-08 01:10:10 --- E O F ---
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.178 [GMT -6:00]
Running from: C:\Documents and Settings\David McCoy\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\David McCoy\Application Data\Dxcdmns.dll
C:\Documents and Settings\David McCoy\Application Data\Dxcknwrd.dll
C:\install.exe
C:\Program Files\Common Files\{08E31~1
C:\Program Files\Common Files\{38E31~1
C:\Program Files\FunWebProducts
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\outlook
C:\Program Files\outlook\p.zip
C:\Program Files\winupdate
C:\Program Files\winupdates
C:\Program Files\winupdates\a.zip
C:\WINDOWS\system32\drivers\core.cache.dsk
.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-07 18:40 . 2007-10-10 17:47 6,067,200 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2008-02-07 18:40 . 2007-06-30 21:31 2,455,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2008-02-07 18:40 . 2007-06-30 21:36 991,232 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2008-02-07 18:40 . 2007-10-10 17:47 459,264 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2008-02-07 18:40 . 2007-10-10 17:47 383,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2008-02-07 18:40 . 2007-10-10 17:47 267,776 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2008-02-07 18:40 . 2007-10-10 17:47 63,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2008-02-07 18:40 . 2007-10-10 17:47 52,224 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2008-02-07 18:40 . 2007-10-10 02:16 13,824 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2008-02-06 22:52 . 2001-08-17 22:37 99,865 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xlog.exe
2008-02-06 22:52 . 2001-08-18 07:00 28,288 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xjis.nls
2008-02-06 22:52 . 2004-08-04 00:29 19,455 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wvchntxx.sys
2008-02-06 22:52 . 2001-08-17 12:11 16,970 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xem336n5.sys
2008-02-06 22:52 . 2004-08-04 00:29 12,063 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wsiintxx.sys
2008-02-06 22:52 . 2004-08-04 02:56 8,192 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wshirda.dll
2008-02-06 22:51 . 2004-08-04 00:31 154,624 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wlluc48.sys
2008-02-06 22:51 . 2001-08-17 12:12 34,890 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wlandrv2.sys
2008-02-06 22:51 . 2004-08-04 01:07 8,832 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wmiacpi.sys
2008-02-06 22:49 . 2001-08-17 13:28 794,654 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\usr1801.sys
2008-02-06 22:48 . 2001-08-17 12:18 285,760 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\stlnata.sys
2008-02-06 22:47 . 2001-08-17 14:56 252,032 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\sis300iv.dll
2008-02-06 22:46 . 2001-08-17 22:36 386,560 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\sgiul50.dll
2008-02-06 22:45 . 2001-08-17 13:28 899,146 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\r2mdkxga.sys
2008-02-06 22:44 . 2004-08-04 02:56 363,520 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\psisdecd.dll
2008-02-06 22:43 . 2001-08-17 14:05 351,616 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ovcodek2.sys
2008-02-06 22:42 . 2001-08-17 12:50 198,144 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\nv3.sys
2008-02-06 22:41 . 2001-08-18 07:00 1,875,968 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\msir3jp.lex
2008-02-06 22:40 . 2001-08-17 13:28 802,683 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ltsm.sys
2008-02-06 22:39 . 2001-08-18 07:00 1,158,818 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\korwbrkr.lex
2008-02-06 22:38 . 2001-08-18 07:00 471,102 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\imskdic.dll
2008-02-06 22:37 . 2001-08-18 07:00 10,129,408 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hwxkor.dll
2008-02-06 22:36 . 2001-08-18 07:00 13,463,552 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hwxjpn.dll
2008-02-06 22:35 . 2001-08-17 14:56 1,733,120 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\g400d.dll
2008-02-06 22:34 . 2001-08-17 13:28 634,134 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\el656ct5.sys
2008-02-06 22:33 . 2001-08-17 12:14 952,007 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\diwan.sys
2008-02-06 22:32 . 2001-08-17 12:13 980,034 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\cicap.sys
2008-02-06 22:31 . 2001-08-18 07:00 1,677,824 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\chsbrkr.dll
2008-02-06 22:30 . 2001-08-17 13:28 871,388 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\bcmdm.sys
2008-02-06 22:29 . 2001-08-17 12:19 747,392 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\adm8830.sys
2008-02-06 22:28 . 2001-08-17 13:28 762,780 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\3cwmcru.sys
2008-02-06 22:28 . 2001-08-17 14:56 66,048 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\s3legacy.dll
2008-02-06 22:28 . 2004-08-04 01:10 53,248 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\1394bus.sys
2008-02-06 22:28 . 2001-08-17 14:06 11,264 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\1394vdbg.sys
2008-02-06 22:19 . 2008-02-06 22:19 <DIR> d-------- C:\Program Files\CCleaner
2008-02-06 22:06 . 2008-02-06 22:19 <DIR> d-------- C:\Documents and Settings\Joel Conley\Programs
2008-02-06 21:50 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-02-06 21:46 . 2008-02-06 21:46 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-06 21:22 . 2008-02-06 21:22 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\TeamViewer
2008-02-06 19:15 . 2008-02-06 19:15 <DIR> dr-h----- C:\Documents and Settings\David McCoy\Application Data\yahoo!
2008-02-06 18:21 . 2008-02-06 18:21 <DIR> d-------- C:\Documents and Settings\David McCoy\Application Data\TeamViewer
2008-02-06 18:18 . 2008-02-06 18:22 <DIR> d-------- C:\Program Files\TeamViewer3
2008-02-06 18:17 . 2008-02-06 18:17 <DIR> d-------- C:\Documents and Settings\David McCoy\temp
2008-01-20 12:30 . 2008-01-20 12:30 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-20 12:30 . 2008-01-20 12:30 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 00:28 --------- d-----w C:\Documents and Settings\David McCoy\Application Data\AVG7
2008-02-07 04:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-07 04:01 --------- d-----w C:\Program Files\Dell
2008-02-07 03:57 --------- d-----w C:\Program Files\CardRecovery
2008-02-07 03:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-07 03:52 --------- d-----w C:\Program Files\DivX
2008-02-07 03:50 --------- d-----w C:\Program Files\Java
2008-02-07 03:41 --------- d-----w C:\Program Files\Symantec
2008-02-07 03:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-07 03:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-07 03:22 --------- d-----w C:\Program Files\McAfee
2008-02-07 03:21 --------- d-----w C:\Program Files\Windows Desktop Search
2008-02-07 03:21 --------- d-----w C:\Program Files\WebIQ
2008-02-07 03:21 --------- d-----w C:\Program Files\Virtools
2008-02-07 03:11 --------- d-----w C:\Program Files\Virtual Laguna Beach
2008-02-07 03:04 --------- d-----w C:\Program Files\Norton Password Manager
2008-02-07 03:03 --------- d-----w C:\Program Files\Yahoo!
2008-02-07 03:02 --------- d-----w C:\Program Files\Opera
2008-02-07 03:00 --------- d-----w C:\Program Files\PartyGaming
2008-02-07 02:59 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-02-07 02:56 --------- d-----w C:\Program Files\Common Files\Real
2008-02-07 02:55 --------- d-----w C:\Program Files\mozilla.org
2008-02-07 02:33 --------- d-----w C:\Program Files\Styler
2008-02-07 02:27 --------- d-----w C:\Program Files\VideoLAN
2008-02-07 02:25 --------- d-----w C:\Program Files\Viewpoint
2008-02-07 02:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-07 01:16 --------- d-----w C:\Program Files\Common Files\Scanner
2008-02-07 01:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-02-06 23:48 --------- d-----w C:\Program Files\McFunSoft Video Solution
2008-02-06 23:43 --------- d-----w C:\Documents and Settings\David McCoy\Application Data\McAfee
2008-02-06 23:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-02-04 02:26 --------- d-----w C:\Documents and Settings\Beth McCoy\Application Data\AVG7
2007-05-18 16:27 25,214 -c--a-w C:\Program Files\B.ico
2007-05-18 16:27 25,214 -c--a-w C:\Program Files\A.ico
2006-07-28 05:22 123,296 -c--a-w C:\Documents and Settings\David McCoy\Application Data\GDIPFONTCACHEV1.DAT
2003-03-02 01:33 32 -csha-w C:\WINDOWS\{234FC75B-0B3A-45DB-B10F-5DFA4B745408}.dat
2003-03-02 01:33 32 -csha-w C:\WINDOWS\SYSTEM32\{EEB70268-39EB-434F-AF8F-D784960261B1}.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Procs]
@={51D8EAB2-A055-487F-BBE0-DFB79DD0E76D}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 09:20 50528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-20 12:18 579072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
"washindex"="C:\Program Files\Cookie Washer\washidx.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [ ]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [ ]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-03 19:04 219136]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"{08E312F2-0891-1033-1207-010322060001}"= "C:\Program Files\Common Files\{08E312F2-0891-1033-1207-010322060001}\Update.exe" mc-110-12-0000140
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Launchpad.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launchpad.lnk
backup=C:\WINDOWS\pss\Launchpad.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MMSYSTRAY_NAME.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MMSYSTRAY_NAME.lnk
backup=C:\WINDOWS\pss\MMSYSTRAY_NAME.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MVP Media Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MVP Media Monitor.lnk
backup=C:\WINDOWS\pss\MVP Media Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^David McCoy^Start Menu^Programs^Startup^Camio Viewer 3.2.lnk]
path=C:\Documents and Settings\David McCoy\Start Menu\Programs\Startup\Camio Viewer 3.2.lnk
backup=C:\WINDOWS\pss\Camio Viewer 3.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0000811163604555mcinstcleanup]
C:\WINDOWS\TEMP\000081~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0048841163555854mcinstcleanup]
C:\WINDOWS\TEMP\004884~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0097661163446971mcinstcleanup]
C:\WINDOWS\TEMP\009766~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0128021163879378mcinstcleanup]
C:\WINDOWS\TEMP\012802~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0139371163779382mcinstcleanup]
C:\WINDOWS\TEMP\013937~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0324641163965674mcinstcleanup]
C:\WINDOWS\TEMP\032464~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcctMgr]
C:\Program Files\Norton Password Manager\AcctMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AccuWeatherDesktopAlerts]
--------- 2004-11-19 20:40 249856 C:\Program Files\AccuWeatherDesktopAlerts\AccuWeatherDesktopAlerts.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AHQInit]
--a------ 2001-03-27 19:00 102400 C:\Program Files\Creative\SBLive\Program\AHQInit.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
--a------ 2004-07-08 10:07 78960 C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ashMaiSv]
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_CC]
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 01:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellTouch]
C:\WINDOWS\DELLMMKB.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Disc Detector]
--a------ 1999-08-30 01:55 189952 C:\Program Files\Creative\ShareDLL\CtNotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fkzihmt]
C:\WINDOWS\fkzihmt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2002-01-08 10:24 401496 C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2005-01-12 14:54 241664 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-16 23:11 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a--c--- 2004-04-06 04:28 172032 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\irkf]
C:\PROGRA~1\COMMON~1\irkf\irkfm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-04-27 10:25 257088 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]
--a------ 2006-03-16 01:07 57344 C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mirabilis ICQ]
C:\Program Files\ICQ\icq.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-08-11 19:43 1519616 C:\WINDOWS\SYSTEM32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\outlook]
C:\Program Files\outlook\outlook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\POINTER]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray]
--a--c--- 2000-06-14 16:55 36864 C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-04-27 08:41 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioAudioCentral]
--a------ 2003-06-23 21:12 319488 C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
--a--c--- 2003-06-25 00:18 868352 C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
--a------ 2003-05-01 18:44 65536 C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
C:\Program Files\SiteAdvisor\6009\SiteAdv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
--a------ 2007-10-01 16:40 5367608 C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
C:\Program Files\Spyware Doctor\swdoctor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TCASUTIEXE]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--a------ 2000-05-11 01:00 90112 C:\WINDOWS\Updreg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WT GameChannel]
C:\Program Files\WildTangent\Apps\GameChannel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XBHOUB]
C:\WINDOWS\XBHOUB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XeroxScannerDaemon]
--a------ 2001-08-17 22:37 27648 C:\Program Files\Xerox\NWWia\XrxFTPLt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
R2 Nhksrv;Netropa NHK Server;C:\WINDOWS\Nhksrv.exe [2001-08-06 13:41]
R2 tcaicchg;tcaicchg;C:\WINDOWS\System32\tcaicchg.sys [2000-06-06 18:08]
R2 TCAITDI;TCAITDI Protocol;C:\WINDOWS\system32\DRIVERS\TCAITDI.sys [2001-09-04 11:22]
R2 TeamViewer;TeamViewer 3;"C:\Program Files\TeamViewer3\TeamViewer_Host.exe" [2008-01-28 03:12]
R3 Msikbd2k;DellTouch;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2000-10-03 15:18]
S2 ousbehci;NEC PCI to USB Enhanced Host Controller;C:\WINDOWS\system32\Drivers\ousbehci.sys [2002-04-01 01:39]
S3 ATICXCAP;ATI TV Wonder Pro A/V Capture;C:\WINDOWS\system32\drivers\aticxcap.sys [2006-06-21 15:22]
S3 ATICXTUN;ATI TV Wonder 200 Tuner (Philips 1236 MK3);C:\WINDOWS\system32\drivers\aticxtun.sys [2006-06-21 15:22]
S3 ATICXXBR;ATI TV Wonder 200 A/V Crossbar;C:\WINDOWS\system32\drivers\aticxxbr.sys [2006-06-21 15:22]
S3 banshee;banshee;C:\WINDOWS\system32\DRIVERS\banshee.sys [2001-08-17 12:48]
S3 DCamUSBUVT;ICM532A;C:\WINDOWS\system32\Drivers\usbuvt.sys []
S3 EraserUtilDrv10614;EraserUtilDrv10614;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10614.sys []
S3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;C:\WINDOWS\system32\DRIVERS\ousb2hub.sys [2002-04-01 01:39]
S4 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2001-08-17 13:52]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d875419-9e81-11db-854d-806d6172696f}]
\Shell\AutoRun\command - H:\Setupx.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{92e65f86-b222-11d9-9b46-00038a000015}]
\Shell\AutoRun\command - JDSecure\Windows\JDSecure20.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{07CDEFFF-22A7-2DEC-0302-070001080100}]
C:\WINDOWS\system32\Run32Dll.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-03-13 20:08:48 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
disk not found C:\
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Aim6 = "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp??
scanning hidden files ...
disk not found C:\
**************************************************************************
.
Completion time: 2008-02-07 19:24:43
ComboFix-quarantined-files.txt 2008-02-08 01:23:46
.
2008-02-08 01:10:10 --- E O F ---