ComboFix 08-10-02.04 - bayern 2008-10-03 1:58:23.2 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1256.963.1033.18.325 [GMT 2:00]
Running from: C:\Documents and Settings\bayern\Desktop\protect\ComboFix1.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - WINDOWS: deleted 0 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\bayern\s\HOILT.QEX
C:\Documents and Settings\bayern\Favorites\Error Cleaner.url
C:\Documents and Settings\bayern\Favorites\Privacy Protector.url
C:\Documents and Settings\bayern\Favorites\Spyware&Malware Protection.url
C:\RECYCLER\ADAPT_Installer.exe
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\taskmgr.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Legacy_NPF
-------\Service_Iprip
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-09-03 to 2008-10-03 )))))))))))))))))))))))))))))))
.
2008-10-03 01:51 . 2008-10-03 01:52 6,262,069 --a------ C:\WINDOWS\REGBK00.ZIP
2008-10-03 01:50 . 2008-10-03 01:50 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\CyberScrub
2008-10-03 01:50 . 2008-10-03 01:50 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\cleaner
2008-10-03 01:47 . 2008-10-03 01:47 3,954 --a------ C:\WINDOWS\system32\tmp.reg
2008-10-03 01:45 . 2008-07-08 14:54 148,496 --a------ C:\WINDOWS\system32\drivers\48321128.sys
2008-10-03 01:12 . 2008-10-03 01:45 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
2008-10-02 21:07 . 2008-10-03 01:43 27 --a------ C:\WINDOWS\Lic.xxx
2008-10-02 21:06 . 2004-08-04 00:56 146,432 --a------ C:\WINDOWS\R.COM
2008-10-02 21:06 . 2004-08-04 00:56 135,680 --a------ C:\WINDOWS\system32\T.COM
2008-10-02 21:05 . 2008-10-02 21:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MicroWorld
2008-10-02 19:26 . 2008-10-02 19:54 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-10-02 17:47 . 2008-10-02 17:47 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-10-02 15:02 . 2008-10-02 15:02 <DIR> d-------- C:\Program Files\Symantec
2008-10-02 15:02 . 2008-10-02 15:02 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\Symantec
2008-10-02 15:01 . 2008-10-02 15:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2008-10-02 13:50 . 2008-09-19 20:47 267,592 --a------ C:\Program Files\Uninstall Ask Toolbar.dll
2008-10-02 13:03 . 2007-03-13 09:02 69,632 -r------- C:\WINDOWS\Alcmtr.exe
2008-10-02 13:02 . 2008-10-02 13:02 315,392 --a------ C:\WINDOWS\HideWin.exe
2008-09-30 07:21 . 2008-09-30 07:21 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-09-30 07:20 . 2008-09-30 07:20 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-09-30 07:20 . 2008-05-07 07:39 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-09-30 07:20 . 2008-05-07 07:38 659,968 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-09-30 07:20 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-09-30 07:20 . 2008-05-07 07:38 20,864 --a------ C:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-09-30 07:20 . 2008-05-07 07:38 17,536 --a------ C:\WINDOWS\system32\drivers\ccdcmb.sys
2008-09-30 07:20 . 2008-05-07 07:38 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
2008-09-30 07:20 . 2008-06-06 09:24 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-09-30 06:45 . 2008-09-30 06:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nokia
2008-09-30 03:16 . 2008-09-30 03:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-09-30 03:15 . 2008-09-30 03:15 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-09-29 13:50 . 2008-09-29 13:50 <DIR> d-------- C:\Program Files\Webteh
2008-09-29 13:50 . 2008-09-29 13:50 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\BSplayer Pro
2008-09-29 13:50 . 2008-10-01 23:42 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\BSplayer
2008-09-28 17:18 . 2008-09-28 17:18 <DIR> d-------- C:\Program Files\MSECache
2008-09-27 22:41 . 2008-09-27 22:49 <DIR> d-------- C:\Program Files\Your Uninstaller 2008
2008-09-27 22:41 . 2008-09-27 22:41 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\URSoft
2008-09-27 22:41 . 2008-10-02 17:30 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-27 18:50 . 2008-10-02 00:44 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\LimeWire
2008-09-27 18:45 . 2008-04-17 13:12 107,368 --a------ C:\WINDOWS\system32\GEARAspi.dll
2008-09-27 18:45 . 2008-04-17 13:12 15,464 --a------ C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-09-27 10:09 . 2008-09-27 10:09 0 --a------ C:\WINDOWS\system32\cid_store.dat
2008-09-27 09:56 . 2008-09-27 23:59 <DIR> d-------- C:\Program Files\IEPro
2008-09-27 09:54 . 2008-09-27 09:54 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\MiniDm
2008-09-27 09:50 . 2008-09-27 22:51 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\IEPro
2008-09-27 09:31 . 2008-09-27 22:48 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\SlipStream
2008-09-27 09:29 . 2007-10-19 05:50 114,688 --a------ C:\WINDOWS\sliprt.dll.old
2008-09-27 09:22 . 2008-09-27 09:22 <DIR> d-------- C:\Program Files\uTorrent
2008-09-27 09:21 . 2008-09-28 10:29 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\uTorrent
2008-09-27 02:16 . 2008-09-27 02:21 <DIR> d-------- C:\Program Files\QuickTime
2008-09-27 02:16 . 2008-09-27 02:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-27 02:15 . 2008-10-02 13:48 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-09-27 01:59 . 2008-09-27 01:59 <DIR> d-------- C:\Program Files\Shareaza
2008-09-27 01:59 . 2008-09-28 00:45 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\Shareaza
2008-09-27 01:52 . 2008-09-27 01:52 <DIR> d-------- C:\Program Files\Plugin
2008-09-26 18:51 . 2008-09-26 20:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DriverScanner
2008-09-26 13:39 . 2008-09-26 18:52 <DIR> d--h-c--- C:\Documents and Settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2008-09-26 13:38 . 2008-09-26 13:39 <DIR> d--h-c--- C:\Documents and Settings\All Users\Application Data\{1377D272-D99F-4A4B-9C83-A918F678475B}
2008-09-26 13:25 . 2008-09-26 18:51 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\uniblue
2008-09-26 13:24 . 2008-09-26 18:51 <DIR> d-------- C:\Program Files\Uniblue
2008-09-26 13:04 . 2008-09-26 13:16 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-09-26 02:13 . 2008-09-26 02:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-26 01:41 . 2008-09-26 01:41 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\kantaris
2008-09-26 01:40 . 2008-10-02 17:32 <DIR> d-------- C:\Program Files\Kantaris
2008-09-25 22:24 . 2004-08-03 22:31 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys
2008-09-25 22:24 . 2004-08-03 22:31 20,992 --a--c--- C:\WINDOWS\system32\dllcache\rtl8139.sys
2008-09-25 17:11 . 2008-09-25 17:14 21,598 --a------ C:\WINDOWS\system32\oemlogo.bmp
2008-09-25 17:11 . 2008-09-25 17:15 130 --a------ C:\WINDOWS\system32\oeminfo.ini
2008-09-25 14:03 . 2008-09-26 13:24 <DIR> d--h-c--- C:\Documents and Settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2008-09-25 13:37 . 2008-09-25 13:37 <DIR> dr-h----- C:\AHCache
2008-09-25 12:40 . 2008-09-30 17:31 <DIR> d-------- C:\Program Files\MACMask
2008-09-25 01:21 . 2008-10-02 13:43 <DIR> d-------- C:\Program Files\Netlog Video Tool
2008-09-24 22:22 . 1997-11-19 15:49 303,616 --a------ C:\WINDOWS\IsUninst.exe
2008-09-24 22:22 . 2008-10-02 14:09 63 --a------ C:\WINDOWS\key.lgl
2008-09-24 19:40 . 2008-09-24 19:53 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\Goverlan
2008-09-24 19:38 . 2003-04-03 12:10 46,080 --a------ C:\WINDOWS\system32\_easywall.dll
2008-09-24 19:32 . 2008-09-24 19:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GoverRMC
2008-09-24 19:32 . 2007-02-16 20:08 57,344 --a------ C:\WINDOWS\system32\AstSrv.exe
2008-09-24 17:14 . 2008-09-24 17:14 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\XArp
2008-09-24 17:13 . 2008-09-24 17:13 4,100 --a------ C:\WINDOWS\system32\hdvirffo.dll
2008-09-24 17:11 . 2008-09-24 17:29 <DIR> d-------- C:\Program Files\XArp
2008-09-24 17:01 . 2008-09-24 17:01 98,304 --a------ C:\WINDOWS\system32\SoftAheadCert.dll
2008-09-24 10:20 . 2008-09-24 19:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hagel Technologies
2008-09-24 09:46 . 2008-09-24 18:29 <DIR> d-------- C:\Program Files\SwitchSniffer
2008-09-23 23:59 . 2008-09-23 23:59 <DIR> d-------- C:\WINDOWS\Sun
2008-09-23 23:57 . 2008-10-03 01:34 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-09-23 11:16 . 2008-09-23 17:08 <DIR> d-------- C:\Program Files\Download Direct
2008-09-23 10:29 . 2008-09-23 10:29 <DIR> d-------- C:\Program Files\Pcsx2
2008-09-22 10:20 . 2008-09-22 10:21 <DIR> d-------- C:\Program Files\Flash Player Pro
2008-09-20 21:05 . 2008-09-20 21:05 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-09-20 18:31 . 2008-09-20 18:35 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-09-20 17:44 . 2008-10-02 17:42 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\MxBoost
2008-09-20 17:40 . 2008-09-29 19:51 <DIR> d-------- C:\Program Files\Maxthon2
2008-09-20 14:33 . 2008-09-20 14:33 <DIR> d-------- C:\Program Files\Netlog Photo Tool
2008-09-20 12:16 . 2008-09-20 12:18 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\RapidGet
2008-09-20 11:34 . 2008-09-20 11:34 <DIR> d-------- C:\Program Files\Ares Ultra
2008-09-19 20:52 . 2008-09-29 00:41 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\FrostWire
2008-09-19 20:47 . 2008-09-19 20:52 <DIR> d-------- C:\Program Files\FrostWire
2008-09-19 20:46 . 2008-09-19 20:46 <DIR> d-------- C:\Program Files\ICQ6Toolbar
2008-09-19 20:46 . 2008-09-19 20:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ICQ
2008-09-19 20:45 . 2008-09-19 20:51 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\ICQ
2008-09-19 20:44 . 2008-09-19 20:51 <DIR> d-------- C:\Program Files\ICQ6
2008-09-19 20:37 . 2008-09-19 20:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-09-19 20:36 . 2008-09-19 20:36 <DIR> d-------- C:\Program Files\Yahoo!
2008-09-19 20:28 . 2008-09-28 00:48 <DIR> d-------- C:\Program Files\LimeWire
2008-09-19 20:10 . 2008-09-28 00:44 <DIR> d-------- C:\Program Files\eMule
2008-09-19 19:38 . 2008-09-26 13:07 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-09-19 19:38 . 2008-09-19 19:38 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-09-19 19:38 . 2008-09-19 19:38 <DIR> d-------- C:\Program Files\MSBuild
2008-09-19 19:37 . 2008-07-18 22:07 270,880 --a------ C:\WINDOWS\system32\mucltui.dll
2008-09-19 19:37 . 2008-07-18 22:07 29,728 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-09-19 19:37 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-09-19 19:33 . 2008-09-19 19:33 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-09-19 19:19 . 2008-10-03 01:34 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-19 19:18 . 2008-09-23 23:57 <DIR> d-------- C:\Program Files\Java
2008-09-19 19:11 . 2008-09-19 19:11 <DIR> d-------- C:\Program Files\Common Files\Java
2008-09-19 19:08 . 2008-09-19 19:08 <DIR> d-------- C:\WINDOWS\Logs
2008-09-19 16:26 . 2008-09-19 16:26 <DIR> d-------- C:\Documents and Settings\bayern\Application Data\Media Player Classic
2008-09-19 15:58 . 2008-09-19 15:58 <DIR> d--h----- C:\WINDOWS\PIF
2008-09-19 15:45 . 2008-10-03 01:18 <DIR> d-------- C:\Program Files\Total Video Converter
2008-09-19 15:45 . 2000-05-22 22:58 608,448 --a------ C:\WINDOWS\system32\comctl32.ocx
2008-09-19 15:43 . 2008-09-19 15:43 <DIR> d-------- C:\Program Files\Samy_Soft
2008-09-19 15:29 . 2008-09-19 15:29 <DIR> d-------- C:\Program Files\OUP
2008-09-19 15:28 . 2008-09-19 15:28 <DIR> d-------- C:\Castle
2008-09-19 13:17 . 2008-09-29 00:48 <DIR> d-------- C:\Program Files\BitComet
2008-09-19 12:44 . 2008-10-03 01:27 <DIR> d-------- C:\Documents and Settings\bayern\Tracing
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-02 23:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-10-02 22:51 524,320 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-02 22:51 2,872 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-02 22:37 16,676 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-02 22:37 1,996,320 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-02 15:12 --------- d-----w C:\Documents and Settings\bayern\Application Data\U3
2008-10-02 11:03 --------- d-----w C:\Program Files\Realtek
2008-09-30 05:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-09-30 05:21 --------- d-----w C:\Program Files\Nokia
2008-09-30 05:21 --------- d-----w C:\Program Files\Common Files\Nokia
2008-09-29 18:52 --------- d-----w C:\Documents and Settings\bayern\Application Data\Nokia
2008-09-29 18:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-09-26 20:20 --------- d-----w C:\Program Files\Intel
2008-09-21 10:01 --------- d-----w C:\Program Files\Microsoft Works
2008-09-19 18:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-19 13:27 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-18 22:35 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-09-18 19:02 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-18 18:57 --------- d-----w C:\Program Files\MSXML 4.0
2008-09-18 18:27 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-18 18:20 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-18 18:16 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-09-18 18:16 --------- d-----w C:\Documents and Settings\bayern\Application Data\PC Suite
2008-09-18 18:15 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-09-18 18:15 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-09-18 18:15 --------- d-----w C:\Program Files\Kaspersky Lab
2008-09-18 18:08 --------- d-----w C:\Program Files\DIFX
2008-08-23 03:47 86,523 ----a-w C:\WINDOWS\WinVerCheck.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
2008-08-21 15:15 94736 --a------ C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper s\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
2008-09-02 21:13 953360 --a------ C:\Program Files\Windows Live\Toolbar\wltcore.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{21FA44EF-376D-4D53-9B0F-8A89D3229068}"= "C:\Program Files\Windows Live\Toolbar\wltcore.dll" [2008-09-02 953360]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{21FA44EF-376D-4D53-9B0F-8A89D3229068}"= "C:\Program Files\Windows Live\Toolbar\wltcore.dll" [2008-09-02 953360]
[HKEY_CLASSES_ROOT\clsid\{21fa44ef-376d-4d53-9b0f-8a89d3229068}]
[HKEY_CLASSES_ROOT\TypeLib\{182E05A4-F4FF-4F73-8C84-D36B87D915AF}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-22 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-07-15 931248]
"ares ultra"="C:\Program Files\Ares Ultra\Ares Ultra.exe" [2007-05-23 2831360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2008-09-09 3513344]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Privacy Suite"="C:\Documents and Settings\bayern\Application Data\cleaner\CSPSeraser.exe" [2007-11-20 872080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" [2007-11-03 6731312]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2008-02-28 137752]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-04 36352]
"NortonAntiBot"="C:\Program Files\Symantec\Norton AntiBot\agent\bin\NortonAntiBot.exe" [2007-11-12 1378840]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-10-02 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-07-29 206088]
"SkyTel"="SkyTel.EXE" [2007-03-13 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-13 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
§ک ں颬نïé ںé«©ïم é• Microsoft Office OneNote 2003.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 64864]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ICQ"="C:\Program Files\ICQ6\ICQ.exe" silent
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"Uniblue RegistryBooster 2009"=C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
"ares ultra"="C:\Program Files\Ares Ultra\Ares Ultra.exe" -h
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
"googletalk"=C:\Program Files\Google\Google Talk\googletalk.exe /autostart
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\Ares Ultra\\Ares Ultra.exe"=
"C:\\WINDOWS\\system32\\ftp.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Java\\jre1.6.0_07\\launch4j-tmp\\JDownloader.exe"=
"C:\\WINDOWS\\system32\\java.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\IEPro\\MiniDM.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP

eer Name Resolution Protocol (PNRP)
"22011:TCP"= 22011:TCP:BitComet 22011 TCP
"22011:UDP"= 22011:UDP:BitComet 22011 UDP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R1 is-Q0AULdrv;is-Q0AULdrv;C:\WINDOWS\system32\DRIVERS\48321128.sys [2008-07-08 148496]
R2 ICQ Service;ICQ Service;C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2008-06-10 222456]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 24592]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2008-02-20 30816]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-09-19 354560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
s of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\bayern\Application Data\Mozilla\Firefox\Profiles\5kiocnvc.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
FF -: plugin - C:\Documents and Settings\bayern\Local Settings\Application Data\Google\Update\1.2.131.11\npGoogleOneClick5.dll
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-03 02:09:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Documents and Settings\bayern\Local Settings\Application Data\Ares Ultra\Data\PHashIdxTemp.dat 2782 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Symantec\Norton AntiBot\agent\Bin\NABAgent.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\AstSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec\Norton AntiBot\agent\Bin\NABMonitor.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\snmp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Symantec\Norton AntiBot\agent\Bin\NABWatcher.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Real\RealPlayer\realplay.exe
C:\Program Files\Winamp\winamp.exe
.
**************************************************************************
.
Completion time: 2008-10-03 2:19:59 - machine was rebooted [bayern]
ComboFix-quarantined-files.txt 2008-10-03 00:19:40
Pre-Run: 10,503,098,368 bytes free
Post-Run: 10,426,765,312 bytes free
330