ComboFix 08-05-25.5 - lisa 2008-05-26 20:59:44.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.772 [GMT -4:00]
Running from: C:\Documents and Settings\lisa\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\lisa\Application Data\inst.exe
C:\WINDOWS\setup.exe
C:\WINDOWS\system32\bszip.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-27 to 2008-05-27 )))))))))))))))))))))))))))))))
.
2008-05-24 21:05 . 2008-05-24 21:05 <DIR> d-------- C:\Documents and Settings\lisa\Application Data\Grisoft
2008-05-24 21:04 . 2007-05-30 08:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-05-24 14:45 . 2008-05-24 14:45 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-24 14:45 . 2008-05-24 14:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-24 12:22 . 2008-05-24 12:22 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-24 12:06 . 2008-05-24 19:54 <DIR> d-------- C:\Program Files\Eusing Free Registry Cleaner
2008-05-21 18:42 . 2008-05-24 19:56 <DIR> d-------- C:\WINDOWS\Motive
2008-05-21 18:37 . 2008-05-24 19:56 <DIR> d-------- C:\Program Files\EMBARQ
2008-05-20 22:34 . 2008-05-20 22:35 <DIR> d-------- C:\Program Files\Satellite TV for PC
2008-05-15 07:38 . 2008-05-15 07:38 <DIR> d-------- C:\Program Files\WinTabber
2008-05-05 19:10 . 2008-05-05 19:10 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-05 19:10 . 2008-05-05 19:10 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-04 19:06 . 2008-05-04 19:06 <DIR> d-------- C:\Program Files\SmartSound Software
2008-05-04 19:06 . 2008-05-04 19:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2008-05-04 19:00 . 2004-03-10 16:26 406,016 --a------ C:\WINDOWS\system32\PSDrvCheck.exe
2008-05-04 18:59 . 2003-11-21 16:48 65,536 --a------ C:\WINDOWS\system32\MFC71DEU.DLL
2008-05-04 18:57 . 2008-05-04 19:00 <DIR> d-------- C:\Program Files\Pinnacle
2008-05-04 18:57 . 2002-03-19 09:29 14,165 --------- C:\WINDOWS\system32\drivers\Pclepci.sys
2008-05-04 13:29 . 2008-05-04 16:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2008-04-30 07:18 . 2008-04-30 07:19 <DIR> dr------- C:\Program Files\TypingMaster
2008-04-30 07:18 . 2008-04-30 19:38 <DIR> d-------- C:\Documents and Settings\lisa\Application Data\TypingMaster7
2008-04-27 22:03 . 2008-04-27 22:04 <DIR> d-------- C:\Program Files\BitLord2
2008-04-27 22:02 . 2008-04-27 22:02 <DIR> d-------- C:\Documents and Settings\lisa\Application Data\vlc
2008-04-27 21:59 . 2008-04-27 21:59 <DIR> d-------- C:\Program Files\VideoLAN
2008-04-27 21:42 . 2008-04-27 21:42 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-04-27 21:40 . 2008-04-27 21:40 <DIR> d-------- C:\WINDOWS\system32\RTCOM
2008-04-27 21:29 . 2008-04-27 21:29 <DIR> d-------- C:\Program Files\MSBuild
2008-04-27 21:26 . 2008-04-27 21:45 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-04-27 21:25 . 2008-04-27 21:25 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-04-27 21:24 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-04-27 21:19 . 2008-04-27 21:19 <DIR> d-------- C:\Program Files\Managed DirectX (0901)
2008-04-27 21:18 . 2006-11-13 02:02 288,768 --------- C:\WINDOWS\system32\rhttpaa.dll
2008-04-27 21:18 . 2006-11-13 02:02 116,736 --------- C:\WINDOWS\system32\aaclient.dll
2008-04-27 21:18 . 2006-11-13 02:02 36,352 --------- C:\WINDOWS\system32\tsgqec.dll
2008-04-27 20:54 . 2006-03-20 23:23 23,040 --------- C:\WINDOWS\kb913800.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-05-25 01:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-05-24 23:56 --------- d-----w C:\Program Files\Motive
2008-05-24 23:56 --------- d-----w C:\Program Files\Common Files\Motive
2008-05-24 23:56 --------- d-----w C:\Program Files\Amazon
2008-05-24 23:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-05-24 17:50 --------- d-----w C:\Documents and Settings\lisa\Application Data\U3
2008-05-23 11:29 --------- d-----w C:\Program Files\PeerGuardian2
2008-05-21 22:40 155,995 ----a-w C:\WINDOWS\java\Packages\DFJ7Z31B.ZIP
2008-05-21 22:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Motive
2008-05-21 11:38 --------- d-----w C:\Program Files\Winamp
2008-05-21 02:33 --------- d-----w C:\Documents and Settings\lisa\Application Data\AVG7
2008-05-16 01:48 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-16 01:46 --------- d-----w C:\Documents and Settings\lisa\Application Data\AdobeUM
2008-05-12 22:37 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Sony Corporation
2008-05-11 17:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-05-04 23:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Pinnacle
2008-05-04 23:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-04 15:38 --------- d-----w C:\Documents and Settings\lisa\Application Data\Vso
2008-04-29 01:03 --------- d-----w C:\Program Files\BitLord
2008-04-25 01:54 --------- d-----w C:\Documents and Settings\lisa\Application Data\Poser 7
2008-04-24 22:01 --------- d-----w C:\Program Files\e frontier
2008-04-20 16:30 --------- d-----w C:\Documents and Settings\lisa\Application Data\RipIt4Me
2008-04-16 23:15 --------- d-----w C:\Program Files\Real Alternative
2008-04-16 22:40 --------- d-----w C:\Program Files\Massive
2008-04-16 21:43 --------- d-----w C:\Program Files\massive_mhost
2008-04-16 15:42 --------- d-----w C:\Documents and Settings\lisa\Application Data\LimeWire
2008-04-02 12:43 --------- d-----w C:\Program Files\Drive Doppler
2008-04-02 12:18 --------- d-----w C:\Documents and Settings\lisa\Application Data\Lionhead Studios
2008-03-16 19:00 47,360 ----a-w C:\Documents and Settings\lisa\Application Data\pcouffin.sys
2007-09-25 15:01 232,192 ----a-w C:\Documents and Settings\lisa\Application Data\GDIPFONTCACHEV1.DAT
2007-03-17 22:21 593,920 ----a-w C:\Program Files\RipIt4Me.exe
2007-03-14 22:53 12,283 ----a-w C:\Program Files\uninstal.log
.
------- Sigcheck -------
md5deep: C:\WINDOWS\system32\svchost.exe: Permission denied
2005-03-02 14:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 11:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2007-03-08 11:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\dllcache\user32.dll
2004-08-10 08:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll
2004-08-10 08:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\dllcache\ws2_32.dll
2005-05-02 16:57 658944 e1e18136f9dd3df1ad9c82193a5898a6 C:\WINDOWS\$hf_mig$\KB883939\SP2QFE\wininet.dll
2005-03-10 03:43 657920 c8663b488996e89a84c3d17c1d12b79e C:\WINDOWS\$hf_mig$\KB890923\SP2QFE\wininet.dll
2005-09-02 19:53 660480 97a6fd7cafd688cf2c78939ebaf0cd0c C:\WINDOWS\$hf_mig$\KB896688\SP2QFE\wininet.dll
2005-07-02 22:09 659456 6e533d155b259eb2363d3e04b5be309f C:\WINDOWS\$hf_mig$\KB896727\SP2QFE\wininet.dll
2005-10-20 23:38 661504 af785c4947676a7fc1673fdc5c8d0b5b C:\WINDOWS\$hf_mig$\KB905915\SP2QFE\wininet.dll
2006-03-03 23:58 663552 c0845ecbf4f9164e618ee381b79c9032 C:\WINDOWS\$hf_mig$\KB912812\SP2QFE\wininet.dll
2006-05-10 01:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc C:\WINDOWS\$hf_mig$\KB916281\SP2QFE\wininet.dll
2006-06-23 07:25 664576 64ce26db72810b30f7855ea51e1df836 C:\WINDOWS\$hf_mig$\KB918899\SP2QFE\wininet.dll
2006-06-23 07:25 664576 64ce26db72810b30f7855ea51e1df836 C:\WINDOWS\ie7\wininet.dll
2006-08-23 00:31 809472 02b4473e3c5fede0d3573ce297e8504a C:\WINDOWS\system32\wininet.dll
2006-08-23 00:31 809472 02b4473e3c5fede0d3573ce297e8504a C:\WINDOWS\system32\dllcache\wininet.dll
2005-05-25 15:07 359936 63fdfea54eb53de2d863ee454937ce1e C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2006-01-13 13:07 360448 5562cc0a47b2aef06d3417b733f3c195 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
2006-04-20 08:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 12:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2007-10-30 13:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 13:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\system32\drivers\tcpip.sys
2004-08-10 08:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe
2004-08-10 08:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\dllcache\winlogon.exe
2004-08-10 08:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\dllcache\ndis.sys
2004-08-10 08:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys
2004-08-10 08:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\dllcache\ip6fw.sys
2004-08-10 08:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
2005-03-01 20:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 12:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 05:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2007-02-28 04:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2007-02-28 04:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\SoftwareDistribution\Download\10e16e65c 532d077de7c89a212bd8df8\sp2gdr\ntkrnlpa.exe
2007-02-28 05:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\SoftwareDistribution\Download\10e16e65c 532d077de7c89a212bd8df8\sp2qfe\ntkrnlpa.exe
2007-02-28 04:38 2015744 a58ac1c6199ef34228abee7fc057ae09 C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 04:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2005-03-01 21:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 12:51 2182016 cef243f6defd20be4adde26c7ecacb54 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 05:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2007-02-28 05:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2007-02-28 05:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\SoftwareDistribution\Download\10e16e65c 532d077de7c89a212bd8df8\sp2gdr\ntoskrnl.exe
2007-02-28 05:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\SoftwareDistribution\Download\10e16e65c 532d077de7c89a212bd8df8\sp2qfe\ntoskrnl.exe
2007-02-28 05:08 2136064 1220faf071dea8653ee21de7dcda8bfd C:\WINDOWS\system32\ntoskrnl.exe
2007-02-28 05:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2007-06-13 06:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\explorer.exe
2007-06-13 07:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 06:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\system32\dllcache\explorer.exe
2004-08-10 08:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\services.exe
2004-08-10 08:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\dllcache\services.exe
2004-08-10 08:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\lsass.exe
2004-08-10 08:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\dllcache\lsass.exe
2004-08-10 08:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\ctfmon.exe
2004-08-10 08:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF )))))))))))))))))))))))))))))))))))))))))))))))))) ))))))))
.
----a-w 344,064 2004-09-29 11:15:00 C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
----a-w 579,072 2007-12-22 10:23:55 C:\Program Files\Grisoft\AVG7\bak\avgcc.exe
----a-w 135,168 2004-03-23 19:16:16 C:\Program Files\Intel\Intel Application Accelerator\bak\iaanotif.exe
----a-w 45,056 2003-08-22 13:22:28 C:\Program Files\Sony\sHotKey\bak\sHotKey.exe
----a-w 315,392 2005-01-14 20:19:32 C:\Program Files\Sony\VAIO Media Integrated Server\Platform\bak\VMConsole.exe
----a-w 86,016 2004-09-05 18:01:51 C:\Program Files\Startup Mechanic\bak\StartupMonitor.exe
----a-w 64,512 2005-08-05 18:56:34 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 64,512 2005-08-05 18:56:34 C:\WINDOWS\ehome\ehtray.exe
----a-w 28,672 2003-04-20 05:08:44 C:\WINDOWS\SONYSYS\VAIO Recovery\bak\PartSeal.exe
----a-w 311,296 2003-01-30 22:55:46 C:\WINDOWS\system32\bak\hphmon03.exe
----a-w 196,608 2003-01-30 22:55:46 C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\hpz tsb04.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40 1421824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 14:56 64512]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 18:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-09-21 10:24 86016 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-09-21 15:32 2807808 C:\WINDOWS\ALCWZRD.EXE]
"rthdcpl"="RTHDCPL.EXE" [2005-09-22 13:36 14854144 C:\WINDOWS\RTHDCPL.EXE]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCh eck.exe" [2004-03-10 16:26 406016]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-20 22:54 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= vdrcodec.dll
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EMBARQ Help.lnk]
backup=C:\WINDOWS\pss\EMBARQ Help.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Suitcase 11.0.lnk]
backup=C:\WINDOWS\pss\Suitcase 11.0.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^lisa^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2006-06-05 10:06 188416 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-04-27 09:41 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
--a------ 2002-04-11 04:19 69632 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-07-26 16:13 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 3]
--a------ 2007-05-15 20:46 551032 C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 18:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ColdFusion Management Service"=2 (0x2)
"ColdFusion Management Repository"=2 (0x2)
"ColdFusion Graphing Server"=2 (0x2)
"Cold Fusion RDS"=2 (0x2)
"Cold Fusion Executive"=2 (0x2)
"Cold Fusion Application Server"=2 (0x2)
"ClusterCATS Service"=2 (0x2)
"RDSessMgr"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Macromedia Licensing Service"=3 (0x3)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"AdobeActiveFileMonitor5.0"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Sony\\VAIO Media 4.0\\Vc.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Sony\\Click to DVD 2\\CtoDvd.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Adobe\\Photoshop Elements 5.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
"C:\\Program Files\\Extensis\\Extensis Suitcase 11\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\e frontier\\Poser 7\\Poser.exe"=
"C:\\Program Files\\BitLord2\\BitLord.exe"=
"C:\\WINDOWS\\system32\\ftp.exe"=
R3 Belkin700F;Belkin Wireless G Desktop Card Service v7;C:\WINDOWS\system32\DRIVERS\BLKWGDv7.sys [2006-10-19 05:44]
S2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2005-08-31 15:13]
S2 McciCMService;McciCMService;"C:\Program Files\Common Files\Motive\McciCMService.exe" [2008-04-01 01:42]
S2 Mhost;Mhost;C:\Program Files\massive_mhost\mhost.exe [2007-08-31 18:58]
S2 SBKUPNT;SBKUPNT;C:\WINDOWS\system32\Drivers\SBKUPN T.SYS [2001-07-13 14:56]
S3 DCamUSBSvis;EVision MEGApro Stream Driver;C:\WINDOWS\system32\DRIVERS\svstream.sys [2002-04-09 12:43]
S3 DNINDIS5

NINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\DNINDIS5.SYS [2003-07-24 12:10]
S3 Dot4Usb HPH09

ot4Usb HPH09;C:\WINDOWS\system32\drivers\hphius09.sys [2003-01-30 18:55]
S3 jswmidin;jswmidin;C:\DOCUME~1\lisa\LOCALS~1\Temp\j swmidin.sys []
S3 Jukebox3_1394;Jukebox3_1394;C:\WINDOWS\system32\DR IVERS\ctpd1394.sys [2003-02-25 02:20]
S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2008-04-01 01:42]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2008-04-01 01:42]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 NETGEAR NETGEAR_MA101_USB_Adapter(R);NETGEAR NETGEAR_MA101_USB_Adapter(R) Service for NETGEAR MA101 USB Adapter;C:\WINDOWS\system32\DRIVERS\ma1012kr.sys []
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.s ys [2002-10-02 09:57]
*Newly Created Service* - PGFILTER
.
Contents of the 'Scheduled Tasks' folder
"2008-05-22 11:21:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-23 05:55:13 C:\WINDOWS\Tasks\User_Feed_Synchronization-{52352EA1-1DE8-4E19-9448-457073112019}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-26 21:04:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Extensis\Extensis Suitcase 11\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Intel Application Accelerator\IAANTmon.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
C:\Program Files\Belkin\PCI F5D700F\Wireless Utility\Belkinwcui.exe
.
************************************************** ************************
.
Completion time: 2008-05-26 21:14:11 - machine was rebooted [lisa]
ComboFix-quarantined-files.txt 2008-05-27 01:14:09
Pre-Run: 209,223,475,200 bytes free
Post-Run: 209,119,240,192 bytes free
302 --- E O F --- 2007-10-27 14:49:54