heres my combo fix log my new hijack log will come in my next post
ComboFix 08-06-20.4 - Sam 2008-06-25 13:02:35.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.932.81.1033.18.262 [GMT -7:00]
Running from: C:\Documents and Settings\Sam\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Sam\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMb307f0f4.xml
C:\WINDOWS\pskt.ini
.
((((((((((((((((((((((((( Files Created from 2008-05-25 to 2008-06-25 )))))))))))))))))))))))))))))))
.
2008-06-24 17:32 . 2008-06-24 17:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-23 23:40 . 2008-06-23 23:40 105,984 --a------ C:\WINDOWS\system32\clarggvp.dll
2008-06-23 23:37 . 2008-06-25 12:43 1,729,026 ---hs---- C:\WINDOWS\system32\cnhhimds.ini
2008-06-23 23:37 . 2008-06-23 23:37 81,408 --a------ C:\WINDOWS\system32\sdmihhnc.dll
2008-06-23 23:34 . 2008-06-23 23:34 91,136 --a------ C:\WINDOWS\system32\rknxxfqn.dll
2008-06-23 23:15 . 2008-06-23 23:15 3,800 --a------ C:\WINDOWS\system32\PerfStringBackup.TMP
2008-06-23 23:04 . 2004-08-04 00:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-06-23 23:02 . 2004-08-04 00:56 96,768 -----c--- C:\WINDOWS\system32\dllcache\dpcdll.dll
2008-06-23 22:56 . 2004-08-04 00:56 2,897,920 --a------ C:\WINDOWS\system32\xpsp2res.dll
2008-06-23 22:54 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\
003412_.tmp
2008-06-23 22:54 . 2004-08-03 22:42 15,872 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-06-23 22:50 . 2008-06-23 22:50 <DIR> d-------- C:\WINDOWS\EHome
2008-06-23 22:41 . 2006-06-27 05:40 12,800 -----c--- C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-06-23 22:41 . 2006-06-27 05:40 3,584 -----c--- C:\WINDOWS\system32\dllcache\WgaLogon.dll
2008-06-23 22:07 . 2008-06-23 22:07 <DIR> d-------- C:\b124b638206a6da228fc
2008-06-23 16:19 . 2008-06-23 16:19 321,536 --a------ C:\WINDOWS\system32\khfCUNHW.dll_old
2008-06-20 12:31 . 2008-06-23 22:00 <DIR> d-------- C:\Perfect World
2008-06-19 21:05 . 2008-06-19 21:05 19,367 --a------ C:\WINDOWS\system32\wbers.dat.dmp
2008-06-17 19:30 . 2008-06-17 19:30 <DIR> d-------- C:\WINDOWS\Logs
2008-06-17 18:59 . 2008-06-17 18:59 <DIR> d-------- C:\WINDOWS\provisioning
2008-06-17 18:59 . 2004-08-03 22:59 423,936 --a------ C:\WINDOWS\system32\html.iec
2008-06-17 18:59 . 2004-07-17 11:35 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2008-06-17 18:59 . 2004-07-17 11:48 66,082 --a------ C:\WINDOWS\system32\c_28603.nls
2008-06-17 18:59 . 2004-07-17 11:36 64,352 --------- C:\WINDOWS\system32\drivers\ativmc20.cod
2008-06-17 18:56 . 2008-06-17 18:56 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-06-17 18:51 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\
002606_.tmp
2008-06-17 17:54 . 2008-06-17 17:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-06-16 21:02 . 2008-03-30 06:06 332,672 --a------ C:\WINDOWS\system32\wgatray.exe.bak
2008-06-16 21:02 . 2008-03-30 06:06 200,064 --a------ C:\WINDOWS\system32\wgalogon.dll.bak
2008-06-16 21:02 . 2008-06-16 22:01 41,984 --a------ C:\WINDOWS\mrofinu1044.exe
2008-06-14 21:03 . 1999-04-09 02:14 416,304 --a------ C:\WINDOWS\system32\MPG4C32.DLL
2008-06-14 21:02 . 2008-06-14 21:02 <DIR> d-------- C:\Program Files\ValuSoft
2008-06-11 20:50 . 2008-06-11 20:50 <DIR> d-------- C:\Program Files\KCP
2008-06-11 20:49 . 2008-06-11 20:49 76,431 --a------ C:\WINDOWS\system32\npkcmsvc.exe
2008-06-11 20:45 . 2008-06-11 20:45 <DIR> d-------- C:\WINDOWS\kdefense
2008-06-11 20:45 . 2008-06-11 20:45 766,816 --a------ C:\WINDOWS\system32\kdfinj.dll
2008-06-11 20:45 . 2008-06-11 20:45 640,352 --a------ C:\WINDOWS\system32\kdfmgr.exe
2008-06-11 20:45 . 2008-06-11 20:45 213,075 --a------ C:\WINDOWS\system32\kdfmod.dll
2008-06-11 20:45 . 2008-06-11 20:45 192,512 --a------ C:\WINDOWS\system32\kdfvmgr.exe
2008-06-11 20:45 . 2008-06-11 20:45 77,824 --a------ C:\WINDOWS\system32\kdfapi.dll
2008-06-11 20:45 . 2008-06-11 20:45 53,248 --a------ C:\WINDOWS\system32\Kdfhok.dll
2008-06-11 20:19 . 2008-06-11 20:19 <DIR> d-------- C:\Program Files\GameSpy Arcade
2008-06-11 20:17 . 2008-06-11 20:17 <DIR> d-------- C:\Program Files\Microsoft Games
2008-06-02 22:19 . 2008-06-02 22:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-02 21:35 . 2001-08-23 05:00 21,504 --a------ C:\WINDOWS\system32\wsock32.dlb
2008-06-02 21:34 . 2008-06-02 21:34 <DIR> d-------- C:\Program Files\Comodo
2008-06-02 21:34 . 2008-06-12 16:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BOC426
2008-06-02 21:34 . 2008-03-28 09:17 212,728 --a------ C:\WINDOWS\CMDLIC.DLL
2008-06-02 21:34 . 2008-03-28 09:16 205,560 --a------ C:\WINDOWS\UNBOC.EXE
2008-06-02 21:34 . 2008-06-25 12:39 9,396 --a------ C:\WINDOWS\BOC426.INI
2008-06-02 21:22 . 2008-06-02 21:22 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-02 21:22 . 2008-06-03 07:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-02 21:01 . 2008-06-03 07:01 90,838 --a------ C:\WINDOWS\system32\phcct2j0e94p.bmp
2008-06-02 21:01 . 2008-06-03 07:01 52,736 --a------ C:\WINDOWS\system32\blphcct2j0e94p.scr
2008-05-31 20:54 . 2008-06-23 23:14 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\Hamachi
2008-05-31 20:49 . 2008-05-31 20:50 <DIR> d-------- C:\Program Files\Hamachi
2008-05-31 20:49 . 2008-05-31 20:49 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2008-05-28 16:35 . 2008-05-28 16:35 <DIR> d-------- C:\Program Files\GAMENAO
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-06-25 19:26 --------- d-----w C:\Documents and Settings\Sam\Application Data\Def
2008-06-24 06:22 --------- d-----w C:\Program Files\Lx_cats
2008-06-24 06:09 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd9485.sys
2008-06-24 05:07 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-06-24 05:07 --------- d-----w C:\Documents and Settings\Sam\Application Data\uTorrent
2008-06-24 05:07 --------- d-----w C:\Documents and Settings\Sam\Application Data\SystemRequirementsLab
2008-06-24 04:41 --------- d-----w C:\Program Files\Steam
2008-06-22 05:29 --------- d-----w C:\Program Files\Warcraft III
2008-06-17 03:27 --------- d-----w C:\Documents and Settings\Sam\Application Data\DivX
2008-06-16 04:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-13 01:13 --------- d-----w C:\Program Files\mIRC
2008-06-12 21:32 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-03 05:20 --------- d-----w C:\Program Files\Lavasoft
2008-06-03 05:20 --------- d-----w C:\Documents and Settings\Sam\Application Data\Lavasoft
2008-06-03 05:16 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-22 22:10 --------- d-----w C:\Program Files\softnyx
2008-05-22 21:55 --------- d-----w C:\Program Files\DAP
2008-05-20 04:08 --------- d--h--w C:\Documents and Settings\Sam\Application Data\ijjigame
2008-05-16 18:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-15 04:45 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll
2008-05-14 23:51 --------- d-----w C:\Program Files\RivaTuner v2.09
2008-05-04 23:55 --------- d-----w C:\Documents and Settings\Sam\Application Data\Skype
2008-05-04 16:45 --------- d-----w C:\Program Files\ARES
2008-05-01 00:27 442,368 -c--a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-04-29 18:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 18:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 18:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-29 04:56 --------- d-----w C:\Program Files\uTorrent
2008-04-28 22:50 57,344 ----a-w C:\cc.exe
2008-04-28 22:50 24,576 ----a-w C:\cn.exe
2008-04-28 00:26 --------- d-----w C:\Program Files\AIM6
2008-04-28 00:26 --------- d-----w C:\Program Files\AIM Search
2008-04-28 00:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-04-28 00:25 --------- d-----w C:\Program Files\Common Files\AOL
2008-04-27 07:00 --------- d-----w C:\Documents and Settings\Sam\Application Data\InstallShield
2008-04-25 01:48 --------- d-----w C:\Program Files\Neffy
1997-06-02 12:17 8,192 -c--a-w C:\Program Files\_ISDEL.EXE
2006-05-17 03:00 56 -csha-r C:\WINDOWS\Copy of system32\CB00905B7F.sys
2006-05-17 03:00 56 -csha-r C:\WINDOWS\system32\CB00905B7F.sys
2006-05-17 03:00 1,890 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a23f6cfe-450a-4de6-81b0-d2e1253a0ecb}]
2008-06-23 23:40 105984 --a------ C:\WINDOWS\system32\clarggvp.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunOnce]
"FlashPlayerUpdate"="C:\WINDOWS\System32\Macromed\ Flash\NPSWF32_FlashUtil.exe" [2007-06-11 13:34 190696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"BOC-426"="C:\PROGRA~1\Comodo\CBOClean\BOC426.exe" [2008-04-10 11:08 351480]
"LXCICATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X 86\3\LXCItime.dll" [2005-09-08 11:44 73728]
"lphcct2j0e94p"="C:\WINDOWS\System32\lphcct2j0e94p .exe" [ ]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2008-05-02 22:46 13529088]
"b034c368"="C:\WINDOWS\system32\sdmihhnc.dll" [2008-06-23 23:37 81408]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\M SConfig.exe" [2004-08-04 00:56 158208]
"RegistryMechanic"="C:\Program Files\Registry Mechanic\RegMech.exe" [2007-08-20 10:58 2483496]
"BMb307f0f4"="C:\WINDOWS\system32\rknxxfqn.dll " [2008-06-23 23:34 91136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=clarggvp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Sam^Start Menu^Programs^Startup^hamachi.lnk]
path=C:\Documents and Settings\Sam\Start Menu\Programs\Startup\hamachi.lnk
backup=C:\WINDOWS\pss\hamachi.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Sam^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\Sam\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Sam^Start Menu^Programs^Startup^YouTube Uploader.lnk]
path=C:\Documents and Settings\Sam\Start Menu\Programs\Startup\YouTube Uploader.lnk
backup=C:\WINDOWS\pss\YouTube Uploader.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a--c--- 2005-06-06 23:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2008-03-25 13:21 50528 C:\Program Files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIMPro]
C:\Program Files\AIM\AIM Pro\aimpro.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a--c--- 2004-09-07 14:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
C:\Program Files\ARES\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atomowns]
C:\DOCUME~1\Sam\APPLIC~1\PINGPA~1\axisdumb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 00:56 15360 C:\WINDOWS\System32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
--a------ 2005-08-01 05:05 94208 C:\Program Files\Lexmark 7300 Series\ezprint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F5D9050]
--a--c--- 2006-03-14 16:52 1585152 C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-03-18 21:49 51184 C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Update\1.1.25.0\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-05-12 00:12 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\I downloaded pirated Software from P2P ]
C:\WINDOWS\System32\
0106.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-03 22:32 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
--a------ 2006-09-10 22:56 218032 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2006-09-10 22:56 218032 c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2006-09-10 22:56 86960 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a--c--- 2007-11-15 14:11 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcimon.exe]
--a--c--- 2005-09-30 07:47 200704 C:\Program Files\Lexmark 7300 Series\lxcimon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 00:56 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
--a------ 2004-08-03 22:31 59392 C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-05-02 22:46 13529088 C:\WINDOWS\System32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-05-02 22:46 86016 C:\WINDOWS\System32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-03 22:32 455168 C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-03 22:32 455168 C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
--------- 2006-04-26 11:42 2490368 C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2007-11-15 00:43 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RAMBooster.Net]
C:\Program Files\RAMBooster.Net\RAMBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2006-11-17 05:42 577536 C:\WINDOWS\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-03-27 15:30 1271032 c:\program files\steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue Registry Booster2]
C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra--c--- 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VideoraiPodConverter]
--a--c--- 2006-02-11 07:23 483328 C:\Program Files\VideoraiPodConverter\VideoraiPodConverter.ex e
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
--a------ 2004-10-22 11:53 53248 C:\WINDOWS\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinSoftwareDvdCool]
C:\Documents and Settings\All Users\Application Data\Enc Cash Win Software\Date owns.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"VideoAcceleratorService"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"C:\Nexon\Combat Arms\CombatArms.exe"= C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Nexon\Combat Arms\Engine.exe"= C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"%windir%\\system32\\sessmgr.exe"=
R2 npkcmsvc;npkcmsvc;C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 13:33]
R2 sbbotdi;sbbotdi;C:\PROGRA~1\SpeedBit Video Accelerator\sbbotdi.sys [2008-04-14 20:44]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]
R3 StreamSurge;StreamSurge Driver (miniport);C:\WINDOWS\system32\DRIVERS\ss.sys [2005-06-18 02:48]
S3 ati2mpaa;ati2mpaa;C:\WINDOWS\system32\DRIVERS\ati2 mpaa.sys [2001-08-17 13:48]
S3 cheetah1;cheetah1;C:\Documents and Settings\Sam\Desktop\g cheetah\Pidis Hack pack\cheetahengine\cheetah.sys []
S3 Dua1

ua1;C:\DOCUME~1\Sam\LOCALS~1\Temp\Rar$EX00.7 51\DualEngine2\DualEngi.sys []
S3 gamecheetah1;gamecheetah1;C:\Documents and Settings\Maple\Desktop\cheetah engine\gamecheetah\gamecheetah.sys []
S3 geebers12;geebers12;C:\Documents and Settings\Sam\Desktop\Blorb\blorbslayerengine\nvid8 88.sys []
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;C:\Documents and Settings\Sam\Desktop\engine\IlvMoney1148.sys []
S3 knapizz;knapizz;C:\WINDOWS\knapiz.sys []
S3 lxci_device;lxci_device;C:\WINDOWS\System32\lxcico ms.exe [2005-10-24 05:33]
S3 saruen;saruen;C:\Documents and Settings\Sam\Desktop\SaruenGang\saruen.sys []
S3 sejt1;sejt1;C:\Documents and Settings\Maple\Desktop\AkumaEngine33\AkumaEngine33 \sejt.sys []
S3 XDva026;XDva026;C:\WINDOWS\System32\XDva026.sys []
S3 XDva028;XDva028;C:\WINDOWS\System32\XDva028.sys []
S3 XDva037;XDva037;C:\WINDOWS\System32\XDva037.sys []
S3 XDva076;XDva076;C:\WINDOWS\System32\XDva076.sys []
S3 XDva121;XDva121;C:\WINDOWS\System32\XDva121.sys []
S3 XDva164;XDva164;C:\WINDOWS\System32\XDva164.sys []
S3 zenx1;zenx1;C:\DOCUME~1\Sam\LOCALS~1\Temp\Rar$EX00 .734\ZenxEngine_LATEST\zenx.sys []
S4 VideoAcceleratorService;VideoAcceleratorService;C: \PROGRA~1\SpeedBit Video Accelerator\VideoAcceleratorService.exe [2008-04-14 20:44]
*Newly Created Service* - SHAREDACCESS
.
Contents of the 'Scheduled Tasks' folder
"2008-06-25 20:00:00 C:\WINDOWS\Tasks\ADAAC77095B97C70.job"
- c:\docume~1\sam\applic~1\pingpa~1\Dentbuildabout.e xe
"2008-06-24 23:01:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-25 13:04:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-06-25 13:06:36
ComboFix-quarantined-files.txt 2008-06-25 20:06:26
ComboFix2.txt 2008-06-25 19:43:45
Pre-Run: 60,193,939,456 bytes free
Post-Run: 60,181,798,912 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Professional" /fastdetect /NoExecute=OptIn
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Micro soft Windows XP Home Edition" /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
294 --- E O F --- 2008-06-24 05:29:42