Finally, I get a log, took so bloody long trying to get this, Combo was freezing/computer was shutting down as it started and as it was finishing, enver thought i'd get the thing, here ya go, hopefully it's done everythin right with the constant interuptions ^^
ComboFix 08-07-11.1 - Dave 2008-07-12 10:04:40.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.223 [GMT 1:00]
Running from: C:\Documents and Settings\Dave\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Program Files\Common Files\{DCFCD~1
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\rqstv.bak2
.
((((((((((((((((((((((((( Files Created from 2008-06-12 to 2008-07-12 )))))))))))))))))))))))))))))))
.
2008-07-11 10:11 . 2008-07-11 10:11 <DIR> d-------- C:\Deckard
2008-07-10 15:52 . 2008-07-10 15:52 165 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
2008-07-10 14:15 . 2008-07-10 14:15 <DIR> d-------- C:\Program Files\Innovative Solutions
2008-06-30 19:37 . 2006-09-26 13:57 28,672 --a------ C:\WINDOWS\system32\AVEQT.dll
2008-06-30 16:45 . 2008-06-30 16:45 <DIR> d-------- C:\Program Files\Octoshape Streaming Services
2008-06-29 17:18 . 2008-06-29 17:45 21,840 --a----t- C:\WINDOWS\system32\SIntfNT.dll
2008-06-29 17:18 . 2008-06-29 17:45 17,212 --a----t- C:\WINDOWS\system32\SIntf32.dll
2008-06-29 17:18 . 2008-06-29 17:45 12,067 --a----t- C:\WINDOWS\system32\SIntf16.dll
2008-06-29 15:20 . 2008-06-29 15:20 94,208 --a------ C:\WINDOWS\DIIUnin.exe
2008-06-29 15:20 . 2008-06-29 18:03 18,167 --a------ C:\WINDOWS\DIIUnin.dat
2008-06-29 15:20 . 2008-06-29 15:20 2,829 --a------ C:\WINDOWS\DIIUnin.pif
2008-06-29 15:08 . 2008-07-03 16:05 <DIR> d-------- C:\Program Files\Diablo II
2008-06-27 18:06 . 2008-06-27 18:06 <DIR> d-------- C:\Program Files\Opera
2008-06-25 09:04 . 2008-06-25 09:04 268 --ah----- C:\sqmdata05.sqm
2008-06-25 09:04 . 2008-06-25 09:04 244 --ah----- C:\sqmnoopt05.sqm
2008-06-22 11:21 . 2008-06-22 11:21 2,320,000 --a------ C:\WINDOWS\system32\TUKernel.exe
2008-06-20 16:40 . 2008-06-20 16:40 <DIR> d-------- C:\Program Files\Lavalys
2008-06-19 18:20 . 2008-06-19 18:20 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-06-19 18:18 . 2008-06-19 18:20 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
2008-06-15 08:44 . 2008-06-15 08:45 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-06-15 08:44 . 2008-06-15 08:44 <DIR> d-------- C:\Documents and Settings\Dave\Application Data\SystemRequirementsLab
2008-06-15 08:33 . 2008-06-15 08:33 <DIR> d-------- C:\Documents and Settings\Dave\Application Data\SPORE Creature Creator
2008-06-15 08:21 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2008-06-15 08:19 . 2008-06-15 08:21 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2008-06-15 08:18 . 2008-06-15 08:18 <DIR> d-------- C:\WINDOWS\Logs
2008-06-15 08:13 . 2008-06-15 08:13 <DIR> d-------- C:\Program Files\Electronic Arts
2008-06-12 12:47 . 2008-06-12 12:47 <DIR> d-------- C:\Program Files\AutoHotkey
2008-06-12 12:43 . 2008-07-01 18:20 <DIR> d-------- C:\Program Files\Notepad++
2008-06-12 12:43 . 2008-06-12 12:45 <DIR> d-------- C:\Documents and Settings\Dave\Application Data\Notepad++
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-07-12 07:49 --------- d-----w C:\Program Files\Winamp
2008-07-12 07:40 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-07-11 07:07 --------- d-----w C:\Program Files\World of Warcraft
2008-06-30 18:37 --------- d-----w C:\Program Files\Ultra QuickTime Converter
2008-06-29 18:39 --------- d-----w C:\Documents and Settings\Dave\Application Data\FrostWire
2008-06-26 13:28 --------- d-----w C:\Program Files\Motive
2008-06-26 13:03 --------- d-----w C:\Program Files\Creative
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 17:18 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-19 16:36 --------- d-----w C:\Documents and Settings\Dave\Application Data\Azureus
2008-06-19 16:31 --------- d-----w C:\Program Files\TuneUp Utilities 2007
2008-06-18 19:31 --------- d-----w C:\Documents and Settings\Dave\Application Data\Free Download Manager
2008-06-15 07:33 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-06-15 07:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-09 09:06 --------- d-----w C:\Program Files\Last.fm
2008-06-04 08:25 --------- d-----w C:\Program Files\Zune
2008-06-04 08:13 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01007_C oinstaller_Critical.Wdf
2008-06-04 08:13 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_zumbus_010 07.Wdf
2008-05-30 13:19 507,400 ----a-w C:\WINDOWS\system32\XAudio2_1.dll
2008-05-30 13:18 238,088 ----a-w C:\WINDOWS\system32\xactengine3_1.dll
2008-05-30 13:17 65,032 ----a-w C:\WINDOWS\system32\XAPOFX1_0.dll
2008-05-30 13:17 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_4.dll
2008-05-30 13:11 467,984 ----a-w C:\WINDOWS\system32\d3dx10_38.dll
2008-05-30 13:11 3,850,760 ----a-w C:\WINDOWS\system32\D3DX9_38.dll
2008-05-30 13:11 1,491,992 ----a-w C:\WINDOWS\system32\D3DCompiler_38.dll
2008-05-25 19:01 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-05-25 18:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-25 18:57 --------- d-----w C:\Documents and Settings\Dave\Application Data\SUPERAntiSpyware.com
2008-05-25 18:49 --------- d-----w C:\Documents and Settings\Dave\Application Data\ICQ
2008-05-25 18:47 --------- d-----w C:\Program Files\Audiosurf
2008-05-16 15:13 --------- d-----w C:\Program Files\Steam
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-29 18:56 61,856 ----a-w C:\WINDOWS\system32\ZuneBusEnum.exe
2008-04-29 18:56 245,664 ----a-w C:\WINDOWS\system32\ZuneWlanCfgSvc.exe
2008-04-29 18:39 70,144 ----a-w C:\WINDOWS\system32\ZuneIpTransport.dll
2008-04-29 18:39 62,464 ----a-w C:\WINDOWS\system32\ZuneUsbTransport.dll
2008-04-29 18:39 35,328 ----a-w C:\WINDOWS\system32\ZuneUsbCOnnection.dll
2008-04-29 18:39 145,408 ----a-w C:\WINDOWS\system32\ZuneMTPZ.dll
2008-04-21 07:04 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-17 18:11 1,112,288 ----a-w C:\WINDOWS\system32\WdfCoInstaller01007.dll
2007-10-31 18:07 24,096 ----a-w C:\Documents and Settings\Dave\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23 102400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-02-12 16:57 188416]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-02-12 16:59 77824]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-14 10:00 267064]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-20 19:54 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41 45056]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 22:34 49152]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2008-04-29 19:56 158624]
"C-Media Mixer"="Mixer.exe" [2002-10-15 18:00 1818624 C:\WINDOWS\mixer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-07-04 10:31:06 113664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.mpegacm "= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\mpegacm.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2006-07-18 12:02]
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2003-03-27 14:55]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2006-07-18 12:02]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2006-02-28 13:00]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 19:39]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 19:56]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.ex e [2008-06-19 18:20]
S3 TunRDriverV32;TunRDriverV32;C:\WINDOWS\system32\dr ivers\TunRDriverV32.sys [2007-07-12 12:10]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 19:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2008-07-12 09:00:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-04-15 20:31:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Explorer_Run-{DCFCDA4D-07CF-1033-0307-03032603002c} - C:\Program Files\Common Files\{DCFCDA4D-07CF-1033-0307-03032603002c}\Update.exe
Notify-vtsqr - C:\WINDOWS\system32\vtsqr.dll
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-12 10:09:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
************************************************** ************************
.
Completion time: 2008-07-12 10:14:15
ComboFix-quarantined-files.txt 2008-07-12 09:13:05
ComboFix 08-07-11.1 - Dave 2008-07-12 10:04:40.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.223 [GMT 1:00]
Running from: C:\Documents and Settings\Dave\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Program Files\Common Files\{DCFCD~1
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\rqstv.bak2
.
((((((((((((((((((((((((( Files Created from 2008-06-12 to 2008-07-12 )))))))))))))))))))))))))))))))
.
2008-07-11 10:11 . 2008-07-11 10:11 <DIR> d-------- C:\Deckard
2008-07-10 15:52 . 2008-07-10 15:52 165 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
2008-07-10 14:15 . 2008-07-10 14:15 <DIR> d-------- C:\Program Files\Innovative Solutions
2008-06-30 19:37 . 2006-09-26 13:57 28,672 --a------ C:\WINDOWS\system32\AVEQT.dll
2008-06-30 16:45 . 2008-06-30 16:45 <DIR> d-------- C:\Program Files\Octoshape Streaming Services
2008-06-29 17:18 . 2008-06-29 17:45 21,840 --a----t- C:\WINDOWS\system32\SIntfNT.dll
2008-06-29 17:18 . 2008-06-29 17:45 17,212 --a----t- C:\WINDOWS\system32\SIntf32.dll
2008-06-29 17:18 . 2008-06-29 17:45 12,067 --a----t- C:\WINDOWS\system32\SIntf16.dll
2008-06-29 15:20 . 2008-06-29 15:20 94,208 --a------ C:\WINDOWS\DIIUnin.exe
2008-06-29 15:20 . 2008-06-29 18:03 18,167 --a------ C:\WINDOWS\DIIUnin.dat
2008-06-29 15:20 . 2008-06-29 15:20 2,829 --a------ C:\WINDOWS\DIIUnin.pif
2008-06-29 15:08 . 2008-07-03 16:05 <DIR> d-------- C:\Program Files\Diablo II
2008-06-27 18:06 . 2008-06-27 18:06 <DIR> d-------- C:\Program Files\Opera
2008-06-25 09:04 . 2008-06-25 09:04 268 --ah----- C:\sqmdata05.sqm
2008-06-25 09:04 . 2008-06-25 09:04 244 --ah----- C:\sqmnoopt05.sqm
2008-06-22 11:21 . 2008-06-22 11:21 2,320,000 --a------ C:\WINDOWS\system32\TUKernel.exe
2008-06-20 16:40 . 2008-06-20 16:40 <DIR> d-------- C:\Program Files\Lavalys
2008-06-19 18:20 . 2008-06-19 18:20 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-06-19 18:18 . 2008-06-19 18:20 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
2008-06-15 08:44 . 2008-06-15 08:45 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-06-15 08:44 . 2008-06-15 08:44 <DIR> d-------- C:\Documents and Settings\Dave\Application Data\SystemRequirementsLab
2008-06-15 08:33 . 2008-06-15 08:33 <DIR> d-------- C:\Documents and Settings\Dave\Application Data\SPORE Creature Creator
2008-06-15 08:21 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2008-06-15 08:19 . 2008-06-15 08:21 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2008-06-15 08:18 . 2008-06-15 08:18 <DIR> d-------- C:\WINDOWS\Logs
2008-06-15 08:13 . 2008-06-15 08:13 <DIR> d-------- C:\Program Files\Electronic Arts
2008-06-12 12:47 . 2008-06-12 12:47 <DIR> d-------- C:\Program Files\AutoHotkey
2008-06-12 12:43 . 2008-07-01 18:20 <DIR> d-------- C:\Program Files\Notepad++
2008-06-12 12:43 . 2008-06-12 12:45 <DIR> d-------- C:\Documents and Settings\Dave\Application Data\Notepad++
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-07-12 07:49 --------- d-----w C:\Program Files\Winamp
2008-07-12 07:40 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-07-11 07:07 --------- d-----w C:\Program Files\World of Warcraft
2008-06-30 18:37 --------- d-----w C:\Program Files\Ultra QuickTime Converter
2008-06-29 18:39 --------- d-----w C:\Documents and Settings\Dave\Application Data\FrostWire
2008-06-26 13:28 --------- d-----w C:\Program Files\Motive
2008-06-26 13:03 --------- d-----w C:\Program Files\Creative
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 17:18 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-19 16:36 --------- d-----w C:\Documents and Settings\Dave\Application Data\Azureus
2008-06-19 16:31 --------- d-----w C:\Program Files\TuneUp Utilities 2007
2008-06-18 19:31 --------- d-----w C:\Documents and Settings\Dave\Application Data\Free Download Manager
2008-06-15 07:33 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-06-15 07:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-09 09:06 --------- d-----w C:\Program Files\Last.fm
2008-06-04 08:25 --------- d-----w C:\Program Files\Zune
2008-06-04 08:13 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01007_C oinstaller_Critical.Wdf
2008-06-04 08:13 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_zumbus_010 07.Wdf
2008-05-30 13:19 507,400 ----a-w C:\WINDOWS\system32\XAudio2_1.dll
2008-05-30 13:18 238,088 ----a-w C:\WINDOWS\system32\xactengine3_1.dll
2008-05-30 13:17 65,032 ----a-w C:\WINDOWS\system32\XAPOFX1_0.dll
2008-05-30 13:17 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_4.dll
2008-05-30 13:11 467,984 ----a-w C:\WINDOWS\system32\d3dx10_38.dll
2008-05-30 13:11 3,850,760 ----a-w C:\WINDOWS\system32\D3DX9_38.dll
2008-05-30 13:11 1,491,992 ----a-w C:\WINDOWS\system32\D3DCompiler_38.dll
2008-05-25 19:01 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-05-25 18:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-25 18:57 --------- d-----w C:\Documents and Settings\Dave\Application Data\SUPERAntiSpyware.com
2008-05-25 18:49 --------- d-----w C:\Documents and Settings\Dave\Application Data\ICQ
2008-05-25 18:47 --------- d-----w C:\Program Files\Audiosurf
2008-05-16 15:13 --------- d-----w C:\Program Files\Steam
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-29 18:56 61,856 ----a-w C:\WINDOWS\system32\ZuneBusEnum.exe
2008-04-29 18:56 245,664 ----a-w C:\WINDOWS\system32\ZuneWlanCfgSvc.exe
2008-04-29 18:39 70,144 ----a-w C:\WINDOWS\system32\ZuneIpTransport.dll
2008-04-29 18:39 62,464 ----a-w C:\WINDOWS\system32\ZuneUsbTransport.dll
2008-04-29 18:39 35,328 ----a-w C:\WINDOWS\system32\ZuneUsbCOnnection.dll
2008-04-29 18:39 145,408 ----a-w C:\WINDOWS\system32\ZuneMTPZ.dll
2008-04-21 07:04 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-17 18:11 1,112,288 ----a-w C:\WINDOWS\system32\WdfCoInstaller01007.dll
2007-10-31 18:07 24,096 ----a-w C:\Documents and Settings\Dave\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23 102400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-02-12 16:57 188416]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-02-12 16:59 77824]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-14 10:00 267064]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-20 19:54 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41 45056]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 22:34 49152]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2008-04-29 19:56 158624]
"C-Media Mixer"="Mixer.exe" [2002-10-15 18:00 1818624 C:\WINDOWS\mixer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-07-04 10:31:06 113664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.mpegacm "= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\mpegacm.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2006-07-18 12:02]
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2003-03-27 14:55]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2006-07-18 12:02]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2006-02-28 13:00]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 19:39]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 19:56]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.ex e [2008-06-19 18:20]
S3 TunRDriverV32;TunRDriverV32;C:\WINDOWS\system32\dr ivers\TunRDriverV32.sys [2007-07-12 12:10]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 19:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2008-07-12 09:00:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-04-15 20:31:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Explorer_Run-{DCFCDA4D-07CF-1033-0307-03032603002c} - C:\Program Files\Common Files\{DCFCDA4D-07CF-1033-0307-03032603002c}\Update.exe
Notify-vtsqr - C:\WINDOWS\system32\vtsqr.dll
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-12 10:09:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
************************************************** ************************
.
Completion time: 2008-07-12 10:14:15
ComboFix-quarantined-files.txt 2008-07-12 09:13:05












