Here are the 2 logs, and the virus scan too.
The virus scan of C:\Documents and Settings\New User\Application Data\39315.exe
at
http://virusscan.jotti.org/
Service load: 0% 100%
File: 39315.exe
Status: OK(Note: file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5: 2f501741705321418d8692e9ed9f75ac
Packers detected: -
Bit9 reports: File not found
Scanner results
Scan taken on 16 Apr 2008 22:40:20 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing
The Combofix Log:
ComboFix 08-04-13.3 - New User 2008-04-16 18:48:33.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.274 [GMT -4:00]
Running from: C:\Documents and Settings\New User\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\New User\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-03-16 to 2008-04-16 )))))))))))))))))))))))))))))))
.
2008-04-15 18:50 . 2007-04-26 08:55 528,797 --a------ C:\WINDOWS\_detmp.1
2008-04-15 18:50 . 2002-08-29 04:00 128,000 --a------ C:\WINDOWS\_detmp.2
2008-04-15 18:36 . 2008-04-15 18:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-04-13 10:34 . 2008-04-13 10:38 <DIR> d-------- C:\Program Files\Panda Security
2008-04-10 21:43 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-04-10 21:43 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-04-10 21:43 . 2008-03-28 23:19 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-10 21:43 . 2008-03-26 08:50 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-10 21:43 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-04-10 21:43 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-10 21:43 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-10 19:10 . 2008-04-10 19:10 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-04-10 19:10 . 2008-04-10 19:10 <DIR> d-------- C:\Documents and Settings\New User\Application Data\SUPERAntiSpyware.com
2008-04-10 19:10 . 2008-04-10 19:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-09 22:33 . 2008-04-09 22:33 <DIR> d-------- C:\Documents and Settings\New User\Application Data\Uniblue
2008-04-09 21:04 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-09 20:50 . 2008-04-09 20:50 <DIR> d-------- C:\Program Files\CCleaner
2008-04-08 20:53 . 2008-03-29 14:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-04-08 20:53 . 2008-03-29 14:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-04-08 20:53 . 2008-01-17 11:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-04-08 20:53 . 2008-03-29 14:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-04-08 20:53 . 2008-03-29 14:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-04-08 20:53 . 2008-03-29 14:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-04-08 20:53 . 2008-03-29 14:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-04-08 20:53 . 2008-03-29 14:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-04-08 20:52 . 2008-04-08 20:52 <DIR> d-------- C:\Program Files\Alwil Software
2008-04-08 20:52 . 2008-03-29 14:45 1,146,232 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-04-08 20:52 . 2004-01-09 04:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-04-08 06:58 . 2008-04-08 06:58 <DIR> d-------- C:\Deckard
2008-04-07 23:36 . 2008-04-07 23:36 <DIR> d-------- C:\Documents and Settings\New User\Application Data\Apple Computer
2008-04-07 22:38 . 2008-04-07 22:52 <DIR> d-------- C:\fixwareout
2008-04-07 22:10 . 2008-04-10 22:42 1,600 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-07 22:02 . 2008-04-07 22:02 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-07 22:02 . 2008-04-07 22:02 <DIR> d-------- C:\Documents and Settings\New User\Application Data\Malwarebytes
2008-04-07 22:02 . 2008-04-07 22:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-07 22:00 . 2008-04-07 22:00 <DIR> d-------- C:\_OTMoveIt
2008-04-07 21:35 . 2008-04-07 21:36 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-07 21:21 . 2008-04-07 21:21 <DIR> d-------- C:\Documents and Settings\Administrator.NEW
2008-04-07 20:37 . 2008-04-07 20:37 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-05 21:14 . 2008-04-11 23:32 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-04-05 21:14 . 2008-04-05 21:14 <DIR> d-------- C:\Documents and Settings\New User\Application Data\PC Tools
2008-04-05 21:14 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-05 21:14 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-05 21:14 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-05 21:14 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-04-02 22:33 . 2005-10-20 21:47 30,592 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-02 22:33 . 2005-10-20 21:47 12,800 --------- C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-02 22:31 . 2008-04-02 22:31 <DIR> d-------- C:\Program Files\MS Extra links
2008-03-30 19:44 . 2008-04-15 18:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-30 17:10 . 2008-04-16 18:33 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-03-30 17:09 . 2008-03-30 17:09 <DIR> d-------- C:\Program Files\Zone Labs
2008-03-30 17:08 . 2008-04-16 18:39 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-03-23 19:42 . 2008-03-23 19:42 <DIR> d-------- C:\Documents and Settings\Administrator
2008-03-21 21:38 . 2008-03-21 21:58 <DIR> d-------- C:\kav
2008-03-21 19:14 . 2008-03-30 15:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-19 20:10 . 2008-03-19 19:33 691,545 --a------ C:\WINDOWS\unins000.exe
2008-03-19 20:10 . 2008-03-19 20:10 2,541 --a------ C:\WINDOWS\unins000.dat
2008-03-17 22:42 . 2008-03-17 22:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SlySoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-16 00:31 --------- d-----w C:\Program Files\WinFax
2008-04-13 15:00 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-13 01:21 1,899,520 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2008-04-12 03:33 1,899,008 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2008-04-12 03:33 1,864,192 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-04-12 02:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-11 03:01 --------- d-----w C:\Program Files\PokerStars
2008-04-10 23:09 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-10 01:04 --------- d-----w C:\Program Files\Java
2008-04-07 03:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-04-07 03:50 --------- d-----w C:\Documents and Settings\New User\Application Data\RipIt4Me
2008-04-03 02:33 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-04-01 00:03 1,557,504 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-03-30 22:47 174,592 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-03-30 22:39 502,272 ----a-w C:\WINDOWS\system32\winlogon.exe
2008-03-28 00:24 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-26 01:04 --------- d-----w C:\Program Files\PCPitstop
2008-03-24 20:44 --------- d-----w C:\Documents and Settings\New User\Application Data\Canon
2008-03-22 01:40 --------- d-----w C:\Program Files\Symantec
2008-03-22 01:40 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-20 00:43 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-07 13:24 97,216 ----a-w C:\WINDOWS\system32\drivers\AnyDVD.sys
2008-03-06 00:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
2008-03-05 23:30 --------- d-----w C:\Program Files\SlySoft
2007-12-03 02:10 24,328 ----a-w C:\Documents and Settings\New User\Application Data\info.dat
2007-12-02 22:50 2,619 ----a-w C:\Documents and Settings\New User\Application Data\39315.exe
2004-10-01 19:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Documents and Settings\Administrator ----
2008-04-14 20:33 1024 --ah----- C:\Documents and Settings\Administrator\NtUser.dat.LOG
2008-04-05 18:39 1572864 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-03-23 19:44 16384 --a------ C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
2008-03-23 19:42 8192 --ah----- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
2008-03-23 19:42 62 --ahs---- C:\Documents and Settings\Administrator\Local Settings\desktop.ini
2008-03-23 19:42 262144 ---h----- C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
2008-03-23 19:42 20 --ahs---- C:\Documents and Settings\Administrator\ntuser.ini
2007-01-07 23:30 67 --ahs---- C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\desktop.ini
2007-01-07 23:30 113 --ahs---- C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\desktop.ini
2007-01-07 23:30 113 --ahs---- C:\Documents and Settings\Administrator\Local Settings\History\desktop.ini
2007-01-07 23:25 84 --ahs---- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\desktop.ini
2007-01-07 23:25 84 --ahs---- C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Entertainment\desktop.ini
2007-01-07 23:25 804 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
2007-01-07 23:25 792 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Windows Media Player.lnk
2007-01-07 23:25 720896 --a------ C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb
2007-01-07 23:25 498 --a------ C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.DTD
2007-01-07 23:25 482 --ahs---- C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\desktop.ini
2007-01-07 23:25 386 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk
2007-01-07 23:25 348 --ahs---- C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\desktop.ini
2007-01-07 23:25 1599 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk
2007-01-07 23:25 1555 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Command Prompt.lnk
2007-01-07 23:25 1539 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk
2007-01-07 23:25 1532 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk
2007-01-07 23:25 1527 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Tour Windows XP.lnk
2007-01-07 23:25 1525 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk
2007-01-07 23:25 1519 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Synchronize.lnk
2007-01-07 23:25 1519 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Notepad.lnk
2007-01-07 23:25 1501 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk
2007-01-07 23:25 148 --ahs---- C:\Documents and Settings\Administrator\Start Menu\Programs\desktop.ini
2007-01-07 23:25 141 --a------ C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\brndlog.txt
2007-01-07 23:25 12784 --a------ C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.XML
2007-01-07 23:25 113 --a------ C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\brndlog.bak
2007-01-07 23:24 181 --ahs---- C:\Documents and Settings\Administrator\SendTo\desktop.ini
2007-01-07 23:24 0 --a------ C:\Documents and Settings\Administrator\SendTo\Mail Recipient.MAPIMail
2007-01-07 23:24 0 --a------ C:\Documents and Settings\Administrator\SendTo\Desktop (create shortcut).DeskLink
2007-01-07 23:24 0 --a------ C:\Documents and Settings\Administrator\SendTo\Compressed (zipped) Folder.ZFSendToTarget
2007-01-07 23:23 1487 --a------ C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Windows Explorer.lnk
2007-01-07 15:05 62 --ahs---- C:\Documents and Settings\Administrator\Start Menu\desktop.ini
2007-01-07 15:05 62 --ahs---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
2004-08-04 08:00 58 --a------ C:\Documents and Settings\Administrator\Templates\sndrec.wav
2004-08-04 08:00 57 -ra------ C:\Documents and Settings\Administrator\Templates\wordpfct.wpg
2004-08-04 08:00 5632 --a------ C:\Documents and Settings\Administrator\Templates\excel.xls
2004-08-04 08:00 461 --a------ C:\Documents and Settings\Administrator\Templates\presenta.shw
2004-08-04 08:00 4608 --a------ C:\Documents and Settings\Administrator\Templates\winword.doc
2004-08-04 08:00 4570 --a------ C:\Documents and Settings\Administrator\Templates\amipro.sam
2004-08-04 08:00 4017 --a------ C:\Documents and Settings\Administrator\Templates\quattro.wb2
2004-08-04 08:00 30 -ra------ C:\Documents and Settings\Administrator\Templates\wordpfct.wpd
2004-08-04 08:00 2448 --a------ C:\Documents and Settings\Administrator\Templates\lotus.wk4
2004-08-04 08:00 1769 --a------ C:\Documents and Settings\Administrator\Templates\winword2.doc
2004-08-04 08:00 1518 --a------ C:\Documents and Settings\Administrator\Templates\excel4.xls
2004-08-04 08:00 12288 --a------ C:\Documents and Settings\Administrator\Templates\powerpnt.ppt
---- Directory of C:\Documents and Settings\Administrator.NEW ----
2008-04-15 18:36 1024 --ah----- C:\Documents and Settings\Administrator.NEW\NtUser.dat.LOG
2008-04-07 21:42 786432 --ah----- C:\Documents and Settings\Administrator.NEW\NTUSER.DAT
2008-04-07 21:42 1024 --ah----- C:\Documents and Settings\Administrator.NEW\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
2008-04-07 21:35 26 --ah----- C:\Documents and Settings\Administrator.NEW\My Documents\My Logitech Pictures\Pictures and Videos\folder.dat
2008-04-07 21:34 62 --ahs---- C:\Documents and Settings\Administrator.NEW\Local Settings\desktop.ini
2008-04-07 21:34 2528 --a------ C:\Documents and Settings\Administrator.NEW\Application Data\$_hpcst$.hpc
2008-04-07 21:34 16384 --a------ C:\Documents and Settings\Administrator.NEW\Local Settings\History\History.IE5\index.dat
2008-04-07 21:34 1488 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Windows Explorer.lnk
2008-04-07 21:23 4240656 --ah----- C:\Documents and Settings\Administrator.NEW\Local Settings\Application Data\IconCache.db
2008-04-07 21:23 262144 --ah----- C:\Documents and Settings\Administrator.NEW\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
2008-04-07 21:23 178 ---hs---- C:\Documents and Settings\Administrator.NEW\ntuser.ini
2007-01-07 23:30 67 --ahs---- C:\Documents and Settings\Administrator.NEW\Local Settings\Temporary Internet Files\desktop.ini
2007-01-07 23:30 113 --ahs---- C:\Documents and Settings\Administrator.NEW\Local Settings\History\History.IE5\desktop.ini
2007-01-07 23:30 113 --ahs---- C:\Documents and Settings\Administrator.NEW\Local Settings\History\desktop.ini
2007-01-07 23:25 84 --ahs---- C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Startup\desktop.ini
2007-01-07 23:25 84 --ahs---- C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Entertainment\desktop.ini
2007-01-07 23:25 804 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
2007-01-07 23:25 792 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Windows Media Player.lnk
2007-01-07 23:25 720896 --a------ C:\Documents and Settings\Administrator.NEW\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb
2007-01-07 23:25 498 --a------ C:\Documents and Settings\Administrator.NEW\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.DTD
2007-01-07 23:25 482 --ahs---- C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\desktop.ini
2007-01-07 23:25 386 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk
2007-01-07 23:25 348 --ahs---- C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Accessibility\desktop.ini
2007-01-07 23:25 1599 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Remote Assistance.lnk
2007-01-07 23:25 1555 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Command Prompt.lnk
2007-01-07 23:25 1539 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk
2007-01-07 23:25 1532 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk
2007-01-07 23:25 1527 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Tour Windows XP.lnk
2007-01-07 23:25 1525 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk
2007-01-07 23:25 1519 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Synchronize.lnk
2007-01-07 23:25 1519 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Notepad.lnk
2007-01-07 23:25 1501 --a------ C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk
2007-01-07 23:25 148 --ahs---- C:\Documents and Settings\Administrator.NEW\Start Menu\Programs\desktop.ini
2007-01-07 23:25 141 --a------ C:\Documents and Settings\Administrator.NEW\Application Data\Microsoft\Internet Explorer\brndlog.txt
2007-01-07 23:25 12784 --a------ C:\Documents and Settings\Administrator.NEW\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.XML
2007-01-07 23:25 113 --a------ C:\Documents and Settings\Administrator.NEW\Application Data\Microsoft\Internet Explorer\brndlog.bak
2007-01-07 23:24 181 --ahs---- C:\Documents and Settings\Administrator.NEW\SendTo\desktop.ini
2007-01-07 23:24 0 --a------ C:\Documents and Settings\Administrator.NEW\SendTo\Mail Recipient.MAPIMail
2007-01-07 23:24 0 --a------ C:\Documents and Settings\Administrator.NEW\SendTo\Desktop (create shortcut).DeskLink
2007-01-07 23:24 0 --a------ C:\Documents and Settings\Administrator.NEW\SendTo\Compressed (zipped) Folder.ZFSendToTarget
2007-01-07 15:05 62 --ahs---- C:\Documents and Settings\Administrator.NEW\Start Menu\desktop.ini
2007-01-07 15:05 62 --ahs---- C:\Documents and Settings\Administrator.NEW\Application Data\desktop.ini
2004-08-04 08:00 58 --a------ C:\Documents and Settings\Administrator.NEW\Templates\sndrec.wav
2004-08-04 08:00 57 -ra------ C:\Documents and Settings\Administrator.NEW\Templates\wordpfct.wpg
2004-08-04 08:00 5632 --a------ C:\Documents and Settings\Administrator.NEW\Templates\excel.xls
2004-08-04 08:00 461 --a------ C:\Documents and Settings\Administrator.NEW\Templates\presenta.shw
2004-08-04 08:00 4608 --a------ C:\Documents and Settings\Administrator.NEW\Templates\winword.doc
2004-08-04 08:00 4570 --a------ C:\Documents and Settings\Administrator.NEW\Templates\amipro.sam
2004-08-04 08:00 4017 --a------ C:\Documents and Settings\Administrator.NEW\Templates\quattro.wb2
2004-08-04 08:00 30 -ra------ C:\Documents and Settings\Administrator.NEW\Templates\wordpfct.wpd
2004-08-04 08:00 2448 --a------ C:\Documents and Settings\Administrator.NEW\Templates\lotus.wk4
2004-08-04 08:00 1769 --a------ C:\Documents and Settings\Administrator.NEW\Templates\winword2.doc
2004-08-04 08:00 1518 --a------ C:\Documents and Settings\Administrator.NEW\Templates\excel4.xls
2004-08-04 08:00 12288 --a------ C:\Documents and Settings\Administrator.NEW\Templates\powerpnt.ppt
(((((((((((((((((((((((((((((
[email protected]_20.57.05.88 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-15 00:51:02 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-16 22:33:42 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-16 22:34:02 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_770.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 13:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2004-03-18 13:33 892928]
"Ad-watch"="C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe" [2003-01-27 06:15 396800]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe
"LGODDFU"="C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
"AVG7_CC"=C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\kav\\kav7\\setup.exe"=
"C:\\kav\\kis\\setup.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 14:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 14:35]
R2 FPMSNT;FPMSNT;C:\WINDOWS\system32\drivers\FPMSNT.sys [2000-06-06 16:47]
R2 Sdselect;Sdselect;C:\WINDOWS\system32\drivers\Sdselect.sys [2000-11-14 11:54]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 08:00]
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2001-09-27 00:32]
S3 EPUSBDSK;EPSON USB Mass Storage Driver;C:\WINDOWS\system32\DRIVERS\EPUSBDSK.sys [2000-02-15 20:00]
S3 MBAMCatchMe;MBAMCatchMe;C:\Program Files\Malwarebytes' Anti-Malware\catchme.sys [2008-04-01 18:13]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2008-03-28 22:28:25 C:\WINDOWS\Tasks\1-Klick-Wartung.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-16 18:52:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\Fdc]
"ImagePath"=multi:"system32\DRIVERS\fdc.sys\
00"
"KeepImagePath"=multi:"system32\DRIVERS\fdc.sys\
00"
"SDImagePath"=multi:"system32\DRIVERS\fdc.sys\
00"
--
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\Flpydisk]
"ImagePath"=multi:"System32\Drivers\Sdfloppy.sys\
00"
"KeepImagePath"=multi:"system32\DRIVERS\flpydisk.sys\
00"
"SDImagePath"=multi:"System32\Drivers\Sdfloppy.sys\
00"
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\Fdc]
"ImagePath"=multi:"system32\DRIVERS\fdc.sys\
00"
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\Fdc]
"ImagePath"=multi:"system32\DRIVERS\fdc.sys\
00"
"KeepImagePath"=multi:"system32\DRIVERS\fdc.sys\
00"
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\Fdc]
"ImagePath"=multi:"system32\DRIVERS\fdc.sys\
00"
"KeepImagePath"=multi:"system32\DRIVERS\fdc.sys\
00"
"SDImagePath"=multi:"system32\DRIVERS\fdc.sys\
00"
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\Flpydisk]
"ImagePath"=multi:"System32\Drivers\Sdfloppy.sys\
00"
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\Flpydisk]
"ImagePath"=multi:"System32\Drivers\Sdfloppy.sys\
00"
"KeepImagePath"=multi:"system32\DRIVERS\flpydisk.sys\
00"
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\Flpydisk]
"ImagePath"=multi:"System32\Drivers\Sdfloppy.sys\
00"
"KeepImagePath"=multi:"system32\DRIVERS\flpydisk.sys\
00"
"SDImagePath"=multi:"System32\Drivers\Sdfloppy.sys\
00"
.
Completion time: 2008-04-16 18:53:52
ComboFix-quarantined-files.txt 2008-04-15 00:58:11
Pre-Run: 33,556,713,472 bytes free
Post-Run: 33,533,169,664 bytes free
.
2007-12-01 01:43:24 --- E O F ---