Sorry for the giant log....didn't know what was needed:
ComboFix 09-09-04.02 - Ryan 09/05/2009 10:04.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2590 [GMT -7:00]
Running from: c:\documents and settings\Ryan\Desktop\C-Fix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Norton AntiVirus *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\dlinfo_0.drv
c:\windows\Installer\3c0897e.msp
c:\windows\Installer\4149e3.msi
----- BITS: Possible infected sites -----
hxxp://msxb-d1.vo.llnw.net:3074
.
((((((((((((((((((((((((( Files Created from 2009-08-05 to 2009-09-05 )))))))))))))))))))))))))))))))
.
2009-09-04 23:52 . 2009-09-05 00:29 -------- d-----w- C:\SDFix
2009-09-04 23:48 . 2009-09-04 23:48 -------- d-----w- c:\program files\Trend Micro
2009-09-04 15:34 . 2009-09-04 15:34 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2009-09-04 14:38 . 2009-09-04 14:38 -------- d-----w- c:\documents and settings\Ryan\Local Settings\Application Data\ESET
2009-08-30 07:59 . 2009-03-09 22:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
2009-08-30 07:59 . 2009-03-09 22:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
2009-08-30 07:59 . 2009-03-09 22:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2009-08-30 07:59 . 2009-03-16 21:18 69448 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-08-30 07:59 . 2009-03-16 21:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
2009-08-30 07:59 . 2009-03-16 21:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
2009-08-30 07:59 . 2009-03-16 21:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2009-08-30 07:59 . 2008-10-10 11:52 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2009-08-30 07:59 . 2008-10-10 11:52 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2009-08-30 07:59 . 2008-10-10 11:52 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2009-08-30 07:59 . 2008-10-27 17:04 514384 ----a-w- c:\windows\system32\XAudio2_3.dll
2009-08-30 07:59 . 2008-10-27 17:04 70992 ----a-w- c:\windows\system32\XAPOFX1_2.dll
2009-08-30 07:58 . 2008-10-27 17:04 235856 ----a-w- c:\windows\system32\xactengine3_3.dll
2009-08-30 07:58 . 2008-10-27 17:04 23376 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2009-08-30 03:35 . 2009-08-30 03:35 -------- d-----w- c:\documents and settings\Ryan\Local Settings\Application Data\assembly
2009-08-30 03:34 . 2009-08-30 03:36 -------- d-----w- c:\program files\NCSoft
2009-08-23 11:06 . 2009-08-23 11:06 -------- d-----w- c:\program files\NVIDIA Corporation
2009-08-23 11:06 . 2009-08-23 11:06 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-08-22 00:09 . 2009-08-22 00:27 35190 ----a-w- c:\windows\scunin.dat
2009-08-22 00:09 . 2009-08-22 00:27 967 ----a-w- c:\windows\ScUnin.pif
2009-08-22 00:09 . 2009-08-22 00:27 94208 ----a-w- c:\windows\ScUnin.exe
2009-08-22 00:07 . 2009-09-03 00:02 -------- d-----w- c:\program files\Starcraft
2009-08-21 23:15 . 2009-08-21 23:15 -------- d-----w- c:\documents and settings\Ryan\Application Data\DivX
2009-08-21 23:13 . 2009-07-14 00:17 120056 ------w- c:\windows\system32\pxcpyi64.exe
2009-08-21 23:13 . 2009-07-14 00:17 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-08-21 23:13 . 2009-08-21 23:14 -------- d-----w- c:\program files\DivX
2009-08-21 23:13 . 2009-08-21 23:13 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-08-21 04:42 . 2009-08-21 04:42 -------- d-----w- c:\program files\ESET
2009-08-21 04:42 . 2009-08-21 04:42 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-08-19 20:37 . 2009-08-19 20:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-08-17 10:04 . 2009-08-17 10:04 2173472 ----a-w- c:\windows\system32\nvcplui.exe
2009-08-17 10:04 . 2009-08-17 10:04 81920 ----a-w- c:\windows\system32\nvwddi.dll
2009-08-17 10:03 . 2009-08-17 10:03 3170304 ----a-w- c:\windows\system32\nvwss.dll
2009-08-17 10:03 . 2009-08-17 10:03 4026368 ----a-w- c:\windows\system32\nvvitvs.dll
2009-08-17 10:03 . 2009-08-17 10:03 188416 ----a-w- c:\windows\system32\nvmccss.dll
2009-08-17 10:03 . 2009-08-17 10:03 1286144 ----a-w- c:\windows\system32\nvmobls.dll
2009-08-17 10:03 . 2009-08-17 10:03 3547136 ----a-w- c:\windows\system32\nvgames.dll
2009-08-17 10:03 . 2009-08-17 10:03 4923392 ----a-w- c:\windows\system32\nvdisps.dll
2009-08-17 10:03 . 2009-08-17 10:03 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-08-17 10:03 . 2009-08-17 10:03 168004 ----a-w- c:\windows\system32\nvsvc32.exe
2009-08-17 10:03 . 2009-08-17 10:03 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-08-17 10:03 . 2009-08-17 10:03 13877248 ----a-w- c:\windows\system32\nvcpl.dll
2009-08-17 10:02 . 2009-08-17 10:02 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-08-17 07:57 . 2009-08-17 07:57 1706528 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-08-17 07:57 . 2009-08-17 07:57 1597690 ----a-w- c:\windows\system32\nvdata.bin
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-05 17:11 . 2009-05-05 12:15 -------- d-----w- c:\program files\DNA
2009-09-05 17:11 . 2009-05-05 12:15 -------- d-----w- c:\documents and settings\Ryan\Application Data\DNA
2009-09-05 17:11 . 2009-03-31 03:26 -------- d-----w- c:\program files\Steam
2009-09-05 17:11 . 2008-11-13 16:07 16608 ----a-w- c:\windows\gdrv.sys
2009-09-05 00:10 . 2009-07-03 21:27 -------- d-----w- c:\documents and settings\Ryan\Application Data\RayV
2009-09-05 00:01 . 2008-11-14 04:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-02 22:24 . 2008-11-29 12:09 -------- d-----w- c:\documents and settings\Ryan\Application Data\LimeWire
2009-09-01 16:10 . 2009-01-09 19:49 -------- d-----w- c:\program files\World of Warcraft
2009-08-30 03:34 . 2008-11-13 16:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-30 03:33 . 2009-01-05 07:53 -------- d-----w- c:\documents and settings\Ryan\Application Data\GetRightToGo
2009-08-25 02:00 . 2008-11-14 23:39 -------- d-----w- c:\program files\Warcraft III
2009-08-19 21:06 . 2009-08-02 03:47 -------- d-----w- c:\documents and settings\Ryan\Application Data\SPORE
2009-08-17 07:57 . 2009-02-18 21:44 2189856 ----a-w- c:\windows\system32\nvcuvid.dll
2009-08-17 07:57 . 2008-11-13 16:16 485920 ----a-w- c:\windows\system32\nvudisp.exe
2009-08-17 07:57 . 2008-05-03 03:16 868352 ----a-w- c:\windows\system32\nvapi.dll
2009-08-17 07:57 . 2008-05-03 03:16 7729568 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-08-17 07:57 . 2008-05-03 03:16 5845760 ----a-w- c:\windows\system32\nv4_disp.dll
2009-08-17 07:57 . 2008-05-03 03:16 2002944 ----a-w- c:\windows\system32\nvcuda.dll
2009-08-17 07:57 . 2008-05-03 03:16 155648 ----a-w- c:\windows\system32\nvcodins.dll
2009-08-17 07:57 . 2008-05-03 03:16 155648 ----a-w- c:\windows\system32\nvcod.dll
2009-08-17 07:57 . 2008-05-03 03:16 10457088 ----a-w- c:\windows\system32\nvoglnt.dll
2009-08-12 19:34 . 2008-11-15 11:43 34 ----a-w- c:\documents and settings\Ryan\jagex_runescape_preferences.dat
2009-08-11 19:35 . 2008-11-13 16:16 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-08-06 09:36 . 2009-06-16 08:40 -------- d-----w- c:\program files\City of Heroes
2009-08-06 03:58 . 2009-08-06 03:58 -------- d-----w- c:\program files\Curse
2009-08-05 13:02 . 2008-11-14 23:42 78533 ----a-w- c:\windows\War3Unin.dat
2009-08-05 09:01 . 2008-04-14 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 20:36 . 2008-11-14 04:55 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 20:36 . 2008-11-14 04:55 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-02 13:21 . 2009-04-01 04:13 -------- d-----w- c:\program files\Windows Live Safety Center
2009-08-02 03:50 . 2009-07-09 03:56 -------- d-----w- c:\program files\Electronic Arts
2009-08-02 03:25 . 2008-12-26 19:19 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-07-31 20:31 . 2009-07-31 20:31 -------- d--h--r- c:\documents and settings\Ryan\Application Data\SecuROM
2009-07-31 06:50 . 2009-07-31 06:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-07-31 06:39 . 2009-04-02 04:57 -------- d-----w- c:\program files\SystemRequirementsLab
2009-07-30 06:34 . 2009-07-30 05:03 -------- d-----w- c:\documents and settings\Ryan\Application Data\Apple Computer
2009-07-30 06:28 . 2009-07-30 06:28 -------- d-----w- c:\program files\EV Nova
2009-07-30 05:03 . 2009-07-30 05:02 -------- d-----w- c:\program files\iTunes
2009-07-30 05:03 . 2009-07-30 05:02 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-30 05:02 . 2009-07-30 05:02 -------- d-----w- c:\program files\iPod
2009-07-30 05:02 . 2009-07-30 05:01 -------- d-----w- c:\program files\Common Files\Apple
2009-07-30 05:02 . 2009-07-30 05:02 -------- d-----w- c:\program files\Bonjour
2009-07-30 05:02 . 2009-07-30 05:02 -------- d-----w- c:\program files\QuickTime
2009-07-30 05:02 . 2009-07-30 05:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-30 05:02 . 2009-07-30 05:02 -------- d-----w- c:\program files\Apple Software Update
2009-07-30 05:01 . 2009-07-30 05:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-07-17 19:01 . 2008-04-14 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 06:43 . 2008-04-14 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 00:15 . 2009-07-14 00:15 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-07-14 00:15 . 2009-07-14 00:15 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-07-14 00:15 . 2009-07-14 00:15 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-07-14 00:15 . 2009-07-14 00:15 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-07-14 00:15 . 2009-07-14 00:15 811008 ----a-w- c:\windows\system32\divx_xx16.dll
2009-07-14 00:15 . 2009-07-14 00:15 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-07-14 00:15 . 2009-07-14 00:15 685056 ----a-w- c:\windows\system32\DivX.dll
2009-07-09 19:16 . 2009-07-30 05:01 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-07-09 19:16 . 2009-07-30 05:01 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-07-09 17:12 . 2009-07-09 17:12 -------- d-----w- c:\program files\LittleFighter2
2009-07-09 00:53 . 2008-11-24 04:23 16888 ----a-w- c:\documents and settings\Ryan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-08 01:23 . 2009-07-08 01:23 -------- d-----w- c:\program files\OGPlanet
2009-06-29 16:12 . 2008-04-14 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2008-04-14 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-04-14 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2008-04-14 12:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2008-04-14 12:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2008-04-14 12:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2008-04-14 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2008-04-14 12:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2008-04-14 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2008-04-14 12:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2008-04-14 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2008-04-14 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2008-04-14 12:00 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2008-04-14 12:00 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 16:19 . 2008-11-13 15:58 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2008-04-14 12:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2008-04-14 12:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-07-14 00:16 . 2009-07-14 00:16 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-07-14 00:16 . 2009-07-14 00:16 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
------- Sigcheck -------
[7] 2008-04-14 12:00 4224 DA1F27D85E0D1525F6621372E7B685E9 c:\windows\system32\dllcache\beep.sys
c:\windows\system32\drivers\beep.sys ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-06 4347120]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Steam"="c:\program files\Steam\Steam.exe" [2009-06-10 1217784]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-05-05 342848]
"RayV"="c:\program files\RayV\RayV\RayV.exe" [2009-06-15 2471208]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-04-29 3338240]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"SaiVolume"="c:\program files\Saitek\CyborgKeyboard\SaiVolume.exe" [2008-01-19 126976]
"ProfilerU"="c:\program files\Saitek\SD6\Software\ProfilerU.exe" [2008-01-19 233472]
"SaiMfd"="c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2008-01-19 131072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-08-13 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-02-13 16857600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
c:\documents and settings\Ryan\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\DreamCatcher\\Painkiller Overdose\\Bin\\Overdose.exe"=
"c:\\Program Files\\DreamCatcher\\Painkiller Overdose\\Bin\\OverdoseEditor.exe"=
"c:\\Program Files\\DreamCatcher\\Painkiller Overdose\\Bin\\OverdoseServer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\World of Warcraft\\Repair.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\WoW-0.1.0-enUS-downloader.exe"=
"c:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dawn of war 2\\DOW2.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Warcraft III\\Frozen Throne.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\ijji\\ENGLISH\\u_gunz.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.2.9901-to-3.1.3.9947-enUS-downloader.exe"=
"c:\\Program Files\\Sega\\Universe At War Earth Assault\\UAWEA.exe"=
"c:\\Program Files\\RayV\\RayV\\RayV.dll"=
"c:\\Program Files\\RayV\\RayV\\RayV.exe"=
"c:\\Program Files\\LittleFighter2\\LF2_v1.9c\\lf2.exe"=
"c:\\Documents and Settings\\Ryan\\Application Data\\RayV\\Viewer\\RayV.dll"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11344:TCP"= 11344:TCP:BitCometLite 11344 TCP
"11344:UDP"= 11344:UDP:BitCometLite 11344 UDP
"15629:TCP"= 15629:TCP:BitCometLite 15629 TCP
"15629:UDP"= 15629:UDP:BitCometLite 15629 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"58074:TCP"= 58074:TCP:Pando Media Booster
"58074:UDP"= 58074:UDP:Pando Media Booster
"6112:TCP"= 6112:TCP:Warcraft 3
"6112:UDP"= 6112:UDP:Warcraft 3
"6113:TCP"= 6113:TCP:Warcraft 3
"6113:UDP"= 6113:UDP:Warcraft 3
"6114:TCP"= 6114:TCP:Warcraft 3
"6114:UDP"= 6114:UDP:Warcraft 3
"6115:TCP"= 6115:TCP:Warcraft 3
"6115:UDP"= 6115:UDP:Warcraft 3
"6116:TCP"= 6116:TCP:Warcraft 3
"6116:UDP"= 6116:UDP:Warcraft 3
"6117:TCP"= 6117:TCP:Warcraft 3
"6117:UDP"= 6117:UDP:Warcraft 3
"6118:TCP"= 6118:TCP:Warcraft 3
"6118:UDP"= 6118:UDP:Warcraft 3
"6119:TCP"= 6119:TCP:Warcraft 3
"6119:UDP"= 6119:UDP:Warcraft 3
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [5/14/2009 3:47 PM 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [5/14/2009 3:49 PM 94360]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [5/14/2009 3:47 PM 731840]
R2 ES lite Service;ES lite Service for program management.;c:\program files\Gigabyte\EasySaver\essvr.exe [11/13/2008 9:09 AM 80392]
R2 WUSB54Gv42SVC;WUSB54Gv42SVC;c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe [11/14/2008 3:59 PM 53307]
R3 PAC7302;PAC7302 VGA USB Camera;c:\windows\system32\drivers\PAC7302.SYS [12/19/2008 10:50 PM 457856]
R3 SaiK0728;SaiK0728;c:\windows\system32\drivers\SaiK0728.sys [12/24/2008 5:27 PM 104960]
S3 XDva248;XDva248;\??\c:\windows\system32\XDva248.sys --> c:\windows\system32\XDva248.sys [?]
S3 XDva273;XDva273;\??\c:\windows\system32\XDva273.sys --> c:\windows\system32\XDva273.sys [?]
S3 XDva279;XDva279;\??\c:\windows\system32\XDva279.sys --> c:\windows\system32\XDva279.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-09-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-PlayNC Launcher - (no file)
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
FF - ProfilePath - c:\documents and settings\Ryan\Application Data\Mozilla\Firefox\Profiles\sp8xwaem.default\
FF - component: c:\documents and settings\Ryan\Application Data\Mozilla\Firefox\Profiles\sp8xwaem.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-05 10:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-299502267-1085031214-1417001333-1003\Software\SecuROM\License information*]
"datasecu"=hex:d1,c6,7f,96,41,8d,d8,e1,1b,87,a4,49,c7,3d,6f,f5,6f,2a,8d,16,71,
6b,b3,68,5a,ad,cd,f8,18,08,d8,ac,ae,c5,6f,ad,98,81,56,b7,99,8d,62,df,fc,42,\
"rkeysecu"=hex:de,f4,12,88,e0,1d,48,13,03,ac,f3,4b,e9,8b,e2,1a
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1792)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
.
**************************************************************************
.
Completion time: 2009-09-05 10:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-05 17:15
Pre-Run: 201,062,088,704 bytes free
Post-Run: 200,913,637,376 bytes free
327 --- E O F --- 2009-08-30 10:00
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:19:02 AM, on 9/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\Program Files\Saitek\CyborgKeyboard\SaiVolume.exe
C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\Weee.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [SaiVolume] C:\Program Files\Saitek\CyborgKeyboard\SaiVolume.exe
O4 - HKLM\..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [RayV] C:\Program Files\RayV\RayV\RayV.exe /background
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - S-1-5-18 Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownlo.../sysreqlab3.cabO16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownlo...sreqlab_nvd.cabO16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/...lscbase1140.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/...b?1226637205401O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
--
End of file - 7652 bytes