ComboFix 08-01-23.1 - Andrew 2008-01-22 15:54:21.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.408 [GMT -8:00]
Running from: C:\Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Guest\Local Settings\Temporary Internet Files\Content.IE5\8C75RNL5\cnsminex[1].htm
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\#SharedObjects\XZHUMKTZ\www.inter-focus.cn
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\#SharedObjects\XZHUMKTZ\www.inter-focus.cn\flashad_beta_1.01.swf\IFFLASHAD.sol
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.inter-focus.cn
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.inter-focus.cn\settings.sol
C:\Program Files\popcorn Terms.html
C:\TeklaStructuresModels\GP2 PROJECT\_desktop.ini
C:\TeklaStructuresModels\GP2 PROJECT\attributes\_desktop.ini
C:\TeklaStructuresModels\GP2 PROJECT\DesignFiles\_desktop.ini
C:\TeklaStructuresModels\GP2 PROJECT\drawings\_desktop.ini
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2007-12-23 to 2008-01-23 )))))))))))))))))))))))))))))))
.
2008-01-22 15:52 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-21 18:08 . 2008-01-21 22:33 <DIR> d-------- C:\Program Files\a-squared Anti-Malware
2008-01-21 16:16 . 2008-01-21 16:17 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-20 22:57 . 2008-01-20 22:57 268 --ah----- C:\sqmdata01.sqm
2008-01-20 22:57 . 2008-01-20 22:57 244 --ah----- C:\sqmnoopt01.sqm
2008-01-16 15:46 . 2008-01-16 15:47 <DIR> d-------- C:\Program Files\iTunes
2008-01-16 15:46 . 2008-01-16 15:46 <DIR> d-------- C:\Program Files\iPod
2008-01-16 15:45 . 2008-01-16 15:45 <DIR> d-------- C:\Program Files\QuickTime
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-01-09 18:03 . 2008-01-09 19:36 51,355 --a------ C:\WINDOWS\system32\muzika.xm
2008-01-05 14:11 . 2008-01-05 14:11 <DIR> d-------- C:\Program Files\Videopot
2008-01-05 13:46 . 2008-01-05 13:46 <DIR> d-------- C:\Program Files\DAUM
2008-01-04 13:59 . 2008-01-04 13:59 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2008-01-04 13:59 . 2008-01-04 13:59 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2008-01-04 13:58 . 2008-01-04 13:58 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-01-04 13:58 . 2008-01-04 13:58 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-01-04 13:58 . 2008-01-04 13:58 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2008-01-04 13:56 . 2008-01-04 13:56 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-01-04 13:56 . 2008-01-04 13:56 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2008-01-03 21:27 . 2008-01-03 21:31 <DIR> d-------- C:\Program Files\TVAnts
2008-01-03 12:24 . 2005-06-23 18:37 40,960 --a------ C:\WINDOWS\system32\lxcqvs.dll
2008-01-03 12:23 . 2006-10-25 00:16 344,064 --a------ C:\WINDOWS\system32\lxcqcoin.dll
2008-01-03 12:22 . 2006-10-23 06:54 692,224 --a------ C:\WINDOWS\system32\lxcqdrs.dll
2008-01-03 12:22 . 2006-09-28 23:28 65,536 --a------ C:\WINDOWS\system32\lxcqcaps.dll
2008-01-03 12:22 . 2006-05-09 02:10 61,440 --a------ C:\WINDOWS\system32\lxcqcnv4.dll
2008-01-03 12:19 . 2006-10-24 01:33 31 --a------ C:\WINDOWS\system32\lxcqrwrd.ini
2008-01-03 12:16 . 2008-01-03 12:22 <DIR> d-------- C:\Program Files\Lexmark 9300 Series
2008-01-01 16:22 . 2008-01-01 16:23 <DIR> d-------- C:\Program Files\Hamachi
2007-12-27 12:52 . 2007-12-27 12:52 244 --ah----- C:\sqmnoopt00.sqm
2007-12-27 12:52 . 2007-12-27 12:52 232 --ah----- C:\sqmdata00.sqm
2007-12-26 17:33 . 2007-12-26 17:33 1,259 --a------ C:\WINDOWS\_ISENV31.INI
2007-12-26 16:15 . 2008-01-06 19:30 <DIR> d-------- C:\Program Files\Lx_cats
2007-12-26 16:08 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-12-26 16:08 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\dllcache\usbscan.sys
2007-12-26 15:46 . 2005-06-01 00:28 9,606 --a------ C:\WINDOWS\system32\NEWSOFT
2007-12-26 15:45 . 2007-12-26 15:45 <DIR> d-------- C:\Program Files\Common Files\NewSoft
2007-12-26 15:45 . 2004-07-30 12:06 28,672 --a------ C:\WINDOWS\hookdllX.dll
2007-12-26 15:44 . 2007-12-26 15:44 <DIR> d-------- C:\WINDOWS\system32\color
2007-12-26 15:44 . 2007-12-26 16:07 <DIR> d-------- C:\Program Files\Lexmark Applications
2007-12-26 15:44 . 1997-10-14 05:19 11,776 --a------ C:\WINDOWS\system32\pmsbfn32.dll
2007-12-26 15:44 . 2008-01-02 13:01 317 --a------ C:\WINDOWS\setup.iss
2007-12-26 15:43 . 2007-12-26 15:44 <DIR> d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-12-26 15:42 . 2006-04-24 08:00 339,968 --a------ C:\WINDOWS\system32\IMGMAN32.DLL
2007-12-26 15:42 . 2006-04-24 08:00 98,345 --a------ C:\WINDOWS\system32\IMHOST32.DLL
2007-12-26 15:42 . 2006-04-24 08:00 98,304 --a------ C:\WINDOWS\system32\IM31XPNG.DEL
2007-12-26 15:42 . 2006-04-24 08:00 69,632 --a------ C:\WINDOWS\system32\IM31XTIF.DEL
2007-12-26 15:42 . 2006-04-24 08:00 49,152 --a------ C:\WINDOWS\system32\IM31IMG.DIL
2007-12-26 15:42 . 2006-10-25 23:03 45,056 --a------ C:\WINDOWS\system32\lxcqpmon.dll
2007-12-26 15:42 . 2006-10-25 23:02 32,768 --a------ C:\WINDOWS\system32\LXCQFXPU.DLL
2007-12-26 15:42 . 2006-10-25 23:09 12,288 --a------ C:\WINDOWS\system32\lxcqpmrc.dll
2007-12-26 15:40 . 2008-01-03 12:19 <DIR> d-------- C:\Program Files\Lexmark Toolbar
2007-12-26 15:39 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-12-26 15:39 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-12-26 15:39 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-12-26 15:39 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\dllcache\usbprint.sys
2007-12-26 15:39 . 2004-08-09 21:00 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2007-12-26 15:39 . 2004-08-09 21:00 9,600 --a------ C:\WINDOWS\system32\dllcache\hidusb.sys
2007-12-26 15:38 . 2008-01-03 12:24 22,991 --a------ C:\WINDOWS\system32\LexFiles.ulf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-22 23:53 --------- d-----w C:\Program Files\FlashGet
2008-01-22 23:44 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-22 02:00 --------- d-----w C:\Program Files\fsupport
2008-01-22 00:15 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-21 03:46 --------- d-----w C:\Program Files\Starcraft
2008-01-21 00:47 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-01-13 08:03 --------- d-----w C:\Program Files\DivX
2008-01-04 21:57 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-01-04 21:57 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-01-04 21:57 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-01-04 21:57 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-01-04 21:57 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-01-04 21:57 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-01-04 21:57 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-01-04 21:57 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-01-04 21:57 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-01-04 21:57 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-01-04 21:57 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-01-04 21:57 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-01-02 21:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-25 19:52 --------- d-----w C:\Program Files\Java
2007-12-17 04:01 --------- d-----w C:\Program Files\MSN Messenger
2007-12-17 04:01 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-12-10 06:10 --------- d-----w C:\Program Files\A Midsummer Day's Resonance
2007-12-04 05:02 --------- d-----w C:\Program Files\Cheat Engine
2007-12-04 01:21 --------- d-----w C:\Program Files\FrostWire
2007-12-04 01:16 --------- d-----w C:\Program Files\LimeWire
2007-12-02 02:15 --------- d-----w C:\Program Files\Real Alternative
2007-11-28 05:45 37,027 ----a-w C:\WINDOWS\atmoUn.exe
2007-11-28 05:45 --------- d-----w C:\Program Files\Viewpoint
2007-11-25 18:23 --------- d-----w C:\Program Files\Counter-Strike Source
2007-11-13 06:09 1,497 ----a-w C:\Program Files\XVI32.ini
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:35 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35 1,287,680 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 01:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-28 01:40 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-03-02 05:27 7,367 ----a-w C:\Program Files\CurrentCfg.tpr
2007-03-02 05:27 51 ----a-w C:\Program Files\CurrentBatch.tbe
2007-03-02 05:27 5,208 ----a-w C:\Program Files\TMPGEnc.ini
2007-02-27 04:22 211 ----a-w C:\Program Files\MediaStage.zip.jei
2005-05-12 06:36 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
2005-04-11 08:15 133,516,151 ----a-w C:\Program Files\MediaStage.zip
2004-10-26 02:11 374,340 ----a-w C:\Program Files\TMPGEnc.vfp
2004-10-26 02:10 936 ----a-w C:\Program Files\Readme.big5.txt
2004-10-26 02:10 933 ----a-w C:\Program Files\Readme.gb.txt
2004-10-26 02:10 891,972 ----a-w C:\Program Files\TMPGEnc.exe
2004-10-26 02:10 4,865 ----a-w C:\Program Files\TMPGEnc.acf
2004-10-26 02:10 2,241 ----a-w C:\Program Files\License.fr.txt
2004-10-26 02:10 2,141 ----a-w C:\Program Files\License.en.txt
2004-10-26 02:10 155,648 ----a-w C:\Program Files\Resample.dll
2004-10-26 02:10 147,543 ----a-w C:\Program Files\P4Package.dll
2004-10-26 02:10 135,255 ----a-w C:\Program Files\P3Package.dll
2004-10-26 02:10 1,965 ----a-w C:\Program Files\License.ja.txt
2004-10-26 02:10 1,363 ----a-w C:\Program Files\License.gb.txt
2004-10-26 02:10 1,363 ----a-w C:\Program Files\License.big5.txt
2004-10-26 02:10 1,341 ----a-w C:\Program Files\Readme.fr.txt
2004-10-26 02:10 1,238 ----a-w C:\Program Files\Readme.ja.txt
2004-10-26 02:10 1,203 ----a-w C:\Program Files\Readme.en.txt
2002-10-08 01:30 104,583 ----a-w C:\Program Files\XVI32U.HLP
2002-10-08 01:14 6,672 ----a-w C:\Program Files\readme.txt
2002-10-07 00:52 763,904 ----a-w C:\Program Files\XVI32.exe
2001-08-27 19:47 947,689 ----a-w C:\Program Files\EditPlus 2.zip
2001-08-15 19:21 1,266 ----a-w C:\Program Files\XVI32U.cnt
1999-09-08 04:24 1,246 ----a-w C:\Program Files\WINEBCDE.XCT
1999-09-08 04:24 1,246 ----a-w C:\Program Files\EBCDEWIN.XCT
1999-09-08 04:24 1,232 ----a-w C:\Program Files\WINEBCUS.XCT
1999-09-08 04:24 1,232 ----a-w C:\Program Files\EBCUSWIN.XCT
1999-09-06 01:13 896 ----a-w C:\Program Files\WINDOS.XCT
1999-09-06 01:13 896 ----a-w C:\Program Files\DOSWIN.XCT
2005-12-23 04:18 32 --sha-w C:\WINDOWS\{87149465-800E-4962-9898-765FF0602633}.dat
2005-12-16 00:55 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
2005-12-23 04:18 32 --sha-w C:\WINDOWS\system32\{6C59E837-BF28-42E1-8775-4553B4EE725E}.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 04:00 15360]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-08-15 02:40 190024]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54 5674352]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-03 14:53 68856]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-04 10:50 405583]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56 64512]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 16:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-08 02:59 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-08 03:03 114688]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 15:35 49152]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-25 14:34 245760]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-11 22:12 49152]
"NeroCheck"="C:\WINDOWS\system32\\NeroCheck.exe" [2001-07-09 02:50 155648]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-12-02 16:11 54296]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2003-12-02 16:11 58392]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-12-23 13:30 100056]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-09 21:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-09 21:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-09 21:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-09 21:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-09 21:00 455168]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 15:44 61440]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-08 03:02 94208]
"WrtMon.exe"="C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 08:35 20480]
"lxcqmon.exe"="C:\Program Files\Lexmark 9300 Series\lxcqmon.exe" [2007-01-11 05:57 291760]
"Lexmark 9300 Series Fax Server"="C:\Program Files\Lexmark 9300 Series\fm3032.exe" [2006-12-05 01:36 304048]
"EzPrint"="C:\Program Files\Lexmark 9300 Series\ezprint.exe" [2006-12-05 01:35 82864]
"LXCQCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCQtime.dll" [2006-11-21 04:27 106496]
"RegistryMechanic"="" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2008-01-07 17:56 1816208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 09:01 437160]
C:\Documents and Settings\Andrew\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-11-20 21:26:53 113664]
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [2007-09-25 20:01:09 557568]
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 20:37:56 217194]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2006-12-17 20:49:44 124912]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 22:23:26 282624]
Image Transfer.lnk - C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe [2006-09-09 10:16:50 73728]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2005-11-29 16:40:57 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R2 lxcq_device;lxcq_device;C:\WINDOWS\system32\lxcqcoms.exe [2006-12-05 01:36]
S2 sentemul;sentemul;C:\WINDOWS\system32\drivers\sentemul.sys []
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 08:05]
S3 XDva009;XDva009;C:\WINDOWS\system32\XDva009.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d49fabd6-7a97-11dc-b28d-0013d4951d0d}]
\Shell\AutoRun\command - L:\Launcher.exe
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2008-01-16 19:32:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-22 23:46:55 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-01-21 10:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\NAVW32.exeG/task:C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\NORTON~1\Tasks\mycomp.sca
"2008-01-23 23:59:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-23 16:02:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCQCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-23 16:03:18
ComboFix-quarantined-files.txt 2008-01-24 00:03:16
.
2008-01-22 23:50:50 --- E O F ---