combofix.txt log:
"Mandeep" - 07-01-29 18:30:51 Service Pack 2
ComboFix 07-01-25 - Running from: "C:\Documents and Settings\Mandeep\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\INSTALL.LOG
((((((((((((((((((((((((((((((( Files Created from 2006-12-29 to 2007-01-29 ))))))))))))))))))))))))))))))))))
2007-01-29 18:16 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-01-28 14:02 4,000 --a------ C:\WINDOWS\system32\tmp.reg
2007-01-28 14:01 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-01-28 14:01 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-01-28 14:01 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-01-28 14:01 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-01-28 14:01 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-01-28 13:51 <DIR> d-------- C:\Program Files\Hijackthis
2007-01-21 21:07 <DIR> d-------- C:\Program Files\TVAnts
2007-01-13 01:50 <DIR> d-------- C:\Program Files\TVUPlayer
2007-01-13 01:34 <DIR> d-------- C:\DOCUME~1\Mandeep\Application Data\ppStream
2007-01-13 01:33 <DIR> d-------- C:\Program Files\21cn
2007-01-13 01:09 <DIR> d-------- C:\Program Files\PPMate
2007-01-13 01:09 <DIR> d-------- C:\ppmaterecord
2007-01-13 01:09 <DIR> d-------- C:\DOCUME~1\Mandeep\Application Data\PPMate
2007-01-13 01:00 <DIR> d-------- C:\Program Files\SopCast
2007-01-13 01:00 <DIR> d-------- C:\DOCUME~1\Mandeep\Application Data\SopCast
2007-01-13 00:46 <DIR> d-------- C:\Program Files\PPStream
2007-01-12 17:05 <DIR> d-------- C:\WINDOWS\ie7updates
2007-01-10 17:25 <DIR> d-------- C:\Program Files\Full Tilt Poker
2007-01-04 20:26 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\Application Data\TEMP
2007-01-04 20:26 <DIR> d-------- C:\DOCUME~1\Mandeep\Application Data\Google
2007-01-04 20:25 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2007-01-04 20:25 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2007-01-04 20:24 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-01-04 20:24 <DIR> d-------- C:\Program Files\Google
2007-01-04 20:24 <DIR> d-------- C:\DOCUME~1\Mandeep\Application Data\PC Tools
2007-01-04 20:24 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google
2007-01-04 19:50 <DIR> d-------- C:\DOCUME~1\Mandeep\Application Data\WinAntiSpyware 2006
2007-01-04 19:25 <DIR> d-------- C:\Program Files\SpywareHeal
2007-01-02 22:28 <DIR> d-------- C:\Program Files\PPLive
2007-01-02 22:28 <DIR> d-------- C:\DOCUME~1\Mandeep\Application Data\PPLive
2007-01-02 22:27 <DIR> d-------- C:\Program Files\Common Files\Synacast
2007-01-02 21:39 98,304 --a------ C:\WINDOWS\system32\msir3jp.dll
2007-01-02 21:39 9,216 --a------ C:\WINDOWS\system32\kbdnecAT.dll
2007-01-02 21:39 838,144 --a------ C:\WINDOWS\system32\chtbrkr.dll
2007-01-02 21:39 70,656 --a------ C:\WINDOWS\system32\korwbrkr.dll
2007-01-02 21:39 7,680 --a------ C:\WINDOWS\system32\kbdnecNT.dll
2007-01-02 21:39 7,168 --a------ C:\WINDOWS\system32\kbdnec95.dll
2007-01-02 21:39 7,168 --a------ C:\WINDOWS\system32\kbdibm02.dll
2007-01-02 21:39 7,168 --a------ C:\WINDOWS\system32\f3ahvoas.dll
2007-01-02 21:39 6,656 --a------ C:\WINDOWS\system32\kbdlk41a.dll
2007-01-02 21:39 6,144 --a------ C:\WINDOWS\system32\kbdlk41j.dll
2007-01-02 21:39 6,144 --a------ C:\WINDOWS\system32\kbdax2.dll
2007-01-02 21:39 6,144 --a------ C:\WINDOWS\system32\kbd106n.dll
2007-01-02 21:39 6,144 --a------ C:\WINDOWS\system32\kbd101a.dll
2007-01-02 21:39 6,144 --a------ C:\WINDOWS\system32\kbd101.dll
2007-01-02 21:39 218,112 --a------ C:\WINDOWS\system32\c_g18030.dll
2007-01-02 21:39 1,677,824 --a------ C:\WINDOWS\system32\chsbrkr.dll
2007-01-02 21:38 811,064 --a------ C:\WINDOWS\system32\imjp81k.dll
2007-01-02 21:38 8,704 --a------ C:\WINDOWS\system32\kbdjpn.dll
2007-01-02 21:38 8,192 --a------ C:\WINDOWS\system32\kbdkor.dll
2007-01-02 21:38 76,288 --a------ C:\WINDOWS\system32\uniime.dll
2007-01-02 21:38 6,656 --a------ C:\WINDOWS\system32\c_is2022.dll
2007-01-02 21:38 6,144 --a------ C:\WINDOWS\system32\kbd106.dll
2007-01-02 21:38 6,144 --a------ C:\WINDOWS\system32\kbd101c.dll
2007-01-02 21:38 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll
2007-01-02 21:38 5,632 --a------ C:\WINDOWS\system32\kbd103.dll
2007-01-02 21:17 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-01-02 21:14 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-01-02 21:14 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-01-02 21:14 <DIR> d-------- C:\9a522205a37d2a84d85e93
2007-01-02 21:13 <DIR> d-------- C:\fc59554ea2290b09dec641f5b3
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-28 14:53 -------- d-------- C:\DOCUME~1\Mandeep\Application Data\xfire
2007-01-28 14:11 -------- d-------- C:\Program Files\gamespy arcade
2007-01-28 13:19 -------- d---s---- C:\Program Files\xfire
2007-01-25 18:41 -------- d-------- C:\Program Files\pokerstars
2007-01-23 19:49 -------- d-------- C:\Program Files\msn messenger
2007-01-17 17:10 -------- d-------- C:\Program Files\red storm entertainment
2007-01-14 22:25 359808 --a------ C:\WINDOWS\system32\drivers\TCPIP.SYS
2007-01-10 17:25 -------- d--h----- C:\Program Files\installshield installation information
2007-01-04 20:17 -------- d-------- C:\Program Files\Common Files\drivecleaner 2006 free
2007-01-04 20:13 -------- d-------- C:\Program Files\warrock
2007-01-04 20:10 -------- d-------- C:\Program Files\war rock toolbar
2006-12-30 22:37 -------- d-------- C:\Program Files\pokerroom.com
2006-12-30 17:48 -------- d-------- C:\Program Files\pacificpoker
2006-12-27 17:05 -------- d-------- C:\Program Files\java
2006-12-24 14:24 -------- d-------- C:\DOCUME~1\Mandeep\Application Data\divx
2006-12-24 12:26 -------- d-------- C:\Program Files\divx
2006-12-18 20:04 -------- d-------- C:\Program Files\abbyy finereader 5.0 sprint
2006-12-18 20:03 -------- d-------- C:\Program Files\faxtools
2006-12-18 20:03 -------- d-------- C:\Program Files\abbyy finereader 6.0
2006-12-18 19:58 -------- d-------- C:\Program Files\lexmark 1200 series
2006-12-12 16:30 520192 --a------ C:\WINDOWS\system32\divxsm.exe
2006-12-12 16:30 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2006-12-12 16:30 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2006-12-12 16:30 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2006-12-12 16:25 806912 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2006-12-12 16:25 806912 --a------ C:\WINDOWS\system32\divx_xx07.dll
2006-12-12 16:25 790528 --a------ C:\WINDOWS\system32\divx_xx11.dll
2006-12-12 16:25 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2006-12-12 16:25 635486 --a------ C:\WINDOWS\system32\divx.dll
2006-12-12 16:25 593920 --a------ C:\WINDOWS\system32\dpugui11.dll
2006-12-12 16:25 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2006-12-12 16:25 53248 --a------ C:\WINDOWS\system32\dpugui10.dll
2006-12-12 16:25 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2006-12-12 16:25 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2006-12-12 16:25 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2006-12-12 16:25 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2006-12-12 16:24 12288 --a------ C:\WINDOWS\system32\divxwmpexttype.dll
2006-12-12 16:24 118784 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe
2006-12-11 22:11 -------- d-------- C:\Program Files\ganymedenet
2006-12-03 19:53 -------- d-------- C:\Program Files\roguespr
2006-11-08 05:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"RogueSpear.exe"="C:\\DOCUME~1\\Mandeep\\Desktop\\ROGUES~1.EXE /r"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"VSOCheckTask"="\"C:\\PROGRA~1\\McAfee.com\\VSO\\mcmnhdlr.exe\" /checktask"
"OASClnt"="C:\\Program Files\\McAfee.com\\VSO\\oasclnt.exe"
"MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe"
"MCUpdateExe"="C:\\PROGRA~1\\mcafee.com\\agent\\McUpdate.exe"
"MSKDetectorExe"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MSKDetct.exe /startup"
"MSKAGENTEXE"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MskAgent.exe"
"VirusScan Online"="C:\\Program Files\\McAfee.com\\VSO\\mcvsshld.exe"
"MPFExe"="C:\\PROGRA~1\\McAfee.com\\PERSON~1\\MpfTray.exe"
"%FP%Friendly fts.exe"="\"C:\\Program Files\\VoyagerTest\\fts.exe\""
"AOLDialer"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1139417421\\ee\\AOLSoftware.exe"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"MPSExe"="c:\\PROGRA~1\\mcafee.com\\mps\\mscifapp.exe /embedding"
"igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe"
"3dfx Tools"="rundll32.exe 3dfxCmn.dll,CMNUpdateOnBoot"
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Thomson\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"TalkTalk"="\"C:\\Program Files\\TalkTalk\\bin\\sprtcmd.exe\" /P TalkTalk"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Lexmark 1200 Series"="\"C:\\Program Files\\Lexmark 1200 Series\\lxczbmgr.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 9.0 Tray Icon.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\AOL 9.0 Tray Icon.lnk"
"backup"="C:\\WINDOWS\\pss\\AOL 9.0 Tray Icon.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\AOL9~1.0\\aoltray.exe -check"
"item"="AOL 9.0 Tray Icon"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mandeep^Start Menu^Programs^Startup^Xfire.lnk]
"path"="C:\\Documents and Settings\\Mandeep\\Start Menu\\Programs\\Startup\\Xfire.lnk"
"backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\Xfire\\Xfire.exe "
"item"="Xfire"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-Blaxx Manager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Anti-Blaxx"
"hkey"="HKLM"
"command"="C:\\Program Files\\Anti-Blaxx\\Anti-Blaxx.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DAP"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\DAP\\DAP.EXE\" /STARTUP"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RealPlay"
"hkey"="HKLM"
"command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Steam"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Steam\\Steam.exe\" -silent"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="pushow6.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"none"="C:\\Program Files\\Video ActiveX Object\\pmsngr.exe"
"Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\%s"="C:\\Program Files\\Video ActiveX Object\\isamonitor.exe"
"isamini.exe"="C:\\Program Files\\Video ActiveX Object\\isamonitor.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{919c1977-7dec-11da-8edb-009096c23cd5}]
Shell\AutoRun\command E:\setup.exe /autorun
Shell\directx\command E:\DirectX\dxsetup.exe
Shell\setup\command E:\setup.exe
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (SIDHU-Mandeep).job
Completion time: 07-01-29 18:36:20