1
Tech Clinic / Win32.Ciadoor.gn
« on: September 02, 2007, 07:36:39 PM »
The Norton Security came with my computer, the pest patrol isn't installed or I can't find it.
http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/sad.gif\' class=\'bbc_emoticon\' alt=\'
\' />
Here is the ComboFix Log
ComboFix 07-08-30.3 - "Owner" 2007-09-02 17:27:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.352 [GMT -7:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\winupdates
C:\WINDOWS\system32\bund1
C:\WINDOWS\system32\bund1\temp.txt
D:\Autorun.inf
((((((((((((((((((((((((( Files Created from 2007-08-03 to 2007-09-03 )))))))))))))))))))))))))))))))
2007-09-02 17:26 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-09-02 14:21 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-02 13:54 <DIR> d-------- C:\WINDOWS\ERUNT
2007-08-27 22:52 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Apple Computer
2007-08-27 22:51 <DIR> d-------- C:\Program Files\iTunes
2007-08-27 22:51 <DIR> d-------- C:\Program Files\iPod
2007-08-27 22:50 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-08-27 22:50 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-08-24 23:19 <DIR> d-------- C:\Program Files\Veoh Networks
2007-08-23 13:44 <DIR> d-------- C:\Program Files\Security Task Manager
2007-08-23 13:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecTaskMan
2007-08-23 11:57 <DIR> d-------- C:\Program Files\QuickTime
2007-08-17 20:17 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Uniblue
2007-08-17 19:44 77,312 --a------ C:\WINDOWS\ua2.dll
2007-08-11 11:10 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-09-02 17:30 1507872 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-09-02 16:52 23602464 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-09-02 16:47 --------- d-------- C:\Program Files\FlashGet
2007-09-02 13:51 316148 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-09-02 13:51 142124 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-08-27 22:51 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-18 11:29 --------- d-------- C:\Program Files\World of Warcraft
2007-08-17 19:52 --------- d-------- C:\Program Files\Tales Of Pirates Online
2007-08-17 19:50 --------- d-------- C:\Program Files\KRU
2007-08-14 16:19 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\IMVU
2007-08-13 00:41 --------- d-------- C:\Program Files\IMVU
2007-08-03 18:32 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\Canon
2007-07-27 13:29 --------- d-------- C:\Program Files\Common Files\Blizzard Entertainment
2007-07-26 13:48 --------- d-------- C:\Program Files\AOL Security Toolbar
2007-07-25 19:25 --------- d-------- C:\Program Files\Lavasoft
2007-07-25 19:25 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-25 19:24 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-21 12:04 --------- d-------- C:\Program Files\Lightside - Legend Ragnarok
2007-07-07 21:47 --------- d-------- C:\Program Files\EA GAMES
2007-05-30 21:11:39 88 --sh--r C:\WINDOWS\system32\4A338E9104.sys
2007-05-30 21:11:50 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 11:04]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-11-15 15:04]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-08-27 16:22]
"CHotkey"="zHotkey.exe" [2005-05-03 14:02 C:\WINDOWS\zHotkey.exe]
"SigmatelSysTrayApp"="sttray.exe" []
"IntelAudioStudio"="C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" [2005-07-20 00:55]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-04-25 10:32]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-25 10:29]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-25 10:32]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 05:19]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-03-11 16:52]
"FlashGet"="C:\Program Files\FlashGet\FlashGet.exe" [2007-07-01 21:56]
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2007-03-07 10:58]
"aol"="C:\Program Files\AOL\Active Virus Shield\avp.exe" [2006-05-30 11:13]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-02-13 11:29]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"HostManager"="C:\Program Files\Common Files\AOL\1180136869\ee\AOLSoftware.exe" [2006-09-25 17:52]
"AOLSPScheduler"="C:\Program Files\Common Files\AOL\1180136869\ee\services\safetyCore\ver210_5_4_1\AOLSP Scheduler.exe" [2007-01-25 14:34]
"sscRun"="C:\Program Files\Common Files\AOL\1180136869\ee\SSCRun.exe" [2007-01-25 14:34]
"MPFExe"="C:\Program Files\mcafee.com\personal firewall\MPfTray.exe" [2006-03-07 15:05]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-08-15 20:15]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" [2007-03-06 17:00]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-06-20 16:02]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2007-08-24 17:37]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
R1 ewido security suite driver;ewido security suite driver;\??\C:\Program Files\ewido\security suite\guard.sys
R2 Belkin Wireless USB Network Adapter Service;Belkin Wireless USB Network Adapter;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
R3 kbdcap;kbdcap;C:\WINDOWS\system32\drivers\kbdcap.sys
S2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
S2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
S3 DCamUSBNW800;CIF USB Camera (2110);C:\WINDOWS\system32\DRIVERS\pcam800.sys
S3 MR97310_USB_DUAL_CAMERA;MR97310 CIF Dual Mode Camera;C:\WINDOWS\system32\DRIVERS\mr97310c.sys
S3 scsk4;SCSK4 Driver Service;C:\WINDOWS\system32\drivers\scsk4.sys
S3 XDva011;XDva011;\??\C:\WINDOWS\system32\XDva011.sys
*Newly Created Service* - CATCHME
Contents of the 'Scheduled Tasks' folder
2006-07-09 18:00:04 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2100 series#1144519201.job - C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
2005-08-12 23:26:07 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-02 17:30:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-09-02 17:31:04
C:\ComboFix-quarantined-files.txt ... 2007-09-02 17:31
--- E O F ---
The HijackThis uninstall log:
(Main Game) Lightside - Legend Ragnarok Online
Active Virus Shield
Ad-Aware 2007
Adobe Download Manager 2.0 (Remove Only)
Adobe Photoshop Elements 3.0
Adobe Reader 7.0
Adobe Shockwave Player
AOL Instant Messenger
AOL Security Toolbar
AOL Uninstaller (Choose which Products to Remove)
Apple Mobile Device Support
Auto Macro Recorder v4.9 and Auto Macro Recorder Pro V5.1 Trial
Belkin 54g USB Network Adapter
CA Pest Patrol Realtime Protection
Camera Driver
Canon CanoScan Toolbox 4.1
ccCommon
CEP - Color Enable Package
CIF USB Camera (2110)
CIF USB Camera (2110)
Comcast High-Speed Internet Install Wizard
Comcast Toolbar
Corel Painter Essentials 2
Dark Ages 7.05
DC1500 Digital Camera
Desktop Doctor
Diablo II
Digital Media Reader
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
Easy GIF Animator 3.2
ewido security suite
FlashGet 1.9.0.1012
Granado Espada
Guild Wars
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
HP Photo and Imaging 1.0 - PSC 2000 Series
HP Photo and Imaging 1.0 - PSC 2000 Series
HP Photo and Imaging 1.0 - PSC 2000 Series Drivers
hp psc 2100 series
Intel Audio Studio
Intel® Graphics Media Accelerator Driver
Intel® PRO Network Connections Drivers
iTunes
J2SE Runtime Environment 5.0 Update 2
LimeWire 4.9.33
LiveUpdate 2.5 (Symantec Corporation)
Macromedia Flash Player 8
MAIET entertainment - Gunz
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Money 2005
Microsoft Office Standard Edition 2003
Microsoft Picture It! Premium 10
Microsoft Works
Mozilla Firefox (2.0.0.6)
MSN
MSN Messenger 7.5
MSXML 4.0 SP2 (KB927978)
Multimedia Keyboard Driver
My DSC
MyDSC_CIF
Napster Burn Engine
Nero BurnRights
Nero OEM
NetZero Internet
nik Color Efex Pro 2.0 GE
Norton Internet Security
Norton Security Center
PowerDVD
Project64 1.6
Pure Networks Port Magic
QuickTime
Ragnarok Sakray
Readiris 7.5
RealPlayer
RPG Maker 2000 1.05
RTP for RM2K (Png, Wav, Midi, Fonts)
Safety and Security Center Uninstaller
Security Task Manager 1.7e
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926247)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
SigmaTel Audio
SoftV92 Data Fax Modem with SmartCP
SPBBC
TeamSpeak 2 RC2
The Sims 2
The Sims 2 Nightlife
The Sims 2 University
Trickster Online
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB929338)
Update for Windows XP (KB931836)
VeohTV BETA
Viewpoint Media Player
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888239
WinRAR archiver
WolfRO - LLRO Patch
World of Warcraft
XoftSpy
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar
ZNRO Client 0505
\' />Here is the ComboFix Log
ComboFix 07-08-30.3 - "Owner" 2007-09-02 17:27:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.352 [GMT -7:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\winupdates
C:\WINDOWS\system32\bund1
C:\WINDOWS\system32\bund1\temp.txt
D:\Autorun.inf
((((((((((((((((((((((((( Files Created from 2007-08-03 to 2007-09-03 )))))))))))))))))))))))))))))))
2007-09-02 17:26 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-09-02 14:21 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-02 13:54 <DIR> d-------- C:\WINDOWS\ERUNT
2007-08-27 22:52 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Apple Computer
2007-08-27 22:51 <DIR> d-------- C:\Program Files\iTunes
2007-08-27 22:51 <DIR> d-------- C:\Program Files\iPod
2007-08-27 22:50 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-08-27 22:50 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-08-24 23:19 <DIR> d-------- C:\Program Files\Veoh Networks
2007-08-23 13:44 <DIR> d-------- C:\Program Files\Security Task Manager
2007-08-23 13:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecTaskMan
2007-08-23 11:57 <DIR> d-------- C:\Program Files\QuickTime
2007-08-17 20:17 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Uniblue
2007-08-17 19:44 77,312 --a------ C:\WINDOWS\ua2.dll
2007-08-11 11:10 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-09-02 17:30 1507872 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-09-02 16:52 23602464 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-09-02 16:47 --------- d-------- C:\Program Files\FlashGet
2007-09-02 13:51 316148 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-09-02 13:51 142124 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-08-27 22:51 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-18 11:29 --------- d-------- C:\Program Files\World of Warcraft
2007-08-17 19:52 --------- d-------- C:\Program Files\Tales Of Pirates Online
2007-08-17 19:50 --------- d-------- C:\Program Files\KRU
2007-08-14 16:19 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\IMVU
2007-08-13 00:41 --------- d-------- C:\Program Files\IMVU
2007-08-03 18:32 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\Canon
2007-07-27 13:29 --------- d-------- C:\Program Files\Common Files\Blizzard Entertainment
2007-07-26 13:48 --------- d-------- C:\Program Files\AOL Security Toolbar
2007-07-25 19:25 --------- d-------- C:\Program Files\Lavasoft
2007-07-25 19:25 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-25 19:24 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-21 12:04 --------- d-------- C:\Program Files\Lightside - Legend Ragnarok
2007-07-07 21:47 --------- d-------- C:\Program Files\EA GAMES
2007-05-30 21:11:39 88 --sh--r C:\WINDOWS\system32\4A338E9104.sys
2007-05-30 21:11:50 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 11:04]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-11-15 15:04]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-08-27 16:22]
"CHotkey"="zHotkey.exe" [2005-05-03 14:02 C:\WINDOWS\zHotkey.exe]
"SigmatelSysTrayApp"="sttray.exe" []
"IntelAudioStudio"="C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" [2005-07-20 00:55]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-04-25 10:32]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-25 10:29]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-25 10:32]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 05:19]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-03-11 16:52]
"FlashGet"="C:\Program Files\FlashGet\FlashGet.exe" [2007-07-01 21:56]
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2007-03-07 10:58]
"aol"="C:\Program Files\AOL\Active Virus Shield\avp.exe" [2006-05-30 11:13]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-02-13 11:29]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"HostManager"="C:\Program Files\Common Files\AOL\1180136869\ee\AOLSoftware.exe" [2006-09-25 17:52]
"AOLSPScheduler"="C:\Program Files\Common Files\AOL\1180136869\ee\services\safetyCore\ver210_5_4_1\AOLSP Scheduler.exe" [2007-01-25 14:34]
"sscRun"="C:\Program Files\Common Files\AOL\1180136869\ee\SSCRun.exe" [2007-01-25 14:34]
"MPFExe"="C:\Program Files\mcafee.com\personal firewall\MPfTray.exe" [2006-03-07 15:05]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-08-15 20:15]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" [2007-03-06 17:00]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-06-20 16:02]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2007-08-24 17:37]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
R1 ewido security suite driver;ewido security suite driver;\??\C:\Program Files\ewido\security suite\guard.sys
R2 Belkin Wireless USB Network Adapter Service;Belkin Wireless USB Network Adapter;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
R3 kbdcap;kbdcap;C:\WINDOWS\system32\drivers\kbdcap.sys
S2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
S2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
S3 DCamUSBNW800;CIF USB Camera (2110);C:\WINDOWS\system32\DRIVERS\pcam800.sys
S3 MR97310_USB_DUAL_CAMERA;MR97310 CIF Dual Mode Camera;C:\WINDOWS\system32\DRIVERS\mr97310c.sys
S3 scsk4;SCSK4 Driver Service;C:\WINDOWS\system32\drivers\scsk4.sys
S3 XDva011;XDva011;\??\C:\WINDOWS\system32\XDva011.sys
*Newly Created Service* - CATCHME
Contents of the 'Scheduled Tasks' folder
2006-07-09 18:00:04 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2100 series#1144519201.job - C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
2005-08-12 23:26:07 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-02 17:30:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-09-02 17:31:04
C:\ComboFix-quarantined-files.txt ... 2007-09-02 17:31
--- E O F ---
The HijackThis uninstall log:
(Main Game) Lightside - Legend Ragnarok Online
Active Virus Shield
Ad-Aware 2007
Adobe Download Manager 2.0 (Remove Only)
Adobe Photoshop Elements 3.0
Adobe Reader 7.0
Adobe Shockwave Player
AOL Instant Messenger
AOL Security Toolbar
AOL Uninstaller (Choose which Products to Remove)
Apple Mobile Device Support
Auto Macro Recorder v4.9 and Auto Macro Recorder Pro V5.1 Trial
Belkin 54g USB Network Adapter
CA Pest Patrol Realtime Protection
Camera Driver
Canon CanoScan Toolbox 4.1
ccCommon
CEP - Color Enable Package
CIF USB Camera (2110)
CIF USB Camera (2110)
Comcast High-Speed Internet Install Wizard
Comcast Toolbar
Corel Painter Essentials 2
Dark Ages 7.05
DC1500 Digital Camera
Desktop Doctor
Diablo II
Digital Media Reader
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
Easy GIF Animator 3.2
ewido security suite
FlashGet 1.9.0.1012
Granado Espada
Guild Wars
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
HP Photo and Imaging 1.0 - PSC 2000 Series
HP Photo and Imaging 1.0 - PSC 2000 Series
HP Photo and Imaging 1.0 - PSC 2000 Series Drivers
hp psc 2100 series
Intel Audio Studio
Intel® Graphics Media Accelerator Driver
Intel® PRO Network Connections Drivers
iTunes
J2SE Runtime Environment 5.0 Update 2
LimeWire 4.9.33
LiveUpdate 2.5 (Symantec Corporation)
Macromedia Flash Player 8
MAIET entertainment - Gunz
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Money 2005
Microsoft Office Standard Edition 2003
Microsoft Picture It! Premium 10
Microsoft Works
Mozilla Firefox (2.0.0.6)
MSN
MSN Messenger 7.5
MSXML 4.0 SP2 (KB927978)
Multimedia Keyboard Driver
My DSC
MyDSC_CIF
Napster Burn Engine
Nero BurnRights
Nero OEM
NetZero Internet
nik Color Efex Pro 2.0 GE
Norton Internet Security
Norton Security Center
PowerDVD
Project64 1.6
Pure Networks Port Magic
QuickTime
Ragnarok Sakray
Readiris 7.5
RealPlayer
RPG Maker 2000 1.05
RTP for RM2K (Png, Wav, Midi, Fonts)
Safety and Security Center Uninstaller
Security Task Manager 1.7e
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926247)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
SigmaTel Audio
SoftV92 Data Fax Modem with SmartCP
SPBBC
TeamSpeak 2 RC2
The Sims 2
The Sims 2 Nightlife
The Sims 2 University
Trickster Online
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB929338)
Update for Windows XP (KB931836)
VeohTV BETA
Viewpoint Media Player
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888239
WinRAR archiver
WolfRO - LLRO Patch
World of Warcraft
XoftSpy
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar
ZNRO Client 0505