ComboFix 07-07-30.2 - "Randy Bell" 2007-07-01 8:28:23.1 [GMT -4:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.True
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\DOWNLO~1.\temp
C:\WINDOWS\NDNuninstall4_88.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NWSAPAGENT
-------\NwSapAgent
((((((((((((((((((((((((( Files Created from 2007-06-01 to 2007-07-01 )))))))))))))))))))))))))))))))
2007-07-01 08:27 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-06-30 15:28 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2007-06-30 15:26 <DIR> d-------- C:\Program Files\MSECACHE
2007-06-30 14:32 <DIR> d-------- C:\My Music
2007-06-30 10:52 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-06-29 20:01 991,232 --a------ C:\WINDOWS\system32\esent.dll
2007-06-29 19:08 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-06-29 19:08 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-06-29 19:08 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-06-29 18:37 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-06-29 18:15 <DIR> d-------- C:\Program Files\Common Files\Viewpoint
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-29 23:14 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-06-29 20:49 --------- d-------- C:\Program Files\Messenger
2007-06-29 18:44 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-04-16 23:47 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-04-16 23:45 92504 --a--c--- C:\WINDOWS\system32\cdm.dll
2007-04-16 23:45 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-04-16 23:45 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-04-16 23:45 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-04-16 23:45 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-04-16 23:45 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-04-16 23:45 1710936 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-04-16 22:43 208248 --a------ C:\WINDOWS\system32\muweb.dll
2004-08-08 16:08 25080 -ra--c--- C:\DOCUME~1\CHRISM~1\APPLIC~1\GDIPFONTCACHEV1.DAT
2003-06-01 23:06 1435 --a--c--- C:\Program Files\INSTALL.LOG
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 nwprovau
R2 NWCWorkstation;Client Service for NetWare;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 CBEN5;Xircom CardBus Ethernet 10/100 Adapter family;C:\WINDOWS\System32\DRIVERS\cben5.sys
R3 ltmodem5;LT Modem Driver;C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys
R3 Maestro;ESS Maestro2E Audio Driver (WDM);C:\WINDOWS\System32\drivers\essm2e.sys
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver;C:\WINDOWS\System32\drivers\msmpu401.sys
R3 NWRDR;NetWare Rdr;C:\WINDOWS\System32\DRIVERS\nwrdr.sys
R3 smimini;smimini;C:\WINDOWS\System32\DRIVERS\smiminib.sys
S0 IFP300;iRiver Internet Audio Player IFP-300;C:\WINDOWS\System32\DRIVERS\ifp300.sys
S3 brfilt;Brother MFC Filter Driver;C:\WINDOWS\System32\Drivers\Brfilt.sys
S3 BrSerWDM;Brother Serial driver;C:\WINDOWS\System32\Drivers\BrSerWdm.sys
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;C:\WINDOWS\System32\Drivers\BrUsbMdm.sys
S3 BrUsbScn;Brother MFC USB Scanner driver;C:\WINDOWS\System32\Drivers\BrUsbScn.sys
S3 Ip6FwHlp;IPv6 Internet Connection Firewall;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 ISLP2;Intersil 802.11 Wireless LAN Driver;C:\WINDOWS\System32\DRIVERS\islp2nds.sys
S3 mf;mf;C:\WINDOWS\System32\DRIVERS\mf.sys
S3 NAVAP;NAVAP;\??\C:\WINDOWS\System32\Drivers\NAVAP.SYS
S3 Rio8Drv;Rio800 driver;C:\WINDOWS\System32\Drivers\Rio8Drv.sys
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\System32\DRIVERS\usbprint.sys
S3 wanatw;WAN Miniport (ATW);C:\WINDOWS\System32\DRIVERS\wanatw4.sys
S3 WPC11;Instant Wireless Network PC Card V3.0 Driver;C:\WINDOWS\System32\DRIVERS\LSWLNDS.sys
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-07-01 08:34:53
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
**************************************************************************
Completion time: 2007-07-01 8:37:51 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-01 08:36
--- E O F ---