Ok, here it is, sorry it took a while, I read the post, got the program, then completely forgot about it
"raven3961" - 07-05-02 11:19:44 Service Pack 2
ComboFix 07-04-28.V - Running from: "Area 51? =P"
/wow section not completed
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\osbvsbti.dll
C:\WINDOWS\system32\tjffrcyb.dll
C:\WINDOWS\system32\tqkmfytk.dll
C:\WINDOWS\system32\xoxefjxh.dll
C:\WINDOWS\system32\ylrtaaee.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\14_43260.dll
C:\WINDOWS\system32\28_83260.dll
C:\Program Files\msmovies\p.zip
C:\Program Files\winupdates\a.zip
C:\WINDOWS\system32\nvs2.inf
C:\Program Files\msmovies
C:\Program Files\winupdates
C:\WINDOWS\system32\drivers\sfsync02.sys
C:\WINDOWS\system32\nvzrbgi_navps.dat
C:\WINDOWS\system32\nvzrbgi.exe
C:\WINDOWS\system32\nvzrbgi.dat
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
-------\sfsync02
((((((((((((((((((((((((((((((( Files Created from 2007-04-02 to 2007-05-02 ))))))))))))))))))))))))))))))))))
2007-05-02 11:24 0 --a------ C:\WINDOWS\SYSTEM32\sfsync02.dll
2007-04-30 23:16 <DIR> d-------- C:\VundoFix Backups
2007-04-30 22:56 284,244 ---hs---- C:\WINDOWS\SYSTEM32\vtsqo.dll
2007-04-30 22:45 <DIR> d-------- C:\Program Files\CCleaner
2007-04-26 21:54 <DIR> d-------- C:\Program Files\WinAVIVideoConverter
2007-04-26 16:39 939,829 ---hs---- C:\WINDOWS\SYSTEM32\qqstv.ini2
2007-04-25 05:32 <DIR> d-------- C:\Program Files\MDM
2007-04-25 05:25 581,632 --a------ C:\kjhgc.exe
2007-04-25 05:08 <DIR> d-------- C:\Install
2007-04-25 05:05 256 ---hs---- C:\SYSJR22.SYS
2007-04-25 05:03 <DIR> d-------- C:\New Folder (2)
2007-04-25 04:58 29,184 --a------ C:\WINDOWS\SYSTEM32\jesterrun.dll
2007-04-25 04:55 <DIR> d-------- C:\Program Files\FlashJester
2007-04-25 04:40 1,236,540 --a------ C:\Interface.exe
2007-04-25 04:37 <DIR> d-------- C:\Program Files\Screenweaver 3 OS
2007-04-25 04:33 86,016 --a------ C:\ncstart.exe
2007-04-25 04:33 1,731,960 --a------ C:\ChatRoom.exe
2007-04-25 04:25 <DIR> d-------- C:\Program Files\Goldshell
2007-04-25 04:19 21,504 --a------ C:\WINDOWS\jestertb.dll
2007-04-25 03:41 <DIR> d-------- C:\DOCUME~1\-Raven-\APPLIC~1\Axialis
2007-04-23 02:38 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2007-04-22 19:10 57,344 --a------ C:\WINDOWS\SYSTEM32\WNASPINT.DLL
2007-04-22 12:18 262,144 --a------ C:\WINDOWS\SYSTEM32\default_user_class.dat
2007-04-22 00:28 <DIR> d-------- C:\Program Files\Dance eJay 2.0 Demo
2007-04-22 00:27 <DIR> d-------- C:\DOCUME~1\-Raven-\APPLIC~1\GetRightToGo
2007-04-21 22:10 <DIR> d-------- C:\DOCUME~1\-Raven-\APPLIC~1\Ahead
2007-04-21 22:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Nero
2007-04-21 22:00 <DIR> d-------- C:\New Folder
2007-04-20 18:08 <DIR> d-------- C:\Program Files\The Creative Assembly
2007-04-20 10:51 248,988 --a------ C:\WINDOWS\SYSTEM32\nvzrbgi_nav.dat
2007-04-13 08:13 0 --a------ C:\WINDOWS\nsreg.dat
2007-04-10 19:22 796,672 --a------ C:\WINDOWS\GPInstall.exe
2007-04-10 15:10 111,227 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\dump_wmimmc.sys
2007-04-07 10:55 <DIR> d-------- C:\Program Files\HHVcdV7Sys
2007-04-06 03:00 <DIR> d-------- C:\WINDOWS\PixArt
2007-04-06 03:00 <DIR> d-------- C:\Program Files\PC Camera
2007-04-06 03:00 <DIR> d-------- C:\Program Files\Common Files\PCCamera
2007-04-04 23:48 53,248 --a------ C:\WINDOWS\SYSTEM32\PAStiSvc.exe
2007-04-03 05:19 <DIR> d-------- C:\Program Files\MsoSetup
2007-04-02 11:21 <DIR> d-------- C:\DOCUME~1\-Raven-\APPLIC~1\Caphyon
2007-04-02 11:20 <DIR> d-------- C:\Program Files\Caphyon
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-02 11:19 -------- d-------- C:\DOCUME~1\-Raven-\APPLIC~1\azureus
2007-05-02 11:15 -------- d-------- C:\DOCUME~1\-Raven-\APPLIC~1\xfire
2007-04-30 23:57 -------- d---s---- C:\Program Files\xfire
2007-04-30 22:22 -------- d-------- C:\DOCUME~1\-Raven-\APPLIC~1\limewire
2007-04-27 23:17 -------- d-------- C:\Program Files\gamespy arcade
2007-04-25 05:13 -------- d--h----- C:\Program Files\installshield installation information
2007-04-22 00:28 -------- d-------- C:\DOCUME~1\-Raven-\APPLIC~1\getrighttogo
2007-04-21 22:01 -------- d-------- C:\Program Files\sony setup
2007-04-21 20:57 -------- d-------- C:\Program Files\tuneup utilities 2006
2007-04-21 20:50 -------- d-------- C:\Program Files\ahead
2007-04-20 18:35 286720 --a------ C:\WINDOWS\iun506.exe
2007-04-18 17:16 733824 --a------ C:\WINDOWS\SYSTEM32\aswboot.exe
2007-04-18 17:12 94552 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswmon2.sys
2007-04-18 17:12 85952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswmon.sys
2007-04-18 17:10 23416 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswRdr.sys
2007-04-18 17:09 43176 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswTdi.sys
2007-04-18 17:07 26888 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aavmker4.sys
2007-04-18 17:06 90112 --a------ C:\WINDOWS\SYSTEM32\avastss.scr
2007-04-13 11:04 5071 --a------ C:\WINDOWS\mozver.dat
2007-04-12 21:41 4212 ---h----- C:\WINDOWS\SYSTEM32\zllictbl.dat
2007-04-11 16:52 -------- d-------- C:\Program Files\yahoo!
2007-04-10 10:40 -------- d-------- C:\Program Files\steam
2007-04-10 06:52 -------- d-------- C:\Program Files\xfire plus
2007-04-10 06:51 -------- d-------- C:\Program Files\winmx
2007-04-10 06:51 -------- d-------- C:\Program Files\voicemaskpro
2007-04-10 06:51 -------- d-------- C:\Program Files\Common Files\wise installation wizard
2007-04-10 06:48 -------- d-------- C:\Program Files\shareaza
2007-04-10 06:30 -------- d-------- C:\Program Files\tortuga - pirates of the new world
2007-04-10 06:30 -------- d-------- C:\DOCUME~1\-Raven-\APPLIC~1\coreftp
2007-04-06 03:46 -------- d-------- C:\Program Files\smartftp client 2.0
2007-04-02 11:21 -------- d-------- C:\DOCUME~1\-Raven-\APPLIC~1\caphyon
2007-04-01 04:00 -------- d-------- C:\Program Files\bearshare applications
2007-04-01 03:16 -------- d-------- C:\Program Files\microsoft games
2007-03-29 01:26 -------- d-------- C:\Program Files\samp keybinds
2007-03-26 13:45 -------- d-------- C:\Program Files\azureus ultra accelerator
2007-03-26 13:45 -------- d-------- C:\Program Files\azureus speedup pro
2007-03-26 13:44 -------- d-------- C:\Program Files\webteh
2007-03-26 13:44 -------- d-------- C:\DOCUME~1\-Raven-\APPLIC~1\bsplayer
2007-03-26 01:05 646392 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sptd.sys
2007-03-21 20:56 -------- d-------- C:\Program Files\rockstar games
2007-03-21 20:37 98304 --a------ C:\WINDOWS\SYSTEM32\cmdlineext.dll
2007-03-21 13:36 -------- d-------- C:\Program Files\nvidia corporation
2007-03-21 13:36 -------- d-------- C:\Program Files\Common Files\nvidia shared
2007-03-20 19:43 -------- d-------- C:\DOCUME~1\-Raven-\APPLIC~1\xfire plus
2007-03-20 19:38 -------- d-------- C:\Program Files\teamspeak2_rc2
2007-03-18 09:34 -------- d-------- C:\Program Files\msn messenger
2007-03-18 09:34 -------- d-------- C:\Program Files\messenger plus! live
2007-03-18 09:34 -------- d-------- C:\DOCUME~1\-Raven-\APPLIC~1\screenshot sender
2007-03-17 14:53 61 --a------ C:\WINDOWS\SYSTEM32\sysvcpdrv.sys
2007-03-17 14:50 -------- d-------- C:\Program Files\blaze audio
2007-03-17 14:43 292864 --a------ C:\WINDOWS\SYSTEM32\winsrv.dll
2007-03-17 12:50 28 --a------ C:\WINDOWS\SYSTEM32\srss.dat
2007-03-16 12:15 -------- d-------- C:\Program Files\ventsrv
2007-03-16 04:01 -------- d-------- C:\DOCUME~1\-Raven-\APPLIC~1\screaming bee
2007-03-16 03:57 -------- d-------- C:\Program Files\screaming bee
2007-03-16 01:47 73216 --a------ C:\WINDOWS\st6unst.exe
2007-03-16 01:47 286720 --------- C:\WINDOWS\setup1.exe
2007-03-14 19:27 972336 --a------ C:\WINDOWS\unrecode.exe
2007-03-14 19:20 133168 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\imagesrv.sys
2007-03-14 19:20 11568 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\imagedrv.sys
2007-03-14 19:19 972336 --a------ C:\WINDOWS\unnerobackitup.exe
2007-03-14 19:19 95864 --a------ C:\WINDOWS\SYSTEM32\neroco.dll
2007-03-12 13:51 972336 --a------ C:\WINDOWS\unneromediahome.exe
2007-03-11 12:03 -------- d-------- C:\Program Files\aaresoft
2007-03-11 11:53 -------- d-------- C:\Program Files\avex
2007-03-10 07:15 -------- d-------- C:\DOCUME~1\-Raven-\APPLIC~1\motive
2007-03-10 05:53 34816 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SSHDRV5C.sys
2007-03-09 04:07 -------- dr-h----- C:\DOCUME~1\-Raven-\APPLIC~1\yahoo!
2007-03-08 20:20 -------- d-------- C:\DOCUME~1\-Raven-\APPLIC~1\coolisoseek
2007-03-08 19:25 -------- d-------- C:\Program Files\bt home hub
2007-03-08 19:25 -------- d-------- C:\Program Files\bt broadband talk softphone
2007-03-08 19:19 -------- d-------- C:\Program Files\Common Files\motive
2007-03-08 19:19 -------- d-------- C:\Program Files\btbb_wcm
2007-03-08 16:36 577536 --a------ C:\WINDOWS\SYSTEM32\user32.dll
2007-03-08 16:36 40960 --a------ C:\WINDOWS\SYSTEM32\mf3216.dll
2007-03-08 16:36 281600 --a------ C:\WINDOWS\SYSTEM32\gdi32.dll
2007-03-08 16:00 -------- d-------- C:\Program Files\coolisoseek
2007-03-08 14:47 1843584 --a------ C:\WINDOWS\SYSTEM32\win32k.sys
2007-03-05 13:55 -------- d-------- C:\Program Files\microsoft application compatibility toolkit 5
2007-03-05 01:10 147138 --a------ C:\DOCUME~1\-Raven-\APPLIC~1\cosmos prefs
2007-02-28 20:53 972336 --a------ C:\WINDOWS\unnerovision.exe
2007-02-28 15:41 972336 --a------ C:\WINDOWS\unneroshowtime.exe
2007-02-24 06:39 2318976 --a------ C:\WINDOWS\SYSTEM32\tukernel.exe
2007-02-20 13:31 2673 --a------ C:\WINDOWS\SYSTEM32\sdbackup.reg
2007-02-19 20:02 288 --a------ C:\WINDOWS\SYSTEM32\dvcstatebkp-{00000001-00000000-00000009-00001102-00000002-80611102}.dat
2007-02-19 20:02 288 --a------ C:\WINDOWS\SYSTEM32\dvcstate-{00000001-00000000-00000009-00001102-00000002-80611102}.dat
2007-02-14 01:49 2348 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-02-13 22:27 22016 --a------ C:\WINDOWS\SYSTEM32\partizan.exe
2007-02-05 21:17 185344 --a------ C:\WINDOWS\SYSTEM32\upnphost.dll
2007-02-02 00:22 58880 --a------ C:\WINDOWS\SYSTEM32\vgzcepj.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{00C6482D-C502-44C8-8409-FCE54AD9C208}"="C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll"
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"ISUSPM Startup"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"avast!"="G:\\PROGRA~1\\APPLIC~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"GSICONEXE"="gsicon.exe"
"DSLAGENTEXE"="dslagent.exe"
"NVMixerTray"="\"C:\\Program Files\\NVIDIA Corporation\\NvMixer\\NVMixerTray.exe\""
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"FreeRAM XP"="\"C:\\Program Files\\YourWare Solutions\\FreeRAM XP Pro\\FreeRAM XP Pro.exe\" -win"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"=dword:00000001
"StartMenuLogOff"=dword:00000001
"NoSaveSettings"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"{e57ce738-33e8-4c51-8354-bb4de9d215d1}"="C:\WINDOWS\system32\upnpui.dll"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winclk32
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"FreeRAM XP"="\"C:\\Program Files\\YourWare Solutions\\FreeRAM XP Pro\\FreeRAM XP Pro.exe\" -win"
"eyeBeam SIP Client"="\"C:\\Program Files\\BT Broadband Talk Softphone\\BTSoftphone.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"SNPSTD2"="C:\\WINDOWS\\vsnpstd2.exe"
"VC7Player"="C:\\Program Files\\HHVcdV7Sys\\VC7Play.exe"
"New.net Startup"="rundll32 C:\\PROGRA~1\\NEWDOT~1\\NEWDOT~1.DLL,ClientStartup -s"
"TQ566808"="\"D:\\Setup.exe\""
"EPSON Stylus CX3600 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9BE.EXE /P26 \"EPSON Stylus CX3600 Series\" /O6 \"USB001\" /M \"Stylus CX3600\""
"\\\\Office\\EPSON Stylus CX3600 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9BE.EXE /P35 \"\\\\Office\\EPSON Stylus CX3600 Series\" /O6 \"USB001\" /M \"Stylus CX3600\""
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"Computer Alarm Clock"="C:\\Program Files\\Computer Alarm Clock\\cac.exe"
"LWBMOUSE"="C:\\Program Files\\PERFECT SERIES\\Optical MOUSE\\4.0\\MOUSE32A.EXE"
"Jet Detection"="\"C:\\Program Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe\""
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"CTHelper"="CTHELPER.EXE"
"KernelFaultCheck"="%systemroot%\\system32\\dumprep 0 -k"
"PWRISOVM.EXE"="C:\\Program Files\\PowerISO\\PWRISOVM.EXE"
"atwtusb"="atwtusb.exe beta"
"Motive SmartBridge"="C:\\PROGRA~1\\BTHOME~1\\Help\\SMARTB~1\\BTHelpNotifier.exe"
"StartBitsReadmeBias"="C:\\Documents and Settings\\All Users.WINDOWS\\Application Data\\Interatomstartbits\\File Mags.exe"
"btbb_wcm_McciTrayApp"="C:\\Program Files\\btbb_wcm\\McciTrayApp.exe"
"XFP: Multi-IM"="\"C:\\Program Files\\Xfire Plus\\Multi-IM\\MultiIM.exe\""
"YBrowser"="C:\\PROGRA~1\\Yahoo!\\browser\\ybrwicon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"RegisterDropHandler"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\REGIST~1.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^-Raven-^Start Menu^Programs^Startup^Adobe Gamma.lnk]
"path"="C:\\Documents and Settings\\-Raven-\\Start Menu\\Programs\\Startup\\Adobe Gamma.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^-Raven-^Start Menu^Programs^Startup^MetaCafe.lnk]
"path"="C:\\Documents and Settings\\-Raven-\\Start Menu\\Programs\\Startup\\MetaCafe.lnk"
"backup"="C:\\WINDOWS\\pss\\MetaCafe.lnkStartup"
"location"="Startup"
"command"="G:\\PROGRA~1\\Metacafe\\METACA~1.EXE /startup"
"item"="MetaCafe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~3.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\Adobe Reader Synchronizer.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Synchronizer.lnkCommon Startup"
"location"="Common Startup"
"command"="G:\\PROGRA~1\\APPLIC~1\\ACROBA~1\\Reader\\ADOBEC~1.EXE "
"item"="Adobe Reader Synchronizer"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^BT Broadband Desktop Help.lnk]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\BT Broadband Desktop Help.lnk"
"backup"="C:\\WINDOWS\\pss\\BT Broadband Desktop Help.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\BTHOME~1\\Help\\bin\\matcli.exe -boot"
"item"="BT Broadband Desktop Help"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^MetaCafe.lnk]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\MetaCafe.lnk"
"backup"="C:\\WINDOWS\\pss\\MetaCafe.lnkCommon Startup"
"location"="Common Startup"
"command"="G:\\PROGRA~1\\Metacafe\\METACA~1.EXE /startup"
"item"="MetaCafe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DSLAGENTEXE]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dslagent"
"hkey"="HKLM"
"command"="dslagent.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eSnips]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ClientGW"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\eSnips\\ClientGW.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GoogleDesktop"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Steam"
"hkey"="HKCU"
"command"="C:\\Program Files\\Steam\\Steam.exe -silent"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector v2]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="monitor"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\Ulead Systems\\AutoDetector\\monitor.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zango]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="zango"
"hkey"="HKLM"
"command"="\"c:\\program files\\zango\\zango.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zboard]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Zboard"
"hkey"="HKLM"
"command"="C:\\Program Files\\Ideazon\\ZEngine\\Zboard.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="zlclient"
"hkey"="HKLM"
"command"="\"G:\\Program Files\\Applications\\ZoneAlarm\\zlclient.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
hklm\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs*
UxTuneUp
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-05-02 11:29:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-05-02 11:31:32 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-05-02 11:31
Enjoy