Ok i did that, the folder is still in Program Files though but it looks like it did a full report for a change! Here is the log:
ComboFix 11-04-24.02 - User 25/04/2011 14:18:08.13.2 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1795 [GMT 1:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Steam\Steam.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-03-25 to 2011-04-25 )))))))))))))))))))))))))))))))
.
.
2011-04-24 20:17 . 2011-04-25 13:23 -------- d-----w- c:\program files\Steam
2011-04-24 17:06 . 2011-04-24 17:06 -------- d-----w- c:\documents and settings\UpdatusUser
2011-04-24 17:06 . 2011-04-24 17:06 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA
2011-04-24 17:05 . 2011-04-08 05:14 944232 ----a-w- c:\windows\system32\nvdispco3220140.dll
2011-04-24 17:05 . 2011-04-08 05:14 855656 ----a-w- c:\windows\system32\nvgenco322060.dll
2011-04-24 17:05 . 2011-04-08 05:14 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-04-24 17:05 . 2011-04-08 05:14 5210112 ----a-w- c:\windows\system32\nvcuda.dll
2011-04-24 17:05 . 2011-04-08 05:14 2770536 ----a-w- c:\windows\system32\nvcuvid.dll
2011-04-24 17:05 . 2011-04-08 05:14 2116894 ----a-w- c:\windows\system32\nvdata.bin
2011-04-24 17:05 . 2011-04-08 05:14 2074216 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-04-24 17:05 . 2011-04-08 05:14 2027008 ----a-w- c:\windows\system32\nvapi.dll
2011-04-24 17:05 . 2011-04-08 05:14 14856192 ----a-w- c:\windows\system32\nvoglnt.dll
2011-04-24 17:05 . 2011-04-08 05:14 13000704 ----a-w- c:\windows\system32\nvcompiler.dll
2011-04-24 15:40 . 2011-04-24 15:40 -------- d-----w- C:\NVIDIA
2011-04-24 13:20 . 2011-04-24 19:53 -------- d-----w- c:\program files\khwsfwle
2011-04-24 13:14 . 2004-08-04 12:00 41600 -c--a-w- c:\windows\system32\dllcache\weitekp9.dll
2011-04-24 13:14 . 2004-08-04 12:00 31232 -c--a-w- c:\windows\system32\dllcache\weitekp9.sys
2011-04-24 13:14 . 2004-08-04 12:00 9216 -c--a-w- c:\windows\system32\dllcache\wamps51.dll
2011-04-24 13:14 . 2004-08-04 12:00 76800 -c--a-w- c:\windows\system32\dllcache\wam51.dll
2011-04-24 13:14 . 2004-08-04 12:00 53248 -c--a-w- c:\windows\system32\dllcache\wamreg51.dll
2011-04-24 13:14 . 2004-08-04 12:00 73728 -c--a-w- c:\windows\system32\dllcache\w3ext.dll
2011-04-24 13:14 . 2004-08-04 12:00 5632 -c--a-w- c:\windows\system32\dllcache\w3svapi.dll
2011-04-24 13:14 . 2004-08-04 12:00 48256 -c--a-w- c:\windows\system32\dllcache\w32.dll
2011-04-24 13:14 . 2004-08-04 12:00 4608 -c--a-w- c:\windows\system32\dllcache\w3ctrs51.dll
2011-04-24 13:14 . 2004-08-04 12:00 363520 -c--a-w- c:\windows\system32\dllcache\w3svc.dll
2011-04-24 13:12 . 2004-08-04 12:00 81976 -c--a-w- c:\windows\system32\dllcache\imjpdct.dll
2011-04-24 13:11 . 2004-08-04 12:00 8192 -c--a-w- c:\windows\system32\dllcache\staxmem.dll
2011-04-24 13:10 . 2004-08-04 12:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2011-04-24 13:10 . 2004-08-04 12:00 16384 ----a-w- c:\program files\Internet Explorer\Connection Wizard\isignup.exe
2011-04-24 13:10 . 2004-08-04 12:00 8192 -c--a-w- c:\windows\system32\dllcache\bitsprx2.dll
2011-04-24 13:10 . 2004-08-04 12:00 8192 ----a-w- c:\windows\system32\bitsprx2.dll
2011-04-24 13:10 . 2004-08-04 12:00 7168 -c--a-w- c:\windows\system32\dllcache\bitsprx3.dll
2011-04-24 13:10 . 2004-08-04 12:00 7168 ----a-w- c:\windows\system32\bitsprx3.dll
2011-04-24 12:58 . 2004-08-04 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2011-04-24 12:58 . 2004-08-04 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2011-04-24 12:58 . 2004-08-04 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-04-24 12:58 . 2004-08-04 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-04-24 01:42 . 2011-04-24 01:42 -------- d-----w- C:\_OTL
2011-04-24 00:10 . 2011-04-24 00:11 -------- d-----w- c:\documents and settings\Administrator
2011-04-23 12:22 . 2011-04-23 13:15 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2011-04-23 02:56 . 2011-04-23 02:56 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-04-23 02:53 . 2011-04-23 02:54 -------- dc-h--w- c:\windows\ie8
2011-04-23 02:53 . 2011-04-23 02:53 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-04-23 02:53 . 2011-04-24 14:28 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Google
2011-04-23 02:52 . 2011-04-23 02:53 -------- d-----w- c:\program files\Google
2011-04-23 00:58 . 2011-04-24 20:21 -------- d-----w- c:\windows\system32\NtmsData
2011-04-23 00:57 . 2011-04-23 00:57 -------- d-----w- c:\documents and settings\User\Application Data\Avira
2011-04-23 00:55 . 2011-03-04 15:11 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-04-23 00:55 . 2011-03-04 13:37 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-04-23 00:55 . 2010-06-17 13:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2011-04-23 00:55 . 2010-06-17 13:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2011-04-23 00:55 . 2011-04-23 00:55 -------- d-----w- c:\program files\Avira
2011-04-23 00:55 . 2011-04-23 00:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2011-04-22 21:30 . 2011-04-23 00:48 166768 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\isuspmmgr.exe
2011-04-22 21:30 . 2011-04-23 00:48 166768 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\agentmgr.exe
2011-04-22 21:23 . 2011-04-22 21:23 -------- d-----w- c:\program files\VS Revo Group
2011-04-15 17:17 . 2011-04-15 17:17 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Trusteer
2011-04-14 22:04 . 2011-04-14 22:04 -------- d-----w- c:\program files\Spotify
2011-04-07 21:15 . 2011-04-07 21:15 81920 ----a-w- c:\windows\system32\nvwddi.dll
2011-04-07 21:15 . 2011-04-07 21:15 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-04-07 21:15 . 2011-04-07 21:15 277608 ----a-w- c:\windows\system32\nvmccs.dll
2011-04-07 21:15 . 2011-04-07 21:15 13891176 ----a-w- c:\windows\system32\nvcpl.dll
2011-04-07 21:15 . 2011-04-07 21:15 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-04-07 21:15 . 2011-04-07 21:15 155752 ----a-w- c:\windows\system32\nvsvc32.exe
2011-04-07 21:15 . 2011-04-07 21:15 145000 ----a-w- c:\windows\system32\nvcolor.exe
2011-04-06 11:23 . 2011-04-06 11:23 -------- d-----w- C:\found.000
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-08 05:14 . 2010-07-10 04:38 4111232 ----a-w- c:\windows\system32\nv4_disp.dll
2011-04-08 05:14 . 2010-07-10 04:38 12501600 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-02-17 12:32 . 2010-10-08 11:31 5120 ----a-w- c:\windows\system32\xpsp4res.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-04-24_19.50.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-12 20:45 . 2011-04-24 20:17 27648 c:\windows\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C91.exe
- 2011-01-12 20:45 . 2011-01-12 20:45 27648 c:\windows\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C91.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-04-23 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2005-12-20 155648]
"RTHDCPL"="RTHDCPL.EXE" [2006-12-19 16062464]
"NvMediaCenter"="NvMCTray.dll" [2011-04-07 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-07 13891176]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-02-24 1753192]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-02-28 44544]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2010\\fm.exe"=
"c:\\Documents and Settings\\User\\My Documents\\Age Of Empires II\\Age Of Empires II The Conquerors\\age2_x1.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\football manager 2011\\fm.exe"=
.
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [03/10/2010 23:43 59240]
S1 RapportCerberus_25973;RapportCerberus_25973;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\25973\RapportCerberus_25973.sys [13/04/2011 12:17 57144]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [03/10/2010 23:43 169320]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [23/04/2011 01:55 135336]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [27/01/2011 19:03 233472]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [23/04/2011 03:53 135664]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [24/04/2011 18:06 2218600]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [27/01/2011 19:03 36608]
S3 W35UND;IS89C35 802.11bg WLAN USB Adapter Driver;c:\windows\system32\drivers\W35UND.SYS [08/10/2010 12:18 117632]
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-23 02:53]
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-23 02:53]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Steam - c:\program files\Steam\Steam.exe
AddRemove-Steam App 34220 - c:\program files\Steam\steam.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-25 14:24
Windows 5.1.2600 Service Pack 2 NTFS
.
detected NTDLL code modification:
ZwQueryDirectoryFile
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
c:\documents and settings\User\Start Menu\Programs\Startup\skofparu.exe 166768 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-04-25 14:26:07
ComboFix-quarantined-files.txt 2011-04-25 13:26
.
Pre-Run: 424,099,659,776 bytes free
Post-Run: 424,078,569,472 bytes free
.
- - End Of File - - 50D51C92107DBF6145369E556CDC86E7
ComboFix 11-04-24.02 - User 25/04/2011 14:18:08.13.2 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1795 [GMT 1:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Steam\Steam.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-03-25 to 2011-04-25 )))))))))))))))))))))))))))))))
.
.
2011-04-24 20:17 . 2011-04-25 13:23 -------- d-----w- c:\program files\Steam
2011-04-24 17:06 . 2011-04-24 17:06 -------- d-----w- c:\documents and settings\UpdatusUser
2011-04-24 17:06 . 2011-04-24 17:06 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA
2011-04-24 17:05 . 2011-04-08 05:14 944232 ----a-w- c:\windows\system32\nvdispco3220140.dll
2011-04-24 17:05 . 2011-04-08 05:14 855656 ----a-w- c:\windows\system32\nvgenco322060.dll
2011-04-24 17:05 . 2011-04-08 05:14 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-04-24 17:05 . 2011-04-08 05:14 5210112 ----a-w- c:\windows\system32\nvcuda.dll
2011-04-24 17:05 . 2011-04-08 05:14 2770536 ----a-w- c:\windows\system32\nvcuvid.dll
2011-04-24 17:05 . 2011-04-08 05:14 2116894 ----a-w- c:\windows\system32\nvdata.bin
2011-04-24 17:05 . 2011-04-08 05:14 2074216 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-04-24 17:05 . 2011-04-08 05:14 2027008 ----a-w- c:\windows\system32\nvapi.dll
2011-04-24 17:05 . 2011-04-08 05:14 14856192 ----a-w- c:\windows\system32\nvoglnt.dll
2011-04-24 17:05 . 2011-04-08 05:14 13000704 ----a-w- c:\windows\system32\nvcompiler.dll
2011-04-24 15:40 . 2011-04-24 15:40 -------- d-----w- C:\NVIDIA
2011-04-24 13:20 . 2011-04-24 19:53 -------- d-----w- c:\program files\khwsfwle
2011-04-24 13:14 . 2004-08-04 12:00 41600 -c--a-w- c:\windows\system32\dllcache\weitekp9.dll
2011-04-24 13:14 . 2004-08-04 12:00 31232 -c--a-w- c:\windows\system32\dllcache\weitekp9.sys
2011-04-24 13:14 . 2004-08-04 12:00 9216 -c--a-w- c:\windows\system32\dllcache\wamps51.dll
2011-04-24 13:14 . 2004-08-04 12:00 76800 -c--a-w- c:\windows\system32\dllcache\wam51.dll
2011-04-24 13:14 . 2004-08-04 12:00 53248 -c--a-w- c:\windows\system32\dllcache\wamreg51.dll
2011-04-24 13:14 . 2004-08-04 12:00 73728 -c--a-w- c:\windows\system32\dllcache\w3ext.dll
2011-04-24 13:14 . 2004-08-04 12:00 5632 -c--a-w- c:\windows\system32\dllcache\w3svapi.dll
2011-04-24 13:14 . 2004-08-04 12:00 48256 -c--a-w- c:\windows\system32\dllcache\w32.dll
2011-04-24 13:14 . 2004-08-04 12:00 4608 -c--a-w- c:\windows\system32\dllcache\w3ctrs51.dll
2011-04-24 13:14 . 2004-08-04 12:00 363520 -c--a-w- c:\windows\system32\dllcache\w3svc.dll
2011-04-24 13:12 . 2004-08-04 12:00 81976 -c--a-w- c:\windows\system32\dllcache\imjpdct.dll
2011-04-24 13:11 . 2004-08-04 12:00 8192 -c--a-w- c:\windows\system32\dllcache\staxmem.dll
2011-04-24 13:10 . 2004-08-04 12:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2011-04-24 13:10 . 2004-08-04 12:00 16384 ----a-w- c:\program files\Internet Explorer\Connection Wizard\isignup.exe
2011-04-24 13:10 . 2004-08-04 12:00 8192 -c--a-w- c:\windows\system32\dllcache\bitsprx2.dll
2011-04-24 13:10 . 2004-08-04 12:00 8192 ----a-w- c:\windows\system32\bitsprx2.dll
2011-04-24 13:10 . 2004-08-04 12:00 7168 -c--a-w- c:\windows\system32\dllcache\bitsprx3.dll
2011-04-24 13:10 . 2004-08-04 12:00 7168 ----a-w- c:\windows\system32\bitsprx3.dll
2011-04-24 12:58 . 2004-08-04 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2011-04-24 12:58 . 2004-08-04 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2011-04-24 12:58 . 2004-08-04 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-04-24 12:58 . 2004-08-04 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-04-24 01:42 . 2011-04-24 01:42 -------- d-----w- C:\_OTL
2011-04-24 00:10 . 2011-04-24 00:11 -------- d-----w- c:\documents and settings\Administrator
2011-04-23 12:22 . 2011-04-23 13:15 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2011-04-23 02:56 . 2011-04-23 02:56 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-04-23 02:53 . 2011-04-23 02:54 -------- dc-h--w- c:\windows\ie8
2011-04-23 02:53 . 2011-04-23 02:53 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-04-23 02:53 . 2011-04-24 14:28 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Google
2011-04-23 02:52 . 2011-04-23 02:53 -------- d-----w- c:\program files\Google
2011-04-23 00:58 . 2011-04-24 20:21 -------- d-----w- c:\windows\system32\NtmsData
2011-04-23 00:57 . 2011-04-23 00:57 -------- d-----w- c:\documents and settings\User\Application Data\Avira
2011-04-23 00:55 . 2011-03-04 15:11 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-04-23 00:55 . 2011-03-04 13:37 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-04-23 00:55 . 2010-06-17 13:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2011-04-23 00:55 . 2010-06-17 13:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2011-04-23 00:55 . 2011-04-23 00:55 -------- d-----w- c:\program files\Avira
2011-04-23 00:55 . 2011-04-23 00:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2011-04-22 21:30 . 2011-04-23 00:48 166768 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\isuspmmgr.exe
2011-04-22 21:30 . 2011-04-23 00:48 166768 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\agentmgr.exe
2011-04-22 21:23 . 2011-04-22 21:23 -------- d-----w- c:\program files\VS Revo Group
2011-04-15 17:17 . 2011-04-15 17:17 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Trusteer
2011-04-14 22:04 . 2011-04-14 22:04 -------- d-----w- c:\program files\Spotify
2011-04-07 21:15 . 2011-04-07 21:15 81920 ----a-w- c:\windows\system32\nvwddi.dll
2011-04-07 21:15 . 2011-04-07 21:15 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-04-07 21:15 . 2011-04-07 21:15 277608 ----a-w- c:\windows\system32\nvmccs.dll
2011-04-07 21:15 . 2011-04-07 21:15 13891176 ----a-w- c:\windows\system32\nvcpl.dll
2011-04-07 21:15 . 2011-04-07 21:15 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-04-07 21:15 . 2011-04-07 21:15 155752 ----a-w- c:\windows\system32\nvsvc32.exe
2011-04-07 21:15 . 2011-04-07 21:15 145000 ----a-w- c:\windows\system32\nvcolor.exe
2011-04-06 11:23 . 2011-04-06 11:23 -------- d-----w- C:\found.000
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-08 05:14 . 2010-07-10 04:38 4111232 ----a-w- c:\windows\system32\nv4_disp.dll
2011-04-08 05:14 . 2010-07-10 04:38 12501600 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-02-17 12:32 . 2010-10-08 11:31 5120 ----a-w- c:\windows\system32\xpsp4res.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-04-24_19.50.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-12 20:45 . 2011-04-24 20:17 27648 c:\windows\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C91.exe
- 2011-01-12 20:45 . 2011-01-12 20:45 27648 c:\windows\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C91.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-04-23 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2005-12-20 155648]
"RTHDCPL"="RTHDCPL.EXE" [2006-12-19 16062464]
"NvMediaCenter"="NvMCTray.dll" [2011-04-07 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-07 13891176]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-02-24 1753192]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-02-28 44544]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2010\\fm.exe"=
"c:\\Documents and Settings\\User\\My Documents\\Age Of Empires II\\Age Of Empires II The Conquerors\\age2_x1.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\football manager 2011\\fm.exe"=
.
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [03/10/2010 23:43 59240]
S1 RapportCerberus_25973;RapportCerberus_25973;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\25973\RapportCerberus_25973.sys [13/04/2011 12:17 57144]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [03/10/2010 23:43 169320]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [23/04/2011 01:55 135336]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [27/01/2011 19:03 233472]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [23/04/2011 03:53 135664]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [24/04/2011 18:06 2218600]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [27/01/2011 19:03 36608]
S3 W35UND;IS89C35 802.11bg WLAN USB Adapter Driver;c:\windows\system32\drivers\W35UND.SYS [08/10/2010 12:18 117632]
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-23 02:53]
.
2011-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-23 02:53]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Steam - c:\program files\Steam\Steam.exe
AddRemove-Steam App 34220 - c:\program files\Steam\steam.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-25 14:24
Windows 5.1.2600 Service Pack 2 NTFS
.
detected NTDLL code modification:
ZwQueryDirectoryFile
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
c:\documents and settings\User\Start Menu\Programs\Startup\skofparu.exe 166768 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-04-25 14:26:07
ComboFix-quarantined-files.txt 2011-04-25 13:26
.
Pre-Run: 424,099,659,776 bytes free
Post-Run: 424,078,569,472 bytes free
.
- - End Of File - - 50D51C92107DBF6145369E556CDC86E7