Virscan showed no infection in any of those 4 files.
ComboFix 09-06-10.02 - OZSA 06/11/2009 19:53.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1467 [GMT 3:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\OZSA\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090610-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\documents and settings\OZSA\Start Menu\Programs\Startup\rncsys32.exe"
"c:\windows\pss\rncsys32.exeStartup"
"c:\windows\system32\drivers\4512ae5.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_4512ae5
((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 )))))))))))))))))))))))))))))))
.
2009-06-11 14:30 . 2009-06-11 14:31 ——– d—–w- c:\windows\Internet Logs
2009-06-11 00:38 . 2009-06-11 00:38 152576 —-a-w- c:\documents and settings\OZSA\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-10 16:14 . 2009-06-10 16:16 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-06-10 16:14 . 2009-06-10 16:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-10 16:09 . 2009-06-10 16:09 ——– d—–w- c:\documents and settings\OZSA\Local Settings\Application Data\GHISLER
2009-06-10 15:59 . 2009-06-10 16:07 ——– d—–w- c:\program files\Safer Networking
2009-06-10 15:23 . 2009-06-10 15:46 195360 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-10 15:23 . 2009-06-10 15:46 15392 –sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-10 15:09 . 2009-06-10 15:43 ——– d—–w- c:\program files\Common Files\ParetoLogic
2009-06-10 15:09 . 2009-06-10 15:43 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-06-07 11:44 . 2009-06-07 11:44 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-06-07 11:36 . 2009-06-07 11:36 ——– d—–w- c:\program files\Trend Micro
2009-06-03 18:47 . 2009-06-06 12:15 ——– d—–w- c:\documents and settings\OZSA\Application Data\Microgaming
2009-06-03 18:45 . 2009-06-03 18:45 ——– d—–w- C:\MicroGaming
2009-06-03 18:35 . 2009-01-09 12:22 114688 —-a-w- c:\documents and settings\OZSA\Application Data\Mozilla\Firefox\Profiles\omhjojdq.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npfax.dll
2009-05-26 17:40 . 2009-05-26 17:40 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\NVIDIA Corporation
2009-05-26 17:40 . 2009-05-26 17:40 ——– d—–w- c:\documents and settings\OZSA\Local Settings\Application Data\NVIDIA Corporation
2009-05-26 17:39 . 2009-05-26 17:39 ——– d—–w- c:\program files\NVIDIA Corporation
2009-05-26 17:39 . 2009-05-26 17:39 ——– d—–w- c:\program files\NVIDIA nTune Performance Application
2009-05-24 16:00 . 2009-05-24 16:00 ——– d—–w- C:\Bittorent
2009-05-20 17:15 . 2009-05-20 17:29 ——– d—–w- c:\documents and settings\OZSA\Local Settings\Application Data\FullTiltPoker
2009-05-20 17:14 . 2009-06-07 18:03 ——– d—–w- c:\program files\Full Tilt Poker
2009-05-14 22:01 . 2009-05-14 22:01 73616 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-14 22:00 . 2009-05-14 22:00 ——– d—–w- c:\windows\system32\XPSViewer
2009-05-14 22:00 . 2009-05-14 22:00 ——– d—–w- c:\program files\MSBuild
2009-05-14 22:00 . 2009-05-14 22:00 ——– d—–w- c:\program files\Reference Assemblies
2009-05-14 22:00 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-05-14 22:00 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-05-14 22:00 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-05-14 22:00 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-05-14 22:00 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-05-14 22:00 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-05-14 22:00 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-05-14 21:57 . 2009-05-14 21:57 ——– d—–w- c:\program files\MSXML 6.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-11 16:56 . 2009-02-25 17:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-11 15:46 . 2009-02-25 21:04 ——– d—–w- c:\documents and settings\OZSA\Application Data\BitTorrent
2009-06-11 00:39 . 2009-03-27 19:56 ——– d—–w- c:\program files\Java
2009-06-10 15:46 . 2009-06-10 15:23 7868 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-10 15:46 . 2009-06-10 15:23 2492 –sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-10 15:44 . 2009-04-12 14:27 ——– d—–w- c:\program files\PokerStars
2009-06-07 22:51 . 2009-03-01 12:15 ——– d—–w- c:\documents and settings\OZSA\Application Data\Skype
2009-06-07 21:15 . 2009-03-01 11:36 ——– d—–w- c:\program files\Garena
2009-06-07 21:08 . 2009-03-01 12:16 ——– d—–w- c:\documents and settings\OZSA\Application Data\skypePM
2009-05-30 08:14 . 2009-03-08 22:27 ——– d—–w- c:\program files\Windows Live Safety Center
2009-05-27 09:56 . 2009-02-25 21:04 ——– d—–w- c:\documents and settings\OZSA\Application Data\uTorrent
2009-05-27 09:24 . 2009-03-15 21:48 ——– d—–w- c:\program files\DC++
2009-05-26 17:45 . 2009-04-25 13:12 ——– d—–w- c:\program files\Pando Networks
2009-05-26 17:44 . 2009-02-25 17:06 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-26 17:39 . 2009-02-25 17:06 ——– d—–w- c:\program files\Common Files\InstallShield
2009-05-26 17:27 . 2009-02-25 16:35 17216 —-a-w- c:\documents and settings\OZSA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-21 08:33 . 2009-03-01 11:59 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-20 21:37 . 2009-04-14 17:24 ——– d—–w- c:\program files\Xvid
2009-05-20 18:40 . 2009-02-28 23:14 ——– d—–w- c:\program files\PartyGaming
2009-05-08 17:15 . 2009-05-07 15:04 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-05-08 15:35 . 2009-05-08 15:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Insight Software Solutions
2009-05-08 15:35 . 2009-05-08 15:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Insight Software
2009-05-07 15:06 . 2009-05-07 15:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard
2009-04-30 15:03 . 2009-04-30 14:58 ——– d—–w- c:\program files\ICQ6.5
2009-04-30 15:03 . 2009-04-30 14:59 ——– d—–w- c:\documents and settings\OZSA\Application Data\ICQ
2009-04-25 17:22 . 2009-04-25 17:22 ——– d—–w- c:\program files\Subagames
2009-04-25 10:59 . 2009-04-25 10:18 ——– d—–w- c:\program files\CyberLink
2009-04-25 10:40 . 2009-04-25 10:21 ——– d—–w- c:\documents and settings\All Users\Application Data\CyberLink
2009-04-25 10:40 . 2009-04-25 10:19 ——– d—–w- c:\documents and settings\OZSA\Application Data\CyberLink
2009-04-25 10:39 . 2009-04-25 10:20 29480 —-a-w- c:\windows\system32\msxml3a.dll
2009-04-14 17:13 . 2009-04-14 17:13 ——– d—–w- c:\program files\AC3Filter
2009-04-13 12:08 . 2009-02-25 20:15 ——– d—–w- c:\program files\Winamp
2009-03-30 17:48 . 2009-03-30 17:48 34 —ha-w- c:\windows\system32\VideoConverter_sysquict.dat
2009-03-27 19:56 . 2009-03-27 19:56 152576 —-a-w- c:\documents and settings\OZSA\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-26 20:46 . 2009-03-26 20:46 10368 —-a-w- c:\windows\system32\drivers\pfc.sys
2004-03-11 10:27 . 2009-04-25 10:18 40960 —-a-w- c:\program files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-06-11_15.45.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-11 15:48 . 2009-06-11 15:48 16384 c:\windows\Temp\Perflib_Perfdata_5a8.dat
+ 2009-06-11 16:55 . 2009-06-11 16:55 16384 c:\windows\Temp\Perflib_Perfdata_59c.dat
+ 2009-06-11 16:56 . 2009-06-11 16:56 16384 c:\windows\Temp\Perflib_Perfdata_3d0.dat
+ 2004-08-04 01:07 . 2009-06-11 15:52 67516 c:\windows\system32\perfc009.dat
- 2004-08-04 01:07 . 2009-06-11 14:01 67516 c:\windows\system32\perfc009.dat
+ 2004-08-04 01:07 . 2009-06-11 15:52 432686 c:\windows\system32\perfh009.dat
- 2004-08-04 01:07 . 2009-06-11 14:01 432686 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 4662776]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Fraps"="c:\fraps\FRAPS.EXE" [2008-01-14 3182248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-06-13 16871936]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-06-28 1626112]
[HKLM\~\startupfolder\c:^documents and settings^ozsa^start menu^programs^startup^rncsys32.exe]
path=c:\documents and settings\OZSA\Start Menu\Programs\Startup\rncsys32.exe
backup=c:\windows\pss\rncsys32.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"d:\\firefox dl\\utorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2/25/2009 8:23 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/25/2009 8:23 PM 20560]
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-11 19:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(1848)
c:\windows\system32\msi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-11 19:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-11 16:59
ComboFix2.txt 2009-06-11 15:53
ComboFix3.txt 2009-06-11 15:47
Pre-Run: 4,918,304,768 bytes free
Post-Run: 4,889,604,096 bytes free
186