johntk
Thanks Raktor, I have followed steps as guided, there were two optional Java downloads that the download manager couldnt connect. Otherwise all are updated now.
Below is the Combo-Fix log, please advise what I should do next.
ComboFix 09-08-10.06 - Viet Do 19/08/2009 1:03.3.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2046.1496 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Viet Do\Desktop\CFScript.txt
FILE ::
"i:\setup\Camye\fgf150.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\6404f.msi
c:\windows\Installer\67181.msi
c:\windows\Installer\676331.msi
c:\windows\Installer\737bd9.msi
c:\windows\Installer\d241b.msi
F:\autorun.inf
G:\autorun.inf
h:\program files\Advanced Searchbar
h:\program files\Advanced Searchbar\Thumbs.db
h:\program files\Advanced Searchbar\Toolbar.dll
h:\program files\Common Files\Real\Toolbar
h:\program files\Common Files\Real\Toolbar\BarControl.dll
h:\program files\Common Files\Real\Toolbar\RealBar.dll
h:\program files\MyWay
h:\program files\MyWay\myBar\1.bin\MYBAR.DLL
h:\program files\MyWay\myBar\History\search
h:\program files\MyWay\myBar\Settings\prevcfg.htm
h:\program files\MyWebSearch
h:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
h:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
h:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
h:\program files\MyWebSearch\bar\History\search
h:\program files\MyWebSearch\bar\Settings\prevcfg.htm
h:\program files\MyWebSearch\bar\Settings\settings.dat
h:\program files\MyWebSearch\bar\Settings\settings.htm
h:\program files\MyWebSearch\SrchAstt\1.bin\UNINSTAL.INF
h:\program files\MyWebSearch\SrchAstt\Cache\00027AEF
h:\program files\MyWebSearch\SrchAstt\Cache\00027E06
h:\program files\MyWebSearch\SrchAstt\Cache\0002BAD1
h:\program files\MyWebSearch\SrchAstt\Cache\files.ini
h:\recycler\NPROTECT\00031575.
h:\recycler\NPROTECT\00031604.
h:\recycler\NPROTECT\00031605.
h:\windows\Temp\Altnet
h:\windows\Temp\Altnet\Atl.dll
h:\windows\Temp\Altnet\DMinfo2.cab
h:\windows\Temp\Altnet\dminstall3.cab
h:\windows\Temp\Altnet\msvcirt.dll
h:\windows\Temp\Altnet\mysearch.cab
h:\windows\Temp\Altnet\pmexe.cab
h:\windows\Temp\Altnet\pminstall.cab
h:\windows\Temp\Altnet\Setup.cab
i:\setup\Camye\fgf150.exe
.
((((((((((((((((((((((((( Files Created from 2009-07-19 to 2009-08-19 )))))))))))))))))))))))))))))))
.
2009-08-19 04:51 . 2009-08-19 04:51 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-08-19 04:41 . 2009-08-19 04:50 ——– d—–w- c:\documents and settings\Viet Do\.SunDownloadManager
2009-08-19 04:32 . 2009-08-19 04:32 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-08-19 04:32 . 2009-08-19 04:54 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-15 20:33 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 20:33 . 2009-08-15 20:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-15 20:33 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-15 02:05 . 2009-08-15 02:05 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2009-08-15 00:00 . 2009-08-15 00:00 88191 —-a-w- c:\windows\system32\reg-list.reg
2009-08-14 23:58 . 2009-08-15 20:31 ——– d—–w- c:\program files\Quick Virus Remover
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- c:\program files\MSBuild
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- c:\program files\Reference Assemblies
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- C:\27769dca0c4095ee5aefc9ddb6fda3a0
2009-08-14 12:19 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-14 12:19 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-14 12:19 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-14 12:19 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-14 12:19 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-14 12:19 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-14 12:19 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-14 02:14 . 2009-08-14 02:14 ——– d—–w- c:\program files\ERUNT
2009-08-13 12:19 . 2009-08-13 12:19 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-08-13 03:44 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-13 03:38 . 2008-10-16 18:06 268648 —-a-w- c:\windows\system32\mucltui.dll
2009-08-13 03:38 . 2008-10-16 18:06 208744 —-a-w- c:\windows\system32\muweb.dll
2009-08-13 02:15 . 2009-08-13 02:15 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-13 02:15 . 2009-08-15 20:30 ——– d—–w- c:\documents and settings\Viet Do\Application Data\SUPERAntiSpyware.com
2009-08-13 02:15 . 2009-08-15 20:30 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-08-13 01:47 . 2009-08-13 01:47 ——– d—–w- c:\program files\Windows Defender
2009-08-13 00:19 . 2009-08-13 00:19 ——– d—–w- c:\documents and settings\Viet Do\Application Data\GetRightToGo
2009-08-12 05:06 . 2009-08-12 05:06 ——– d—–w- c:\program files\Microsoft Works
2009-08-12 05:05 . 2009-08-12 05:05 ——– d—–w- c:\program files\Microsoft.NET
2009-08-12 05:03 . 2009-08-12 05:03 ——– d—–w- c:\documents and settings\Viet Do\Local Settings\Application Data\Microsoft Help
2009-08-12 05:03 . 2009-08-13 12:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-12 05:03 . 2009-08-12 05:03 ——– d–h–r- C:\MSOCache
2009-08-12 04:00 . 2009-08-12 04:00 1152 —-a-w- c:\windows\system32\windrv.sys
2009-08-12 02:47 . 2009-08-12 02:47 ——– d—–w- c:\documents and settings\Viet Do\Application Data\Malwarebytes
2009-08-12 02:47 . 2009-08-12 02:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-11 01:14 . 2009-08-11 01:14 ——– d—–w- c:\documents and settings\Viet Do\Application Data\M-HTOEFL
2009-08-11 01:14 . 2009-08-11 01:14 ——– d—–w- c:\program files\TOEFL Official Guide
2009-08-07 19:44 . 2009-08-07 19:44 1961720 —-a-w- c:\documents and settings\Viet Do\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c—-w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-04 00:55 . 2009-08-04 00:55 ——– d—–w- c:\program files\Common Files\IviSDK
2009-08-04 00:54 . 2006-05-08 13:55 28672 —-a-w- c:\windows\system32\hcwsched.dll
2009-08-04 00:54 . 2006-01-25 21:38 69632 —-a-w- c:\windows\system32\3DES.dll
2009-08-04 00:54 . 2006-05-08 13:54 65536 —-a-w- c:\windows\system32\dmcrypto.dll
2009-08-04 00:54 . 2009-08-04 00:55 ——– d—–w- c:\windows\system32\hauppauge
2009-08-04 00:54 . 2009-08-04 00:54 ——– d—–w- C:\MyVideos
2009-08-04 00:54 . 2008-05-29 21:00 806985 ——w- c:\windows\system32\hcwtvwnd.dll
2009-08-04 00:54 . 2008-04-22 18:53 163840 —-a-w- c:\windows\system32\hcwChDB.dll
2009-08-04 00:54 . 2008-03-26 18:54 30720 —-a-w- c:\windows\system32\hcwWinTVCI.dll
2009-08-04 00:54 . 2006-10-10 21:47 36921 —-a-w- c:\windows\system32\hcwutl32.dll
2009-08-04 00:54 . 2004-01-26 18:49 90190 —-a-w- c:\windows\system32\Bt848WST.DLL
2009-08-04 00:53 . 2003-11-07 16:45 106559 —-a-w- c:\windows\system32\hcwTVDlg.dll
2009-08-04 00:53 . 2008-05-09 01:13 294968 ——w- c:\windows\system32\hcwpnp32.dll
2009-08-04 00:53 . 2001-07-19 12:44 393216 —-a-w- c:\windows\system32\hcwsnbd9.dll
2009-08-04 00:53 . 2009-08-14 04:28 ——– d—–w- c:\program files\WinTV
2009-08-04 00:53 . 2008-03-11 21:36 106552 —-a-w- c:\windows\system32\hcwi2c32.dll
2009-08-04 00:53 . 2004-12-20 16:11 213050 —-a-w- c:\windows\system32\hcwChan.dll
2009-08-04 00:53 . 1999-04-27 20:26 11264 —-a-w- c:\windows\system32\hcwhook.dll
2009-08-04 00:52 . 2008-04-13 23:46 15232 -c–a-w- c:\windows\system32\dllcache\mpe.sys
2009-08-04 00:52 . 2008-04-13 23:46 15232 —-a-w- c:\windows\system32\drivers\MPE.sys
2009-08-04 00:50 . 2008-04-14 05:12 363520 -c–a-w- c:\windows\system32\dllcache\psisdecd.dll
2009-08-04 00:50 . 2008-04-14 05:12 363520 —-a-w- c:\windows\system32\PsisDecd.dll
2009-08-04 00:50 . 2008-04-13 23:46 11776 -c–a-w- c:\windows\system32\dllcache\bdasup.sys
2009-08-04 00:50 . 2008-04-13 23:46 11776 —-a-w- c:\windows\system32\drivers\BdaSup.sys
2009-08-04 00:41 . 2008-04-11 20:52 43008 —-a-w- c:\windows\system32\hcw72Co.dll
2009-08-04 00:41 . 2008-04-11 20:53 1208448 —-a-w- c:\windows\system32\drivers\hcw72ATV.sys
2009-08-04 00:41 . 2008-04-11 20:52 27904 —-a-w- c:\windows\system32\drivers\hcw72ADFilter.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-19 05:10 . 2008-03-17 19:03 ——– d—–w- c:\documents and settings\Viet Do\Application Data\DNA
2009-08-19 05:10 . 2008-03-17 19:03 ——– d—–w- c:\program files\DNA
2009-08-19 04:51 . 2007-06-24 11:24 ——– d—–w- c:\program files\Java
2009-08-19 04:34 . 2007-05-28 20:22 ——– d—–w- c:\program files\Common Files\Adobe
2009-08-19 04:28 . 2007-10-15 00:27 ——– d—–w- c:\program files\BitTorrent
2009-08-15 20:30 . 2007-08-24 20:36 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-08-15 01:47 . 2007-07-01 21:51 ——– d—–w- c:\documents and settings\Viet Do\Application Data\Skype
2009-08-15 00:05 . 2007-05-28 14:57 90112 —-a-w- c:\windows\DUMP7242.tmp
2009-08-14 12:39 . 2007-05-28 15:45 61648 —-a-w- c:\documents and settings\Viet Do\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-13 01:42 . 2007-08-19 10:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-13 01:05 . 2007-08-14 19:53 ——– d—–w- c:\program files\Google
2009-08-12 04:24 . 2008-01-21 21:48 ——– d—–w- c:\documents and settings\All Users\Application Data\avg7
2009-08-05 09:01 . 2004-08-04 10:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 00:55 . 2007-05-28 15:18 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-25 04:48 . 2007-05-28 22:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Autodesk
2009-07-25 04:47 . 2007-05-28 22:21 ——– d—–w- c:\program files\Common Files\Autodesk Shared
2009-07-17 19:01 . 2004-08-04 10:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 10:00 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2006-03-04 03:33 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2004-08-04 10:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 10:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 10:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 10:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 10:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 10:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2004-08-04 10:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 10:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2004-08-04 10:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-04 10:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-08-04 10:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2007-05-28 14:15 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-08-04 10:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-04 11:41 . 2009-06-04 11:41 390664 —-a-w- c:\documents and settings\Viet Do\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-06-03 19:09 . 2004-08-04 10:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2007-11-16 21:56 . 2007-09-16 17:22 88 –sha-r- c:\windows\system32\8512A362E6.sys
2007-11-16 22:00 . 2007-09-16 16:52 2516 –sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-08-17_03.04.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-19 05:09 . 2009-08-19 05:09 16384 c:\windows\temp\Perflib_Perfdata_73c.dat
+ 2009-08-19 04:32 . 2009-08-19 04:32 20480 c:\windows\Installer\77b48.msi
+ 2009-08-18 00:46 . 2009-08-18 00:46 8192 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
- 2009-08-17 03:01 . 2009-08-17 03:01 8192 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
+ 2009-08-18 00:46 . 2009-08-18 00:46 8192 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
- 2009-08-17 03:01 . 2009-08-17 03:01 8192 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
+ 2009-08-19 04:51 . 2009-08-19 04:51 149280 c:\windows\system32\javaws.exe
+ 2009-08-19 04:51 . 2009-08-19 04:51 145184 c:\windows\system32\javaw.exe
+ 2009-08-19 04:51 . 2009-08-19 04:51 145184 c:\windows\system32\java.exe
+ 2009-08-18 00:46 . 2009-08-18 00:46 442368 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
- 2009-08-17 03:01 . 2009-08-17 03:01 442368 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
+ 2009-08-18 00:46 . 2009-08-18 00:46 229376 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
- 2009-08-17 03:01 . 2009-08-17 03:01 229376 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
+ 2009-08-18 00:46 . 2009-08-18 00:46 229376 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
- 2009-08-17 03:01 . 2009-08-17 03:01 229376 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
+ 2009-08-19 04:35 . 2009-08-19 04:35 3938816 c:\windows\Installer\77b52.msi
+ 2009-08-19 04:51 . 2009-08-19 04:51 1757696 c:\windows\Installer\1aca1d.msi
- 2009-08-17 03:01 . 2009-08-17 03:01 11296768 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT
+ 2009-08-18 00:46 . 2009-08-18 00:46 11296768 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-19 342848]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 856064]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 376912]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-19 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-24 185896]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2007-10-16 585728]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTorrent_DNA\\dna.exe"=
"c:\\Program Files\\@Last Software\\SketchUp 4\\SketchUp.exe"=
"c:\\Program Files\\Autodesk\\VIZ2008\\3dsviz.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\SonicWALL\\SonicWALL Global VPN Client\\SWGVpnClient.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2008\\3dsmax.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [09/05/2009 12:43 57320]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [09/05/2009 12:43 238952]
R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [20/03/2008 13:00 101528]
R2 mi-raysat_VIZ2008_32;mental ray 3.5 Satellite for Autodesk VIZ 2008;c:\program files\Autodesk\VIZ2008\mentalray\satellite\raysat_VIZ2008_32server.exe [07/03/2007 11:32 65536]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [04/06/2009 23:05 648424]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
S3 hcw72ADFilter;WinTV HVR-950 USB Audio Filter Driver;c:\windows\system32\drivers\hcw72ADFilter.sys [03/08/2009 20:41 27904]
S3 hcw72ATV;WinTV HVR-950 NTSC;c:\windows\system32\drivers\hcw72ATV.sys [03/08/2009 20:41 1208448]
S3 hcw72DTV;WinTV HVR-950 ATSC/QAM;c:\windows\system32\drivers\hcw72DTV.sys [08/07/2008 18:41 1200768]
S3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [20/03/2008 13:00 24876]
.
Contents of the 'Scheduled Tasks' folder
2009-05-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-08-19 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-19 01:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1024)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(7608)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
c:\program files\Trusteer\Rapport\bin\rooksbas.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Virgin Broadband Wireless\AffinegyService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
c:\program files\Common Files\Protexis\License Service\PSIService.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Trusteer\Rapport\bin\RapportService.exe
c:\windows\system32\wscntfy.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-08-19 1:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-19 05:19
ComboFix2.txt 2009-08-18 00:58
ComboFix3.txt 2009-08-17 03:14
Pre-Run: 41,380,044,800 bytes free
Post-Run: 41,428,770,816 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
361 — E O F — 2009-08-16 07:00
Below is the Combo-Fix log, please advise what I should do next.
ComboFix 09-08-10.06 - Viet Do 19/08/2009 1:03.3.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2046.1496 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Viet Do\Desktop\CFScript.txt
FILE ::
"i:\setup\Camye\fgf150.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\6404f.msi
c:\windows\Installer\67181.msi
c:\windows\Installer\676331.msi
c:\windows\Installer\737bd9.msi
c:\windows\Installer\d241b.msi
F:\autorun.inf
G:\autorun.inf
h:\program files\Advanced Searchbar
h:\program files\Advanced Searchbar\Thumbs.db
h:\program files\Advanced Searchbar\Toolbar.dll
h:\program files\Common Files\Real\Toolbar
h:\program files\Common Files\Real\Toolbar\BarControl.dll
h:\program files\Common Files\Real\Toolbar\RealBar.dll
h:\program files\MyWay
h:\program files\MyWay\myBar\1.bin\MYBAR.DLL
h:\program files\MyWay\myBar\History\search
h:\program files\MyWay\myBar\Settings\prevcfg.htm
h:\program files\MyWebSearch
h:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
h:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
h:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
h:\program files\MyWebSearch\bar\History\search
h:\program files\MyWebSearch\bar\Settings\prevcfg.htm
h:\program files\MyWebSearch\bar\Settings\settings.dat
h:\program files\MyWebSearch\bar\Settings\settings.htm
h:\program files\MyWebSearch\SrchAstt\1.bin\UNINSTAL.INF
h:\program files\MyWebSearch\SrchAstt\Cache\00027AEF
h:\program files\MyWebSearch\SrchAstt\Cache\00027E06
h:\program files\MyWebSearch\SrchAstt\Cache\0002BAD1
h:\program files\MyWebSearch\SrchAstt\Cache\files.ini
h:\recycler\NPROTECT\00031575.
h:\recycler\NPROTECT\00031604.
h:\recycler\NPROTECT\00031605.
h:\windows\Temp\Altnet
h:\windows\Temp\Altnet\Atl.dll
h:\windows\Temp\Altnet\DMinfo2.cab
h:\windows\Temp\Altnet\dminstall3.cab
h:\windows\Temp\Altnet\msvcirt.dll
h:\windows\Temp\Altnet\mysearch.cab
h:\windows\Temp\Altnet\pmexe.cab
h:\windows\Temp\Altnet\pminstall.cab
h:\windows\Temp\Altnet\Setup.cab
i:\setup\Camye\fgf150.exe
.
((((((((((((((((((((((((( Files Created from 2009-07-19 to 2009-08-19 )))))))))))))))))))))))))))))))
.
2009-08-19 04:51 . 2009-08-19 04:51 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-08-19 04:41 . 2009-08-19 04:50 ——– d—–w- c:\documents and settings\Viet Do\.SunDownloadManager
2009-08-19 04:32 . 2009-08-19 04:32 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-08-19 04:32 . 2009-08-19 04:54 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-15 20:33 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 20:33 . 2009-08-15 20:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-15 20:33 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-15 02:05 . 2009-08-15 02:05 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2009-08-15 00:00 . 2009-08-15 00:00 88191 —-a-w- c:\windows\system32\reg-list.reg
2009-08-14 23:58 . 2009-08-15 20:31 ——– d—–w- c:\program files\Quick Virus Remover
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- c:\program files\MSBuild
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- c:\program files\Reference Assemblies
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- C:\27769dca0c4095ee5aefc9ddb6fda3a0
2009-08-14 12:19 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-14 12:19 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-14 12:19 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-14 12:19 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-14 12:19 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-14 12:19 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-14 12:19 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-14 02:14 . 2009-08-14 02:14 ——– d—–w- c:\program files\ERUNT
2009-08-13 12:19 . 2009-08-13 12:19 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-08-13 03:44 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-13 03:38 . 2008-10-16 18:06 268648 —-a-w- c:\windows\system32\mucltui.dll
2009-08-13 03:38 . 2008-10-16 18:06 208744 —-a-w- c:\windows\system32\muweb.dll
2009-08-13 02:15 . 2009-08-13 02:15 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-13 02:15 . 2009-08-15 20:30 ——– d—–w- c:\documents and settings\Viet Do\Application Data\SUPERAntiSpyware.com
2009-08-13 02:15 . 2009-08-15 20:30 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-08-13 01:47 . 2009-08-13 01:47 ——– d—–w- c:\program files\Windows Defender
2009-08-13 00:19 . 2009-08-13 00:19 ——– d—–w- c:\documents and settings\Viet Do\Application Data\GetRightToGo
2009-08-12 05:06 . 2009-08-12 05:06 ——– d—–w- c:\program files\Microsoft Works
2009-08-12 05:05 . 2009-08-12 05:05 ——– d—–w- c:\program files\Microsoft.NET
2009-08-12 05:03 . 2009-08-12 05:03 ——– d—–w- c:\documents and settings\Viet Do\Local Settings\Application Data\Microsoft Help
2009-08-12 05:03 . 2009-08-13 12:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-12 05:03 . 2009-08-12 05:03 ——– d–h–r- C:\MSOCache
2009-08-12 04:00 . 2009-08-12 04:00 1152 —-a-w- c:\windows\system32\windrv.sys
2009-08-12 02:47 . 2009-08-12 02:47 ——– d—–w- c:\documents and settings\Viet Do\Application Data\Malwarebytes
2009-08-12 02:47 . 2009-08-12 02:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-11 01:14 . 2009-08-11 01:14 ——– d—–w- c:\documents and settings\Viet Do\Application Data\M-HTOEFL
2009-08-11 01:14 . 2009-08-11 01:14 ——– d—–w- c:\program files\TOEFL Official Guide
2009-08-07 19:44 . 2009-08-07 19:44 1961720 —-a-w- c:\documents and settings\Viet Do\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c—-w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-04 00:55 . 2009-08-04 00:55 ——– d—–w- c:\program files\Common Files\IviSDK
2009-08-04 00:54 . 2006-05-08 13:55 28672 —-a-w- c:\windows\system32\hcwsched.dll
2009-08-04 00:54 . 2006-01-25 21:38 69632 —-a-w- c:\windows\system32\3DES.dll
2009-08-04 00:54 . 2006-05-08 13:54 65536 —-a-w- c:\windows\system32\dmcrypto.dll
2009-08-04 00:54 . 2009-08-04 00:55 ——– d—–w- c:\windows\system32\hauppauge
2009-08-04 00:54 . 2009-08-04 00:54 ——– d—–w- C:\MyVideos
2009-08-04 00:54 . 2008-05-29 21:00 806985 ——w- c:\windows\system32\hcwtvwnd.dll
2009-08-04 00:54 . 2008-04-22 18:53 163840 —-a-w- c:\windows\system32\hcwChDB.dll
2009-08-04 00:54 . 2008-03-26 18:54 30720 —-a-w- c:\windows\system32\hcwWinTVCI.dll
2009-08-04 00:54 . 2006-10-10 21:47 36921 —-a-w- c:\windows\system32\hcwutl32.dll
2009-08-04 00:54 . 2004-01-26 18:49 90190 —-a-w- c:\windows\system32\Bt848WST.DLL
2009-08-04 00:53 . 2003-11-07 16:45 106559 —-a-w- c:\windows\system32\hcwTVDlg.dll
2009-08-04 00:53 . 2008-05-09 01:13 294968 ——w- c:\windows\system32\hcwpnp32.dll
2009-08-04 00:53 . 2001-07-19 12:44 393216 —-a-w- c:\windows\system32\hcwsnbd9.dll
2009-08-04 00:53 . 2009-08-14 04:28 ——– d—–w- c:\program files\WinTV
2009-08-04 00:53 . 2008-03-11 21:36 106552 —-a-w- c:\windows\system32\hcwi2c32.dll
2009-08-04 00:53 . 2004-12-20 16:11 213050 —-a-w- c:\windows\system32\hcwChan.dll
2009-08-04 00:53 . 1999-04-27 20:26 11264 —-a-w- c:\windows\system32\hcwhook.dll
2009-08-04 00:52 . 2008-04-13 23:46 15232 -c–a-w- c:\windows\system32\dllcache\mpe.sys
2009-08-04 00:52 . 2008-04-13 23:46 15232 —-a-w- c:\windows\system32\drivers\MPE.sys
2009-08-04 00:50 . 2008-04-14 05:12 363520 -c–a-w- c:\windows\system32\dllcache\psisdecd.dll
2009-08-04 00:50 . 2008-04-14 05:12 363520 —-a-w- c:\windows\system32\PsisDecd.dll
2009-08-04 00:50 . 2008-04-13 23:46 11776 -c–a-w- c:\windows\system32\dllcache\bdasup.sys
2009-08-04 00:50 . 2008-04-13 23:46 11776 —-a-w- c:\windows\system32\drivers\BdaSup.sys
2009-08-04 00:41 . 2008-04-11 20:52 43008 —-a-w- c:\windows\system32\hcw72Co.dll
2009-08-04 00:41 . 2008-04-11 20:53 1208448 —-a-w- c:\windows\system32\drivers\hcw72ATV.sys
2009-08-04 00:41 . 2008-04-11 20:52 27904 —-a-w- c:\windows\system32\drivers\hcw72ADFilter.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-19 05:10 . 2008-03-17 19:03 ——– d—–w- c:\documents and settings\Viet Do\Application Data\DNA
2009-08-19 05:10 . 2008-03-17 19:03 ——– d—–w- c:\program files\DNA
2009-08-19 04:51 . 2007-06-24 11:24 ——– d—–w- c:\program files\Java
2009-08-19 04:34 . 2007-05-28 20:22 ——– d—–w- c:\program files\Common Files\Adobe
2009-08-19 04:28 . 2007-10-15 00:27 ——– d—–w- c:\program files\BitTorrent
2009-08-15 20:30 . 2007-08-24 20:36 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-08-15 01:47 . 2007-07-01 21:51 ——– d—–w- c:\documents and settings\Viet Do\Application Data\Skype
2009-08-15 00:05 . 2007-05-28 14:57 90112 —-a-w- c:\windows\DUMP7242.tmp
2009-08-14 12:39 . 2007-05-28 15:45 61648 —-a-w- c:\documents and settings\Viet Do\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-13 01:42 . 2007-08-19 10:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-13 01:05 . 2007-08-14 19:53 ——– d—–w- c:\program files\Google
2009-08-12 04:24 . 2008-01-21 21:48 ——– d—–w- c:\documents and settings\All Users\Application Data\avg7
2009-08-05 09:01 . 2004-08-04 10:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 00:55 . 2007-05-28 15:18 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-25 04:48 . 2007-05-28 22:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Autodesk
2009-07-25 04:47 . 2007-05-28 22:21 ——– d—–w- c:\program files\Common Files\Autodesk Shared
2009-07-17 19:01 . 2004-08-04 10:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 10:00 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2006-03-04 03:33 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2004-08-04 10:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 10:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 10:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 10:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 10:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 10:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2004-08-04 10:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 10:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2004-08-04 10:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-04 10:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-08-04 10:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2007-05-28 14:15 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-08-04 10:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-04 11:41 . 2009-06-04 11:41 390664 —-a-w- c:\documents and settings\Viet Do\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-06-03 19:09 . 2004-08-04 10:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2007-11-16 21:56 . 2007-09-16 17:22 88 –sha-r- c:\windows\system32\8512A362E6.sys
2007-11-16 22:00 . 2007-09-16 16:52 2516 –sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-08-17_03.04.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-19 05:09 . 2009-08-19 05:09 16384 c:\windows\temp\Perflib_Perfdata_73c.dat
+ 2009-08-19 04:32 . 2009-08-19 04:32 20480 c:\windows\Installer\77b48.msi
+ 2009-08-18 00:46 . 2009-08-18 00:46 8192 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
- 2009-08-17 03:01 . 2009-08-17 03:01 8192 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
+ 2009-08-18 00:46 . 2009-08-18 00:46 8192 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
- 2009-08-17 03:01 . 2009-08-17 03:01 8192 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
+ 2009-08-19 04:51 . 2009-08-19 04:51 149280 c:\windows\system32\javaws.exe
+ 2009-08-19 04:51 . 2009-08-19 04:51 145184 c:\windows\system32\javaw.exe
+ 2009-08-19 04:51 . 2009-08-19 04:51 145184 c:\windows\system32\java.exe
+ 2009-08-18 00:46 . 2009-08-18 00:46 442368 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
- 2009-08-17 03:01 . 2009-08-17 03:01 442368 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
+ 2009-08-18 00:46 . 2009-08-18 00:46 229376 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
- 2009-08-17 03:01 . 2009-08-17 03:01 229376 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
+ 2009-08-18 00:46 . 2009-08-18 00:46 229376 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
- 2009-08-17 03:01 . 2009-08-17 03:01 229376 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
+ 2009-08-19 04:35 . 2009-08-19 04:35 3938816 c:\windows\Installer\77b52.msi
+ 2009-08-19 04:51 . 2009-08-19 04:51 1757696 c:\windows\Installer\1aca1d.msi
- 2009-08-17 03:01 . 2009-08-17 03:01 11296768 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT
+ 2009-08-18 00:46 . 2009-08-18 00:46 11296768 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-19 342848]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 856064]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 376912]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-19 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-24 185896]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2007-10-16 585728]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTorrent_DNA\\dna.exe"=
"c:\\Program Files\\@Last Software\\SketchUp 4\\SketchUp.exe"=
"c:\\Program Files\\Autodesk\\VIZ2008\\3dsviz.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\SonicWALL\\SonicWALL Global VPN Client\\SWGVpnClient.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2008\\3dsmax.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [09/05/2009 12:43 57320]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [09/05/2009 12:43 238952]
R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [20/03/2008 13:00 101528]
R2 mi-raysat_VIZ2008_32;mental ray 3.5 Satellite for Autodesk VIZ 2008;c:\program files\Autodesk\VIZ2008\mentalray\satellite\raysat_VIZ2008_32server.exe [07/03/2007 11:32 65536]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [04/06/2009 23:05 648424]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
S3 hcw72ADFilter;WinTV HVR-950 USB Audio Filter Driver;c:\windows\system32\drivers\hcw72ADFilter.sys [03/08/2009 20:41 27904]
S3 hcw72ATV;WinTV HVR-950 NTSC;c:\windows\system32\drivers\hcw72ATV.sys [03/08/2009 20:41 1208448]
S3 hcw72DTV;WinTV HVR-950 ATSC/QAM;c:\windows\system32\drivers\hcw72DTV.sys [08/07/2008 18:41 1200768]
S3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [20/03/2008 13:00 24876]
.
Contents of the 'Scheduled Tasks' folder
2009-05-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-08-19 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-19 01:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1024)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(7608)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
c:\program files\Trusteer\Rapport\bin\rooksbas.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Virgin Broadband Wireless\AffinegyService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
c:\program files\Common Files\Protexis\License Service\PSIService.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Trusteer\Rapport\bin\RapportService.exe
c:\windows\system32\wscntfy.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-08-19 1:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-19 05:19
ComboFix2.txt 2009-08-18 00:58
ComboFix3.txt 2009-08-17 03:14
Pre-Run: 41,380,044,800 bytes free
Post-Run: 41,428,770,816 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
361 — E O F — 2009-08-16 07:00