lazyjr2003
Topic Starter
I recently had this happen to me my backround was blue and said Blue screen warning:spyware threat has been detected on your pc. I checked the forums and found something so heres the results and thanks a lot.
ComboFix 08-02.05.3 - valuable customer 2008-02-06 19:35:04.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2578 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\nnnmljg.dll
C:\Documents and Settings\All Users\Application Data.\gtaxsxof.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Michael\Application Data\inst.exe
C:\Documents and Settings\Michael\Application Data\ShoppingReport
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\absolute key logger.lnk
C:\WINDOWS\aconti.exe
C:\WINDOWS\aconti.ini
C:\WINDOWS\aconti.log
C:\WINDOWS\aconti.sdb
C:\WINDOWS\acontidialer.txt
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\default.htm
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\OPTIONS\CABS\_desktop.ini
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\acespy\__acelog.ndx
C:\WINDOWS\system32\acespy\systune.exe
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\nnnmljg.dll
C:\WINDOWS\system32\sysmwwod.dll
C:\WINDOWS\system32\sysogg.dll
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xqtkpadw.dll
C:\WINDOWS\xxxvideo.exe
—– BITS: Possible infected sites —–
hxxp://softworldnetwork.com
hxxp://softworldnetwork2.com
.
((((((((((((((((((((((((( Files Created from 2008-01-07 to 2008-02-07 )))))))))))))))))))))))))))))))
.
2008-02-06 19:17 . 2008-02-06 19:17 268 –ah—– C:\sqmdata16.sqm
2008-02-06 19:17 . 2008-02-06 19:17 244 –ah—– C:\sqmnoopt16.sqm
2008-02-06 19:02 . 2008-02-06 19:02 268 –ah—– C:\sqmdata15.sqm
2008-02-06 19:02 . 2008-02-06 19:02 244 –ah—– C:\sqmnoopt15.sqm
2008-02-06 18:36 . 2008-02-06 18:36 3,793,862 –a—— C:\WINDOWS\zwFqOxVylq.exe
2008-02-06 18:35 . 2008-02-06 18:46 d——– C:\WINDOWS\cblmwrrl
2008-02-06 18:35 . 2008-02-06 18:35 256,000 –a—— C:\WINDOWS\system32\apiuser32.dll
2008-02-06 18:35 . 2008-02-06 18:35 184,832 –a—— C:\WINDOWS\mfcliryx.dll
2008-02-06 18:35 . 2008-02-06 18:35 89,617 –a—— C:\WINDOWS\system32\rxjddnvj.exe
2008-02-06 18:35 . 2008-02-06 18:35 89,617 –a—— C:\WINDOWS\lelezwro.exe
2008-02-06 18:35 . 2008-02-06 18:35 58,368 –a—— C:\wpohl.exe
2008-02-06 18:35 . 2008-02-06 18:35 54,764 –a—— C:\WINDOWS\system32\jnhjkfrn
2008-02-06 18:35 . 2008-02-06 18:35 39,424 –a—— C:\WINDOWS\wpydgfwj.exe
2008-02-06 18:35 . 2008-02-06 18:35 32,768 –a—— C:\arbfikac.exe
2008-02-06 18:35 . 2008-02-06 18:35 3,584 –a—— C:\qrwkjyd.exe
2008-02-05 16:03 . 2008-02-05 16:03 d——– C:\Documents and Settings\Jason\WINDOWS
2008-02-04 17:07 . 2008-02-04 17:24 d——– C:\Program Files\Wolfenstein - Enemy Territory
2008-02-03 00:08 . 2008-02-04 20:48 d——– C:\vcs5BGEffects
2008-02-03 00:06 . 2008-02-03 00:16 d——– C:\Program Files\AV Vcs 6.0 DIAMOND
2008-02-02 21:01 . 2008-02-02 21:01 dr-h—– C:\Documents and Settings\Mike's Mom\Application Data\SecuROM
2008-02-02 12:10 . 2008-02-02 12:10 dr-h—– C:\Documents and Settings\Guest\Application Data\SecuROM
2008-02-02 00:18 . 2008-02-02 00:18 dr-h—– C:\Documents and Settings\Jason\Application Data\SecuROM
2008-01-31 20:50 . 2008-01-31 20:50 d——– C:\Program Files\RivaTuner v2.06
2008-01-31 15:10 . 2008-01-31 15:10 d——– C:\Program Files\uTorrent
2008-01-31 15:10 . 2008-02-06 15:45 d——– C:\Documents and Settings\Michael\Application Data\uTorrent
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\Common Files\Motive
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\ATT
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Documents and Settings\All Users\Application Data\Motive
2008-01-30 14:54 . 2008-01-30 14:54 268 –ah—– C:\sqmdata14.sqm
2008-01-30 14:54 . 2008-01-30 14:54 244 –ah—– C:\sqmnoopt14.sqm
2008-01-30 14:30 . 2008-01-30 14:30 d——– C:\WINDOWS\ERUNT
2008-01-30 14:26 . 2008-02-06 19:13 d——– C:\SDFix
2008-01-30 14:12 . 2008-01-30 14:12 268 –ah—– C:\sqmdata13.sqm
2008-01-30 14:12 . 2008-01-30 14:12 244 –ah—– C:\sqmnoopt13.sqm
2008-01-30 13:00 . 2008-01-30 13:00 268 –ah—– C:\sqmdata12.sqm
2008-01-30 13:00 . 2008-01-30 13:00 244 –ah—– C:\sqmnoopt12.sqm
2008-01-29 19:32 . 2008-01-29 19:32 268 –ah—– C:\sqmdata11.sqm
2008-01-29 19:32 . 2008-01-29 19:32 244 –ah—– C:\sqmnoopt11.sqm
2008-01-26 20:47 . 2008-01-26 20:47 d——– C:\Documents and Settings\Jason\.jagex_cache_32
2008-01-26 20:19 . 2008-01-26 20:19 d——– C:\Documents and Settings\Michael\Application Data\EPSON
2008-01-22 22:45 . 2008-01-27 22:05 d——– C:\Program Files\DNA
2008-01-22 22:45 . 2008-01-25 12:47 d——– C:\Documents and Settings\Michael\Application Data\BitTorrent
2008-01-21 00:59 . 2008-01-21 00:59 244 –ah—– C:\sqmnoopt10.sqm
2008-01-21 00:59 . 2008-01-21 00:59 232 –ah—– C:\sqmdata10.sqm
2008-01-17 16:13 . 2008-01-17 16:47 d——– C:\HLServer
2008-01-17 16:02 . 2008-01-17 16:46 d——– C:\Documents and Settings\Michael\Application Data\GetRightToGo
2008-01-17 14:16 . 2008-01-17 14:16 268 –ah—– C:\sqmdata09.sqm
2008-01-17 14:16 . 2008-01-17 14:16 244 –ah—– C:\sqmnoopt09.sqm
2008-01-12 13:22 . 2008-01-12 13:22 d——– C:\Documents and Settings\Mike's Mom\Application Data\Disney Interactive Studios
2008-01-09 17:30 . 2008-01-09 17:30 d——– C:\Documents and Settings\Jason\Application Data\Disney Interactive Studios
2008-01-07 23:24 . 2008-01-24 13:28 d——– C:\HammerAutosave
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-07 02:11 ——— d—–w C:\Documents and Settings\Michael\Application Data\LimeWire
2008-02-07 00:39 ——— d—–w C:\Program Files\Steam
2008-02-06 23:46 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-06 23:24 ——— d—–w C:\Program Files\HP
2008-02-06 01:14 ——— d—–w C:\Program Files\AIMTunes
2008-02-05 13:06 ——— d—–w C:\Program Files\WinTV
2008-02-03 20:54 6,776 —-a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2008-02-01 23:15 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-01 23:15 ——— d—–w C:\Program Files\Sierra
2008-01-30 22:51 ——— d—–w C:\Program Files\Real
2008-01-29 21:05 ——— d—–w C:\Documents and Settings\Michael\Application Data\Xfire
2008-01-17 23:58 ——— d—–w C:\Documents and Settings\Michael\Application Data\IGN_DLM
2008-01-07 05:34 ——— d—–w C:\Documents and Settings\Michael\Application Data\Disney Interactive Studios
2008-01-07 01:59 ——— d—–w C:\Documents and Settings\Jason\Application Data\Ahead
2007-12-31 15:21 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\DivX
2007-12-30 20:45 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\Yahoo!
2007-12-30 06:54 ——— d—–w C:\Program Files\Audacity
2007-12-26 06:55 ——— d—–w C:\Program Files\ACE-HIGH MP3 WAV WMA OGG Converter
2007-12-26 06:52 ——— d—–w C:\Program Files\MP3 Converter Simple
2007-12-23 16:24 ——— d—–w C:\Program Files\QuickTime
2007-12-22 23:37 ——— d—–w C:\Program Files\iTunes
2007-12-22 23:37 ——— d—–w C:\Program Files\iPod
2007-12-22 23:11 ——— d—–w C:\Program Files\Common Files\Download Manager
2007-12-22 02:35 ——— d—–w C:\Program Files\AV Vcs 5.0 DIAMOND
2007-12-20 01:56 ——— d—–w C:\Program Files\Illustrate
2007-12-17 01:02 ——— d—–w C:\Documents and Settings\Jason\Application Data\DivX
2007-12-14 22:17 ——— d—–w C:\Program Files\DivX
2007-12-12 01:12 ——— d—–w C:\Documents and Settings\valuable customer\Application Data\HP
2007-12-10 07:00 ——— d—–w C:\Program Files\OOBOX
2007-12-09 19:48 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Xfire
2007-12-07 21:21 ——— d—–w C:\Documents and Settings\Michael\Application Data\HP
2007-12-07 06:06 ——— d—–w C:\Documents and Settings\Jason\Application Data\Apple Computer
2007-12-07 04:08 ——— d—–w C:\Documents and Settings\Jason\Application Data\HP
2007-12-07 02:28 ——— d—–w C:\Program Files\Common Files\xing shared
2007-12-07 02:28 ——— d—–w C:\Program Files\Common Files\Real
2007-12-03 06:52 47,360 —-a-w C:\Documents and Settings\Michael\Application Data\pcouffin.sys
2007-12-03 06:43 356,352 —-a-w C:\WINDOWS\eSellerateEngine.dll
2007-10-11 03:05 22,328 —-a-w C:\Documents and Settings\Michael\Application Data\PnkBstrK.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}]
C:\Program Files\Helper\1202351811.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 17:05 143360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 16:43 4670704]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 13:57 1103480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 01:33 16132608 C:\WINDOWS\RTHDCPL.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 23:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 23:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 23:43 81920]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 17:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 17:09 842584]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 08:30 81920]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [ ]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 15:19 129536]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 23:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-06-26 12:48 509224]
"YPC"="C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe" [2005-02-11 17:14 352256]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-09-08 15:47 277296]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2007-11-06 19:09 166304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-06 18:28 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"drmsrv32"="c:\arbfikac.exe" [2008-02-06 18:35 32768]
C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]
C:\Documents and Settings\Mike's Mom\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]
C:\Documents and Settings\valuable customer\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoStart IR.lnk - C:\Program Files\WinTV\Ir.exe [2007-10-10 16:33:07 106551]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 21:44:08 257752]
Wireless Configuration Utility HW.14.lnk - C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe [2007-06-07 17:05:22 634880]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 12:11 233472]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-09-08 15:47]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 13:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-06 18:58]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-06 19:09]
R3 hcw18bda;Hauppauge WinTV 418 Driver;C:\WINDOWS\system32\drivers\hcw18bda.sys [2007-05-10 10:43]
R3 MSHUSBVideo;NX6000 Filter Driver;C:\WINDOWS\system32\Drivers\nx6000.sys [2006-08-23 16:33]
S2 RCService;RCService;"C:\Program Files\gigabyte\RCService\RCService.exe" []
S3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys []
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-09-25 17:18]
S3 HauppaugeTVServer;HauppaugeTVServer;C:\PROGRA~1\WinTV\HCWTVS~1.EXE [2007-02-20 14:11]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2007-05-04 04:40]
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2002-10-01 17:57]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-06 19:10]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\AutoRun.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-31 05:00:00 C:\WINDOWS\Tasks\!Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-01 04:00:00 C:\WINDOWS\Tasks\!smallville.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-01-31 06:01:12 C:\WINDOWS\Tasks\Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\BGRecorder.exeC -c3 -ntod -startr:Bionic_Woman_1114_2100###.mpg -qdef -limit:3660
"2008-02-07 03:38:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-01 04:06:04 C:\WINDOWS\Tasks\smallville.job"
- C:\PROGRA~1\WinTV\BGRecorder.exe8 -c12 -ntod -startr:smallville###.mpg -qdef -limit:3600
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-06 19:40:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\Program Files\Zune\ZuneNss.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\YPCSER~1.EXE
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
.
**************************************************************************
.
Completion time: 2008-02-06 19:44:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-07 03:44:30
.
2008-01-09 07:46:14 — E O F —
ComboFix 08-02.05.3 - valuable customer 2008-02-06 19:35:04.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2578 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\nnnmljg.dll
C:\Documents and Settings\All Users\Application Data.\gtaxsxof.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Michael\Application Data\inst.exe
C:\Documents and Settings\Michael\Application Data\ShoppingReport
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Michael\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Mike's Mom\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\absolute key logger.lnk
C:\WINDOWS\aconti.exe
C:\WINDOWS\aconti.ini
C:\WINDOWS\aconti.log
C:\WINDOWS\aconti.sdb
C:\WINDOWS\acontidialer.txt
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\default.htm
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\OPTIONS\CABS\_desktop.ini
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\acespy\__acelog.ndx
C:\WINDOWS\system32\acespy\systune.exe
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\nnnmljg.dll
C:\WINDOWS\system32\sysmwwod.dll
C:\WINDOWS\system32\sysogg.dll
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xqtkpadw.dll
C:\WINDOWS\xxxvideo.exe
—– BITS: Possible infected sites —–
hxxp://softworldnetwork.com
hxxp://softworldnetwork2.com
.
((((((((((((((((((((((((( Files Created from 2008-01-07 to 2008-02-07 )))))))))))))))))))))))))))))))
.
2008-02-06 19:17 . 2008-02-06 19:17 268 –ah—– C:\sqmdata16.sqm
2008-02-06 19:17 . 2008-02-06 19:17 244 –ah—– C:\sqmnoopt16.sqm
2008-02-06 19:02 . 2008-02-06 19:02 268 –ah—– C:\sqmdata15.sqm
2008-02-06 19:02 . 2008-02-06 19:02 244 –ah—– C:\sqmnoopt15.sqm
2008-02-06 18:36 . 2008-02-06 18:36 3,793,862 –a—— C:\WINDOWS\zwFqOxVylq.exe
2008-02-06 18:35 . 2008-02-06 18:46 d——– C:\WINDOWS\cblmwrrl
2008-02-06 18:35 . 2008-02-06 18:35 256,000 –a—— C:\WINDOWS\system32\apiuser32.dll
2008-02-06 18:35 . 2008-02-06 18:35 184,832 –a—— C:\WINDOWS\mfcliryx.dll
2008-02-06 18:35 . 2008-02-06 18:35 89,617 –a—— C:\WINDOWS\system32\rxjddnvj.exe
2008-02-06 18:35 . 2008-02-06 18:35 89,617 –a—— C:\WINDOWS\lelezwro.exe
2008-02-06 18:35 . 2008-02-06 18:35 58,368 –a—— C:\wpohl.exe
2008-02-06 18:35 . 2008-02-06 18:35 54,764 –a—— C:\WINDOWS\system32\jnhjkfrn
2008-02-06 18:35 . 2008-02-06 18:35 39,424 –a—— C:\WINDOWS\wpydgfwj.exe
2008-02-06 18:35 . 2008-02-06 18:35 32,768 –a—— C:\arbfikac.exe
2008-02-06 18:35 . 2008-02-06 18:35 3,584 –a—— C:\qrwkjyd.exe
2008-02-05 16:03 . 2008-02-05 16:03 d——– C:\Documents and Settings\Jason\WINDOWS
2008-02-04 17:07 . 2008-02-04 17:24 d——– C:\Program Files\Wolfenstein - Enemy Territory
2008-02-03 00:08 . 2008-02-04 20:48 d——– C:\vcs5BGEffects
2008-02-03 00:06 . 2008-02-03 00:16 d——– C:\Program Files\AV Vcs 6.0 DIAMOND
2008-02-02 21:01 . 2008-02-02 21:01 dr-h—– C:\Documents and Settings\Mike's Mom\Application Data\SecuROM
2008-02-02 12:10 . 2008-02-02 12:10 dr-h—– C:\Documents and Settings\Guest\Application Data\SecuROM
2008-02-02 00:18 . 2008-02-02 00:18 dr-h—– C:\Documents and Settings\Jason\Application Data\SecuROM
2008-01-31 20:50 . 2008-01-31 20:50 d——– C:\Program Files\RivaTuner v2.06
2008-01-31 15:10 . 2008-01-31 15:10 d——– C:\Program Files\uTorrent
2008-01-31 15:10 . 2008-02-06 15:45 d——– C:\Documents and Settings\Michael\Application Data\uTorrent
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\Common Files\Motive
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Program Files\ATT
2008-01-30 15:12 . 2008-01-30 15:12 d——– C:\Documents and Settings\All Users\Application Data\Motive
2008-01-30 14:54 . 2008-01-30 14:54 268 –ah—– C:\sqmdata14.sqm
2008-01-30 14:54 . 2008-01-30 14:54 244 –ah—– C:\sqmnoopt14.sqm
2008-01-30 14:30 . 2008-01-30 14:30 d——– C:\WINDOWS\ERUNT
2008-01-30 14:26 . 2008-02-06 19:13 d——– C:\SDFix
2008-01-30 14:12 . 2008-01-30 14:12 268 –ah—– C:\sqmdata13.sqm
2008-01-30 14:12 . 2008-01-30 14:12 244 –ah—– C:\sqmnoopt13.sqm
2008-01-30 13:00 . 2008-01-30 13:00 268 –ah—– C:\sqmdata12.sqm
2008-01-30 13:00 . 2008-01-30 13:00 244 –ah—– C:\sqmnoopt12.sqm
2008-01-29 19:32 . 2008-01-29 19:32 268 –ah—– C:\sqmdata11.sqm
2008-01-29 19:32 . 2008-01-29 19:32 244 –ah—– C:\sqmnoopt11.sqm
2008-01-26 20:47 . 2008-01-26 20:47 d——– C:\Documents and Settings\Jason\.jagex_cache_32
2008-01-26 20:19 . 2008-01-26 20:19 d——– C:\Documents and Settings\Michael\Application Data\EPSON
2008-01-22 22:45 . 2008-01-27 22:05 d——– C:\Program Files\DNA
2008-01-22 22:45 . 2008-01-25 12:47 d——– C:\Documents and Settings\Michael\Application Data\BitTorrent
2008-01-21 00:59 . 2008-01-21 00:59 244 –ah—– C:\sqmnoopt10.sqm
2008-01-21 00:59 . 2008-01-21 00:59 232 –ah—– C:\sqmdata10.sqm
2008-01-17 16:13 . 2008-01-17 16:47 d——– C:\HLServer
2008-01-17 16:02 . 2008-01-17 16:46 d——– C:\Documents and Settings\Michael\Application Data\GetRightToGo
2008-01-17 14:16 . 2008-01-17 14:16 268 –ah—– C:\sqmdata09.sqm
2008-01-17 14:16 . 2008-01-17 14:16 244 –ah—– C:\sqmnoopt09.sqm
2008-01-12 13:22 . 2008-01-12 13:22 d——– C:\Documents and Settings\Mike's Mom\Application Data\Disney Interactive Studios
2008-01-09 17:30 . 2008-01-09 17:30 d——– C:\Documents and Settings\Jason\Application Data\Disney Interactive Studios
2008-01-07 23:24 . 2008-01-24 13:28 d——– C:\HammerAutosave
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-07 02:11 ——— d—–w C:\Documents and Settings\Michael\Application Data\LimeWire
2008-02-07 00:39 ——— d—–w C:\Program Files\Steam
2008-02-06 23:46 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-06 23:24 ——— d—–w C:\Program Files\HP
2008-02-06 01:14 ——— d—–w C:\Program Files\AIMTunes
2008-02-05 13:06 ——— d—–w C:\Program Files\WinTV
2008-02-03 20:54 6,776 —-a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2008-02-01 23:15 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-01 23:15 ——— d—–w C:\Program Files\Sierra
2008-01-30 22:51 ——— d—–w C:\Program Files\Real
2008-01-29 21:05 ——— d—–w C:\Documents and Settings\Michael\Application Data\Xfire
2008-01-17 23:58 ——— d—–w C:\Documents and Settings\Michael\Application Data\IGN_DLM
2008-01-07 05:34 ——— d—–w C:\Documents and Settings\Michael\Application Data\Disney Interactive Studios
2008-01-07 01:59 ——— d—–w C:\Documents and Settings\Jason\Application Data\Ahead
2007-12-31 15:21 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\DivX
2007-12-30 20:45 ——— d—–w C:\Documents and Settings\Mike's Mom\Application Data\Yahoo!
2007-12-30 06:54 ——— d—–w C:\Program Files\Audacity
2007-12-26 06:55 ——— d—–w C:\Program Files\ACE-HIGH MP3 WAV WMA OGG Converter
2007-12-26 06:52 ——— d—–w C:\Program Files\MP3 Converter Simple
2007-12-23 16:24 ——— d—–w C:\Program Files\QuickTime
2007-12-22 23:37 ——— d—–w C:\Program Files\iTunes
2007-12-22 23:37 ——— d—–w C:\Program Files\iPod
2007-12-22 23:11 ——— d—–w C:\Program Files\Common Files\Download Manager
2007-12-22 02:35 ——— d—–w C:\Program Files\AV Vcs 5.0 DIAMOND
2007-12-20 01:56 ——— d—–w C:\Program Files\Illustrate
2007-12-17 01:02 ——— d—–w C:\Documents and Settings\Jason\Application Data\DivX
2007-12-14 22:17 ——— d—–w C:\Program Files\DivX
2007-12-12 01:12 ——— d—–w C:\Documents and Settings\valuable customer\Application Data\HP
2007-12-10 07:00 ——— d—–w C:\Program Files\OOBOX
2007-12-09 19:48 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Xfire
2007-12-07 21:21 ——— d—–w C:\Documents and Settings\Michael\Application Data\HP
2007-12-07 06:06 ——— d—–w C:\Documents and Settings\Jason\Application Data\Apple Computer
2007-12-07 04:08 ——— d—–w C:\Documents and Settings\Jason\Application Data\HP
2007-12-07 02:28 ——— d—–w C:\Program Files\Common Files\xing shared
2007-12-07 02:28 ——— d—–w C:\Program Files\Common Files\Real
2007-12-03 06:52 47,360 —-a-w C:\Documents and Settings\Michael\Application Data\pcouffin.sys
2007-12-03 06:43 356,352 —-a-w C:\WINDOWS\eSellerateEngine.dll
2007-10-11 03:05 22,328 —-a-w C:\Documents and Settings\Michael\Application Data\PnkBstrK.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}]
C:\Program Files\Helper\1202351811.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 17:05 143360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 16:43 4670704]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 13:57 1103480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 01:33 16132608 C:\WINDOWS\RTHDCPL.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 23:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 23:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 23:43 81920]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 17:08 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 17:09 842584]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 08:30 81920]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [ ]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 15:19 129536]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 23:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-06-26 12:48 509224]
"YPC"="C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe" [2005-02-11 17:14 352256]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-09-08 15:47 277296]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2007-11-06 19:09 166304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-06 18:28 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"drmsrv32"="c:\arbfikac.exe" [2008-02-06 18:35 32768]
C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]
C:\Documents and Settings\Mike's Mom\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]
C:\Documents and Settings\valuable customer\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoStart IR.lnk - C:\Program Files\WinTV\Ir.exe [2007-10-10 16:33:07 106551]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 21:44:08 257752]
Wireless Configuration Utility HW.14.lnk - C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe [2007-06-07 17:05:22 634880]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 12:11 233472]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-09-08 15:47]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 13:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-06 18:58]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-06 19:09]
R3 hcw18bda;Hauppauge WinTV 418 Driver;C:\WINDOWS\system32\drivers\hcw18bda.sys [2007-05-10 10:43]
R3 MSHUSBVideo;NX6000 Filter Driver;C:\WINDOWS\system32\Drivers\nx6000.sys [2006-08-23 16:33]
S2 RCService;RCService;"C:\Program Files\gigabyte\RCService\RCService.exe" []
S3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys []
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-09-25 17:18]
S3 HauppaugeTVServer;HauppaugeTVServer;C:\PROGRA~1\WinTV\HCWTVS~1.EXE [2007-02-20 14:11]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2007-05-04 04:40]
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2002-10-01 17:57]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-06 19:10]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\AutoRun.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-31 05:00:00 C:\WINDOWS\Tasks\!Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-02-01 04:00:00 C:\WINDOWS\Tasks\!smallville.job"
- C:\PROGRA~1\WinTV\Scheduler\StayAwake.exe
"2008-01-31 06:01:12 C:\WINDOWS\Tasks\Bionic_Woman_1114_2100.job"
- C:\PROGRA~1\WinTV\BGRecorder.exeC -c3 -ntod -startr:Bionic_Woman_1114_2100###.mpg -qdef -limit:3660
"2008-02-07 03:38:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-01 04:06:04 C:\WINDOWS\Tasks\smallville.job"
- C:\PROGRA~1\WinTV\BGRecorder.exe8 -c12 -ntod -startr:smallville###.mpg -qdef -limit:3600
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-06 19:40:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\Program Files\Zune\ZuneNss.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\YPCSER~1.EXE
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
.
**************************************************************************
.
Completion time: 2008-02-06 19:44:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-07 03:44:30
.
2008-01-09 07:46:14 — E O F —