chocokoko
Topic Starter
http://forums.whatthetech.com/Invalid_synt…tml&hl;=pos1
I had the same problem and followed your instruction. What do I do now? is my problem fixed ?
Thanks in advance.
ComboFix 08-02-25.3 - HingWah 2008-02-28 10:36:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.[removed].18.300 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\check_LSA7.txt
C:\Documents and Settings\All Users\Application Data\salesmonitor
C:\Documents and Settings\HingWah\Application Data\.rdr.ini
C:\Documents and Settings\HingWah\Application Data\APPATC~1
C:\Documents and Settings\HingWah\Application Data\DriveCleaner Freeware
C:\Documents and Settings\HingWah\Application Data\DriveCleaner Freeware\Logs\update.log
C:\Documents and Settings\HingWah\Application Data\ICROSO~1.NET
C:\Documents and Settings\HingWah\Application Data\MBOLS~1
C:\Documents and Settings\HingWah\Application Data\SpyGuardPro
C:\Documents and Settings\HingWah\Application Data\SpyGuardPro\Logs\threats.log
C:\Documents and Settings\HingWah\Application Data\SpyGuardPro\Logs\update.log
C:\Documents and Settings\HingWah\Application Data\SSTEM~1
C:\Documents and Settings\HingWah\Application Data\tmp10.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp118.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp11D.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp143.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp144.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp167.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp16C.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp1A5.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp1C.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp1C1.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp1DB1.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp21EE.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp245.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp27.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp28.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp36.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp377.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp4F.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp50.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp51.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp5B6.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp5D.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp63.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp6A7.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp70.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp72.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp7A.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp82.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp86.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmpBA8.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmpC75.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmpE.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmpEF8.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmpF.tmp.exe
C:\Documents and Settings\HingWah\Application Data\WinTouch
C:\Documents and Settings\HingWah\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\HingWah\err.log
C:\Documents and Settings\HingWah\My Documents\CURITY~1
C:\Documents and Settings\HingWah\My Documents\ECURIT~1
C:\Documents and Settings\HingWah\My Documents\MCROSO~1.NET
C:\Documents and Settings\HingWah\My Documents\STEM~1
C:\Documents and Settings\LocalService\Application Data\.rdr.ini
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\LocalService\Desktop\searchus.exe
C:\Documents and Settings\LocalService\Local Settings\Application Data\n.ini
C:\Documents and Settings\NetworkService\Desktop\searchus.exe
C:\New Folder\[星野?一]官能實驗\_desktop.ini
C:\Program Files\Common Files\SpyGuardPro
C:\Program Files\Common Files\SpyGuardPro\bm.exe
C:\Program Files\Common Files\SpyGuardPro\ugac.exe
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\inetget2
C:\Program Files\Internet Explorer\promyfsywuewu.html
C:\Program Files\livabigas89104.dll
C:\Program Files\mbols~1
C:\Program Files\network monitor
C:\Program Files\network monitor\netmon.exe
C:\Program Files\SpyGuardPro
C:\Program Files\SpyGuardPro\Activate.exe
C:\Program Files\SpyGuardPro\al.dat
C:\Program Files\SpyGuardPro\Config\pgs.xml
C:\Program Files\SpyGuardPro\Dat\Activate.dat
C:\Program Files\SpyGuardPro\Dat\BkSites.dat
C:\Program Files\SpyGuardPro\Dat\bnlink.dat
C:\Program Files\SpyGuardPro\Dat\cd.dat
C:\Program Files\SpyGuardPro\Dat\incmp.dat
C:\Program Files\SpyGuardPro\Dat\index.dat
C:\Program Files\SpyGuardPro\Dat\pv.dat
C:\Program Files\SpyGuardPro\dhlp.dll
C:\Program Files\SpyGuardPro\Engines\AWBase\database\enemies.dat
C:\Program Files\SpyGuardPro\Engines\AWBase\vbpv.dat
C:\Program Files\SpyGuardPro\Engines\PGBase\vbpv.dat
C:\Program Files\SpyGuardPro\Engines\plugins\BORLNDMM.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANADWR.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANBCDR.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANDLDR.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANDOS1.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANEMUL.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANFUNC.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANKRNL.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANMCR1.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANOTHR.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANSCR.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANTOOL.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANTROJ.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANWIN1.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UNACPU.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UNADBX.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\unamscan.dll
C:\Program Files\SpyGuardPro\Engines\plugins\UNMIME.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UNPACK.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UNPACKS.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UNPACKS2.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UNPEPACK.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UpDate\UA27601.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UpDate\UA27602.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UpDate\UA27603.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UpDate\UA27604.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UpDate\UADAILY.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\vbpv.dat
C:\Program Files\SpyGuardPro\FWSettings.bin
C:\Program Files\SpyGuardPro\Graphics\cross.gif
C:\Program Files\SpyGuardPro\Graphics\ga6p.gif
C:\Program Files\SpyGuardPro\Graphics\kb.url
C:\Program Files\SpyGuardPro\Graphics\main.ico
C:\Program Files\SpyGuardPro\Graphics\mini.ico
C:\Program Files\SpyGuardPro\Graphics\Online.url
C:\Program Files\SpyGuardPro\Graphics\rm.url
C:\Program Files\SpyGuardPro\Graphics\support.ico
C:\Program Files\SpyGuardPro\Graphics\Support.url
C:\Program Files\SpyGuardPro\Graphics\uninstall.ico
C:\Program Files\SpyGuardPro\history.db
C:\Program Files\SpyGuardPro\LA\lapv.dat
C:\Program Files\SpyGuardPro\LA\License.rtf
C:\Program Files\SpyGuardPro\main.log
C:\Program Files\SpyGuardPro\pgs.exe
C:\Program Files\SpyGuardPro\ptask.exe
C:\Program Files\SpyGuardPro\reload.exe
C:\Program Files\SpyGuardPro\ResErrors.log
C:\Program Files\SpyGuardPro\scnkrnl.dll
C:\Program Files\SpyGuardPro\settings.ini
C:\Program Files\SpyGuardPro\sqlite3.dll
C:\Program Files\SpyGuardPro\sr.log
C:\Program Files\SpyGuardPro\Tools\pblock.dll
C:\Program Files\SpyGuardPro\Tools\sbiebho.dll
C:\Program Files\SpyGuardPro\unins000.dat
C:\Program Files\SpyGuardPro\unins000.exe
C:\Program Files\SpyGuardPro\Up\ASupdater.dat
C:\Program Files\SpyGuardPro\Up\gup.exe
C:\Program Files\SpyGuardPro\Up\PGupdater.dat
C:\Program Files\SpyGuardPro\Up\UBupdater.dat
C:\Program Files\SpyGuardPro\Up\up.dat
C:\Program Files\SpyGuardPro\Up\updater.dat
C:\Program Files\stem~1
C:\Program Files\web buying
C:\Program Files\web buying\v1.8.8\wbuninst.exe
C:\Program Files\web buying\v1.8.8\webbuying.exe
C:\Program Files\winpop
C:\Program Files\ystem3~1
C:\SpyGuardPro
C:\temp\0c2
C:\temp\0c2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\isgTi19
C:\Temp\isgTi19\lPig.log
C:\Temp\tpBe12
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\acrsecB.fon
C:\WINDOWS\Fonts\acrsecI.fon
C:\WINDOWS\g4356cbvy63.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\SGluZ1dhaA\
C:\WINDOWS\SGluZ1dhaA\\asappsrv.dll
C:\WINDOWS\SGluZ1dhaA\\command.exe
C:\WINDOWS\SGluZ1dhaA\\m35RtYx1uE.vbs
C:\WINDOWS\SGluZ1dhaA\command.exe
C:\WINDOWS\system32\a1
C:\WINDOWS\system32\a1\tliamdll2.exe
C:\WINDOWS\system32\aocsejpf.dll
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\awtsr.exe
C:\WINDOWS\system32\axfryrxi.dll
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\b06FdUe
C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini
C:\WINDOWS\system32\dnd440e210.dat
C:\WINDOWS\system32\gebcbbx.dll
C:\WINDOWS\system32\gwpiwjwj.dll
C:\WINDOWS\system32\ineWc01
C:\WINDOWS\system32\ineWc01\ineWc011065.exe
C:\WINDOWS\system32\k5
C:\WINDOWS\system32\k5\thgd2241dll.exe
C:\WINDOWS\system32\kbxmdgwu.dll
C:\WINDOWS\system32\kdqdvivv.dll
C:\WINDOWS\system32\kvpgizqc.dll
C:\WINDOWS\system32\kvpgizqc.dllbox
C:\WINDOWS\system32\ldfpgkht.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\lomjrtdl.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mtynqlve.dll
C:\WINDOWS\system32\n.ini
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe
C:\WINDOWS\system32\nmxvelwn.dll
C:\WINDOWS\SYSTEM32\nremxrks.ini
C:\WINDOWS\system32\obylfocq.dll
C:\WINDOWS\system32\p9
C:\WINDOWS\system32\p9\liopud89104.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\SYSTEM32\pqtss.bak1
C:\WINDOWS\SYSTEM32\pqtss.bak2
C:\WINDOWS\SYSTEM32\pqtss.ini
C:\WINDOWS\system32\qdkvrdlo.dll
C:\WINDOWS\system32\qnnsjlsh.dll
C:\WINDOWS\system32\rfmgd.dat
C:\WINDOWS\system32\rmypscvd.dll
C:\WINDOWS\system32\rwnhkobk.dll
C:\WINDOWS\system32\sahbbyhr.dll
C:\WINDOWS\system32\skrxmern.dll
C:\WINDOWS\system32\sstqp.dll
C:\WINDOWS\system32\sttlqbqh.dll
C:\WINDOWS\system32\theuiomp.dll
C:\WINDOWS\system32\tmp11E.tmp.dll
C:\WINDOWS\system32\tmp16C.tmp.dll
C:\WINDOWS\system32\tmp197.tmp.dll
C:\WINDOWS\system32\tmp21EE.tmp.dll
C:\WINDOWS\system32\tmp377.tmp.dll
C:\WINDOWS\system32\tmp50.tmp.dll
C:\WINDOWS\system32\tmp6A6.tmp.dll
C:\WINDOWS\system32\tmp72.tmp.dll
C:\WINDOWS\system32\tmp82.tmp.dll
C:\WINDOWS\system32\tmpC75.tmp.dll
C:\WINDOWS\system32\tyfcmihl.dll
C:\WINDOWS\system32\uovabjxm.dll
C:\WINDOWS\system32\uoymjamj.dll
C:\WINDOWS\system32\v6
C:\WINDOWS\system32\version69ie7fix.dll
C:\WINDOWS\system32\w11
C:\WINDOWS\system32\w11\hiba3133.exe
C:\WINDOWS\system32\win
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\winnb58.dll
C:\WINDOWS\system32\winpfz32.sys
C:\WINDOWS\system32\wnscpicomsv32.exe
C:\WINDOWS\system32\X1
C:\WINDOWS\system32\X1\kmhp83122.exe
C:\WINDOWS\system32\X11
C:\WINDOWS\system32\X3
C:\WINDOWS\system32\X7
C:\WINDOWS\system32\X9
C:\WINDOWS\system32\xuolqjdn.dll
C:\WINDOWS\system32\ystem~1
C:\WINDOWS\uni_eh44.exe
C:\WINDOWS\uninst1014.exe
C:\WINDOWS\uninst2.htm
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\unist1.htm
C:\WINDOWS\wr.txt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_CMDSERVICE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_IPRIP
——-\LEGACY_NETWORK_MONITOR
——-\LEGACY_NET_AGENT
——-\LEGACY_WINDOWS_OVERLAY_COMPONENTS
——-\cmdService
——-\DomainService
——-\Iprip
——-\Network Monitor
——-\Windows Overlay Components
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-28 )))))))))))))))))))))))))))))))
.
2008-02-25 15:54 . 2008-02-26 10:29 1,102,888 —hs—- C:\WINDOWS\SYSTEM32\voirefyh.ini
2008-02-22 17:45 . 2008-02-25 15:45 1,187,971 —hs—- C:\WINDOWS\SYSTEM32\ccmmixrm.ini
2008-02-22 16:47 . 2008-02-22 16:48 1,163,227 —hs—- C:\WINDOWS\SYSTEM32\pgwyakij.ini
2008-02-21 16:44 . 2008-02-22 16:45 1,164,392 —hs—- C:\WINDOWS\SYSTEM32\knokkegw.ini
2008-02-21 16:44 . 2008-02-27 19:54 63,850 –a—— C:\WINDOWS\BMd773d123.xml
2008-02-21 16:44 . 2008-02-28 09:29 22 –a—— C:\WINDOWS\pskt.ini
2008-02-21 15:47 . 2008-02-21 15:48 1,163,956 —hs—- C:\WINDOWS\SYSTEM32\skjcphsh.ini
2008-02-20 15:45 . 2008-02-21 15:46 1,241,401 —hs—- C:\WINDOWS\SYSTEM32\grkhydoa.ini
2008-02-20 12:45 . 2008-02-20 12:45 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-20 12:45 . 2008-02-20 12:45 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-19 15:42 . 2008-02-20 15:43 1,246,975 —hs—- C:\WINDOWS\SYSTEM32\hxrbpiln.ini
2008-02-19 14:42 . 2008-02-19 14:42 1,238,251 —hs—- C:\WINDOWS\SYSTEM32\unerwfie.ini
2008-02-18 14:39 . 2008-02-19 14:41 1,238,191 —hs—- C:\WINDOWS\SYSTEM32\jlglufvn.ini
2008-02-17 12:41 . 2008-02-18 13:36 1,248,887 —hs—- C:\WINDOWS\SYSTEM32\mvvaotnn.ini
2008-02-17 11:44 . 2008-02-17 11:44 1,248,707 —hs—- C:\WINDOWS\SYSTEM32\elxvrqsf.ini
2008-02-16 11:45 . 2008-02-16 11:45 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-16 11:43 . 2008-02-17 11:43 1,248,647 —hs—- C:\WINDOWS\SYSTEM32\hciuucdv.ini
2008-02-16 11:32 . 2008-02-16 12:42 d——– C:\Program Files\Fοnts
2008-02-16 11:32 . 2008-02-16 11:32 483,452 –a—— C:\Temp\chtOna0119.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-26 21:04 ——— d—–w C:\Documents and Settings\HingWah\Application Data\AdobeUM
2008-02-25 21:45 ——— d—–w C:\Program Files\FlashGet
2008-02-16 17:42 ——— d—–w C:\Program Files\Fοnts
2008-02-12 16:20 ——— d—–w C:\Program Files\MSN Messenger
2008-02-04 18:48 ——— d—–w C:\Program Files\MySpace
2008-02-04 18:37 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-04 18:30 ——— d—–w C:\Program Files\Uniblue
2008-02-04 18:30 ——— d—–w C:\Documents and Settings\HingWah\Application Data\Uniblue
2008-02-04 18:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-04 18:27 ——— d—–w C:\Program Files\Lavasoft
2008-02-04 18:27 ——— d—–w C:\Documents and Settings\HingWah\Application Data\Lavasoft
2008-01-09 01:39 ——— d—–w C:\Program Files\FLV Player
2007-12-04 22:35 74,532 —-a-w C:\WINDOWS\fccawu.dll
2006-01-19 16:11 784 —-a-w C:\Documents and Settings\HingWah\Application Data\mpauth.dat
2005-10-19 22:26 122 -c–a-w C:\Program Files\ppunistall.bat
2004-05-29 16:32 2,814 -csha-w C:\WINDOWS\agcpu.dat
2004-07-07 00:22 65,536 -csha-w C:\WINDOWS\n_yrlroq.dat
2004-01-09 06:55 4,402 -csha-w C:\WINDOWS\vpmpa.dat
2007-08-04 12:41 6,467 –sha-w C:\WINDOWS\SYSTEM32\mlnmp.bak1
2007-08-05 12:41 1,730,419 –sha-w C:\WINDOWS\SYSTEM32\mlnmp.bak2
2007-08-06 04:13 1,798,478 –sha-w C:\WINDOWS\SYSTEM32\mlnmp.ini2
2007-08-02 15:02 32,768 –sha-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012007080220070803\index.dat
2007-10-16 15:59 230,912 –sh–r C:\WINDOWS\ΑppPatch\svchost.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A85F6C9C-F658-F589-0C54-FF9A85FE4DC5}]
2007-10-16 10:58 60928 –a—— C:\WINDOWS\system32\vckhlxci.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-13 16:59 68856]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2007-05-16 09:18 1856544]
"Uniblue RegistryBooster2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2007-05-16 09:18 1856544]
"Uniblue SpeedUpMyPC"="C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe" [2007-05-23 13:03 8631840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-12-14 15:12 180269]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-10-22 13:32 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\actMTF]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\C_1FAT]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\c_2mon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igm082]
igm082.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jpatD32]
jpatD32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MAINtpp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlm]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnkij]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 8.0 Tray Icon.lnk]
backup=C:\WINDOWS\pss\America Online 8.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GStartup.lnk]
backup=C:\WINDOWS\pss\GStartup.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HingWah^Start Menu^Programs^Startup^Spykiller Pro v2.0.lnk]
backup=C:\WINDOWS\pss\Spykiller Pro v2.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AltnetPointsManager]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
–a—— 2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CMESys]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
–a–c— 2002-11-22 14:49 188416 C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon04]
–a–c— 2002-11-22 14:48 348160 C:\WINDOWS\System32\hphmon04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD04]
–a–c— 2002-11-22 14:50 49152 C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAZAA]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
–a—— 2001-07-08 22:50 155648 C:\WINDOWS\system32\\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2003-04-24 16:58 4616192 C:\WINDOWS\System32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2005-10-22 13:32 155648 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
–a–c— 2002-04-17 09:42 69632 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a–c— 2004-02-22 22:44 32881 C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2005-12-14 15:12 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updater]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
–a—— 2004-11-12 12:24 106557 C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winva32.exe]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Netscape\\Netscape\\Netscp.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"16918:TCP"= 16918:TCP:BitComet 16918 TCP
"16918:UDP"= 16918:UDP:BitComet 16918 UDP
"7681:TCP"= 7681:TCP:BitComet 7681 TCP
"7681:UDP"= 7681:UDP:BitComet 7681 UDP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 dhlp;dhlp;C:\WINDOWS\system32\Drivers\dhlp.sys [2007-12-15 11:09]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\System32\svchost.exe [2004-08-04 02:56]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\System32\svchost.exe [2004-08-04 02:56]
S3 p2psvc;Peer Networking;C:\WINDOWS\System32\svchost.exe [2004-08-04 02:56]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\System32\svchost.exe [2004-08-04 02:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
"2008-02-28 16:05:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-12 16:04:00 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-08-06 15:03:59 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-08-06 17:14:58 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-28 11:01:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
.
**************************************************************************
.
Completion time: 2008-02-28 11:06:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-28 16:06:18
.
2008-02-13 08:03:44 — E O F —
I had the same problem and followed your instruction. What do I do now? is my problem fixed ?
Thanks in advance.
ComboFix 08-02-25.3 - HingWah 2008-02-28 10:36:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.[removed].18.300 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\check_LSA7.txt
C:\Documents and Settings\All Users\Application Data\salesmonitor
C:\Documents and Settings\HingWah\Application Data\.rdr.ini
C:\Documents and Settings\HingWah\Application Data\APPATC~1
C:\Documents and Settings\HingWah\Application Data\DriveCleaner Freeware
C:\Documents and Settings\HingWah\Application Data\DriveCleaner Freeware\Logs\update.log
C:\Documents and Settings\HingWah\Application Data\ICROSO~1.NET
C:\Documents and Settings\HingWah\Application Data\MBOLS~1
C:\Documents and Settings\HingWah\Application Data\SpyGuardPro
C:\Documents and Settings\HingWah\Application Data\SpyGuardPro\Logs\threats.log
C:\Documents and Settings\HingWah\Application Data\SpyGuardPro\Logs\update.log
C:\Documents and Settings\HingWah\Application Data\SSTEM~1
C:\Documents and Settings\HingWah\Application Data\tmp10.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp118.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp11D.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp143.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp144.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp167.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp16C.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp1A5.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp1C.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp1C1.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp1DB1.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp21EE.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp245.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp27.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp28.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp36.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp377.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp4F.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp50.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp51.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp5B6.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp5D.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp63.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp6A7.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp70.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp72.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp7A.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp82.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmp86.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmpBA8.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmpC75.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmpE.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmpEF8.tmp.exe
C:\Documents and Settings\HingWah\Application Data\tmpF.tmp.exe
C:\Documents and Settings\HingWah\Application Data\WinTouch
C:\Documents and Settings\HingWah\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\HingWah\err.log
C:\Documents and Settings\HingWah\My Documents\CURITY~1
C:\Documents and Settings\HingWah\My Documents\ECURIT~1
C:\Documents and Settings\HingWah\My Documents\MCROSO~1.NET
C:\Documents and Settings\HingWah\My Documents\STEM~1
C:\Documents and Settings\LocalService\Application Data\.rdr.ini
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\LocalService\Desktop\searchus.exe
C:\Documents and Settings\LocalService\Local Settings\Application Data\n.ini
C:\Documents and Settings\NetworkService\Desktop\searchus.exe
C:\New Folder\[星野?一]官能實驗\_desktop.ini
C:\Program Files\Common Files\SpyGuardPro
C:\Program Files\Common Files\SpyGuardPro\bm.exe
C:\Program Files\Common Files\SpyGuardPro\ugac.exe
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\inetget2
C:\Program Files\Internet Explorer\promyfsywuewu.html
C:\Program Files\livabigas89104.dll
C:\Program Files\mbols~1
C:\Program Files\network monitor
C:\Program Files\network monitor\netmon.exe
C:\Program Files\SpyGuardPro
C:\Program Files\SpyGuardPro\Activate.exe
C:\Program Files\SpyGuardPro\al.dat
C:\Program Files\SpyGuardPro\Config\pgs.xml
C:\Program Files\SpyGuardPro\Dat\Activate.dat
C:\Program Files\SpyGuardPro\Dat\BkSites.dat
C:\Program Files\SpyGuardPro\Dat\bnlink.dat
C:\Program Files\SpyGuardPro\Dat\cd.dat
C:\Program Files\SpyGuardPro\Dat\incmp.dat
C:\Program Files\SpyGuardPro\Dat\index.dat
C:\Program Files\SpyGuardPro\Dat\pv.dat
C:\Program Files\SpyGuardPro\dhlp.dll
C:\Program Files\SpyGuardPro\Engines\AWBase\database\enemies.dat
C:\Program Files\SpyGuardPro\Engines\AWBase\vbpv.dat
C:\Program Files\SpyGuardPro\Engines\PGBase\vbpv.dat
C:\Program Files\SpyGuardPro\Engines\plugins\BORLNDMM.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANADWR.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANBCDR.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANDLDR.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANDOS1.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANEMUL.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANFUNC.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANKRNL.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANMCR1.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANOTHR.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANSCR.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANTOOL.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANTROJ.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\SCANWIN1.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UNACPU.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UNADBX.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\unamscan.dll
C:\Program Files\SpyGuardPro\Engines\plugins\UNMIME.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UNPACK.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UNPACKS.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UNPACKS2.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UNPEPACK.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UpDate\UA27601.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UpDate\UA27602.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UpDate\UA27603.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UpDate\UA27604.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\UpDate\UADAILY.DLL
C:\Program Files\SpyGuardPro\Engines\plugins\vbpv.dat
C:\Program Files\SpyGuardPro\FWSettings.bin
C:\Program Files\SpyGuardPro\Graphics\cross.gif
C:\Program Files\SpyGuardPro\Graphics\ga6p.gif
C:\Program Files\SpyGuardPro\Graphics\kb.url
C:\Program Files\SpyGuardPro\Graphics\main.ico
C:\Program Files\SpyGuardPro\Graphics\mini.ico
C:\Program Files\SpyGuardPro\Graphics\Online.url
C:\Program Files\SpyGuardPro\Graphics\rm.url
C:\Program Files\SpyGuardPro\Graphics\support.ico
C:\Program Files\SpyGuardPro\Graphics\Support.url
C:\Program Files\SpyGuardPro\Graphics\uninstall.ico
C:\Program Files\SpyGuardPro\history.db
C:\Program Files\SpyGuardPro\LA\lapv.dat
C:\Program Files\SpyGuardPro\LA\License.rtf
C:\Program Files\SpyGuardPro\main.log
C:\Program Files\SpyGuardPro\pgs.exe
C:\Program Files\SpyGuardPro\ptask.exe
C:\Program Files\SpyGuardPro\reload.exe
C:\Program Files\SpyGuardPro\ResErrors.log
C:\Program Files\SpyGuardPro\scnkrnl.dll
C:\Program Files\SpyGuardPro\settings.ini
C:\Program Files\SpyGuardPro\sqlite3.dll
C:\Program Files\SpyGuardPro\sr.log
C:\Program Files\SpyGuardPro\Tools\pblock.dll
C:\Program Files\SpyGuardPro\Tools\sbiebho.dll
C:\Program Files\SpyGuardPro\unins000.dat
C:\Program Files\SpyGuardPro\unins000.exe
C:\Program Files\SpyGuardPro\Up\ASupdater.dat
C:\Program Files\SpyGuardPro\Up\gup.exe
C:\Program Files\SpyGuardPro\Up\PGupdater.dat
C:\Program Files\SpyGuardPro\Up\UBupdater.dat
C:\Program Files\SpyGuardPro\Up\up.dat
C:\Program Files\SpyGuardPro\Up\updater.dat
C:\Program Files\stem~1
C:\Program Files\web buying
C:\Program Files\web buying\v1.8.8\wbuninst.exe
C:\Program Files\web buying\v1.8.8\webbuying.exe
C:\Program Files\winpop
C:\Program Files\ystem3~1
C:\SpyGuardPro
C:\temp\0c2
C:\temp\0c2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\isgTi19
C:\Temp\isgTi19\lPig.log
C:\Temp\tpBe12
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\acrsecB.fon
C:\WINDOWS\Fonts\acrsecI.fon
C:\WINDOWS\g4356cbvy63.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\SGluZ1dhaA\
C:\WINDOWS\SGluZ1dhaA\\asappsrv.dll
C:\WINDOWS\SGluZ1dhaA\\command.exe
C:\WINDOWS\SGluZ1dhaA\\m35RtYx1uE.vbs
C:\WINDOWS\SGluZ1dhaA\command.exe
C:\WINDOWS\system32\a1
C:\WINDOWS\system32\a1\tliamdll2.exe
C:\WINDOWS\system32\aocsejpf.dll
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\awtsr.exe
C:\WINDOWS\system32\axfryrxi.dll
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\b06FdUe
C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini
C:\WINDOWS\system32\dnd440e210.dat
C:\WINDOWS\system32\gebcbbx.dll
C:\WINDOWS\system32\gwpiwjwj.dll
C:\WINDOWS\system32\ineWc01
C:\WINDOWS\system32\ineWc01\ineWc011065.exe
C:\WINDOWS\system32\k5
C:\WINDOWS\system32\k5\thgd2241dll.exe
C:\WINDOWS\system32\kbxmdgwu.dll
C:\WINDOWS\system32\kdqdvivv.dll
C:\WINDOWS\system32\kvpgizqc.dll
C:\WINDOWS\system32\kvpgizqc.dllbox
C:\WINDOWS\system32\ldfpgkht.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\lomjrtdl.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mtynqlve.dll
C:\WINDOWS\system32\n.ini
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe
C:\WINDOWS\system32\nmxvelwn.dll
C:\WINDOWS\SYSTEM32\nremxrks.ini
C:\WINDOWS\system32\obylfocq.dll
C:\WINDOWS\system32\p9
C:\WINDOWS\system32\p9\liopud89104.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\SYSTEM32\pqtss.bak1
C:\WINDOWS\SYSTEM32\pqtss.bak2
C:\WINDOWS\SYSTEM32\pqtss.ini
C:\WINDOWS\system32\qdkvrdlo.dll
C:\WINDOWS\system32\qnnsjlsh.dll
C:\WINDOWS\system32\rfmgd.dat
C:\WINDOWS\system32\rmypscvd.dll
C:\WINDOWS\system32\rwnhkobk.dll
C:\WINDOWS\system32\sahbbyhr.dll
C:\WINDOWS\system32\skrxmern.dll
C:\WINDOWS\system32\sstqp.dll
C:\WINDOWS\system32\sttlqbqh.dll
C:\WINDOWS\system32\theuiomp.dll
C:\WINDOWS\system32\tmp11E.tmp.dll
C:\WINDOWS\system32\tmp16C.tmp.dll
C:\WINDOWS\system32\tmp197.tmp.dll
C:\WINDOWS\system32\tmp21EE.tmp.dll
C:\WINDOWS\system32\tmp377.tmp.dll
C:\WINDOWS\system32\tmp50.tmp.dll
C:\WINDOWS\system32\tmp6A6.tmp.dll
C:\WINDOWS\system32\tmp72.tmp.dll
C:\WINDOWS\system32\tmp82.tmp.dll
C:\WINDOWS\system32\tmpC75.tmp.dll
C:\WINDOWS\system32\tyfcmihl.dll
C:\WINDOWS\system32\uovabjxm.dll
C:\WINDOWS\system32\uoymjamj.dll
C:\WINDOWS\system32\v6
C:\WINDOWS\system32\version69ie7fix.dll
C:\WINDOWS\system32\w11
C:\WINDOWS\system32\w11\hiba3133.exe
C:\WINDOWS\system32\win
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\winnb58.dll
C:\WINDOWS\system32\winpfz32.sys
C:\WINDOWS\system32\wnscpicomsv32.exe
C:\WINDOWS\system32\X1
C:\WINDOWS\system32\X1\kmhp83122.exe
C:\WINDOWS\system32\X11
C:\WINDOWS\system32\X3
C:\WINDOWS\system32\X7
C:\WINDOWS\system32\X9
C:\WINDOWS\system32\xuolqjdn.dll
C:\WINDOWS\system32\ystem~1
C:\WINDOWS\uni_eh44.exe
C:\WINDOWS\uninst1014.exe
C:\WINDOWS\uninst2.htm
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\unist1.htm
C:\WINDOWS\wr.txt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_CMDSERVICE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_IPRIP
——-\LEGACY_NETWORK_MONITOR
——-\LEGACY_NET_AGENT
——-\LEGACY_WINDOWS_OVERLAY_COMPONENTS
——-\cmdService
——-\DomainService
——-\Iprip
——-\Network Monitor
——-\Windows Overlay Components
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-28 )))))))))))))))))))))))))))))))
.
2008-02-25 15:54 . 2008-02-26 10:29 1,102,888 —hs—- C:\WINDOWS\SYSTEM32\voirefyh.ini
2008-02-22 17:45 . 2008-02-25 15:45 1,187,971 —hs—- C:\WINDOWS\SYSTEM32\ccmmixrm.ini
2008-02-22 16:47 . 2008-02-22 16:48 1,163,227 —hs—- C:\WINDOWS\SYSTEM32\pgwyakij.ini
2008-02-21 16:44 . 2008-02-22 16:45 1,164,392 —hs—- C:\WINDOWS\SYSTEM32\knokkegw.ini
2008-02-21 16:44 . 2008-02-27 19:54 63,850 –a—— C:\WINDOWS\BMd773d123.xml
2008-02-21 16:44 . 2008-02-28 09:29 22 –a—— C:\WINDOWS\pskt.ini
2008-02-21 15:47 . 2008-02-21 15:48 1,163,956 —hs—- C:\WINDOWS\SYSTEM32\skjcphsh.ini
2008-02-20 15:45 . 2008-02-21 15:46 1,241,401 —hs—- C:\WINDOWS\SYSTEM32\grkhydoa.ini
2008-02-20 12:45 . 2008-02-20 12:45 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-20 12:45 . 2008-02-20 12:45 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-19 15:42 . 2008-02-20 15:43 1,246,975 —hs—- C:\WINDOWS\SYSTEM32\hxrbpiln.ini
2008-02-19 14:42 . 2008-02-19 14:42 1,238,251 —hs—- C:\WINDOWS\SYSTEM32\unerwfie.ini
2008-02-18 14:39 . 2008-02-19 14:41 1,238,191 —hs—- C:\WINDOWS\SYSTEM32\jlglufvn.ini
2008-02-17 12:41 . 2008-02-18 13:36 1,248,887 —hs—- C:\WINDOWS\SYSTEM32\mvvaotnn.ini
2008-02-17 11:44 . 2008-02-17 11:44 1,248,707 —hs—- C:\WINDOWS\SYSTEM32\elxvrqsf.ini
2008-02-16 11:45 . 2008-02-16 11:45 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-16 11:43 . 2008-02-17 11:43 1,248,647 —hs—- C:\WINDOWS\SYSTEM32\hciuucdv.ini
2008-02-16 11:32 . 2008-02-16 12:42 d——– C:\Program Files\Fοnts
2008-02-16 11:32 . 2008-02-16 11:32 483,452 –a—— C:\Temp\chtOna0119.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-26 21:04 ——— d—–w C:\Documents and Settings\HingWah\Application Data\AdobeUM
2008-02-25 21:45 ——— d—–w C:\Program Files\FlashGet
2008-02-16 17:42 ——— d—–w C:\Program Files\Fοnts
2008-02-12 16:20 ——— d—–w C:\Program Files\MSN Messenger
2008-02-04 18:48 ——— d—–w C:\Program Files\MySpace
2008-02-04 18:37 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-04 18:30 ——— d—–w C:\Program Files\Uniblue
2008-02-04 18:30 ——— d—–w C:\Documents and Settings\HingWah\Application Data\Uniblue
2008-02-04 18:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-04 18:27 ——— d—–w C:\Program Files\Lavasoft
2008-02-04 18:27 ——— d—–w C:\Documents and Settings\HingWah\Application Data\Lavasoft
2008-01-09 01:39 ——— d—–w C:\Program Files\FLV Player
2007-12-04 22:35 74,532 —-a-w C:\WINDOWS\fccawu.dll
2006-01-19 16:11 784 —-a-w C:\Documents and Settings\HingWah\Application Data\mpauth.dat
2005-10-19 22:26 122 -c–a-w C:\Program Files\ppunistall.bat
2004-05-29 16:32 2,814 -csha-w C:\WINDOWS\agcpu.dat
2004-07-07 00:22 65,536 -csha-w C:\WINDOWS\n_yrlroq.dat
2004-01-09 06:55 4,402 -csha-w C:\WINDOWS\vpmpa.dat
2007-08-04 12:41 6,467 –sha-w C:\WINDOWS\SYSTEM32\mlnmp.bak1
2007-08-05 12:41 1,730,419 –sha-w C:\WINDOWS\SYSTEM32\mlnmp.bak2
2007-08-06 04:13 1,798,478 –sha-w C:\WINDOWS\SYSTEM32\mlnmp.ini2
2007-08-02 15:02 32,768 –sha-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012007080220070803\index.dat
2007-10-16 15:59 230,912 –sh–r C:\WINDOWS\ΑppPatch\svchost.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A85F6C9C-F658-F589-0C54-FF9A85FE4DC5}]
2007-10-16 10:58 60928 –a—— C:\WINDOWS\system32\vckhlxci.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-13 16:59 68856]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2007-05-16 09:18 1856544]
"Uniblue RegistryBooster2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2007-05-16 09:18 1856544]
"Uniblue SpeedUpMyPC"="C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe" [2007-05-23 13:03 8631840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-12-14 15:12 180269]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-10-22 13:32 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\actMTF]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\C_1FAT]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\c_2mon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igm082]
igm082.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jpatD32]
jpatD32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MAINtpp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlm]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnkij]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 8.0 Tray Icon.lnk]
backup=C:\WINDOWS\pss\America Online 8.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GStartup.lnk]
backup=C:\WINDOWS\pss\GStartup.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HingWah^Start Menu^Programs^Startup^Spykiller Pro v2.0.lnk]
backup=C:\WINDOWS\pss\Spykiller Pro v2.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AltnetPointsManager]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
–a—— 2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CMESys]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
–a–c— 2002-11-22 14:49 188416 C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon04]
–a–c— 2002-11-22 14:48 348160 C:\WINDOWS\System32\hphmon04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD04]
–a–c— 2002-11-22 14:50 49152 C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAZAA]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
–a—— 2001-07-08 22:50 155648 C:\WINDOWS\system32\\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2003-04-24 16:58 4616192 C:\WINDOWS\System32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2005-10-22 13:32 155648 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
–a–c— 2002-04-17 09:42 69632 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a–c— 2004-02-22 22:44 32881 C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2005-12-14 15:12 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updater]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
–a—— 2004-11-12 12:24 106557 C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winva32.exe]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Netscape\\Netscape\\Netscp.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"16918:TCP"= 16918:TCP:BitComet 16918 TCP
"16918:UDP"= 16918:UDP:BitComet 16918 UDP
"7681:TCP"= 7681:TCP:BitComet 7681 TCP
"7681:UDP"= 7681:UDP:BitComet 7681 UDP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 dhlp;dhlp;C:\WINDOWS\system32\Drivers\dhlp.sys [2007-12-15 11:09]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\System32\svchost.exe [2004-08-04 02:56]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\System32\svchost.exe [2004-08-04 02:56]
S3 p2psvc;Peer Networking;C:\WINDOWS\System32\svchost.exe [2004-08-04 02:56]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\System32\svchost.exe [2004-08-04 02:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
"2008-02-28 16:05:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-12 16:04:00 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-08-06 15:03:59 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-08-06 17:14:58 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-28 11:01:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
.
**************************************************************************
.
Completion time: 2008-02-28 11:06:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-28 16:06:18
.
2008-02-13 08:03:44 — E O F —