OK….HERE IS THE COMBOFIX LOG:
ComboFix 08-05-01.3 - Owner 2008-05-07 9:33:49.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.144 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\IA
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\command.pif
C:\WINDOWS\system32\FhiiRXyb.ini
C:\WINDOWS\system32\FhiiRXyb.ini2
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_NWSAPAGENT
——-\Service_NwSapAgent
((((((((((((((((((((((((( Files Created from 2008-04-07 to 2008-05-07 )))))))))))))))))))))))))))))))
.
2008-05-05 16:58 . 2008-05-05 16:58 d——– C:\Documents and Settings\Owner\Application Data\Gamelab
2008-05-05 16:57 . 2008-05-05 16:58 d——– C:\Program Files\Jojo's Fashion Show
2008-05-05 16:31 . 2008-05-06 21:38 d——– C:\Program Files\SpongeBob SquarePants Diner Dash
2008-05-05 00:48 . 2008-05-05 00:48 d——– C:\Documents and Settings\All Users\Application Data\Zylom
2008-05-04 23:13 . 2008-05-04 23:13 d——– C:\Documents and Settings\Owner\Application Data\iWin
2008-05-04 16:37 . 2008-05-04 16:37 d——– C:\Program Files\Trend Micro
2008-05-04 10:19 . 2008-05-07 08:32 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-05-04 10:19 . 2008-05-04 10:19 1,409 –a—— C:\WINDOWS\QTFont.for
2008-04-30 17:38 . 2008-04-30 17:38 d——– C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-04-30 17:28 . 2008-04-30 17:28 d——– C:\Program Files\SUPERAntiSpyware
2008-04-30 17:28 . 2008-04-30 17:28 d——– C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2008-04-30 17:28 . 2008-04-30 17:28 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-30 16:39 . 2008-04-30 16:39 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-04-30 13:24 . 2008-04-30 13:31 d——– C:\WINDOWS\system32\NtmsData
2008-04-30 10:51 . 2008-04-30 10:51 d——– C:\Documents and Settings\Owner\Application Data\iWinArcade
2008-04-30 00:26 . 2008-04-30 00:26 d——– C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-04-30 00:09 . 2006-09-18 10:57 d——– C:\Documents and Settings\Administrator\WINDOWS
2008-04-30 00:09 . 2006-09-18 11:41 d——– C:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver
2008-04-30 00:09 . 2006-09-18 11:39 d——– C:\Documents and Settings\Administrator\Application Data\SampleView
2008-04-30 00:09 . 2006-09-18 11:54 d——– C:\Documents and Settings\Administrator\Application Data\AOL
2008-04-30 00:09 . 2008-04-30 00:09 d——– C:\Documents and Settings\Administrator
2008-04-30 00:09 . 2008-05-07 09:33 1,024 –ah—– C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-04-29 17:16 . 2008-04-29 17:16 d——– C:\Program Files\Mystery P.I. - The Vegas Heist
2008-04-29 17:16 . 2008-04-29 17:16 d——– C:\Documents and Settings\Owner\Application Data\SpinTop
2008-04-28 18:01 . 2008-04-28 23:36 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-04-28 18:01 . 2008-04-28 18:01 d——– C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-04-28 18:01 . 2008-04-28 18:01 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-28 17:00 . 2008-04-28 17:00 d——– C:\Program Files\Svconr
2008-04-28 16:45 . 2008-04-28 16:45 109,738 –a—— C:\WINDOWS\BMa3f72945.xml
2008-04-27 00:30 . 2006-09-14 11:53 1,941,504 –a—— C:\WINDOWS\system32\Tropix.scr
2008-04-21 03:45 . 2008-04-21 03:45 d——– C:\Program Files\The Hidden Object Show
2008-04-20 02:20 . 2008-04-20 02:20 d——– C:\WINDOWS\Dream Day - First Home
2008-04-20 02:20 . 2008-04-20 02:21 d——– C:\Program Files\Dream Day - First Home
2008-04-19 02:15 . 2008-04-20 01:15 d——– C:\Program Files\Dream Day First Home
2008-04-19 02:04 . 2008-05-04 23:14 d——– C:\Program Files\Family Feud III - Dream Home
2008-04-10 00:13 . 2008-04-10 00:13 d——– C:\Documents and Settings\All Users\Application Data\Interama
2008-04-07 02:13 . 2008-04-07 02:13 d——– C:\Documents and Settings\Owner\Application Data\Pi Eye Games
2008-04-07 01:52 . 2008-04-07 01:53 d——– C:\Documents and Settings\All Users\Application Data\MostFun
2008-04-07 01:41 . 2008-04-09 23:48 d——– C:\Program Files\MostFun
2008-04-07 01:25 . 2008-05-06 21:49 d——– C:\Program Files\Brain Booster
2008-04-07 01:23 . 2008-04-07 01:23 d——– C:\Program Files\Circulate
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-07 07:14 ——— d—–w C:\Documents and Settings\Owner\Application Data\PlayFirst
2008-05-07 07:14 ——— d—–w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-05-07 02:43 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-05 06:28 ——— d—–w C:\Program Files\Lx_cats
2008-05-04 05:59 ——— d—–w C:\Program Files\AOL Games
2008-05-01 05:41 ——— d—–w C:\Program Files\2Wire
2008-04-30 05:35 ——— d—–w C:\Documents and Settings\Owner\Application Data\Uniblue
2008-04-29 08:45 ——— d—–w C:\Program Files\GameHouse
2008-04-29 07:13 ——— d—–w C:\Documents and Settings\Owner\Application Data\Big Fish Games
2008-04-29 06:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Fugazo
2008-04-29 00:20 ——— d—–w C:\Program Files\BFG
2008-04-21 08:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\Gogii
2008-04-21 02:30 ——— d—–w C:\Program Files\Tropix
2008-04-20 22:13 13,984 —-a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
2008-04-19 06:59 ——— d—–w C:\Program Files\bfgclient
2008-04-04 19:52 ——— d—–w C:\Program Files\iTunes
2008-04-04 19:43 ——— d—–w C:\Program Files\iPod
2008-04-04 19:41 ——— d—–w C:\Program Files\Bonjour
2008-04-04 19:40 ——— d—–w C:\Program Files\QuickTime
2008-04-04 18:52 ——— d—–w C:\Program Files\LimeWire
2008-04-02 19:21 ——— d—–w C:\Program Files\Games
2008-04-02 03:18 ——— d—–w C:\Documents and Settings\Owner\Application Data\Ludia
2008-04-02 03:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Ludia
2008-04-01 07:50 ——— d—–w C:\Documents and Settings\Owner\Application Data\Boomzap
2008-04-01 07:02 ——— d—–w C:\Program Files\Common Files\Download Manager
2008-03-28 01:24 ——— d—–w C:\Program Files\CardRecovery
2008-03-26 18:52 ——— d—–w C:\Documents and Settings\Owner\Application Data\Leadertech
2008-03-26 18:34 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-03-26 17:36 ——— d—–w C:\Program Files\Digital Photo Recovery
2008-03-21 07:16 ——— d—–w C:\Documents and Settings\Owner\Application Data\Friday's games
2008-03-19 09:47 1,845,248 —-a-w C:\WINDOWS\system32\win32k.sys
2008-03-12 15:10 0 —-a-w C:\Program Files\temp01
2008-03-12 15:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
2008-02-20 06:51 282,624 —-a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 —-a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:32 666,112 —-a-w C:\WINDOWS\system32\wininet.dll
2006-12-19 00:21 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2006-11-11 23:06 1,727,833 —-a-w C:\Program Files\ChayceAndRoland.JPG
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 50,776 2005-06-23 16:24:12 C:\Program Files\America Online 9.0\bak\AOL.EXE
—-a-w 125,528 2004-11-03 21:03:00 C:\Program Files\Common Files\AOL\1158597562\EE\bak\AOLHostManager.exe
—-a-w 185,896 2007-07-02 14:54:17 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
—-a-w 58,488 2004-08-27 23:22:40 C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe
—-a-w 218,240 2004-08-06 00:23:14 C:\Program Files\Common Files\Symantec Shared\Security Center\bak\UsrPrmpt.exe
—-a-w 32,768 2004-11-03 03:24:46 C:\Program Files\CyberLink\PowerDVD\bak\PDVDServ.exe
—-a-w 135,168 2004-11-15 22:04:32 C:\Program Files\Digital Media Reader\bak\shwiconem.exe
—-a-w 68,856 2007-08-04 04:07:15 C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe
—-a-w 267,064 2007-09-05 23:03:52 C:\Program Files\iTunes\bak\iTunesHelper.exe
—-a-w 267,048 2008-03-30 15:36:40 C:\Program Files\iTunes\iTunesHelper.exe
—-a-w 83,608 2007-03-14 08:43:44 C:\Program Files\Java\jre1.6.0_01\bin\bak\jusched.exe
—-a-w 327,680 2006-01-06 20:14:20 C:\Program Files\McAfee\McAfee AntiSpyware\bak\masalert.exe
—-a-w 303,104 2005-09-23 01:29:08 C:\Program Files\McAfee.com\Agent\bak\mcagent.exe
—-a-w 212,992 2006-01-11 19:05:42 C:\Program Files\McAfee.com\Agent\bak\McUpdate.exe
—-a-w 277,296 2006-10-13 23:01:18 C:\Program Files\Microsoft LifeCam\bak\LifeExp.exe
—-a-w 132,248 2004-08-17 22:36:18 C:\Program Files\Norton Internet Security\bak\cfgwiz.exe
—-a-w 33,936 2004-08-31 02:29:36 C:\Program Files\Norton Internet Security\bak\UrlLstCk.exe
—-a-w 286,720 2007-06-29 11:24:52 C:\Program Files\QuickTime\bak\QTTask.exe
—-a-w 413,696 2008-03-29 04:37:20 C:\Program Files\QuickTime\QTTask.exe
—-a-w 1,028,096 2003-07-14 19:55:01 C:\Program Files\SBC Yahoo!\Connection Manager\bak\ConnectionManager.exe
—-a-w 81,920 2006-05-08 10:17:56 C:\Program Files\Sony\SonicStage\bak\SsAAD.exe
—-a-w 57,344 2003-07-11 21:51:16 C:\Program Files\Yahoo!\browser\bak\ybrwicon.exe
—-a-w 224,248 2007-06-08 14:59:38 C:\Program Files\Yahoo!\Search Protection\bak\SearchProtection.exe
—-a-w 707,376 2006-10-13 23:04:06 C:\WINDOWS\bak\vVX3000.exe
—-a-w 118,784 2004-08-20 22:51:14 C:\WINDOWS\system32\bak\hkcmd.exe
—-a-w 155,648 2004-08-20 22:55:14 C:\WINDOWS\system32\bak\igfxtray.exe
—-a-w 155,648 2001-07-09 18:50:42 C:\WINDOWS\system32\bak\NeroCheck.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91fe716b-5c56-4a48-afd1-c17f3eb87335}]
C:\WINDOWS\system32\aypbmcjp.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShutterflyStudio"="C:\Program Files\Shutterfly\Studio\BIN\SFlyStudio.exe" [2007-03-06 13:05 2496512]
"Svconr"="C:\Program Files\Svconr\Svconr.exe" [2008-04-28 17:00 57344]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 19:42 79448]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\bak\mcupdate.exe" [2006-01-11 14:05 212992]
"LXCFCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 14:47 73728]
"avast! Web Scanner"="C:\PROGRA~1\ALWILS~1\Avast4\ashWebSv.exe" [ ]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"a0c41ad9"="C:\WINDOWS\system32\bbbiksxo.dll" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"avast!"="C:\Program Files\Alwil Software\Avast4\ashServ.exe" [ ]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
2WireSetup.lnk - C:\Program Files\2Wire\WebWorks.exe [2008-05-01 00:40:53 622592]
Event Minder Reminders.lnk - C:\HALLMARK\EMREMIND.EXE [2007-07-09 16:39:42 6240]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
Install Pending Files.LNK - C:\Program Files\SIFXINST\SIFXINST.EXE [2006-09-18 11:35:37 729088]
iWin Desktop Alerts.lnk - C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe [2008-01-28 19:51:51 107520]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1158597562\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\Yahoo!\\browser\\ybrowser.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MostFun\\Bin\\MostFun.exe"=
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-10-13 18:01]
R3 2WIREPCP;2Wire USB;C:\WINDOWS\system32\DRIVERS\2WirePCP.sys [2005-05-12 11:26]
R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 01:01]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-30 16:44:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-07 14:29:03 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-04-29 13:43:41 C:\WINDOWS\Tasks\McAfee AntiSpyware.job"
- c:\progra~1\mcafee\MCAFEE~1\MASCon.exe
"2008-05-05 23:28:16 C:\WINDOWS\Tasks\ParetoLogic Registration.job"
- C:\WINDOWS\system32\rundll32.exe@
"2006-09-18 16:26:07 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2008-03-22 13:24:00 C:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job"
- C:\PROGRA~1\Uniblue\SPYERA~1\SpyEraser.exe
"2007-10-14 06:03:04 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\PROGRA~1\Uniblue\SPYERA~1\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-07 09:43:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\McAfee AntiSpyware\MASSrv.exe
C:\Program Files\McAfee.com\Agent\Mcdetect.exe
C:\PROGRA~1\McAfee.com\Agent\McTskshd.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\snmp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MostFun\Bin\MostFun.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-05-07 9:58:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-07 14:58:29
Pre-Run: 65,679,998,976 bytes free
Post-Run: 68,223,328,256 bytes free
260 — E O F — 2008-04-09 08:16:23