ComboFix 08-06-08.8 - xplicitz 2008-06-09 12:45:08.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.201 [GMT -7:00]
Running from: C:\Documents and Settings\xplicitz\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\xplicitz\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\444.0
C:\WINDOWS\444.470
C:\WINDOWS\portsv.exe
C:\WINDOWS\system32\{1d619cc7-79b9-257f-d140-6158e753a647}.dll
C:\WINDOWS\system32\{1d619cc7-79b9-257f-d140-6158e753a647}.dll-uninst.exe
C:\WINDOWS\system32\{a2ac4b12-8775-5d94-2c0d-f0514d50175d}.dll
C:\WINDOWS\system32\{a2ac4b12-8775-5d94-2c0d-f0514d50175d}.dll-uninst.exe
C:\WINDOWS\system32\519.tmp
C:\WINDOWS\system32\blphc10oj0ecbr.scr
C:\WINDOWS\system32\g88.exe
C:\WINDOWS\system32\iftuyszv.exe
C:\WINDOWS\system32\jjwnw64k.exe
C:\WINDOWS\system32\lphc10oj0ecbr.exe
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\phc10oj0ecbr.bmp
C:\WINDOWS\system32\rwwnw64d.exe
C:\WINDOWS\system32\sysrest32.exe
C:\WINDOWS\TEK76.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\Documents and Settings\xplicitz\Application Data\MBOLS~1
C:\Documents and Settings\xplicitz\Application Data\MBOLS~1\??mbols\
C:\Documents and Settings\xplicitz\Application Data\MBOLS~1\services.exe
C:\Documents and Settings\xplicitz\Application Data\SpeedRunner
C:\Documents and Settings\xplicitz\Application Data\SpeedRunner\config.cfg
C:\Documents and Settings\xplicitz\Application Data\SpeedRunner\SpeedRunner.exe
C:\Documents and Settings\xplicitz\Application Data\SpeedRunner\SRUninstall.exe
C:\Documents and Settings\xplicitz\Local Settings\Temporary Internet Files\bestwiner.stt
C:\Program Files\AntiSpywareMaster
C:\Program Files\AntiSpywareMaster\asm.exe
C:\Program Files\Common Files\qmfk
C:\Program Files\Common Files\qmfk\qmfka.exe
C:\Program Files\Common Files\qmfk\qmfka.lck
C:\Program Files\Common Files\qmfk\qmfkd\class-barrel
C:\Program Files\Common Files\qmfk\qmfkd\qmfkc.dll
C:\Program Files\Common Files\qmfk\qmfkd\vocabulary
C:\Program Files\Common Files\qmfk\qmfkl.exe
C:\Program Files\Common Files\qmfk\qmfkl.lck
C:\Program Files\Common Files\qmfk\qmfkm.exe
C:\Program Files\Common Files\qmfk\qmfkm.lck
C:\Program Files\Common Files\qmfk\qmfkp.exe
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\inetget2
C:\Program Files\inetget2\SRInstaller.exe
C:\Program Files\Internet Explorer\dicovunej.html
C:\Program Files\Internet Explorer\zysihytuk.dll
C:\Program Files\Internet Explorer\zysihytuk427.dll
C:\Program Files\JavaCore
C:\Program Files\JavaCore\JavaCore.exe
C:\Program Files\JavaCore\UnInstall.exe
C:\Program Files\network monitor
C:\Program Files\network monitor\netmon.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\shc70oj0ecbr
C:\Program Files\shc70oj0ecbr\database.dat
C:\Program Files\shc70oj0ecbr\license.txt
C:\Program Files\shc70oj0ecbr\MFC71.dll
C:\Program Files\shc70oj0ecbr\MFC71ENU.DLL
C:\Program Files\shc70oj0ecbr\msvcp71.dll
C:\Program Files\shc70oj0ecbr\msvcr71.dll
C:\Program Files\shc70oj0ecbr\shc70oj0ecbr.exe
C:\Program Files\shc70oj0ecbr\shc70oj0ecbr.exe.local
C:\Program Files\shc70oj0ecbr\shc70oj0ecbrSkin.dll
C:\Program Files\shc70oj0ecbr\Uninstall.exe
C:\Program Files\Spcron
C:\Program Files\Spcron\Spc.dll
C:\Program Files\Svconr
C:\Program Files\Svconr\Svconr.exe
C:\Program Files\Temporary
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\Temp\vtmp2
C:\Temp\vtmp2\ktnv33.log
C:\WINDOWS\444.0
C:\WINDOWS\444.470
C:\WINDOWS\b103.exe
C:\WINDOWS\b116.exe
C:\WINDOWS\b152.exe
C:\WINDOWS\b155.exe
C:\WINDOWS\b156.exe
C:\WINDOWS\b157.exe
C:\WINDOWS\eHBsaWNpdHo
C:\WINDOWS\eHBsaWNpdHo\asappsrv.dll
C:\WINDOWS\eHBsaWNpdHo\command.exe
C:\WINDOWS\eHBsaWNpdHo\yJ1PuqhDxJC.vbs
C:\WINDOWS\lfn.exe
C:\WINDOWS\mainms.vpi
C:\WINDOWS\megavid.cdt
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\mrofinu572.exe.tmp
C:\WINDOWS\muotr.so
C:\WINDOWS\portsv.exe
C:\WINDOWS\qmfk
C:\WINDOWS\qmfk\qmfk.dat
C:\WINDOWS\qmfk\wu
C:\WINDOWS\system32\{1d619cc7-79b9-257f-d140-6158e753a647}.dll-uninst.exe
C:\WINDOWS\system32\{1d619cc7-79b9-257f-d140-6158e753a647}.dll
C:\WINDOWS\system32\{a2ac4b12-8775-5d94-2c0d-f0514d50175d}.dll-uninst.exe
C:\WINDOWS\system32\{a2ac4b12-8775-5d94-2c0d-f0514d50175d}.dll
C:\WINDOWS\system32\105772
C:\WINDOWS\system32\105772\dllsockt.exe
C:\WINDOWS\system32\519.tmp
C:\WINDOWS\system32\A.tmp
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\blphc10oj0ecbr.scr
C:\WINDOWS\system32\btz
C:\WINDOWS\system32\btz\L3pars2.exe
C:\WINDOWS\system32\dgOXwyxx.ini
C:\WINDOWS\system32\dgOXwyxx.ini2
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\parvdmm.sys
C:\WINDOWS\system32\expo
C:\WINDOWS\system32\expo\mtcon66225.exe
C:\WINDOWS\system32\ffeal.dll
C:\WINDOWS\system32\g88.exe
C:\WINDOWS\system32\iftuyszv.exe
C:\WINDOWS\system32\inet2
C:\WINDOWS\system32\inet2\xVXdll.exe
C:\WINDOWS\system32\irlbgcww.ini
C:\WINDOWS\system32\jjwnw64k.exe
C:\WINDOWS\system32\khfDvSll.dll
C:\WINDOWS\system32\lphc10oj0ecbr.exe
C:\WINDOWS\system32\mbols~1
C:\WINDOWS\system32\mbols~1\i?xplore.exe
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\nnnmjgge.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\phc10oj0ecbr.bmp
C:\WINDOWS\system32\rcntkkdm.exe
C:\WINDOWS\system32\rqRKAtTk.dll
C:\WINDOWS\system32\rwwnw64d.exe
C:\WINDOWS\system32\sysrest.sys
C:\WINDOWS\system32\sysrest32.exe
C:\WINDOWS\system32\tsuninst.exe
C:\WINDOWS\system32\vntiho06
C:\WINDOWS\system32\vntiho06\vntiho061083.exe
C:\WINDOWS\system32\winpfz33.sys
C:\WINDOWS\system32\wwcgblri.dll
C:\WINDOWS\system32\xrem
C:\WINDOWS\system32\xrem\imapIP95.exe
C:\WINDOWS\system32\xxywXOgd.dll
C:\WINDOWS\system32\zxdnt3d.cfg
C:\WINDOWS\TEK76.exe
C:\WINDOWS\uninstall_nmon.vbs
Infected copy of C:\WINDOWS\system32\userinit.exe was found & disinfected
Restored copy from - C:\WINDOWS\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
-------\Legacy_MSSECURITY1.209.4
-------\Legacy_NETWORK_MONITOR
-------\Legacy_PARVDMM
-------\Service_cmdService
-------\Service_MsSecurity1.209.4
-------\Service_Network Monitor
-------\Service_parvdmm
((((((((((((((((((((((((( Files Created from 2008-05-09 to 2008-06-09 )))))))))))))))))))))))))))))))
.
2008-06-09 12:42 . 2008-06-09 12:42 43,065 --a------ C:\WINDOWS\acdt-pid76.exe
2008-06-09 11:01 . 2008-06-09 11:01 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Yahoo!
2008-06-09 10:51 . 2008-06-09 10:51 <DIR> d-------- C:\WINDOWS\system32\vntiho01
2008-06-09 10:24 . 2008-06-09 10:14 52,736 --a------ C:\WINDOWS\system32\36.tmp
2008-06-09 10:14 . 2008-06-09 10:04 52,736 --a------ C:\WINDOWS\system32\30.tmp
2008-06-09 09:54 . 2008-06-09 09:44 52,736 --a------ C:\WINDOWS\system32\27.tmp
2008-06-09 09:44 . 2008-06-09 09:34 52,736 --a------ C:\WINDOWS\system32\23.tmp
2008-06-09 09:34 . 2008-06-09 09:24 52,736 --a------ C:\WINDOWS\system32\1F.tmp
2008-06-09 09:24 . 2008-06-09 09:14 52,736 --a------ C:\WINDOWS\system32\1C.tmp
2008-06-09 09:14 . 2008-06-09 09:04 52,736 --a------ C:\WINDOWS\system32\19.tmp
2008-06-09 09:04 . 2008-06-09 08:53 52,736 --a------ C:\WINDOWS\system32\15.tmp
2008-06-09 08:53 . 2008-06-09 08:43 52,736 --a------ C:\WINDOWS\system32\12.tmp
2008-06-08 20:46 . 2008-06-08 20:46 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-08 14:08 . 2008-06-08 14:08 <DIR> d-------- C:\Documents and Settings\Administrator
2008-06-08 13:57 . 2008-06-08 20:35 513 --a------ C:\WINDOWS\wininit.ini
2008-06-08 13:15 . 2008-06-08 13:15 13,942 --a------ C:\WINDOWS\system32\iphone-011.ico
2008-06-08 10:33 . 2008-06-08 14:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-08 10:25 . 2008-06-08 10:25 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-06-08 10:19 . 2008-06-08 10:26 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-08 10:18 . 2008-06-08 10:18 <DIR> d-------- C:\Documents and Settings\xplicitz\Application Data\shc70oj0ecbr
2008-06-08 10:18 . 2005-04-15 19:58 1,071,088 --a------ C:\WINDOWS\system32\MSCOMCTL.OCX
2008-06-08 10:17 . 2005-08-25 18:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2008-06-08 10:14 . 2008-06-08 10:14 <DIR> d-------- C:\Program Files\uTorrent
2008-06-08 10:14 . 2008-06-09 08:31 <DIR> d-------- C:\Documents and Settings\xplicitz\Application Data\uTorrent
2008-06-07 18:35 . 2008-06-09 12:46 <DIR> d-------- C:\Temp
2008-06-07 18:35 . 2008-06-07 18:35 <DIR> d-------- C:\Documents and Settings\xplicitz\Application Data\Syntrillium
2008-06-07 18:35 . 2001-10-19 14:40 1,683,792 --a------ C:\WINDOWS\system32\wmvcore2.dll
2008-06-07 18:35 . 2001-10-19 14:40 665,424 --a------ C:\WINDOWS\system32\wmv8dmoe.dll
2008-06-07 18:35 . 2001-10-19 14:39 572,752 --a------ C:\WINDOWS\system32\wmvdmoe.dll
2008-06-07 18:35 . 2001-10-19 14:40 438,608 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2008-06-07 18:35 . 2001-10-19 02:05 285,184 --a------ C:\WINDOWS\system32\wmidx2.ocx
2008-06-07 18:35 . 2008-06-07 18:35 156,910 --a------ C:\WINDOWS\WMSysPr8.prx
2008-06-07 18:31 . 2008-06-07 18:31 <DIR> d-------- C:\WINDOWS\McAfee.com
2008-06-06 10:57 . 2008-06-06 10:57 <DIR> d-------- C:\WINDOWS\system32\SolidStateNetworks
2008-06-06 00:47 . 2008-06-06 00:47 <DIR> d-------- C:\mGame
2008-06-06 00:47 . 2008-06-06 00:47 <DIR> d-------- C:\Documents and Settings\xplicitz\Application Data\InstallShield
2008-06-06 00:44 . 2008-06-06 00:44 <DIR> d-------- C:\WINDOWS\Setup2K
2008-06-06 00:44 . 2008-06-06 00:44 <DIR> d-------- C:\Program Files\DSC Driver
2008-06-06 00:44 . 2002-10-01 14:43 119,798 --a------ C:\WINDOWS\system32\drivers\SPCA561.SYS
2008-06-06 00:44 . 2002-09-12 15:37 118,784 --a------ C:\WINDOWS\ShowBmp.exe
2008-06-06 00:44 . 2002-10-10 17:06 53,248 --a------ C:\WINDOWS\ap561.exe
2008-06-06 00:44 . 2002-08-13 18:01 14,385 --a------ C:\WINDOWS\Tw561a.ini
2008-06-06 00:44 . 2002-09-20 19:44 14,336 --a------ C:\WINDOWS\system32\dshow508.ax
2008-06-06 00:44 . 2002-08-13 18:01 7,431 --a------ C:\WINDOWS\Tw561a.src
2008-06-06 00:44 . 2002-10-11 14:27 180 --a------ C:\WINDOWS\ap561.ini
2008-06-06 00:44 . 2002-03-19 14:11 81 --a------ C:\WINDOWS\Setup8a.ini
2008-06-06 00:39 . 2008-06-06 00:39 <DIR> d-------- C:\WINDOWS\PixArt
2008-06-06 00:39 . 2008-06-06 00:39 <DIR> d-------- C:\Program Files\Common Files\PAC207
2008-06-06 00:39 . 2008-06-06 00:39 <DIR> d-------- C:\Program Files\Basic Webcam
2008-06-06 00:39 . 2006-11-03 10:59 48,128 --a------ C:\WINDOWS\system32\Remove.exe
2008-06-06 00:39 . 2007-03-16 00:10 316 --a------ C:\WINDOWS\system32\Remover.ini
2008-06-06 00:38 . 2008-06-06 00:42 <DIR> d-------- C:\Documents and Settings\xplicitz\Application Data\Yahoo!
2008-06-06 00:38 . 2008-06-06 00:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-06-06 00:36 . 2008-06-06 00:36 <DIR> d-------- C:\webcam driver pack
2008-06-06 00:32 . 2008-06-06 00:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-06-06 00:31 . 2008-06-06 00:31 <DIR> d-------- C:\Program Files\Yahoo!
2008-06-06 00:25 . 2008-06-06 00:25 <DIR> d-------- C:\Program Files\Google
2008-06-06 00:11 . 2008-06-06 00:17 <DIR> d-------- C:\WINDOWS\PAC207
2008-06-06 00:11 . 2008-06-06 00:11 <DIR> d-------- C:\Program Files\Common Files\PXIINSTC
2008-06-06 00:11 . 2008-06-06 00:11 <DIR> d-------- C:\Program Files\Common Files\PXIINST64C
2008-06-05 23:50 . 2004-08-03 23:15 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-06-05 23:50 . 2004-08-03 23:15 82,944 --a--c--- C:\WINDOWS\system32\dllcache\wdmaud.sys
2008-06-05 23:50 . 2001-08-17 14:00 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-06-05 23:50 . 2001-08-17 14:00 54,272 --a--c--- C:\WINDOWS\system32\dllcache\swmidi.sys
2008-06-05 23:50 . 2004-08-03 23:07 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2008-06-05 23:50 . 2004-08-03 23:07 52,864 --a--c--- C:\WINDOWS\system32\dllcache\dmusic.sys
2008-06-05 23:50 . 2004-08-03 23:07 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-06-05 23:50 . 2004-08-03 23:07 6,400 --a--c--- C:\WINDOWS\system32\dllcache\splitter.sys
2008-06-05 23:49 . 2008-06-05 23:49 <DIR> d-------- C:\Program Files\Realtek AC97
2008-06-05 23:40 . 2008-05-22 08:12 3,850,760 --a------ C:\WINDOWS\system32\D3DX9_38.dll
2008-06-05 23:39 . 2008-06-05 23:39 <DIR> d-------- C:\WINDOWS\system32\RTCOM
2008-06-05 23:39 . 2008-06-05 23:39 <DIR> d-------- C:\Documents and Settings\xplicitz\Application Data\Winamp
2008-06-05 23:38 . 2008-06-05 23:38 <DIR> d-------- C:\WINDOWS\Logs
2008-06-05 23:38 . 2008-06-05 23:38 <DIR> d-------- C:\Program Files\Realtek
2008-06-05 23:38 . 2008-03-05 18:07 520,192 -ra------ C:\WINDOWS\RtlExUpd.dll
2008-06-05 23:38 . 2008-06-05 23:38 315,392 --a------ C:\WINDOWS\HideWin.exe
2008-06-05 23:38 . 2004-11-18 10:42 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-06-05 23:36 . 2008-06-06 00:47 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-06-05 23:35 . 2008-06-06 00:11 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-06-05 23:31 . 2008-06-05 23:32 <DIR> d-------- C:\Program Files\middle_man
2008-06-05 23:27 . 2008-06-05 23:27 <DIR> d-------- C:\Documents and Settings\xplicitz\Application Data\Aim
2008-06-05 23:24 . 2008-06-05 23:24 <DIR> d-------- C:\WINDOWS\nvidia icons
2008-06-05 23:24 . 2008-06-05 23:31 <DIR> d-------- C:\Program Files\Viewpoint
2008-06-05 23:24 . 2008-06-05 23:24 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-06-05 23:24 . 2008-06-05 23:29 <DIR> d-------- C:\Program Files\AOD
2008-06-05 23:24 . 2008-06-05 23:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-06-05 23:24 . 2004-02-25 13:05 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-06-05 23:23 . 2008-06-05 23:23 <DIR> d-------- C:\WINDOWS\nview
2008-06-05 23:23 . 2008-06-06 00:44 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-06-05 23:23 . 2008-04-30 17:27 442,368 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-06-05 23:23 . 2008-05-02 22:46 442,368 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-06-05 23:23 . 2008-06-09 12:52 182,038 --a------ C:\WINDOWS\system32\nvapps.xml
2008-06-05 23:23 . 2008-05-02 22:46 181,895 --a------ C:\WINDOWS\system32\nvdsp.chm
2008-06-05 23:23 . 2008-05-02 22:46 121,529 --a------ C:\WINDOWS\system32\nvcpl.chm
2008-06-05 23:23 . 2008-05-02 22:46 116,384 --a------ C:\WINDOWS\system32\nv3d.chm
2008-06-05 23:23 . 2008-05-02 22:46 54,988 --a------ C:\WINDOWS\system32\nvmob.chm
2008-06-05 23:23 . 2008-05-02 22:46 18,070 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-06-05 23:21 . 2008-06-05 23:21 <DIR> d---s---- C:\Documents and Settings\xplicitz\UserData
2008-06-05 23:18 . 2008-06-05 23:18 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-06-05 23:07 . 2007-03-19 16:18 104,064 --a------ C:\WINDOWS\system32\drivers\viamraid.sys
2008-06-05 23:00 . 2008-06-08 09:08 <DIR> d-------- C:\Documents and Settings\xplicitz
2008-05-20 14:02 . 2008-05-20 14:02 32,768 --a------ C:\WINDOWS\system32\vntiho01\vntiho011065.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-06 05:52 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-28 13:22 507,400 ----a-w C:\WINDOWS\system32\XAudio2_1.dll
2008-05-28 13:22 238,088 ----a-w C:\WINDOWS\system32\xactengine3_1.dll
2008-05-28 13:21 65,032 ----a-w C:\WINDOWS\system32\XAPOFX1_0.dll
2008-05-28 13:21 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_4.dll
2008-05-22 15:12 467,984 ----a-w C:\WINDOWS\system32\d3dx10_38.dll
2008-05-22 15:12 1,491,992 ----a-w C:\WINDOWS\system32\D3DCompiler_38.dll
2008-05-21 00:53 4,800,000 ----a-r C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-05-16 21:39 16,862,720 ----a-r C:\WINDOWS\RTHDCPL.exe
2008-04-26 09:41 142 ----a-w C:\Program Files\page.html
2008-04-02 16:27 1,196,032 ----a-r C:\WINDOWS\RtlUpd.exe
2006-12-03 01:05 2,522 ----a-w C:\Program Files\func.js
2006-11-25 07:57 482 ----a-w C:\Program Files\Del.js
2006-06-08 07:02 2,048 ----a-w C:\Program Files\func.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-09_ 8.36.33.95 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-09 15:32:35 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-09 19:50:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2001-07-15 00:32:24 69,632 ----a-w C:\WINDOWS\setupupd\temp\wsdueng.dll
- 2008-06-07 00:01:46 70,144 ----a-w C:\WINDOWS\system32\userinit.exe
+ 2004-08-04 12:00:00 24,576 ----a-w C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AFF07893-7B45-4F42-887F-8129790B6CBB}]
2008-02-27 18:54 217088 --a------ C:\Program Files\MSN Gaming Zone\hysizyfum66225.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Rihl"="C:\DOCUME~1\xplicitz\APPLIC~1\MBOLS~1\services.exe" [ ]
"AIM"="E:\Program Files\AIM\aim.exe" [2006-08-01 15:35 67112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"{9e550fc6-82f4-83e0-4687-2713c0def7b2}"="C:\WINDOWS\system32\{1d619cc7-79b9-257f-d140-6158e753a647}.dll" [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Icatch(VI) SnapDetect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Icatch(VI) SnapDetect.lnk
backup=C:\WINDOWS\pss\Icatch(VI) SnapDetect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^xplicitz^Start Menu^Programs^Startup^Deewoo.lnk]
path=C:\Documents and Settings\xplicitz\Start Menu\Programs\Startup\Deewoo.lnk
backup=C:\WINDOWS\pss\Deewoo.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xplicitz^Start Menu^Programs^Startup^DW_Start.lnk]
path=C:\Documents and Settings\xplicitz\Start Menu\Programs\Startup\DW_Start.lnk
backup=C:\WINDOWS\pss\DW_Start.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^xplicitz^Start Menu^Programs^Startup^SpywareGuard.lnk]
path=C:\Documents and Settings\xplicitz\Start Menu\Programs\Startup\SpywareGuard.lnk
backup=C:\WINDOWS\pss\SpywareGuard.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
--a------ 2006-08-01 15:35 67112 E:\Program Files\AIM\aim.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
C:\WINDOWS\system32\rcntkkdm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JavaCore]
C:\Program Files\\JavaCore\\JavaCore.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lphc10oj0ecbr]
C:\WINDOWS\system32\lphc10oj0ecbr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-05-02 22:46 13529088 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-05-02 22:46 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\qmfk]
C:\Program Files\Common Files\qmfk\qmfkm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rihl]
C:\DOCUME~1\xplicitz\APPLIC~1\MBOLS~1\services.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu572.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMshc70oj0ecbr]
C:\Program Files\shc70oj0ecbr\shc70oj0ecbr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-ra------ 2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedRunner]
C:\Documents and Settings\xplicitz\Application Data\SpeedRunner\SpeedRunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 e:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Svconr]
C:\Program Files\Svconr\Svconr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-06-06 00:25 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vycn]
C:\Program Files\Common Files\??sks\l?gonui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zmarrn]
C:\WINDOWS\system32\??mbols\i?xplore.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{62-2E-E9-91-DW}]
c:\windows\system32\jjwnw64k.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{9e550fc6-82f4-83e0-4687-2713c0def7b2}]
C:\WINDOWS\system32\{1d619cc7-79b9-257f-d140-6158e753a647}.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"cmdService"=2 (0x2)
"Network Monitor"=2 (0x2)
"MsSecurity1.209.4"=2 (0x2)
"gusvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"E:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18677:TCP"= 18677:TCP:*:Disabled:SolidNetworkManager
"18677:UDP"= 18677:UDP:*:Disabled:SolidNetworkManager
"58740:TCP"= 58740:TCP:*:Disabled:SolidNetworkManager
"58740:UDP"= 58740:UDP:*:Disabled:SolidNetworkManager
"30324:TCP"= 30324:TCP:*:Disabled:SolidNetworkManager
"30324:UDP"= 30324:UDP:*:Disabled:SolidNetworkManager
S3 XDva168;XDva168;C:\WINDOWS\system32\XDva168.sys []
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-09 12:51:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-06-09 12:53:34 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-09 19:53:25
ComboFix2.txt 2008-06-09 15:37:07
Pre-Run: 26,907,942,912 bytes free
Post-Run: 26,947,522,560 bytes free
419