ComboFix 08-09-30.03 - Oscar 2008-10-01 19:32:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.629 [GMT 1:00]
Running from: C:\Documents and Settings\Oscar\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\aoortcfq.ini
C:\WINDOWS\system32\byXQJDsP.dll
C:\WINDOWS\system32\cgcwlvki.ini
C:\WINDOWS\system32\gcccpvsh.ini
C:\WINDOWS\system32\hmrimfnp.ini
C:\WINDOWS\system32\hqlqrkla.ini
C:\WINDOWS\system32\iaoxhlpn.ini
C:\WINDOWS\system32\ibysuwld.ini
C:\WINDOWS\system32\iPpYbccf.ini
C:\WINDOWS\system32\jmsvgyxq.ini
C:\WINDOWS\system32\jngubkns.ini
C:\WINDOWS\system32\jnhlqjkp.ini
C:\WINDOWS\system32\kifsgtcl.ini
C:\WINDOWS\system32\mmnonUtv.ini
C:\WINDOWS\system32\mmnonUtv.ini2
C:\WINDOWS\system32\mVutCJjl.ini
C:\WINDOWS\system32\nybcdcga.dll
C:\WINDOWS\system32\oiosevxj.ini
C:\WINDOWS\system32\opkqqxld.ini
C:\WINDOWS\system32\pwrxwvhf.dll
C:\WINDOWS\system32\rqcffhfh.ini
C:\WINDOWS\system32\rtqbmpvo.ini
C:\WINDOWS\system32\rvrsvxeo.ini
C:\WINDOWS\system32\tqgdeovj.ini
C:\WINDOWS\system32\uoxhavxq.ini
C:\WINDOWS\system32\uuhikpet.ini
C:\WINDOWS\system32\vtUnonmm.dll
C:\WINDOWS\system32\vyufyecb.ini
C:\WINDOWS\system32\xgxjyaer.ini
C:\WINDOWS\system32\ymfsgfds.ini
C:\WINDOWS\system32\yywljdwk.ini
D:\WinRAR.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MCHINJDRV
-------\Legacy_RESTORE
((((((((((((((((((((((((( Files Created from 2008-09-01 to 2008-10-01 )))))))))))))))))))))))))))))))
.
2008-10-01 18:20 . 2008-10-01 18:23 <DIR> d-------- C:\fixwareout
2008-09-30 23:06 . 2008-09-30 23:06 937,655 --ahs---- C:\WINDOWS\system32\cgcwlvki.tmp
2008-09-30 22:35 . 2008-09-30 22:35 79,488 --a------ C:\WINDOWS\system32\sdfgsfmy.dll
2008-09-30 22:31 . 2008-09-30 22:31 79,488 --a------ C:\WINDOWS\system32\lctgsfik.dll
2008-09-30 10:40 . 2008-09-30 10:40 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2008-09-30 10:40 . 2008-09-30 19:23 <DIR> d-------- C:\Documents and Settings\Oscar\Application Data\U3
2008-09-29 22:20 . 2008-09-29 22:20 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2008-09-29 22:20 . 2008-09-29 22:20 <DIR> d-------- C:\Program Files\MSECACHE
2008-09-29 17:47 . 2008-09-29 17:55 <DIR> d-------- C:\Documents and Settings\Oscar\.scorched3d
2008-09-29 17:26 . 2008-09-29 17:26 20 --a------ C:\WINDOWS\mafosav.INI
2008-09-28 21:57 . 2008-09-28 21:58 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-28 21:57 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-28 21:57 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-28 20:45 . 2008-09-28 20:45 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-28 20:44 . 2008-09-28 20:44 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-28 20:34 . 2008-09-28 20:49 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-28 20:33 . 2008-06-23 17:57 6,066,176 --a------ C:\WINDOWS\system32\DllCache\ieframe.dll
2008-09-28 20:33 . 2007-04-17 10:32 2,455,488 --a------ C:\WINDOWS\system32\DllCache\ieapfltr.dat
2008-09-28 20:33 . 2007-03-08 06:10 991,232 --a------ C:\WINDOWS\system32\DllCache\ieframe.dll.mui
2008-09-28 20:33 . 2008-06-23 17:57 459,264 --a------ C:\WINDOWS\system32\DllCache\msfeeds.dll
2008-09-28 20:33 . 2008-06-23 17:57 383,488 --a------ C:\WINDOWS\system32\DllCache\ieapfltr.dll
2008-09-28 20:33 . 2008-05-01 15:30 331,776 --a------ C:\WINDOWS\system32\DllCache\msadce.dll
2008-09-28 20:33 . 2008-06-23 17:57 267,776 --a------ C:\WINDOWS\system32\DllCache\iertutil.dll
2008-09-28 20:33 . 2008-06-23 17:57 63,488 --a------ C:\WINDOWS\system32\DllCache\icardie.dll
2008-09-28 20:33 . 2008-06-23 17:57 52,224 --a------ C:\WINDOWS\system32\DllCache\msfeedsbs.dll
2008-09-28 20:33 . 2008-06-23 10:20 13,824 --a------ C:\WINDOWS\system32\DllCache\ieudinit.exe
2008-09-28 20:22 . 2008-09-28 20:22 <DIR> d-------- C:\WINDOWS\ERUNT
2008-09-28 20:17 . 2008-10-01 18:09 <DIR> d-------- C:\SDFix
2008-09-28 20:06 . 2008-09-28 20:06 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-09-28 13:36 . 2008-09-28 13:36 <DIR> d-------- C:\Documents and Settings\Oscar\Application Data\TuneUp Software
2008-09-28 13:03 . 2008-09-28 20:16 1,536 --a------ C:\WINDOWS\system32\6
2008-09-28 03:44 . 2008-09-28 03:44 <DIR> d-------- C:\Program Files\Bonjour
2008-09-28 02:42 . 2008-09-28 02:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-09-28 02:34 . 2008-09-28 02:34 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-09-28 01:03 . 2008-09-28 01:03 3,420,480 -r-hs---- C:\WINDOWS\tsvss.exe
2008-09-28 00:16 . 2008-09-28 00:16 <DIR> d-------- C:\Documents and Settings\Oscar\Application Data\Ambient Design
2008-09-10 21:35 . 2008-09-10 22:34 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-09-09 21:01 . 2008-09-09 21:01 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-09-09 20:57 . 2008-09-20 23:21 1,796 --a------ C:\WINDOWS\system32\ealregsnapshot1.reg
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-01 18:36 --------- d-----w C:\Documents and Settings\Oscar\Application Data\WTablet
2008-10-01 17:23 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-30 22:22 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-28 19:45 --------- d-----w C:\Documents and Settings\Oscar\Application Data\SUPERAntiSpyware.com
2008-09-20 22:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-09 20:28 --------- d-----w C:\Documents and Settings\Oscar\Application Data\SecondLife
2008-09-09 19:56 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-30 18:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-19 20:56 --------- d-----w C:\Documents and Settings\LocalService\Application Data\WTablet
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-10-01 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7qexx.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 D:\Program Files\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2008-02-20 15:33 963072 D:\Program Files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2007-01-10 08:59 115816 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-10-01 13:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2004-09-13 15:49 49152 D:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a--c--- 2008-02-19 14:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSN]
-r-hs---- 2008-09-28 01:03 3420480 C:\WINDOWS\tsvss.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a--c--- 2007-12-05 02:41 8523776 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a--c--- 2007-12-05 02:41 81920 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
--a------ 2008-02-22 22:42 3537968 D:\Program Files\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a--c--- 2005-05-03 17:43 69632 C:\WINDOWS\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
--a--c--- 2006-05-04 15:26 2808832 C:\WINDOWS\ALCWZRD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a--c--- 2006-10-01 13:00 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a--c--- 2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a--c--- 2006-07-21 15:14 86016 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"D:\Program Files\Combat Arms\Combat Arms\CombatArms.exe"= D:\Program Files\Combat Arms\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"D:\Program Files\Combat Arms\Combat Arms\Engine.exe"= D:\Program Files\Combat Arms\Combat Arms\Engine.exe:*Enabled:Engine.exe
"D:\\Program Files\\Combat Arms\\Combat Arms\\NMService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8392:TCP"= 8392:TCP:BitComet 8392 TCP
"8392:UDP"= 8392:UDP:BitComet 8392 UDP
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2006-02-14 5632]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2006-11-15 6272]
S3 iMSPCLOj;iMSPCLOj;C:\DOCUME~1\Oscar\LOCALS~1\Temp\iMSPCLOj.sys [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\SetupWizard.exe
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
BHO-{1883990C-EB31-499A-81A9-AA821349A344} - C:\WINDOWS\system32\vtUnonmm.dll
MSConfigStartUp-a0d9a747 - C:\WINDOWS\system32\ikvlwcgc.dll
MSConfigStartUp-ANTIVIRUS - C:\Program Files\MicroAV\MicroAV.exe
MSConfigStartUp-BMa3ea94db - C:\WINDOWS\system32\lwiegwvd.dll
MSConfigStartUp-Google Desktop Search - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
MSConfigStartUp-Jnskdfmf9eldfd - C:\DOCUME~1\Oscar\LOCALS~1\Temp\csrssc.exe
MSConfigStartUp-ksjf93orkekfniw73nfdd - C:\DOCUME~1\Oscar\LOCALS~1\Temp\winlogen.exe
MSConfigStartUp-lphcjvkj0ejdg - C:\WINDOWS\system32\lphcjvkj0ejdg.exe
MSConfigStartUp-rs32net - C:\WINDOWS\System32\rs32net.exe
MSConfigStartUp-SUPERAntiSpyware - D:\Program Files\Ares Songs\SUPERAntiSpyware.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Oscar\Application Data\Mozilla\Firefox\Profiles\tbd6nkx8.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://my.att.net/
FF -: plugin - C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - D:\Program Files\Plugins\noreg\NPVeohVersion.dll
FF -: plugin - D:\Program Files\plugins\npBitCometAgent.dll
FF -: plugin - D:\Program Files\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF -: plugin - D:\Program Files\plugins\npnul32.dll
FF -: plugin - D:\Program Files\Reader 8.0\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-01 19:38:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
.
**************************************************************************
.
Completion time: 2008-10-01 19:42:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-01 18:42:39
Pre-Run: 652,840,960 bytes free
Post-Run: 571,482,112 bytes free
256 --- E O F --- 2008-09-28 22:53:00
anything ? that might help u