Combofixlog
ComboFix 09-06-17.04 - Owner 06/18/2009 9:58.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.146 [GMT -7:00]
Running from: c:\documents and settings\Owner\Desktop\adsa.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\UACvxdpmylyxmynsms.sys
c:\windows\system32\UACdthjvrndakqgxvv.dll
c:\windows\system32\UACehjfenoeouudtkh.dll
c:\windows\system32\UACeoerrhuqspfsitu.dll
c:\windows\system32\UACgvpbifpfcidjtkq.log
c:\windows\system32\UACjduiwsippaqwkjx.dll
c:\windows\system32\UACkrgikjlhlpqtkba.dat
c:\windows\system32\UAClxutahdmdrltrdy.log
c:\windows\system32\UACobqoikqxwnkoobr.dll
c:\windows\system32\UACqcqmltensqimoyp.dll
c:\windows\system32\UACslkllaltgfbekwf.log
c:\windows\system32\UACvdsiqlhghkfkyxq.db
c:\windows\system32\drivers\SKYNETrnfvcxxl.sys
c:\windows\system32\drivers\UACvxdpmylyxmynsms.sys
c:\windows\system32\kungsfbyeqdwij.dat
c:\windows\system32\kungsfdvtyhosw.dll
c:\windows\system32\kungsfmbiimicg.dll
c:\windows\system32\UACdthjvrndakqgxvv.dll
c:\windows\system32\UACehjfenoeouudtkh.dll
c:\windows\system32\UACeoerrhuqspfsitu.dll
c:\windows\system32\UACgvpbifpfcidjtkq.log
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjduiwsippaqwkjx.dll
c:\windows\system32\UACkrgikjlhlpqtkba.dat
c:\windows\system32\UAClxutahdmdrltrdy.log
c:\windows\system32\UACobqoikqxwnkoobr.dll
c:\windows\system32\UACqcqmltensqimoyp.dll
c:\windows\system32\UACslkllaltgfbekwf.log
c:\windows\system32\uactmp.db
c:\windows\system32\UACvdsiqlhghkfkyxq.db
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Service_SKYNEToixjinix
((((((((((((((((((((((((( Files Created from 2009-05-18 to 2009-06-18 )))))))))))))))))))))))))))))))
.
2009-06-18 04:44 . 2009-06-18 04:44 -------- d-----w- c:\program files\UltraISO
2009-06-18 04:44 . 2009-06-18 04:44 -------- d-----w- c:\program files\Common Files\EZB Systems
2009-06-17 21:56 . 2009-06-17 21:56 -------- d-----w- C:\2.TEMPO
2009-06-17 21:56 . 2009-06-17 21:56 -------- d-----w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2009-06-17 21:55 . 2009-06-17 21:54 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-17 21:52 . 2009-06-17 21:52 152576 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-17 20:46 . 2009-06-17 20:46 -------- d--h--w- c:\windows\PIF
2009-06-17 10:49 . 2009-06-17 10:50 -------- d-----w- C:\gmer
2009-06-17 08:05 . 2009-06-17 08:05 -------- d-----w- c:\program files\RFA
2009-06-17 06:15 . 2009-05-26 20:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 06:15 . 2009-06-17 06:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-17 06:15 . 2009-06-17 06:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-17 06:15 . 2009-05-26 20:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-17 03:50 . 2009-06-18 09:59 -------- d-----w- C:\1.Junk
2009-06-17 03:47 . 2009-06-17 22:00 -------- d-----w- c:\program files\uTorrent
2009-06-17 03:47 . 2009-06-17 22:00 -------- d-----w- c:\documents and settings\Owner\Application Data\uTorrent
2009-06-17 03:38 . 2009-06-18 09:22 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-17 03:38 . 2009-06-17 03:39 -------- d-----w- c:\program files\SpywareBlaster
2009-06-17 03:38 . 2009-06-17 22:01 -------- d-----w- c:\program files\PeerGuardian2
2009-06-17 03:38 . 2009-06-17 21:55 -------- d-----w- c:\program files\SpywareGuard
2009-06-17 03:20 . 2009-06-17 10:39 -------- d-----w- c:\documents and settings\All Users\Application Data\RFA_Backups
2009-06-17 00:35 . 2009-06-17 00:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-17 00:35 . 2009-06-17 00:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-17 00:25 . 2009-06-17 00:26 -------- d-----w- c:\documents and settings\Owner\Application Data\Media Player Classic
2009-06-17 00:25 . 2009-06-17 00:25 -------- d-----w- c:\program files\Trend Micro
2009-06-17 00:10 . 2008-12-09 04:45 92488 ----a-w- c:\windows\system32\drivers\SysPlant.sys
2009-06-17 00:10 . 2009-06-17 00:10 60800 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-06-17 00:10 . 2009-06-17 00:10 123952 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-06-17 00:06 . 2008-12-09 05:42 669000 -c--a-w- c:\documents and settings\All Users\Application Data\Symantec\Cached Installs\{3BAB4914-9CC1-4CC2-A3DA-56EF62DFD373}\smcinst.exe
2009-06-17 00:06 . 2006-05-16 18:58 2584848 -c--a-w- c:\documents and settings\All Users\Application Data\Symantec\Cached Installs\{3BAB4914-9CC1-4CC2-A3DA-56EF62DFD373}\WindowsInstaller-KB893803-x86.exe
2009-06-17 00:06 . 2008-12-12 03:18 300432 -c--a-w- c:\documents and settings\All Users\Application Data\Symantec\Cached Installs\{3BAB4914-9CC1-4CC2-A3DA-56EF62DFD373}\Setup.exe
2009-06-17 00:06 . 2008-06-30 23:36 927088 -c--a-w- c:\documents and settings\All Users\Application Data\Symantec\Cached Installs\{3BAB4914-9CC1-4CC2-A3DA-56EF62DFD373}\LuCheck.exe
2009-06-17 00:06 . 2008-06-30 23:37 3554472 -c--a-w- c:\documents and settings\All Users\Application Data\Symantec\Cached Installs\{3BAB4914-9CC1-4CC2-A3DA-56EF62DFD373}\LUSETUP.EXE
2009-06-17 00:05 . 2009-06-17 00:10 -------- d-----w- c:\program files\Symantec
2009-06-16 23:48 . 2004-05-26 21:53 15781 ----a-w- c:\windows\system32\drivers\mdc8021x.sys
2009-06-16 23:48 . 2004-05-07 20:47 79616 ----a-w- c:\windows\system32\rt2500usb.sys
2009-06-16 23:48 . 2004-05-07 20:47 79616 ----a-w- c:\windows\system32\drivers\rt2500usb.sys
2009-06-16 23:48 . 2004-04-24 05:43 374752 ----a-w- c:\windows\system32\WUSBGXP.sys
2009-06-16 23:48 . 2004-01-08 00:04 339488 ----a-w- c:\windows\system32\WUSB20XP.sys
2009-06-16 23:48 . 2003-10-13 22:30 94208 ----a-w- c:\windows\system32\GTW32N50.dll
2009-06-16 23:48 . 2003-09-26 05:15 15872 ----a-w- c:\windows\system32\GTNDIS5.sys
2009-06-16 23:48 . 2009-06-16 23:48 -------- d-----w- c:\program files\Linksys Wireless-G USB Wireless Network Monitor
2009-06-16 23:43 . 2004-08-04 04:58 14848 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-06-16 23:43 . 2004-08-04 04:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2009-06-16 10:28 . 2009-06-16 10:28 60880 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-16 10:28 . 2009-06-16 10:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\TuneUp Software
2009-06-16 10:06 . 2009-06-16 10:06 -------- d-----w- c:\documents and settings\Owner\Application Data\TuneUp Software
2009-06-16 10:06 . 2009-06-16 10:06 306432 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-06-16 10:06 . 2007-12-20 17:41 29440 ----a-w- c:\windows\system32\uxtuneup.dll
2009-06-16 10:05 . 2009-06-16 10:05 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-06-16 10:05 . 2009-06-16 10:06 -------- d-----w- c:\program files\TuneUp Utilities 2008
2009-06-16 10:04 . 2009-06-16 10:04 7406 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{376DA9DC-71B3-4AB7-A80C-8ED02A736172}\_613b295c.exe
2009-06-16 10:04 . 2009-06-16 10:04 7406 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{376DA9DC-71B3-4AB7-A80C-8ED02A736172}\_31c75249.exe
2009-06-16 10:04 . 2009-06-16 10:04 23558 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{376DA9DC-71B3-4AB7-A80C-8ED02A736172}\_12bb5fca.exe
2009-06-16 10:04 . 2009-06-16 10:04 -------- d-----w- c:\program files\Foxit Software
2009-06-16 10:02 . 2009-06-17 03:26 -------- d-----w- C:\Registry Back Up Files
2009-06-16 09:27 . 2009-06-16 09:27 -------- d-----w- c:\program files\Driver Magician
2009-06-16 09:27 . 2009-06-16 09:27 -------- d-----w- c:\program files\DAMN NFO Viewer
2009-06-16 09:24 . 2007-09-04 16:56 164352 ----a-w- c:\windows\system32\unrar.dll
2009-06-16 09:24 . 2009-06-16 09:26 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2009-06-16 09:24 . 2009-06-16 09:26 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2009-06-16 09:24 . 2009-06-16 09:25 141312 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2009-06-16 09:24 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-06-16 09:24 . 2008-01-10 12:16 159839 ----a-w- c:\windows\system32\xvidvfw.dll
2009-06-16 09:24 . 2008-01-10 12:15 755027 ----a-w- c:\windows\system32\xvidcore.dll
2009-06-16 09:24 . 2008-07-25 08:34 81920 ----a-w- c:\windows\system32\dpl100.dll
2009-06-16 09:24 . 2008-07-23 16:50 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2009-06-16 09:24 . 2008-07-25 08:34 683520 ----a-w- c:\windows\system32\divx.dll
2009-06-16 09:24 . 2008-06-12 18:36 7680 ----a-w- c:\windows\system32\ff_vfw.dll
2009-06-16 09:23 . 2009-06-16 09:24 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-06-16 09:23 . 2009-06-17 21:36 -------- d-----w- c:\documents and settings\Owner\Application Data\Spyware Terminator
2009-06-16 09:23 . 2009-06-17 20:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-06-16 09:23 . 2009-06-17 22:16 -------- d-----w- c:\program files\Spyware Terminator
2009-06-16 09:20 . 2009-06-18 07:44 -------- d-----w- c:\program files\Registry Clean Expert
2009-06-16 09:18 . 2009-06-17 21:53 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-16 09:16 . 2009-06-17 00:38 -------- d-----w- c:\program files\CCleaner
2009-06-16 08:52 . 2009-06-16 08:52 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Help
2009-06-16 08:48 . 2009-06-16 08:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\Template
2009-06-16 08:44 . 2009-06-16 08:44 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AOL
2009-06-16 08:31 . 2003-01-03 13:20 65536 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{49FC50FC-F965-40D9-89B4-CBFF80941033}\ARPPRODUCTICON.exe
2009-06-08 23:22 . 2009-06-08 23:22 -------- d-----w- c:\documents and settings\Frankie & Thelma\Local Settings\Application Data\AOL Email Toolbar
2009-06-03 04:38 . 2009-06-03 04:38 -------- d-----w- c:\documents and settings\Owner\Application Data\acccore
2009-06-03 04:24 . 2009-06-03 04:24 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL OCP
2009-06-03 04:06 . 2009-06-03 04:06 686928 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\SinfInst.exe
2009-06-03 04:06 . 2009-06-03 04:06 607392 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\wbsetup.exe
2009-06-03 04:06 . 2009-06-03 04:06 7976 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\wappchck.dll
2009-06-03 04:06 . 2009-06-03 04:06 95792 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\AOLFwMgr.dll
2009-06-03 04:06 . 2009-06-03 04:06 1174536 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\prfrd.exe
2009-06-03 04:06 . 2009-06-03 04:06 383128 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\tbsetup.exe
2009-06-03 04:05 . 2009-06-03 04:06 1651320 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\reginst4.exe
2009-06-03 04:05 . 2009-06-03 04:05 205360 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\maillang.exe
2009-06-03 04:04 . 2009-06-03 04:05 6363152 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\ocpinst.exe
2009-06-03 04:04 . 2009-06-03 04:04 641960 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\SLinst.exe
2009-06-03 04:03 . 2009-06-03 04:04 357304 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\frntinst.exe
2009-06-03 04:03 . 2009-06-03 04:03 2439824 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\ocpinsti.exe
2009-06-03 04:03 . 2009-06-03 04:03 17192 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\brwschk.dll
2009-06-03 04:03 . 2009-06-03 04:03 7976 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\jgchck.dll
2009-06-03 04:03 . 2009-06-03 04:03 36136 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\postproc.exe
2009-06-03 04:03 . 2009-06-03 04:03 127224 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\afixlang.exe
2009-06-03 04:03 . 2009-06-03 04:03 1362936 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\msvc9rt.exe
2009-06-03 04:02 . 2009-06-03 04:03 964544 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\acslaeu.exe
2009-06-03 04:02 . 2009-06-03 04:02 37672 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\ACSInstC.dll
2009-06-03 04:02 . 2009-06-03 04:02 1218808 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\mailinst.exe
2009-06-03 04:02 . 2009-06-03 04:02 80368 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\alsetup.exe
2009-06-03 04:02 . 2009-06-03 04:02 15144 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\ocpchk.dll
2009-06-03 04:02 . 2009-06-03 04:02 17704 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\imappver.dll
2009-06-03 04:02 . 2009-06-03 04:02 849096 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\muinst.exe
2009-06-03 04:02 . 2009-06-03 04:02 74536 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\instSup.dll
2009-06-03 04:02 . 2009-06-03 04:02 49960 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\SiNdInst.dll
2009-06-03 04:02 . 2009-06-03 04:02 8032 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\vistachk.dll
2009-06-03 04:00 . 2009-06-03 04:00 1364064 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\fdosetup.exe
2009-06-03 04:00 . 2009-06-03 04:00 11048 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\ocfcheck.dll
2009-06-03 04:00 . 2009-06-03 04:00 294376 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\iacinst.exe
2009-06-03 04:00 . 2009-06-03 04:00 45864 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\ACSInstA.dll
2009-06-03 04:00 . 2009-06-03 04:00 74536 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\instSup.dll
2009-06-03 04:00 . 2009-06-03 04:00 1612544 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\acslang.exe
2009-06-03 04:00 . 2009-06-03 04:00 83808 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\ProgUpd.dll
2009-06-03 03:58 . 2009-06-03 04:00 10533216 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\noneCodesignFilesBundle.exe
2009-06-03 03:58 . 2009-06-03 03:58 7976 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\suitedet.dll
2009-06-03 03:57 . 2009-06-03 03:58 1484136 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\acscore.exe
2009-06-03 03:57 . 2009-06-03 03:57 420152 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\AIMLang.exe
2009-06-03 03:57 . 2009-06-03 03:57 122832 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\jginst.exe
2009-06-03 03:57 . 2009-06-03 03:57 7464 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\ie7chck.dll
2009-06-03 03:57 . 2009-06-03 03:57 2426184 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\frntlang.exe
2009-06-03 03:57 . 2009-06-03 03:57 11048 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\tbinst.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-18 16:37 . 2006-11-30 22:24 -------- d-----w- c:\program files\Google
2009-06-18 16:21 . 2003-01-03 13:27 -------- d-----w- c:\program files\Common Files\Real
2009-06-18 16:20 . 2003-01-03 13:26 -------- d-----w- c:\program files\Common Files\aolshare
2009-06-18 16:20 . 2003-01-03 13:26 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-06-18 16:18 . 2003-01-03 13:41 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-18 07:20 . 2006-10-20 19:30 -------- d-----w- c:\program files\LimeWire
2009-06-18 07:20 . 2003-01-03 13:26 -------- d-----w- c:\program files\America Online 9.0
2009-06-17 21:54 . 2003-01-03 13:44 -------- d-----w- c:\program files\Java
2009-06-17 00:13 . 2003-01-03 13:42 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-17 00:12 . 2003-01-03 13:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-17 00:10 . 2009-06-17 00:10 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-06-17 00:10 . 2009-06-17 00:10 10563 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-06-16 23:34 . 2008-02-06 03:14 -------- d-----w- c:\program files\MySpace
2009-06-16 09:02 . 2006-07-28 19:10 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-06-16 09:00 . 2009-06-16 08:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\AOL
2009-06-16 08:48 . 2003-01-03 13:26 -------- d-----w- c:\program files\Common Files\AOL
2009-06-16 08:48 . 2009-06-16 08:48 44 ----a-w- c:\documents and settings\Administrator\Application Data\wklnhst.dat
2009-06-16 08:43 . 2003-01-03 13:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-09 08:24 . 2006-02-13 23:51 3994 -c--a-w- c:\documents and settings\Frankie & Thelma\Application Data\wklnhst.dat
2009-06-08 23:18 . 2006-02-13 23:51 60880 ----a-w- c:\documents and settings\Frankie & Thelma\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-03 04:02 . 2009-06-03 04:01 1983120 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\NexusSuite\2.1.84.1\comps\toolbar.exe
2009-06-03 03:56 . 2006-07-28 18:56 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2009-06-02 02:34 . 2007-07-24 22:21 -------- d-----w- c:\documents and settings\Owner\Application Data\Simple Star
2009-06-02 02:33 . 2007-07-24 22:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Simple Star
2009-06-02 02:33 . 2007-07-24 22:21 -------- d-----w- c:\program files\Common Files\Simple Star Shared
2009-06-01 16:38 . 2006-08-04 19:24 6201 ----a-w- c:\documents and settings\All Users\Application Data\AOL\AOLszs.drv
2009-06-01 03:48 . 2004-10-13 19:18 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-01 03:22 . 2004-10-08 06:03 34968 ----a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat
2009-05-07 15:44 . 2003-01-03 11:41 344064 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2004-02-07 02:05 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 09:58 . 2003-01-03 11:42 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:26 . 2003-01-03 13:16 583168 ----a-w- c:\windows\system32\rpcrt4.dll
2007-01-22 02:19 . 2005-08-17 01:31 7168 -csha-w- c:\program files\Thumbs.db
2005-06-17 21:57 . 2005-05-03 01:54 205824 -c--a-w- c:\program files\GoodFaithEstimates[1].DOC.xls
2005-06-10 02:28 . 2005-05-09 21:00 235008 -c--a-w- c:\program files\GoodFaithEstimates(1).DOC.xls
2005-04-29 20:48 . 2005-04-29 20:48 131584 -c--a-w- c:\program files\ATTACHMENT1.doc
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WUSB54Gv4"="c:\program files\Linksys Wireless-G USB Wireless Network Monitor\InvokeSvc3.exe" [2004-04-19 24576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-17 148888]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2004-03-03 46080]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-03-03 2904064]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-08-14 115560]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-03-03 782336]
"nForce Tray Options"="sstray.exe" - c:\windows\system32\sstray.exe [2003-09-03 73728]
"CHotkey"="zHotkey.exe" - c:\windows\zHotkey.exe [2004-05-18 543232]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\2.tempo\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w- c:\2.tempo\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^Kevin & Joey^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^AOL Desktop.lnk]
backup=c:\windows\pss\AOL Desktop.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^SpywareGuard.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\SpywareGuard.lnk
backup=c:\windows\pss\SpywareGuard.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1154027607\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/16/2009 6:04 PM 101936]
R3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;c:\windows\system32\drivers\rt2500usb.sys [6/16/2009 4:48 PM 79616]
S2 Ca533av;Mega DV(Video);c:\windows\system32\Drivers\Ca533av.sys --> c:\windows\system32\Drivers\Ca533av.sys [?]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [11/18/2008 6:17 PM 23888]
S3 Radialpoint Security Services;Radialpoint Security Services;c:\windows\system32\dllhost.exe [1/3/2003 4:41 AM 5120]
S3 USBCamera;DSC Still Image Capture (CA533A);c:\windows\system32\Drivers\Bulk533.sys --> c:\windows\system32\Drivers\Bulk533.sys [?]
S4 Viewpoint Manager Service;Viewpoint Manager Service; [x]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ATWPKT2
*NewlyCreated* - GTNDIS5
*Deregistered* - ATWPKT2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-06-16 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2008-01-08 20:31]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-Symantec Antvirus
.
------- Supplementary Scan -------
.
uStart Page = hxxp://yahoo.com/
mStart Page = hxxp://www.msn.com
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-18 10:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(796)
c:\2.tempo\SASWINLO.dll
- - - - - - - > 'explorer.exe'(3564)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\SpywareGuard\spywareguard.dll
c:\2.tempo\SASSEH.DLL
c:\windows\system32\browselc.dll
c:\program files\SpywareGuard\dlprotect.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\BRSS01A.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\InfoMyCa.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\wanmpsvc.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Common Files\AOL\1154027607\ee\aolsoftware.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-18 10:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-18 17:22
Pre-Run: 134,823,608,320 bytes free
Post-Run: 135,320,940,544 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptOut
347 --- E O F --- 2009-06-17 06:33