Allright, that seemed to work fairly well, ComboFix ran un-interrupted for about 20 mins before finishing.
One note though, it started off by displaying a dialog box titled "Registry Editor", saying: "Cannot import import: Error opening the file. There may be a disk or file system error". Not sure if that matters.
I'll keep the two logs in two separate posts for easy reading, and since my real name also appears in the ComboFix log I replaced it with MYREALNAME. I don't mind telling it to specific people here, I just don't want it spiderable on any public forums
ComboFix log:
ComboFix 08-03-23.5 - MYREALNAME 2008-03-24 12:52:46.1 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.705 [GMT 1:00]
Running from: C:\Documents and Settings\MYREALNAME\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\MYREALNAME\Application Data\macromedia\Flash Player\#SharedObjects\EHB8NA6E\iforex.com
C:\Documents and Settings\MYREALNAME\Application Data\macromedia\Flash Player\#SharedObjects\EHB8NA6E\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\MYREALNAME\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\MYREALNAME\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Program Files\Common Files\mcroso~1.net
C:\Program Files\Common Files\mcroso~1.net\M?crosoft.NET\
C:\Program Files\Common Files\mcroso~1.net\winword.exe
C:\Program Files\Common Files\oe
C:\Program Files\outerinfo
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINNT\BM5ba86914.xml
C:\WINNT\pskt.ini
C:\WINNT\system32\ext
C:\WINNT\system32\ext\TGbn1dll.exe
C:\WINNT\system32\hbgveofp.ini
C:\WINNT\system32\ljjkihe.dll
C:\WINNT\system32\mnnmp.ini
C:\WINNT\system32\mnnmp.ini2
C:\WINNT\system32\pac.txt
C:\WINNT\system32\pfoevgbh.dll
C:\WINNT\system32\pmnnm.dll
C:\WINNT\system32\pthreadVC.dll
C:\WINNT\system32\rfxbtebd.dll
C:\WINNT\system32\ssqrppo.dll
C:\WINNT\system32\xbrceekd.dll
C:\WINNT\Web\default.htt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
-------\Legacy_GB
-------\Legacy_LDRSVC
-------\Legacy_NETWORK_MONITOR
-------\Service_cmdService
((((((((((((((((((((((((( Files Created from 2008-02-24 to 2008-03-24 )))))))))))))))))))))))))))))))
.
2008-03-24 13:05 . 08-03-24 13:05 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_840.dat
2008-03-24 13:04 . 08-03-24 13:04 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_f8.dat
2008-03-23 13:25 . 08-03-23 13:25 <DIR> d-------- C:\Documents and Settings\MYREALNAME\Application Data\Grisoft
2008-03-23 13:25 . 08-03-23 13:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-23 13:25 . 07-05-30 13:10 10,872 --a------ C:\WINNT\system32\drivers\AvgAsCln.sys
2008-03-23 11:09 . 08-03-23 11:30 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-23 10:50 . 08-03-23 10:57 1,543,219 ---hs---- C:\WINNT\system32\sowgoras.ini
2008-03-23 10:31 . 08-03-23 10:31 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-22 22:39 . 08-03-23 13:46 <DIR> d--hs---- C:\WINNT\Um9iZXJ0IENlZGVyaG9sbQ
2008-03-22 22:39 . 08-03-22 22:39 <DIR> d-------- C:\WINNT\system32\xir
2008-03-22 22:39 . 08-03-23 13:46 <DIR> d-------- C:\WINNT\system32\imd4
2008-03-22 22:39 . 08-03-22 22:39 <DIR> d-------- C:\WINNT\system32\aqVreo01
2008-03-22 22:39 . 08-03-22 22:39 <DIR> d-------- C:\Temp\gbRve12
2008-03-22 22:39 . 08-03-22 22:39 37,376 --a------ C:\WINNT\17PHolmes572.exe
2008-03-22 22:39 . 08-03-22 22:39 37,376 --a------ C:\WINNT\17PHolmes1000106.exe
2008-03-20 19:37 . 08-03-20 19:37 <DIR> d-------- C:\Documents and Settings\MYREALNAME\Application Data\vlc
2008-03-20 19:36 . 08-03-20 19:36 <DIR> d-------- C:\Program Files\VideoLAN
2008-03-15 13:43 . 08-03-15 13:43 32,768 --a------ C:\WINNT\system32\aqVreo01\aqVreo011065.exe
2008-03-01 19:33 . 08-03-01 19:32 691,545 --a------ C:\WINNT\unins000.exe
2008-03-01 19:33 . 08-03-01 19:33 2,555 --a------ C:\WINNT\unins000.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-24 00:17 --------- d-----w C:\Program Files\mIRC
2008-03-23 22:52 --------- d-----w C:\Program Files\BPFTP
2008-03-23 10:55 --------- d-----w C:\Program Files\Microsoft.NET
2008-03-23 10:55 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-03-23 10:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-23 10:30 --------- d-----w C:\Program Files\SpywareBlaster
2008-03-22 23:50 --------- d-----w C:\Program Files\MSN Games
2008-03-22 23:46 --------- d-----w C:\Program Files\MadTracker
2008-03-22 23:46 --------- d-----w C:\Program Files\Macromedia
2008-03-22 23:32 --------- d-----w C:\Program Files\BulletProof FTP Client
2008-03-20 18:37 --------- d-----w C:\Documents and Settings\MYREALNAME\Application Data\vlc
2008-03-01 18:39 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-01 18:36 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-01 18:08 --------- d-----w C:\Program Files\DC++
2008-02-17 23:07 --------- d-----w C:\Program Files\SecondLife
2008-01-28 11:54 --------- d-----w C:\Program Files\Flash Slideshow Maker Professional
2006-03-14 20:11 7,385,046 ----a-w C:\Program Files\skale081.zip
2005-09-10 21:26 44 ----a-w C:\Documents and Settings\MYREALNAME\civ.bat
2004-05-04 10:24 439 ----a-w C:\Program Files\INSTALL.LOG
2002-07-24 18:51 271 ---h--w C:\Program Files\desktop.ini
2002-07-24 18:51 21,952 ---h--w C:\Program Files\folder.htt
2007-07-09 19:08 479,232 ----a-w C:\Program Files\mozilla firefox\plugins\msvcm80.dll
2007-07-09 19:08 548,864 ----a-w C:\Program Files\mozilla firefox\plugins\msvcp80.dll
2007-07-09 19:08 626,688 ----a-w C:\Program Files\mozilla firefox\plugins\msvcr80.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C3DCFC7-7773-5CA7-0617-5200B8B2DACC}]
C:\WINNT\system32\ohkgfoe.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [01-05-08 13:00 20752 C:\WINNT\system32\internat.exe]
"stonedrv"="c:\winnt\system32\stonedrv.exe" [ ]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [06-05-16 17:51 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 20:05 111376 C:\WINNT\system32\mobsync.exe]
"NvCplDaemon"="C:\WINNT\system32\NvCpl.dll" [05-02-24 06:32 5537792]
"nwiz"="nwiz.exe" [05-02-24 06:32 1495040 C:\WINNT\system32\nwiz.exe]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [02-01-07 00:59 204800]
"Smapp"="Smtray.exe" [01-07-25 13:22 65536 C:\WINNT\system32\SMTray.exe]
"IMONTRAY"="C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe" [01-08-20 18:24 32768]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [01-07-03 08:11 57344]
"HPDJ Taskbar Utility"="C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe" [01-12-12 01:33 196608]
"PenLock"="" []
"MOD"="C:\Program Files\Microangelo\muamgr.exe" [03-05-01 15:33 73728]
"NvMediaCenter"="C:\WINNT\system32\NvMcTray.dll" [05-02-24 06:32 86016]
"NeroFilterCheck"="C:\WINNT\system32\NeroCheck.exe" [01-07-09 10:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06-06-15 17:56 282624]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [05-11-10 12:03 36975]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [05-10-26 16:17 159744]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [06-05-16 17:50 40960]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [04-12-14 01:12 483328]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [07-06-11 10:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [01-05-08 13:00 20752 C:\WINNT\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 20:05 186640]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINNT\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2007-03-28 23:18:03 25214]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-06-26 01:28:27 98304]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2002-07-24 20:50:54 122880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjkihe]
ljjkihe.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINNT\system32\pmnnm.dll
R0 NVDual;NVDual;C:\WINNT\system32\DRIVERS\nvDual.sys [02-01-15 08:06 ]
R0 pnpshark;pnpshark;C:\WINNT\system32\DRIVERS\pnpshark.sys [03-10-02 03:16 ]
R0 st3shark;st3shark;C:\WINNT\system32\DRIVERS\st3shark.sys [03-09-27 14:37 ]
R1 SMBus;Intel(R) SMBus Driver;C:\WINNT\system32\DRIVERS\SMBus.sys [01-08-20 16:33 ]
R3 lne100v5;Linksys LNE100TX(v5) Fast Ethernet Adapter;C:\WINNT\system32\DRIVERS\lne100v5.sys [01-04-02 04:01 ]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINNT\system32\DRIVERS\k510bus.sys [06-12-22 21:46 ]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINNT\system32\DRIVERS\k510mdfl.sys [06-12-22 21:46 ]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINNT\system32\DRIVERS\k510mdm.sys [06-12-22 21:46 ]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINNT\system32\DRIVERS\k510mgmt.sys [06-12-22 21:46 ]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINNT\system32\DRIVERS\k510obex.sys [06-12-22 21:46 ]
S3 utblfilt;utblfilt;C:\WINNT\system32\drivers\utblfilt.sys [01-05-23 14:42 ]
*Newly Created Service* - IPNAT
*Newly Created Service* - RASAUTO
*Newly Created Service* - SHAREDACCESS
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-24 13:05:23
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]
"ImagePath"="C:/mysql/bin/mysqld-nt.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]
"ImagePath"="C:/mysql/bin/mysqld-nt.exe"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\mysql\bin\mysqld-nt.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\VeriSign\NAVI\naviagent.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\PROGRA~1\VeriSign\NAVI\NAVICL~1.EXE
C:\WINNT\system32\mspmspsv.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
.
**************************************************************************
.
Completion time: 2008-03-24 13:10:57 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-24 12:10:54
.
2007-09-28 18:44:56 --- E O F ---