MrPositive
2009-03-31, 23:49
I apologize, i thought you wanted an attachment due to the fact that you said you wanted the C:\Combofix.txt which i took as an attachment, not posted in the forums. Here are the logs
ComboFix 09-03-31.01 - Marc-MSU 2009-03-31 16:20:32.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1279.865 [GMT -4:00]
Running from: c:\documents and settings\Marc-MSU\Desktop\ComboFix.exe
AV: Norton AntiVirus 2005 *On-access scanning enabled* (Updated)
FW: Norton Internet Worm Protection *enabled*
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\system32\akanowun.ini
c:\windows\system32\bawawaza.dll
c:\windows\system32\hifavemu.dll
c:\windows\system32\ihohekom.ini
c:\windows\system32\kolojebe.dll.tmp
c:\windows\system32\matidaha.dll.tmp
c:\windows\system32\mokehohi.dll
c:\windows\system32\nevaluso.dll
c:\windows\system32\nuwonaka.dll
c:\windows\system32\pizakuma.dll
c:\windows\system32\tuyubeva.dll.tmp
c:\windows\system32\ufifakov.ini
c:\windows\system32\wepozara.dll
.
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-31 )))))))))))))))))))))))))))))))
.
2009-03-29 11:42 . 2009-03-29 11:42 <DIR> d-------- c:\program files\ERUNT
2009-03-22 19:32 . 2009-03-22 19:35 <DIR> d-------- c:\program files\FL music
2009-03-22 15:52 . 2009-03-22 15:52 <DIR> d-------- c:\program files\ASIO4ALL v2
2009-03-22 15:47 . 2009-03-22 15:47 <DIR> d-------- c:\program files\VstPlugins
2009-03-22 15:47 . 2002-07-07 18:14 1,294,336 --a------ c:\windows\system32\vorbis.acm
2009-03-22 15:47 . 2006-06-20 04:56 225,280 --a------ c:\windows\system32\rewire.dll
2009-03-22 15:46 . 2009-03-22 15:46 <DIR> d-------- c:\program files\Outsim
2009-03-22 15:45 . 2009-03-29 10:25 <DIR> d-------- c:\program files\Image-Line
2009-02-20 16:05 . 2008-12-02 23:13 165,200 --a------ c:\documents and settings\Marc-MSU\_ImagineUpdate.exe
2009-02-16 10:22 . 2009-02-16 10:22 <DIR> d-------- c:\program files\Common Files\DirectX
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-31 07:00 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-29 02:04 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-22 19:42 --------- d-----w c:\documents and settings\Marc-MSU\Application Data\FrostWire
2009-03-14 23:01 --------- d-----w c:\program files\Starcraft
2009-03-02 16:10 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-25 23:03 --------- d-----w c:\program files\DivX
2007-06-28 18:00 15,505,200 ----a-w c:\program files\IE7-WindowsXP-x86-enu.exe
2006-05-22 00:06 37,311,488 ----a-w c:\program files\iTunesSetup.exe
2006-05-17 22:39 8,715,352 ----a-w c:\program files\Install_AIM.exe
2005-11-08 20:04 1,145 ----a-w c:\program files\README.txt
2008-01-25 17:52 2 --shatr c:\windows\winstart.bat
1601-01-01 00:12 49,152 --sha-w c:\windows\system32\lupojuki.dll
1601-01-01 00:12 49,152 --sha-w c:\windows\system32\yiyerufe.dll
2008-11-20 00:26 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008111920081120\index.dat
.
((((((((((((((((((((((((((((( snapshot_2009-01-16_17.02.50.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-11 12:33:59 333,952 ----a-w c:\windows\$hf_mig$\KB958687\SP3QFE\srv.sys
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB958687\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB958687\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB958687\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w c:\windows\$hf_mig$\KB958687\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w c:\windows\$hf_mig$\KB958687\update\updspapi.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB958687$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB958687$\spuninst\updspapi.dll
+ 2008-09-08 10:41:42 333,824 -c----w c:\windows\$NtUninstallKB958687$\srv.sys
+ 2005-10-20 16:02:28 163,328 ----a-w c:\windows\erdnt\3-29-2009\ERDNT.EXE
- 2005-10-21 01:02:28 163,328 ----a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-21 00:02:28 163,328 ----a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
- 2005-10-21 01:02:28 163,328 ----a-w c:\windows\erdnt\subs\ERDNT.EXE
+ 2005-10-21 00:02:28 163,328 ----a-w c:\windows\erdnt\subs\ERDNT.EXE
+ 2009-01-22 01:28:53 102,032 ------w c:\windows\hpoins04.dat
+ 2009-01-22 01:28:53 102,032 ------w c:\windows\hpoins04.dat.temp
+ 2004-06-22 09:20:34 17,218 ------w c:\windows\hpomdl04.dat
+ 2004-06-22 09:20:34 17,218 ------w c:\windows\hpomdl04.dat.temp
+ 2008-10-16 20:38:34 124,928 -c----w c:\windows\ie7updates\KB961260-IE7\advpack.dll
+ 2008-10-16 20:38:34 347,136 -c----w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll
+ 2008-10-16 20:38:34 214,528 -c----w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll
+ 2008-10-16 20:38:35 133,120 -c----w c:\windows\ie7updates\KB961260-IE7\extmgr.dll
+ 2008-10-16 20:38:35 63,488 -c----w c:\windows\ie7updates\KB961260-IE7\icardie.dll
+ 2008-10-16 13:11:09 70,656 -c----w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe
+ 2008-10-16 20:38:35 153,088 -c----w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll
+ 2008-10-16 20:38:35 230,400 -c----w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll
+ 2008-10-15 07:04:53 161,792 -c----w c:\windows\ie7updates\KB961260-IE7\ieakui.dll
+ 2008-10-16 20:38:35 383,488 -c----w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll
+ 2008-10-16 20:38:35 384,512 -c----w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll
+ 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\ie7updates\KB961260-IE7\ieframe.dll
+ 2008-10-16 20:38:37 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\iernonce.dll
+ 2008-10-16 20:38:37 267,776 -c----w c:\windows\ie7updates\KB961260-IE7\iertutil.dll
+ 2008-10-16 13:11:09 13,824 -c----w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe
+ 2008-10-15 07:06:26 633,632 -c----w c:\windows\ie7updates\KB961260-IE7\iexplore.exe
+ 2008-10-16 20:38:37 27,648 -c----w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll
+ 2008-10-16 20:38:37 459,264 -c----w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll
+ 2008-10-16 20:38:37 52,224 -c----w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll
+ 2008-12-13 06:40:02 3,593,216 -c----w c:\windows\ie7updates\KB961260-IE7\mshtml.dll
+ 2008-10-16 20:38:38 477,696 -c----w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll
+ 2008-10-16 20:38:38 193,024 -c----w c:\windows\ie7updates\KB961260-IE7\msrating.dll
+ 2008-10-16 20:38:39 671,232 -c----w c:\windows\ie7updates\KB961260-IE7\mstime.dll
+ 2008-10-16 20:38:39 102,912 -c----w c:\windows\ie7updates\KB961260-IE7\occache.dll
+ 2008-10-16 20:38:39 44,544 -c----w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll
+ 2007-03-06 01:22:41 213,216 -c----w c:\windows\ie7updates\KB961260-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w c:\windows\ie7updates\KB961260-IE7\spuninst\updspapi.dll
+ 2008-10-16 20:38:39 105,984 -c----w c:\windows\ie7updates\KB961260-IE7\url.dll
+ 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\ie7updates\KB961260-IE7\urlmon.dll
+ 2008-10-16 20:38:39 233,472 -c----w c:\windows\ie7updates\KB961260-IE7\webcheck.dll
+ 2008-10-16 20:38:40 826,368 -c----w c:\windows\ie7updates\KB961260-IE7\wininet.dll
- 1998-10-29 22:45:06 306,688 ----a-w c:\windows\IsUninst.exe
+ 1998-10-29 21:45:06 306,688 ----a-w c:\windows\IsUninst.exe
- 2000-08-31 13:00:00 29,696 ----a-w c:\windows\Nircmd.exe
+ 2000-08-31 12:00:00 29,696 ----a-w c:\windows\Nircmd.exe
- 2000-08-31 13:00:00 161,792 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 12:00:00 161,792 ----a-w c:\windows\SWREG.exe
- 2008-10-16 20:38:34 124,928 ----a-w c:\windows\system32\advpack.dll
+ 2008-12-20 23:15:11 124,928 ----a-w c:\windows\system32\advpack.dll
+ 2009-03-30 18:46:01 61,440 --sha-w c:\windows\system32\baniwiki.exe
+ 2009-03-29 02:13:27 61,440 --sha-w c:\windows\system32\bujusufe.exe
- 2009-01-11 20:00:39 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-13 11:25:59 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-01-11 20:00:39 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-13 11:25:59 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-11 20:00:39 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-13 11:25:59 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-18 17:08:33 410,984 ----a-w c:\windows\system32\deploytk.dll
- 2008-10-16 20:38:34 124,928 -c--a-w c:\windows\system32\dllcache\advpack.dll
+ 2008-12-20 23:15:11 124,928 -c--a-w c:\windows\system32\dllcache\advpack.dll
- 2008-10-16 20:38:34 347,136 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
- 2008-10-16 20:38:35 133,120 -c--a-w c:\windows\system32\dllcache\extmgr.dll
+ 2008-12-20 23:15:13 133,120 -c--a-w c:\windows\system32\dllcache\extmgr.dll
- 2008-10-16 20:38:35 63,488 -c--a-w c:\windows\system32\dllcache\icardie.dll
+ 2008-12-20 23:15:13 63,488 -c--a-w c:\windows\system32\dllcache\icardie.dll
- 2008-10-16 13:11:09 70,656 -c--a-w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 -c--a-w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 -c--a-w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 -c--a-w c:\windows\system32\dllcache\ieakeng.dll
- 2008-10-16 20:38:35 230,400 -c--a-w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 -c--a-w c:\windows\system32\dllcache\ieaksie.dll
- 2008-10-15 07:04:53 161,792 -c--a-w c:\windows\system32\dllcache\ieakui.dll
+ 2008-12-19 05:23:56 161,792 -c--a-w c:\windows\system32\dllcache\ieakui.dll
- 2008-10-16 20:38:35 383,488 -c--a-w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 -c--a-w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 -c--a-w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 -c--a-w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-16 20:38:37 6,066,176 -c--a-w c:\windows\system32\dllcache\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 -c--a-w c:\windows\system32\dllcache\ieframe.dll
- 2008-10-16 20:38:37 44,544 -c--a-w c:\windows\system32\dllcache\iernonce.dll
+ 2008-12-20 23:15:21 44,544 -c--a-w c:\windows\system32\dllcache\iernonce.dll
- 2008-10-16 20:38:37 267,776 -c--a-w c:\windows\system32\dllcache\iertutil.dll
+ 2008-12-20 23:15:22 267,776 -c--a-w c:\windows\system32\dllcache\iertutil.dll
- 2008-10-16 13:11:09 13,824 -c--a-w c:\windows\system32\dllcache\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 -c--a-w c:\windows\system32\dllcache\ieudinit.exe
- 2008-10-15 07:06:26 633,632 -c--a-w c:\windows\system32\dllcache\iexplore.exe
+ 2008-12-19 05:25:25 634,024 -c--a-w c:\windows\system32\dllcache\iexplore.exe
- 2008-10-16 20:38:37 27,648 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
- 2008-10-16 20:38:37 459,264 -c--a-w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 -c--a-w c:\windows\system32\dllcache\msfeeds.dll
- 2008-10-16 20:38:37 52,224 -c--a-w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 -c--a-w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-12-13 06:40:02 3,593,216 -c--a-w c:\windows\system32\dllcache\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 -c--a-w c:\windows\system32\dllcache\mshtml.dll
- 2008-10-16 20:38:38 477,696 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
- 2008-10-16 20:38:38 193,024 -c--a-w c:\windows\system32\dllcache\msrating.dll
+ 2008-12-20 23:15:31 193,024 -c--a-w c:\windows\system32\dllcache\msrating.dll
- 2008-10-16 20:38:39 671,232 -c--a-w c:\windows\system32\dllcache\mstime.dll
+ 2008-12-20 23:15:32 671,232 -c--a-w c:\windows\system32\dllcache\mstime.dll
- 2008-10-16 20:38:39 102,912 -c--a-w c:\windows\system32\dllcache\occache.dll
+ 2008-12-20 23:15:38 102,912 -c--a-w c:\windows\system32\dllcache\occache.dll
- 2008-10-16 20:38:39 44,544 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
- 2008-09-08 10:41:42 333,824 -c--a-w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 10:57:09 333,952 -c--a-w c:\windows\system32\dllcache\srv.sys
- 2008-10-16 20:38:39 105,984 -c--a-w c:\windows\system32\dllcache\url.dll
+ 2008-12-20 23:15:39 105,984 -c--a-w c:\windows\system32\dllcache\url.dll
- 2008-10-16 20:38:39 1,160,192 -c--a-w c:\windows\system32\dllcache\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 -c--a-w c:\windows\system32\dllcache\urlmon.dll
- 2008-10-16 20:38:39 233,472 -c--a-w c:\windows\system32\dllcache\webcheck.dll
+ 2008-12-20 23:15:40 233,472 -c--a-w c:\windows\system32\dllcache\webcheck.dll
- 2008-10-16 20:38:40 826,368 -c--a-w c:\windows\system32\dllcache\wininet.dll
+ 2008-12-20 23:15:41 826,368 -c--a-w c:\windows\system32\dllcache\wininet.dll
+ 2004-03-22 10:35:48 51,088 ----a-w c:\windows\system32\drivers\hpzid412.sys
+ 2004-03-22 10:35:52 16,496 ----a-w c:\windows\system32\drivers\HPZipr12.sys
+ 2004-03-22 10:35:58 21,744 ----a-w c:\windows\system32\drivers\HPZius12.sys
- 2008-09-08 10:41:42 333,824 ----a-w c:\windows\system32\drivers\srv.sys
+ 2008-12-11 10:57:09 333,952 ----a-w c:\windows\system32\drivers\srv.sys
- 2008-10-16 20:38:34 347,136 ----a-w c:\windows\system32\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 ----a-w c:\windows\system32\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 ----a-w c:\windows\system32\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 ----a-w c:\windows\system32\dxtrans.dll
- 2008-10-16 20:38:35 133,120 ----a-w c:\windows\system32\extmgr.dll
+ 2008-12-20 23:15:13 133,120 ----a-w c:\windows\system32\extmgr.dll
- 2008-11-20 02:59:06 1,595,480 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-03-29 14:32:28 1,586,592 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-03-31 18:46:06 61,440 --sha-w c:\windows\system32\hegubagu.exe
+ 2004-03-14 08:32:06 278,528 ----a-w c:\windows\system32\hpgwiamd.dll
+ 2004-04-13 06:10:24 581,632 ----a-w c:\windows\system32\hpotscl.dll
+ 2004-04-13 06:10:16 90,112 ----a-w c:\windows\system32\hpovst08.dll
+ 2004-03-14 08:34:10 270,336 ----a-w c:\windows\system32\HPZc3212.dll
+ 2004-04-07 12:34:26 196,608 ----a-w c:\windows\system32\hpzcoi10.dll
+ 2004-04-07 12:33:20 344,064 ----a-w c:\windows\system32\hpzcon10.dll
+ 2004-03-18 21:53:54 278,584 ----a-w c:\windows\system32\HPZidr12.dll
+ 2004-03-18 21:38:00 61,440 ----a-w c:\windows\system32\HPZinw12.exe
+ 2004-03-18 21:55:48 65,536 ----a-w c:\windows\system32\HPZipm12.exe
+ 2004-03-18 21:56:28 204,800 ----a-w c:\windows\system32\HPZipr12.dll
+ 2004-03-18 21:39:24 94,208 ----a-w c:\windows\system32\HPZipt12.dll
+ 2004-03-18 21:39:30 57,344 ----a-w c:\windows\system32\HPZisn12.dll
+ 2004-03-14 08:43:30 135,249 ----a-w c:\windows\system32\hpzlnt10.dll
- 2008-10-16 20:38:35 63,488 ----a-w c:\windows\system32\icardie.dll
+ 2008-12-20 23:15:13 63,488 ----a-w c:\windows\system32\icardie.dll
- 2008-10-16 13:11:09 70,656 ----a-w c:\windows\system32\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 ----a-w c:\windows\system32\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 ----a-w c:\windows\system32\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 ----a-w c:\windows\system32\ieakeng.dll
- 2008-10-16 20:38:35 230,400 ----a-w c:\windows\system32\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 ----a-w c:\windows\system32\ieaksie.dll
- 2008-10-15 07:04:53 161,792 ----a-w c:\windows\system32\ieakui.dll
+ 2008-12-19 05:23:56 161,792 ----a-w c:\windows\system32\ieakui.dll
- 2008-10-16 20:38:35 383,488 ----a-w c:\windows\system32\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 ----a-w c:\windows\system32\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 ----a-w c:\windows\system32\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 ----a-w c:\windows\system32\iedkcs32.dll
- 2008-10-16 20:38:37 6,066,176 ----a-w c:\windows\system32\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 ----a-w c:\windows\system32\ieframe.dll
- 2008-10-16 20:38:37 44,544 ----a-w c:\windows\system32\iernonce.dll
+ 2008-12-20 23:15:21 44,544 ----a-w c:\windows\system32\iernonce.dll
- 2008-10-16 20:38:37 267,776 ----a-w c:\windows\system32\iertutil.dll
+ 2008-12-20 23:15:22 267,776 ----a-w c:\windows\system32\iertutil.dll
- 2008-10-16 13:11:09 13,824 ----a-w c:\windows\system32\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 ----a-w c:\windows\system32\ieudinit.exe
- 2007-09-25 03:30:28 135,168 ----a-w c:\windows\system32\java.exe
+ 2009-01-18 17:08:33 144,792 ----a-w c:\windows\system32\java.exe
- 2007-09-25 03:30:30 135,168 ----a-w c:\windows\system32\javaw.exe
+ 2009-01-18 17:08:33 144,792 ----a-w c:\windows\system32\javaw.exe
- 2007-09-25 04:31:42 139,264 ----a-w c:\windows\system32\javaws.exe
+ 2009-01-18 17:08:33 148,888 ----a-w c:\windows\system32\javaws.exe
+ 2009-03-29 14:13:25 61,440 --sha-w c:\windows\system32\joyiwila.exe
- 2008-10-16 20:38:37 27,648 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 ----a-w c:\windows\system32\jsproxy.dll
- 2007-03-01 21:45:32 1,044,480 ----a-w c:\windows\system32\libdivx.dll
+ 2008-11-06 16:35:00 1,044,480 ----a-w c:\windows\system32\libdivx.dll
- 2008-10-16 20:38:37 459,264 ----a-w c:\windows\system32\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 ----a-w c:\windows\system32\msfeeds.dll
- 2008-10-16 20:38:37 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
- 2008-12-13 06:40:02 3,593,216 ----a-w c:\windows\system32\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 ----a-w c:\windows\system32\mshtml.dll
- 2008-10-16 20:38:38 477,696 ----a-w c:\windows\system32\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 ----a-w c:\windows\system32\mshtmled.dll
- 2008-10-16 20:38:38 193,024 ----a-w c:\windows\system32\msrating.dll
+ 2008-12-20 23:15:31 193,024 ----a-w c:\windows\system32\msrating.dll
- 2008-10-16 20:38:39 671,232 ----a-w c:\windows\system32\mstime.dll
+ 2008-12-20 23:15:32 671,232 ----a-w c:\windows\system32\mstime.dll
- 2008-10-16 20:38:39 102,912 ----a-w c:\windows\system32\occache.dll
+ 2008-12-20 23:15:38 102,912 ----a-w c:\windows\system32\occache.dll
- 2008-11-20 00:28:33 60,362 ----a-w c:\windows\system32\perfc009.dat
+ 2009-03-29 02:07:56 60,362 ----a-w c:\windows\system32\perfc009.dat
- 2008-11-20 00:28:33 398,968 ----a-w c:\windows\system32\perfh009.dat
+ 2009-03-29 02:07:56 398,968 ----a-w c:\windows\system32\perfh009.dat
- 2008-10-16 20:38:39 44,544 ----a-w c:\windows\system32\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 ----a-w c:\windows\system32\pngfilt.dll
+ 2009-03-31 18:46:37 49,152 --sha-w c:\windows\system32\rayowoju.dll
+ 2009-03-31 06:45:48 61,440 --sha-w c:\windows\system32\rosobogu.exe
- 2007-11-30 12:39:22 17,272 ----a-w c:\windows\system32\spmsg.dll
+ 2008-07-09 07:38:24 17,272 ------w c:\windows\system32\spmsg.dll
+ 2004-04-08 07:16:46 131,329 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpop6110.dat
+ 2004-03-14 08:43:28 196,608 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpz2ku10.dll
+ 2004-03-24 05:04:48 286,720 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzcfg10.exe
+ 2004-04-07 12:34:26 196,608 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzcoi10.dll
+ 2004-04-07 12:33:20 344,064 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzcon10.dll
+ 2004-03-24 05:04:54 647,168 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzeng10.exe
+ 2004-03-24 05:04:58 69,632 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzflt10.dll
+ 2004-03-24 05:05:00 1,589,248 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzimc10.dll
+ 2004-03-24 05:05:04 352,256 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzime10.dll
+ 2004-03-24 05:05:08 1,671,168 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzims10.dll
+ 2004-03-24 05:05:14 200,704 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzjui10.dll
+ 2004-03-14 08:43:30 135,249 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzlnt10.dll
+ 2004-03-24 05:05:18 143,360 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzpcl10.dll
+ 2004-03-14 08:43:30 487,424 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzpm310.dll
+ 2004-03-24 05:05:22 331,776 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzpre10.exe
+ 2004-03-14 08:44:34 3,182,592 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzr3210.dll
+ 2004-03-24 05:05:26 368,640 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzres10.dll
+ 2004-03-14 08:44:36 1,695,744 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzrm310.dll
+ 2004-03-24 05:05:28 679,936 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzslk10.dll
+ 2004-03-14 08:43:30 180,315 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzsnt10.dll
+ 2004-03-24 05:05:32 385,024 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzstc10.exe
+ 2004-03-24 05:05:36 163,840 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzstw10.exe
+ 2004-03-24 05:05:38 61,440 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpztbi10.dll
+ 2004-03-24 05:05:42 172,032 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpztbu10.exe
+ 2004-04-09 17:51:56 7,331,840 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpztbx10.exe
+ 2004-03-24 05:05:52 155,708 ----a-w c:\windows\system32\spool\drivers\w32x86\3\hpzvip10.dll
+ 2004-04-08 07:16:46 131,329 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpop6110.dat
+ 2004-03-14 08:43:28 196,608 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpz2ku10.dll
+ 2004-03-24 05:04:48 286,720 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzcfg10.exe
+ 2004-04-07 12:34:26 196,608 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzcoi10.dll
+ 2004-04-07 12:33:20 344,064 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzcon10.dll
+ 2004-03-24 05:04:54 647,168 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzeng10.exe
+ 2004-03-24 05:04:58 69,632 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzflt10.dll
+ 2004-03-24 05:05:00 1,589,248 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzimc10.dll
+ 2004-03-24 05:05:04 352,256 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzime10.dll
+ 2004-03-24 05:05:08 1,671,168 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzims10.dll
+ 2004-03-24 05:05:14 200,704 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzjui10.dll
+ 2004-03-14 08:43:30 135,249 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzlnt10.dll
+ 2004-03-24 05:05:18 143,360 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzpcl10.dll
+ 2004-03-14 08:43:30 487,424 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzpm310.dll
+ 2004-03-24 05:05:22 331,776 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzpre10.exe
+ 2004-03-14 08:44:34 3,182,592 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzr3210.dll
+ 2004-03-24 05:05:26 368,640 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzres10.dll
+ 2004-03-14 08:44:36 1,695,744 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzrm310.dll
+ 2004-03-24 05:05:28 679,936 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzslk10.dll
+ 2004-03-14 08:43:30 180,315 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzsnt10.dll
+ 2004-03-24 05:05:32 385,024 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzstc10.exe
+ 2004-03-24 05:05:36 163,840 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzstw10.exe
+ 2004-03-24 05:05:38 61,440 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpztbi10.dll
+ 2004-03-24 05:05:42 172,032 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpztbu10.exe
+ 2004-04-09 17:51:56 7,331,840 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpztbx10.exe
+ 2004-03-24 05:05:52 155,708 ----a-w c:\windows\system32\spool\drivers\w32x86\hewlett_packardoffic3c09\hpzvip10.dll
- 2007-03-01 21:45:32 200,704 ----a-w c:\windows\system32\ssldivx.dll
+ 2008-11-06 16:35:00 200,704 ----a-w c:\windows\system32\ssldivx.dll
- 2008-10-16 20:38:39 105,984 ----a-w c:\windows\system32\url.dll
+ 2008-12-20 23:15:39 105,984 ----a-w c:\windows\system32\url.dll
- 2008-10-16 20:38:39 1,160,192 ----a-w c:\windows\system32\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 ----a-w c:\windows\system32\urlmon.dll
- 2008-10-16 20:38:39 233,472 ----a-w c:\windows\system32\webcheck.dll
+ 2008-12-20 23:15:40 233,472 ----a-w c:\windows\system32\webcheck.dll
- 2008-10-16 20:38:40 826,368 ----a-w c:\windows\system32\wininet.dll
+ 2008-12-20 23:15:41 826,368 ----a-w c:\windows\system32\wininet.dll
+ 2009-03-31 20:25:54 16,384 ----atw c:\windows\temp\Perflib_Perfdata_600.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cc4a38d1-8ad6-4155-9cfb-0efe2d0bd7c0}]
49152 --ahs---- c:\windows\system32\lupojuki.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"biniforifa"="c:\windows\system32\yiyerufe.dll" [ 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\hifavemu.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\windows\system32\hifavemu.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Start Menu^Programs^Startup^MEMonitor.lnk]
backup=c:\windows\pss\MEMonitor.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
--a------ 2007-02-08 02:12 488984 c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
--a------ 2007-02-08 02:13 774168 c:\program files\Logitech\QuickCam10\QuickCam10.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-11-07 15:31 21633320 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-04-04 19:38 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"c:\\Program Files\\Microsoft Games\\HCE\\haloce.exe"=
"c:\\Program Files\\Steam\\SteamApps\\allerka\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\allerka\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\AeriaGames\\ProjectTorque\\ProjectTorque.bin"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\Core-Static\\MOM.exe"=
"c:\\WINDOWS\\explorer.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-07-07 24652]
S2 CX88XBAR;AVerMedia AVerTV MPEG Crossbar (Dual-Input);c:\windows\system32\drivers\A88BarBB.sys [2005-04-07 10112]
S3 CXAVSAUD;AVerMedia AVerTV AvStream Audio Capture;c:\windows\system32\drivers\A88AudBB.sys [2005-04-07 9216]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-01-25 747912]
S3 XDva134;XDva134;\??\c:\windows\system32\XDva134.sys --> c:\windows\system32\XDva134.sys [?]
S3 XDva158;XDva158;\??\c:\windows\system32\XDva158.sys --> c:\windows\system32\XDva158.sys [?]
S3 XDva164;XDva164;\??\c:\windows\system32\XDva164.sys --> c:\windows\system32\XDva164.sys [?]
S3 XDva165;XDva165;\??\c:\windows\system32\XDva165.sys --> c:\windows\system32\XDva165.sys [?]
S3 XDva167;XDva167;\??\c:\windows\system32\XDva167.sys --> c:\windows\system32\XDva167.sys [?]
S3 XDva177;XDva177;\??\c:\windows\system32\XDva177.sys --> c:\windows\system32\XDva177.sys [?]
S3 XDva186;XDva186;\??\c:\windows\system32\XDva186.sys --> c:\windows\system32\XDva186.sys [?]
S3 XDva189;XDva189;\??\c:\windows\system32\XDva189.sys --> c:\windows\system32\XDva189.sys [?]
S3 XDva201;XDva201;\??\c:\windows\system32\XDva201.sys --> c:\windows\system32\XDva201.sys [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Z]
\Shell\AutoRun\command - Z:\Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2009-03-31 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-01-26 16:31]
.
- - - - ORPHANS REMOVED - - - -
BHO-{1486AAEE-C48E-4B3B-9B9D-052E2AA31439} - (no file)
BHO-{31B6002A-E311-4373-957A-E439FC87D0D0} - (no file)
BHO-{5BD5E023-A449-4446-8075-D527315E4F2F} - (no file)
BHO-{60C0A167-FE13-4983-A14A-BE2C8EBE8B3A} - (no file)
BHO-{907222db-a44c-4be6-94ae-cd2085034f7e} - (no file)
BHO-{EA0BAC65-EB94-441F-BA58-583A75984E56} - (no file)
Notify-hgGabaBU - (no file)
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
FF - ProfilePath - c:\documents and settings\Marc-MSU\Application Data\Mozilla\Firefox\Profiles\7lbz2wc9.default\
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Marc-MSU\Application Data\Mozilla\Firefox\Profiles\7lbz2wc9.default\extensions\flashplugin@idm\platform\WINNT\plugins\npidmdcp.dll
FF - plugin: c:\documents and settings\Marc-MSU\Application Data\Mozilla\Firefox\Profiles\7lbz2wc9.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07074039.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npigl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-31 16:26:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.0\my.ini\" MySQL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(808)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\dllhost.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2009-03-31 16:30:44 - machine was rebooted [Marc-MSU]
ComboFix-quarantined-files.txt 2009-03-31 20:30:41
ComboFix2.txt 2009-01-18 17:04:15
ComboFix3.txt 2009-01-16 22:04:16
ComboFix4.txt 2008-01-25 13:15:23
ComboFix5.txt 2009-03-31 19:12:24
Pre-Run: 81,025,327,104 bytes free
Post-Run: 81,006,145,536 bytes free
472