Hi Steam, here's my Combofix log:
ComboFix 08-03-14.4 - in hong chong 2008-03-18 21:10:23.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.239 [GMT -5:00]
Running from: C:\Documents and Settings\in hong chong\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\_000111_.tmp.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-19 to 2008-03-19 )))))))))))))))))))))))))))))))
.
2008-03-17 19:52 . 2008-03-17 21:29 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-17 19:52 . 2008-03-17 19:52 <DIR> d-------- C:\Documents and Settings\in hong chong\Application Data\SUPERAntiSpyware.com
2008-03-17 19:52 . 2008-03-17 19:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-17 19:51 . 2008-03-17 19:51 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-17 19:09 . 2008-03-17 19:09 <DIR> d-------- C:\Program Files\CCleaner
2008-03-14 22:07 . 2008-03-14 22:07 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-14 19:36 . 2008-03-14 19:36 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-03-14 19:36 . 2008-03-14 19:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-14 18:51 . 2008-03-14 19:18 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-14 18:51 . 2008-03-14 19:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-14 18:41 . 2008-03-14 22:04 1,366,923 ---hs---- C:\WINDOWS\SYSTEM32\nradiffq.ini
2008-03-13 21:19 . 2008-03-14 00:16 <DIR> d-------- C:\Program Files\Security Task Manager
2008-03-13 21:19 . 2008-03-14 17:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-03-13 18:33 . 2008-03-13 18:38 1,346,717 ---hs---- C:\WINDOWS\SYSTEM32\xkmfkxmi.ini
2008-03-09 20:47 . 2008-03-09 20:47 80,959,471 --a------ C:\WINDOWS\pav.sig
2008-03-09 20:38 . 2005-10-20 10:34 69,632 --a------ C:\WINDOWS\SYSTEM32\asprouni.exe
2008-03-09 20:37 . 2008-03-09 20:38 <DIR> d-------- C:\WINDOWS\SYSTEM32\ASPRO
2008-03-09 20:37 . 2008-03-09 21:15 30,590 --a------ C:\WINDOWS\SYSTEM32\pavaspro.ico
2008-03-09 20:37 . 2008-03-09 21:15 3,377 --a------ C:\WINDOWS\SYSTEM32\.ico
2008-03-09 20:37 . 2008-03-09 21:15 2,550 --a------ C:\WINDOWS\SYSTEM32\Uninstallpro.ico
2008-03-09 20:37 . 2008-03-09 21:15 1,406 --a------ C:\WINDOWS\SYSTEM32\Helppro.ico
2008-03-09 19:42 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SDTHOOK.SYS
2008-03-09 19:41 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\hyemhslckupp.sys
2008-03-09 19:28 . 2008-03-09 20:07 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2008-03-09 19:28 . 2008-03-09 19:28 30,590 --a------ C:\WINDOWS\SYSTEM32\pavas.ico
2008-03-09 19:28 . 2008-03-09 19:28 2,550 --a------ C:\WINDOWS\SYSTEM32\Uninstall.ico
2008-03-09 19:28 . 2008-03-09 19:28 1,406 --a------ C:\WINDOWS\SYSTEM32\Help.ico
2008-03-09 19:12 . 2008-03-13 18:33 1,346,570 ---hs---- C:\WINDOWS\SYSTEM32\dnrfhvki.ini
2008-03-09 18:54 . 2008-03-09 18:54 4,172 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2008-03-09 18:25 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\SYSTEM32\VCCLSID.exe
2008-03-09 18:25 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\SYSTEM32\SrchSTS.exe
2008-03-09 18:25 . 2008-03-09 01:15 86,528 --a------ C:\WINDOWS\SYSTEM32\VACFix.exe
2008-03-09 18:25 . 2008-03-05 22:29 82,432 --a------ C:\WINDOWS\SYSTEM32\IEDFix.exe
2008-03-09 18:25 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\SYSTEM32\Process.exe
2008-03-09 18:25 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\SYSTEM32\dumphive.exe
2008-03-09 18:25 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\SYSTEM32\WS2Fix.exe
2008-03-08 21:48 . 2008-03-08 21:48 1,307,561 ---hs---- C:\WINDOWS\SYSTEM32\espobsqd.ini
2008-03-08 20:46 . 2008-03-09 20:12 3,289 --a------ C:\WINDOWS\SYSTEM32\RCX4B_tmp.vir
2008-03-07 21:47 . 2008-03-08 20:48 1,307,648 ---hs---- C:\WINDOWS\SYSTEM32\eqnvihkd.ini
2008-03-06 21:44 . 2008-03-07 18:10 1,306,737 ---hs---- C:\WINDOWS\SYSTEM32\oawvheed.ini
2008-03-05 21:46 . 2008-03-06 17:39 1,307,452 ---hs---- C:\WINDOWS\SYSTEM32\xoifusud.ini
2008-03-05 19:42 . 2008-03-05 19:42 <DIR> d-------- C:\Documents and Settings\eun soon chong\Application Data\HPAppData
2008-03-03 19:55 . 2008-03-03 19:55 1,302,442 ---hs---- C:\WINDOWS\SYSTEM32\gnopfhwh.ini
2008-03-02 17:31 . 2008-03-14 16:28 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-02 17:31 . 2008-03-02 17:31 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-28 21:41 . 2008-02-28 21:41 <DIR> d-------- C:\Program Files\iPod
2008-02-20 12:09 . 2008-03-09 20:12 3,289 --a------ C:\WINDOWS\SYSTEM32\RCX84_tmp.vir
2008-02-19 15:34 . 2008-03-09 20:12 3,289 --a------ C:\WINDOWS\SYSTEM32\RCX7E_tmp.vir
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-18 01:04 --------- d-----w C:\Documents and Settings\in hong chong\Application Data\HPAppData
2008-03-18 00:42 --------- d-----w C:\Program Files\Yahoo!
2008-03-16 21:57 --------- d-----w C:\Program Files\QuickTime
2008-03-16 21:47 4,736 ----a-w C:\WINDOWS\system32\drivers\cijexctk.sys
2008-03-14 21:45 --------- d-----w C:\Program Files\iTunes
2008-03-14 21:45 --------- d-----w C:\Program Files\DellSupport
2008-03-14 21:44 --------- d-----w C:\Program Files\SmileyDistrict
2008-03-14 21:27 94,208 ----a-w C:\WINDOWS\SYSTEM32\igfxtray .exe
2008-03-14 21:27 77,824 ----a-w C:\WINDOWS\SYSTEM32\hkcmd .exe
2008-03-14 21:27 114,688 ----a-w C:\WINDOWS\SYSTEM32\igfxpers .exe
2008-03-13 23:49 --------- d-----w C:\Program Files\Jasc Software Inc
2008-03-10 01:12 3,289 ----a-w C:\WINDOWS\SYSTEM32\RCX6B_tmp.vir
2008-03-10 01:12 3,289 ----a-w C:\WINDOWS\SYSTEM32\RCX61_tmp.vir
2008-03-10 01:12 3,289 ----a-w C:\WINDOWS\SYSTEM32\RCX55_tmp.vir
2008-03-10 01:12 3,289 ----a-w C:\WINDOWS\SYSTEM32\RCX48_tmp.vir
2008-03-10 01:10 3,289 ----a-w C:\WINDOWS\SYSTEM32\jkhhf_exe.vir
2008-03-10 00:42 --------- d-----w C:\Program Files\Bonjour
2008-03-10 00:04 15,360 ----a-w C:\WINDOWS\SYSTEM32\ctfmon .exe
2008-03-06 00:55 98,048 ----a-w C:\WINDOWS\SYSTEM32\asferro.dll
2008-03-01 01:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-02-18 17:29 --------- d-----w C:\Documents and Settings\in ji chong\Application Data\Apple Computer
2008-02-18 03:35 --------- d-----w C:\Documents and Settings\in hong chong\Application Data\Apple Computer
2008-02-18 03:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-18 01:52 --------- d-----w C:\Program Files\Apple Software Update
2008-02-18 01:48 --------- d-----w C:\Program Files\Common Files\Apple
2008-02-18 01:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-02-17 22:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-17 22:29 --------- d-----w C:\Program Files\Ulead Systems
2008-02-17 22:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-02-17 22:26 --------- d-----w C:\Program Files\CyberLink
2008-02-17 22:25 --------- d-----w C:\Program Files\Common Files\AOL
2008-02-17 22:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-17 22:24 --------- d-----w C:\Program Files\Common Files\aolshare
2008-02-17 22:21 --------- d-----w C:\Program Files\WildTangent
2008-02-17 22:13 --------- d-----w C:\Program Files\Common Files\Real
2008-02-01 04:16 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-25 21:42 --------- d-----w C:\Program Files\Intel
2008-01-25 21:32 --------- d-----w C:\Program Files\MUSICMATCH
2008-01-25 20:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-01-25 20:19 --------- d-----w C:\Program Files\Dell Support Center
2008-01-25 20:18 --------- d-----w C:\Program Files\Common Files\supportsoft
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\pngfilt.dll
2007-12-19 23:01 347,136 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtmsft.dll
2007-06-09 16:10 1,816,394 --sha-w C:\WINDOWS\Cursors\cdoavg.tmp
2007-03-02 00:35 65,552 ----a-w C:\Documents and Settings\in ji chong\Application Data\GDIPFONTCACHEV1.DAT
2002-09-19 03:42 3,178,828 ------w C:\Program Files\E.msi
.
Code:
<pre>
----a-w 39,792 2008-03-14 21:27:41 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
----a-w 1,388,544 2008-03-14 21:27:20 C:\Program Files\Analog Devices\SoundMAX\SMax4PNP .exe
----a-w 159,832 2008-03-14 21:27:21 C:\Program Files\Common Files\AOL\1135963495\ee\AOLHostManager .exe
----a-w 290,816 2008-03-14 21:27:15 C:\Program Files\Dell\Media Experience\PCMService .exe
----a-w 202,544 2008-03-14 21:28:01 C:\Program Files\Dell Support Center\bin\sprtcmd .exe
----a-w 16,384 2008-03-14 21:27:37 C:\Program Files\Dell Support Center\gs_agent\custom\dsca .exe
----a-w 460,784 2008-03-14 21:27:56 C:\Program Files\DellSupport\DSAgnt .exe
----a-w 49,152 2008-03-14 21:27:36 C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
----a-w 267,048 2008-03-14 21:27:44 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 32,881 2008-03-14 21:27:07 C:\Program Files\Java\j2re1.4.2_03\bin\jusched .exe
----a-w 303,104 2008-03-14 21:27:16 C:\Program Files\McAfee.com\Agent\mcagent .exe
----a-w 212,992 2008-03-14 21:26:42 C:\Program Files\McAfee.com\Agent\mcupdate .exe
----a-w 212,992 2008-03-02 04:10:36 C:\Program Files\McAfee.com\Agent\mcupdate .exe
----a-w 212,992 2008-03-01 23:19:01 C:\Program Files\McAfee.com\Agent\MCUPDA~2 .EXE
----a-w 1,327,104 2008-03-14 21:27:23 C:\Program Files\McAfee.com\Personal Firewall\MpfTray .exe
----a-w 139,264 2008-03-14 21:27:14 C:\Program Files\McAfee.com\VSO\mcmnhdlr .exe
----a-w 180,224 2008-03-14 21:27:18 C:\Program Files\McAfee.com\VSO\mcvsshld .exe
----a-w 98,304 2008-03-10 00:56:41 C:\Program Files\QuickTime\qttask .exe
----a-w 98,304 2008-03-10 00:56:41 C:\Program Files\QuickTime\qttask .exe
----a-w 98,304 2008-03-10 00:56:42 C:\Program Files\QuickTime\qttask .exe
----a-w 98,304 2008-03-10 00:56:42 C:\Program Files\QuickTime\qttask .exe
----a-w 98,304 2008-03-10 00:56:42 C:\Program Files\QuickTime\qttask .exe
----a-w 98,304 2008-03-10 00:56:44 C:\Program Files\QuickTime\qttask .exe
----a-w 98,304 2008-03-10 00:56:44 C:\Program Files\QuickTime\qttask .exe
----a-w 385,024 2008-03-10 00:56:47 C:\Program Files\QuickTime\qttask .exe
----a-w 26,112 2008-02-17 22:03:32 C:\Program Files\Real\RealPlayer\RealPlay .exe
----a-w 53,248 2008-03-14 21:27:33 C:\Program Files\SmileyDistrict\plugin .exe
----a-w 15,360 2008-03-10 00:04:21 C:\WINDOWS\SYSTEM32\ctfmon .exe
----a-w 77,824 2008-03-14 21:27:31 C:\WINDOWS\SYSTEM32\hkcmd .exe
----a-w 114,688 2008-03-14 21:27:33 C:\WINDOWS\SYSTEM32\igfxpers .exe
----a-w 94,208 2008-03-14 21:27:24 C:\WINDOWS\SYSTEM32\igfxtray .exe
</pre>
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{99DC9AB0-94F0-4ACA-B943-8FCCE5DEF0B3}]
2008-03-05 19:55 98048 --a------ C:\WINDOWS\system32\asferro.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"Aim6"="" []
"fresxstyle"="lockbar.exe" []
"MSI Configuration"="msiconf.exe" []
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"fresxstyle"="lockbar.exe" []
"MRT"="C:\WINDOWS\system32\MRT.exe" [ ]
"0cf5bf5f"="C:\WINDOWS\system32\qffidarn.dll" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"fresxstyle"="lockbar.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 22:26:24 210520]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-12 20:01:04 83360]
TabUserW.exe.lnk - C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe [2005-11-06 11:12:29 106496]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtstuu]
awtstuu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtsqo]
vtsqo.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\WINDOWS\\system32"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1135963495\\ee\\AOLServiceHost.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 nftkecaa;nftkecaa;C:\WINDOWS\system32\drivers\lpjcqiax.sys []
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 10:23]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
S2 SVKP;SVKP;C:\WINDOWS\system32\SVKP.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
*Newly Created Service* - SASDIFSV
.
Contents of the 'Scheduled Tasks' folder
"2008-03-14 01:03:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-18 21:14:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-18 21:15:38
ComboFix-quarantined-files.txt 2008-03-19 02:15:04
ComboFix2.txt 2008-03-16 22:11:57
.
2008-02-14 00:18:51 --- E O F ---