ComboFix 08-02.05.3 - Owner 2008-02-08 4:22:10.1 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\qommllj.dll
C:\WINDOWS\system32\ssqrp.dll
C:\Documents and Settings\Owner\Application Data\ICROSO~1.NET
C:\Documents and Settings\Owner\Application Data\ICROSO~1.NET\?hkntfs.exe
C:\Program Files\Common Files\dobe~1
C:\Program Files\Common Files\dobe~1\?dobe\
C:\Program Files\Common Files\dobe~1\regedit.exe
C:\Program Files\outerinfo
C:\WINDOWS\system32\efcbxww.dll
C:\WINDOWS\system32\emutbwid.dll
C:\WINDOWS\system32\hwjtgpyd.dll
C:\WINDOWS\system32\jkkjkli.dll
C:\WINDOWS\system32\mnomnfkq.ini
C:\WINDOWS\system32\otylp.dll
C:\WINDOWS\system32\prqss.ini
C:\WINDOWS\system32\prqss.ini2
C:\WINDOWS\system32\qkfnmonm.dll
C:\WINDOWS\system32\qommllj.dll
C:\WINDOWS\system32\ssqrp.dll
C:\WINDOWS\system32\v9
C:\WINDOWS\system32\v9\rabs2135.exe
.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-08 03:02 . 2008-02-08 04:03 <DIR> d-------- C:\SDFix
2008-02-08 02:52 . 2008-02-08 04:22 21 --a------ C:\WINDOWS\pskt.ini
2008-02-07 02:39 . 2008-02-07 02:39 <DIR> d-------- C:\Program Files\Drmupgds
2008-02-07 02:35 . 2008-02-07 02:35 <DIR> d-------- C:\WINDOWS\system32\rp4
2008-02-07 02:35 . 2008-02-07 02:35 <DIR> d-------- C:\WINDOWS\system32\cz6
2008-02-07 02:35 . 2008-02-07 02:39 <DIR> d-------- C:\Program Files\RABCO
2008-02-07 02:34 . 2008-02-07 02:35 <DIR> d-------- C:\temp\isgTi19
2008-02-06 23:10 . 2004-08-04 05:00 388,608 --a------ C:\kmd.exe
2008-02-03 05:37 . 2008-02-08 02:52 118 --a------ C:\WINDOWS\BM0f9cc11e.xml
2008-02-01 04:57 . 2003-08-23 07:34 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-02-01 04:57 . 2003-08-28 20:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-01 04:57 . 2003-08-23 07:12 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2008-02-01 04:57 . 2003-08-23 20:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2008-02-01 04:57 . 2003-08-28 20:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\interMute
2008-02-01 04:16 . 2008-02-01 04:16 <DIR> d-------- C:\WINDOWS\mozi
2008-02-01 04:16 . 2008-02-01 15:49 <DIR> d-------- C:\Program Files\Common Files\mozi
2008-02-01 04:11 . 2008-02-01 04:11 <DIR> d-------- C:\WINDOWS\system32\7B7D8585818685
2008-02-01 03:51 . 2008-02-08 03:29 <DIR> d-------- C:\WINDOWS\RGFuaWVsbGEgRGVsbGEtR2l1c3RpbmE
2008-02-01 03:50 . 2008-02-01 15:49 <DIR> d-------- C:\WINDOWS\system32\tip4
2008-02-01 03:50 . 2008-02-01 03:50 <DIR> d-------- C:\WINDOWS\system32\nGpxx01
2008-02-01 03:50 . 2008-02-01 15:49 <DIR> d-------- C:\WINDOWS\system32\lis6
2008-02-01 03:50 . 2008-02-01 03:50 <DIR> d-------- C:\WINDOWS\system32\kps5
2008-02-01 03:50 . 2008-02-01 03:50 <DIR> d-------- C:\WINDOWS\system32\hs9
2008-02-01 03:50 . 2008-02-01 03:50 <DIR> d-------- C:\temp\gTiis19
2008-02-01 03:50 . 2008-02-01 03:50 <DIR> d-------- C:\temp\cXzz9
2008-01-27 17:38 . 2008-01-27 17:38 0 --ahs---- C:\Documents and Settings\Owner\Application Data\00479d2407.dat
2008-01-27 17:12 . 2008-01-27 17:10 14,336 --a------ C:\Documents and Settings\Owner\Application Data\fydyp.exe
2008-01-27 15:23 . 2008-01-27 15:23 270,698 --a------ C:\WINDOWS\system32\L327E.tmp
2008-01-27 15:22 . 2008-01-27 15:22 181,965 --a------ C:\WINDOWS\system32\L360.tmp
2008-01-24 01:27 . 2008-01-24 01:27 3,145,868 --a------ C:\rail01_NRM3.tif
2008-01-24 01:24 . 2008-01-24 01:24 3,145,868 --a------ C:\rail01_NRM2.tif
2008-01-24 01:21 . 2008-01-24 01:21 3,145,868 --a------ C:\rail01_NRM.tif
2008-01-22 23:11 . 2008-02-08 04:56 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-22 23:11 . 2008-01-22 23:11 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-21 03:37 . 2008-01-21 03:38 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Autodesk
2008-01-21 03:32 . 2008-01-21 03:32 231 --a------ C:\WINDOWS\system32\3dsmax.ini
2008-01-21 03:32 . 2008-01-21 03:32 43 --a------ C:\WINDOWS\system32\InstallSettings.ini
2008-01-21 03:12 . 2004-08-20 15:50 159,744 --a------ C:\WINDOWS\system32\igfxres.dll
2008-01-21 03:04 . 2004-08-04 05:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-01-21 03:03 . 2004-08-04 05:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-01-21 03:02 . 2004-08-04 05:00 2,134,528 --a--c--- C:\WINDOWS\system32\dllcache\smtpsnap.dll
2008-01-21 02:59 . 2008-01-21 02:59 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-01-21 02:59 . 2008-01-21 02:59 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-01-21 02:59 . 2008-01-21 02:59 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-01-21 02:59 . 2008-01-21 02:59 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-01-21 02:59 . 2008-01-21 02:59 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-01-21 02:59 . 2008-01-21 02:59 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-01-21 02:56 . 2004-08-04 05:00 358,912 --a--c--- C:\WINDOWS\system32\dllcache\wmic.exe
2008-01-21 02:56 . 2004-08-04 05:00 92,672 --a--c--- C:\WINDOWS\system32\dllcache\policman.dll
2008-01-21 02:47 . 2004-08-04 05:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-01-21 02:47 . 2004-08-04 05:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-01-21 02:47 . 2004-08-04 05:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-01-21 02:47 . 2004-08-04 05:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-01-21 02:47 . 2008-01-21 02:47 34 --a------ C:\WINDOWS\system\oeminfo.ini
2008-01-21 02:21 . 2008-01-21 02:24 24 ---hs---- C:\WINDOWS\S865EA9EB.tmp
2008-01-21 02:20 . 2008-01-21 02:20 <DIR> d-------- C:\Program Files\SlySoft
2008-01-16 12:05 . 2008-01-16 12:05 <DIR> d-------- C:\Program Files\uTorrent
2008-01-16 12:04 . 2008-01-27 16:20 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\uTorrent
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 11:56 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-08 01:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-07 06:43 --------- d-----w C:\Program Files\Spyware Doctor
2008-01-28 21:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-28 07:19 --------- d-----w C:\Program Files\IntelliMover Data Transfer Demo
2008-01-28 07:18 --------- d-----w C:\Documents and Settings\Owner\Application Data\interMute
2008-01-28 00:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-24 06:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodesk
2008-01-23 06:37 --------- d-----w C:\Program Files\QuickTime
2008-01-23 05:54 --------- d-----w C:\Program Files\mudBox
2008-01-21 17:43 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-01-21 10:32 --------- d-----w C:\Program Files\Autodesk
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{12220E22-64BA-403C-B48E-015E43625B2C}]
C:\Program Files\Windows NT\niqytegun83122.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5BAAE1D-109B-4A31-68AD-76E86596DECA}]
C:\Program Files\Common Files\rycin.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2003-06-22 21:25 24576]
"NVIEW"="nview.dll" [2003-05-02 23:19 835654 C:\WINDOWS\system32\nview.dll]
"Aim6"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"Uzbcffwd"="C:\Documents and Settings\Owner\Application Data\?icrosoft.NET\?hkntfs.exe" [ ]
"Drmupgds"="C:\Program Files\Drmupgds\Drmupgds.exe" [2008-02-07 02:39 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04 52736]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-20 15:51 118784]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 07:23 90112]
"HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-13 23:53 49152]
"HPHUPD05"="c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-23 03:03 49152]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-05-23 02:55 483328]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 20:02 61440]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 08:01 155648]
"AutoTKit"="C:\hp\bin\AUTOTKIT.EXE" [2003-06-18 19:19 53248]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 21:42 212992]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-05-02 23:19 4640768]
"nwiz"="nwiz.exe" [2003-05-02 23:19 323584 C:\WINDOWS\system32\nwiz.exe]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 15:55 155648]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 22:46 624248]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 16:40 1884160]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27 1065288]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-27 12:51 185632]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11 267048]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 12:21 57344]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 16:57 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-03 22:59 44544]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
AutoTBar.exe [2003-06-18 19:19:08 53248]
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 07:11:14 27136]
C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
AutoTBar.exe [2003-06-18 19:19:08 53248]
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 07:11:14 27136]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
RABCO - Auto Update.lnk - C:\Program Files\RABCO\RABCOse.exe [2008-02-07 02:35:17 183216]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Device Detector 3.lnk - C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe [2006-03-14 11:17:50 114688]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 12:45:28 126136]
Hanvon Shell.lnk - C:\Hanvon_soft\hwshell.exe [2006-11-05 15:33:10 917504]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2003-06-13 04:08:16 233472]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2002-09-20 19:20:02 53248]
Updates from HP.lnk - C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe [2003-08-23 20:34:35 16384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2003-02-21 03:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 05:00 15360 C:\WINDOWS\system32\ctfmon.exe
R0 hypen;Hy Pen;C:\WINDOWS\system32\Drivers\hypen.sys [2002-04-26 14:22]
R2 HWSuperPowerTablet;HWSuperPowerTablet;C:\WINDOWS\System32\JWPEN.exe [2005-12-02 16:57]
R2 mi-raysat_3dsMax2008_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit;"C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe" [2007-09-24 17:05]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\A5AGU.sys [2004-10-06 10:39]
S3 adxapie;adxapie;C:\DOCUME~1\Owner\LOCALS~1\Temp\adxapie.sys []
S3 ATHFMWDL;D-Link predator Bootloader driver;C:\WINDOWS\system32\Drivers\ATHFMWDL.sys [2004-10-04 06:28]
S3 VNUSB;VN Series Device;C:\WINDOWS\system32\DRIVERS\VNUSB.sys [2003-12-15 18:22]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b99c14f4-16a4-11da-a0c2-000ea6133102}]
\Shell\AutoRun\command - F:\LinksysConnectPC.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 22:16:33 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-08 04:56:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Softex\OmniPass\opxpgina.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-08 5:00:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-08 12:00:39
ComboFix2.txt 2008-02-07 06:18:20
ComboFix3.txt 2008-02-06 20:36:30
.
2008-02-08 07:45:07 --- E O F ---
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\qommllj.dll
C:\WINDOWS\system32\ssqrp.dll
C:\Documents and Settings\Owner\Application Data\ICROSO~1.NET
C:\Documents and Settings\Owner\Application Data\ICROSO~1.NET\?hkntfs.exe
C:\Program Files\Common Files\dobe~1
C:\Program Files\Common Files\dobe~1\?dobe\
C:\Program Files\Common Files\dobe~1\regedit.exe
C:\Program Files\outerinfo
C:\WINDOWS\system32\efcbxww.dll
C:\WINDOWS\system32\emutbwid.dll
C:\WINDOWS\system32\hwjtgpyd.dll
C:\WINDOWS\system32\jkkjkli.dll
C:\WINDOWS\system32\mnomnfkq.ini
C:\WINDOWS\system32\otylp.dll
C:\WINDOWS\system32\prqss.ini
C:\WINDOWS\system32\prqss.ini2
C:\WINDOWS\system32\qkfnmonm.dll
C:\WINDOWS\system32\qommllj.dll
C:\WINDOWS\system32\ssqrp.dll
C:\WINDOWS\system32\v9
C:\WINDOWS\system32\v9\rabs2135.exe
.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-08 03:02 . 2008-02-08 04:03 <DIR> d-------- C:\SDFix
2008-02-08 02:52 . 2008-02-08 04:22 21 --a------ C:\WINDOWS\pskt.ini
2008-02-07 02:39 . 2008-02-07 02:39 <DIR> d-------- C:\Program Files\Drmupgds
2008-02-07 02:35 . 2008-02-07 02:35 <DIR> d-------- C:\WINDOWS\system32\rp4
2008-02-07 02:35 . 2008-02-07 02:35 <DIR> d-------- C:\WINDOWS\system32\cz6
2008-02-07 02:35 . 2008-02-07 02:39 <DIR> d-------- C:\Program Files\RABCO
2008-02-07 02:34 . 2008-02-07 02:35 <DIR> d-------- C:\temp\isgTi19
2008-02-06 23:10 . 2004-08-04 05:00 388,608 --a------ C:\kmd.exe
2008-02-03 05:37 . 2008-02-08 02:52 118 --a------ C:\WINDOWS\BM0f9cc11e.xml
2008-02-01 04:57 . 2003-08-23 07:34 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-02-01 04:57 . 2003-08-28 20:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-01 04:57 . 2003-08-23 07:12 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2008-02-01 04:57 . 2003-08-23 20:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2008-02-01 04:57 . 2003-08-28 20:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\interMute
2008-02-01 04:16 . 2008-02-01 04:16 <DIR> d-------- C:\WINDOWS\mozi
2008-02-01 04:16 . 2008-02-01 15:49 <DIR> d-------- C:\Program Files\Common Files\mozi
2008-02-01 04:11 . 2008-02-01 04:11 <DIR> d-------- C:\WINDOWS\system32\7B7D8585818685
2008-02-01 03:51 . 2008-02-08 03:29 <DIR> d-------- C:\WINDOWS\RGFuaWVsbGEgRGVsbGEtR2l1c3RpbmE
2008-02-01 03:50 . 2008-02-01 15:49 <DIR> d-------- C:\WINDOWS\system32\tip4
2008-02-01 03:50 . 2008-02-01 03:50 <DIR> d-------- C:\WINDOWS\system32\nGpxx01
2008-02-01 03:50 . 2008-02-01 15:49 <DIR> d-------- C:\WINDOWS\system32\lis6
2008-02-01 03:50 . 2008-02-01 03:50 <DIR> d-------- C:\WINDOWS\system32\kps5
2008-02-01 03:50 . 2008-02-01 03:50 <DIR> d-------- C:\WINDOWS\system32\hs9
2008-02-01 03:50 . 2008-02-01 03:50 <DIR> d-------- C:\temp\gTiis19
2008-02-01 03:50 . 2008-02-01 03:50 <DIR> d-------- C:\temp\cXzz9
2008-01-27 17:38 . 2008-01-27 17:38 0 --ahs---- C:\Documents and Settings\Owner\Application Data\00479d2407.dat
2008-01-27 17:12 . 2008-01-27 17:10 14,336 --a------ C:\Documents and Settings\Owner\Application Data\fydyp.exe
2008-01-27 15:23 . 2008-01-27 15:23 270,698 --a------ C:\WINDOWS\system32\L327E.tmp
2008-01-27 15:22 . 2008-01-27 15:22 181,965 --a------ C:\WINDOWS\system32\L360.tmp
2008-01-24 01:27 . 2008-01-24 01:27 3,145,868 --a------ C:\rail01_NRM3.tif
2008-01-24 01:24 . 2008-01-24 01:24 3,145,868 --a------ C:\rail01_NRM2.tif
2008-01-24 01:21 . 2008-01-24 01:21 3,145,868 --a------ C:\rail01_NRM.tif
2008-01-22 23:11 . 2008-02-08 04:56 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-22 23:11 . 2008-01-22 23:11 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-21 03:37 . 2008-01-21 03:38 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Autodesk
2008-01-21 03:32 . 2008-01-21 03:32 231 --a------ C:\WINDOWS\system32\3dsmax.ini
2008-01-21 03:32 . 2008-01-21 03:32 43 --a------ C:\WINDOWS\system32\InstallSettings.ini
2008-01-21 03:12 . 2004-08-20 15:50 159,744 --a------ C:\WINDOWS\system32\igfxres.dll
2008-01-21 03:04 . 2004-08-04 05:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-01-21 03:03 . 2004-08-04 05:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-01-21 03:02 . 2004-08-04 05:00 2,134,528 --a--c--- C:\WINDOWS\system32\dllcache\smtpsnap.dll
2008-01-21 02:59 . 2008-01-21 02:59 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-01-21 02:59 . 2008-01-21 02:59 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-01-21 02:59 . 2008-01-21 02:59 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-01-21 02:59 . 2008-01-21 02:59 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-01-21 02:59 . 2008-01-21 02:59 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-01-21 02:59 . 2008-01-21 02:59 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-01-21 02:56 . 2004-08-04 05:00 358,912 --a--c--- C:\WINDOWS\system32\dllcache\wmic.exe
2008-01-21 02:56 . 2004-08-04 05:00 92,672 --a--c--- C:\WINDOWS\system32\dllcache\policman.dll
2008-01-21 02:47 . 2004-08-04 05:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-01-21 02:47 . 2004-08-04 05:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-01-21 02:47 . 2004-08-04 05:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-01-21 02:47 . 2004-08-04 05:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-01-21 02:47 . 2008-01-21 02:47 34 --a------ C:\WINDOWS\system\oeminfo.ini
2008-01-21 02:21 . 2008-01-21 02:24 24 ---hs---- C:\WINDOWS\S865EA9EB.tmp
2008-01-21 02:20 . 2008-01-21 02:20 <DIR> d-------- C:\Program Files\SlySoft
2008-01-16 12:05 . 2008-01-16 12:05 <DIR> d-------- C:\Program Files\uTorrent
2008-01-16 12:04 . 2008-01-27 16:20 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\uTorrent
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 11:56 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-08 01:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-07 06:43 --------- d-----w C:\Program Files\Spyware Doctor
2008-01-28 21:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-28 07:19 --------- d-----w C:\Program Files\IntelliMover Data Transfer Demo
2008-01-28 07:18 --------- d-----w C:\Documents and Settings\Owner\Application Data\interMute
2008-01-28 00:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-24 06:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodesk
2008-01-23 06:37 --------- d-----w C:\Program Files\QuickTime
2008-01-23 05:54 --------- d-----w C:\Program Files\mudBox
2008-01-21 17:43 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-01-21 10:32 --------- d-----w C:\Program Files\Autodesk
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{12220E22-64BA-403C-B48E-015E43625B2C}]
C:\Program Files\Windows NT\niqytegun83122.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5BAAE1D-109B-4A31-68AD-76E86596DECA}]
C:\Program Files\Common Files\rycin.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2003-06-22 21:25 24576]
"NVIEW"="nview.dll" [2003-05-02 23:19 835654 C:\WINDOWS\system32\nview.dll]
"Aim6"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"Uzbcffwd"="C:\Documents and Settings\Owner\Application Data\?icrosoft.NET\?hkntfs.exe" [ ]
"Drmupgds"="C:\Program Files\Drmupgds\Drmupgds.exe" [2008-02-07 02:39 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04 52736]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-20 15:51 118784]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 07:23 90112]
"HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-13 23:53 49152]
"HPHUPD05"="c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-23 03:03 49152]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-05-23 02:55 483328]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 20:02 61440]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 08:01 155648]
"AutoTKit"="C:\hp\bin\AUTOTKIT.EXE" [2003-06-18 19:19 53248]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 21:42 212992]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-05-02 23:19 4640768]
"nwiz"="nwiz.exe" [2003-05-02 23:19 323584 C:\WINDOWS\system32\nwiz.exe]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 15:55 155648]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 22:46 624248]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 16:40 1884160]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27 1065288]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-27 12:51 185632]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11 267048]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 12:21 57344]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 16:57 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-03 22:59 44544]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
AutoTBar.exe [2003-06-18 19:19:08 53248]
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 07:11:14 27136]
C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
AutoTBar.exe [2003-06-18 19:19:08 53248]
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 07:11:14 27136]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
RABCO - Auto Update.lnk - C:\Program Files\RABCO\RABCOse.exe [2008-02-07 02:35:17 183216]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Device Detector 3.lnk - C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe [2006-03-14 11:17:50 114688]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 12:45:28 126136]
Hanvon Shell.lnk - C:\Hanvon_soft\hwshell.exe [2006-11-05 15:33:10 917504]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2003-06-13 04:08:16 233472]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2002-09-20 19:20:02 53248]
Updates from HP.lnk - C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe [2003-08-23 20:34:35 16384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2003-02-21 03:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 05:00 15360 C:\WINDOWS\system32\ctfmon.exe
R0 hypen;Hy Pen;C:\WINDOWS\system32\Drivers\hypen.sys [2002-04-26 14:22]
R2 HWSuperPowerTablet;HWSuperPowerTablet;C:\WINDOWS\System32\JWPEN.exe [2005-12-02 16:57]
R2 mi-raysat_3dsMax2008_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit;"C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe" [2007-09-24 17:05]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\A5AGU.sys [2004-10-06 10:39]
S3 adxapie;adxapie;C:\DOCUME~1\Owner\LOCALS~1\Temp\adxapie.sys []
S3 ATHFMWDL;D-Link predator Bootloader driver;C:\WINDOWS\system32\Drivers\ATHFMWDL.sys [2004-10-04 06:28]
S3 VNUSB;VN Series Device;C:\WINDOWS\system32\DRIVERS\VNUSB.sys [2003-12-15 18:22]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b99c14f4-16a4-11da-a0c2-000ea6133102}]
\Shell\AutoRun\command - F:\LinksysConnectPC.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 22:16:33 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-08 04:56:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Softex\OmniPass\opxpgina.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-08 5:00:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-08 12:00:39
ComboFix2.txt 2008-02-07 06:18:20
ComboFix3.txt 2008-02-06 20:36:30
.
2008-02-08 07:45:07 --- E O F ---