HJT log.
Log seems to show one instance of the random .dlls still running in 04 but the actual HJT screen doesn't show the same and there's no .dll file of that name in that temp folder.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:17:53 PM, on 03/06/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Opera\Opera.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://ca.rd.yahoo.com/customize/ycomp/defaults/sp/*http://ca.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://en.ca.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://en.ca.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://ca.rd.yahoo.com/customize/ycomp/defaults/su/*http://ca.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\Andrew\AppData\Local\Temp\ljJYQHwx.dll,c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O13 - Gopher Prefix:
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
--
End of file - 6333 bytes
Combofix Log
ComboFix 08-06-07.3 - Andrew 2008-06-09 15:35:30.4 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1155 [GMT -4:00]
Running from: C:\Users\Andrew\Desktop\ComboFix.exe
Command switches used :: C:\Users\Andrew\Desktop\CFScript.txt
FILE ::
C:\Users\Andrew\AppData\Local\Temp\fccYSMDs.dll
C:\Users\Andrew\AppData\Local\Temp\iifFYSji.dll
C:\Users\Andrew\AppData\Local\Temp\iujnycnd.dll
C:\Users\Andrew\AppData\Local\Temp\krnciubf.dll
C:\Users\Andrew\AppData\Local\Temp\ljJCsqRl.dll
C:\Users\Andrew\AppData\Local\Temp\ndmxkvbv.dll
C:\Users\Andrew\AppData\Local\Temp\tiyjpghg.dll
C:\Users\Andrew\AppData\Local\Temp\tuVLdbxX.dll
C:\Users\Andrew\AppData\Local\Temp\urQiggfF.dll
C:\Users\Andrew\AppData\Local\Temp\uvskcuqc.dll
C:\Windows\System32\msupdatgms.exe
.
The following files were disabled during the run:
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\SDFix
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\download.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FixComponents.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixSchedule.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\grep.exe
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\HPFix3.reg
C:\SDFix\apps\HPFix4.reg
C:\SDFix\apps\HPFix5.reg
C:\SDFix\apps\HPFix6.reg
C:\SDFix\apps\HPFix7.reg
C:\SDFix\apps\HPFix8.reg
C:\SDFix\apps\HPFix9.reg
C:\SDFix\apps\isadmin.exe
C:\SDFix\apps\leg2.txt
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\Process.exe
C:\SDFix\apps\procs.exe
C:\SDFix\apps\psservice.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\regedit.exe
C:\SDFix\apps\Replace\W2K.exe
C:\SDFix\apps\Replace\w2k\beep.sys
C:\SDFix\apps\Replace\w2k\null.sys
C:\SDFix\apps\Replace\XP.exe
C:\SDFix\apps\Replace\xp\beep.sys
C:\SDFix\apps\Replace\xp\null.sys
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\sed.exe
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\srv2bk.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\vfind.exe
C:\SDFix\apps\WINMSG.EXE
C:\SDFix\apps\winsec.reg
C:\SDFix\apps\zip.exe
C:\SDFix\catchme.exe
C:\SDFix\dummy.sys
C:\SDFix\RunThis.bat
C:\SDFix\SDFIX_ReadMe_Online.url
C:\SDFix\W2K_CodecRepair.inf
C:\SDFix\XP_CodecRepair.inf
C:\Users\Andrew\AppData\Local\Temp\fccYSMDs.dll
C:\Users\Andrew\AppData\Local\Temp\iifFYSji.dll
C:\Users\Andrew\AppData\Local\Temp\iujnycnd.dll
C:\Users\Andrew\AppData\Local\Temp\krnciubf.dll
C:\Users\Andrew\AppData\Local\Temp\ljJCsqRl.dll
C:\Users\Andrew\AppData\Local\Temp\ndmxkvbv.dll
C:\Users\Andrew\AppData\Local\Temp\tiyjpghg.dll
C:\Users\Andrew\AppData\Local\Temp\tuVLdbxX.dll
C:\Users\Andrew\AppData\Local\Temp\urQiggfF.dll
C:\Users\Andrew\AppData\Local\Temp\uvskcuqc.dll
C:\VundoFix Backups
C:\Windows\System32\msupdatgms.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-09 to 2008-06-09 )))))))))))))))))))))))))))))))
.
2008-06-06 11:45 . 2008-06-06 11:45 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-06-06 11:27 . 2008-06-06 11:27 300 --a------ C:\Windows\wininit.ini
2008-06-06 08:47 . 2008-06-06 08:48 74,966,424 --a------ C:\Users\Public\jdk-6u6-windows-i586-p.exe
2008-06-05 01:52 . 2008-06-05 01:52 <DIR> d-------- C:\Users\Ruth\AppData\Roaming\SUPERAntiSpyware.com
2008-06-05 01:47 . 2008-06-05 01:47 <DIR> d-------- C:\Users\Andrew\AppData\Roaming\SUPERAntiSpyware.com
2008-06-05 01:47 . 2008-06-05 01:47 <DIR> d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-06-05 01:47 . 2008-06-05 01:47 <DIR> d-------- C:\ProgramData\SUPERAntiSpyware.com
2008-06-05 01:47 . 2008-06-05 01:47 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-06-05 01:47 . 2008-06-05 01:47 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-05 01:28 . 2008-06-05 01:28 <DIR> d-------- C:\Users\Ruth\AppData\Roaming\DivX
2008-06-05 01:17 . 2008-06-05 01:17 524,288 --ahs---- C:\ntuser.dat{708136a8-32af-11dd-b1d3-0019210fe5b2}.TMContainer00000000000000000002.regtrans-ms
2008-06-05 01:17 . 2008-06-06 11:27 524,288 --ahs---- C:\ntuser.dat{708136a8-32af-11dd-b1d3-0019210fe5b2}.TMContainer00000000000000000001.regtrans-ms
2008-06-05 01:17 . 2008-06-05 01:17 524,288 --ahs---- C:\ntuser.dat{708136a4-32af-11dd-b1d3-0019210fe5b2}.TMContainer00000000000000000002.regtrans-ms
2008-06-05 01:17 . 2008-06-05 01:17 524,288 --ahs---- C:\ntuser.dat{708136a4-32af-11dd-b1d3-0019210fe5b2}.TMContainer00000000000000000001.regtrans-ms
2008-06-05 01:17 . 2008-06-06 10:46 262,144 --a------ C:\ntuser.dat
2008-06-05 01:17 . 2008-06-06 11:27 65,536 --ahs---- C:\ntuser.dat{708136a8-32af-11dd-b1d3-0019210fe5b2}.TM.blf
2008-06-05 01:17 . 2008-06-05 01:17 65,536 --ahs---- C:\ntuser.dat{708136a4-32af-11dd-b1d3-0019210fe5b2}.TM.blf
2008-06-05 01:17 . 2008-06-06 10:46 5,120 --ah----- C:\ntuser.dat.LOG1
2008-06-05 01:17 . 2008-06-05 01:17 0 --ah----- C:\ntuser.dat.LOG2
2008-06-03 12:31 . 2008-06-03 12:31 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-06-03 12:17 . 2008-06-03 12:17 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-03 10:40 . 2008-06-03 10:40 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-06-02 18:55 . 2008-06-03 01:01 <DIR> d-------- C:\PerfLogs
2008-06-01 11:52 . 2008-06-01 11:52 <DIR> dr------- C:\Users\David\Searches
2008-06-01 11:52 . 2008-06-01 11:52 <DIR> dr------- C:\Users\David\Contacts
2008-06-01 11:52 . 2008-06-01 11:52 <DIR> d-------- C:\Users\David\AppData\Roaming\Symantec
2008-06-01 11:51 . 2008-06-01 11:52 <DIR> dr------- C:\Users\David\Videos
2008-06-01 11:51 . 2008-06-01 11:52 <DIR> dr------- C:\Users\David\Saved Games
2008-06-01 11:51 . 2008-06-01 11:52 <DIR> dr------- C:\Users\David\Pictures
2008-06-01 11:51 . 2008-06-01 11:52 <DIR> dr------- C:\Users\David\Music
2008-06-01 11:51 . 2008-06-01 11:52 <DIR> dr------- C:\Users\David\Links
2008-06-01 11:51 . 2008-06-01 11:52 <DIR> dr------- C:\Users\David\Downloads
2008-06-01 11:51 . 2008-06-01 11:52 <DIR> dr------- C:\Users\David\Documents
2008-06-01 11:51 . 2006-11-02 08:37 <DIR> d-------- C:\Users\David\AppData\Roaming\Media Center Programs
2008-06-01 11:51 . 2008-06-01 11:52 <DIR> d--h----- C:\Users\David\AppData
2008-06-01 11:51 . 2008-06-01 11:52 <DIR> d-------- C:\Users\David
2008-06-01 11:09 . 2008-06-01 11:09 <DIR> dr------- C:\Users\Ruth\Searches
2008-06-01 11:09 . 2008-06-01 11:09 <DIR> dr------- C:\Users\Ruth\Contacts
2008-06-01 11:09 . 2008-06-01 11:09 <DIR> d-------- C:\Users\Ruth\AppData\Roaming\Symantec
2008-06-01 11:08 . 2008-06-01 11:09 <DIR> dr------- C:\Users\Ruth\Videos
2008-06-01 11:08 . 2008-06-01 11:09 <DIR> dr------- C:\Users\Ruth\Saved Games
2008-06-01 11:08 . 2008-06-01 11:09 <DIR> dr------- C:\Users\Ruth\Pictures
2008-06-01 11:08 . 2008-06-01 11:09 <DIR> dr------- C:\Users\Ruth\Music
2008-06-01 11:08 . 2008-06-01 11:09 <DIR> dr------- C:\Users\Ruth\Links
2008-06-01 11:08 . 2008-06-01 11:09 <DIR> dr------- C:\Users\Ruth\Downloads
2008-06-01 11:08 . 2008-06-01 11:09 <DIR> dr------- C:\Users\Ruth\Documents
2008-06-01 11:08 . 2006-11-02 08:37 <DIR> d-------- C:\Users\Ruth\AppData\Roaming\Media Center Programs
2008-06-01 11:08 . 2008-06-01 11:09 <DIR> d--h----- C:\Users\Ruth\AppData
2008-06-01 11:08 . 2008-06-01 11:09 <DIR> d-------- C:\Users\Ruth
2008-05-30 08:06 . 2008-05-30 08:06 <DIR> d-------- C:\Users\Andrew\AppData\Roaming\Microsoft Game Studios
2008-05-27 21:02 . 2008-03-07 22:08 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-27 21:02 . 2008-03-08 00:21 1,695,744 --a------ C:\Windows\System32\gameux.dll
2008-05-27 16:51 . 2008-05-27 16:51 <DIR> d-------- C:\Users\Andrew\AppData\Roaming\Symantec
2008-05-27 16:48 . 2008-05-27 16:50 <DIR> d-------- C:\Program Files\Norton Internet Security
2008-05-27 16:46 . 2008-05-27 16:50 123,952 --a------ C:\Windows\System32\drivers\SYMEVENT.SYS
2008-05-27 16:46 . 2008-05-27 16:50 10,563 --a------ C:\Windows\System32\drivers\SYMEVENT.CAT
2008-05-27 16:46 . 2008-05-27 16:50 805 --a------ C:\Windows\System32\drivers\SYMEVENT.INF
2008-05-27 16:19 . 2008-05-27 16:31 <DIR> d-------- C:\Users\All Users\avg8
2008-05-27 16:19 . 2008-05-27 16:31 <DIR> d-------- C:\ProgramData\avg8
2008-05-27 16:19 . 2008-05-27 16:19 <DIR> d-------- C:\Program Files\AVG
2008-05-19 05:12 . 2008-05-20 00:25 <DIR> d-a------ C:\Users\All Users\TEMP
2008-05-19 05:12 . 2008-05-20 00:25 <DIR> d-a------ C:\ProgramData\TEMP
2008-05-19 05:12 . 2008-05-20 00:51 <DIR> d-------- C:\Fraps
2008-05-17 05:52 . 2008-01-19 03:43 3,600,440 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-05-17 05:52 . 2008-01-19 03:43 3,548,728 --a------ C:\Windows\System32\ntoskrnl.exe
2008-05-17 05:52 . 2008-01-19 03:33 2,623,488 --a------ C:\Windows\System32\SLsvc.exe
2008-05-17 05:52 . 2008-01-19 03:36 1,541,120 --a------ C:\Windows\System32\onex.dll
2008-05-17 05:52 . 2008-01-19 03:42 51,768 --a------ C:\Windows\System32\PSHED.DLL
2008-05-17 05:50 . 2008-01-19 03:35 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll
2008-05-17 05:49 . 2008-01-19 03:35 3,072,000 --a------ C:\Windows\System32\networkmap.dll
2008-05-17 05:48 . 2008-01-19 02:06 8,147,456 --a------ C:\Windows\System32\wmploc.DLL
2008-05-17 05:47 . 2008-01-19 03:36 704,512 --a------ C:\Windows\System32\SmiEngine.dll
2008-05-17 05:47 . 2008-01-19 03:36 357,888 --a------ C:\Windows\System32\wbemcomn.dll
2008-05-17 05:47 . 2008-01-19 03:34 305,152 --a------ C:\Windows\System32\msdelta.dll
2008-05-17 05:47 . 2008-01-19 03:34 258,560 --a------ C:\Windows\System32\dpx.dll
2008-05-17 05:47 . 2008-01-19 03:34 246,784 --a------ C:\Windows\System32\drvstore.dll
2008-05-17 05:47 . 2008-01-19 03:36 218,624 --a------ C:\Windows\System32\wdscore.dll
2008-05-17 05:47 . 2008-01-19 03:36 139,264 --a------ C:\Windows\System32\SmiInstaller.dll
2008-05-17 05:47 . 2008-01-19 03:33 130,560 --a------ C:\Windows\System32\PkgMgr.exe
2008-05-17 05:47 . 2008-01-19 03:35 35,328 --a------ C:\Windows\System32\mspatcha.dll
2008-05-11 05:43 . 2008-05-11 05:44 <DIR> d-------- C:\mame32u901
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-06 15:27 --------- d-----w C:\Program Files\BearShare
2008-06-06 14:58 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-06-04 16:17 --------- d-----w C:\Program Files\Privacy Guardian
2008-06-03 17:48 --------- d-----w C:\Users\Andrew\AppData\Roaming\uTorrent
2008-06-02 23:23 --------- d-----w C:\ProgramData\NVIDIA
2008-06-02 23:05 174 --sha-w C:\Program Files\desktop.ini
2008-06-02 22:57 --------- d-----w C:\Program Files\Windows Sidebar
2008-06-02 22:57 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-06-02 22:57 --------- d-----w C:\Program Files\Windows Mail
2008-06-02 22:57 --------- d-----w C:\Program Files\Windows Defender
2008-06-02 22:57 --------- d-----w C:\Program Files\Windows Calendar
2008-06-02 22:33 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-06-02 22:33 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-06-01 16:43 --------- d-----w C:\Program Files\PeerGuardian2
2008-05-27 21:08 --------- d-----w C:\ProgramData\Symantec
2008-05-27 21:07 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-27 20:50 --------- d-----w C:\Program Files\Symantec
2008-05-25 09:44 --------- d-----w C:\Program Files\Microsoft Games
2008-05-11 05:46 --------- d-----w C:\Program Files\DivX
2008-05-05 22:33 --------- d-----w C:\Users\Andrew\AppData\Roaming\DVD Flick
2008-05-03 06:26 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-24 04:15 --------- d-----w C:\Program Files\Kotor Tool
2008-04-23 03:26 1,122,304 ---h--w C:\Windows\System32\wodfamop.dll
2008-04-23 03:26 --------- d-----w C:\Program Files\Abrosoft
2008-04-14 13:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-14 13:38 --------- d-----w C:\Program Files\LucasArts
2008-03-31 21:25 831,488 ----a-w C:\Windows\System32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w C:\Windows\System32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w C:\Windows\System32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w C:\Windows\System32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w C:\Windows\System32\DivX.dll
2008-03-31 21:25 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-03-21 20:30 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\Windows\System32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\Windows\System32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\Windows\System32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\Windows\System32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\Windows\System32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2008-01-01 03:30 31,768,752 ----a-w C:\Users\Andrew\avg75free_516a1225.exe
.
((((((((((((((((((((((((((((( snapshot_2008-06-08_ 9.06.57.45 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-08 12:58:38 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-06-09 19:38:39 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-06-08 13:00:11 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-06-09 19:39:00 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-06-09 19:39:00 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-06-08 13:00:06 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-06-09 19:39:00 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-06-09 19:39:00 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-06-08 12:59:00 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-06-09 19:39:03 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-06-08 12:59:00 65,536 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-09 19:39:03 65,536 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-06-08 12:59:00 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-06-09 19:39:03 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-06-08 01:05:32 105,448 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-06-09 19:31:40 105,448 ----a-w C:\Windows\System32\perfc009.dat
- 2008-06-08 01:05:32 599,942 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-06-09 19:31:40 599,942 ----a-w C:\Windows\System32\perfh009.dat
- 2008-06-08 13:00:31 8,648 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3913138051-876839874-3641419066-1000_UserData.bin
+ 2008-06-09 12:32:31 8,664 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3913138051-876839874-3641419066-1000_UserData.bin
- 2008-06-08 13:00:30 67,658 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-06-09 19:26:02 68,162 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-06-08 13:00:29 41,498 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-06-09 19:26:00 41,900 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-02-07 00:05 349552 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-05-27 16:49 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll" [2008-02-07 00:05 349552]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll [2008-02-07 00:05 349552]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 03:33 125952]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour"="" []
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 17:49 77824]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-25 21:47 51048]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2006-11-17 09:26 453120]
"eRecoveryService"="" []
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-12-11 17:06 8530464]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-12-11 17:06 81920]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-12-11 17:06 86016]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SHStartup.exe" [2008-01-23 15:48 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i263_32.drv
"msacm.mkdmp3enc"= C:\PROGRA~1\ACERZO~1\ACERZO~2\Kernel\Burner\MKDMP3Enc.ACM
"msacm.g723"= g723.acm
"vidc.I263"= I263_32.drv
"msacm.divxa32"= divxa32.acm
[HKLM\~\startupfolder\C:^Users^Andrew^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=C:\Windows\pss\Microsoft Find Fast.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Empowering Technology Monitor]
--a------ 2006-11-23 19:24 319488 C:\Windows\system32\SysMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2006-11-08 22:57 3784704 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-19 03:33 202240 C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\?????????]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{606F9767-608B-402B-961F-09F4FD26CF0D}"= UDP:C:\Program Files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{F805D548-A289-46D1-BD6F-D4F60A7C6050}"= TCP:C:\Program Files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{B72072FB-56BB-43FD-9A80-9BCF8D7289E0}"= UDP:C:\Program Files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{0C764EEA-4B92-4251-88CF-A63A3B6BAC2F}"= TCP:C:\Program Files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{CCC058AA-2F4C-4604-8F3C-93811B85C4A2}"= UDP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{53DBA74A-093C-4270-BF2C-A9A443CAA248}"= TCP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{69E5CD57-D89E-46A5-BB98-A79C39D6EC2A}"= UDP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{9DE2CC96-75DC-47FF-BA30-9162BE1C38CF}"= TCP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{7A5CBA66-D006-4CD7-BA7B-7086872ADBC1}"= UDP:C:\Program Files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{03DE0338-B9D1-4DEA-986A-80946EA0CDE7}"= TCP:C:\Program Files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{98228D92-F771-4D0A-BF54-308EC1C49965}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{104B8FD7-8498-4319-99A2-588C91E2C0F0}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{85914A26-40C0-4ABD-933A-2122375C44E2}"= UDP

:\Call of Duty 4\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{D7764EF8-8D64-42E6-ABA1-30005C85E1AE}"= TCP

:\Call of Duty 4\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{C7C20955-C86E-4CEA-8944-039B83A87449}"= UDP:C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{9C4E023E-2153-47C2-B880-78489806B731}"= TCP:C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080607.001\IDSvix86.sys [2008-03-20 16:37]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 SpyHunter3 Service;SpyHunter3 Service;"C:\Program Files\Enigma Software Group\SpyHunter\SHService.exe" [2008-01-23 15:48]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-02-05 15:34]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-07-31 09:22]
S3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-02-27 08:48]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-06-03 00:35:54 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Andrew.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-09 15:39:18
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\system32\winlogon.exe
-> C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
PROCESS: C:\Windows\system32\lsass.exe
-> C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
PROCESS: C:\Windows\Explorer.exe
-> C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\conime.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2008-06-09 15:44:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-09 19:43:08
ComboFix2.txt 2008-06-08 13:41:28
ComboFix3.txt 2008-06-08 13:07:22
ComboFix4.txt 2008-06-05 18:06:46
ComboFix5.txt 2008-06-05 08:19:33
Pre-Run: 93,949,407,232 bytes free
Post-Run: 93,912,436,736 bytes free
418 --- E O F --- 2008-06-06 12:03:53
Thanks for all your help in this.