ESET found this:
C:\Qoobox\Quarantine\C\WINDOWS\system32\_zdinouhd_.dll.zip Win32/Conficker.AA worm
here is the DDS log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Joe- at 9:10:43.65 on Mon 03/29/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2045.1134 [GMT -4:00]
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\idt\intelxpv_v103\wdm\STacSV.exe
svchost.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
C:\Documents and Settings\Joe-\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uURLSearchHooks: H - No File
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [DiskeeperSystray] "c:\program files\executive software\diskeeper\DkIcon.exe"
mRun: [ChangeTPMAuth] c:\program files\wave systems corp\common\ChangeTPMAuth.exe /T:NTRU12
mRun: [SecureUpgrade] c:\program files\wave systems corp\SecureUpgrade.exe
mRun: [EmbassySecurityCheck] "c:\program files\wave systems corp\embassy security setup\EMBASSYSecurityCheck.exe"
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\biolsp.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
LSA: Authentication Packages = msv1_0 wvauth
============= SERVICES / DRIVERS ===============
R0 stmtpm;STM TPM Service;c:\windows\system32\drivers\stm_tpm.sys [2009-7-17 21504]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2007-5-29 192104]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2007-5-29 169576]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-10-7 1822648]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [2004-8-4 5120]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-3-27 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100327.003\naveng.sys [2010-3-27 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100327.003\navex15.sys [2010-3-27 1324720]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-10-7 116664]
S3 sessavs;sessavs;c:\windows\system32\drivers\sessavs.sys [2009-10-5 25600]
S3 sessusb;sessusb;c:\windows\system32\drivers\sessusb.sys [2009-10-5 186368]
S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\synasUSB.sys [2009-10-5 18432]
=============== Created Last 30 ================
2010-03-29 13:06:45 0 d-----w- c:\program files\ESET
2010-03-29 12:38:22 176 ----a-w- c:\documents and settings\joe-\defogger_reenable
2010-03-27 20:58:28 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-03-27 20:45:00 0 d-sha-r- C:\cmdcons
2010-03-27 20:43:11 77312 ----a-w- c:\windows\MBR.exe
2010-03-27 20:43:10 98816 ----a-w- c:\windows\sed.exe
2010-03-27 20:43:10 261632 ----a-w- c:\windows\PEV.exe
2010-03-27 20:43:10 161792 ----a-w- c:\windows\SWREG.exe
2010-03-21 15:34:50 0 ----a-w- c:\windows\vpc32.INI
2010-03-21 13:15:17 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-03-21 13:15:17 8014 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-03-21 13:15:17 48768 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-03-21 13:15:17 110952 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-03-21 13:14:29 0 d-----w- c:\program files\Symantec
2010-03-21 13:14:21 0 d-----w- c:\program files\Symantec AntiVirus
2010-03-21 13:14:21 0 d-----w- c:\program files\common files\Symantec Shared
2010-03-21 13:14:21 0 d-----w- c:\docume~1\alluse~1\applic~1\Symantec
2010-03-20 00:41:41 0 d-----w- c:\program files\Trend Micro
2010-03-15 20:46:09 36864 ----a-w- c:\windows\system32\trayicon_handler.ocx
2010-03-15 20:33:44 0 d-----w- c:\program files\Free Easy Burner
2010-03-14 13:58:04 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2010-03-14 13:48:27 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2010-03-14 13:48:27 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2010-03-14 13:48:26 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2010-03-14 13:48:26 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2010-03-14 13:48:26 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2010-03-14 13:48:25 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-03-14 13:48:25 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-03-14 13:47:09 0 d-----w- c:\windows\SxsCaPendDel
==================== Find3M ====================
2010-03-28 22:27:18 138784 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-03-28 22:27:08 111928 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-03-14 13:58:28 138056 ----a-w- c:\docume~1\joe-\applic~1\PnkBstrK.sys
============= FINISH: 9:11:09.03 ===============
And combofix:
ComboFix 10-03-28.03 - Joe- 03/29/2010 8:48.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2045.1294 [GMT -4:00]
Running from: c:\documents and settings\Joe-\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Joe-\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Joe-\Application Data\ntos.exe
c:\documents and settings\Joe-\Application Data\uTorrent
c:\documents and settings\Joe-\Application Data\uTorrent\[PSX] Chrono.Cross.NTSC.US.2CDS.rar.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\Battlefield.Bad.Company.2-RELOADED.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\Borderlands-RELOADED.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\Borderlands.Mad.Moxxis.Underdome.Riot.DLC-RELOADED.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\Borderlands.The.Zombie.Island.of.Dr.Ned.DLC-RELOADED.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\Call of duty 5 World at war [PC-DVD] [English] [
www.divxatope.com].1.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\Call of duty 5 World at war [PC-DVD] [English] [
www.divxatope.com].torrent
c:\documents and settings\Joe-\Application Data\uTorrent\dht.dat
c:\documents and settings\Joe-\Application Data\uTorrent\dht.dat.old
c:\documents and settings\Joe-\Application Data\uTorrent\Ed, Edd, n' Eddy - Seasons 1-5 + Extras.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\Enemy territory quake wars [PC-DVD] [Multi5] [
www.topetorrent.com].torrent
c:\documents and settings\Joe-\Application Data\uTorrent\Pulp.Fiction.[1994].DvDrip[ENG]-P4DGE_[
www.superfundo.org].torrent
c:\documents and settings\Joe-\Application Data\uTorrent\resume.dat
c:\documents and settings\Joe-\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Joe-\Application Data\uTorrent\ReturnToCastleWolfenstein.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\rss.dat
c:\documents and settings\Joe-\Application Data\uTorrent\rss.dat.old
c:\documents and settings\Joe-\Application Data\uTorrent\settings.dat
c:\documents and settings\Joe-\Application Data\uTorrent\settings.dat.old
c:\documents and settings\Joe-\Application Data\uTorrent\SYMANTEC ANTIVIRUS FOR XP, VISTA, AND VISTAX64.rar.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\The.Big.Lebowski.DVDRip.AC3.XviD-Bayfilms.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\Transcribe ver 7.51.0 with video tutorial.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\utorrent.lng
c:\documents and settings\Joe-\Application Data\uTorrent\Vampire Weekend - Contra CDRip 2010 [Cov+CD][Bubanee]public edition.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\White Chicks[2004]DvDrip-Exe.avi.torrent
c:\documents and settings\Joe-\Application Data\uTorrent\Wolfenstein-Razor1911.torrent
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_GVAIUU
-------\Service_gvaiuu
((((((((((((((((((((((((( Files Created from 2010-02-28 to 2010-03-29 )))))))))))))))))))))))))))))))
.
2010-03-27 22:56 . 2010-03-27 22:56 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2010-03-27 20:58 . 2010-02-24 14:16 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-03-21 13:16 . 2010-03-21 13:16 -------- d-----w- c:\documents and settings\Joe-\Local Settings\Application Data\Symantec
2010-03-21 13:15 . 2010-03-21 13:15 48768 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-03-21 13:15 . 2010-03-21 13:15 110952 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-03-21 13:14 . 2010-03-21 13:15 -------- d-----w- c:\program files\Symantec
2010-03-21 13:14 . 2010-03-29 12:54 -------- d-----w- c:\program files\Symantec AntiVirus
2010-03-21 13:14 . 2010-03-21 13:15 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-03-21 13:14 . 2010-03-21 13:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-03-20 01:01 . 2010-03-20 01:01 -------- d-----w- c:\program files\Windows Defender
2010-03-20 00:41 . 2010-03-20 00:41 -------- d-----w- c:\program files\Trend Micro
2010-03-15 20:33 . 2005-03-11 22:37 1986560 ----a-w- c:\windows\system32\AudFile.dll
2010-03-15 20:33 . 2005-02-24 17:11 1212416 ----a-w- c:\windows\system32\AudioInfos.dll
2010-03-15 20:33 . 2005-02-24 16:51 348160 ----a-w- c:\windows\system32\WMAFile.dll
2010-03-15 20:33 . 2003-01-26 16:41 40960 ----a-w- c:\windows\system32\SSubTmr6.dll
2010-03-15 20:33 . 2000-10-01 22:00 119568 ----a-w- c:\windows\system32\VB6FR.DLL
2010-03-15 20:33 . 1999-03-25 22:00 101888 ----a-w- c:\windows\system32\VB6STKIT.DLL
2010-03-15 20:33 . 1998-07-13 02:00 15360 ----a-w- c:\windows\system32\inetfr.DLL
2010-03-15 20:33 . 1998-07-13 02:00 141312 ----a-w- c:\windows\system32\MSCMCFR.DLL
2010-03-15 20:33 . 1998-07-12 22:00 32768 ----a-w- c:\windows\system32\CMDLGFR.DLL
2010-03-15 20:33 . 2010-03-16 23:18 -------- d-----w- c:\program files\Free Easy Burner
2010-03-15 20:33 . 2003-04-18 19:29 44544 ----a-w- c:\windows\system32\msxml4a.dll
2010-03-14 13:58 . 2010-03-14 13:58 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2010-03-14 13:48 . 2010-03-14 13:48 -------- d-----w- c:\program files\Electronic Arts
2010-03-14 13:48 . 2009-09-04 21:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2010-03-14 13:48 . 2009-09-04 21:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2010-03-14 13:48 . 2009-09-04 21:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2010-03-14 13:48 . 2009-09-04 21:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2010-03-14 13:48 . 2009-09-04 21:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2010-03-14 13:48 . 2009-09-04 21:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-03-14 13:48 . 2009-09-04 21:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-03-14 13:47 . 2010-03-14 15:29 -------- d-----w- c:\windows\SxsCaPendDel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-29 12:56 . 2009-07-18 02:28 -------- d-----w- c:\program files\Steam
2010-03-29 12:45 . 2009-11-02 23:29 -------- d-----w- c:\documents and settings\Joe-\Application Data\HPAppData
2010-03-29 12:30 . 2009-12-19 12:03 -------- d-----w- c:\documents and settings\LocalService\Application Data\HPAppData
2010-03-29 00:39 . 2009-07-18 03:15 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-29 00:19 . 2009-08-04 03:02 -------- d-----w- c:\documents and settings\Joe-\Application Data\vlc
2010-03-28 22:27 . 2009-08-03 12:50 138784 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-03-28 22:27 . 2009-08-03 12:49 111928 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-03-27 18:11 . 2009-08-07 18:02 -------- d-----w- c:\program files\StepMania
2010-03-21 13:15 . 2010-03-21 13:15 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-03-21 13:15 . 2010-03-21 13:15 8014 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-03-20 12:46 . 2009-07-24 17:17 -------- d-----w- c:\program files\Wolfenstein - Enemy Territory
2010-03-20 12:45 . 2009-07-18 01:29 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-20 01:04 . 2009-07-18 02:52 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-03-14 13:58 . 2009-08-28 13:41 138056 ----a-w- c:\documents and settings\Joe-\Application Data\PnkBstrK.sys
2010-03-14 13:58 . 2009-08-28 13:41 138056 ----a-w- c:\documents and settings\Joe-\Application Data\PnkBstrK.sys
2010-02-26 15:42 . 2009-08-26 22:55 -------- d-----w- c:\program files\Return to Castle Wolfenstein
2010-02-26 15:42 . 2009-10-03 15:16 -------- d-----w- c:\program files\Common Files\Common Share
2010-02-26 15:42 . 2009-10-05 22:06 -------- d-----w- c:\program files\Common Files\Native Instruments
2010-02-26 15:41 . 2009-07-18 03:12 -------- d-----w- c:\program files\Vstplugins
2010-02-26 15:40 . 2009-07-18 01:45 -------- d-----w- c:\program files\NewTech Infosystems
2010-02-26 15:40 . 2009-07-18 01:30 -------- d-----w- c:\program files\Intel
2010-02-26 15:37 . 2009-11-02 22:10 -------- d-----w- c:\program files\Yahoo!
2010-02-26 15:36 . 2009-08-11 02:07 401408 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2010-02-25 08:16 . 2009-08-19 03:39 262416 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-30 16:24 . 2009-08-26 13:58 220926964 ----a-w- c:\documents and settings\Joe-\Application Data\ijjigame\U_GUNZ_setup.exe
2009-12-31 16:14 . 2004-08-04 03:14 352640 ----a-w- c:\windows\system32\drivers\srv.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2010-02-21 1217872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DiskeeperSystray"="c:\program files\Executive Software\Diskeeper\DkIcon.exe" [2005-04-30 196696]
"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2007-01-31 176128]
"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2007-04-16 212992]
"EmbassySecurityCheck"="c:\program files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe" [2007-04-16 65536]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-03-12 483422]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 52840]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-10-08 125368]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PurpleBean.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Wolfenstein\\MP\\Wolf2MP.exe"=
"c:\\Program Files\\Activision\\Wolfenstein\\MP\\Wolf2MPLite.exe"=
"c:\\Program Files\\River Past\\Audio Converter\\AudioConverter.exe"=
"c:\\Program Files\\Steam\\steamapps\\noreturn12\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\noreturn12\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\id Software\\Enemy Territory - QUAKE Wars\\etqw.exe"=
"c:\\Program Files\\id Software\\Enemy Territory - QUAKE Wars\\etqwded.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\2K Games\\Gearbox Software\\Borderlands\\Binaries\\Borderlands.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\ijjiOptimizer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56202:TCP"= 56202:TCP

ando Media Booster
"56202:UDP"= 56202:UDP

ando Media Booster
R0 stmtpm;STM TPM Service;c:\windows\system32\drivers\stm_tpm.sys [7/17/2009 9:48 PM 21504]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [8/4/2004 12:56 AM 5120]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/27/2010 5:29 PM 102448]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [10/7/2007 8:48 PM 116664]
S3 sessavs;sessavs;c:\windows\system32\drivers\sessavs.sys [10/5/2009 6:56 PM 25600]
S3 sessusb;sessusb;c:\windows\system32\drivers\sessusb.sys [10/5/2009 6:56 PM 186368]
S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\synasUSB.sys [10/5/2009 6:31 PM 18432]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8/28/2009 9:24 AM 721904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-03-29 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\biolsp.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-29 08:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-1614895754-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:9f,f3,0b,fe,3b,7a,50,48,2d,28,d6,8f,22,f5,2a,0e,a9,c1,a4,79,d9,
6f,2e,39,b2,75,87,7c,fc,03,43,4b,a7,49,e7,60,fe,17,08,3f,87,e2,7d,a0,ab,de,\
"rkeysecu"=hex:89,f8,61,35,fd,89,2c,a1,94,75,93,25,1c,e3,76,33
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(736)
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll
- - - - - - - > 'explorer.exe'(1412)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\idt\intelxpv_v103\wdm\STacSV.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Executive Software\Diskeeper\DkService.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\program files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\msdtc.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2010-03-29 09:02:11 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-29 13:02
ComboFix2.txt 2010-03-27 20:59
Pre-Run: 165,203,173,376 bytes free
Post-Run: 165,184,958,464 bytes free
- - End Of File - - ABE8F8FF649F0F5FAAECF76BC01984A2