Unique_Madness
New member
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, April 26, 2008 6:12:58 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/04/2008
Kaspersky Anti-Virus database records: 726789
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Scan Statistics:
Total number of scanned objects: 68205
Number of viruses found: 5
Number of infected objects: 8
Number of suspicious objects: 0
Duration of the scan process: 00:48:20
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Desktop\Random Shit\Kyle's\Shared\friends request dressed for tw.mpg Infected: Trojan-Downloader.WMA.Wimad.n skipped
C:\Documents and Settings\Owner\Desktop\Random Shit\Kyle's\Shared\pin yeah yeahs.mp3 Infected: Trojan-Downloader.WMA.Wimad.n skipped
C:\Documents and Settings\Owner\Desktop\Random Shit\Kyle's\Shared\Rare Recording.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012008042620080427\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temp\~DF7B22.tmp Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\My Documents\My Music\iTunes\iTunes Library.itl Object is locked skipped
C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\eMachines_Vista.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\eMachine_Specific.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\General.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\Security.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\Security_UK.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\UK_Specific.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\Urgent.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\Virus.dat Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mlJCRJYS.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP27\A0009964.exe Infected: Trojan-Downloader.Win32.Zlob.lqg skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP30\A0013109.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP32\A0013329.exe Infected: Trojan-Downloader.Win32.Obfuscated.ut skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP32\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\lajwpafa.exe Infected: Trojan-Downloader.Win32.Obfuscated.ut skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_6b4.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP32\change.log Object is locked skipped
Scan process completed.
The following is the HjackThis Report.
ComboFix 08-04-24.1 - Owner 2008-04-25 23:06:18.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.826 [GMT -4:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\FOUND.000
C:\FOUND.001
C:\FOUND.002
C:\FOUND.003
C:\FOUND.004
C:\FOUND.005
C:\FOUND.006
C:\FOUND.007
C:\FOUND.008
C:\WINDOWS\system32\abkmpjxl.ini
C:\WINDOWS\system32\cfuqfgfe.dll
C:\WINDOWS\system32\dbuesgni.dll
C:\WINDOWS\system32\efcddefc.dll
C:\WINDOWS\system32\hsbaohoq.ini
C:\WINDOWS\system32\opnlllli.dll
C:\WINDOWS\system32\xrxjuujo.ini
C:\WINDOWS\system32\ydtbljpa.ini
C:\WINDOWS\system32\ypqnsasw.ini
.
((((((((((((((((((((((((( Files Created from 2008-03-26 to 2008-04-26 )))))))))))))))))))))))))))))))
.
2008-04-25 22:55 . 2008-04-25 22:55 98,304 --a------ C:\WINDOWS\system32\ofmrudyz.exe
2008-04-25 20:28 . 2008-04-25 20:28 98,304 --a------ C:\WINDOWS\system32\ovolqdwh.exe
2008-04-25 10:37 . 2008-04-25 10:37 90,112 --a------ C:\WINDOWS\system32\evutetwl.exe
2008-04-25 09:43 . 2008-04-25 09:43 1,503,313 --ahs---- C:\WINDOWS\system32\lfmvdeuw.ini
2008-04-25 09:38 . 2008-04-25 09:38 90,112 --a------ C:\WINDOWS\system32\nqhslufi.exe
2008-04-25 09:13 . 2008-04-25 20:24 385 --a------ C:\WINDOWS\wininit.ini
2008-04-24 22:28 . 2008-04-24 22:28 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-24 22:28 . 2008-04-24 22:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-24 19:09 . 2008-04-25 09:31 1,509,211 --ahs---- C:\WINDOWS\system32\krcusoro.ini
2008-04-24 18:28 . 2008-04-24 05:29 286,720 --a------ C:\WINDOWS\vadokmxt.dll
2008-04-24 18:28 . 2008-04-24 05:29 106,496 --a------ C:\WINDOWS\olgdqarf.exe
2008-04-24 18:27 . 2008-04-24 18:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\lqdofajk
2008-04-23 23:51 . 2008-04-23 23:51 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\DivX
2008-04-23 23:50 . 2008-04-23 23:51 <DIR> d-------- C:\Program Files\DivX
2008-04-18 22:49 . 2008-04-23 23:45 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\BitTorrent
2008-04-18 19:11 . 2008-04-18 19:11 <DIR> d-------- C:\WINDOWS\Sun
2008-04-18 19:11 . 2008-04-18 22:43 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\LimeWire
2008-04-18 19:11 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-18 19:09 . 2008-04-18 19:09 <DIR> d-------- C:\Program Files\LimeWire
2008-04-17 00:02 . 2008-04-17 00:02 <DIR> d-------- C:\Westwood
2008-04-16 20:34 . 2008-04-16 20:34 <DIR> d-------- C:\Program Files\Safari
2008-04-16 20:29 . 2008-04-16 20:29 <DIR> d-------- C:\Program Files\Apple Software Update
2008-04-16 20:24 . 2008-04-16 20:24 <DIR> d-------- C:\Program Files\iTunes
2008-04-16 20:24 . 2008-04-16 20:24 <DIR> d-------- C:\Program Files\iPod
2008-04-16 20:24 . 2008-04-20 21:39 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Apple Computer
2008-04-16 20:24 . 2008-04-25 22:55 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-16 20:24 . 2008-04-16 20:24 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-16 20:23 . 2008-04-16 20:23 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-04-16 20:23 . 2008-04-16 20:23 <DIR> d-------- C:\Program Files\QuickTime
2008-04-16 20:23 . 2008-04-16 20:23 <DIR> d-------- C:\Program Files\Bonjour
2008-04-16 20:23 . 2008-04-16 20:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-16 20:23 . 2008-02-18 11:16 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2008-04-16 20:22 . 2008-04-16 20:22 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-04-16 20:22 . 2008-04-16 20:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-04-16 20:15 . 2008-04-16 20:15 <DIR> d-------- C:\Program Files\DNA
2008-04-16 20:15 . 2008-04-16 20:15 <DIR> d-------- C:\Program Files\BitTorrent
2008-04-16 20:15 . 2008-04-25 23:05 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\DNA
2008-04-16 19:58 . 2008-04-16 19:58 <DIR> d-------- C:\Program Files\Alwil Software
2008-04-16 00:29 . 2008-04-16 00:29 <DIR> d-------- C:\WINDOWS\system32\Radeon1600 dir
2008-04-16 00:29 . 2008-04-16 00:29 532,480 --a------ C:\WINDOWS\system32\Radeon1600.scr
2008-04-16 00:25 . 2008-04-16 00:25 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\ATI
2008-04-16 00:25 . 2008-04-16 00:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-04-16 00:24 . 2008-04-16 00:24 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-04-16 00:22 . 2008-04-16 00:35 <DIR> d-------- C:\Program Files\Steam
2008-04-16 00:19 . 2008-02-25 21:05 593,920 --a------ C:\WINDOWS\system32\ati2sgag.exe
2008-04-16 00:18 . 2008-04-16 00:18 <DIR> d-------- C:\ATI
2008-03-31 17:25 . 2008-03-31 17:25 831,488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 17:25 . 2008-03-31 17:25 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 17:25 . 2008-03-31 17:25 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 17:25 . 2008-03-31 17:25 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 17:25 . 2008-03-31 17:25 682,496 --a------ C:\WINDOWS\system32\DivX.dll
2008-03-31 17:25 . 2008-03-31 17:25 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-18 23:11 --------- d-----w C:\Program Files\Java
2008-04-17 00:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-16 23:47 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-16 23:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-16 04:22 --------- d-----w C:\Program Files\ATI Technologies
2008-04-16 04:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-16 04:21 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-21 20:30 9,464 ----a-w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-03-21 20:30 9,336 ----a-w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 43,528 ----a-w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 129,784 ----a-w C:\WINDOWS\system32\pxafs.dll
2008-03-21 20:30 120,056 ----a-w C:\WINDOWS\system32\pxcpyi64.exe
2008-03-21 20:30 118,520 ----a-w C:\WINDOWS\system32\pxinsi64.exe
2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-26 05:51 2,863,616 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-02-26 03:12 372,736 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-02-26 03:10 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-02-26 03:10 299,520 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-02-26 03:02 172,032 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-02-26 03:02 126,976 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-02-26 03:01 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-02-26 03:01 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-02-26 03:01 126,976 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-02-26 03:00 520,192 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-02-26 02:59 9,797,632 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-02-26 02:58 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-02-26 02:49 3,176,480 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-02-26 02:41 1,755,264 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-02-26 02:29 46,080 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-02-26 02:25 393,216 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-02-26 02:23 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-02-26 02:22 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-02-26 02:21 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-02-26 02:19 167,936 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-02-26 02:16 520,192 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-01-29 16:02 107,368 ----a-w C:\WINDOWS\system32\GEARAspi.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{50466A9F-7CD0-432F-88A7-49667D2D63A6}]
C:\WINDOWS\system32\geBTLFWN.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DEC4196C-5CDA-4840-891D-E524451AB002}]
C:\WINDOWS\system32\efcDWMfg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F5DDA8C4-57CE-4761-9BDF-FB26D2D8EBA7}]
C:\WINDOWS\system32\qoMcyWOh.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 15360]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-04-16 20:15 288576]
"yyryqapm"="C:\WINDOWS\system32\xszqvepk.exe" [2008-04-24 18:27 106496]
"ljbksyul"="C:\WINDOWS\system32\nqhslufi.exe" [2008-04-25 09:38 90112]
"hxnwlfju"="C:\WINDOWS\system32\evutetwl.exe" [2008-04-25 10:37 90112]
"zgatzawv"="C:\WINDOWS\system32\ovolqdwh.exe" [2008-04-25 20:28 98304]
"jtpyfngg"="C:\WINDOWS\system32\ofmrudyz.exe" [2008-04-25 22:55 98304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 16:42 212992]
"CHotkey"="zHotkey.exe" [2004-05-17 21:30 543232 C:\WINDOWS\zHotkey.exe]
"ShowWnd"="ShowWnd.exe" [2003-09-19 12:09 36864 C:\WINDOWS\ShowWnd.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-06-04 22:05 116328]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 19:20 77824 C:\WINDOWS\SOUNDMAN.EXE]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-11-15 18:04 135168]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-12 00:10 344064]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 15:10 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 22:55 54832]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2007-09-01 14:54:21 1742384]
run_startmenu.cmd [2004-10-11 20:20:38 45]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"NXeHMdlE3o"= C:\Documents and Settings\All Users\Application Data\lqdofajk\ngnatmtu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJCRJYS]
mlJCRJYS.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 14:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 14:35]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{064ecfa8-0c16-11dd-99dc-001109121afa}]
\Shell\AutoRun\command - K:\wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-04-24 00:50:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-01 20:11:13 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2007-09-01 20:11:14 C:\WINDOWS\Tasks\ISP signup reminder 2.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2007-09-01 20:11:14 C:\WINDOWS\Tasks\ISP signup reminder 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-25 23:07:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-25 23:07:25
ComboFix-quarantined-files.txt 2008-04-26 03:07:22
ComboFix2.txt 2008-04-26 02:56:53
Pre-Run: 212,799,369,216 bytes free
Post-Run: 212,786,622,464 bytes free
225 --- E O F --- 2008-04-16 07:05:09
Can you help please... I keep geting things that look like it is something Windows is doing but I know a little better then that. I ran spybot a couple of time and it still shows up.
KASPERSKY ONLINE SCANNER REPORT
Saturday, April 26, 2008 6:12:58 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/04/2008
Kaspersky Anti-Virus database records: 726789
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Scan Statistics:
Total number of scanned objects: 68205
Number of viruses found: 5
Number of infected objects: 8
Number of suspicious objects: 0
Duration of the scan process: 00:48:20
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Desktop\Random Shit\Kyle's\Shared\friends request dressed for tw.mpg Infected: Trojan-Downloader.WMA.Wimad.n skipped
C:\Documents and Settings\Owner\Desktop\Random Shit\Kyle's\Shared\pin yeah yeahs.mp3 Infected: Trojan-Downloader.WMA.Wimad.n skipped
C:\Documents and Settings\Owner\Desktop\Random Shit\Kyle's\Shared\Rare Recording.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012008042620080427\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temp\~DF7B22.tmp Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\My Documents\My Music\iTunes\iTunes Library.itl Object is locked skipped
C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\eMachines_Vista.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\eMachine_Specific.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\General.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\Security.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\Security_UK.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\UK_Specific.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\Urgent.dat Object is locked skipped
C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\Virus.dat Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mlJCRJYS.dll.vir Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP27\A0009964.exe Infected: Trojan-Downloader.Win32.Zlob.lqg skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP30\A0013109.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP32\A0013329.exe Infected: Trojan-Downloader.Win32.Obfuscated.ut skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP32\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\lajwpafa.exe Infected: Trojan-Downloader.Win32.Obfuscated.ut skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_6b4.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP32\change.log Object is locked skipped
Scan process completed.
The following is the HjackThis Report.
ComboFix 08-04-24.1 - Owner 2008-04-25 23:06:18.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.826 [GMT -4:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\FOUND.000
C:\FOUND.001
C:\FOUND.002
C:\FOUND.003
C:\FOUND.004
C:\FOUND.005
C:\FOUND.006
C:\FOUND.007
C:\FOUND.008
C:\WINDOWS\system32\abkmpjxl.ini
C:\WINDOWS\system32\cfuqfgfe.dll
C:\WINDOWS\system32\dbuesgni.dll
C:\WINDOWS\system32\efcddefc.dll
C:\WINDOWS\system32\hsbaohoq.ini
C:\WINDOWS\system32\opnlllli.dll
C:\WINDOWS\system32\xrxjuujo.ini
C:\WINDOWS\system32\ydtbljpa.ini
C:\WINDOWS\system32\ypqnsasw.ini
.
((((((((((((((((((((((((( Files Created from 2008-03-26 to 2008-04-26 )))))))))))))))))))))))))))))))
.
2008-04-25 22:55 . 2008-04-25 22:55 98,304 --a------ C:\WINDOWS\system32\ofmrudyz.exe
2008-04-25 20:28 . 2008-04-25 20:28 98,304 --a------ C:\WINDOWS\system32\ovolqdwh.exe
2008-04-25 10:37 . 2008-04-25 10:37 90,112 --a------ C:\WINDOWS\system32\evutetwl.exe
2008-04-25 09:43 . 2008-04-25 09:43 1,503,313 --ahs---- C:\WINDOWS\system32\lfmvdeuw.ini
2008-04-25 09:38 . 2008-04-25 09:38 90,112 --a------ C:\WINDOWS\system32\nqhslufi.exe
2008-04-25 09:13 . 2008-04-25 20:24 385 --a------ C:\WINDOWS\wininit.ini
2008-04-24 22:28 . 2008-04-24 22:28 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-24 22:28 . 2008-04-24 22:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-24 19:09 . 2008-04-25 09:31 1,509,211 --ahs---- C:\WINDOWS\system32\krcusoro.ini
2008-04-24 18:28 . 2008-04-24 05:29 286,720 --a------ C:\WINDOWS\vadokmxt.dll
2008-04-24 18:28 . 2008-04-24 05:29 106,496 --a------ C:\WINDOWS\olgdqarf.exe
2008-04-24 18:27 . 2008-04-24 18:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\lqdofajk
2008-04-23 23:51 . 2008-04-23 23:51 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\DivX
2008-04-23 23:50 . 2008-04-23 23:51 <DIR> d-------- C:\Program Files\DivX
2008-04-18 22:49 . 2008-04-23 23:45 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\BitTorrent
2008-04-18 19:11 . 2008-04-18 19:11 <DIR> d-------- C:\WINDOWS\Sun
2008-04-18 19:11 . 2008-04-18 22:43 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\LimeWire
2008-04-18 19:11 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-18 19:09 . 2008-04-18 19:09 <DIR> d-------- C:\Program Files\LimeWire
2008-04-17 00:02 . 2008-04-17 00:02 <DIR> d-------- C:\Westwood
2008-04-16 20:34 . 2008-04-16 20:34 <DIR> d-------- C:\Program Files\Safari
2008-04-16 20:29 . 2008-04-16 20:29 <DIR> d-------- C:\Program Files\Apple Software Update
2008-04-16 20:24 . 2008-04-16 20:24 <DIR> d-------- C:\Program Files\iTunes
2008-04-16 20:24 . 2008-04-16 20:24 <DIR> d-------- C:\Program Files\iPod
2008-04-16 20:24 . 2008-04-20 21:39 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Apple Computer
2008-04-16 20:24 . 2008-04-25 22:55 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-16 20:24 . 2008-04-16 20:24 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-16 20:23 . 2008-04-16 20:23 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-04-16 20:23 . 2008-04-16 20:23 <DIR> d-------- C:\Program Files\QuickTime
2008-04-16 20:23 . 2008-04-16 20:23 <DIR> d-------- C:\Program Files\Bonjour
2008-04-16 20:23 . 2008-04-16 20:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-16 20:23 . 2008-02-18 11:16 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2008-04-16 20:22 . 2008-04-16 20:22 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-04-16 20:22 . 2008-04-16 20:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-04-16 20:15 . 2008-04-16 20:15 <DIR> d-------- C:\Program Files\DNA
2008-04-16 20:15 . 2008-04-16 20:15 <DIR> d-------- C:\Program Files\BitTorrent
2008-04-16 20:15 . 2008-04-25 23:05 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\DNA
2008-04-16 19:58 . 2008-04-16 19:58 <DIR> d-------- C:\Program Files\Alwil Software
2008-04-16 00:29 . 2008-04-16 00:29 <DIR> d-------- C:\WINDOWS\system32\Radeon1600 dir
2008-04-16 00:29 . 2008-04-16 00:29 532,480 --a------ C:\WINDOWS\system32\Radeon1600.scr
2008-04-16 00:25 . 2008-04-16 00:25 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\ATI
2008-04-16 00:25 . 2008-04-16 00:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-04-16 00:24 . 2008-04-16 00:24 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-04-16 00:22 . 2008-04-16 00:35 <DIR> d-------- C:\Program Files\Steam
2008-04-16 00:19 . 2008-02-25 21:05 593,920 --a------ C:\WINDOWS\system32\ati2sgag.exe
2008-04-16 00:18 . 2008-04-16 00:18 <DIR> d-------- C:\ATI
2008-03-31 17:25 . 2008-03-31 17:25 831,488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 17:25 . 2008-03-31 17:25 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 17:25 . 2008-03-31 17:25 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 17:25 . 2008-03-31 17:25 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 17:25 . 2008-03-31 17:25 682,496 --a------ C:\WINDOWS\system32\DivX.dll
2008-03-31 17:25 . 2008-03-31 17:25 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-18 23:11 --------- d-----w C:\Program Files\Java
2008-04-17 00:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-16 23:47 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-16 23:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-16 04:22 --------- d-----w C:\Program Files\ATI Technologies
2008-04-16 04:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-16 04:21 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-21 20:30 9,464 ----a-w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-03-21 20:30 9,336 ----a-w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 43,528 ----a-w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 129,784 ----a-w C:\WINDOWS\system32\pxafs.dll
2008-03-21 20:30 120,056 ----a-w C:\WINDOWS\system32\pxcpyi64.exe
2008-03-21 20:30 118,520 ----a-w C:\WINDOWS\system32\pxinsi64.exe
2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-26 05:51 2,863,616 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-02-26 03:12 372,736 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-02-26 03:10 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-02-26 03:10 299,520 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-02-26 03:02 172,032 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-02-26 03:02 126,976 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-02-26 03:01 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-02-26 03:01 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-02-26 03:01 126,976 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-02-26 03:00 520,192 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-02-26 02:59 9,797,632 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-02-26 02:58 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-02-26 02:49 3,176,480 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-02-26 02:41 1,755,264 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-02-26 02:29 46,080 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-02-26 02:25 393,216 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-02-26 02:23 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-02-26 02:22 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-02-26 02:21 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-02-26 02:19 167,936 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-02-26 02:16 520,192 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-01-29 16:02 107,368 ----a-w C:\WINDOWS\system32\GEARAspi.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{50466A9F-7CD0-432F-88A7-49667D2D63A6}]
C:\WINDOWS\system32\geBTLFWN.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DEC4196C-5CDA-4840-891D-E524451AB002}]
C:\WINDOWS\system32\efcDWMfg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F5DDA8C4-57CE-4761-9BDF-FB26D2D8EBA7}]
C:\WINDOWS\system32\qoMcyWOh.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 15360]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-04-16 20:15 288576]
"yyryqapm"="C:\WINDOWS\system32\xszqvepk.exe" [2008-04-24 18:27 106496]
"ljbksyul"="C:\WINDOWS\system32\nqhslufi.exe" [2008-04-25 09:38 90112]
"hxnwlfju"="C:\WINDOWS\system32\evutetwl.exe" [2008-04-25 10:37 90112]
"zgatzawv"="C:\WINDOWS\system32\ovolqdwh.exe" [2008-04-25 20:28 98304]
"jtpyfngg"="C:\WINDOWS\system32\ofmrudyz.exe" [2008-04-25 22:55 98304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 16:42 212992]
"CHotkey"="zHotkey.exe" [2004-05-17 21:30 543232 C:\WINDOWS\zHotkey.exe]
"ShowWnd"="ShowWnd.exe" [2003-09-19 12:09 36864 C:\WINDOWS\ShowWnd.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-06-04 22:05 116328]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 19:20 77824 C:\WINDOWS\SOUNDMAN.EXE]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-11-15 18:04 135168]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-12 00:10 344064]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 15:10 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 22:55 54832]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2007-09-01 14:54:21 1742384]
run_startmenu.cmd [2004-10-11 20:20:38 45]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"NXeHMdlE3o"= C:\Documents and Settings\All Users\Application Data\lqdofajk\ngnatmtu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJCRJYS]
mlJCRJYS.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 14:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 14:35]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{064ecfa8-0c16-11dd-99dc-001109121afa}]
\Shell\AutoRun\command - K:\wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-04-24 00:50:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-01 20:11:13 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2007-09-01 20:11:14 C:\WINDOWS\Tasks\ISP signup reminder 2.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2007-09-01 20:11:14 C:\WINDOWS\Tasks\ISP signup reminder 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-25 23:07:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-25 23:07:25
ComboFix-quarantined-files.txt 2008-04-26 03:07:22
ComboFix2.txt 2008-04-26 02:56:53
Pre-Run: 212,799,369,216 bytes free
Post-Run: 212,786,622,464 bytes free
225 --- E O F --- 2008-04-16 07:05:09
Can you help please... I keep geting things that look like it is something Windows is doing but I know a little better then that. I ran spybot a couple of time and it still shows up.