when i pasted the text file on combofix the first thing that happened was an update for combofix. it restarted after updating but i think it got the files, as theyre mentioned in the log. dds.txt log will follow shortly.
machine is running pretty good, a lot faster than it was before this mess. thanks again for your help.
ComboFix 09-10-07.05 - Spiderman 10/08/2009 17:21.4.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.242 [GMT -4:00]
Running from: c:\documents and settings\Spiderman\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Spiderman\Desktop\CFScript.txt
FILE ::
"c:\windows\Downloaded Program Files\StripSaver_116.EXE"
"c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6JYLAZOX\podli[1].exe"
"c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O9YJK1IJ\b[1].exe"
"c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O9YJK1IJ\Z[1].exe"
"c:\windows\SYSTEM32\dhero"
file zipped: c:\windows\Downloaded Program Files\StripSaver_116.EXE
file zipped: c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6JYLAZOX\podli[1].exe
file zipped: c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O9YJK1IJ\b[1].exe
file zipped: c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O9YJK1IJ\Z[1].exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\StripSaver_116.EXE
c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6JYLAZOX\podli[1].exe
c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O9YJK1IJ\b[1].exe
c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O9YJK1IJ\Z[1].exe
c:\windows\SYSTEM32\dhero
.
((((((((((((((((((((((((( Files Created from 2009-09-08 to 2009-10-08 )))))))))))))))))))))))))))))))
.
2009-10-07 21:53 . 2009-10-08 11:15 790560 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-05 22:15 . 2009-10-05 22:15 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-04 17:37 . 2009-10-04 17:39 -------- d-----w- c:\windows\system32\Adobe
2009-10-04 17:18 . 2009-10-04 17:18 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-10-04 17:16 . 2009-10-05 21:58 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-10-04 17:09 . 2009-10-04 17:09 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-09-12 19:11 . 2009-09-12 19:11 -------- d-----w- c:\windows\system32\wbem\Repository
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-08 11:15 . 2009-10-07 21:53 10340 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-07 21:53 . 2007-11-22 17:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-10-05 22:15 . 2004-05-19 15:18 -------- d-----w- c:\program files\Java
2009-10-05 21:51 . 2007-09-16 20:15 -------- d-----w- c:\program files\PeerGuardian2
2009-10-04 17:21 . 2004-07-20 03:08 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-04 17:08 . 2005-09-25 02:53 -------- d-----w- c:\program files\AIM
2009-10-04 17:08 . 2005-09-25 02:53 -------- d-----w- c:\documents and settings\Spiderman\Application Data\Aim
2009-10-04 13:21 . 2002-08-29 10:00 182656 ------w- c:\windows\system32\drivers\ndis.sys
2009-09-30 00:02 . 2005-12-30 00:37 -------- d-----w- c:\program files\Common Files\KnifeEdge
2009-09-14 21:38 . 2005-07-13 03:08 -------- d-----w- c:\program files\Program Files
2009-09-12 19:10 . 2009-03-15 00:26 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-03 03:58 . 2004-07-09 22:13 118440 ----a-w- c:\documents and settings\Spiderman\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-25 21:35 . 2009-08-25 16:29 -------- d-----w- c:\documents and settings\All Users\Application Data\10983904
2009-08-06 23:24 . 2004-08-12 15:45 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 23:24 . 2004-08-12 15:45 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 23:24 . 2005-05-26 08:16 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 23:24 . 2004-08-12 15:45 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 23:24 . 2002-08-29 10:00 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 23:24 . 2002-08-29 10:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 23:23 . 2004-08-12 15:45 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 23:23 . 2006-11-02 22:34 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 23:23 . 2006-11-02 22:34 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 23:23 . 2002-08-29 10:00 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-07-17 19:01 . 2002-08-29 10:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-17 19:01 . 2002-08-29 10:00 58880 ----a-w- c:\windows\system32\atl(3)(3).dll
2009-07-14 03:43 . 2004-08-11 05:45 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2005-08-21 16:42 . 2005-06-27 23:17 905 -c--a-w- c:\program files\uninstal.log
2006-01-11 06:41 . 2004-08-29 00:07 56 --sh--r- c:\windows\SYSTEM32\6BBF71BA10.sys
2006-09-24 00:47 . 2004-08-29 00:07 10856 --sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-10-04_14.11.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-05 20:55 . 2009-08-06 23:24 44768 c:\windows\SYSTEM32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.4.7600.226\wups2.dll
+ 2009-10-05 20:55 . 2009-08-06 23:24 35552 c:\windows\SYSTEM32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll
+ 2009-10-04 17:43 . 2009-10-04 17:43 88589 c:\windows\SYSTEM32\Macromed\Flash\uninstall_activeX.exe
+ 2004-08-12 15:45 . 2009-08-06 23:24 35552 c:\windows\SYSTEM32\DLLCACHE\wups.dll
+ 2002-08-29 10:00 . 2009-08-06 23:24 53472 c:\windows\SYSTEM32\DLLCACHE\wuauclt.exe
+ 2002-08-29 10:00 . 2009-08-06 23:24 96480 c:\windows\SYSTEM32\DLLCACHE\cdm.dll
+ 2009-10-04 17:38 . 2009-10-04 17:38 87618 c:\windows\SYSTEM32\Adobe\Shockwave 11\uninstaller.exe
+ 2009-07-31 13:26 . 2009-07-31 13:26 94208 c:\windows\SYSTEM32\Adobe\Shockwave 11\SwMenu.dll
+ 2009-07-31 12:54 . 2009-07-31 12:54 79488 c:\windows\SYSTEM32\Adobe\Shockwave 11\gtapi.dll
+ 2009-07-31 13:42 . 2009-07-31 13:42 67000 c:\windows\SYSTEM32\Adobe\Director\SWDNLD.EXE
+ 2009-10-04 17:18 . 2009-10-04 17:18 21504 c:\windows\Installer\6c7a1.msi
+ 2009-10-04 17:18 . 2009-10-04 17:18 27648 c:\windows\Installer\6c79c.msi
+ 2009-07-31 13:28 . 2009-07-31 13:28 9216 c:\windows\SYSTEM32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2009-10-04 17:09 . 2009-10-04 17:09 2560 c:\windows\_MSRSTRT.EXE
+ 2009-07-18 03:12 . 2009-07-18 03:12 257440 c:\windows\SYSTEM32\Macromed\Flash\FlashUtil10c.exe
+ 2009-10-05 22:15 . 2009-10-05 22:15 149280 c:\windows\SYSTEM32\javaws.exe
+ 2009-10-05 22:15 . 2009-10-05 22:15 145184 c:\windows\SYSTEM32\javaw.exe
+ 2009-10-05 22:15 . 2009-10-05 22:15 145184 c:\windows\SYSTEM32\java.exe
+ 2004-08-12 15:45 . 2009-08-06 23:24 209632 c:\windows\SYSTEM32\DLLCACHE\wuweb.dll
+ 2004-08-12 15:45 . 2009-08-06 23:24 327896 c:\windows\SYSTEM32\DLLCACHE\wucltui.dll
+ 2004-08-12 15:45 . 2009-08-06 23:23 575704 c:\windows\SYSTEM32\DLLCACHE\wuapi.dll
+ 2009-07-31 12:54 . 2009-07-31 12:54 132472 c:\windows\SYSTEM32\Adobe\Shockwave 11\SYMCCHECKER.DLL
+ 2009-07-31 13:26 . 2009-07-31 13:26 114688 c:\windows\SYSTEM32\Adobe\Shockwave 11\SwInit.exe
+ 2009-07-31 13:40 . 2009-07-31 13:40 468408 c:\windows\SYSTEM32\Adobe\Shockwave 11\SwHelper_1151601.exe
+ 2009-07-31 13:28 . 2009-07-31 13:28 446464 c:\windows\SYSTEM32\Adobe\Shockwave 11\Proj.dll
+ 2009-07-31 13:26 . 2009-07-31 13:26 372736 c:\windows\SYSTEM32\Adobe\Shockwave 11\Plugin.dll
+ 2009-07-31 12:54 . 2009-07-31 12:54 714752 c:\windows\SYSTEM32\Adobe\Shockwave 11\gi.dll
+ 2009-07-31 13:25 . 2009-07-31 13:25 614400 c:\windows\SYSTEM32\Adobe\Shockwave 11\Control.dll
+ 2009-07-31 13:41 . 2009-07-31 13:41 206264 c:\windows\SYSTEM32\Adobe\Director\SwDir.dll
+ 2009-07-31 13:27 . 2009-07-31 13:27 131072 c:\windows\SYSTEM32\Adobe\Director\np32dsw.dll
+ 2009-01-18 20:05 . 2009-01-18 20:05 675840 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\JP2KLib.dll
+ 2002-08-29 10:00 . 2009-08-06 23:23 1929952 c:\windows\SYSTEM32\DLLCACHE\wuaueng.dll
+ 2009-07-31 13:00 . 2009-07-31 13:00 1011712 c:\windows\SYSTEM32\Adobe\Shockwave 11\iml32.dll
+ 2009-07-31 12:54 . 2009-07-31 12:54 1886320 c:\windows\SYSTEM32\Adobe\Shockwave 11\gt.exe
+ 2009-07-31 13:04 . 2009-07-31 13:04 1798144 c:\windows\SYSTEM32\Adobe\Shockwave 11\dirapi.dll
+ 2009-10-04 17:21 . 2009-10-04 17:21 3938816 c:\windows\Installer\6c7a6.msi
+ 2009-10-04 17:36 . 2009-10-04 17:36 1697792 c:\windows\Installer\143596.msp
+ 2009-10-04 17:34 . 2009-10-04 17:34 6653952 c:\windows\Installer\143588.msp
+ 2009-10-04 17:32 . 2009-10-04 17:32 2150400 c:\windows\Installer\143564.msp
+ 2009-10-05 22:15 . 2009-10-05 22:15 1757696 c:\windows\Installer\102ee5.msi
+ 2008-12-18 20:48 . 2008-12-18 20:48 3645440 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\authplay.dll
+ 2009-02-27 20:37 . 2009-02-27 20:37 20403568 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\AcroRd32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-05-12 6729728]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2007-02-08 295856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-05 149280]
"NvMediaCenter"="NvMCTray.dll" - c:\windows\SYSTEM32\nvmctray.dll [2005-05-12 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\SYSTEM32\narrator.exe [2008-04-14 53760]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk.disabled
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
backup=c:\windows\pss\Exif Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Spiderman^Start Menu^Programs^Startup^clippy.exe]
path=c:\documents and settings\Spiderman\Start Menu\Programs\Startup\clippy.exe
backup=c:\windows\pss\clippy.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Spiderman^Start Menu^Programs^Startup^Magnifier.lnk]
path=c:\documents and settings\Spiderman\Start Menu\Programs\Startup\Magnifier.lnk
backup=c:\windows\pss\Magnifier.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Spiderman^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
path=c:\documents and settings\Spiderman\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
backup=c:\windows\pss\Stardock ObjectDock.lnkStartup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Insider"=c:\program files\Insider\Insider.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\bak\qttask.exe" -atboottime
"nwiz"=nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\SYSTEM32\\lxczcoms.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Summitsoft\\Business Card Shop\\FRegister.exe"=
"c:\\Program Files\\Summitsoft\\Business Card Shop\\BCGUpdate.exe"=
"c:\\Program Files\\Summitsoft\\Business Card Shop\\Summitsoft Products.exe"=
"c:\\Program Files\\Summitsoft\\Business Card Shop\\BCGFonts.exe"=
"c:\\Program Files\\Summitsoft\\Business Card Shop\\Splash_LDS.exe"=
"c:\\Program Files\\Summitsoft\\Business Card Shop\\Splash Series 1_Oct132008.exe"=
S3 brfilt;Brother MFC Filter Driver;c:\windows\SYSTEM32\DRIVERS\BrFilt.sys [8/13/2006 9:48 AM 2944]
S3 brparimg;Brother Multi Function Parallel Image driver;c:\windows\SYSTEM32\DRIVERS\BrParImg.sys [8/13/2006 9:48 AM 3168]
S3 BrParWdm;Brother WDM Parallel Driver;c:\windows\SYSTEM32\DRIVERS\BrParwdm.sys [8/13/2006 9:48 AM 39552]
S3 BrSerWDM;Brother Serial driver;c:\windows\SYSTEM32\DRIVERS\BrSerWdm.sys [8/13/2006 9:48 AM 60416]
S3 DMSKSSRh;DMSKSSRh;\??\c:\docume~1\SPIDER~1\LOCALS~1\Temp\DMSKSSRh.sys --> c:\docume~1\SPIDER~1\LOCALS~1\Temp\DMSKSSRh.sys [?]
S3 SaiNtSub;SaiNtSub;c:\windows\SYSTEM32\DRIVERS\SaiNtSub.sys [2/4/2005 10:28 PM 19200]
S3 samhid;samhid;c:\windows\system32\drivers\samhid.sys --> c:\windows\system32\drivers\samhid.sys [?]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.98rock.com/cc-common/babes/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: &Search
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {D9EA64B2-B966-E177-332C-78B69886526D} - hxxp://download.newaol.com/bkpromo/download/PerformerSetup.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-08 17:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1665667976-894762885-3311537992-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2009-10-08 17:37
ComboFix-quarantined-files.txt 2009-10-08 21:36
ComboFix2.txt 2009-10-04 16:54
ComboFix3.txt 2009-10-04 14:17
ComboFix4.txt 2007-11-30 03:16
Pre-Run: 4,294,623,232 bytes free
Post-Run: 4,333,191,168 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
227 --- E O F --- 2009-08-27 21:59
Upload was successful