ComboFix 08-05-27.4 - User 2008-05-28 20:33:25.5 - NTFSx86
Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\User\Desktop\cfscript.txt
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\exixvbuo.dll
C:\WINDOWS\system32\hdghdjho.dll
C:\WINDOWS\system32\iquahsob.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\exixvbuo.dll
C:\WINDOWS\system32\hdghdjho.dll
C:\WINDOWS\system32\iquahsob.dll
.
---- Previous Run -------
.
C:\WINDOWS\BM57284976.xml
C:\WINDOWS\Config\csrss.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\alwlhqaq.ini
C:\WINDOWS\system32\berfrajt.dll
C:\WINDOWS\system32\dqbklpxg.exe
C:\WINDOWS\system32\hgGwtsTJ.dll
C:\WINDOWS\system32\iosklmrb.dll
C:\WINDOWS\system32\kuldmtan.dll
C:\WINDOWS\system32\maheneyp.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\natmdluk.ini
C:\WINDOWS\system32\pqehvjwe.dll
C:\WINDOWS\system32\qaqhlwla.dll
C:\WINDOWS\system32\rjgfyifb.dll
C:\WINDOWS\system32\rvoipbxf.ini
C:\WINDOWS\system32\stjnarvj.exe
C:\WINDOWS\system32\tqfkadmf.exe
C:\WINDOWS\system32\tuDNTBeg.ini
C:\WINDOWS\system32\tuDNTBeg.ini2
C:\WINDOWS\system32\vekwasyi.ini
C:\WINDOWS\system32\vfkxpxbm.dll
C:\WINDOWS\system32\wjxyjvrh.dll
C:\WINDOWS\system32\xhfwfcqv.exe
C:\WINDOWS\system32\xlnpdiij.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-28 )))))))))))))))))))))))))))))))
.
2008-05-28 20:24 . 2008-05-28 20:24 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-28 19:47 . 2008-05-28 19:47 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-27 19:23 . 2008-05-27 19:23 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-05-27 19:10 . 2008-05-27 19:10 <DIR> d-------- C:\Program Files\BillP Studios
2008-05-27 19:10 . 2008-05-27 19:10 <DIR> d-------- C:\Documents and Settings\User\Application Data\WinPatrol
2008-05-27 19:06 . 2008-05-28 20:31 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-27 19:06 . 2008-05-28 20:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-27 18:55 . 2008-05-28 19:49 <DIR> d-------- C:\Program Files\Yahoo!
2008-05-27 09:36 . 2008-05-27 10:12 <DIR> d-------- C:\Documents and Settings\User\Application Data\GetRightToGo
2008-05-26 10:21 . 2008-05-04 21:33 1,663 --a------ C:\Vegas Pro 8.0.lnk
2008-05-24 11:31 . 2008-05-24 11:31 <DIR> d-------- C:\Documents and Settings\User\Application Data\Subversion
2008-05-24 10:34 . 2008-05-24 10:34 32 --a------ C:\WINDOWS\go
2008-05-24 10:30 . 2008-05-24 10:39 <DIR> d-------- C:\Program Files\DNA
2008-05-24 09:40 . 2007-07-11 11:11 888,832 --a------ C:\WINDOWS\system32\securenet.dll
2008-05-24 09:30 . 2008-05-24 23:18 110 --a------ C:\WINDOWS\GMouse.ini
2008-05-24 09:23 . 2008-05-24 09:23 <DIR> d-------- C:\Documents and Settings\User\WINDOWS
2008-05-24 09:23 . 1996-01-09 10:38 283,648 --a------ C:\WINDOWS\uninst.exe
2008-05-10 11:54 . 2008-05-10 11:54 <DIR> d-------- C:\Program Files\TechSmith
2008-05-10 11:54 . 2008-05-10 11:54 <DIR> d-------- C:\Program Files\Common Files\TechSmith Shared
2008-05-10 10:59 . 2008-05-10 11:10 <DIR> d-------- C:\WINDOWS\.mpr_file_store_32
2008-05-05 22:03 . 2008-05-05 22:03 <DIR> d-------- C:\Program Files\Viewpoint
2008-05-05 22:03 . 2008-05-05 22:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-05 22:03 . 2008-05-05 22:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-05-05 22:03 . 2008-05-05 22:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-05-05 22:02 . 2008-05-08 17:01 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-05-05 22:02 . 2008-05-05 22:03 364 --ah----- C:\IPH.PH
2008-05-03 09:09 . 2008-05-03 09:09 124,688 --a------ C:\WINDOWS\system32\MSWINSCK.OCX
2008-05-02 16:32 . 2008-05-02 16:32 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-05-02 16:32 . 2002-12-17 16:23 33,340 --a------ C:\WINDOWS\system32\dbmsqlgc.dll
2008-05-02 16:32 . 2002-10-20 14:05 24,576 --a------ C:\WINDOWS\system32\dbmsgnet.dll
2008-05-02 16:29 . 2008-05-02 16:29 <DIR> d-------- C:\Program Files\Vstplugins
2008-05-02 16:29 . 2008-05-07 19:23 <DIR> d-------- C:\Program Files\Sony
2008-05-02 16:29 . 2008-05-07 19:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sony
2008-05-02 16:28 . 2008-05-04 21:31 <DIR> d-------- C:\Program Files\Sony Setup
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-28 09:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-27 22:02 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-22 19:51 --------- d-----w C:\Documents and Settings\User\Application Data\LimeWire
2008-05-15 18:45 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-14 20:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-05-10 15:12 2,256 ----a-w C:\WINDOWS\current_settings.bin
2008-05-08 15:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-02 15:46 --------- d-----w C:\Documents and Settings\User\Application Data\Sony
2008-04-24 17:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2008-04-15 16:08 --------- d-----w C:\Documents and Settings\User\Application Data\Uniblue
2008-04-12 08:03 --------- d-----w C:\Documents and Settings\User\Application Data\Roxio
2008-04-11 20:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
2008-04-11 19:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Pinnacle
2008-04-11 19:47 --------- d-----w C:\Program Files\Pinnacle
2008-04-11 19:46 --------- d-----w C:\Program Files\SmartSound Software
2008-04-11 19:46 --------- d-----w C:\Program Files\QuickTime
2008-04-11 19:45 --------- d-----w C:\Program Files\DivX
2008-03-28 11:11 --------- d-----w C:\Program Files\Java
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-12 19:27 50,520 ----a-w C:\WINDOWS\system32\csvidcap.dll
2008-03-05 15:03 479,752 ----a-w C:\WINDOWS\system32\XAudio2_0.dll
2008-03-05 15:03 238,088 ----a-w C:\WINDOWS\system32\xactengine3_0.dll
2008-03-05 15:00 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_3.dll
2008-03-05 14:56 3,786,760 ----a-w C:\WINDOWS\system32\D3DX9_37.dll
2008-03-05 14:56 1,420,824 ----a-w C:\WINDOWS\system32\D3DCompiler_37.dll
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
"McAfee QuickClean Imonitor"="C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe" [2003-12-08 05:01 81920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-29 18:26 68856]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 13:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 13:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 13:00 455168]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-05-23 22:05 344064]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 19:18 151552]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 13:49 163840]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 19:29 303104]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 13:05 212992]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [2003-12-22 17:51 98304]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2004-11-02 15:51 1063424]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-08-10 13:10 221184]
"DMXLauncher"="C:\Program Files\Roxio\Media Experience\DMXLauncher.exe" [2006-08-14 02:07 102400]
"RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-07-31 10:00 1116920]
"MimBoot"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mimboot.exe" [2004-12-10 20:44 11776]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2004-03-24 16:56 1380352]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 23:02 53248]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2004-03-11 00:26 406016]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-04-11 20:46 98304]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 15:30 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 15:30 81920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= Pvmjpg30.dll
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"C:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"C:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"=
R0 SI3112r;ATI-4379 Serial ATA Controller;C:\WINDOWS\system32\DRIVERS\SI3112r.sys [2007-08-29 04:04]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-01 21:06]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 22:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{758ef2c2-b754-11db-9ff0-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-28 20:35:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-28 20:36:57
ComboFix-quarantined-files.txt 2008-05-28 19:36:47
Pre-Run: 14,557,028,352 bytes free
Post-Run: 14,550,609,920 bytes free
190 --- E O F --- 2008-05-27 22:17:07