ComboFix (Sorry i had to double post said all of it was too long)
"Billy" - 2007-07-29 19:37:28 [GMT -5:00] - ComboFix 07-07-24 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Billy\Desktop.\internet explorer.lnk
C:\WINDOWS\system32\lpbwxtms.exe
C:\WINDOWS\system32\rjkmcvab.exe
C:\WINDOWS\system32\ukvvukfa.exe
((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-30 )))))))))))))))))))))))))))))))
2007-07-29 19:37 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-29 18:14 <DIR> d-------- C:\VundoFix Backups
2007-07-29 07:25 <DIR> d-------- C:\HJT
2007-07-28 10:17 69,184 --a------ C:\WINDOWS\system32\uuuydcnr.dll
2007-07-23 15:17 <DIR> d-------- C:\MBSTRUTH
2007-07-22 21:18 <DIR> d-------- C:\DOCUME~1\Billy\APPLIC~1\SmartFTP
2007-07-22 21:15 <DIR> d-------- C:\Program Files\SmartFTP Client
2007-07-22 19:36 <DIR> d-------- C:\Program Files\PSPad editor
2007-07-22 19:36 <DIR> d-------- C:\DOCUME~1\Billy\APPLIC~1\PSpad
2007-07-22 19:09 5,248 --a------ C:\WINDOWS\system32\drivers\Vax347s.sys
2007-07-22 19:09 159,616 --a------ C:\WINDOWS\system32\drivers\Vax347b.sys
2007-07-19 23:37 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\pixelStorm
2007-07-09 17:21 <DIR> d-------- C:\Program Files\World of Warcraft
2007-07-06 18:14 <DIR> d-------- C:\DOCUME~1\Billy\APPLIC~1\acccore
2007-07-06 18:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-07-06 18:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
2007-07-06 18:11 <DIR> d-------- C:\Program Files\Viewpoint
2007-07-06 18:11 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
2007-07-06 18:10 <DIR> d-------- C:\Program Files\Common Files\AOL
2007-07-06 18:10 <DIR> d-------- C:\Program Files\AIM6
2007-07-06 18:07 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
2007-07-06 10:19 <DIR> d-------- C:\Program Files\HLSW
2007-06-30 23:26 520,192 --------- C:\WINDOWS\system32\ati2sgag.exe
2007-06-30 23:19 <DIR> d-------- C:\NV22002204.TMP
2007-06-30 23:18 <DIR> d-------- C:\NV36003604.TMP
2007-06-30 23:18 <DIR> d-------- C:\NV35923596.TMP
2007-06-30 23:17 <DIR> d-------- C:\NVIDIA
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-29 23:41:58 -------- d-----w C:\DOCUME~1\Billy\APPLIC~1\Xfire
2007-07-28 23:10:50 -------- d-----w C:\DOCUME~1\Billy\APPLIC~1\uTorrent
2007-07-28 04:15:04 -------- d-s---w C:\Program Files\Xfire
2007-07-27 09:30:34 -------- d-----w C:\Program Files\Zoom Player
2007-07-17 04:05:40 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-07-09 22:30:19 -------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2007-07-09 21:15:29 -------- d-----w C:\Program Files\Warcraft III
2007-07-06 23:10:24 335 ----a-w C:\WINDOWS\nsreg.dat
2007-07-01 04:27:13 -------- d-----w C:\Program Files\ATI Technologies
2007-07-01 04:26:42 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-07-01 03:16:39 -------- d-----w C:\Program Files\SHOUTcast Source
2007-06-26 04:18:52 -------- d-----w C:\Program Files\Diablo II
2007-06-23 11:18:21 -------- d-----w C:\Program Files\GSP
2007-06-21 02:39:30 -------- d-----w C:\Program Files\Realtek AC97
2007-06-21 02:29:08 -------- d-----w C:\Program Files\Setup Files
2007-06-16 00:58:56 75,892 ----a-w C:\WINDOWS\War3Unin.dat
2007-06-16 00:22:18 2,829 ----a-w C:\WINDOWS\War3Unin.pif
2007-06-16 00:22:18 139,264 ----a-w C:\WINDOWS\War3Unin.exe
2007-06-15 10:59:53 -------- d--h--r C:\DOCUME~1\Billy\APPLIC~1\yahoo!
2007-06-15 10:59:04 -------- d-----w C:\Program Files\Yahoo!
2007-06-15 02:55:38 -------- d-----w C:\Program Files\Kaos Software
2007-06-14 22:55:45 -------- d-----w C:\DOCUME~1\Billy\APPLIC~1\Motive
2007-06-14 22:49:59 -------- d-----w C:\Program Files\SBC Self Support Tool
2007-06-14 22:48:26 -------- d-----w C:\Program Files\Common Files\Motive
2007-06-14 08:59:54 -------- d-----w C:\Program Files\LiveUpdate
2007-06-14 07:11:47 -------- d-----w C:\Program Files\MSI
2007-06-13 19:50:17 43,152 ----a-w C:\WINDOWS\system32\drivers\ativvpxx.vp
2007-06-13 19:25:36 339,968 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-06-13 19:24:32 268,288 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2007-06-13 19:24:13 2,155,520 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-06-13 19:23:23 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2007-06-13 19:17:37 139,264 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2007-06-13 19:17:26 118,784 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2007-06-13 19:17:18 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-06-13 19:17:12 42,496 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2007-06-13 19:16:59 118,784 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2007-06-13 19:15:39 483,328 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2007-06-13 19:14:51 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-06-13 19:10:33 8,097,792 ----a-w C:\WINDOWS\system32\atioglx2.dll
2007-06-13 19:07:26 2,922,208 ----a-w C:\WINDOWS\system32\ati3duag.dll
2007-06-13 18:57:21 1,512,960 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2007-06-13 18:57:04 972,072 ----a-w C:\WINDOWS\system32\ativva6x.dat
2007-06-13 18:57:04 3,107,788 ----a-w C:\WINDOWS\system32\ativvaxx.dat
2007-06-13 18:57:04 3,107,788 ----a-w C:\WINDOWS\system32\ativva5x.dat
2007-06-13 18:46:28 5,431,296 ----a-w C:\WINDOWS\system32\atioglxx.dll
2007-06-13 18:43:53 262,144 ----a-w C:\WINDOWS\system32\atikvmag.dll
2007-06-13 18:42:29 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2007-06-13 18:41:46 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2007-06-13 18:41:06 50,176 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2007-06-13 18:36:45 368,640 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2007-06-11 19:23:05 -------- d-----w C:\DOCUME~1\Billy\APPLIC~1\dvdcss
2007-06-05 15:07:53 -------- d-----w C:\DOCUME~1\Billy\APPLIC~1\fltk.org
2007-06-05 13:23:34 -------- d-----w C:\DOCUME~1\Billy\APPLIC~1\IMVU
2007-06-01 00:30:22 266,088 ----a-w C:\WINDOWS\system32\xactengine2_8.dll
2007-06-01 00:29:42 18,280 ----a-w C:\WINDOWS\system32\x3daudio1_2.dll
2007-05-16 21:45:16 443,752 ----a-w C:\WINDOWS\system32\d3dx10_34.dll
2007-05-16 21:45:16 3,497,832 ----a-w C:\WINDOWS\system32\d3dx9_34.dll
2007-05-16 21:45:16 1,124,720 ----a-w C:\WINDOWS\system32\D3DCompiler_34.dll
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5A4A2D56-931A-4733-9121-033A2D95A274}]
C:\WINDOWS\system32\efcdede.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D9F712E-1816-4E28-8555-EA318D1542BD}]
C:\WINDOWS\system32\ssqpm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{957EF3ED-C97C-4CEE-BA36-276B0848248A}]
C:\WINDOWS\system32\gebyv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6039E6C-BDE9-4de5-BB40-768CAA584FDC}]
2007-07-28 10:17 69184 --a------ C:\WINDOWS\system32\uuuydcnr.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FLMMEMOREX203"="C:\Program Files\Browser Mouse\2.03\mouse32a.exe" [2007-03-06 23:25]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 18:18]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 12:49]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 22:02]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 12:05]
"PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2006-11-06 07:35]
"Motive SmartBridge"="C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 07:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"SMSERIAL"="sm56hlpr.exe" [2004-12-28 17:01 C:\WINDOWS\sm56hlpr.exe]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-09 21:45]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"Aim6"="" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AT&T Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2007-06-14 17:47:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"ZboardTray"="C:\Program Files\Ideazon\Zboard Software\Driver\ZboardTray.exe" /autolaunch
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5A4A2D56-931A-4733-9121-033A2D95A274}"= C:\WINDOWS\system32\efcdede.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Zboard]
Winlognotif.dll 2003-09-03 07:14 49152 C:\WINDOWS\system32\Winlognotif.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ATI CATALYST System Tray.lnk
backup=C:\WINDOWS\pss\ATI CATALYST System Tray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Billy^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Billy\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxtorOneTouch]
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
"C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioAudioCentral]
"C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
"C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
"C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareBot]
C:\Program Files\SpywareBot\SpywareBot.exe -boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Ati HotKey Poller"=2 (0x2)
R0 Vax347b;Vax347b;C:\WINDOWS\system32\DRIVERS\Vax347b.sys
R0 Vax347s;Vax347s;C:\WINDOWS\system32\Drivers\Vax347s.sys
R1 AmdK8;AMD Athlon64 Processor Driver;C:\WINDOWS\system32\DRIVERS\AmdK8.sys
R1 Cdr4_xp;Cdr4_xp;C:\WINDOWS\system32\drivers\Cdr4_xp.sys
R1 Cdralw2k;Cdralw2k;C:\WINDOWS\system32\drivers\Cdralw2k.sys
R1 cdudf_xp;cdudf_xp;C:\WINDOWS\system32\drivers\cdudf_xp.sys
R1 DVDVRRdr_xp;DVDVRRdr_xp;C:\WINDOWS\system32\drivers\DVDVRRdr_xp.sys
R1 mnmdd;mnmdd;C:\WINDOWS\system32\drivers\mnmdd.sys
R1 pwd_2k;pwd_2k;C:\WINDOWS\system32\drivers\pwd_2k.sys
R1 UdfReadr_xp;UdfReadr_xp;C:\WINDOWS\system32\drivers\UdfReadr_xp.sys
R2 Fax;Fax;C:\WINDOWS\system32\fxssvc.exe
R2 Hardlock;Hardlock;\??\C:\WINDOWS\system32\drivers\hardlock.sys
R2 Haspnt;Haspnt;\??\C:\WINDOWS\system32\drivers\Haspnt.sys
R2 lanmanserver;Server;C:\WINDOWS\system32\svchost.exe -k netsvcs
R2 lanmanworkstation;Workstation;C:\WINDOWS\system32\svchost.exe -k netsvcs
R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\pstrip.sys
R2 Sentinel;Sentinel;C:\WINDOWS\system32\Drivers\SENTINEL.SYS
R2 winmgmt;Windows Management Instrumentation;C:\WINDOWS\system32\svchost.exe -k netsvcs
R3 dvd_2K;dvd_2K;C:\WINDOWS\system32\drivers\dvd_2K.sys
R3 hidusb;Microsoft HID Class Driver;C:\WINDOWS\system32\DRIVERS\hidusb.sys
R3 OmniUsb;Ideazon USB Zboard Driver;C:\WINDOWS\system32\DRIVERS\OmniUsb.sys
R3 OmniUsbl;Ideazon USBl Zboard Driver;C:\WINDOWS\system32\DRIVERS\OmniUsbl.sys
R3 smserial;smserial;C:\WINDOWS\system32\DRIVERS\smserial.sys
R3 usbccgp;Microsoft USB Generic Parent Driver;C:\WINDOWS\system32\DRIVERS\usbccgp.sys
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver;C:\WINDOWS\system32\DRIVERS\usbehci.sys
R3 usbhub;USB2 Enabled Hub;C:\WINDOWS\system32\DRIVERS\usbhub.sys
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver;C:\WINDOWS\system32\DRIVERS\usbohci.sys
R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys
R3 wdmaud;Microsoft WINMM WDM Audio Compatibility Driver;C:\WINDOWS\system32\drivers\wdmaud.sys
S2 DS1410D;DS1410D;\??\C:\WINDOWS\system32\drivers\ds1410d.sys
S3 GMSIPCI;GMSIPCI;\??\E:\INSTALL\GMSIPCI.SYS
S3 mmc_2K;mmc_2K;C:\WINDOWS\system32\drivers\mmc_2K.sys
S3 mnmsrvc;NetMeeting Remote Desktop Sharing;C:\WINDOWS\system32\mnmsrvc.exe
S3 MSICPL;MSICPL;\??\E:\install4\MSICPL.sys
S3 MXOPSWD;Maxtor OneTouch Security Driver;C:\WINDOWS\system32\DRIVERS\mxopswd.sys
S3 nm;Network Monitor Driver;C:\WINDOWS\system32\DRIVERS\NMnt.sys
S3 NTACCESS;NTACCESS;\??\E:\NTACCESS.sys
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\PCAMPR5.SYS
S3 ROOTMODEM;Microsoft Legacy Modem Driver;C:\WINDOWS\system32\Drivers\RootMdm.sys
S3 SetupNTGLM7X;SetupNTGLM7X;\??\E:\NTGLM7X.sys
S3 Sntnlusb;Rainbow USB SuperPro;C:\WINDOWS\system32\DRIVERS\SNTNLUSB.SYS
S3 USBSTOR;USB Mass Storage Driver;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
S3 vaxscsi;vaxscsi;C:\WINDOWS\system32\Drivers\vaxscsi.sys
Contents of the 'Scheduled Tasks' folder
2007-07-29 08:00:01 C:\WINDOWS\tasks\SpywareBot Scheduled Scan.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-29 19:42:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\\24\xd2\21]
"DisplayName"="\xdbf4\21"
"DeviceDesc"="\xdbf4\21"
"ProviderName"="\xee54\21\xee18\x7c90\xeec4\21\b"
"MFG"="\x63c0\34\t"
"ReinstallString"="8.380.0.0000"
"DeviceInstanceIds"=str(7):"c:\ati\support\7-5_xp_dd_46743\driver\xp_inf\cx_46743.inf"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}]
"DisplayName"="Alcohol 120"
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-29 19:50:39
C:\ComboFix-quarantined-files.txt ... 2007-07-29 19:50
--- E O F ---