Yep, c:\scurvy is normal.
Tried scanning those two files with virustotal, but it errored and said they were too big. Both files are about 22megs each.
Did CFScript and it sped through it fairly quickly as before. Since you mention a reboot if it finds malware, it didn't want a reboot on this scan or on the earlier one. I just rebooted after the first scan because it seemed like a decent idea.
Ran ATF and cleaned everything up.
Took a whopping 5 hours for Kaspersky to scan, and it claims to have found a bunch of infections. It looks as though it mostly founds things Housecall found ages ago (Which even then I was dubious on a lot of them but had it clean them anyway). The "Kazaa lite" installer is really ancient and I didn't even know it was still on here, so I'll sure as hell delete that, virus or no. It didn't like VNC being on here, but at least it mentions it not being a virus. Rainbow Six seems odd for it to complain about, but I guess I could toast it. Then the next to last two I have no idea on. It looks like Kaspersky doesn't delete the files itself and doesn't seem to give me the option, so I'll hold off on deleting anything until you mention it. Otherwise I'll delete the old Kazaa installer, Rainbow Six, and the next to last two files it listed.
And though I'm listing the logs in the order of Kaspersky, DDS, Combofix, I actually ran them in the order of Combofix, Kaspersky, DDS.
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Wednesday, June 3, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, June 03, 2009 23:56:13
Records in database: 2303792
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan statistics:
Files scanned: 436165
Threat name: 7
Infected objects: 44
Suspicious objects: 0
Duration of the scan: 05:15:52
File name / Threat name / Threats count
C:\Documents and Settings\Administrator\Desktop\Misc\kazaa_lite_202_english_(kpp_203_edition).exe Infected: Trojan-Downloader.Win32.VB.kxl 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\12202.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\12202.temp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\17292.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\17292.temp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\25029.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\25029.temp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\33446.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\33446.temp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\39491.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\39491.temp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\43212.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\43212.temp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\45104.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\45104.temp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\49148.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\49148.temp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\65145.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\65145.temp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\65588.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\65588.temp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\73364.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\73364.temp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\98404.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\98404.temp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\engine.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\lua.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\lua.exe.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\lua_c.exe.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\lua_interpreter.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\lw_2.lua.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\lw_2.lua.ztmp.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\lw_2.lua.ztmp.bac_a03132 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\render.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\s9.dll.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\target.exe.bac_a01824 Infected: Virus.Lua.LuaDef.b 1
C:\Documents and Settings\SqueeXP\.housecall6.6\Quarantine\Uninstall.exe.bac_a03916 Infected: Backdoor.Win32.Small.hob 1
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
C:\Program Files\RealVNC\WinVNC\othread2.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c 1
C:\Program Files\RealVNC\WinVNC\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c 1
C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe Infected: Trojan-Dropper.Win32.Agent.acvm 1
C:\System Volume Information\_restore{58CD5132-DE8F-4FB9-8FA0-6C1FD0E17579}\RP416\A0075941.exe Infected: Backdoor.Win32.Small.hob 1
C:\System Volume Information\_restore{58CD5132-DE8F-4FB9-8FA0-6C1FD0E17579}\RP416\A0076863.exe Infected: Trojan-Dropper.Win32.Agent.acvm 1
C:\System Volume Information\_restore{58CD5132-DE8F-4FB9-8FA0-6C1FD0E17579}\RP416\A0076864.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 1
The selected area was scanned.
DDS (Ver_09-05-14.01) - NTFSx86
Run by SqueeXP at 22:39:37.20 on Wed 06/03/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1376 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Razer\Reclusa\razerhid.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Razer\Reclusa\razertra.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ALCFDRTM.EXE
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\SqueeXP\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: : {fffffef0-5b30-21d4-945d-000000000000} - c:\progra~1\stardo~1\SDIEInt.dll
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTProAgent.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [EVGAPrecision] "c:\program files\evga precision\EVGAPrecision.exe" /s
mRun: [Reclusa] c:\program files\razer\reclusa\razerhid.exe
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: alluring-illusions.com
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228469806921
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {99FE5072-78AA-4FEE-89BA-69A5FA55343F} - hxxp://download.microsoft.com/download/B/3/A/B3A2EA73-793D-4ABE-992D-C81140384044/igdtoolx.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} - hxxp://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\squeexp\applic~1\mozilla\firefox\profiles\yvm5gah6.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\all users.windows\application data\id software\quakelive\npquakezero.dll
FF - plugin: c:\documents and settings\squeexp\application data\mozilla\firefox\profiles\yvm5gah6.default\extensions\battlefieldheroespatcher@ea.com\platform\winnt_x86-msvc\plugins\npBFHUpdater.dll
============= SERVICES / DRIVERS ===============
R0 uliagpkx;ULi AGP Bus Filter Driver;c:\windows\system32\drivers\AGPKX.SYS [2006-9-30 45056]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-17 325896]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-6-17 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-6-17 108552]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2008-6-14 13696]
R1 BS_I2cIo;BS_I2cIo;c:\windows\system32\drivers\BS_I2cIo.sys [2008-6-14 8192]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-3 298776]
R3 RecFltr;Reclusa Keyboard;c:\windows\system32\drivers\RecFltr.sys [2008-12-25 41984]
S1 atitray;atitray;\??\c:\program files\radeon omega drivers\v3.8.421\ati tray tools\atitray.sys --> c:\program files\radeon omega drivers\v3.8.421\ati tray tools\atitray.sys [?]
S3 efipsk;efipsk;\??\c:\docume~1\squeexp\locals~1\temp\efipsk.sys --> c:\docume~1\squeexp\locals~1\temp\efipsk.sys [?]
S3 hipeer81;Remobo Virtual Interface;c:\windows\system32\drivers\hipeer81.sys [2006-12-6 54528]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-2 32512]
S3 ULI5261XP;ULi M526X Ethernet NT Driver;c:\windows\system32\drivers\ULILAN51.SYS [2006-9-29 28672]
=============== Created Last 30 ================
2009-06-03 16:22 161,792 a------- c:\windows\SWREG.exe
2009-06-03 16:22 154,624 a------- c:\windows\PEV.exe
2009-06-03 16:22 98,816 a------- c:\windows\sed.exe
2009-06-03 16:22 <DIR> --ds---- C:\ComboFix
2009-06-02 19:45 <DIR> a-dshr-- C:\cmdcons
2009-05-31 04:35 73,728 a------- c:\windows\system32\javacpl.cpl
2009-05-31 00:36 <DIR> --d----- c:\program files\Old Games
2009-05-28 21:03 <DIR> --d----- c:\program files\Trend Micro
2009-05-28 04:57 <DIR> --dsh--- c:\documents and settings\squeexp\PrivacIE
2009-05-28 04:56 <DIR> --dsh--- c:\documents and settings\squeexp\IETldCache
2009-05-28 03:58 <DIR> --d----- c:\windows\ie8updates
2009-05-28 03:57 102,912 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-05-28 03:55 78,336 a------- c:\windows\system32\ieencode.dll
2009-05-28 03:55 78,336 a------- c:\windows\system32\dllcache\ieencode.dll
2009-05-19 20:39 <DIR> --d----- c:\program files\Microsoft WSE
2009-05-15 01:48 54,156 a---h--- c:\windows\QTFont.qfn
2009-05-15 01:48 1,409 a------- c:\windows\QTFont.for
2009-05-05 01:23 25 a------- c:\windows\popcinfot.dat
2009-05-05 01:14 <DIR> --d----- C:\scurvy
==================== Find3M ====================
2009-05-31 04:34 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-04 04:50 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-05-04 04:50 325,896 a------- c:\windows\system32\drivers\avgldx86.sys
2009-05-04 04:50 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-04-22 00:20 14,311,680 a------- c:\windows\system32\xlive.dll
2009-04-22 00:20 13,642,496 a------- c:\windows\system32\xlivefnt.dll
2009-04-20 00:47 22,502,160 a------- c:\windows\system32\xa44654109.exe
2009-04-20 00:47 22,502,160 a------- c:\windows\system32\xa44652390.exe
2009-04-14 16:15 22,328 a------- c:\windows\system32\drivers\PnkBstrK.sys
2009-04-14 16:15 22,328 a------- c:\docume~1\squeexp\applic~1\PnkBstrK.sys
2009-04-14 16:15 107,832 a------- c:\windows\system32\PnkBstrB.exe
2009-04-14 16:15 2,337,865 a------- c:\windows\system32\pbsvc.exe
2009-03-09 16:55 413,696 a------- c:\windows\system32\wrap_oal.dll
2009-03-09 16:55 110,592 a------- c:\windows\system32\OpenAL32.dll
2009-03-06 09:22 284,160 a------- c:\windows\system32\pdh.dll
2008-01-29 18:11 32 a------- c:\docume~1\alluse~1.win\applic~1\ezsid.dat
2003-12-18 11:33 20,102 a------- c:\program files\Readme.txt
2003-09-03 07:46 10,960 a------- c:\program files\EULA.txt
2002-12-05 22:03 21,952 a---h--- c:\program files\folder.htt
2002-12-05 22:03 271 ---sh--- c:\program files\desktop.ini
============= FINISH: 22:40:05.29 ===============
ComboFix 09-06-03.01 - SqueeXP 06/03/2009 16:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1497 [GMT -5:00]
Running from: c:\documents and settings\SqueeXP\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\SqueeXP\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-05-03 to 2009-06-03 )))))))))))))))))))))))))))))))
.
2009-05-31 05:36 . 2009-05-31 05:36 -------- d-----w- c:\program files\Old Games
2009-05-29 02:03 . 2009-05-29 02:03 -------- d-----w- c:\program files\Trend Micro
2009-05-28 09:57 . 2009-05-28 09:57 -------- d-sh--w- c:\documents and settings\SqueeXP\PrivacIE
2009-05-28 09:56 . 2009-05-28 09:56 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-05-28 09:56 . 2009-05-28 09:56 -------- d-sh--w- c:\documents and settings\SqueeXP\IETldCache
2009-05-28 08:58 . 2009-05-31 09:06 -------- d-----w- c:\windows\ie8updates
2009-05-28 08:57 . 2009-05-12 05:11 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-05-28 08:55 . 2009-02-20 18:09 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-05-28 08:55 . 2009-02-20 18:09 78336 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2009-05-20 01:39 . 2009-05-20 01:39 10134 ----a-r- c:\documents and settings\SqueeXP\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-05-20 01:39 . 2009-05-20 01:39 -------- d-----w- c:\program files\Microsoft WSE
2009-05-05 06:23 . 2009-06-03 09:05 25 ----a-w- c:\windows\popcinfot.dat
2009-05-05 06:14 . 2009-05-27 05:30 -------- d-----w- C:\scurvy
2009-05-05 03:01 . 2009-05-05 03:01 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PopCap Games
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 06:58 . 2008-08-06 04:59 -------- d-----w- c:\documents and settings\SqueeXP\Application Data\FileZilla
2009-05-31 09:34 . 2008-11-22 23:52 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-31 09:34 . 2009-04-01 01:56 152576 ----a-w- c:\documents and settings\SqueeXP\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-30 23:37 . 2006-08-04 23:33 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-30 23:35 . 2006-10-23 01:48 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-05-30 22:57 . 2006-08-04 23:34 -------- d-----w- c:\program files\Java
2009-05-30 08:55 . 2008-08-24 20:39 -------- d-----w- c:\documents and settings\SqueeXP\Application Data\mIRC
2009-05-28 21:22 . 2006-08-04 23:33 -------- d-----w- c:\program files\Trillian
2009-05-20 01:35 . 2006-08-04 23:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-07 18:35 . 2007-05-13 08:36 32 ----a-w- c:\windows\popcinfo.dat
2009-05-05 03:01 . 2006-08-04 23:36 -------- d-----w- c:\program files\PopCap Games
2009-05-05 01:49 . 2007-05-25 19:23 -------- d-----w- c:\documents and settings\SqueeXP\Application Data\GetRightToGo
2009-05-04 09:50 . 2008-06-18 02:20 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-04 09:50 . 2008-06-18 02:20 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-04 09:50 . 2008-06-18 02:20 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-04 09:50 . 2008-06-18 02:20 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-03 05:11 . 2009-05-03 05:11 -------- d-----w- c:\program files\Western Digital
2009-05-02 07:54 . 2009-05-02 07:52 -------- d-----w- c:\program files\Age of Wonders Shadow Magic
2009-05-01 00:04 . 2007-11-22 00:48 -------- d-----w- c:\documents and settings\SqueeXP\Application Data\Hamachi
2009-04-29 10:05 . 2009-03-24 22:24 71120 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-22 05:20 . 2009-04-22 05:20 14311680 ----a-w- c:\windows\system32\xlive.dll
2009-04-22 05:20 . 2009-04-22 05:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll
2009-04-20 05:47 . 2009-04-20 05:47 22502160 ----a-w- c:\windows\system32\xa44654109.exe
2009-04-20 05:47 . 2009-04-20 05:47 22502160 ----a-w- c:\windows\system32\xa44652390.exe
2009-04-14 21:15 . 2009-04-14 21:15 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Ubisoft
2009-04-14 21:15 . 2008-04-02 18:15 22328 ----a-w- c:\documents and settings\SqueeXP\Application Data\PnkBstrK.sys
2009-04-14 21:15 . 2008-04-02 18:15 22328 ----a-w- c:\documents and settings\SqueeXP\Application Data\PnkBstrK.sys
2009-04-14 21:15 . 2007-04-14 02:18 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-04-14 21:15 . 2007-04-13 04:36 107832 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-04-14 21:15 . 2008-10-08 22:33 2337865 ----a-w- c:\windows\system32\pbsvc.exe
2009-04-14 20:45 . 2006-08-04 23:33 -------- d-----w- c:\program files\Ubisoft
2009-04-11 03:08 . 2008-10-27 20:26 -------- d-----w- c:\program files\Sierra Entertainment
2009-04-10 06:35 . 2007-12-02 06:00 -------- d-----w- c:\program files\Microsoft Games
2009-03-09 21:55 . 2007-05-22 04:48 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-03-09 21:55 . 2006-10-05 01:42 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-03-06 14:22 . 2004-08-04 12:00 284160 ----a-w- c:\windows\system32\pdh.dll
2003-12-18 16:33 . 2004-04-14 22:31 20102 ----a-w- c:\program files\Readme.txt
2003-09-03 12:46 . 2004-04-14 22:31 10960 ----a-w- c:\program files\EULA.txt
2002-12-06 03:03 . 2002-12-06 03:03 21952 ---ha-w- c:\program files\folder.htt
.
((((((((((((((((((((((((((((( SnapShot@2009-06-03_00.52.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-03 20:41 . 2009-06-03 20:41 16384 c:\windows\Temp\Perflib_Perfdata_168.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-22 149040]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-04 1947928]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-16 153136]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13680640]
"EVGAPrecision"="c:\program files\EVGA Precision\EVGAPrecision.exe" [2008-10-27 240656]
"Reclusa"="c:\program files\Razer\Reclusa\razerhid.exe" [2007-06-18 167936]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-31 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-10-16 16855552]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-09 1657376]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2005-11-7 225280]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-04 09:50 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WinVNC4"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"d:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"d:\\Program Files\\Sierra\\SWAT 4\\ContentExpansion\\System\\Swat4X.exe"=
"d:\\Program Files\\Sierra\\SWAT 4\\ContentExpansion\\System\\Swat4XDedicatedServer.exe"=
"d:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"d:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Microsoft Games\\Dungeon Siege 2\\DungeonSiege2.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\trackmania nations forever\\TmForever.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\trackmania nations forever\\TmForeverLauncher.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\squeemk2\\codename gordon\\cg.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\peggle deluxe\\Peggle.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\peggle extreme\\PeggleExtreme.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\titan quest\\help.htm"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\titan quest immortal throne\\Tqit.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\titan quest immortal throne\\help.htm"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\trials 2 second edition\\launcher.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\mount and blade\\runme.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\world of goo\\WorldOfGoo.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\peggle nights\\PeggleNights.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\defensegridtheawakening\\DefenseGrid.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\oddworld abes oddysee\\AbeWin.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\oddworld abes exoddus\\Exoddus.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\ghost master\\ghost.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sacred gold\\Sacred.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\jagged alliance 2 gold\\ja2.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\jagged alliance 2 gold unfinished business\\JA2UB.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\RelicDownloader\\RelicDownloader.exe"=
"d:\\Program Files\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\xrEngine.exe"=
"d:\\Program Files\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\dedicated\\xrEngine.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\alien shooter vengeance\\AlienShooter.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\unreal tournament 3\\Binaries\\UT3.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sam and max episode 4\\sammax104_drm.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sam and max episode 1\\sammax101.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sam and max episode 2\\sammax102.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sam and max episode 6\\sammax106_drm.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sam and max episode 5\\sammax105_drm.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sam and max episode 3\\sammax103_drm.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sam and max season 2 episode 2\\SamMax202.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sam and max season 2 episode 1\\SamMax201.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sam and max season 2 episode 4\\SamMax204.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sam and max season 2 episode 5\\SamMax205.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\sam and max season 2 episode 3\\SamMax203.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\plants vs zombies\\PlantsVsZombies.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\alien shooter 2 - reloaded\\AlienShooter.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\far cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\far cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\far cry 2\\bin\\FC2BenchmarkTool.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\far cry 2\\bin\\FC2ServerLauncher.exe"=
R0 uliagpkx;ULi AGP Bus Filter Driver;c:\windows\system32\drivers\AGPKX.SYS [9/30/2006 4:14 PM 45056]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/17/2008 9:20 PM 325896]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/17/2008 9:20 PM 108552]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [6/14/2008 2:09 AM 13696]
R1 BS_I2cIo;BS_I2cIo;c:\windows\system32\drivers\BS_I2cIo.sys [6/14/2008 2:31 AM 8192]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/3/2008 4:40 AM 298776]
R3 RecFltr;Reclusa Keyboard;c:\windows\system32\drivers\RecFltr.sys [12/25/2008 1:13 PM 41984]
S1 atitray;atitray;\??\c:\program files\Radeon Omega Drivers\v3.8.421\ATI Tray Tools\atitray.sys --> c:\program files\Radeon Omega Drivers\v3.8.421\ATI Tray Tools\atitray.sys [?]
S3 efipsk;efipsk;\??\c:\docume~1\SqueeXP\LOCALS~1\Temp\efipsk.sys --> c:\docume~1\SqueeXP\LOCALS~1\Temp\efipsk.sys [?]
S3 hipeer81;Remobo Virtual Interface;c:\windows\system32\drivers\hipeer81.sys [12/6/2006 2:08 PM 54528]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [8/2/2005 4:10 PM 32512]
S3 ULI5261XP;ULi M526X Ethernet NT Driver;c:\windows\system32\drivers\ULILAN51.SYS [9/29/2006 11:25 PM 28672]
.
Contents of the 'Scheduled Tasks' folder
2009-02-03 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2008-06-10 18:56]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
Trusted Zone: alluring-illusions.com
FF - ProfilePath - c:\documents and settings\SqueeXP\Application Data\Mozilla\Firefox\Profiles\yvm5gah6.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\All Users.WINDOWS\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\SqueeXP\Application Data\Mozilla\Firefox\Profiles\yvm5gah6.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-03 16:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-790525478-1647877149-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\}®*" ]
"Order"=hex:08,00,00,00,02,00,00,00,80,00,00,00,01,00,00,00,01,00,00,00,74,00,
00,00,00,00,00,00,66,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,54,00,31,\
[HKEY_USERS\S-1-5-21-790525478-1647877149-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\}®*" \DEVIL FORCE]
"Order"=hex:08,00,00,00,02,00,00,00,14,02,00,00,01,00,00,00,04,00,00,00,84,00,
00,00,00,00,00,00,76,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,64,00,32,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1816)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-06-03 16:31
ComboFix-quarantined-files.txt 2009-06-03 21:30
ComboFix2.txt 2009-06-03 00:54
Pre-Run: 35,050,414,080 bytes free
Post-Run: 35,022,508,032 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
229 --- E O F --- 2009-06-01 08:02