Heres are the new logs
ComboFix 08-03-07.4 - Travis 2008-03-10 22:24:08.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.760 [GMT -7:00]
Running from: C:\Documents and Settings\Travis.TRAVIS-36FDF295\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Travis.TRAVIS-36FDF295\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\pxulvfej.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\pxulvfej.ini
C:\WINDOWS\system32\RCX7.tmp
.
((((((((((((((((((((((((( Files Created from 2008-02-11 to 2008-03-11 )))))))))))))))))))))))))))))))
.
2008-03-10 15:14 . 2008-03-10 15:14 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-03-08 05:42 . 2008-03-08 05:42 <DIR> d-------- C:\Program Files\MSBuild
2008-03-08 05:38 . 2008-03-08 05:38 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-03-08 05:37 . 2008-03-08 05:37 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-03-08 05:36 . 2006-06-29 14:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-03-08 05:30 . 2008-03-08 05:30 <DIR> d-------- C:\Documents and Settings\Travis.TRAVIS-36FDF295\Application Data\Sony Setup
2008-03-07 23:07 . 2008-03-07 23:07 1,158 --a------ C:\WINDOWS\mozver.dat
2008-03-06 18:12 . 2007-12-06 19:21 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-03-06 18:12 . 2007-06-30 20:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-03-06 18:12 . 2007-06-30 20:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-03-06 18:12 . 2007-12-06 19:21 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-03-06 18:12 . 2007-12-06 19:21 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-03-06 18:12 . 2007-12-06 19:21 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-03-06 18:12 . 2007-12-06 19:21 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-03-06 18:12 . 2007-12-06 19:21 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-03-06 18:12 . 2007-12-06 04:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-03-06 16:46 . 2008-03-06 16:47 <DIR> d-------- C:\Program Files\Combined Community Codec Pack
2008-03-06 16:30 . 2005-04-06 01:43 1,024,000 --a------ C:\WINDOWS\system\3ivx.dll
2008-03-06 16:03 . 2008-03-07 22:50 255 --a------ C:\WINDOWS\wininit.ini
2008-03-06 15:04 . 2008-03-06 15:38 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-03-06 04:00 . 2006-10-16 17:10 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-03-06 00:09 . 2008-03-06 17:59 1,307,734 --ahs---- C:\WINDOWS\system32\airswffq.ini
2008-03-05 22:06 . 2008-03-10 22:29 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-05 22:06 . 2008-03-05 22:06 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-05 22:06 . 2008-03-09 01:44 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-05 22:04 . 2008-03-06 14:46 <DIR> d-------- C:\Documents and Settings\Travis.TRAVIS-36FDF295\Application Data\Apple Computer
2008-03-05 22:00 . 2008-03-05 22:03 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
2008-03-05 21:59 . 2008-03-05 21:59 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-03-05 21:59 . 2008-03-05 21:59 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-03-05 21:59 . 2008-03-05 21:59 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple
2008-03-05 16:11 . 2008-03-05 16:11 <DIR> d-------- C:\Program Files\Common Files\BitCtrl
2008-03-05 15:44 . 2008-03-05 15:55 <DIR> d-------- C:\Program Files\Elecard
2008-03-05 15:32 . 2008-03-05 15:32 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-03-05 00:53 . 2008-03-05 00:53 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-04 23:13 . 2003-11-03 19:15 1,902 --a------ C:\WINDOWS\system32\SetupBD.din
2008-03-04 23:12 . 2008-03-04 23:12 <DIR> d-------- C:\Documents and Settings\TRAVIS~1~TRA\LOCALS~1
2008-03-04 23:11 . 2006-06-14 01:47 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2008-03-04 23:06 . 2008-03-04 23:07 28,352 --a------ C:\WINDOWS\system32\drivers\MxlW2k.sys
2008-03-04 23:03 . 1999-06-25 11:55 149,504 --a------ C:\WINDOWS\UNWISE.EXE
2008-03-04 23:00 . 1998-09-24 13:03 171,967 --a------ C:\WINDOWS\system32\Odbcjet.hlp
2008-03-04 23:00 . 1998-06-18 00:00 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL
2008-03-04 23:00 . 2001-08-22 09:42 13,632 --------- C:\WINDOWS\system32\drivers\omci.sys
2008-03-04 23:00 . 1998-09-24 13:03 7,348 --a------ C:\WINDOWS\system32\Odbcjet.cnt
2008-03-04 21:02 . 2008-03-05 16:05 <DIR> d-------- C:\Program Files\GemMaster
2008-03-04 21:02 . 2008-03-04 21:02 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\DIGStream
2008-03-04 20:54 . 2008-03-04 20:54 8,192 --a------ C:\WINDOWS\REGLOCS.OLD
2008-03-04 20:52 . 2004-08-10 05:13 73,728 --a--c--- C:\WINDOWS\system32\dllcache\ehresja.dll
2008-03-04 20:52 . 2004-08-10 05:13 69,632 --a--c--- C:\WINDOWS\system32\dllcache\ehresko.dll
2008-03-04 20:52 . 2004-08-10 05:13 69,632 --a--c--- C:\WINDOWS\system32\dllcache\ehresfr.dll
2008-03-04 20:52 . 2004-08-10 05:13 69,632 --a--c--- C:\WINDOWS\system32\dllcache\ehresde.dll
2008-03-04 20:52 . 2004-08-10 05:13 61,440 --a--c--- C:\WINDOWS\system32\dllcache\ehreschs.dll
2008-03-04 20:50 . 2004-08-10 04:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-03-04 20:49 . 2004-08-10 04:00 10,096,640 --a--c--- C:\WINDOWS\system32\dllcache\hwxcht.dll
2008-03-04 20:48 . 2004-05-13 01:39 876,653 --a--c--- C:\WINDOWS\system32\dllcache\fp4awel.dll
2008-03-04 20:47 . 2008-03-04 20:47 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-03-04 20:47 . 2008-03-04 20:47 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-03-04 20:47 . 2008-03-04 20:47 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-03-04 20:47 . 2008-03-04 20:47 2,577 --a------ C:\WINDOWS\system32\CONFIG.NT
2008-03-04 20:47 . 2008-03-04 20:47 0 --a------ C:\WINDOWS\control.ini
2008-03-04 20:45 . 2008-03-05 16:03 <DIR> d--hs---- C:\Documents and Settings\All Users.WINDOWS\DRM
2008-03-04 20:45 . 2008-03-04 20:45 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-03-04 20:45 . 2008-03-04 20:45 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-03-04 20:45 . 2008-03-04 20:45 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-03-04 20:45 . 2008-03-04 20:45 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-03-04 20:45 . 2008-03-04 20:45 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-03-04 20:45 . 2008-03-04 20:45 749 -rah----- C:\WINDOWS\system32\cdplayer.exe.manifest
2008-03-04 20:45 . 2008-03-04 20:45 488 -rah----- C:\WINDOWS\system32\WindowsLogon.manifest
2008-03-04 20:45 . 2008-03-04 20:45 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-03-04 20:42 . 2008-03-04 20:42 21,640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-03-04 20:42 . 2008-03-04 20:42 37 --a------ C:\WINDOWS\vbaddin.ini
2008-03-04 20:42 . 2008-03-04 20:42 36 --a------ C:\WINDOWS\vb.ini
2008-03-04 20:41 . 2004-08-10 04:43 7,093,760 --a------ C:\WINDOWS\system32\space.scr
2008-03-04 20:41 . 2004-08-10 04:43 5,068,800 --a------ C:\WINDOWS\system32\davinci.scr
2008-03-04 20:41 . 2004-08-10 04:43 4,396,544 --a------ C:\WINDOWS\system32\wpgldfsh.scr
2008-03-04 20:41 . 2004-08-10 04:43 3,343,360 --a------ C:\WINDOWS\system32\nature.scr
2008-03-04 20:41 . 2004-08-10 04:43 1,742,336 --a------ C:\WINDOWS\system32\mypixdx.scr
2008-03-04 20:41 . 2004-08-10 05:11 85,504 --a------ C:\WINDOWS\system32\mhn.dll
2008-03-04 20:41 . 2004-08-10 04:39 19,840 --a------ C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-03-04 20:41 . 2004-04-22 03:07 11,452 --a------ C:\WINDOWS\system32\mypixdx.chm
2008-03-04 20:41 . 2004-08-10 04:45 11,008 --a------ C:\WINDOWS\system32\drivers\mhndrv.sys
2008-03-04 20:41 . 2004-08-10 05:11 8,704 --a------ C:\WINDOWS\system32\igdetect.dll
2008-03-04 20:39 . 2004-08-10 04:00 1,352,192 --a--c--- C:\WINDOWS\system32\dllcache\cimwin32.dll
2008-03-04 16:49 . 2008-03-04 16:49 426 --a------ C:\Shortcut to StubInstaller.lnk
2008-03-04 16:46 . 2008-03-04 16:46 <DIR> d-------- C:\New Folder
2008-03-04 14:47 . 2008-03-04 14:47 <DIR> d-------- C:\Program Files\Modem Helper
2008-03-04 14:45 . 2008-03-04 12:01 <DIR> d-------- C:\WINDOWS\system32\vmm32
2008-03-04 12:35 . 2004-08-03 17:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-03-04 12:35 . 2001-08-17 06:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-03-04 12:34 . 2004-08-03 15:59 57,472 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-03-04 12:33 . 2004-08-03 17:56 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2008-03-04 12:33 . 2004-08-03 15:59 5,504 --a------ C:\WINDOWS\system32\drivers\intelide.sys
2008-03-04 12:29 . 2008-03-04 20:55 <DIR> dr------- C:\Documents and Settings\All Users.WINDOWS\Documents
2008-03-04 12:29 . 2004-08-10 04:00 176,157 --a--c--- C:\WINDOWS\system32\dllcache\dgrpsetu.dll
2008-03-04 12:28 . 2004-08-10 04:00 2,008,817 --a--c--- C:\WINDOWS\system32\dllcache\NT5.CAT
2008-03-04 12:25 . 2008-03-04 20:52 560 --a------ C:\WINDOWS\system32\$winnt$.inf
2008-03-04 01:15 . 2008-03-04 21:07 <DIR> d-------- C:\Program Files\RGB
2008-03-04 01:10 . 2008-03-04 21:02 <DIR> d-------- C:\Program Files\ESPNMotion
2008-03-04 01:10 . 2008-03-04 01:10 <DIR> d-------- C:\Program Files\EnglishOtto
2008-03-04 01:10 . 2008-03-04 21:02 <DIR> d-------- C:\Program Files\DIGStream
2008-02-23 17:57 . 2008-02-23 17:57 <DIR> d-------- C:\Documents and Settings\Troy\Application Data\Skype
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-11 05:24 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-11 05:24 --------- d-----w C:\Program Files\QuickTime
2008-03-11 05:24 --------- d-----w C:\Program Files\iTunes
2008-03-11 05:24 --------- d-----w C:\Program Files\AIV Reminder
2008-03-08 12:30 --------- d-----w C:\Program Files\Sony Setup
2008-03-06 05:02 --------- d-----w C:\Program Files\Bonjour
2008-03-06 05:00 --------- d-----w C:\Program Files\Apple Software Update
2008-03-05 06:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-04 23:49 419 ----a-w C:\Program Files\Shortcut to a8a5ff21a835984487.lnk
2008-03-04 23:49 409 ----a-w C:\Program Files\Shortcut to Application Data.lnk
2008-03-04 23:49 379 ----a-w C:\Program Files\Shortcut to New Folder.lnk
2008-03-04 23:49 378 ----a-w C:\Program Files\Shortcut to WINDOWS.lnk
2008-03-04 23:49 374 ----a-w C:\Program Files\Shortcut to Downloads.lnk
2008-03-04 23:49 369 ----a-w C:\Program Files\Shortcut to mstalkit.lnk
2008-03-04 23:49 345 ----a-w C:\Program Files\Shortcut to DELL.lnk
2008-02-23 08:15 --------- d-----w C:\Documents and Settings\Others\Application Data\CyberLink
2008-02-23 08:12 --------- d-----w C:\Program Files\DivX
2008-02-23 08:10 --------- d-----w C:\Program Files\Opera
2008-02-02 07:15 --------- d-----w C:\Program Files\LimeWire
2008-01-13 22:27 --------- d-----w C:\Documents and Settings\Troy\Application Data\Aim
2008-01-13 19:16 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-01-13 19:10 --------- d-----w C:\Program Files\FlashGet
2008-01-12 19:47 --------- d-----w C:\Program Files\Virtual Personality
2008-01-12 19:41 --------- d-----w C:\Program Files\Google
2008-01-12 14:47 10 -c--a-w C:\Program Files\.autoreg
2008-01-12 09:59 --------- d-----w C:\Program Files\Incomplete
2008-01-12 09:59 --------- d-----w C:\Documents and Settings\Troy\Application Data\LimeWire
2007-09-08 19:35 229 -c--a-w C:\Program Files\player.nfo
2007-06-03 15:39 281 -c--a-w C:\Program Files\player.nfx
2000-08-08 18:44 340 -c--a-w C:\Program Files\setup.bat
2000-08-08 18:43 4,395,575 -c--a-w C:\Program Files\myth.pak
2000-08-08 18:39 45,056 ----a-w C:\Program Files\SETUPREG.EXE
2000-08-08 18:18 34 -c--a-w C:\Program Files\fonts.bat
2000-08-08 18:17 0 -c--a-w C:\Program Files\STPENUX.DLL
2000-08-08 18:17 0 -c--a-w C:\Program Files\EBUSetup.sem
2000-08-08 04:13 2,695,213 ----a-w C:\Program Files\age2_x1.exe
2000-08-07 04:11 20,992 ----a-w C:\Program Files\mythxpak.exe
2000-06-28 04:00 44,452 -c--a-w C:\Program Files\Readmex.rtf
2000-06-21 13:52 32,768 ----a-w C:\Program Files\replwavs.exe
2000-06-13 04:09 339,968 -c--a-w C:\Program Files\language_x1.dll
2000-06-13 03:59 53,299 -c--a-w C:\Program Files\ebueulax.dll
2000-05-27 04:58 39,647 -c--a-w C:\Program Files\EULAx.RTF
2000-04-01 01:47 301,568 -c--a-w C:\Program Files\myth.acm
1999-11-17 16:00 32,768 -c--a-w C:\Program Files\SETUPENU.DLL
1999-09-22 06:32 57,363 -c--a-w C:\Program Files\Readme.rtf
1999-09-22 06:32 53,304 -c--a-w C:\Program Files\EBUEula.dll
1999-09-22 06:32 499,712 -c--a-w C:\Program Files\language.dll
1999-09-22 06:32 40,507 -c--a-w C:\Program Files\EULA.RTF
1999-09-22 06:32 365,568 -c--a-w C:\Program Files\HA312W32.DLL
1999-09-22 06:32 158,902 -c--a-w C:\Program Files\scenariobkg.bmp
1999-09-22 06:32 112,688 ----a-w C:\Program Files\SHW32.DLL
1999-09-21 21:46 2,560,000 ----a-w C:\Program Files\empires2.exe
1997-04-01 04:00 83,456 -c--a-w C:\Program Files\README.DOC
1997-04-01 04:00 662,016 ----a-w C:\Program Files\WWINT32V.DLL
1997-04-01 04:00 5,238 -c--a-w C:\Program Files\INSTALL.TXT
1997-04-01 04:00 5,044 -c--a-w C:\Program Files\LICENSE.TXT
1997-04-01 04:00 3,567,104 ----a-w C:\Program Files\WORDVIEW.EXE
.
Code:
<pre>
----a-w 4,670,968 2008-02-24 06:20:56 C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
----a-w 59,392 2008-03-06 21:25:44 C:\WINDOWS\ehome\ehtray .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB612661-6A10-4BEF-86F4-D3A94FEAD47D}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-03-07 22:50 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 05:04 59392]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2008-03-07 22:50 53248]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-07 22:50 267048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
Contents of the 'Scheduled Tasks' folder
"2008-03-06 05:00:17 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-10 22:29:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wpabaln.exe
.
**************************************************************************
.
Completion time: 2008-03-10 22:32:00 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-11 05:31:57
ComboFix2.txt 2008-03-08 08:12:01
.
2008-03-10 22:14:49 --- E O F ---
Malwarebytes' Anti-Malware 1.08
Database version: 476
Scan type: Quick Scan
Objects scanned: 49893
Time elapsed: 6 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)