2nd part of combofix
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-29 17:27 --------- d-----w C:\Program Files\The Redlink for Oklahoma
2008-01-29 17:24 73,216 ----a-w C:\windows\ST6UNST.EXE
2008-01-29 17:24 286,720 ------w C:\windows\Setup1.exe
2008-01-29 04:06 --------- d-----w C:\Program Files\USB Storage RW
2008-01-29 04:06 --------- d-----w C:\Program Files\PowerISO
2008-01-29 04:06 --------- d-----w C:\Program Files\Multimedia Card Reader
2008-01-29 04:06 --------- d-----w C:\Program Files\Microsoft IntelliType Pro
2008-01-29 04:06 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2008-01-25 17:18 15,360 ----a-w C:\windows\system32\dllcache\ctfmon.exe
2008-01-25 17:18 15,360 ----a-w C:\windows\system32\ctfmon.exe
2008-01-25 17:17 50,176 ----a-w C:\windows\system32\dllcache\ehtray.exe
2008-01-25 17:14 109,056 ----a-w C:\windows\Internet Logs\xDB2.tmp
2008-01-25 17:14 1,403,392 ----a-w C:\windows\Internet Logs\xDB3.tmp
2008-01-25 02:15 251,392 ----a-w C:\windows\Internet Logs\xDB1.tmp
2008-01-23 00:02 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-22 20:10 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ACI
2008-01-19 15:02 --------- d-----w C:\Program Files\iPod
2008-01-17 15:18 --------- d-----w C:\Program Files\DivX
2008-01-10 20:26 --------- d-----w C:\Program Files\Java
2008-01-10 19:37 --------- d-----r C:\Program Files\ACI32
2008-01-07 05:57 --------- d-----w C:\Program Files\dvdSanta
2008-01-04 21:57 823,296 ----a-w C:\windows\system32\divx_xx0c.dll
2008-01-04 21:57 823,296 ----a-w C:\windows\system32\divx_xx07.dll
2008-01-04 21:57 81,920 ----a-w C:\windows\system32\dpl100.dll
2008-01-04 21:57 802,816 ----a-w C:\windows\system32\divx_xx11.dll
2008-01-04 21:57 682,496 ----a-w C:\windows\system32\DivX.dll
2008-01-04 21:57 593,920 ----a-w C:\windows\system32\dpuGUI11.dll
2008-01-04 21:57 57,344 ----a-w C:\windows\system32\dpv11.dll
2008-01-04 21:57 53,248 ----a-w C:\windows\system32\dpuGUI10.dll
2008-01-04 21:57 344,064 ----a-w C:\windows\system32\dpus11.dll
2008-01-04 21:57 294,912 ----a-w C:\windows\system32\dpu11.dll
2008-01-04 21:57 294,912 ----a-w C:\windows\system32\dpu10.dll
2008-01-04 21:57 196,608 ----a-w C:\windows\system32\dtu100.dll
2007-12-30 23:12 --------- d-----w C:\Documents and Settings\Administrator\Application Data\U3
2007-12-30 22:51 --------- d-----w C:\Program Files\Picasa2
2007-12-28 19:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-19 22:47 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-17 20:59 --------- d-----w C:\Program Files\Yahoo!
2007-11-29 22:30 43,528 ----a-w C:\windows\system32\drivers\pxhelp20.sys
2007-11-29 22:30 129,784 ----a-w C:\windows\system32\pxafs.dll
2007-11-29 22:30 120,056 ----a-w C:\windows\system32\pxcpyi64.exe
2007-11-29 22:30 118,520 ----a-w C:\windows\system32\pxinsi64.exe
2007-11-14 22:05 1,086,952 ----a-w C:\windows\system32\zpeng24.dll
2007-11-07 09:26 721,920 ----a-w C:\windows\system32\lsasrv.dll
2007-11-07 09:26 721,920 ----a-w C:\windows\system32\dllcache\lsasrv.dll
2007-10-30 23:42 3,590,656 ----a-w C:\windows\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ----a-w C:\windows\system32\dllcache\tcpip.sys
2007-10-29 22:43 1,287,680 ----a-w C:\windows\system32\quartz.dll
2007-10-29 22:43 1,287,680 ----a-w C:\windows\system32\dllcache\quartz.dll
2007-10-27 23:40 227,328 ----a-w C:\windows\system32\wmasf.dll
2007-10-27 23:40 227,328 ----a-w C:\windows\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\windows\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 ----a-w C:\windows\system32\wininet.dll
2007-10-10 23:56 824,832 ----a-w C:\windows\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ----a-w C:\windows\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ----a-w C:\windows\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ----a-w C:\windows\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ----a-w C:\windows\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ----a-w C:\windows\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ----a-w C:\windows\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ----a-w C:\windows\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ----a-w C:\windows\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ----a-w C:\windows\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ----a-w C:\windows\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ----a-w C:\windows\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ----a-w C:\windows\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ----a-w C:\windows\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ----a-w C:\windows\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ----a-w C:\windows\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ----a-w C:\windows\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ----a-w C:\windows\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ----a-w C:\windows\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ----a-w C:\windows\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ----a-w C:\windows\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ----a-w C:\windows\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ----a-w C:\windows\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ----a-w C:\windows\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ----a-w C:\windows\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ----a-w C:\windows\system32\dllcache\ieakui.dll
2007-05-24 22:46 176 ----a-w C:\Documents and Settings\Administrator\NERO OVERBURN.REG
2007-02-15 22:55 114,888 ----a-w C:\windows\Internet Logs\vsmon_2nd_2007_02_15_13_29_42_small.dmp.zip
2007-02-13 19:28 19,380,007 ----a-w C:\windows\Internet Logs\vsmon_2nd_2007_02_13_13_09_49_full.dmp.zip
2007-02-06 01:10 113,763 ----a-w C:\windows\Internet Logs\vsmon_2nd_2007_02_02_01_46_50_small.dmp.zip
2007-01-30 14:53 113,479 ----a-w C:\windows\Internet Logs\vsmon_2nd_2007_01_29_17_41_02_small.dmp.zip
2007-01-29 15:58 108,378 ----a-w C:\windows\Internet Logs\vsmon_2nd_2007_01_28_18_41_08_small.dmp.zip
2007-01-11 05:29 116,197 ----a-w C:\windows\Internet Logs\vsmon_2nd_2007_01_10_15_28_36_small.dmp.zip
2007-01-10 16:30 112,859 ----a-w C:\windows\Internet Logs\vsmon_2nd_2007_01_10_01_47_22_small.dmp.zip
2005-12-23 14:15 107,114 ----a-w C:\windows\Internet Logs\vsmon_2nd_2005_12_22_19_11_06_small.dmp.zip
2005-12-20 03:27 114,117 ----a-w C:\windows\Internet Logs\vsmon_2nd_2005_12_19_21_12_41_small.dmp.zip
2005-12-19 01:36 48,211 ----a-w C:\windows\Internet Logs\zlclient_2nd_2005_12_18_19_34_09_small.dmp.zip
2005-03-07 23:12 13,824 ----a-w C:\Documents and Settings\Administrator\atwbxdet.dll
2001-01-11 13:20 61,888 ----a-w C:\windows\inf\WIN2000\KTC111.SYS
2002-08-29 12:00 94,784 --sha-w C:\windows\twain.dll
2004-08-04 07:56 50,688 --sha-w C:\windows\twain_32.dll
2004-05-17 17:11 0 --sha-w C:\windows\SMINST\HPCD.sys
2005-12-20 10:07 8 --sha-r C:\windows\system32\fgxp8.dll
2004-08-04 07:56 1,028,096 --sha-w C:\windows\system32\mfc42.dll
2004-08-04 07:56 54,784 --sha-w C:\windows\system32\msvcirt.dll
2004-08-04 07:56 413,696 --sha-w C:\windows\system32\msvcp60.dll
2004-08-04 07:56 343,040 --sha-w C:\windows\system32\msvcrt.dll
2007-05-17 11:28 549,376 --sha-w C:\windows\system32\oleaut32.dll
2004-08-04 07:56 83,456 --sha-w C:\windows\system32\olepro32.dll
2004-08-04 07:56 11,776 --sha-w C:\windows\system32\regsvr32.exe
.
Code:
<pre>
----a-w 919,016 2008-01-25 17:18:37 C:\_OTMoveIt\MovedFiles\[u]0[/u]1292008_114705\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
----a-w 155,648 2008-01-25 17:17:47 C:\_OTMoveIt\MovedFiles\[u]0[/u]1292008_114705\WINDOWS\system32\NeroCheck .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2008-01-25 11:18 15360]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\nbj .exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"Sonic RecordNow! Deluxe"="" []
"Dot1XCfg"="C:\Program Files\Dot1XCfg\Dot1XCfg.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [ ]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [ ]
"KBD"="C:\HP\KBD\KBD.EXE" [ ]
"IPInSightMonitor 01"="C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe" [ ]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2008-01-25 11:17 50176]
"Sunkist2k"="C:\Program Files\Multimedia Card Reader\shwicon2k.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"KYE_Showicon"="C:\Program Files\USB Storage RW\shwicon.exe" [ ]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [ ]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [ ]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [ ]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [ ]
"WHITNEY_S2P"="C:\Program Files\Samsung\Samsung SCX-4x21 Series\PSU\Scan2pc.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [ ]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"NvCplDaemon"="C:\windows\system32\NvCpl.dll" [2004-02-23 15:43 3026944]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 23:24 620152]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 12:45 36040]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 19:17 443968]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\IOGEAR\Bluetooth Software\BTTray.exe [2004-11-29 19:55:44 569405]
Digimax Viewer 2.1.lnk - C:\Program Files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe [2005-12-19 21:38:03 634880]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-12-19 16:46:46 67128]
Microsoft Office Outlook 2003.lnk - C:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe [2007-05-01 09:17:58 794624]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 C:\Program Files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 9.0]
--a------ 2004-11-22 17:20 1126400 C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2004-02-23 15:43 753664 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
--a------ 2002-04-17 18:42 69632 c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-06-19 11:09 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2006-11-03 18:20 866584 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"navapsvc"=2 (0x2)
R0 PQV2i;PQV2i;C:\windows\system32\drivers\PQV2i.sys [2004-11-22 16:51]
R1 PQIMount;PQIMount;C:\windows\system32\drivers\PQIMount.sys [2004-11-22 17:08]
R2 lowpp;Lowrance MMC Parallel Port Driver;C:\windows\system32\Drivers\lowpp.sys [2000-11-14 09:30]
R3 hcwPVRP2;Hauppauge WinTV PVR PCI II (Encoder);C:\windows\system32\DRIVERS\hcwPVRP2.sys [2003-12-02 16:23]
S3 MSControlService;Microsoft cache control;C:\windows\system32\windows []
S3 PCDRDRV;Pcdr Helper Driver;C:\PROGRA~1\PC-DOC~1\DIAGNO~1\PCDRDRV.sys []
S3 StMp3Rec;Player Recovery Device Control Driver;C:\windows\system32\Drivers\StMp3Rec.sys [2006-05-16 14:22]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23d57e89-9a7e-11db-bba9-000c6e4cb699}]
\Shell\AutoRun\command - N:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23d57e8a-9a7e-11db-bba9-000c6e4cb699}]
\Shell\AutoRun\command - O:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-25 23:15:00 C:\windows\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2004\SystemOptimizer.exe
"2008-01-26 05:04:07 C:\windows\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-04-04 14:38:46 C:\windows\Tasks\MP Scheduled Quick Scan.job"
- C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe%Scan -RestrictPrivileges -ScanType 1
"2008-01-29 23:58:11 C:\windows\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-29 18:05:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-29 18:07:58
ComboFix-quarantined-files.txt 2008-01-30 00:07:54
ComboFix2.txt 2008-01-29 16:10:20
ComboFix3.txt 2008-01-28 15:16:12
.
2008-01-24 22:40:08 --- E O F ---