ComboFix 08-10-12.01 - nancy 2008-10-18 14:33:22.4 - NTFSx86
Running from: C:\Documents and Settings\nancy\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\nancy\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\mbqhmbcv
C:\Program Files\Applications
C:\Program Files\hxdmjaf
C:\Program Files\hxdmjaf\genensh.dll
C:\temp\mtc2
C:\temp\mtc2\h5v.log
C:\temp\xp34
C:\temp\xp34\cPH.log
C:\WINDOWS\system32\EV02
C:\WINDOWS\system32\mC02
C:\WINDOWS\system32\np5
C:\WINDOWS\system32\p
C:\WINDOWS\system32\UES
C:\WINDOWS\system32\UES\dx6tb3.exe
C:\WINDOWS\system32\winf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_OFLPYDIN
-------\Service_oflpydin
((((((((((((((((((((((((( Files Created from 2008-09-18 to 2008-10-18 )))))))))))))))))))))))))))))))
.
2008-10-17 20:43 . 2008-10-17 20:43 53,248 --a------ C:\WINDOWS\system32\suppdll.dll
2008-10-17 20:43 . 2008-10-17 20:43 35,363 --a------ C:\WINDOWS\system32\windrvNT.sys
2008-10-12 01:13 . 2008-10-12 01:13 <DIR> d-------- C:\695d627f403feaa5dbe1
2008-10-11 22:36 . 2008-10-11 22:36 86,016 --a------ C:\WINDOWS\system32\evcjargp.exe
2008-10-11 00:17 . 2004-08-04 01:59 36,352 --a------ C:\WINDOWS\system32\drivers\disk.sys
2008-10-11 00:17 . 2004-08-04 01:59 36,352 --a--c--- C:\WINDOWS\system32\dllcache\disk.sys
2008-10-09 23:02 . 2008-10-09 23:02 <DIR> d-------- C:\Program Files\Avira
2008-10-09 23:02 . 2008-10-09 23:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-10-07 18:58 . 2008-10-09 19:10 8,704 --a------ C:\WINDOWS\system32\smwin32.dll
2008-10-05 19:18 . 2008-10-05 19:18 121 --ahs---- C:\WINDOWS\system32\wkldxmiv.ini
2008-10-04 23:29 . 2008-10-04 23:33 122 --ahs---- C:\WINDOWS\system32\mdedmflg.ini
2008-10-04 16:44 . 2008-10-04 16:44 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-10-03 18:48 . 2004-08-04 03:56 24,576 --a------ C:\WINDOWS\system32\stus.exe
2008-09-28 16:31 . 2008-09-28 16:31 121 --ahs---- C:\WINDOWS\system32\bwwctmqe.ini
2008-09-27 20:04 . 2008-10-02 19:53 <DIR> d-------- C:\rsit
2008-09-26 19:31 . 2008-09-26 19:32 38,880 --ahs---- C:\WINDOWS\system32\kihvhbxk.ini
2008-09-25 20:22 . 2008-09-26 19:12 38,880 --ahs---- C:\WINDOWS\system32\kycnkbuh.ini
2008-09-24 22:41 . 2008-09-25 20:13 1,171 --ahs---- C:\WINDOWS\system32\wavuosre.ini
2008-09-24 20:57 . 2008-09-24 20:57 699 --ahs---- C:\WINDOWS\system32\pxnhabof.ini
2008-09-24 18:53 . 2008-09-24 20:36 527 --ahs---- C:\WINDOWS\system32\jkloietj.ini
2008-09-22 18:07 . 2008-09-22 18:07 3,752 --a------ C:\WINDOWS\system32\tmp.reg
2008-09-21 23:21 . 2008-09-21 23:21 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-09-21 15:50 . 2008-09-21 15:51 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-20 18:06 . 2008-09-20 18:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-18 22:11 . 2008-09-22 17:54 345 --ahs---- C:\WINDOWS\system32\dddJlRCf.ini
2008-09-18 19:03 . 2008-09-18 19:03 71 --a------ C:\Documents and Settings\nancy\3151.bat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-18 00:42 --------- d-----w C:\Documents and Settings\nancy\Application Data\OpenOffice.org2
2008-10-15 22:53 --------- d-----w C:\Program Files\GameBiz2
2008-10-15 00:45 21,504 ----a-w C:\Documents and Settings\nancy\39dll.dll
2008-10-15 00:45 157,696 ----a-w C:\Documents and Settings\nancy\supersound.dll
2008-10-14 02:27 --------- d-----w C:\Documents and Settings\nancy\Application Data\Free Download Manager
2008-10-02 00:32 --------- d-----w C:\Program Files\The Tower of Babel
2008-09-25 23:51 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-24 00:28 --------- d-----w C:\Program Files\EarthLink TotalAccess
2008-09-22 22:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-21 18:04 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-20 16:40 --------- d-----w C:\Program Files\Phun
2008-09-12 20:36 --------- d-----w C:\Program Files\Galactic Capitalism
2008-09-05 23:58 --------- d-----w C:\Program Files\Axon Data
2008-09-01 03:37 --------- d-----w C:\Program Files\Risk
2008-08-31 02:28 --------- d-----w C:\Program Files\Zombie Cow Studios
2008-08-29 18:26 8,992 ----a-w C:\Documents and Settings\nancy\Device.dat
2008-08-29 00:30 --------- d-----w C:\Program Files\VDMSound
2008-08-28 22:04 --------- d-----w C:\Program Files\DOSBox-0.72
2008-08-26 03:56 --------- d-----w C:\Program Files\Cheat Engine
2008-08-25 10:55 --------- d-----w C:\Program Files\Carbiz demo
2008-08-19 20:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-19 20:23 --------- d-----w C:\Program Files\Cat Daddy Games
2008-08-19 17:26 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-08-19 17:20 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-08-19 17:20 --------- d-----w C:\Documents and Settings\nancy\Application Data\DAEMON Tools
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-03-31 00:17 336 ----a-w C:\Program Files\temp995.bat
2007-09-29 04:04 714,936 ----a-w C:\Documents and Settings\Guest\Application Data\New Compressed (zipped) Folder.zip
1987-09-18 16:31 26,785 ----a-w C:\Documents and Settings\nancy\ELECTION.EXE
1987-09-18 16:12 26,705 ----a-w C:\Documents and Settings\nancy\PE.EXE
1987-09-18 15:46 57,425 ----a-w C:\Documents and Settings\nancy\MAP.EXE
1987-09-18 04:59 51,185 ----a-w C:\Documents and Settings\nancy\CAMPAIGN.EXE
1987-09-18 02:26 26,689 ----a-w C:\Documents and Settings\nancy\DEBATE.EXE
1987-09-18 02:23 39,921 ----a-w C:\Documents and Settings\nancy\NOMINATE.EXE
1987-09-17 22:30 5,921 ----a-w C:\Documents and Settings\nancy\START.EXE
1987-04-07 15:48 70,680 ----a-w C:\Documents and Settings\nancy\BRUN30.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CyberLat Ram Cleaner"="C:\Program Files\CyberLat\CyberLat RAM Cleaner 1.1\CyberLat Ram Cleaner 1" [X]
"Dell AIO Printer A960"="C:\Program Files\Dell AIO Printer A960\dlbfbmgr.exe" [2003-09-21 270336]
"VolControl"="C:\Program Files\Volume Control\Volume Control.exe" [2007-01-24 102400]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk.disabled [2006-10-19 1757]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
"Twain"=C:\Program Files\Twain\Twain.exe
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
"PLNRNote"="C:\Program Files\SierraHome\Hallmark Card Studio Special Edition\Planner\PLNRNote.exe"
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe"
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
"flockbox"=F:\My Lockbox\flockbox.exe /a
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\Java\\jre1.5.0_04\\bin\\javaw.exe"=
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"=
"C:\\Program Files\\Freeciv-2.0.9-gtk2\\civserver.exe"=
"C:\\Documents and Settings\\Nancy_2\\Desktop\\Freeciv-2.0.9-gtk2\\civserver.exe"=
"C:\\Documents and Settings\\nancy\\Desktop\\Freeciv-2.0.9-gtk2\\civserver.exe"=
"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaw.exe"=
"C:\\Program Files\\Globulation_2\\glob2.exe"=
"C:\\Documents and Settings\\nancy\\Desktop\\KMIVBR2\\KMI.Cstore.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support
R0 MPRIFL;MPRIFL;C:\WINDOWS\system32\DRIVERS\MPRIFL.SYS [2007-04-18 17264]
R2 EarthLinkMonitor;EarthLink Monitor Service;C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe [2005-01-26 65604]
S3 ADSFilter;ADSFilter - (Aluria Filter Driver);C:\WINDOWS\system32\DRIVERS\ADSFilter.sys [ ]
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys [2004-11-01 17536]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-18 14:49:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\sccfg.sys 312 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Dell AIO Printer A960\dlbfbmon.exe
C:\Program Files\CyberLat\CyberLat RAM Cleaner 1.1\CyberLat Ram Cleaner 1,1.exe
.
**************************************************************************
.
Completion time: 2008-10-18 14:57:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-18 18:57:07
ComboFix2.txt 2008-10-16 00:52:23
ComboFix3.txt 2008-10-16 00:16:34
Pre-Run: 55,853,699,072 bytes free
Post-Run: 55,849,873,408 bytes free
188 --- E O F --- 2008-10-13 03:51:36