Apologies, I said I was a novice!
ComboFix 08-01-18.5 - Nick 2008-01-20 22:25:33.3 - NTFSx86
Running from: C:\Documents and Settings\Nick\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Nick\My Documents\WORK\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
:\WINDOWS\system32\yyigg.exe
C:\WINDOWS\system32\hfcuoandjrae.exe
C:\WINDOWS\system32\jfzpzapewwiq.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))
.
2008-01-17 22:22 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-16 18:29 . 2008-01-16 18:30 <DIR> d-------- C:\Program Files\Hot Dish
2008-01-16 18:25 . 2008-01-16 18:25 <DIR> d-------- C:\Program Files\Chocolatier 2 - Secret Ingredients
2008-01-16 18:22 . 2008-01-16 18:23 <DIR> d-------- C:\Program Files\bfgclient
2008-01-16 18:22 . 2008-01-16 18:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
2008-01-16 16:22 . 2008-01-16 16:22 268 --ah----- C:\sqmdata11.sqm
2008-01-16 16:22 . 2008-01-16 16:22 244 --ah----- C:\sqmnoopt11.sqm
2008-01-10 23:16 . 2008-01-10 23:16 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-01-10 23:05 . 2008-01-10 23:05 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-01-10 22:53 . 2008-01-10 22:53 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-10 09:13 . 2008-01-10 09:13 <DIR> d-------- C:\Documents and Settings\Ginny\Application Data\Webroot
2008-01-09 23:24 . 2008-01-09 23:24 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-09 23:24 . 2008-01-09 23:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-09 21:46 . 2008-01-09 21:46 <DIR> d-------- C:\Program Files\Webroot
2008-01-09 21:46 . 2008-01-09 21:46 <DIR> d-------- C:\Documents and Settings\Nick\Application Data\Webroot
2008-01-09 21:46 . 2008-01-09 21:46 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-01-09 21:46 . 2008-01-09 21:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-01-09 21:46 . 2007-10-01 16:40 1,526,072 --a------ C:\WINDOWS\WRSetup.dll
2008-01-09 21:46 . 2007-10-01 16:24 163,640 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-01-09 21:46 . 2007-10-01 16:24 23,864 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-01-09 21:46 . 2007-10-01 16:24 21,816 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-01-09 21:46 . 2007-10-01 16:24 20,280 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2008-01-09 21:45 . 2008-01-09 21:45 164 --a------ C:\install.dat
2008-01-06 08:42 . 2008-01-06 08:58 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-01-06 08:42 . 2008-01-06 08:42 <DIR> d-------- C:\Documents and Settings\Nick\Application Data\PC Tools
2008-01-06 08:42 . 2007-10-18 00:16 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-01-06 08:42 . 2007-10-18 00:15 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-01-06 08:42 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-01-06 08:42 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-01-06 08:41 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-01-05 17:15 . 2008-01-05 17:21 <DIR> d-------- C:\Program Files\Windows Live
2008-01-05 17:15 . 2008-01-05 17:20 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-05 17:15 . 2008-01-20 21:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-04 21:43 . 2008-01-04 21:43 <DIR> d-------- C:\Program Files\RegCure
2007-12-31 14:54 . 2007-12-31 14:54 <DIR> d-------- C:\Program Files\Kontiki
2007-12-31 14:54 . 2008-01-20 22:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kontiki
2007-12-30 21:14 . 2007-12-30 21:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZipEC
2007-12-30 21:13 . 2007-12-31 07:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2007-12-28 20:09 . 2007-12-28 20:09 244 --ah----- C:\sqmnoopt10.sqm
2007-12-28 20:09 . 2007-12-28 20:09 232 --ah----- C:\sqmdata10.sqm
2007-12-24 21:36 . 2007-12-24 21:36 118,784 -ra------ C:\WINDOWS\system32\yyigg.exe
2007-12-24 21:01 . 2007-12-24 21:01 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-24 21:01 . 2007-12-24 21:01 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 21:42 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-16 19:47 --------- d-----w C:\Program Files\TikGames
2008-01-16 19:28 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-16 18:26 --------- d-----w C:\Documents and Settings\Nick\Application Data\PlayFirst
2008-01-16 18:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-01-08 00:07 --------- d-----w C:\Program Files\OpenVPN
2008-01-04 21:35 --------- d-----w C:\Program Files\XoftSpySE
2008-01-03 22:00 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-03 22:00 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-03 22:00 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-03 22:00 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-03 22:00 --------- d-----w C:\Program Files\Symantec
2007-12-19 20:52 --------- d-----w C:\Program Files\Microsoft.NET
2007-12-19 20:09 --------- d-----w C:\Program Files\New Folder
2007-12-10 19:59 --------- d-----w C:\Program Files\Gamesville
2007-12-04 19:11 --------- d-----w C:\Program Files\GameShadow
2007-12-04 19:10 --------- d-----w C:\Program Files\Shockwave.com
2007-12-04 15:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\MumboJumbo
2007-11-30 06:58 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-25 16:15 --------- d-----w C:\Program Files\Common Files\xing shared
2007-11-25 16:15 --------- d-----w C:\Program Files\Common Files\Real
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 18:53 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-10-27 17:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-21 20:38 218,929 ----a-w C:\WINDOWS\Prison Tycoon 2 Uninstaller.exe
2007-09-07 15:50 6,920 ----a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2006-10-14 09:22 19,215,997 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2006_10_13_23_03_05_full.dmp.zip
2006-10-12 18:21 18,964,280 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2006_10_12_19_19_27_full.dmp.zip
2006-10-04 20:02 19,158,535 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2006_10_04_21_00_40_full.dmp.zip
2006-10-04 13:31 19,070,463 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2006_10_04_14_29_25_full.dmp.zip
2006-10-04 07:23 19,143,543 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2006_10_03_23_24_54_full.dmp.zip
2006-09-19 14:02 19,108,367 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2006_09_18_23_24_59_full.dmp.zip
2006-09-04 04:16 19,126,759 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2006_09_04_03_21_19_full.dmp.zip
2005-11-22 08:06 55,296 ----a-w C:\Documents and Settings\Nick\Application Data\GDIPFONTCACHEV1.DAT
2005-11-22 06:48 51,773 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2005_11_21_11_40_03_small.dmp.zip
2005-11-22 06:48 49,075 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2005_11_21_11_40_17_small.dmp.zip
2003-08-27 14:19 36,963 ----a-r C:\Program Files\Common Files\SM1updtr.dll
.
((((((((((((((((((((((((((((( snapshot@2008-01-18_22.49.42.35 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-17 22:31:33 1,429,504 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-20 22:24:43 1,429,504 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-17 22:31:34 1,191,936 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-20 22:24:43 1,191,936 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-17 22:31:34 1,425,408 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-20 22:24:44 1,425,408 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-17 22:31:34 1,191,936 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-20 22:24:44 1,191,936 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-17 22:31:35 8,851,456 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-20 22:24:44 8,851,456 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-17 22:31:35 1,765,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-20 22:24:45 1,769,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2000-08-31 08:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2008-01-20 20:28:31 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_5d4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" [2005-08-31 17:11 2478080]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 12:00 200704]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56 15360]
"IFStub"="C:\WINDOWS\Temp\Adware\InstaFinderK_inst.exe" [ ]
"kdx"="C:\Program Files\Kontiki\KHost.exe" [2007-11-27 11:58 1032376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-13 21:10 339968]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 15:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-03-11 15:18 135168]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"CHotkey"="zHotkey.exe" [2004-05-17 17:30 543232 C:\WINDOWS\zHotkey.exe]
"ShowWnd"="ShowWnd.exe" [2003-09-19 08:09 36864 C:\WINDOWS\ShowWnd.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 19:58 73728 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-06 02:05 2550272 C:\WINDOWS\ALCWZRD.EXE]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 13:54 241664]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-07 10:32 50688]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58 282624]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 16:19 129536]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"btbb_wcm_McciTrayApp"="C:\Program Files\btbb_wcm\McciTrayApp.exe" [2006-11-30 10:51 935936]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Sizzling_Blondes"="C:\Program Files\szl\Dialers\Sizzling_Blondes\Sizzling_Blondes.exe" [ ]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2006-08-31 16:01 448040]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-22 22:19 52840]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"NSLauncher"="C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 00:12 2658304]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 12:20 227328]
"Motive SmartBridge"="C:\PROGRA~1\BTBROA~1\SMARTB~1\BTHelpNotifier.exe" [2006-05-24 12:20 458839]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-25 16:14 185896]
"jfzpzapewwiq"="C:\WINDOWS\system32\jfzpzapewwiq.exe" [ ]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24 1065800]
"openvpn-gui"="C:\Program Files\OpenVPN\bin\openvpn-gui.exe" [2005-08-18 08:55 99328]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 16:40 5367608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"DJSNetCN"="C:\Program Files\Common Files\Symantec Shared\DJSNETCN.exe" [2006-02-02 18:54 54976]
"jfzpzapewwiq"="C:\WINDOWS\system32\jfzpzapewwiq.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 14:58 1744896]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2002-01-01 05:57:48]
BT Broadband Desktop Help.lnk - C:\Program Files\BT Broadband Desktop Help\bin\matcli.exe [2007-05-23 20:12:25]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 04:19:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
R3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2006-10-01 12:37]
S3 FTLUND;Lundinova Filter Driver;C:\WINDOWS\system32\drivers\ftlund.sys [2003-02-24 07:36]
S3 gUSBSTOi;gUSBSTOi;C:\DOCUME~1\Glynn\LOCALS~1\Temp\gUSBSTOi.sys []
S3 PCTINDIS5;PCTINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\PCTINDIS5.SYS []
S3 w550bus;Sony Ericsson W550 driver (WDM);C:\WINDOWS\system32\DRIVERS\w550bus.sys []
S3 w550mdfl;Sony Ericsson W550 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w550mdfl.sys []
S3 w550mdm;Sony Ericsson W550 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\w550mdm.sys []
S3 w550mgmt;Sony Ericsson W550 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\w550mgmt.sys []
S3 w550obex;Sony Ericsson W550 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\w550obex.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0d5be68-444c-11e2-8365-806d6172696f}]
\shell\PlayWithPowerDVD\Command - "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" "%L"
*Newly Created Service* - WLSETUPSVC
.
Contents of the 'Scheduled Tasks' folder
"2008-01-16 18:58:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-20 21:51:12 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-04 21:19:26 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Nick.job"
- C:\PROGRA~1\Yahoo!\NAV\Navw32.exeh/TASK:
"2008-01-20 20:29:18 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-04 21:43:24 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-19 23:07:07 C:\WINDOWS\Tasks\WebReg 20080119230706.job"
- C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exeX/TaskName 20080119230706 /N
"2008-01-15 16:53:25 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe&/ScheduleSweep=wrSpySweeperTrialSweep
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- C:\
"2005-09-01 06:15:56 C:\WINDOWS\Tasks\XoftSpy.job"
- C:\Program Files\XoftSpy\XoftSpy.exe
"2008-01-20 20:29:22 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2007-08-25 08:06:41 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-20 22:35:37
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-20 22:42:49
ComboFix-quarantined-files.txt 2008-01-20 22:42:37
ComboFix2.txt 2008-01-20 18:25:13
ComboFix3.txt 2008-01-18 22:51:08
.
2008-01-08 20:25:08 --- E O F ---