lizardlize
New member
It worked this time here is both logs
ComboFix 08-09-26.06 - Owner 2008-09-28 10:46:21.3 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\windows\BM57247bb3.txt
C:\WINDOWS\system32\akcskd.dll
C:\WINDOWS\system32\aqkrohsi.ini
C:\WINDOWS\system32\blqsdmbn.dll
C:\WINDOWS\system32\bskxlmrh.ini
C:\WINDOWS\system32\btedxycx.dll
C:\WINDOWS\system32\bwfytjkn.dll
C:\WINDOWS\system32\cdezcp.dll
C:\WINDOWS\system32\cfioldln.ini
C:\WINDOWS\system32\ddLUvyay.ini
C:\WINDOWS\system32\ddLUvyay.ini2
C:\WINDOWS\system32\dldjdgpb.dll
C:\WINDOWS\system32\dowdrmdm.dll
C:\WINDOWS\system32\epttasrt.dll
C:\WINDOWS\system32\eqlrtjwc.dll
C:\WINDOWS\system32\eysijgoc.dll
C:\WINDOWS\system32\ffmlux.dll
C:\WINDOWS\system32\fiqhlfgs.ini
C:\WINDOWS\system32\frjdpkfp.dll
C:\WINDOWS\system32\gcfkfrvj.dll
C:\WINDOWS\system32\gndewlnl.ini
C:\WINDOWS\system32\gogtflpg.dll
C:\WINDOWS\system32\gsybahph.dll
C:\WINDOWS\system32\hejwhasx.dll
C:\WINDOWS\system32\hfbpzu.dll
C:\WINDOWS\system32\hggeBsPj.dll
C:\WINDOWS\system32\hijyqy.dll
C:\WINDOWS\system32\hjrcmntv.dll
C:\WINDOWS\system32\hohqil.dll
C:\WINDOWS\system32\hpepyvtt.dll
C:\WINDOWS\system32\htyoltvx.dll
C:\WINDOWS\system32\hucofkti.dll
C:\WINDOWS\system32\hxwaap.dll
C:\WINDOWS\system32\hyuxwaak.ini
C:\WINDOWS\system32\iacgms.dll
C:\WINDOWS\system32\icpwhfeh.ini
C:\WINDOWS\system32\ieencode.dll
C:\WINDOWS\system32\iiFUmMfd.dll
C:\WINDOWS\system32\iiqnshct.ini
C:\WINDOWS\system32\jahxmi.dll
C:\WINDOWS\system32\jbksnxhl.dll
C:\WINDOWS\system32\jdsyhtrr.dll
C:\WINDOWS\system32\jflphxuo.dll
C:\WINDOWS\system32\jihrwqmq.dll
C:\WINDOWS\system32\kesxfccs.dll
C:\WINDOWS\system32\khfDTNEt.dll
C:\WINDOWS\system32\knvknwjd.dll
C:\WINDOWS\system32\kugnlc.dll
C:\WINDOWS\system32\kxkgphkq.dll
C:\WINDOWS\system32\kyikvrpi.dll
C:\WINDOWS\system32\lcisicjc.ini
C:\WINDOWS\system32\leulfi.dll
C:\WINDOWS\system32\mcsfqram.dll
C:\WINDOWS\system32\mcuiivho.dll
C:\WINDOWS\system32\mdldtxkb.dll
C:\WINDOWS\system32\mdygoxfe.dll
C:\WINDOWS\system32\mskqmb.dll
C:\WINDOWS\system32\nghlvivg.dll
C:\WINDOWS\system32\niesnuco.ini
C:\WINDOWS\system32\njslkici.dll
C:\WINDOWS\system32\nmemoh.dll
C:\WINDOWS\system32\nnicsm.dll
C:\WINDOWS\system32\nnnkJAsP.dll
C:\WINDOWS\system32\nnnoLEWo.dll
C:\WINDOWS\system32\nnnoPgHA.dll
C:\WINDOWS\system32\nrvprgka.dll
C:\WINDOWS\system32\ntcxws.dll
C:\WINDOWS\system32\oikednnm.dll
C:\WINDOWS\system32\omcyibwl.ini
C:\WINDOWS\system32\onlbgw.dll
C:\WINDOWS\system32\pahqhe.dll
C:\WINDOWS\system32\pbbwacnk.dll
C:\WINDOWS\system32\phmkln.dll
C:\WINDOWS\system32\pwhepwsr.dll
C:\WINDOWS\system32\qkiizc.dll
C:\WINDOWS\system32\qlnbcmqq.dll
C:\WINDOWS\system32\qpityipw.ini
C:\WINDOWS\system32\qtpfopgn.dll
C:\WINDOWS\system32\rcajwmty.dll
C:\WINDOWS\system32\rcuiue.dll
C:\WINDOWS\system32\rgkjuxjs.dll
C:\WINDOWS\system32\rqRhIBSk.dll
C:\WINDOWS\system32\rqRIxuTM.dll
C:\WINDOWS\system32\scckgugp.ini
C:\WINDOWS\system32\sdxhrljf.dll
C:\WINDOWS\system32\srqginiw.ini
C:\WINDOWS\system32\sSmjiiIx.dll
C:\WINDOWS\system32\swgatpcp.ini
C:\WINDOWS\system32\swlhpwhw.dll
C:\WINDOWS\system32\sxksoonm.dll
C:\WINDOWS\system32\tcgqauvy.ini
C:\WINDOWS\system32\tchsnqii.dll
C:\WINDOWS\system32\tehogmas.dll
C:\WINDOWS\system32\tmgaebio.dll
C:\WINDOWS\system32\ujyjlj.dll
C:\WINDOWS\system32\vfexxy.dll
C:\WINDOWS\system32\vhypgmdj.dll
C:\WINDOWS\system32\vobkrdoi.dll
C:\WINDOWS\system32\vppgnbit.dll
C:\WINDOWS\system32\vsalhfng.dll
C:\WINDOWS\system32\winigqrs.dll
C:\WINDOWS\system32\wokfjqqd.ini
C:\WINDOWS\system32\xacykm.dll
C:\WINDOWS\system32\xcbwtqed.dll
C:\WINDOWS\system32\xIiijmSs.ini
C:\WINDOWS\system32\xIiijmSs.ini2
C:\WINDOWS\system32\XIOVxyxx.ini
C:\WINDOWS\system32\XIOVxyxx.ini2
C:\WINDOWS\system32\xjbmwcgl.dll
C:\WINDOWS\system32\xtcbmxkr.ini
C:\WINDOWS\system32\xtvdjaij.ini
C:\WINDOWS\system32\ydpoidih.ini
C:\WINDOWS\system32\ytmwjacr.ini
C:\WINDOWS\system32\yvwepumr.dll
C:\WINDOWS\system32\zewzrl.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\windows\BM57247bb3.txt
C:\windows\BM57247bb3.xml
C:\windows\pskt.ini
C:\WINDOWS\system32\ieencode.dll
.
---- Previous Run -------
.
C:\Program Files\ewido anti-spyware 4.0
C:\Program Files\ewido anti-spyware 4.0\updater.ewidolog
C:\windows\BM57247bb3.txt
C:\windows\pskt.ini
C:\WINDOWS\system32\akcskd.dll
C:\WINDOWS\system32\aqkrohsi.ini
C:\WINDOWS\system32\blqsdmbn.dll
C:\WINDOWS\system32\bskxlmrh.ini
C:\WINDOWS\system32\btedxycx.dll
C:\WINDOWS\system32\bwfytjkn.dll
C:\WINDOWS\system32\cdezcp.dll
C:\WINDOWS\system32\cfioldln.ini
C:\WINDOWS\system32\ddLUvyay.ini
C:\WINDOWS\system32\ddLUvyay.ini2
C:\WINDOWS\system32\dldjdgpb.dll
C:\WINDOWS\system32\dowdrmdm.dll
C:\WINDOWS\system32\epttasrt.dll
C:\WINDOWS\system32\eqlrtjwc.dll
C:\WINDOWS\system32\eysijgoc.dll
C:\WINDOWS\system32\ffmlux.dll
C:\WINDOWS\system32\fiqhlfgs.ini
C:\WINDOWS\system32\frjdpkfp.dll
C:\WINDOWS\system32\gcfkfrvj.dll
C:\WINDOWS\system32\gndewlnl.ini
C:\WINDOWS\system32\gogtflpg.dll
C:\WINDOWS\system32\gsybahph.dll
C:\WINDOWS\system32\hejwhasx.dll
C:\WINDOWS\system32\hfbpzu.dll
C:\WINDOWS\system32\hggeBsPj.dll
C:\WINDOWS\system32\hijyqy.dll
C:\WINDOWS\system32\hjrcmntv.dll
C:\WINDOWS\system32\hohqil.dll
C:\WINDOWS\system32\hpepyvtt.dll
C:\WINDOWS\system32\htyoltvx.dll
C:\WINDOWS\system32\hucofkti.dll
C:\WINDOWS\system32\hxwaap.dll
C:\WINDOWS\system32\hyuxwaak.ini
C:\WINDOWS\system32\iacgms.dll
C:\WINDOWS\system32\icpwhfeh.ini
C:\WINDOWS\system32\ieencode.dll
C:\WINDOWS\system32\iiFUmMfd.dll
C:\WINDOWS\system32\iiqnshct.ini
C:\WINDOWS\system32\jahxmi.dll
C:\WINDOWS\system32\jbksnxhl.dll
C:\WINDOWS\system32\jdsyhtrr.dll
C:\WINDOWS\system32\jflphxuo.dll
C:\WINDOWS\system32\jihrwqmq.dll
C:\WINDOWS\system32\kesxfccs.dll
C:\WINDOWS\system32\khfDTNEt.dll
C:\WINDOWS\system32\knvknwjd.dll
C:\WINDOWS\system32\kugnlc.dll
C:\WINDOWS\system32\kxkgphkq.dll
C:\WINDOWS\system32\kyikvrpi.dll
C:\WINDOWS\system32\lcisicjc.ini
C:\WINDOWS\system32\leulfi.dll
C:\WINDOWS\system32\mcsfqram.dll
C:\WINDOWS\system32\mcuiivho.dll
C:\WINDOWS\system32\mdldtxkb.dll
C:\WINDOWS\system32\mdygoxfe.dll
C:\WINDOWS\system32\mskqmb.dll
C:\WINDOWS\system32\nghlvivg.dll
C:\WINDOWS\system32\niesnuco.ini
C:\WINDOWS\system32\njslkici.dll
C:\WINDOWS\system32\nmemoh.dll
C:\WINDOWS\system32\nnicsm.dll
C:\WINDOWS\system32\nnnkJAsP.dll
C:\WINDOWS\system32\nnnoLEWo.dll
C:\WINDOWS\system32\nnnoPgHA.dll
C:\WINDOWS\system32\nrvprgka.dll
C:\WINDOWS\system32\ntcxws.dll
C:\WINDOWS\system32\oikednnm.dll
C:\WINDOWS\system32\omcyibwl.ini
C:\WINDOWS\system32\onlbgw.dll
C:\WINDOWS\system32\pahqhe.dll
C:\WINDOWS\system32\pbbwacnk.dll
C:\WINDOWS\system32\phmkln.dll
C:\WINDOWS\system32\pwhepwsr.dll
C:\WINDOWS\system32\qkiizc.dll
C:\WINDOWS\system32\qlnbcmqq.dll
C:\WINDOWS\system32\qpityipw.ini
C:\WINDOWS\system32\qtpfopgn.dll
C:\WINDOWS\system32\rcajwmty.dll
C:\WINDOWS\system32\rcuiue.dll
C:\WINDOWS\system32\rgkjuxjs.dll
C:\WINDOWS\system32\rqRhIBSk.dll
C:\WINDOWS\system32\rqRIxuTM.dll
C:\WINDOWS\system32\scckgugp.ini
C:\WINDOWS\system32\sdxhrljf.dll
C:\WINDOWS\system32\srqginiw.ini
C:\WINDOWS\system32\sSmjiiIx.dll
C:\WINDOWS\system32\swgatpcp.ini
C:\WINDOWS\system32\swlhpwhw.dll
C:\WINDOWS\system32\sxksoonm.dll
C:\WINDOWS\system32\tcgqauvy.ini
C:\WINDOWS\system32\tchsnqii.dll
C:\WINDOWS\system32\tehogmas.dll
C:\WINDOWS\system32\tmgaebio.dll
C:\WINDOWS\system32\ujyjlj.dll
C:\WINDOWS\system32\vfexxy.dll
C:\WINDOWS\system32\vhypgmdj.dll
C:\WINDOWS\system32\vobkrdoi.dll
C:\WINDOWS\system32\vppgnbit.dll
C:\WINDOWS\system32\vsalhfng.dll
C:\WINDOWS\system32\winigqrs.dll
C:\WINDOWS\system32\wokfjqqd.ini
C:\WINDOWS\system32\xacykm.dll
C:\WINDOWS\system32\xcbwtqed.dll
C:\WINDOWS\system32\xIiijmSs.ini
C:\WINDOWS\system32\xIiijmSs.ini2
C:\WINDOWS\system32\XIOVxyxx.ini
C:\WINDOWS\system32\XIOVxyxx.ini2
C:\WINDOWS\system32\xjbmwcgl.dll
C:\WINDOWS\system32\xtcbmxkr.ini
C:\WINDOWS\system32\xtvdjaij.ini
C:\WINDOWS\system32\ydpoidih.ini
C:\WINDOWS\system32\ytmwjacr.ini
C:\WINDOWS\system32\yvwepumr.dll
C:\WINDOWS\system32\zewzrl.dll
.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-28 )))))))))))))))))))))))))))))))
.
2008-09-28 10:21 . 2008-09-28 10:21 42,496 --a------ C:\WINDOWS\system32\wvUljHAt.dll
2008-09-28 10:21 . 2008-09-28 10:21 42,496 --a------ C:\WINDOWS\system32\tuvWnoMf.dll
2008-09-28 09:47 . 2008-09-28 09:47 988,183 ---hs---- C:\WINDOWS\system32\djqmrbul.ini
2008-09-28 09:47 . 2008-09-28 09:47 78,848 --a------ C:\WINDOWS\system32\lubrmqjd.dll
2008-09-28 09:44 . 2008-09-28 09:44 111,616 --a------ C:\WINDOWS\system32\epktljnl.dll
2008-09-28 09:44 . 2008-09-28 09:44 111,616 --a------ C:\WINDOWS\system32\agdryk.dll
2008-09-28 09:43 . 2008-09-28 09:43 105,984 --a------ C:\WINDOWS\system32\euvcndwv.dll
2008-09-28 08:37 . 2008-09-28 08:37 42,496 --a------ C:\WINDOWS\system32\urqQhhIc.dll
2008-09-28 08:37 . 2008-09-28 08:37 42,496 --a------ C:\WINDOWS\system32\urqNDvsQ.dll
2008-09-27 19:00 . 2008-09-27 19:00 46,080 --a------ C:\WINDOWS\system32\xxyxWNGX.dll
2008-09-27 19:00 . 2008-09-27 19:00 46,080 --a------ C:\WINDOWS\system32\fccARHyy.dll
2008-09-27 18:27 . 2008-09-27 18:27 46,080 --a------ C:\WINDOWS\system32\xxyxusTl.dll
2008-09-27 18:27 . 2008-09-27 18:27 46,080 --a------ C:\WINDOWS\system32\awtsSlmL.dll
2008-09-27 18:26 . 2008-09-27 18:26 155,648 --a------ C:\WINDOWS\system32\qayfrxfo.dll
2008-09-27 18:09 . 2008-09-27 18:09 155,648 --a------ C:\WINDOWS\system32\ubtnypty.dll
2008-09-27 18:09 . 2008-09-27 18:09 107,008 --a------ C:\WINDOWS\system32\wfmfoavm.dll
2008-09-27 18:08 . 2008-09-27 18:08 155,648 --a------ C:\WINDOWS\system32\tklhyjjf.dll
2008-09-27 18:06 . 2008-09-27 18:06 107,008 --a------ C:\WINDOWS\system32\dmvjlulc.dll
2008-09-27 18:05 . 2008-09-28 10:46 875,566 --ahs---- C:\WINDOWS\system32\FeKmWvut.ini2
2008-09-27 18:05 . 2008-09-28 10:46 875,566 --ahs---- C:\WINDOWS\system32\FeKmWvut.ini
2008-09-27 18:05 . 2008-09-27 18:05 253,440 --a------ C:\WINDOWS\system32\tuvWmKeF.dll
2008-09-26 17:58 . 2008-09-27 10:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-26 10:28 . 2008-09-27 08:57 427 --a------ C:\WINDOWS\wininit.ini
2008-09-26 07:19 . 2008-09-26 07:19 <DIR> d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-09-25 13:46 . 2007-08-13 18:45 78,336 --a--c--- C:\WINDOWS\system32\dllcache\ieencode.dll
2008-09-25 13:00 . 2008-09-25 13:00 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-09-23 21:27 . 2008-09-23 21:27 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Avanquest
2008-09-23 21:26 . 2008-09-23 21:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-09-23 21:21 . 2008-09-23 21:21 <DIR> dr-hs---- C:\_Backup.RC
2008-09-23 21:21 . 2008-09-24 00:20 <DIR> d--h----- C:\_Backup
2008-09-23 21:19 . 2008-09-23 21:19 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Avanquest
2008-09-23 21:14 . 2008-09-23 21:14 <DIR> d-------- C:\Program Files\Avanquest
2008-09-23 21:10 . 2008-09-23 21:10 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-22 20:28 . 2008-09-23 20:36 921,005 --ahs---- C:\WINDOWS\system32\fcmlcxix.ini
2008-09-22 20:25 . 2008-09-22 20:25 99,328 --a------ C:\WINDOWS\system32\elbyvebf.dll
2008-09-22 14:28 . 2008-09-22 14:28 879,630 --ahs---- C:\WINDOWS\system32\ifvyfbwc.ini
2008-09-22 14:25 . 2008-09-22 14:25 113,152 --a------ C:\WINDOWS\system32\pgnvgrox.dll
2008-09-22 14:25 . 2008-09-22 14:25 113,152 --a------ C:\WINDOWS\system32\cguzet.dll
2008-09-22 14:23 . 2008-09-22 14:23 99,328 --a------ C:\WINDOWS\system32\ylxxhiob.dll
2008-09-22 14:19 . 2008-09-22 14:22 879,570 --ahs---- C:\WINDOWS\system32\gbkfunct.ini
2008-09-22 14:16 . 2008-09-26 10:33 876,630 --ahs---- C:\WINDOWS\system32\TAyJlUtv.ini2
2008-09-22 14:16 . 2008-09-26 10:34 876,630 --ahs---- C:\WINDOWS\system32\TAyJlUtv.ini
2008-09-22 14:16 . 2008-09-22 14:16 99,328 --a------ C:\WINDOWS\system32\baieqfob.dll
2008-09-22 14:10 . 2008-09-22 14:10 43,008 --a------ C:\WINDOWS\system32\ssqNHwTm.dll
2008-09-21 17:23 . 2004-08-30 21:00 365,568 --a------ C:\WINDOWS\system32\doskeys.exe
2008-09-21 17:23 . 2008-09-21 17:23 51,712 --a------ C:\WINDOWS\system32\dllhosts.exe
2008-09-21 17:23 . 2008-09-28 10:37 215 --a------ C:\WINDOWS\system32\Monitored2.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-28 17:53 --------- d-----w C:\Program Files\QuickTime
2008-09-28 16:31 --------- d-----w C:\Program Files\Zinio
2008-09-28 16:31 --------- d-----w C:\Program Files\iTunes
2008-09-28 16:31 --------- d-----w C:\Program Files\Digital Media Reader
2008-09-27 03:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\CanonIJPLM
2008-09-27 01:12 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-26 16:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-25 22:30 --------- d-----w C:\Program Files\xxx.xxx
2008-09-25 19:47 --------- d-----w C:\Program Files\Opera
2008-09-24 02:55 --------- d-----w C:\Program Files\Symantec
2008-09-24 02:28 --------- d-----w C:\Program Files\Photo Manager
2008-09-24 02:17 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-22 00:02 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2008-08-24 16:43 --------- d-----w C:\Program Files\Sun
2008-08-24 16:42 --------- d-----w C:\Program Files\Java
2008-03-26 15:20 228,336 -c--a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-03-09 01:48 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2005-12-18 18:20 0 -c--a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
2002-07-26 22:02 153,088 -c--a-w C:\Program Files\UNWISE.EXE
.
((((((((((((((((((((((((((((( snapshot@2008-09-27_12.33.38.84 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-07-09 15:50:42 155,648 -c--a-w C:\windows\system32\NeroCheck.exe
+ 2004-03-10 21:26:10 406,016 -c--a-w C:\windows\system32\PSDrvCheck.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00BA82ED-AF2F-40BD-995C-320BBD6A509e}]
2008-09-27 18:26 155648 --a------ C:\windows\system32\qayfrxfo.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca3a2052-0769-4c60-a246-99628fb3eb7c}]
2008-09-28 09:44 111616 --a------ C:\windows\system32\agdryk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CAA91B0C-B261-4328-B3C1-07F4E5D8F3E9}]
2008-09-27 18:05 253440 --a------ C:\windows\system32\tuvWmKeF.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E538488B-36AB-42FF-8498-271810C9C599}]
2008-09-22 14:10 43008 --a------ C:\windows\system32\ssqNHwTm.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="C:\windows\system32\dumprep 0 -u" [X]
"HostManager"="C:\Program Files\Common Files\AOL\1191778237\ee\AOLSoftware.exe" [2006-09-25 50736]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"LVCOMSX"="C:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"VirusScannerPro"="C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe" [2008-08-26 173312]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-10-02 67488]
"5417482f"="C:\windows\system32\lubrmqjd.dll" [2008-09-28 78848]
"BM57247bb3"="C:\windows\system32\euvcndwv.dll" [2008-09-28 105984]
"ShowWnd"="ShowWnd.exe" [2003-09-19 C:\WINDOWS\ShowWnd.exe]
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"NT Printing Services6"="dllhosts.exe" [2008-09-21 C:\WINDOWS\system32\dllhosts.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{E538488B-36AB-42FF-8498-271810C9C599}"= "C:\windows\system32\ssqNHwTm.dll" [2008-09-22 43008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqNHwTm]
2008-09-22 14:10 43008 C:\WINDOWS\system32\ssqNHwTm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 LStone;Pinnacle Systems Studio AV/DV Overlay;C:\windows\system32\DRIVERS\lstone2k.sys [2002-12-10 11:20]
R3 I97DRIVER;I97DRIVER;C:\PROGRA~1\AVANQU~1\Fix-It\dgs.sys [2007-08-31 11:18]
S1 MemAlloc;MemAlloc;C:\windows\system32\DRIVERS\memalloc.sys [2002-08-26 04:51]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 14:46]
S2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 09:20]
S3 MailScan;MailScan;C:\PROGRA~1\AVANQU~1\Fix-It\MailScan.sys [2008-08-26 14:14]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17147075-1ead-11d9-bea6-806d6172696f}]
\Shell\AutoRun\command - F:\cdplayer.exe
*Newly Created Service* - MAILSCAN
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-AOLAspSunset - C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-28 10:54:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\windows\system32\winlogon.exe
-> C:\windows\system32\ssqNHwTm.dll
PROCESS: C:\windows\explorer.exe
-> C:\windows\system32\lubrmqjd.dll
-> C:\windows\system32\euvcndwv.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\AOL\acs\AOLacsd.exe
C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\BigFix\BigFix.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-09-28 11:05:04 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-09-28 18:04:55
ComboFix2.txt 2008-09-27 19:36:10
Pre-Run: 117,386,391,552 bytes free
Post-Run: 117,369,040,896 bytes free
422 --- E O F --- 2008-09-10 10:01:09
ComboFix 08-09-26.06 - Owner 2008-09-28 10:46:21.3 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\windows\BM57247bb3.txt
C:\WINDOWS\system32\akcskd.dll
C:\WINDOWS\system32\aqkrohsi.ini
C:\WINDOWS\system32\blqsdmbn.dll
C:\WINDOWS\system32\bskxlmrh.ini
C:\WINDOWS\system32\btedxycx.dll
C:\WINDOWS\system32\bwfytjkn.dll
C:\WINDOWS\system32\cdezcp.dll
C:\WINDOWS\system32\cfioldln.ini
C:\WINDOWS\system32\ddLUvyay.ini
C:\WINDOWS\system32\ddLUvyay.ini2
C:\WINDOWS\system32\dldjdgpb.dll
C:\WINDOWS\system32\dowdrmdm.dll
C:\WINDOWS\system32\epttasrt.dll
C:\WINDOWS\system32\eqlrtjwc.dll
C:\WINDOWS\system32\eysijgoc.dll
C:\WINDOWS\system32\ffmlux.dll
C:\WINDOWS\system32\fiqhlfgs.ini
C:\WINDOWS\system32\frjdpkfp.dll
C:\WINDOWS\system32\gcfkfrvj.dll
C:\WINDOWS\system32\gndewlnl.ini
C:\WINDOWS\system32\gogtflpg.dll
C:\WINDOWS\system32\gsybahph.dll
C:\WINDOWS\system32\hejwhasx.dll
C:\WINDOWS\system32\hfbpzu.dll
C:\WINDOWS\system32\hggeBsPj.dll
C:\WINDOWS\system32\hijyqy.dll
C:\WINDOWS\system32\hjrcmntv.dll
C:\WINDOWS\system32\hohqil.dll
C:\WINDOWS\system32\hpepyvtt.dll
C:\WINDOWS\system32\htyoltvx.dll
C:\WINDOWS\system32\hucofkti.dll
C:\WINDOWS\system32\hxwaap.dll
C:\WINDOWS\system32\hyuxwaak.ini
C:\WINDOWS\system32\iacgms.dll
C:\WINDOWS\system32\icpwhfeh.ini
C:\WINDOWS\system32\ieencode.dll
C:\WINDOWS\system32\iiFUmMfd.dll
C:\WINDOWS\system32\iiqnshct.ini
C:\WINDOWS\system32\jahxmi.dll
C:\WINDOWS\system32\jbksnxhl.dll
C:\WINDOWS\system32\jdsyhtrr.dll
C:\WINDOWS\system32\jflphxuo.dll
C:\WINDOWS\system32\jihrwqmq.dll
C:\WINDOWS\system32\kesxfccs.dll
C:\WINDOWS\system32\khfDTNEt.dll
C:\WINDOWS\system32\knvknwjd.dll
C:\WINDOWS\system32\kugnlc.dll
C:\WINDOWS\system32\kxkgphkq.dll
C:\WINDOWS\system32\kyikvrpi.dll
C:\WINDOWS\system32\lcisicjc.ini
C:\WINDOWS\system32\leulfi.dll
C:\WINDOWS\system32\mcsfqram.dll
C:\WINDOWS\system32\mcuiivho.dll
C:\WINDOWS\system32\mdldtxkb.dll
C:\WINDOWS\system32\mdygoxfe.dll
C:\WINDOWS\system32\mskqmb.dll
C:\WINDOWS\system32\nghlvivg.dll
C:\WINDOWS\system32\niesnuco.ini
C:\WINDOWS\system32\njslkici.dll
C:\WINDOWS\system32\nmemoh.dll
C:\WINDOWS\system32\nnicsm.dll
C:\WINDOWS\system32\nnnkJAsP.dll
C:\WINDOWS\system32\nnnoLEWo.dll
C:\WINDOWS\system32\nnnoPgHA.dll
C:\WINDOWS\system32\nrvprgka.dll
C:\WINDOWS\system32\ntcxws.dll
C:\WINDOWS\system32\oikednnm.dll
C:\WINDOWS\system32\omcyibwl.ini
C:\WINDOWS\system32\onlbgw.dll
C:\WINDOWS\system32\pahqhe.dll
C:\WINDOWS\system32\pbbwacnk.dll
C:\WINDOWS\system32\phmkln.dll
C:\WINDOWS\system32\pwhepwsr.dll
C:\WINDOWS\system32\qkiizc.dll
C:\WINDOWS\system32\qlnbcmqq.dll
C:\WINDOWS\system32\qpityipw.ini
C:\WINDOWS\system32\qtpfopgn.dll
C:\WINDOWS\system32\rcajwmty.dll
C:\WINDOWS\system32\rcuiue.dll
C:\WINDOWS\system32\rgkjuxjs.dll
C:\WINDOWS\system32\rqRhIBSk.dll
C:\WINDOWS\system32\rqRIxuTM.dll
C:\WINDOWS\system32\scckgugp.ini
C:\WINDOWS\system32\sdxhrljf.dll
C:\WINDOWS\system32\srqginiw.ini
C:\WINDOWS\system32\sSmjiiIx.dll
C:\WINDOWS\system32\swgatpcp.ini
C:\WINDOWS\system32\swlhpwhw.dll
C:\WINDOWS\system32\sxksoonm.dll
C:\WINDOWS\system32\tcgqauvy.ini
C:\WINDOWS\system32\tchsnqii.dll
C:\WINDOWS\system32\tehogmas.dll
C:\WINDOWS\system32\tmgaebio.dll
C:\WINDOWS\system32\ujyjlj.dll
C:\WINDOWS\system32\vfexxy.dll
C:\WINDOWS\system32\vhypgmdj.dll
C:\WINDOWS\system32\vobkrdoi.dll
C:\WINDOWS\system32\vppgnbit.dll
C:\WINDOWS\system32\vsalhfng.dll
C:\WINDOWS\system32\winigqrs.dll
C:\WINDOWS\system32\wokfjqqd.ini
C:\WINDOWS\system32\xacykm.dll
C:\WINDOWS\system32\xcbwtqed.dll
C:\WINDOWS\system32\xIiijmSs.ini
C:\WINDOWS\system32\xIiijmSs.ini2
C:\WINDOWS\system32\XIOVxyxx.ini
C:\WINDOWS\system32\XIOVxyxx.ini2
C:\WINDOWS\system32\xjbmwcgl.dll
C:\WINDOWS\system32\xtcbmxkr.ini
C:\WINDOWS\system32\xtvdjaij.ini
C:\WINDOWS\system32\ydpoidih.ini
C:\WINDOWS\system32\ytmwjacr.ini
C:\WINDOWS\system32\yvwepumr.dll
C:\WINDOWS\system32\zewzrl.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\windows\BM57247bb3.txt
C:\windows\BM57247bb3.xml
C:\windows\pskt.ini
C:\WINDOWS\system32\ieencode.dll
.
---- Previous Run -------
.
C:\Program Files\ewido anti-spyware 4.0
C:\Program Files\ewido anti-spyware 4.0\updater.ewidolog
C:\windows\BM57247bb3.txt
C:\windows\pskt.ini
C:\WINDOWS\system32\akcskd.dll
C:\WINDOWS\system32\aqkrohsi.ini
C:\WINDOWS\system32\blqsdmbn.dll
C:\WINDOWS\system32\bskxlmrh.ini
C:\WINDOWS\system32\btedxycx.dll
C:\WINDOWS\system32\bwfytjkn.dll
C:\WINDOWS\system32\cdezcp.dll
C:\WINDOWS\system32\cfioldln.ini
C:\WINDOWS\system32\ddLUvyay.ini
C:\WINDOWS\system32\ddLUvyay.ini2
C:\WINDOWS\system32\dldjdgpb.dll
C:\WINDOWS\system32\dowdrmdm.dll
C:\WINDOWS\system32\epttasrt.dll
C:\WINDOWS\system32\eqlrtjwc.dll
C:\WINDOWS\system32\eysijgoc.dll
C:\WINDOWS\system32\ffmlux.dll
C:\WINDOWS\system32\fiqhlfgs.ini
C:\WINDOWS\system32\frjdpkfp.dll
C:\WINDOWS\system32\gcfkfrvj.dll
C:\WINDOWS\system32\gndewlnl.ini
C:\WINDOWS\system32\gogtflpg.dll
C:\WINDOWS\system32\gsybahph.dll
C:\WINDOWS\system32\hejwhasx.dll
C:\WINDOWS\system32\hfbpzu.dll
C:\WINDOWS\system32\hggeBsPj.dll
C:\WINDOWS\system32\hijyqy.dll
C:\WINDOWS\system32\hjrcmntv.dll
C:\WINDOWS\system32\hohqil.dll
C:\WINDOWS\system32\hpepyvtt.dll
C:\WINDOWS\system32\htyoltvx.dll
C:\WINDOWS\system32\hucofkti.dll
C:\WINDOWS\system32\hxwaap.dll
C:\WINDOWS\system32\hyuxwaak.ini
C:\WINDOWS\system32\iacgms.dll
C:\WINDOWS\system32\icpwhfeh.ini
C:\WINDOWS\system32\ieencode.dll
C:\WINDOWS\system32\iiFUmMfd.dll
C:\WINDOWS\system32\iiqnshct.ini
C:\WINDOWS\system32\jahxmi.dll
C:\WINDOWS\system32\jbksnxhl.dll
C:\WINDOWS\system32\jdsyhtrr.dll
C:\WINDOWS\system32\jflphxuo.dll
C:\WINDOWS\system32\jihrwqmq.dll
C:\WINDOWS\system32\kesxfccs.dll
C:\WINDOWS\system32\khfDTNEt.dll
C:\WINDOWS\system32\knvknwjd.dll
C:\WINDOWS\system32\kugnlc.dll
C:\WINDOWS\system32\kxkgphkq.dll
C:\WINDOWS\system32\kyikvrpi.dll
C:\WINDOWS\system32\lcisicjc.ini
C:\WINDOWS\system32\leulfi.dll
C:\WINDOWS\system32\mcsfqram.dll
C:\WINDOWS\system32\mcuiivho.dll
C:\WINDOWS\system32\mdldtxkb.dll
C:\WINDOWS\system32\mdygoxfe.dll
C:\WINDOWS\system32\mskqmb.dll
C:\WINDOWS\system32\nghlvivg.dll
C:\WINDOWS\system32\niesnuco.ini
C:\WINDOWS\system32\njslkici.dll
C:\WINDOWS\system32\nmemoh.dll
C:\WINDOWS\system32\nnicsm.dll
C:\WINDOWS\system32\nnnkJAsP.dll
C:\WINDOWS\system32\nnnoLEWo.dll
C:\WINDOWS\system32\nnnoPgHA.dll
C:\WINDOWS\system32\nrvprgka.dll
C:\WINDOWS\system32\ntcxws.dll
C:\WINDOWS\system32\oikednnm.dll
C:\WINDOWS\system32\omcyibwl.ini
C:\WINDOWS\system32\onlbgw.dll
C:\WINDOWS\system32\pahqhe.dll
C:\WINDOWS\system32\pbbwacnk.dll
C:\WINDOWS\system32\phmkln.dll
C:\WINDOWS\system32\pwhepwsr.dll
C:\WINDOWS\system32\qkiizc.dll
C:\WINDOWS\system32\qlnbcmqq.dll
C:\WINDOWS\system32\qpityipw.ini
C:\WINDOWS\system32\qtpfopgn.dll
C:\WINDOWS\system32\rcajwmty.dll
C:\WINDOWS\system32\rcuiue.dll
C:\WINDOWS\system32\rgkjuxjs.dll
C:\WINDOWS\system32\rqRhIBSk.dll
C:\WINDOWS\system32\rqRIxuTM.dll
C:\WINDOWS\system32\scckgugp.ini
C:\WINDOWS\system32\sdxhrljf.dll
C:\WINDOWS\system32\srqginiw.ini
C:\WINDOWS\system32\sSmjiiIx.dll
C:\WINDOWS\system32\swgatpcp.ini
C:\WINDOWS\system32\swlhpwhw.dll
C:\WINDOWS\system32\sxksoonm.dll
C:\WINDOWS\system32\tcgqauvy.ini
C:\WINDOWS\system32\tchsnqii.dll
C:\WINDOWS\system32\tehogmas.dll
C:\WINDOWS\system32\tmgaebio.dll
C:\WINDOWS\system32\ujyjlj.dll
C:\WINDOWS\system32\vfexxy.dll
C:\WINDOWS\system32\vhypgmdj.dll
C:\WINDOWS\system32\vobkrdoi.dll
C:\WINDOWS\system32\vppgnbit.dll
C:\WINDOWS\system32\vsalhfng.dll
C:\WINDOWS\system32\winigqrs.dll
C:\WINDOWS\system32\wokfjqqd.ini
C:\WINDOWS\system32\xacykm.dll
C:\WINDOWS\system32\xcbwtqed.dll
C:\WINDOWS\system32\xIiijmSs.ini
C:\WINDOWS\system32\xIiijmSs.ini2
C:\WINDOWS\system32\XIOVxyxx.ini
C:\WINDOWS\system32\XIOVxyxx.ini2
C:\WINDOWS\system32\xjbmwcgl.dll
C:\WINDOWS\system32\xtcbmxkr.ini
C:\WINDOWS\system32\xtvdjaij.ini
C:\WINDOWS\system32\ydpoidih.ini
C:\WINDOWS\system32\ytmwjacr.ini
C:\WINDOWS\system32\yvwepumr.dll
C:\WINDOWS\system32\zewzrl.dll
.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-28 )))))))))))))))))))))))))))))))
.
2008-09-28 10:21 . 2008-09-28 10:21 42,496 --a------ C:\WINDOWS\system32\wvUljHAt.dll
2008-09-28 10:21 . 2008-09-28 10:21 42,496 --a------ C:\WINDOWS\system32\tuvWnoMf.dll
2008-09-28 09:47 . 2008-09-28 09:47 988,183 ---hs---- C:\WINDOWS\system32\djqmrbul.ini
2008-09-28 09:47 . 2008-09-28 09:47 78,848 --a------ C:\WINDOWS\system32\lubrmqjd.dll
2008-09-28 09:44 . 2008-09-28 09:44 111,616 --a------ C:\WINDOWS\system32\epktljnl.dll
2008-09-28 09:44 . 2008-09-28 09:44 111,616 --a------ C:\WINDOWS\system32\agdryk.dll
2008-09-28 09:43 . 2008-09-28 09:43 105,984 --a------ C:\WINDOWS\system32\euvcndwv.dll
2008-09-28 08:37 . 2008-09-28 08:37 42,496 --a------ C:\WINDOWS\system32\urqQhhIc.dll
2008-09-28 08:37 . 2008-09-28 08:37 42,496 --a------ C:\WINDOWS\system32\urqNDvsQ.dll
2008-09-27 19:00 . 2008-09-27 19:00 46,080 --a------ C:\WINDOWS\system32\xxyxWNGX.dll
2008-09-27 19:00 . 2008-09-27 19:00 46,080 --a------ C:\WINDOWS\system32\fccARHyy.dll
2008-09-27 18:27 . 2008-09-27 18:27 46,080 --a------ C:\WINDOWS\system32\xxyxusTl.dll
2008-09-27 18:27 . 2008-09-27 18:27 46,080 --a------ C:\WINDOWS\system32\awtsSlmL.dll
2008-09-27 18:26 . 2008-09-27 18:26 155,648 --a------ C:\WINDOWS\system32\qayfrxfo.dll
2008-09-27 18:09 . 2008-09-27 18:09 155,648 --a------ C:\WINDOWS\system32\ubtnypty.dll
2008-09-27 18:09 . 2008-09-27 18:09 107,008 --a------ C:\WINDOWS\system32\wfmfoavm.dll
2008-09-27 18:08 . 2008-09-27 18:08 155,648 --a------ C:\WINDOWS\system32\tklhyjjf.dll
2008-09-27 18:06 . 2008-09-27 18:06 107,008 --a------ C:\WINDOWS\system32\dmvjlulc.dll
2008-09-27 18:05 . 2008-09-28 10:46 875,566 --ahs---- C:\WINDOWS\system32\FeKmWvut.ini2
2008-09-27 18:05 . 2008-09-28 10:46 875,566 --ahs---- C:\WINDOWS\system32\FeKmWvut.ini
2008-09-27 18:05 . 2008-09-27 18:05 253,440 --a------ C:\WINDOWS\system32\tuvWmKeF.dll
2008-09-26 17:58 . 2008-09-27 10:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-26 10:28 . 2008-09-27 08:57 427 --a------ C:\WINDOWS\wininit.ini
2008-09-26 07:19 . 2008-09-26 07:19 <DIR> d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-09-25 13:46 . 2007-08-13 18:45 78,336 --a--c--- C:\WINDOWS\system32\dllcache\ieencode.dll
2008-09-25 13:00 . 2008-09-25 13:00 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-09-23 21:27 . 2008-09-23 21:27 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Avanquest
2008-09-23 21:26 . 2008-09-23 21:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-09-23 21:21 . 2008-09-23 21:21 <DIR> dr-hs---- C:\_Backup.RC
2008-09-23 21:21 . 2008-09-24 00:20 <DIR> d--h----- C:\_Backup
2008-09-23 21:19 . 2008-09-23 21:19 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Avanquest
2008-09-23 21:14 . 2008-09-23 21:14 <DIR> d-------- C:\Program Files\Avanquest
2008-09-23 21:10 . 2008-09-23 21:10 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-22 20:28 . 2008-09-23 20:36 921,005 --ahs---- C:\WINDOWS\system32\fcmlcxix.ini
2008-09-22 20:25 . 2008-09-22 20:25 99,328 --a------ C:\WINDOWS\system32\elbyvebf.dll
2008-09-22 14:28 . 2008-09-22 14:28 879,630 --ahs---- C:\WINDOWS\system32\ifvyfbwc.ini
2008-09-22 14:25 . 2008-09-22 14:25 113,152 --a------ C:\WINDOWS\system32\pgnvgrox.dll
2008-09-22 14:25 . 2008-09-22 14:25 113,152 --a------ C:\WINDOWS\system32\cguzet.dll
2008-09-22 14:23 . 2008-09-22 14:23 99,328 --a------ C:\WINDOWS\system32\ylxxhiob.dll
2008-09-22 14:19 . 2008-09-22 14:22 879,570 --ahs---- C:\WINDOWS\system32\gbkfunct.ini
2008-09-22 14:16 . 2008-09-26 10:33 876,630 --ahs---- C:\WINDOWS\system32\TAyJlUtv.ini2
2008-09-22 14:16 . 2008-09-26 10:34 876,630 --ahs---- C:\WINDOWS\system32\TAyJlUtv.ini
2008-09-22 14:16 . 2008-09-22 14:16 99,328 --a------ C:\WINDOWS\system32\baieqfob.dll
2008-09-22 14:10 . 2008-09-22 14:10 43,008 --a------ C:\WINDOWS\system32\ssqNHwTm.dll
2008-09-21 17:23 . 2004-08-30 21:00 365,568 --a------ C:\WINDOWS\system32\doskeys.exe
2008-09-21 17:23 . 2008-09-21 17:23 51,712 --a------ C:\WINDOWS\system32\dllhosts.exe
2008-09-21 17:23 . 2008-09-28 10:37 215 --a------ C:\WINDOWS\system32\Monitored2.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-28 17:53 --------- d-----w C:\Program Files\QuickTime
2008-09-28 16:31 --------- d-----w C:\Program Files\Zinio
2008-09-28 16:31 --------- d-----w C:\Program Files\iTunes
2008-09-28 16:31 --------- d-----w C:\Program Files\Digital Media Reader
2008-09-27 03:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\CanonIJPLM
2008-09-27 01:12 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-26 16:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-25 22:30 --------- d-----w C:\Program Files\xxx.xxx
2008-09-25 19:47 --------- d-----w C:\Program Files\Opera
2008-09-24 02:55 --------- d-----w C:\Program Files\Symantec
2008-09-24 02:28 --------- d-----w C:\Program Files\Photo Manager
2008-09-24 02:17 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-22 00:02 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2008-08-24 16:43 --------- d-----w C:\Program Files\Sun
2008-08-24 16:42 --------- d-----w C:\Program Files\Java
2008-03-26 15:20 228,336 -c--a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-03-09 01:48 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2005-12-18 18:20 0 -c--a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
2002-07-26 22:02 153,088 -c--a-w C:\Program Files\UNWISE.EXE
.
((((((((((((((((((((((((((((( snapshot@2008-09-27_12.33.38.84 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-07-09 15:50:42 155,648 -c--a-w C:\windows\system32\NeroCheck.exe
+ 2004-03-10 21:26:10 406,016 -c--a-w C:\windows\system32\PSDrvCheck.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00BA82ED-AF2F-40BD-995C-320BBD6A509e}]
2008-09-27 18:26 155648 --a------ C:\windows\system32\qayfrxfo.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca3a2052-0769-4c60-a246-99628fb3eb7c}]
2008-09-28 09:44 111616 --a------ C:\windows\system32\agdryk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CAA91B0C-B261-4328-B3C1-07F4E5D8F3E9}]
2008-09-27 18:05 253440 --a------ C:\windows\system32\tuvWmKeF.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E538488B-36AB-42FF-8498-271810C9C599}]
2008-09-22 14:10 43008 --a------ C:\windows\system32\ssqNHwTm.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="C:\windows\system32\dumprep 0 -u" [X]
"HostManager"="C:\Program Files\Common Files\AOL\1191778237\ee\AOLSoftware.exe" [2006-09-25 50736]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"LVCOMSX"="C:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"VirusScannerPro"="C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe" [2008-08-26 173312]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-10-02 67488]
"5417482f"="C:\windows\system32\lubrmqjd.dll" [2008-09-28 78848]
"BM57247bb3"="C:\windows\system32\euvcndwv.dll" [2008-09-28 105984]
"ShowWnd"="ShowWnd.exe" [2003-09-19 C:\WINDOWS\ShowWnd.exe]
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"NT Printing Services6"="dllhosts.exe" [2008-09-21 C:\WINDOWS\system32\dllhosts.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{E538488B-36AB-42FF-8498-271810C9C599}"= "C:\windows\system32\ssqNHwTm.dll" [2008-09-22 43008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqNHwTm]
2008-09-22 14:10 43008 C:\WINDOWS\system32\ssqNHwTm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 LStone;Pinnacle Systems Studio AV/DV Overlay;C:\windows\system32\DRIVERS\lstone2k.sys [2002-12-10 11:20]
R3 I97DRIVER;I97DRIVER;C:\PROGRA~1\AVANQU~1\Fix-It\dgs.sys [2007-08-31 11:18]
S1 MemAlloc;MemAlloc;C:\windows\system32\DRIVERS\memalloc.sys [2002-08-26 04:51]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 14:46]
S2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 09:20]
S3 MailScan;MailScan;C:\PROGRA~1\AVANQU~1\Fix-It\MailScan.sys [2008-08-26 14:14]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17147075-1ead-11d9-bea6-806d6172696f}]
\Shell\AutoRun\command - F:\cdplayer.exe
*Newly Created Service* - MAILSCAN
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-AOLAspSunset - C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-28 10:54:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\windows\system32\winlogon.exe
-> C:\windows\system32\ssqNHwTm.dll
PROCESS: C:\windows\explorer.exe
-> C:\windows\system32\lubrmqjd.dll
-> C:\windows\system32\euvcndwv.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\AOL\acs\AOLacsd.exe
C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\BigFix\BigFix.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-09-28 11:05:04 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-09-28 18:04:55
ComboFix2.txt 2008-09-27 19:36:10
Pre-Run: 117,386,391,552 bytes free
Post-Run: 117,369,040,896 bytes free
422 --- E O F --- 2008-09-10 10:01:09
ComboFix 08-09-26.06 - Owner 2008-09-28 10:46:21.3 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\windows\BM57247bb3.txt
C:\WINDOWS\system32\akcskd.dll
C:\WINDOWS\system32\aqkrohsi.ini
C:\WINDOWS\system32\blqsdmbn.dll
C:\WINDOWS\system32\bskxlmrh.ini
C:\WINDOWS\system32\btedxycx.dll
C:\WINDOWS\system32\bwfytjkn.dll
C:\WINDOWS\system32\cdezcp.dll
C:\WINDOWS\system32\cfioldln.ini
C:\WINDOWS\system32\ddLUvyay.ini
C:\WINDOWS\system32\ddLUvyay.ini2
C:\WINDOWS\system32\dldjdgpb.dll
C:\WINDOWS\system32\dowdrmdm.dll
C:\WINDOWS\system32\epttasrt.dll
C:\WINDOWS\system32\eqlrtjwc.dll
C:\WINDOWS\system32\eysijgoc.dll
C:\WINDOWS\system32\ffmlux.dll
C:\WINDOWS\system32\fiqhlfgs.ini
C:\WINDOWS\system32\frjdpkfp.dll
C:\WINDOWS\system32\gcfkfrvj.dll
C:\WINDOWS\system32\gndewlnl.ini
C:\WINDOWS\system32\gogtflpg.dll
C:\WINDOWS\system32\gsybahph.dll
C:\WINDOWS\system32\hejwhasx.dll
C:\WINDOWS\system32\hfbpzu.dll
C:\WINDOWS\system32\hggeBsPj.dll
C:\WINDOWS\system32\hijyqy.dll
C:\WINDOWS\system32\hjrcmntv.dll
C:\WINDOWS\system32\hohqil.dll
C:\WINDOWS\system32\hpepyvtt.dll
C:\WINDOWS\system32\htyoltvx.dll
C:\WINDOWS\system32\hucofkti.dll
C:\WINDOWS\system32\hxwaap.dll
C:\WINDOWS\system32\hyuxwaak.ini
C:\WINDOWS\system32\iacgms.dll
C:\WINDOWS\system32\icpwhfeh.ini
C:\WINDOWS\system32\ieencode.dll
C:\WINDOWS\system32\iiFUmMfd.dll
C:\WINDOWS\system32\iiqnshct.ini
C:\WINDOWS\system32\jahxmi.dll
C:\WINDOWS\system32\jbksnxhl.dll
C:\WINDOWS\system32\jdsyhtrr.dll
C:\WINDOWS\system32\jflphxuo.dll
C:\WINDOWS\system32\jihrwqmq.dll
C:\WINDOWS\system32\kesxfccs.dll
C:\WINDOWS\system32\khfDTNEt.dll
C:\WINDOWS\system32\knvknwjd.dll
C:\WINDOWS\system32\kugnlc.dll
C:\WINDOWS\system32\kxkgphkq.dll
C:\WINDOWS\system32\kyikvrpi.dll
C:\WINDOWS\system32\lcisicjc.ini
C:\WINDOWS\system32\leulfi.dll
C:\WINDOWS\system32\mcsfqram.dll
C:\WINDOWS\system32\mcuiivho.dll
C:\WINDOWS\system32\mdldtxkb.dll
C:\WINDOWS\system32\mdygoxfe.dll
C:\WINDOWS\system32\mskqmb.dll
C:\WINDOWS\system32\nghlvivg.dll
C:\WINDOWS\system32\niesnuco.ini
C:\WINDOWS\system32\njslkici.dll
C:\WINDOWS\system32\nmemoh.dll
C:\WINDOWS\system32\nnicsm.dll
C:\WINDOWS\system32\nnnkJAsP.dll
C:\WINDOWS\system32\nnnoLEWo.dll
C:\WINDOWS\system32\nnnoPgHA.dll
C:\WINDOWS\system32\nrvprgka.dll
C:\WINDOWS\system32\ntcxws.dll
C:\WINDOWS\system32\oikednnm.dll
C:\WINDOWS\system32\omcyibwl.ini
C:\WINDOWS\system32\onlbgw.dll
C:\WINDOWS\system32\pahqhe.dll
C:\WINDOWS\system32\pbbwacnk.dll
C:\WINDOWS\system32\phmkln.dll
C:\WINDOWS\system32\pwhepwsr.dll
C:\WINDOWS\system32\qkiizc.dll
C:\WINDOWS\system32\qlnbcmqq.dll
C:\WINDOWS\system32\qpityipw.ini
C:\WINDOWS\system32\qtpfopgn.dll
C:\WINDOWS\system32\rcajwmty.dll
C:\WINDOWS\system32\rcuiue.dll
C:\WINDOWS\system32\rgkjuxjs.dll
C:\WINDOWS\system32\rqRhIBSk.dll
C:\WINDOWS\system32\rqRIxuTM.dll
C:\WINDOWS\system32\scckgugp.ini
C:\WINDOWS\system32\sdxhrljf.dll
C:\WINDOWS\system32\srqginiw.ini
C:\WINDOWS\system32\sSmjiiIx.dll
C:\WINDOWS\system32\swgatpcp.ini
C:\WINDOWS\system32\swlhpwhw.dll
C:\WINDOWS\system32\sxksoonm.dll
C:\WINDOWS\system32\tcgqauvy.ini
C:\WINDOWS\system32\tchsnqii.dll
C:\WINDOWS\system32\tehogmas.dll
C:\WINDOWS\system32\tmgaebio.dll
C:\WINDOWS\system32\ujyjlj.dll
C:\WINDOWS\system32\vfexxy.dll
C:\WINDOWS\system32\vhypgmdj.dll
C:\WINDOWS\system32\vobkrdoi.dll
C:\WINDOWS\system32\vppgnbit.dll
C:\WINDOWS\system32\vsalhfng.dll
C:\WINDOWS\system32\winigqrs.dll
C:\WINDOWS\system32\wokfjqqd.ini
C:\WINDOWS\system32\xacykm.dll
C:\WINDOWS\system32\xcbwtqed.dll
C:\WINDOWS\system32\xIiijmSs.ini
C:\WINDOWS\system32\xIiijmSs.ini2
C:\WINDOWS\system32\XIOVxyxx.ini
C:\WINDOWS\system32\XIOVxyxx.ini2
C:\WINDOWS\system32\xjbmwcgl.dll
C:\WINDOWS\system32\xtcbmxkr.ini
C:\WINDOWS\system32\xtvdjaij.ini
C:\WINDOWS\system32\ydpoidih.ini
C:\WINDOWS\system32\ytmwjacr.ini
C:\WINDOWS\system32\yvwepumr.dll
C:\WINDOWS\system32\zewzrl.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\windows\BM57247bb3.txt
C:\windows\BM57247bb3.xml
C:\windows\pskt.ini
C:\WINDOWS\system32\ieencode.dll
.
---- Previous Run -------
.
C:\Program Files\ewido anti-spyware 4.0
C:\Program Files\ewido anti-spyware 4.0\updater.ewidolog
C:\windows\BM57247bb3.txt
C:\windows\pskt.ini
C:\WINDOWS\system32\akcskd.dll
C:\WINDOWS\system32\aqkrohsi.ini
C:\WINDOWS\system32\blqsdmbn.dll
C:\WINDOWS\system32\bskxlmrh.ini
C:\WINDOWS\system32\btedxycx.dll
C:\WINDOWS\system32\bwfytjkn.dll
C:\WINDOWS\system32\cdezcp.dll
C:\WINDOWS\system32\cfioldln.ini
C:\WINDOWS\system32\ddLUvyay.ini
C:\WINDOWS\system32\ddLUvyay.ini2
C:\WINDOWS\system32\dldjdgpb.dll
C:\WINDOWS\system32\dowdrmdm.dll
C:\WINDOWS\system32\epttasrt.dll
C:\WINDOWS\system32\eqlrtjwc.dll
C:\WINDOWS\system32\eysijgoc.dll
C:\WINDOWS\system32\ffmlux.dll
C:\WINDOWS\system32\fiqhlfgs.ini
C:\WINDOWS\system32\frjdpkfp.dll
C:\WINDOWS\system32\gcfkfrvj.dll
C:\WINDOWS\system32\gndewlnl.ini
C:\WINDOWS\system32\gogtflpg.dll
C:\WINDOWS\system32\gsybahph.dll
C:\WINDOWS\system32\hejwhasx.dll
C:\WINDOWS\system32\hfbpzu.dll
C:\WINDOWS\system32\hggeBsPj.dll
C:\WINDOWS\system32\hijyqy.dll
C:\WINDOWS\system32\hjrcmntv.dll
C:\WINDOWS\system32\hohqil.dll
C:\WINDOWS\system32\hpepyvtt.dll
C:\WINDOWS\system32\htyoltvx.dll
C:\WINDOWS\system32\hucofkti.dll
C:\WINDOWS\system32\hxwaap.dll
C:\WINDOWS\system32\hyuxwaak.ini
C:\WINDOWS\system32\iacgms.dll
C:\WINDOWS\system32\icpwhfeh.ini
C:\WINDOWS\system32\ieencode.dll
C:\WINDOWS\system32\iiFUmMfd.dll
C:\WINDOWS\system32\iiqnshct.ini
C:\WINDOWS\system32\jahxmi.dll
C:\WINDOWS\system32\jbksnxhl.dll
C:\WINDOWS\system32\jdsyhtrr.dll
C:\WINDOWS\system32\jflphxuo.dll
C:\WINDOWS\system32\jihrwqmq.dll
C:\WINDOWS\system32\kesxfccs.dll
C:\WINDOWS\system32\khfDTNEt.dll
C:\WINDOWS\system32\knvknwjd.dll
C:\WINDOWS\system32\kugnlc.dll
C:\WINDOWS\system32\kxkgphkq.dll
C:\WINDOWS\system32\kyikvrpi.dll
C:\WINDOWS\system32\lcisicjc.ini
C:\WINDOWS\system32\leulfi.dll
C:\WINDOWS\system32\mcsfqram.dll
C:\WINDOWS\system32\mcuiivho.dll
C:\WINDOWS\system32\mdldtxkb.dll
C:\WINDOWS\system32\mdygoxfe.dll
C:\WINDOWS\system32\mskqmb.dll
C:\WINDOWS\system32\nghlvivg.dll
C:\WINDOWS\system32\niesnuco.ini
C:\WINDOWS\system32\njslkici.dll
C:\WINDOWS\system32\nmemoh.dll
C:\WINDOWS\system32\nnicsm.dll
C:\WINDOWS\system32\nnnkJAsP.dll
C:\WINDOWS\system32\nnnoLEWo.dll
C:\WINDOWS\system32\nnnoPgHA.dll
C:\WINDOWS\system32\nrvprgka.dll
C:\WINDOWS\system32\ntcxws.dll
C:\WINDOWS\system32\oikednnm.dll
C:\WINDOWS\system32\omcyibwl.ini
C:\WINDOWS\system32\onlbgw.dll
C:\WINDOWS\system32\pahqhe.dll
C:\WINDOWS\system32\pbbwacnk.dll
C:\WINDOWS\system32\phmkln.dll
C:\WINDOWS\system32\pwhepwsr.dll
C:\WINDOWS\system32\qkiizc.dll
C:\WINDOWS\system32\qlnbcmqq.dll
C:\WINDOWS\system32\qpityipw.ini
C:\WINDOWS\system32\qtpfopgn.dll
C:\WINDOWS\system32\rcajwmty.dll
C:\WINDOWS\system32\rcuiue.dll
C:\WINDOWS\system32\rgkjuxjs.dll
C:\WINDOWS\system32\rqRhIBSk.dll
C:\WINDOWS\system32\rqRIxuTM.dll
C:\WINDOWS\system32\scckgugp.ini
C:\WINDOWS\system32\sdxhrljf.dll
C:\WINDOWS\system32\srqginiw.ini
C:\WINDOWS\system32\sSmjiiIx.dll
C:\WINDOWS\system32\swgatpcp.ini
C:\WINDOWS\system32\swlhpwhw.dll
C:\WINDOWS\system32\sxksoonm.dll
C:\WINDOWS\system32\tcgqauvy.ini
C:\WINDOWS\system32\tchsnqii.dll
C:\WINDOWS\system32\tehogmas.dll
C:\WINDOWS\system32\tmgaebio.dll
C:\WINDOWS\system32\ujyjlj.dll
C:\WINDOWS\system32\vfexxy.dll
C:\WINDOWS\system32\vhypgmdj.dll
C:\WINDOWS\system32\vobkrdoi.dll
C:\WINDOWS\system32\vppgnbit.dll
C:\WINDOWS\system32\vsalhfng.dll
C:\WINDOWS\system32\winigqrs.dll
C:\WINDOWS\system32\wokfjqqd.ini
C:\WINDOWS\system32\xacykm.dll
C:\WINDOWS\system32\xcbwtqed.dll
C:\WINDOWS\system32\xIiijmSs.ini
C:\WINDOWS\system32\xIiijmSs.ini2
C:\WINDOWS\system32\XIOVxyxx.ini
C:\WINDOWS\system32\XIOVxyxx.ini2
C:\WINDOWS\system32\xjbmwcgl.dll
C:\WINDOWS\system32\xtcbmxkr.ini
C:\WINDOWS\system32\xtvdjaij.ini
C:\WINDOWS\system32\ydpoidih.ini
C:\WINDOWS\system32\ytmwjacr.ini
C:\WINDOWS\system32\yvwepumr.dll
C:\WINDOWS\system32\zewzrl.dll
.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-28 )))))))))))))))))))))))))))))))
.
2008-09-28 10:21 . 2008-09-28 10:21 42,496 --a------ C:\WINDOWS\system32\wvUljHAt.dll
2008-09-28 10:21 . 2008-09-28 10:21 42,496 --a------ C:\WINDOWS\system32\tuvWnoMf.dll
2008-09-28 09:47 . 2008-09-28 09:47 988,183 ---hs---- C:\WINDOWS\system32\djqmrbul.ini
2008-09-28 09:47 . 2008-09-28 09:47 78,848 --a------ C:\WINDOWS\system32\lubrmqjd.dll
2008-09-28 09:44 . 2008-09-28 09:44 111,616 --a------ C:\WINDOWS\system32\epktljnl.dll
2008-09-28 09:44 . 2008-09-28 09:44 111,616 --a------ C:\WINDOWS\system32\agdryk.dll
2008-09-28 09:43 . 2008-09-28 09:43 105,984 --a------ C:\WINDOWS\system32\euvcndwv.dll
2008-09-28 08:37 . 2008-09-28 08:37 42,496 --a------ C:\WINDOWS\system32\urqQhhIc.dll
2008-09-28 08:37 . 2008-09-28 08:37 42,496 --a------ C:\WINDOWS\system32\urqNDvsQ.dll
2008-09-27 19:00 . 2008-09-27 19:00 46,080 --a------ C:\WINDOWS\system32\xxyxWNGX.dll
2008-09-27 19:00 . 2008-09-27 19:00 46,080 --a------ C:\WINDOWS\system32\fccARHyy.dll
2008-09-27 18:27 . 2008-09-27 18:27 46,080 --a------ C:\WINDOWS\system32\xxyxusTl.dll
2008-09-27 18:27 . 2008-09-27 18:27 46,080 --a------ C:\WINDOWS\system32\awtsSlmL.dll
2008-09-27 18:26 . 2008-09-27 18:26 155,648 --a------ C:\WINDOWS\system32\qayfrxfo.dll
2008-09-27 18:09 . 2008-09-27 18:09 155,648 --a------ C:\WINDOWS\system32\ubtnypty.dll
2008-09-27 18:09 . 2008-09-27 18:09 107,008 --a------ C:\WINDOWS\system32\wfmfoavm.dll
2008-09-27 18:08 . 2008-09-27 18:08 155,648 --a------ C:\WINDOWS\system32\tklhyjjf.dll
2008-09-27 18:06 . 2008-09-27 18:06 107,008 --a------ C:\WINDOWS\system32\dmvjlulc.dll
2008-09-27 18:05 . 2008-09-28 10:46 875,566 --ahs---- C:\WINDOWS\system32\FeKmWvut.ini2
2008-09-27 18:05 . 2008-09-28 10:46 875,566 --ahs---- C:\WINDOWS\system32\FeKmWvut.ini
2008-09-27 18:05 . 2008-09-27 18:05 253,440 --a------ C:\WINDOWS\system32\tuvWmKeF.dll
2008-09-26 17:58 . 2008-09-27 10:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-26 10:28 . 2008-09-27 08:57 427 --a------ C:\WINDOWS\wininit.ini
2008-09-26 07:19 . 2008-09-26 07:19 <DIR> d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-09-25 13:46 . 2007-08-13 18:45 78,336 --a--c--- C:\WINDOWS\system32\dllcache\ieencode.dll
2008-09-25 13:00 . 2008-09-25 13:00 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-09-23 21:27 . 2008-09-23 21:27 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Avanquest
2008-09-23 21:26 . 2008-09-23 21:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-09-23 21:21 . 2008-09-23 21:21 <DIR> dr-hs---- C:\_Backup.RC
2008-09-23 21:21 . 2008-09-24 00:20 <DIR> d--h----- C:\_Backup
2008-09-23 21:19 . 2008-09-23 21:19 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Avanquest
2008-09-23 21:14 . 2008-09-23 21:14 <DIR> d-------- C:\Program Files\Avanquest
2008-09-23 21:10 . 2008-09-23 21:10 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-22 20:28 . 2008-09-23 20:36 921,005 --ahs---- C:\WINDOWS\system32\fcmlcxix.ini
2008-09-22 20:25 . 2008-09-22 20:25 99,328 --a------ C:\WINDOWS\system32\elbyvebf.dll
2008-09-22 14:28 . 2008-09-22 14:28 879,630 --ahs---- C:\WINDOWS\system32\ifvyfbwc.ini
2008-09-22 14:25 . 2008-09-22 14:25 113,152 --a------ C:\WINDOWS\system32\pgnvgrox.dll
2008-09-22 14:25 . 2008-09-22 14:25 113,152 --a------ C:\WINDOWS\system32\cguzet.dll
2008-09-22 14:23 . 2008-09-22 14:23 99,328 --a------ C:\WINDOWS\system32\ylxxhiob.dll
2008-09-22 14:19 . 2008-09-22 14:22 879,570 --ahs---- C:\WINDOWS\system32\gbkfunct.ini
2008-09-22 14:16 . 2008-09-26 10:33 876,630 --ahs---- C:\WINDOWS\system32\TAyJlUtv.ini2
2008-09-22 14:16 . 2008-09-26 10:34 876,630 --ahs---- C:\WINDOWS\system32\TAyJlUtv.ini
2008-09-22 14:16 . 2008-09-22 14:16 99,328 --a------ C:\WINDOWS\system32\baieqfob.dll
2008-09-22 14:10 . 2008-09-22 14:10 43,008 --a------ C:\WINDOWS\system32\ssqNHwTm.dll
2008-09-21 17:23 . 2004-08-30 21:00 365,568 --a------ C:\WINDOWS\system32\doskeys.exe
2008-09-21 17:23 . 2008-09-21 17:23 51,712 --a------ C:\WINDOWS\system32\dllhosts.exe
2008-09-21 17:23 . 2008-09-28 10:37 215 --a------ C:\WINDOWS\system32\Monitored2.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-28 17:53 --------- d-----w C:\Program Files\QuickTime
2008-09-28 16:31 --------- d-----w C:\Program Files\Zinio
2008-09-28 16:31 --------- d-----w C:\Program Files\iTunes
2008-09-28 16:31 --------- d-----w C:\Program Files\Digital Media Reader
2008-09-27 03:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\CanonIJPLM
2008-09-27 01:12 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-26 16:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-25 22:30 --------- d-----w C:\Program Files\xxx.xxx
2008-09-25 19:47 --------- d-----w C:\Program Files\Opera
2008-09-24 02:55 --------- d-----w C:\Program Files\Symantec
2008-09-24 02:28 --------- d-----w C:\Program Files\Photo Manager
2008-09-24 02:17 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-22 00:02 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2008-08-24 16:43 --------- d-----w C:\Program Files\Sun
2008-08-24 16:42 --------- d-----w C:\Program Files\Java
2008-03-26 15:20 228,336 -c--a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-03-09 01:48 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2005-12-18 18:20 0 -c--a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
2002-07-26 22:02 153,088 -c--a-w C:\Program Files\UNWISE.EXE
.
((((((((((((((((((((((((((((( snapshot@2008-09-27_12.33.38.84 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-07-09 15:50:42 155,648 -c--a-w C:\windows\system32\NeroCheck.exe
+ 2004-03-10 21:26:10 406,016 -c--a-w C:\windows\system32\PSDrvCheck.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00BA82ED-AF2F-40BD-995C-320BBD6A509e}]
2008-09-27 18:26 155648 --a------ C:\windows\system32\qayfrxfo.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca3a2052-0769-4c60-a246-99628fb3eb7c}]
2008-09-28 09:44 111616 --a------ C:\windows\system32\agdryk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CAA91B0C-B261-4328-B3C1-07F4E5D8F3E9}]
2008-09-27 18:05 253440 --a------ C:\windows\system32\tuvWmKeF.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E538488B-36AB-42FF-8498-271810C9C599}]
2008-09-22 14:10 43008 --a------ C:\windows\system32\ssqNHwTm.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="C:\windows\system32\dumprep 0 -u" [X]
"HostManager"="C:\Program Files\Common Files\AOL\1191778237\ee\AOLSoftware.exe" [2006-09-25 50736]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"LVCOMSX"="C:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"VirusScannerPro"="C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe" [2008-08-26 173312]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-10-02 67488]
"5417482f"="C:\windows\system32\lubrmqjd.dll" [2008-09-28 78848]
"BM57247bb3"="C:\windows\system32\euvcndwv.dll" [2008-09-28 105984]
"ShowWnd"="ShowWnd.exe" [2003-09-19 C:\WINDOWS\ShowWnd.exe]
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"NT Printing Services6"="dllhosts.exe" [2008-09-21 C:\WINDOWS\system32\dllhosts.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{E538488B-36AB-42FF-8498-271810C9C599}"= "C:\windows\system32\ssqNHwTm.dll" [2008-09-22 43008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqNHwTm]
2008-09-22 14:10 43008 C:\WINDOWS\system32\ssqNHwTm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 LStone;Pinnacle Systems Studio AV/DV Overlay;C:\windows\system32\DRIVERS\lstone2k.sys [2002-12-10 11:20]
R3 I97DRIVER;I97DRIVER;C:\PROGRA~1\AVANQU~1\Fix-It\dgs.sys [2007-08-31 11:18]
S1 MemAlloc;MemAlloc;C:\windows\system32\DRIVERS\memalloc.sys [2002-08-26 04:51]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 14:46]
S2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 09:20]
S3 MailScan;MailScan;C:\PROGRA~1\AVANQU~1\Fix-It\MailScan.sys [2008-08-26 14:14]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17147075-1ead-11d9-bea6-806d6172696f}]
\Shell\AutoRun\command - F:\cdplayer.exe
*Newly Created Service* - MAILSCAN
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-AOLAspSunset - C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-28 10:54:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\windows\system32\winlogon.exe
-> C:\windows\system32\ssqNHwTm.dll
PROCESS: C:\windows\explorer.exe
-> C:\windows\system32\lubrmqjd.dll
-> C:\windows\system32\euvcndwv.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\AOL\acs\AOLacsd.exe
C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\BigFix\BigFix.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-09-28 11:05:04 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-09-28 18:04:55
ComboFix2.txt 2008-09-27 19:36:10
Pre-Run: 117,386,391,552 bytes free
Post-Run: 117,369,040,896 bytes free
422 --- E O F --- 2008-09-10 10:01:09
ComboFix 08-09-26.06 - Owner 2008-09-28 10:46:21.3 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\windows\BM57247bb3.txt
C:\WINDOWS\system32\akcskd.dll
C:\WINDOWS\system32\aqkrohsi.ini
C:\WINDOWS\system32\blqsdmbn.dll
C:\WINDOWS\system32\bskxlmrh.ini
C:\WINDOWS\system32\btedxycx.dll
C:\WINDOWS\system32\bwfytjkn.dll
C:\WINDOWS\system32\cdezcp.dll
C:\WINDOWS\system32\cfioldln.ini
C:\WINDOWS\system32\ddLUvyay.ini
C:\WINDOWS\system32\ddLUvyay.ini2
C:\WINDOWS\system32\dldjdgpb.dll
C:\WINDOWS\system32\dowdrmdm.dll
C:\WINDOWS\system32\epttasrt.dll
C:\WINDOWS\system32\eqlrtjwc.dll
C:\WINDOWS\system32\eysijgoc.dll
C:\WINDOWS\system32\ffmlux.dll
C:\WINDOWS\system32\fiqhlfgs.ini
C:\WINDOWS\system32\frjdpkfp.dll
C:\WINDOWS\system32\gcfkfrvj.dll
C:\WINDOWS\system32\gndewlnl.ini
C:\WINDOWS\system32\gogtflpg.dll
C:\WINDOWS\system32\gsybahph.dll
C:\WINDOWS\system32\hejwhasx.dll
C:\WINDOWS\system32\hfbpzu.dll
C:\WINDOWS\system32\hggeBsPj.dll
C:\WINDOWS\system32\hijyqy.dll
C:\WINDOWS\system32\hjrcmntv.dll
C:\WINDOWS\system32\hohqil.dll
C:\WINDOWS\system32\hpepyvtt.dll
C:\WINDOWS\system32\htyoltvx.dll
C:\WINDOWS\system32\hucofkti.dll
C:\WINDOWS\system32\hxwaap.dll
C:\WINDOWS\system32\hyuxwaak.ini
C:\WINDOWS\system32\iacgms.dll
C:\WINDOWS\system32\icpwhfeh.ini
C:\WINDOWS\system32\ieencode.dll
C:\WINDOWS\system32\iiFUmMfd.dll
C:\WINDOWS\system32\iiqnshct.ini
C:\WINDOWS\system32\jahxmi.dll
C:\WINDOWS\system32\jbksnxhl.dll
C:\WINDOWS\system32\jdsyhtrr.dll
C:\WINDOWS\system32\jflphxuo.dll
C:\WINDOWS\system32\jihrwqmq.dll
C:\WINDOWS\system32\kesxfccs.dll
C:\WINDOWS\system32\khfDTNEt.dll
C:\WINDOWS\system32\knvknwjd.dll
C:\WINDOWS\system32\kugnlc.dll
C:\WINDOWS\system32\kxkgphkq.dll
C:\WINDOWS\system32\kyikvrpi.dll
C:\WINDOWS\system32\lcisicjc.ini
C:\WINDOWS\system32\leulfi.dll
C:\WINDOWS\system32\mcsfqram.dll
C:\WINDOWS\system32\mcuiivho.dll
C:\WINDOWS\system32\mdldtxkb.dll
C:\WINDOWS\system32\mdygoxfe.dll
C:\WINDOWS\system32\mskqmb.dll
C:\WINDOWS\system32\nghlvivg.dll
C:\WINDOWS\system32\niesnuco.ini
C:\WINDOWS\system32\njslkici.dll
C:\WINDOWS\system32\nmemoh.dll
C:\WINDOWS\system32\nnicsm.dll
C:\WINDOWS\system32\nnnkJAsP.dll
C:\WINDOWS\system32\nnnoLEWo.dll
C:\WINDOWS\system32\nnnoPgHA.dll
C:\WINDOWS\system32\nrvprgka.dll
C:\WINDOWS\system32\ntcxws.dll
C:\WINDOWS\system32\oikednnm.dll
C:\WINDOWS\system32\omcyibwl.ini
C:\WINDOWS\system32\onlbgw.dll
C:\WINDOWS\system32\pahqhe.dll
C:\WINDOWS\system32\pbbwacnk.dll
C:\WINDOWS\system32\phmkln.dll
C:\WINDOWS\system32\pwhepwsr.dll
C:\WINDOWS\system32\qkiizc.dll
C:\WINDOWS\system32\qlnbcmqq.dll
C:\WINDOWS\system32\qpityipw.ini
C:\WINDOWS\system32\qtpfopgn.dll
C:\WINDOWS\system32\rcajwmty.dll
C:\WINDOWS\system32\rcuiue.dll
C:\WINDOWS\system32\rgkjuxjs.dll
C:\WINDOWS\system32\rqRhIBSk.dll
C:\WINDOWS\system32\rqRIxuTM.dll
C:\WINDOWS\system32\scckgugp.ini
C:\WINDOWS\system32\sdxhrljf.dll
C:\WINDOWS\system32\srqginiw.ini
C:\WINDOWS\system32\sSmjiiIx.dll
C:\WINDOWS\system32\swgatpcp.ini
C:\WINDOWS\system32\swlhpwhw.dll
C:\WINDOWS\system32\sxksoonm.dll
C:\WINDOWS\system32\tcgqauvy.ini
C:\WINDOWS\system32\tchsnqii.dll
C:\WINDOWS\system32\tehogmas.dll
C:\WINDOWS\system32\tmgaebio.dll
C:\WINDOWS\system32\ujyjlj.dll
C:\WINDOWS\system32\vfexxy.dll
C:\WINDOWS\system32\vhypgmdj.dll
C:\WINDOWS\system32\vobkrdoi.dll
C:\WINDOWS\system32\vppgnbit.dll
C:\WINDOWS\system32\vsalhfng.dll
C:\WINDOWS\system32\winigqrs.dll
C:\WINDOWS\system32\wokfjqqd.ini
C:\WINDOWS\system32\xacykm.dll
C:\WINDOWS\system32\xcbwtqed.dll
C:\WINDOWS\system32\xIiijmSs.ini
C:\WINDOWS\system32\xIiijmSs.ini2
C:\WINDOWS\system32\XIOVxyxx.ini
C:\WINDOWS\system32\XIOVxyxx.ini2
C:\WINDOWS\system32\xjbmwcgl.dll
C:\WINDOWS\system32\xtcbmxkr.ini
C:\WINDOWS\system32\xtvdjaij.ini
C:\WINDOWS\system32\ydpoidih.ini
C:\WINDOWS\system32\ytmwjacr.ini
C:\WINDOWS\system32\yvwepumr.dll
C:\WINDOWS\system32\zewzrl.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\windows\BM57247bb3.txt
C:\windows\BM57247bb3.xml
C:\windows\pskt.ini
C:\WINDOWS\system32\ieencode.dll
.
---- Previous Run -------
.
C:\Program Files\ewido anti-spyware 4.0
C:\Program Files\ewido anti-spyware 4.0\updater.ewidolog
C:\windows\BM57247bb3.txt
C:\windows\pskt.ini
C:\WINDOWS\system32\akcskd.dll
C:\WINDOWS\system32\aqkrohsi.ini
C:\WINDOWS\system32\blqsdmbn.dll
C:\WINDOWS\system32\bskxlmrh.ini
C:\WINDOWS\system32\btedxycx.dll
C:\WINDOWS\system32\bwfytjkn.dll
C:\WINDOWS\system32\cdezcp.dll
C:\WINDOWS\system32\cfioldln.ini
C:\WINDOWS\system32\ddLUvyay.ini
C:\WINDOWS\system32\ddLUvyay.ini2
C:\WINDOWS\system32\dldjdgpb.dll
C:\WINDOWS\system32\dowdrmdm.dll
C:\WINDOWS\system32\epttasrt.dll
C:\WINDOWS\system32\eqlrtjwc.dll
C:\WINDOWS\system32\eysijgoc.dll
C:\WINDOWS\system32\ffmlux.dll
C:\WINDOWS\system32\fiqhlfgs.ini
C:\WINDOWS\system32\frjdpkfp.dll
C:\WINDOWS\system32\gcfkfrvj.dll
C:\WINDOWS\system32\gndewlnl.ini
C:\WINDOWS\system32\gogtflpg.dll
C:\WINDOWS\system32\gsybahph.dll
C:\WINDOWS\system32\hejwhasx.dll
C:\WINDOWS\system32\hfbpzu.dll
C:\WINDOWS\system32\hggeBsPj.dll
C:\WINDOWS\system32\hijyqy.dll
C:\WINDOWS\system32\hjrcmntv.dll
C:\WINDOWS\system32\hohqil.dll
C:\WINDOWS\system32\hpepyvtt.dll
C:\WINDOWS\system32\htyoltvx.dll
C:\WINDOWS\system32\hucofkti.dll
C:\WINDOWS\system32\hxwaap.dll
C:\WINDOWS\system32\hyuxwaak.ini
C:\WINDOWS\system32\iacgms.dll
C:\WINDOWS\system32\icpwhfeh.ini
C:\WINDOWS\system32\ieencode.dll
C:\WINDOWS\system32\iiFUmMfd.dll
C:\WINDOWS\system32\iiqnshct.ini
C:\WINDOWS\system32\jahxmi.dll
C:\WINDOWS\system32\jbksnxhl.dll
C:\WINDOWS\system32\jdsyhtrr.dll
C:\WINDOWS\system32\jflphxuo.dll
C:\WINDOWS\system32\jihrwqmq.dll
C:\WINDOWS\system32\kesxfccs.dll
C:\WINDOWS\system32\khfDTNEt.dll
C:\WINDOWS\system32\knvknwjd.dll
C:\WINDOWS\system32\kugnlc.dll
C:\WINDOWS\system32\kxkgphkq.dll
C:\WINDOWS\system32\kyikvrpi.dll
C:\WINDOWS\system32\lcisicjc.ini
C:\WINDOWS\system32\leulfi.dll
C:\WINDOWS\system32\mcsfqram.dll
C:\WINDOWS\system32\mcuiivho.dll
C:\WINDOWS\system32\mdldtxkb.dll
C:\WINDOWS\system32\mdygoxfe.dll
C:\WINDOWS\system32\mskqmb.dll
C:\WINDOWS\system32\nghlvivg.dll
C:\WINDOWS\system32\niesnuco.ini
C:\WINDOWS\system32\njslkici.dll
C:\WINDOWS\system32\nmemoh.dll
C:\WINDOWS\system32\nnicsm.dll
C:\WINDOWS\system32\nnnkJAsP.dll
C:\WINDOWS\system32\nnnoLEWo.dll
C:\WINDOWS\system32\nnnoPgHA.dll
C:\WINDOWS\system32\nrvprgka.dll
C:\WINDOWS\system32\ntcxws.dll
C:\WINDOWS\system32\oikednnm.dll
C:\WINDOWS\system32\omcyibwl.ini
C:\WINDOWS\system32\onlbgw.dll
C:\WINDOWS\system32\pahqhe.dll
C:\WINDOWS\system32\pbbwacnk.dll
C:\WINDOWS\system32\phmkln.dll
C:\WINDOWS\system32\pwhepwsr.dll
C:\WINDOWS\system32\qkiizc.dll
C:\WINDOWS\system32\qlnbcmqq.dll
C:\WINDOWS\system32\qpityipw.ini
C:\WINDOWS\system32\qtpfopgn.dll
C:\WINDOWS\system32\rcajwmty.dll
C:\WINDOWS\system32\rcuiue.dll
C:\WINDOWS\system32\rgkjuxjs.dll
C:\WINDOWS\system32\rqRhIBSk.dll
C:\WINDOWS\system32\rqRIxuTM.dll
C:\WINDOWS\system32\scckgugp.ini
C:\WINDOWS\system32\sdxhrljf.dll
C:\WINDOWS\system32\srqginiw.ini
C:\WINDOWS\system32\sSmjiiIx.dll
C:\WINDOWS\system32\swgatpcp.ini
C:\WINDOWS\system32\swlhpwhw.dll
C:\WINDOWS\system32\sxksoonm.dll
C:\WINDOWS\system32\tcgqauvy.ini
C:\WINDOWS\system32\tchsnqii.dll
C:\WINDOWS\system32\tehogmas.dll
C:\WINDOWS\system32\tmgaebio.dll
C:\WINDOWS\system32\ujyjlj.dll
C:\WINDOWS\system32\vfexxy.dll
C:\WINDOWS\system32\vhypgmdj.dll
C:\WINDOWS\system32\vobkrdoi.dll
C:\WINDOWS\system32\vppgnbit.dll
C:\WINDOWS\system32\vsalhfng.dll
C:\WINDOWS\system32\winigqrs.dll
C:\WINDOWS\system32\wokfjqqd.ini
C:\WINDOWS\system32\xacykm.dll
C:\WINDOWS\system32\xcbwtqed.dll
C:\WINDOWS\system32\xIiijmSs.ini
C:\WINDOWS\system32\xIiijmSs.ini2
C:\WINDOWS\system32\XIOVxyxx.ini
C:\WINDOWS\system32\XIOVxyxx.ini2
C:\WINDOWS\system32\xjbmwcgl.dll
C:\WINDOWS\system32\xtcbmxkr.ini
C:\WINDOWS\system32\xtvdjaij.ini
C:\WINDOWS\system32\ydpoidih.ini
C:\WINDOWS\system32\ytmwjacr.ini
C:\WINDOWS\system32\yvwepumr.dll
C:\WINDOWS\system32\zewzrl.dll
.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-28 )))))))))))))))))))))))))))))))
.
2008-09-28 10:21 . 2008-09-28 10:21 42,496 --a------ C:\WINDOWS\system32\wvUljHAt.dll
2008-09-28 10:21 . 2008-09-28 10:21 42,496 --a------ C:\WINDOWS\system32\tuvWnoMf.dll
2008-09-28 09:47 . 2008-09-28 09:47 988,183 ---hs---- C:\WINDOWS\system32\djqmrbul.ini
2008-09-28 09:47 . 2008-09-28 09:47 78,848 --a------ C:\WINDOWS\system32\lubrmqjd.dll
2008-09-28 09:44 . 2008-09-28 09:44 111,616 --a------ C:\WINDOWS\system32\epktljnl.dll
2008-09-28 09:44 . 2008-09-28 09:44 111,616 --a------ C:\WINDOWS\system32\agdryk.dll
2008-09-28 09:43 . 2008-09-28 09:43 105,984 --a------ C:\WINDOWS\system32\euvcndwv.dll
2008-09-28 08:37 . 2008-09-28 08:37 42,496 --a------ C:\WINDOWS\system32\urqQhhIc.dll
2008-09-28 08:37 . 2008-09-28 08:37 42,496 --a------ C:\WINDOWS\system32\urqNDvsQ.dll
2008-09-27 19:00 . 2008-09-27 19:00 46,080 --a------ C:\WINDOWS\system32\xxyxWNGX.dll
2008-09-27 19:00 . 2008-09-27 19:00 46,080 --a------ C:\WINDOWS\system32\fccARHyy.dll
2008-09-27 18:27 . 2008-09-27 18:27 46,080 --a------ C:\WINDOWS\system32\xxyxusTl.dll
2008-09-27 18:27 . 2008-09-27 18:27 46,080 --a------ C:\WINDOWS\system32\awtsSlmL.dll
2008-09-27 18:26 . 2008-09-27 18:26 155,648 --a------ C:\WINDOWS\system32\qayfrxfo.dll
2008-09-27 18:09 . 2008-09-27 18:09 155,648 --a------ C:\WINDOWS\system32\ubtnypty.dll
2008-09-27 18:09 . 2008-09-27 18:09 107,008 --a------ C:\WINDOWS\system32\wfmfoavm.dll
2008-09-27 18:08 . 2008-09-27 18:08 155,648 --a------ C:\WINDOWS\system32\tklhyjjf.dll
2008-09-27 18:06 . 2008-09-27 18:06 107,008 --a------ C:\WINDOWS\system32\dmvjlulc.dll
2008-09-27 18:05 . 2008-09-28 10:46 875,566 --ahs---- C:\WINDOWS\system32\FeKmWvut.ini2
2008-09-27 18:05 . 2008-09-28 10:46 875,566 --ahs---- C:\WINDOWS\system32\FeKmWvut.ini
2008-09-27 18:05 . 2008-09-27 18:05 253,440 --a------ C:\WINDOWS\system32\tuvWmKeF.dll
2008-09-26 17:58 . 2008-09-27 10:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-26 10:28 . 2008-09-27 08:57 427 --a------ C:\WINDOWS\wininit.ini
2008-09-26 07:19 . 2008-09-26 07:19 <DIR> d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-09-25 13:46 . 2007-08-13 18:45 78,336 --a--c--- C:\WINDOWS\system32\dllcache\ieencode.dll
2008-09-25 13:00 . 2008-09-25 13:00 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-09-23 21:27 . 2008-09-23 21:27 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Avanquest
2008-09-23 21:26 . 2008-09-23 21:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-09-23 21:21 . 2008-09-23 21:21 <DIR> dr-hs---- C:\_Backup.RC
2008-09-23 21:21 . 2008-09-24 00:20 <DIR> d--h----- C:\_Backup
2008-09-23 21:19 . 2008-09-23 21:19 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Avanquest
2008-09-23 21:14 . 2008-09-23 21:14 <DIR> d-------- C:\Program Files\Avanquest
2008-09-23 21:10 . 2008-09-23 21:10 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-22 20:28 . 2008-09-23 20:36 921,005 --ahs---- C:\WINDOWS\system32\fcmlcxix.ini
2008-09-22 20:25 . 2008-09-22 20:25 99,328 --a------ C:\WINDOWS\system32\elbyvebf.dll
2008-09-22 14:28 . 2008-09-22 14:28 879,630 --ahs---- C:\WINDOWS\system32\ifvyfbwc.ini
2008-09-22 14:25 . 2008-09-22 14:25 113,152 --a------ C:\WINDOWS\system32\pgnvgrox.dll
2008-09-22 14:25 . 2008-09-22 14:25 113,152 --a------ C:\WINDOWS\system32\cguzet.dll
2008-09-22 14:23 . 2008-09-22 14:23 99,328 --a------ C:\WINDOWS\system32\ylxxhiob.dll
2008-09-22 14:19 . 2008-09-22 14:22 879,570 --ahs---- C:\WINDOWS\system32\gbkfunct.ini
2008-09-22 14:16 . 2008-09-26 10:33 876,630 --ahs---- C:\WINDOWS\system32\TAyJlUtv.ini2
2008-09-22 14:16 . 2008-09-26 10:34 876,630 --ahs---- C:\WINDOWS\system32\TAyJlUtv.ini
2008-09-22 14:16 . 2008-09-22 14:16 99,328 --a------ C:\WINDOWS\system32\baieqfob.dll
2008-09-22 14:10 . 2008-09-22 14:10 43,008 --a------ C:\WINDOWS\system32\ssqNHwTm.dll
2008-09-21 17:23 . 2004-08-30 21:00 365,568 --a------ C:\WINDOWS\system32\doskeys.exe
2008-09-21 17:23 . 2008-09-21 17:23 51,712 --a------ C:\WINDOWS\system32\dllhosts.exe
2008-09-21 17:23 . 2008-09-28 10:37 215 --a------ C:\WINDOWS\system32\Monitored2.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-28 17:53 --------- d-----w C:\Program Files\QuickTime
2008-09-28 16:31 --------- d-----w C:\Program Files\Zinio
2008-09-28 16:31 --------- d-----w C:\Program Files\iTunes
2008-09-28 16:31 --------- d-----w C:\Program Files\Digital Media Reader
2008-09-27 03:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\CanonIJPLM
2008-09-27 01:12 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-26 16:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-25 22:30 --------- d-----w C:\Program Files\xxx.xxx
2008-09-25 19:47 --------- d-----w C:\Program Files\Opera
2008-09-24 02:55 --------- d-----w C:\Program Files\Symantec
2008-09-24 02:28 --------- d-----w C:\Program Files\Photo Manager
2008-09-24 02:17 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-22 00:02 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2008-08-24 16:43 --------- d-----w C:\Program Files\Sun
2008-08-24 16:42 --------- d-----w C:\Program Files\Java
2008-03-26 15:20 228,336 -c--a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-03-09 01:48 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2005-12-18 18:20 0 -c--a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
2002-07-26 22:02 153,088 -c--a-w C:\Program Files\UNWISE.EXE
.
((((((((((((((((((((((((((((( snapshot@2008-09-27_12.33.38.84 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-07-09 15:50:42 155,648 -c--a-w C:\windows\system32\NeroCheck.exe
+ 2004-03-10 21:26:10 406,016 -c--a-w C:\windows\system32\PSDrvCheck.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00BA82ED-AF2F-40BD-995C-320BBD6A509e}]
2008-09-27 18:26 155648 --a------ C:\windows\system32\qayfrxfo.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca3a2052-0769-4c60-a246-99628fb3eb7c}]
2008-09-28 09:44 111616 --a------ C:\windows\system32\agdryk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CAA91B0C-B261-4328-B3C1-07F4E5D8F3E9}]
2008-09-27 18:05 253440 --a------ C:\windows\system32\tuvWmKeF.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E538488B-36AB-42FF-8498-271810C9C599}]
2008-09-22 14:10 43008 --a------ C:\windows\system32\ssqNHwTm.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="C:\windows\system32\dumprep 0 -u" [X]
"HostManager"="C:\Program Files\Common Files\AOL\1191778237\ee\AOLSoftware.exe" [2006-09-25 50736]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"LVCOMSX"="C:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"VirusScannerPro"="C:\PROGRA~1\AVANQU~1\Fix-It\MemCheck.exe" [2008-08-26 173312]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-10-02 67488]
"5417482f"="C:\windows\system32\lubrmqjd.dll" [2008-09-28 78848]
"BM57247bb3"="C:\windows\system32\euvcndwv.dll" [2008-09-28 105984]
"ShowWnd"="ShowWnd.exe" [2003-09-19 C:\WINDOWS\ShowWnd.exe]
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"NT Printing Services6"="dllhosts.exe" [2008-09-21 C:\WINDOWS\system32\dllhosts.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{E538488B-36AB-42FF-8498-271810C9C599}"= "C:\windows\system32\ssqNHwTm.dll" [2008-09-22 43008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqNHwTm]
2008-09-22 14:10 43008 C:\WINDOWS\system32\ssqNHwTm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 LStone;Pinnacle Systems Studio AV/DV Overlay;C:\windows\system32\DRIVERS\lstone2k.sys [2002-12-10 11:20]
R3 I97DRIVER;I97DRIVER;C:\PROGRA~1\AVANQU~1\Fix-It\dgs.sys [2007-08-31 11:18]
S1 MemAlloc;MemAlloc;C:\windows\system32\DRIVERS\memalloc.sys [2002-08-26 04:51]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 14:46]
S2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 09:20]
S3 MailScan;MailScan;C:\PROGRA~1\AVANQU~1\Fix-It\MailScan.sys [2008-08-26 14:14]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17147075-1ead-11d9-bea6-806d6172696f}]
\Shell\AutoRun\command - F:\cdplayer.exe
*Newly Created Service* - MAILSCAN
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-AOLAspSunset - C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-28 10:54:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\windows\system32\winlogon.exe
-> C:\windows\system32\ssqNHwTm.dll
PROCESS: C:\windows\explorer.exe
-> C:\windows\system32\lubrmqjd.dll
-> C:\windows\system32\euvcndwv.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\AOL\acs\AOLacsd.exe
C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\BigFix\BigFix.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-09-28 11:05:04 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-09-28 18:04:55
ComboFix2.txt 2008-09-27 19:36:10
Pre-Run: 117,386,391,552 bytes free
Post-Run: 117,369,040,896 bytes free
422 --- E O F --- 2008-09-10 10:01:09