Combofix report
Hi,
Here's the new combofix report. I'm noticing a big improvement in my computer's performance!
ComboFix 07-09-21.2 - "Darrell Fryman" 2007-09-30 16:47:27.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.153 [GMT -4:00]
* Created a new restore point
FILE::
C:\WINDOWS\system32\iyoqohpu.dll
C:\WINDOWS\system32\selwomea.dll
C:\WINDOWS\system32\knhlpmgo.dll
C:\WINDOWS\system32\yrdbtnwb.dll
C:\WINDOWS\system32\eanhtqgx.dll
C:\WINDOWS\system32\eggbidjy.dll
C:\WINDOWS\system32\jisxlfrj.dll
C:\WINDOWS\system32\ishxlqhq.dll
C:\WINDOWS\system32\dvrqmswr.dll
C:\WINDOWS\system32\sksdsifv.dll
C:\WINDOWS\system32\fwmowpvv.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\dvrqmswr.dll
C:\WINDOWS\system32\eanhtqgx.dll
C:\WINDOWS\system32\eggbidjy.dll
C:\WINDOWS\system32\fwmowpvv.dll
C:\WINDOWS\system32\ishxlqhq.dll
C:\WINDOWS\system32\iyoqohpu.dll
C:\WINDOWS\system32\jisxlfrj.dll
C:\WINDOWS\system32\knhlpmgo.dll
C:\WINDOWS\system32\selwomea.dll
C:\WINDOWS\system32\sksdsifv.dll
C:\WINDOWS\system32\yrdbtnwb.dll
.
((((((((((((((((((((((((( Files Created from 2007-08-28 to 2007-09-30 )))))))))))))))))))))))))))))))
.
2007-09-25 03:05 <DIR> d-------- C:\Program Files\Notepad++
2007-09-25 03:05 <DIR> d-------- C:\DOCUME~1\DARREL~1\APPLIC~1\Notepad++
2007-09-22 18:03 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-22 17:39 <DIR> d-------- C:\VundoFix Backups
2007-09-21 16:36 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-21 05:39 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-09-21 05:39 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-20 21:57 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-09-19 04:30 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-09-19 02:48 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-18 23:30 51,104 --a------ C:\WINDOWS\system32\drivers\fsdfw.sys
2007-09-18 23:30 29,984 --a------ C:\WINDOWS\system32\drivers\fsndis5.sys
2007-09-18 23:29 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\F-Secure
2007-09-18 23:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
2007-09-17 22:16 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab Setup Files
2007-09-17 16:05 <DIR> d-------- C:\KAV
2007-09-17 14:23 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 14:23 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 14:22 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 14:22 739,840 --a------ C:\WINDOWS\system32\DivX.dll
2007-09-15 21:41 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
2007-09-15 21:33 <DIR> d-------- C:\Program Files\Bonjour
2007-09-15 21:22 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2007-09-11 19:14 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-09-09 22:09 1,156 --a------ C:\WINDOWS\mozver.dat
2007-09-09 22:07 <DIR> d-------- C:\DOCUME~1\DARREL~1\APPLIC~1\Talkback
2007-09-07 16:33 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-09-07 16:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
2007-09-07 16:25 <DIR> dr-h----- C:\MSOCache
2007-09-03 22:41 <DIR> d-------- C:\Program Files\Cake Mania 2
2007-09-02 02:03 <DIR> d-------- C:\Program Files\Veoh Networks
2007-09-02 01:29 10 --a------ C:\WINDOWS\smdat32m.sys
2007-09-02 01:19 <DIR> d-------- C:\DOCUME~1\DARREL~1\APPLIC~1\Kazaa Lite
2007-08-29 20:05 <DIR> d-------- C:\Program Files\YouTube Downloader
2007-08-25 03:00 <DIR> d-------- C:\WINDOWS\FLV Player
2007-08-25 01:38 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2007-08-24 21:38 <DIR> d-------- C:\Program Files\Linksys EasyLink Advisor
2007-08-24 17:25 <DIR> d-------- C:\Program Files\GPL MPEG Decoder
2007-08-20 20:26 81,920 --a------ C:\WINDOWS\system32\dpl100.dll
2007-08-20 20:26 196,608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-08-15 18:33 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-08-15 18:33 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-08-15 18:33 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-08-15 18:33 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-08-15 18:31 593,920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2007-08-15 18:31 57,344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-08-15 18:31 53,248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2007-08-15 18:31 344,064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-08-15 18:31 294,912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-08-15 18:31 294,912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-08-15 18:30 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2007-08-08 14:37 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games
2007-08-07 05:59 <DIR> d-------- C:\DOCUME~1\DARREL~1\APPLIC~1\Hulabee
2007-08-07 03:25 <DIR> d-------- C:\DOCUME~1\DARREL~1\APPLIC~1\Sauce
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-30 02:40 --------- d-------- C:\Program Files\GetRight
2007-09-22 03:35 --------- d-------- C:\Program Files\Windows Media Connect 2
2007-09-22 02:10 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-09-22 01:55 --------- d-------- C:\Program Files\Dell
2007-09-21 02:59 --------- d-------- C:\Program Files\DivX
2007-09-18 23:32 --------- d-------- C:\Program Files\EMBARQ Online Security
2007-09-18 22:39 --------- d-------- C:\DOCUME~1\DARREL~1\APPLIC~1\U3
2007-09-09 02:11 --------- d-------- C:\Program Files\Shockwave.com
2007-09-07 16:35 --------- d-------- C:\Program Files\MSBuild
2007-09-04 00:36 --------- d-------- C:\Program Files\Lexmark X1100 Series
2007-09-02 01:29 905 --a------ C:\WINDOWS\Fonts.\acrsecI.fon
2007-09-02 01:29 854 --a------ C:\WINDOWS\Fonts.\acrsec.fon
2007-09-02 01:29 1761 --a------ C:\WINDOWS\Fonts.\acrsecB.fon
2007-08-08 23:06 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Musicnotes
2007-08-04 12:45 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\OPUSTEXT.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\OPUSS___.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\OPUSROMC.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\OPUSPC__.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\OPUSP___.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\OPUSM___.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\OPUSJAPC.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\OPUSFBE_.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\OPUSFB__.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\OPUSC___.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\OPUS____.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\INKPEN2_.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\INK2TEXT.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\INK2SPEC.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\INK2SCRI.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\INK2METR.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\INK2CHOR.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\HELST___.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\HELSS___.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\HELSM___.FOT
2007-07-27 19:43 1409 --a------ C:\WINDOWS\Fonts.\HELSINKI.FOT
2007-06-13 06:23 1033216 --a------ C:\WINDOWS\explorer.exe
2006-05-16 22:39 774144 --a------ C:\Program Files\RngInterstitial.dll
2006-09-06 22:15:43 56 --sh--r C:\WINDOWS\system32\DC25FDEFC1.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 20:42]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 04:12]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 11:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 06:43]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-04-24 10:39]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36]
"Motive SmartBridge"="C:\PROGRA~1\VIRTUA~2\SMARTB~1\SprintDSLAlert.exe" [2007-05-15 14:25]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-07-04 02:30]
"F-Secure Manager"="C:\Program Files\EMBARQ Online Security\Common\FSM32.exe" [2007-04-26 07:43]
"F-Secure TNB"="C:\Program Files\EMBARQ Online Security\FSGUI\TNBUtil.exe" [2007-04-26 07:41]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" []
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-24 10:36:45]
C:\DOCUME~1\DARREL~1\STARTM~1\Programs\Startup\
Online Wallpaper.lnk - C:\Program Files\Online Wallpaper Changer\OnlineWallpaper.exe [2007-07-05 17:45:04]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys
R1 F-Secure HIPS;F-Secure HIPS;\??\C:\Program Files\EMBARQ Online Security\HIPS\fshs.sys
R2 CdaD10BA;CdaD10BA;\??\C:\WINDOWS\system32\drivers\CdaD10BA.SYS
R2 elagopro;GoProto Protocol Driver for LELA;C:\WINDOWS\system32\DRIVERS\elagopro.sys
R2 elaunidr;UniDriver for LELA;C:\WINDOWS\system32\DRIVERS\elaunidr.sys
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;\??\C:\Program Files\EMBARQ Online Security\Anti-Virus\minifilter\fsgk.sys
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
S4 F-Secure Filter;F-Secure File System Filter;\??\C:\Program Files\EMBARQ Online Security\Anti-Virus\Win2K\FSfilter.sys
S4 F-Secure Recognizer;F-Secure File System Recognizer;\??\C:\Program Files\EMBARQ Online Security\Anti-Virus\Win2K\FSrec.sys
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-30 16:56:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-09-30 17:00:27 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-30 16:59
C:\ComboFix2.txt ... 2007-09-29 16:15
.
--- E O F ---