ComboFix Log
ComboFix 08-04-18.3 - Owner 2008-04-19 21:55:02.1 - NTFSx86
Running from: C:\Documents and Settings\Owner.lapdawg\Desktop\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Austin\Application Data\ultra
C:\Documents and Settings\Austin\Application Data\ultra\uninstall.bat
C:\Documents and Settings\Owner.lapdawg\Desktopvirii
C:\Program Files\iSecurity
C:\Program Files\iSecurity\iSecurity.dat
C:\Program Files\iSecurity\syscleaner.bmp
C:\Program Files\iSecurity\syscleanerinstalled.bmp
C:\Program Files\iSecurity\systemdefender.bmp
C:\Program Files\iSecurity\systemdefenderinstalled.bmp
C:\Program Files\iSecurity\winifixer.bmp
C:\Program Files\iSecurity\winifixerinstalled.bmp
C:\WINDOWS\a.bat
C:\WINDOWS\base64.tmp
C:\WINDOWS\bdn.com
C:\WINDOWS\BMc7fc3833.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\FVProtect.exe
C:\WINDOWS\Installer\{3947cb6b-1b3c-471f-bda6-45656f86a359}\CDComponent.dll
C:\WINDOWS\Installer\{631f7f2d-b799-49c9-b0e9-70ea1e194f22}\ComponentService.dll
C:\WINDOWS\Installer\{895e50c2-aaa2-4747-8e56-f23073f90dbc}\AvpSetup.dll
C:\WINDOWS\Installer\{a5e83139-4d41-4fdf-9a6b-7c6c66d55cc0}\RamKernel.dll
C:\WINDOWS\iTunesMusic.exe
C:\WINDOWS\mssecu.exe
C:\WINDOWS\PerfInfo
C:\WINDOWS\ppqvmpqr
C:\WINDOWS\ppqvmpqr\1.png
C:\WINDOWS\ppqvmpqr\2.png
C:\WINDOWS\ppqvmpqr\3.png
C:\WINDOWS\ppqvmpqr\4.png
C:\WINDOWS\ppqvmpqr\5.png
C:\WINDOWS\ppqvmpqr\6.png
C:\WINDOWS\ppqvmpqr\bottom-rc.gif
C:\WINDOWS\ppqvmpqr\content.png
C:\WINDOWS\ppqvmpqr\download.gif
C:\WINDOWS\ppqvmpqr\frame-bottom-left.gif
C:\WINDOWS\ppqvmpqr\frame-h1bg.gif
C:\WINDOWS\ppqvmpqr\head.png
C:\WINDOWS\ppqvmpqr\indexuc.html
C:\WINDOWS\ppqvmpqr\indexud.html
C:\WINDOWS\ppqvmpqr\main.css
C:\WINDOWS\ppqvmpqr\net.png
C:\WINDOWS\ppqvmpqr\pc-mag.gif
C:\WINDOWS\ppqvmpqr\pc.gif
C:\WINDOWS\ppqvmpqr\poloska1.png
C:\WINDOWS\ppqvmpqr\poloska2.png
C:\WINDOWS\ppqvmpqr\poloska3.png
C:\WINDOWS\ppqvmpqr\promouc1.html
C:\WINDOWS\ppqvmpqr\promouc2.html
C:\WINDOWS\ppqvmpqr\promouc3.html
C:\WINDOWS\ppqvmpqr\promouc4.html
C:\WINDOWS\ppqvmpqr\promouc5.html
C:\WINDOWS\ppqvmpqr\promoud1.html
C:\WINDOWS\ppqvmpqr\promoud2.html
C:\WINDOWS\ppqvmpqr\promoud3.html
C:\WINDOWS\ppqvmpqr\promoud4.html
C:\WINDOWS\ppqvmpqr\promoud5.html
C:\WINDOWS\ppqvmpqr\reg.png
C:\WINDOWS\ppqvmpqr\repair.png
C:\WINDOWS\ppqvmpqr\scr-1.png
C:\WINDOWS\ppqvmpqr\scr-2.png
C:\WINDOWS\ppqvmpqr\styles.css
C:\WINDOWS\ppqvmpqr\Thumbs.db
C:\WINDOWS\ppqvmpqr\top-rc.gif
C:\WINDOWS\ppqvmpqr\vline.gif
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\ajebjjdx.ini
C:\WINDOWS\system32\bLnorBeg.ini
C:\WINDOWS\system32\bLnorBeg.ini2
C:\WINDOWS\system32\blwjvwjj.ini
C:\WINDOWS\system32\cbXqolME.dll
C:\WINDOWS\system32\cfhkj.ini2
C:\WINDOWS\system32\cfhkj.tmp
C:\WINDOWS\system32\cvbmpwlu.ini
C:\WINDOWS\system32\cylqroef.ini
C:\WINDOWS\system32\dbxkbafk.ini
C:\WINDOWS\system32\ebaxgceh.ini
C:\WINDOWS\system32\ejkyauhb.ini
C:\WINDOWS\system32\fanjpkns.ini
C:\WINDOWS\system32\FNpYaccf.ini
C:\WINDOWS\system32\FNpYaccf.ini2
C:\WINDOWS\system32\fpixxdin.ini
C:\WINDOWS\system32\gbtkwebs.ini
C:\WINDOWS\system32\gbvuhbqb.ini
C:\WINDOWS\system32\gmfvrmhg.ini
C:\WINDOWS\system32\gwdfrsts.ini
C:\WINDOWS\system32\gyhrenod.ini
C:\WINDOWS\system32\hhdncpdr.ini
C:\WINDOWS\system32\icbnsmdp.ini
C:\WINDOWS\system32\ifpyfpqd.ini
C:\WINDOWS\system32\irhirxfe.ini
C:\WINDOWS\system32\iSecurity.cpl
C:\WINDOWS\system32\jcdsksge.ini
C:\WINDOWS\system32\jcmpdnvp.ini
C:\WINDOWS\system32\jjomcmct.ini
C:\WINDOWS\system32\kUwHjRqr.ini
C:\WINDOWS\system32\kUwHjRqr.ini2
C:\WINDOWS\system32\lbqdvnfy.ini
C:\WINDOWS\system32\lcduodhn.ini
C:\WINDOWS\system32\ljdxlpdy.ini
C:\WINDOWS\system32\ndaTqsVqrX.dll
C:\WINDOWS\system32\neneyjso.ini
C:\WINDOWS\system32\nhjjajab.ini
C:\WINDOWS\system32\nibmiiys.ini
C:\WINDOWS\system32\nnnNGXqO.dll
C:\WINDOWS\system32\npbrhqiy.ini
C:\WINDOWS\system32\nqwdkfoy.ini
C:\WINDOWS\system32\nvirqgvf.ini
C:\WINDOWS\system32\ofepxiic.ini
C:\WINDOWS\system32\olvnenxa.ini
C:\WINDOWS\system32\opnooNfC.dll
C:\WINDOWS\system32\othqitbw.ini
C:\WINDOWS\system32\pdixgxot.ini
C:\WINDOWS\system32\phccqvnb.ini
C:\WINDOWS\system32\psahachn.ini
C:\WINDOWS\system32\qqkgrevq.ini
C:\WINDOWS\system32\qwwcijpq.ini
C:\WINDOWS\system32\rfsgfntr.ini
C:\WINDOWS\system32\rgmilwlw.ini
C:\WINDOWS\system32\rosahpny.ini
C:\WINDOWS\system32\saokhhyh.ini
C:\WINDOWS\system32\skjivkgr.ini
C:\WINDOWS\system32\ssqRjHab.dll
C:\WINDOWS\system32\tjgactya.ini
C:\WINDOWS\system32\uncertou.ini
C:\WINDOWS\system32\upxcfejj.ini
C:\WINDOWS\system32\urqQjjig.dll
C:\WINDOWS\system32\vlbbwyyv.ini
C:\WINDOWS\system32\wkobduhm.ini
C:\WINDOWS\system32\xnqajkwr.ini
C:\WINDOWS\system32akttzn.exe
C:\WINDOWS\system32anticipator.dll
C:\WINDOWS\system32awtoolb.dll
C:\WINDOWS\system32bdn.com
C:\WINDOWS\system32bsva-egihsg52.exe
C:\WINDOWS\system32dpcproxy.exe
C:\WINDOWS\system32emesx.dll
C:\WINDOWS\system32h@tkeysh@@k.dll
C:\WINDOWS\system32hoproxy.dll
C:\WINDOWS\system32hxiwlgpm.dat
C:\WINDOWS\system32hxiwlgpm.exe
C:\WINDOWS\system32medup012.dll
C:\WINDOWS\system32medup020.dll
C:\WINDOWS\system32msgp.exe
C:\WINDOWS\system32msnbho.dll
C:\WINDOWS\system32mssecu.exe
C:\WINDOWS\system32msvchost.exe
C:\WINDOWS\system32mtr2.exe
C:\WINDOWS\system32mwin32.exe
C:\WINDOWS\system32netode.exe
C:\WINDOWS\system32newsd32.exe
C:\WINDOWS\system32ps1.exe
C:\WINDOWS\system32psof1.exe
C:\WINDOWS\system32psoft1.exe
C:\WINDOWS\system32regc64.dll
C:\WINDOWS\system32regm64.dll
C:\WINDOWS\system32Rundl1.exe
C:\WINDOWS\system32smp
C:\WINDOWS\system32smp\msrc.exe
C:\WINDOWS\system32sncntr.exe
C:\WINDOWS\system32ssurf022.dll
C:\WINDOWS\system32ssvchost.com
C:\WINDOWS\system32ssvchost.exe
C:\WINDOWS\system32sysreq.exe
C:\WINDOWS\system32taack.dat
C:\WINDOWS\system32taack.exe
C:\WINDOWS\system32temp#01.exe
C:\WINDOWS\system32thun.dll
C:\WINDOWS\system32thun32.dll
C:\WINDOWS\system32VBIEWER.OCX
C:\WINDOWS\system32vbsys2.dll
C:\WINDOWS\system32vcatchpi.dll
C:\WINDOWS\system32winlogonpc.exe
C:\WINDOWS\system32winsystem.exe
C:\WINDOWS\system32WINWGPX.EXE
C:\WINDOWS\userconfig9x.dll
C:\WINDOWS\Web\def.htm
C:\WINDOWS\winsystem.exe
C:\WINDOWS\zip1.tmp
C:\WINDOWS\zip2.tmp
C:\WINDOWS\zip3.tmp
C:\WINDOWS\zipped.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DOMAINSERVICE
-------\Legacy_NTLOAD
((((((((((((((((((((((((( Files Created from 2008-03-20 to 2008-04-20 )))))))))))))))))))))))))))))))
.
2008-04-15 20:32 . 2008-04-15 20:32 <DIR> d-------- C:\Program Files\Blender Foundation
2008-04-15 20:32 . 2008-04-15 20:32 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-15 20:32 . 2008-04-15 20:32 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-13 20:57 . 2008-04-13 21:19 <DIR> d-------- C:\Documents and Settings\Owner.lapdawg\.gimp-2.4
2008-04-13 20:56 . 2008-04-13 20:56 <DIR> d-------- C:\Program Files\GIMP-2.0
2008-04-09 18:39 . 2008-04-09 18:41 1,355 --a------ C:\WINDOWS\imsins.BAK
2008-04-06 14:37 . 2007-12-29 15:50 6,854,656 --a--c--- C:\hellgate_sp_dx9_x86.exe
2008-04-04 20:47 . 2008-04-04 20:47 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-04 20:47 . 2008-04-05 19:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-04 00:07 . 2008-04-04 00:52 <DIR> d-------- C:\Program Files\DominateGame
2008-04-02 00:35 . 2008-04-02 22:18 <DIR> d-------- C:\Program Files\Rheingold3D
2008-04-01 21:40 . 2008-04-01 21:40 <DIR> d-------- C:\Program Files\Uniblue
2008-04-01 20:23 . 2008-04-01 20:24 1,600,027 ---hs---- C:\WINDOWS\system32\qpbmkhyq.ini
2008-04-01 09:21 . 2008-04-01 09:21 3,914 --a------ C:\WINDOWS\system32\ofxihahf.dll
2008-04-01 09:18 . 2008-04-01 09:18 3,914 --a------ C:\WINDOWS\system32\fsnadiof.dll
2008-03-31 23:20 . 2008-03-31 23:20 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-31 23:20 . 2008-03-31 23:20 <DIR> d-------- C:\Documents and Settings\Owner.lapdawg\Application Data\SUPERAntiSpyware.com
2008-03-31 23:20 . 2008-03-31 23:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-31 23:19 . 2008-03-31 23:19 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-31 21:28 . 2008-04-04 17:59 4,678 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-31 21:25 . 2008-03-31 21:25 18,944 --a------ C:\WINDOWS\system32\drvbin.dll
2008-03-30 23:40 . 2008-03-30 23:40 3,914 --a------ C:\WINDOWS\system32\uobdtxlj.dll
2008-03-30 23:37 . 2008-03-30 23:37 3,914 --a------ C:\WINDOWS\system32\euuwkpkc.dll
2008-03-30 00:32 . 2008-03-30 00:32 18,944 --a------ C:\WINDOWS\system32\drvsew.dll
2008-03-29 23:35 . 2008-03-31 23:28 1,584,057 ---hs---- C:\WINDOWS\system32\tkhwjyrg.ini
2008-03-29 22:39 . 2008-04-01 18:04 <DIR> d----c--- C:\!KillBox
2008-03-29 21:11 . 2008-03-29 21:11 18,944 --a------ C:\WINDOWS\system32\drvses.dll
2008-03-29 20:23 . 2008-03-29 20:24 <DIR> d-------- C:\Program Files\DancingGorilla
2008-03-29 18:51 . 2008-03-29 18:51 <DIR> d----c--- C:\67597b168ad9622978893c1ec50d8205
2008-03-29 17:18 . 2008-03-29 17:18 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-03-29 17:06 . 2008-03-29 18:41 1,583,937 ---hs---- C:\WINDOWS\system32\uluetamf.ini
2008-03-29 16:59 . 2008-03-29 16:59 4,096 --a------ C:\Documents and Settings\Owner.lapdawg\DesktopTrojan.Win32.BlackBird.exe
2008-03-29 15:34 . 2008-03-29 16:59 1,583,697 ---hs---- C:\WINDOWS\system32\tmwphuqu.ini
2008-03-29 15:01 . 2008-03-29 15:04 1,583,637 ---hs---- C:\WINDOWS\system32\sdeqfofe.ini
2008-03-29 14:53 . 2008-04-01 18:04 <DIR> d-------- C:\Program Files\IE Extensions
2008-03-29 01:40 . 2008-03-30 21:08 <DIR> d-------- C:\FLEXLM
2008-03-29 01:37 . 2008-03-29 01:37 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-03-27 21:18 . 2008-03-27 21:18 124,928 --ahs---- C:\WINDOWS\system32\iSecurity(2).cpl
2008-03-23 18:06 . 2008-04-13 20:54 <DIR> d-------- C:\Program Files\GIMPshop
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-20 02:56 --------- d-----w C:\Documents and Settings\Owner.lapdawg\Application Data\.purple
2008-04-15 12:35 27,588 ----a-w C:\Documents and Settings\Owner.lapdawg\Application Data\wklnhst.dat
2008-04-15 04:38 --------- d-----w C:\Documents and Settings\Owner.lapdawg\Application Data\gtk-2.0
2008-04-02 00:45 --------- d-----w C:\Program Files\twbwzijk
2008-03-30 05:37 --------- d-----w C:\Program Files\Diablo II
2008-03-30 01:56 --------- d-----w C:\Program Files\StepMania
2008-03-29 22:08 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-29 06:39 --------- d-----w C:\Program Files\AviCreator 1.5
2008-03-29 06:38 --------- d-----w C:\Program Files\Steam
2008-03-02 00:03 --------- d-----w C:\Documents and Settings\Owner.lapdawg\Application Data\Template
2008-02-28 04:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-28 04:04 --------- d-----w C:\Program Files\Zone Labs
2008-02-28 04:04 --------- d-----w C:\Program Files\Pure Networks
2008-02-28 04:04 --------- d-----w C:\Program Files\NibblesRHS
2008-02-28 04:04 --------- d-----w C:\Program Files\IMVU
2008-02-28 04:04 --------- d-----w C:\Program Files\Elaborate Bytes
2008-02-28 04:03 --------- d-----w C:\Program Files\Xfire
2008-02-23 22:19 --------- d-----w C:\Program Files\Finale NotePad 2007
2007-11-23 18:02 24,249 ----a-w C:\Documents and Settings\Owner.lapdawg\Application Data\info.dat
2007-05-06 02:22 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2007-09-15 19:22 66,936 --sha-w C:\WINDOWS\dlinfo_0.drv
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-03 15:49 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00 15360]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-10-24 17:10 4662776]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 09:47 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 09:47 688218]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"SigmatelSysTrayApp"="stsystra.exe" [2005-12-27 12:20 413696 C:\WINDOWS\stsystra.exe]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-05-23 21:22 573440]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 20:18 151552]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-12 00:02 53248]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-07-01 21:22 303104]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2005-08-26 16:26 212992]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 12:26 110592]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2005-08-12 18:16 1121792]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2005-08-10 14:49 163840]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-09-27 19:17 999424]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-26 18:03 98304]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 14:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 14:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 14:00 455168]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-09-26 18:02 26112]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2007-08-19 01:01 190024]
"c4cf0baf"="C:\WINDOWS\system32\bhuaykje.dll" [ ]
"BMc7fc3833"="C:\WINDOWS\system32\jiprusqe.dll" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Run Google Web Accelerator.lnk - C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe [2007-07-09 22:24:38 1134592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"9Zuux9F8B1"= C:\WINDOWS\TEMP\win3B0.exe
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddccCTmk]
ddccCTmk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winldd32]
winldd32.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2006-11-07 10:29 50736 C:\Program Files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\TEMP\win1A.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
--a------ 2007-09-07 18:01 43008 C:\Program Files\BitTorrent\bittorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMc7fc3833]
C:\WINDOWS\system32\qsoljkfr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bqratsvc]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\bqratsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c4cf0baf]
C:\WINDOWS\system32\feorqlyc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2006-09-28 14:21 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2007-08-29 10:09 171464 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\khuzqdmv]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\khuzqdmv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\klahizuf]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\klahizuf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSDisp32]
--a------ 2008-02-06 00:17 15872 C:\WINDOWS\system32\drvbuj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSDrive]
C:\WINDOWS\system32\drvgan.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-09-26 18:03 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\twbwzijk]
C:\Program Files\twbwzijk\pgtahqvk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2006-10-24 17:10 4662776 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Diablo\\diablo.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\BYOND\\bin\\byond.exe"=
"C:\\Program Files\\Starcraft\\StarCraft.exe"=
"C:\\Program Files\\Alias\\Maya8.0\\bin\\maya.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24686:TCP"= 24686:TCP:BitTorrent
"5738:TCP"= 5738:TCP:vbalink
"4664:TCP"= 4664:TCP:EMule
"4674:UDP"= 4674:UDP:Emule0
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-19 22:01:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\McAfee.com\Agent\Mcdetect.exe
C:\PROGRA~1\McAfee.com\VSO\McShield.exe
C:\PROGRA~1\McAfee.com\Agent\McTskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\McAfee\SpamKiller\MSKAgent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\VSO\McVSEscn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Google\Web Accelerator\GoogleWebAccClient.exe
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-04-19 22:06:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-20 03:06:27
Pre-Run: 56,224,247,808 bytes free
Post-Run: 56,089,899,008 bytes free
407 --- E O F --- 2008-04-10 08:01:48