sorry, i checked my computer again after i posted and a log file was on the screen. i dont know what happened but i guess i just needed to wait longer
ComboFix 09-12-08.03 - Anthony 12/14/2009 15:36:30.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.855 [GMT -5:00]
Running from: c:documents and settingsAnthonyMy DocumentsMathemergencycommy.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:docume~1AnthonyLOCALS~1Templsass.exe
c:docume~1AnthonyLOCALS~1Tempwinlogon.exe
c:docume~1AnthonyLOCALS~1Tempwscsvc32.exe
c:documents and settingsAll UsersApplication DataMicrosoftNetworkDownloaderqmgr0.dat
c:documents and settingsAll UsersApplication DataMicrosoftNetworkDownloaderqmgr1.dat
c:documents and settingsAnthonyLocal SettingsApplication Datapdvqtj
c:documents and settingsAnthonyLocal SettingsApplication Datapdvqtjcivssysguard.exe
c:documents and settingsAnthonyStart MenuProgramsStartupscandisk.dll
c:documents and settingsAnthonyStart MenuProgramsStartupscandisk.lnk
c:recyclerS-1-5-21-3781777486-0661304054-339478247-8690
c:recyclerS-1-5-21-3781777486-0661304054-339478247-8690Desktop.ini
c:recyclerS-1-5-21-3781777486-0661304054-339478247-8690msimfo32.exe
c:recyclerS-1-5-21-5289978000-5408025882-951223212-7940
c:windowsInstall.txt
c:windowssystem326to4v32.dll
c:windowssystem32AVR10.exe
c:windowssystem32BtwSrv.dll
c:windowssystem32certstore.dat
c:windowssystem32critical_warning.html
c:windowssystem32crt4.dll
c:windowssystem32FastNetSrv.exe
c:windowssystem32FInstall.sys
c:windowssystem32Iasv32.dll
c:windowssystem32Install.txt
c:windowssystem32kbdatat4.dll
c:windowssystem32kboem32.dat
c:windowssystem32kbupdate.dll
c:windowssystem32kidowavi.dll
c:windowssystem32md2092f86.dll
c:windowssystem32nijufagi.dll
c:windowssystem32nobiyaki.dll
c:windowssystem32notepad.dll
c:windowssystem32opeia.exe
c:windowssystem32penipure.dll
c:windowssystem32sazukojo.exe
c:windowssystem32tafiwizo.dll
c:windowssystem32tegavipo.exe
c:windowssystem32vidohosi.dll
c:windowssystem32winhelper86.dll
c:windowssystem32winlogon86.exe
c:windowssystem32winupdate86.exe
c:windowssystem32wmdtc.exe
c:windowssystem32yemopego.dll
c:windowsTasksmpgtzcdm.job
c:windowsTemp989609876.exe
c:windowsTEMPmta13187.dll
----- BITS: Possible infected sites -----
hxxp://82.98.231.102
hxxp://92.241.165.204
hxxp://thekmultimedia.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------Legacy_BTWSRV
-------Legacy_FASTNETSRV
-------Legacy_IAS
-------Service_BtwSrv
-------Service_fastnetsrv
-------Service_Ias
((((((((((((((((((((((((( Files Created from 2009-11-14 to 2009-12-14 )))))))))))))))))))))))))))))))
.
2009-12-11 16:36 . 2009-12-11 16:36 0 --sha-w- c:documents and settingsNetworkServicentload.dll
2009-12-11 07:40 . 2009-12-14 20:32 20 ----a-w- c:windowssystem32crt.dat
2009-12-11 07:40 . 2009-12-11 07:40 3584 ----a-w- C:udhkiixx.exe
2009-12-11 07:40 . 2009-12-11 07:40 156672 ----a-w- C:nymeu.exe
2009-12-11 07:40 . 2009-12-11 07:40 40960 ----a-w- C:pdvwd.exe
2009-12-11 07:39 . 2009-12-11 07:39 8704 ----a-w- C:ryiasu.exe
2009-12-11 07:39 . 2009-12-11 07:39 135168 ----a-w- C:dcgwhpoh.exe
2009-12-10 02:52 . 2009-12-10 02:52 -------- d-----w- c:documents and settingsAll UsersApplication DataF-Secure
2009-12-09 01:09 . 2009-12-09 01:09 -------- d-----w- c:documents and settingsAnthonyApplication DataMalwarebytes
2009-12-09 01:09 . 2009-12-03 21:14 38224 ----a-w- c:windowssystem32driversmbamswissarmy.sys
2009-12-09 01:09 . 2009-12-09 01:09 -------- d-----w- c:documents and settingsAll UsersApplication DataMalwarebytes
2009-12-09 01:09 . 2009-12-09 01:09 -------- d-----w- c:program filesMalwarebytes' Anti-Malware
2009-12-09 01:09 . 2009-12-03 21:13 19160 ----a-w- c:windowssystem32driversmbam.sys
2009-11-29 03:10 . 2009-11-29 03:10 -------- d-----w- c:documents and settingsAnthonyLocal SettingsApplication DataThreat Expert
2009-11-28 17:32 . 2009-11-28 17:32 79488 ----a-w- c:documents and settingsChrisApplication DataSunJavajre1.6.0_17gtapi.dll
2009-11-27 16:21 . 2009-11-27 16:21 -------- d-----w- c:program filesTrend Micro
2009-11-27 05:31 . 2009-11-27 05:31 -------- d-----w- c:documents and settingsChrisApplication DataAvanquest
2009-11-27 04:56 . 2009-11-27 04:58 -------- d-----w- c:program filesWindows Live Safety Center
2009-11-23 20:07 . 2009-11-29 05:24 79488 ----a-w- c:documents and settingsAnthonyApplication DataSunJavajre1.6.0_17gtapi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-09 04:19 . 2007-06-08 18:22 -------- d-----w- c:program filesFull Tilt Poker
2009-11-29 03:37 . 2008-03-07 20:05 -------- d-----w- c:program filesSpyware Doctor
2009-11-29 03:12 . 2008-03-07 20:06 -------- d---a-w- c:documents and settingsAll UsersApplication DataTEMP
2009-11-15 01:05 . 2009-10-10 23:31 -------- d-----w- c:program filesWorld of Warcraft
2009-10-29 07:46 . 2005-10-21 17:51 832512 ----a-w- c:windowssystem32wininet.dll
2009-10-29 07:46 . 2004-08-04 07:56 78336 ----a-w- c:windowssystem32ieencode.dll
2009-10-29 07:46 . 2003-07-16 20:25 17408 ----a-w- c:windowssystem32corpol.dll
2009-10-29 03:42 . 2006-03-02 22:30 39952 ----a-w- c:documents and settingsAnthonyLocal SettingsApplication DataGDIPFONTCACHEV1.DAT
2009-10-21 05:38 . 2004-08-04 07:56 75776 ----a-w- c:windowssystem32strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 ----a-w- c:windowssystem32httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 ------w- c:windowssystem32drivershttp.sys
2009-10-20 04:15 . 2009-10-20 04:15 -------- d-----w- c:program filesMicrosoft Silverlight
2009-10-13 10:30 . 2003-07-16 20:40 270336 ----a-w- c:windowssystem32oakley.dll
2009-10-12 13:38 . 2003-07-16 20:42 149504 ----a-w- c:windowssystem32rastls.dll
2009-10-12 13:38 . 2003-07-16 20:42 79872 ----a-w- c:windowssystem32raschap.dll
2009-10-11 04:04 . 2006-02-23 00:43 77423 ----a-w- c:windowsPCHealthHelpCtrOfflineCacheindex.dat
2009-09-12 04:03 . 2009-09-12 04:03 39424 --sha-w- c:windowssystem32barijatu.dll
2009-09-12 04:03 . 2009-09-12 04:03 54272 --sha-w- c:windowssystem32kabujupe.dll
2009-09-13 03:56 . 2009-09-13 03:56 39424 --sha-w- c:windowssystem32mayotomo.dll
2009-09-12 04:04 . 2009-09-12 04:04 54272 --sha-w- c:windowssystem32pebuhewe.dll
2009-09-14 19:18 . 2009-09-14 19:18 61952 --sha-w- c:windowssystem32vajatika.dll
2009-09-14 19:18 . 2009-09-14 19:18 39424 --sha-w- c:windowssystem32vohelipe.dll
2009-09-13 03:56 . 2009-09-13 03:56 45568 --sha-w- c:windowssystem32wogutopa.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE~Browser Helper Objects{14a12408-071b-4e7c-8b8d-9c195174b0be}]
2009-09-12 04:04 54272 --sha-w- c:windowssystem32pebuhewe.dll
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"MSMSGS"="c:program filesMessengermsmsgs.exe" [2008-04-14 1695232]
"swg"="c:program filesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe" [2007-06-26 68856]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NvCplDaemon"="c:windowsSystem32NvCpl.dll" [2003-11-03 4800512]
"diagent"="c:program filesCreativeSBLiveDiagnosticsdiagent.exe" [2002-04-03 135264]
"UpdReg"="c:windowsUpdReg.EXE" [2000-05-11 90112]
"dla"="c:windowssystem32dlatfswctrl.exe" [2004-03-15 122933]
"Dell AIO Printer A920"="c:program filesDell AIO Printer A920dlbkbmgr.exe" [2003-06-02 270336]
"masqform.exe"="c:program filesPureEdgeViewer 6.0masqform.exe" [2004-01-27 1048576]
"Ulead AutoDetector"="c:program filesUlead SystemsUlead Photo Explorer 8.0 SE BasicMonitor.exe" [2003-11-18 45056]
"Ulead Photo Express Calendar Checker"="c:program filesUlead SystemsUlead Photo Express 5 SEcalcheck.exe" [2004-01-13 69632]
"QuickTime Task"="c:program filesQuickTimeqttask.exe" [2008-01-10 385024]
"VirusScannerPro"="c:progra~1AVANQU~1Fix-ItMemCheck.exe" [2007-09-01 173312]
"Symantec PIF AlertEng"="c:program filesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PifSvc.exe" [2007-03-12 517768]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:documents and settingsAll UsersStart MenuProgramsStartup
Adobe Reader Speed Launch.lnk - c:program filesAdobeAcrobat 7.0Readerreader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalsdauxservice]
@=""
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalsdcoreservice]
@=""
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"c:\Program Files\Bonjour\mDNSResponder.exe"=
R2 tmpreflt;tmpreflt;c:progra~1AVANQU~1Fix-Ittmpreflt.sys [8/31/2007 12:36 PM 32528]
R3 MailScan;MailScan;c:progra~1AVANQU~1Fix-ItMailScan.sys [9/1/2007 5:58 AM 20496]
S3 ndisdrv;ndisdrv;c:windowssystem32ndisdrv.sys [7/16/2003 3:33 PM 2304]
S3 winsts;winsts;c:windowssystem32winsts.sys [7/16/2003 3:33 PM 2304]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MAILSCAN
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: &Yahoo! Search - file:///c:program filesYahoo!Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:progra~1MICROS~3Office12EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:program filesYahoo!Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:program filesYahoo!Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:program filesYahoo!Common/ycsms.htm
TCP: {B5CE61BE-37D9-4C95-8031-F02ABCFDCCB3} = 193.104.110.38,4.2.2.1,192.168.1.254
.
- - - - ORPHANS REMOVED - - - -
BHO-{C5B24B16-23F2-41AD-F4E4-00ABC39C0004} - c:windowssystem32md2092f86.dll
HKCU-Run-ngqbbvca - c:documents and settingsAnthonyLocal SettingsApplication Datapdvqtjcivssysguard.exe
HKLM-Run-notepad - c:windowssystem32notepad.dll
HKLM-Run-StartServiceNMDECMPM - c:documents and settingsAnthonyLocal SettingsApplication DataNMDECMPMStartService.exe
HKLM-Run-ngqbbvca - c:documents and settingsAnthonyLocal SettingsApplication Datapdvqtjcivssysguard.exe
HKLM-Run-pafulomip - c:windowssystem32kidowavi.dll
HKLM-Run-pugirofuge - tafiwizo.dll
SharedTaskScheduler-{C5B24B16-23F2-41AD-F4E4-00ABC39C0004} - c:windowssystem32md2092f86.dll
SharedTaskScheduler-{e7eaac45-3be4-48bc-b587-c625968085e2} - c:windowssystem32wewusigo.dll
SharedTaskScheduler-{b10269a1-0229-4fcc-bcb7-1402f6331ecb} - c:windowssystem32sonosuje.dll
SharedTaskScheduler-{82e79279-52b7-4927-81cf-ce75211e8af6} - c:windowssystem32kidowavi.dll
SSODL-jinakabiw-{e7eaac45-3be4-48bc-b587-c625968085e2} - c:windowssystem32wewusigo.dll
SSODL-sudodefuf-{b10269a1-0229-4fcc-bcb7-1402f6331ecb} - c:windowssystem32sonosuje.dll
SSODL-jokufovag-{82e79279-52b7-4927-81cf-ce75211e8af6} - c:windowssystem32kidowavi.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-14 15:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3512)
c:windowssystem32WININET.dll
c:progra~1AVANQU~1Fix-ItWinHook.dll
c:windowssystem32ieframe.dll
c:windowssystem32mshtml.dll
.
------------------------ Other Running Processes ------------------------
.
c:windowssystem32LEXBCES.EXE
c:windowssystem32LEXPPS.EXE
c:program filesSymantecLiveUpdateAluSchedulerSvc.exe
c:program filesBonjourmDNSResponder.exe
c:windowsSystem32CTsvcCDA.exe
c:progra~1AVANQU~1Fix-Itmxtask.exe
c:program filesJavajre6binjqs.exe
c:windowsSystem32nvsvc32.exe
c:program filesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
c:windowsSystem32MsPMSPSv.exe
c:progra~1AVANQU~1Fix-Itmxtask.exe
c:windowssystem32wscntfy.exe
c:program filesDell AIO Printer A920dlbkbmon.exe
.
**************************************************************************
.
Completion time: 2009-12-14 15:55:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-14 20:55
ComboFix2.txt 2009-12-08 19:36
ComboFix3.txt 2009-11-29 03:49
Pre-Run: 8,525,221,888 bytes free
Post-Run: 8,823,894,016 bytes free
- - End Of File - - 2C44215E99278466C0A299E811237243
ComboFix 09-12-08.03 - Anthony 12/14/2009 15:36:30.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.855 [GMT -5:00]
Running from: c:documents and settingsAnthonyMy DocumentsMathemergencycommy.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:docume~1AnthonyLOCALS~1Templsass.exe
c:docume~1AnthonyLOCALS~1Tempwinlogon.exe
c:docume~1AnthonyLOCALS~1Tempwscsvc32.exe
c:documents and settingsAll UsersApplication DataMicrosoftNetworkDownloaderqmgr0.dat
c:documents and settingsAll UsersApplication DataMicrosoftNetworkDownloaderqmgr1.dat
c:documents and settingsAnthonyLocal SettingsApplication Datapdvqtj
c:documents and settingsAnthonyLocal SettingsApplication Datapdvqtjcivssysguard.exe
c:documents and settingsAnthonyStart MenuProgramsStartupscandisk.dll
c:documents and settingsAnthonyStart MenuProgramsStartupscandisk.lnk
c:recyclerS-1-5-21-3781777486-0661304054-339478247-8690
c:recyclerS-1-5-21-3781777486-0661304054-339478247-8690Desktop.ini
c:recyclerS-1-5-21-3781777486-0661304054-339478247-8690msimfo32.exe
c:recyclerS-1-5-21-5289978000-5408025882-951223212-7940
c:windowsInstall.txt
c:windowssystem326to4v32.dll
c:windowssystem32AVR10.exe
c:windowssystem32BtwSrv.dll
c:windowssystem32certstore.dat
c:windowssystem32critical_warning.html
c:windowssystem32crt4.dll
c:windowssystem32FastNetSrv.exe
c:windowssystem32FInstall.sys
c:windowssystem32Iasv32.dll
c:windowssystem32Install.txt
c:windowssystem32kbdatat4.dll
c:windowssystem32kboem32.dat
c:windowssystem32kbupdate.dll
c:windowssystem32kidowavi.dll
c:windowssystem32md2092f86.dll
c:windowssystem32nijufagi.dll
c:windowssystem32nobiyaki.dll
c:windowssystem32notepad.dll
c:windowssystem32opeia.exe
c:windowssystem32penipure.dll
c:windowssystem32sazukojo.exe
c:windowssystem32tafiwizo.dll
c:windowssystem32tegavipo.exe
c:windowssystem32vidohosi.dll
c:windowssystem32winhelper86.dll
c:windowssystem32winlogon86.exe
c:windowssystem32winupdate86.exe
c:windowssystem32wmdtc.exe
c:windowssystem32yemopego.dll
c:windowsTasksmpgtzcdm.job
c:windowsTemp989609876.exe
c:windowsTEMPmta13187.dll
----- BITS: Possible infected sites -----
hxxp://82.98.231.102
hxxp://92.241.165.204
hxxp://thekmultimedia.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------Legacy_BTWSRV
-------Legacy_FASTNETSRV
-------Legacy_IAS
-------Service_BtwSrv
-------Service_fastnetsrv
-------Service_Ias
((((((((((((((((((((((((( Files Created from 2009-11-14 to 2009-12-14 )))))))))))))))))))))))))))))))
.
2009-12-11 16:36 . 2009-12-11 16:36 0 --sha-w- c:documents and settingsNetworkServicentload.dll
2009-12-11 07:40 . 2009-12-14 20:32 20 ----a-w- c:windowssystem32crt.dat
2009-12-11 07:40 . 2009-12-11 07:40 3584 ----a-w- C:udhkiixx.exe
2009-12-11 07:40 . 2009-12-11 07:40 156672 ----a-w- C:nymeu.exe
2009-12-11 07:40 . 2009-12-11 07:40 40960 ----a-w- C:pdvwd.exe
2009-12-11 07:39 . 2009-12-11 07:39 8704 ----a-w- C:ryiasu.exe
2009-12-11 07:39 . 2009-12-11 07:39 135168 ----a-w- C:dcgwhpoh.exe
2009-12-10 02:52 . 2009-12-10 02:52 -------- d-----w- c:documents and settingsAll UsersApplication DataF-Secure
2009-12-09 01:09 . 2009-12-09 01:09 -------- d-----w- c:documents and settingsAnthonyApplication DataMalwarebytes
2009-12-09 01:09 . 2009-12-03 21:14 38224 ----a-w- c:windowssystem32driversmbamswissarmy.sys
2009-12-09 01:09 . 2009-12-09 01:09 -------- d-----w- c:documents and settingsAll UsersApplication DataMalwarebytes
2009-12-09 01:09 . 2009-12-09 01:09 -------- d-----w- c:program filesMalwarebytes' Anti-Malware
2009-12-09 01:09 . 2009-12-03 21:13 19160 ----a-w- c:windowssystem32driversmbam.sys
2009-11-29 03:10 . 2009-11-29 03:10 -------- d-----w- c:documents and settingsAnthonyLocal SettingsApplication DataThreat Expert
2009-11-28 17:32 . 2009-11-28 17:32 79488 ----a-w- c:documents and settingsChrisApplication DataSunJavajre1.6.0_17gtapi.dll
2009-11-27 16:21 . 2009-11-27 16:21 -------- d-----w- c:program filesTrend Micro
2009-11-27 05:31 . 2009-11-27 05:31 -------- d-----w- c:documents and settingsChrisApplication DataAvanquest
2009-11-27 04:56 . 2009-11-27 04:58 -------- d-----w- c:program filesWindows Live Safety Center
2009-11-23 20:07 . 2009-11-29 05:24 79488 ----a-w- c:documents and settingsAnthonyApplication DataSunJavajre1.6.0_17gtapi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-09 04:19 . 2007-06-08 18:22 -------- d-----w- c:program filesFull Tilt Poker
2009-11-29 03:37 . 2008-03-07 20:05 -------- d-----w- c:program filesSpyware Doctor
2009-11-29 03:12 . 2008-03-07 20:06 -------- d---a-w- c:documents and settingsAll UsersApplication DataTEMP
2009-11-15 01:05 . 2009-10-10 23:31 -------- d-----w- c:program filesWorld of Warcraft
2009-10-29 07:46 . 2005-10-21 17:51 832512 ----a-w- c:windowssystem32wininet.dll
2009-10-29 07:46 . 2004-08-04 07:56 78336 ----a-w- c:windowssystem32ieencode.dll
2009-10-29 07:46 . 2003-07-16 20:25 17408 ----a-w- c:windowssystem32corpol.dll
2009-10-29 03:42 . 2006-03-02 22:30 39952 ----a-w- c:documents and settingsAnthonyLocal SettingsApplication DataGDIPFONTCACHEV1.DAT
2009-10-21 05:38 . 2004-08-04 07:56 75776 ----a-w- c:windowssystem32strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 ----a-w- c:windowssystem32httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 ------w- c:windowssystem32drivershttp.sys
2009-10-20 04:15 . 2009-10-20 04:15 -------- d-----w- c:program filesMicrosoft Silverlight
2009-10-13 10:30 . 2003-07-16 20:40 270336 ----a-w- c:windowssystem32oakley.dll
2009-10-12 13:38 . 2003-07-16 20:42 149504 ----a-w- c:windowssystem32rastls.dll
2009-10-12 13:38 . 2003-07-16 20:42 79872 ----a-w- c:windowssystem32raschap.dll
2009-10-11 04:04 . 2006-02-23 00:43 77423 ----a-w- c:windowsPCHealthHelpCtrOfflineCacheindex.dat
2009-09-12 04:03 . 2009-09-12 04:03 39424 --sha-w- c:windowssystem32barijatu.dll
2009-09-12 04:03 . 2009-09-12 04:03 54272 --sha-w- c:windowssystem32kabujupe.dll
2009-09-13 03:56 . 2009-09-13 03:56 39424 --sha-w- c:windowssystem32mayotomo.dll
2009-09-12 04:04 . 2009-09-12 04:04 54272 --sha-w- c:windowssystem32pebuhewe.dll
2009-09-14 19:18 . 2009-09-14 19:18 61952 --sha-w- c:windowssystem32vajatika.dll
2009-09-14 19:18 . 2009-09-14 19:18 39424 --sha-w- c:windowssystem32vohelipe.dll
2009-09-13 03:56 . 2009-09-13 03:56 45568 --sha-w- c:windowssystem32wogutopa.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE~Browser Helper Objects{14a12408-071b-4e7c-8b8d-9c195174b0be}]
2009-09-12 04:04 54272 --sha-w- c:windowssystem32pebuhewe.dll
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"MSMSGS"="c:program filesMessengermsmsgs.exe" [2008-04-14 1695232]
"swg"="c:program filesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe" [2007-06-26 68856]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NvCplDaemon"="c:windowsSystem32NvCpl.dll" [2003-11-03 4800512]
"diagent"="c:program filesCreativeSBLiveDiagnosticsdiagent.exe" [2002-04-03 135264]
"UpdReg"="c:windowsUpdReg.EXE" [2000-05-11 90112]
"dla"="c:windowssystem32dlatfswctrl.exe" [2004-03-15 122933]
"Dell AIO Printer A920"="c:program filesDell AIO Printer A920dlbkbmgr.exe" [2003-06-02 270336]
"masqform.exe"="c:program filesPureEdgeViewer 6.0masqform.exe" [2004-01-27 1048576]
"Ulead AutoDetector"="c:program filesUlead SystemsUlead Photo Explorer 8.0 SE BasicMonitor.exe" [2003-11-18 45056]
"Ulead Photo Express Calendar Checker"="c:program filesUlead SystemsUlead Photo Express 5 SEcalcheck.exe" [2004-01-13 69632]
"QuickTime Task"="c:program filesQuickTimeqttask.exe" [2008-01-10 385024]
"VirusScannerPro"="c:progra~1AVANQU~1Fix-ItMemCheck.exe" [2007-09-01 173312]
"Symantec PIF AlertEng"="c:program filesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PifSvc.exe" [2007-03-12 517768]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:documents and settingsAll UsersStart MenuProgramsStartup
Adobe Reader Speed Launch.lnk - c:program filesAdobeAcrobat 7.0Readerreader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalsdauxservice]
@=""
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalsdcoreservice]
@=""
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"c:\Program Files\Bonjour\mDNSResponder.exe"=
R2 tmpreflt;tmpreflt;c:progra~1AVANQU~1Fix-Ittmpreflt.sys [8/31/2007 12:36 PM 32528]
R3 MailScan;MailScan;c:progra~1AVANQU~1Fix-ItMailScan.sys [9/1/2007 5:58 AM 20496]
S3 ndisdrv;ndisdrv;c:windowssystem32ndisdrv.sys [7/16/2003 3:33 PM 2304]
S3 winsts;winsts;c:windowssystem32winsts.sys [7/16/2003 3:33 PM 2304]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MAILSCAN
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: &Yahoo! Search - file:///c:program filesYahoo!Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:progra~1MICROS~3Office12EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:program filesYahoo!Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:program filesYahoo!Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:program filesYahoo!Common/ycsms.htm
TCP: {B5CE61BE-37D9-4C95-8031-F02ABCFDCCB3} = 193.104.110.38,4.2.2.1,192.168.1.254
.
- - - - ORPHANS REMOVED - - - -
BHO-{C5B24B16-23F2-41AD-F4E4-00ABC39C0004} - c:windowssystem32md2092f86.dll
HKCU-Run-ngqbbvca - c:documents and settingsAnthonyLocal SettingsApplication Datapdvqtjcivssysguard.exe
HKLM-Run-notepad - c:windowssystem32notepad.dll
HKLM-Run-StartServiceNMDECMPM - c:documents and settingsAnthonyLocal SettingsApplication DataNMDECMPMStartService.exe
HKLM-Run-ngqbbvca - c:documents and settingsAnthonyLocal SettingsApplication Datapdvqtjcivssysguard.exe
HKLM-Run-pafulomip - c:windowssystem32kidowavi.dll
HKLM-Run-pugirofuge - tafiwizo.dll
SharedTaskScheduler-{C5B24B16-23F2-41AD-F4E4-00ABC39C0004} - c:windowssystem32md2092f86.dll
SharedTaskScheduler-{e7eaac45-3be4-48bc-b587-c625968085e2} - c:windowssystem32wewusigo.dll
SharedTaskScheduler-{b10269a1-0229-4fcc-bcb7-1402f6331ecb} - c:windowssystem32sonosuje.dll
SharedTaskScheduler-{82e79279-52b7-4927-81cf-ce75211e8af6} - c:windowssystem32kidowavi.dll
SSODL-jinakabiw-{e7eaac45-3be4-48bc-b587-c625968085e2} - c:windowssystem32wewusigo.dll
SSODL-sudodefuf-{b10269a1-0229-4fcc-bcb7-1402f6331ecb} - c:windowssystem32sonosuje.dll
SSODL-jokufovag-{82e79279-52b7-4927-81cf-ce75211e8af6} - c:windowssystem32kidowavi.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-14 15:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3512)
c:windowssystem32WININET.dll
c:progra~1AVANQU~1Fix-ItWinHook.dll
c:windowssystem32ieframe.dll
c:windowssystem32mshtml.dll
.
------------------------ Other Running Processes ------------------------
.
c:windowssystem32LEXBCES.EXE
c:windowssystem32LEXPPS.EXE
c:program filesSymantecLiveUpdateAluSchedulerSvc.exe
c:program filesBonjourmDNSResponder.exe
c:windowsSystem32CTsvcCDA.exe
c:progra~1AVANQU~1Fix-Itmxtask.exe
c:program filesJavajre6binjqs.exe
c:windowsSystem32nvsvc32.exe
c:program filesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
c:windowsSystem32MsPMSPSv.exe
c:progra~1AVANQU~1Fix-Itmxtask.exe
c:windowssystem32wscntfy.exe
c:program filesDell AIO Printer A920dlbkbmon.exe
.
**************************************************************************
.
Completion time: 2009-12-14 15:55:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-14 20:55
ComboFix2.txt 2009-12-08 19:36
ComboFix3.txt 2009-11-29 03:49
Pre-Run: 8,525,221,888 bytes free
Post-Run: 8,823,894,016 bytes free
- - End Of File - - 2C44215E99278466C0A299E811237243