ComboFix 09-08-10.01 - Maxim 08/10/2009 14:49.1.2 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3582.3333 [GMT -4:00]
Running from: c:\documents and settings\Maxim\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
?
c:\windows\system32\drivers\UACrwnrkixtpd.sys
c:\windows\system32\UACcsptoklwkb.dat
c:\windows\system32\UAChdkfuakvay.dll
c:\windows\system32\UACndkflaslxw.db
c:\windows\system32\UACnulwbcnkvu.dll
c:\windows\system32\UACsejisqdmxk.dll
c:\windows\system32\UACtknthyaymp.dll
c:\windows\system32\UACxfugmjnjqn.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_UACd.sys
-------\Legacy_SYSTEMNTMI
-------\Legacy_pnwjcule
-------\Legacy_zcvz
-------\Service_pnwjcule
-------\Service_zcvz
((((((((((((((((((((((((( Files Created from 2009-07-10 to 2009-08-10 )))))))))))))))))))))))))))))))
.
2009-08-10 18:31 . 2009-08-10 18:31 61440 ----a-w- c:\windows\system32\drivers\kdvegt.sys
2009-08-10 18:22 . 2009-08-10 18:22 61440 ----a-w- c:\windows\system32\drivers\zfibn.sys
2009-08-10 00:44 . 2009-08-10 00:44 -------- d-----w- c:\program files\Trend Micro
2009-08-09 23:11 . 2009-08-09 23:11 -------- d--h--w- c:\windows\PIF
2009-08-09 22:46 . 2009-08-09 22:46 -------- d-----w- C:\1ddc18167fe8f93cba4482ec9264
2009-08-09 22:35 . 2009-08-09 22:35 -------- d-----w- c:\program files\AVG
2009-08-09 22:35 . 2009-08-09 22:35 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\avg8
2009-08-09 22:29 . 2009-08-09 22:29 -------- d-----w- c:\documents and settings\Maxim\Application Data\AVG8
2009-08-09 22:02 . 2009-08-09 22:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-09 21:59 . 2009-08-09 21:59 -------- d-----w- c:\documents and settings\All Users\Malwarebytes' Anti-Malware
2009-08-09 21:53 . 2009-08-09 21:53 -------- d-----w- c:\documents and settings\Maxim\Malwarebytes' Anti-Malware
2009-08-09 21:50 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-09 21:50 . 2009-08-09 21:50 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
2009-08-09 21:50 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-09 21:42 . 2009-08-09 21:42 -------- d-----w- c:\program files\VS Revo Group
2009-08-09 20:36 . 2009-08-09 20:36 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-09 19:11 . 2009-06-05 17:23 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-08-07 03:09 . 2009-08-07 03:50 -------- d-----w- c:\documents and settings\Maxim\RAN
2009-07-26 05:11 . 2009-07-26 20:56 -------- d-----w- c:\documents and settings\Maxim\Starship.Troopers.2.2004.STV.DVDRip.XviD
2009-07-13 19:24 . 2009-07-17 15:46 -------- d-----w- c:\documents and settings\Maxim\Renzu
2009-07-13 15:13 . 2009-07-13 21:14 -------- d-----w- c:\documents and settings\Maxim\Bible Black Complete
2009-07-12 19:35 . 2009-07-12 19:35 326479 ----a-w- C:\722h.exe
2009-07-12 16:51 . 2009-07-12 19:27 326511 ----a-w- C:\72h.exe
2009-07-12 12:18 . 2009-07-12 13:51 326507 ----a-w- C:\23d2s2327h.exe
2009-07-12 12:13 . 2009-07-12 12:14 326507 ----a-w- C:\23ds2327h.exe
2009-07-12 12:12 . 2009-07-12 12:12 326511 ----a-w- C:\3ds2327h.exe
2009-07-12 12:08 . 2009-07-12 12:08 326511 ----a-w- C:\3ds327h.exe
2009-07-12 12:07 . 2009-07-12 12:07 326507 ----a-w- C:\3ds27h.exe
2009-07-11 22:50 . 2009-07-11 22:50 326511 ----a-w- C:\3222227h.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-10 18:57 . 2008-03-03 02:24 -------- d-----w- c:\documents and settings\Maxim\Application Data\OpenOffice.org2
2009-08-10 18:31 . 2009-08-10 18:31 286 ----a-w- c:\program files\qjhnfze.txt
2009-08-10 17:28 . 2007-07-03 06:04 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Google Updater
2009-08-10 02:01 . 2008-06-28 20:17 -------- d-----w- c:\program files\Electronic Arts
2009-08-09 23:29 . 2007-06-23 06:10 -------- d-----w- c:\program files\Belkin
2009-08-09 23:18 . 2009-03-13 21:59 -------- d-----w- c:\program files\Atari
2009-08-09 23:02 . 2007-12-04 03:04 -------- d-----w- c:\program files\Apprentice
2009-08-09 18:23 . 2007-08-19 21:42 -------- d-----w- c:\program files\Java
2009-08-09 05:36 . 2008-02-11 04:29 -------- d-----w- c:\documents and settings\Maxim\Application Data\uTorrent
2009-08-03 19:45 . 2007-10-21 21:38 -------- d-----w- c:\program files\Warcraft III
2009-07-25 09:23 . 2009-04-29 19:51 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-11 13:58 . 2009-07-11 13:58 326507 ----a-w- C:\32227h.exe
2009-07-11 13:46 . 2009-07-11 12:14 326507 ----a-w- C:\3227h.exe
2009-07-11 00:04 . 2009-07-10 18:26 326479 ----a-w- C:\327h.exe
2009-07-10 15:55 . 2009-07-10 15:50 326507 ----a-w- C:\2o322re.exe
2009-07-10 14:46 . 2009-07-10 14:46 326501 ----a-w- C:\2vo2te.exe
2009-07-10 14:39 . 2009-07-10 14:39 326505 ----a-w- C:\2vote.exe
2009-07-10 14:35 . 2009-07-10 14:35 326505 ----a-w- C:\vote.exe
2009-07-09 14:12 . 2007-06-26 05:43 -------- d-----w- c:\program files\DivX
2009-07-09 14:11 . 2009-05-11 18:45 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-07-03 18:33 . 2009-07-03 18:33 86016 ----a-w- c:\windows\system32\OpenAL32.dll
2009-07-03 18:33 . 2009-07-03 18:33 262144 ----a-w- c:\windows\system32\wrap_oal.dll
2009-07-03 18:30 . 2009-07-03 18:30 -------- d-----w- c:\program files\Futuremark
2009-07-03 18:30 . 2007-06-21 05:03 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-29 16:12 . 2006-02-28 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2006-02-28 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2006-02-28 12:00 17408 ------w- c:\windows\system32\corpol.dll
2009-06-16 14:36 . 2006-02-28 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2006-02-28 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-05 17:15 . 2007-06-23 05:09 15664 ----a-w- c:\documents and settings\Maxim\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-03 19:09 . 2006-02-28 12:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"Google Update"="c:\documents and settings\Maxim\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-03-14 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-04-20 53248]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2004-04-20 118784]
"OfficeKB"="c:\progra~1\OfficeKB\OfficeKB.EXE" [2004-10-22 200704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-06-02 267048]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-09-22 185896]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-18 1657376]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2004-10-21 29696]
c:\documents and settings\Maxim\Start Menu\Programs\Startup\
Flip.lnk - c:\program files\Belkin\Flip\flip.exe [2006-8-22 385024]
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Loadout Manager.lnk - c:\program files\Belkin\Nostromo\nost_LM.exe [2003-6-24 442368]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-6-23 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2007-6-23 581632]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Apprentice\\Appr.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"c:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe"=
"c:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\GGclient.exe"=
"c:\\Program Files\\THQ\\Dawn Of War\\W40k.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Tortun\\gui.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Documents and Settings\\Maxim\\Desktop\\Max\\Pokemon Game.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.0.8.9506-to-3.0.9.9551-enUS-downloader.exe"=
"c:\\Program Files\\Dawn of War 2\\DOW2.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/9/2009 6:35 PM 297752]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [4/1/2008 10:47 AM 24652]
S2 fmpqvxxg;fmpqvxxg;c:\windows\system32\drivers\yfhjax.sys --> c:\windows\system32\drivers\yfhjax.sys [?]
S3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys [7/23/2003 3:16 PM 22821]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-LDM - c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = localhost
FF - ProfilePath - c:\docume~1\Maxim\APPLIC~1\Mozilla\Firefox\Profiles\pu9jai39.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.ca/FF - plugin: c:\documents and settings\Maxim\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-10 14:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2016)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\program files\Belkin\Nostromo\nost_FSH.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\OpenOffice.org 2.3\program\soffice.exe
c:\program files\OpenOffice.org 2.3\program\soffice.bin
c:\program files\Logitech\SetPoint\KHALMNPR.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-08-10 15:00 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-10 19:00
Pre-Run: 41,180,155,904 bytes free
Post-Run: 42,429,214,720 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
227 --- E O F --- 2009-07-30 07:00