ComboFix 08-03-03.16 - Edward 2008-03-04 16:01:37.3 - NTFSx86 Running from: C:\Documents and Settings\Edward\Desktop\Combo-Fix.exe Command switches used :: C:\Documents and Settings\Edward\Desktop\CFScript.txt FILE :: C:\arbfikac.exe C:\Documents and Settings\Edward\.exe C:\jupss.exe C:\qsdjpwpb.exe C:\WINDOWS\BMf784c838.xml C:\WINDOWS\eqodowomuq.dll C:\WINDOWS\SYSTEM32\ebwgxhsq.ini C:\WINDOWS\SYSTEM32\frgrraem.ini C:\WINDOWS\SYSTEM32\iuhejwry.ini C:\WINDOWS\SYSTEM32\jhbykovs.ini C:\WINDOWS\SYSTEM32\jkghje.dll C:\WINDOWS\SYSTEM32\ldbjrkjv.ini C:\WINDOWS\SYSTEM32\ydcnlsfl.ini C:\WINDOWS\SYSTEM32\yljmgbvp.ini C:\WINDOWS\SYSTEM32\yoenolaw.dll C:\wpohl.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\arbfikac.exe C:\Documents and Settings\Edward\.exe C:\Documents and Settings\Edward\Application Data\FrostWire C:\Documents and Settings\Edward\Application Data\FrostWire\.NetworkShare\LimeWireWin4.16.3.exe C:\Documents and Settings\Edward\Application Data\FrostWire\createtimes.cache C:\Documents and Settings\Edward\Application Data\FrostWire\data.ser C:\Documents and Settings\Edward\Application Data\FrostWire\fileurns.bak C:\Documents and Settings\Edward\Application Data\FrostWire\fileurns.cache C:\Documents and Settings\Edward\Application Data\FrostWire\filters.props C:\Documents and Settings\Edward\Application Data\FrostWire\frostwire.props C:\Documents and Settings\Edward\Application Data\FrostWire\gnutella.net C:\Documents and Settings\Edward\Application Data\FrostWire\installation.props C:\Documents and Settings\Edward\Application Data\FrostWire\library.dat C:\Documents and Settings\Edward\Application Data\FrostWire\pub1.key C:\Documents and Settings\Edward\Application Data\FrostWire\public.key C:\Documents and Settings\Edward\Application Data\FrostWire\questions.props C:\Documents and Settings\Edward\Application Data\FrostWire\responses.cache C:\Documents and Settings\Edward\Application Data\FrostWire\secureMessage.key C:\Documents and Settings\Edward\Application Data\FrostWire\spam.dat C:\Documents and Settings\Edward\Application Data\FrostWire\tables.props C:\Documents and Settings\Edward\Application Data\FrostWire\themes\frostwire_theme.skin C:\Documents and Settings\Edward\Application Data\FrostWire\themes\frostwire_theme\kill.png C:\Documents and Settings\Edward\Application Data\FrostWire\themes\frostwire_theme\kill_on.png C:\Documents and Settings\Edward\Application Data\FrostWire\themes\frostwire_theme\theme.txt C:\Documents and Settings\Edward\Application Data\FrostWire\ttree.cache C:\Documents and Settings\Edward\Application Data\FrostWire\version.key C:\Documents and Settings\Edward\Application Data\FrostWire\version.xml C:\Documents and Settings\Edward\Application Data\FrostWire\xml\data\audio.sxml C:\Documents and Settings\Edward\Application Data\FrostWire\xml\data\delete_me C:\Documents and Settings\Edward\Application Data\FrostWire\xml\data\video.sxml C:\Documents and Settings\Edward\Application Data\FrostWire\xml\misc\application.gif C:\Documents and Settings\Edward\Application Data\FrostWire\xml\misc\audio.gif C:\Documents and Settings\Edward\Application Data\FrostWire\xml\misc\document.gif C:\Documents and Settings\Edward\Application Data\FrostWire\xml\misc\image.gif C:\Documents and Settings\Edward\Application Data\FrostWire\xml\misc\video.gif C:\Documents and Settings\Edward\Application Data\FrostWire\xml\schemas\application.xsd C:\Documents and Settings\Edward\Application Data\FrostWire\xml\schemas\audio.xsd C:\Documents and Settings\Edward\Application Data\FrostWire\xml\schemas\document.xsd C:\Documents and Settings\Edward\Application Data\FrostWire\xml\schemas\image.xsd C:\Documents and Settings\Edward\Application Data\FrostWire\xml\schemas\video.xsd C:\Documents and Settings\Edward\Application Data\uTorrent C:\Documents and Settings\Edward\Application Data\uTorrent\Ad-Aware SE Professional v1.06 + Multi Lang + All Ad-Ons.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\dht.dat C:\Documents and Settings\Edward\Application Data\uTorrent\dht.dat.old C:\Documents and Settings\Edward\Application Data\uTorrent\ESET.NOD32.Antivirus.Business.Edition.v3.0.566.CRACKED-CU.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\Mr.Brooks.DVDR-Replica.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\PC Booster 2008 1.0.0.1.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\Photoshop CS3 Extended Crack - WORKS.1.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\Photoshop CS3 Extended Crack - WORKS.2.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\Photoshop CS3 Extended Crack - WORKS.3.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\Photoshop CS3 Extended Crack - WORKS.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\Pop up Blocker Pro (Rich-Media Ads Edition)5.0.1.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\resume.dat C:\Documents and Settings\Edward\Application Data\uTorrent\resume.dat.old C:\Documents and Settings\Edward\Application Data\uTorrent\settings.dat C:\Documents and Settings\Edward\Application Data\uTorrent\settings.dat.old C:\Documents and Settings\Edward\Application Data\uTorrent\SpyHunter.3.4.9-MKDEV.TEAM.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\Spyware Doctor 5.5.0.178 - Final UPDATED.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\ss2g-ialdvdr.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\The_Fast_And_The_Furious_Tokyo_Drift_EUR_PSP-REV0.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\Transformers.MP4.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\Transformers.PROPER.DVDR-ThP.torrent C:\Documents and Settings\Edward\Application Data\uTorrent\wintasksprotrial2.rar.torrent C:\jupss.exe C:\Program Files\.autoreg\ C:\Program Files\FrostWire C:\Program Files\FrostWire\log.txt C:\Program Files\uTorrent C:\Program Files\uTorrent\uTorrent.exe C:\qsdjpwpb.exe C:\WINDOWS\BMf784c838.xml C:\WINDOWS\eqodowomuq.dll C:\WINDOWS\SYSTEM32\bbbbb\ C:\WINDOWS\SYSTEM32\ebwgxhsq.ini C:\WINDOWS\SYSTEM32\frgrraem.ini C:\WINDOWS\SYSTEM32\iuhejwry.ini C:\WINDOWS\SYSTEM32\jhbykovs.ini C:\WINDOWS\SYSTEM32\jkghje.dll C:\WINDOWS\SYSTEM32\ldbjrkjv.ini C:\WINDOWS\SYSTEM32\ydcnlsfl.ini C:\WINDOWS\SYSTEM32\yljmgbvp.ini C:\WINDOWS\SYSTEM32\yoenolaw.dll C:\wpohl.exe . ((((((((((((((((((((((((( Files Created from 2008-02-04 to 2008-03-04 ))))))))))))))))))))))))))))))) . 2008-03-03 23:15 . 2008-03-04 15:52 0 ---hs---- C:\WINDOWS\S7E46A0CD.tmp 2008-03-02 22:45 . 2008-03-02 23:32
----a-w 5,367,664 2008-02-20 02:31:03 C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI .exe[/code] ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {DE9C389F-3316-41A7-809B-AA305ED9D922} {2318C2B1-4965-11D4-9B18-009027A5CD4F} {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} {8E718888-423F-11D2-876E-00A0C9082467} [HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360] "Pop up Blocker Pro Rich-Media Ads Edition"="C:\Program Files\Pop up Blocker Pro RMA Edition\pdie.exe" [2008-03-03 15:19 1311232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="RUNDLL32.exe" [2004-08-04 02:56 33280 C:\WINDOWS\SYSTEM32\rundll32.exe] "Logitech Utility"="Logi_MwX.Exe" [2002-11-08 04:50 19968 C:\WINDOWS\LOGI_MWX.EXE] "SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-03-03 15:19 847872] "PC Booster"="C:\Program Files\inKline Global\PC Booster\pcbooster.exe" [2008-03-03 15:19 14450688] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2008-02-19 21:30 132496] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696] Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2002-11-24 03:40:29 45056] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "AllowLegacyWebView"= 1 (0x1) "AllowUnhashedWebView"= 1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoViewOnDrive"= 0 (0x0) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 nwprovau [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\yserver.exe"= "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\Common Files\\AOL\\1130193630\\ee\\aolsoftware.exe"= "C:\\Program Files\\Common Files\\AOL\\1130193630\\ee\\aim6.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\Program Files\\UltraVNC\\repeater.exe"= "C:\\Program Files\\UltraVNC\\winvnc.exe"= "C:\\Program Files\\UltraVNC\\vncviewer.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5900:TCP"= 5900:TCP:VNC [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{50292d6e-7815-11db-8d54-0007e9bbeae2}] \Shell\AutoRun\command - F:\LaunchU3.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{50292d6f-7815-11db-8d54-0007e9bbeae2}] \Shell\AutoRun\command - H:\setupSNK.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8bc06e0-c3bd-11db-8d74-0007e9bbeae2}] \Shell\AutoRun\command - F:\LaunchU3.exe [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\f5d94ac0-0718-4ed1-83fd-e34a38ac835b] C:\WINDOWS\System32\obarnxq.exe . Contents of the 'Scheduled Tasks' folder "2008-03-04 08:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job" - C:\Program Files\AdwareAlert\AdwareAlert .exe - C:\Program Files\AdwareAlert "2008-02-29 21:16:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-03-04 06:49:01 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe "2008-03-04 21:15:10 C:\WINDOWS\Tasks\PCHealth Scheduler for Upload Library.job" - C:\WINDOWS\PCHealth\UploadLB\Binaries\UploadM.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-03-04 16:12:50 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PSIService.exe C:\WINDOWS\System32\wdfmgr.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\UltraVNC\winvnc.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Logitech\MouseWare\system\em_exec.exe . ************************************************************************** . Completion time: 2008-03-04 16:20:11 - machine was rebooted ComboFix-quarantined-files.txt 2008-03-04 21:20:06 ComboFix2.txt 2008-03-04 04:24:38 ComboFix3.txt 2008-03-04 01:10:55 . 2008-02-13 08:13:07 --- E O F ---