One more time let me say Thanks for all your help
Edit: also still getting this stupid dodouble site god im hateing that site more and more every day
ComboFix 08-02.05.3 - Sheila Joy 2008-02-09 10:43:08.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.546 [GMT -5:00]
Running from: D:\Documents and Settings\Sheila Joy\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
D:\WINDOWS\msvrc20.dll
D:\WINDOWS\start.exe
D:\WINDOWS\system32\_000005_.tmp.dll
D:\WINDOWS\system32\windows.scr
D:\WINDOWS\Web\default.htt
----- BITS: Possible infected sites -----
hxxp://www.download.windowsupdate.com
.
((((((((((((((((((((((((( Files Created from 2008-01-09 to 2008-02-09 )))))))))))))))))))))))))))))))
.
2008-02-08 22:22 . 2008-02-08 22:22 54,156 --ah----- D:\WINDOWS\QTFont.qfn
2008-02-08 22:22 . 2008-02-08 22:22 1,409 --a------ D:\WINDOWS\QTFont.for
2008-02-08 22:07 . 2008-02-08 22:07 <DIR> d-------- D:\Program Files\QuickTime
2008-02-08 22:07 . 2008-02-08 22:07 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-08 19:04 . 2008-02-08 19:04 <DIR> d-------- D:\Documents and Settings\NetworkService\Application Data\Apple
2008-02-08 14:51 . 2008-02-08 14:51 <DIR> d-------- D:\_OTMoveIt
2008-02-08 14:30 . 2008-02-08 14:30 <DIR> d-------- D:\WINDOWS\ERUNT
2008-02-08 14:30 . 2008-02-07 15:37 <DIR> d-------- D:\SDFix
2008-02-08 13:46 . 2008-02-08 13:46 <DIR> d-------- D:\Deckard
2008-02-08 10:27 . 2008-02-08 10:27 <DIR> d-------- D:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-02-08 10:27 . 2008-02-08 10:27 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-08 00:00 . 2008-02-08 00:00 12,052 --a------ D:\Charis Sig2.JPG
2008-02-07 23:57 . 2008-02-07 23:57 13,398 --a------ D:\Charis Sig.JPG
2008-02-07 23:57 . 2008-02-07 23:57 9,385 --a------ D:\Charis Sig1.JPG
2008-02-07 23:52 . 2008-02-07 23:53 240,054 --a------ D:\Charis Sig.bmp
2008-02-07 09:27 . 2008-02-07 09:27 <DIR> d-------- D:\Program Files\Lavasoft
2008-02-07 09:15 . 2008-02-07 09:15 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-07 09:13 . 2008-02-07 09:13 <DIR> d-------- D:\Program Files\Common Files\Wise Installation Wizard
2008-02-07 07:25 . 2008-02-07 07:25 <DIR> d-------- D:\WINDOWS\SYSTEM32\ActiveScan
2008-02-07 07:25 . 2008-02-07 08:59 30,590 --a------ D:\WINDOWS\SYSTEM32\pavas.ico
2008-02-07 07:25 . 2008-02-07 08:59 2,550 --a------ D:\WINDOWS\SYSTEM32\Uninstall.ico
2008-02-07 07:25 . 2008-02-07 08:59 1,406 --a------ D:\WINDOWS\SYSTEM32\Help.ico
2008-02-04 22:48 . 2008-02-04 22:48 <DIR> d-------- D:\Program Files\Apple Software Update
2008-02-04 22:48 . 2008-02-04 22:48 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Apple
2008-02-04 22:44 . 2008-02-04 22:44 <DIR> d-------- D:\Documents and Settings\Sheila Joy\Application Data\Apple Computer
2008-02-04 20:42 . 2008-02-04 20:42 <DIR> d-------- D:\Program Files\Veoh Networks
2008-01-31 23:13 . 2008-01-31 23:13 90,112 --a------ D:\WINDOWS\SYSTEM32\QuickTimeVR.qtx
2008-01-31 23:13 . 2008-01-31 23:13 57,344 --a------ D:\WINDOWS\SYSTEM32\QuickTime.qts
2008-01-31 21:33 . 2008-01-31 21:33 <DIR> d-------- D:\Program Files\CCleaner
2008-01-30 20:23 . 2008-01-30 20:23 <DIR> d-------- D:\Documents and Settings\Administrator\Application Data\Grisoft
2008-01-30 15:50 . 2008-01-30 15:50 <DIR> d-------- D:\Documents and Settings\Sheila Joy\Application Data\Grisoft
2008-01-30 15:48 . 2007-05-30 07:10 10,872 --a------ D:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2008-01-30 15:47 . 2008-01-30 15:47 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-30 15:23 . 2008-01-30 15:23 <DIR> d-------- D:\VundoFix Backups
2008-01-29 14:48 . 2008-01-29 14:48 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\ATI
2008-01-29 14:39 . 2007-12-20 21:05 593,920 --------- D:\WINDOWS\SYSTEM32\ati2sgag.exe
2008-01-29 14:31 . 2008-01-29 14:33 664 --a------ D:\WINDOWS\SYSTEM32\d3d9caps.dat
2008-01-29 14:25 . 2008-01-29 14:25 <DIR> d-------- D:\Documents and Settings\Sheila Joy\Application Data\INAC
2008-01-29 14:25 . 2008-01-29 14:25 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\INAC
2008-01-29 14:15 . 2008-01-29 14:15 <DIR> d-------- D:\Program Files\ATI Technologies
2008-01-29 12:28 . 2008-01-29 14:21 67,645 --a------ D:\WINDOWS\SYSTEM32\DRIVERS\pshook11.sys
2008-01-29 12:27 . 2008-01-29 12:27 <DIR> d-------- D:\Program Files\INAC
2008-01-29 11:19 . 2004-09-10 15:52 <DIR> d-------- D:\WINDOWS\SYSTEM32\DRIVERS\INFUpdate
2008-01-29 11:18 . 2005-01-06 10:19 <DIR> d-------- D:\WINDOWS\SYSTEM32\DRIVERS\IAA
2008-01-29 01:33 . 2008-01-29 01:33 <DIR> d-------- D:\Program Files\Microsoft Silverlight
2008-01-29 01:03 . 2008-02-01 21:03 40 --a------ D:\WINDOWS\nero.INI
2008-01-28 22:01 . 2003-07-13 02:49 1,204,224 --------- D:\WINDOWS\UNMRW.exe
2008-01-28 22:01 . 2003-07-13 02:49 1,155,072 --------- D:\WINDOWS\UNNMIX.exe
2008-01-28 22:01 . 2003-07-13 02:49 1,155,072 --------- D:\WINDOWS\NuNinst.exe
2008-01-28 22:01 . 2003-07-13 02:49 172,248 --------- D:\WINDOWS\UNNMIX.cfg
2008-01-28 22:01 . 2003-07-13 02:50 106,496 --a------ D:\WINDOWS\SYSTEM32\TwnLib20.dll
2008-01-28 22:01 . 2003-07-13 02:49 47,262 --------- D:\WINDOWS\NuNinst.cfg
2008-01-28 22:01 . 2003-07-13 02:49 29,390 --------- D:\WINDOWS\UNMRW.cfg
2008-01-28 22:01 . 2003-07-13 02:49 23,920 --------- D:\WINDOWS\SYSTEM32\DRIVERS\incdrm.sys
2008-01-28 22:00 . 2008-01-28 22:00 <DIR> d-------- D:\WINDOWS\InCD
2008-01-28 22:00 . 2008-01-28 22:00 <DIR> d-------- D:\Documents and Settings\Sheila Joy\Application Data\NeroVision
2008-01-28 22:00 . 2003-07-13 02:50 1,155,072 --------- D:\WINDOWS\UNNeroVision.exe
2008-01-28 22:00 . 2003-07-13 02:49 85,360 --------- D:\WINDOWS\SYSTEM32\DRIVERS\incdfs.sys
2008-01-28 22:00 . 2003-07-13 02:50 65,056 --------- D:\WINDOWS\UNNeroVision.cfg
2008-01-28 22:00 . 2003-07-13 02:49 26,784 --------- D:\WINDOWS\SYSTEM32\DRIVERS\incdpass.sys
2008-01-28 22:00 . 2003-07-13 02:49 4,976 --------- D:\WINDOWS\SYSTEM32\DRIVERS\incdrec.sys
2008-01-28 21:59 . 2003-07-13 02:49 89,184 --------- D:\WINDOWS\SYSTEM32\DRIVERS\imagedrv.sys
2008-01-28 21:59 . 2003-07-13 02:49 57,344 --------- D:\WINDOWS\SYSTEM32\ImageDrive.cpl
2008-01-28 21:58 . 2003-07-13 02:50 569,344 --a------ D:\WINDOWS\SYSTEM32\imagr5.dll
2008-01-28 21:58 . 2003-07-13 02:50 544,768 --a------ D:\WINDOWS\SYSTEM32\imagx5.dll
2008-01-28 21:58 . 2003-07-13 02:50 283,920 --a------ D:\WINDOWS\SYSTEM32\ImagXpr5.dll
2008-01-28 21:58 . 2003-07-13 02:49 155,648 --a------ D:\WINDOWS\SYSTEM32\NeroCheck.exe
2008-01-28 21:58 . 2003-07-13 02:50 38,912 --a------ D:\WINDOWS\SYSTEM32\picn20.dll
2008-01-28 21:13 . 2008-01-28 21:13 0 --a------ D:\WINDOWS\Irremote.ini
2008-01-28 20:51 . 2008-01-28 20:51 <DIR> d-------- D:\Documents and Settings\Sheila Joy\Application Data\Nero
2008-01-28 20:47 . 2008-01-28 20:47 <DIR> d-------- D:\Program Files\Common Files\Nero
2008-01-28 20:47 . 2008-01-28 20:47 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Nero
2008-01-28 15:39 . 2001-05-11 13:18 420,240 --a------ D:\WINDOWS\SYSTEM32\mpg4c32.dll
2008-01-28 15:39 . 2001-05-16 17:54 309,616 --a------ D:\WINDOWS\SYSTEM32\wmv8dmod.dll
2008-01-28 15:39 . 2001-03-26 04:41 245,760 --a------ D:\WINDOWS\SYSTEM32\mp4sds32.ax
2008-01-28 15:24 . 2008-01-28 15:25 <DIR> d-------- D:\Program Files\CamStudio
2008-01-27 11:16 . 2008-01-27 11:17 268 --ah----- D:\sqmdata06.sqm
2008-01-27 11:16 . 2008-01-27 11:17 244 --ah----- D:\sqmnoopt06.sqm
2008-01-26 22:23 . 2008-01-26 22:23 0 --a------ D:\WINDOWS\SelSet.INI
2008-01-26 15:59 . 2004-08-03 23:08 31,616 --a------ D:\WINDOWS\SYSTEM32\DRIVERS\usbccgp.sys
2008-01-26 15:59 . 2004-08-03 23:08 31,616 --a------ D:\WINDOWS\SYSTEM32\dllcache\usbccgp.sys
2008-01-26 15:59 . 2004-08-04 00:56 21,504 --a------ D:\WINDOWS\SYSTEM32\hidserv.dll
2008-01-26 15:59 . 2004-08-04 00:56 21,504 --a------ D:\WINDOWS\SYSTEM32\dllcache\hidserv.dll
2008-01-26 15:59 . 2004-08-03 22:58 14,848 --a------ D:\WINDOWS\SYSTEM32\DRIVERS\kbdhid.sys
2008-01-26 15:59 . 2004-08-03 22:58 14,848 --a------ D:\WINDOWS\SYSTEM32\dllcache\kbdhid.sys
2008-01-26 15:59 . 2001-08-17 13:48 12,160 --a------ D:\WINDOWS\SYSTEM32\DRIVERS\mouhid.sys
2008-01-26 15:59 . 2001-08-17 13:48 12,160 --a------ D:\WINDOWS\SYSTEM32\dllcache\mouhid.sys
2008-01-26 15:59 . 2001-08-17 14:02 9,600 --a------ D:\WINDOWS\SYSTEM32\DRIVERS\hidusb.sys
2008-01-26 15:59 . 2001-08-17 14:02 9,600 --a------ D:\WINDOWS\SYSTEM32\dllcache\hidusb.sys
2008-01-25 20:42 . 2008-01-25 20:42 <DIR> d-------- D:\Documents and Settings\Sheila Joy\Application Data\Motive
2008-01-25 20:40 . 2008-01-25 20:40 <DIR> d-------- D:\WINDOWS\Motive
2008-01-25 20:31 . 2008-01-25 20:31 <DIR> d-------- D:\Program Files\Common Files\Motive
2008-01-25 20:31 . 2008-01-25 20:31 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Motive
2008-01-25 20:31 . 2004-08-11 01:50 589,824 --a------ D:\WINDOWS\SYSTEM32\MCCDNSHLP_1-0-0_DSR.dll
2008-01-24 20:13 . 2008-01-24 20:13 <DIR> d-------- D:\Fraps
2008-01-22 10:01 . 2008-01-22 10:01 <DIR> d-------- D:\L2blaze
2008-01-16 05:13 . 2008-01-16 05:13 <DIR> d-------- D:\l2tc
2008-01-15 21:36 . 2008-01-15 21:36 <DIR> d-------- D:\Program Files\KeyScrambler
2008-01-15 21:36 . 2007-12-29 09:35 112,992 --a------ D:\WINDOWS\SYSTEM32\DRIVERS\keyscrambler.sys
2008-01-14 07:52 . 2008-01-14 07:52 81,920 --a------ D:\WINDOWS\SYSTEM32\frapsvid.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 15:55 32 --sha-w D:\WINDOWS\system32\drivers\fidbox.idx
2008-02-09 15:55 32 --sha-w D:\WINDOWS\system32\drivers\fidbox.dat
2008-02-08 05:43 5,505,024 ------w D:\WINDOWS\Internet Logs\xDBBE.tmp
2008-02-08 05:43 1,457,152 ------w D:\WINDOWS\Internet Logs\xDBBD.tmp
2008-02-07 17:57 1,606,656 ------w D:\WINDOWS\Internet Logs\xDBBC.tmp
2008-02-07 09:12 5,505,024 ------w D:\WINDOWS\Internet Logs\xDBBB.tmp
2008-02-07 06:26 5,505,024 ------w D:\WINDOWS\Internet Logs\xDBBA.tmp
2008-02-07 06:26 1,212,416 ------w D:\WINDOWS\Internet Logs\xDBB9.tmp
2008-02-07 01:57 5,505,024 ------w D:\WINDOWS\Internet Logs\xDBB8.tmp
2008-02-06 05:02 1,958,912 ------w D:\WINDOWS\Internet Logs\xDBB7.tmp
2008-02-05 07:09 1,439,232 ------w D:\WINDOWS\Internet Logs\xDBB6.tmp
2008-02-04 23:48 526,848 ------w D:\WINDOWS\Internet Logs\xDBB5.tmp
2008-02-04 21:08 734,720 ------w D:\WINDOWS\Internet Logs\xDBB4.tmp
2008-02-04 15:10 69,120 ------w D:\WINDOWS\Internet Logs\xDBB3.tmp
2008-02-04 12:55 150,016 ------w D:\WINDOWS\Internet Logs\xDBB2.tmp
2008-02-04 05:31 5,505,024 ------w D:\WINDOWS\Internet Logs\xDBB1.tmp
2008-02-04 05:31 1,307,648 ------w D:\WINDOWS\Internet Logs\xDBB0.tmp
2008-02-03 20:30 5,505,024 ------w D:\WINDOWS\Internet Logs\xDBAF.tmp
2008-02-03 20:30 3,506,176 ------w D:\WINDOWS\Internet Logs\xDBAE.tmp
2008-02-02 07:18 5,505,024 ------w D:\WINDOWS\Internet Logs\xDBAD.tmp
2008-02-02 07:18 1,098,752 ------w D:\WINDOWS\Internet Logs\xDBAC.tmp
2008-02-01 05:52 882,176 ------w D:\WINDOWS\Internet Logs\xDBAA.tmp
2008-02-01 05:52 5,505,024 ------w D:\WINDOWS\Internet Logs\xDBAB.tmp
2008-02-01 01:34 5,505,024 ------w D:\WINDOWS\Internet Logs\xDBA9.tmp
2008-02-01 01:34 46,080 ------w D:\WINDOWS\Internet Logs\xDBA8.tmp
2008-02-01 00:18 168,448 ------w D:\WINDOWS\Internet Logs\xDBA7.tmp
2008-01-31 10:58 1,687,552 ------w D:\WINDOWS\Internet Logs\xDBA6.tmp
2008-01-31 06:46 5,505,024 ------w D:\WINDOWS\Internet Logs\xDBA5.tmp
2008-01-31 06:46 1,212,416 ------w D:\WINDOWS\Internet Logs\xDBA4.tmp
2008-01-31 03:22 69,544 ----a-w D:\Documents and Settings\Sheila Joy\Application Data\GDIPFONTCACHEV1.DAT
2008-01-31 02:57 5,505,024 ------w D:\WINDOWS\Internet Logs\xDBA3.tmp
2008-01-31 02:57 164,864 ------w D:\WINDOWS\Internet Logs\xDBA2.tmp
2008-01-31 01:21 5,505,024 ------w D:\WINDOWS\Internet Logs\xDBA1.tmp
2008-01-31 01:21 2,760,192 ------w D:\WINDOWS\Internet Logs\xDBA0.tmp
2008-01-30 19:21 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB9F.tmp
2008-01-30 19:21 1,409,024 ------w D:\WINDOWS\Internet Logs\xDB9E.tmp
2008-01-30 17:22 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB9D.tmp
2008-01-30 17:22 1,081,344 ------w D:\WINDOWS\Internet Logs\xDB9C.tmp
2008-01-30 17:14 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB9B.tmp
2008-01-30 17:14 1,146,880 ------w D:\WINDOWS\Internet Logs\xDB9A.tmp
2008-01-30 16:43 1,343,488 ------w D:\WINDOWS\Internet Logs\xDB99.tmp
2008-01-30 15:45 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB98.tmp
2008-01-30 15:45 160,256 ------w D:\WINDOWS\Internet Logs\xDB97.tmp
2008-01-30 15:23 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB96.tmp
2008-01-30 15:23 1,081,344 ------w D:\WINDOWS\Internet Logs\xDB95.tmp
2008-01-30 08:26 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB94.tmp
2008-01-30 08:26 1,183,232 ------w D:\WINDOWS\Internet Logs\xDB93.tmp
2008-01-30 01:56 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB92.tmp
2008-01-30 01:56 1,600,000 ------w D:\WINDOWS\Internet Logs\xDB91.tmp
2008-01-29 19:18 676,864 ------w D:\WINDOWS\Internet Logs\xDB90.tmp
2008-01-29 16:31 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB8F.tmp
2008-01-29 07:02 587,776 ------w D:\WINDOWS\Internet Logs\xDB8E.tmp
2008-01-29 06:15 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB105.tmp
2008-01-29 04:22 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB8D.tmp
2008-01-29 04:22 1,081,344 ------w D:\WINDOWS\Internet Logs\xDB8C.tmp
2008-01-29 03:02 195,072 ------w D:\WINDOWS\Internet Logs\xDB8B.tmp
2008-01-29 02:21 2,129,920 ------w D:\WINDOWS\Internet Logs\xDB8A.tmp
2008-01-28 21:38 9,623,677 ------w D:\WINDOWS\Internet Logs\tvDebug.zip
2008-01-28 01:57 863,232 ------w D:\WINDOWS\Internet Logs\xDB89.tmp
2008-01-27 18:36 863,744 ------w D:\WINDOWS\Internet Logs\xDB87.tmp
2008-01-27 18:36 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB88.tmp
2008-01-27 07:46 1,081,344 ------w D:\WINDOWS\Internet Logs\xDB86.tmp
2008-01-27 03:23 197,632 ------w D:\WINDOWS\Internet Logs\xDB85.tmp
2008-01-26 23:44 688,128 ------w D:\WINDOWS\Internet Logs\xDB83.tmp
2008-01-26 23:44 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB84.tmp
2008-01-26 16:55 504,320 ------w D:\WINDOWS\Internet Logs\xDB82.tmp
2008-01-26 05:52 993,792 ------w D:\WINDOWS\Internet Logs\xDB80.tmp
2008-01-26 05:52 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB81.tmp
2008-01-26 01:00 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB7F.tmp
2008-01-26 01:00 326,144 ------w D:\WINDOWS\Internet Logs\xDB7E.tmp
2008-01-25 23:50 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB7D.tmp
2008-01-25 23:50 1,300,992 ------w D:\WINDOWS\Internet Logs\xDB7C.tmp
2008-01-25 15:33 707,072 ------w D:\WINDOWS\Internet Logs\xDB7A.tmp
2008-01-25 15:33 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB7B.tmp
2008-01-25 04:49 599,552 ------w D:\WINDOWS\Internet Logs\xDB78.tmp
2008-01-25 04:49 5,505,024 ------w D:\WINDOWS\Internet Logs\xDB79.tmp
2008-01-25 02:11 1,081,344 ------w D:\WINDOWS\Internet Logs\xDB77.tmp
2008-01-24 06:15 530,944 ------w D:\WINDOWS\Internet Logs\xDB75.tmp
2008-01-24 06:14 4,454,400 ------w D:\WINDOWS\Internet Logs\xDB76.tmp
2008-01-24 02:51 4,453,888 ------w D:\WINDOWS\Internet Logs\xDB74.tmp
2008-01-24 02:51 2,086,912 ------w D:\WINDOWS\Internet Logs\xDB73.tmp
2008-01-23 09:59 4,453,376 ------w D:\WINDOWS\Internet Logs\xDB72.tmp
2008-01-23 09:59 1,765,376 ------w D:\WINDOWS\Internet Logs\xDB71.tmp
2008-01-23 01:17 4,451,328 ------w D:\WINDOWS\Internet Logs\xDB70.tmp
2008-01-23 01:17 1,655,808 ------w D:\WINDOWS\Internet Logs\xDB6F.tmp
2008-01-22 09:13 111,104 ------w D:\WINDOWS\Internet Logs\xDB6E.tmp
2008-01-22 08:52 2,839,040 ------w D:\WINDOWS\Internet Logs\xDB6D.tmp
2008-01-21 04:40 858,112 ------w D:\WINDOWS\Internet Logs\xDB6B.tmp
2008-01-21 04:40 4,428,800 ------w D:\WINDOWS\Internet Logs\xDB6C.tmp
2008-01-20 05:45 4,428,288 ------w D:\WINDOWS\Internet Logs\xDB6A.tmp
2008-01-20 05:45 1,413,120 ------w D:\WINDOWS\Internet Logs\xDB69.tmp
2008-01-19 21:46 4,427,776 ------w D:\WINDOWS\Internet Logs\xDB68.tmp
2008-01-19 21:46 177,664 ------w D:\WINDOWS\Internet Logs\xDB67.tmp
2008-01-19 20:43 599,040 ------w D:\WINDOWS\Internet Logs\xDB65.tmp
2008-01-19 20:43 4,426,240 ------w D:\WINDOWS\Internet Logs\xDB66.tmp
2008-01-19 06:42 4,425,216 ------w D:\WINDOWS\Internet Logs\xDB64.tmp
2008-01-19 06:42 1,132,544 ------w D:\WINDOWS\Internet Logs\xDB63.tmp
2008-01-18 07:16 4,424,192 ------w D:\WINDOWS\Internet Logs\xDB62.tmp
2008-01-18 07:16 322,048 ------w D:\WINDOWS\Internet Logs\xDB61.tmp
2008-01-18 06:15 88,448 ------w D:\WINDOWS\Internet Logs\vsmon_2nd_2008_01_18_01_02_52_small.dmp.zip
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="D:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"!1_ProcessGuard_Startup"="D:\Program Files\ProcessGuard\procguard.exe" [2005-01-20 14:24 280064]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"Veoh"="D:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-01-30 12:55 3497984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
"RemoteControl"="D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 21:01 71216]
"HPDJ Taskbar Utility"="D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 10:46 172032]
"!1_pgaccount"="D:\Program Files\ProcessGuard\pgaccount.exe" [2005-01-20 14:14 184320]
"QuickTime Task"="D:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADUserMon]
D:\Program Files\Iomega\AutoDisk\ADUserMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiPTA]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"Zone Labs Client"="D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
R0 tdrpman;tdrpman;D:\WINDOWS\system32\DRIVERS\tdrpman.sys [2008-01-05 11:35]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};D:\Program Files\CyberLink\PowerDVD\
000.fcl [2007-09-19 21:37]
R2 DCSPGSRV;DiamondCS Process Guard Service v3.000;"D:\Program Files\ProcessGuard\dcsuserprot.exe" [2005-01-20 14:25]
R2 procguard;procguard;D:\WINDOWS\system32\drivers\procguard.sys [2005-01-20 14:13]
R3 KeyScrambler;KeyScrambler;D:\WINDOWS\system32\drivers\keyscrambler.sys [2007-12-29 09:35]
S1 atitray;atitray;D:\Program Files\Radeon Omega Drivers\v3.8.421\ATI Tray Tools\atitray.sys []
S3 MS1000;MS1000;D:\WINDOWS\system32\DRIVERS\MS1000.sys [2007-12-25 15:50]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"D:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"D:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
"D:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"D:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"D:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
"D:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
D:\WINDOWS\SYSTEM32\updcrl.exe -e -u D:\WINDOWS\SYSTEM\verisignpub1.crl
.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 04:00:04 D:\WINDOWS\Tasks\Tune-up Application Start.job"
"2008-02-09 15:49:00 D:\WINDOWS\Tasks\PCHealth Scheduler for Data Collection.job"
- D:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE
"2008-02-09 00:03:02 D:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- D:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-09 10:59:00
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\WINDOWS\System32\snmp.exe
D:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
D:\WINDOWS\SYSTEM32\ZONELABS\avsys\ScanningProcess.exe
D:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
.
**************************************************************************
.
Completion time: 2008-02-09 11:03:39 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-09 16:03:16
.
2008-01-23 01:06:50 --- E O F ---
Logfile of HijackThis v1.99.1
Scan saved at 11:08:57 AM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Program Files\ProcessGuard\dcsuserprot.exe
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\WINDOWS\System32\snmp.exe
D:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
D:\Program Files\ProcessGuard\pgaccount.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\ProcessGuard\procguard.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Veoh Networks\Veoh\VeohClient.exe
D:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\Program Files\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - D:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [RemoteControl] "D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [!1_pgaccount] "D:\Program Files\ProcessGuard\pgaccount.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [!1_ProcessGuard_Startup] "D:\Program Files\ProcessGuard\procguard.exe" -minimize
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Veoh] "D:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone:
http://l2.hopzone.netO15 - Trusted Zone:
http://www.veoh.comO16 - DPF: Win32 Classes -
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://pcpitstop.com...p/PCPitStop.CABO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) -
http://messenger.zon...ds.cab57176.cabO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) -
http://www.fileplane...C_2.3.6.108.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.hotmail....es/MSNPUpld.cabO16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zon...1/GAME_UNO1.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1198496957953O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1198854948453O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://messenger.zon...ro.cab56649.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab56907.cabO16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://www.adobe.com...obat/nos/gp.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) -
http://messenger.zon...ss.cab57176.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - D:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - D:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - D:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - D:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - DiamondCS - D:\Program Files\ProcessGuard\dcsuserprot.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Unknown owner - D:\Program Files\Iomega\AutoDisk\ADService.exe (file missing)
Edited by Charis1973, 09 February 2008 - 10:13 AM.