Thanks for the continued help. My computer was pretty blasted, huh?
ComboFix 08-04-09.8 - Owner 2008-04-11 18:47:29.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.191 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINNT\system32\ohajerqn.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-11 to 2008-04-11 )))))))))))))))))))))))))))))))
.
2008-04-11 15:02 . 2008-04-11 15:02 118 --a------ C:\WINNT\system32\MRT.INI
2008-04-10 21:32 . 2008-04-10 21:32 106,496 --a------ C:\WINNT\system32\enubwvqr.exe
2008-04-08 22:26 . 2008-04-08 22:26 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\True Sword
2008-04-08 22:25 . 2008-04-08 22:29 <DIR> d-------- C:\Program Files\True Sword 4
2008-04-08 00:10 . 2008-04-08 00:10 9,662 --a------ C:\WINNT\system32\ZoneAlarmIconUS.ico
2008-04-06 20:06 . 2008-04-06 20:06 <DIR> d-------- C:\WINNT\FLEOK
2008-04-06 02:26 . 2008-04-06 02:26 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-06 00:03 . 2008-04-06 00:03 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Uniblue
2008-03-31 20:04 . 2008-03-31 20:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-19 09:47 1,845,248 ----a-w C:\WINNT\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINNT\system32\dllcache\win32k.sys
2008-02-20 06:51 282,624 ----a-w C:\WINNT\system32\gdi32.dll
2008-02-20 06:51 282,624 ------w C:\WINNT\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINNT\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ------w C:\WINNT\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ------w C:\WINNT\system32\dllcache\dnsapi.dll
2008-02-16 22:29 3,059,712 ------w C:\WINNT\system32\dllcache\mshtml.dll
2008-02-15 09:23 18,432 ------w C:\WINNT\system32\dllcache\iedw.exe
2008-02-04 23:23 693,792 ----a-w C:\WINNT\system32\OGACheckControl.DLL
2007-01-20 05:30 87,288 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( snapshot@2008-04-09_21.25.53.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-19 09:40:27 1,845,888 ----a-w C:\WINNT\$hf_mig$\KB941693\SP2QFE\win32k.sys
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINNT\$hf_mig$\KB941693\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINNT\$hf_mig$\KB941693\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINNT\$hf_mig$\KB941693\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINNT\$hf_mig$\KB941693\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINNT\$hf_mig$\KB941693\update\updspapi.dll
+ 2007-12-18 14:32:13 450,560 ----a-w C:\WINNT\$hf_mig$\KB944338\SP2QFE\jscript.dll
+ 2007-12-18 14:32:13 417,792 ----a-w C:\WINNT\$hf_mig$\KB944338\SP2QFE\vbscript.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINNT\$hf_mig$\KB944338\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINNT\$hf_mig$\KB944338\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINNT\$hf_mig$\KB944338\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINNT\$hf_mig$\KB944338\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINNT\$hf_mig$\KB944338\update\updspapi.dll
+ 2008-02-20 05:19:35 147,968 ----a-w C:\WINNT\$hf_mig$\KB945553\SP2QFE\dnsapi.dll
+ 2008-02-20 18:49:36 45,568 ----a-w C:\WINNT\$hf_mig$\KB945553\SP2QFE\dnsrslvr.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINNT\$hf_mig$\KB945553\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINNT\$hf_mig$\KB945553\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINNT\$hf_mig$\KB945553\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINNT\$hf_mig$\KB945553\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINNT\$hf_mig$\KB945553\update\updspapi.dll
+ 2008-02-16 09:32:03 1,024,000 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\browseui.dll
+ 2008-02-16 09:32:03 151,040 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\cdfview.dll
+ 2008-02-16 09:32:03 1,054,208 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\danim.dll
+ 2008-02-16 09:32:04 357,888 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\dxtmsft.dll
+ 2008-02-16 09:32:04 205,312 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\dxtrans.dll
+ 2008-02-16 09:32:04 55,808 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\extmgr.dll
+ 2008-02-15 09:07:53 18,432 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\iedw.exe
+ 2008-02-16 09:32:04 251,904 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\iepeers.dll
+ 2008-02-16 09:32:04 96,256 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\inseng.dll
+ 2008-02-16 09:32:04 16,384 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\jsproxy.dll
+ 2008-02-16 09:32:06 3,066,880 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\mshtml.dll
+ 2008-02-16 09:32:06 449,024 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\mshtmled.dll
+ 2008-02-16 09:32:06 146,432 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\msrating.dll
+ 2008-02-16 09:32:07 532,480 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\mstime.dll
+ 2008-02-16 09:32:07 39,424 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\pngfilt.dll
+ 2008-02-16 09:32:08 1,499,136 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\shdocvw.dll
+ 2008-02-16 09:32:08 474,112 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\shlwapi.dll
+ 2008-02-16 09:32:08 618,496 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\urlmon.dll
+ 2008-02-16 09:32:09 666,112 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\wininet.dll
+ 2008-02-15 09:06:21 351,744 ----a-w C:\WINNT\$hf_mig$\KB947864\SP2QFE\xpsp3res.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINNT\$hf_mig$\KB947864\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINNT\$hf_mig$\KB947864\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINNT\$hf_mig$\KB947864\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINNT\$hf_mig$\KB947864\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINNT\$hf_mig$\KB947864\update\updspapi.dll
+ 2008-02-20 06:52:43 282,624 ----a-w C:\WINNT\$hf_mig$\KB948590\SP2QFE\gdi32.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINNT\$hf_mig$\KB948590\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINNT\$hf_mig$\KB948590\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINNT\$hf_mig$\KB948590\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINNT\$hf_mig$\KB948590\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINNT\$hf_mig$\KB948590\update\updspapi.dll
- 2008-04-10 02:18:00 53,248 ----a-w C:\WINNT\PSEXESVC.EXE
+ 2008-04-11 23:51:37 53,248 ----a-w C:\WINNT\PSEXESVC.EXE
- 2007-12-07 01:07:12 1,023,488 ----a-w C:\WINNT\system32\browseui.dll
+ 2008-02-16 08:59:34 1,023,488 ----a-w C:\WINNT\system32\browseui.dll
- 2007-12-07 01:07:12 151,040 ----a-w C:\WINNT\system32\cdfview.dll
+ 2008-02-16 08:59:35 151,040 ----a-w C:\WINNT\system32\cdfview.dll
- 2007-12-07 01:07:12 1,054,208 ----a-w C:\WINNT\system32\danim.dll
+ 2008-02-16 08:59:35 1,054,208 ----a-w C:\WINNT\system32\danim.dll
- 2007-12-07 01:07:12 1,023,488 ------w C:\WINNT\system32\dllcache\browseui.dll
+ 2008-02-16 08:59:34 1,023,488 ------w C:\WINNT\system32\dllcache\browseui.dll
- 2007-12-07 01:07:12 151,040 ------w C:\WINNT\system32\dllcache\cdfview.dll
+ 2008-02-16 08:59:35 151,040 ------w C:\WINNT\system32\dllcache\cdfview.dll
- 2007-12-07 01:07:12 1,054,208 ------w C:\WINNT\system32\dllcache\danim.dll
+ 2008-02-16 08:59:35 1,054,208 ------w C:\WINNT\system32\dllcache\danim.dll
- 2007-12-07 01:07:12 357,888 ------w C:\WINNT\system32\dllcache\dxtmsft.dll
+ 2008-02-16 08:59:35 357,888 ------w C:\WINNT\system32\dllcache\dxtmsft.dll
- 2007-12-07 01:07:12 205,312 ------w C:\WINNT\system32\dllcache\dxtrans.dll
+ 2008-02-16 08:59:35 205,312 ------w C:\WINNT\system32\dllcache\dxtrans.dll
- 2007-12-07 01:07:12 55,808 ------w C:\WINNT\system32\dllcache\extmgr.dll
+ 2008-02-16 08:59:35 55,808 ------w C:\WINNT\system32\dllcache\extmgr.dll
- 2007-12-07 01:07:12 251,392 ------w C:\WINNT\system32\dllcache\iepeers.dll
+ 2008-02-16 08:59:35 251,392 ------w C:\WINNT\system32\dllcache\iepeers.dll
- 2007-12-07 01:07:12 96,256 ------w C:\WINNT\system32\dllcache\inseng.dll
+ 2008-02-16 08:59:35 96,256 ------w C:\WINNT\system32\dllcache\inseng.dll
- 2007-11-14 07:26:56 450,560 ------w C:\WINNT\system32\dllcache\jscript.dll
+ 2007-12-18 14:40:58 450,560 ------w C:\WINNT\system32\dllcache\jscript.dll
- 2007-12-07 01:07:12 16,384 ------w C:\WINNT\system32\dllcache\jsproxy.dll
+ 2008-02-16 08:59:35 16,384 ------w C:\WINNT\system32\dllcache\jsproxy.dll
- 2007-12-07 01:07:13 449,024 ------w C:\WINNT\system32\dllcache\mshtmled.dll
+ 2008-02-16 08:59:37 449,024 ------w C:\WINNT\system32\dllcache\mshtmled.dll
- 2007-12-07 01:07:13 146,432 ------w C:\WINNT\system32\dllcache\msrating.dll
+ 2008-02-16 08:59:37 146,432 ------w C:\WINNT\system32\dllcache\msrating.dll
- 2007-12-07 01:07:13 532,480 ------w C:\WINNT\system32\dllcache\mstime.dll
+ 2008-02-16 08:59:37 532,480 ------w C:\WINNT\system32\dllcache\mstime.dll
- 2007-12-07 01:07:13 39,424 ------w C:\WINNT\system32\dllcache\pngfilt.dll
+ 2008-02-16 08:59:37 39,424 ------w C:\WINNT\system32\dllcache\pngfilt.dll
- 2007-12-07 01:07:13 1,494,528 ------w C:\WINNT\system32\dllcache\shdocvw.dll
+ 2008-02-16 08:59:38 1,494,528 ------w C:\WINNT\system32\dllcache\shdocvw.dll
- 2007-12-07 01:07:13 474,112 ------w C:\WINNT\system32\dllcache\shlwapi.dll
+ 2008-02-16 08:59:38 474,112 ------w C:\WINNT\system32\dllcache\shlwapi.dll
- 2007-12-07 01:07:14 615,424 ------w C:\WINNT\system32\dllcache\urlmon.dll
+ 2008-02-16 08:59:38 615,936 ------w C:\WINNT\system32\dllcache\urlmon.dll
+ 2007-12-18 14:40:58 417,792 ------w C:\WINNT\system32\dllcache\vbscript.dll
- 2007-12-07 01:07:14 659,456 ------w C:\WINNT\system32\dllcache\wininet.dll
+ 2008-02-16 08:59:39 659,456 ------w C:\WINNT\system32\dllcache\wininet.dll
- 2006-06-26 17:37:10 148,480 ----a-w C:\WINNT\system32\dnsapi.dll
+ 2008-02-20 05:32:43 148,992 ----a-w C:\WINNT\system32\dnsapi.dll
- 2007-12-07 01:07:12 357,888 ----a-w C:\WINNT\system32\dxtmsft.dll
+ 2008-02-16 08:59:35 357,888 ----a-w C:\WINNT\system32\dxtmsft.dll
- 2007-12-07 01:07:12 205,312 ----a-w C:\WINNT\system32\dxtrans.dll
+ 2008-02-16 08:59:35 205,312 ----a-w C:\WINNT\system32\dxtrans.dll
- 2007-12-07 01:07:12 55,808 ------w C:\WINNT\system32\extmgr.dll
+ 2008-02-16 08:59:35 55,808 ------w C:\WINNT\system32\extmgr.dll
- 2007-04-06 20:07:16 302,824 ----a-w C:\WINNT\system32\FNTCACHE.DAT
+ 2008-04-11 20:09:34 302,824 ----a-w C:\WINNT\system32\FNTCACHE.DAT
- 2007-12-07 01:07:12 251,392 ----a-w C:\WINNT\system32\iepeers.dll
+ 2008-02-16 08:59:35 251,392 ----a-w C:\WINNT\system32\iepeers.dll
- 2007-12-07 01:07:12 96,256 ----a-w C:\WINNT\system32\inseng.dll
+ 2008-02-16 08:59:35 96,256 ----a-w C:\WINNT\system32\inseng.dll
- 2007-11-14 07:26:56 450,560 ----a-w C:\WINNT\system32\jscript.dll
+ 2007-12-18 14:40:58 450,560 ----a-w C:\WINNT\system32\jscript.dll
- 2007-12-07 01:07:12 16,384 ----a-w C:\WINNT\system32\jsproxy.dll
+ 2008-02-16 08:59:35 16,384 ----a-w C:\WINNT\system32\jsproxy.dll
+ 2008-04-06 03:56:22 19,836,024 ----a-w C:\WINNT\system32\MRT.exe
- 2007-12-07 14:37:14 3,059,200 ----a-w C:\WINNT\system32\mshtml.dll
+ 2008-02-16 22:29:38 3,059,712 ----a-w C:\WINNT\system32\mshtml.dll
- 2007-12-07 01:07:13 449,024 ----a-w C:\WINNT\system32\mshtmled.dll
+ 2008-02-16 08:59:37 449,024 ----a-w C:\WINNT\system32\mshtmled.dll
- 2007-12-07 01:07:13 146,432 ----a-w C:\WINNT\system32\msrating.dll
+ 2008-02-16 08:59:37 146,432 ----a-w C:\WINNT\system32\msrating.dll
- 2007-12-07 01:07:13 532,480 ----a-w C:\WINNT\system32\mstime.dll
+ 2008-02-16 08:59:37 532,480 ----a-w C:\WINNT\system32\mstime.dll
- 2007-12-07 01:07:13 39,424 ----a-w C:\WINNT\system32\pngfilt.dll
+ 2008-02-16 08:59:37 39,424 ----a-w C:\WINNT\system32\pngfilt.dll
- 2007-12-07 01:07:13 1,494,528 ----a-w C:\WINNT\system32\shdocvw.dll
+ 2008-02-16 08:59:38 1,494,528 ----a-w C:\WINNT\system32\shdocvw.dll
- 2007-12-07 01:07:13 474,112 ----a-w C:\WINNT\system32\shlwapi.dll
+ 2008-02-16 08:59:38 474,112 ----a-w C:\WINNT\system32\shlwapi.dll
- 2007-12-07 01:07:14 615,424 ----a-w C:\WINNT\system32\urlmon.dll
+ 2008-02-16 08:59:38 615,936 ----a-w C:\WINNT\system32\urlmon.dll
- 2004-08-04 07:56:46 417,792 ----a-w C:\WINNT\system32\vbscript.dll
+ 2007-12-18 14:40:58 417,792 ----a-w C:\WINNT\system32\vbscript.dll
- 2007-12-07 01:07:14 659,456 ----a-w C:\WINNT\system32\wininet.dll
+ 2008-02-16 08:59:39 659,456 ----a-w C:\WINNT\system32\wininet.dll
- 2007-12-06 09:38:31 350,720 ----a-w C:\WINNT\system32\xpsp3res.dll
+ 2008-02-15 09:06:21 351,744 ----a-w C:\WINNT\system32\xpsp3res.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [ ]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-28 13:39 68856]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"auezilll"="C:\WINNT\system32\enubwvqr.exe" [2008-04-10 21:32 106496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 02:56 33280 C:\WINNT\system32\rundll32.exe]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" [2001-01-03 14:50 66048 C:\WINNT\system32\SK9910DM.EXE]
"Keyboard Preload Check"="C:\OEMDRVRS\KEYB\Preload.exe" [ ]
"PROMon.exe"="PROMon.exe" [2002-04-18 18:32 73728 C:\WINNT\system32\PROMon.exe]
"WINDVDPatch"="CTHELPER.EXE" [2002-02-07 18:01 40960 C:\WINNT\system32\CTHELPER.EXE]
"UpdReg"="C:\WINNT\UpdReg.EXE" [2000-05-11 01:00 90112]
"Jet Detection"="C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe" [2001-10-04 01:00 28672]
"AdaptecDirectCD"="C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-02-28 08:47 675840]
"MMTray"="C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe" [2003-03-14 18:15 143360]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-05-21 01:21 90112]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 16:48 479232]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-06-01 13:55 180269]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-05 17:03 282624]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-06-21 18:57 5355832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-03-07 00:06 5181440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"cLfe2ZWsjU"= C:\Documents and Settings\All Users\Application Data\vepezgbu\hczqfmny.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\BearShare\\BearShare.exe"=
"C:\\Program Files\\AIM95\\aim.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
R0 SSFS0BB8;Spy Sweeper File System Filer Driver: 0BB8;C:\WINNT\system32\Drivers\SSFS0BB8.SYS [2007-06-21 18:43]
R2 NMSSvc;Intel® NMS;C:\WINNT\System32\NMSSvc.exe [2002-05-03 12:36]
R3 NMSCFG;NIC Management Service Configuration Driver;C:\WINNT\system32\drivers\NMSCFG.SYS [2002-05-03 12:36]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" []
S3 PCDRDRV;Pcdr Helper Driver;C:\Atf\Qctest\PCDoc\PCDRDRV.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe
*Newly Created Service* - NMSSVC
*Newly Created Service* - SYMTDI
.
Contents of the 'Scheduled Tasks' folder
"2008-04-11 22:30:00 C:\WINNT\Tasks\Disk Cleanup.job"
- C:\WINNT\system32\cleanmgr.exe
"2002-09-19 14:55:49 C:\WINNT\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2008-03-31 07:00:03 C:\WINNT\Tasks\wrSpySweeperTrialSweep.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe&/ScheduleSweep=wrSpySweeperTrialSweep
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- A:\
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-11 18:51:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINNT\system32\winlogon.exe
-> C:\WINNT\System32\NavLogon.dll
.
Completion time: 2008-04-11 18:53:11
ComboFix-quarantined-files.txt 2008-04-11 23:52:57
ComboFix2.txt 2008-04-10 18:34:58
ComboFix3.txt 2008-04-10 02:27:19
Pre-Run: 17,886,814,208 bytes free
Post-Run: 17,873,133,568 bytes free
.
2008-04-11 20:03:36 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:54:05 PM, on 4/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\System32\NMSSvc.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\system32\SK9910DM.EXE
C:\WINNT\system32\PROMon.exe
C:\WINNT\system32\CTHELPER.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINNT\system32\enubwvqr.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.protopage.com/bwkaelinR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINNT\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files\Google\Gmail Notifier\gnotify.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [auezilll] C:\WINNT\system32\enubwvqr.exe
O4 - HKLM\..\Policies\Explorer\Run: [cLfe2ZWsjU] C:\Documents and Settings\All Users\Application Data\vepezgbu\hczqfmny.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=58813O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....ploader1006.cabO16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) -
http://upload.facebo...toUploader3.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebo...otoUploader.cabO16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) -
http://web1.shutterf...ds/Uploader.cabO23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
--
End of file - 6797 bytes