ComboFix 08-04-13.3 - Administrator 2008-04-15 21:36:30.2 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.364 [GMT -5:00]
Running from: F:\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\spools.exe
C:\WINDOWS\system32\ntos.exe
C:\WINDOWS\system32\wsnpoem
C:\WINDOWS\system32\wsnpoem\audio.dll
C:\WINDOWS\system32\wsnpoem\video.dll
.
---- Previous Run -------
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Ruben\Application Data\Anti-Virus-Pro.com
C:\Documents and Settings\Ruben\Start Menu\Programs\Brave-Sentry
C:\Documents and Settings\Ruben\Start Menu\Programs\Brave-Sentry\BraveSentry.lnk
C:\Documents and Settings\Ruben\Start Menu\Programs\Brave-Sentry\Uninstall.lnk
C:\Documents and Settings\Ruben\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Ruben\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Ruben\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\Ruben\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Ruben\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Ruben\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\AntiVirusPro
C:\Program Files\bravesentry
C:\Program Files\bravesentry\BraveSentry.exe
C:\Program Files\bravesentry\BraveSentry.lic
C:\Program Files\bravesentry\BraveSentry0.bs
C:\Program Files\bravesentry\BraveSentry1.bs
C:\Program Files\bravesentry\Uninstall.exe
C:\Program Files\Helper
C:\Program Files\Helper\1208089291.dll
C:\Program Files\ISM
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\NetProject
C:\Program Files\NetProject\ot.ico
C:\Program Files\NetProject\sbmdl.dll
C:\Program Files\NetProject\sbmntr.exe
C:\Program Files\NetProject\sbsm.exe
C:\Program Files\NetProject\scit.exe
C:\Program Files\NetProject\scm.exe
C:\Program Files\NetProject\ts.ico
C:\Program Files\NetProject\waun.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\QdrDrive15.dll
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\dicy.gz
C:\Program Files\QdrModule\kwdy.gz
C:\Program Files\QdrModule\pckr.dat
C:\Program Files\QdrModule\QdrModule15.exe
C:\Program Files\QdrPack
C:\Program Files\QdrPack\dicts.gz
C:\Program Files\QdrPack\QdrPack15.exe
C:\Program Files\QdrPack\trgts.gz
C:\Program Files\scurit~1
C:\Program Files\scurit~1\s?curity\
C:\Program Files\scurit~1\svchost.exe
C:\Program Files\SystemDefender
C:\Program Files\VirusHeat 4.3
C:\Program Files\VirusHeat 4.3\blacklist.txt
C:\Program Files\VirusHeat 4.3\ignored.lst
C:\Program Files\VirusHeat 4.3\Lang\English.ini
C:\Program Files\VirusHeat 4.3\msvcp71.dll
C:\Program Files\VirusHeat 4.3\msvcr71.dll
C:\Program Files\VirusHeat 4.3\uninst.exe
C:\Program Files\VirusHeat 4.3\vht.dat
C:\Program Files\VirusHeat 4.3\VirusHeat 4.3.url
C:\Program Files\VirusHeat 4.3\vpp.ini
C:\Program Files\webhancer
C:\Program Files\webhancer\Programs\license.txt
C:\Program Files\webhancer\Programs\readme.txt
C:\Program Files\webhancer\Programs\sporder.dll
C:\Program Files\webhancer\Programs\whagent.ini
C:\WINDOWS\conf.inf
C:\WINDOWS\Installer\{7021957c-9195-4357-84c1-f696a7614968}
C:\WINDOWS\Installer\{7021957c-9195-4357-84c1-f696a7614968}\DrvSys.dll
C:\WINDOWS\kavir.exe
C:\WINDOWS\ky.sxc
C:\WINDOWS\lfn.exe
C:\WINDOWS\mscon.sio
C:\WINDOWS\nivavir.config
C:\WINDOWS\PerfInfo
C:\WINDOWS\PerfInfo\sZoIKae42Swp.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\
000060.exe
C:\WINDOWS\system32\
000080.exe
C:\WINDOWS\system32\
000090.exe
C:\WINDOWS\system32\12274992141.dll
C:\WINDOWS\system32\215651\215651.dll
C:\WINDOWS\system32\BluetoothAuthorizationAgent.exe
C:\WINDOWS\system32\byXPJCvt.dll
C:\WINDOWS\system32\ddcYsRHB.dll
C:\WINDOWS\system32\drivers\asc3550p.sys
C:\WINDOWS\system32\drivers\spools.exe
C:\WINDOWS\system32\drivers\Wfn08.sys
C:\WINDOWS\system32\kr_done1
C:\WINDOWS\system32\msdefender.exe
C:\WINDOWS\system32\n.ini
C:\WINDOWS\system32\rkvdr.dll
C:\WINDOWS\system32\rqRhIYpM.dll
C:\WINDOWS\system32\svcp.csv
C:\WINDOWS\system32\tuvVOEwx.dll
C:\WINDOWS\system32\tvCJPXyb.ini
C:\WINDOWS\system32\tvCJPXyb.ini2
C:\WINDOWS\system32\vx.tll
C:\WINDOWS\system32\WGOponpo.ini
C:\WINDOWS\system32\WGOponpo.ini2
C:\WINDOWS\system32\wind32.exe
C:\WINDOWS\system32\winfrun32.bin
C:\WINDOWS\system32\winsub.xml
C:\WINDOWS\system32\WLCtrl32.dl_
C:\WINDOWS\system32\WLCtrl32.dll
C:\WINDOWS\system32\wmsdkns.exe
C:\WINDOWS\system32\wnsxs~1
C:\WINDOWS\system32\wnsxs~1\t?skmgr.exe
C:\WINDOWS\system32\xkpisxen.dll
C:\WINDOWS\taskmon.exe
C:\WINDOWS\Temp\1396886080.exe
C:\WINDOWS\winself.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3550P
-------\Legacy_icf
-------\Legacy_wfn08
-------\Service_asc3550p
-------\Service_ICF
-------\Service_Wfn08
-------\Service_wfn08
-------\Legacy_MSSysInterv1
-------\Legacy_Schedule
-------\MSSysInterv1
-------\Schedule
((((((((((((((((((((((((( Files Created from 2008-03-16 to 2008-04-16 )))))))))))))))))))))))))))))))
.
2008-04-15 19:31 . 2008-04-15 19:31 101,156 --a------ C:\WINDOWS\BM8b7051e1.xml
2008-04-15 19:17 . 2008-04-15 19:29 <DIR> d-------- C:\fixwareout
2008-04-15 18:53 . 2008-04-15 18:53 269,334 --a------ C:\WINDOWS\system32\fepojilsrilgf.bmp
2008-04-15 18:51 . 2008-04-15 18:51 269,334 --a------ C:\WINDOWS\system32\jilsjehojatsb.bmp
2008-04-15 18:44 . 2008-04-15 18:44 269,334 --a------ C:\WINDOWS\system32\kjalgr.bmp
2008-04-14 11:26 . 2008-04-14 11:26 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-14 10:04 . 2008-04-14 10:04 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\TrojanHunter
2008-04-14 07:21 . 2008-04-14 07:22 <DIR> d-------- C:\Program Files\TrojanHunter 5.0
2008-04-13 13:33 . 2008-04-13 13:33 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-04-13 13:16 . 2008-04-13 13:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\MSN6
2008-04-13 13:03 . 2008-04-13 13:03 269,334 --a------ C:\WINDOWS\system32\qhkfqdor.bmp
2008-04-13 10:58 . 2008-04-13 10:58 269,334 --a------ C:\WINDOWS\system32\lknadcn.bmp
2008-04-13 08:30 . 2008-04-13 08:30 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-13 08:10 . 2008-04-13 08:10 269,334 --a------ C:\WINDOWS\system32\etcfmpon.bmp
2008-04-13 08:04 . 2008-03-29 12:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-04-13 08:04 . 2008-03-29 12:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-04-13 08:03 . 2008-03-29 12:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-04-13 08:03 . 2008-03-29 12:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-04-13 08:03 . 2008-01-17 10:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-04-13 08:03 . 2008-03-29 12:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-04-13 08:03 . 2008-03-29 12:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-04-13 08:03 . 2008-03-29 12:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-04-13 08:02 . 2008-04-13 08:02 <DIR> d-------- C:\Program Files\Alwil Software
2008-04-13 08:02 . 2008-03-29 12:45 1,146,232 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-04-13 08:02 . 2003-03-18 14:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-04-13 08:02 . 2003-03-18 13:14 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll
2008-04-13 08:02 . 2004-01-09 03:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-04-13 08:02 . 2003-02-20 21:42 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll
2008-04-13 07:52 . 2008-04-13 07:52 37,888 -r-hs---- C:\WINDOWS\system32\3532924907m.exe
2008-04-13 07:42 . 2008-04-13 07:42 15 --a------ C:\WINDOWS\system32\dllgh8jkd1q8.exe
2008-04-13 07:33 . 2008-04-13 07:33 269,334 --a------ C:\WINDOWS\system32\rmhknid.bmp
2008-04-13 07:32 . 2008-04-13 07:32 66,864 --ahs---- C:\Documents and Settings\LocalService\cftmon.exe
2008-04-13 07:27 . 2008-04-13 07:53 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-13 07:27 . 2008-04-13 07:27 22,016 --ahs---- C:\WINDOWS\system32\accesse.dll
2008-04-13 07:26 . 2008-04-13 07:26 47,104 --a------ C:\A0.tmp
2008-04-13 07:26 . 2008-04-13 07:25 37,888 -r-hs---- C:\WINDOWS\system32\advpacku.exe
2008-04-13 07:26 . 2008-04-13 07:26 3,276 --a------ C:\A1.tmp
2008-04-13 07:26 . 2008-04-13 07:26 3,276 --a------ C:\9F.tmp
2008-04-13 07:26 . 2008-04-13 07:27 86 --a-s---- C:\WINDOWS\system32\3532924907.dat
2008-04-13 07:25 . 2008-04-15 19:51 <DIR> d-------- C:\WINDOWS\system32\215651
2008-04-13 07:25 . 2008-04-13 07:25 391,168 --a------ C:\WINDOWS\system32\alt.exe.exe
2008-04-13 07:25 . 2008-04-13 07:25 132,096 --a------ C:\WINDOWS\system32\shift.exe.exe
2008-04-13 07:25 . 2008-04-13 07:25 38,400 --a------ C:\WINDOWS\mrofinu27.exe
2008-04-13 07:25 . 2008-04-13 07:25 37,888 -r-hs---- C:\WINDOWS\system32\admparses.exe
2008-04-13 07:25 . 2008-04-13 07:35 7,168 --a------ C:\WINDOWS\win32ole.dll
2008-04-13 07:24 . 2004-08-04 01:56 113,664 --a------ C:\WINDOWS\system32\ilsbelknidg.sys
2008-04-13 07:24 . 2008-04-13 07:24 40,960 --a------ C:\WINDOWS\system32\vedxga3me2.exe
2008-04-13 07:24 . 2008-04-13 07:24 22,528 --a------ C:\WINDOWS\system32\vedxg4am1et2.exe
2008-04-13 07:24 . 2008-04-13 07:24 20,988 --a------ C:\WINDOWS\system32\vedxga1me4t1.exe
2008-04-13 07:24 . 2008-04-13 07:24 20,988 --a------ C:\WINDOWS\system32\maxpaynow1.exe
2008-04-13 07:24 . 2008-04-13 07:24 19,456 --a------ C:\WINDOWS\system32\vedxg6ame4.exe
2008-04-13 07:23 . 2008-04-13 07:23 1,086,376 --a------ C:\Documents and Settings\Ruben\Application Data\Install.dat
2008-04-13 07:23 . 2008-04-13 07:22 21,874 --a------ C:\WINDOWS\system32\maxpaynowti1.exe
2008-04-13 07:22 . 2008-04-13 07:22 40,310 --a------ C:\WINDOWS\system32\dllgh8jkd1q2.exe
2008-04-13 07:22 . 2008-04-13 07:22 22,078 --a------ C:\WINDOWS\system32\dllgh8jkd1q7.exe
2008-04-13 07:22 . 2008-04-13 07:22 21,874 --a------ C:\WINDOWS\system32\dllgh8jkd1q5.exe
2008-04-13 07:22 . 2008-04-13 07:22 21,642 --a------ C:\WINDOWS\system32\dllgh8jkd1q6.exe
2008-04-13 07:21 . 2008-04-13 07:19 61,952 --a------ C:\WINDOWS\system32\gavurjjf.exe
2008-04-13 07:20 . 2008-04-13 07:20 20,426 --a------ C:\WINDOWS\system32\dllgh8jkd1q1.exe
2008-04-13 07:20 . 2008-04-13 07:22 2 --a------ C:\-2008849710
2008-04-13 07:19 . 2008-04-13 07:19 61,952 --a------ C:\gavurjjf.exe
2008-04-13 07:19 . 2008-04-13 07:19 58,880 --a------ C:\lilsesn.exe
2008-04-13 07:19 . 2008-04-13 07:19 55,218 --a------ C:\WINDOWS\zeqbqwp.sys
2008-04-13 07:19 . 2008-04-13 07:19 13,312 --a------ C:\gjtxc.exe
2008-04-13 07:19 . 2008-04-13 07:19 10,000 --a------ C:\WINDOWS\system32\jfiehayd.dll
2008-04-13 07:19 . 2008-04-13 07:52 47 --a------ C:\smp.bat
2008-04-13 07:19 . 2008-04-13 07:19 29 --a------ C:\WINDOWS\system32\uqfudaid.tmp
2008-04-13 07:18 . 2008-04-13 07:18 269,334 --a------ C:\WINDOWS\system32\atknqpsnel.bmp
2008-04-13 07:18 . 2008-04-13 10:58 82,008 --ahs---- C:\Documents and Settings\Ruben\cftmon.exe
2008-04-13 07:18 . 2008-04-13 07:18 12,800 --a------ C:\pOXJ.exe
2008-04-13 07:06 . 2008-04-13 07:06 <DIR> d-------- C:\WINDOWS\cuawsppw
2008-04-13 07:06 . 2008-04-13 07:08 <DIR> d-------- C:\Program Files\Bat
2008-04-13 07:06 . 2008-04-13 07:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\tefobujm
2008-04-13 07:06 . 2008-04-13 07:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-04-13 07:06 . 2008-04-13 07:06 196,096 --a------ C:\WINDOWS\klelityl.dll
2008-04-13 07:06 . 2008-04-13 07:06 94,208 --a------ C:\WINDOWS\system32\hspmfqlc.exe
2008-04-13 07:06 . 2008-04-13 07:06 70,144 --a------ C:\WINDOWS\fgvcjmbs.dll
2008-04-13 07:06 . 2008-04-13 07:06 70,144 --a------ C:\Documents and Settings\All Users\Application Data\ovotmtab.dll
2008-04-13 07:05 . 2008-04-13 07:05 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-04-13 07:05 . 2008-04-13 07:05 41,724 ---hs---- C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
2008-04-13 07:05 . 2008-04-13 07:05 6,656 --a------ C:\WINDOWS\s.dll
2008-04-11 14:44 . 2008-04-11 14:44 187,904 ---hs---- C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
2008-04-09 11:47 . 2008-04-09 11:47 <DIR> d-------- C:\Program Files\QuickTime
2008-04-09 11:47 . 2008-04-09 11:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-09 11:44 . 2008-04-13 13:33 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-09 11:44 . 2008-04-09 11:44 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-30 08:02 . 2008-03-30 08:02 190,464 --a------ C:\WINDOWS\system32\luapvs.dll
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-03-25 00:28 . 2008-03-25 00:28 <DIR> d-------- C:\Documents and Settings\Ruben\Application Data\MSN6
2008-03-25 00:28 . 2008-03-25 00:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MSN6
2008-03-17 23:00 . 2008-03-17 23:01 <DIR> d-------- C:\Documents and Settings\Ruben\Application Data\Walgreens
2008-03-17 22:48 . 2008-03-17 22:59 <DIR> d-------- C:\WINDOWS\NKCCDViewerSetting
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-13 12:18 17,408 ----a-w C:\WINDOWS\system32\svchost.exe
2008-04-09 02:55 --------- d-----w C:\Documents and Settings\Ruben\Application Data\LimeWire
2008-03-14 00:05 --------- d-----w C:\Program Files\Azureus
2008-03-14 00:05 --------- d-----w C:\Documents and Settings\Ruben\Application Data\Azureus
2008-03-03 22:41 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-03-03 22:41 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_motport_01005.Wdf
2008-03-03 22:41 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-03-03 22:41 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2008-03-03 22:41 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2008-03-03 22:15 --------- d-----w C:\Program Files\Motorola Phone Tools
2008-03-03 22:13 --------- d-----w C:\Program Files\Avanquest update
2008-03-03 22:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-03 22:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-03-03 22:08 --------- d-----w C:\Program Files\Common Files\Motorola Shared
2008-03-03 22:08 --------- d-----w C:\Documents and Settings\Ruben\Application Data\InstallShield
2008-03-03 19:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-03-01 05:38 --------- d-----w C:\Program Files\Apple Software Update
2008-03-01 05:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-03-01 05:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-03-01 05:30 --------- d-----w C:\Program Files\Kodak
2008-03-01 05:30 --------- d-----w C:\Program Files\Common Files\Kodak
2008-03-01 05:01 --------- d-----w C:\Documents and Settings\Ruben\Application Data\Snapfish
2008-02-23 15:58 --------- d-----w C:\Documents and Settings\Ruben\Application Data\Ahead
2008-02-09 22:46 6,144 ----a-w C:\wintogi.exe
2008-02-09 22:46 6,144 ----a-w C:\WINDOWS\ons.dll
.
------- Sigcheck -------
2001-08-18 07:00 12800 0f7d9c87b0ce1fa520473119752c6f79 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2004-08-04 01:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2008-04-13 07:18 17408 c357a9031d4c637112df2a4a8fa21ac4 C:\WINDOWS\system32\svchost.exe
2001-08-18 07:00 327168 e7774698bb0d14b0710a9a31e209f9b6 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 00:14 359040 1745b00fc1141404b28f4b94f69a8871 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2004-08-04 00:14 359040 1745b00fc1141404b28f4b94f69a8871 C:\WINDOWS\system32\drivers\tcpip.sys
2001-08-18 07:00 430080 2b0e480e975ee51f2d5ce5f068fed6e2 C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2004-08-04 01:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2004-08-04 01:56 506368 b270125e1557a24f8de54857d8199dcf C:\WINDOWS\system32\winlogon.exe
2004-08-04 01:56 1034752 99641a4d634ddf0403ac065c51b365e7 C:\WINDOWS\explorer.exe
2001-08-18 07:00 1000960 5a26fc6010886d25b3e412493dd95ed8 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 01:56 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5AF49A2-94F3-42BD-F434-2604812C897D}]
2008-04-13 07:19 10000 --a------ C:\WINDOWS\system32\jfiehayd.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 01:56 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-04-29 14:56 45056]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 15:12 32768]
"NWEReboot"="" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"RTHDCPL"="RTHDCPL.EXE" [2005-06-29 13:25 14720000 C:\WINDOWS\RTHDCPL.EXE]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-29 14:33 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-29 14:33 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-29 14:33 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 05:00 132496]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"jqhcnidg"="C:\DOCUME~1\Ruben\LOCALS~1\Temp\indco.drv WLEntryPoint" [ ]
"jdgf894jrghoiiskd"="C:\DOCUME~1\Ruben\LOCALS~1\Temp\winlogan.exe" [ ]
"msvtt"="C:\WINDOWS\system32\gavurjjf.exe" [2008-04-13 07:19 61952]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 12:37 79224]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 05:33:46 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"fssbmoec"= rundll32.exe "C:\WINDOWS\system32\japojatkrap.dll" WLEntryPoint
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{C5AF49A2-94F3-42BD-F434-2604812C897D}"= C:\WINDOWS\system32\jfiehayd.dll [2008-04-13 07:19 10000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PWakHPt"= {884362D3-22E9-C879-60AE-B7168DB7B43B} - C:\WINDOWS\system32\qanh.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pgbitgbilsfal]
pgbitgbilsfal.dll 2004-08-04 01:56 113664 C:\WINDOWS\system32\pgbitgbilsfal.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2005-05-20 18:42 73728 C:\WINDOWS\system32\VESWinlogon.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1733:TCP"= 1733:TCP:@xpsp2res.dll,-22005
"39688:TCP"= 39688:TCP:@xpsp2res.dll,-22005
"35799:TCP"= 35799:TCP:@xpsp2res.dll,-22005
"4218:TCP"= 4218:TCP:@xpsp2res.dll,-22005
S1 aswsp;avast! Self Protection;C:\WINDOWS\system32\drivers\aswsp.sys [2008-03-29 12:31]
S1 zeqbqwp;zeqbqwp;C:\WINDOWS\zeqbqwp.sys [2008-04-13 07:19]
S2 aswfsblk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 12:35]
S2 fastuserswitchingcompatibilityshellhwdetection;Fast User Switching Compatibility FastUserSwitchingCompatibilityShellHWDetection;C:\WINDOWS\system32\advpacku.exe [2008-04-13 07:25]
S2 wuauservappmgmt;Automatic Updates wuauservAppMgmt;C:\DOCUME~1\Ruben\LOCALS~1\Temp\8.tmp []
S3 motccgp;Motorola USB Composite Device Driver;C:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-02-27 15:31]
S3 motccgpfl;MotCcgpFlService;C:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-23 20:03]
S3 motport;Motorola USB Diagnostic Port;C:\WINDOWS\system32\DRIVERS\motport.sys [2007-02-27 15:31]
.
Contents of the 'Scheduled Tasks' folder
"2008-03-01 05:38:28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-15 21:38:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\wuauservappmgmt]
"ImagePath"="C:\DOCUME~1\Ruben\LOCALS~1\Temp\8.tmp srv"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\ojmpsfal.dll
.
Completion time: 2008-04-15 21:38:42
ComboFix-quarantined-files.txt 2008-04-16 02:38:34
Pre-Run: 72,152,510,464 bytes free
Post-Run: 72,143,077,376 bytes free
-----------------------------------------------------------------------------------------------
+++++++++++++++++++++++++++++++++++++++++++++++++++++
-----------------------------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:42:54 PM, on 4/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.aprotecti.../test/?c=419608R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: C:\WINDOWS\system32\jfiehayd.dll - {C5AF49A2-94F3-42BD-F434-2604812C897D} - C:\WINDOWS\system32\jfiehayd.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [jqhcnidg] rundll32.exe "C:\DOCUME~1\Ruben\LOCALS~1\Temp\dsgjeicpr.sys" WLEntryPoint
O4 - HKLM\..\Run: [jdgf894jrghoiiskd] C:\DOCUME~1\Ruben\LOCALS~1\Temp\winlogan.exe
O4 - HKLM\..\Run: [msvtt] C:\WINDOWS\system32\gavurjjf.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\Policies\Explorer\Run: [fssbmoec] rundll32.exe "C:\WINDOWS\system32\japojatkrap.dll" WLEntryPoint
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\ojmpsfal.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ojmpsfal.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.113.140 85.255.112.93
O17 - HKLM\System\CS3\Services\Tcpip\..\{66333E9F-5D3E-489A-969C-F66A0CA943FB}: NameServer = 85.255.113.140,85.255.112.93
O20 - Winlogon Notify: pgbitgbilsfal - C:\WINDOWS\SYSTEM32\pgbitgbilsfal.dll
O21 - SSODL: PWakHPt - {884362D3-22E9-C879-60AE-B7168DB7B43B} - C:\WINDOWS\system32\qanh.dll (file missing)
O22 - SharedTaskScheduler: jhsf8d984jief8dsfus98jkefn - {C5AF49A2-94F3-42BD-F434-2604812C897D} - C:\WINDOWS\system32\jfiehayd.dll
O23 - Service: avast! iAVS4 Control Service (aswupdsv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus (avast! antivirus) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner (avast! mail scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner (avast! web scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Fast User Switching Compatibility FastUserSwitchingCompatibilityShellHWDetection (fastuserswitchingcompatibilityshellhwdetection) - Unknown owner - C:\WINDOWS\system32\advpacku.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: Automatic Updates wuauservAppMgmt (wuauservappmgmt) - Unknown owner - C:\DOCUME~1\Ruben\LOCALS~1\Temp\8.tmp.exe (file missing)
--
End of file - 5489 bytes
Edited by desireejassel, 15 April 2008 - 08:49 PM.