ComboFixComboFix 08-04-26.3 - User 2008-05-01 14:51:52.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2183 [GMT -4:00]
Running from: C:\Users\User\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\aufobsxw.dll
C:\Windows\system32\bfdlnrxh.dll
C:\Windows\System32\cegcapch.ini
C:\Windows\system32\cnfyngro.dll
C:\Windows\system32\cooorlmw.dll
C:\Windows\system32\corqglhi.dll
C:\Windows\system32\davclvvl.dll
C:\Windows\system32\efCTNEUm.dll
C:\Windows\System32\ehQXaccf.ini
C:\Windows\System32\ehQXaccf.ini2
C:\Windows\system32\fccaXQhe.dll
C:\Windows\System32\FgNTtBeg.ini
C:\Windows\System32\FgNTtBeg.ini2
C:\Windows\System32\flqdjbfk.ini
C:\Windows\system32\folkohux.dll
C:\Windows\system32\hcpacgec.dll
C:\Windows\system32\hlkrktkf.dll
C:\Windows\system32\hpqpffey.dll
C:\Windows\system32\ifamntom.dll
C:\Windows\System32\IQrBaHQr.ini
C:\Windows\System32\IQrBaHQr.ini2
C:\Windows\System32\jqtyyffc.ini
C:\Windows\system32\jqwgrvmb.dll
C:\Windows\System32\kcdjiwkw.ini
C:\Windows\System32\kfaufcko.ini
C:\Windows\System32\lacueabw.ini
C:\Windows\system32\loadcwmt.dll
C:\Windows\system32\mcrh.tmp
C:\Windows\System32\motnmafi.ini
C:\Windows\System32\mUENTCfe.ini
C:\Windows\System32\mUENTCfe.ini2
C:\Windows\System32\naiuohjy.ini
C:\Windows\System32\nyatjgch.ini
C:\Windows\system32\pvyecoxr.dll
C:\Windows\system32\qsxrltjt.dll
C:\Windows\system32\rpolvpyo.dll
C:\Windows\system32\rQHaBrQI.dll
C:\Windows\system32\siauwhje.dll
C:\Windows\system32\stpnhvrh.dll
C:\Windows\system32\tmuskkrj.dll
C:\Windows\system32\tuvUOGxW.dll
C:\Windows\system32\ubwtwoag.dll
C:\Windows\system32\uhluqplv.dll
C:\Windows\system32\umxxsuus.dll
C:\Windows\System32\Uvybayxx.ini
C:\Windows\System32\Uvybayxx.ini2
C:\Windows\System32\wgwukltb.ini
C:\Windows\System32\WxGOUvut.ini
C:\Windows\System32\WxGOUvut.ini2
C:\Windows\System32\xsdopccb.ini
C:\Windows\system32\xxyabyvU.dll
C:\Windows\system32\ykegyerw.dll
C:\Windows\system32\yleutgnh.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-01 to 2008-05-01 )))))))))))))))))))))))))))))))
.
2008-04-30 20:31 . 2008-04-30 20:31 22,328 --a------ C:\Users\User\AppData\Roaming\PnkBstrK.sys
2008-04-30 20:14 . 2008-04-30 20:14 <DIR> d--hs---- C:\Windows\ftpcache
2008-04-29 17:31 . 2008-04-29 17:31 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-29 17:22 . 2008-04-29 17:22 24,576 --a------ C:\Windows\System32\VundoFixSVC.exe
2008-04-29 17:14 . 2008-04-29 17:22 <DIR> d-------- C:\VundoFix Backups
2008-04-29 07:59 . 2008-04-25 18:25 38,400 --a------ C:\Windows\System32\efcBrRLD.dll
2008-04-28 19:07 . 2008-04-30 20:14 <DIR> d-------- C:\Windows\Downlods
2008-04-28 18:31 . 2008-04-28 18:31 <DIR> d-------- C:\Program Files\uTorrent
2008-04-28 17:34 . 2008-04-30 20:30 319 --a------ C:\Windows\game.ini
2008-04-28 17:31 . 2008-04-30 20:16 <DIR> d-------- C:\Program Files\Activision
2008-04-27 19:20 . 2008-04-28 14:54 <DIR> d-------- C:\Users\User\Downloadslol
2008-04-27 16:36 . 2008-04-27 16:36 <DIR> d-------- C:\Users\User\AppData\Roaming\AVSMedia
2008-04-27 16:36 . 2008-04-27 16:36 <DIR> d-------- C:\Users\All Users\AVS4YOU
2008-04-27 16:36 . 2008-04-27 16:36 <DIR> d-------- C:\ProgramData\AVS4YOU
2008-04-27 16:31 . 2008-04-28 15:05 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2008-04-27 16:31 . 2008-04-28 15:06 <DIR> d-------- C:\Program Files\AVSMedia
2008-04-25 21:32 . 2008-04-25 21:32 <DIR> d-------- C:\Program Files\VALVe
2008-04-25 18:25 . 2008-04-27 15:39 <DIR> d-------- C:\Users\User\AppData\Roaming\Uniblue
2008-04-25 13:28 . 2008-04-26 18:06 578 --a------ C:\Windows\settings.cfg
2008-04-25 12:46 . 2008-04-25 12:46 <DIR> d-------- C:\Program Files\Apple Software Update
2008-04-25 10:18 . 2008-04-27 15:39 <DIR> d-------- C:\Program Files\AoE2
2008-04-23 22:26 . 2008-04-23 22:26 <DIR> d-------- C:\Program Files\HyCam2
2008-04-23 12:38 . 2008-04-23 12:38 <DIR> d-------- C:\Users\User\AppData\Roaming\Apple Computer
2008-04-23 12:38 . 2008-04-23 12:38 <DIR> d-------- C:\Users\All Users\Apple Computer
2008-04-23 12:38 . 2008-04-23 12:38 <DIR> d-------- C:\Users\All Users\Apple
2008-04-23 12:38 . 2008-04-23 12:38 <DIR> d-------- C:\ProgramData\Apple Computer
2008-04-23 12:38 . 2008-04-23 12:38 <DIR> d-------- C:\ProgramData\Apple
2008-04-23 12:38 . 2008-04-23 12:38 <DIR> d-------- C:\Program Files\QuickTime
2008-04-23 12:38 . 2008-04-23 12:38 <DIR> d-------- C:\Program Files\iTunes
2008-04-23 12:38 . 2008-04-23 12:38 <DIR> d-------- C:\Program Files\iPod
2008-04-23 12:38 . 2008-04-23 12:38 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-04-23 12:38 . 2008-05-01 14:55 54,156 --ah----- C:\Windows\QTFont.qfn
2008-04-23 12:38 . 2008-04-23 12:38 1,409 --a------ C:\Windows\QTFont.for
2008-04-21 11:52 . 2008-04-25 21:31 <DIR> d-------- C:\Program Files\Counter-Strike Source
2008-04-21 10:14 . 2008-04-21 10:14 <DIR> d-------- C:\Users\User\AppData\Roaming\Sony
2008-04-21 10:14 . 2008-04-21 10:14 <DIR> d-------- C:\Users\User\AppData\Roaming\Publish Providers
2008-04-21 10:14 . 2008-04-24 13:32 156 --a------ C:\Windows\Twunk001.MTX
2008-04-21 10:14 . 2008-04-24 13:32 2 --a------ C:\Windows\Twain001.Mtx
2008-04-21 10:14 . 2008-04-21 10:14 0 --a------ C:\Windows\Twunk002.MTX
2008-04-21 10:10 . 2008-04-21 10:10 <DIR> d-------- C:\Program Files\Sony
2008-04-21 10:09 . 2008-04-21 10:09 <DIR> d-------- C:\Program Files\Sony Setup
2008-04-18 15:14 . 2008-04-18 15:46 <DIR> d-------- C:\Users\User\AppData\Roaming\Ulead Systems
2008-04-18 15:13 . 2008-04-18 15:13 <DIR> d-------- C:\Users\All Users\InterVideo
2008-04-18 15:13 . 2008-04-18 15:13 <DIR> d-------- C:\ProgramData\InterVideo
2008-04-18 15:13 . 2008-04-18 15:13 <DIR> d-------- C:\Program Files\Windows Media Components
2008-04-18 15:13 . 2008-04-18 15:13 <DIR> d-------- C:\Program Files\Common Files\InterVideo
2008-04-18 15:13 . 2007-03-06 11:58 210,456 --a------ C:\Windows\System32\IVIresizeW7.dll
2008-04-18 15:13 . 2007-03-06 11:58 206,360 --a------ C:\Windows\System32\IVIresizeA6.dll
2008-04-18 15:13 . 2007-03-06 11:58 198,168 --a------ C:\Windows\System32\IVIresizeP6.dll
2008-04-18 15:13 . 2007-03-06 11:58 198,168 --a------ C:\Windows\System32\IVIresizeM6.dll
2008-04-18 15:13 . 2007-03-06 11:58 194,072 --a------ C:\Windows\System32\IVIresizePX.dll
2008-04-18 15:13 . 2007-03-06 11:58 26,136 --a------ C:\Windows\System32\IVIresize.dll
2008-04-18 15:12 . 2008-04-18 15:14 <DIR> d-------- C:\Users\All Users\Ulead Systems
2008-04-18 15:12 . 2008-04-18 15:14 <DIR> d-------- C:\ProgramData\Ulead Systems
2008-04-18 15:12 . 2008-04-18 15:12 <DIR> d-------- C:\Program Files\Ulead Systems
2008-04-18 15:12 . 2008-04-18 15:13 <DIR> d-------- C:\Program Files\Common Files\Ulead Systems
2008-04-17 15:02 . 2008-04-28 19:46 <DIR> d-a------ C:\Users\All Users\TEMP
2008-04-17 15:02 . 2008-04-28 19:46 <DIR> d-a------ C:\ProgramData\TEMP
2008-04-17 15:02 . 2008-04-20 15:30 <DIR> d-------- C:\Fraps
2008-04-14 07:11 . 2008-04-14 07:11 <DIR> d-------- C:\Users\User\AppData\Roaming\Ubisoft
2008-04-14 07:10 . 2008-04-14 07:10 <DIR> d-------- C:\Users\All Users\Ubisoft
2008-04-14 07:10 . 2008-04-14 07:10 <DIR> d-------- C:\ProgramData\Ubisoft
2008-04-12 17:02 . 2008-04-12 17:02 <DIR> d-------- C:\Users\User\AppData\Roaming\Leadertech
2008-04-12 17:02 . 2008-04-12 17:02 <DIR> d-------- C:\Users\User\AppData\Roaming\Atari
2008-04-06 13:24 . 2008-04-06 13:24 <DIR> d-------- C:\Program Files\Siber Systems
2008-04-06 08:40 . 2008-04-06 08:40 0 --a------ C:\Windows\nsreg.dat
2008-04-06 08:39 . 2008-04-06 08:39 <DIR> d-------- C:\Program Files\ProxyShell
2008-04-05 18:57 . 2008-04-14 07:03 <DIR> d-------- C:\Program Files\Ubisoft
2008-04-02 14:52 . 2007-03-12 19:42 3,495,784 --a------ C:\Windows\System32\d3dx9_33.dll
2008-04-02 14:52 . 2006-09-28 19:05 2,414,360 --a------ C:\Windows\System32\d3dx9_31.dll
2008-04-02 14:52 . 2007-03-12 19:42 1,123,696 --a------ C:\Windows\System32\D3DCompiler_33.dll
2008-04-02 14:52 . 2007-03-15 19:57 443,752 --a------ C:\Windows\System32\d3dx10_33.dll
2008-04-02 14:52 . 2006-11-29 16:06 440,080 --a------ C:\Windows\System32\d3dx10.dll
2008-04-02 14:52 . 2007-04-04 21:53 81,768 --a------ C:\Windows\System32\xinput1_3.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-01 18:48 --------- d-----w C:\Users\User\AppData\Roaming\OpenOffice.org2
2008-05-01 01:53 66,872 ----a-w C:\Windows\System32\PnkBstrA.exe
2008-05-01 01:53 22,328 ----a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-05-01 01:53 103,736 ----a-w C:\Windows\System32\PnkBstrB.exe
2008-05-01 00:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-01 00:34 --------- d-----w C:\Users\User\AppData\Roaming\uTorrent
2008-04-29 21:06 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-28 19:00 --------- d-----w C:\Program Files\Opera
2008-04-27 23:13 --------- d-----w C:\Users\User\AppData\Roaming\LimeWire
2008-04-23 16:58 --------- d-----w C:\Program Files\LimeWire
2008-04-23 16:38 --------- d-----w C:\Program Files\Bonjour
2008-04-18 19:13 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-11 18:44 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2008-04-10 23:02 --------- d-----w C:\Program Files\Project64 1.6
2008-04-10 23:01 --------- d-----w C:\Program Files\Paradox Interactive
2008-04-08 23:28 --------- d-----w C:\Program Files\Windows Mail
2008-04-08 21:11 --------- d-----w C:\ProgramData\Microsoft Help
2008-03-29 23:48 --------- d-----w C:\Program Files\EA SPORTS
2008-03-29 18:32 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-03-28 03:24 --------- d-----w C:\Program Files\America's Army Server Manager
2008-03-28 03:24 --------- d-----w C:\Program Files\America's Army
2008-03-28 01:54 --------- d-----w C:\Users\User\AppData\Roaming\temp
2008-03-28 01:12 107,888 ----a-w C:\Windows\System32\CmdLineExt.dll
2008-03-28 01:12 --------- d--h--r C:\Users\User\AppData\Roaming\SecuROM
2008-03-19 22:42 --------- d-----w C:\Program Files\The All-Seeing Eye
2008-03-18 02:18 --------- d-----w C:\Users\User\AppData\Roaming\U3
2008-03-18 02:02 --------- d--h--w C:\ProgramData\CanonBJ
2008-03-18 02:02 --------- d--h--w C:\Program Files\CanonBJ
2008-03-17 23:39 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-03-17 23:39 --------- d-----w C:\Program Files\Java
2008-03-17 04:10 --------- d-----w C:\ProgramData\NVIDIA
2008-03-14 05:03 --------- d-----w C:\ProgramData\FLEXnet
2008-03-14 05:02 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-14 04:56 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-03-11 22:01 --------- d-----w C:\ProgramData\Yahoo!
2008-03-11 22:00 --------- d-----w C:\Program Files\Yahoo!
2008-03-11 14:47 --------- d-----w C:\Program Files\Google
2008-03-10 22:31 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-03-10 22:29 --------- d-----w C:\Users\User\AppData\Roaming\SystemRequirementsLab
2008-03-10 21:40 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-03-10 21:38 716,272 ----a-w C:\Windows\system32\drivers\sptd.sys
2008-03-10 21:38 --------- d-----w C:\Users\User\AppData\Roaming\DAEMON Tools
2008-03-10 20:08 --------- d-----w C:\Program Files\Alwil Software
2008-03-10 19:52 --------- d-----w C:\Program Files\Common Files\Java
2008-03-10 19:28 --------- d-----w C:\Program Files\Windows Live
2008-03-10 19:27 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-10 19:25 --------- d-----w C:\ProgramData\WLInstaller
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe
2008-02-13 11:04 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-13 11:04 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-13 11:02 2,048 ----a-w C:\Windows\System32\tzres.dll
2007-11-01 20:48 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5B966794-F0F4-44F7-AE90-43E9488E610E}]
C:\Windows\system32\geBtTNgF.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 14:34 5724184]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-02-13 19:09 486856]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-03-10 18:30 171448]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 20:43 4670704]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 08:35 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-11-01 16:42 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2006-12-01 01:37 4186112 C:\Windows\RtHDVCpl.exe]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2008-01-09 05:53 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-01-09 05:53 8530464]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-01-09 05:53 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 07:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 01:16 39792]
"UVS11 Preload"="C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe" [2007-07-23 13:55 341232]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"MSServer"="C:\Windows\system32\efcBrRLD.dll" [2008-04-25 18:25 38400]
"BM75bddc7c"="C:\Windows\system32\gkroatsd.dll" [ ]
C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-18 00:57:56 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.scg726"= scg726.acm
"msacm.alf2cd"= alf2cd.acm
"vidc.dvsd"= mcdvd_32.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{81D7BF92-F5BB-43F2-A01E-AD1EA4330283}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{48889214-A715-4268-8BE3-CAA51A7985CB}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{9D7BA063-E8A4-486F-A0B4-7B87EE8CC699}C:\\program files\\counter-strike source\\hl2.exe"= UDP:C:\program files\counter-strike source\hl2.exe:hl2
"UDP Query User{7954B7DC-2564-4988-A4EC-62F50F97C039}C:\\program files\\counter-strike source\\hl2.exe"= TCP:C:\program files\counter-strike source\hl2.exe:hl2
"{6AC00770-3614-4D36-BE18-DD645271A883}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{D94AFF63-9988-4DF0-9BAC-A1195B1CF887}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{B60D45A3-4F93-46BC-835D-61F6EF02D1DF}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{9C7F8C24-E9A3-4BAF-997B-BCE14BA2E848}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{D369E4F3-12CC-4884-89FF-FA7F326D9605}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{6BCD118D-0576-4366-A1E6-941D50928DEA}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"TCP Query User{A6F84519-F5D6-4218-A43F-5D04AA6BD76D}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{6549B5FB-181D-4133-AA0E-59CF40759E16}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{79E1C113-8384-40D5-A4E8-F150EED63834}C:\\users\\user\\desktop\\wowclient-downloader.exe"= UDP:C:\users\user\desktop\wowclient-downloader.exe:wowclient-downloader.exe
"UDP Query User{D65A628C-5519-449C-878A-197A6E144591}C:\\users\\user\\desktop\\wowclient-downloader.exe"= TCP:C:\users\user\desktop\wowclient-downloader.exe:wowclient-downloader.exe
"TCP Query User{9C8D1594-1EC2-49DB-8095-B0D2056B6A8B}C:\\program files\\world of warcraft\\backgrounddownloader.exe"= UDP:C:\program files\world of warcraft\backgrounddownloader.exe:Blizzard Downloader
"UDP Query User{C5BAB003-848C-499D-A70E-5C193E158A54}C:\\program files\\world of warcraft\\backgrounddownloader.exe"= TCP:C:\program files\world of warcraft\backgrounddownloader.exe:Blizzard Downloader
"{24937A8D-A265-4652-A5DA-920D51CF2798}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{E1C82EEA-0584-4E40-9F8B-E00CBEFAD447}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{A0DF6EC1-99A4-4528-B86B-C39783648784}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{420D7BAB-224E-47BA-AAE2-43A86956D436}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{56E53C46-15B2-4478-B75A-2B2EB86E1E9D}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{FE5EDE01-7FC5-4AA8-BB5C-99528CB2FB00}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{85738131-7937-48AC-9068-9F787F5A495E}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{99E8A96C-47D2-44D9-82E1-ACFDD1393061}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{9491FE3A-ECB3-4FFD-AD15-6EB6EE07141F}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{971FABE3-85CF-45F4-9767-4F26DDA402C3}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{521E2B55-4F0D-4987-9139-7302FBA507D9}C:\\program files\\counter-strike source\\hl2.exe"= UDP:C:\program files\counter-strike source\hl2.exe:hl2
"UDP Query User{0E42D575-AC9B-423E-9999-3F59D7A8CC1B}C:\\program files\\counter-strike source\\hl2.exe"= TCP:C:\program files\counter-strike source\hl2.exe:hl2
"{076918EF-58D8-4793-96C0-F0E64F2C4730}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{11D1C23A-946A-48E5-83EC-47934AD6D2FB}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{6F8A8ECE-7B38-48CA-9D79-6D7DF0CB5BF1}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{55084A1C-4CAF-43D3-9554-DFA062734825}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{10B8A810-1A49-4BAE-A6F2-B1E548B5F242}C:\\program files\\valve\\counter-strike source\\hl2.exe"= UDP:C:\program files\valve\counter-strike source\hl2.exe:hl2
"UDP Query User{640F6F7D-9339-44D6-9494-F2200BF1120F}C:\\program files\\valve\\counter-strike source\\hl2.exe"= TCP:C:\program files\valve\counter-strike source\hl2.exe:hl2
"TCP Query User{F91C02E7-26BE-408A-B029-FA23ABA0EDF0}C:\\program files\\valve\\counter-strike source\\srcds.exe"= UDP:C:\program files\valve\counter-strike source\srcds.exe:srcds
"UDP Query User{98CC651B-1FC6-4DF8-B390-5D3D86164F2C}C:\\program files\\valve\\counter-strike source\\srcds.exe"= TCP:C:\program files\valve\counter-strike source\srcds.exe:srcds
"TCP Query User{9D45E324-5A56-407A-BDBA-5E4BC9FB1B13}C:\\program files\\opera\\opera.exe"= UDP:C:\program files\opera\opera.exe:Opera Internet Browser
"UDP Query User{B4FD23B0-47CA-492F-BE23-A2C9B3BAADF6}C:\\program files\\opera\\opera.exe"= TCP:C:\program files\opera\opera.exe:Opera Internet Browser
"TCP Query User{BA50DB92-5DF7-4796-AD65-71175E36F09D}C:\\program files\\opera\\opera.exe"= UDP:C:\program files\opera\opera.exe:Opera Internet Browser
"UDP Query User{F11F1224-2B13-4176-AE4B-A0E7DD04176A}C:\\program files\\opera\\opera.exe"= TCP:C:\program files\opera\opera.exe:Opera Internet Browser
"{53EAE2B6-9DD2-42B6-B1A7-4647A955B438}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{AD9128FF-AE2C-4135-8541-3863D500381D}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{C3B89A7E-8091-4860-BC10-BFE64F91E6A0}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{062FCB82-0404-4B7A-B757-7545819828BF}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{5980CEC1-6A62-4B1C-AACF-1963DB01B5D8}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare
"{0F155F30-0628-44BD-ACD2-8AE74CB75A6E}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-03-29 14:31]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-03-29 14:35]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 14:32]
R3 rt61x86;Gigabyte RT61 Wireless Driver for Windows Vista;C:\Windows\system32\DRIVERS\netr61.sys [2007-09-28 16:37]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c9525d9-eef0-11dc-9816-001d60883400}]
\shell\AutoRun\command - I:\setup\rsrc\Autorun.exe
\shell\dinstall\command - I:\Directx\dxsetup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-04-25 23:36:52 C:\Windows\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-04-25 22:25:41 C:\Windows\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-01 14:55:01
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Users\User\AppData\Local\Temp\Cab9F4A.tmp
C:\Users\User\AppData\Local\Temp\Tar9F4B.tmp
scan completed successfully
hidden files: 2
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Windows\System32\PnkBstrA.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.bin
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\wbem\WMIADAP.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-05-01 14:59:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-01 18:59:21
Pre-Run: 382,029,336,576 bytes free
Post-Run: 381,873,242,112 bytes free
352 --- E O F --- 2008-04-30 12:00:25
HiJackThisLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:01:11 PM, on 5/1/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {5B966794-F0F4-44F7-AE90-43E9488E610E} - C:\Windows\system32\geBtTNgF.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\efcBrRLD.dll,#1
O4 - HKLM\..\Run: [BM75bddc7c] Rundll32.exe "C:\Windows\system32\gkroatsd.dll",s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://pcpitstop.com...p/PCPitStop.CABO16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.systemreq.../sysreqlab2.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
--
End of file - 7189 bytes
And yes, I understand that P2P is very dangerous. I just needed to get some songs I deleted by accident and which I lost the CD to.
Edited by Flufeeh, 01 May 2008 - 01:05 PM.