GREYKNIGHt, hi again.
webHancer wasnt there to un install, but onestep was. By the way, when i first had he virus(s), i saw something come up in avg, the trojan stuff, and it was in a folder called 'winvi' so i scanned that folder, and moved the harmful contents to vault, then deleted them. anyway, just because i noticed it, in add/remove programs, there was a 'program' called 'winvi' and it had '(remove only) in brackets next to it anyway, just thought u might need to know this or something, let me know if i should remove and/or delete it e.t.c... here is the requested 'combofix log':
COMBOFIX LOG:
ComboFix 08-05-01.3 - r 2008-05-11 7:51:31.3 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.90 [GMT 10:00]
Running from: C:\Documents and Settings\r\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\r\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\Documents and Settings\Jake\Desktop\stressreducer.exe
C:\WINDOWS\Installer\7065B7.MSI
c:\windows\system32\rlvknlg.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Jake\Desktop\stressreducer.exe
C:\DOCUMENTS AND SETTINGS\R\LOCAL SETTINGS\TEMP\{CC965873-F913-4866-9203-92E87DAB99B7}\
C:\DOCUMENTS AND SETTINGS\R\LOCAL SETTINGS\TEMP\{CC965873-F913-4866-9203-92E87DAB99B7}\\_extra\objects\cmdline.dll
C:\Program Files\EZT\
C:\Program Files\EZT\\downloadqueue.xml
C:\Program Files\EZT\\Downloads\
003_Apologize.mp3
C:\Program Files\EZT\\Downloads\Theme From The Simpsons Movie.mp3
C:\Program Files\EZT\\Downloads\We Will Rock You_MV0724004.mp3
C:\Program Files\EZT\\queue.raw
C:\Program Files\EZT\\webhancer.exe
C:\WINDOWS\Installer\7065B7.MSI
c:\windows\system32\rlvknlg.exe
.
((((((((((((((((((((((((( Files Created from 2008-04-10 to 2008-05-10 )))))))))))))))))))))))))))))))
.
2008-05-11 06:09 . 2008-05-11 06:09 <DIR> d--hs---- C:\FOUND.010
2008-05-09 15:45 . 2008-05-09 15:45 <DIR> d-------- C:\Program Files\Panda Security
2008-05-07 17:17 . 2008-05-07 17:17 <DIR> d-------- C:\Program Files\Microsoft Works
2008-05-07 17:16 . 2008-05-07 17:16 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-05-07 17:14 . 2008-05-07 17:14 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-05-07 17:13 . 2008-05-07 17:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-07 17:12 . 2008-05-07 17:12 <DIR> dr-h----- C:\MSOCache
2008-05-06 16:16 . 2008-05-06 16:16 <DIR> d-------- C:\_OTMoveIt
2008-05-05 15:35 . 2008-05-05 15:35 <DIR> d-------- C:\Program Files\FileSubmit
2008-05-05 15:32 . 2008-05-05 15:32 1,594,706 --a------ C:\WINDOWS\system32\ashes to ashes.wav
2008-05-05 15:32 . 2008-05-05 15:32 493,293 --a------ C:\WINDOWS\system32\Butterfly Fantasia.edm
2008-05-05 15:32 . 2008-05-05 15:32 361,984 --a------ C:\WINDOWS\system32\Butterfly Fantasia.scr
2008-05-05 08:44 . 2008-05-05 08:45 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-05 08:44 . 2008-05-05 08:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-04 15:34 . 2008-05-04 15:34 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-04 14:32 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-05-04 14:32 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-05-04 14:32 . 2008-04-24 08:10 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-05-04 14:32 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-05-04 14:32 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-05-04 14:32 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-04 14:32 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-04 14:32 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-04 14:32 . 2008-05-04 15:47 4,400 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-04 11:29 . 2008-05-04 11:29 <DIR> d-------- C:\Documents and Settings\r\Application Data\LimeWire
2008-04-28 21:28 . 2008-04-28 21:28 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-04-28 21:26 . 2008-04-28 21:26 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-04-28 15:47 . 2008-04-28 15:47 <DIR> d-------- C:\Program Files\High-Logic
2008-04-28 15:47 . 2008-04-28 15:47 <DIR> d-------- C:\Documents and Settings\r\Application Data\FontCreator
2008-04-28 15:47 . 2008-04-28 15:47 145 --a------ C:\WINDOWS\fcp5.cfg
2008-04-21 16:28 . 2008-04-21 16:28 <DIR> dr-h----- C:\$VAULT$.AVG
2008-04-10 16:55 . 2008-04-10 16:55 0 --a------ C:\WINDOWS\nsreg.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-09 09:16 --------- d-----w C:\Documents and Settings\r\Application Data\AVG7
2008-04-09 09:16 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-09 09:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-09 09:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-04-06 23:18 --------- d-----w C:\Program Files\Active GIF Creator 3.2
2008-04-03 06:14 --------- d-----w C:\Documents and Settings\r\Application Data\Hamachi
2008-04-03 06:13 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-04-03 06:13 --------- d-----w C:\Program Files\Hamachi
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-01 08:36 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 05:44 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
.
((((((((((((((((((((((((((((( snapshot@2008-05-05_11.03.31.76 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-29 11:31:00 204,081 ----a-w C:\WINDOWS\.silabclient_store_32\code.dat
+ 2008-05-08 05:45:52 200,605 ----a-w C:\WINDOWS\.silabclient_store_32\code.dat
+ 2008-05-07 07:17:30 110,592 ----a-w C:\WINDOWS\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll
+ 2008-05-07 07:17:32 4,608 ----a-w C:\WINDOWS\assembly\GAC\Extensibility\7.0.3300.0__b03f5f7f11d50a3a\extensibility.dll
+ 2008-05-07 07:17:30 8,007,680 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll
+ 2008-05-07 07:16:46 80,696 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access.Dao\12.0.0.0__71e9bce111e9429c\Microsoft.Office.interop.access.dao.dll
+ 2008-05-07 07:17:10 1,276,720 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
+ 2008-05-07 07:17:10 150,320 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
+ 2008-05-07 07:17:12 920,376 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll
+ 2008-05-07 07:17:12 35,648 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll
+ 2008-05-07 07:17:12 248,632 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2008-05-07 07:17:10 20,280 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
+ 2008-05-07 07:17:12 781,104 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2008-05-07 07:17:30 13,312 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.stdformat.dll
+ 2008-05-07 07:17:10 371,496 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop.Forms\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.Forms.dll
+ 2008-05-07 07:17:12 64,288 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2008-05-07 07:17:30 229,376 ----a-w C:\WINDOWS\assembly\GAC\mscomctl\10.0.4504.0__31bf3856ad364e35\MSCOMCTL.DLL
+ 2008-05-07 07:17:30 4,096 ----a-w C:\WINDOWS\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll
+ 2008-05-07 07:17:10 416,544 ----a-w C:\WINDOWS\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2008-05-07 07:16:48 12,096 ----a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll
+ 2008-05-07 07:17:16 12,096 ----a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll
+ 2008-05-07 07:17:22 12,104 ----a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Outlook.dll
+ 2008-05-07 07:17:22 12,632 ----a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.OutlookViewCtl.dll
+ 2008-05-07 07:17:22 12,112 ----a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
+ 2008-05-07 07:17:18 12,104 ----a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
+ 2008-05-07 07:17:26 12,096 ----a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2008-05-07 07:17:18 12,080 ----a-w C:\WINDOWS\assembly\GAC\Policy.11.0.Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll
+ 2008-05-07 07:17:18 11,544 ----a-w C:\WINDOWS\assembly\GAC\Policy.11.0.office\12.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll
+ 2008-05-07 07:17:30 16,384 ----a-w C:\WINDOWS\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
- 2008-05-05 00:59:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-10 21:54:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-03-25 08:13:04 124,208 ----a-w C:\WINDOWS\Downloaded Program Files\as2stubie.dll
+ 2007-07-18 03:49:56 12,592 ----a-w C:\WINDOWS\Downloaded Program Files\libcomm.dll
+ 2006-10-27 05:16:36 133,936 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\CONTAB32.DLL
+ 2006-10-26 10:55:32 87,344 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\DLGSETP.DLL
+ 2006-10-27 05:07:36 17,891,112 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\EXCEL.EXE
+ 2006-10-26 10:55:48 340,248 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\MIMEDIR.DLL
+ 2006-10-27 05:16:46 2,939,704 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\OLMAPI32.DLL
+ 2006-10-26 10:34:12 660,792 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\OMSMAIN.DLL
+ 2006-10-26 10:34:10 192,848 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\OMSXP32.DLL
+ 2006-09-15 06:25:18 3,611,416 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\OUTLFLTR.DAT
+ 2006-10-27 05:16:44 594,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\OUTLMIME.DLL
+ 2006-10-27 05:16:48 12,813,096 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\OUTLOOK.EXE
+ 2006-10-27 05:16:40 176,976 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\OUTLPH.DLL
+ 2006-10-26 10:55:54 413,472 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\PSTPRX32.DLL
+ 2006-10-26 10:55:44 263,520 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\SCNPST32.DLL
+ 2006-10-26 10:55:44 272,744 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\SCNPST64.DLL
+ 2006-10-26 11:13:08 14,674,216 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\XL12CNV.EXE
+ 2006-10-26 11:17:08 11,072 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119210000000000000000F01FEC\12.0.4518\XLCALL32.DLL
+ 2008-05-07 07:14:00 217,864 ----a-r C:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2008-05-07 19:37:36 20,240 ----a-r C:\WINDOWS\Installer\{91120000-0012-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-05-07 19:37:36 217,864 ----a-r C:\WINDOWS\Installer\{91120000-0012-0000-0000-0000000FF1CE}\misc.exe
+ 2008-05-07 19:37:36 18,704 ----a-r C:\WINDOWS\Installer\{91120000-0012-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-05-07 19:37:36 35,088 ----a-r C:\WINDOWS\Installer\{91120000-0012-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-05-07 19:37:36 845,584 ----a-r C:\WINDOWS\Installer\{91120000-0012-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-05-07 19:37:36 922,384 ----a-r C:\WINDOWS\Installer\{91120000-0012-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-05-07 19:37:36 888,080 ----a-r C:\WINDOWS\Installer\{91120000-0012-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-05-07 19:37:36 1,172,240 ----a-r C:\WINDOWS\Installer\{91120000-0012-0000-0000-0000000FF1CE}\xlicons.exe
+ 2006-10-26 04:10:08 1,190,688 ----a-w C:\WINDOWS\system32\FM20.DLL
+ 2006-10-26 04:10:06 33,088 ----a-w C:\WINDOWS\system32\FM20ENU.DLL
- 2008-04-09 20:17:20 157,160 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-05-07 19:32:04 203,328 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2006-10-26 03:45:04 207,360 ----a-w C:\WINDOWS\system32\INKED.DLL
+ 2006-07-24 00:50:38 125,744 ----a-w C:\WINDOWS\system32\MSSTDFMT.DLL
+ 2006-07-24 00:50:40 39,728 ----a-w C:\WINDOWS\system32\SCP32.DLL
+ 2006-07-24 00:50:40 47,920 ----a-w C:\WINDOWS\system32\VBAME.DLL
+ 2006-10-26 03:45:04 293,376 ----a-w C:\WINDOWS\system32\WISPTIS.EXE
+ 2006-10-26 03:40:34 95,744 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841\ATL80.dll
+ 2006-10-26 03:40:36 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2006-10-26 03:40:36 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2006-10-26 03:40:36 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2006-10-26 03:40:36 1,093,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
+ 2006-10-26 03:40:36 1,079,808 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2006-10-26 03:40:36 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2006-10-26 03:40:36 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2006-10-26 03:40:36 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
+ 2006-10-26 03:40:36 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
+ 2006-10-26 03:40:36 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
+ 2006-10-26 03:40:36 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
+ 2006-10-26 03:40:36 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
+ 2006-10-26 03:40:36 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
+ 2006-10-26 03:40:36 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
+ 2006-10-26 03:40:36 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
+ 2006-10-26 03:40:36 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-02-16 18:26 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" []
"RTHDCPL"="RTHDCPL.EXE" [2005-11-16 20:27 15600128 C:\WINDOWS\RTHDCPL.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-07 16:17 102491]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-07 16:16 692315]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 05:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 05:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00 455168]
"ADMTray.exe"="C:\Acer\Empowering Technology\admtray.exe" [2005-10-24 16:45 2462208]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 15:50 69632]
"PCMService"="C:\Program Files\Acer\Acer Arcade\PCMService.exe" [2005-08-31 19:59 147456]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-18 04:09 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-18 04:06 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-18 04:10 114688]
"EPM-DM"="c:\acer\Empowering Technology\ePower\epm-dm.exe" [2005-11-25 15:59 212992]
"Acer ePower Management"="C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe" [2005-11-09 11:04 3084288]
"LManager"="C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE" [2006-03-30 20:39 471040]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2006-01-24 18:00 397312]
"Desktop Service Centre"="C:\Program Files\OptusNet DSL Internet\DSC.exe" [2005-11-30 12:21 2919831]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"Super Screen Capture"="C:\Program Files\Zeallsoft\Super Screen Capture\SSCapture.exe" [2007-11-27 11:32 3026432]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-18 13:01 579584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-04-09 19:15 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
NETGEAR WG111v2 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111v2\WG111v2.exe [2006-05-17 16:05:52 2297856]
SnagIt 8.lnk - C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe [2007-05-01 11:11:48 6395464]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.mkdmp3enc"= C:\PROGRA~1\Acer\ACERAR~1\Kernel\Burner\MKDMP3Enc.ACM
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"43954:TCP"= 43954:TCP:demonicangels.no-ip.biz
"43594:TCP"= 43594:TCP:...
R1 OsaFsLoc;OsaFsLoc;C:\WINDOWS\system32\drivers\OsaFsLoc.sys [2005-10-15 18:20]
R2 EpmPsd;Acer EPM Power Scheme Driver;C:\WINDOWS\system32\drivers\epm-psd.sys [2004-07-19 13:10]
R2 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\drivers\epm-shd.sys [2005-04-07 18:08]
R2 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 16:58]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57]
R3 NdisFilt;OSA NdisFilter Protocol;C:\WINDOWS\system32\Drivers\NdisFilt.sys [2005-09-13 15:34]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2006-03-27 17:53]
*Newly Created Service* - INT15.SYS
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-11 07:55:49
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\sccfg.sys 16384 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\RtlGina2.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Zeallsoft\Super Screen Capture\zHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\EVTENG.EXE
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\S24EVMON.EXE
C:\PROGRAM FILES\LAVASOFT\AD-AWARE 2007\AAWSERVICE.EXE
C:\PROGRAM FILES\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGUPSVC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGEMC.EXE
C:\ACER\EMPOWERING TECHNOLOGY\ADMSERV.EXE
C:\PROGRAM FILES\ACER\ACER ARCADE\KERNEL\TV\CLCAPSVC.EXE
C:\PROGRAM FILES\ACER\ACER ARCADE\KERNEL\CLML_NTSERVICE\CLMLSERVER.EXE
C:\PROGRAM FILES\ACER\ACER ARCADE\KERNEL\CLML_NTSERVICE\CLMLSERVICE.EXE
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\REGSRVC.EXE
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\PROGRAM FILES\LAUNCH MANAGER\QTZGACER.EXE
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\SYSTEM32\IGFXSRVC.EXE
C:\Program Files\TechSmith\SnagIt 8\TSCHelp.exe
C:\Program Files\TechSmith\SnagIt 8\SnagPriv.exe
C:\Program Files\Java\jre1.6.0_04\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2008-05-11 8:02:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-10 22:02:00
ComboFix3.txt 2008-05-05 01:04:32
ComboFix2.txt 2008-05-05 03:41:08
Pre-Run: 8,124,645,376 bytes free
Post-Run: 8,185,249,792 bytes free
288 --- E O F --- 2008-05-07 19:37:36
Thanks again,
~Jake