Hi,
ComboFix log:
ComboFix 08-06-12.2 - Charmaine 2008-06-14 11:49:28.1 - NTFSx86
Running from: C:\Documents and Settings\Charmaine\Desktop\download items\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Charmaine\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\Fonts\CALIBRIB.TTF
C:\WINDOWS\smdat32a.sys
C:\WINDOWS\smdat32m.sys
.
((((((((((((((((((((((((( Files Created from 2008-05-14 to 2008-06-14 )))))))))))))))))))))))))))))))
.
2008-06-14 08:29 . 2008-06-14 08:29 <DIR> d-------- C:\Deckard
2008-06-11 19:45 . 2008-06-11 19:45 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-11 19:45 . 2008-06-11 19:45 <DIR> d-------- C:\Documents and Settings\Charmaine\Application Data\Malwarebytes
2008-06-11 19:45 . 2008-06-11 19:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-11 19:45 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-11 19:45 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-11 08:51 . 2008-04-14 06:01 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-10 23:13 . 2008-06-10 23:13 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-03 10:31 . 2008-06-03 10:31 <DIR> d-------- C:\Documents and Settings\Dione\Application Data\Skype
2008-06-02 17:10 . 2008-06-08 13:09 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-02 17:10 . 2008-06-02 17:10 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-01 22:20 . 2008-06-01 22:20 <DIR> d-------- C:\Program Files\Common Files\snp2std
2008-06-01 22:20 . 2005-01-26 15:45 349,472 --a------ C:\WINDOWS\WindowsXP-KB822603-x86.exe
2008-06-01 22:20 . 2007-01-05 17:12 258,048 --a------ C:\WINDOWS\tsnp2std.exe
2008-06-01 22:20 . 2006-10-12 17:21 151,552 --a------ C:\WINDOWS\system32\rsnp2std.dll
2008-06-01 22:20 . 2006-07-03 10:31 94,208 --a------ C:\WINDOWS\amcap.exe
2008-05-31 17:38 . 2008-06-13 00:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-05-31 17:37 . 2008-06-12 21:54 <DIR> d-------- C:\Program Files\Winamp Remote
2008-05-29 23:14 . 2008-06-07 16:45 <DIR> d-------- C:\Program Files\eMule
2008-05-18 18:09 . 2008-05-18 18:09 22 --a------ C:\WINDOWS\iexplore.ini
2008-05-18 18:08 . 2008-05-18 18:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MumboJumbo
2008-05-17 23:08 . 2008-05-17 23:08 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_Motousbnet_01005.Wdf
2008-05-17 23:08 . 2008-05-17 23:08 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motfilt_01005.Wdf
2008-05-17 23:07 . 2008-05-17 23:07 <DIR> d-------- C:\Program Files\Motorola
2008-05-17 22:16 . 2008-05-17 22:22 <DIR> d-------- C:\Program Files\Avanquest update
2008-05-17 22:15 . 2007-01-23 22:36 22,016 --a------ C:\WINDOWS\system32\drivers\Motousbnet.sys
2008-05-17 22:15 . 2006-12-06 18:33 6,400 --a------ C:\WINDOWS\system32\drivers\motswch.sys
2008-05-17 22:15 . 2007-01-23 22:36 6,016 --a------ C:\WINDOWS\system32\drivers\motfilt.sys
2008-05-17 22:14 . 2008-05-17 22:26 <DIR> d-------- C:\Program Files\Motorola Phone Tools
2008-05-17 22:14 . 2008-05-17 22:14 <DIR> d-------- C:\Program Files\Common Files\Motorola Shared
2008-05-17 22:14 . 2008-05-17 22:14 <DIR> d-------- C:\Documents and Settings\Charmaine\Application Data\InstallShield
2008-05-17 22:14 . 2006-12-14 11:27 40,832 --a------ C:\WINDOWS\system32\drivers\motodrv.sys
2008-05-17 20:54 . 2008-05-17 20:54 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-05-17 20:54 . 2008-05-17 20:54 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-05-17 20:52 . 2006-11-13 09:45 1,419,232 -ra------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-05-17 20:52 . 2007-04-02 16:13 21,632 -ra------ C:\WINDOWS\system32\drivers\motmodem.sys
2008-05-17 20:45 . 2008-05-17 20:45 <DIR> d--hs---- C:\WINDOWS\ftpcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 16:56 --------- d-----w C:\Documents and Settings\Charmaine\Application Data\Skype
2008-06-14 15:36 --------- d-----w C:\Program Files\Java
2008-06-10 18:27 --------- d-----w C:\Program Files\Microsoft Works
2008-06-02 21:51 --------- d-----w C:\Program Files\Winamp
2008-06-02 03:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-30 05:22 --------- d-----w C:\Documents and Settings\Charmaine\Application Data\uTorrent
2008-05-26 00:28 --------- d-----w C:\Program Files\Lexmark X1100 Series
2008-05-22 10:22 --------- d-----w C:\Program Files\DivX
2008-05-18 11:45 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-18 11:41 --------- d-----w C:\Documents and Settings\Charmaine\Application Data\AdobeUM
2008-05-18 03:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-05-16 08:53 --------- d-----w C:\Program Files\PFConfig
2008-05-13 01:53 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-05-13 01:53 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-13 01:51 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-13 01:51 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-05-13 01:49 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-13 01:49 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-02 02:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-05-01 21:07 --------- d-----w C:\Documents and Settings\Charmaine\Application Data\AVG7
2008-04-27 02:45 --------- d-----w C:\Program Files\Common Files\xing shared
2008-04-27 02:45 --------- d-----w C:\Program Files\Common Files\Real
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-21 14:55 --------- d-----w C:\Documents and Settings\Dione\Application Data\AVG7
2008-04-14 11:01 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2007-03-24 04:08 56 --sh--r C:\WINDOWS\system32\18CEE83599.sys
2007-03-24 04:08 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-26 09:18 68856]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-05-10 16:09 23395880]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-04-01 18:35 3587120]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-03-31 20:54 507904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2003-08-19 22:56 45056 C:\WINDOWS\system32\VTTimer.exe]
"SoundMan"="SOUNDMAN.EXE" [2003-12-19 04:53 65024 C:\WINDOWS\SOUNDMAN.EXE]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 05:43 57344]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 22:32 53248]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-10-18 11:58 278528]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 16:22 3739648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38 241664]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2005-07-22 22:25 172032]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-07-22 22:25 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-26 21:44 185896]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 18:19 79224]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 13:49 36352]
"tsnp2std"="C:\WINDOWS\tsnp2std.exe" [2007-01-05 17:12 258048]
"snp2std"="C:\WINDOWS\vsnp2std.exe" [2006-09-15 13:21 675840]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 02:56 53760 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\Charmaine\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2005-07-21 10:58:26 45056]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
Exif Launcher.lnk - C:\Program Files\FinePixViewer\QuickDCF.exe [2004-12-22 15:34:11 200704]
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2005-03-17 14:06:14 59080]
Photo Loader supervisory.lnk - C:\Program Files\CASIO\Photo Loader\Plauto.exe [2006-12-15 15:40:58 229376]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.IV41"= ir41_32.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Kazaa\\kazaa.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"C:\\Program Files\\Google\\Gmail Notifier\\G001-1.0.25.0\\gnotify.exe"=
"C:\\Program Files\\Maxthon\\Maxthon.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Winamp\\winamp.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\IntelliChart Desktop\\FXChart.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"C:\\Program Files\\Motorola\\RSD Lite\\SDL.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12019:TCP"= 12019:TCP:Utorrent
"57419:TCP"= 57419:TCP:utor1
"6129:TCP"= 6129:TCP:DameWare Mini Remote Control Service
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 18:20]
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;C:\WINDOWS\system32\DRIVERS\dwvkbd.sys [2007-02-15 06:00]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 18:16]
R3 DwMirror;DwMirror;C:\WINDOWS\system32\DRIVERS\DamewareMini.sys [2007-02-07 06:00]
S3 BTCFilterService;USB Networking Driver Filter Service;C:\WINDOWS\system32\DRIVERS\motfilt.sys [2007-01-23 22:36]
S3 DCamUSBUVT;Micro Webcam Basic IC50C;C:\WINDOWS\system32\Drivers\usbuvt.sys []
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys [2006-12-14 11:27]
S3 Motousbnet;Motorola USB Networking Driver Service;C:\WINDOWS\system32\DRIVERS\Motousbnet.sys [2007-01-23 22:36]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD);C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2007-04-27 18:02]
S3 usb2vcom;USB to Serial Bridge Controller;C:\WINDOWS\system32\DRIVERS\usb2vcom.sys [2005-06-23 03:26]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-27 22:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{244a5352-0cac-11dc-91e9-0a18f3d9b8d6}]
\Shell\Auto\command - F:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5c29c9df-87d1-11db-90e5-000c76b8e01d}]
\Shell\AutoRun\command - uxdeiect.com
\Shell\explore\Command - uxdeiect.com
\Shell\open\Command - uxdeiect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a2ee702e-86d7-11db-90e1-000c76b8e01d}]
\Shell\Auto\command - F:\MSInfnd.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MSInfnd.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-11 20:44:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-14 11:56:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-14 12:01:00
ComboFix-quarantined-files.txt 2008-06-14 17:00:56
Pre-Run: 59,570,143,232 bytes free
Post-Run: 60,254,982,144 bytes free
209 --- E O F --- 2008-06-11 19:02:43