here's the ComboFix log and the VirusTotal results
ComboFix 08-06-16.5 - Snow Flake 2008-06-20 17:43:08.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.652 [GMT 10:00]
Running from: C:\Program Files\ComboFix.exe
Command switches used :: C:\Documents and Settings\Snow Flake.SNOW\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\system32\drivers\i8042prtt.sys
C:\WINDOWS\system32\jkkli.dll
C:\WINDOWS\system32\rgkhobdk.exe
E:\LaunchU3.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Snow Flake.SNOW\Start Menu\Programs\Startup\Deewoo.lnk
C:\Documents and Settings\Snow Flake.SNOW\Start Menu\Programs\Startup\DW_Start.lnk
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\i8042prtt.sys
C:\WINDOWS\system32\rgkhobdk.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_i8042prtt
-------\Service_i8042prtt
((((((((((((((((((((((((( Files Created from 2008-05-20 to 2008-06-20 )))))))))))))))))))))))))))))))
.
2008-06-19 22:27 . 2008-06-19 22:27 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-19 22:27 . 2008-06-19 22:27 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-19 21:03 . 2008-06-19 21:04 <DIR> d-------- C:\things
2008-06-19 18:21 . 2008-06-19 18:21 <DIR> d-------- C:\WINDOWS\Sun
2008-06-19 18:21 . 2008-06-19 18:21 <DIR> d-------- C:\Program Files\Sun
2008-06-19 18:11 . 2008-05-09 00:02 203,136 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-19 18:10 . 2008-04-14 22:30 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-19 18:10 . 2008-04-14 22:30 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-19 17:39 . 2008-06-19 17:39 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-06-19 16:46 . 2008-06-19 18:30 <DIR> d-------- C:\comp
2008-06-19 16:45 . 2008-06-19 16:45 1,842,686 --a------ C:\Program Files\ComboFix.exe
2008-06-19 16:33 . 2008-06-19 16:33 50,688 --a------ C:\Program Files\ATF-Cleaner.exe
2008-06-18 11:50 . 2008-06-18 11:50 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-18 11:50 . 2008-06-18 11:50 812,344 --a------ C:\Program Files\HJTInstall.exe
2008-06-08 00:04 . 2008-06-08 00:06 <DIR> d-------- C:\Tram
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-20 07:40 --------- d-----w C:\Documents and Settings\Snow Flake.SNOW\Application Data\MxBoost
2008-06-19 13:28 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
2008-06-19 12:17 --------- d-----w C:\Documents and Settings\Snow Flake.SNOW\Application Data\uTorrent
2008-06-19 08:21 --------- d-----w C:\Program Files\Java
2008-06-19 07:13 1,951,685 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-06-17 03:18 --------- d-----w C:\Documents and Settings\Snow Flake.SNOW\Application Data\U3
2008-06-13 02:19 3,109,376 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-06-13 02:19 2,677,760 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2008-06-07 12:58 --------- d-----w C:\Documents and Settings\Snow Flake.SNOW\Application Data\LimeWire
2008-05-23 13:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-20 12:52 --------- d-----w C:\Program Files\Unlocker
2008-05-18 01:51 --------- d-----w C:\Program Files\Zoom Player
2008-05-09 12:58 --------- d-----w C:\Program Files\uTorrent
2008-05-09 12:56 263,984 ----a-w C:\Program Files\utorrent-1.8-beta-9363.upx.exe
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 03:07 2,557,952 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-05-08 03:07 1,441,792 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:12 1,288,192 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2008-05-06 09:17 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\FLEXnet
2008-04-26 05:57 --------- d-----w C:\Documents and Settings\Snow Flake.SNOW\Application Data\GRETECH
2008-04-26 05:57 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\GRETECH
2008-04-26 05:56 --------- d-----w C:\Program Files\GRETECH
2008-04-26 04:56 --------- d-----w C:\Documents and Settings\Snow Flake.SNOW\Application Data\Talkback
2008-04-25 14:19 --------- d-----w C:\Program Files\LimeWire
2008-04-22 08:02 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 08:02 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 08:02 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 10:53 --------- d-----w C:\Documents and Settings\Snow Flake.SNOW\Application Data\Ahead
2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-04-08 11:19 159,855 ----a-w C:\WINDOWS\Marsu-Fix Uninstaller.exe
2008-04-06 10:09 3,987,088 ----a-w C:\Program Files\mx_2.0.9.1640.exe
2008-04-05 14:40 8,464 ----a-w C:\WINDOWS\system32\sporder.dll
2008-04-04 06:10 89 ----a-w C:\Documents and Settings\Snow Flake\Del2220.bat
2008-04-04 03:23 89 ----a-w C:\WINDOWS\system32\config\systemprofile\Del2228.bat
2008-04-04 03:23 89 ----a-w C:\Documents and Settings\Snow Flake.SNOW\Del2228.bat
2008-04-04 03:23 89 ----a-w C:\Documents and Settings\Default User.WINDOWS\Del2228.bat
2008-03-19 20:55 113,664 ----a-w C:\WINDOWS\inf\hdaudio.sys
.
------- Sigcheck -------
2008-03-20 06:55 361344 cef393e4697b14d310320a62c3643f77 C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-19_17.17.32.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-27 10:46:15 60,416 ----a-w C:\WINDOWS\$hf_mig$\KB942763\SP3QFE\tzchange.exe
+ 2007-11-30 11:18:51 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB942763\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB942763\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\update.exe
+ 2007-11-30 11:18:51 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\updspapi.dll
+ 2007-11-30 11:18:51 231,288 -c----w C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe
+ 2007-11-30 11:18:51 382,840 -c----w C:\WINDOWS\$NtUninstallKB942763$\spuninst\updspapi.dll
+ 2008-03-07 07:46:28 60,416 -c----w C:\WINDOWS\$NtUninstallKB942763$\tzchange.exe
- 2008-06-19 07:13:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-20 07:49:27 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-14 12:30:49 272,128 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
+ 2008-03-19 20:54:23 124,928 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\advpack.dll
+ 2008-03-19 20:54:24 347,136 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\dxtmsft.dll
+ 2008-03-19 20:54:25 214,528 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\dxtrans.dll
+ 2008-03-19 20:54:25 133,120 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\extmgr.dll
+ 2008-03-19 20:54:41 63,488 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\icardie.dll
+ 2008-03-19 20:54:26 70,656 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ie4uinit.exe
+ 2008-03-19 20:54:26 153,088 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieakeng.dll
+ 2008-03-19 20:54:26 230,400 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieaksie.dll
+ 2008-03-19 20:54:27 161,792 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieakui.dll
+ 2008-03-19 20:54:43 383,488 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieapfltr.dll
+ 2008-03-19 20:54:27 388,096 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iedkcs32.dll
+ 2008-03-19 20:54:50 6,067,200 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieframe.dll
+ 2008-03-19 20:54:28 44,544 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iernonce.dll
+ 2008-03-19 20:54:50 267,776 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iertutil.dll
+ 2008-03-19 20:54:50 13,824 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieudinit.exe
+ 2008-03-19 20:54:29 625,664 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
+ 2008-03-19 20:54:32 27,648 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\jsproxy.dll
+ 2008-03-19 20:54:51 459,264 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msfeeds.dll
+ 2007-12-06 18:01:12 52,224 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msfeedsbs.dll
+ 2008-01-16 07:20:50 3,593,728 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mshtml.dll
+ 2008-03-19 20:54:34 478,208 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mshtmled.dll
+ 2007-12-06 18:01:14 193,024 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msrating.dll
+ 2008-03-19 20:54:35 671,232 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mstime.dll
+ 2008-03-19 20:54:36 102,912 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\occache.dll
+ 2008-01-10 21:57:26 44,544 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\updspapi.dll
+ 2008-03-19 20:54:38 105,984 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\url.dll
+ 2008-03-19 20:54:39 1,162,752 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\urlmon.dll
+ 2007-12-06 18:01:14 233,472 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\webcheck.dll
+ 2008-03-19 20:54:40 825,344 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
+ 2006-10-27 05:04:08 497,504 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.4518\MORPH9.DLL
+ 2006-10-27 23:04:10 9,581,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.4518\MSPUB.EXE
+ 2006-10-27 04:09:36 136,008 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.4518\PRTF9.DLL
+ 2006-10-27 23:04:06 624,456 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.4518\PTXT9.DLL
+ 2006-10-27 04:09:44 590,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.4518\PUBCONV.DLL
+ 2006-10-27 23:23:04 347,432 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.4518\WINWORD.EXE
+ 2006-10-27 23:11:38 4,235,560 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.4518\WRD12CNV.DLL
+ 2006-10-27 23:11:36 21,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.4518\WRD12EXE.EXE
+ 2006-10-27 23:23:08 17,483,560 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.4518\WWLIB.DLL
- 2008-04-06 12:59:27 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-06-19 13:27:58 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2008-04-06 12:59:27 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-06-19 13:27:59 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-04-06 12:59:27 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2008-06-19 13:27:58 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2008-04-06 12:59:27 184,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-06-19 13:27:58 184,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2008-04-06 12:59:27 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2008-06-19 13:27:58 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2008-04-06 12:59:27 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-06-19 13:27:59 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-04-06 12:59:27 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-06-19 13:27:59 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-04-06 12:59:27 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-06-19 13:27:58 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2008-04-06 12:59:27 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-06-19 13:27:58 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2008-04-06 12:59:27 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-06-19 13:27:59 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2008-04-06 12:59:27 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-06-19 13:27:59 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-04-06 12:59:27 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-06-19 13:27:58 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-03-19 20:54:23 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
+ 2008-04-23 03:35:35 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
+ 2008-04-23 03:35:35 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-04-23 03:35:35 347,136 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-04-23 03:35:35 214,528 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-04-23 03:35:35 132,608 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-04-23 03:35:35 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
+ 2008-04-23 03:35:35 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-04-23 03:35:35 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2007-04-17 09:32:38 2,455,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dat
+ 2008-04-23 03:35:35 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
+ 2008-04-23 03:35:35 388,608 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-04-23 03:35:36 6,068,224 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
+ 2008-04-23 03:35:36 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-04-23 03:35:36 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
+ 2008-04-23 03:35:36 27,648 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-04-23 03:35:36 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2008-04-23 03:35:36 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
+ 2008-04-23 03:35:36 3,593,728 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-04-23 03:35:36 478,208 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-04-23 03:35:36 193,024 ------w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-04-23 03:35:36 671,232 ------w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-04-23 03:35:36 102,912 ------w C:\WINDOWS\system32\dllcache\occache.dll
+ 2008-04-23 03:35:36 44,544 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-04-23 03:35:36 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
+ 2008-04-23 03:35:36 1,162,752 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-04-23 03:35:36 233,472 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-04-23 03:35:36 827,392 ------w C:\WINDOWS\system32\dllcache\wininet.dll
- 2008-03-19 20:54:24 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-04-23 03:35:35 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2008-03-19 20:54:25 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-04-23 03:35:35 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2008-03-19 20:54:25 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2008-04-23 03:35:35 132,608 ----a-w C:\WINDOWS\system32\extmgr.dll
- 2008-03-19 20:54:41 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
+ 2008-04-23 03:35:35 63,488 ----a-w C:\WINDOWS\system32\icardie.dll
- 2008-03-19 20:54:26 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2008-04-22 08:02:19 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe
- 2008-03-19 20:54:26 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll
+ 2008-04-23 03:35:35 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll
- 2008-03-19 20:54:26 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll
+ 2008-04-23 03:35:35 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll
- 2008-03-19 20:54:27 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
+ 2008-04-20 05:07:38 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
- 2008-03-19 20:54:43 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
+ 2008-04-23 03:35:35 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll
- 2008-03-19 20:54:27 388,096 ----a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2008-04-23 03:35:35 388,608 ----a-w C:\WINDOWS\system32\iedkcs32.dll
- 2008-03-19 20:54:50 6,067,200 ----a-w C:\WINDOWS\system32\ieframe.dll
+ 2008-04-23 03:35:36 6,068,224 ----a-w C:\WINDOWS\system32\ieframe.dll
- 2008-03-19 20:54:28 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll
+ 2008-04-23 03:35:36 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll
- 2008-03-19 20:54:50 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
+ 2008-04-23 03:35:36 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll
- 2008-03-19 20:54:50 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2008-04-22 08:02:19 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
- 2008-02-21 15:23:35 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-03-24 15:28:39 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2008-02-21 15:23:39 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-03-24 15:28:43 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2008-02-21 16:33:32 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-03-24 16:37:01 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
- 2008-03-19 20:54:32 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2008-04-23 03:35:36 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll
- 2008-03-19 20:54:51 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
+ 2008-04-23 03:35:36 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll
- 2007-12-06 18:01:12 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2008-04-23 03:35:36 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll
- 2008-01-16 07:20:50 3,593,728 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-04-23 03:35:36 3,593,728 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2008-03-19 20:54:34 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-04-23 03:35:36 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2007-12-06 18:01:14 193,024 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2008-04-23 03:35:36 193,024 ----a-w C:\WINDOWS\system32\msrating.dll
- 2008-03-19 20:54:35 671,232 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2008-04-23 03:35:36 671,232 ----a-w C:\WINDOWS\system32\mstime.dll
- 2008-03-19 20:54:36 102,912 ----a-w C:\WINDOWS\system32\occache.dll
+ 2008-04-23 03:35:36 102,912 ----a-w C:\WINDOWS\system32\occache.dll
- 2008-01-10 21:57:26 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-04-23 03:35:36 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2006-09-25 07:58:48 14,640 ----a-w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ------w C:\WINDOWS\system32\spmsg.dll
- 2008-03-07 07:46:28 60,416 ----a-w C:\WINDOWS\system32\tzchange.exe
+ 2008-03-27 10:40:24 60,416 ----a-w C:\WINDOWS\system32\tzchange.exe
- 2008-03-19 20:54:38 105,984 ----a-w C:\WINDOWS\system32\url.dll
+ 2008-04-23 03:35:36 105,984 ----a-w C:\WINDOWS\system32\url.dll
- 2008-03-19 20:54:39 1,162,752 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-04-23 03:35:36 1,162,752 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2007-12-06 18:01:14 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2008-04-23 03:35:36 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
- 2008-03-19 20:54:40 825,344 ----a-w C:\WINDOWS\system32\wininet.dll
+ 2008-04-23 03:35:36 827,392 ----a-w C:\WINDOWS\system32\wininet.dll
- 2008-05-22 11:38:36 246,272 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2008-06-19 10:31:18 267,776 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2008-06-20 07:49:45 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_150.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9d3bb967-1d3e-433f-ad22-25f00bbbce32}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 14:59 62976]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-03-07 17:46 15360]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2008-04-04 14:03 503808]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04 139264]
"CMWallpaperChanger"="C:\WINDOWS\system32\WallChan.exe" [2006-11-03 21:52 69632]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-02-28 23:06 2321600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2008-03-07 07:52 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2008-03-07 07:52 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2008-03-07 07:52 455168]
"LClock"="C:\Program Files\LClock\LClock.exe" [2004-09-19 12:27 65536]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-02-27 09:33 15872]
"VisualTooltip"="C:\Program Files\Utilities\VisualTooltip\VisualToolTip.exe" [2007-04-25 09:45 956928]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36 114688]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-16 08:54 37376]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 14:59 62976]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-04-23 13:35 124928 C:\WINDOWS\system32\advpack.dll]
"ShowDeskFix"="regsvr32 /s /n /i:u shell32" []
C:\Documents and Settings\Snow Flake.SNOW\Start Menu\Programs\Startup\
Styler.lnk - C:\Documents and Settings\Snow Flake.SNOW\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2008-04-04 13:33:42 15086]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
S0 partizan;Partizan;C:\WINDOWS\system32\drivers\Partizan.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
.
Contents of the 'Scheduled Tasks' folder
"2008-06-19 12:29:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-06-20 07:51:09 C:\WINDOWS\Tasks\User_Feed_Synchronization-{84353920-A903-4F02-8387-C23A244332A5}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-20 17:50:21
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Unlocker\UnlockerHook.dll
-> C:\Program Files\LClock\LC.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\snmp.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Styler\Styler.exe
C:\WINDOWS\system32\igfxsrvc.exe
.
**************************************************************************
.
Completion time: 2008-06-20 17:53:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-20 07:52:59
ComboFix2.txt 2008-06-19 07:18:32
Pre-Run: 43,081,785,344 bytes free
Post-Run: 43,097,198,592 bytes free
361 --- E O F --- 2008-06-19 13:28:01
Antivirus Version Last Update Result
AhnLab-V3 2008.6.19.0 2008.06.20 -
AntiVir 7.8.0.55 2008.06.19 -
Authentium 5.1.0.4 2008.06.20 -
Avast 4.8.1195.0 2008.06.19 -
AVG 7.5.0.516 2008.06.19 -
BitDefender 7.2 2008.06.20 -
CAT-QuickHeal 9.50 2008.06.19 -
ClamAV 0.93.1 2008.06.20 -
DrWeb 4.44.0.09170 2008.06.19 -
eSafe 7.0.15.0 2008.06.19 -
eTrust-Vet 31.6.5889 2008.06.19 -
Ewido 4.0 2008.06.19 -
F-Prot 4.4.4.56 2008.06.19 -
F-Secure 7.60.13501.0 2008.06.17 -
Fortinet 3.14.0.0 2008.06.20 -
GData 2.0.7306.1023 2008.06.19 -
Ikarus T3.1.1.26.0 2008.06.20 -
Kaspersky 7.0.0.125 2008.06.20 -
McAfee 5321 2008.06.19 -
Microsoft 1.3604 2008.06.20 -
NOD32v2 3201 2008.06.19 -
Norman 5.80.02 2008.06.19 -
Panda 9.0.0.4 2008.06.19 -
Prevx1 V2 2008.06.20 -
Rising 20.49.40.00 2008.06.20 -
Sophos 4.30.0 2008.06.20 -
Sunbelt 3.0.1153.1 2008.06.15 -
Symantec 10 2008.06.20 -
TheHacker 6.2.92.355 2008.06.19 -
TrendMicro 8.700.0.1004 2008.06.20 -
VBA32 3.12.6.7 2008.06.19 -
VirusBuster 4.3.26:9 2008.06.12 -
Webwasher-Gateway 6.6.2 2008.06.20 -
Additional information
File size: 89 bytes
MD5...: 1990c132b83f3ec59a710faad3bc1580
SHA1..: 66cef134b1225a3f3356d6e76421e16fb44698bd
SHA256: 4d52573140d4b12f7cf8d0ee8899a83ab46ecbd18d91450068fd7762ab1f1d2b
SHA512: c127720547a15f440c7b4609424229b42a458be5d768f861b05f1efa09dc99a5
399ce4b90c406fac88973af95746d432b35e0a8d73c61010f8729db9d24b3440
PEiD..: -
PEInfo: -