ComboFix 08-06-16.5 - Owner 2008-06-17 21:12:43.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.571 [GMT -4:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\nsv
C:\Documents and Settings\All Users\Application Data\nsv\cache\294.dfn
C:\Documents and Settings\All Users\Application Data\nsv\cache\538.dfn
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\ijjistarter2.exe
C:\Program Files\Common Files\uninstall information
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\PopSwatr\History\allowed
C:\Program Files\FunWebProducts\PopSwatr\History\notallow
C:\Program Files\FunWebProducts\Shared\Cache\FunBuddyIconBtn-new.htmlx
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\2.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\2.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\2.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\2.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\2.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\2.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\2.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\2.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\2.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\budyicon\fwpbuddy.png
C:\Program Files\MyWebSearch\bar\Cache\02BF207D
C:\Program Files\MyWebSearch\bar\Cache\02C10411
C:\WINDOWS\Downloaded Program Files\setup.inf
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-05-18 to 2008-06-18 )))))))))))))))))))))))))))))))
.
2008-06-11 09:55 . 2008-04-14 07:01 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 23:48 . 2008-06-09 23:48 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Pogo Games
2008-06-09 23:46 . 2008-06-09 23:47 <DIR> d-------- C:\Program Files\Lottso! Deluxe
2008-06-09 23:46 . 2008-06-09 23:46 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SpinTop
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-17 05:06 --------- d-----w C:\Program Files\Winamp Remote
2008-06-16 01:19 --------- d-----w C:\Documents and Settings\Owner\Application Data\gtk-2.0
2008-06-13 17:18 --------- d-----w C:\Program Files\Google
2008-06-10 04:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-09 03:37 --------- d-----w C:\Documents and Settings\Owner\Application Data\BitTorrent
2008-05-30 01:49 --------- d--h--w C:\Documents and Settings\Owner\Application Data\ijjigame
2008-05-30 01:37 --------- d-----w C:\Documents and Settings\Owner\Application Data\Alibre Design
2008-05-30 01:15 --------- d-----w C:\Program Files\DivX
2008-05-29 15:02 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-29 00:30 --------- d-----w C:\Program Files\PowerArchiver
2008-05-26 22:09 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-05-18 00:11 --------- d-----w C:\Documents and Settings\Owner\Application Data\Hoyle Casino
2008-05-13 01:53 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-05-13 01:53 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-13 01:51 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-13 01:51 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-05-13 01:49 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-13 01:49 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-09 21:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Alibre Design
2008-05-09 21:16 --------- d-----w C:\Program Files\Java
2008-05-09 21:07 --------- d-----w C:\Program Files\Alibre Design Help
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 21:57 --------- d-----w C:\Documents and Settings\Owner\Application Data\pshape7
2008-04-30 21:01 --------- d-----w C:\Program Files\Common Files\Delcam
2008-04-28 20:38 --------- d-----w C:\Program Files\Three Rings Design
2008-04-28 20:36 --------- d-----w C:\Documents and Settings\Owner\Application Data\yoclient
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-22 02:15 249,856 ------w C:\WINDOWS\Setup1.exe
2008-04-21 03:11 --------- d-----w C:\Documents and Settings\Owner\Application Data\GetRightToGo
2008-04-10 01:42 357 ----a-w C:\Documents and Settings\Owner\.cb_layout.bin
2008-04-05 22:39 73,216 ------w C:\WINDOWS\ST6UNST.EXE
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 02:43 21 ----a-w C:\promptset.bat
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-28 20:48 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2007-09-16 14:44 56 --sh--r C:\WINDOWS\system32\C3EAFAF4EF.sys
2005-05-24 02:22 475 --sh--w C:\WINDOWS\system32\ffp.dll
2007-09-16 14:44 1,734 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
2008-01-17 20:48 31744 --a------ C:\Program Files\Java\jre6\bin\jp2ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
2008-01-17 20:48 73728 --a------ C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F007E221-018D-4baf-924A-B0E9092F3853}]
2005-05-31 22:42 159024 --a------ C:\WINDOWS\System32\WinStat11.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ANONYMIZER_SPYWAREKILLER"="C:\Program Files\Anonymizer\Anti-Spyware\AnonAntiSpyware.exe" [2004-12-31 16:38 446464]
"c005RWM3l"="catads.exe" []
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 17:22 3739648]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 21:41 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04 52736]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 20:11 114688]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 22:02 61440]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 11:01 155648]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 00:42 212992]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 17:19 129536]
"IPInSightMonitor 01"="C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe" [2003-07-14 15:30 98304]
"2wSysTray"="C:\Program Files\2Wire\2PortalMon.exe" [2004-09-15 04:52 393216]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-01-04 22:18 98304]
"CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2007-01-03 02:03 230512]
"CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2007-01-03 02:03 185456]
"IFMX_AVOIDBAR"="C:\INFORMIX\BIN\ISpawn.exe" [1998-09-15 13:40 16384]
"BPT"="C:\Program Files\Bpt\bpt.exe" [2005-01-04 15:14 524288]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 14:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"S3TRAY2"="S3tray2.exe" [2003-02-25 05:33 69632 C:\WINDOWS\system32\S3tray2.exe]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 06:03 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 06:03 81920]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-07-28 15:53 180269]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2006-07-21 11:43 407032]
"HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 13:38 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18 241664]
"MaxBlastMonitor.exe"="C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe" [2007-04-20 07:59 1169720]
"AcronisTimounterMonitor"="C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe" [2007-04-20 08:09 1945712]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe" [2007-04-20 08:03 149024]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 16:10 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 23:55 54832]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 18:54 37376]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]
"SecurDisc"="H:\Nero 7\InCD\NBHGui.exe" [2007-05-15 16:55 1628208]
"InCD"="H:\Nero 7\InCD\InCD.exe" [2007-05-15 16:55 1057328]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-13 23:11 919016]
"NvMediaCenter"="NvMCTray.dll" [2007-12-05 01:41 81920 C:\WINDOWS\system32\nvmctray.dll]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-01-17 20:48 148888]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe [2003-04-10 06:53:45 552960]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2003-04-10 07:08:26 16384]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 22:31:38 241664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 16:05:56 65588]
Run Google Web Accelerator.lnk - C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe [2007-07-09 22:24:38 1134592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2003-02-21 06:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\yserver.exe"= C:\\Program Files\\Yahoo!\\Messenger\\yserver.exe
"C:\\Program Files\\SmartFTP\\SmartFTP.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R2 JavaQuickStarterService;Java Quick Starter;"C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" []
R3 2WIREPCP;2Wire USB;C:\WINDOWS\system32\DRIVERS\2WirePCP.sys [2003-04-14 07:38]
S2 ServerAgent;IDS - Personal Edition Server Agent;C:\INFORMIX\bin\saloader.exe [1998-09-15 13:40]
S3 jswmidin;jswmidin;C:\DOCUME~1\Owner\LOCALS~1\Temp\jswmidin.sys []
S3 MsgServ;IDS - Personal Edition Message Service;C:\INFORMIX\bin\msgserv.exe [1998-09-15 13:39]
S3 OnLine;Informix Dynamic Server - Personal Edition;C:\INFORMIX\bin\online.exe [1998-09-15 13:39]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-17 21:46:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Softex\OmniPass\opxpgina.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
C:\Program Files\Yahoo!\Antivirus\iSafe.exe
H:\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Softex\OmniPass\omniServ.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\INFORMIX\bin\instal.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-06-17 22:06:39 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-18 02:06:30
Pre-Run: 1,681,592,320 bytes free
Post-Run: 8,132,661,248 bytes free
210 --- E O F --- 2008-06-16 06:30:37
Edited by Tymorus, 19 June 2008 - 03:41 PM.