Hi, thanks for your reply
ComboFix 08-07-04.1 - Sam Cho 2008-07-04 13:49:20.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.433 [GMT -4:00]
Running from: C:\Documents and Settings\Sam Cho\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Sam Cho\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Sam Cho\Local Settings\Temporary Internet Files\ijjistarter2FxB.exe
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\esorxhij.ini
C:\WINDOWS\system32\iSBKmUtv.ini
C:\WINDOWS\system32\iSBKmUtv.ini2
C:\WINDOWS\system32\jihxrose.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-04 to 2008-07-04 )))))))))))))))))))))))))))))))
.
2008-07-02 23:46 . 2008-07-02 23:58 <DIR> d-------- C:\Documents and Settings\Sam Cho\.gimp-2.4
2008-07-02 22:53 . 2008-07-02 22:54 <DIR> d-------- C:\Program Files\Panda Security
2008-07-02 22:47 . 2008-07-02 22:47 <DIR> d----c--- C:\_OTMoveIt
2008-07-02 22:32 . 2008-07-02 22:32 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-02 22:22 . 2008-07-02 22:40 1,734 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-02 22:21 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-07-02 22:21 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-07-02 22:21 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-07-02 22:21 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-07-02 22:21 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-07-02 22:21 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-07-02 22:21 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-07-02 22:21 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-07-02 22:21 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-07-02 20:17 . 2008-07-04 01:03 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-02 20:17 . 2008-07-02 20:17 <DIR> d-------- C:\Program Files\AVG
2008-07-02 20:17 . 2008-07-02 20:17 <DIR> d-------- C:\Documents and Settings\Sam Cho\Application Data\AVGTOOLBAR
2008-07-02 20:17 . 2008-07-03 06:39 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-02 20:17 . 2008-07-03 06:40 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-02 20:17 . 2008-07-03 06:39 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-02 16:30 . 2008-07-02 16:30 <DIR> d-------- C:\Program Files\DJ ToneXpress 4
2008-07-02 15:29 . 2008-07-02 15:29 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-26 15:01 . 2008-06-26 15:01 <DIR> d-------- C:\Program Files\BitPim
2008-06-26 09:45 . 2008-07-01 14:42 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-26 09:45 . 2008-06-26 09:45 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-24 20:23 . 2008-06-24 20:23 <DIR> d-------- C:\Program Files\Acon Digital Media
2008-06-24 20:14 . 2008-06-24 20:14 <DIR> d-------- C:\Documents and Settings\Sam Cho\Application Data\DJ ToneXpress
2008-06-23 15:45 . 2008-07-04 10:12 <DIR> d--h-c--- C:\$AVG8.VAULT$
2008-06-23 15:06 . 2008-07-02 20:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-23 10:45 . 2008-06-23 10:45 <DIR> d-------- C:\Program Files\WinCustomize
2008-06-23 10:45 . 2000-05-17 09:52 187,392 --a------ C:\WINDOWS\system32\JPGUtils.dll
2008-06-23 10:45 . 2008-06-15 16:18 24 --a------ C:\WINDOWS\LogonStudio.ini
2008-06-22 13:23 . 2007-12-04 16:44 23,600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS
2008-06-22 12:46 . 2008-06-22 12:51 <DIR> d-------- C:\Program Files\Netcom3 Cleaner
2008-06-20 03:00 . 2008-06-20 03:00 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-06-19 21:41 . 2008-06-13 09:10 272,128 --a------ C:\WINDOWS\system32\drivers\bthport.sys
2008-06-19 21:41 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-18 11:28 . 2008-06-18 11:28 <DIR> d----c--- C:\ijji
2008-06-17 21:59 . 2008-06-17 21:59 <DIR> d-------- C:\Documents and Settings\Sam Cho\Application Data\TVU Networks
2008-06-17 21:59 . 2008-06-17 21:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-06-17 21:58 . 2008-06-17 21:58 <DIR> d-------- C:\Program Files\TVUPlayer
2008-06-17 21:58 . 2008-06-17 21:58 <DIR> d-------- C:\Documents and Settings\Sam Cho\LocalLow
2008-06-16 08:54 . 2008-06-16 08:54 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-06-16 00:10 . 2008-06-16 00:10 <DIR> d-------- C:\Documents and Settings\Sam Cho\Application Data\ATI
2008-06-16 00:10 . 2008-06-16 00:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-06-16 00:05 . 2008-06-16 00:05 <DIR> d-------- C:\Program Files\ATI
2008-06-16 00:02 . 2008-06-16 00:04 <DIR> d-------- C:\Program Files\ATI Technologies
2008-06-16 00:01 . 2008-06-16 00:01 <DIR> d----c--- C:\ATI
2008-06-15 23:52 . 2008-05-30 14:11 3,850,760 --a------ C:\WINDOWS\system32\D3DX9_38.dll
2008-06-15 23:52 . 2008-05-30 14:11 1,491,992 --a------ C:\WINDOWS\system32\D3DCompiler_38.dll
2008-06-15 23:52 . 2008-05-30 14:19 507,400 --a------ C:\WINDOWS\system32\XAudio2_1.dll
2008-06-15 23:52 . 2008-05-30 14:11 467,984 --a------ C:\WINDOWS\system32\d3dx10_38.dll
2008-06-15 23:52 . 2008-05-30 14:18 238,088 --a------ C:\WINDOWS\system32\xactengine3_1.dll
2008-06-15 23:52 . 2008-05-30 14:17 65,032 --a------ C:\WINDOWS\system32\XAPOFX1_0.dll
2008-06-15 23:52 . 2008-05-30 14:17 25,608 --a------ C:\WINDOWS\system32\X3DAudio1_4.dll
2008-06-15 23:51 . 2008-06-15 23:51 <DIR> d-------- C:\WINDOWS\Logs
2008-06-15 16:48 . 2008-06-15 16:52 <DIR> d-------- C:\Program Files\ACW
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-03 21:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-07-03 03:44 --------- d-----w C:\Program Files\GIMP-2.0
2008-07-03 02:54 --------- d-----w C:\Program Files\Trend Micro
2008-07-02 23:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-02 22:46 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-02 20:25 --------- d-----w C:\Program Files\Java
2008-07-02 19:29 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-27 19:38 --------- d-----w C:\Program Files\Warcraft III
2008-06-26 19:13 --------- d-----w C:\Documents and Settings\Sam Cho\Application Data\LimeWire
2008-06-22 17:16 --------- d-----w C:\Documents and Settings\Sam Cho\Application Data\Uniblue
2008-06-18 15:28 --------- d--h--w C:\Documents and Settings\Sam Cho\Application Data\ijjigame
2008-06-16 04:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-09 22:22 --------- d-----w C:\Program Files\Softnyx
2008-06-08 18:55 --------- d-----w C:\Program Files\LimeWire
2008-05-23 19:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-23 19:18 --------- d-----w C:\Documents and Settings\Sam Cho\Application Data\Lavasoft
2008-05-18 18:57 --------- d-----w C:\Program Files\VideoLAN
2008-05-14 20:47 --------- d-----w C:\Program Files\AIM6
2008-05-14 12:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-14 11:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-05-12 16:30 3,007,488 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-05-12 15:02 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-03 20:48 94,208 ----a-w C:\WINDOWS\ScUnin.exe
2008-04-20 01:13 2,829 ----a-w C:\WINDOWS\War3Unin.pif
2008-04-20 01:13 139,264 ----a-w C:\WINDOWS\War3Unin.exe
2007-08-10 19:03 6,275,816 ----a-w C:\Program Files\mozilla firefox\plugins\ScorchPDFWrapper.dll
2007-09-27 00:21 88 -csh--r C:\WINDOWS\system32\E737E3896A.sys
2007-09-01 01:43 88 --sha-r C:\WINDOWS\system32\F9E1786936.sys
2007-09-27 00:21 4,496 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-01 15:39 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"ATICustomerCare"="C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe" [2007-10-04 18:38 307200]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-03 06:40 1232152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"SENTINEL"= snti386.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SmartUI.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SmartUI.lnk
backup=C:\WINDOWS\pss\SmartUI.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TabUserW.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk
backup=C:\WINDOWS\pss\TabUserW.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Sam Cho^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Sam Cho\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
--a------ 2007-02-28 23:06 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2008-01-03 12:15 50528 C:\Program Files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-27 19:03 152872 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
--a------ 2006-02-09 18:34 106496 C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 05:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2006-11-12 06:48 157592 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2007-03-15 11:09 460784 C:\Program Files\DellSupport\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]
--a------ 2005-09-08 05:20 122940 C:\WINDOWS\system32\DLA\DLACTRLW.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
--a------ 2005-10-05 03:12 94208 C:\Program Files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DRScan]
--a------ 2007-02-06 20:32 40960 C:\Program Files\DRScan\DRScanMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ESP]
--a------ 2007-05-09 13:40 62952 C:\Program Files\Cox\Applications\App\start.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-05-09 20:24 50760 C:\Program Files\Common Files\AOL\1146272344\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
--a------ 2002-08-12 11:07 36864 C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-08-11 16:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-08-11 16:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
--a------ 2005-08-12 16:16 1121792 C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
--a------ 2002-08-12 10:33 45108 C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2006-09-09 05:16 196608 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2006-12-15 03:23 75520 C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-05-01 15:39 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
--a------ 2007-11-30 17:31 3461120 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiPTA]
--a------ 2006-02-21 20:05 344064 C:\WINDOWS\system32\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 2005-03-22 23:20 339968 C:\WINDOWS\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1146272344\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\AOL\\1146272344\\ee\\aim6.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Hamachi\\hamachi.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Starcraft\\starcraft.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"J:\\Samuel Cho -=do not touch=-\\Rakion\\Rakion\\Bin\\rakion.bin"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Warcraft III\\War3.exe"=
"C:\\Program Files\\WC3Banlist\\WC3Banlist.exe"=
"C:\\Program Files\\Warcraft III\\Frozen Throne.exe"=
"C:\\Program Files\\Radeon Omega Drivers\\v3.8.330\\MultiRes\\multires.exe"=
"C:\\Nexon\\MapleStory\\MapleStory.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Documents and Settings\\Sam Cho\\Desktop\\New Folder\\pickup.listchecker.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\ijji\\ENGLISH\\u_sf.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"27000:UDP"= 27000:UDP:27000-27020
"27001:UDP"= 27001:UDP:27001
"27002:UDP"= 27002:UDP:27002
"27003:UDP"= 27003:UDP:27003
"27006:UDP"= 27006:UDP:27006
"27005:UDP"= 27005:UDP:27005
"27004:UDP"= 27004:UDP:27004
"27007:UDP"= 27007:UDP:27007
"27009:UDP"= 27009:UDP:27009
"27008:UDP"= 27008:UDP:27008
"27010:UDP"= 27010:UDP:27010
"27011:UDP"= 27011:UDP:27011
"27012:UDP"= 27012:UDP:27012
"27013:UDP"= 27013:UDP:27013
"27014:UDP"= 27014:UDP:27014
"27015:UDP"= 27015:UDP:27015
"27016:TCP"= 27016:TCP:27016
"27017:UDP"= 27017:UDP:27017
"27018:UDP"= 27018:UDP:27018
"27019:UDP"= 27019:UDP:27019
"27020:UDP"= 27020:UDP:27020
"27021:TCP"= 27021:TCP:27020-27050
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-03 06:39]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-03 06:39]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-03 06:40]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-03 06:40]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
S3 brfilt;Brother MFC Filter Driver;C:\WINDOWS\system32\Drivers\Brfilt.sys [2001-08-17 13:12]
S3 BrSerWDM;Brother WDM Serial driver;C:\WINDOWS\system32\Drivers\BrSerWdm.sys [2001-08-17 13:12]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;C:\WINDOWS\system32\Drivers\BrUsbMdm.sys [2001-08-17 13:12]
S3 BrUsbScn;Brother MFC USB Scanner driver;C:\WINDOWS\system32\Drivers\BrUsbScn.sys [2001-08-17 13:12]
S3 CEDRIVER53;CEDRIVER53;C:\Program Files\Cheat Engine\dbk32.sys []
S3 DADriv1;DADriv1;C:\Documents and Settings\Sam Cho\Desktop\New Folder (2)\DA Engine\DAK32.sys []
S3 Dua1;Dua1;C:\DOCUME~1\SAMCHO~1\LOCALS~1\Temp\Rar$EX00.798\DualEngi.sys []
S3 Dual2;Dual2;C:\Documents and Settings\Sam Cho\Desktop\Sam + Abba\Dual2.sys []
S3 geebers12;geebers12;C:\Documents and Settings\Sam Cho\Desktop\UCE\blorbslayerengine\nvid888.sys []
S3 iCheat1;iCheat1;C:\Documents and Settings\Sam Cho\Desktop\UCE\nvid999.sys []
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;C:\Documents and Settings\Sam Cho\Desktop\New Folder\Akash's v.46 HackPack\IlvMoney1083.sys []
S3 MzBot;MzBot;C:\MzBot.sys []
S3 Netcom3;NetCom3 Service;C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe []
S3 Nigga4;Nigga4;C:\DOCUME~1\SAMCHO~1\LOCALS~1\Temp\Rar$EX01.718\Nigga.sys []
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2005-08-02 17:10]
S3 Revolution1;Revolution1;C:\Documents and Settings\Sam Cho\Desktop\UCE\SHAK3.sys []
S3 toBzM;toBzM;C:\toBzM.sys []
S3 V0080Dev;Creative Camera VF0080 Driver;C:\WINDOWS\system32\DRIVERS\V0080Dev.sys [2004-10-09 05:51]
S3 XDva037;XDva037;C:\WINDOWS\system32\XDva037.sys []
S3 xp1;xp1;C:\Documents and Settings\Sam Cho\Desktop\dxwind\UCE\xp.sys []
S3 zenx1;zenx1;C:\DOCUME~1\SAMCHO~1\LOCALS~1\Temp\Rar$EX01.235\zenx.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\O]
\Shell\AutoRun\command - O:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4abb4218-e15e-11da-85dc-00038a000015}]
\Shell\AutoRun\command - J:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{56647b6c-a419-11db-869b-00038a000015}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-07-02 21:50:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-27 19:00:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2008-07-01 18:41:00 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-12-04 19:41:52 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
- - - - ORPHANS REMOVED - - - -
BHO-{28220052-D9A9-44B1-AB98-EDC594D238B6} - C:\WINDOWS\system32\byXQIAqr.dll
BHO-{3E9D3179-5E73-4220-AAF7-EF9120EF48AF} - C:\WINDOWS\system32\vtUmKBSi.dll
BHO-{6D0386B3-FD72-488E-9740-90355AE21735} - C:\WINDOWS\system32\digonyx.dll
Toolbar-{1F98C59B-DB4B-454B-98C8-95D0668B11A6} - C:\WINDOWS\nqgpedlr.dll
HKCU-Run-Aim6 - (no file)
HKLM-Run-5cf879f7 - C:\WINDOWS\system32\jihxrose.dll
ShellExecuteHooks-{28220052-D9A9-44B1-AB98-EDC594D238B6} - C:\WINDOWS\system32\byXQIAqr.dll
SSODL-okmdepgb-{03CEA1E2-C9E7-492B-9B8B-0EF4887333B5} - C:\WINDOWS\okmdepgb.dll
SSODL-axrfgvek-{FFB9BC6D-304A-438C-9E8A-5DAF20294EEC} - C:\WINDOWS\axrfgvek.dll
Notify-byXQIAqr - byXQIAqr.dll
MSConfigStartUp-00PCTFW - C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
MSConfigStartUp-PCTAVApp - C:\Program Files\PC Tools AntiVirus\PCTAV.exe
MSConfigStartUp-SDTray - C:\Program Files\Spyware Doctor\SDTrayApp.exe
MSConfigStartUp-Steam - c:\program files\steam\steam.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-04 13:57:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Cox\Applications\App\syssvcnt.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-07-04 14:02:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-04 18:02:06
Pre-Run: 44,577,009,664 bytes free
Post-Run: 44,426,289,152 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
351 --- E O F --- 2008-06-20 07:00:55
THEN
Malwarebytes' Anti-Malware 1.19
Database version: 921
Windows 5.1.2600 Service Pack 2
2:12:32 PM 7/4/2008
mbam-log-7-4-2008 (14-12-32).txt
Scan type: Quick Scan
Objects scanned: 46309
Time elapsed: 6 minute(s), 8 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{6d0386b3-fd72-488e-9740-90355ae21735} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d0386b3-fd72-488e-9740-90355ae21735} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\nqgpedlr.bfmt (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\nqgpedlr.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)