ComboFix 08-08-17.03 - LuckyDog 2008-08-18 5:42:55.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1209 [GMT -4:00]
Running from: C:\Users\LuckyDog\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\LuckyDog\AppData\Roaming\macromedia\Flash Player\#SharedObjects\B3N39KTS\interclick.com
C:\Users\LuckyDog\AppData\Roaming\macromedia\Flash Player\#SharedObjects\B3N39KTS\interclick.com\ud.sol
C:\Users\LuckyDog\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Users\LuckyDog\AppData\Roaming\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Users\LuckyDog\AppData\Roaming\Microsoft\Windows\Cookies\
[email protected][2].txt
C:\Users\LuckyDog\AppData\Roaming\Microsoft\Windows\Cookies\luckydog@myspace[2].txt
.
((((((((((((((((((((((((( Files Created from 2008-07-18 to 2008-08-18 )))))))))))))))))))))))))))))))
.
2008-08-14 04:50 . 2008-08-14 04:50 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\Download Manager
2008-08-14 04:43 . 2008-08-14 04:44 <DIR> d-------- C:\Program Files\Trojan Killer
2008-08-14 04:41 . 2008-08-14 04:41 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\Simply Super Software
2008-08-14 04:41 . 2008-08-14 04:41 <DIR> d-------- C:\Users\All Users\Simply Super Software
2008-08-14 04:41 . 2008-08-14 04:41 <DIR> d-------- C:\ProgramData\Simply Super Software
2008-08-14 04:41 . 2006-05-25 15:52 162,304 --a------ C:\Windows\System32\ztvunrar36.dll
2008-08-14 04:41 . 2003-02-02 20:06 153,088 --a------ C:\Windows\System32\unrar3.dll
2008-08-14 04:41 . 2005-08-26 01:50 77,312 --a------ C:\Windows\System32\ztvunace26.dll
2008-08-14 04:41 . 2002-03-06 01:00 75,264 --a------ C:\Windows\System32\unacev2.dll
2008-08-14 04:41 . 2006-06-19 13:01 69,632 --a------ C:\Windows\System32\ztvcabinet.dll
2008-08-14 03:02 . 2008-07-15 19:48 2,048 --a------ C:\Windows\System32\tzres.dll
2008-08-13 20:40 . 2008-06-18 23:25 361,984 --a------ C:\Windows\System32\IPSECSVC.DLL
2008-08-13 20:40 . 2008-06-18 23:25 272,896 --a------ C:\Windows\System32\polstore.dll
2008-08-13 20:40 . 2008-04-19 04:13 268,800 --a------ C:\Windows\System32\es.dll
2008-08-13 20:40 . 2008-06-18 23:25 61,440 --a------ C:\Windows\System32\winipsec.dll
2008-08-13 20:40 . 2008-06-18 23:25 28,672 --a------ C:\Windows\System32\FwRemoteSvr.dll
2008-08-13 20:38 . 2008-04-10 01:01 737,792 --a------ C:\Windows\System32\inetcomm.dll
2008-08-13 20:38 . 2008-04-09 22:43 84,480 --a------ C:\Windows\System32\INETRES.dll
2008-08-13 12:52 . 2008-08-13 12:56 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\Roxio
2008-08-13 12:32 . 2008-08-13 12:32 <DIR> d-------- C:\Windows\System32\Adobe
2008-08-13 07:07 . 2008-08-13 07:09 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-08-13 06:17 . 2008-08-13 06:55 <DIR> d-------- C:\Program Files\a-squared Free
2008-08-10 15:17 . 2008-08-10 15:17 <DIR> dr------- C:\Users\Mcx1\Searches
2008-08-10 15:09 . 2006-11-02 06:23 <DIR> dr------- C:\Users\Mcx1\Videos
2008-08-10 15:09 . 2006-11-02 06:23 <DIR> d-------- C:\Users\Mcx1\Saved Games
2008-08-10 15:09 . 2008-08-02 07:03 <DIR> d-------- C:\Users\Mcx1\Roaming
2008-08-10 15:09 . 2006-11-02 06:23 <DIR> dr------- C:\Users\Mcx1\Pictures
2008-08-10 15:09 . 2006-11-02 06:23 <DIR> dr------- C:\Users\Mcx1\Music
2008-08-10 15:09 . 2006-11-02 06:23 <DIR> dr------- C:\Users\Mcx1\Links
2008-08-10 15:09 . 2006-11-02 06:23 <DIR> dr------- C:\Users\Mcx1\Downloads
2008-08-10 15:09 . 2008-08-10 15:09 <DIR> dr------- C:\Users\Mcx1\Documents
2008-08-10 15:09 . 2008-08-10 15:09 <DIR> d--h----- C:\Users\Mcx1\AppData
2008-08-10 15:09 . 2008-08-10 15:17 <DIR> d-------- C:\Users\Mcx1
2008-08-09 09:48 . 2008-08-09 09:48 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\Template
2008-08-09 09:48 . 2008-08-09 09:48 0 --a------ C:\Users\LuckyDog\AppData\Roaming\wklnhst.dat
2008-08-08 06:01 . 2008-08-08 06:01 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\Snapfish
2008-08-08 01:08 . 2008-08-08 10:33 <DIR> d-------- C:\Windows\System32\quicktime
2008-08-08 01:05 . 2008-08-08 01:50 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\DivX
2008-08-08 01:05 . 2008-08-08 01:05 <DIR> d-------- C:\Program Files\Common Files\PX Storage Engine
2008-08-07 23:36 . 2008-08-17 01:50 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\LimeWire
2008-08-07 23:36 . 2008-08-10 15:42 <DIR> d-------- C:\Program Files\LimeWire
2008-08-07 19:33 . 2008-08-07 19:33 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\IrfanView
2008-08-07 19:33 . 2008-08-07 19:33 <DIR> d-------- C:\Program Files\IrfanView
2008-08-06 20:40 . 2008-08-06 20:40 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\Malwarebytes
2008-08-06 20:39 . 2008-08-06 20:39 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-08-06 20:39 . 2008-08-06 20:39 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-08-06 20:39 . 2008-08-14 04:50 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-06 20:39 . 2008-07-30 20:07 38,472 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-08-06 20:39 . 2008-07-30 20:07 17,144 --a------ C:\Windows\System32\drivers\mbam.sys
2008-08-06 20:30 . 2008-08-06 20:30 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-06 18:37 . 2008-08-06 18:37 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-08-06 07:39 . 2008-08-06 07:39 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\TrojanHunter
2008-08-06 07:36 . 2008-08-06 07:39 <DIR> d-------- C:\Program Files\TrojanHunter 5.0
2008-08-06 06:39 . 2008-08-17 18:39 <DIR> d-------- C:\Users\All Users\Google Updater
2008-08-06 06:39 . 2008-08-17 18:39 <DIR> d-------- C:\ProgramData\Google Updater
2008-08-06 06:29 . 2008-08-06 06:29 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-08-06 06:28 . 2008-08-06 06:28 <DIR> d-------- C:\Users\All Users\Adobe
2008-08-06 06:28 . 2008-08-06 06:28 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-08-05 06:10 . 2008-08-09 15:44 <DIR> d-------- C:\Program Files\Lx_cats
2008-08-05 06:08 . 2008-08-05 06:08 <DIR> d-------- C:\Program Files\Lexmark 4300 Series
2008-08-04 17:26 . 2008-08-06 06:32 <DIR> d-------- C:\Users\All Users\NOS
2008-08-04 17:26 . 2008-08-06 06:32 <DIR> d-------- C:\ProgramData\NOS
2008-08-04 17:26 . 2008-08-06 06:32 <DIR> d-------- C:\Program Files\NOS
2008-08-03 22:19 . 2008-08-03 22:20 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\Ventrilo
2008-08-03 22:14 . 2008-08-03 22:14 <DIR> d-------- C:\Program Files\Ventrilo
2008-08-03 22:14 . 2008-08-03 22:14 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-03 07:27 . 2008-08-03 07:27 <DIR> d-------- C:\Users\All Users\Yahoo!
2008-08-03 07:27 . 2008-08-03 07:27 <DIR> d-------- C:\ProgramData\Yahoo!
2008-08-03 02:48 . 2008-08-08 12:52 189 --a------ C:\Windows\BF2HitRegTweaker.ini
2008-08-03 02:47 . 2008-08-03 02:47 <DIR> d-------- C:\Program Files\AutoHotkey
2008-08-02 08:27 . 2008-08-02 08:27 <DIR> d-------- C:\Windows\Sun
2008-08-02 08:27 . 2008-08-08 01:40 <DIR> d-------- C:\Program Files\DivX
2008-08-02 07:32 . 2008-08-08 11:27 137,840 --a------ C:\Windows\System32\drivers\PnkBstrK.sys
2008-08-02 07:31 . 2008-08-08 11:26 111,928 --a------ C:\Windows\System32\PnkBstrB.exe
2008-08-02 07:31 . 2008-08-02 07:31 66,872 --a------ C:\Windows\System32\PnkBstrA.exe
2008-08-02 07:19 . 2008-08-02 07:19 <DIR> d-------- C:\Program Files\CleanUp!
2008-08-02 07:03 . 2008-08-02 07:03 <DIR> d-------- C:\Users\LuckyDog\Roaming
2008-08-02 07:03 . 2008-08-02 07:03 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\MySpace
2008-08-02 07:03 . 2008-08-02 07:03 <DIR> d-------- C:\Users\IUSR_NMPR\Roaming
2008-08-02 07:03 . 2008-08-02 07:03 <DIR> d-------- C:\Users\Default\Roaming
2008-08-02 07:03 . 2008-08-02 07:03 <DIR> d-------- C:\Program Files\MySpace
2008-08-02 06:56 . 2008-08-02 06:56 9,407 --a------ C:\Windows\System32\pbgame.htm
2008-08-02 06:56 . 2008-08-02 06:56 55 --a------ C:\Windows\System32\pbuser.htm
2008-08-02 06:48 . 2008-08-02 06:48 <DIR> d-------- C:\Program Files\DFPinger
2008-08-01 22:08 . 2008-08-01 22:08 95,727 --a------ C:\Windows\ShocknAwe Uninstaller.exe
2008-08-01 21:33 . 2008-08-01 21:33 <DIR> d-------- C:\Windows\PCHEALTH
2008-08-01 21:30 . 2008-08-01 21:30 <DIR> d-------- C:\Users\All Users\WLInstaller
2008-08-01 21:30 . 2008-08-01 21:30 <DIR> d-------- C:\ProgramData\WLInstaller
2008-08-01 21:30 . 2008-08-01 21:33 <DIR> d-------- C:\Program Files\Windows Live
2008-08-01 21:30 . 2008-08-01 21:33 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-01 21:17 . 2008-08-01 21:18 <DIR> d--h----- C:\Windows\msdownld.tmp
2008-08-01 21:16 . 2008-08-01 21:16 <DIR> d-------- C:\Users\All Users\Yahoo! Companion
2008-08-01 21:16 . 2008-08-01 21:16 <DIR> d-------- C:\ProgramData\Yahoo! Companion
2008-08-01 21:15 . 2008-08-01 21:15 <DIR> d-------- C:\Users\LuckyDog\AppData\Roaming\Leadertech
2008-08-01 21:11 . 2008-08-01 21:11 <DIR> d-------- C:\Program Files\NovaLogic
2008-08-01 20:42 . 2008-08-03 03:37 <DIR> d-------- C:\Program Files\EA GAMES
2008-07-25 04:36 . 2008-07-25 04:36 524,288 --a------ C:\Windows\System32\DivXsm.exe
2008-07-25 04:36 . 2008-07-25 04:36 4,816 --a------ C:\Windows\System32\divxsm.tlb
2008-07-23 12:50 . 2008-07-23 12:50 3,596,288 --a------ C:\Windows\System32\qt-dx331.dll
2008-07-23 12:48 . 2008-07-23 12:48 1,044,480 --a------ C:\Windows\System32\libdivx.dll
2008-07-23 12:48 . 2008-07-23 12:48 200,704 --a------ C:\Windows\System32\ssldivx.dll
2008-07-23 12:47 . 2008-07-23 12:47 416 --a------ C:\Windows\System32\dtu100.dll.manifest
2008-07-23 12:47 . 2008-07-23 12:47 416 --a------ C:\Windows\System32\dpl100.dll.manifest
2008-07-23 12:46 . 2008-07-23 12:46 12,288 --a------ C:\Windows\System32\DivXWMPExtType.dll
2008-07-22 17:17 . 2008-07-23 08:46 <DIR> d-------- C:\Users\All Users\NVIDIA
2008-07-22 17:17 . 2008-07-23 08:46 <DIR> d-------- C:\ProgramData\NVIDIA
2008-07-22 16:46 . 2008-07-22 16:46 205,824 --a------ C:\Windows\System32\msoeacct.dll
2008-07-22 16:46 . 2008-07-22 16:46 87,040 --a------ C:\Windows\System32\msoert2.dll
2008-07-22 16:46 . 2008-07-22 16:46 39,424 --a------ C:\Windows\System32\ACCTRES.dll
2008-07-22 16:44 . 2008-07-22 16:44 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-07-22 16:44 . 2008-07-22 16:44 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-07-22 16:43 . 2008-07-22 16:43 376,320 --a------ C:\Windows\System32\winsrv.dll
2008-07-22 16:43 . 2008-07-22 16:43 49,664 --a------ C:\Windows\System32\csrsrv.dll
2008-07-22 16:38 . 2008-07-22 16:38 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-07-22 16:38 . 2008-07-22 16:38 374,456 --a------ C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-07-22 16:38 . 2008-07-22 16:38 41,984 --a------ C:\Windows\System32\drivers\monitor.sys
2008-07-22 16:37 . 2008-07-22 16:37 8,147,968 --a------ C:\Windows\System32\wmploc.DLL
2008-07-22 16:37 . 2008-07-22 16:37 414,208 --a------ C:\Windows\System32\msscp.dll
2008-07-22 16:37 . 2008-07-22 16:37 356,864 --a------ C:\Windows\System32\MediaMetadataHandler.dll
2008-07-22 16:37 . 2008-07-22 16:37 7,680 --a------ C:\Windows\System32\spwmp.dll
2008-07-22 16:37 . 2008-07-22 16:37 4,096 --a------ C:\Windows\System32\msdxm.ocx
2008-07-22 16:37 . 2008-07-22 16:37 4,096 --a------ C:\Windows\System32\dxmasf.dll
2008-07-22 16:36 . 2008-07-22 16:36 396,800 --a------ C:\Windows\System32\MPSSVC.dll
2008-07-22 16:36 . 2008-07-22 16:36 392,192 --a------ C:\Windows\System32\FirewallAPI.dll
2008-07-22 16:36 . 2008-07-22 16:36 178,688 --a------ C:\Windows\System32\iphlpsvc.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-14 07:00 --------- d-----w C:\Program Files\Windows Mail
2008-08-13 16:33 --------- d-----w C:\Program Files\Java
2008-08-13 16:32 --------- d-----w C:\Program Files\Google
2008-08-03 07:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-23 16:50 129,784 ------w C:\Windows\System32\PxAFS.DLL
2008-07-22 21:16 174 --sha-w C:\Program Files\desktop.ini
2008-07-22 21:12 --------- d-----w C:\Program Files\Windows Defender
2008-07-22 21:12 --------- d-----w C:\Program Files\Windows Calendar
2008-07-22 21:11 --------- d-----w C:\Program Files\Windows Sidebar
2008-07-22 20:45 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2008-07-22 20:45 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2008-07-22 20:45 542,720 ----a-w C:\Windows\System32\sysmain.dll
2008-07-22 20:45 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2008-07-22 20:45 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2008-07-22 20:45 297,984 ----a-w C:\Windows\System32\wlansec.dll
2008-07-22 20:45 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2008-07-22 20:45 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2008-07-22 20:45 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2008-07-22 20:45 2,923,520 ----a-w C:\Windows\explorer.exe
2008-07-22 20:30 9,892,864 ----a-w C:\Windows\System32\NlsLexicons000a.dll
2008-07-22 20:28 944,184 ----a-w C:\Windows\System32\winload.exe
2008-07-22 20:23 88,576 ----a-w C:\Windows\System32\avifil32.dll
2008-07-22 20:21 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-22 20:21 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-22 19:14 --------- d-sh--w C:\ProgramData\Templates
2008-07-22 19:14 --------- d-sh--w C:\ProgramData\Start Menu
2008-07-22 19:14 --------- d-sh--w C:\ProgramData\Favorites
2008-07-22 19:14 --------- d-sh--w C:\ProgramData\Documents
2008-07-22 19:14 --------- d-sh--w C:\ProgramData\Desktop
2008-07-22 19:14 --------- d-sh--w C:\ProgramData\Application Data
2008-06-27 03:54 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-06-27 03:54 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-06-27 03:54 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-06-27 03:54 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-06-12 06:54 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-06-12 06:54 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-06-12 01:21 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-05-30 18:19 507,400 ----a-w C:\Windows\System32\XAudio2_1.dll
2008-05-30 18:18 238,088 ----a-w C:\Windows\System32\xactengine3_1.dll
2008-05-30 18:17 65,032 ----a-w C:\Windows\System32\XAPOFX1_0.dll
2008-05-30 18:17 25,608 ----a-w C:\Windows\System32\X3DAudio1_4.dll
2008-05-30 18:11 467,984 ----a-w C:\Windows\System32\d3dx10_38.dll
2008-05-30 18:11 3,850,760 ----a-w C:\Windows\System32\D3DX9_38.dll
2008-05-30 18:11 1,491,992 ----a-w C:\Windows\System32\D3DCompiler_38.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\Windows\System32\msconfig.exe" [2006-11-02 05:45 222208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCUTRAYICON]
--a------ 2006-11-18 08:01 182744 C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
--a------ 2006-11-02 08:35 125440 C:\Windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
--a------ 2006-09-29 13:39 151552 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2006-10-03 12:37 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXCECATS]
--a------ 2007-02-22 05:17 73728 C:\Windows\System32\spool\drivers\w32x86\3\lxcetime.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2008-04-17 19:27 9117696 C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NMSSupport]
--a------ 2006-09-26 11:56 423424 C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-09-17 08:07 8497696 C:\Windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-09-17 08:07 81920 C:\Windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2007-09-17 08:07 86016 C:\Windows\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-07-22 16:40 1006264 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2006-11-02 08:36 201728 C:\Program Files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3FAA1FB2-E60A-46BA-AB28-836A7DD5BC6A}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{2E6F48B0-50D5-49DC-97F7-8469CA0097C6}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{9AB506B8-1191-4D55-AF85-47910435FDB3}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{C49343C0-AB8C-444F-9F86-AF3992DC0CBB}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{88239B9A-A932-4989-B523-3B273D7A398F}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv Media Server
"{45D84681-1A09-4454-AE5B-1AA7937CAA36}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv Media Server
"{F32DB355-2CB0-4084-BF3B-0BDFC40406FD}"= TCP:Profile=Private|Profile=Public|9442:127.0.0.1:Intel® Viiv Media Server Discovery
"{DF67A1CF-DBBF-4F93-8FA6-A8DD3CA5417B}"= TCP:Profile=Private|Profile=Public|1900:LocalSubnet:LocalSubnet:Intel® Viiv Media Server UPnP Discovery
"{4D19A5DB-93AF-4CE8-A432-E831D5EFAA85}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{EF1D5DD2-C445-4264-815B-4D9B52CCC023}C:\\program files\\novalogic\\delta force black hawk down\\shocknawe.exe"= UDP:C:\program files\novalogic\delta force black hawk down\shocknawe.exe:ShocknAwe
"UDP Query User{37C65138-98DA-4A13-943C-ED3DC4C5AABD}C:\\program files\\novalogic\\delta force black hawk down\\shocknawe.exe"= TCP:C:\program files\novalogic\delta force black hawk down\shocknawe.exe:ShocknAwe
"TCP Query User{2B43B491-1652-402D-85AB-07115C5076FA}C:\\program files\\dfpinger\\dfbhdpinger\\dfbhdpinger.exe"= UDP:C:\program files\dfpinger\dfbhdpinger\dfbhdpinger.exe:DFBHDPinger
"UDP Query User{76AB40AC-39EA-4907-83A1-8514DC190EE5}C:\\program files\\dfpinger\\dfbhdpinger\\dfbhdpinger.exe"= TCP:C:\program files\dfpinger\dfbhdpinger\dfbhdpinger.exe:DFBHDPinger
"{4A61D1D8-4531-40BE-A8EE-30B746C73930}"= C:\Program Files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{B3110FFD-07C1-41E5-BE5F-F4834B85DA7E}"= UDP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{3209D960-1871-4C32-ACEC-1DA26A21393E}"= TCP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{CBF70B29-07BD-411D-8AED-43410D2BDCE7}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{506AF502-C43F-4A4E-ACC6-C6A705F76D2D}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{D653DFF5-0314-43EB-A939-07106D56E089}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{4972CA94-3319-4344-B110-18CC6366CD8B}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{3EC656E3-F682-4DE1-B136-5CAA02588FA8}"= UDP:C:\Windows\System32\lxcecoms.exe:Lexmark Communications System
"{1741AE83-98E3-430B-97B3-F48AD9F2DE2F}"= TCP:C:\Windows\System32\lxcecoms.exe:Lexmark Communications System
"TCP Query User{4CB1130E-9AB3-4E84-806A-E0731E7D6C5E}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{1E5B211A-9D78-49F2-8E8E-29215BB4ECF1}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{98F0198C-6539-4A17-B277-4D35320F7A3A}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{3F90F752-F70C-45F7-A437-1C01262D9E93}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{8C1EC23F-EA23-44BF-9346-4DFD9F109406}C:\\program files\\dfpinger\\dfbhdpinger\\dfbhdpinger.exe"= UDP:C:\program files\dfpinger\dfbhdpinger\dfbhdpinger.exe:DFBHDPinger
"UDP Query User{5137329F-3DD0-43F7-951A-62E9A510E856}C:\\program files\\dfpinger\\dfbhdpinger\\dfbhdpinger.exe"= TCP:C:\program files\dfpinger\dfbhdpinger\dfbhdpinger.exe:DFBHDPinger
"TCP Query User{38030A7A-35E5-4A19-A689-85DEF4431956}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{A1AB404C-3345-4B54-A0E6-5815AA6D3193}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{944C2AB0-BA8B-46DD-AF13-4BEB823982D8}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{BB3F5847-E3B7-497F-A743-5D17B036F9E3}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"TCP Query User{58A29DB1-A121-45AF-8947-32828C238E0D}C:\\program files\\novalogic\\delta force black hawk down\\shocknawe.exe"= UDP:C:\program files\novalogic\delta force black hawk down\shocknawe.exe:ShocknAwe
"UDP Query User{A4ACE2E9-1AA0-4EB7-89A3-1287B341D0F5}C:\\program files\\novalogic\\delta force black hawk down\\shocknawe.exe"= TCP:C:\program files\novalogic\delta force black hawk down\shocknawe.exe:ShocknAwe
"{AD8C930A-1982-433B-A362-5EC70C137DA8}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{DC1B571C-1E50-496A-9E22-1D3C0026D59B}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R2 nmsgopro;GoProto Protocol Driver for NMS;C:\Windows\system32\DRIVERS\nmsgopro.sys [2006-09-27 17:37]
R2 nmsunidr;UniDriver for NMS;C:\Windows\system32\DRIVERS\nmsunidr.sys [2006-10-19 16:49]
R3 IntelDH;IntelDH Driver;C:\Windows\system32\Drivers\IntelDH.sys [2007-05-10 20:07]
R4 DQLWinService;DQLWinService;C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-10-29 10:03]
S3 UMPass;Microsoft UMPass Driver;C:\Windows\system32\DRIVERS\umpass.sys [2006-11-02 04:55]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{835e6952-582a-11dd-9b4e-0019d169d9fc}]
\shell\AutoRun\command - CA_EdgeLitemobile.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://my.yahoo.com/
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-18 05:44:51
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-18 5:45:56
ComboFix-quarantined-files.txt 2008-08-18 09:45:54
Pre-Run: 208,025,583,616 bytes free
Post-Run: 208,041,422,848 bytes free
299 --- E O F --- 2008-08-14 07:03:21
and highjack log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:51:30 AM, on 8/18/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16711)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\notepad.exe
C:\Windows\Explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\System32\msconfig.exe" /auto
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) -
http://cdn.scan.onec...s/wlscctrl2.cabO16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx...owserPlugin.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cab--
End of file - 3375 bytes