So far I am not seeing any problem, no pop ups of any kind. The only thing is, the spybot search and destroy was showing me a prompt, it's asking me if I allow and important change in my registry, i am so afraid to allow anything right now after what happened to i selected no. This prompt came up after I did the last thing you asked me to do. I am not sure if it will affect the combofix. Here is the log:
ComboFix 08-12-23.01 - Maila 2008-12-24 15:07:55.2 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.558 [GMT -7:00]
Running from: c:\documents and settings\Maila\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Maila\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\63868068
C:\aqpbouph.exe
c:\windows\system32\yAtqroPi.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\63868068
C:\aqpbouph.exe
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\yAtqroPi.dll
----- BITS: Possible infected sites -----
hxxp://childhe.com
.
((((((((((((((((((((((((( Files Created from 2008-11-24 to 2008-12-24 )))))))))))))))))))))))))))))))
.
2008-12-24 08:05 . 2008-12-24 08:05 <DIR> d-------- C:\VundoFix Backups
2008-12-24 07:42 . 2008-12-24 07:42 <DIR> d-------- c:\program files\ERUNT
2008-12-24 07:32 . 2008-12-24 07:32 <DIR> d-------- c:\program files\Trend Micro
2008-12-23 19:49 . 2008-12-23 19:49 <DIR> d-------- c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-12-23 19:49 . 2008-12-23 19:49 <DIR> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)
2008-12-23 19:49 . 2008-12-23 19:49 <DIR> d-------- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2008-12-23 19:49 . 2008-12-23 19:49 <DIR> d-------- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-12-23 19:39 . 2008-12-23 19:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avg7
2008-12-23 18:28 . 2008-12-23 18:28 <DIR> d-------- c:\program files\Alwil Software
2008-12-23 15:02 . 2008-12-23 15:02 <DIR> d-------- c:\documents and settings\Maila\Application Data\Malwarebytes
2008-12-23 15:00 . 2008-12-23 15:00 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-23 15:00 . 2008-12-23 15:00 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-23 15:00 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-23 15:00 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-23 13:30 . 2008-12-23 13:30 <DIR> d-------- C:\ProgramData
2008-12-23 13:30 . 2008-12-23 13:30 <DIR> d-------- c:\program files\Angle Interactive
2008-12-20 13:02 . 2008-12-24 15:00 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-20 13:02 . 2008-12-20 13:02 1,409 --a------ c:\windows\QTFont.for
2008-11-30 19:56 . 2008-11-30 19:56 <DIR> d-------- c:\temp\google
2008-11-30 19:56 . 2008-11-30 19:56 <DIR> d-------- C:\temp
2008-11-30 10:13 . 2008-11-30 10:13 <DIR> d-------- c:\windows\system32\IOSUBSYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-13 06:40 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-11-17 20:04 2,306,113 ----a-w c:\windows\system32\GPhotos.scr
2008-11-05 02:23 --------- d-----w c:\documents and settings\All Users\Application Data\PopCap
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:21 455,296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 12:36 286,720 ------w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 21:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 21:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 21:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 21:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 21:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 21:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 21:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 21:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 21:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 21:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 21:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 21:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 21:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 21:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 21:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 21:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 21:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 13:11 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 17:34 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ----a-w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\dllcache\strmdll.dll
2008-09-30 23:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2006-12-27 21:11 251 ----a-w c:\program files\wt3d.ini
2005-02-14 21:09 111 ----a-w c:\program files\Common Files\Register.ini
2005-01-17 18:17 4,798,024 ----a-w c:\program files\Common Files\NetZeroCosmiSetup.exe
2004-11-08 19:10 1,115,136 ----a-w c:\program files\Common Files\Register.exe
.
((((((((((((((((((((((((((((( snapshot@2008-12-24_ 9.09.57.76 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-23 18:00:44 16,384 ------w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-24 17:00:28 16,384 ------w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-23 18:00:44 32,768 ------w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-24 17:00:28 32,768 ------w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-23 18:00:44 32,768 ------w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-24 17:00:28 32,768 ------w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-24 21:55:08 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_178.dat
+ 2008-12-24 21:54:54 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_658.dat
+ 2008-12-24 21:58:08 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_878.dat
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\aqpbouph.exe
2008-12-23 10:20 178176 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP6\A0000597.exe
2008-12-24 09:10 1142 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegBHO-Global.reg
2008-12-24 09:00 1142 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000520.reg
2008-12-24 09:10 122 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDCMD-Maila.reg
2008-12-24 09:00 78 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000480.reg
2008-12-24 09:10 145 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDContxM-Global.reg
2008-12-24 09:00 145 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000472.reg
2008-12-24 09:10 135 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDFind-Maila.reg
2008-12-24 09:00 135 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000471.reg
2008-12-24 09:10 132 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDGB-Maila.reg
2008-12-24 09:00 78 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000478.reg
2008-12-24 09:10 151 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDMyCProp-Maila.reg
2008-12-24 09:00 151 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000470.reg
2008-12-24 09:10 152 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDMyDProp-Maila.reg
2008-12-24 09:00 152 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000469.reg
2008-12-24 09:10 11638 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDPF-Global.reg
2008-12-24 09:00 11638 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000519.reg
2008-12-24 09:10 133 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDRegT-Global.reg
2008-12-24 09:00 148 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000476.reg
2008-12-24 09:10 132 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDRegT-Maila.reg
2008-12-24 09:00 78 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000479.reg
2008-12-24 09:10 128 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDScrP-Maila.reg
2008-12-24 09:00 78 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000477.reg
2008-12-24 09:10 132 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDSysRes-Global.reg
2008-12-24 09:00 89 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000474.reg
2008-12-24 09:10 136 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDSysResC-Global.reg
2008-12-24 09:00 89 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000475.reg
2008-12-24 09:10 142 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDTaskMgr-Global.reg
2008-12-24 09:00 142 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000473.reg
2008-12-24 09:10 60 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDummy-Maila.reg
2008-12-24 09:00 60 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000531.reg
2008-12-24 09:10 77 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtBat-Global.reg
2008-12-24 09:00 77 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000502.reg
2008-12-24 09:10 77 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtCmd-Global.reg
2008-12-24 09:00 77 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000496.reg
2008-12-24 09:10 77 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtCom-Global.reg
2008-12-24 09:00 77 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000501.reg
2008-12-24 09:10 77 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtExe-Global.reg
2008-12-24 09:00 77 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000500.reg
2008-12-24 09:10 77 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtPif-Global.reg
2008-12-24 09:00 77 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000499.reg
2008-12-24 09:10 86 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtReg-Global.reg
2008-12-24 09:00 86 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000497.reg
2008-12-24 09:10 77 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtScr-Global.reg
2008-12-24 09:00 77 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000498.reg
2008-12-24 09:10 81 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBME-Global.reg
2008-12-24 09:00 81 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000515.reg
2008-12-24 09:10 116 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBP1-Global.reg
2008-12-24 09:00 116 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000509.reg
2008-12-24 09:10 352 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBP2a-Global.reg
2008-12-24 09:00 352 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000506.reg
2008-12-24 09:10 516 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBP2b-Global.reg
2008-12-24 09:00 516 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000505.reg
2008-12-24 09:10 277 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBP3-Global.reg
2008-12-24 09:00 277 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000504.reg
2008-12-24 09:10 116 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBP4-Global.reg
2008-12-24 09:00 83 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000503.reg
2008-12-24 09:10 186 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBTB1-Global.reg
2008-12-24 09:00 186 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000521.reg
2008-12-24 09:10 240 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBTB2-Global.reg
2008-12-24 09:00 240 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000517.reg
2008-12-24 14:58 87 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGCP-Global.reg
2008-12-24 09:00 87 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000466.reg
2008-12-24 09:10 87 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000586.reg
2008-12-24 09:10 88 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGIESH-Global.reg
2008-12-24 09:00 88 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000483.reg
2008-12-24 09:10 89 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGNTCVW-Global.reg
2008-12-24 09:00 244 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000493.reg
2008-12-24 09:10 336 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGNTCVWL-Global.reg
2008-12-24 09:00 336 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000491.reg
2008-12-24 09:10 673 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS1-Global.reg
2008-12-24 09:00 673 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000526.reg
2008-12-24 09:10 205 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS1SM-Global.reg
2008-12-24 09:00 205 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000488.reg
2008-12-24 15:07 86 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS2-Global.reg
2008-12-23 21:25 191 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP4\A0000423.reg
2008-12-24 09:10 86 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000589.reg
2008-12-24 09:10 205 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS2SM-Global.reg
2008-12-24 09:00 205 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000487.reg
2008-12-24 09:10 90 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS3-Global.reg
2008-12-24 09:00 90 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000524.reg
2008-12-24 09:10 180 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS3SM-Global.reg
2008-12-24 09:00 81 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000486.reg
2008-12-24 09:10 94 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS4-Global.reg
2008-12-24 09:00 94 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000523.reg
2008-12-24 09:10 13929 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGSS-Global.reg
2008-12-24 09:00 13737 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000481.reg
2008-12-24 09:10 383 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGSSODL-Global.reg
2008-12-24 09:00 383 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000489.reg
2008-12-24 09:10 6906 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGWLN-Global.reg
2008-12-24 09:00 6906 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000482.reg
2008-12-24 09:10 1142 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBME-Maila.reg
2008-12-24 09:00 1142 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000516.reg
2008-12-24 09:10 115 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBP1-Maila.reg
2008-12-24 09:00 115 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000514.reg
2008-12-24 09:10 290 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBP2a-Maila.reg
2008-12-24 09:00 290 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000513.reg
2008-12-24 09:10 407 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBP2b-Maila.reg
2008-12-24 09:00 407 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000512.reg
2008-12-24 09:10 177 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBP3-Maila.reg
2008-12-24 09:00 79 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000511.reg
2008-12-24 09:10 115 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBP4-Maila.reg
2008-12-24 09:00 115 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000510.reg
2008-12-24 09:10 3734 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBTB1-Maila.reg
2008-12-24 09:00 3734 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000522.reg
2008-12-24 09:10 86 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBTB2-Maila.reg
2008-12-24 09:00 86 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000518.reg
2008-12-24 09:10 113 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUCP-Maila.reg
2008-12-24 09:00 113 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000495.reg
2008-12-24 09:10 136 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUDesk-Maila.reg
2008-12-24 09:00 136 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000485.reg
2008-12-24 09:10 132 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUIESH-Maila.reg
2008-12-24 09:00 132 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000484.reg
2008-12-24 09:10 235 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUNTCVW-Maila.reg
2008-12-24 09:00 208 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000494.reg
2008-12-24 09:10 390 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUNTCVWL-Maila.reg
2008-12-24 09:00 390 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000492.reg
2008-12-24 09:10 213 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUS1-Maila.reg
2008-12-24 09:00 213 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000530.reg
2008-12-24 09:10 85 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUS2-Maila.reg
2008-12-24 09:00 85 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000529.reg
2008-12-24 09:10 89 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUS3-Maila.reg
2008-12-24 09:00 89 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000528.reg
2008-12-24 09:10 93 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUS4-Maila.reg
2008-12-24 09:00 93 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000527.reg
2008-12-24 09:10 105 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUSSODL-Maila.reg
2008-12-24 09:00 105 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000490.reg
2008-12-24 14:54 229320 c:\program files\Alwil Software\Avast4\DATA\aswar0.dll
2008-12-23 20:39 229320 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP4\A0000414.dll
2008-12-24 09:06 229320 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000581.dll
2008-12-24 14:54 391216 c:\program files\Alwil Software\Avast4\DATA\clnr0.dll
2008-12-23 20:39 391216 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP4\A0000412.dll
2008-12-24 09:06 391216 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000579.dll
2008-12-24 14:54 9080 c:\program files\Alwil Software\Avast4\DATA\exts0.dll
2008-12-23 20:39 9080 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP4\A0000413.dll
2008-12-24 09:06 9080 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000580.dll
c:\windows\aazalirt.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000437.exe
c:\windows\iddqdops.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000438.exe
c:\windows\jikglond.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000439.exe
c:\windows\jiklagka.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000440.exe
c:\windows\jungertab.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000441.exe
c:\windows\klopnidret.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000442.exe
c:\windows\ronitfst.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000443.exe
c:\windows\salrtybek.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000444.exe
c:\windows\seeukluba.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000445.exe
c:\windows\skaaanret.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000446.exe
c:\windows\system32\bmvhwlgf.dll
2008-12-23 10:11 130048 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000450.dll
c:\windows\system32\HXHNVY.DLL
2008-12-23 10:11 130048 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000451.DLL
c:\windows\system32\yAtqroPi.dll
2008-12-23 10:05 45056 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP6\A0000598.dll
c:\windows\tobmygers.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000447.exe
c:\windows\tobykke.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000448.exe
c:\windows\zibaglertz.exe
2008-12-23 14:02 0 {099D30DC-C26B-4E90-9285-C34D0601D32B}\RP5\A0000449.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-05-30 421888]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer Empowering Technology.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk
backup=c:\windows\pss\Acer Empowering Technology.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Maila^Start Menu^Programs^Startup^OpenOffice.org 2.1.lnk]
path=c:\documents and settings\Maila\Start Menu\Programs\Startup\OpenOffice.org 2.1.lnk
backup=c:\windows\pss\OpenOffice.org 2.1.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD]
--a------ 2006-03-31 16:39 204800 c:\acer\Empowering Technology\ePresentation\ePresentation.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
-ra------ 2007-03-01 10:37 2321600 c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
--a------ 2006-05-10 11:12 90112 c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
--------- 2006-04-14 22:35 53248 c:\program files\Realtek\InstallShield\AzMixerSel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot]
--a------ 2006-03-15 22:12 579584 c:\acer\Empowering Technology\ePower\Boot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
--a------ 2006-03-21 18:30 1191936 c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative WebCam Tray]
--a------ 2003-10-13 03:04 184320 c:\program files\Creative\Shared Files\CamTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 18:12 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTRegRun]
--------- 1999-10-10 19:00 41984 c:\windows\Ctregrun.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2005-08-05 13:56 64512 c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC]
--a------ 2006-05-30 12:11 421888 c:\acer\Empowering Technology\ePower\ePower_DMC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]
--a------ 2006-06-01 14:40 413696 c:\acer\Empowering Technology\eRecovery\eRAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-10 20:00 208952 c:\windows\ime\imjp8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
--a------ 2006-06-23 06:59 602112 c:\progra~1\LAUNCH~1\LManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
--a------ 2004-08-10 20:00 59392 c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntiMUI]
--a------ 2005-05-11 17:15 45056 c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-10 20:00 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-10 20:00 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-12-23 20:21 282624 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-07-27 22:39 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2006-03-03 13:07 761946 c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2006-11-03 19:20 866584 c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2006-06-27 23:54 16248320 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
--a------ 2006-05-16 03:04 2879488 c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WinDefend"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"LightScribeService"=2 (0x2)
"IDriverT"=3 (0x3)
"gusvc"=2 (0x2)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-23 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-23 20560]
S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;\??\c:\windows\system32\eLock2BurnerLockDriver.sys []
S2 eLock2FSCTLDriver;eLock2FSCTLDriver;\??\c:\windows\system32\eLock2FSCTLDriver.sys []
S4 WinDefend;Windows Defender;"c:\program files\Windows Defender\MsMpEng.exe" [2006-11-03 13592]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
2008-12-24 c:\windows\Tasks\ifowopbu.job
- c:\windows\system32\rundll32.exe [2008-04-13 18:12]
.
- - - - ORPHANS REMOVED - - - -
BHO-{8D8344B2-1B88-40FE-90B0-FC607E84A3EC} - (no file)
BHO-{ad7d2853-dd91-4725-a409-bd1807fd9a8f} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: Yahoo! Spelldown - hxxp://origin.games.yahoo.net/games/clients/y/sdt1_x.cab
c:\windows\Downloaded Program Files\Yahoo! Spelldown.osd
O16 -: Yahoo! Word Racer - hxxp://origin.games.yahoo.net/games/clients/y/wt1_x.cab
c:\windows\Downloaded Program Files\Yahoo! Word Racer.osd
FF - ProfilePath - c:\documents and settings\Maila\Application Data\Mozilla\Firefox\Profiles\aa34a4oi.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
FF - component: c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nphssb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npsnapfish.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-24 15:10:30
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2008-12-24 15:11:46
ComboFix-quarantined-files.txt 2008-12-24 22:11:44
ComboFix2.txt 2008-12-24 16:11:04
Pre-Run: 18,132,074,496 bytes free
Post-Run: 18,113,167,360 bytes free
417 --- E O F --- 2008-12-22 16:08:51