I had a problem with my laptop and I am posting here just because I still do not know what exactly was the problem with my computer.
I myself am 25 years old and rather experienced with computers and IT.
I am expert Java, PHP, Java EE programmer and love car driving and gaming.
So aboot that problem.
Time to fix ~20hours
Problem: At first popups appear while browsing the internet. Antivirus 2008 XP starts scanning. Does not matter which browser.
Used software: ESET Smart Security -> found some problems, fixed them, but the main behaviour still remained. Scanning tool awful 15 hours
Used software: Spyware Doctor -> Found a lot of problems, fixed them, after that it is impossible to perform search on Google, Yahoo, login to Orkut, so the problem is not fixed.
After finding out that the traditional Spyware and Antivirus won't help tried alternatives, monitored the active ports and found out that %SYSTEMROOT%\Explorer.exe was infected. When I killed the process, my internet connection was working fine. So I Started to look for a proper program to fix the problem and found out ComboFix.
Scanned the computer and found A LOT of infections + had to reinstall network drivers + power options + re-set desktop settings and security center settings and now Everything seems to be back in order.
However I still do not know what was the reason, I do know that it is not the casino software on my computer, because I has been over a month on my PC and no problems at all. Problem itself occured 3rd of August 2008 and on the 5th of August 2008 it is fixed.
So here is the log, and also I can post the quarantined files if You like.
CODE
ComboFix 08-08-03.05 - Administrator 2008-08-04 22:50:42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2540 [GMT 3:00]
Running from: C:\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMa316ea41.txt
C:\WINDOWS\BMa316ea41.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\fgdtypql.dll
C:\WINDOWS\system32\ipclxjlp.dll
C:\WINDOWS\system32\iSYHNqru.ini
C:\WINDOWS\system32\iSYHNqru.ini2
C:\WINDOWS\system32\iucpvbqv.dll
C:\WINDOWS\system32\iykesihr.ini
C:\WINDOWS\system32\jsyfiroa.ini
C:\WINDOWS\system32\njxdplgf.dll
C:\WINDOWS\system32\pysaldns.dll
C:\WINDOWS\system32\qrsadntf.dll
C:\WINDOWS\system32\sbhkkxrg.dll
C:\WINDOWS\system32\sndlasyp.ini
C:\WINDOWS\system32\urqNHYSi.dll
C:\WINDOWS\system32\wxmclork.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-04 to 2008-08-04 )))))))))))))))))))))))))))))))
.
2008-08-04 23:13 . 2008-08-04 23:13 53,248 --a------ C:\TEMP\catchme.dll
2008-08-04 23:10 . 2008-08-04 23:10 <DIR> d-------- C:\TEMP\WPDNSE
2008-08-04 22:44 . 2008-08-04 22:39 2,677,907 --a------ C:\ComboFix.exe
2008-08-04 21:30 . 2008-08-04 23:11 <DIR> d-------- C:\TEMP\is-AK1K5.tmp
2008-08-04 21:12 . 2008-08-04 21:12 <DIR> d--hs---- C:\TEMP\History
2008-08-04 21:12 . 2008-08-04 23:11 <DIR> d--hs---- C:\TEMP\Cookies
2008-08-04 20:43 . 2008-08-04 21:52 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-04 20:41 . 2008-08-04 21:52 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-08-04 20:41 . 2008-08-04 20:41 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-08-04 20:41 . 2007-10-04 17:10 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-08-04 20:41 . 2007-10-04 17:10 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-08-04 20:41 . 2007-10-04 17:10 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-08-04 20:41 . 2007-10-04 17:11 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-08-04 20:40 . 2008-08-04 23:11 <DIR> d-------- C:\TEMP\is-GC95J.tmp
2008-08-04 20:40 . 2008-08-04 20:40 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-08-04 20:40 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-08-04 20:39 . 2008-08-04 23:11 <DIR> d-------- C:\TEMP\DRDld
2008-08-04 20:39 . 2008-08-04 20:40 128,344 --a------ C:\Download_5.1.0.272f-5.1.0.272-sdregnow.exe
2008-08-04 20:38 . 2008-08-04 20:38 2,048 --a------ C:\WINDOWS\system32\etxeodpc.exe
2008-08-04 20:17 . 2008-08-04 20:17 15,631 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_8_4_20_17_45.dmp
2008-08-04 20:02 . 2008-08-04 20:02 15,631 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_8_4_20_2_21.dmp
2008-08-04 19:49 . 2008-08-04 19:50 187,072 --a------ C:\FixSwen.exe
2008-08-04 18:48 . 2008-08-04 18:48 15,843 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_8_4_18_48_33.dmp
2008-08-03 14:23 . 2008-08-03 14:23 <DIR> d-------- C:\Program Files\Hasbro
2008-08-03 14:22 . 2008-08-03 14:22 33,792 --a------ C:\WINDOWS\system32\efcDUnOg.dll.bak
2008-08-03 13:49 . 2008-08-03 13:49 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-1016403232
2008-08-03 13:42 . 2008-08-03 13:42 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war1760985868
2008-08-03 13:32 . 2008-08-03 13:32 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-1626335074
2008-08-03 13:19 . 2008-08-03 13:19 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-896084363
2008-08-03 13:00 . 2008-08-03 13:00 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-1147908829
2008-08-03 12:22 . 2008-08-03 12:22 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-297603296
2008-08-02 08:52 . 2008-08-02 08:52 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war1916745708
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 9 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 8 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 7 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 6 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 5 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 4 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 3 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 2 for My Pictures.zip
2008-08-01 10:19 . 2008-08-01 10:19 <DIR> d--h----- C:\TEMP\Temporary Directory 1 for My Pictures.zip
2008-07-31 09:01 . 2008-07-31 09:01 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war888629511
2008-07-29 10:24 . 2008-07-29 10:24 <DIR> d-------- C:\Program Files\MetaTrader 4 - Dealing24
2008-07-25 10:38 . 2008-07-25 10:38 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war695103424
2008-07-24 11:02 . 2008-07-24 11:02 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-1675922835
2008-07-24 00:22 . 2008-07-24 00:23 <DIR> d-------- C:\TEMP\svoik.tmp
2008-07-22 17:18 . 2008-08-04 23:11 <DIR> d-------- C:\TEMP\nsa3.tmp
2008-07-22 17:17 . 2008-07-22 17:17 0 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_7_22_17_17_50.dmp
2008-07-22 16:56 . 2008-07-22 17:10 <DIR> d-------- C:\TEMP\plugtmp-38
2008-07-22 08:55 . 2008-07-22 14:35 <DIR> d-------- C:\TEMP\plugtmp-37
2008-07-17 20:29 . 2008-07-17 20:29 <DIR> d-------- C:\TEMP\moz_mapi
2008-07-13 18:23 . 2008-07-13 18:23 13,489 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_7_13_18_23_47.dmp
2008-07-11 20:24 . 2008-07-11 20:24 13,701 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_7_11_20_24_23.dmp
2008-07-11 19:29 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-07-11 19:29 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-07-11 19:29 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-07-11 19:29 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-07-10 19:23 . 2008-07-10 19:23 0 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_7_10_19_23_4.dmp
2008-07-10 10:24 . 2008-07-10 10:25 <DIR> d-------- C:\abi
2008-07-09 20:56 . 2008-07-09 20:56 <DIR> d-------- C:\WINDOWS\system32\FlashAX2
2008-07-09 15:13 . 2008-07-09 15:13 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war737556225
2008-07-09 15:03 . 2008-07-09 15:03 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war1193152091
2008-07-09 14:56 . 2008-07-09 14:56 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war839207413
2008-07-09 14:43 . 2008-07-09 14:43 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war660514237
2008-07-09 13:04 . 2008-07-09 13:04 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-2057143812
2008-07-09 08:53 . 2008-07-09 08:53 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-103214277
2008-07-06 14:41 . 2008-07-06 14:41 <DIR> d-------- C:\Program Files\Ant Movie Catalog
2008-07-04 16:54 . 2008-07-04 16:54 0 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_7_4_16_54_40.dmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-04 20:12 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2008-08-04 15:49 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-08-04 15:45 --------- d-----w C:\Documents and Settings\Administrator\Application Data\skypePM
2008-08-04 08:51 --------- d-----w C:\Program Files\Zipang Casino
2008-08-04 08:45 --------- d-----w C:\Program Files\XXL Club Casino
2008-08-04 07:23 --------- d-----w C:\Program Files\Grand Online Casino
2008-08-04 07:18 --------- d-----w C:\Program Files\Europa Casino
2008-08-04 07:16 --------- d-----w C:\Program Files\EuroGrand Casino
2008-08-04 06:47 --------- d-----w C:\Program Files\Casino Tropez
2008-08-04 06:47 --------- d-----w C:\Program Files\Casino Fortune
2008-08-04 06:47 --------- d-----w C:\Program Files\Casino Bellini
2008-07-23 21:22 --------- d-----w C:\Documents and Settings\Administrator\Application Data\SunODFPluginforMicrosoftOffice1
2008-07-18 21:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-04 13:49 --------- d-----w C:\Program Files\Trillian
2008-07-04 12:23 --------- d-----w C:\Program Files\IDoser v4
2008-07-03 11:04 --------- d-----w C:\Program Files\MySQL
2008-07-03 05:06 --------- d-----w C:\Program Files\Common Files\Skype
2008-07-02 18:14 --------- d-----w C:\Program Files\Microsoft Games
2008-07-02 13:00 --------- d-----w C:\Program Files\Sun
2008-06-30 11:22 --------- d-----w C:\Program Files\Playboy Casino GBP
2008-06-30 08:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microgaming
2008-06-27 16:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\MGS
2008-06-27 16:10 --------- d-----w C:\Program Files\Casino
2008-06-27 12:35 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CasinoOnNet
2008-06-27 12:31 --------- d-----w C:\Program Files\CasinoOnNet
2008-06-20 07:13 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-07 15:21 --------- d-----w C:\Program Files\Omasoft
2008-06-05 10:33 --------- d-----w C:\Program Files\Stocker
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-05-30 15:54 21718312]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2006-01-24 11:37 7094272]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 16:35 202024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-09-21 02:07 184320]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 16:10 851968]
"OEM04Mon.exe"="C:\WINDOWS\OEM04Mon.exe" [2007-06-11 01:01 36864]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2007-07-20 17:55 1228800]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-22 23:35 8433664]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 16:32 823296]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 16:30 974848]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 15:00 59392]
"VersatoMs"="C:\Program Files\MagicMus\MulMouse.exe" [2004-06-17 16:14 282624]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-28 15:12 222720]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 10:51 1836328]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 17:40 1884160]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"nwiz"="nwiz.exe" [2007-05-22 23:35 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2007-05-22 23:35 81920 C:\WINDOWS\system32\nvmctray.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 18:15 1634304]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-05-17 15:43:18 568176]
Device Detector 3.lnk - C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe [2007-10-03 10:06:11 118784]
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2003-08-06 13:23:32 51776]
Monitor Apache Servers.lnk - C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe [2006-07-27 15:59:08 41042]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 15:29:20 54512]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"C:\\Program Files\\Yahoo!\\UPnP\\yupnpsrv.exe"=
"C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R2 MUsbFltr;USB WTMouse Filter Service;C:\WINDOWS\system32\DRIVERS\MUsbFltr.sys [2004-03-22 13:45]
R2 OracleDBConsoleMATIS;OracleDBConsoleMATIS;C:\oracle\product\10.1.0\Db_1\bin\nmesrvc.exe [2006-11-14 07:22]
R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2005-09-06 12:39]
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2005-09-06 12:39]
R3 OEM04Afx;Provides a software interface to control audio effects of OEM004 camera.;C:\WINDOWS\system32\Drivers\OEM04Afx.sys [2007-06-07 18:00]
R3 OEM04Vfx;Creative Camera OEM004 Video VFX Driver;C:\WINDOWS\system32\DRIVERS\OEM04Vfx.sys [2007-03-05 11:45]
R3 OEM04Vid;Creative Camera OEM004 Driver;C:\WINDOWS\system32\DRIVERS\OEM04Vid.sys [2007-10-10 18:01]
S3 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2005-09-06 12:39]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 23:22]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\NSNDIS5.SYS [2004-03-24 05:12]
S3 OracleOraDb10g_home1TNSListener;OracleOraDb10g_home1TNSListener;C:\oracle\product\10.1.0\Db_1\BIN\TNSLSNR []
S3 OracleServiceMATIS;OracleServiceMATIS;c:\oracle\product\10.1.0\db_1\bin\ORACLE.EXE MATIS []
S3 VNUSB;VN Series Device;C:\WINDOWS\system32\DRIVERS\VNUSB.sys [2006-04-07 17:06]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 07:01]
S4 OracleJobSchedulerMATIS;OracleJobSchedulerMATIS;c:\oracle\product\10.1.0\db_1\Bin\extjob.exe MATIS []
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-BMa316ea41 - C:\WINDOWS\system32\njxdplgf.dll
Notify-efcDUnOg - efcDUnOg.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\mxdlesb6.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.neti.ee/
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-04 23:14:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\TEMP\VDMC1Oj5FV
C:\TEMP\VDMC1Oj5FV
scan completed successfully
hidden files: 2
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"C:\Program Files\MySQL\MySQL Server 5.0\my.ini\" MySQL"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OracleOraDb10g_home1TNSListener]
"ImagePath"="C:\oracle\product\10.1.0\Db_1\BIN\TNSLSNR "
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\stacsv.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\oracle\product\10.1.0\Db_1\perl\5.8.3\bin\MSWin32-x86-multi-thread\perl.exe
C:\oracle\product\10.1.0\Db_1\jdk\bin\java.exe
C:\oracle\product\10.1.0\Db_1\bin\emagent.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\PC Connectivity Solution\NclBTHandler.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2008-08-04 23:50:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-04 20:50:03
Pre-Run: 16,663,916,544 bytes free
Post-Run: 21,993,426,944 bytes free
288
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2540 [GMT 3:00]
Running from: C:\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMa316ea41.txt
C:\WINDOWS\BMa316ea41.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\fgdtypql.dll
C:\WINDOWS\system32\ipclxjlp.dll
C:\WINDOWS\system32\iSYHNqru.ini
C:\WINDOWS\system32\iSYHNqru.ini2
C:\WINDOWS\system32\iucpvbqv.dll
C:\WINDOWS\system32\iykesihr.ini
C:\WINDOWS\system32\jsyfiroa.ini
C:\WINDOWS\system32\njxdplgf.dll
C:\WINDOWS\system32\pysaldns.dll
C:\WINDOWS\system32\qrsadntf.dll
C:\WINDOWS\system32\sbhkkxrg.dll
C:\WINDOWS\system32\sndlasyp.ini
C:\WINDOWS\system32\urqNHYSi.dll
C:\WINDOWS\system32\wxmclork.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-04 to 2008-08-04 )))))))))))))))))))))))))))))))
.
2008-08-04 23:13 . 2008-08-04 23:13 53,248 --a------ C:\TEMP\catchme.dll
2008-08-04 23:10 . 2008-08-04 23:10 <DIR> d-------- C:\TEMP\WPDNSE
2008-08-04 22:44 . 2008-08-04 22:39 2,677,907 --a------ C:\ComboFix.exe
2008-08-04 21:30 . 2008-08-04 23:11 <DIR> d-------- C:\TEMP\is-AK1K5.tmp
2008-08-04 21:12 . 2008-08-04 21:12 <DIR> d--hs---- C:\TEMP\History
2008-08-04 21:12 . 2008-08-04 23:11 <DIR> d--hs---- C:\TEMP\Cookies
2008-08-04 20:43 . 2008-08-04 21:52 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-04 20:41 . 2008-08-04 21:52 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-08-04 20:41 . 2008-08-04 20:41 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-08-04 20:41 . 2007-10-04 17:10 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-08-04 20:41 . 2007-10-04 17:10 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-08-04 20:41 . 2007-10-04 17:10 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-08-04 20:41 . 2007-10-04 17:11 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-08-04 20:40 . 2008-08-04 23:11 <DIR> d-------- C:\TEMP\is-GC95J.tmp
2008-08-04 20:40 . 2008-08-04 20:40 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-08-04 20:40 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-08-04 20:39 . 2008-08-04 23:11 <DIR> d-------- C:\TEMP\DRDld
2008-08-04 20:39 . 2008-08-04 20:40 128,344 --a------ C:\Download_5.1.0.272f-5.1.0.272-sdregnow.exe
2008-08-04 20:38 . 2008-08-04 20:38 2,048 --a------ C:\WINDOWS\system32\etxeodpc.exe
2008-08-04 20:17 . 2008-08-04 20:17 15,631 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_8_4_20_17_45.dmp
2008-08-04 20:02 . 2008-08-04 20:02 15,631 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_8_4_20_2_21.dmp
2008-08-04 19:49 . 2008-08-04 19:50 187,072 --a------ C:\FixSwen.exe
2008-08-04 18:48 . 2008-08-04 18:48 15,843 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_8_4_18_48_33.dmp
2008-08-03 14:23 . 2008-08-03 14:23 <DIR> d-------- C:\Program Files\Hasbro
2008-08-03 14:22 . 2008-08-03 14:22 33,792 --a------ C:\WINDOWS\system32\efcDUnOg.dll.bak
2008-08-03 13:49 . 2008-08-03 13:49 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-1016403232
2008-08-03 13:42 . 2008-08-03 13:42 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war1760985868
2008-08-03 13:32 . 2008-08-03 13:32 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-1626335074
2008-08-03 13:19 . 2008-08-03 13:19 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-896084363
2008-08-03 13:00 . 2008-08-03 13:00 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-1147908829
2008-08-03 12:22 . 2008-08-03 12:22 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-297603296
2008-08-02 08:52 . 2008-08-02 08:52 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war1916745708
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 9 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 8 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 7 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 6 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 5 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 4 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 3 for My Pictures.zip
2008-08-01 10:20 . 2008-08-01 10:20 <DIR> d--h----- C:\TEMP\Temporary Directory 2 for My Pictures.zip
2008-08-01 10:19 . 2008-08-01 10:19 <DIR> d--h----- C:\TEMP\Temporary Directory 1 for My Pictures.zip
2008-07-31 09:01 . 2008-07-31 09:01 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war888629511
2008-07-29 10:24 . 2008-07-29 10:24 <DIR> d-------- C:\Program Files\MetaTrader 4 - Dealing24
2008-07-25 10:38 . 2008-07-25 10:38 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war695103424
2008-07-24 11:02 . 2008-07-24 11:02 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-1675922835
2008-07-24 00:22 . 2008-07-24 00:23 <DIR> d-------- C:\TEMP\svoik.tmp
2008-07-22 17:18 . 2008-08-04 23:11 <DIR> d-------- C:\TEMP\nsa3.tmp
2008-07-22 17:17 . 2008-07-22 17:17 0 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_7_22_17_17_50.dmp
2008-07-22 16:56 . 2008-07-22 17:10 <DIR> d-------- C:\TEMP\plugtmp-38
2008-07-22 08:55 . 2008-07-22 14:35 <DIR> d-------- C:\TEMP\plugtmp-37
2008-07-17 20:29 . 2008-07-17 20:29 <DIR> d-------- C:\TEMP\moz_mapi
2008-07-13 18:23 . 2008-07-13 18:23 13,489 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_7_13_18_23_47.dmp
2008-07-11 20:24 . 2008-07-11 20:24 13,701 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_7_11_20_24_23.dmp
2008-07-11 19:29 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-07-11 19:29 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-07-11 19:29 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-07-11 19:29 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-07-10 19:23 . 2008-07-10 19:23 0 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_7_10_19_23_4.dmp
2008-07-10 10:24 . 2008-07-10 10:25 <DIR> d-------- C:\abi
2008-07-09 20:56 . 2008-07-09 20:56 <DIR> d-------- C:\WINDOWS\system32\FlashAX2
2008-07-09 15:13 . 2008-07-09 15:13 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war737556225
2008-07-09 15:03 . 2008-07-09 15:03 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war1193152091
2008-07-09 14:56 . 2008-07-09 14:56 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war839207413
2008-07-09 14:43 . 2008-07-09 14:43 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war660514237
2008-07-09 13:04 . 2008-07-09 13:04 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-2057143812
2008-07-09 08:53 . 2008-07-09 08:53 <DIR> d-------- C:\TEMP\soov-web-admin-1.6.2.8.war-103214277
2008-07-06 14:41 . 2008-07-06 14:41 <DIR> d-------- C:\Program Files\Ant Movie Catalog
2008-07-04 16:54 . 2008-07-04 16:54 0 --a------ C:\WINDOWS\system32\nmesrvc_core_2008_7_4_16_54_40.dmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-04 20:12 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2008-08-04 15:49 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-08-04 15:45 --------- d-----w C:\Documents and Settings\Administrator\Application Data\skypePM
2008-08-04 08:51 --------- d-----w C:\Program Files\Zipang Casino
2008-08-04 08:45 --------- d-----w C:\Program Files\XXL Club Casino
2008-08-04 07:23 --------- d-----w C:\Program Files\Grand Online Casino
2008-08-04 07:18 --------- d-----w C:\Program Files\Europa Casino
2008-08-04 07:16 --------- d-----w C:\Program Files\EuroGrand Casino
2008-08-04 06:47 --------- d-----w C:\Program Files\Casino Tropez
2008-08-04 06:47 --------- d-----w C:\Program Files\Casino Fortune
2008-08-04 06:47 --------- d-----w C:\Program Files\Casino Bellini
2008-07-23 21:22 --------- d-----w C:\Documents and Settings\Administrator\Application Data\SunODFPluginforMicrosoftOffice1
2008-07-18 21:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-04 13:49 --------- d-----w C:\Program Files\Trillian
2008-07-04 12:23 --------- d-----w C:\Program Files\IDoser v4
2008-07-03 11:04 --------- d-----w C:\Program Files\MySQL
2008-07-03 05:06 --------- d-----w C:\Program Files\Common Files\Skype
2008-07-02 18:14 --------- d-----w C:\Program Files\Microsoft Games
2008-07-02 13:00 --------- d-----w C:\Program Files\Sun
2008-06-30 11:22 --------- d-----w C:\Program Files\Playboy Casino GBP
2008-06-30 08:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microgaming
2008-06-27 16:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\MGS
2008-06-27 16:10 --------- d-----w C:\Program Files\Casino
2008-06-27 12:35 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CasinoOnNet
2008-06-27 12:31 --------- d-----w C:\Program Files\CasinoOnNet
2008-06-20 07:13 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-07 15:21 --------- d-----w C:\Program Files\Omasoft
2008-06-05 10:33 --------- d-----w C:\Program Files\Stocker
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 12:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-05-30 15:54 21718312]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2006-01-24 11:37 7094272]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 16:35 202024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-09-21 02:07 184320]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 16:10 851968]
"OEM04Mon.exe"="C:\WINDOWS\OEM04Mon.exe" [2007-06-11 01:01 36864]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2007-07-20 17:55 1228800]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-22 23:35 8433664]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 16:32 823296]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 16:30 974848]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 15:00 59392]
"VersatoMs"="C:\Program Files\MagicMus\MulMouse.exe" [2004-06-17 16:14 282624]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-28 15:12 222720]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 10:51 1836328]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 17:40 1884160]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"nwiz"="nwiz.exe" [2007-05-22 23:35 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2007-05-22 23:35 81920 C:\WINDOWS\system32\nvmctray.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 18:15 1634304]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-05-17 15:43:18 568176]
Device Detector 3.lnk - C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe [2007-10-03 10:06:11 118784]
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2003-08-06 13:23:32 51776]
Monitor Apache Servers.lnk - C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe [2006-07-27 15:59:08 41042]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 15:29:20 54512]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"C:\\Program Files\\Yahoo!\\UPnP\\yupnpsrv.exe"=
"C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R2 MUsbFltr;USB WTMouse Filter Service;C:\WINDOWS\system32\DRIVERS\MUsbFltr.sys [2004-03-22 13:45]
R2 OracleDBConsoleMATIS;OracleDBConsoleMATIS;C:\oracle\product\10.1.0\Db_1\bin\nmesrvc.exe [2006-11-14 07:22]
R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2005-09-06 12:39]
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2005-09-06 12:39]
R3 OEM04Afx;Provides a software interface to control audio effects of OEM004 camera.;C:\WINDOWS\system32\Drivers\OEM04Afx.sys [2007-06-07 18:00]
R3 OEM04Vfx;Creative Camera OEM004 Video VFX Driver;C:\WINDOWS\system32\DRIVERS\OEM04Vfx.sys [2007-03-05 11:45]
R3 OEM04Vid;Creative Camera OEM004 Driver;C:\WINDOWS\system32\DRIVERS\OEM04Vid.sys [2007-10-10 18:01]
S3 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2005-09-06 12:39]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 23:22]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\NSNDIS5.SYS [2004-03-24 05:12]
S3 OracleOraDb10g_home1TNSListener;OracleOraDb10g_home1TNSListener;C:\oracle\product\10.1.0\Db_1\BIN\TNSLSNR []
S3 OracleServiceMATIS;OracleServiceMATIS;c:\oracle\product\10.1.0\db_1\bin\ORACLE.EXE MATIS []
S3 VNUSB;VN Series Device;C:\WINDOWS\system32\DRIVERS\VNUSB.sys [2006-04-07 17:06]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 07:01]
S4 OracleJobSchedulerMATIS;OracleJobSchedulerMATIS;c:\oracle\product\10.1.0\db_1\Bin\extjob.exe MATIS []
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-BMa316ea41 - C:\WINDOWS\system32\njxdplgf.dll
Notify-efcDUnOg - efcDUnOg.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\mxdlesb6.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.neti.ee/
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-04 23:14:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\TEMP\VDMC1Oj5FV
C:\TEMP\VDMC1Oj5FV
scan completed successfully
hidden files: 2
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"C:\Program Files\MySQL\MySQL Server 5.0\my.ini\" MySQL"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OracleOraDb10g_home1TNSListener]
"ImagePath"="C:\oracle\product\10.1.0\Db_1\BIN\TNSLSNR "
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\stacsv.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\oracle\product\10.1.0\Db_1\perl\5.8.3\bin\MSWin32-x86-multi-thread\perl.exe
C:\oracle\product\10.1.0\Db_1\jdk\bin\java.exe
C:\oracle\product\10.1.0\Db_1\bin\emagent.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\PC Connectivity Solution\NclBTHandler.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2008-08-04 23:50:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-04 20:50:03
Pre-Run: 16,663,916,544 bytes free
Post-Run: 21,993,426,944 bytes free
288
Thanks in advance