Hi JSntgRvr and thank you for your help. Here are my Malwarebytes' Anti-Malware report and my Combofix reports:
Malwarebytes' Anti-Malware 1.40
Database version: 2708
Windows 5.1.2600 Service Pack 2 (Safe Mode)
8/28/2009 12:49:07 AM
mbam-log-2009-08-28 (00-49-07).txt
Scan type: Quick Scan
Objects scanned: 97483
Time elapsed: 5 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 9
Registry Values Infected: 3
Registry Data Items Infected: 2
Folders Infected: 2
Files Infected: 14
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
\\?\globalroot\systemroot\system32\UACaebwudpbgr.dll (Rogue.Agent) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{bf56a325-23f2-42ad-f4e4-00aac39caa53} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bf56a325-23f2-42ad-f4e4-00aac39caa53} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf56a325-23f2-42ad-f4e4-00aac39caa53} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\97c9b68f (Rootkit.Rustock) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\97c9b68f (Rootkit.Rustock) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\97c9b68f (Rootkit.Rustock) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5e2121ee-0300-11d4-8d3b-444553540000} (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\protection system (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\protection system (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{bf56a325-23f2-42ad-f4e4-00aac39caa53} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5e2121ee-0300-11d4-8d3b-444553540000} (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
Folders Infected:
C:\Program Files\Protection System (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Protection System (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
Files Infected:
\\?\globalroot\systemroot\system32\UACaebwudpbgr.dll (Rogue.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Protection System\psystem.exe (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wingenocx.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\97c9b68f.sys (Rootkit.Rustock) -> Quarantined and deleted successfully.
C:\Program Files\Protection System\blacklist.cga (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
C:\Program Files\Protection System\core.cga (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
C:\Program Files\Protection System\coreext.dll (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
C:\Program Files\Protection System\firewall.dll (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
C:\Program Files\Protection System\help.ico (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
C:\Program Files\Protection System\uninstall.exe (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Protection System\Protection System Support.lnk (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Protection System\Protection System.lnk (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Protection System\Uninstall Protection System.lnk (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Delete on reboot.
ComboFix 09-08-27.06 - abc 08/28/2009 1:21.5.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.304 [GMT -7:00]
Running from: c:\documents and settings\abc\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\dhcp
c:\windows\Install.txt
c:\windows\Installer\2467efaf.msi
c:\windows\Installer\27f984.msi
c:\windows\run.log
c:\windows\system32\drivers\UACkxvmtbowil.sys
c:\windows\system32\Install.txt
c:\windows\system32\nerocheck .exe
c:\windows\system32\resdll.dll
c:\windows\system32\UACaebwudpbgr.dll
c:\windows\system32\UACalcdsrqrdk.dll
c:\windows\system32\UACfoivxsmtsa.dll
c:\windows\system32\UACftlwhwwkrr.log
c:\windows\system32\uacinit.dll
c:\windows\system32\UACqsbnrbfhqk.dat
c:\windows\system32\UACvbxhqqentp.dll
c:\windows\system32\wscsvc32.exe
c:\windows\wpd99.drv
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-28 )))))))))))))))))))))))))))))))
.
2009-08-28 07:26 . 2009-08-28 07:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malwareab
2009-08-25 02:55 . 2009-08-25 02:55 152576 ----a-w- c:\documents and settings\abc\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-24 11:31 . 2009-08-24 11:31 -------- d-s---w- c:\documents and settings\LocalService\UserData
2009-08-24 10:58 . 2009-08-24 10:58 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-08-24 10:23 . 2009-08-24 10:23 120 ----a-w- c:\windows\Wwoqagidim.dat
2009-08-24 09:58 . 2009-08-24 09:58 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-24 03:36 . 2009-08-24 03:36 -------- d-----w- c:\documents and settings\abc\Local Settings\Application Data\{7832857B-BD46-4296-B7F0-0C8D7A73265D}
2009-08-07 15:41 . 2009-08-07 15:41 436224 ----a-w- c:\windows\isvchost.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-28 08:21 . 2002-08-29 02:09 182912 ----a-w- c:\windows\system32\drivers\ndis.sys
2009-08-28 07:24 . 2009-01-05 01:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-26 00:48 . 2004-01-24 18:53 -------- d-----w- c:\program files\nbpro
2009-08-25 02:55 . 2009-01-05 05:45 -------- d-----w- c:\program files\Java
2009-08-25 02:53 . 2005-04-23 16:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-08-25 02:52 . 2005-10-03 00:00 -------- d-----w- c:\program files\EPSON
2009-08-25 02:51 . 2005-07-17 14:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-25 02:49 . 2007-10-30 00:00 -------- d-----w- c:\program files\Common Files\Apple
2009-08-25 02:48 . 2007-01-26 14:41 -------- d-----w- c:\program files\Apple Software Update
2009-08-25 01:38 . 2005-03-26 21:38 -------- d-----w- c:\program files\iTunes
2009-08-24 11:26 . 2009-01-11 04:21 3942048 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-24 09:55 . 2003-10-12 18:08 -------- d-----w- c:\program files\Common Files\InstallShield
2009-08-24 09:55 . 2003-10-12 18:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-06 02:11 . 2009-06-17 13:52 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-03 20:36 . 2009-01-05 01:23 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 20:36 . 2009-01-05 01:23 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-25 12:23 . 2009-01-05 05:46 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-06-26 16:18 . 2004-08-24 03:32 659456 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-09-02 21:26 81920 ------w- c:\windows\system32\ieencode.dll
2009-06-16 14:55 . 2002-09-10 13:46 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2002-09-10 13:45 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:27 . 2003-12-17 02:58 1290752 ----a-w- c:\windows\system32\quartz.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-06-15_03.35.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 09:19 . 2007-11-07 09:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2009-08-28 08:31 . 2009-08-28 08:31 16384 c:\windows\temp\Perflib_Perfdata_690.dat
+ 2003-09-26 13:19 . 2009-05-26 11:40 17272 c:\windows\system32\spmsg.dll
- 2003-09-26 13:19 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll
- 2002-08-29 03:41 . 2009-04-29 04:52 39424 c:\windows\system32\pngfilt.dll
+ 2002-08-29 03:41 . 2009-06-26 16:18 39424 c:\windows\system32\pngfilt.dll
+ 2002-08-29 03:40 . 2004-08-04 07:56 55808 c:\windows\system32\logevent.dll
+ 2002-09-10 13:45 . 2009-06-26 16:18 16384 c:\windows\system32\jsproxy.dll
- 2002-09-10 13:45 . 2009-04-29 04:52 16384 c:\windows\system32\jsproxy.dll
- 2004-08-26 17:53 . 2009-04-29 04:52 96256 c:\windows\system32\inseng.dll
+ 2004-08-26 17:53 . 2009-06-26 16:18 96256 c:\windows\system32\inseng.dll
+ 2004-09-02 21:26 . 2009-06-26 16:18 55808 c:\windows\system32\extmgr.dll
- 2004-09-02 21:26 . 2009-04-29 04:52 55808 c:\windows\system32\extmgr.dll
+ 2006-05-10 05:23 . 2009-06-26 16:18 39424 c:\windows\system32\dllcache\pngfilt.dll
- 2006-05-10 05:23 . 2009-04-29 04:52 39424 c:\windows\system32\dllcache\pngfilt.dll
- 2006-05-10 05:22 . 2009-04-29 04:52 16384 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 16384 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 96256 c:\windows\system32\dllcache\inseng.dll
- 2006-05-10 05:22 . 2009-04-29 04:52 96256 c:\windows\system32\dllcache\inseng.dll
- 2009-02-20 08:30 . 2009-04-29 04:52 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2009-02-20 08:30 . 2009-06-26 16:18 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2006-05-09 11:00 . 2009-06-22 11:38 18432 c:\windows\system32\dllcache\iedw.exe
- 2006-05-09 11:00 . 2009-04-27 09:17 18432 c:\windows\system32\dllcache\iedw.exe
+ 2002-09-10 13:45 . 2009-06-16 14:55 82432 c:\windows\system32\dllcache\fontsub.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 55808 c:\windows\system32\dllcache\extmgr.dll
- 2006-05-10 05:22 . 2009-04-29 04:52 55808 c:\windows\system32\dllcache\extmgr.dll
+ 2009-05-30 02:39 . 2009-08-07 16:05 32768 c:\windows\system32\config\systemprofile\UserData\index.dat
- 2009-05-30 02:39 . 2009-06-03 14:04 32768 c:\windows\system32\config\systemprofile\UserData\index.dat
+ 2009-08-24 09:44 . 2009-08-24 11:28 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009082420090825\index.dat
+ 2009-08-24 09:43 . 2009-08-24 09:43 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009081720090824\index.dat
+ 2009-08-24 03:38 . 2009-08-24 03:38 98304 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009080320090810\index.dat
+ 2003-08-23 06:56 . 2009-08-28 07:51 49152 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2005-10-02 23:05 . 2005-10-02 23:05 20480 c:\windows\Installer\35252e0.msi
+ 2008-11-13 13:06 . 2008-11-13 13:06 20992 c:\windows\Installer\1e9d4967.msi
+ 2008-11-13 13:05 . 2008-11-13 13:05 24576 c:\windows\Installer\1e9d4962.msi
+ 2009-07-27 14:18 . 2005-10-17 21:14 80896 c:\windows\$NtUninstallKB961371$\fontsub.dll
+ 2009-07-27 14:21 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB973346\update\spcustom.dll
+ 2009-07-27 14:21 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB973346\spmsg.dll
+ 2009-07-27 14:21 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB971633\update\spcustom.dll
+ 2009-07-27 14:21 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB971633\spmsg.dll
+ 2009-07-27 14:18 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB961371\update\spcustom.dll
+ 2009-07-27 14:18 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB961371\spmsg.dll
+ 2009-06-16 14:43 . 2009-06-16 14:43 81920 c:\windows\$hf_mig$\KB961371\SP3QFE\fontsub.dll
+ 2009-06-16 14:36 . 2009-06-16 14:36 81920 c:\windows\$hf_mig$\KB961371\SP3GDR\fontsub.dll
+ 2009-06-16 14:45 . 2009-06-16 14:45 81920 c:\windows\$hf_mig$\KB961371\SP2QFE\fontsub.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 10:54 . 2008-07-29 10:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2005-05-17 00:25 . 2009-06-22 11:26 352768 c:\windows\system32\xpsp3res.dll
+ 2004-09-24 00:08 . 2009-06-26 16:18 616448 c:\windows\system32\urlmon.dll
- 2004-09-24 00:08 . 2009-04-29 04:52 616448 c:\windows\system32\urlmon.dll
+ 2004-08-20 22:01 . 2009-06-26 16:18 474112 c:\windows\system32\shlwapi.dll
- 2004-08-20 22:01 . 2009-04-29 04:52 474112 c:\windows\system32\shlwapi.dll
- 2002-08-29 03:41 . 2009-04-29 04:52 532480 c:\windows\system32\mstime.dll
+ 2002-08-29 03:41 . 2009-06-26 16:18 532480 c:\windows\system32\mstime.dll
- 2002-08-29 03:41 . 2009-04-29 04:52 449024 c:\windows\system32\mshtmled.dll
+ 2002-08-29 03:41 . 2009-06-26 16:18 449024 c:\windows\system32\mshtmled.dll
+ 2009-08-25 02:56 . 2009-07-25 12:23 149280 c:\windows\system32\javaws.exe
+ 2009-08-25 02:56 . 2009-07-25 12:23 145184 c:\windows\system32\javaw.exe
+ 2009-08-25 02:56 . 2009-07-25 12:23 145184 c:\windows\system32\java.exe
+ 2002-08-29 03:40 . 2009-06-26 16:18 251392 c:\windows\system32\iepeers.dll
- 2002-08-29 03:40 . 2009-04-29 04:52 251392 c:\windows\system32\iepeers.dll
+ 2002-08-29 03:40 . 2009-06-26 16:18 205312 c:\windows\system32\dxtrans.dll
- 2002-08-29 03:40 . 2009-04-29 04:52 205312 c:\windows\system32\dxtrans.dll
- 2002-08-29 03:40 . 2009-04-29 04:52 357888 c:\windows\system32\dxtmsft.dll
+ 2002-08-29 03:40 . 2009-06-26 16:18 357888 c:\windows\system32\dxtmsft.dll
+ 2006-05-10 05:23 . 2009-06-26 16:18 659456 c:\windows\system32\dllcache\wininet.dll
- 2006-05-10 05:23 . 2009-04-29 04:52 659456 c:\windows\system32\dllcache\wininet.dll
+ 2006-05-10 05:23 . 2009-06-26 16:18 616448 c:\windows\system32\dllcache\urlmon.dll
- 2006-05-10 05:23 . 2009-04-29 04:52 616448 c:\windows\system32\dllcache\urlmon.dll
+ 2009-06-16 14:55 . 2009-06-16 14:55 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2006-05-10 05:23 . 2009-06-26 16:18 474112 c:\windows\system32\dllcache\shlwapi.dll
- 2006-05-10 05:23 . 2009-04-29 04:52 474112 c:\windows\system32\dllcache\shlwapi.dll
+ 2009-05-30 01:04 . 2009-08-28 08:21 182912 c:\windows\system32\dllcache\ndis.sys
- 2006-05-10 05:23 . 2009-04-29 04:52 532480 c:\windows\system32\dllcache\mstime.dll
+ 2006-05-10 05:23 . 2009-06-26 16:18 532480 c:\windows\system32\dllcache\mstime.dll
+ 2006-05-10 05:23 . 2009-06-26 16:18 146432 c:\windows\system32\dllcache\msrating.dll
- 2006-05-10 05:23 . 2009-04-29 04:52 146432 c:\windows\system32\dllcache\msrating.dll
+ 2006-05-10 05:23 . 2009-06-26 16:18 449024 c:\windows\system32\dllcache\mshtmled.dll
- 2006-05-10 05:23 . 2009-04-29 04:52 449024 c:\windows\system32\dllcache\mshtmled.dll
- 2006-05-10 05:22 . 2009-04-29 04:52 251392 c:\windows\system32\dllcache\iepeers.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 251392 c:\windows\system32\dllcache\iepeers.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 205312 c:\windows\system32\dllcache\dxtrans.dll
- 2006-05-10 05:22 . 2009-04-29 04:52 205312 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 357888 c:\windows\system32\dllcache\dxtmsft.dll
- 2006-05-10 05:22 . 2009-04-29 04:52 357888 c:\windows\system32\dllcache\dxtmsft.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 151040 c:\windows\system32\dllcache\cdfview.dll
- 2006-05-10 05:22 . 2009-04-29 04:52 151040 c:\windows\system32\dllcache\cdfview.dll
- 2002-09-10 13:44 . 2009-04-29 04:52 151040 c:\windows\system32\cdfview.dll
+ 2002-09-10 13:44 . 2009-06-26 16:18 151040 c:\windows\system32\cdfview.dll
+ 2003-08-23 06:59 . 2003-08-23 06:59 264704 c:\windows\Installer\1dcc1.msi
+ 2004-03-27 04:45 . 2004-03-27 04:45 954368 c:\windows\Installer\1c01ea9f.msi
+ 2009-06-17 13:42 . 2009-06-17 13:42 228352 c:\windows\Installer\184352.msi
+ 2004-08-25 16:47 . 2004-08-25 16:47 134656 c:\windows\Installer\11081a.msp
+ 2004-03-10 17:01 . 2004-03-10 17:01 812544 c:\windows\Installer\1107b2.msp
+ 2009-07-27 14:21 . 2008-07-08 13:02 382840 c:\windows\$NtUninstallKB973346$\spuninst\updspapi.dll
+ 2009-07-27 14:21 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB973346$\spuninst\spuninst.exe
+ 2009-07-27 14:21 . 2008-07-09 07:38 382840 c:\windows\$NtUninstallKB971633$\spuninst\updspapi.dll
+ 2009-07-27 14:21 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB971633$\spuninst\spuninst.exe
+ 2009-07-27 14:18 . 2005-10-17 21:14 118272 c:\windows\$NtUninstallKB961371$\t2embed.dll
+ 2009-07-27 14:18 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB961371$\spuninst\updspapi.dll
+ 2009-07-27 14:18 . 2008-07-08 13:02 231288 c:\windows\$NtUninstallKB961371$\spuninst\spuninst.exe
+ 2009-07-27 14:21 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB973346\update\updspapi.dll
+ 2009-07-27 14:21 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB973346\update\update.exe
+ 2009-07-27 14:21 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB973346\spuninst.exe
+ 2009-07-27 14:21 . 2008-07-09 07:38 382840 c:\windows\$hf_mig$\KB971633\update\updspapi.dll
+ 2009-07-27 14:21 . 2008-07-09 07:38 755576 c:\windows\$hf_mig$\KB971633\update\update.exe
+ 2009-07-27 14:21 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB971633\spuninst.exe
+ 2009-07-27 14:18 . 2009-05-26 11:40 382840 c:\windows\$hf_mig$\KB961371\update\updspapi.dll
+ 2009-07-27 14:18 . 2009-05-26 11:40 755576 c:\windows\$hf_mig$\KB961371\update\update.exe
+ 2009-07-27 14:18 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB961371\spuninst.exe
+ 2009-06-16 14:43 . 2009-06-16 14:43 119808 c:\windows\$hf_mig$\KB961371\SP3QFE\t2embed.dll
+ 2009-06-16 14:36 . 2009-06-16 14:36 119808 c:\windows\$hf_mig$\KB961371\SP3GDR\t2embed.dll
+ 2009-06-16 14:45 . 2009-06-16 14:45 119808 c:\windows\$hf_mig$\KB961371\SP2QFE\t2embed.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2002-07-01 21:38 . 2004-07-17 18:35 1326080 c:\windows\system32\webfldrs.msi
+ 2004-08-27 20:58 . 2009-07-18 16:20 1506304 c:\windows\system32\shdocvw.dll
+ 2004-09-29 07:57 . 2009-07-18 16:20 3062272 c:\windows\system32\mshtml.dll
+ 2006-05-29 15:30 . 2009-07-18 16:20 1506304 c:\windows\system32\dllcache\shdocvw.dll
+ 2007-10-29 22:43 . 2009-06-03 19:27 1290752 c:\windows\system32\dllcache\quartz.dll
+ 2006-05-19 15:08 . 2009-07-18 16:20 3062272 c:\windows\system32\dllcache\mshtml.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 1054208 c:\windows\system32\dllcache\danim.dll
- 2006-05-10 05:22 . 2009-04-29 04:52 1054208 c:\windows\system32\dllcache\danim.dll
+ 2006-05-10 05:22 . 2009-06-26 16:18 1023488 c:\windows\system32\dllcache\browseui.dll
- 2006-05-10 05:22 . 2009-04-29 04:52 1023488 c:\windows\system32\dllcache\browseui.dll
- 2002-08-29 03:40 . 2009-04-29 04:52 1054208 c:\windows\system32\danim.dll
+ 2002-08-29 03:40 . 2009-06-26 16:18 1054208 c:\windows\system32\danim.dll
+ 2003-08-23 06:56 . 2009-08-28 07:51 7192576 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-08-23 02:34 . 2009-06-26 16:18 1023488 c:\windows\system32\browseui.dll
- 2004-08-23 02:34 . 2009-04-29 04:52 1023488 c:\windows\system32\browseui.dll
+ 2004-07-17 18:35 . 2004-07-17 18:35 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi
+ 2007-05-25 19:08 . 2007-05-25 19:08 9609728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp
+ 2005-01-07 07:04 . 2005-01-07 07:04 3485184 c:\windows\Installer\a6018.msi
+ 2009-01-05 01:20 . 2009-01-05 01:20 1805824 c:\windows\Installer\7a4eab.msi
+ 2005-10-02 23:31 . 2005-10-02 23:31 5864960 c:\windows\Installer\5e126.msp
+ 2008-04-15 05:05 . 2008-04-15 05:05 9633792 c:\windows\Installer\4d9cdde1.msp
+ 2008-04-15 05:00 . 2008-04-15 05:00 3856384 c:\windows\Installer\4d9cd7e6.msi
+ 2009-04-12 17:44 . 2009-04-12 17:44 3851776 c:\windows\Installer\4b80bf.msi
+ 2005-10-02 23:12 . 2005-10-02 23:12 3443712 c:\windows\Installer\357af40.msi
+ 2008-11-13 13:04 . 2008-11-13 13:04 1780736 c:\windows\Installer\1e9d495d.msi
+ 2009-05-07 23:18 . 2009-05-07 23:18 3966976 c:\windows\Installer\1b884c81.msi
+ 2009-05-07 22:56 . 2009-05-07 22:56 1659392 c:\windows\Installer\1b884c4f.msi
+ 2009-05-07 22:52 . 2009-05-07 22:53 8992256 c:\windows\Installer\1b884c49.msi
+ 2009-06-17 13:17 . 2009-06-17 13:17 1563648 c:\windows\Installer\148a0.msi
+ 2005-03-26 21:36 . 2005-03-26 21:36 7846912 c:\windows\Installer\12676ff9.msi
+ 2004-09-22 03:46 . 2004-09-22 03:46 3865088 c:\windows\Installer\11082f.msp
+ 2004-09-13 08:35 . 2004-09-13 08:35 1452544 c:\windows\Installer\110805.msp
+ 2004-11-18 00:29 . 2004-11-18 00:29 6017024 c:\windows\Installer\105ab093.msi
+ 2004-11-18 00:29 . 2004-11-18 00:29 5892096 c:\windows\Installer\105ab089.msi
+ 2009-07-27 14:21 . 2008-12-20 22:43 1287680 c:\windows\$NtUninstallKB971633$\quartz.dll
+ 2004-10-29 13:20 . 2002-07-01 21:38 1325568 c:\windows\$NtServicePackUninstall$\webfldrs.msi
+ 2009-06-03 19:12 . 2009-06-03 19:12 1291264 c:\windows\$hf_mig$\KB971633\SP3QFE\quartz.dll
+ 2009-06-03 19:09 . 2009-06-03 19:09 1291264 c:\windows\$hf_mig$\KB971633\SP3GDR\quartz.dll
+ 2009-06-03 19:24 . 2009-06-03 19:24 1291264 c:\windows\$hf_mig$\KB971633\SP2QFE\quartz.dll
+ 2005-05-11 02:38 . 2009-07-07 15:10 24539592 c:\windows\system32\MRT.exe
+ 2009-04-12 17:47 . 2009-04-12 17:47 29457920 c:\windows\Installer\4b86e1.msp
+ 2005-10-02 23:17 . 2005-10-02 23:17 19210240 c:\windows\Installer\323de.msp
+ 2007-08-15 23:55 . 2007-08-15 23:55 15256576 c:\windows\Installer\1e0d9e3f.msp
+ 2004-01-30 11:19 . 2004-01-30 11:19 56269996 c:\windows\Installer\11079f.msp
+ 2005-03-26 21:34 . 2005-03-26 21:34 27464704 c:\windows\Downloaded Installations\{F021361C-F1A6-4269-AF68-361A943D7D13}\iPod for Windows 2005-01-11.msi
+ 2004-11-18 00:29 . 2004-11-18 00:29 19069440 c:\windows\Downloaded Installations\{92C299DB-F4E8-46B3-BEC6-27D1117B177C}\iTunes.msi
+ 2004-11-18 00:37 . 2004-11-18 00:37 20807680 c:\windows\Downloaded Installations\{8A232810-B5F1-48DD-A63D-B439D7680D94}\iTunes.msi
+ 2005-03-26 21:37 . 2005-03-26 21:37 20877312 c:\windows\Downloaded Installations\{628E8630-7947-49EA-BE90-7F8BFF77A79C}\iTunes.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Samsung Common SM"="c:\windows\Samsung\ComSMMgr\ssmmgr.exe" [2005-07-03 372736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2005-4-23 156784]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2003-10-12 118784]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^abc^Start Menu^Programs^Startup^BHODemon 2.0.lnk]
path=c:\documents and settings\abc\Start Menu\Programs\Startup\BHODemon 2.0.lnk
backup=c:\windows\pss\BHODemon 2.0.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinScheduler.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinScheduler.lnk
backup=c:\windows\pss\InterVideo WinScheduler.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:blizzard downloader
"6112:TCP"= 6112:TCP:blizzard downloader
"8449:TCP"= 8449:TCP:BitComet 8449 TCP
"8449:UDP"= 8449:UDP:BitComet 8449 UDP
R0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [3/26/2004 9:45 PM 140800]
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [3/26/2004 9:45 PM 5248]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;"c:\program files\Avira\AntiVir Desktop\sched.exe" --> c:\program files\Avira\AntiVir Desktop\sched.exe [?]
S2 evdoserver;evdoserver;c:\windows\system32\svchost.exe -k netsvcs [9/10/2002 6:46 AM 14336]
S3 arvroyzi;arvroyzi;c:\windows\system32\drivers\arvroyzi.sys --> c:\windows\system32\drivers\arvroyzi.sys [?]
S3 batqmrjv;batqmrjv;c:\windows\system32\drivers\batqmrjv.sys --> c:\windows\system32\drivers\batqmrjv.sys [?]
S3 bbwlexjz;bbwlexjz;c:\windows\system32\drivers\bbwlexjz.sys --> c:\windows\system32\drivers\bbwlexjz.sys [?]
S3 blcgdvbn;blcgdvbn;c:\windows\system32\drivers\blcgdvbn.sys --> c:\windows\system32\drivers\blcgdvbn.sys [?]
S3 eusnlqko;eusnlqko;c:\windows\system32\drivers\eusnlqko.sys --> c:\windows\system32\drivers\eusnlqko.sys [?]
S3 fqnotkid;fqnotkid;c:\windows\system32\drivers\fqnotkid.sys --> c:\windows\system32\drivers\fqnotkid.sys [?]
S3 grlqcycu;grlqcycu;c:\windows\system32\drivers\grlqcycu.sys --> c:\windows\system32\drivers\grlqcycu.sys [?]
S3 hjiddecu;hjiddecu;c:\windows\system32\drivers\hjiddecu.sys --> c:\windows\system32\drivers\hjiddecu.sys [?]
S3 ieerghnd;ieerghnd;c:\windows\system32\drivers\ieerghnd.sys --> c:\windows\system32\drivers\ieerghnd.sys [?]
S3 iieluola;iieluola;c:\windows\system32\drivers\iieluola.sys --> c:\windows\system32\drivers\iieluola.sys [?]
S3 jyutevoa;jyutevoa;c:\windows\system32\drivers\jyutevoa.sys --> c:\windows\system32\drivers\jyutevoa.sys [?]
S3 kacuhjos;kacuhjos;c:\windows\system32\drivers\kacuhjos.sys --> c:\windows\system32\drivers\kacuhjos.sys [?]
S3 kghxelzl;kghxelzl;c:\windows\system32\drivers\kghxelzl.sys --> c:\windows\system32\drivers\kghxelzl.sys [?]
S3 kunpwdwl;kunpwdwl;c:\windows\system32\drivers\kunpwdwl.sys --> c:\windows\system32\drivers\kunpwdwl.sys [?]
S3 kwapbfwr;kwapbfwr;c:\windows\system32\drivers\kwapbfwr.sys --> c:\windows\system32\drivers\kwapbfwr.sys [?]
S3 mhvmdtna;mhvmdtna;c:\windows\system32\drivers\mhvmdtna.sys --> c:\windows\system32\drivers\mhvmdtna.sys [?]
S3 ndwuwbec;ndwuwbec;c:\windows\system32\drivers\ndwuwbec.sys --> c:\windows\system32\drivers\ndwuwbec.sys [?]
S3 nynqpcse;nynqpcse;c:\windows\system32\drivers\nynqpcse.sys --> c:\windows\system32\drivers\nynqpcse.sys [?]
S3 pflvkpon;pflvkpon;c:\windows\system32\drivers\pflvkpon.sys --> c:\windows\system32\drivers\pflvkpon.sys [?]
S3 rkrgrfid;rkrgrfid;c:\windows\system32\drivers\rkrgrfid.sys --> c:\windows\system32\drivers\rkrgrfid.sys [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
S3 suojpnzx;suojpnzx;c:\windows\system32\drivers\suojpnzx.sys --> c:\windows\system32\drivers\suojpnzx.sys [?]
S3 vjloqktt;vjloqktt;c:\windows\system32\drivers\vjloqktt.sys --> c:\windows\system32\drivers\vjloqktt.sys [?]
S3 vszzejmm;vszzejmm;c:\windows\system32\drivers\vszzejmm.sys --> c:\windows\system32\drivers\vszzejmm.sys [?]
S3 xknjzivx;xknjzivx;c:\windows\system32\drivers\xknjzivx.sys --> c:\windows\system32\drivers\xknjzivx.sys [?]
S3 zlbplwky;zlbplwky;c:\windows\system32\drivers\zlbplwky.sys --> c:\windows\system32\drivers\zlbplwky.sys [?]
S3 zmzsijnt;zmzsijnt;c:\windows\system32\drivers\zmzsijnt.sys --> c:\windows\system32\drivers\zmzsijnt.sys [?]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
Trusted Zone: aol.com\free
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-28 01:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(560)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-08-28 1:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-28 08:37
ComboFix2.txt 2009-06-15 04:01
ComboFix3.txt 2009-06-15 03:38
ComboFix4.txt 2009-05-30 15:24
ComboFix5.txt 2009-08-28 07:58
Pre-Run: 3,620,794,368 bytes free
Post-Run: 3,651,952,640 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
372 --- E O F --- 2009-07-31 07:27