EDIT: after running combofix and letting it fix the infections and reboot, my internet is back to normal. thanks so much...now i just need to get my auto updates turned on....
vundufix didnt find any infections and thats all the log says..as for the other 2:
combofix:
ComboFix 08-05-21.3 - Troncoso 2008-05-23 9:13:31.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.326 [GMT -4:00]
Running from: C:\Documents and Settings\Troncoso\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMb3ebe41f.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\AaJmnnpo.ini
C:\WINDOWS\system32\AaJmnnpo.ini2
C:\WINDOWS\system32\aewwtfih.dll
C:\WINDOWS\system32\ajaadwvb.dll
C:\WINDOWS\system32\brxlpcbn.exe
C:\WINDOWS\system32\buuqrshl.dll
C:\WINDOWS\system32\ddcBTMcc.dll
C:\WINDOWS\system32\dhpyenuc.dll
C:\WINDOWS\system32\ehrduihp.dll
C:\WINDOWS\system32\ewklpbtv.dll
C:\WINDOWS\system32\gcudnsql.dll
C:\WINDOWS\system32\gxcypxsu.dll
C:\WINDOWS\system32\hgGawWQj.dll
C:\WINDOWS\system32\hqopiwat.exe
C:\WINDOWS\system32\ieegodhu.dll
C:\WINDOWS\system32\igcwjxex.dll
C:\WINDOWS\system32\irwdyypt.dll
C:\WINDOWS\system32\jkkHARkI.dll
C:\WINDOWS\system32\jmmoeojn.dll
C:\WINDOWS\system32\kkwhtouu.exe
C:\WINDOWS\system32\klStAJlm.ini
C:\WINDOWS\system32\klStAJlm.ini2
C:\WINDOWS\system32\lhsrquub.ini
C:\WINDOWS\system32\lksckixy.exe
C:\WINDOWS\system32\lltbupmn.dll
C:\WINDOWS\system32\lnyrgeaa.dll
C:\WINDOWS\system32\lpdmnjut.ini
C:\WINDOWS\system32\luqrursy.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlJAsTjj.dll
C:\WINDOWS\system32\mlJAtSlk.dll
C:\WINDOWS\system32\mlJBSkLe.dll
C:\WINDOWS\system32\mslqidlt.dll
C:\WINDOWS\system32\nvyehvso.ini
C:\WINDOWS\system32\odydjqia.dll
C:\WINDOWS\system32\oebmmyai.ini
C:\WINDOWS\system32\oitkvaao.dll
C:\WINDOWS\system32\okxuamqd.ini
C:\WINDOWS\system32\opnmkkig.dll
C:\WINDOWS\system32\opnnmJaA.dll
C:\WINDOWS\system32\oupqjkpm.dll
C:\WINDOWS\system32\qbfxykes.dll
C:\WINDOWS\system32\roppntfg.exe
C:\WINDOWS\system32\rrbiaqgj.dll
C:\WINDOWS\system32\svvvfnxa.dll
C:\WINDOWS\system32\tsoxjtas.dll
C:\WINDOWS\system32\tyfxeirr.dll
C:\WINDOWS\system32\uhwwxpco.dll
C:\WINDOWS\system32\unqgxycu.dll
C:\WINDOWS\system32\uvslacrs.dll
C:\WINDOWS\system32\vmwlhrun.dll
C:\WINDOWS\system32\wkauchcx.dll
C:\WINDOWS\system32\xdatqlud.dll
C:\WINDOWS\system32\ycvojdjq.dll
C:\WINDOWS\system32\ylohqjoy.dll
C:\WINDOWS\system32\yugsbfxd.dll
C:\WINDOWS\system32\yuhktmnk.dll
C:\WINDOWS\system32\yxijlmev.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-23 to 2008-05-23 )))))))))))))))))))))))))))))))
.
2008-05-22 22:43 . 2008-05-22 22:43 114,176 --a------ C:\WINDOWS\system32\iaymmbeo.dll
2008-05-22 17:47 . 2008-05-22 17:47 <DIR> d-------- C:\VundoFix Backups
2008-05-22 09:55 . 2008-05-22 09:55 <DIR> d-------- C:\Program Files\Viewpoint
2008-05-22 08:53 . 2008-05-22 08:53 61,440 --a------ C:\WINDOWS\system32\drivers\szlwgwe.sys
2008-05-22 08:53 . 2008-05-22 08:53 19,286 --a------ C:\cleanup.exe
2008-05-21 18:39 . 2008-05-21 18:39 61,440 --a------ C:\WINDOWS\system32\drivers\vpsl.sys
2008-05-21 17:09 . 2008-05-21 17:50 4,294 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-21 17:08 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-05-21 17:08 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-05-21 17:08 . 2008-05-15 23:22 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-05-21 17:08 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-05-21 17:08 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-05-21 17:08 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-21 17:08 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-21 17:08 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-21 11:46 . 2008-05-23 09:31 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-05-20 22:00 . 2008-05-22 09:22 4,194,371 --a------ C:\WINDOWS\pfirewall.log.old
2008-05-20 19:10 . 2008-05-01 10:30 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-05-19 21:08 . 2008-05-19 21:08 294 --ahs---- C:\WINDOWS\system32\sedjhhta.ini
2008-05-19 10:29 . 2008-05-19 10:29 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-17 23:53 . 2008-05-18 23:33 211 --a------ C:\WINDOWS\wininit.ini
2008-05-17 22:24 . 2008-05-19 17:20 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-17 22:24 . 2008-05-19 17:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-16 18:37 . 2005-01-05 23:22 39,794 --a------ C:\WINDOWS\_detmp.1
2008-05-15 02:38 . 2008-05-15 02:38 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-05-15 02:38 . 2008-05-15 02:38 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-15 02:38 . 2008-05-15 02:38 22,328 --a------ C:\Documents and Settings\Troncoso\Application Data\PnkBstrK.sys
2008-05-15 02:37 . 2008-05-15 02:37 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-05-15 02:37 . 2008-05-15 02:37 319 --a------ C:\WINDOWS\game.ini
2008-05-15 02:04 . 2008-05-15 02:04 <DIR> d-------- C:\Program Files\Activision
2008-05-15 00:02 . 2008-05-16 13:57 <DIR> d-------- C:\Program Files\CA Yahoo! Anti-Spy
2008-05-14 00:23 . 2008-05-14 00:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-14 00:22 . 2008-05-14 00:22 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-13 23:49 . 2008-05-16 01:43 0 --a------ C:\WINDOWS\system32\pelhljaq.exe
2008-05-13 00:04 . 2008-05-13 00:04 <DIR> d-------- C:\Documents and Settings\Troncoso\Application Data\Lavasoft
2008-05-12 23:38 . 2008-05-16 01:43 0 --a------ C:\WINDOWS\system32\ssobyovw.dll
2008-05-11 19:59 . 2008-05-16 01:44 0 --a------ C:\WINDOWS\system32\unrxxueh.exe
2008-05-11 11:47 . 2008-05-11 11:47 <DIR> d-------- C:\Documents and Settings\Dude\Application Data\Lavasoft
2008-05-11 11:25 . 2008-05-16 01:43 0 --a------ C:\WINDOWS\system32\sdfujewh.exe
2008-04-30 00:22 . 2008-04-30 00:22 <DIR> d-------- C:\Documents and Settings\Troncoso\Application Data\dBpoweramp
2008-04-24 00:07 . 2008-04-28 06:03 <DIR> d-------- C:\Program Files\Warcraft III
2008-04-23 12:35 . 2008-05-04 12:40 23,542 --a------ C:\VETlog.dmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-23 13:31 --------- d-----w C:\Documents and Settings\Troncoso\Application Data\DNA
2008-05-21 20:47 --------- d-----w C:\Program Files\NewTech Infosystems
2008-05-21 20:47 --------- d-----w C:\Documents and Settings\Troncoso\Application Data\Yahoo!
2008-05-21 20:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-05-21 20:42 --------- d-----w C:\Program Files\Google
2008-05-21 20:38 --------- d-----w C:\Program Files\Common Files\InterVideo
2008-05-21 20:37 --------- d-----w C:\Program Files\InterVideo
2008-05-21 02:15 --------- d-----w C:\Documents and Settings\Dude\Application Data\Yahoo!
2008-05-20 00:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-18 00:25 --------- d-----w C:\Program Files\World of Warcraft
2008-05-16 02:17 --------- d-----w C:\Program Files\Common Files\Scanner
2008-05-15 06:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-14 04:24 --------- d-----w C:\Program Files\Lavasoft
2008-05-14 04:24 --------- d-----w C:\Documents and Settings\1\Application Data\Lavasoft
2008-05-13 03:41 --------- d-----w C:\Documents and Settings\Troncoso\Application Data\BitTorrent
2008-05-11 05:05 --------- d-----w C:\Documents and Settings\Troncoso\Application Data\dvdcss
2008-05-11 02:14 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-10 05:28 --------- d-----w C:\Program Files\BitTorrent
2008-04-21 02:32 4,230,520 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe
2008-04-21 02:32 --------- d-----w C:\Documents and Settings\Troncoso\Application Data\AccurateRip
2008-04-20 05:44 --------- d-----w C:\Documents and Settings\Troncoso\Application Data\Skype
2008-04-20 05:39 --------- d-----w C:\Documents and Settings\Troncoso\Application Data\skypePM
2008-04-17 02:06 --------- d-----w C:\Documents and Settings\Troncoso\Application Data\Any Video Converter
2008-04-07 14:20 --------- d-----w C:\Documents and Settings\Giggles\Application Data\Skype
2008-04-02 01:26 --------- d-----w C:\Program Files\Any Video Converter
2008-04-02 01:16 --------- d-----w C:\Program Files\AviSynth 2.5
2008-03-31 01:28 --------- d-----w C:\Program Files\Audio Converter
2008-03-30 02:19 --------- d-----w C:\Program Files\Common Files\Ahead
2008-03-30 01:38 --------- d-----w C:\Documents and Settings\Troncoso\Application Data\Apple Computer
2008-03-30 01:27 --------- d-----w C:\Program Files\DNA
2008-03-29 01:07 --------- d-----w C:\Program Files\Shockwave.com
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-25 02:22 --------- d-----w C:\Documents and Settings\Troncoso\Application Data\Ahead
2008-03-25 01:06 --------- d-----w C:\Documents and Settings\Troncoso\Application Data\MSN6
2008-03-25 01:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\MSN6
2008-03-25 00:46 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-03-23 15:25 --------- d-----w C:\Program Files\Common Files\xing shared
2008-03-23 15:25 --------- d-----w C:\Program Files\Common Files\Real
2008-03-23 15:24 --------- d-----w C:\Program Files\Real
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2005-04-01 06:17 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-19_21.07.24.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-03-06 01:22:36 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\spmsg.dll
+ 2007-03-06 01:22:33 14,048 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\spmsg.dll
- 2007-03-06 01:22:41 213,216 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\spuninst.exe
+ 2007-03-06 01:22:39 213,216 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\spuninst.exe
- 2007-03-06 01:22:34 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\update\spcustom.dll
+ 2007-03-06 01:22:31 22,752 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\update\spcustom.dll
- 2007-03-06 01:22:59 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\update\update.exe
+ 2007-03-06 01:22:56 716,000 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\update\update.exe
- 2007-03-06 01:23:51 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\update\updspapi.dll
+ 2007-03-06 01:23:47 371,424 -c--a-w C:\WINDOWS\$hf_mig$\KB941644\update\updspapi.dll
- 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe
- 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB941644$\spuninst\updspapi.dll
- 2006-04-20 11:51:50 359,808 -c----w C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\$NtUninstallKB941644_0$\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\$NtUninstallKB941644_0$\spuninst\updspapi.dll
+ 2006-04-20 11:51:50 359,808 -c----w C:\WINDOWS\$NtUninstallKB941644_0$\tcpip.sys
- 2008-05-20 00:57:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-23 13:34:30 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2007-10-30 17:20:55 360,064 -c----w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2007-10-30 16:53:32 360,832 -c----w C:\WINDOWS\system32\dllcache\tcpip.sys
- 2007-10-30 17:20:55 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2007-10-30 16:53:32 360,832 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
- 2008-05-09 21:35:04 16,863,864 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-05-09 18:35:06 16,863,864 ----a-w C:\WINDOWS\system32\MRT.exe
- 2008-04-27 22:43:14 64,372 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-05-21 02:07:13 64,372 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-04-27 22:43:14 409,232 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-05-21 02:07:13 409,232 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2006-09-26 01:58:48 14,640 ----a-w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ----a-w C:\WINDOWS\system32\spmsg.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7872A60F-9E46-454F-93DF-80DCE341A045}]
C:\WINDOWS\system32\urqrpoLb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E4C6FEFD-DA3D-421B-9087-17DB2A3CA2D4}]
C:\WINDOWS\system32\ddcbAtQi.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-12-17 21:13 3810544]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]
"LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 18:36 455968]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-07 18:53 289088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 20:28 790528]
"IMONTRAY"="C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe" [2003-11-03 20:44 32768]
"SonicFocus"="C:\Program Files\Sonic Focus\SFIGUI\SFIGUI.exe" [2003-04-17 01:16 1220608]
"HostManager"="C:\Program Files\Common Files\AOL\1104650641\ee\AOLSoftware.exe" [2006-09-25 20:52 50736]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 08:50 71216]
"vptray"="C:\Program Files\NavNT\vptray.exe" [2001-09-24 10:59 73728]
"Pure Networks Port Magic"="C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" [2004-04-05 17:33 99480]
"MaxBlastMonitor.exe"="C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe" [2007-04-20 11:59 1169720]
"AcronisTimounterMonitor"="C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe" [2007-04-20 12:09 1945712]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe" [2007-04-20 12:03 149024]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.3\apdproxy.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-23 11:24 185896]
"b0d8d783"="C:\WINDOWS\system32\iaymmbeo.dll" [2008-05-22 22:43 114176]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 23:29 39264]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\KEM.exe [2005-11-03 01:35:18 573440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\Program Files\AlienGUIse\fastload.dll 2001-12-21 03:34 24576 C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap C:\WINDOWS\system32\opnnmJaA
Notification Packages REG_MULTI_SZ scecli scecli scecli
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1104650641\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.3.0-enUS-downloader.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Common Files\\AOL\\1104650641\\EE\\aolsoftware.exe"=
"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\Win32\\RpcDataSrv.exe"=
"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\RpcSandraSrv.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 VVBackd5;VVBackd5;C:\WINDOWS\system32\drivers\VVBackd5.sys [2003-01-20 06:21]
S3 ATICXCAP;ATI TV Wonder Pro A/V Capture;C:\WINDOWS\system32\drivers\aticxcap.sys [2005-03-30 15:22]
S3 ATICXTUN;ATI TV Wonder Pro Tuner (Philips 1236 MK3);C:\WINDOWS\system32\drivers\aticxtun.sys [2005-03-30 15:22]
S3 ATICXXBR;ATI TV Wonder Pro A/V Crossbar;C:\WINDOWS\system32\drivers\aticxxbr.sys [2005-03-30 15:22]
S4 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{269dedf4-cf74-11dc-b6ea-00038a000015}]
\Shell\AutoRun\command - K:\Autorun.exe /run
\Shell\Shell00\Command - K:\Autorun.exe /run
\Shell\Shell01\Command - K:\Autorun.exe /action
\Shell\Shell02\Command - K:\Autorun.exe /uninstall
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-05-12 01:00:22 C:\WINDOWS\Tasks\DeFrag.job"
- C:\Documents and Settings\All Users\Start Menu\Programs\Diskeeper Lite.lnk
"2008-05-23 13:38:09 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-05-21 13:00:00 C:\WINDOWS\Tasks\rpc.job"
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-23 09:36:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\iaymmbeo.dll
-> C:\Program Files\Logitech\SetPoint\lgscroll.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imonNT.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\system32\MSGSYS.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.exe
C:\Program Files\Common Files\AOL\1104650641\EE\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-05-23 9:43:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-23 13:42:52
ComboFix2.txt 2008-05-20 01:08:40
Pre-Run: 40,044,204,032 bytes free
Post-Run: 40,009,109,504 bytes free
344 --- E O F --- 2008-05-16 08:26:16