Heres a Combofix log.
Thank you again.
ComboFix 09-10-16.09 - Owner 10/18/2009 0:21.5.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.603 [GMT -5:00]
Running from: N:\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Xilisoft\Audio Converter\lang\_desktop.ini
c:\program files\Xilisoft\Audio Converter\Plugins\_desktop.ini
c:\program files\Xilisoft\Audio Converter\skin\Default\_desktop.ini
c:\windows\Install.txt
c:\windows\system32\bakefuni.dll
c:\windows\system32\Drivers\yezzejmo.sys
c:\windows\system32\Install.txt
c:\windows\system32\kilatape.dll
c:\windows\system32\mejiyolo.exe
c:\windows\system32\schtml
c:\windows\system32\schtml\images\i1.gif
c:\windows\system32\schtml\images\i2.gif
c:\windows\system32\schtml\images\i3.gif
c:\windows\system32\schtml\images\j1.gif
c:\windows\system32\schtml\images\j2.gif
c:\windows\system32\schtml\images\j3.gif
c:\windows\system32\schtml\images\jj1.gif
c:\windows\system32\schtml\images\jj2.gif
c:\windows\system32\schtml\images\jj3.gif
c:\windows\system32\schtml\images\l1.gif
c:\windows\system32\schtml\images\l2.gif
c:\windows\system32\schtml\images\l3.gif
c:\windows\system32\schtml\images\pix.gif
c:\windows\system32\schtml\images\t1.gif
c:\windows\system32\schtml\images\t2.gif
c:\windows\system32\schtml\images\up1.gif
c:\windows\system32\schtml\images\up2.gif
c:\windows\system32\schtml\images\w1.gif
c:\windows\system32\schtml\images\w11.gif
c:\windows\system32\schtml\images\w2.gif
c:\windows\system32\schtml\images\w3.gif
c:\windows\system32\schtml\images\w3.jpg
c:\windows\system32\schtml\images\wt1.gif
c:\windows\system32\schtml\images\wt2.gif
c:\windows\system32\schtml\images\wt3.gif
c:\windows\system32\schtml\wispex.html
c:\windows\system32\vahoremo.exe
c:\windows\system32\yasijote.exe
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\autorun.inf
c:\program files\Need2Find
c:\program files\Need2Find\bar\History\search
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\temp\vtmp2
c:\temp\vtmp2\ktnv33.log
c:\windows\ctions.dll
c:\windows\Install.txt
c:\windows\Installer\3cb8e.msi
c:\windows\Installer\57292ec.msi
c:\windows\Installer\57292ed.msp
c:\windows\Installer\57292ee.msp
c:\windows\Installer\57292ef.msp
c:\windows\Installer\57292f0.msp
c:\windows\Installer\57292f1.msp
c:\windows\Installer\57292f2.msp
c:\windows\Installer\57292f3.msp
c:\windows\Installer\57292f4.msp
c:\windows\Installer\57292f5.msp
c:\windows\Installer\57292f6.msp
c:\windows\kb913800.exe
c:\windows\strictions.dll
c:\windows\system32\ahoyuwad.ini
c:\windows\system32\dasejaru.dll
c:\windows\system32\dijuzihi.dll
c:\windows\system32\dl32.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\SKYNETwjaakoeh.sys
c:\windows\system32\drivers\UACpixrownv.sys
c:\windows\system32\FInstall.sys
c:\windows\system32\forukabe.dll
c:\windows\system32\giwawawo.dll
c:\windows\system32\gogihuho.dll
c:\windows\system32\hljwugsf.bin
c:\windows\system32\huhugafe.dll
c:\windows\system32\Install.txt
c:\windows\system32\isasdk.sys
c:\windows\system32\kedisuzo.dll
c:\windows\system32\kejepuha.dll
c:\windows\system32\konowahu.dll
c:\windows\system32\lspqxy.dll
c:\windows\system32\luyeduje.dll
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\refobaju.dll
c:\windows\system32\remebeyi.dll
c:\windows\system32\s9sfsa.exe
c:\windows\system32\SKYNETesisvtmp.dll
c:\windows\system32\SKYNETftnxvkpd.dll
c:\windows\system32\SKYNETipfwoscp.dll
c:\windows\system32\SKYNETmitgggyw.dll
c:\windows\system32\SKYNETqskltdhy.dat
c:\windows\system32\SKYNETqvdkrjlk.dat
c:\windows\system32\SKYNETrcjpibmi.dll
c:\windows\system32\UACccrdksgd.log
c:\windows\system32\UACewftiqsa.dll
c:\windows\system32\UACogxgkday.log
c:\windows\system32\UACpcwemoyf.dll
c:\windows\system32\UACswwehwee.dll
c:\windows\system32\UACtegrfuxv.dll
c:\windows\system32\UACxblxagut.dat
c:\windows\system32\UACyrvkkhbp.log
c:\windows\system32\ufujinub.ini
c:\windows\system32\uwuvajam.ini
c:\windows\system32\WanPacket.dll
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\winio.vxd
c:\windows\system32\wpcap.dll
c:\windows\system32\wujuleza.dll
c:\windows\system32\yekotosu.dll
c:\windows\system32\yozekute.dll
c:\windows\system32\zehekilo.dll
c:\windows\Tasks\jsaplbsj.job
c:\windows\TEMP\mta32910.dll
c:\windows\win32k.sys
-- Previous Run --
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
c:\windows\system32\proquota.exe . . . is missing!!
--------
c:\windows\system32\proquota.exe . . . is missing!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_ANTIPPRO2009_100
-------\Legacy_ISASDK
-------\Legacy_NPF
-------\Legacy_SKYNETppjoyxvi
-------\Legacy_UACd.sys
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Service_isasdk
-------\Service_NPF
-------\Service_SKYNETppjoyxvi
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-09-18 to 2009-10-18 )))))))))))))))))))))))))))))))
.
2009-10-12 16:18 . 2009-10-12 16:18 -------- d-----w- c:\program files\Activision
2009-10-12 16:10 . 2009-10-12 16:10 -------- d-----w- c:\program files\PowerISO
2009-10-12 15:55 . 2009-10-12 15:55 -------- d-----w- c:\program files\MagicDisc
2009-10-12 15:55 . 2009-02-24 23:42 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys
2009-10-12 06:24 . 2009-10-12 06:24 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\The Witcher
2009-10-10 08:03 . 2009-10-10 08:03 -------- d-----w- c:\windows\ServicePackFiles
2009-10-10 03:57 . 2009-10-10 03:57 -------- d-----w- c:\documents and settings\Owner\DoctorWeb
2009-10-08 22:27 . 2009-10-08 22:27 -------- d-----w- c:\program files\Sophos
2009-10-08 21:12 . 2009-10-08 21:12 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-10-08 21:12 . 2009-10-08 21:12 -------- d-----w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2009-10-06 06:24 . 2008-06-19 22:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-06 06:24 . 2009-10-06 06:24 -------- d-----w- c:\program files\Panda Security
2009-10-06 06:15 . 2009-10-06 06:15 -------- d-----w- C:\log
2009-10-06 06:15 . 2009-08-27 21:23 2457600 ----a-w- C:\RootkitBuster.exe
2009-10-06 05:45 . 2009-10-06 06:14 160272 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-10-06 05:45 . 2009-10-06 05:46 -------- d-----w- c:\documents and settings\Owner\.housecall6.6
2009-10-05 18:32 . 2009-10-05 18:32 31822 ----a-w- c:\windows\system32\stmod1.exe
2009-10-05 18:05 . 2009-10-05 22:57 102188 ----a-w- c:\windows\system32\9b2b3dbd.exe
2009-10-05 14:03 . 2009-10-05 14:03 -------- d-----w- c:\program files\Starbreeze Studios
2009-10-03 07:20 . 2009-10-03 07:20 -------- d-----w- c:\program files\Microsoft Games
2009-10-02 04:23 . 2009-10-02 04:23 -------- d-----w- c:\program files\McAfee Security Scan
2009-10-02 04:23 . 2009-10-02 04:23 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-10-02 04:23 . 2009-10-03 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-10-02 01:57 . 2009-10-02 01:57 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Ascaron Entertainment
2009-10-02 01:51 . 2009-10-02 01:51 -------- d--h--r- c:\documents and settings\Owner\Application Data\SecuROM
2009-09-28 04:27 . 2006-04-29 19:25 40960 ----a-w- c:\windows\system32\psfind.dll
2009-09-27 19:54 . 1999-12-17 15:13 86016 ----a-w- c:\windows\unvise32.exe
2009-09-25 05:47 . 2009-09-25 05:47 -------- d-----w- c:\program files\Common Files\ATI Technologies
2009-09-25 05:47 . 2009-09-27 08:22 -------- d-----w- c:\program files\DIFX
2009-09-24 23:25 . 2009-09-25 06:36 -------- d-----w- c:\program files\NCSoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
3427-09-26 03:40 . 2009-05-17 06:42 77824 ----a-w- c:\windows\system32\vorbisfile.dll
2009-10-17 23:05 . 2008-05-26 02:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-10-17 18:43 . 2007-01-13 20:20 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-12 16:37 . 2009-09-06 10:35 -------- d-----w- c:\documents and settings\Owner\Application Data\Activision
2009-10-12 16:32 . 2005-10-20 19:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-12 16:09 . 2006-06-06 08:09 -------- d-----w- c:\documents and settings\Owner\Application Data\uTorrent
2009-10-08 21:12 . 2009-06-02 00:51 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-08 07:06 . 2008-05-25 23:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-06 05:21 . 2006-10-27 22:46 -------- d-----w- c:\documents and settings\Owner\Application Data\U3
2009-10-06 05:06 . 2006-01-26 08:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-03 01:56 . 2005-12-18 03:13 42416 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-01 23:33 . 2008-10-30 07:04 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-10-01 23:33 . 2008-10-30 07:04 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-10-01 04:42 . 2005-12-23 07:19 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-09-27 22:18 . 2008-01-20 03:57 -------- d-----w- c:\program files\SystemRequirementsLab
2009-09-27 19:54 . 2009-09-13 10:18 -------- d-----w- c:\program files\Parallel Port Joystick
2009-09-25 06:34 . 2009-01-14 23:46 -------- d-----w- c:\documents and settings\Owner\Application Data\GetRightToGo
2009-09-25 05:49 . 2005-04-13 16:56 668672 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:48 . 2005-04-13 16:55 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-25 05:12 . 2009-03-09 03:07 -------- d-----w- c:\documents and settings\Owner\Application Data\SystemRequirementsLab
2009-09-18 02:23 . 2006-01-07 06:23 -------- d-----w- c:\program files\World of Warcraft
2009-09-12 20:28 . 2008-02-07 06:17 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-11 14:33 . 2005-04-13 16:55 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 19:54 . 2009-07-11 05:11 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 19:53 . 2009-07-11 05:11 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-07 16:40 . 2009-09-07 16:40 42416 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-09-07 05:51 . 2009-09-07 05:50 -------- d-----w- c:\documents and settings\All Users\Application Data\ijjigame
2009-09-07 05:48 . 2009-09-07 05:48 -------- d-----w- c:\program files\ijji
2009-09-07 05:40 . 2009-09-07 05:40 -------- d-----w- c:\documents and settings\Owner\Application Data\InstallShield
2009-09-07 03:06 . 2009-09-07 03:06 -------- d-----w- c:\program files\Common Files\Futuremark Shared
2009-09-07 00:49 . 2009-09-07 00:49 -------- d-----w- c:\documents and settings\Owner\Application Data\System Requirements Lab BETA
2009-09-06 10:35 . 2009-09-06 10:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Activision
2009-09-04 20:45 . 2005-04-13 16:55 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-30 06:52 . 2009-08-30 06:52 -------- d-----w- c:\documents and settings\Owner\Application Data\Microsoft Games
2009-08-30 02:54 . 2007-06-22 07:21 -------- d-----w- c:\program files\PeerGuardian2
2009-08-26 08:16 . 2005-04-13 16:57 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-25 22:04 . 2009-09-07 05:51 75264 ----a-w- c:\windows\system32\uc_holybeast_launching.dll
2009-08-22 21:40 . 2009-07-17 03:40 -------- d-----w- c:\program files\Free-Soft
2009-08-21 01:13 . 2009-08-21 01:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-08-05 09:11 . 2005-04-13 16:55 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 13:58 . 2005-04-13 16:55 2136064 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 13:13 . 2004-08-04 05:59 2015744 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-07-29 04:53 . 2005-04-13 16:56 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:53 . 2005-04-13 16:55 82432 ----a-w- c:\windows\system32\fontsub.dll
2008-12-17 00:57 . 2009-01-02 01:24 942205576 ----a-w- c:\program files\data3.cab
2008-12-17 00:57 . 2009-01-02 01:24 555 ----a-w- c:\program files\layout.bin
2008-12-17 00:56 . 2009-01-02 01:22 1416036352 ----a-w- c:\program files\data2.cab
2008-12-17 00:54 . 2009-01-02 01:22 9727978 ----a-w- c:\program files\data1.cab
2008-12-17 00:54 . 2009-01-02 01:22 5460557 ----a-w- c:\program files\data1.hdr
2008-12-17 00:53 . 2009-01-02 01:24 328885 ----a-w- c:\program files\setup.boot
2008-12-17 00:53 . 2009-01-02 01:24 448 ----a-w- c:\program files\setup.ini
2008-12-05 23:51 . 2009-01-02 01:24 173571 ----a-w- c:\program files\setup.inx
2008-07-09 17:41 . 2009-01-02 01:24 1287356 ----a-w- c:\program files\Setup.bmp
2007-09-20 16:58 . 2008-06-09 04:49 52156 ----a-w- c:\program files\Copyright.txt
2007-09-19 04:41 . 2008-06-09 04:49 258352 ----a-w- c:\program files\unicows.dll
2007-09-19 04:41 . 2008-06-09 04:49 4968 ----a-w- c:\program files\install.ini
2007-09-19 04:41 . 2008-06-09 04:49 1196032 ----a-w- c:\program files\install.exe
2007-09-19 04:41 . 2008-06-09 04:49 372736 ----a-w- c:\program files\ijl15.dll
2007-09-19 04:41 . 2008-06-09 04:49 4150 ----a-w- c:\program files\icon.ico
2007-09-19 04:41 . 2008-06-09 04:51 514337164 ----a-w- c:\program files\data4.pck
2007-09-19 03:55 . 2008-06-09 04:50 629164503 ----a-w- c:\program files\data3.pck
2007-09-18 22:10 . 2008-06-09 04:49 629175968 ----a-w- c:\program files\data2.pck
2007-09-18 17:03 . 2008-06-09 04:49 629147117 ----a-w- c:\program files\data1.pck
2007-09-18 14:58 . 2008-06-09 04:49 1080216 ----a-w- c:\program files\check.md
2002-12-05 20:16 . 2009-01-02 01:24 418296 ----a-w- c:\program files\engine32.cab
2002-10-17 23:05 . 2009-01-02 01:24 28131 ----a-w- c:\program files\setup.skin
2009-09-23 10:48 . 2009-10-05 18:05 1934848 ----a-w- c:\program files\mozilla firefox\components\3e6b23d6.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-03-20 00:54 . 2008-03-20 00:45 24 --sh--w- c:\windows\SF2868A9E.tmp
2009-03-27 03:16 . 1601-01-01 00:12 61440 --sha-w- c:\windows\system32\finozute.exe
2009-04-25 01:45 . 2009-01-25 01:45 47616 --sha-w- c:\windows\system32\hesanebo.exe
2009-07-06 06:05 . 2009-07-06 06:05 194134 --sha-w- c:\windows\system32\loyuwisa.exe
2009-05-01 01:29 . 2009-02-01 01:29 47104 --sha-w- c:\windows\system32\mazimiru.exe
2009-05-02 04:42 . 2009-02-02 04:42 47104 --sha-w- c:\windows\system32\monajole.exe
2009-04-27 07:32 . 2009-01-27 07:32 46592 --sha-w- c:\windows\system32\rakoyopo.exe
2009-04-26 19:32 . 2009-01-26 19:32 47104 --sha-w- c:\windows\system32\yimazitu.exe
2009-04-26 01:45 . 2009-01-26 01:45 46592 --sha-w- c:\windows\system32\yobaruzi.exe
2009-04-27 19:32 . 2009-01-27 19:32 47616 --sha-w- c:\windows\system32\zepulabe.exe
.
------- Sigcheck -------
[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
[7] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 10:23 . !HASH: COULD NOT OPEN FILE !!!!! . 1033216 . . [------] . . c:\windows\explorer.exe
[7] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\system32\dllcache\explorer.exe
[7] 2004-08-10 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-24 68856]
"scheduler_monitor"="c:\program files\ReaConverter 5.5 Pro\init_scheduler.exe" [2007-06-15 27136]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"SUPERAntiSpyware"="N:\SUPERAntiSpyware.exe" [2009-09-15 1998576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-19 148888]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-03-09 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-12-01 126976]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"PSPVideoConverter_upgrade"="c:\program files\E-Zsoft\PSPVideoConverter\PSPVideoConverter.exe" [2009-01-05 495616]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-04-11 68592]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-03-09 37888]
"QuickTime Task"="c:\program files\QuickTime Alternative\qttask.exe" [2009-01-05 413696]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2009-09-29 1241872]
"Malwarebytes Anti-Malware (reboot)"="n:\malwarebytes' anti-malware\zzasa.exe" [2009-09-10 1312080]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-10-21 77824]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" - c:\windows\system32\Hdaudpropshortcut.exe [2004-08-13 61952]
"CHotkey"="zHotkey.exe" - c:\windows\zHotkey.exe [2005-05-03 543232]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2004-10-22 2744832]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "N:\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 ----a-w- N:\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2007-07-06 15:16 176128 ----a-w- c:\progra~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Emy33.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Gnq56.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Uxi00.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"c:\\Program Files\\Sierra\\FEAR\\FEAR.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Sierra\\FEAR\\fpupdate.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.4.6314-to-2.0.5.6320-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"c:\\Program Files\\Doom 3\\Doom3.exe"=
"c:\\Documents and Settings\\Owner\\Desktop\\SypherX\\Movie Pirate Stff\\utorrent.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\Owner\\Desktop\\SypherX\\psp controller\\wificon\\WiFiController-0.4.4\\PC\\WiFiServer.exe"=
"c:\\WINDOWS\\ehome\\ehrecvr.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\PSPdisp\\bin\\app\\PSPdisp.exe"=
"c:\\Program Files\\Microsoft Games\\Dungeon Siege 2\\DungeonSiege2.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\Documents and Settings\\Owner\\Desktop\\SypherX\\Computer Info Software\\procexp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"49190:TCP"= 49190:TCP:*:Disabled:SolidNetworkManager
"49190:UDP"= 49190:UDP:*:Disabled:SolidNetworkManager
"20702:TCP"= 20702:TCP:*:Disabled:SolidNetworkManager
"20702:UDP"= 20702:UDP:*:Disabled:SolidNetworkManager
"62140:TCP"= 62140:TCP:*:Disabled:SolidNetworkManager
"62140:UDP"= 62140:UDP:*:Disabled:SolidNetworkManager
"32735:TCP"= 32735:TCP:*:Disabled:SolidNetworkManager
"32735:UDP"= 32735:UDP:*:Disabled:SolidNetworkManager
"64198:TCP"= 64198:TCP:*:Disabled:SolidNetworkManager
"64198:UDP"= 64198:UDP:*:Disabled:SolidNetworkManager
"36645:TCP"= 36645:TCP:*:Disabled:SolidNetworkManager
"36645:UDP"= 36645:UDP:*:Disabled:SolidNetworkManager
"23452:TCP"= 23452:TCP:*:Disabled:SolidNetworkManager
"23452:UDP"= 23452:UDP:*:Disabled:SolidNetworkManager
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"57035:TCP"= 57035:TCP:Pando Media Booster
"57035:UDP"= 57035:UDP:Pando Media Booster
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [10/6/2009 1:24 AM 28544]
R1 atitray;atitray;c:\program files\Ray Adams\ATI Tray Tools\atitray.sys [9/27/2006 4:47 AM 13952]
R3 PPJoyBus;Parallel Port Joystick Bus device driver;c:\windows\system32\drivers\PPJoyBus.sys [8/8/2002 6:27 PM 13952]
R3 PPortJoystick;Parallel Port Joystick device driver;c:\windows\system32\drivers\PPortJoy.sys [6/8/2003 2:00 PM 28800]
R3 pspdisp;pspdisp;c:\windows\system32\drivers\pspdisp.sys [7/8/2009 10:04 PM 3072]
S0 Emy33;Emy33;c:\windows\system32\Drivers\Emy33.sys --> c:\windows\system32\Drivers\Emy33.sys [?]
S0 Gnq56;Gnq56;c:\windows\system32\Drivers\Gnq56.sys --> c:\windows\system32\Drivers\Gnq56.sys [?]
S0 Uxi00;Uxi00;c:\windows\system32\Drivers\Uxi00.sys --> c:\windows\system32\Drivers\Uxi00.sys [?]
S1 SASDIFSV;SASDIFSV;N:\sasdifsv.sys [9/15/2009 11:42 AM 9968]
S1 SASKUTIL;SASKUTIL;N:\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
S2 HDDTempNetServer;HDD Temperature Enterprise Server;c:\program files\PalickSoft\HDD Temperature Enterprise\HDDNetTempServer.exe /startedbyscm:B15A26C5-40E2B66C-HDDNetTemp --> c:\program files\PalickSoft\HDD Temperature Enterprise\HDDNetTempServer.exe [?]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [8/3/2009 12:09 AM 309008]
S3 cpuz130;cpuz130;\??\c:\docume~1\Owner\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\Owner\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\documents and settings\Owner\Desktop\SypherX\Computer Info Software\Everest.Ultimate.Edition.2006.2.80.534\kerneld.wnt [4/9/2006 11:09 AM 11776]
S3 libusb0;LibUsb-Win32 - Kernel Driver 03/20/2007, 0.1.12.1;c:\windows\system32\drivers\libusb0.sys [3/16/2009 1:14 AM 28672]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\6.tmp --> c:\windows\system32\6.tmp [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 rcp_service;ReaConverter scheduler service;c:\program files\ReaConverter 5.5 Pro\rcp_scheduler.exe [11/30/2007 12:27 PM 558592]
S3 SASENUM;SASENUM;N:\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S3 Service_Desktop;Desktop;c:\program files\Free-Soft\Virtual Desktop\Desktop.exe --> c:\program files\Free-Soft\Virtual Desktop\Desktop.exe [?]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [10/1/2006 7:37 AM 26624]
S3 XDva164;XDva164;\??\c:\windows\system32\XDva164.sys --> c:\windows\system32\XDva164.sys [?]
S3 XDva219;XDva219;\??\c:\windows\system32\XDva219.sys --> c:\windows\system32\XDva219.sys [?]
S3 XDva220;XDva220;\??\c:\windows\system32\XDva220.sys --> c:\windows\system32\XDva220.sys [?]
S3 XDva224;XDva224;\??\c:\windows\system32\XDva224.sys --> c:\windows\system32\XDva224.sys [?]
S3 XDva225;XDva225;\??\c:\windows\system32\XDva225.sys --> c:\windows\system32\XDva225.sys [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - PROCEXP100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
BtwSrv
.
Contents of the 'Scheduled Tasks' folder
2009-04-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.gatewaybiz.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=localhost:7171
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
TCP: {4E709758-3F9A-409C-9E32-8912A721E9D2} = 208.67.220.220,208.67.222.222
DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} - hxxp://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\n6fqbcm7.default\
FF - prefs.js: browser.search.selectedEngine - GoogleCOM
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google-searchbar.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\program files\Mozilla Firefox\components\3e6b23d6.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\n6fqbcm7.default\extensions\{5601B994-0E9B-4ce2-8AB9-AD1155F2ABBD}\plugins\NPNeffyPlugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.search.selectedEngine - GoogleCOM
FF - user.js: keyword.URL - hxxp://www.google-searchbar.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
.
- - - - ORPHANS REMOVED - - - -
BHO-{ad2c2290-be52-4728-a5c3-d8b4d0851675} - wujuleza.dll
HKCU-Run-VD - (no file)
HKCU-Run-PlayNC Launcher - (no file)
SharedTaskScheduler-{7d5ee03f-06e8-4879-951c-326f42595c9a} - c:\windows\system32\refobaju.dll
SharedTaskScheduler-{a0dadd45-a590-404d-b9e6-c56fc3e09245} - c:\windows\system32\giwawawo.dll
SSODL-puferadod-{d3db0d13-be4e-428a-a5cb-12d8b00cb9a5} - (no file)
SSODL-vofaribay-{25e3e1e3-daaf-420b-8d6f-02f57ec7d0b8} - (no file)
SSODL-yuwimivuv-{48ba8d8c-2237-4324-b50e-e3ce7093a182} - (no file)
SSODL-pazesawof-{ce7e8964-ebb1-4cdc-ad03-d8392fbfbe44} - (no file)
SSODL-kutubaduv-{36f1a11d-5ade-40c4-9ae4-33143a10d182} - (no file)
SSODL-yimobunej-{10dc079c-9224-4ba1-99b8-23b2ad3a691e} - (no file)
SSODL-fimakodur-{a95a2358-feb9-4df7-9cee-6a17f3c5dc8a} - (no file)
SSODL-yuwudagat-{7ef22fb4-d8ce-4775-88cd-56b05fad62e5} - (no file)
SSODL-dokihehih-{86bcaf1f-ba04-4679-99e9-13ea47ce8d1e} - (no file)
SSODL-nuravujas-{358dfbf5-88e9-4bf6-93fb-8eddd06dc280} - (no file)
SSODL-medisobew-{bd380dff-30a7-4d0b-ada3-d31a2267928c} - (no file)
SSODL-resusijom-{7d5ee03f-06e8-4879-951c-326f42595c9a} - c:\windows\system32\refobaju.dll
SSODL-peyujosef-{a0dadd45-a590-404d-b9e6-c56fc3e09245} - c:\windows\system32\giwawawo.dll
Notify-pmnmmNhF - pmnmmNhF.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-18 00:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\HDDTempNetServer]
"ImagePath"="c:\program files\PalickSoft\HDD Temperature Enterprise\HDDNetTempServer.exe /startedbyscm:B15A26C5-40E2B66C-HDDNetTemp"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\EverestDriver]
"ImagePath"="\??\c:\documents and settings\Owner\Desktop\SypherX\Computer Info Software\Everest.Ultimate.Edition.2006.2.80.534\kerneld.wnt"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\6.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2627011371-2010092445-3762394428-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-2627011371-2010092445-3762394428-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
@SACL=
[HKEY_LOCAL_MACHINE\software\swearware\backup\winsock2]
@DACL=(02 0000)
@SACL=
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(900)
N:\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\progra~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
c:\windows\system32\igfxsrvc.dll
c:\windows\system32\hccutils.DLL
.
Completion time: 2009-10-18 0:39
ComboFix-quarantined-files.txt 2009-10-18 05:39
ComboFix2.txt 2008-06-02 07:31
ComboFix3.txt 2008-05-26 00:57
Pre-Run: 40,435,281,920 bytes free
Post-Run: 41,228,713,984 bytes free
Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
496 --- E O F --- 2009-10-15 01:38