Combofix log:
ComboFix 08-03-07.4 - Compaq_Owner 2008-03-08 0:26:55.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.117 [GMT -5:00]
Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\int_rem.bat
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\License_Manager
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\WINDOWS\baaadd.ini
C:\WINDOWS\BM7b351950.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\crosof~1.net
C:\WINDOWS\crosof~1.net\j?vaw.exe
C:\WINDOWS\ddaaab.dll
C:\WINDOWS\pskt.ini
C:\WINDOWS\ssembl~1
C:\WINDOWS\stem~1
C:\WINDOWS\stem~1\??stem\
C:\WINDOWS\stem~1\rundll32.exe
C:\WINDOWS\system32\alqywqkh.dll
C:\WINDOWS\system32\amddqsom.dll
C:\WINDOWS\system32\avfliqwm.dll
C:\WINDOWS\system32\baayyhkj.dll
C:\WINDOWS\system32\bdlyfppb.dll
C:\WINDOWS\system32\bppfyldb.ini
C:\WINDOWS\system32\cfqrmtbo.dll
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\dvifotjb.dll
C:\WINDOWS\system32\erdgvdxe.dll
C:\WINDOWS\system32\evndcvcm.dll
C:\WINDOWS\system32\faypimal.dll
C:\WINDOWS\system32\glyraphp.dll
C:\WINDOWS\system32\grpwxodq.dll
C:\WINDOWS\system32\hpxgbwth.dll
C:\WINDOWS\system32\ivjcswrs.dll
C:\WINDOWS\system32\iwwfkjdv.dll
C:\WINDOWS\system32\jipjcufq.dll
C:\WINDOWS\system32\lfhbmpac.dll
C:\WINDOWS\system32\ljxpnata.dll
C:\WINDOWS\system32\lniyeysd.dll
C:\WINDOWS\system32\luflcnyc.dll
C:\WINDOWS\system32\lulfraxh.dll
C:\WINDOWS\system32\maogjxyx.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mrtkaeaw.dll
C:\WINDOWS\system32\nvktngwg.dll
C:\WINDOWS\system32\nyossclw.dll
C:\WINDOWS\system32\otwgsawm.dll
C:\WINDOWS\system32\pihkcnjr.dll
C:\WINDOWS\system32\pyyobvbc.dll
C:\WINDOWS\system32\qqxqefbe.dll
C:\WINDOWS\system32\quligxew.dll
C:\WINDOWS\system32\reqjqxoe.dll
C:\WINDOWS\system32\rgeaayhf.dll
C:\WINDOWS\system32\rytpmmwj.dll
C:\WINDOWS\system32\system.exe
C:\WINDOWS\system32\thylfnwu.dll
C:\WINDOWS\system32\tqsupyhj.dll
C:\WINDOWS\system32\ufrftlgk.dll
C:\WINDOWS\system32\uogjvymh.dll
C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\uwvsluhw.dll
C:\WINDOWS\system32\vtutu.dll
C:\WINDOWS\system32\widgskub.dll
C:\WINDOWS\system32\wpyrdevm.dll
C:\WINDOWS\system32\xdpjllhy.dll
C:\WINDOWS\system32\xdqrprov.dll
C:\WINDOWS\system32\xwuhxxny.dll
C:\WINDOWS\system32\ylumvmjs.dll
C:\WINDOWS\system32\yudjrchd.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-02-08 to 2008-03-08 )))))))))))))))))))))))))))))))
.
2008-03-07 19:35 . 2008-03-07 19:35 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Malwarebytes
2008-03-07 19:28 . 2008-03-07 19:28 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-07 19:28 . 2008-03-07 19:28 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-05 21:07 . 2008-03-05 21:07 326,656 --a------ C:\WINDOWS\system32\RCX4B.tmp
2008-03-04 23:15 . 2008-03-04 23:15 326,656 --a------ C:\WINDOWS\system32\RCX44.tmp
2008-03-04 15:33 . 2008-03-05 07:12 1,494 ---hs---- C:\WINDOWS\system32\emcbsbik.ini
2008-03-03 23:38 . 2008-03-08 00:21 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-03 23:38 . 2008-03-03 23:38 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-03 23:36 . 2008-03-03 23:36 326,656 --a------ C:\WINDOWS\system32\RCX41.tmp
2008-03-03 15:31 . 2008-03-04 15:32 1,314 ---hs---- C:\WINDOWS\system32\wqvpfgxw.ini
2008-03-02 08:44 . 2008-03-03 15:25 1,194 ---hs---- C:\WINDOWS\system32\csiuloni.ini
2008-02-29 18:36 . 2008-02-29 18:36 326,656 --a------ C:\WINDOWS\system32\RCX3E.tmp
2008-02-29 15:32 . 2008-03-02 08:41 1,074 ---hs---- C:\WINDOWS\system32\pprkuifl.ini
2008-02-28 15:28 . 2008-02-29 15:29 774 ---hs---- C:\WINDOWS\system32\xorohqel.ini
2008-02-26 21:14 . 2008-02-28 15:28 654 ---hs---- C:\WINDOWS\system32\sroikmrx.ini
2008-02-25 19:10 . 2008-02-26 21:11 534 ---hs---- C:\WINDOWS\system32\xchqoame.ini
2008-02-25 18:07 . 2008-02-25 18:08 294 ---hs---- C:\WINDOWS\system32\tcecreer.ini
2008-02-24 13:28 . 2008-02-24 13:28 d-------- C:\Program Files\Webroot
2008-02-24 13:28 . 2008-02-24 13:28 d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-02-24 13:28 . 2008-02-24 13:28 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Webroot
2008-02-24 13:28 . 2008-02-24 13:28 d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-02-24 13:28 . 2008-01-04 20:56 1,526,640 --a------ C:\WINDOWS\WRSetup.dll
2008-02-24 13:28 . 2008-01-04 20:34 163,696 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-02-24 13:28 . 2008-01-04 20:34 23,920 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-02-24 13:28 . 2008-01-04 20:34 21,872 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-02-24 13:28 . 2008-01-04 20:34 20,336 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2008-02-24 13:23 . 2008-02-24 13:25 d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2008-02-24 11:32 . 2008-02-24 11:32 d-------- C:\Program Files\Enigma Software Group
2008-02-23 16:36 . 2008-02-24 16:37 1,154,241 ---hs---- C:\WINDOWS\system32\ikrvtjmh.ini
2008-02-23 15:30 . 2008-02-23 15:31 1,153,692 ---hs---- C:\WINDOWS\system32\rbkugrmv.ini
2008-02-22 15:30 . 2008-02-22 22:47 1,154,857 ---hs---- C:\WINDOWS\system32\jgyqprlr.ini
2008-02-21 15:34 . 2008-02-22 15:26 1,154,361 ---hs---- C:\WINDOWS\system32\qurpshjd.ini
2008-02-20 15:29 . 2008-02-21 15:29 1,207,013 ---hs---- C:\WINDOWS\system32\ntcpimka.ini
2008-02-18 21:05 . 2008-02-20 15:28 1,250,261 ---hs---- C:\WINDOWS\system32\pqpcnvbh.ini
2008-02-18 11:06 . 2008-02-18 21:05 1,238,973 ---hs---- C:\WINDOWS\system32\rxfdbuje.ini
2008-02-17 22:30 . 2008-02-17 22:30 d-------- C:\WINDOWS\.jagex_cache_32
2008-02-17 22:20 . 2008-02-18 11:05 1,248,947 ---hs---- C:\WINDOWS\system32\enldmlcr.ini
2008-02-16 22:21 . 2008-02-17 02:06 1,248,767 ---hs---- C:\WINDOWS\system32\tdwjuhba.ini
2008-02-16 22:07 . 2007-06-28 18:52 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-02-16 22:07 . 2007-06-28 18:54 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-02-16 22:07 . 2007-06-28 18:55 77,824 --a------ C:\WINDOWS\system32\xvid.ax
2008-02-16 21:55 . 2008-02-16 21:56 d-------- C:\Program Files\AVI MPEG Video Converter
2008-02-15 22:19 . 2008-02-16 22:19 1,248,647 ---hs---- C:\WINDOWS\system32\bmttocru.ini
2008-02-15 21:19 . 2008-02-15 21:20 1,248,467 ---hs---- C:\WINDOWS\system32\yrhtflmr.ini
2008-02-14 21:19 . 2008-02-15 12:22 1,242,300 ---hs---- C:\WINDOWS\system32\nhrmnthc.ini
2008-02-12 21:22 . 2008-02-13 16:09 1,235,221 ---hs---- C:\WINDOWS\system32\kfjnncvu.ini
2008-02-11 23:56 . 2008-02-12 20:36 1,222,540 ---hs---- C:\WINDOWS\system32\vexnjjpj.ini
2008-02-11 01:08 . 2008-02-11 01:08 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-11 01:08 . 2008-02-11 01:08 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-11 00:58 . 2008-02-11 00:58 d-------- C:\Program Files\Trend Micro
2008-02-10 19:51 . 2008-02-10 20:07 9,296 --a------ C:\22.exe
2008-02-09 21:16 . 2008-02-10 17:49 1,220,770 ---hs---- C:\WINDOWS\system32\tthlccou.ini
2008-02-09 14:34 . 2008-02-09 14:34 dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-02-08 22:13 . 2008-02-09 02:14 137,248 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-08 22:13 . 2008-02-09 02:14 4,128 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-02-08 22:13 . 2008-02-09 02:14 2,684 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-08 22:13 . 2008-02-09 02:14 1,460 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-02-08 22:12 . 2008-02-08 22:12 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-02-08 22:12 . 2008-02-10 17:46 364,544 --a------ C:\WINDOWS\mrofinu1285.exe.tmp
2008-02-08 21:40 . 2007-10-10 18:55 6,065,664 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-02-08 21:40 . 2007-06-30 22:31 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-02-08 21:40 . 2007-06-30 22:36 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-02-08 21:40 . 2007-10-10 18:55 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-02-08 21:40 . 2007-10-10 18:55 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-02-08 21:40 . 2007-10-10 18:55 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-02-08 21:40 . 2007-10-10 18:55 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-02-08 21:40 . 2007-10-10 18:55 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-02-08 21:40 . 2007-10-10 05:59 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-08 19:29 . 2008-03-05 21:08 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
2008-02-08 16:21 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-08 15:36 . 2008-02-08 15:36 d-------- C:\Program Files\MSXML 4.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-08 05:36 --------- d-----w C:\Program Files\QuickTime
2008-03-08 05:36 --------- d-----w C:\Program Files\iTunes
2008-03-04 02:59 --------- d-----w C:\Documents and Settings\Compaq_Owner\Application Data\uTorrent
2008-02-27 21:08 --------- d-----w C:\Documents and Settings\Compaq_Owner\Application Data\AdobeUM
2008-02-27 20:41 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-02-24 17:49 --------- d-----w C:\Program Files\Sonic
2008-02-24 15:08 --------- d-----w C:\Program Files\iPod
2008-02-17 03:07 --------- d-----w C:\Program Files\XviD
2008-02-13 01:23 --------- d-----w C:\Documents and Settings\Compaq_Owner\Application Data\Apple Computer
2008-02-09 03:35 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-09 03:34 --------- d-----w C:\Program Files\Common Files\Command Software
2008-02-09 00:26 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-09 00:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-08 21:20 --------- d-----w C:\Program Files\Java
2008-02-08 20:23 --------- d-----w C:\Program Files\PC-Doctor 5 for Windows
2008-02-08 02:43 --------- d-----w C:\Program Files\Apple Software Update
2008-02-08 02:23 --------- d-----w C:\Program Files\Google
2008-02-08 02:00 --------- d-----w C:\Program Files\WildTangent
2008-01-26 21:21 --------- d-----w C:\Program Files\World of Warcraft
2008-01-26 01:30 --------- d-----w C:\Program Files\7-Zip
2008-01-14 05:36 5,197 ----a-w C:\is9.exe
2008-01-02 19:44 3,029,431 ----a-w C:\steam.exe
2007-10-02 18:51 2,674,688 ----a-w C:\Documents and Settings\Compaq_Owner\Application Data\Steam.dll
2007-03-29 14:57 6,656 ----a-w C:\Documents and Settings\Compaq_Owner\Application Data\sx.exe
2006-10-01 21:38 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
<pre>
----a-w 27,136 2007-02-08 22:40:48 C:\hp\bin\cloaker .exe
----a-w 307,200 2008-02-19 02:04:39 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
----a-w 50,528 2007-02-05 20:26:05 C:\Program Files\AIM6\aim6 .exe
----a-w 344,064 2007-02-08 22:40:28 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
----a-w 180,269 2008-03-02 13:41:29 C:\Program Files\Common Files\Real\Update_OB\realsched .exe
----a-w 52,848 2008-02-08 22:00:43 C:\Program Files\Common Files\Symantec Shared\ccApp .exe
----a-w 218,240 2008-02-08 22:00:53 C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt .exe
----a-w 847,872 2008-02-24 17:39:04 C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3 .exe
----a-w 249,856 2007-02-07 05:31:45 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-02-07 05:29:36 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-02-07 03:45:18 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-02-06 20:24:04 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-02-05 20:25:02 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-02-05 02:15:54 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-02-04 20:30:06 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-02-04 03:42:20 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-02-03 23:49:31 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-03 14:10:03 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-03 06:22:07 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-03 01:18:38 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-02 16:42:30 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-01 20:46:12 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-01 20:24:40 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-31 20:24:48 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-31 02:06:28 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-30 20:28:12 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-29 21:16:31 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-29 20:26:38 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-28 20:25:39 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-27 17:24:07 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-26 20:59:29 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-26 15:35:53 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-25 16:21:11 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-25 01:47:56 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-25 01:34:29 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-25 01:26:40 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-01-24 14:23:51 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-01-23 16:42:43 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-01-23 16:25:36 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-01-23 00:48:06 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-01-22 20:34:51 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-01-22 20:23:53 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-01-22 01:08:56 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2007-01-21 23:08:16 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-21 15:26:49 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-20 18:39:47 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-20 08:37:27 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-20 02:15:04 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-19 14:34:43 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-18 20:30:46 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-18 01:11:49 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-17 02:42:23 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-17 02:14:22 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-16 20:26:23 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-15 20:29:15 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-15 02:14:22 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-14 20:25:40 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-13 15:59:26 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-13 15:33:34 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-13 02:20:48 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-12 15:56:11 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-11 20:25:48 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-11 04:22:42 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-10 21:30:31 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-09 20:27:04 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-08 20:27:47 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-07 22:51:06 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-07 20:30:46 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-07 01:24:02 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-06 19:15:59 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-06 08:46:24 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-05 18:28:42 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-05 18:19:42 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-04 17:49:14 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-01-04 02:12:51 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-11 04:42:03 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-10 22:46:34 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-10 14:27:29 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-10 03:16:52 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-10 02:08:58 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-09 21:39:08 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-09 20:06:08 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-09 19:39:56 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-09 18:48:05 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-09 16:31:54 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-09 16:05:52 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-09 03:05:15 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-09 01:06:45 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 577,536 2008-02-09 00:26:57 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe
----a-w 49,152 2008-02-10 22:47:49 C:\Program Files\HP\HP Software Update\HPwuSchd2 .exe
----a-w 267,048 2008-03-08 05:20:36 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 36,975 2007-02-08 22:40:25 C:\Program Files\Java\jre1.5.0_05\bin\jusched .exe
----a-w 132,496 2008-02-10 22:47:56 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
----a-w 1,694,208 2008-02-10 22:48:58 C:\Program Files\Messenger\msmsgs .exe
----a-w 53,248 2008-02-08 20:25:45 C:\Program Files\PC-Doctor 5 for Windows\RunProfiler .exe
----a-w 286,720 2007-01-24 14:24:49 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2007-01-24 14:24:01 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2007-01-23 16:42:45 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2007-01-23 16:25:38 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2007-01-23 00:48:09 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2007-01-22 20:34:54 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2007-01-22 20:23:56 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2007-01-22 01:08:59 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2007-01-21 23:08:19 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-21 15:26:52 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-20 18:39:51 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-20 08:37:29 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-20 02:15:07 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-19 14:34:50 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-18 20:30:53 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-18 01:11:52 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-18 01:04:12 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-17 20:28:30 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-17 02:42:25 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-17 02:14:30 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-16 20:26:27 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-15 20:29:20 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-15 02:14:25 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-14 20:25:43 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-14 05:33:48 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-13 15:59:28 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-13 15:33:37 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-13 02:20:50 C:\Program Files\QuickTime\qttask .exe
----a-w 640,512 2008-01-12 15:56:13 C:\Program Files\QuickTime\qttask .exe
----a-w 385,024 2006-02-07 05:31:59 C:\Program Files\QuickTime\qttask .exe
----a-w 738,816 2007-02-07 05:29:44 C:\Program Files\QuickTime\qttask .exe
----a-w 738,816 2007-02-07 03:45:36 C:\Program Files\QuickTime\qttask .exe
----a-w 738,816 2007-02-06 20:24:12 C:\Program Files\QuickTime\qttask .exe
----a-w 738,816 2007-02-06 13:06:03 C:\Program Files\QuickTime\qttask .exe
----a-w 738,816 2007-02-05 20:25:09 C:\Program Files\QuickTime\qttask .exe
----a-w 738,816 2007-02-05 02:16:00 C:\Program Files\QuickTime\qttask .exe
----a-w 738,816 2007-02-04 20:30:11 C:\Program Files\QuickTime\qttask .exe
----a-w 738,816 2007-02-04 03:42:26 C:\Program Files\QuickTime\qttask .exe
----a-w 738,816 2007-02-03 23:49:39 C:\Program Files\QuickTime\qttask .exe
----a-w 738,816 2008-02-03 18:28:10 C:\Program Files\QuickTime\qttask .exe
----a-w 738,816 2008-02-03 14:10:07 C:\Program Files\QuickTime\qttask .exe
----a-w 738,816 2008-02-03 06:22:14 C:\Program Files\QuickTime\qttask .exe
----a-w 385,024 2008-03-06 02:07:49 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-03-06 02:07:16 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-03-05 12:10:13 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-03-05 04:15:14 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-03-04 04:36:04 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-03-01 10:59:57 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-02-29 23:36:09 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-02-29 05:11:36 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-02-26 20:59:17 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-02-25 03:43:22 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-02-24 21:43:05 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-02-24 18:31:30 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-02-24 17:59:38 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-02-24 17:37:57 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-02-24 16:50:46 C:\Program Files\QuickTime\QTTask .exe
----a-w 738,816 2008-02-24 15:14:32 C:\Program Files\QuickTime\QTTask .exe
----a-w 5,367,664 2008-03-08 05:20:42 C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI .exe
----a-w 189,952 2007-02-07 05:31:46 C:\WINDOWS\wkssvr .exe
----a-w 237,568 2008-02-10 22:47:39 C:\WINDOWS\SMINST\RECGUARD .EXE
----a-w 52,736 2007-02-08 22:40:24 C:\WINDOWS\system\hpsysdrv .exe
----a-w 15,360 2008-03-06 02:08:38 C:\WINDOWS\system32\ctfmon .exe
</pre>
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 67,112 2006-08-01 21:35:36 C:\Program Files\AIM\bak\aim.exe
----a-w 24,080 2007-08-23 04:01:23 C:\Program Files\AIM\aim.exe
----a-w 50,736 2007-04-27 21:17:26 C:\Program Files\AIM6\bak\aim6.exe
----a-w 57,344 2002-05-22 15:57:16 C:\Program Files\AIM95\bak\aim.exe
----a-w 344,064 2006-04-05 02:05:00 C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
----a-w 344,064 2005-08-14 12:05:00 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
----a-w 185,896 2007-03-26 03:46:16 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 249,856 2005-11-10 00:29:16 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe
----a-w 577,536 2008-02-08 01:29:57 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
----a-w 49,152 2005-02-17 14:11:42 C:\Program Files\HP\HP Software Update\bak\HPwuSchd2.exe
----a-w 377,856 2008-02-10 22:46:36 C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
----a-w 1,592 2007-11-16 21:26:11 C:\Program Files\Steam\bak\ClientRegistry.blob
----a-w 335,992 2007-10-03 21:47:28 C:\Program Files\Steam\ClientRegistry.blob
----a-w 1,258,744 2007-09-01 03:07:11 C:\Program Files\Steam\bak\Steam.exe
----a-w 28,176 2007-10-03 22:02:27 C:\Program Files\Steam\Steam.exe
----a-w 29,228 2007-11-12 04:01:56 C:\Program Files\Steam\bak\Steamexe__237340__2007_11_12T4_1_52C5859.mdmp
----a-w 29,228 2007-11-16 21:26:11 C:\Program Files\Steam\bak\Steamexe__237340__2007_11_16T21_26_8C8296.mdmp
----a-w 29,228 2007-11-03 15:14:32 C:\Program Files\Steam\bak\Steamexe__237340__2007_11_3T15_14_30C8828.mdmp
----a-w 2,560,000 2007-09-13 01:33:30 C:\Program Files\Veoh Networks\Veoh\bak\VeohClient.exe
----a-w 3,252,224 2007-10-03 15:46:40 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
----a-w 237,568 2005-07-23 06:14:00 C:\WINDOWS\SMINST\bak\RECGUARD.EXE
----a-w 573,952 2008-02-11 04:42:02 C:\WINDOWS\SMINST\RECGUARD.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCDrProfiler"="" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [2008-03-05 21:07 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe [2006-02-22 10:39:49 36903]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ylbkaleq]
ylbkaleq.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-08 00:49:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
.
**************************************************************************
.
Completion time: 2008-03-08 0:54:51 - machine was rebooted [Compaq_Owner]
ComboFix-quarantined-files.txt 2008-03-08 05:54:28
.
2008-02-09 02:46:54 --- E O F ---