ComboFix 07-08-30.3 - "Owner" 2007-09-01 9:48:07.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.69 [GMT -4:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Owner\APPLIC~1\install.dat
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\armvpynl.dll
C:\WINDOWS\system32\clodcssj.exe
C:\WINDOWS\system32\hggfghg.dll
C:\WINDOWS\system32\hgggday.dll
C:\WINDOWS\system32\iltjwneu.dll
C:\WINDOWS\system32\lnypvmra.ini
C:\WINDOWS\system32\nsw57.dll
C:\WINDOWS\system32\nsw60.dll
C:\WINDOWS\system32\nsx8E.dll
C:\WINDOWS\system32\orqss.bak1
C:\WINDOWS\system32\orqss.bak2
C:\WINDOWS\system32\orqss.ini
C:\WINDOWS\system32\pwmwxquu.exe
C:\WINDOWS\system32\ssqro.dll
C:\WINDOWS\system32\tfyqsnjf.dll
C:\WINDOWS\system32\tmjqpvnd.dll
C:\WINDOWS\system32\uenwjtli.ini
D:\Autorun.inf
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-08-01 to 2007-09-01 )))))))))))))))))))))))))))))))
2007-09-01 09:44 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-31 17:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-30 13:05 95,232 --a------ C:\WINDOWS\system32\drvnod.dll
2007-08-30 13:05 15,360 --a------ C:\WINDOWS\system32\drvnodr.dll
2007-08-30 07:44 <DIR> d-------- C:\!KillBox
2007-08-29 08:05 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-29 07:02 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-08-29 06:58 <DIR> d-------- C:\DOCUME~1\Owner\.housecall6.6
2007-08-28 06:44 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\AdwareAlert
2007-08-28 06:43 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-08-27 15:46 <DIR> d--h----- C:\WINDOWS\PIF
2007-08-27 15:05 <DIR> d-------- C:\Program Files\XoftSpySE
2007-08-27 14:28 1,601,769 --ahs---- C:\WINDOWS\system32\onnmp.bak2
2007-08-27 06:23 <DIR> d-------- C:\DOCUME~1\ADMINI~1\WINDOWS
2007-08-27 06:23 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver
2007-08-27 06:23 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\SampleView
2007-08-27 06:23 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
2007-08-26 18:01 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-26 10:06 6,513 --ahs---- C:\WINDOWS\system32\onnmp.bak1
2007-08-26 09:57 <DIR> d-------- C:\VundoFix Backups
2007-08-25 02:12 <DIR> d-------- C:\Program Files\a-squared Free
2007-08-25 02:05 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\McAfee
2007-08-24 04:17 90,112 --a------ C:\WINDOWS\system32\mcrtl32.dll
2007-08-24 04:17 32,768 --a------ C:\WINDOWS\system32\instlsp.exe
2007-08-24 04:17 131,072 --a------ C:\WINDOWS\system32\mclsp.dll
2007-08-24 04:17 11,264 --a------ C:\WINDOWS\system32\sporder.dll
2007-08-24 04:17 <DIR> d-------- C:\WINDOWS\system32\mclsphlr
2007-08-24 03:52 <DIR> d-------- C:\Program Files\DAMN NFO Viewer
2007-08-24 03:39 93,184 --a------ C:\WINDOWS\system32\drvpuw.dll
2007-08-24 03:39 15,360 --a------ C:\WINDOWS\system32\drvpuwr.dll
2007-08-18 15:45 <DIR> d-------- C:\My Downloads
2007-08-18 15:45 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
2007-08-18 15:44 <DIR> d-------- C:\Program Files\BitDownload
2007-08-18 14:38 32,768 --a------ C:\WINDOWS\system32\cardinfo.dll
2007-08-18 14:38 28,160 --a------ C:\WINDOWS\system32\bravemail.dll
2007-08-18 14:38 <DIR> d-------- C:\Program Files\PhotoBuilder
2007-08-18 14:14 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Morpheus Software
2007-08-18 13:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-31 1OCUME~1\Owner\APPLIC~1\AdobeUM
2007-08-28 0rogram Files\LimeWire
2007-08-24 0rogram Files\McAfee.com
2007-08-24 0OCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
2007-08-18 1rogram Files\Napster
2007-08-18 1OCUME~1\ALLUSE~1\APPLIC~1\Napster
2007-08-18 1rogram Files\InstallShield Installation Information
2007-08-11 1rogram Files\userdata
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-06-26 02:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 09:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-13 06:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-06-03 01:45 7168 --ahsc--- C:\Program Files\Thumbs.db
2006-11-23 11:24 18029 --a--c--- C:\Program Files\irunin.ini
2006-11-23 11:23 8134 --a--c--- C:\Program Files\irunin.bmp
2006-11-23 11:23 15938 --a--c--- C:\Program Files\irunin.lng
2006-11-23 11:23 149841 --a--c--- C:\Program Files\irunin.dat
2003-12-14 17:34 57 --a--c--- C:\Program Files\status.js
2003-12-14 17:32 27587 --a--c--- C:\Program Files\theUninstallFile.txt
2003-12-14 17:32 1290240 --a------ C:\Program Files\Zuma.exe
2003-12-14 17:31 95 --a--c--- C:\Program Files\mainimage_top.gif
2003-12-14 17:31 91 --a--c--- C:\Program Files\mainimage_bottom.gif
2003-12-14 17:31 902 --a--c--- C:\Program Files\contentbox.gif
2003-12-14 17:31 828 --a--c--- C:\Program Files\button_center.gif
2003-12-14 17:31 741 --a--c--- C:\Program Files\mainimage_left.gif
2003-12-14 17:31 6561 --a--c--- C:\Program Files\racnotinstalled.htm
2003-12-14 17:31 53 --a--c--- C:\Program Files\empty.gif
2003-12-14 17:31 49 --a--c--- C:\Program Files\spacer.gif
2003-12-14 17:31 38543 --a--c--- C:\Program Files\gameart.jpg
2003-12-14 17:31 333 --a--c--- C:\Program Files\wrapper.ini
2003-12-14 17:31 314 --a--c--- C:\Program Files\butt_next_over.gif
2003-12-14 17:31 310 --a--c--- C:\Program Files\butt_back_over.gif
2003-12-14 17:31 287 --a--c--- C:\Program Files\launch.ini
2003-12-14 17:31 285 --a--c--- C:\Program Files\osd212.osd
2003-12-14 17:31 27957 --a--c--- C:\Program Files\readme.html
2003-12-14 17:31 279 --a--c--- C:\Program Files\meter_bottom.gif
2003-12-14 17:31 263 --a--c--- C:\Program Files\meter_top.gif
2003-12-14 17:31 224 --a--c--- C:\Program Files\feedback.htm
2003-12-14 17:31 218 --a--c--- C:\Program Files\butt_next.gif
2003-12-14 17:31 213 --a--c--- C:\Program Files\butt_back.gif
2003-12-14 17:31 210 --a--c--- C:\Program Files\setup.ini
2003-12-14 17:31 208 --a--c--- C:\Program Files\button_right.gif
2003-12-14 17:31 192 --a--c--- C:\Program Files\meter_right.gif
2003-12-14 17:31 191 --a--c--- C:\Program Files\meter_left.gif
2003-12-14 17:31 187 --a--c--- C:\Program Files\button_left.gif
2003-12-14 17:31 150 --a--c--- C:\Program Files\horzline.gif
2003-12-14 17:31 149 --a--c--- C:\Program Files\meter_upperleft.gif
2003-12-14 17:31 149 --a--c--- C:\Program Files\meter_lowerright.gif
2003-12-14 17:31 147 --a--c--- C:\Program Files\meter_upperright.gif
2003-12-14 17:31 146 --a--c--- C:\Program Files\meter_lowerleft.gif
2003-12-14 17:31 14190 --a--c--- C:\Program Files\pregame.htm
2003-12-14 17:31 1285 --a--c--- C:\Program Files\contentbox_bottom.gif
2003-12-14 17:31 1241 --a--c--- C:\Program Files\contentbox_top.gif
2003-12-14 17:31 124 --a--c--- C:\Program Files\butt_left.gif
2003-12-14 17:31 123 --a--c--- C:\Program Files\butt_right.gif
2003-12-14 17:31 115 --a--c--- C:\Program Files\mainimage_right.gif
2003-12-14 17:31 102196 --a------ C:\Program Files\bass.dll
2003-12-14 17:31 101 --a--c--- C:\Program Files\fill.gif
2003-11-21 17:11 49 --ah-c--- C:\Program Files\Config.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{027D35C1-9701-454C-98FC-2F06466EDE0E}]
C:\WINDOWS\system32\awtqn.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9CDC926D-1540-4323-9072-6E4B2813869E}]
C:\WINDOWS\system32\pmnno.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D3C7F3A4-D6DC-407A-8F54-73C7E7FC1E9F}]
C:\WINDOWS\system32\geeby.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 19:18]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-12 02:02]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 19:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 13:05]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 14:26]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2006-11-07 15:49]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 16:49]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 18:00]
"MPSExe"="c:\PROGRA~1\mcafee.com\mps\mscifapp.exe" [2005-09-28 16:28]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-09-17 20:32]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Power2GoExpress"=NA
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winosz32]
winosz32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Image Transfer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Image Transfer.lnk
backup=C:\WINDOWS\pss\Image Transfer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^svchost.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
backup=C:\WINDOWS\pss\svchost.exeCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AAWTray]
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdwareAlert]
C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
"C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
zHotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
rundll32.exe C:\WINDOWS\system32\drvnod.dll,startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
HDAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1164119477\EE\AOLHostManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
"C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\outlook]
C:\Program Files\outlook\outlook.exe /auto
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\readericon]
C:\Program Files\Digital Media Reader\readericon45G.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
%WINDIR%\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
%WINDIR%\Creator\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\system32\iltjwneu.dll",forkonce
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winlog]
winlog.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{7C-CB-B2-27-ZN}]
c:\windows\system32\dwdsrngt.exe P2D002
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PrismXL"=2 (0x2)
"ose"=3 (0x3)
"DomainService"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)
"AOL ACS"=2 (0x2)
"AdwareAlertSrv"=2 (0x2)
S4 AdwareAlertSrv;AdwareAlert Scanning Engine;"C:\Program Files\AdwareAlert\AdwareAlertSrv.srv.exe"
Contents of the 'Scheduled Tasks' folder
2007-09-01 07:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job - C:\Program Files\AdwareAlert\AdwareAlert.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-01 09:55:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-09-01 9:57:40 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-01 09:57
--- E O F ---