This time I could submit the file to bleeping conputer site, and here is the log:
ComboFix 08-06-16.5 - Owner 2008-06-20 9:52:47.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.164 [GMT 1:00]
Running from: C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\bgswxfhs.dll
C:\WINDOWS\system32\dmkraciu.dll
C:\WINDOWS\system32\gmgggucp.dll
C:\WINDOWS\system32\kgaadvfv.dll
C:\WINDOWS\system32\mlxfroku.dll
C:\WINDOWS\system32\oyubsgog.dll
C:\WINDOWS\system32\pbrxauoo.dll
C:\WINDOWS\system32\shdhmqkl.dll
C:\WINDOWS\system32\wgmfywdx.dll
C:\WINDOWS\system32\whqigmjc.dll
C:\WINDOWS\system32\ymwrrmjo.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-20 to 2008-06-20 )))))))))))))))))))))))))))))))
.
2008-06-19 17:38 . 2008-06-19 17:38 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-06-19 17:38 . 2008-06-19 17:40 <DIR> d-------- C:\Program Files\McDonaldsDragons
2008-06-19 12:00 . 2008-06-19 12:00 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-06-19 12:00 . 2008-06-19 12:00 <DIR> d-------- C:\WINDOWS\system32\npp
2008-06-19 12:00 . 2008-06-19 12:00 <DIR> d-------- C:\WINDOWS\srchasst
2008-06-19 11:59 . 2008-06-19 11:59 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-06-19 11:33 . 2008-04-14 12:01 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-19 11:33 . 2008-05-08 13:14 203,008 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-17 14:29 . 2008-06-17 14:29 <DIR> d-------- C:\Deckard
2008-06-17 08:08 . 2008-06-17 08:08 <DIR> d-------- C:\WINDOWS\Sun
2008-06-17 07:27 . 2008-06-17 07:27 <DIR> d-------- C:\Program Files\MyHeritage
2008-06-17 07:27 . 2008-06-17 07:27 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\The Complete Genealogy Reporter - FTB
2008-06-17 07:27 . 2002-03-07 07:19 454,656 --a------ C:\WINDOWS\system32\PaintX.dll
2008-06-17 07:27 . 2003-07-06 20:07 372,736 --a------ C:\WINDOWS\system32\ijl15.dll
2008-06-17 07:27 . 1998-06-24 06:00 137,000 --a------ C:\WINDOWS\system32\msmapi32.ocx
2008-06-16 18:37 . 2008-06-20 09:54 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Skype
2008-06-16 18:36 . 2008-06-16 18:36 <DIR> d-------- C:\Program Files\Skype
2008-06-16 18:36 . 2008-06-16 18:36 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-06-16 13:09 . 2008-06-16 13:09 <DIR> d--h----- C:\WINDOWS\PIF
2008-06-16 12:38 . 2008-06-19 08:59 53,192 --a------ C:\WINDOWS\system32\drivers\rp_skt32.sys
2008-06-16 12:38 . 2007-04-19 17:36 48,384 --a------ C:\WINDOWS\system32\drivers\rp_pkt32.sys
2008-06-16 12:37 . 2008-06-16 12:37 <DIR> d-------- C:\Program Files\Common Files\Authentium
2008-06-16 12:36 . 2008-06-16 12:36 <DIR> d-------- C:\Program Files\Raxco
2008-06-16 12:36 . 2008-06-16 12:36 <DIR> d-------- C:\Program Files\CA
2008-06-16 12:36 . 2008-06-16 12:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Raxco
2008-06-16 12:35 . 2008-06-16 13:12 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-06-16 12:23 . 2008-06-16 12:34 <DIR> d-------- C:\Program Files\Virgin Broadband
2008-06-16 12:23 . 2008-06-16 13:24 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Virgin Broadband
2008-06-16 12:23 . 2008-06-16 12:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Virgin Broadband
2008-06-16 11:37 . 2008-06-16 11:37 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-06-14 16:42 . 2008-06-14 16:42 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\VTExtra
2008-06-11 21:48 . 2008-06-11 21:48 <DIR> d-------- C:\Program Files\BitTorrent Fastest Tool
2008-06-11 15:48 . 2008-06-11 19:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\great coal love default
2008-06-06 20:53 . 2008-06-06 20:53 <DIR> d-------- C:\WINDOWS\system32\djpclib
2008-06-06 20:53 . 2008-06-06 20:53 <DIR> d-------- C:\WINDOWS\E4153266612C460FAB94C9DB6802459A.TMP
2008-06-06 20:53 . 2008-06-06 20:53 <DIR> d-------- C:\Virtual
2008-06-06 20:53 . 2008-06-06 20:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BufferZone
2008-06-06 20:52 . 2008-06-06 20:52 <DIR> d-------- C:\Program Files\Share_Accelerator_MM
2008-06-06 20:52 . 2008-06-06 20:52 <DIR> d-------- C:\Program Files\ALCATech
2008-06-06 20:51 . 2008-06-06 20:51 <DIR> d-------- C:\WINDOWS\Philips
2008-06-06 20:51 . 2008-06-06 20:51 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\InstallShield
2008-06-06 20:51 . 2008-06-06 20:51 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\ArcSoft
2008-06-06 20:47 . 2008-06-06 20:47 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Windows Live Writer
2008-06-06 20:46 . 2008-06-06 20:46 <DIR> d-------- C:\Documents and Settings\Owner\Documents and Settings
2008-06-06 20:46 . 2008-06-06 20:46 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Application Data
2008-06-06 20:45 . 2008-06-06 20:46 <DIR> d-------- C:\Program Files\SpacialAudio
2008-06-06 20:27 . 2008-06-06 20:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Disk Cleaner
2008-06-06 20:26 . 2008-06-06 20:47 <DIR> d-------- C:\Program Files\nvcoi(2)
2008-06-03 16:42 . 2008-06-16 12:49 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\LimeWire
2008-06-03 16:42 . 2008-03-25 08:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-03 16:41 . 2008-06-06 20:53 <DIR> d-------- C:\Program Files\Java
2008-06-03 16:40 . 2008-06-06 20:53 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-03 16:37 . 2008-06-17 08:49 <DIR> d-------- C:\Program Files\LimeWire
2008-06-01 16:03 . 2008-06-01 16:11 <DIR> d-------- C:\Program Files\DJ Music Mixer
2008-06-01 11:39 . 2008-06-06 20:18 <DIR> d-------- C:\Documents and Settings\Owner\.ultramixer
2008-06-01 10:43 . 2002-09-21 21:33 65,536 --a------ C:\WINDOWS\system32\cpvslider.ocx
2008-06-01 10:43 . 2002-09-13 23:09 45,056 --a------ C:\WINDOWS\system32\BPM_Control.ocx
2008-05-31 19:13 . 2008-06-06 20:52 <DIR> d-------- C:\Program Files\Native Instruments
2008-05-31 19:01 . 2008-05-31 19:01 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\NCH Software
2008-05-31 18:54 . 2005-01-20 18:02 344,576 --a------ C:\WINDOWS\system32\MMRTKRNL.DLL
2008-05-31 18:54 . 2005-01-11 23:05 92,672 --a------ C:\WINDOWS\system32\drivers\mmrtkrnl.sys
2008-05-31 18:54 . 1997-12-23 08:00 48,128 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2008-05-31 18:54 . 1997-12-23 08:00 23,936 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-05-31 18:54 . 1997-12-23 08:00 5,600 --a------ C:\WINDOWS\system\WNASPI32.NT
2008-05-31 18:54 . 1997-12-23 08:00 4,672 --a------ C:\WINDOWS\system\WOWPOST.EXE
2008-05-28 15:46 . 2008-02-26 12:48 297,984 --------- C:\WINDOWS\system32\dllcache\msctf.dll
2008-05-24 13:13 . 2008-06-06 20:52 <DIR> d-------- C:\Program Files\Zapu
2008-05-24 13:13 . 2004-02-17 06:00 434,252 --a------ C:\WINDOWS\system32\Msvcrtd.dll
2008-05-22 23:20 . 2008-05-22 23:20 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-05-22 23:20 . 2008-05-22 23:20 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-06-20 07:03 --------- d-----w C:\Documents and Settings\Owner\Application Data\skypePM
2008-06-20 00:31 --------- d-----w C:\Program Files\ICQToolbar
2008-06-18 15:39 --------- d-----w C:\Documents and Settings\Owner\Application Data\ICQ Toolbar
2008-06-17 12:39 --------- d-----w C:\Program Files\eMule
2008-06-16 17:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-06-16 17:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-11 18:55 --------- d-----w C:\Program Files\NotePad++
2008-06-11 16:37 --------- d-----w C:\Program Files\DivX
2008-06-11 16:18 --------- d-----w C:\Program Files\NCH Software
2008-06-11 16:16 --------- d-----w C:\Program Files\Movavi Video Converter 5
2008-06-06 19:53 --------- d-----w C:\Program Files\VirtualDJ
2008-06-06 19:53 --------- d-----w C:\Program Files\Secured IE
2008-06-06 19:53 --------- d-----w C:\Program Files\NCH Swift Sound
2008-06-06 19:53 --------- d-----w C:\Documents and Settings\Owner\Application Data\NCH Swift Sound
2008-06-06 19:52 --------- d-----w C:\Documents and Settings\Owner\Application Data\Yahoo!
2008-06-06 19:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-06-06 19:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Software
2008-06-06 19:51 --------- d-----w C:\Program Files\Common Files\Real
2008-06-06 19:51 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-06 19:50 --------- d-----w C:\Program Files\Winferno
2008-06-06 19:50 --------- d-----w C:\Program Files\UltraMixer
2008-06-06 19:50 --------- d-----w C:\Program Files\Mixxx
2008-06-06 19:50 --------- d-----w C:\Program Files\BearShare Applications
2008-06-06 19:50 --------- d-----w C:\Program Files\AVS4YOU
2008-06-06 19:47 --------- d-----w C:\Program Files\ICQ6
2008-06-06 19:47 --------- d-----w C:\Program Files\Astonsoft
2008-06-06 19:46 --------- d-----w C:\Program Files\Smart PC Solutions
2008-06-06 19:46 --------- d-----w C:\Program Files\PC Registry Cleaner
2008-06-06 19:46 --------- d-----w C:\Program Files\Exo Adult
2008-06-06 19:46 --------- d-----w C:\Documents and Settings\Owner\Application Data\Smart PC Solutions
2008-06-06 19:21 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-06-04 12:53 57,632 ----a-w C:\SPC220NC.DAT
2008-06-01 12:16 --------- d-----w C:\Documents and Settings\Owner\Application Data\BearShare
2008-05-09 19:33 --------- d-----w C:\Program Files\Philips
2008-05-09 19:33 --------- d-----w C:\Program Files\ArcSoft
2008-05-08 17:09 8,464 ----a-w C:\WINDOWS\system32\sporder.dll
2008-05-08 15:30 675,328 ----a-w C:\WINDOWS\isRS-000.tmp
2008-05-08 15:30 --------- d-----w C:\Program Files\SoftwareClub.ws
2008-05-08 12:14 203,008 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 04:55 1,288,192 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-24 03:16 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:40 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 07:39 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-03-26 08:09 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-26 08:09 151,583 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-25 15:20 219,936 ----a-w C:\WINDOWS\system32\msltus40.dll
2008-03-25 15:20 219,936 ------w C:\WINDOWS\system32\dllcache\msltus40.dll
2008-03-06 19:27 13,123 ----a-w C:\Documents and Settings\Smart PC\unins000.dat
2008-03-06 19:26 673,553 ----a-w C:\Documents and Settings\Smart PC\unins000.exe
2008-03-04 19:44 261,896 ----a-w C:\Documents and Settings\Owner\Application Data\setup_en[1].exe
2008-02-28 18:58 11,915,264 ----a-w C:\Documents and Settings\Smart PC\SmartPC.exe
2008-02-28 18:01 360,448 ----a-w C:\Documents and Settings\Smart PC\SmartPCSchedule.exe
2008-01-11 15:39 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2007-11-16 00:13 212,992 ----a-w C:\Documents and Settings\Smart PC\SmartPCBoost.exe
2007-03-01 22:00 53,248 ----a-w C:\Documents and Settings\Smart PC\SmartPC.dll
2007-01-23 21:54 152,064 ----a-w C:\Documents and Settings\Smart PC\Uninst.exe
.
((((((((((((((((((((((((((((( snapshot_2008-06-19_ 7.39.54.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-19 12:34:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-20 00:19:12 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2005-10-21 01:02:28 163,328 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-20 19:02:28 163,328 ----a-w C:\WINDOWS\ERDNT\Hiv-backup\ERDNT.EXE
- 2000-08-31 13:00:00 28,160 ----a-w C:\WINDOWS\Nircmd.exe
+ 2000-08-31 07:00:00 28,160 ----a-w C:\WINDOWS\Nircmd.exe
- 2000-08-31 13:00:00 161,792 ----a-w C:\WINDOWS\swreg.exe
+ 2000-08-31 07:00:00 161,792 ----a-w C:\WINDOWS\swreg.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 07:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2005-06-01 09:04 700416]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 18:34 5724184]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-01-23 18:23 3497984]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-05-30 21:54 21718312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"snpstd3"="C:\WINDOWS\vsnpstd3.exe" [2006-09-19 16:07 827392]
"Realtime Audio Engine"="mmrtkrnl.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 10:28 144784]
"Broadbandadvisor.exe"="C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2007-08-08 00:49 2061552]
"PCguard"="C:\Program Files\Virgin Broadband\PCguard\Rps.exe" [2007-09-05 20:10 310000]
"-FreedomNeedsReboot"="C:\Program Files\Virgin Broadband\PCguard\ZkRunOnceR.exe" [2007-09-05 20:10 13552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunOnce]
"WIAWizardMenu"="C:\WINDOWS\system32\sti_ci.dl l" [2004-08-12 07:00 136704]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-04-23 05:16 124928 C:\WINDOWS\system32\advpack.dll]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
TrayMin220.lnk - C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe [2008-05-09 20:33:08 278528]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Zapu\\Zapu\\wDivi.exe"=
"C:\\Program Files\\VirtualDJ\\virtualdj.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2007-10-12 15:34]
S2 NwSapAgent;SAP Agent;C:\WINDOWS\system32\svchost.exe [2004-08-12 07:00]
S3 Radialpoint Security Services;Virgin Broadband PCguard;C:\WINDOWS\system32\dllhost.exe [2004-08-12 07:00]
S3 SPC220NC;Philips SPC220NC Webcam;C:\WINDOWS\system32\DRIVERS\SPC220NC.SYS [2007-01-09 23:59]
.
Contents of the 'Scheduled Tasks' folder
"2008-06-20 08:27:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-06-20 00:19:21 C:\WINDOWS\Tasks\PCConfidential.job"
- C:\Program Files\Winferno\PC Confidential\PCConfidential.exe
"2008-06-20 08:00:00 C:\WINDOWS\Tasks\rpc.job"
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean. exe
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-20 09:54:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-06-20 9:56:13
ComboFix-quarantined-files.txt 2008-06-20 08:55:55
ComboFix2.txt 2008-06-20 00:30:00
ComboFix3.txt 2008-06-20 00:00:02
ComboFix4.txt 2008-06-19 12:40:17
ComboFix5.txt 2008-06-19 10:33:53
Pre-Run: 52,969,529,344 bytes free
Post-Run: 52,958,900,224 bytes free
241 --- E O F --- 2008-06-19 10:36:17