Man, was that scary!!! All those warnings of 1/100 PCs crash using it and then it taking 2 1/2 hours(THE THING SAID 10 MINS!!! waaaaaaaaaah). PS, after running CF and SDFix, Vfinder.exe, CF23135.exe, cmd.exe, and C:\$Mft show up as corrupt... anyway...
ComboFix 08-06-19.2 - b 2008-06-20 1:43:57.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.227 [GMT -5:00]
Running from: C:\Documents and Settings\b\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\b\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Temp\abW9
C:\Temp\fse
C:\temp\iee
C:\WINDOWS\BM73507e2f.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\AceMonmp.ini
C:\WINDOWS\system32\AceMonmp.ini2
C:\WINDOWS\system32\dgdgatmu.ini2
C:\WINDOWS\system32\dgdgatmu.tmp
C:\WINDOWS\system32\iifedaYo.dll
C:\WINDOWS\system32\ilropbkt.ini
C:\WINDOWS\system32\kytnumej.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pmnoMecA.dll
C:\WINDOWS\system32\tkbporli.dll
C:\WINDOWS\system32\utnqmhrw.dll
C:\WINDOWS\system32\vhmuirnv.dll
C:\WINDOWS\system32\vnriumhv.ini
C:\WINDOWS\system32\watetuce.dll
C:\WINDOWS\system32\wvUllmMg.dll
C:\WINDOWS\system32\WxbJkUvw.ini
C:\WINDOWS\system32\WxbJkUvw.ini2
.
((((((((((((((((((((((((( Files Created from 2008-05-20 to 2008-06-20 )))))))))))))))))))))))))))))))
.
2008-06-20 01:22 . 2008-06-20 01:24 <DIR> d-------- C:\Documents and Settings\b\Application Data\Yahoo!
2008-06-20 00:25 . 2006-05-26 00:59 <DIR> d-------- C:\Documents and Settings\b\Application Data\Symantec
2008-06-20 00:25 . 2008-06-20 00:27 <DIR> d-------- C:\Documents and Settings\b\Application Data\Gtek
2008-06-20 00:25 . 2008-06-20 00:25 <DIR> d-------- C:\Documents and Settings\b
2008-06-20 00:17 . 2008-06-20 00:17 <DIR> d-------- C:\SDFix
2008-06-19 22:16 . 2008-06-19 22:16 80,384 --a------ C:\WINDOWS\system32\umtagdgd.dll
2008-06-19 22:13 . 2008-06-19 22:13 90,112 --a------ C:\WINDOWS\system32\hcfjomiy.dll
2008-06-19 15:02 . 2008-06-19 15:02 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-19 11:23 . 2008-06-19 11:23 <DIR> d-------- C:\Documents and Settings\Administrator\.java
2008-06-19 03:40 . 2008-06-19 15:01 <DIR> d-------- C:\Program Files\CCleaner
2008-06-19 02:26 . 2004-08-04 00:56 116,224 --a------ C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2008-06-19 02:24 . 2001-08-17 13:28 771,581 --a------ C:\WINDOWS\system32\dllcache\winacisa.sys
2008-06-19 02:23 . 2001-08-17 13:28 604,253 --a------ C:\WINDOWS\system32\dllcache\vmodem.sys
2008-06-19 02:22 . 2001-08-17 13:28 794,654 --a------ C:\WINDOWS\system32\dllcache\usr1801.sys
2008-06-19 02:21 . 2001-08-17 22:36 216,064 --a------ C:\WINDOWS\system32\dllcache\um34scan.dll
2008-06-19 02:20 . 2001-08-17 22:36 525,568 --a------ C:\WINDOWS\system32\dllcache\tridxp.dll
2008-06-19 02:19 . 2004-08-04 05:00 571,392 --a------ C:\WINDOWS\system32\dllcache\tintlgnt.ime
2008-06-19 02:18 . 2001-08-17 14:56 172,768 --a------ C:\WINDOWS\system32\dllcache\t2r4disp.dll
2008-06-19 02:17 . 2001-08-17 12:18 285,760 --a------ C:\WINDOWS\system32\dllcache\stlnata.sys
2008-06-19 02:17 . 2001-08-17 22:36 114,688 --a------ C:\WINDOWS\system32\dllcache\sonypi.dll
2008-06-19 02:17 . 2001-08-17 22:36 106,584 --a------ C:\WINDOWS\system32\dllcache\spdports.dll
2008-06-19 02:17 . 2004-08-04 05:00 101,376 --a------ C:\WINDOWS\system32\dllcache\srusbusd.dll
2008-06-19 02:17 . 2001-08-17 22:36 99,328 --a------ C:\WINDOWS\system32\dllcache\srusd.dll
2008-06-19 02:17 . 2001-08-17 13:51 61,824 --a------ C:\WINDOWS\system32\dllcache\speed.sys
2008-06-19 02:17 . 2001-08-17 12:11 48,736 --a------ C:\WINDOWS\system32\dllcache\srwlnd5.sys
2008-06-19 02:17 . 2001-08-17 12:51 37,040 --a------ C:\WINDOWS\system32\dllcache\sonypi.sys
2008-06-19 02:17 . 2001-08-17 22:36 24,660 --a------ C:\WINDOWS\system32\dllcache\spxupchk.dll
2008-06-19 02:17 . 2001-08-17 13:51 16,896 --a------ C:\WINDOWS\system32\dllcache\stcusb.sys
2008-06-19 02:17 . 2001-08-17 13:56 7,552 --a------ C:\WINDOWS\system32\dllcache\sonypvu1.sys
2008-06-19 02:15 . 2004-08-03 22:41 404,990 --a------ C:\WINDOWS\system32\dllcache\slntamr.sys
2008-06-19 02:14 . 2001-08-17 22:36 386,560 --a------ C:\WINDOWS\system32\dllcache\sgiul50.dll
2008-06-19 02:13 . 2001-08-17 22:36 495,616 --a------ C:\WINDOWS\system32\dllcache\sblfx.dll
2008-06-19 02:12 . 2004-08-04 00:56 397,056 --a------ C:\WINDOWS\system32\dllcache\s3gnb.dll
2008-06-19 02:11 . 2001-08-17 13:28 899,146 --a------ C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-06-19 02:10 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\dllcache\ptpusd.dll
2008-06-19 02:09 . 2004-08-04 00:56 363,520 --a------ C:\WINDOWS\system32\dllcache\psisdecd.dll
2008-06-19 02:03 . 2004-08-04 05:00 482,304 --a------ C:\WINDOWS\system32\dllcache\pintlgnt.ime
2008-06-19 02:02 . 2001-08-17 14:05 351,616 --a------ C:\WINDOWS\system32\dllcache\ovcodek2.sys
2008-06-19 02:01 . 2001-08-17 12:50 198,144 --a------ C:\WINDOWS\system32\dllcache\nv3.sys
2008-06-19 02:00 . 2001-08-17 12:11 128,000 --a------ C:\WINDOWS\system32\dllcache\n100325.sys
2008-06-19 01:59 . 2004-08-04 05:00 1,875,968 --a------ C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-06-19 01:58 . 2001-08-17 12:50 320,384 --a------ C:\WINDOWS\system32\dllcache\mgaum.sys
2008-06-19 01:57 . 2001-08-17 13:28 802,683 --a------ C:\WINDOWS\system32\dllcache\ltsm.sys
2008-06-19 01:56 . 2004-08-04 05:00 1,158,818 --a------ C:\WINDOWS\system32\dllcache\korwbrkr.lex
2008-06-19 01:55 . 2004-08-04 05:00 811,064 --a------ C:\WINDOWS\system32\dllcache\imjp81k.dll
2008-06-19 01:54 . 2004-08-04 00:56 702,845 --a------ C:\WINDOWS\system32\dllcache\i81xdnt5.dll
2008-06-19 01:53 . 2004-08-04 05:00 13,463,552 --a------ C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-06-19 01:52 . 2001-08-17 22:36 324,608 --a------ C:\WINDOWS\system32\dllcache\hpojwia.dll
2008-06-19 01:51 . 2001-08-17 14:56 1,733,120 --a------ C:\WINDOWS\system32\dllcache\g400d.dll
2008-06-19 01:50 . 2001-08-17 12:15 455,680 --a------ C:\WINDOWS\system32\dllcache\fus2base.sys
2008-06-19 01:49 . 2001-08-17 12:17 629,952 --a------ C:\WINDOWS\system32\dllcache\eqn.sys
2008-06-19 01:48 . 2001-08-17 13:28 634,134 --a------ C:\WINDOWS\system32\dllcache\el656ct5.sys
2008-06-19 01:47 . 2001-08-17 12:14 952,007 --a------ C:\WINDOWS\system32\dllcache\diwan.sys
2008-06-19 01:46 . 2001-08-17 22:36 419,357 --a------ C:\WINDOWS\system32\dllcache\dgconfig.dll
2008-06-19 01:45 . 2004-08-04 00:56 249,856 --a------ C:\WINDOWS\system32\dllcache\ctmasetp.dll
2008-06-19 01:44 . 2004-08-04 05:00 1,677,824 --a------ C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-06-19 01:43 . 2001-08-17 13:28 871,388 --a------ C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-06-19 01:42 . 2004-08-04 00:56 1,888,992 --a------ C:\WINDOWS\system32\dllcache\ati3duag.dll
2008-06-19 01:41 . 2001-08-17 13:28 762,780 --a------ C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-06-19 01:39 . 2003-03-24 16:52 32,827 --a------ C:\WINDOWS\system32\dllcache\tcptest.exe
2008-06-19 01:39 . 2003-03-24 16:52 20,536 --a------ C:\WINDOWS\system32\dllcache\shtml.dll
2008-06-19 01:39 . 2003-03-24 16:52 16,437 --a------ C:\WINDOWS\system32\dllcache\shtml.exe
2008-06-19 01:39 . 2003-03-24 16:52 16,384 --a------ C:\WINDOWS\system32\dllcache\tcptsat.dll
2008-06-19 01:38 . 2001-08-17 14:56 66,048 --a------ C:\WINDOWS\system32\dllcache\s3legacy.dll
2008-06-19 01:25 . 2003-03-24 16:52 188,480 --a------ C:\WINDOWS\system32\dllcache\cfgwiz.exe
2008-06-19 01:25 . 2003-03-24 16:52 20,540 --a------ C:\WINDOWS\system32\dllcache\author.dll
2008-06-19 01:25 . 2003-03-24 16:52 20,540 --a------ C:\WINDOWS\system32\dllcache\admin.dll
2008-06-19 01:25 . 2003-03-24 16:52 16,439 --a------ C:\WINDOWS\system32\dllcache\author.exe
2008-06-19 01:25 . 2003-03-24 16:52 16,439 --a------ C:\WINDOWS\system32\dllcache\admin.exe
2008-06-18 21:47 . 2008-06-19 01:22 <DIR> d-------- C:\WINDOWS\wt
2008-06-18 02:25 . 2008-06-18 21:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-16 14:43 . 2008-06-16 14:46 <DIR> d-------- C:\WINDOWS\system32\netrax01
2008-06-16 14:43 . 2008-06-16 14:43 <DIR> d-------- C:\Temp\itmp4
2008-06-13 01:55 . 2002-08-07 12:09 430,080 --a------ C:\WINDOWS\system32\cmcs21.ocx
2008-06-13 01:55 . 1998-06-24 00:00 103,744 --a------ C:\WINDOWS\system32\mscomm32.ocx
2008-06-13 01:55 . 1998-03-26 01:12 53,248 --a------ C:\WINDOWS\system32\zlib.dll
2008-06-13 00:32 . 2008-06-13 00:32 <DIR> d-------- C:\songs
2008-06-13 00:26 . 2008-06-13 00:26 <DIR> d-------- C:\Documents and Settings\Braondon\Application Data\fretsonfire
2008-06-13 00:16 . 2008-06-13 00:18 <DIR> d-------- C:\Program Files\Alarian
2008-06-12 18:24 . 2008-06-15 02:50 <DIR> d-------- C:\Documents and Settings\Braondon\Application Data\Hamachi
2008-06-12 16:04 . 2008-06-12 16:04 144 --a------ C:\Dark_Silence's private ro server tutorial with hamachi(and images!) - GamerzPlanet - For All Your Online Gaming Needs!!.URL
2008-06-12 15:44 . 2008-06-19 02:32 <DIR> d-------- C:\Program Files\Hamachi
2008-06-12 15:44 . 2008-06-12 15:49 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2008-06-12 15:40 . 2008-02-27 20:03 <DIR> d-------- C:\12255_eathena_stable_sql
2008-06-12 14:18 . 2008-06-12 15:12 <DIR> d-------- C:\Program Files\Macromedia
2008-06-12 14:18 . 2008-06-12 15:12 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2008-06-12 07:41 . 2008-06-12 07:41 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_C oinstaller_Critical.Wdf
2008-06-12 07:41 . 2008-06-12 07:41 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_xusb21_010 05.Wdf
2008-06-12 07:20 . 2008-06-12 07:20 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\fretsonfire
2008-06-10 18:29 . 2008-04-14 06:01 272,128 --a------ C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 18:29 . 2008-04-14 06:01 272,128 --a------ C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-01 01:27 . 2008-06-19 16:24 <DIR> d-------- C:\Documents and Settings\Braondon\Application Data\uTorrent
2008-05-27 22:57 . 2008-05-27 22:57 <DIR> d-------- C:\Documents and Settings\Braondon\Application Data\InstallShield Installation Information
2008-05-27 22:22 . 2008-06-08 00:57 <DIR> d-------- C:\Documents and Settings\Braondon\Application Data\LimeWire
2008-05-26 19:49 . 2008-05-26 19:58 <DIR> d-------- C:\Documents and Settings\Braondon\Application Data\Yahoo!
2008-05-24 02:25 . 2008-05-31 21:48 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-24 02:25 . 2008-05-24 02:25 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-24 01:39 . 2008-06-12 10:58 89 --a------ C:\WINDOWS\RCASMVVC.ini
2008-05-24 01:02 . 2008-05-24 01:02 <DIR> d-------- C:\Program Files\Sun
2008-05-24 01:01 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-24 00:56 . 2008-05-24 00:56 <DIR> d-------- C:\Program Files\Common Files\Java
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-06-20 07:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-19 07:33 --------- d-----w C:\Program Files\Graal
2008-06-16 19:04 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-08 02:23 --------- d-----w C:\Documents and Settings\Sydney\Application Data\Yahoo!
2008-05-24 06:01 --------- d-----w C:\Program Files\Java
2008-05-11 02:58 --------- d-----w C:\Documents and Settings\Braondon\Application Data\Talkback
2008-05-11 02:45 --------- d--h--w C:\Documents and Settings\Braondon\Application Data\Gtek
2008-05-10 05:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-10 05:54 --------- d-----w C:\Program Files\RCA
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 06:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-02 12:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-04-28 03:38 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-27 04:28 --------- d-----w C:\Documents and Settings\Guest\Application Data\fretsonfire
2008-04-26 15:44 --------- d-----w C:\Documents and Settings\Guest\Application Data\uTorrent
2007-11-08 03:26 88 --sh--r C:\WINDOWS\system32\F3A02192FC.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16 454784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-07-25 04:51 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 19:42 1404928]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-04-05 19:22 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-05 19:19 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.ex e" [2005-04-05 19:23 114688]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 03:12 94208]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 10:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 10:44 81920]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20 122940]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-05-26 01:07 169472]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-06-26 16:30 282624]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 10:24 16384]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 19:05 1117184]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 00:59 115816]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-01-14 02:11 771704]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-05-02 07:44 185896]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dmlang]
dmlang.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~ 1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Documents and Settings\\Guest\\Desktop\\utorrent.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Documents and Settings\\Guest\\Application Data\\MySpace\\IM\\bin\\MySpaceIM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"10386:TCP"= 10386:TCP:BitComet 10386 TCP
"10386:UDP"= 10386:UDP:BitComet 10386 UDP
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 10:23]
S3 npkycryp;npkycryp;C:\Program Files\Gravity\RO\npkycryp.sys []
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-05-27 01:00:00 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - FeAr.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-20 02:53:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
.
************************************************** ************************
.
Completion time: 2008-06-20 3:06:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-20 08:06:24
Pre-Run: 86,597,545,984 bytes free
Post-Run: 88,120,975,360 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOW S
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Micro soft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
254 --- E O F --- 2008-06-11 00:28:31
SDFix Report:
SDFix: Version 1.194
Run by Administrator on Fri 06/20/2008 at 03:26 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Folder C:\WINDOWS\system32\netrax01 - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-20 03:36:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\ system32\\LEXPPS.EXE:*

isabled:LEXPPS.EXE"
"C:\\Documents and Settings\\Guest\\Desktop\\utorrent.exe"="C:\\Docum ents and Settings\\Guest\\Desktop\\utorrent.exe:*

isabled: utorrent"
"C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS \\system32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\\Documents and Settings\\Guest\\Application Data\\MySpace\\IM\\bin\\MySpaceIM.exe"="C:\\Docume nts and Settings\\Guest\\Application Data\\MySpace\\IM\\bin\\MySpaceIM.exe:*

isabled:M ySpace Instant Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
Files with Hidden Attributes :
Wed 7 Jun 2006 88 A.SHR --- "C:\i386\F3A02192FC.sys"
Wed 7 Jun 2006 3,350 A.SH. --- "C:\i386\KGyGaAvL.sys"
Wed 7 Nov 2007 88 ..SHR --- "C:\WINDOWS\system32\F3A02192FC.sys"
Wed 2 Apr 2008 104 ..SHR --- "C:\WINDOWS\system32\FC9221A0F3.sys"
Wed 2 Apr 2008 5,852 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Mon 18 Jun 2007 177,152 A..H. --- "C:\Documents and Settings\Braondon\Desktop\utorrent.exe"
Mon 18 Jun 2007 177,152 A..H. --- "C:\Documents and Settings\Guest\Desktop\utorrent.exe"
Mon 26 May 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Fri 9 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\385cb67d da0ffd4dea8c0d990dc65796\BIT2C.tmp"
Thu 20 Mar 2008 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Thu 20 Mar 2008 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch6\lock.tmp"
Thu 20 Mar 2008 8 A..H. --- "C:\Documents and Settings\b\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp "
Fri 20 Jun 2008 8 A..H. --- "C:\Documents and Settings\b\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp "
Thu 20 Mar 2008 8 A..H. --- "C:\Documents and Settings\b\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp "
Thu 20 Mar 2008 8 A..H. --- "C:\Documents and Settings\Braondon\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp "
Sat 10 May 2008 8 A..H. --- "C:\Documents and Settings\Braondon\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp "
Thu 20 Mar 2008 8 A..H. --- "C:\Documents and Settings\Braondon\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp "
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp "
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp "
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp "
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp "
Thu 20 Mar 2008 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u5\lock.tmp "
Thu 20 Mar 2008 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u6\lock.tmp "
Tue 10 Apr 2007 8 A..H. --- "C:\Documents and Settings\Reve\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp "
Tue 10 Apr 2007 8 A..H. --- "C:\Documents and Settings\Reve\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp "
Mon 16 Apr 2007 8 A..H. --- "C:\Documents and Settings\Reve\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp "
Mon 16 Apr 2007 8 A..H. --- "C:\Documents and Settings\Reve\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp "
Thu 20 Mar 2008 8 A..H. --- "C:\Documents and Settings\Reve\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u5\lock.tmp "
Thu 20 Mar 2008 8 A..H. --- "C:\Documents and Settings\Reve\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u6\lock.tmp "
Fri 20 Apr 2007 8 A..H. --- "C:\Documents and Settings\Sydney\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp "
Fri 20 Apr 2007 8 A..H. --- "C:\Documents and Settings\Sydney\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp "
Fri 20 Apr 2007 8 A..H. --- "C:\Documents and Settings\Sydney\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp "
Fri 20 Apr 2007 8 A..H. --- "C:\Documents and Settings\Sydney\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp "
Thu 20 Mar 2008 8 A..H. --- "C:\Documents and Settings\Sydney\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u5\lock.tmp "
Thu 20 Mar 2008 8 A..H. --- "C:\Documents and Settings\Sydney\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u6\lock.tmp "
Finished!