A EVO GA I COMBO LOG:
ComboFix 08-02.05.3 - 5eul 2008-02-08 14:18:22.1 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.437 [GMT 1:00]
Running from: C:\Users\5eul\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\5.exe
C:\6.exe
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible infected sites -----
hxxp://www.download.windowsupdate.com
.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-05 03:01 . 2008-02-05 03:01 <DIR> d-------- C:\Program Files\Elaborate Bytes
2008-02-04 19:07 . 2008-02-04 19:07 <DIR> d-------- C:\Users\5eul\{7837d3a8-3f0b-4885-87ff-f1491baa733e}
2008-02-04 19:07 . 2002-07-12 09:33 1,581,056 --a------ C:\windows\mixer.exe
2008-02-04 19:07 . 2000-10-20 11:28 765,952 --a------ C:\windows\system\crlds3d.dll
2008-02-04 19:07 . 2001-11-23 05:08 712,704 --a------ C:\windows\System32\Audio3D.dll
2008-02-04 19:07 . 2002-07-16 03:58 379,726 --a------ C:\windows\System32\drivers\cmaudio.sys
2008-02-04 19:07 . 2002-07-11 04:24 139,264 --a------ C:\windows\cmuninst.exe
2008-02-04 19:07 . 2002-07-11 05:13 135,168 --a------ C:\windows\cmuninst.dat
2008-02-04 19:07 . 2002-07-16 14:47 36,924 --a------ C:\windows\cmijack.dat
2008-02-04 19:07 . 2002-03-29 07:52 32,768 --a------ C:\windows\System32\cmnprop.dll
2008-02-04 19:07 . 2002-07-16 13:33 20,333 --a------ C:\windows\cmaudio.dat
2008-02-04 17:46 . 2008-02-06 20:54 <DIR> d-------- C:\VundoFix Backups
2008-02-03 21:33 . 2008-02-03 21:33 8,704 --a------ C:\windows\System32\hcrstco.dll
2008-02-03 21:32 . 2008-02-03 21:32 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-02-03 20:45 . 2008-02-04 00:10 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-03 20:44 . 2007-11-05 17:22 690 --a------ C:\windows\win.tmp
2008-02-03 20:44 . 2007-09-07 00:15 250 --a------ C:\windows\system.tmp
2008-02-03 20:41 . 2008-02-03 20:41 <DIR> d-------- C:\Users\5eul\AppData\Roaming\PC Tools
2008-02-03 18:01 . 2008-02-03 18:01 512,096 --a------ C:\windows\System32\drivers\amon.sys
2008-02-03 18:01 . 2008-02-03 18:01 298,104 --a------ C:\windows\System32\imon.dll
2008-02-03 18:01 . 2008-02-03 18:00 15,424 --a------ C:\windows\System32\drivers\nod32drv.sys
2008-02-02 23:44 . 2008-02-02 23:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-02 21:28 . 2008-02-02 21:28 <DIR> d-------- C:\windows\System32\ZoneLabs
2008-02-02 21:28 . 2007-11-16 19:31 <DIR> d-------- C:\windows\Internet Logs
2008-02-02 21:28 . 2008-02-02 21:28 <DIR> d-------- C:\Program Files\Zone Labs
2008-02-02 21:28 . 2008-02-02 21:28 31,547 --ah----- C:\windows\System32\vsconfig.xml
2008-02-02 21:12 . 2008-02-02 21:12 374,456 --a------ C:\windows\System32\mcupdate_GenuineIntel.dll
2008-02-02 21:11 . 2008-02-02 21:11 2,605,568 --a------ C:\windows\System32\SLsvc.exe
2008-02-02 21:11 . 2008-02-02 21:11 566,784 --a------ C:\windows\System32\SLCommDlg.dll
2008-02-02 21:11 . 2008-02-02 21:11 351,232 --a------ C:\windows\System32\SLUI.exe
2008-02-02 21:11 . 2008-02-02 21:11 268,288 --a------ C:\windows\System32\mcbuilder.exe
2008-02-02 21:11 . 2008-02-02 21:11 223,232 --a------ C:\windows\System32\SLC.dll
2008-02-02 21:11 . 2008-02-02 21:11 186,368 --a------ C:\windows\System32\SLLUA.exe
2008-02-02 21:11 . 2008-02-02 21:11 57,856 --a------ C:\windows\System32\SLUINotify.dll
2008-02-02 21:11 . 2008-02-02 21:11 39,936 --a------ C:\windows\System32\slcinst.dll
2008-02-02 21:11 . 2008-02-02 21:11 33,280 --a------ C:\windows\System32\slwmi.dll
2008-02-02 21:11 . 2008-02-02 21:11 11,776 --a------ C:\windows\System32\sbunattend.exe
2008-02-02 03:06 . 2008-02-02 03:06 414,208 --a------ C:\windows\System32\msscp.dll
2008-02-02 03:05 . 2008-02-02 03:05 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-02-02 03:02 . 2008-02-02 03:02 3,504,824 --a------ C:\windows\System32\ntkrnlpa.exe
2008-02-02 03:02 . 2008-02-02 03:02 3,470,520 --a------ C:\windows\System32\ntoskrnl.exe
2008-02-02 03:02 . 2008-02-02 03:02 130,048 --a------ C:\windows\System32\drivers\srv2.sys
2008-02-02 03:02 . 2008-02-02 03:02 101,888 --a------ C:\windows\System32\drivers\mrxsmb.sys
2008-02-02 03:02 . 2008-02-02 03:02 84,992 --a------ C:\windows\System32\drivers\srvnet.sys
2008-02-02 03:02 . 2008-02-02 03:02 58,368 --a------ C:\windows\System32\drivers\mrxsmb20.sys
2008-02-02 03:01 . 2008-02-02 03:01 2,048 --a------ C:\windows\System32\tzres.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-06 23:41 --------- d-----w C:\Program Files\Windows Defender
2008-02-06 19:48 --------- d-----w C:\Program Files\SpeedFan
2008-02-06 19:47 --------- d-----w C:\Program Files\TrojanHunter 4.1
2008-02-06 19:37 --------- d-----w C:\Program Files\Crystal Player
2008-02-06 19:35 174 --sha-w C:\Program Files\desktop.ini
2008-02-06 19:17 --------- d-----w C:\Program Files\Spyware Doctor
2008-02-05 02:03 --------- d-----w C:\Program Files\SlySoft
2008-02-04 18:34 --------- d-----w C:\Program Files\Native Instruments
2008-02-03 22:24 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-02-03 17:29 --------- d-----w C:\Program Files\ESET
2008-02-03 17:00 --------- d-----w C:\Program Files\MSN Messenger
2008-02-02 20:11 --------- d-----w C:\Program Files\Windows Sidebar
2008-02-02 03:15 --------- d-----w C:\Program Files\Windows Mail
2008-02-02 02:01 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-02-01 17:47 --------- d-----w C:\Program Files\Gigabyte
2008-01-27 16:47 --------- d-----w C:\Program Files\everestultimate_build_1120_sqdkp3nm7xc
2007-11-25 17:26 819,200 ----a-w C:\windows\is-4C0P6.exe
2007-11-20 15:04 1,523,536 ----a-w C:\windows\FP_AX_CAB_INSTALLER.exe
2007-11-13 12:26 87,608 ----a-w C:\Users\5eul\AppData\Roaming\ezpinst.exe
2007-11-13 12:26 47,360 ----a-w C:\Users\5eul\AppData\Roaming\pcouffin.sys
2007-11-11 22:32 45,056 ----a-w C:\windows\NCUNINST.EXe
2007-11-11 22:32 40,960 ----a-w C:\windows\NCLAUNCH.EXe
2006-11-29 16:41 400 -c--a-w C:\Users\5eul\score.dat
2007-11-02 18:35 56 --sh--r C:\windows\System32\A75CBCF84A.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{13416D70-8111-4208-8DEA-63918477C68D}]
C:\windows\system32\jkhfg.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-02 21:11 1232896]
"DVDXGhost"="C:\Program Files\DVD X Studios\DVD X Utilities 2.1\DVDGhost\DVDGhost.EXE" [2006-01-18 14:59 1552384]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 16:30 249856]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2007-11-21 00:59 1625024]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2006-02-18 18:41 1992928]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"EVEREST AutoStart"="C:\Program Files\everestultimate_build_1120_sqdkp3nm7xc\everest.exe" [2007-09-04 17:28 2014816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sleepy"="C:\Users\5eul\Desktop\sleepy\sleepy.exe" [2001-07-23 21:48 94208]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-02-03 18:01 949376]
"C-Media Mixer"="Mixer.exe" [2002-07-12 09:33 1581056 C:\windows\mixer.exe]
"MSServer"="C:\windows\system32\jkkhiif.dll" [ ]
"THGuard"="C:\Program Files\TrojanHunter 4.1\THGuard.exe" [2004-12-22 11:51 1071616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2006-02-18 18:41 1992928]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{569DAC0F-2791-46ab-8EFC-A54B77C04C20}"= C:\Program Files\DVD X Studios\DVD X Utilities 2.1\DVDGhost\ExecuteHooker.dll [2005-11-14 14:10 90112]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program Files\Qualcomm\Eudora\EuShlExt.dll [ ]
S1 UBHelper;UBHelper;C:\windows\system32\drivers\UBHelper.sys [2004-12-17 17:14]
S2 27937;27937;C:\windows\system32\27937.sys [2006-12-22 22:44]
S2 LrWdm;Video Wonder Series PnP Controller;C:\windows\system32\Drivers\Lr25Wdm.sys [2000-05-25 11:00]
S2 Prvflder;Prvflder;C:\windows\system32\DRIVERS\prvflder.sys [2006-04-21 08:22]
S3 BT848;Video Wonder Pro II V2 WDM Video Capture;C:\windows\system32\drivers\BT848.sys [2002-04-01 11:00]
S3 BTTUNER;Video Wonder Pro II V2 WDM TvTuner;C:\windows\system32\drivers\BTTUNER.sys [2002-04-01 11:00]
S3 BTXBAR;Video Wonder Pro II V2 WDM Crossbar;C:\windows\system32\drivers\BTXBAR.sys [2002-04-01 11:00]
S3 Cap7134;Video Wonder Pro III WDM Video Capture;C:\windows\system32\DRIVERS\Cap7134.sys [2002-03-26 11:00]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;C:\Program Files\everestultimate_build_1120_sqdkp3nm7xc\kerneld.wnt [2007-08-19 13:38]
S3 GAGPDrv;GAGPDrv;C:\windows\system32\drivers\GAGPDrv.sys [2003-05-30 12:04]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\windows\system32\DRIVERS\yk60x86.sys [2007-12-06 09:51]
S4 usbprint;Microsoft USB PRINTER Class;C:\windows\system32\drivers\usbprint.sys [2006-11-02 10:14]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
rsmsvcs REG_MULTI_SZ ntmssvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c6c7b3bb-56f9-11dc-89ac-806e6f6e6963}]
\shell\AutoRun\command - D:\ASUSACPI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {BF35267B-8DF2-FEBF-ECE7-9D6CF8227273} /qb
.
Contents of the 'Scheduled Tasks' folder
"2008-02-06 19:08:32 C:\windows\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-06 19:01:00 C:\windows\Tasks\User_Feed_Synchronization-{43CA5BDC-267B-491B-8632-E0A6AF9074E3}.job"
- C:\windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-08 14:34:52
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2008-02-08 14:39:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-08 13:39:06
.
2008-02-06 18:56:17 --- E O F ---