View Single Post
Old 06-26-2007, 12:52 AM   #10 (permalink)
Sillybear
Registered User
 
Join Date: Jun 2007
Posts: 6
OS: XP


Re: Malware Possibly...Need Help.

I'm sorry if I'm making this difficult, I really appreciate your help.

"Administrator" - 2007-06-25 23:47:28 - ComboFix 07-06-25.3 - Service Pack 1 NTFS


((((((((((((((((((((((((( Files Created from 2007-05-26 to 2007-06-26 )))))))))))))))))))))))))))))))


2007-06-25 03:06 <DIR> d---s---- C:\DOCUME~1\ADMINI~1\UserData
2007-06-25 03:06 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-06-25 02:17 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-12 19:23 <DIR> d-------- C:\Program Files\Teamspeak2_RC2
2007-06-12 19:23 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\teamspeak2
2007-06-06 17:52 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-06-06 17:14 98,816 --a------ C:\WINDOWS\system32\dmstyle.dll
2007-06-06 17:14 974,848 --a------ C:\WINDOWS\system32\dxdiag.exe
2007-06-06 17:14 83,968 --a------ C:\WINDOWS\system32\drivers\nabtsfec.sys
2007-06-06 17:14 80,896 --a------ C:\WINDOWS\system32\dpvsetup.exe
2007-06-06 17:14 8,192 --a------ C:\WINDOWS\system32\d3d8thk.dll
2007-06-06 17:14 797,184 --a------ C:\WINDOWS\system32\d3dim700.dll
2007-06-06 17:14 79,360 --a------ C:\WINDOWS\system32\dpwsockx.dll
2007-06-06 17:14 77,824 --a------ C:\WINDOWS\system32\dpmodemx.dll
2007-06-06 17:14 76,800 --a------ C:\WINDOWS\system32\dmscript.dll
2007-06-06 17:14 733,184 --a------ C:\WINDOWS\system32\qedwipes.dll
2007-06-06 17:14 723,968 --a------ C:\WINDOWS\system32\dpnet.dll
2007-06-06 17:14 7,424 --a------ C:\WINDOWS\system32\drivers\mskssrv.sys
2007-06-06 17:14 68,096 --a------ C:\WINDOWS\system32\dpnhupnp.dll
2007-06-06 17:14 64,512 --a------ C:\WINDOWS\system32\amstream.dll
2007-06-06 17:14 602,624 --a------ C:\WINDOWS\system32\dx7vb.dll
2007-06-06 17:14 58,368 --a------ C:\WINDOWS\system32\dmcompos.dll
2007-06-06 17:14 52,096 --a------ C:\WINDOWS\system32\drivers\msdv.sys
2007-06-06 17:14 5,504 --a------ C:\WINDOWS\system32\drivers\mstee.sys
2007-06-06 17:14 5,248 --a------ C:\WINDOWS\system32\drivers\mspclock.sys
2007-06-06 17:14 491,520 --a------ C:\WINDOWS\system32\dsdmoprp.dll
2007-06-06 17:14 48,512 --a------ C:\WINDOWS\system32\drivers\stream.sys
2007-06-06 17:14 470,528 --a------ C:\WINDOWS\system32\qdvd.dll
2007-06-06 17:14 47,104 --a------ C:\WINDOWS\system32\wstdecod.dll
2007-06-06 17:14 46,592 --a------ C:\WINDOWS\system32\dxdllreg.exe
2007-06-06 17:14 4,608 --a------ C:\WINDOWS\system32\drivers\mspqm.sys
2007-06-06 17:14 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-06-06 17:14 4,096 --a------ C:\WINDOWS\system32\drivers\swenum.sys
2007-06-06 17:14 381,952 --a------ C:\WINDOWS\system32\dsound.dll
2007-06-06 17:14 381,952 --a------ C:\WINDOWS\system32\dpvoice.dll
2007-06-06 17:14 354,816 --a------ C:\WINDOWS\system32\psisdecd.dll
2007-06-06 17:14 34,304 --a------ C:\WINDOWS\system32\mciqtz32.dll
2007-06-06 17:14 33,280 --a------ C:\WINDOWS\system32\dmloader.dll
2007-06-06 17:14 324,096 --a------ C:\WINDOWS\system32\mswebdvd.dll
2007-06-06 17:14 32,768 --a------ C:\WINDOWS\system32\dpnhpast.dll
2007-06-06 17:14 316,928 --a------ C:\WINDOWS\system32\qdv.dll
2007-06-06 17:14 3,072 --a------ C:\WINDOWS\system32\dpnlobby.dll
2007-06-06 17:14 3,072 --a------ C:\WINDOWS\system32\dpnaddr.dll
2007-06-06 17:14 292,864 --a------ C:\WINDOWS\system32\ddraw.dll
2007-06-06 17:14 28,160 --a------ C:\WINDOWS\system32\dplaysvr.exe
2007-06-06 17:14 27,136 --a------ C:\WINDOWS\system32\dmband.dll
2007-06-06 17:14 257,024 --a------ C:\WINDOWS\system32\qcap.dll
2007-06-06 17:14 24,064 --a------ C:\WINDOWS\system32\ddrawex.dll
2007-06-06 17:14 230,400 --a------ C:\WINDOWS\system32\dplayx.dll
2007-06-06 17:14 19,968 --a------ C:\WINDOWS\system32\dpvacm.dll
2007-06-06 17:14 186,880 --a------ C:\WINDOWS\system32\dsdmo.dll
2007-06-06 17:14 181,248 --a------ C:\WINDOWS\system32\dmime.dll
2007-06-06 17:14 18,944 --a------ C:\WINDOWS\system32\encapi.dll
2007-06-06 17:14 18,688 --a------ C:\WINDOWS\system32\drivers\wstcodec.sys
2007-06-06 17:14 18,432 --a------ C:\WINDOWS\system32\dswave.dll
2007-06-06 17:14 16,896 --a------ C:\WINDOWS\system32\msyuv.dll
2007-06-06 17:14 16,896 --a------ C:\WINDOWS\system32\dpnsvr.exe
2007-06-06 17:14 16,384 --a------ C:\WINDOWS\system32\drivers\ccdecode.sys
2007-06-06 17:14 15,104 --a------ C:\WINDOWS\system32\drivers\mpe.sys
2007-06-06 17:14 14,976 --a------ C:\WINDOWS\system32\drivers\streamip.sys
2007-06-06 17:14 132,608 --a------ C:\WINDOWS\system32\devenum.dll
2007-06-06 17:14 130,304 --a------ C:\WINDOWS\system32\drivers\ks.sys
2007-06-06 17:14 13,312 --a------ C:\WINDOWS\system32\msdmo.dll
2007-06-06 17:14 122,880 --a------ C:\WINDOWS\system32\dmusic.dll
2007-06-06 17:14 112,128 --a------ C:\WINDOWS\system32\dpvvox.dll
2007-06-06 17:14 11,392 --a------ C:\WINDOWS\system32\drivers\bdasup.sys
2007-06-06 17:14 100,864 --a------ C:\WINDOWS\system32\dmsynth.dll
2007-06-06 17:14 10,880 --a------ C:\WINDOWS\system32\drivers\slip.sys
2007-06-06 17:14 10,112 --a------ C:\WINDOWS\system32\drivers\ndisip.sys
2007-06-06 17:14 1,962,496 --a------ C:\WINDOWS\system32\quartz.dll
2007-06-06 17:14 1,798,144 --a------ C:\WINDOWS\system32\qedit.dll
2007-06-06 17:14 1,769,472 --a------ C:\WINDOWS\system32\dxdiagn.dll
2007-06-06 17:14 1,703,936 --a------ C:\WINDOWS\system32\d3d9.dll
2007-06-06 17:14 1,294,336 --a------ C:\WINDOWS\system32\dsound3d.dll
2007-06-06 17:14 1,230,336 --a------ C:\WINDOWS\system32\msvidctl.dll
2007-06-06 17:14 1,201,152 --a------ C:\WINDOWS\system32\d3d8.dll
2007-06-06 17:14 1,189,888 --a------ C:\WINDOWS\system32\dx8vb.dll
2007-06-06 15:57 <DIR> d-------- C:\Program Files\Steam


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-24 23:50:28 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\uTorrent
2007-06-20 22:48:01 -------- d-----w C:\Program Files\StepMania
2007-06-16 08:48:56 3,436 ----a-w C:\WINDOWS\system32\tmp.reg
2007-06-14 21:26:47 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
2007-05-04 08:33:43 11,812,063 ------w C:\AVG7QT.DAT
2007-04-29 17:39:46 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2007-04-28 00:53:55 17,448 ----a-w C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
2007-04-21 05:29:04 1,807 ----a-w C:\WINDOWS\mozver.dat
2007-04-19 21:14:14 208,896 ----a-w C:\WINDOWS\system32\nvudisp.exe
2007-04-19 20:26:00 888,832 ----a-w C:\WINDOWS\system32\nvmobls.dll
2007-04-19 20:26:00 86,016 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-04-19 20:26:00 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-04-19 20:26:00 794,624 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-04-19 20:26:00 7,700,480 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-04-19 20:26:00 581,632 ----a-w C:\WINDOWS\system32\nvhwvid.dll
2007-04-19 20:26:00 5,644,288 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-04-19 20:26:00 5,619,712 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-04-19 20:26:00 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll
2007-04-19 20:26:00 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-04-19 20:26:00 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2007-04-19 20:26:00 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2007-04-19 20:26:00 4,543,616 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-04-19 20:26:00 35,840 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-04-19 20:26:00 35,840 ----a-w C:\WINDOWS\system32\nvcod.dll
2007-04-19 20:26:00 311,296 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-04-19 20:26:00 3,035,136 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-04-19 20:26:00 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-04-19 20:26:00 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-04-19 20:26:00 212,992 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-04-19 20:26:00 2,924,544 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-04-19 20:26:00 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll
2007-04-19 20:26:00 159,810 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2007-04-19 20:26:00 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe
2007-04-19 20:26:00 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-04-19 20:26:00 1,626,112 ----a-w C:\WINDOWS\system32\nwiz.exe
2007-04-19 20:26:00 1,474,560 ----a-w C:\WINDOWS\system32\nview.dll
2007-04-19 20:26:00 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe
2007-04-19 20:26:00 1,236,992 ----a-w C:\WINDOWS\system32\nvwss.dll
2007-04-19 20:26:00 1,019,904 ----a-w C:\WINDOWS\system32\nvwimg.dll
2007-04-19 20:26:00 1,011,712 ----a-w C:\WINDOWS\system32\nvcpluir.dll
2007-04-10 03:04:00 516,608 ----a-w C:\WINDOWS\system32\winlogon.exe
2007-04-10 02:52:06 8,192 ----a-w C:\WINDOWS\system32\resetwpa.reg


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 02:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe" [2006-09-28 22:56]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe" [2007-02-06 17:30]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 16:07]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 11:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-02 16:24]
"nwiz"="nwiz.exe" [2007-04-19 13:26 C:\WINDOWS\system32\nwiz.exe]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39]


Contents of the 'Scheduled Tasks' folder
2007-06-25 15:22:00 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-25 23:48:27
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-06-25 23:48:38
C:\ComboFix-quarantined-files.txt ... 2007-06-25 23:48
C:\ComboFix3.txt ... 2007-06-25 02:20

--- E O F ---
Sillybear is offline