Combo fix log file
"NB" - 2007-05-16 22:46:00 Service Pack 1
ComboFix 07-05.09.V - Running from: "C:\Documents and Settings\NB\Desktop\"
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-16 ))))))))))))))))))))))))))))))))))
2007-05-16 05:31 9,416 --a------ C:\dnsbak.reg
2007-05-15 06:26 <DIR> d-------- C:\Program Files\SkillSoft
2007-05-11 18:36 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-05-10 09:19 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-05-08 21:17 67,167 --a------ C:\WINDOWS\system32\drivers\hsf_bsc2.sys
2007-05-08 21:17 50,751 --a------ C:\WINDOWS\system32\drivers\hsf_tone.sys
2007-05-08 21:17 488,383 --a------ C:\WINDOWS\system32\drivers\hsf_v124.sys
2007-05-08 21:17 44,863 --a------ C:\WINDOWS\system32\drivers\hsf_soar.sys
2007-05-07 10:41 397,312 -ra------ C:\WINDOWS\system32\ZSHP1020.EXE
2007-05-07 10:41 106,496 -ra------ C:\WINDOWS\system32\VSHP1020.DLL
2007-05-07 10:40 86,016 -ra------ C:\WINDOWS\system32\ZLhp1020.DLL
2007-05-07 07:29 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
2007-05-02 06:05 83,208 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-05-02 06:05 82,136 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-04-23 09:42 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-04-23 09:42 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-04-23 09:42 <DIR> d-------- C:\Program Files\Xvid
2007-04-23 09:40 <DIR> d-------- C:\DOCUME~1\NB\APPLIC~1\DivX
2007-04-22 21:56 <DIR> d-------- C:\Program Files\Google
2007-04-22 09:28 <DIR> d-------- C:\Program Files\Windows FTP key
2007-04-22 09:21 <DIR> d-------- C:\WINDOWS\system32\lrdaiqrs
2007-04-22 09:18 54,272 --a------ C:\WINDOWS\system32\zstgtazo.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-08 10:44:15 -------- d-----w C:\DOCUME~1\NB\APPLIC~1\Canon
2007-05-03 09:36:48 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-05-01 20:35:51 -------- d-----w C:\Program Files\Norton SystemWorks
2007-05-01 20:12:30 -------- d-----w C:\Program Files\Symantec
2007-04-22 23:38:41 -------- d-----w C:\Program Files\DivX
2007-04-01 19:36:04 -------- d-----w C:\DOCUME~1\NB\APPLIC~1\Uniblue
2007-03-27 07:55:57 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-03-27 07:55:48 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-03-27 07:55:32 2,560 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-03-27 07:55:32 2,432 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-03-27 07:55:31 36,624 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-03-27 07:55:31 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-03-27 07:55:31 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-03-27 07:55:31 116,472 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-03-27 07:55:23 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-03-27 07:55:23 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-03-27 07:49:07 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-03-27 07:49:07 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-03-27 07:49:05 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-03-27 07:49:03 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-03-27 07:49:02 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-03-27 07:49:02 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-03-27 07:49:02 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-03-27 07:49:02 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-03-27 07:48:59 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-03-27 07:48:58 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-03-27 07:48:58 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-03-27 07:48:58 639,066 ----a-w C:\WINDOWS\system32\DivX.dll
2007-03-17 19:45:49 -------- d-----w C:\DOCUME~1\NB\APPLIC~1\AdobeUM
2007-03-17 19:45:26 -------- d-----w C:\DOCUME~1\NB\APPLIC~1\Opera
2007-03-17 19:45:03 -------- d-----w C:\Program Files\Opera
2007-03-09 20:37:57 1,024 ----a-w C:\hjibde.exe
2007-03-08 11:15:29 -------- d--h--w C:\Program Files\WindowsUpdate
2007-02-16 01:40:35 124,472 ----a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects]
"{41CC72EE-6DC3-4045-90B3-66ADC6395189}"="C:\PROGRA~1\WINDOW~4\tbu07847\WIN_FT~1.DLL"
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll"
"{BDF3E430-B101-42AD-A544-FADC6B084872}"="C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"RemoteControl"="\"C:\\Program Files\\CyberLink DVD Solution\\PowerDVD\\PDVDServ.exe\""
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"SvcManager"="runservice7.exe"
"zstgtazo.exe"="C:\\WINDOWS\\System32\\zstgtazo.exe"
"Privacy tools"="C:\\WINDOWS\\System32\\stcheck32.exe"
"googletalk"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe /autostart"
"xdsqwe2r"="C:\\WINDOWS\\System32\\pyvidqvm.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"GhostStartTrayApp"="C:\\Program Files\\Norton SystemWorks\\Norton Ghost\\GhostStartTrayApp.exe"
"AcctMgr"="C:\\Program Files\\Norton SystemWorks\\Password Manager\\AcctMgr.exe /startup"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe\""
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\0\0
Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages scecli\0\0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService DnsCache\0\0
rpcss RpcSs\0\0
imgsvc StiSvc\0\0
termsvcs TermService\0\0
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
C:\WINDOWS\tasks\Norton SystemWorks One Button Checkup.job
C:\WINDOWS\tasks\Symantec Drmc.job
C:\WINDOWS\tasks\Symantec NetDetect.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-05-16 22:49:39
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\RECYCLER\NPROTECT
C:\RECYCLER\NPROTECT\00000210.win 16384 bytes
C:\RECYCLER\NPROTECT\00000213.win 4096 bytes
C:\RECYCLER\NPROTECT\00000214.win 4096 bytes
C:\RECYCLER\NPROTECT\00000216.win 656 bytes
C:\RECYCLER\NPROTECT\00000217.js 144 bytes
.
.
.This list goes on for 1500 file have cut it out if you require it I can post all
..
C:\RECYCLER\NPROTECT\00002025.cf 96 bytes
C:\RECYCLER\NPROTECT\00002026.cf 104 bytes
C:\RECYCLER\NPROTECT\00002027.cf 96 bytes
C:\RECYCLER\NPROTECT\00002028.cf 96 bytes
C:\RECYCLER\NPROTECT\00002029.cf 96 bytes
C:\RECYCLER\NPROTECT\NPROTECT.LOG 647168 bytes
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1506
********************************************************************
Completion time: 2007-05-16 22:49:54
C:\ComboFix-quarantined-files.txt ... 2007-05-16 22:49
C:\ComboFix2.txt ... 2007-05-11 18:36
Thanks again for all this help