ComboFix 08-02.05.3 - kim 2008-02-05 21:30:32.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.59 [GMT -6:00]
Running from: C:\Documents and Settings\kim\My Documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\kim\Desktop\CFScript.txt.lnk
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-01-06 to 2008-02-06 )))))))))))))))))))))))))))))))
.
2008-02-04 23:18 . 2008-02-04 23:18 <DIR> d-------- C:\_OTMoveIt
2008-02-04 21:33 . 2008-02-04 21:33 <DIR> d-------- C:\Deckard
2008-02-04 18:41 . 2008-02-04 18:41 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-28 16:54 . 2008-01-28 16:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-28 16:53 . 2008-02-04 15:04 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-28 16:53 . 2008-01-28 16:53 <DIR> d-------- C:\Documents and Settings\kim\Application Data\SUPERAntiSpyware.com
2008-01-28 15:52 . 2008-01-28 15:52 1,024 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\2E24A38A-CD61-4270-8938-E75280F9090E.cxv
2008-01-28 11:54 . 2008-01-28 11:54 <DIR> d-------- C:\Documents and Settings\kim\Application Data\Grisoft
2008-01-28 11:53 . 2007-05-30 06:10 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2008-01-28 11:52 . 2008-01-28 11:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-28 09:59 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SDTHOOK.SYS
2008-01-28 09:56 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\doxahacacnep.sys
2008-01-28 09:41 . 2008-01-28 09:41 156,160 --a------ C:\WINDOWS\SYSTEM32\D3.tmp
2008-01-27 00:30 . 2008-01-27 00:30 1,024 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\6123D187-1DFE-4405-B813-F17BEF579219.cxv
2008-01-27 00:25 . 2008-02-04 09:08 <DIR> d-------- C:\Program Files\STOPzilla!
2008-01-27 00:25 . 2008-01-27 00:25 <DIR> d-------- C:\Program Files\Common Files\iS3
2008-01-27 00:25 . 2008-02-04 09:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-01-25 00:19 . 2008-01-25 00:19 <DIR> d-------- C:\Program Files\CCleaner
2008-01-24 02:26 . 2008-01-28 10:56 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-01-24 02:19 . 2008-01-24 02:19 <DIR> d-------- C:\Program Files\MSBuild
2008-01-24 02:11 . 2008-01-24 02:11 <DIR> d-------- C:\WINDOWS\SYSTEM32\XPSViewer
2008-01-24 02:07 . 2008-01-24 02:07 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-01-24 02:05 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\SYSTEM32\spmsg2.dll
2008-01-24 02:03 . 2008-01-24 02:03 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-01-24 02:03 . 2008-01-24 02:03 <DIR> d-------- C:\74c32015e95a4c429486495272
2008-01-24 02:01 . 2006-10-04 08:06 1,197,294 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\sysmain.sdb
2008-01-24 02:01 . 2006-10-04 08:06 764,868 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\apph_sp.sdb
2008-01-24 02:01 . 2006-10-04 08:06 217,118 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\apphelp.sdb
2008-01-24 01:58 . 2008-01-24 01:58 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-01-24 01:43 . 2006-11-13 00:02 288,768 --------- C:\WINDOWS\SYSTEM32\rhttpaa.dll
2008-01-24 01:43 . 2006-11-13 00:02 116,736 --------- C:\WINDOWS\SYSTEM32\aaclient.dll
2008-01-24 01:43 . 2006-11-13 00:02 36,352 --------- C:\WINDOWS\SYSTEM32\tsgqec.dll
2008-01-23 22:40 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\qnptamuyyngn.sys
2008-01-23 21:58 . 2008-01-28 11:22 <DIR> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2008-01-23 21:58 . 2008-01-28 09:50 30,590 --a------ C:\WINDOWS\SYSTEM32\pavas.ico
2008-01-23 21:58 . 2008-01-28 09:50 2,550 --a------ C:\WINDOWS\SYSTEM32\Uninstall.ico
2008-01-23 21:58 . 2008-01-28 09:50 1,406 --a------ C:\WINDOWS\SYSTEM32\Help.ico
2008-01-13 21:07 . 2008-01-17 06:51 123,952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
2008-01-13 21:07 . 2008-01-17 06:51 60,800 --a------ C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2008-01-13 21:07 . 2008-01-17 06:51 10,740 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
2008-01-13 21:07 . 2008-01-17 06:51 805 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
2008-01-13 20:37 . 2008-01-13 20:37 <DIR> d-------- C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP
2008-01-13 20:10 . 2008-01-13 20:10 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-01-13 20:10 . 2008-01-28 19:30 <DIR> d-------- C:\Program Files\Norton AntiVirus
2008-01-10 18:23 . 2008-01-24 02:26 <DIR> d-------- C:\temp
2008-01-06 09:05 . 2008-01-06 09:05 <DIR> d-------- C:\Program Files\MSXML 4.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-05 04:14 --------- d-----w C:\Program Files\iTunes
2008-02-04 20:48 --------- d-----w C:\Program Files\Intel
2008-02-04 15:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-04 15:22 --------- d-----w C:\Program Files\ArcSoft
2008-02-01 12:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-29 03:52 --------- d-----w C:\Documents and Settings\kim\Application Data\MSN6
2008-01-28 22:50 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-28 22:10 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-28 16:50 --------- d-----w C:\Program Files\FinePixViewer
2008-01-28 16:46 --------- d-----w C:\Program Files\Common Files\SWF Studio
2008-01-27 16:19 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-01-25 05:52 --------- d-----w C:\Program Files\CyberLink
2008-01-20 22:40 --------- d-----w C:\Program Files\QuickTime
2008-01-17 12:51 --------- d-----w C:\Program Files\Symantec
2008-01-15 15:54 10,537 ----a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-01-15 11:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-14 02:09 --------- d-----w C:\Program Files\Common Files\Authentium Shared
2008-01-14 01:45 --------- d-----w C:\Program Files\Yahoo!
2008-01-13 00:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-05 01:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Authentium
2008-01-05 01:07 --------- d-----w C:\Program Files\Common Files\RuleSpace
2008-01-05 01:06 --------- d-----w C:\Program Files\Common Files\Aluria
2008-01-05 01:04 --------- d-----w C:\Program Files\Common Files\Authentium
2008-01-05 00:57 --------- d-----w C:\Program Files\Cox
2008-01-05 00:39 --------- d-----w C:\Program Files\Windows Defender
2008-01-05 00:34 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-05 00:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-05 00:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-12-28 05:22 --------- d-----w C:\Documents and Settings\kim\Application Data\AVG7
2007-12-27 03:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-27 03:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller
2007-12-27 03:24 --------- d-----w C:\Documents and Settings\kim\Application Data\Yahoo!
2007-12-27 03:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-12-27 03:21 --------- d-----w C:\Documents and Settings\kim\Application Data\Move Networks
2007-12-27 03:20 --------- d-----w C:\Program Files\IrfanView
2007-12-27 00:03 --------- d-----w C:\Program Files\REGSHAVE
2007-12-26 23:24 155,648 ----a-w C:\WINDOWS\SYSTEM32\igfxtray .exe
2007-12-26 23:24 126,976 ----a-w C:\WINDOWS\SYSTEM32\hkcmd .exe
2007-12-26 23:23 169,984 ----a-w C:\WINDOWS\SYSTEM32\LEXPPS .EXE
2007-12-25 17:17 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-25 15:57 15,360 ----a-w C:\WINDOWS\SYSTEM32\ctfmon .exe
2007-12-19 03:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Protexis
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\SYSTEM32\lsasrv.dll
2007-11-07 09:26 721,920 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\lsasrv.dll
2007-01-10 04:23 4 ----a-w C:\Documents and Settings\kim\controls.dat
2007-01-10 04:20 60,928 ----a-w C:\Documents and Settings\kim\jbfmod.dll
2007-01-10 04:20 161,280 ----a-w C:\Documents and Settings\kim\fmod.dll
2005-07-06 01:32 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
<pre> ----a-w 185,632 2007-12-26 23:24:43 C:\Program Files\Common Files\Real\Update_OB\realsched .exe ----a-w 51,048 2008-01-14 02:16:11 C:\Program Files\Common Files\Symantec Shared\ccApp .exe ----a-w 0 2008-01-28 21:57:38 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe ----a-w 579,072 2007-12-26 23:24:55 C:\Program Files\Grisoft\AVG7\avgcc .exe ----a-w 36,975 2007-12-26 23:24:48 C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe ----a-w 282,624 2008-01-14 21:34:55 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:34:56 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:34:52 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:34:54 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:34:55 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:35:02 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:35:01 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:35:01 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:35:02 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:34:58 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:35:03 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:35:03 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:35:05 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:35:04 C:\Program Files\QuickTime\qttask .exe ----a-w 282,624 2008-01-14 21:35:00 C:\Program Files\QuickTime\qttask .exe ----a-w 53,248 2007-12-26 23:24:38 C:\Program Files\REGSHAVE\REGSHAVE .EXE ----a-w 1,310,720 2008-01-29 01:14:38 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe ----a-w 777,424 2007-12-26 23:24:33 C:\Program Files\Windows Defender\MSASCui .exe ----a-w 4,670,704 2007-12-25 16:02:03 C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE ----a-w 15,360 2007-12-25 15:57:21 C:\WINDOWS\SYSTEM32\ctfmon .exe ----a-w 126,976 2007-12-26 23:24:21 C:\WINDOWS\SYSTEM32\hkcmd .exe ----a-w 155,648 2007-12-26 23:24:16 C:\WINDOWS\SYSTEM32\igfxtray .exe ----a-w 169,984 2007-12-26 23:23:04 C:\WINDOWS\SYSTEM32\LEXPPS .EXE </pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-01-30 22:06 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
"washindex"="C:\Program Files\Washer\washidx.exe" [2002-08-15 04:07 33792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LexStart"="" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]
"ESP"="c:\Program Files\Cox\Applications\app\start.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Exif Launcher 2.lnk - C:\Program Files\FinePixViewer\QuickDCF2.exe [2007-02-03 15:26:02 294912]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-08-24 23:07]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 18:27]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-01-12 18:32]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 18:27]
S3 USBCamera;Bulk USB Device;C:\WINDOWS\system32\Drivers\Bulk533.sys [2002-07-25 10:19]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-06 00:24:00 C:\WINDOWS\Tasks\HP Usg Daily.job"
- C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\pexpress\hphped05.exe
"2008-01-14 03:36:56 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - kim.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-05 21:35:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-05 21:39:04
ComboFix-quarantined-files.txt 2008-02-06 03:38:57
ComboFix2.txt 2008-02-06 02:42:57
.