ComboFix 08-02.05.3 - Administrator 2008-02-07 22:53:36.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.820 [GMT -8:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\sean\Application Data\SSTEM~1
C:\Documents and Settings\sean\Application Data\SSTEM~1\s?stem\
C:\Documents and Settings\sean\My Documents\CROSOF~1
C:\Documents and Settings\sean\My Documents\CROSOF~1\w?nlogon.exe
C:\Documents and Settings\sean\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\sean\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\sean\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\sean\Start Menu\Programs\Outerinfo
C:\Documents and Settings\sean\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\sean\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\Program Files\internet optimizer
C:\Program Files\ISM
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\dic.gz
C:\Program Files\QdrModule\kwd.gz
C:\Program Files\QdrPack
C:\Program Files\QdrPack\dicts.gz
C:\Program Files\QdrPack\trgts.gz
C:\Program Files\Temporary
C:\Program Files\Temporary\kernInst.exe
C:\WIN\b122.exe
C:\WIN\system32\jjkmp.ini
C:\WIN\system32\jjkmp.ini2
C:\WIN\system32\wvustqo.dll
H:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-07 22:49 . 2004-08-03 23:56 388,608 --a------ C:\kmd.exe
2008-02-04 18:34 . 2008-02-04 18:42 <DIR> d-------- C:\Program Files\Security Task Manager
2008-02-04 18:34 . 2008-02-04 18:41 <DIR> d-------- C:\Documents and Settings\All Users.WIN\Application Data\SecTaskMan
2008-02-04 18:34 . 2008-02-04 18:34 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Ipswitch
2008-02-02 21:49 . 2008-02-02 21:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-01-27 11:23 . 2008-01-31 18:21 <DIR> d-------- C:\Program Files\Dot1XCfg
2008-01-27 11:19 . 2008-01-27 11:19 270,698 --a------ C:\WIN\system32\LD8F9.tmp
2008-01-27 11:19 . 2008-01-27 11:19 181,965 --a------ C:\WIN\system32\LCE6A.tmp
2008-01-25 20:17 . 2008-01-25 20:17 <DIR> d-------- C:\Documents and Settings\All Users.WIN\Application Data\EPSON
2008-01-25 20:16 . 2008-01-25 20:16 <DIR> d-------- C:\EPSONREG
2008-01-25 20:16 . 2008-01-25 20:16 <DIR> d-------- C:\Documents and Settings\sean\Application Data\Leadertech
2008-01-25 20:14 . 2008-01-25 20:14 <DIR> d-------- C:\Program Files\ArcSoft
2008-01-25 20:14 . 1995-08-01 04:44 212,480 --a------ C:\WIN\PCDLIB32.DLL
2008-01-25 20:14 . 2005-02-23 14:58 11,776 --a------ C:\WIN\system32\drivers\afc.sys
2008-01-25 20:11 . 2008-01-25 20:11 <DIR> d-------- C:\Documents and Settings\sean\Application Data\InstallShield
2008-01-25 20:06 . 2008-01-25 20:15 <DIR> d-------- C:\Program Files\epson
2008-01-25 20:06 . 2006-08-10 01:02 75,264 --a------ C:\WIN\system32\E_FLBBVA.DLL
2008-01-25 20:06 . 2006-04-19 01:00 62,976 --a------ C:\WIN\system32\E_FD4BBVA.DLL
2008-01-25 20:06 . 2006-10-13 00:00 61,952 --a------ C:\WIN\system32\escwiad.dll
2008-01-25 20:05 . 2008-01-25 20:16 44 --a------ C:\WIN\EP_CX5000.ini
2008-01-10 23:20 . 2008-01-10 23:20 <DIR> d-------- C:\Documents and Settings\All Users.WIN\Application Data\FLEXnet
2008-01-10 23:08 . 2008-01-10 23:08 <DIR> d-------- C:\Program Files\Bonjour
2008-01-10 22:56 . 2008-01-10 22:56 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-01 02:21 --------- d-----w C:\Program Files\QuickTime
2008-02-01 02:21 --------- d-----w C:\Program Files\iTunes
2008-02-01 02:21 --------- d-----w C:\Program Files\eFax Messenger 4.3
2008-01-26 04:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-21 21:11 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-01-14 00:11 --------- d-----w C:\Documents and Settings\sean\Application Data\Skype
2008-01-11 07:08 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-11 06:48 --------- d-----w C:\Program Files\Macromedia
2008-01-11 06:47 --------- d-----w C:\Program Files\GIMP-2.0
2008-01-11 06:45 --------- d-----w C:\Program Files\eBay
2008-01-11 06:44 --------- d-----w C:\Documents and Settings\sean\Application Data\Walgreens
2006-06-03 19:18 17,288 ----a-w C:\Documents and Settings\mae\Application Data\GDIPFONTCACHEV1.DAT
2005-11-27 23:50 95,744 ----a-w C:\Program Files\metapad.exe
2005-09-26 19:41 17,288 ----a-w C:\Documents and Settings\sean\Application Data\GDIPFONTCACHEV1.DAT
2005-08-28 19:43 119 ----a-w C:\Documents and Settings\Owner\PageSuckerRegistration.dat
2005-03-27 00:53 56,712 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BlazeServoTool"="C:\Program Files\BlazeVideo\BlazeDVD 4 Professional\MediaDetector.exe" [ ]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"Smrr"="C:\DOCUME~1\sean\APPLIC~1\SSTEM~1\scanregw.exe" [ ]
"Fnrkp"="C:\Documents and Settings\sean\My Documents\??crosoft\w?nlogon.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 12:47 57344 C:\WIN\ALCXMNTR.EXE]
"NvCplDaemon"="C:\WIN\system32\NvCpl.dll" [2005-07-20 20:07 7110656]
"nwiz"="nwiz.exe" [2005-07-20 20:07 1519616 C:\WIN\system32\nwiz.exe]
"NvMediaCenter"="C:\WIN\system32\NvMcTray.dll" [2005-07-20 20:07 86016]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2004-06-16 20:49:51 225280]
C:\Documents and Settings\All Users.WIN\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-07-07 19:47:08 98304]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Automation Anywhere Event Monitor.lnk - C:\Program Files\Automation Anywhere 3.5\AAEventMonitor.exe [2007-04-27 21:05:20 57344]
Automation Anywhere Hotkeys.lnk - C:\Program Files\Automation Anywhere 3.5\AAHotkeys.exe [2007-04-16 17:18:48 98304]
eFax 4.3.lnk - C:\Program Files\eFax Messenger 4.3\J2GTray.exe [2007-03-14 13:35:18 629248]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]
R2 Automation Anywhere Service;Automation Anywhere Service;C:\Program Files\Automation Anywhere 3.5\Automation Anywhere Service.exe [2007-04-02 13:37]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-07 23:08:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WIN\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Automation Anywhere 3.5\AAService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WIN\system32\Ati2evxx.exe
.
**************************************************************************
.
Completion time: 2008-02-07 23:13:03 - machine was rebooted [sean]
ComboFix-quarantined-files.txt 2008-02-08 07:12:59
.
2008-02-01 16:19:19 --- E O F ---