ComboFix 08-03-18.1 - Home 2008-03-20 14:14:14.2 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6000.0.1252.1.1033.18.143 [GMT -4:00]
Running from: C:\Users\Home\Desktop\ComboFix.exe
Command switches used :: C:\Users\Home\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\nujwjkwv6.exe
.
TimedOut: Windir.dat
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\nujwjkwv6.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SAWADTWW6
-------\Service_sawadtww6
((((((((((((((((((((((((( Files Created from 2008-02-20 to 2008-03-20 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-20 17:45 --------- d-----w C:\ProgramData\Symantec
2008-03-15 15:51 --------- d-----w C:\Program Files\Trend Micro
2008-03-15 01:51 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-15 01:46 --------- d---a-w C:\ProgramData\TEMP
2008-03-15 01:44 --------- d-----w C:\Program Files\Enigma Software Group
2008-03-15 01:43 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-03-15 01:29 3,612 ----a-w C:\Windows\System32\tmp.reg
2008-03-14 13:09 86,528 ----a-w C:\Windows\System32\VACFix.exe
2008-03-13 13:13 --------- d-----w C:\Program Files\Windows Mail
2008-03-13 13:01 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys
2008-03-13 13:01 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-03-08 21:33 --------- d-----w C:\Program Files\Norton Internet Security
2008-03-08 21:33 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-08 20:49 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2008-03-08 20:49 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2008-03-08 20:49 10,740 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2008-03-08 20:49 --------- d-----w C:\Program Files\Symantec
2008-03-08 08:26 174 --sha-w C:\Program Files\desktop.ini
2008-03-08 08:12 --------- d-----w C:\Program Files\Windows Defender
2008-03-08 08:12 --------- d-----w C:\Program Files\Windows Calendar
2008-03-08 08:11 --------- d-----w C:\Program Files\Windows Sidebar
2008-03-08 07:51 8,192 ----a-w C:\Windows\System32\riched32.dll
2008-03-08 07:51 77,824 ----a-w C:\Windows\System32\rascfg.dll
2008-03-08 07:51 52,736 ----a-w C:\Windows\System32\rasdiag.dll
2008-03-08 07:51 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
2008-03-08 07:51 22,016 ----a-w C:\Windows\System32\rasser.dll
2008-03-08 07:51 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
2008-03-08 07:49 87,040 ----a-w C:\Windows\System32\msoert2.dll
2008-03-08 07:49 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2008-03-08 07:49 205,824 ----a-w C:\Windows\System32\msoeacct.dll
2008-03-08 07:48 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2008-03-08 07:47 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2008-03-08 07:47 542,720 ----a-w C:\Windows\System32\sysmain.dll
2008-03-08 07:47 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2008-03-08 07:47 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2008-03-08 07:47 297,984 ----a-w C:\Windows\System32\wlansec.dll
2008-03-08 07:47 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2008-03-08 07:47 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2008-03-08 07:47 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2008-03-08 07:47 2,923,520 ----a-w C:\Windows\explorer.exe
2008-03-08 07:47 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-03-08 07:46 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-03-08 07:46 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-03-08 07:44 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2008-03-08 07:44 376,320 ----a-w C:\Windows\System32\winsrv.dll
2008-03-08 07:31 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-03-08 07:29 414,208 ----a-w C:\Windows\System32\msscp.dll
2008-03-08 07:27 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2008-03-08 07:27 7,680 ----a-w C:\Windows\System32\spwmp.dll
2008-03-08 07:27 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2008-03-08 07:27 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2008-03-08 07:25 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2008-03-08 07:25 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-03-08 07:25 61,952 ----a-w C:\Windows\System32\cmifw.dll
2008-03-08 07:25 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2008-03-08 07:25 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2008-03-08 07:25 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys
2008-03-08 07:25 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2008-03-08 07:25 16,896 ----a-w C:\Windows\System32\wfapigp.dll
2008-03-08 07:25 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-03-08 07:22 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-03-08 07:22 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-03-08 07:22 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-03-08 07:22 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-03-08 07:22 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-03-08 07:22 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys
2008-03-08 07:22 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-03-08 07:22 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-03-08 07:21 104,448 ----a-w C:\Windows\System32\DWWIN.EXE
2008-03-08 07:20 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2008-03-08 07:19 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2008-03-08 07:19 8,704 ----a-w C:\Windows\System32\hccoin.dll
2008-03-08 07:19 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2008-03-08 07:19 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2008-03-08 07:19 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2008-03-08 07:19 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2008-03-08 07:19 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2008-03-08 07:19 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2008-03-08 07:16 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-03-08 07:16 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-03-08 07:16 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-03-08 07:16 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-03-08 07:16 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-03-08 07:15 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-03-08 07:14 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-03-08 07:14 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2008-03-08 07:13 57,856 ----a-w C:\Windows\System32\SLUINotify.dll
2008-03-08 07:13 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll
2008-03-08 07:13 39,936 ----a-w C:\Windows\System32\slcinst.dll
2008-03-08 07:13 351,232 ----a-w C:\Windows\System32\SLUI.exe
2008-03-08 07:13 33,280 ----a-w C:\Windows\System32\slwmi.dll
2008-03-08 07:13 268,288 ----a-w C:\Windows\System32\mcbuilder.exe
2008-03-08 07:13 223,232 ----a-w C:\Windows\System32\SLC.dll
2008-03-08 07:13 2,605,568 ----a-w C:\Windows\System32\SLsvc.exe
2008-03-08 07:13 186,368 ----a-w C:\Windows\System32\SLLUA.exe
2008-03-08 07:12 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
2008-03-08 07:09 84,480 ----a-w C:\Windows\System32\INETRES.dll
2008-03-08 07:09 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2008-03-08 07:09 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-03-08 07:09 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2006-08-09 01:55 152 --sha-r C:\Windows\System32\1EF6FB4423.sys
2006-08-23 04:50 5,852 --sha-w C:\Windows\System32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-03-19_20.41.03.93 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-19 21:10:41 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-03-20 18:24:36 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2000-08-31 12:00:00 163,328 ----a-w C:\Windows\ERDNT\subs\ERDNT.EXE
+ 2004-07-15 06:49:16 258,048 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1048\_aspnet_isapi.dll
+ 2004-07-15 05:32:22 81,920 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1048\_CORPerfMonExt.dll
+ 2004-07-15 05:24:30 282,624 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1048\_fusion.dll
+ 2004-07-15 05:25:06 315,392 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1048\_mscorjit.dll
+ 2004-07-15 19:29:02 2,138,112 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1048\_mscorlib.dll
+ 2003-02-21 00:09:18 77,824 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1048\_mscorsn.dll
+ 2004-07-15 05:26:52 2,510,848 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1048\_mscorsvr.dll
+ 2004-07-15 05:28:34 2,502,656 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1048\_mscorwks.dll
+ 2003-02-21 09:42:22 348,160 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1048\_msvcr71.dll
+ 2004-07-15 05:34:50 94,208 ----a-w C:\Windows\Microsoft.NET\Framework\v1.1.4322\SHADOW1048\_PerfCounter.dll
- 2008-03-19 21:12:41 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-03-20 18:25:32 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-03-20 18:25:32 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-03-19 21:12:46 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-03-20 18:25:32 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-03-20 18:25:32 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-03-19 23:25:13 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-03-20 17:44:31 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-03-19 23:25:13 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-20 17:44:31 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-03-19 23:25:13 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-03-20 17:44:31 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-03-19 21:13:13 5,604 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4125837550-2163220547-2190492486-1009_UserData.bin
+ 2008-03-20 13:34:33 5,752 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4125837550-2163220547-2190492486-1009_UserData.bin
- 2008-03-19 21:13:13 48,404 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-03-20 13:34:32 48,420 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-03-19 21:13:08 28,016 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-03-20 13:34:30 28,812 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-24 23:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-03-07 23:01 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll" [2007-08-24 23:51 316784]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 23:51 316784]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-11-02 05:45 8704]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-21 06:55 68856]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2003-08-13 12:27 28672]
"HostManager"="C:\Program Files\Common Files\AOL\1133723631\ee\AOLSoftware.exe" [2005-11-02 23:01 50792]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 09:38 241664]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 18:28 49152]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 16:24 278528]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2003-08-26 21:47 204800]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-02 22:13 282624]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-01-07 00:39 151597]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-14 12:01 51048]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0c\aoltray.exe [2005-06-28 18:54:13 36953]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 06:19:24 237568]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 16:05:56 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"= %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
"%windir%\\system32\\sessmgr.exe"= %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
"C:\\Program Files\\AIM\\aim.exe"= C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"= C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe-UDP-Domain"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe-TCP-Domain"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe-UDP-Domain"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe-TCP-Domain"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:AOL
"C:\\Program Files\\AIM\\aim.exe-UDP-Domain"= TCP:C:\Program Files\AIM\aim.exe:AOL Instant Messenger
"C:\\Program Files\\AIM\\aim.exe-TCP-Domain"= UDP:C:\Program Files\AIM\aim.exe:AOL Instant Messenger
"%windir%\\Network Diagnostic\\xpnetdiag.exe-UDP-Domain"= TCP:%windir%\Network Diagnostic\xpnetdiag.exe:@xpsp3res.dll,-20000
"%windir%\\Network Diagnostic\\xpnetdiag.exe-TCP-Domain"= UDP:%windir%\Network Diagnostic\xpnetdiag.exe:@xpsp3res.dll,-20000
"C:\\XP_FixWinpack.exe-UDP-Standard"= TCP:Profile=Public|C:\XP_FixWinpack.exe:XP_FixWinpack
"C:\\XP_FixWinpack.exe-TCP-Standard"= UDP:Profile=Public|C:\XP_FixWinpack.exe:XP_FixWinpack
"C:\\WINDOWS\\SYSTEM32\\smsc.exe-UDP-Standard"= TCP:Profile=Public|C:\WINDOWS\SYSTEM32\smsc.exe:smsc
"C:\\WINDOWS\\SYSTEM32\\smsc.exe-TCP-Standard"= UDP:Profile=Public|C:\WINDOWS\SYSTEM32\smsc.exe:smsc
"C:\\WINDOWS\\SYSTEM32\\rnhtfans.exe-UDP-Standard"= TCP:Profile=Public|C:\WINDOWS\SYSTEM32\rnhtfans.exe:rnhtfans
"C:\\WINDOWS\\SYSTEM32\\rnhtfans.exe-TCP-Standard"= UDP:Profile=Public|C:\WINDOWS\SYSTEM32\rnhtfans.exe:rnhtfans
"C:\\WINDOWS\\system32-UDP-Standard"= TCP:Profile=Public|C:\WINDOWS\system32:lockx
"C:\\WINDOWS\\system32-TCP-Standard"= UDP:Profile=Public|C:\WINDOWS\system32:lockx
"C:\\Program Files\\LimeWire\\LimeWire.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"C:\\Program Files\\LimeWire\\LimeWire.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"C:\\Program Files\\iTunes\\iTunes.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\iTunes\iTunes.exe:iTunes
"C:\\Program Files\\iTunes\\iTunes.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\iTunes\iTunes.exe:iTunes
"C:\\Program Files\\Internet Explorer\\iexplore.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Internet Explorer\iexplore.exe:Internet Explorer
"C:\\Program Files\\Internet Explorer\\iexplore.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Internet Explorer\iexplore.exe:Internet Explorer
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Grisoft\AVG7\avginet.exe:avginet.exe
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Grisoft\AVG7\avginet.exe:avginet.exe
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Grisoft\AVG7\avgemc.exe:avgemc.exe
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Grisoft\AVG7\avgemc.exe:avgemc.exe
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Grisoft\AVG7\avgcc.exe:avgcc.exe
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Grisoft\AVG7\avgcc.exe:avgcc.exe
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Grisoft\AVG7\avgamsvr.exe:avgamsvr.exe
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Grisoft\AVG7\avgamsvr.exe:avgamsvr.exe
"C:\\Program Files\\Dell Computer\\Dell Picture Studio v2.0\\launch.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Dell Computer\Dell Picture Studio v2.0\launch.exe:Jasc Paint Shop Photo Album Application
"C:\\Program Files\\Dell Computer\\Dell Picture Studio v2.0\\launch.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Dell Computer\Dell Picture Studio v2.0\launch.exe:Jasc Paint Shop Photo Album Application
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:AOL
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:AOLTsMon
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:AOLTsMon
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:AOLTopSpeed
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:AOLTopSpeed
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Common Files\AOL\System Information\sinf.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Common Files\AOL\System Information\sinf.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Application Loader
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Application Loader
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\1110582691\\EE\\AOLServiceHost.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\Common Files\AOL\1110582691\EE\AOLServiceHost.exe:AOL
"C:\\Program Files\\Common Files\\AOL\\1110582691\\EE\\AOLServiceHost.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\Common Files\AOL\1110582691\EE\AOLServiceHost.exe:AOL
"C:\\Program Files\\America Online 9.0a\\waol.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\America Online 9.0a\waol.exe:AOL
"C:\\Program Files\\America Online 9.0a\\waol.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\America Online 9.0a\waol.exe:AOL
"C:\\Program Files\\AIM\\AIM95_c2\\aim.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\AIM\AIM95_c2\aim.exe:AOL Instant Messenger
"C:\\Program Files\\AIM\\AIM95_c2\\aim.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\AIM\AIM95_c2\aim.exe:AOL Instant Messenger
"C:\\Program Files\\AIM\\AIM95_c1\\aim.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\AIM\AIM95_c1\aim.exe:AOL Instant Messenger
"C:\\Program Files\\AIM\\AIM95_c1\\aim.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\AIM\AIM95_c1\aim.exe:AOL Instant Messenger
"C:\\Program Files\\AIM\\AIM95_c0\\aim.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\AIM\AIM95_c0\aim.exe:AOL Instant Messenger
"C:\\Program Files\\AIM\\AIM95_c0\\aim.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\AIM\AIM95_c0\aim.exe:AOL Instant Messenger
"C:\\Program Files\\AIM\\aim.exe-UDP-Standard"= TCP:Profile=Public|C:\Program Files\AIM\aim.exe:AOL Instant Messenger
"C:\\Program Files\\AIM\\aim.exe-TCP-Standard"= UDP:Profile=Public|C:\Program Files\AIM\aim.exe:AOL Instant Messenger
"%windir%\\Network Diagnostic\\xpnetdiag.exe-UDP-Standard"= TCP:Profile=Public|%windir%\Network Diagnostic\xpnetdiag.exe:@xpsp3res.dll,-20000
"%windir%\\Network Diagnostic\\xpnetdiag.exe-TCP-Standard"= UDP:Profile=Public|%windir%\Network Diagnostic\xpnetdiag.exe:@xpsp3res.dll,-20000
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"= %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
"%windir%\\system32\\sessmgr.exe"= %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
"C:\\Program Files\\AIM\\aim.exe"= C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger
"C:\\Program Files\\AIM\\AIM95_c0\\aim.exe"= C:\Program Files\AIM\AIM95_c0\aim.exe:*:Enabled:AOL Instant Messenger
"C:\\Program Files\\AIM\\AIM95_c1\\aim.exe"= C:\Program Files\AIM\AIM95_c1\aim.exe:*:Enabled:AOL Instant Messenger
"C:\\Program Files\\AIM\\AIM95_c2\\aim.exe"= C:\Program Files\AIM\AIM95_c2\aim.exe:*:Enabled:AOL Instant Messenger
"C:\\Program Files\\America Online 9.0a\\waol.exe"= C:\Program Files\America Online 9.0a\waol.exe:*:Enabled:AOL
"C:\\Program Files\\Common Files\\AOL\\1110582691\\EE\\AOLHostManager.exe"= C:\Program Files\Common Files\AOL\1110582691\EE\AOLHostManager.exe:*:Disabled:AOLHostManager Service
"C:\\Program Files\\Common Files\\AOL\\1110582691\\EE\\AOLServiceHost.exe"= C:\Program Files\Common Files\AOL\1110582691\EE\AOLServiceHost.exe:*:Enabled:AOL
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"= C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"= C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"= C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"= C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"= C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"= C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"= C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL
"C:\\Program Files\\Dell Computer\\Dell Picture Studio v2.0\\launch.exe"= C:\Program Files\Dell Computer\Dell Picture Studio v2.0\launch.exe:*:Enabled:Jasc Paint Shop Photo Album Application
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"= C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"= C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"= C:\Program Files\Grisoft\AVG7\avgemc.exe:*:Enabled:avgemc.exe
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"= C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe
"C:\\Program Files\\iTunes\\iTunes.exe"= C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
"C:\\Program Files\\LimeWire\\LimeWire.exe"= C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"C:\\Program Files\\Save\\Save.exe"= C:\Program Files\Save\Save.exe:*:Disabled:Save!
"C:\\WINDOWS\\system32"= C:\WINDOWS\system32:*:Enabled:lockx
"C:\\WINDOWS\\SYSTEM32\\rnhtfans.exe"= C:\WINDOWS\SYSTEM32\rnhtfans.exe:*:Enabled:rnhtfans
"C:\\WINDOWS\\SYSTEM32\\smsc.exe"= C:\WINDOWS\SYSTEM32\smsc.exe:*:Enabled:smsc
"C:\\XP_FixWinpack.exe"= C:\XP_FixWinpack.exe:*:Enabled:XP_FixWinpack
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080314.001\IDSvix86.sys [2008-02-13 12:18]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R3 SymIMMP;SymIMMP;C:\Windows\system32\DRIVERS\SymIM.sys [2007-08-09 20:27]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-08-13 16:50]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" []
S3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2008-01-12 19:32]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\Windows\system32\DRIVERS\SymIM.sys [2007-08-09 20:27]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-03-18 00:38:11 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Home.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-20 14:25:46
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
.
**************************************************************************
.
Completion time: 2008-03-20 14:33:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-20 18:32:50
ComboFix2.txt 2008-03-20 00:41:39
.
2008-03-20 08:51:40 --- E O F ---