Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1597 [GMT -3:00]
Running from: C:\Documents and Settings\Mustapha Maynard\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\alexa toolbar
C:\Program Files\alexa toolbar\uninstall.exe
C:\Program Files\PlayMP3z
C:\Program Files\PlayMP3z\PlayMP3.exe
C:\Program Files\PlayMP3z\uninstall.exe
C:\Program Files\TTC.dll
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\Fonts\'
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu1188.exe
C:\WINDOWS\system32\alxres.dll
C:\WINDOWS\system32\AlxTB1.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\tuvSijhh.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-20 to 2008-03-20 )))))))))))))))))))))))))))))))
.
2008-03-20 10:46 . 2008-03-20 10:46 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-03-20 10:43 . 2008-03-20 10:43 <DIR> d-------- C:\WINDOWS\system32\spol6
2008-03-20 10:43 . 2008-03-20 10:43 <DIR> d-------- C:\WINDOWS\system32\obe9
2008-03-20 10:43 . 2008-03-20 10:43 <DIR> d-------- C:\WINDOWS\system32\dhcb3
2008-03-20 10:42 . 2008-03-20 10:43 <DIR> d-------- C:\WINDOWS\system32\aqVreo18
2008-03-20 10:42 . 2008-03-20 10:43 <DIR> d-------- C:\Temp\gbRve12
2008-03-20 10:42 . 2008-03-20 10:42 18,944 --a------ C:\WINDOWS\system32\khfFYRhE.dll
2008-03-20 09:45 . 2008-03-20 09:45 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2008-03-20 09:45 . 2006-11-09 05:04 73,288 --a------ C:\WINDOWS\system32\drivers\tmtdi.sys
2008-03-19 14:41 . 2008-03-19 14:41 <DIR> d-------- C:\Documents and Settings\Mustapha Maynard\Application Data\PrevxCSI
2008-03-19 14:27 . 2008-03-19 14:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avg7
2008-03-19 11:47 . 2008-03-19 11:47 0 --a------ C:\WINDOWS\system32\SBRC.dat
2008-03-19 11:47 . 2008-03-19 11:47 0 --a------ C:\WINDOWS\system32\SBFC.dat
2008-03-19 11:37 . 2008-03-19 11:37 <DIR> d-------- C:\Documents and Settings\Mustapha Maynard\Application Data\Sunbelt Software
2008-03-17 19:33 . 2008-03-17 19:33 <DIR> d-------- C:\Documents and Settings\Mustapha Maynard\Application Data\Vso
2008-03-17 09:47 . 2008-03-17 09:47 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-17 09:47 . 2008-03-17 09:47 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2008-03-15 23:48 . 2008-03-15 23:48 <DIR> dr-h----- C:\$VAULT$.AVG
2008-03-15 09:58 . 2008-03-15 09:58 32,768 --a------ C:\WINDOWS\system32\aqVreo18\aqVreo182328.exe
2008-03-14 13:27 . 2008-03-14 13:27 <DIR> d-------- C:\Program Files\FBrowsingAdvisor
2008-03-14 13:27 . 2008-03-14 13:27 <DIR> d-------- C:\Program Files\FBrowserAdvisor
2008-03-14 12:01 . 2008-03-14 12:01 <DIR> d-------- C:\Program Files\Palm Inc
2008-03-14 11:34 . 1999-12-08 18:33 411,352 --------- C:\WINDOWS\system32\Vsflex6.ocx
2008-03-14 11:31 . 2008-03-14 11:31 <DIR> d-------- C:\Program Files\palmOne
2008-03-07 19:17 . 2008-03-07 19:17 <DIR> d-------- C:\Program Files\QuickTax 2007
2008-03-07 19:17 . 2008-03-07 19:17 <DIR> d-------- C:\Program Files\Common Files\Intuit
2008-03-07 19:17 . 2008-03-07 19:17 <DIR> d-------- C:\Program Files\Common Files\AnswerWorks 4.0
2008-03-07 19:17 . 2008-03-07 19:17 <DIR> d-------- C:\Documents and Settings\Mustapha Maynard\Application Data\Intuit Canada
2008-03-07 19:16 . 2008-03-07 19:16 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Intuit Canada
2008-03-04 07:39 . 2008-03-04 07:39 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-03 12:37 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-03 12:37 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-03-03 12:37 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-03 12:12 . 2008-03-03 12:12 <DIR> d-------- C:\Program Files\Windows Live
2008-03-03 12:12 . 2008-03-03 12:12 <DIR> d--hs---- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-03 12:11 . 2008-03-03 12:11 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
2008-02-28 12:58 . 2008-03-10 14:25 34 --a------ C:\WINDOWS\system32\BD7020.DAT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-19 15:55 81,920 ----a-w C:\Documents and Settings\Mustapha Maynard\Application Data\ezpinst.exe
2008-03-19 15:55 47,360 ----a-w C:\Documents and Settings\Mustapha Maynard\Application Data\pcouffin.sys
2008-02-18 15:54 --------- d-----w C:\Program Files\Shockwave.com
2008-02-08 18:03 --------- d-----r C:\Documents and Settings\Mustapha Maynard\Application Data\Brother
2008-02-05 14:01 --------- d-----w C:\Documents and Settings\Mustapha Maynard\Application Data\Apple Computer
2008-02-02 21:43 --------- d-----w C:\Documents and Settings\Mustapha Maynard\Application Data\ATI
2008-02-02 21:41 --------- d-----w C:\Program Files\Aliant Dial-up Accelerator
2008-01-24 11:58 --------- d-----w C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-01-24 11:58 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Corporation
2008-01-11 04:53 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-09 10:18 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-01-09 10:18 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-01-09 10:18 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-01-09 10:18 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-01-09 10:16 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-01-09 10:16 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-01-09 10:16 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-01-09 10:16 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-01-09 10:16 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-01-09 10:16 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-01-06 14:25 1,712,201 ----a-w C:\WINDOWS\system32\InetClnt.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6738B68C-14C7-407A-BE53-893BAD844CB8}]
\C:\WINDOWS\system32\spol6\ax89104.exe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A66AA08A-9BF0-4e87-99E6-6972731D6B99}]
2007-10-24 10:47 602112 --a------ C:\Program Files\Aliant Dial-up Accelerator\Prefetch.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 20:00 15360]
"OM2_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-02-08 20:43 95800]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [2006-11-01 11:08 321040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56 64512]
"LaunchApp"="" []
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41 45056]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2006-04-14 22:35 53248]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 20:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 20:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 20:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 20:00 455168]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-17 23:27 16207872 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 13:07 761946]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2006-06-23 06:59 602112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"LXCGCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-04-27 11:21 69632]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-04 12:11 185632]
"ePower_DMC"="C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-05-30 12:11 421888]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57 282624]
"SlipStream"="C:\Program Files\Aliant Dial-up Accelerator\slipcore.exe" [2007-10-24 10:47 348160]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe" [2007-08-16 08:12 1807696]
C:\Documents and Settings\Mustapha Maynard\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\palmOne\HOTSYNC.EXE [2004-11-08 14:29:42 299008]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 07:05:56 65588]
Aliant Dial-up Accelerator.lnk - C:\Program Files\Aliant Dial-up Accelerator\slipgui.exe [2008-02-02 18:41:27 233472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer Empowering Technology.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk
backup=C:\WINDOWS\pss\Acer Empowering Technology.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD]
--a------ 2006-03-31 16:39 204800 C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot]
--a------ 2006-03-15 22:12 579584 C:\Acer\Empowering Technology\ePower\Boot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2007-09-18 11:16 171464 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC]
--a------ 2006-05-30 12:11 421888 C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]
--a------ 2006-06-01 14:40 413696 C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
--a------ 2005-05-09 17:06 73728 C:\Program Files\Lexmark 2300 Series\ezprint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
--a------ 2005-05-03 15:20 299008 C:\Program Files\Lexmark Fax Solutions\fm3032.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcgmon.exe]
--a------ 2005-05-05 00:24 200704 C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntiMUI]
--a------ 2005-05-11 17:15 45056 C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\System32\\lxcgcoms.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;C:\WINDOWS\system32\eLock2BurnerLockDriver.sys []
S2 eLock2FSCTLDriver;eLock2FSCTLDriver;C:\WINDOWS\system32\eLock2FSCTLDriver.sys []
S3 CH341SER;CH341SER;C:\WINDOWS\system32\Drivers\CH341SER.SYS [2006-10-25 00:00]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-20 12:37:29
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
.
**************************************************************************
.
Completion time: 2008-03-20 12:40:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-20 15:40:52
.
2008-03-14 11:33:09 --- E O F ---