C:\WINDOWS\system32\atmf.dll unregistered successfully.
File move failed. C:\WINDOWS\system32\atmf.dll scheduled to be moved on reboot.
C:\WINDOWS\system32\kavo.exe moved successfully.
File/Folder C:\WINDOWS\system32\mcxgexn.dll not found.
< Purity >
OTMoveIt2 by OldTimer - Version 1.0.4.0 log created on 04052008_234940
Files moved on Reboot...
C:\WINDOWS\system32\atmf.dll unregistered successfully.
File move failed. C:\WINDOWS\system32\atmf.dll scheduled to be moved on reboot.
ComboFix 08-04-04.1 - Lalala 2008-04-05 23:57:16.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.719 [GMT -7:00]
Running from: C:\Documents and Settings\Lalala\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\o.exe
C:\WINDOWS\msettings.ini
C:\WINDOWS\system32\atmf.dll
C:\WINDOWS\system32\drivers\zybxiogn.dat
C:\WINDOWS\system32\kavo0.dll
C:\WINDOWS\system32\kavo1.dll
C:\WINDOWS\system32\msiconf.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_nknglhkw
-------\Legacy_nknglhkw
-------\nknglhkw
((((((((((((((((((((((((( Files Created from 2008-03-06 to 2008-04-06 )))))))))))))))))))))))))))))))
.
2008-04-05 23:49 . 2008-04-05 23:49 <DIR> d-------- C:\_OTMoveIt
2008-04-04 13:00 . 2008-04-04 13:00 117,834 -r-hs---- C:\wkcay8u.cmd
2008-04-03 15:19 . 2008-04-03 15:18 117,465 -r-hs---- C:\u9.com
2008-04-02 16:25 . 2008-04-02 16:24 117,817 -r-hs---- C:\ermvu8.cmd
2008-03-30 17:18 . 2008-03-30 17:18 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-30 17:18 . 2008-03-30 17:18 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-29 15:19 . 2008-03-29 15:19 117,622 -r-hs---- C:\op.bat
2008-03-28 15:40 . 2008-03-28 15:40 116,653 -r-hs---- C:\u3dsc.com
2008-03-27 15:25 . 2008-03-27 15:24 118,116 -r-hs---- C:\lhwdcgcb.bat
2008-03-25 17:28 . 2008-03-25 17:27 114,201 -r-hs---- C:\diox3j.com
2008-03-25 01:05 . 2008-03-25 01:04 117,067 -r-hs---- C:\gicchk2s.exe
2008-03-25 01:05 . 2008-04-04 22:47 808 -r-hs---- C:\autorun.inf
2008-03-22 00:42 . 2008-03-22 00:42 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-03-22 00:42 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2008-03-22 00:42 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2008-03-22 00:42 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2008-03-22 00:42 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2008-03-22 00:42 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-03-22 00:42 . 2004-03-02 17:37 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys
2008-03-22 00:42 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-03-22 00:42 . 2004-03-02 17:37 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-25 08:51 --------- d-----w C:\Documents and Settings\Lalala\Application Data\Skype
2008-03-15 20:51 --------- d-----w C:\Documents and Settings\Lalala\Application Data\LimeWire
2008-02-14 00:35 --------- d-----w C:\Documents and Settings\Lalala\Application Data\Apple Computer
.
C:\WINDOWS\system32\drivers\tcpip.sys ... is infected !! (additional data below) 401,408 2007-10-08 07:10:22 C:\WINDOWS\system32\dllcache\tcpip.sys
401,408 2007-10-08 07:10:25 C:\WINDOWS\system32\drivers\tcpip.sys
------- Sigcheck -------
2007-10-08 00:10 401408 4ee94d29d4688e21209e56e0312dbf04 C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-08 00:10 401408 4ee94d29d4688e21209e56e0312dbf04 C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-12 15:58 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 15:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 00:06 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24 286720]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"vidc.tscc"= tsccvid.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^msn_0802_upd060053.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\msn_0802_upd060053.exe
backup=C:\WINDOWS\pss\msn_0802_upd060053.exeCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-03 15:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Firewall auto setup]
C:\DOCUME~1\Lalala\LOCALS~1\Temp\winlogon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-07-10 08:18 270648 D:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSI Configuration]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 00:06 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 11:54 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 2006-04-26 08:29 237568 D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
--a------ 2006-04-11 17:52 1409024 D:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 05:24 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShareSearcher]
c:\wsusupd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2004-09-23 11:41 860160 C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2004-10-14 08:11 1388544 C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--a------ 2007-08-31 15:46 1460560 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-04-03 15:24 1271032 D:\Program Files\Valve\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 03:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-07-12 15:58 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"ose"=3 (0x3)
"MDM"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"D:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14803:TCP"= 14803:TCP:BitComet 14803 TCP
"14803:UDP"= 14803:UDP:BitComet 14803 UDP
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f16946b6-e05c-11dc-a9fd-0015f2f58e0d}]
\Shell\AutoRun\command - H:\gicchk2s.exe
\Shell\explore\Command - H:\gicchk2s.exe
\Shell\open\Command - H:\gicchk2s.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-03-13 05:14:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-06 00:04:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-04-06 0:06:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-06 07:06:25
ComboFix2.txt 2007-10-17 21:50:42
Pre-Run: 10,652,237,824 bytes free
Post-Run: 11,314,880,512 bytes free