ComboFix 08-04-15.1 - N1N3TY51X 2008-04-15 22:27:41.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.110 [GMT -7:00]
Running from: C:\Documents and Settings\N1N3TY51X\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\Fonts\Setup.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-16 to 2008-04-16 )))))))))))))))))))))))))))))))
.
2008-04-12 20:47 . 2008-04-12 22:44 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-04-12 20:46 . 2008-04-12 20:46 <DIR> d-------- C:\Program Files\Red Kawa
2008-04-12 20:23 . 2008-04-12 20:23 <DIR> d-------- C:\Documents and Settings\N1N3TY51X\Application Data\AVS4YOU
2008-04-12 20:23 . 2008-04-12 20:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-04-12 20:19 . 2008-04-12 20:28 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2008-04-12 20:18 . 2008-04-12 20:30 <DIR> d-------- C:\Program Files\AVS4YOU
2008-04-12 20:18 . 2007-02-27 19:36 638,976 --a------ C:\WINDOWS\system32\divx.dll
2008-04-12 20:18 . 2007-02-27 19:36 524,288 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-04-12 20:18 . 2007-02-27 19:36 413,760 --a------ C:\WINDOWS\system32\mpg4c32.dll
2008-04-12 20:18 . 2007-02-27 19:36 261,632 --a------ C:\WINDOWS\system32\mcdvd_32.dll
2008-04-12 20:18 . 2007-02-27 19:36 221,215 --a------ C:\WINDOWS\system32\divxdec.ax
2008-04-12 20:18 . 2007-02-27 19:36 139,264 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-04-12 20:18 . 2007-02-27 19:36 82,944 --a------ C:\WINDOWS\system32\vct3216.acm
2008-04-12 20:18 . 2007-02-27 19:36 81,920 --a------ C:\WINDOWS\system32\AC3ACM.acm
2008-04-12 20:18 . 2007-02-27 19:36 38,912 --a------ C:\WINDOWS\system32\alf2cd.acm
2008-04-12 20:18 . 2007-02-27 19:36 13,239 --a------ C:\WINDOWS\system32\Scg726.acm
2008-04-12 01:34 . 2008-04-12 01:36 185 --a------ C:\WINDOWS\wininit.ini
2008-04-09 22:07 . 2008-04-09 22:07 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-09 20:50 . 2008-04-09 20:51 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-09 20:50 . 2008-04-09 21:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-08 21:41 . 2008-04-08 21:41 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-04-08 21:34 . 2008-04-12 22:10 <DIR> d-------- C:\Program Files\FBrowsingAdvisor
2008-04-08 21:23 . 2008-04-08 21:23 <DIR> d-------- C:\Program Files\321Studios
2008-04-08 20:52 . 1999-09-10 12:06 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2008-04-08 20:52 . 1999-09-10 12:06 25,244 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-04-08 20:52 . 1999-09-10 12:06 5,600 --a------ C:\WINDOWS\system\WINASPI.DLL
2008-04-08 20:52 . 1999-09-10 12:06 4,672 --a------ C:\WINDOWS\system\WOWPOST.EXE
2008-04-08 20:41 . 2008-04-08 20:41 <DIR> d-------- C:\ConverterOutput
2008-04-08 20:40 . 2008-04-08 20:40 <DIR> d-------- C:\Program Files\Cucusoft
2008-04-08 20:40 . 2007-03-25 00:51 3,049,984 --a------ C:\WINDOWS\system32\libavcodec.dll
2008-04-08 20:40 . 2007-03-25 21:40 2,174,976 --a------ C:\WINDOWS\system32\ffdshow.ax
2008-04-08 20:40 . 2007-03-25 00:51 404,480 --a------ C:\WINDOWS\system32\libmplayer.dll
2008-04-08 20:40 . 2007-01-01 05:30 200,704 --a------ C:\WINDOWS\system32\TomsMoComp_ff.dll
2008-04-08 20:40 . 2007-03-25 00:51 114,688 --a------ C:\WINDOWS\system32\libmpeg2_ff.dll
2008-04-08 20:40 . 2007-02-27 19:36 53,248 --a------ C:\WINDOWS\system32\xvid.ax
2008-04-08 20:40 . 2004-09-10 13:50 34,820 --a------ C:\WINDOWS\system32\ffdshow.reg
2008-04-08 20:39 . 2008-04-08 20:39 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-04-05 20:16 . 2004-08-04 05:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-05 20:14 . 2008-04-05 20:14 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-04-05 20:06 . 2008-04-05 20:06 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-04-05 20:06 . 2008-04-05 20:11 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-04-03 15:19 . 2008-04-03 15:19 <DIR> d-------- C:\WINDOWS\Sun
2008-04-03 06:43 . 2008-04-09 12:02 <DIR> d-------- C:\Documents and Settings\N1N3TY51X\Application Data\LimeWire
2008-04-03 00:41 . 2008-03-01 06:06 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-03 00:41 . 2007-06-30 20:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-03 00:41 . 2007-06-30 20:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-03 00:41 . 2008-03-01 06:06 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-03 00:41 . 2008-03-01 06:06 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-03 00:41 . 2008-03-01 06:06 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-03 00:41 . 2008-03-01 06:06 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-03 00:41 . 2008-03-01 06:06 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-03 00:41 . 2008-02-22 03:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-03 00:33 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-03 00:15 . 2008-04-03 00:33 <DIR> d-------- C:\Program Files\Java
2008-04-03 00:15 . 2008-04-03 00:15 <DIR> d-------- C:\Program Files\Common Files\Java
2008-04-03 00:13 . 2008-04-09 12:02 <DIR> d-------- C:\Program Files\LimeWire
2008-04-02 23:53 . 2008-04-02 23:53 1,158 --a------ C:\WINDOWS\mozver.dat
2008-04-02 23:50 . 2008-04-02 23:50 <DIR> d-------- C:\Documents and Settings\N1N3TY51X\Application Data\Talkback
2008-04-02 23:50 . 2008-04-02 23:50 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-02 23:27 . 2008-04-02 23:27 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-02 19:31 . 2008-04-02 19:32 <DIR> d-------- C:\Documents and Settings\N1N3TY51X\Application Data\Yahoo!
2008-04-02 19:31 . 2008-04-02 19:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-02 19:24 . 2008-04-02 19:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-02 19:23 . 2008-04-02 19:24 <DIR> d-------- C:\Program Files\Yahoo!
2008-04-02 13:28 . 2008-04-15 22:22 7,300 --a------ C:\WINDOWS\system32\Config.MPF
2008-04-02 13:26 . 2006-03-03 12:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-04-02 13:21 . 2008-02-06 10:51 171,400 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-04-02 13:21 . 2007-06-25 15:54 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-04-02 13:21 . 2007-06-25 11:57 37,480 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-04-02 13:21 . 2007-06-25 11:57 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-04-02 13:21 . 2007-06-25 11:57 32,008 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-04-02 13:20 . 2007-03-02 15:16 109,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-04-02 13:16 . 2008-04-02 13:17 <DIR> d-------- C:\Program Files\McAfee.com
2008-04-02 13:16 . 2008-04-02 13:33 <DIR> d-------- C:\Program Files\McAfee
2008-04-02 13:16 . 2008-04-02 13:26 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-04-02 13:08 . 2008-04-02 13:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-04-02 12:57 . 2006-09-25 17:58 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-04-02 12:56 . 2008-04-08 15:31 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-04-02 12:53 . 2007-07-30 20:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-04-02 12:53 . 2007-07-30 20:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-04-02 12:53 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-04-02 12:53 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-04-02 12:53 . 2007-07-30 20:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-04-02 12:22 . 2008-04-02 12:22 <DIR> d-------- C:\Program Files\support.com
2008-04-02 12:22 . 2008-04-02 12:22 <DIR> d-------- C:\Program Files\Common Files\SupportSoft
2008-04-02 12:22 . 2008-04-02 12:22 1,000 --a------ C:\net_save.dna
2008-03-29 20:33 . 2008-03-29 20:33 94,208 --a------ C:\WINDOWS\ScUnin.exe
2008-03-29 20:33 . 2008-03-29 20:33 13,044 --a------ C:\WINDOWS\scunin.dat
2008-03-29 20:33 . 2008-03-29 20:33 967 --a------ C:\WINDOWS\ScUnin.pif
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-09 03:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-04-05 06:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-13 21:15 --------- d-----w C:\Program Files\HP
2008-03-06 03:51 --------- d-----w C:\Program Files\Common Files\HP
2008-03-06 03:49 --------- d-----w C:\Program Files\Hewlett-Packard
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-22 01:06 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-22 01:04 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-21 21:05 --------- d-----w C:\Program Files\Dirct x
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2004-12-14 09:07 176128]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogoff"= 0 (0x0)
"NoRecentDocsNetHood"= 01000000
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
"NoNetworkConnections"= 01000000
"NoUserNameInStartMenu"= 01000000
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^N1N3TY51X^Start Menu^Programs^Startup^Backyard Skateboarding Registration.lnk]
path=C:\Documents and Settings\N1N3TY51X\Start Menu\Programs\Startup\Backyard Skateboarding Registration.lnk
backup=C:\WINDOWS\pss\Backyard Skateboarding Registration.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]
-----c--- 2002-05-02 08:57 98304 C:\Program Files\ATI Multimedia\main\launchpd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Remote Control]
C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a--c--- 2002-11-01 11:28 294912 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a--c--- 2004-09-13 15:49 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
-----c--- 2005-02-10 17:00 1937408 C:\Program Files\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"Pml Driver HPZ12"=2 (0x2)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"Adobe LM Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
R3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys [2001-10-10 23:51]
S2 CINEMSUP;Software Cinemaster NT4.0 Driver;C:\WINDOWS\system32\DRIVERS\CINEMSUP.SYS []
S3 MaRdPnp;MaRdPnp;C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys [2004-09-12 20:11]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-02 20:17:27 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-04-02 20:17:24 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-15 22:30:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-15 22:32:38
ComboFix-quarantined-files.txt 2008-04-16 05:32:33
Pre-Run: 4,770,041,856 bytes free
Post-Run: 4,841,197,568 bytes free
.
2008-04-14 15:10:51 --- E O F ---