ComboFix 08-05-08.1 - Administrator 2008-05-09 14:15:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.166 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\autorun.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\afboxtsg.ini
C:\WINDOWS\system32\coifreue.ini
C:\WINDOWS\system32\dcbrcblb.ini
C:\WINDOWS\system32\exjujvsb.ini
C:\WINDOWS\system32\gwawblgh.ini
C:\WINDOWS\system32\lmmorvru.ini
C:\WINDOWS\system32\watbjlao.ini
C:\WINDOWS\system32\yxmffnql.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-09 to 2008-05-09 )))))))))))))))))))))))))))))))
.
2009-03-22 22:58 . 2009-03-22 22:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2009-03-22 22:35 . 2009-03-22 22:35 <DIR> d-------- C:\Program Files\Alwil Software
2009-03-22 18:45 . 2007-11-15 10:06 301,656 --a------ C:\WINDOWS\system32\BtCoreIf.dll
2009-03-22 18:44 . 2009-03-22 18:45 <DIR> d-------- C:\Program Files\Common Files\Logishrd
2009-03-22 18:44 . 2009-03-22 18:44 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InstallShield
2009-03-22 15:32 . 2009-03-22 23:40 <DIR> d-------- C:\Program Files\eREAD6.0
2008-05-09 14:15 . 2008-05-09 14:15 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-05-02 01:10 . 2008-05-02 01:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-30 19:38 . 2008-04-30 19:38 <DIR> d-------- C:\Deckard
2008-04-26 01:26 . 2008-04-26 01:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-04-23 16:19 . 2008-04-23 16:23 <DIR> d-------- C:\Program Files\uTorrentSpeedOptimizer
2008-04-23 16:19 . 2001-09-06 10:00 1,700,352 --a------ C:\WINDOWS\system32\gdiplus.dll
2008-04-23 16:11 . 2008-04-23 16:14 <DIR> d-------- C:\Program Files\EZ Boosters
2008-04-23 15:56 . 2008-04-23 16:06 <DIR> d-------- C:\Program Files\FlashGet
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\VundoFix Backups
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\Program Files\Stardock
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-21 21:50 . 2008-04-21 21:50 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-04-20 17:31 . 2008-04-22 06:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Logitech
2008-04-20 17:29 . 2007-01-30 01:46 163,840 --a------ C:\WINDOWS\system32\kemutb.dll
2008-04-20 17:29 . 2007-01-30 01:46 135,168 --a------ C:\WINDOWS\system32\KemUtil.dll
2008-04-20 17:29 . 2007-01-30 01:46 110,592 --a------ C:\WINDOWS\system32\KemWnd.dll
2008-04-20 17:29 . 2007-01-30 01:46 69,632 --a------ C:\WINDOWS\system32\KemXML.dll
2008-04-20 17:28 . 2008-04-22 06:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-04-20 16:16 . 2008-04-20 16:16 0 --------- C:\WINDOWS\WB.ini
2008-04-20 16:04 . 2007-07-11 14:06 42,672 --------- C:\WINDOWS\system32\wbsys.dll
2008-04-20 15:33 . 2006-12-03 17:15 111,104 --a------ C:\WINDOWS\system32\uharc.exe
2008-04-20 15:33 . 2004-09-03 23:43 199 --a------ C:\WINDOWS\system32\paypal.url
2008-04-20 15:33 . 2006-05-26 22:54 83 --a------ C:\WINDOWS\system32\winx.url
2008-04-19 19:42 . 2008-04-19 19:42 182 --a------ C:\WINDOWS\ulead32.ini
2008-04-19 15:46 . 2008-04-22 06:42 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-04-19 15:46 . 2008-04-19 15:46 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-04-19 02:16 . 2008-04-19 02:16 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-19 02:16 . 2008-04-19 02:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-19 02:16 . 2008-04-19 02:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-04-19 02:15 . 2008-04-19 02:15 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-04-15 17:17 . 2008-04-15 17:18 <DIR> d-------- C:\Documents and Settings\Administrator\Sahil
2008-04-13 19:35 . 2008-04-13 19:42 <DIR> d-------- C:\Program Files\MessengerDiscovery
2008-04-13 19:35 . 2004-03-08 23:00 152,848 --a------ C:\WINDOWS\system32\comdlg32.OCX
2008-04-13 19:35 . 2004-03-09 01:00 124,688 --a------ C:\WINDOWS\system32\MSWINSCK.ocx
2008-04-13 15:21 . 2008-04-13 15:21 0 --a------ C:\WINDOWS\BM0f33d01b.xml
2008-04-13 00:04 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-04-13 00:04 . 2004-08-03 23:08 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-04-13 00:04 . 2008-04-13 00:04 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-04-13 00:04 . 2008-04-13 00:04 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-04-12 23:59 . 2008-02-01 15:17 138,112 --a------ C:\WINDOWS\system32\drivers\nmwcdnsu.sys
2008-04-12 23:59 . 2008-02-01 15:17 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdnsuc.sys
2008-04-12 23:58 . 2008-04-12 23:58 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-04-12 23:58 . 2007-11-29 10:33 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-04-12 23:58 . 2007-11-29 10:39 95,744 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-04-12 23:58 . 2007-11-29 10:39 19,328 --a------ C:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-04-12 23:58 . 2007-11-29 10:39 16,896 --a------ C:\WINDOWS\system32\drivers\ccdcmb.sys
2008-04-12 23:58 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
2008-04-12 23:58 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-04-09 16:12 . 2008-04-10 23:17 7,680 --ahs---- C:\WINDOWS\Thumbs.db
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-22 22:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2009-03-22 13:42 --------- d-----w C:\Program Files\PS2 Keyboard English Edition 2.0
2009-03-22 13:42 --------- d-----w C:\Program Files\Mouse
2009-03-22 13:03 --------- d-----w C:\Program Files\Java
2009-03-22 12:32 --------- d-----w C:\Program Files\Real
2008-05-09 11:20 404,512 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-09 11:20 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-05-09 11:19 12,388,128 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-09 11:18 45,188 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-09 11:18 170,072 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-30 13:49 --------- d-----w C:\Program Files\uTorrent
2008-04-23 12:33 360,064 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-04-22 03:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-22 03:42 --------- d-----w C:\Program Files\Logitech
2008-04-20 14:28 --------- d-----w C:\Program Files\Common Files\Logitech
2008-04-12 20:59 --------- d-----w C:\Program Files\Nokia
2008-04-12 20:54 --------- d-----w C:\Program Files\Common Files\Nokia
2008-04-12 20:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-04-12 11:10 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Vso
2008-04-07 14:50 --------- d-----w C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-04-02 19:03 --------- d-----w C:\Program Files\MegauploadToolbar
2008-04-02 19:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MegauploadToolbar
2008-03-30 23:27 --------- d-----w C:\Program Files\VideoLAN
2008-03-24 19:59 --------- d-----w C:\Program Files\Kaspersky Lab
2008-03-20 00:19 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-03-20 00:18 --------- d-----w C:\Program Files\Real Alternative
2008-03-20 00:08 --------- d-----w C:\Program Files\Common Files\Real
2008-03-18 20:12 --------- d-----w C:\Program Files\Azureus
2008-03-18 20:10 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Azureus
2008-03-18 11:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-03-17 01:50 --------- d-----w C:\Program Files\Total Video Converter
2008-03-13 18:18 --------- d-----w C:\Program Files\LimeWire
2008-03-04 14:19 87,608 ----a-w C:\Documents and Settings\Administrator\Application Data\inst.exe
2008-03-04 14:19 47,360 ----a-w C:\Documents and Settings\Administrator\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-14 22:46 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 15:00 15360]
"WhatPulse"="C:\Program Files\WhatPulse\WhatPulse.exe" [2006-08-21 20:48 665600]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-04-20 14:20 1481968]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2008-04-30 16:49 219952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 23:36 14854144 C:\WINDOWS\RTHDCPL.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CAMTRAY.EXE" [2004-07-30 11:04 245760]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 15:10 271360]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe]
"kav"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2006-03-24 19:09 139367]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 10:17 1241088]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-04-20 17:29:06 688128]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2008-04-20 14:20 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll 2007-11-15 10:10 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyxyxur]
xxyxyxur.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23381:UDP"= 23381:UDP:Utorrent
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2008-02-01 15:17]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2008-02-01 15:17]
S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39]
S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39]
S3 V0090VID;Creative WebCam Vista Plus;C:\WINDOWS\system32\DRIVERS\V0090Vid.sys [2005-04-14 04:00]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-09 10:54:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-09 14:19:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-05-09 14:21:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-09 11:21:50
Pre-Run: 30,911,033,344 bytes free
Post-Run: 30,823,124,992 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
217 --- E O F --- 2008-04-18 09:42:49
♠