ComboFix 08-04-20.5 - Alex 2008-04-21 19:15:25.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.599 [GMT -7:00]
Running from: C:\Documents and Settings\Alex\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Alex\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Alex\Application Data\macromedia\Flash Player\#SharedObjects\D86KUP8J\www.broadcaster.com
C:\Documents and Settings\Alex\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Alex\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\123messenger.per
C:\WINDOWS\2020search.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\apphelp32.dll
C:\WINDOWS\asferror32.dll
C:\WINDOWS\asycfilt32.dll
C:\WINDOWS\athprxy32.dll
C:\WINDOWS\ati2dvaa32.dll
C:\WINDOWS\ati2dvag32.dll
C:\WINDOWS\audiosrv32.dll
C:\WINDOWS\autodisc32.dll
C:\WINDOWS\avifile32.dll
C:\WINDOWS\avisynthex32.dll
C:\WINDOWS\aviwrap32.dll
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\browserad.dll
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\changeurl_30.dll
C:\WINDOWS\default.htm
C:\WINDOWS\didduid.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\lfn.exe
C:\WINDOWS\licencia.txt
C:\WINDOWS\msa64chk.dll
C:\WINDOWS\msapasrc.dll
C:\WINDOWS\mspphe.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\ntnut.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\saiemod.dll
C:\WINDOWS\shdocpe.dll
C:\WINDOWS\shdocpl.dll
C:\WINDOWS\stcloader.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\kgpllesj.dll
C:\WINDOWS\system32\wmsdkns.exe
C:\WINDOWS\telefonos.txt
C:\WINDOWS\textos.txt
C:\WINDOWS\voiceip.dll
C:\WINDOWS\winsb.dll
C:\WINDOWS\winself.exe
----- BITS: Possible infected sites -----
hxxp://80.93.48.74
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MsSecurity1.209.4
-------\Service_MsSecurity1.209.4
((((((((((((((((((((((((( Files Created from 2008-03-22 to 2008-04-22 )))))))))))))))))))))))))))))))
.
2008-04-21 11:13 . 2008-04-21 11:13 <DIR> d-------- C:\Documents and Settings\Alex\Application Data\Malwarebytes
2008-04-21 11:12 . 2008-04-21 17:31 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-21 11:12 . 2008-04-21 11:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-21 11:10 . 2008-04-21 11:10 <DIR> d-------- C:\_OTMoveIt
2008-04-21 11:02 . 2008-04-21 11:02 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-21 10:59 . 2008-04-21 10:59 <DIR> d-------- C:\Program Files\ERUNT
2008-04-20 21:03 . 2008-04-20 21:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel
2008-04-20 21:02 . 2004-11-15 20:57 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-04-20 21:02 . 2004-11-15 22:30 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver
2008-04-20 21:02 . 2001-04-04 02:31 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\toshiba
2008-04-20 21:02 . 2004-11-15 22:07 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-04-20 21:02 . 2004-11-15 21:32 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intuit
2008-04-20 21:02 . 2004-11-15 23:07 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterVideo
2008-04-20 21:02 . 2004-11-15 22:22 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-04-20 21:02 . 2004-11-15 22:44 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AOL
2008-04-20 21:02 . 2008-04-20 21:02 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-20 21:02 . 2008-04-21 19:13 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-04-20 20:57 . 2008-04-21 10:43 1,246 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-20 20:55 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-04-20 20:55 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-04-20 20:55 . 2008-04-14 19:28 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-20 20:55 . 2008-04-20 00:38 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-20 20:55 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-04-20 20:55 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-20 20:55 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-20 20:41 . 2008-04-20 20:41 <DIR> d-------- C:\Program Files\backups
2008-04-20 20:35 . 2008-04-20 20:35 401,720 --a------ C:\Program Files\HiJackThis.exe
2008-04-20 17:12 . 2008-04-21 10:58 109,798 --a------ C:\WINDOWS\BMb78e940f.xml
2008-04-20 12:20 . 2008-04-21 12:21 138 -r-hs---- C:\WINDOWS\mainms.vpi
2008-04-20 12:20 . 2008-04-21 19:09 33 -r-hs---- C:\WINDOWS\muotr.so
2008-04-20 12:20 . 2008-04-21 19:07 4 --------- C:\WINDOWS\megavid.cdt
2008-04-20 12:19 . 2008-04-20 12:19 398 --a------ C:\WINDOWS\system32\LB1C4.tmp
2008-04-20 12:19 . 2008-04-20 12:19 398 --a------ C:\WINDOWS\system32\LB0DD.tmp
2008-04-20 12:19 . 2008-04-20 12:19 398 --a------ C:\WINDOWS\system32\LAD8A.tmp
2008-04-20 12:19 . 2008-04-20 12:19 398 --a------ C:\WINDOWS\system32\LA8B0.tmp
2008-04-13 16:55 . 2008-04-13 16:55 <DIR> d-------- C:\WINDOWS\system32\COD4MW Screensaver dir
2008-04-13 16:55 . 2008-04-13 16:55 203,264 --a------ C:\WINDOWS\system32\COD4MW Screensaver.scr
2008-04-10 20:52 . 2008-04-19 16:09 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-05 21:27 . 2008-04-05 21:27 38 --a------ C:\WINDOWS\AviSplitter.INI
2008-04-04 20:49 . 2008-04-04 20:49 <DIR> d-------- C:\Program Files\iTunes
2008-04-04 20:49 . 2008-04-04 20:49 <DIR> d-------- C:\Program Files\iPod
2008-04-04 20:46 . 2008-04-04 20:46 <DIR> d-------- C:\Program Files\QuickTime
2008-03-31 19:15 . 2008-04-20 17:18 <DIR> d-------- C:\Program Files\VirtuaWin
2008-03-31 19:15 . 2008-03-31 19:15 <DIR> d-------- C:\Documents and Settings\Alex\Application Data\VirtuaWin
2008-03-31 19:11 . 2008-03-31 19:11 <DIR> d-------- C:\Program Files\Techlogg.com ToneShop
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-03-26 14:26 . 2008-03-26 14:26 <DIR> d-------- C:\Program Files\Western Digital Technologies
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-21 03:42 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-20 19:23 --------- d-----w C:\Documents and Settings\Alex\Application Data\Azureus
2008-04-20 02:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-04-19 03:41 --------- d-----w C:\Program Files\Apple Software Update
2008-04-17 23:11 --------- d-----w C:\Program Files\Azureus
2008-04-11 06:23 --------- d-----w C:\Program Files\VideoLAN
2008-03-23 16:01 --------- d-----w C:\Documents and Settings\Alex\Application Data\Tunebite
2008-03-23 15:59 --------- d-----w C:\Program Files\Google
2008-03-23 15:59 --------- d-----w C:\Program Files\Bulk Rename Utility
2008-03-18 00:22 --------- d-----w C:\Program Files\Conduit
2008-03-18 00:22 --------- d-----w C:\Program Files\BTjunkie
2008-03-13 14:06 --------- d-----w C:\Program Files\MSXML 6.0
2008-03-12 23:54 --------- d-----w C:\Documents and Settings\Alex\Application Data\Apple Computer
2008-03-12 02:19 --------- d-----w C:\Program Files\Illustrate
2008-03-12 02:19 --------- d-----w C:\Documents and Settings\Alex\Application Data\AccurateRip
2008-03-12 01:29 --------- d-----w C:\Program Files\Reference Assemblies
2008-03-03 04:28 --------- d-----w C:\Program Files\IrfanView
2008-02-25 21:36 --------- d-----w C:\Documents and Settings\Alex\Application Data\Any Video Converter
2008-02-22 08:35 --------- d-----w C:\Program Files\MSBuild
2008-02-22 08:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-22 08:19 --------- d-----w C:\Program Files\Microsoft XNA
2008-02-22 08:06 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-02-22 07:13 --------- d-----w C:\Documents and Settings\Alex\Application Data\RTPlayer
2008-02-22 07:10 --------- d-----w C:\Program Files\PixiePack Codec Pack
2008-02-22 07:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\RapidSolution
2008-02-22 07:07 --------- d-----w C:\Program Files\RapidSolution
2008-02-22 06:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-17 23:11 12,288 ----a-w C:\WINDOWS\impborl.dll
2003-08-27 22:19 36,963 -c--a-r C:\Program Files\Common Files\SM1updtr.dll
2007-11-19 22:12 2 --shatr C:\WINDOWS\winstart.bat
2007-11-19 22:24 438,440 -csha-w C:\WINDOWS\system32\cehkj.ini2
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1a71246c-3eb0-4d6c-af77-3ab756017c3a}]
2008-03-13 10:30 1524248 --a------ C:\Program Files\BTjunkie\tbBTju.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{1A71246C-3EB0-4D6C-AF77-3AB756017C3A}"= C:\Program Files\BTjunkie\tbBTju.dll [2008-03-13 10:30 1524248]
[HKEY_CLASSES_ROOT\clsid\{1a71246c-3eb0-4d6c-af77-3ab756017c3a}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
C:\Documents and Settings\Alex\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE [2005-10-20 12:04:08 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-10-15 11:27 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= C:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"=
"C:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"=
"C:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
"C:\\Documents and Settings\\Alex\\Desktop\\MySpaceMp3Gopher.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"41952:TCP"= 41952:TCP:tyversityport
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e27fb7b0-e1a1-11db-a85b-00038a000015}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{621FCD24-4498-4324-A81E-07D331376EDF}]
C:\Program Files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-04-19 03:41:36 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-21 19:20:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-04-21 19:26:54 - machine was rebooted [Alex]
ComboFix-quarantined-files.txt 2008-04-22 02:26:49
Pre-Run: 19,770,658,816 bytes free
Post-Run: 20,135,043,072 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
239 --- E O F --- 2008-04-21 17:18:53