ComboFix 08-04-27.3 - Kevin 2008-05-01 0:16:45.2 - NTFSx86
Running from: C:\Documents and Settings\Kevin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kevin\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\Internet Logs\tvDebug.zip
C:\WINDOWS\Internet Logs\xDB17.tmp
C:\WINDOWS\Internet Logs\xDB18.tmp
C:\WINDOWS\Internet Logs\xDB19.tmp
C:\WINDOWS\Internet Logs\xDB1A.tmp
C:\WINDOWS\Internet Logs\xDB1B.tmp
C:\WINDOWS\Internet Logs\xDB1C.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\WINDOWS\Internet Logs\tvDebug.zip
C:\WINDOWS\Internet Logs\xDB17.tmp
C:\WINDOWS\Internet Logs\xDB18.tmp
C:\WINDOWS\Internet Logs\xDB19.tmp
C:\WINDOWS\Internet Logs\xDB1A.tmp
C:\WINDOWS\Internet Logs\xDB1B.tmp
C:\WINDOWS\Internet Logs\xDB1C.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_GEEBERS12
-------\Legacy_IMSPCLOJ
-------\Legacy_KASPERSKY1
-------\Service_geebers12
-------\Service_iMSPCLOj
-------\Service_Kaspersky1
((((((((((((((((((((((((( Files Created from 2008-04-01 to 2008-05-01 )))))))))))))))))))))))))))))))
.
2008-04-29 16:34 . 2008-04-29 16:34 <DIR> d-------- C:\Documents and Settings\Kevin\Application Data\AVS4YOU
2008-04-29 16:33 . 2008-04-29 16:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-04-29 16:28 . 2008-04-29 17:26 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2008-04-27 13:59 . 2008-04-27 13:59 <DIR> d-------- C:\Documents and Settings\Kevin\Application Data\Malwarebytes
2008-04-27 13:58 . 2008-04-27 13:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-16 17:09 . 2008-04-30 23:05 959 --a--c--- C:\rollback.ini
2008-04-13 03:38 . 2008-04-13 03:38 268 --ah-c--- C:\sqmdata19.sqm
2008-04-13 03:38 . 2008-04-13 03:38 244 --ah-c--- C:\sqmnoopt19.sqm
2008-04-13 01:59 . 2008-04-13 01:59 268 --ah-c--- C:\sqmdata18.sqm
2008-04-13 01:59 . 2008-04-13 01:59 244 --ah-c--- C:\sqmnoopt18.sqm
2008-04-12 19:16 . 2008-04-12 19:16 268 --ah-c--- C:\sqmdata17.sqm
2008-04-12 19:16 . 2008-04-12 19:16 244 --ah-c--- C:\sqmnoopt17.sqm
2008-04-12 18:45 . 2008-04-12 18:45 <DIR> d-------- C:\Documents and Settings\Gordon\Application Data\TaxCut
2008-04-12 18:38 . 2008-04-12 18:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TaxCut
2008-04-09 03:59 . 2008-04-09 03:59 268 --ah-c--- C:\sqmdata16.sqm
2008-04-09 03:59 . 2008-04-09 03:59 244 --ah-c--- C:\sqmnoopt16.sqm
2008-04-06 02:10 . 2008-04-06 02:10 244 --ah-c--- C:\sqmnoopt15.sqm
2008-04-06 02:10 . 2008-04-06 02:10 232 --ah-c--- C:\sqmdata15.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-01 07:38 14,081,568 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-01 07:30 189,620 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-30 07:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-04-29 23:08 2,793,472 ----a-w C:\WINDOWS\Internet Logs\xDB1F.tmp
2008-04-29 23:08 1,796,608 ----a-w C:\WINDOWS\Internet Logs\xDB1E.tmp
2008-04-29 22:53 2,792,960 ----a-w C:\WINDOWS\Internet Logs\xDB1D.tmp
2008-04-26 05:03 --------- d-----w C:\Documents and Settings\Kevin\Application Data\AVG7
2008-04-24 21:33 --------- d-----w C:\Documents and Settings\Kevin\Application Data\uTorrent
2008-04-14 21:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-04-13 02:13 51,716 ----a-w C:\WINDOWS\system32\pdf995mon.dll
2008-04-13 02:13 249,856 ----a-w C:\WINDOWS\system32\pdfmona.dll
2008-03-23 03:16 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Viewpoint
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-14 06:11 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-03-14 06:11 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2008-03-05 11:52 --------- d-----w C:\Documents and Settings\Kevin\Application Data\Free Download Manager
2008-03-03 22:50 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-03 22:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
1601-01-01 00:00 0 ------w C:\Program Files\
.
((((((((((((((((((((((((((((( snapshot@2008-04-28_16.03.41.51 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-28 22:52:18 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-01 07:33:35 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2007-02-28 02:36:08 638,976 ----a-w C:\WINDOWS\system32\divx.dll
- 2008-04-13 02:18:55 240,736 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-04-30 14:17:40 241,536 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2007-02-28 02:36:14 1,700,352 ----a-w C:\WINDOWS\system32\GdiPlus.dll
+ 2007-02-28 02:36:08 261,632 ----a-w C:\WINDOWS\system32\mcdvd_32.dll
+ 2007-02-28 02:36:14 974,848 ----a-w C:\WINDOWS\system32\mfc70.dll
+ 2007-02-28 02:36:08 413,760 ----a-w C:\WINDOWS\system32\mpg4c32.dll
+ 2007-02-28 02:36:14 487,424 ----a-w C:\WINDOWS\system32\msvcp70.dll
+ 2007-02-28 02:36:14 344,064 ----a-w C:\WINDOWS\system32\msvcr70.dll
- 2001-03-09 02:30:00 24,064 ----a-w C:\WINDOWS\system32\msxml3a.dll
+ 2007-02-28 02:36:12 24,576 ----a-w C:\WINDOWS\system32\msxml3a.dll
- 2006-11-01 22:52:38 765,952 ----a-w C:\WINDOWS\system32\xvidcore.dll
+ 2007-02-28 02:36:08 524,288 ----a-w C:\WINDOWS\system32\xvidcore.dll
- 2006-11-01 22:54:30 180,224 ----a-w C:\WINDOWS\system32\xvidvfw.dll
+ 2007-02-28 02:36:08 139,264 ----a-w C:\WINDOWS\system32\xvidvfw.dll
- 2008-04-28 21:24:13 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
+ 2008-04-28 23:14:52 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
- 2008-04-28 21:36:04 566,060 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2008-05-01 06:05:44 575,076 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
- 2008-04-25 15:07:26 8,849,255 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
+ 2008-04-30 23:24:52 8,900,532 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
- 2008-04-28 22:09:45 4,096 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2008-05-01 07:17:28 5,632 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2006-12-02 07:08:00 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-02 07:08:00 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-02 07:08:00 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-02 07:08:00 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-02 07:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-02 07:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-02 07:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-02 07:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-02 07:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-02 07:46:44 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-03 06:54 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2005-07-20 22:07 7110656]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 14:22 3739648]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-12 16:35 185632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-13 23:11 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-24 15:59 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 01:15:54 65588]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Kevin^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\Kevin\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
--a------ 2008-04-25 09:38 579584 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 06:24 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2007-12-24 18:20 1266936 c:\program files\steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-09-12 16:35 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
--a------ 2007-10-03 17:31 3256320 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Steam\\Steam.exe"=
"C:\\Program Files\\Steam\\steamapps\\spherimorph\\condition zero\\hl.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Steam\\steamapps\\spherimorph\\counter-strike\\hl.exe"=
"C:\\Program Files\\Steam\\steamapps\\darkfl4m3\\counter-strike\\hl.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Eclipse\\eclipse.exe"=
"C:\\Program Files\\Eclipse\\jre\\bin\\javaw.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Sierra\\Empire Earth II\\EE2.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R2 Pctspk;PCTEL Speaker Phone;C:\WINDOWS\system32\pctspk.exe [2001-08-17 15:36]
R3 Ptserlp;PCTEL Serial Device Driver for PCI;C:\WINDOWS\system32\DRIVERS\ptserlp.sys [2001-08-17 06:28]
S4 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2007-10-12 09:34]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-27 23:16:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-01 00:35:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-05-01 0:44:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-01 07:44:21
ComboFix2.txt 2008-04-28 23:04:59
Pre-Run: 6,074,224,640 bytes free
Post-Run: 6,137,421,824 bytes free
230 --- E O F --- 2008-04-09 10:10:52
I'm still unable to access my Program Files folder