ComboFix 08-04-26.1 - owner 2008-04-27 11:59:25.1 - NTFSx86
Running from: C:\Documents and Settings\owner\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-27 to 2008-04-27 )))))))))))))))))))))))))))))))
.
2008-04-27 11:36 . 2007-12-12 15:41 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-04-27 11:23 . 2008-04-27 11:23 <DIR> d-------- C:\Deckard
2008-04-27 02:03 . 2008-04-27 02:18 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-04-27 02:03 . 2008-04-27 02:03 <DIR> d-------- C:\Documents and Settings\owner\Application Data\PC Tools
2008-04-27 02:03 . 2008-04-27 11:59 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-27 02:03 . 2007-12-10 13:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-27 02:03 . 2007-12-10 13:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-27 02:03 . 2008-02-01 11:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-27 02:03 . 2007-12-10 13:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-04-26 23:07 . 2008-04-26 23:07 <DIR> d-------- C:\Documents and Settings\owner\Application Data\TmpRecentIcons
2008-04-26 21:39 . 2008-04-26 21:39 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-26 20:39 . 2008-04-26 20:40 <DIR> d-------- C:\Program Files\XoftSpySE
2008-04-26 20:25 . 2008-04-26 20:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\mhuzyxcr
2008-04-26 20:24 . 2008-04-26 08:17 331,776 --a------ C:\WINDOWS\bdkpfxqw.dll
2008-04-26 20:24 . 2008-04-26 08:17 307,200 --a------ C:\WINDOWS\qadovnel.dll
2008-04-26 20:24 . 2008-04-26 08:18 262,144 --a------ C:\WINDOWS\gndarmblvpg.dll
2008-04-26 20:24 . 2008-04-26 08:18 188,416 --a------ C:\WINDOWS\wxdbpfvo.dll
2008-04-26 20:24 . 2008-04-26 08:17 106,496 --a------ C:\WINDOWS\xbaqktfv.exe
2008-04-26 20:24 . 2008-04-26 08:18 90,112 --a------ C:\WINDOWS\spwoqbmv.exe
2008-04-22 15:24 . 2008-04-22 15:27 <DIR> d-------- C:\Program Files\ICQ6
2008-04-05 12:37 . 2008-04-05 12:37 <DIR> d-------- C:\Logs
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 16:11 --------- d-----w C:\Documents and Settings\owner\Application Data\OpenOffice.org2
2008-04-27 16:08 --------- d-----w C:\Documents and Settings\owner\Application Data\Skype
2008-04-27 06:45 --------- d-----w C:\Documents and Settings\owner\Application Data\skypePM
2008-04-27 06:38 4,332 ----a-w C:\WINDOWS\system32\tmp.reg
2008-04-24 21:03 398 ----a-w C:\Documents and Settings\owner\Application Data\wklnhst.dat
2008-04-22 20:25 --------- d-----w C:\Program Files\ICQToolbar
2008-04-20 02:11 --------- d-----w C:\Program Files\World of Warcraft
2008-04-13 20:51 --------- d-----w C:\Documents and Settings\owner\Application Data\LimeWire
2008-03-27 16:47 --------- d-----w C:\Program Files\Java
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-14 02:05 --------- d-----w C:\Documents and Settings\owner\Application Data\Ventrilo
2008-03-13 16:51 --------- d-----w C:\Program Files\EuroTalk
2008-03-13 16:51 --------- d-----w C:\Documents and Settings\owner\Application Data\EuroTalk
2008-03-10 21:49 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-01 23:36 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 05:44 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-01-14 22:02 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-03-08 14:20 72,776 ----a-w C:\Documents and Settings\owner\Application Data\GDIPFONTCACHEV1.DAT
2007-02-04 05:50 558,369 ----a-w C:\Program Files\F5D7230_6.00.03.rar
2003-08-05 17:41 53,248 ----a-w C:\WINDOWS\inf\ap561.exe
2002-11-26 22:24 32,768 ----a-w C:\WINDOWS\inf\Remove561.exe
2002-11-22 21:56 118,784 ----a-w C:\WINDOWS\inf\ShowBmp.exe
2002-10-30 00:07 36,864 ----a-w C:\WINDOWS\inf\Setup8a.exe
2002-10-01 20:43 119,798 ----a-w C:\WINDOWS\inf\spca561.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDFF8B71-EF58-4922-ACF2-2003FE2B7481}]
2008-04-26 08:18 262144 --a------ C:\WINDOWS\gndarmblvpg.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 11:15 50528]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 10:00 15360]
"igndlm.exe"="C:\Program Files\IGN\Download Manager\DLM.exe" [2007-01-11 17:07 972432]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-17 12:29 68856]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 15:22 4670968]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 19:04 5562368]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-12-07 16:08 21686568]
"ICQ"="C:\Program Files\ICQ6\ICQ.exe" [2008-04-01 05:40 172280]
"uwkledrs"="C:\WINDOWS\system32\urwvanap.exe" [2008-04-26 20:25 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-10 23:05 344064]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 01:11 49152]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 15:50 729178]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-09-17 09:27 52848]
"IS CfgWiz"="c:\Program Files\Norton Internet Security\cfgwiz.exe" [2005-09-30 07:33 120464]
"SSC_UserPrompt"="c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [2004-11-03 01:59 218240]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2005-12-12 13:39 94208]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-22 10:57 405504]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-08-01 16:26 233534]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 12:23 1187840]
"Reminder"="C:\Windows\CREATOR\Remind_XP.exe" [2006-02-09 11:52 643072]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 16:45 507904]
"Systems32"="C:\WINDOWS\system32\WinServer.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-13 13:35 185784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-11-02 03:11 282624]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 19:04 5562368]
C:\Documents and Settings\owner\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 23:57:56 393216]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Extender Resource Monitor.lnk - C:\WINDOWS\ehome\RMSysTry.exe [2005-10-20 20:55:40 18432]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bdkpfxqw"= {5CFD63CC-BF82-4E85-908D-5EE2A5E4E8E6} - C:\WINDOWS\bdkpfxqw.dll [2008-04-26 08:17 331776]
"qadovnel"= {8730FC6E-2A9B-43DB-A108-8EB238D88BA7} - C:\WINDOWS\qadovnel.dll [2008-04-26 08:17 307200]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\utorrent\\utorrent.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"6112:TCP"= 6112:TCP:Blizzard Downloader
"3724:TCP"= 3724:TCP:Blizzard Downloader
R2 RMSvc;Media Center Extender Resource Monitor;C:\WINDOWS\ehome\RMSvc.exe [2005-10-20 20:55]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
R2 X4HSX32;X4HSX32;C:\Program Files\GameTap\bin\Release\X4HSX32.Sys [2007-07-20 07:37]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 04:06]
S3 QWAVE;QWAVE service;C:\WINDOWS\system32\svchost.exe [2004-08-10 10:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
*Newly Created Service* - TMCOMM
.
Contents of the 'Scheduled Tasks' folder
"2006-04-13 13:39:39 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2008-04-27 16:04:49 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2008-04-27 01:39:42 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-27 12:04:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe??????????M????|?????? ???B?????????????hLC? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> ?:\WINDOWS\system32\MLANG.dll
-> ?:\WINDOWS\system32\MLANG.dll
-> ?:\WINDOWS\system32\MLANG.dll
-> ?:\WINDOWS\system32\MLANG.dll
.
Completion time: 2008-04-27 12:06:27
ComboFix-quarantined-files.txt 2008-04-27 17:05:57
ComboFix2.txt 2008-04-27 06:23:25
ComboFix3.txt 2008-04-27 02:32:38
Pre-Run: 10,236,502,016 bytes free
Post-Run: 10,240,286,720 bytes free
185 --- E O F --- 2008-04-09 08:03:47