ComboFix 08-05-12.1 - User 2008-05-13 19:15:08.1 - NTFSx86
Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\_000110_.tmp.dll
C:\WINDOWS\system32\ctfmona.exe
.
((((((((((((((((((((((((( Files Created from 2008-04-13 to 2008-05-13 )))))))))))))))))))))))))))))))
.
2008-05-13 18:42 . 2008-05-13 18:42 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-13 16:09 . 2008-05-13 16:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adsl Software Limited
2008-05-13 16:09 . 2008-05-13 16:09 269,334 --a------ C:\WINDOWS\system32\ctfmonb.bmp
2008-05-13 16:09 . 2008-05-13 16:09 160,256 --a------ C:\WINDOWS\system32\blackster.scr
2008-05-09 18:44 . 2008-05-09 18:44 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-05-03 11:43 . 2008-05-03 11:43 65,024 --a------ C:\WINDOWS\IFinst26.exe
2008-05-01 14:36 . 2008-05-01 14:38 12,363,488 --a------ C:\WINDOWS\BMW 3 Series Coupé.exe
2008-05-01 14:36 . 2008-05-01 14:38 302,244 --a------ C:\WINDOWS\BMW 3 Series Coupé.scr
2008-05-01 14:36 . 2008-05-01 14:38 40,960 --a------ C:\WINDOWS\BMW 3 Series Coupé.dll
2008-05-01 14:36 . 2008-05-01 14:38 18,192 --a------ C:\WINDOWS\BMW 3 Series Coupé.dat
2008-05-01 12:28 . 2008-05-01 12:28 <DIR> d-------- C:\Program Files\Apple Software Update
2008-04-28 20:53 . 2008-04-28 21:05 <DIR> d-------- C:\Documents and Settings\User\Application Data\GanymedeNet
2008-04-22 12:06 . 2008-04-22 12:06 <DIR> d-------- C:\THINK_X
2008-04-22 12:06 . 1994-08-24 00:00 188,960 --a------ C:\WINDOWS\system\WINGDE.DLL
2008-04-22 12:06 . 1994-09-21 00:00 92,208 --a------ C:\WINDOWS\system\WING.DLL
2008-04-22 12:06 . 1994-09-21 00:00 12,800 --a------ C:\WINDOWS\system\WING32.DLL
2008-04-22 12:06 . 1994-09-21 00:00 6,736 --a------ C:\WINDOWS\system\WINGDIB.DRV
2008-04-22 12:06 . 1994-09-21 00:00 5,024 --a------ C:\WINDOWS\system\WINGPAL.WND
2008-04-22 12:06 . 1994-06-27 00:00 1,966 --a------ C:\WINDOWS\system\DVA.386
2008-04-22 12:06 . 2008-04-25 18:03 49 --a------ C:\WINDOWS\TC.INI
2008-04-19 13:40 . 2003-05-23 10:10 26,112 -ra------ C:\WINDOWS\LgUninst.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-10 06:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-09 00:57 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-08 14:31 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-04-26 11:51 --------- d-----w C:\Documents and Settings\User\Application Data\Apple Computer
2008-04-22 12:10 --------- d-----w C:\Documents and Settings\User\Application Data\My Battle for Middle-earth II Files
2008-04-22 08:31 --------- d-----w C:\Documents and Settings\User\Application Data\Hamachi
2008-04-21 11:18 31,856 ----a-w C:\Documents and Settings\User\Application Data\GDIPFONTCACHEV1.DAT
2008-04-11 07:18 --------- d--h--w C:\Documents and Settings\All Users\Application Data\{0E8E33D8-193A-414A-A909-0F101A142D26}
2008-04-11 07:13 --------- d-----w C:\Program Files\Stardock Games
2008-04-11 05:01 --------- d-----w C:\Program Files\QuickTime
2008-04-10 07:13 --------- d-----w C:\Program Files\iTunes
2008-04-10 07:12 --------- d-----w C:\Program Files\iPod
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-25 08:03 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 08:44 4,608 ----a-w C:\WINDOWS\system32\w95inf32.dll
2008-02-16 08:44 2,272 ----a-w C:\WINDOWS\system32\w95inf16.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 10:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00 15360]
"MalWarrior"="C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\MalWarrior 2008\Malwarrior.exe" [2008-05-13 16:10 1025536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 21:05 344064]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 07:56 139264]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 18:20 339968 C:\WINDOWS\stsystra.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 03:25 144784]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 20:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 20:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 20:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 20:00 455168]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 16:19 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-03-16 05:33 127037]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50 81920]
"snpstd3"="C:\WINDOWS\vsnpstd3.exe" [2006-09-19 08:07 827392]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-17 11:42 58728]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-11-23 09:30 100056]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 21:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"sjbhyymn"="C:\WINDOWS\system32\sjbhyymn.exe" [ ]
"enzx"="C:\WINDOWS\system32\enzx.exe" [ ]
"ctfmona"="C:\WINDOWS\system32\ctfmona.exe" [ ]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-01-23 15:47 847872]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= D:\Eugene\Games\Maplesea\l3codeca.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Eugene\\hamachi\\hamachi.exe"=
"D:\\Eugene\\Games\\Maplesea\\MapleStory.exe"=
"C:\\Program Files\\LucasArts\\Star Wars Galactic Battlegrounds Saga\\Game\\battlegrounds_x1.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"D:\\Eugene\\Games\\Battefield 2\\BF2.exe"=
"D:\\Eugene\\Games\\BFME 2\\game.dat"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
R3 2WIREPCP;2Wire USB;C:\WINDOWS\system32\DRIVERS\2WirePCP.sys [2004-10-19 06:44]
S2 o3iaraaay;Dell Printer Status Watcher;C:\WINDOWS\system32\enzx.exe []
S3 PVUSB;CESG502 USB Driver;C:\WINDOWS\system32\DRIVERS\CESG502.sys [2008-02-19 18:17]
*Newly Created Service* - CATCHME
*Newly Created Service* - MCHINJDRV
.
Contents of the 'Scheduled Tasks' folder
"2008-05-12 11:30:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-09 16:51:58 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - User.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-13 19:24:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
.
Completion time: 2008-05-13 19:28:46
ComboFix-quarantined-files.txt 2008-05-13 11:27:39
Pre-Run: 19,948,138,496 bytes free
Post-Run: 21,203,890,176 bytes free
145 --- E O F --- 2008-05-10 14:30:00