combofix log:
ComboFix 08-05-28.4 - sbalsinger 2008-05-29 10:40:58.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.698 [GMT -4:00]
Running from: C:\Documents and Settings\sbalsinger\Desktop\Combo-Fix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\clbdriver.sys
.
---- Previous Run -------
.
C:\Documents and Settings\administrator.CAMBRIA\cftmon.exe
C:\Documents and Settings\Administrator\cftmon.exe
C:\Documents and Settings\LocalService\cftmon.exe
C:\Documents and Settings\sbalsinger\Application Data\install.dat
C:\Documents and Settings\sbalsinger\cftmon.exe
C:\Program Files\WinAntivirusPro3.8
C:\Program Files\WinAntivirusPro3.8\WinAntivirusPro.exe
C:\WINDOWS\system32\__c00166B2.exe
C:\WINDOWS\system32\__c0030350.exe
C:\WINDOWS\system32\__c00362A.exe
C:\WINDOWS\system32\__c0074305.exe
C:\WINDOWS\system32\__c008DD0C.exe
C:\WINDOWS\system32\__c00A8054.dat
C:\WINDOWS\system32\__c00AC88E.dat
C:\WINDOWS\system32\__c00D9790.exe
C:\WINDOWS\system32\__c00DA46F.exe
C:\WINDOWS\system32\__c00EF9A0.exe
C:\WINDOWS\system32\__c00F3E24.exe
C:\WINDOWS\system32\__c00F71C6.exe
C:\WINDOWS\system32\baseatc32.dll
C:\WINDOWS\system32\clbdll.dll
C:\WINDOWS\system32\drivers\spools.exe
C:\windows\xpupdate.exe
C:\xcrashdump.dat
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-29 )))))))))))))))))))))))))))))))
.
2008-05-28 14:44 . 2008-05-28 14:44 61,440 --a------ C:\WINDOWS\system32\rexesvr.exe
2008-05-28 11:18 . 2004-03-04 23:46 83,168 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-05-28 11:18 . 2004-03-04 23:46 82,832 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-28 10:27 . 2008-05-28 10:27 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-28 09:55 . 2008-05-28 10:34 <DIR> d-------- C:\SDFix
2008-05-28 09:51 . 2008-05-28 09:51 1,681,135 --a------ C:\SDFix.exe
2008-05-28 09:41 . 2008-05-28 09:41 <DIR> d-------- C:\_OTMoveIt
2008-05-27 15:14 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-05-27 15:14 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-05-27 15:14 . 2008-04-13 23:31 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-05-27 15:14 . 2008-04-12 13:49 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-05-27 15:14 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-27 15:14 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-27 15:14 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-27 15:07 . 2008-05-28 13:33 5,120 --a------ C:\Documents and Settings\Administrator\ftp34.dll
2008-05-27 15:03 . 2008-05-28 13:25 5,120 --a------ C:\Documents and Settings\administrator.CAMBRIA\ftp34.dll
2008-05-27 11:01 . 2004-08-04 06:00 4,224 --a------ C:\WINDOWS\system32\beep.sys
2008-05-27 08:40 . 2008-05-28 14:34 5,120 --a------ C:\Documents and Settings\LocalService\ftp34.dll
2008-05-22 09:40 . 2008-05-28 15:21 5,120 --a------ C:\WINDOWS\system32\ftp34.dll
2008-05-22 09:40 . 2008-05-28 15:21 5,120 --a------ C:\Documents and Settings\sbalsinger\ftp34.dll
2008-04-30 09:50 . 2008-04-30 09:50 101,153 --a------ C:\WINDOWS\system32\usb
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-29 14:43 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-05-28 15:18 --------- d-----w C:\Program Files\Symantec
2008-05-28 15:18 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-28 15:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-27 16:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-20 13:03 --------- d-----w C:\Documents and Settings\sbalsinger\Application Data\AdobeUM
2008-04-29 14:44 --------- d-----w C:\Program Files\Hewlett-Packard
2008-04-28 18:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-04-15 14:27 --------- d-----w C:\Program Files\SpywareBlaster
2008-04-15 14:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-15 13:04 --------- d-----w C:\Program Files\Yahoo!
2008-04-15 13:04 --------- d-----w C:\Program Files\CCleaner
2008-04-14 13:50 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-04-14 13:41 --------- d-----w C:\Program Files\TightVNC
2006-05-17 17:04 1,568 ----a-w C:\Documents and Settings\All Users\Application Data\SSIHistory.dat
2004-08-04 10:00 4,096 --sha-w C:\WINDOWS\system32\1112.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 16:44 66680]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-03-12 15:18 124128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c00A8054]
C:\WINDOWS\system32\__c00A8054.dat
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= jl_mjpg2.drv
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
S3 JL2005;JL2005A Toy Camera;C:\WINDOWS\system32\Drivers\toywdm.sys [2005-05-09 20:22]
S3 rexesvr;BeyondLogic RmtExec Server;C:\WINDOWS\System32\rexesvr.exe [2008-05-28 14:44]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-29 10:43:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\BAsfIpM.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\system32\userinit.exe
.
**************************************************************************
.
Completion time: 2008-05-29 10:44:48 - machine was rebooted [sbalsinger]
ComboFix-quarantined-files.txt 2008-05-29 14:44:45
Pre-Run: 71,462,572,032 bytes free
Post-Run: 71,449,161,728 bytes free
130