hey
first part here second part will come tommorow
ComboFix 08-06-30.2 - Tim Steer 2008-07-02 23:18:40.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.579 [GMT 10:00]
Running from: C:\Documents and Settings\Tim Steer\Desktop\Ads served by Adzgalore\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tim Steer\Desktop\Ads served by Adzgalore\CFScript.txt
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_KBEEPM
-------\Service_kbeepm
((((((((((((((((((((((((( Files Created from 2008-06-02 to 2008-07-02 )))))))))))))))))))))))))))))))
.
2008-06-23 19:31 . 2008-06-23 19:31 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-06-23 18:30 . 2008-06-23 18:30 <DIR> d-------- C:\Program Files\Microsoft Games
2008-06-23 17:49 . 2008-06-23 17:49 <DIR> d-------- C:\_OTMoveIt
2008-06-22 15:19 . 2008-06-22 15:19 <DIR> d-------- C:\WINDOWS\Off Road Arena
2008-06-22 15:19 . 2008-06-22 15:19 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-06-22 00:09 . 2008-06-22 00:09 <DIR> d-------- C:\Program Files\Shockwave.com
2008-06-21 23:41 . 2008-06-21 23:41 <DIR> d-------- C:\Deckard
2008-06-21 22:00 . 2008-06-21 22:00 <DIR> d-------- C:\Program Files\Unity
2008-06-12 22:48 . 2008-06-12 22:48 <DIR> d-------- C:\Program Files\Common Files\Blueberry Software
2008-06-12 22:48 . 2008-06-12 22:49 <DIR> d-------- C:\Documents and Settings\Tim Steer\Application Data\LogSys
2008-06-12 22:48 . 2008-06-12 22:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogSys
2008-06-12 22:48 . 2008-06-12 22:48 <DIR> d--h----- C:\Documents and Settings\All Users\Application Data\{726649E6-8F90-456E-B22B-3DFDD02D58C8}
2008-06-11 16:51 . 2008-06-13 23:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 16:51 . 2008-06-13 23:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-10 22:27 . 2008-06-13 18:29 <DIR> d-------- C:\Program Files\Playboy - The Mansion
2008-06-05 16:54 . 2008-06-05 17:41 <DIR> d-------- C:\Documents and Settings\Tim Steer\DoctorWeb
2008-06-04 17:23 . 2008-06-04 17:47 <DIR> d-------- C:\Program Files\Panda Security
2008-06-02 17:28 . 2008-06-02 17:28 <DIR> d-------- C:\Program Files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-02 13:35 15,361,056 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-02 13:25 209,864 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-02 13:25 1,076,224 ----a-w C:\WINDOWS\Internet Logs\xDB6C.tmp
2008-07-01 14:19 --------- d-----w C:\Documents and Settings\Tim Steer\Application Data\uTorrent
2008-07-01 14:18 --------- d-----w C:\Program Files\SpeedFan
2008-06-30 08:14 --------- d-----w C:\Documents and Settings\Tim Steer\Application Data\LimeWire
2008-06-28 05:38 2,706,432 ----a-w C:\WINDOWS\Internet Logs\xDB6A.tmp
2008-06-27 06:06 64,000 ----a-w C:\WINDOWS\Internet Logs\xDB67.tmp
2008-06-27 06:06 2,335,232 ----a-w C:\WINDOWS\Internet Logs\xDB69.tmp
2008-06-25 22:13 3,002,880 ----a-w C:\WINDOWS\Internet Logs\xDB66.tmp
2008-06-25 17:48 2,334,720 ----a-w C:\WINDOWS\Internet Logs\xDB6B.tmp
2008-06-23 09:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-22 10:04 3,000,832 ----a-w C:\WINDOWS\Internet Logs\xDB64.tmp
2008-06-22 10:04 2,302,976 ----a-w C:\WINDOWS\Internet Logs\xDB65.tmp
2008-06-15 03:46 --------- d-----w C:\Documents and Settings\Tim Steer\Application Data\MailFrontier
2008-06-15 03:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-06-14 04:27 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-06-12 12:55 --------- d-----w C:\Documents and Settings\Tim Steer\Application Data\Blueberry
2008-06-12 12:49 2,944 ----a-w C:\WINDOWS\system32\drivers\bbcap.sys
2008-06-12 12:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Blueberry
2008-05-28 07:15 --------- d-----w C:\Program Files\WildTangent
2008-05-23 11:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-03 14:13 2,092,032 ----a-w C:\WINDOWS\Internet Logs\xDB63.tmp
2008-05-03 13:57 2,091,520 ----a-w C:\WINDOWS\Internet Logs\xDB62.tmp
2008-04-30 13:17 266,240 ----a-w C:\WINDOWS\Internet Logs\xDB61.tmp
2008-04-19 15:50 59,904 ----a-w C:\WINDOWS\Internet Logs\xDB60.tmp
2008-04-18 14:54 273,920 ----a-w C:\WINDOWS\Internet Logs\xDB5F.tmp
2008-04-04 13:23 256,512 ----a-w C:\WINDOWS\Internet Logs\xDB5E.tmp
2008-03-09 06:49 22,328 ----a-w C:\Documents and Settings\Tim Steer\Application Data\PnkBstrK.sys
2007-12-27 16:16 47,360 ------w C:\Documents and Settings\Tim Steer\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((( snapshot@2008-07-02_17.14.46.78 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-02 07:04:49 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-02 13:26:06 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-10-20 10:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2008-07-02 06:38:30 410,604 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2008-07-02 13:27:15 410,604 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
- 2008-06-28 13:56:54 9,676,234 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
+ 2008-07-02 10:56:20 9,702,985 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
- 2008-07-02 06:54:23 9,996,288 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2008-07-02 13:19:02 9,996,288 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 23:18 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-18 02:51 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 01:01 110592]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22 155648]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 20:15 290816]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 14:45 40960]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-13 01:05 122939]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [2005-05-17 17:42 933888]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 21:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 03:25 144784]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-13 22:11 919016]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-12 23:18 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
--------- 2005-03-17 14:25 57393 C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefPrt]
--------- 2005-01-26 18:02 49152 C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R1 bbcap;bbcap;C:\WINDOWS\system32\DRIVERS\bbcap.sys [2008-06-12 22:49]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-02 23:34:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
.
**************************************************************************
.
Completion time: 2008-07-02 23:39:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-02 13:39:15
ComboFix2.txt 2008-07-02 07:16:35
ComboFix3.txt 2008-06-03 08:08:46
Pre-Run: 45,203,628,032 bytes free
Post-Run: 45,157,236,736 bytes free
160 --- E O F --- 2008-06-24 17:01:50