ComboFix 08-07-31.01 - Owner 2008-08-01 19:30:34.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.333 [GMT -8:00]
Running from: C:\Documents and Settings\Owner.YOUR-KYBTG65GXE.000\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner.YOUR-KYBTG65GXE.000\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\{7026FA23-A796-43C9-BF9D-223558230A97}.dat
C:\WINDOWS\{C70DBAF0-79B6-4F26-A6D9-40DD6412DCD2}.dat
C:\WINDOWS\system32\{1F0BCF34-AF6E-4B35-AC62-AEF898B1D097}.dat
C:\WINDOWS\system32\{8444D0C8-A2A4-4623-9B9E-B04F8589CCEB}.dat
C:\WINDOWS\system32\55.tmp
C:\WINDOWS\system32\AE.tmp
C:\WINDOWS\system32\ovjy.dll
C:\WINDOWS\system32\vdfvqydc.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentMgr_03000F11.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\Cursors.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\DataTracking.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\IEUI.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMgr.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPVideo.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPVideo2.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\WaveletReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\DownLoadHist.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\HostRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Media Player\MTSDownloadSites.txt
C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.xpt
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\-1420194370.MTZ
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\-1725972020.MTZ
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\-512559710.swf
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\1504369768.MTZ
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\190457878.MTZ
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\253621806.mtx
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_01\-1250239307.MTS
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_01\722093742.mtz
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\-1250239310.MTZ
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\-430710159.swf
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\518054506.mtx
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\979266177.MTZ
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03\-825244877.SWF
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03\-983945651.MTZ
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03\716494328.MTZ
C:\Program Files\Viewpoint\Viewpoint Media Player\Resources\UpdateVersionList_v2.mtx
C:\WINDOWS\{7026FA23-A796-43C9-BF9D-223558230A97}.dat
C:\WINDOWS\{C70DBAF0-79B6-4F26-A6D9-40DD6412DCD2}.dat
C:\WINDOWS\system32\{1F0BCF34-AF6E-4B35-AC62-AEF898B1D097}.dat
C:\WINDOWS\system32\{8444D0C8-A2A4-4623-9B9E-B04F8589CCEB}.dat
C:\WINDOWS\system32\55.tmp
C:\WINDOWS\system32\AE.tmp
C:\WINDOWS\System32\dccnncr.exe
C:\WINDOWS\system32\ovjy.dll
C:\WINDOWS\system32\vdfvqydc.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-07-02 to 2008-08-02 )))))))))))))))))))))))))))))))
.
2008-07-31 23:51 . 2008-07-31 23:52 <DIR> d-------- C:\Program Files\ERUNT
2008-07-31 14:35 . 2008-07-31 14:35 <DIR> d-------- C:\Program Files\Common Files\SupportSoft
2008-07-30 21:20 . 2008-07-30 21:20 <DIR> d-------- C:\fsaua.data
2008-07-29 19:27 . 2008-07-29 19:27 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-07-29 19:27 . 2008-07-29 19:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-29 13:11 . 2008-07-29 13:11 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-29 13:11 . 2008-07-29 13:11 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-KYBTG65GXE.000\Application Data\Malwarebytes
2008-07-29 13:11 . 2008-07-29 13:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-29 13:11 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-29 13:11 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-29 12:52 . 2008-07-29 12:52 <DIR> d-------- C:\_OTMoveIt
2008-07-28 21:44 . 2008-07-28 21:44 <DIR> d-------- C:\Documents and Settings\Owner.YOUR-KYBTG65GXE.000\Application Data\Comcast
2008-07-28 21:23 . 2008-07-29 11:57 3,022 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-28 21:22 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-07-28 21:22 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-07-28 21:22 . 2008-05-29 08:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-07-28 21:22 . 2008-05-23 17:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-07-28 21:22 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-07-28 21:22 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-07-28 21:22 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-07-28 10:07 . 2008-07-28 10:07 <DIR> d-------- C:\Deckard
2008-07-27 23:47 . 2008-07-27 23:47 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-27 23:15 . 2008-07-27 23:45 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-27 19:16 . 2002-08-29 02:41 150,528 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-07-27 19:16 . 2001-08-17 21:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-07-25 23:20 . 2008-07-25 23:20 <DIR> d-------- C:\Documents and Settings\OWNERY~1~000\LOCALS~1
2008-07-25 23:20 . 2008-07-25 23:20 <DIR> d-------- C:\Documents and Settings\OWNERY~1~000
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-02 03:36 --------- d-----w C:\Program Files\QuickTime
2008-08-02 03:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-02 03:30 --------- d-----w C:\Program Files\MSN Messenger
2008-08-02 03:30 --------- d-----w C:\Program Files\iTunes
2008-07-31 23:15 --------- d-----w C:\Program Files\support.com
2008-07-31 08:31 --------- d-----w C:\Program Files\hbinst
2008-07-29 05:56 --------- d-----w C:\Program Files\WildTangent
2008-07-29 05:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-29 05:52 --------- d-----w C:\Program Files\NewSoft
2008-07-29 05:50 --------- d-----w C:\Program Files\MUSICMATCH
2008-07-29 05:50 --------- d-----w C:\Documents and Settings\Owner.YOUR-KYBTG65GXE.000\Application Data\Musicmatch
2008-07-29 05:48 --------- d-----w C:\Program Files\Microsoft Money
2008-07-29 05:41 --------- d-----w C:\Program Files\Common Files\aolshare
2008-07-29 05:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-06-24 20:26 --------- d-----w C:\Program Files\McAfee
2008-06-23 22:31 --------- d-----w C:\Program Files\Common Files\McAfee
2008-06-03 06:36 --------- d-----w C:\Program Files\LimeWire
2007-02-24 05:49 25,600 ----a-w C:\Documents and Settings\Owner.YOUR-KYBTG65GXE.000\usbsermptxp.sys
2007-02-24 05:49 22,768 ----a-w C:\Documents and Settings\Owner.YOUR-KYBTG65GXE.000\usbsermpt.sys
2005-09-05 21:32 601 ---ha-w C:\Documents and Settings\Guest.JAINIE\hpothb07.dat
2005-05-29 00:06 637 ---ha-w C:\Documents and Settings\Guest\hpothb07.dat
2004-02-08 04:21 0 ---ha-w C:\Documents and Settings\NetworkService\hpothb07.dat
2003-10-10 01:23 665 ---ha-w C:\WINDOWS\system32\config\systemprofile\hpothb07.dat
2003-10-10 01:23 665 ---ha-w C:\Documents and Settings\Owner.YOUR-KYBTG65GXE.000\hpothb07.dat
2003-10-10 01:23 665 ---ha-w C:\Documents and Settings\Guest.YOUR-KYBTG65GXE\hpothb07.dat
2003-10-10 01:23 665 ---ha-w C:\Documents and Settings\Guest.YOUR-KYBTG65GXE.000\hpothb07.dat
2003-10-10 01:23 665 ---ha-w C:\Documents and Settings\Default User\hpothb07.dat
2003-10-10 01:23 164 ---ha-w C:\Documents and Settings\All Users\hpothb07.dat
2003-10-10 01:23 0 ---ha-w C:\Documents and Settings\LocalService\hpothb07.dat
.
------- Sigcheck -------
2004-08-03 22:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
2004-08-03 22:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\SoftwareDistribution\Download\9ded4ee34a35fced0033d3e152a36e0e\ip6fw.sys
2004-08-03 22:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
.
((((((((((((((((((((((((((((( snapshot@2008-08-01_12.19.33.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2002-09-14 05:42:26 212,992 ----a-w C:\WINDOWS\SMINST\RECGUARD.EXE
+ 1998-05-08 00:04:38 52,736 ----a-w C:\WINDOWS\system\hpsysdrv.exe
- 2008-08-01 18:49:15 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-08-01 23:08:50 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-08-01 18:49:15 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-08-01 23:08:50 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-08-01 18:49:15 49,152 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-08-01 23:08:50 49,152 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2002-09-09 15:05:52 114,688 ----a-w C:\WINDOWS\system32\hkcmd.exe
+ 2002-08-01 04:28:38 81,920 ----a-w C:\WINDOWS\system32\ps2.exe
+ 2002-12-04 08:23:24 188,416 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll" [2002-09-30 23:39 548933 C:\WINDOWS\system32\nview.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"HostManager"="C:\Program Files\Common Files\AOL\1139186156\ee\AOLSoftware.exe" [2006-09-25 16:52 50736]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 21:16 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-16 19:59 185784]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2005-09-22 18:29 303104]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 12:05 212992]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\McAgent.exe" [2005-09-22 18:29 303104]
"nwiz"="nwiz.exe" [2002-09-30 23:39 372736 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2006-11-16 13:42 1327104]
C:\Documents and Settings\Owner.YOUR-KYBTG65GXE.000\Start Menu\Programs\Startup\
AOL OpenRide.lnk - C:\Program Files\Common Files\AOL\Launch\aollaunch.exe [2006-09-25 16:52:49 50736]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-03 16:58:20 40960]
NkvMon.exe.lnk - C:\Program Files\Nikon\NkView6\NkvMon.exe [2003-10-11 08:19:17 237568]
officejet 6100.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2002-12-03 16:23:30 147456]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2002-09-20 19:20:02 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
R0 sonypvl2;sonypvl2;C:\WINDOWS\System32\drivers\sonypvl2.sys [2003-07-25 14:02]
R1 sonypvf2;sonypvf2;C:\WINDOWS\System32\drivers\sonypvf2.sys [2004-04-08 10:04]
R1 sonypvt2;sonypvt2;C:\WINDOWS\System32\drivers\sonypvt2.sys [2003-08-20 09:44]
R2 SVKP;SVKP;C:\WINDOWS\System32\SVKP.sys [2005-07-18 15:36]
S1 sonypvd2;sonypvd2;C:\WINDOWS\System32\DRIVERS\sonypvd2.sys [2003-06-24 09:29]
S3 msCMTSrvc;Content Monitoring Tool;C:\WINDOWS\system32\msCMTSrvc.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\86942b4f-d046-4526-8f8c-669ad3dd860b]
C:\WINDOWS\System32\dccnncr.exe
.
Contents of the 'Scheduled Tasks' folder
2003-05-22 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1052015226.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-12-03 16:40]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-PhotoShow Deluxe Media Manager - C:\PROGRA~1\Comcast\COMCAS~1\data\xtras\mssysmgr.exe
HKCU-Run-Yahoo! Pager - C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-BlockTracker - c:\hp\bin\BlockTracker.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-01 19:36:36
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Common Files\AOL\1139186156\ee\AOLOpenRide.exe
C:\Program Files\Common Files\AOL\1139186156\ee\anotify.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-08-01 20:07:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-02 04:06:55
ComboFix2.txt 2008-08-01 20:21:28
Pre-Run: 75,289,374,720 bytes free
Post-Run: 75,230,162,944 bytes free
229