ComboFix 08-08-21.02 - Douglas 2008-08-23 11:49:56.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1405 [GMT -5:00]
Running from: C:\Documents and Settings\Douglas\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM1fe922f8.txt
C:\WINDOWS\BM1fe922f8.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\afexujfe.dll
C:\WINDOWS\system32\atklalje.dll
C:\WINDOWS\system32\bwrgsvaj.dll
C:\WINDOWS\system32\efjuxefa.ini
C:\WINDOWS\system32\etaifdil.ini
C:\WINDOWS\system32\ftxrfhwo.dll
C:\WINDOWS\system32\ikRsDJlm.ini
C:\WINDOWS\system32\ikRsDJlm.ini2
C:\WINDOWS\system32\lidfiate.dll
C:\WINDOWS\system32\ljJCuVlm.dll
C:\WINDOWS\system32\ljJDTMfe.dll
C:\WINDOWS\system32\mlJDsRki.dll
C:\WINDOWS\system32\opnonnNd.dll
C:\WINDOWS\system32\owwtkjtk.dll
C:\WINDOWS\system32\oxypibmd.dll
C:\WINDOWS\system32\vtUlIaxW.dll
C:\WINDOWS\system32\winiaqcr.dll
C:\WINDOWS\system32\xrmguase.dll
C:\WINDOWS\system32\zuicfo.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-23 to 2008-08-23 )))))))))))))))))))))))))))))))
.
2008-08-22 22:21 . 2008-08-22 22:21 <DIR> d-------- C:\_OTMoveIt
2008-08-20 05:17 . 2008-08-20 05:17 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-08-18 15:06 . 2008-08-18 15:06 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-18 15:06 . 2008-08-18 15:06 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-18 15:06 . 2008-08-18 15:06 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-18 15:06 . 2008-08-18 15:06 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-18 15:03 . 2008-08-18 15:03 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-18 14:46 . 2008-08-18 14:46 <DIR> d-------- C:\WINDOWS\EHome
2008-08-17 15:48 . 2008-08-17 15:48 <DIR> d-------- C:\Program Files\BitTorrent
2008-08-17 15:48 . 2008-08-17 18:00 <DIR> d-------- C:\Documents and Settings\Douglas\Application Data\BitTorrent
2008-08-17 15:43 . 2008-08-23 12:27 <DIR> d-------- C:\Program Files\DNA
2008-08-17 15:43 . 2008-08-23 12:27 <DIR> d-------- C:\Documents and Settings\Douglas\Application Data\DNA
2008-08-17 15:09 . 2008-08-17 15:01 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-17 15:09 . 2008-08-17 15:01 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-17 15:02 . 2008-08-17 15:02 0 --a------ C:\WINDOWS\system32\null
2008-08-15 23:44 . 2008-08-15 23:44 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-15 00:23 . 2008-08-15 00:23 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-08-14 23:42 . 2008-08-15 00:13 <DIR> d-------- C:\Program Files\Common Files\ParetoLogic
2008-08-14 23:42 . 2008-08-14 23:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
2008-08-14 12:24 . 2008-04-11 14:04 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-14 12:22 . 2008-05-01 09:33 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-14 00:03 . 2008-08-14 00:03 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-08-13 23:57 . 2008-08-13 23:57 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-08-13 23:55 . 2008-08-14 12:16 <DIR> d-------- C:\Program Files\Webroot
2008-08-13 23:55 . 2008-08-13 23:55 <DIR> d-------- C:\Documents and Settings\Douglas\Application Data\Webroot
2008-08-13 23:55 . 2008-08-13 23:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-08-13 23:55 . 2008-07-13 09:53 1,538,928 --a------ C:\WINDOWS\WRSetup.dll
2008-08-13 23:11 . 2008-08-13 23:11 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-13 17:53 . 2008-04-13 13:45 60,032 --a------ C:\WINDOWS\system32\drivers\usbaudio.sys
2008-08-12 10:53 . 2008-08-16 15:13 <DIR> d-------- C:\VundoFix Backups
2008-08-11 22:41 . 2008-08-11 22:41 <DIR> d-------- C:\Documents and Settings\Douglas\Application Data\Malwarebytes
2008-08-11 22:40 . 2008-08-17 15:10 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-11 22:40 . 2008-08-11 22:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-11 21:41 . 2008-08-11 21:43 <DIR> d-------- C:\Program Files\Lavasoft
2008-08-11 21:41 . 2008-08-11 21:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-11 21:08 . 2008-08-11 21:08 0 --a------ C:\WINDOWS\VPC32.INI
2008-08-11 19:37 . 2008-08-23 11:41 <DIR> d-------- C:\Program Files\Symantec AntiVirus
2008-08-11 19:37 . 2008-08-23 11:41 <DIR> d-------- C:\Program Files\Symantec
2008-08-11 19:37 . 2008-08-23 11:41 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-08-11 19:37 . 2008-08-23 11:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-07 16:08 . 2008-08-17 18:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-08-06 18:20 . 2008-08-06 18:20 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-08-06 18:20 . 2008-08-23 01:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rosetta Stone
2008-08-06 17:44 . 2008-08-18 09:21 <DIR> d-------- C:\Program Files\Rosetta Stone
2008-08-06 08:55 . 2008-08-22 22:17 216 --a------ C:\WINDOWS\system32\Monitored3.dat
2008-07-23 11:14 . 2008-07-23 11:17 37 --a------ C:\WINDOWS\GBRoom.INI
2008-07-23 11:06 . 2008-07-23 11:06 <DIR> d-------- C:\Program Files\TOSHIBA
2008-07-23 11:05 . 2008-07-23 11:05 <DIR> d-------- C:\Program Files\Common Files\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-17 20:38 --------- d-----w C:\Documents and Settings\Douglas\Application Data\LimeWire
2008-08-14 04:10 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-12 18:45 --------- d--h--r C:\Documents and Settings\Douglas\Application Data\yahoo!
2008-08-12 18:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-12 18:44 --------- d-----w C:\Program Files\Yahoo!
2008-08-08 02:31 --------- d-----w C:\Program Files\Emulator Roms
2008-07-26 02:47 --------- d-----w C:\Documents and Settings\Douglas\Application Data\U3
2008-07-25 05:54 --------- d-----w C:\Program Files\Lx_cats
2008-07-23 16:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-14 04:53 --------- d-----w C:\Program Files\GoldWave
2008-07-13 06:03 29,808 ----a-w C:\WINDOWS\system32\drivers\ssfs0bbc.sys
2008-07-13 06:03 23,152 ----a-w C:\WINDOWS\system32\drivers\sshrmd.sys
2008-07-13 06:03 166,512 ----a-w C:\WINDOWS\system32\drivers\ssidrv.sys
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:26 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-26 08:15 619,520 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2008-06-26 08:15 1,499,136 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-23 15:09 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-23 15:09 666,112 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2008-06-23 15:09 3,067,392 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:46 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:46 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-04-08 17:28 666 ----a-w C:\Documents and Settings\Douglas\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellAutomatedPCTuneUp"="C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 09:49 465136]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 18:56 202544]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-08-17 15:43 342336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-03 15:20 851968]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-06-06 16:30 138008]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-06-06 16:30 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-06-06 16:30 138008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2007-05-14 14:23 1191936]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2007-12-11 14:22 2183168]
"SigmatelSysTrayApp"="C:\WINDOWS\stsystra.exe" [2007-06-06 16:28 405504]
"KADxMain"="C:\WINDOWS\system32\KADxMain.exe" [2006-11-02 14:05 282624]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 18:57 16384]
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 15:39 189736]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 18:56 202544]
"TosGbWatcher"="C:\Program Files\TOSHIBA\gigabeat room 2.0.2\TosGbWatcher.exe" [2005-04-26 02:02 118837]
"LXBUCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll" [2004-11-02 15:03 69632]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-07-13 09:53 5418864]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-05-17 15:43:18 568176]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-03-15 19:29:31 50688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\RosettaStoneVersion3.exe"=
"C:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\support\\bin\\RosettaStoneLtdServices.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
"1104:UDP"= 1104:UDP:Windows Media Format SDK (firefox.exe)
"1105:UDP"= 1105:UDP:Windows Media Format SDK (firefox.exe)
"<NO NAME>"=
R0 Spssys;Toshiba SPS Service;C:\WINDOWS\system32\drivers\spssys.sys [2004-05-07 21:56]
R0 ssfs0bbc;ssfs0bbc;C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys [2008-07-13 01:03]
R2 datunidr;DellAutomatedPCTuneUp UniDriver;C:\WINDOWS\system32\DRIVERS\datunidr.sys [2007-08-23 18:29]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 16:38]
.
Contents of the 'Scheduled Tasks' folder
2008-08-23 C:\WINDOWS\Tasks\wrSpySweeperFullSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-07-13 09:53]
2008-08-23 C:\WINDOWS\Tasks\wrSpySweeperFullSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-07-13 09:53]
2008-08-23 C:\WINDOWS\Tasks\wrSpySweeperFullSweep.job
- C:\","D:\" []
.
- - - - ORPHANS REMOVED - - - -
BHO-{2E6A08B9-42D7-4BC7-8AA7-987486BE7BAC} - C:\Documents and Settings\Douglas\Local Settings\Temporary Internet Files\Content.IE5\ZQQBBUH0\3077htsbdjyf[1].dll
HKLM-Run-BM1fe922f8 - C:\WINDOWS\system32\ftxrfhwo.dll
HKLM-Run-1cda1164 - C:\WINDOWS\system32\afexujfe.dll
HKCU-Explorer_Run-NT Printing Services - ftps.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Douglas\Application Data\Mozilla\Firefox\Profiles\a1cnb0nr.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.msnbc.msn.com/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-23 12:27:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.exe
.
**************************************************************************
.
Completion time: 2008-08-23 12:37:41 - machine was rebooted [Douglas]
ComboFix-quarantined-files.txt 2008-08-23 17:37:16
Pre-Run: 205,016,829,952 bytes free
Post-Run: 204,922,396,672 bytes free
229 --- E O F --- 2008-08-20 08:37:08