Running from: C:\Documents and Settings\BRETT\My Documents\Billy Downloads\ComboFix.exe
Command switches used :: C:\Documents and Settings\BRETT\My Documents\Billy Downloads\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
C:\WINDOWS\System32\dllcache\lsass.exe --> C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
C:\WINDOWS\System32\dllcache\services.exe --> C:\WINDOWS\$NtServicePackUninstall$\services.exe
C:\WINDOWS\System32\dllcache\spoolsv.exe --> C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
C:\WINDOWS\System32\dllcache\svchost.exe --> C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
C:\WINDOWS\System32\dllcache\winlogon.exe --> C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
.
((((((((((((((((((((((((( Files Created from 2008-08-01 to 2008-09-01 )))))))))))))))))))))))))))))))
.
2008-08-29 21:07 . 2008-08-29 21:07 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-29 21:07 . 2008-08-29 21:07 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-29 21:07 . 2008-08-29 21:07 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-29 21:07 . 2008-08-29 21:07 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-29 21:05 . 2008-08-29 21:08 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-29 20:58 . 2008-08-29 20:58 <DIR> d-------- C:\WINDOWS\EHome
2008-08-29 19:28 . 2008-04-13 20:12 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2008-08-29 19:27 . 2008-04-13 20:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-08-25 22:55 . 2008-08-29 21:51 <DIR> d-------- C:\Program Files\Symantec AntiVirus
2008-08-25 22:55 . 2008-08-25 22:55 110,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-08-25 22:55 . 2008-08-25 22:55 48,768 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-08-25 22:55 . 2008-08-25 22:55 8,014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-08-25 22:55 . 2008-08-25 22:55 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-08-24 02:41 . 2008-08-24 02:41 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-24 02:22 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-24 00:58 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-24 00:58 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-23 20:09 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-23 20:09 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-23 20:09 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-23 13:40 . 2008-08-21 23:41 87,552 --a------ C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-08-22 19:18 . 2008-08-22 19:18 <DIR> d-------- C:\Documents and Settings\BRETT\Application Data\Symantec
2008-08-20 21:33 . 2008-08-24 02:22 4,182 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-20 18:58 . 2008-08-20 18:59 <DIR> d-------- C:\Program Files\Advanced Registry Doctor
2008-08-20 10:51 . 2008-08-21 01:04 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-20 10:51 . 2008-08-20 11:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-19 13:02 . 2008-08-19 13:02 <DIR> d-------- C:\Program Files\Gadwin Systems
2008-08-19 09:49 . 2008-08-24 01:05 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-19 09:48 . 2008-08-23 17:33 <DIR> d-------- C:\Program Files\Trojan Remover
2008-08-19 09:48 . 2008-08-19 09:48 <DIR> d-------- C:\Documents and Settings\BRETT\Application Data\Simply Super Software
2008-08-19 09:48 . 2008-08-19 09:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-08-19 09:48 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-08-19 09:48 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-08-19 09:48 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-08-19 09:48 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-08-19 09:38 . 2008-08-19 09:52 <DIR> d-------- C:\Program Files\EndItAll
2008-08-18 12:28 . 2008-08-18 12:28 <DIR> d-------- C:\Program Files\AVG
2008-08-18 12:28 . 2008-08-19 14:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-08-13 18:14 . 2008-04-11 15:04 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-13 18:14 . 2008-05-01 10:33 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-01 01:41 --------- d-----w C:\Program Files\BAE
2008-08-31 03:57 --------- d-----w C:\Program Files\McAfee
2008-08-31 03:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-31 03:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-08-26 02:56 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-26 02:55 --------- d-----w C:\Program Files\Symantec
2008-08-26 02:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-22 02:32 --------- d-----w C:\Program Files\America Online 9.0
2008-08-22 02:18 --------- d-----w C:\Program Files\CoreFTP
2008-08-20 22:57 --------- d-----w C:\Documents and Settings\BRETT\Application Data\U3
2008-08-19 15:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-17 18:33 --------- d-----w C:\Documents and Settings\BRETT\Application Data\FUJIFILM
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-16 01:23 --------- d-----w C:\Program Files\MSBuild
2008-07-16 01:23 --------- d-----w C:\Program Files\Microsoft Works
2008-07-15 12:07 --------- d-----w C:\Program Files\Dell Support Center
2008-07-15 12:07 --------- d-----w C:\Program Files\Common Files\supportsoft
2008-07-15 12:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-07-15 12:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:26 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-26 08:15 619,520 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2008-06-26 08:15 1,499,136 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-23 15:09 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-23 15:09 666,112 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2008-06-23 15:09 3,067,392 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:46 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:46 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2006-12-18 04:39 0 -c--a-w C:\Documents and Settings\BRETT\Application Data\wklnhst.dat
2007-02-09 23:42 88 -csh--r C:\WINDOWS\system32\7515257F65.sys
2007-02-09 23:42 3,350 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot_2008-08-31_21.53.08.71 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 09:00:00 14,848 -c----w C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
+ 2008-04-14 00:12:24 13,312 -c--a-w C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
- 2004-08-04 09:00:00 110,592 -c----w C:\WINDOWS\$NtServicePackUninstall$\services.exe
+ 2008-04-14 00:12:34 108,544 -c--a-w C:\WINDOWS\$NtServicePackUninstall$\services.exe
- 2005-06-10 23:53:32 58,880 -c----w C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
+ 2008-04-14 00:12:36 57,856 -c--a-w C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
- 2004-08-04 09:00:00 17,408 -c----w C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
+ 2008-04-14 00:12:36 14,336 -c--a-w C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
- 2004-08-04 09:00:00 506,368 -c----w C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
+ 2008-04-14 00:12:39 507,904 -c--a-w C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 20:12 1695232]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 12:28 139264]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-20 02:18 68856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 18:41 1832272]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 20:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 20:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 20:50 114688]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 03:12 94208]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-09-18 13:42 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-18 13:42 98304]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-09-08 19:20 110592]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20 122940]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-09-18 13:49 169984]
"DellHelp"="C:\Dell\DellHelp\DellHelp.exe" [2004-04-01 15:51 1589248]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-02-09 18:34 106496]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40 155648]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 23:32 53248]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 15:49 1121280]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-08-23 17:33 914512]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 17:38 52840]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-14 19:49 125632]
"SigmatelSysTrayApp"="stsystra.exe" [2006-02-10 18:17 282624 C:\WINDOWS\stsystra.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2006-09-18 13:41:40 156784]
Exif Launcher.lnk - C:\Program Files\FinePixViewer\QuickDCF.exe [2007-11-04 18:58:00 200704]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 16:05:56 65588]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 22:07:32 81920]
Veritrax AS-215.lnk - C:\Program Files\Rosslare\Veritrax AS-215\VeriTrax.exe [2008-04-13 19:16:01 9244672]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-09-21 20:57:14 122880]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WPORTAL\\JRE\\bin\\javaw.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-01 18:04:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-01 18:06:08
ComboFix-quarantined-files.txt 2008-09-01 22:05:29
ComboFix2.txt 2008-09-01 01:53:33
ComboFix3.txt 2008-08-30 02:02:03
ComboFix4.txt 2008-08-25 02:13:22
ComboFix5.txt 2008-09-01 22:00:09
Pre-Run: 50,822,930,432 bytes free
Post-Run: 50,896,023,552 bytes free
207 --- E O F --- 2008-08-31 07:01:18