ComboFix 08-01-18.5 - Administrator 2008-01-19 18:23:06.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.620 [GMT -8:00]
Running from: C:\Documents and Settings\Administrator.JOHN-F58760FC57\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator.JOHN-F58760FC57\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\sonydcamm.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1560OinAdmin.exe
C:\Program Files\Common Files\Yazzle1560OinUninstaller.exe
C:\Program Files\inetget2
C:\Temp
C:\Temp\gTiis19\lTig.log
C:\Temp\Ryuan1\tepU.log
C:\temp\tn3
C:\WINDOWS\b128.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\Sm9obiBTYW5ndmVyYXBodW5zaXJp
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\sonydcamm.sys
C:\WINDOWS\system32\edcA01
C:\WINDOWS\system32\icqmlib.exe
C:\WINDOWS\system32\iepref32.dll
C:\WINDOWS\system32\ierplc.dll
C:\WINDOWS\system32\ips.dll
C:\WINDOWS\system32\ksvcl.dll
C:\WINDOWS\system32\lanmandrv.sys
C:\WINDOWS\system32\lanmanwrk.exe
C:\WINDOWS\system32\laprxy.dllexe
C:\WINDOWS\system32\nnnnmnm.dll
C:\WINDOWS\system32\ocxapi.dll
C:\WINDOWS\system32\ocxloader.exe
C:\WINDOWS\system32\opnkigf.dll
C:\WINDOWS\system32\opnlkli.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\qmopt.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_LANMANDRV
-------\LEGACY_SONYDCAMM
-------\LEGACY_YHST
-------\lanmandrv
-------\sonydcamm
-------\YHST
((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))
.
2008-01-19 15:29 . 2008-01-19 15:29 36,864 --a------ C:\WINDOWS\17PHolmes572.exe
2008-01-19 15:26 . 2008-01-19 15:26 <DIR> d-------- C:\WINDOWS\system32\nGpxx01
2008-01-19 15:26 . 2008-01-19 15:26 36,864 --a------ C:\WINDOWS\mrofinu572.exe.tmp
2008-01-18 13:24 . 2008-01-18 13:24 39,424 --a------ C:\WINDOWS\system32\KernelDrv.exe
2008-01-18 13:24 . 2008-01-19 18:16 25,093 --a------ C:\WINDOWS\system32\kcopt.dll
2008-01-18 13:24 . 2008-01-18 13:24 13,824 --a------ C:\WINDOWS\system32\Dll.dll
2008-01-18 12:59 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-17 19:25 . 2008-01-18 14:12 <DIR> d-------- C:\Program Files\Steam
2008-01-17 19:23 . 2008-01-17 19:23 <DIR> d-------- C:\Program Files\Valve
2008-01-17 19:10 . 2008-01-17 19:10 <DIR> d--hs---- C:\WINDOWS\system32\dllcache
2008-01-17 19:05 . 2008-01-17 19:05 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-16 14:08 . 2008-01-16 14:09 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-01-16 14:07 . 2008-01-16 14:07 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-16 04:09 . 2008-01-16 04:09 <DIR> d-------- C:\Documents and Settings\Administrator.JOHN-F58760FC57\Application Data\Apple Computer
2008-01-16 02:10 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-01-16 01:58 . 2008-01-16 04:26 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-16 01:58 . 2008-01-16 04:06 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-16 01:58 . 2008-01-16 04:06 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-16 01:58 . 2008-01-16 04:06 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-16 00:42 . 2008-01-16 00:42 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-01-16 00:42 . 2008-01-16 00:42 <DIR> d-------- C:\Documents and Settings\Administrator.JOHN-F58760FC57\Application Data\Grisoft
2008-01-14 22:08 . 2008-01-14 22:09 2,604 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-14 16:05 . 2008-01-15 23:04 90,112 --a------ C:\WINDOWS\UpdReg.EXE
2008-01-14 16:04 . 2008-01-14 23:23 15,360 --a------ C:\WINDOWS\system32\ctfmon.exe
2008-01-14 16:04 . 2008-01-16 04:01 265 --a------ C:\WINDOWS\wininit.ini
2008-01-14 15:08 . 2008-01-14 16:23 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-01-03 19:00 . 2008-01-03 19:00 <DIR> d---s---- C:\Documents and Settings\Administrator.JOHN-F58760FC57\UserData
2007-12-23 22:32 . 2007-12-23 22:32 <DIR> d-------- C:\Documents and Settings\Administrator.JOHN-F58760FC57\Application Data\Ventrilo
2007-12-21 14:45 . 2008-01-18 13:07 <DIR> d-------- C:\Documents and Settings\Administrator.JOHN-F58760FC57\Application Data\skypePM
2007-12-21 14:45 . 2008-01-19 18:30 <DIR> d-------- C:\Documents and Settings\Administrator.JOHN-F58760FC57\Application Data\Skype
2007-12-21 14:45 . 2007-12-21 14:45 32 --a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\ezsid.dat
2007-12-21 14:44 . 2007-12-21 14:44 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-12-21 14:44 . 2007-12-21 14:44 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype
2007-12-21 14:38 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2007-12-21 14:37 . 2007-12-21 14:37 <DIR> d-------- C:\Program Files\MSBuild
2007-12-21 14:37 . 2007-12-21 14:37 <DIR> d-------- C:\Program Files\Microsoft Works
2007-12-21 14:30 . 2007-12-21 14:39 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
2007-12-21 14:29 . 2007-12-21 14:29 <DIR> dr-h----- C:\MSOCache
2007-12-21 14:24 . 2008-01-16 03:53 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-21 14:24 . 2007-12-22 16:49 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-21 14:23 . 2008-01-19 18:22 <DIR> d-------- C:\Program Files\QuickTime
2007-12-21 14:23 . 2007-12-21 14:23 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
2007-12-21 14:22 . 2007-12-21 14:22 <DIR> d-------- C:\Program Files\Apple Software Update
2007-12-21 14:22 . 2007-12-21 14:22 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple
2007-12-21 14:02 . 2008-01-17 19:02 4,958,588 --------- C:\WINDOWS\{00000003-00000000-00000001-00001102-00000008-10211102}.BAK
2007-12-21 14:00 . 2008-01-19 18:28 30,432 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000003-00000000-00000001-00001102-00000008-10211102}.rfx
2007-12-21 14:00 . 2008-01-19 18:28 30,432 --a------ C:\WINDOWS\system32\BMXState-{00000003-00000000-00000001-00001102-00000008-10211102}.rfx
2007-12-21 14:00 . 2008-01-19 18:28 29,604 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000003-00000000-00000001-00001102-00000008-10211102}.rfx
2007-12-21 14:00 . 2008-01-19 18:28 29,604 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000003-00000000-00000001-00001102-00000008-10211102}.rfx
2007-12-21 14:00 . 2008-01-19 18:28 11,564 --a------ C:\WINDOWS\system32\DVCState-{00000003-00000000-00000001-00001102-00000008-10211102}.rfx
2007-12-21 14:00 . 2008-01-19 18:28 1,080 --a------ C:\WINDOWS\system32\settingsbkup.sfm
2007-12-21 14:00 . 2008-01-19 18:28 1,080 --a------ C:\WINDOWS\system32\settings.sfm
2007-12-21 13:26 . 2000-05-22 00:58 647,872 --a------ C:\WINDOWS\system32\Mscomct2.ocx
2007-12-21 13:26 . 1999-10-10 17:00 41,984 --------- C:\WINDOWS\Ctregrun.exe
2007-12-21 13:24 . 1999-12-12 17:01 44,032 --a------ C:\WINDOWS\system32\CTSVCCDA.EXE
2007-12-21 13:24 . 1999-11-17 17:00 25,088 --a------ C:\WINDOWS\system32\CTSVCCTL.EXE
2007-12-21 13:24 . 2007-12-21 13:25 183 --a------ C:\WINDOWS\setuplog
2007-12-21 13:22 . 2007-12-21 13:22 <DIR> d-------- C:\WINDOWS\system32\Defaults
2007-12-21 13:21 . 2007-12-21 13:21 <DIR> d-------- C:\WINDOWS\system32\Data
2007-12-21 13:21 . 2008-01-19 18:30 4,958,588 --a------ C:\WINDOWS\{00000003-00000000-00000001-00001102-00000008-10211102}.CDF
2007-12-21 13:21 . 2007-12-21 13:21 233,472 --a------ C:\WINDOWS\system32\wrap_oal.dll
2007-12-21 13:21 . 2007-12-21 13:21 81,920 --a------ C:\WINDOWS\system32\OpenAL32.dll
2007-12-21 13:21 . 2005-06-17 22:41 46,593 -ra------ C:\WINDOWS\system32\e10kxwdm.ini
2007-12-21 13:21 . 2005-06-17 22:08 11,776 --a------ C:\WINDOWS\INRES.DLL
2007-12-21 13:21 . 2005-06-17 22:01 10,240 --a------ C:\WINDOWS\CTDCRES.DLL
2007-12-21 13:21 . 2001-08-16 20:42 7,406 -ra------ C:\WINDOWS\system32\SBAudigy.ico
2007-12-21 13:21 . 2001-11-12 17:48 1,912 -ra------ C:\WINDOWS\system32\Audigy.bmp
2007-12-21 13:21 . 2005-06-17 21:41 193 -ra------ C:\WINDOWS\system32\ctzapxx.ini
2007-12-21 13:20 . 2007-12-23 20:06 <DIR> d-------- C:\Documents and Settings\Administrator.JOHN-F58760FC57\Application Data\Creative
2007-12-21 13:20 . 2003-11-11 11:08 77,824 --a------ C:\WINDOWS\system32\ctdvda32.dll
2007-12-21 13:19 . 2007-12-21 13:26 <DIR> d-------- C:\Program Files\Creative
2007-12-21 13:08 . 2008-01-19 18:22 <DIR> d-------- C:\Program Files\Mouse Driver
2007-12-21 12:50 . 2007-12-21 12:50 <DIR> d-------- C:\WINDOWS\Samsung
2007-12-21 12:50 . 2007-12-21 12:50 <DIR> d-------- C:\Program Files\Samsung ML-2010 Series
2007-12-21 12:50 . 2005-03-13 21:01 208,896 --a------ C:\WINDOWS\system32\SSRemove.exe
2007-12-21 12:50 . 2005-03-02 20:32 151,552 --a------ C:\WINDOWS\system32\SSCoInst.exe
2007-12-21 12:50 . 2005-03-03 02:09 57,344 --a------ C:\WINDOWS\system32\SSCoInst.dll
2007-12-21 12:50 . 2005-03-13 21:01 41,984 --------- C:\WINDOWS\system32\drivers\DGIVECP.SYS
2007-12-21 12:50 . 2005-04-07 18:29 20,622 --a------ C:\WINDOWS\system32\SUGS2LMK.DLL
2007-12-21 12:50 . 2005-03-13 21:01 8,478 --a------ C:\WINDOWS\system32\SP119.ICO
2007-12-21 12:50 . 2005-03-13 21:01 766 --------- C:\WINDOWS\Uninstall.ico
2007-12-21 12:50 . 2005-03-03 03:23 604 --a------ C:\WINDOWS\system32\SUGS2LMK.SMT
2007-12-21 12:48 . 2008-01-19 18:22 <DIR> d-------- C:\Program Files\HP USB Multimedia Keyboard
2007-12-21 12:48 . 2006-12-03 18:03 77,824 --a------ C:\WINDOWS\system32\KmRemove.exe
2007-12-21 12:46 . 2005-11-04 18:57 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2007-12-21 12:40 . 2005-11-04 18:57 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2007-12-21 12:39 . 2005-11-04 18:58 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-12-21 12:39 . 2005-11-04 18:58 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-12-20 20:55 . 2005-11-04 18:57 42,368 --a------ C:\WINDOWS\system32\drivers\AGP440.SYS
2007-12-20 20:53 . 2005-11-04 18:57 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2007-12-20 20:53 . 2005-11-04 18:57 870,784 --a------ C:\WINDOWS\system32\ati3d1ag.dll
2007-12-20 20:53 . 2005-11-04 18:57 701,440 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-12-20 20:53 . 2005-11-04 18:57 516,768 --a------ C:\WINDOWS\system32\ativvaxx.dll
2007-12-20 20:53 . 2005-11-04 18:57 229,376 --a------ C:\WINDOWS\system32\ati2cqag.dll
2007-12-20 20:53 . 2005-11-04 18:57 201,728 --a------ C:\WINDOWS\system32\ati2dvag.dll
2007-12-20 20:53 . 2005-11-04 18:57 117,760 --a------ C:\WINDOWS\system32\drivers\e100b325.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-16 22:08 --------- d-----w C:\Program Files\Lavasoft
2007-12-22 03:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-22 03:46 --------- d-----w C:\Program Files\InterVideo
2007-12-21 22:44 --------- d-----w C:\Program Files\Skype
2007-12-21 21:18 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
.
<pre>
----a-w 21,686,568 2008-01-16 07:05:20 C:\Program Files\Skype\Phone\Skype .exe
</pre>
((((((((((((((((((((((((((((( snapshot@2008-01-18_13.08.31.40 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-18 21:00:05 1,433,600 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-20 02:21:47 1,433,600 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-18 21:00:05 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-20 02:21:47 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-18 21:00:05 1,433,600 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-20 02:21:48 1,433,600 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-18 21:00:05 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-20 02:21:48 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-18 21:00:05 4,268,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-20 02:21:48 4,268,032 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-18 21:00:05 28,672 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-20 02:21:48 28,672 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-15 06:13:16 372,736 ----a-w C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe
+ 2008-01-19 13:13:12 32,768 ----a-w C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe
+ 2008-01-20 02:29:32 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5f0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2008-01-15 23:04 102400]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-14 23:23 15360]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-12-07 15:08 21686568]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-15 23:05 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Samsung Common SM"="C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" [2008-01-14 22:13 372736]
"WireLessMouse"="C:\Program Files\Mouse Driver\StartAutorun.exe" [2008-01-15 23:04 94208]
"CTSysVol"="C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe" [2008-01-15 23:04 57344]
"AudioDrvEmulator"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2008-01-15 23:04 49152]
"CTHelper"="CTHELPER.EXE" [2005-06-17 22:01 16384 C:\WINDOWS\CTHELPER.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe" [2008-01-15 23:04 36975]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-01-14 22:53 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="cmd.exe" [2004-08-03 20:56 388608 C:\WINDOWS\system32\cmd.exe]
"nlhr"="C:\WINDOWS\System32\AdvPack.Dll" [2004-08-03 20:56 99840]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-03 18:59 44544]
C:\Documents and Settings\Vic Sangveraphunsiri.P4_800\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Handspring\HOTSYNC.EXE [2005-07-02 20:20:58]
Webshots.lnk - C:\Program Files\Webshots\WebshotsTray.exe [2006-02-05 23:50:12]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{A051B1FF-8D7E-418B-AABE-4FF82F4280A2}"= C:\WINDOWS\system32\nnnnmnm.dll [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##192.168.0.108#public]
\Shell\AutoRun\command - Z:\autorun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-19 18:30:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-19 18:32:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-20 02:32:14
ComboFix2.txt 2008-01-18 21:08:46