Microsoft Windows XP Home Edition 5.1.2600.2.1254.90.1033.18.1043 [GMT -8:00]
Running from: c:\documents and settings\OKUCU\Desktop\ComboFix.exe
Command switches used :: / Snapshot
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\08223B03.cfg
c:\windows\system32\122B901E.cfg
c:\windows\system32\2EF0D734.cfg
c:\windows\system32\43ACDCC5.cfg
c:\windows\system32\4D023DE9.cfg
c:\windows\system32\58FF3024.cfg
c:\windows\system32\66AFCB56.cfg
c:\windows\system32\9CA963CA.cfg
c:\windows\system32\9F684DE8.cfg
c:\windows\system32\B3721C07.cfg
c:\windows\system32\BA7EDF54.cfg
c:\windows\system32\ca99d57.sys
c:\windows\system32\D7C79813.cfg
c:\windows\system32\DA63E650.cfg
c:\windows\system32\DFEC5CB7.cfg
c:\windows\system32\E0D39066.cfg
c:\windows\system32\E3367679.cfg
c:\windows\system32\E3367679.dll
c:\windows\system32\E4814792.cfg
c:\windows\system32\F65BDEC7.cfg
.
((((((((((((((((((((((((( Files Created from 2008-10-14 to 2008-11-14 )))))))))))))))))))))))))))))))
.
2008-11-13 09:05 . 2008-11-13 09:05 11,328 --ahs---- c:\windows\system32\E4814792.dll
2008-11-13 09:04 . 2008-11-13 09:04 11,927 --ahs---- c:\windows\system32\E0D39066.dll
2008-11-13 09:03 . 2008-11-13 09:03 216,873 --ahs---- c:\windows\system32\755D0ED0.dll
2008-11-13 09:03 . 2008-11-13 09:03 216,381 --ahs---- c:\windows\system32\16AF66EB.dll
2008-11-13 09:03 . 2008-11-13 09:03 5,504 --a------ c:\windows\system32\f35ee9e.sys
2008-11-13 09:03 . 2008-11-13 09:03 296 --ahs---- c:\windows\system32\16AF66EB.cfg
2008-11-13 09:03 . 2008-11-13 09:03 244 --ahs---- c:\windows\system32\755D0ED0.cfg
2008-11-13 09:01 . 2008-11-13 09:01 11,555 --ahs---- c:\windows\system32\9F684DE8.dll
2008-11-13 07:30 . 2008-11-13 07:30 11,825 --ahs---- c:\windows\system32\DFEC5CB7.dll
2008-11-12 08:27 . 2008-11-12 08:30 <DIR> d-------- C:\Lop SD
2008-11-12 08:22 . 2008-11-12 08:22 217,077 --ahs---- c:\windows\system32\2EF0D734.dll
2008-11-12 08:22 . 2008-11-12 08:22 12,798 --ahs---- c:\windows\system32\66AFCB56.dll
2008-11-12 08:22 . 2008-11-12 08:22 12,269 --ahs---- c:\windows\system32\93DEE065.dll
2008-11-12 08:22 . 2008-11-12 08:22 12,103 --ahs---- c:\windows\system32\C8FFD223.dll
2008-11-12 08:22 . 2008-11-12 08:22 11,938 --ahs---- c:\windows\system32\BA7EDF54.dll
2008-11-12 07:53 . 2008-11-12 07:53 <DIR> d-------- c:\windows\ERUNT
2008-11-12 07:48 . 2008-11-12 07:48 12,717 --ahs---- c:\windows\system32\5934EA2B.dll
2008-11-12 07:48 . 2008-11-12 07:48 11,722 --ahs---- c:\windows\system32\F65BDEC7.dll
2008-11-12 07:47 . 2008-11-06 02:03 <DIR> d-------- C:\SDFix
2008-11-12 07:46 . 2008-11-12 07:46 217,404 --ahs---- c:\windows\system32\70B0129E.dll
2008-11-12 07:46 . 2008-11-12 07:46 217,351 --ahs---- c:\windows\system32\4FBFD5A4.dll
2008-11-12 07:46 . 2008-11-12 07:46 216,781 --ahs---- c:\windows\system32\F8E07BB2.dll
2008-11-12 07:46 . 2008-11-12 07:46 216,659 --ahs---- c:\windows\system32\F2CBFAC4.dll
2008-11-12 07:46 . 2008-11-12 07:46 11,219 --ahs---- c:\windows\system32\01AFE3DC.dll
2008-11-12 07:45 . 2008-11-12 07:45 216,338 --ahs---- c:\windows\system32\3F21AA0C.dll
2008-11-12 07:38 . 2008-11-12 07:38 24,625 --a------ c:\windows\MSVB50CHS.dll
2008-11-11 20:06 . 2008-11-12 08:22 10,240 --a------ c:\windows\MKMKrnl.dll
2008-11-11 20:06 . 2008-11-11 20:06 204 --ahs---- c:\windows\system32\C8FFD223.cfg
2008-11-11 20:05 . 2008-11-11 20:05 184 --ahs---- c:\windows\system32\93DEE065.cfg
2008-11-11 20:04 . 2008-11-12 07:48 20,480 --a------ c:\windows\MPKrnl.dll
2008-11-11 20:04 . 2008-11-13 09:03 468 --ahs---- c:\windows\system32\70B0129E.cfg
2008-11-11 20:04 . 2008-11-11 20:04 272 --ahs---- c:\windows\system32\F2CBFAC4.cfg
2008-11-11 20:04 . 2008-11-11 20:04 220 --ahs---- c:\windows\system32\F8E07BB2.cfg
2008-11-11 20:04 . 2008-11-11 20:04 204 --ahs---- c:\windows\system32\5934EA2B.cfg
2008-11-11 20:04 . 2008-11-11 20:04 152 --ahs---- c:\windows\system32\01AFE3DC.cfg
2008-11-11 20:03 . 2008-11-11 20:03 5,504 --a------ c:\windows\system32\de8296f.sys
2008-11-11 20:03 . 2008-11-11 20:03 5,504 --a------ c:\windows\system32\d7b49fa.sys
2008-11-11 20:03 . 2008-11-11 20:03 5,504 --a------ c:\windows\system32\c39e8db.sys
2008-11-11 20:03 . 2008-11-11 20:03 312 --ahs---- c:\windows\system32\3F21AA0C.cfg
2008-11-11 20:03 . 2008-11-11 20:03 212 --ahs---- c:\windows\system32\4FBFD5A4.cfg
2008-11-02 18:25 . 2008-11-02 18:25 <DIR> d-------- c:\documents and settings\OKUCU\DoctorWeb
2008-11-02 17:46 . 2008-11-02 18:24 250 --a------ c:\windows\gmer.ini
2008-10-27 09:43 . 2008-11-05 23:48 54,156 --ah----- c:\windows\QTFont.qfn
2008-10-27 09:43 . 2008-10-27 09:43 1,409 --a------ c:\windows\QTFont.for
2008-10-26 18:12 . 2008-10-26 18:12 <DIR> d-------- C:\rsit
2008-10-25 05:09 . 2008-10-25 05:09 <DIR> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)
2008-10-24 19:55 . 2008-10-24 19:55 <DIR> d-------- C:\_OTScanIt
2008-10-23 16:18 . 2008-10-23 16:18 2,302,017 --a------ c:\windows\system32\GPhotos.scr
2008-10-15 06:16 . 2008-11-03 18:16 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\SolidDocuments
2008-10-15 01:49 . 2008-10-15 01:49 <DIR> d-------- c:\program files\Visage
2008-10-15 01:49 . 2008-10-15 01:49 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-10-15 01:49 . 2008-10-15 01:49 <DIR> d-------- c:\program files\Common Files\Visage Software
2008-10-15 00:12 . 2008-11-01 20:24 167 --a------ c:\windows\ConverterCore.INI
2008-10-15 00:10 . 2008-10-15 00:10 <DIR> d-------- c:\program files\SolidDocuments
2008-10-15 00:10 . 2008-11-12 20:43 <DIR> d-------- c:\documents and settings\OKUCU\Application Data\SolidDocuments
2008-10-15 00:09 . 2008-10-15 00:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\SolidDocuments
2008-10-15 00:00 . 2008-03-27 04:42 7,477 --a------ c:\windows\system32\novap5.ctm
2008-10-14 23:58 . 2008-03-27 04:42 7,477 --a------ c:\windows\system32\dopdf6.ctm
2008-10-14 23:47 . 2008-10-14 23:49 <DIR> d-------- C:\STA4V12
2008-10-14 23:47 . 2008-10-14 23:48 <DIR> d-------- C:\STA4
2008-10-14 23:41 . 2008-10-25 08:06 <DIR> d-------- C:\Sta4v11
2008-10-14 23:38 . 2008-10-14 23:38 <DIR> d-------- c:\program files\PDFCreator
2008-10-14 23:38 . 2008-10-14 23:38 <DIR> d-------- c:\documents and settings\OKUCU\Application Data\PDFCreator
2008-10-14 23:30 . 2004-01-31 09:14 420,000 --a------ c:\windows\system32\drivers\hardlock.sys
2008-10-14 23:30 . 2003-12-18 07:53 47,616 --a------ c:\windows\system32\drivers\haspnt.sys
2008-10-14 23:29 . 2008-10-14 23:42 <DIR> d-------- C:\HaspEmulPE.XP
2008-10-14 23:19 . 2004-02-22 13:00 1,386,496 --a------ c:\windows\system32\MSVBVM60.DLL
2008-10-14 23:19 . 2003-09-10 18:08 665,600 --a------ c:\windows\system32\HARDLOCK.SYS
2008-10-14 23:19 . 2002-07-29 18:13 434,252 --a------ c:\windows\system32\HARDLOCK.VXD
2008-10-14 23:19 . 2002-08-27 19:07 291,328 --a------ c:\windows\system32\hlvdd.dll
2008-10-14 23:19 . 2003-07-25 08:17 148,992 --a------ c:\windows\system32\HASPVB32.DLL
2008-10-14 23:19 . 2001-11-01 23:50 49,750 --a------ c:\windows\system32\HASP95DL.VXD
2008-10-14 23:19 . 2001-11-01 22:15 45,664 --a------ c:\windows\system32\HASP95.VXD
2008-10-14 23:19 . 2001-11-01 22:15 6,656 --a------ c:\windows\system32\haspvdd.dll
2008-10-14 23:19 . 2001-03-02 05:00 383 --a------ c:\windows\system32\haspdos.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-14 02:45 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-14 02:36 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-11-12 06:16 --------- d-----w c:\documents and settings\OKUCU\Application Data\Skype
2008-10-31 15:27 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-26 04:12 76,856 ----a-w c:\documents and settings\OKUCU\Application Data\GDIPFONTCACHEV1.DAT
2008-10-25 13:09 --------- d-----w c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-10-25 12:51 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-10-22 23:10 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 23:10 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-18 15:47 --------- d-----w c:\documents and settings\OKUCU\Application Data\LimeWire
2008-10-14 05:17 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-13 20:55 --------- d-----w c:\program files\MathType
2008-10-12 11:08 --------- d-----w c:\documents and settings\OKUCU\Application Data\Autodesk
2008-10-12 11:08 --------- d-----w c:\documents and settings\All Users\Application Data\Autodesk
2008-10-11 09:25 --------- d-----w c:\program files\MSXML 6.0
2008-10-10 08:32 --------- d-----w c:\program files\Nikon_Capture_NX2_v2.1.0
2008-10-10 08:13 --------- d-----w c:\program files\AutoCAD 2008
2008-10-10 08:12 --------- d-----w c:\program files\Common Files\Autodesk Shared
2008-10-09 18:42 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2008-10-09 18:30 --------- d-----w c:\program files\Common Files\Adobe
2008-10-09 18:30 --------- d-----w c:\program files\Bonjour
2008-10-09 18:17 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-10-09 17:00 --------- d-----w c:\program files\turbo squid tentacles
2008-10-09 16:54 --------- d-----w c:\program files\Autodesk
2008-10-05 06:22 --------- d-----w c:\program files\Google
2008-10-02 06:33 --------- d-----w c:\program files\eMule
2008-10-02 06:31 --------- d-----w c:\program files\Swiss International Air Lines TravelDesk
2008-10-02 06:29 --------- d-----w c:\program files\Netopia
2008-09-29 12:20 61,440 ----a-w c:\windows\system32\drivers\qkcgs.sys
2008-09-29 05:52 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2008-09-29 05:47 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT
2008-09-25 07:44 --------- d-----w c:\documents and settings\OKUCU\Application Data\U3
2008-08-10 06:58 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLbz.DAT
.
((((((((((((((((((((((((((((( snapshot_2008-11-04_ 7.03.36.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 23:27:04 163,328 ----a-w c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2008-11-12 15:53:57 10,006,528 ----a-w c:\windows\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-11-12 15:53:57 540,672 ----a-w c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 23:27:04 163,328 ----a-w c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-11-12 15:53:29 10,006,528 ----a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-11-12 15:53:29 540,672 ----a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2005-12-25 15:50:14 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-11-14 02:55:38 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2005-12-25 15:50:14 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-14 02:55:38 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-09 06:58:58 8,470 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\17HTUR26\msusp[1].bin
+ 2008-11-11 03:13:25 15,770 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\17HTUR26\msusp[2].bin
+ 2008-11-11 05:18:34 8,470 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\17HTUR26\msusp[3].bin
+ 2008-11-14 02:55:38 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2004-08-04 12:00:00 66,048 ----a-w c:\windows\system32\mscaeo.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-19 68856]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 1207080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"SVPWUTIL"="c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2004-05-01 65536]
"Tvs"="c:\program files\TOSHIBA\Tvs\TvsTray.exe" [2005-04-05 73728]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2005-09-06 671744]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2005-08-25 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-28 286720]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-23 196608]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-30 122941]
"HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 28672]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-19 48752]
"URLLSTCK.exe"="c:\program files\Norton Internet Security\UrlLstCk.exe" [2005-05-05 22656]
"MPKrnl"="c:\windows\MPKrnl.dll" [2008-11-12 20480]
"TFncKy"="TFncKy.exe" [BU]
"CFSServ.exe"="CFSServ.exe" [BU]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-03-28 c:\windows\KHALMNPR.Exe]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-08-22 c:\windows\system32\TCtrlIOHook.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-22 c:\windows\agrsmmsg.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"MPMKrnl"="c:\windows\MKMKrnl.dll" [2008-11-12 10240]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2005-12-28 155648]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{F8E07BB2-7A19-4057-80F1-E14646E630B4}"= "F8E07BB2.dll" [BU]
"{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96}"= "4FBFD5A4.dll" [BU]
"{3F21AA0C-2A9E-4BE9-9083-9E58AB41BA01}"= "3F21AA0C.dll" [BU]
"{F2CBFAC4-6FF9-4DE9-BCB1-0F2FA2AA0B4C}"= "F2CBFAC4.dll" [BU]
"{70B0129E-726E-4789-A7C0-5DDC33241E94}"= "70B0129E.dll" [BU]
"{01AFE3DC-2242-436E-9B44-6DD1C664E828}"= "01AFE3DC.dll" [BU]
"{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40}"= "5934EA2B.dll" [BU]
"{93DEE065-EC9B-4505-ADD3-19880AD3C38F}"= "93DEE065.dll" [BU]
"{C8FFD223-C0FB-40C5-94A0-FD7891AC18E9}"= "C8FFD223.dll" [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=01AFE3DC.dll,HBmhly.dll,HBZHUXIAN.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=c:\windows\pss\Picture Package VCD Maker.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Google Web Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Run Google Web Accelerator.lnk
backup=c:\windows\pss\Run Google Web Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=c:\windows\pss\Windows Desktop Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^OKUCU^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\OKUCU\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^OKUCU^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\OKUCU\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^OKUCU^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=c:\documents and settings\OKUCU\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^OKUCU^Start Menu^Programs^Startup^Nikon Monitor.lnk]
path=c:\documents and settings\OKUCU\Start Menu\Programs\Startup\Nikon Monitor.lnk
backup=c:\windows\pss\Nikon Monitor.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-09-03 09:11 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-06-20 12:36 1207080 c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2005-10-18 03:58 278528 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
--a------ 2007-02-27 01:18 67128 c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
--a------ 2003-08-19 06:43 57344 c:\program files\Lexmark X1100 Series\lxbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a------ 2005-06-08 05:44 196608 c:\program files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a------ 2005-06-08 06:24 458752 c:\program files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a------ 2005-06-08 06:14 217088 c:\program files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PadTouch]
--a------ 2005-08-30 02:53 1077329 c:\program files\Toshiba\Touch and Launch\PadExe.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
--a------ 2006-10-13 08:20 20058152 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
--a------ 2005-05-12 01:31 118784 c:\program files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2006-03-10 09:45 35328 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zooming]
--a------ 2005-06-06 00:58 24576 c:\windows\system32\ZoomingHook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2008\\3dsmax.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R3 de8296f;de8296f;c:\windows\system32\de8296f.sys [2008-11-11 5504]
S3 c39e8db;c39e8db;c:\windows\system32\c39e8db.sys [2008-11-11 5504]
S3 ca99d57;ca99d57;c:\windows\system32\ca99d57.sys [ ]
S3 d7b49fa;d7b49fa;c:\windows\system32\d7b49fa.sys [2008-11-11 5504]
S3 f35ee9e;f35ee9e;c:\windows\system32\f35ee9e.sys [2008-11-13 5504]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-03 29744]
.
Contents of the 'Scheduled Tasks' folder
2008-11-13 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-12-14 03:24]
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46} - 16AF66EB.dll
ShellExecuteHooks-{755D0ED0-3996-4ADB-9B1F-AD8F0E9E4738} - 755D0ED0.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\OKUCU\Application Data\Mozilla\Firefox\Profiles\c4f6pgvi.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-13 18:53:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
c:\program files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\fxssvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\Toshiba\TOSHIBA Controls\TFncKy.exe
c:\program files\Toshiba\ConfigFree\CFSServ.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\progra~1\MICROS~4\rapimgr.exe
c:\program files\Apoint2K\ApntEx.exe
.
**************************************************************************
.
Completion time: 2008-11-13 19:01:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-14 03:01:35
ComboFix2.txt 2008-11-12 15:41:13
ComboFix3.txt 2008-11-12 07:33:00
ComboFix4.txt 2008-11-12 03:58:35
ComboFix5.txt 2008-11-14 02:50:53
Pre-Run: 14,327,734,272 bytes free
Post-Run: 14,329,004,032 bytes free
372 --- E O F --- 2008-10-16 20:32:25