ComboFix 08-11-06.01 - User 2008-11-07 10:43:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.191 [GMT -5:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\User\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\User\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\User\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\Common Files\fqkk
c:\program files\Common Files\fqkk\fqkkd\class-barrel
c:\program files\Common Files\fqkk\fqkkd\fqkkc.dll
c:\program files\Common Files\fqkk\fqkkd\vocabulary
c:\program files\Common Files\fqkk\fqkkl.exe
c:\program files\Common Files\fqkk\fqkkp.exe
c:\temp\tn3
c:\windows\Fonts\acrsecB.fon
c:\windows\Fonts\acrsecI.fon
c:\windows\fqkk
c:\windows\fqkk\fqkk.dat
c:\windows\fqkk\wu
c:\windows\system32\drivers\core.cache.dsk
c:\windows\system32\drivers\dxapii.sys
c:\windows\system32\MSINET.oca
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DXAPII
-------\Legacy_MSDIRECT
-------\Service_dxapii
((((((((((((((((((((((((( Files Created from 2008-10-07 to 2008-11-07 )))))))))))))))))))))))))))))))
.
2008-11-04 12:08 . 2008-11-04 12:25 <DIR> d-------- c:\documents and settings\User\DoctorWeb
2008-11-04 10:36 . 2008-11-04 10:36 578,560 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-11-04 10:34 . 2008-11-04 10:35 <DIR> d-------- c:\windows\ERUNT
2008-11-04 10:24 . 2008-11-04 10:50 <DIR> d-------- C:\SDFix
2008-11-04 10:13 . 2008-11-04 10:13 <DIR> d-------- C:\rsit
2008-11-04 09:56 . 2008-11-04 09:56 <DIR> d-------- C:\_OTMoveIt
2008-11-03 10:09 . 2008-11-03 10:09 <DIR> d-------- c:\documents and settings\Administrator
2008-11-03 10:02 . 2008-11-04 08:39 <DIR> d-------- C:\Lop SD
2008-11-03 08:26 . 2008-11-03 08:26 <DIR> d-------- c:\program files\Trend Micro
2008-11-01 02:23 . 2008-11-01 02:23 9,662 --a------ c:\windows\system32\ZoneAlarmIconUS.ico
2008-11-01 02:13 . 2008-11-02 02:15 4,286 --a------ c:\windows\system32\Jamster.ico
2008-11-01 02:02 . 2008-11-01 02:02 <DIR> d-------- c:\program files\OINAnalytics
2008-11-01 01:57 . 2008-11-01 08:31 <DIR> d--hs---- c:\windows\Lg
2008-10-31 00:12 . 2008-10-31 00:12 <DIR> d-------- c:\windows\system32\vb
2008-10-31 00:12 . 2008-10-31 08:04 <DIR> d-------- c:\windows\system32\im
2008-10-31 00:12 . 2008-10-31 00:12 <DIR> d-------- c:\windows\system32\CPX
2008-10-31 00:12 . 2008-10-31 00:13 <DIR> d-------- c:\windows\system32\BOT2
2008-10-30 09:07 . 2008-10-30 09:07 <DIR> d-------- c:\windows\system32\QI02
2008-10-30 09:07 . 2008-10-31 00:12 <DIR> d-------- c:\temp\NT32
2008-10-23 22:23 . 2008-10-15 11:34 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-14 16:15 . 2008-09-15 07:12 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-10-14 16:15 . 2008-09-08 05:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-10-14 16:14 . 2008-08-14 05:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-14 16:14 . 2008-08-14 05:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-14 16:14 . 2008-08-14 04:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-14 16:14 . 2008-08-14 04:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-07 15:17 --------- d-----w c:\documents and settings\User\Application Data\LimeWire
2008-11-01 13:39 --------- d-----w c:\program files\CA Yahoo! Anti-Spy
2008-10-04 20:52 --------- d-----w c:\documents and settings\User\Application Data\Wal-Mart Digital Photo Manager
2008-10-01 12:52 --------- d-----w c:\program files\LimeWire
2008-09-23 02:23 --------- d-----w c:\program files\iTunes
2008-09-23 02:23 --------- d-----w c:\program files\iPod
2008-09-23 02:23 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-23 02:20 --------- d-----w c:\program files\QuickTime
2008-09-23 02:19 --------- d-----w c:\program files\Common Files\Apple
2008-09-23 01:45 --------- d-----w c:\program files\Bonjour
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\drivers\srv.sys
2008-07-10 16:44 23,272 ----a-w c:\documents and settings\User\Application Data\GDIPFONTCACHEV1.DAT
2005-07-29 20:24 472 --sha-r c:\windows\Lg\M0.vbs
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 49263]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"SoundMan"="SOUNDMAN.EXE" [2005-11-11 c:\windows\SOUNDMAN.EXE]
"VTTimer"="VTTimer.exe" [2005-03-07 c:\windows\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-10-31 c:\windows\system32\VTTrayp.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\User\Start Menu\Programs\Startup\
MEMonitor.lnk - c:\program files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2007-12-04 951640]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-22 734872]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
Contents of the 'Scheduled Tasks' folder
2008-11-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2007-04-15 c:\windows\Tasks\MP Scheduled Quick Scan.job
- c:\program files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe []
2008-11-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Corn - c:\docume~1\User\MYDOCU~1\PPATCH~1\javaw.exe
ShellExecuteHooks-{C988A1BF-D300-4A4C-9A63-AFDF23671052} - c:\windows\system32\vtUooMdd.dll
Notify-vtUooMdd - vtUooMdd.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
R1 -: HKCU-SearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O8 -: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-07 10:47:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Windows Defender\MsMpEng.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-11-07 10:50:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-07 15:50:01
Pre-Run: 15,351,443,456 bytes free
Post-Run: 15,431,663,616 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
171 --- E O F --- 2008-11-07 15:18:19