ComboFix 08-12-16.03 - admin 2008-12-17 11:15:57.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1983.1317 [GMT 0:00]
Running from: c:\documents and settings\admin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\admin\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
FILE ::
c:\windows\system32\REN111.tmp
c:\windows\system32\REN112.tmp
c:\windows\system32\REN113.tmp
c:\windows\system32\REN136.tmp
c:\windows\system32\REN137.tmp
c:\windows\system32\REN138.tmp
c:\windows\system32\REN155.tmp
c:\windows\system32\REN156.tmp
c:\windows\system32\REN157.tmp
c:\windows\system32\REN2B.tmp
c:\windows\system32\REN2C.tmp
c:\windows\system32\REN2D.tmp
c:\windows\system32\REN49.tmp
c:\windows\system32\REN4A.tmp
c:\windows\system32\REN4B.tmp
c:\windows\system32\REN4C.tmp
c:\windows\system32\REN4D.tmp
c:\windows\system32\REN4E.tmp
c:\windows\system32\REN80.tmp
c:\windows\system32\REN81.tmp
c:\windows\system32\REN82.tmp
c:\windows\system32\RENF2.tmp
c:\windows\system32\RENF3.tmp
c:\windows\system32\RENF4.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\REN111.tmp
c:\windows\system32\REN112.tmp
c:\windows\system32\REN113.tmp
c:\windows\system32\REN136.tmp
c:\windows\system32\REN137.tmp
c:\windows\system32\REN138.tmp
c:\windows\system32\REN155.tmp
c:\windows\system32\REN156.tmp
c:\windows\system32\REN157.tmp
c:\windows\system32\REN2B.tmp
c:\windows\system32\REN2C.tmp
c:\windows\system32\REN2D.tmp
c:\windows\system32\REN49.tmp
c:\windows\system32\REN4A.tmp
c:\windows\system32\REN4B.tmp
c:\windows\system32\REN4C.tmp
c:\windows\system32\REN4D.tmp
c:\windows\system32\REN4E.tmp
c:\windows\system32\REN80.tmp
c:\windows\system32\REN81.tmp
c:\windows\system32\REN82.tmp
c:\windows\system32\RENF2.tmp
c:\windows\system32\RENF3.tmp
c:\windows\system32\RENF4.tmp
.
((((((((((((((((((((((((( Files Created from 2008-11-17 to 2008-12-17 )))))))))))))))))))))))))))))))
.
2008-12-16 12:34 . 2008-12-16 12:44 <DIR> d-------- c:\documents and settings\admin\DoctorWeb
2008-12-16 11:24 . 2008-12-16 11:24 <DIR> d-------- c:\program files\Common Files\Java
2008-12-16 10:42 . 2008-12-16 10:50 <DIR> d-------- c:\program files\Unlocker
2008-12-16 10:42 . 2008-12-16 10:43 <DIR> d-------- c:\documents and settings\admin\Application Data\Desktopicon
2008-12-15 15:39 . 2008-12-16 11:25 <DIR> d-------- c:\program files\Java
2008-12-15 12:36 . 2001-08-17 22:37 24,576 --a--c--- c:\windows\system32\dllcache\agcgauge.ax
2008-12-15 09:41 . 2008-12-16 09:20 <DIR> d-------- c:\documents and settings\admin\Application Data\IDM
2008-12-15 09:40 . 2008-12-15 11:06 <DIR> d-------- c:\program files\Internet Download Manager
2008-12-14 17:00 . 2008-12-14 17:00 <DIR> d-------- c:\program files\Windows Installer Clean Up
2008-12-14 17:00 . 2008-12-14 17:00 <DIR> d-------- c:\program files\MSECACHE
2008-12-14 13:40 . 2008-12-14 13:40 <DIR> d-------- c:\program files\Common Files\Insight Software Solutions
2008-12-14 13:40 . 2008-12-14 13:40 <DIR> d-------- c:\program files\Capture Express
2008-12-14 13:40 . 2008-12-14 13:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\Insight Software Solutions
2008-12-14 13:40 . 2008-12-14 13:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\Insight Software
2008-12-14 00:02 . 2008-12-14 00:02 268 --ah----- C:\sqmdata01.sqm
2008-12-14 00:02 . 2008-12-14 00:02 244 --ah----- C:\sqmnoopt01.sqm
2008-12-13 16:27 . 2008-12-13 16:27 <DIR> d-------- C:\fsaua.data
2008-12-13 09:59 . 2008-12-12 00:57 78,336 --a------ c:\windows\system32\Agent.OMZ.Fix.exe
2008-12-12 09:36 . 2008-12-12 09:36 578,560 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-12-12 09:34 . 2008-12-12 09:34 <DIR> d-------- c:\windows\ERUNT
2008-12-11 19:39 . 2008-12-11 19:39 268 --ah----- C:\sqmdata00.sqm
2008-12-11 19:39 . 2008-12-11 19:39 244 --ah----- C:\sqmnoopt00.sqm
2008-12-11 16:34 . 2008-12-11 16:34 0 --a------ c:\windows\nsreg.dat
2008-12-11 11:02 . 2008-12-11 11:02 <DIR> d-------- c:\program files\Trend Micro
2008-12-11 07:43 . 2008-06-08 12:44 <DIR> d-------- c:\documents and settings\Administrator\WINDOWS
2008-12-11 07:43 . 2008-12-11 07:43 <DIR> d-------- c:\documents and settings\Administrator
2008-12-10 19:24 . 2008-12-10 19:24 <DIR> d-------- c:\documents and settings\admin\Application Data\Malwarebytes
2008-12-10 19:22 . 2008-12-10 19:27 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-10 19:22 . 2008-12-10 19:22 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-10 19:22 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-10 19:22 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-10 17:58 . 2008-12-10 17:57 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-10 13:47 . 2008-12-10 13:47 0 --a------ c:\windows\system32\8104297.jun
2008-12-09 19:30 . 2006-02-28 12:00 4,224 --a------ c:\windows\system32\drivers\beep.sys
2008-12-09 19:30 . 2006-02-28 12:00 4,224 --a--c--- c:\windows\system32\dllcache\beep.sys
2008-12-09 18:40 . 2008-12-09 18:40 <DIR> d-------- C:\Binaries
2008-12-09 18:25 . 2008-12-10 14:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-08 18:54 . 2006-01-04 01:00 65,536 --a------ c:\windows\system32\ICE_JNIRegistry.dll
2008-12-06 14:25 . 2008-12-06 14:40 <DIR> d-------- c:\documents and settings\admin\Application Data\GrabPro
2008-12-06 14:24 . 2008-12-06 17:52 <DIR> d-------- c:\documents and settings\admin\Application Data\Orbit
2008-12-06 14:11 . 2008-12-06 14:16 237,568 --a------ c:\windows\system32\rmc_rtspdl.dll
2008-12-06 14:11 . 2008-12-06 14:16 156,672 --a------ c:\windows\system32\rmc_fixasf.exe
2008-12-06 14:09 . 2008-12-06 14:16 323,584 --a------ c:\windows\system32\AUDIOGENIE2.DLL
2008-12-06 14:08 . 2008-12-06 14:08 <DIR> d-------- c:\windows\Replay Media Catcher
2008-12-04 16:19 . 2008-12-11 08:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\Ulead Systems
2008-12-01 19:12 . 2008-12-03 16:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\River Past G5
2008-12-01 19:12 . 2008-12-01 19:12 <DIR> d-------- c:\documents and settings\admin\Application Data\River Past G5
2008-12-01 14:54 . 2008-12-01 14:54 <DIR> d-------- c:\documents and settings\admin\Application Data\dvdcss
2008-11-30 20:16 . 2008-11-30 20:19 20,358 --a------ c:\windows\vgirl.prf
2008-11-27 09:41 . 2008-12-11 17:53 <DIR> d-------- c:\documents and settings\admin\Application Data\Apple Computer
2008-11-26 17:32 . 2008-11-26 17:32 <DIR> d-------- c:\program files\Common Files\Apple
2008-11-26 17:32 . 2008-11-26 17:32 <DIR> d-------- c:\program files\Apple Software Update
2008-11-26 17:32 . 2008-11-26 17:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-26 17:32 . 2008-11-26 17:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2008-11-26 17:28 . 2008-11-26 17:33 <DIR> d-------- c:\program files\QuickTime
2008-11-24 16:30 . 2000-04-30 18:12 92,160 --a------ c:\windows\system32\BarCod32.OCX
2008-11-24 11:10 . 2008-11-24 11:10 <DIR> d-------- c:\documents and settings\admin\Application Data\vlc
2008-11-22 17:39 . 2008-11-22 17:39 0 --a------ c:\documents and settings\admin\Application Data\wklnhst.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-17 11:16 --------- d-----w c:\documents and settings\admin\Application Data\DMCache
2008-12-17 11:02 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-15 21:05 --------- d-----w c:\documents and settings\admin\Application Data\VSO
2008-12-11 08:14 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-11 08:11 --------- d-----w c:\documents and settings\All Users\Application Data\DriverScanner
2008-12-11 08:11 --------- d-----w c:\documents and settings\admin\Application Data\Uniblue
2008-12-09 15:36 --------- d-----w c:\program files\Your Uninstaller 2008
2008-12-04 19:14 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
2008-12-04 16:03 --------- d-----w c:\documents and settings\admin\Application Data\Canon
2008-11-17 20:40 --------- d-----w c:\documents and settings\admin\Application Data\LimeWire
2008-11-16 17:44 --------- d-----w c:\program files\McAfee
2008-11-12 11:37 --------- d-----w c:\documents and settings\All Users\Application Data\13242
2008-11-05 08:30 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-29 16:47 --------- d-----w c:\documents and settings\admin\Application Data\CyberLink
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 20:45 --------- d-----w c:\program files\MSBuild
2008-10-23 20:44 --------- d-----w c:\program files\Reference Assemblies
2008-10-23 19:49 --------- d-----w c:\documents and settings\All Users\Application Data\ATI
2008-10-23 19:49 --------- d-----w c:\documents and settings\admin\Application Data\ATI
2008-10-23 18:56 --------- d-----w c:\program files\Microsoft IntelliPoint
2008-10-23 18:51 --------- d-----w c:\program files\ATI Technologies
2008-10-23 18:34 --------- dc-h--w c:\documents and settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 14:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 14:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 14:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 14:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 14:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 14:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 14:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 14:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-06 16:02 98,304 ----a-w c:\windows\system32\CmdLineExt.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 16:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-07-15 931248]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Privacy Suite"="c:\program files\CyberScrub Privacy Suite\CSPSeraser.exe" [2008-07-23 876680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-26 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Capture Express.lnk - c:\program files\Capture Express\capexp.exe [2008-12-14 5373952]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" [2008-10-04 203280]
S3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2008-06-02 30464]
S3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2008-06-02 12672]
S3 stppp;Speedtouch PPP Adapter Adapter;c:\windows\system32\DRIVERS\stppp.sys [2008-06-02 32000]
S3 Z302Mic;Vimicro Z302 Mic Audio Filter Driver;c:\windows\system32\drivers\UsbMicfilt.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fb2a7764-e932-11db-a0f9-00508d9d5209}]
\Shell\AutoRun\command - F:\autorun.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
2008-10-15 c:\windows\Tasks\McDefragTask.job
- c:\windows\system32\defrag.exe [2008-04-14 00:12]
2007-04-12 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2008-07-09 17:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-17 11:17:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(716)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2008-12-17 11:18:49
ComboFix-quarantined-files.txt 2008-12-17 11:18:46
Pre-Run: 226,990,387,200 bytes free
Post-Run: 227,077,810,176 bytes free
228 --- E O F --- 2008-12-11 07:18:36