ComboFix 08-02-13.2 - Admin 02/13/2008 13:02:02.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1478 [GMT -5:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\cookies.ini C:\WINDOWS\system32\bpobmsbj.ini C:\WINDOWS\system32\mlnmp.ini C:\WINDOWS\system32\mlnmp.ini2 C:\WINDOWS\system32\oqtss.ini C:\WINDOWS\system32\oqtss.ini2 . ((((((((((((((((((((((((( Files Created from 2008-01-13 to 2008-02-13 ))))))))))))))))))))))))))))))) . 2008-02-12 21:28 . 2008-02-12 21:10 691,545 --a------ C:\WINDOWS\unins000.exe 2008-02-12 21:28 . 2008-02-12 21:28 3,443 --a------ C:\WINDOWS\unins000.dat 2008-02-12 20:21 . 2008-02-12 20:22 1,374 --a------ C:\WINDOWS\imsins.BAK 2008-02-06 14:44 . 2008-02-06 15:04 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll 2008-02-06 14:33 . 2008-02-06 14:51 d-------- C:\Program Files\Railroad Tycoon 3 2008-02-03 18:30 . 2005-07-19 10:05 135,168 --a------ C:\WINDOWS\system32\igfxres.dll 2008-02-03 17:51 . 2008-02-03 17:51 d-------- C:\Program Files\Enlight 2008-01-30 13:07 . 2008-01-30 13:10 d-------- C:\Program Files\Spyware Doctor 2008-01-30 13:07 . 2008-01-30 13:07 d-------- C:\Documents and Settings\Admin\Application Data\PC Tools 2008-01-30 13:07 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys 2008-01-30 13:07 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys 2008-01-30 13:07 . 2007-12-10 14:53 41,864 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys 2008-01-30 13:07 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys 2008-01-30 12:25 . 2008-01-30 12:25 d-------- C:\Program Files\Microsoft Silverlight 2008-01-22 14:05 . 2008-01-22 14:49 533 --a------ C:\WINDOWS\eReg.dat . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-13 18:37 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k7 2008-02-13 18:37 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k6 2008-02-13 18:37 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k5 2008-02-13 18:37 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k4 2008-02-13 18:37 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k3 2008-02-13 18:37 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k2 2008-02-13 18:37 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k1 2008-02-13 18:37 113,678 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k0 2008-02-13 02:33 --------- d-----w C:\Program Files\Spybot - Search & Destroy 2008-02-13 02:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-02-06 19:33 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-02-06 17:27 --------- d-----w C:\Program Files\Motorola Phone Tools 2008-02-06 17:27 --------- d-----w C:\Program Files\Microsoft Works 2008-02-06 17:27 --------- d-----w C:\Program Files\LD-Anime 2008-02-06 17:27 --------- d-----w C:\Program Files\DivX 2008-02-06 17:27 --------- d-----w C:\Program Files\Avanquest update 2008-02-06 17:27 --------- d-----w C:\Program Files\ActivIcons 2008-02-06 17:22 --------- d-----w C:\Program Files\Java 2008-02-06 17:20 --------- d-----w C:\Program Files\Sony 2008-01-31 00:13 --------- d-----w C:\Program Files\TrojanHunter 5.0 2008-01-30 20:10 --------- d-----w C:\Program Files\High Quality Photo Resizer 2008-01-30 20:09 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-01-22 19:49 --------- d-----w C:\Program Files\Maxis 2008-01-22 02:17 --------- d-----w C:\Documents and Settings\Admin\Application Data\uTorrent 2008-01-09 21:03 --------- d-----w C:\Program Files\Infogrames Interactive 2008-01-09 14:24 662 ----a-w C:\Documents and Settings\Admin\Application Data\wklnhst.dat 2008-01-08 17:00 --------- d-----w C:\Program Files\SIM editor 2008-01-08 16:42 348,160 ----a-w C:\WINDOWS\MSVCR71.DLL 2008-01-08 16:42 1,060,864 ----a-w C:\WINDOWS\MFC71.DLL 2008-01-08 16:38 40,960 ----a-w C:\WINDOWS\SimTestDll.dll 2008-01-07 02:12 --------- d-----w C:\Program Files\Google 2008-01-07 01:16 --------- d-----w C:\Program Files\PhotoFusion 2008-01-07 01:08 --------- d-----w C:\Documents and Settings\Admin\Application Data\Image Zone Express 2008-01-07 01:06 --------- d-----w C:\Documents and Settings\Admin\Application Data\Printer Info Cache 2008-01-07 00:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bluetooth 2008-01-05 15:23 --------- d-----w C:\Program Files\AC3Filter 2008-01-05 15:19 --------- d-----w C:\Program Files\Mediatwins software 2008-01-05 03:35 --------- d-----w C:\Program Files\Webroot 2008-01-05 03:35 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Webroot 2008-01-05 03:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Webroot 2008-01-05 03:35 --------- d-----w C:\Documents and Settings\Admin\Application Data\Webroot 2008-01-05 03:34 164 ----a-w C:\install.dat 2008-01-01 02:16 --------- d-----w C:\Program Files\CCleaner 2008-01-01 01:42 --------- d-----w C:\Documents and Settings\Admin\Application Data\TrojanHunter 2007-12-21 03:43 --------- d-----w C:\Documents and Settings\Admin\Application Data\Move Networks 2007-12-20 21:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet 2007-12-19 22:13 --------- d-----w C:\Program Files\Railroad Tycoon II 2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys 2007-12-10 04:50 82,672 ----a-w C:\WindowsXP-KB892489-x86-Symbols-ENU.exe 2007-12-10 04:50 367,344 ----a-w C:\WindowsXP-KB892489-x86-ENU.exe 2007-08-22 14:47 92,064 ----a-w C:\Documents and Settings\Admin\mqdmmdm.sys 2007-08-22 14:47 9,232 ----a-w C:\Documents and Settings\Admin\mqdmmdfl.sys 2007-08-22 14:47 79,328 ----a-w C:\Documents and Settings\Admin\mqdmserd.sys 2007-08-22 14:47 66,656 ----a-w C:\Documents and Settings\Admin\mqdmbus.sys 2007-08-22 14:47 6,208 ----a-w C:\Documents and Settings\Admin\mqdmcmnt.sys 2007-08-22 14:47 5,936 ----a-w C:\Documents and Settings\Admin\mqdmwhnt.sys 2007-08-22 14:47 4,048 ----a-w C:\Documents and Settings\Admin\mqdmcr.sys 2007-08-22 14:47 25,600 ----a-w C:\Documents and Settings\Admin\usbsermptxp.sys 2007-08-22 14:47 22,768 ----a-w C:\Documents and Settings\Admin\usbsermpt.sys 2007-06-14 17:30 928,456 ----a-w C:\Program Files\indexdat-setup.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mcbs] @={0DB27A62-5684-44F0-A8D3-8D6AEEB7ABD9} [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 13:40 98394] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 02:27 1015808] "eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 12:24 290816] "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2004-11-05 15:52 233534] "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 15:54 253952] "hpWirelessAssistant"="" [] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 18:50 81920] "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11 49152] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58 282624] "cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-10-07 16:39 177416] "CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-10-07 16:39 230928] "cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2007-10-07 16:47 1193224] "capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2007-10-07 16:47 173320] "capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2007-10-07 16:47 253952] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe] "BluetoothAuthenticationAgent"="rundll32.exe" [2004-08-04 03:00 33280 C:\WINDOWS\system32\rundll32.exe] "THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [2007-09-09 09:31 1046688] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 10:09 94208] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 10:06 77824] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 10:10 114688] "SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 02:29 102400] "SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 16:40 5367608] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW] UmxWnp.Dll 2007-05-18 13:30 79368 C:\WINDOWS\system32\UmxWNP.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent] --a------ 2004-08-04 03:00 110592 C:\WINDOWS\system32\bthprops.cpl [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX7800 Series] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2006-10-30 09:36 256576 C:\Program Files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] ---hs---- 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2006-10-25 18:58 282624 C:\Program Files\QuickTime\qttask.exe R0 KmxStart;KmxStart;C:\WINDOWS\system32\DRIVERS\kmxstart.sys [2007-05-31 12:47] R1 KmxAgent;KmxAgent;C:\WINDOWS\system32\DRIVERS\kmxagent.sys [2007-05-18 13:30] R1 KmxFile;KmxFile;C:\WINDOWS\system32\DRIVERS\KmxFile.sys [2007-05-18 13:30] R1 KmxFw;KmxFw;C:\WINDOWS\system32\DRIVERS\kmxfw.sys [2007-05-31 12:47] R2 KmxCF;KmxCF;C:\WINDOWS\system32\DRIVERS\KmxCF.sys [2007-07-24 16:00] R2 KmxSbx;KmxSbx;C:\WINDOWS\system32\DRIVERS\KmxSbx.sys [2007-05-18 13:30] R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2007-04-22 14:16] R2 UmxAgent;HIPS Event Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe" [2007-07-24 12:44] R2 UmxCfg;HIPS Configuration Interpreter;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe" [2007-05-18 13:30] R2 UmxPol;HIPS Policy Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe" [2007-05-18 13:30] R3 KmxCfg;KmxCfg;C:\WINDOWS\system32\DRIVERS\kmxcfg.sys [2007-05-18 13:30] S2 pciinfo;HP Pci Information;C:\DOCUME~1\Admin\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys [] S3 mamotou;mamotou;C:\WINDOWS\system32\DRIVERS\mamotou.sys [2005-11-07 04:50] S3 MaRdPnp;MaRdPnp;C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys [2005-08-17 22:44] S3 motccgp;Motorola USB Composite Device Driver;C:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-06-20 14:57] S3 motccgpfl;MotCcgpFlService;C:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-23 18:03] S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys [2007-05-04 16:04] S3 motport;Motorola USB Diagnostic Port;C:\WINDOWS\system32\DRIVERS\motport.sys [2007-06-20 14:57] . Contents of the 'Scheduled Tasks' folder "2008-02-03 13:23:34 C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Admin at 3 30 AM.job" - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe "2008-02-13 09:52:11 C:\WINDOWS\Tasks\Disk Cleanup.job" - C:\WINDOWS\system32\cleanmgr.exe "2008-02-13 18:38:35 C:\WINDOWS\Tasks\RegCure Program Check.job" - C:\Program Files\RegCure\RegCure.exe "2008-02-03 13:17:51 C:\WINDOWS\Tasks\RegCure.job" - C:\Program Files\RegCure\RegCure.exe "2007-12-31 05:17:42 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job" - C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe "2008-02-13 18:42:01 C:\WINDOWS\Tasks\User_Feed_Synchronization-{C1C56BD6-B19A-4FA2-BA83-3E41846FFED8}.job" - C:\WINDOWS\system32\msfeedssync.exe "2008-02-12 05:32:07 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job" - C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe&/ScheduleSweep=wrSpySweeperTrialSweep - C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex - C:\ . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-13 13:39:55 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe . ************************************************************************** . Completion time: 2008-02-13 13:52:45 - machine was rebooted ComboFix-quarantined-files.txt 2008-02-13 18:51:41 . 2008-02-13 01:24:38 --- E O F ---