ComboFix 08-02-22 - Suraj 2008-02-21 19:40:54.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1590 [GMT -7:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe * Created a new restore point [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat C:\Documents and Settings\Suraj\Application Data\macromedia\Flash Player\#SharedObjects\4QW94YDA\www.broadcaster.com C:\Documents and Settings\Suraj\Application Data\macromedia\Flash Player\#SharedObjects\4QW94YDA\www.broadcaster.com\played_list.sol C:\Documents and Settings\Suraj\Application Data\macromedia\Flash Player\#SharedObjects\4QW94YDA\www.broadcaster.com\video_queue.sol C:\Documents and Settings\Suraj\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com C:\Documents and Settings\Suraj\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol C:\Program Files\kernel C:\temp\17o7 C:\temp\17o7\tmpTF.log C:\Temp\1cb C:\Temp\1cb\syscheck.log C:\Temp\isgTi19 C:\temp\tn3 C:\WINDOWS\cookies.ini C:\WINDOWS\rs.txt C:\WINDOWS\search_res.txt C:\WINDOWS\system32\cdrtbcva.ini C:\WINDOWS\system32\dajshgpm.ini C:\WINDOWS\system32\drivers\core.cache(10).dsk C:\WINDOWS\system32\drivers\core.cache(11).dsk C:\WINDOWS\system32\drivers\core.cache(12).dsk C:\WINDOWS\system32\drivers\core.cache(13).dsk C:\WINDOWS\system32\drivers\core.cache(2).dsk C:\WINDOWS\system32\drivers\core.cache(3).dsk C:\WINDOWS\system32\drivers\core.cache(4).dsk C:\WINDOWS\system32\drivers\core.cache(5).dsk C:\WINDOWS\system32\drivers\core.cache(6).dsk C:\WINDOWS\system32\drivers\core.cache(7).dsk C:\WINDOWS\system32\drivers\core.cache(8).dsk C:\WINDOWS\system32\drivers\core.cache(9).dsk C:\WINDOWS\system32\drivers\core.cache.dsk C:\WINDOWS\system32\drivers\ql10wntt.sys C:\WINDOWS\system32\fdykhnug.ini C:\WINDOWS\system32\flwklhcj.ini C:\WINDOWS\system32\ftriqehx.ini C:\WINDOWS\system32\hlbxqmfv.ini C:\WINDOWS\system32\hvkstbmr.ini C:\WINDOWS\system32\hvmrogru.ini C:\WINDOWS\system32\kwhubtvs.ini C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\nGpxx01 C:\WINDOWS\system32\pac.txt C:\WINDOWS\system32\smbbwrew.ini C:\WINDOWS\system32\ttstv.ini C:\WINDOWS\system32\ttstv.ini2 C:\WINDOWS\system32\vqpesgfs.ini C:\WINDOWS\system32\wintsvtr32.exe C:\WINDOWS\system32\xxocpdag.ini C:\WINDOWS\wr.txt ----- BITS: Possible infected sites ----- hxxp://au.downlo�j hxxp://au.download.windo . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\LEGACY_DOMAINSERVICE -------\LEGACY_QL10WNTT -------\DomainService -------\ql10wntt ((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 ))))))))))))))))))))))))))))))) . 2008-02-21 14:29 . 2008-02-21 14:29 49 --a------ C:\WINDOWS\winzipsp.ini 2008-02-21 14:21 . 2008-02-21 14:39
----a-w 307,200 2008-01-09 20:06:18 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe ----a-w 102,400 2008-01-09 20:06:06 C:\Program Files\Creative\MediaSource\Detector\CTDetect .exe ----a-w 856,064 2008-01-13 16:40:21 C:\Program Files\I8kfanGUI\I8kfanGUI .exe ----a-w 267,064 2008-01-19 22:34:15 C:\Program Files\iTunes\iTunesHelper .exe ----a-w 136,768 2008-01-17 07:13:06 C:\Program Files\McAfee\Common Framework\UdaterUI .exe ----a-w 112,216 2008-01-19 22:34:14 C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT .EXE ----a-w 405,584 2008-01-24 09:24:47 C:\Program Files\Microsoft ActiveSync\WCESCOMM .EXE ----a-w 405,584 2008-01-24 09:24:49 C:\Program Files\Microsoft ActiveSync\WCESCOMM .EXE ----a-w 405,584 2008-01-24 09:24:50 C:\Program Files\Microsoft ActiveSync\WCESCOMM .EXE ----a-w 405,584 2008-01-13 16:40:21 C:\Program Files\Microsoft ActiveSync\WCESCOMM .EXE ----a-w 176,201 2008-01-09 20:05:57 C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon .exe ----a-w 158,208 2008-01-13 23:48:31 C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe ----a-w 15,360 2008-02-13 08:54:31 C:\WINDOWS\system32\ctfmon .exe[/code] ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 04:00 15360] "Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [ ] "AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" [ ] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"="c:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" [ ] "Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [ ] "ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [ ] "McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [ ] "googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 14:22 3739648] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 18:17 443968] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RunNarrator"="Narrator.exe" [2004-08-10 04:00 53760 C:\WINDOWS\system32\narrator.exe] C:\Documents and Settings\Suraj\Start Menu\Programs\Startup\ Spyware Vaccine.lnk - C:\Program Files\Spyware Vaccine\Spyware Vaccine\spv.exe [2008-02-01 15:40:50 1265664] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Launchy.lnk - C:\Program Files\Launchy\Launchy.exe [2007-01-24 13:23:19 552960] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless] C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 15:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk backup=C:\WINDOWS\pss\Bluetooth Manager.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Suraj^Start Menu^Programs^Startup^Metacafe Downloader.lnk] path=C:\Documents and Settings\Suraj\Start Menu\Programs\Startup\Metacafe Downloader.lnk backup=C:\WINDOWS\pss\Metacafe Downloader.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet] --a------ 2005-05-06 17:47 2224128 C:\Program Files\BitLord\BitLord.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BSplayer_WhenUSave_Installer] C:\Program Files\BSplayer_WhenUSave_Installer\BSplayer_WhenUSave_Installer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c866d692] C:\WINDOWS\system32\gunhkydf.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\comup] C:\WINDOWS\system32\mobjchku.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Crammer] C:\Program Files\crammer\crammer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher] --------- 2005-02-23 15:19 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk] --a------ 2007-01-01 14:22 3739648 C:\Program Files\Google\Google Talk\googletalk.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent] --a------ 2008-01-13 09:40 405584 C:\Program Files\Microsoft ActiveSync\WCESCOMM .EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\i8kfangui] --a------ 2008-01-13 09:40 856064 C:\Program Files\I8kfanGUI\I8kfanGUI .exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2008-01-19 15:29 700928 C:\Program Files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kernel] C:\Program Files\kernel\kernel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXSUPMON] C:\WINDOWS\system32\LXSUPMON.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-01-09 19:38 286720 C:\Program Files\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2003-11-19 16:48 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "UPS"=3 (0x3) "SPTISRV"=3 (0x3) "iPodService"=3 (0x3) "CCALib8"=2 (0x2) "TapiSrv"=3 (0x3) "iPod Service"=3 (0x3) "gusvc"=3 (0x3) "gupdate"=2 (0x2) "Fax"=2 (0x2) "Bonjour Service"=2 (0x2) "Apple Mobile Device"=2 (0x2) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{30e2d81f-0e3b-11db-922c-001422e0ebc8}] \Shell\AutoRun\command - F:\LaunchU3.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}] \Shell\AutoRun\command - E:\setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd46c7a2-7f34-11da-90fd-00038a000015}] \Shell\AutoRun\command - F:\wd_windows_tools\setup.exe . Contents of the 'Scheduled Tasks' folder "2007-09-13 22:48:28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-02-22 02:47:32 C:\WINDOWS\Tasks\GoogleUpdateTask.job" - C:\Program Files\Google\Update\1.0.103.3\GoogleUpdate.exe "2008-02-20 08:41:00 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-21 19:47:57 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... ? [3484] scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\Common Framework\naPrdMgr.exe C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\UPHClean\uphclean.exe C:\WINDOWS\ehome\mcrdsvc.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\cscript.exe . ************************************************************************** . Completion time: 2008-02-21 19:52:55 - machine was rebooted ComboFix-quarantined-files.txt 2008-02-22 02:52:51 . 2008-02-21 23:55:47 --- E O F ---