ComboFix 08-02-22 - Suraj 2008-02-21 19:40:54.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1590 [GMT -7:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe * Created a new restore point [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat C:\Documents and Settings\Suraj\Application Data\macromedia\Flash Player\#SharedObjects\4QW94YDA\www.broadcaster.com C:\Documents and Settings\Suraj\Application Data\macromedia\Flash Player\#SharedObjects\4QW94YDA\www.broadcaster.com\played_list.sol C:\Documents and Settings\Suraj\Application Data\macromedia\Flash Player\#SharedObjects\4QW94YDA\www.broadcaster.com\video_queue.sol C:\Documents and Settings\Suraj\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com C:\Documents and Settings\Suraj\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol C:\Program Files\kernel C:\temp\17o7 C:\temp\17o7\tmpTF.log C:\Temp\1cb C:\Temp\1cb\syscheck.log C:\Temp\isgTi19 C:\temp\tn3 C:\WINDOWS\cookies.ini C:\WINDOWS\rs.txt C:\WINDOWS\search_res.txt C:\WINDOWS\system32\cdrtbcva.ini C:\WINDOWS\system32\dajshgpm.ini C:\WINDOWS\system32\drivers\core.cache(10).dsk C:\WINDOWS\system32\drivers\core.cache(11).dsk C:\WINDOWS\system32\drivers\core.cache(12).dsk C:\WINDOWS\system32\drivers\core.cache(13).dsk C:\WINDOWS\system32\drivers\core.cache(2).dsk C:\WINDOWS\system32\drivers\core.cache(3).dsk C:\WINDOWS\system32\drivers\core.cache(4).dsk C:\WINDOWS\system32\drivers\core.cache(5).dsk C:\WINDOWS\system32\drivers\core.cache(6).dsk C:\WINDOWS\system32\drivers\core.cache(7).dsk C:\WINDOWS\system32\drivers\core.cache(8).dsk C:\WINDOWS\system32\drivers\core.cache(9).dsk C:\WINDOWS\system32\drivers\core.cache.dsk C:\WINDOWS\system32\drivers\ql10wntt.sys C:\WINDOWS\system32\fdykhnug.ini C:\WINDOWS\system32\flwklhcj.ini C:\WINDOWS\system32\ftriqehx.ini C:\WINDOWS\system32\hlbxqmfv.ini C:\WINDOWS\system32\hvkstbmr.ini C:\WINDOWS\system32\hvmrogru.ini C:\WINDOWS\system32\kwhubtvs.ini C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\nGpxx01 C:\WINDOWS\system32\pac.txt C:\WINDOWS\system32\smbbwrew.ini C:\WINDOWS\system32\ttstv.ini C:\WINDOWS\system32\ttstv.ini2 C:\WINDOWS\system32\vqpesgfs.ini C:\WINDOWS\system32\wintsvtr32.exe C:\WINDOWS\system32\xxocpdag.ini C:\WINDOWS\wr.txt ----- BITS: Possible infected sites ----- hxxp://au.downlo�j hxxp://au.download.windo . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\LEGACY_DOMAINSERVICE -------\LEGACY_QL10WNTT -------\DomainService -------\ql10wntt ((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 ))))))))))))))))))))))))))))))) . 2008-02-21 14:29 . 2008-02-21 14:29 49 --a------ C:\WINDOWS\winzipsp.ini 2008-02-21 14:21 . 2008-02-21 14:39 d-------- C:\Program Files\Anti-Virus&Spyware 2008-02-21 14:06 . 2008-02-21 14:06 d-------- C:\Program Files\Spyware Vaccine 2008-02-19 01:36 . 2008-02-19 01:37 d-------- C:\Program Files\PowerMenu 2008-02-18 03:34 . 2008-02-18 04:09 d-------- C:\VundoFix Backups 2008-02-17 16:49 . 2008-02-17 16:49 d-------- C:\Program Files\Lavasoft 2008-02-17 16:49 . 2008-02-17 16:50 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-02-08 18:15 . 2007-01-03 19:48 450,560 -ra------ C:\WINDOWS\system32\mcs_cor1.dll 2008-02-08 18:15 . 2007-01-03 19:48 245,760 -ra------ C:\WINDOWS\system32\mcs_dec2.ax 2008-02-08 18:15 . 2007-01-03 19:48 172,032 -ra------ C:\WINDOWS\system32\mcs_cor2.dll 2008-02-08 18:15 . 2007-01-03 19:48 114,688 -ra------ C:\WINDOWS\system32\mcs_enc.ax 2008-02-08 18:15 . 2007-01-03 19:48 4,111 -ra------ C:\WINDOWS\system32\install.inf 2008-02-05 11:48 . 2008-02-05 11:48 8,191 --a------ C:\WINDOWS\17PHolmes572.exe 2008-01-30 23:51 . 2008-01-30 23:52 d-------- C:\Documents and Settings\Suraj\Application Data\dvdcss 2008-01-28 14:13 . 2008-01-28 14:13 2,568 --a------ C:\WINDOWS\system32\PerfStringBackup.TMP 2008-01-28 13:54 . 2004-09-29 13:36 15,360 -rah----- C:\WINDOWS\system32\drivers\NetMotCM.sys 2008-01-27 14:31 . 2008-02-13 01:54 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-22 02:32 --------- d-----w C:\Documents and Settings\Suraj\Application Data\Launchy 2008-02-22 02:29 --------- d-----w C:\Program Files\Mozilla Thunderbird 2008-02-21 22:41 --------- d-----w C:\Program Files\Trend Micro 2008-02-17 23:48 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-02-05 08:58 --------- d-----w C:\Program Files\Google 2008-02-02 00:23 --------- d-----w C:\Program Files\Yahoo! 2008-01-24 19:47 --------- d-----w C:\Documents and Settings\Suraj\Application Data\U3 2008-01-22 10:42 --------- d-----w C:\Program Files\Winamp 2008-01-22 10:25 --------- d-----w C:\Program Files\Media Tagger 2008-01-20 09:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft 2008-01-19 22:29 --------- d-----w C:\Program Files\iTunes 2008-01-15 07:02 --------- d-----w C:\Program Files\Microsoft ActiveSync 2008-01-13 17:26 --------- d-----w C:\Program Files\Dell 2008-01-13 17:24 --------- d-----w C:\Program Files\Apoint 2008-01-13 16:40 --------- d-----w C:\Program Files\I8kfanGUI 2008-01-11 02:24 --------- d-----w C:\Program Files\Dell Support 2008-01-10 07:15 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-01-10 01:58 --------- d-----w C:\Program Files\QuickTime 2008-01-10 00:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\SecTaskMan 2008-01-09 23:38 --------- d-----w C:\Program Files\Windows Plus 2008-01-09 21:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee 2008-01-09 21:46 --------- d-----w C:\Program Files\McAfee 2008-01-09 21:39 --------- d-----w C:\Program Files\Common Files\McAfee 2008-01-09 21:14 --------- d-----w C:\Program Files\Common Files\Cisco Systems 2008-01-09 19:31 5,828 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2008-01-09 19:31 354,848 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat 2008-01-09 19:31 2,636 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx 2008-01-09 19:31 17,184 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat 2008-01-09 19:30 --------- d-----w C:\Program Files\Security Task Manager 2008-01-09 19:23 --------- d-----w C:\Program Files\Launchy 2008-01-09 19:21 --------- d-----w C:\Program Files\Windows Defender 2008-01-09 19:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2008-01-09 09:18 --------- d-----w C:\Program Files\Kaspersky Lab 2008-01-05 19:16 --------- d-----w C:\Documents and Settings\Suraj\Application Data\Ruckus Network 2007-10-24 03:21 52,776 ----a-w C:\Documents and Settings\Suraj\Application Data\GDIPFONTCACHEV1.DAT 2006-10-05 00:26 380,928 ----a-w C:\Program Files\npCortona.dll 2006-04-21 21:43 2,895,168 ----a-w C:\Program Files\FoxitReader.exe 2006-03-28 00:38 104 --sh--r C:\WINDOWS\system32\[u]0[/u]BBBE2E644.sys . [code]
----a-w           307,200 2008-01-09 20:06:18  C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
----a-w           102,400 2008-01-09 20:06:06  C:\Program Files\Creative\MediaSource\Detector\CTDetect .exe
----a-w           856,064 2008-01-13 16:40:21  C:\Program Files\I8kfanGUI\I8kfanGUI .exe
----a-w           267,064 2008-01-19 22:34:15  C:\Program Files\iTunes\iTunesHelper .exe
----a-w           136,768 2008-01-17 07:13:06  C:\Program Files\McAfee\Common Framework\UdaterUI .exe
----a-w           112,216 2008-01-19 22:34:14  C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT .EXE
----a-w           405,584 2008-01-24 09:24:47  C:\Program Files\Microsoft ActiveSync\WCESCOMM    .EXE
----a-w           405,584 2008-01-24 09:24:49  C:\Program Files\Microsoft ActiveSync\WCESCOMM   .EXE
----a-w           405,584 2008-01-24 09:24:50  C:\Program Files\Microsoft ActiveSync\WCESCOMM  .EXE
----a-w           405,584 2008-01-13 16:40:21  C:\Program Files\Microsoft ActiveSync\WCESCOMM .EXE
----a-w           176,201 2008-01-09 20:05:57  C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon .exe
----a-w           158,208 2008-01-13 23:48:31  C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
----a-w            15,360 2008-02-13 08:54:31  C:\WINDOWS\system32\ctfmon .exe
[/code] ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 04:00 15360] "Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [ ] "AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" [ ] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"="c:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" [ ] "Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [ ] "ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [ ] "McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [ ] "googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 14:22 3739648] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 18:17 443968] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RunNarrator"="Narrator.exe" [2004-08-10 04:00 53760 C:\WINDOWS\system32\narrator.exe] C:\Documents and Settings\Suraj\Start Menu\Programs\Startup\ Spyware Vaccine.lnk - C:\Program Files\Spyware Vaccine\Spyware Vaccine\spv.exe [2008-02-01 15:40:50 1265664] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Launchy.lnk - C:\Program Files\Launchy\Launchy.exe [2007-01-24 13:23:19 552960] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless] C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 15:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk backup=C:\WINDOWS\pss\Bluetooth Manager.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Suraj^Start Menu^Programs^Startup^Metacafe Downloader.lnk] path=C:\Documents and Settings\Suraj\Start Menu\Programs\Startup\Metacafe Downloader.lnk backup=C:\WINDOWS\pss\Metacafe Downloader.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet] --a------ 2005-05-06 17:47 2224128 C:\Program Files\BitLord\BitLord.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BSplayer_WhenUSave_Installer] C:\Program Files\BSplayer_WhenUSave_Installer\BSplayer_WhenUSave_Installer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c866d692] C:\WINDOWS\system32\gunhkydf.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\comup] C:\WINDOWS\system32\mobjchku.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Crammer] C:\Program Files\crammer\crammer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher] --------- 2005-02-23 15:19 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk] --a------ 2007-01-01 14:22 3739648 C:\Program Files\Google\Google Talk\googletalk.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent] --a------ 2008-01-13 09:40 405584 C:\Program Files\Microsoft ActiveSync\WCESCOMM .EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\i8kfangui] --a------ 2008-01-13 09:40 856064 C:\Program Files\I8kfanGUI\I8kfanGUI .exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2008-01-19 15:29 700928 C:\Program Files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kernel] C:\Program Files\kernel\kernel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXSUPMON] C:\WINDOWS\system32\LXSUPMON.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-01-09 19:38 286720 C:\Program Files\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2003-11-19 16:48 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "UPS"=3 (0x3) "SPTISRV"=3 (0x3) "iPodService"=3 (0x3) "CCALib8"=2 (0x2) "TapiSrv"=3 (0x3) "iPod Service"=3 (0x3) "gusvc"=3 (0x3) "gupdate"=2 (0x2) "Fax"=2 (0x2) "Bonjour Service"=2 (0x2) "Apple Mobile Device"=2 (0x2) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{30e2d81f-0e3b-11db-922c-001422e0ebc8}] \Shell\AutoRun\command - F:\LaunchU3.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}] \Shell\AutoRun\command - E:\setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd46c7a2-7f34-11da-90fd-00038a000015}] \Shell\AutoRun\command - F:\wd_windows_tools\setup.exe . Contents of the 'Scheduled Tasks' folder "2007-09-13 22:48:28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-02-22 02:47:32 C:\WINDOWS\Tasks\GoogleUpdateTask.job" - C:\Program Files\Google\Update\1.0.103.3\GoogleUpdate.exe "2008-02-20 08:41:00 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-21 19:47:57 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... ? [3484] scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\Common Framework\naPrdMgr.exe C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\UPHClean\uphclean.exe C:\WINDOWS\ehome\mcrdsvc.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\cscript.exe . ************************************************************************** . Completion time: 2008-02-21 19:52:55 - machine was rebooted ComboFix-quarantined-files.txt 2008-02-22 02:52:51 . 2008-02-21 23:55:47 --- E O F ---