ComboFix 08-03-10.1 - Phil 2008-03-10 19:17:10.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.399 [GMT 0:00]
Running from: F:\ComboFix.exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\ljjhheb.dll
C:\WINDOWS\system32\sttss.ini
C:\WINDOWS\system32\sttss.ini2
.
((((((((((((((((((((((((( Files Created from 2008-02-10 to 2008-03-10 )))))))))))))))))))))))))))))))
.
2008-03-10 18:54 . 2008-03-10 18:54
d-------- C:\WINDOWS\LastGood.Tmp
2008-03-10 18:41 . 2008-03-10 18:41 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-03-10 18:21 . 2008-03-10 18:41 d-------- C:\VundoFix Backups
2008-03-10 14:50 . 2008-03-10 18:38 d-------- C:\Program Files\Spyware Doctor
2008-03-10 14:50 . 2008-03-10 14:50 d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-03-10 14:50 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-10 14:50 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-10 14:50 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-10 14:50 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-03-10 14:10 . 2008-03-10 14:10 d-------- C:\Program Files\Trend Micro
2008-03-10 14:09 . 2008-03-10 14:09 d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-10 14:09 . 2008-03-10 14:09 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-10 13:44 . 2008-03-10 13:44 58,368 --a------ C:\mhyvfa.exe
2008-03-10 13:44 . 2008-03-10 13:44 35,840 --a------ C:\WINDOWS\system32\bnsock.dll
2008-03-03 10:27 . 2008-03-03 10:34 d-------- C:\Documents and Settings\Phil\Application Data\gtk-2.0
2008-03-03 10:26 . 2008-03-03 10:32 d-------- C:\Documents and Settings\Phil\.thumbnails
2008-03-03 10:24 . 2008-03-03 10:24 d-------- C:\Program Files\GIMP-2.0
2008-03-03 10:24 . 2008-03-03 10:34 d-------- C:\Documents and Settings\Phil\.gimp-2.4
2008-02-27 22:52 . 2008-02-27 22:52 d-a------ C:\BridgeData Backup 27Feb08
2008-02-27 08:42 . 2008-02-27 08:42 d-------- C:\Documents and Settings\Phil\Application Data\Nokia Multimedia Player
2008-02-24 20:10 . 2008-02-24 20:10 d-------- C:\Program Files\FileZilla FTP Client
2008-02-24 20:10 . 2008-02-24 21:03 d-------- C:\Documents and Settings\Phil\Application Data\FileZilla
2008-02-19 10:43 . 2008-02-19 10:43 d-------- C:\Program Files\Apple Software Update
2008-02-19 10:43 . 2008-02-19 10:43 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-02-18 16:04 . 2008-02-18 16:04 d-------- C:\Documents and Settings\Phil\Application Data\Stellarium
2008-02-18 16:03 . 2008-02-18 16:03 d-------- C:\Program Files\Stellarium
2008-02-15 10:27 . 2008-03-10 09:25 d-------- C:\Program Files\Mozilla Firefox 3 Beta 3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-10 19:28 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-10 18:38 --------- d-----w C:\Program Files\PowerISO
2008-03-10 16:15 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-09 18:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-21 23:08 --------- d-----w C:\Documents and Settings\Phil\Application Data\uTorrent
2008-02-20 20:44 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-19 10:45 --------- d-----w C:\Program Files\QuickTime
2008-02-19 10:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-17 20:11 --------- d-----w C:\Program Files\PokerStars.NET
2008-02-01 22:20 --------- d-----w C:\Program Files\MSECACHE
2008-01-15 09:54 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-15 05:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-12 18:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0CA10898-7F98-4709-A479-B8134AB3D9F3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCFBAEED-9653-4005-A5BC-7CC9BD78EBA3}]
C:\WINDOWS\system32\sstts.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 17:12 131072]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 17:30 45632]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"MaxtorOneTouch"="C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe" [2006-03-01 10:58 712704]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2005-10-17 15:24 81920]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 14:10 271360]
"RegistryMechanic"="" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59 115816]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 15:40 1884160]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 14:52 849280]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 23:13 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:56 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 09:17 1241088]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 21:18 443968]
C:\Documents and Settings\Phil\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2007-09-17 14:58:46 3450608]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
GammaTray.lnk - C:\Program Files\MagicTune Premium\GammaTray.exe [2007-08-01 19:13:53 36864]
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 00:17:18 147456]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 00:06:58 28672]
NCProTray.lnk - C:\Program Files\SEC\Natural Color Pro\NCProTray.exe [2007-07-30 19:53:39 49220]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 01000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
--a------ 2007-02-19 12:39 2875392 C:\Program Files\Electronic Arts\EA Link\Core.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"S:\\My Documents\\Downloads\\Torrents\\utorrent.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Adobe\\Adobe Dreamweaver CS3\\Dreamweaver.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R0 hotcore2;hotcore2;C:\WINDOWS\system32\drivers\hotcore2.sys [2006-10-02 10:39]
R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\drivers\si3112r.sys [2007-08-29 02:04]
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 04:29]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 []
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-27 10:08:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-31 09:45:53 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1188331334.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
"2007-08-27 22:26:54 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job"
- c:\Program Files\Microsoft IntelliPoint\ipoint.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-10 19:26:33
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\rqksgpu]
"ImagePath"="\??\C:\WINDOWS\Cursors\rqksgpu.cur"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\Stardock\ObjectDock\DockShellHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\MagicTune Premium\MagicTune.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
.
**************************************************************************
.
Completion time: 2008-03-10 19:32:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-10 19:32:09
.
2008-02-14 00:07:37 --- E O F ---