ComboFix 08-03-10.1 - Phil 2008-03-10 19:17:10.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.399 [GMT 0:00] Running from: F:\ComboFix.exe [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\ljjhheb.dll C:\WINDOWS\system32\sttss.ini C:\WINDOWS\system32\sttss.ini2 . ((((((((((((((((((((((((( Files Created from 2008-02-10 to 2008-03-10 ))))))))))))))))))))))))))))))) . 2008-03-10 18:54 . 2008-03-10 18:54 d-------- C:\WINDOWS\LastGood.Tmp 2008-03-10 18:41 . 2008-03-10 18:41 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe 2008-03-10 18:21 . 2008-03-10 18:41 d-------- C:\VundoFix Backups 2008-03-10 14:50 . 2008-03-10 18:38 d-------- C:\Program Files\Spyware Doctor 2008-03-10 14:50 . 2008-03-10 14:50 d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools 2008-03-10 14:50 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys 2008-03-10 14:50 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys 2008-03-10 14:50 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys 2008-03-10 14:50 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys 2008-03-10 14:10 . 2008-03-10 14:10 d-------- C:\Program Files\Trend Micro 2008-03-10 14:09 . 2008-03-10 14:09 d-------- C:\Program Files\Spybot - Search & Destroy 2008-03-10 14:09 . 2008-03-10 14:09 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-03-10 13:44 . 2008-03-10 13:44 58,368 --a------ C:\mhyvfa.exe 2008-03-10 13:44 . 2008-03-10 13:44 35,840 --a------ C:\WINDOWS\system32\bnsock.dll 2008-03-03 10:27 . 2008-03-03 10:34 d-------- C:\Documents and Settings\Phil\Application Data\gtk-2.0 2008-03-03 10:26 . 2008-03-03 10:32 d-------- C:\Documents and Settings\Phil\.thumbnails 2008-03-03 10:24 . 2008-03-03 10:24 d-------- C:\Program Files\GIMP-2.0 2008-03-03 10:24 . 2008-03-03 10:34 d-------- C:\Documents and Settings\Phil\.gimp-2.4 2008-02-27 22:52 . 2008-02-27 22:52 d-a------ C:\BridgeData Backup 27Feb08 2008-02-27 08:42 . 2008-02-27 08:42 d-------- C:\Documents and Settings\Phil\Application Data\Nokia Multimedia Player 2008-02-24 20:10 . 2008-02-24 20:10 d-------- C:\Program Files\FileZilla FTP Client 2008-02-24 20:10 . 2008-02-24 21:03 d-------- C:\Documents and Settings\Phil\Application Data\FileZilla 2008-02-19 10:43 . 2008-02-19 10:43 d-------- C:\Program Files\Apple Software Update 2008-02-19 10:43 . 2008-02-19 10:43 d-------- C:\Documents and Settings\All Users\Application Data\Apple 2008-02-18 16:04 . 2008-02-18 16:04 d-------- C:\Documents and Settings\Phil\Application Data\Stellarium 2008-02-18 16:03 . 2008-02-18 16:03 d-------- C:\Program Files\Stellarium 2008-02-15 10:27 . 2008-03-10 09:25 d-------- C:\Program Files\Mozilla Firefox 3 Beta 3 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-03-10 19:28 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-03-10 18:38 --------- d-----w C:\Program Files\PowerISO 2008-03-10 16:15 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-03-09 18:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec 2008-02-21 23:08 --------- d-----w C:\Documents and Settings\Phil\Application Data\uTorrent 2008-02-20 20:44 --------- d-----w C:\Program Files\Common Files\Adobe 2008-02-19 10:45 --------- d-----w C:\Program Files\QuickTime 2008-02-19 10:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer 2008-02-17 20:11 --------- d-----w C:\Program Files\PokerStars.NET 2008-02-01 22:20 --------- d-----w C:\Program Files\MSECACHE 2008-01-15 09:54 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat 2008-01-15 05:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf 2008-01-12 18:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0CA10898-7F98-4709-A479-B8134AB3D9F3}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCFBAEED-9653-4005-A5BC-7CC9BD78EBA3}] C:\WINDOWS\system32\sstts.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 17:12 131072] "CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 17:30 45632] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648] "MaxtorOneTouch"="C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe" [2006-03-01 10:58 712704] "mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2005-10-17 15:24 81920] "PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 14:10 271360] "RegistryMechanic"="" [] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59 115816] "Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 15:40 1884160] "IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 14:52 849280] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 23:13 385024] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048] "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:56 15360] "Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 09:17 1241088] "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 21:18 443968] C:\Documents and Settings\Phil\Start Menu\Programs\Startup\ Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2007-09-17 14:58:46 3450608] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ GammaTray.lnk - C:\Program Files\MagicTune Premium\GammaTray.exe [2007-08-01 19:13:53 36864] hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 00:17:18 147456] hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 00:06:58 28672] NCProTray.lnk - C:\Program Files\SEC\Natural Color Pro\NCProTray.exe [2007-07-30 19:53:39 49220] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoUserNameInStartMenu"= 01000000 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk] backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core] --a------ 2007-02-19 12:39 2875392 C:\Program Files\Electronic Arts\EA Link\Core.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "S:\\My Documents\\Downloads\\Torrents\\utorrent.exe"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\livecall.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\Program Files\\Adobe\\Adobe Dreamweaver CS3\\Dreamweaver.exe"= "C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server "3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server "50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server "50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server R0 hotcore2;hotcore2;C:\WINDOWS\system32\drivers\hotcore2.sys [2006-10-02 10:39] R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\drivers\si3112r.sys [2007-08-29 02:04] R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 04:29] S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 [] *Newly Created Service* - COMHOST . Contents of the 'Scheduled Tasks' folder "2008-02-27 10:08:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2007-10-31 09:45:53 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1188331334.job" - C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I "2007-08-27 22:26:54 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job" - c:\Program Files\Microsoft IntelliPoint\ipoint.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-03-10 19:26:33 Windows 5.1.2600 Service Pack 2 NTFS detected NTDLL code modification: ZwClose scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet002\Services\rqksgpu] "ImagePath"="\??\C:\WINDOWS\Cursors\rqksgpu.cur" . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156] -> C:\Program Files\Stardock\ObjectDock\DockShellHook.dll . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\MagicTune Premium\MagicTuneEngine.exe C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\MagicTune Premium\MagicTune.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe . ************************************************************************** . Completion time: 2008-03-10 19:32:16 - machine was rebooted ComboFix-quarantined-files.txt 2008-03-10 19:32:09 . 2008-02-14 00:07:37 --- E O F ---