ComboFix 08-05-08.1 - Shane 2008-05-10 10:23:26.1 - NTFSx86
Running from: E:\Documents and Settings\Shane\Desktop\ComboFix.exe
Command switches used :: E:\Documents and Settings\Shane\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\WINDOWS\system32\hpmbuseg.ini
E:\WINDOWS\system32\modvtmhm.ini
E:\WINDOWS\system32\wjffyovc.ini
E:\WINDOWS\system32\ymxbeakb.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-10 to 2008-05-10 )))))))))))))))))))))))))))))))
.
2008-05-09 08:04 . 2008-05-09 08:04 <DIR> d-------- E:\Program Files\Trend Micro
2008-05-08 22:47 . 2008-04-14 14:00 2,178,131 --a--c--- E:\WINDOWS\system32\dllcache\shvlres.dll
2008-05-08 22:23 . 2008-05-08 22:30 <DIR> d-------- E:\Program Files\nLite
2008-05-08 17:08 . 2008-05-08 17:08 <DIR> d-------- E:\Deckard
2008-05-07 21:12 . 2008-05-07 21:24 <DIR> d-------- E:\Program Files\Free Download Manager
2008-05-07 18:56 . 2008-05-07 18:56 <DIR> d-------- E:\Program Files\Common Files\Adobe AIR
2008-05-07 18:56 . 2008-05-07 18:56 <DIR> d-------- E:\Program Files\Adobe Media Player
2008-05-07 16:13 . 2008-05-07 16:13 54,156 --ah----- E:\WINDOWS\QTFont.qfn
2008-05-07 16:13 . 2008-05-07 16:13 1,409 --a------ E:\WINDOWS\QTFont.for
2008-05-03 12:32 . 2008-05-03 12:32 354,560 --a------ E:\WINDOWS\system32\TuneUpDefragService.exe
2008-05-03 12:32 . 2008-04-04 14:51 28,416 --a------ E:\WINDOWS\system32\uxtuneup.dll
2008-05-02 19:03 . 2008-05-08 17:45 <DIR> d-------- E:\WINDOWS\system32\Kaspersky Lab
2008-05-02 18:42 . 2008-05-02 18:42 0 --ah----- E:\Documents and Settings\Shane\NTUSER.DAT_TU_95276.LOG
2008-05-02 18:42 . 2008-05-02 18:42 0 --ah----- E:\Documents and Settings\NetworkService\NTUSER.DAT_TU_28899.LOG
2008-05-02 18:42 . 2008-05-02 18:42 0 --ah----- E:\Documents and Settings\LocalService\NTUSER.DAT_TU_96838.LOG
2008-05-01 19:02 . 2008-05-02 17:48 <DIR> d-------- E:\Program Files\Microsoft Bootvis
2008-04-27 12:16 . 2008-04-27 12:16 <DIR> d-------- E:\Documents and Settings\Shane\dwhelper
2008-04-26 22:24 . 2008-04-26 22:24 85,520 --a------ E:\WINDOWS\system32\drivers\bdfndisf.sys
2008-04-26 22:00 . 2008-04-26 22:26 81,984 --a------ E:\WINDOWS\system32\bdod.bin
2008-04-26 21:58 . 2008-04-26 21:59 <DIR> d-------- E:\Program Files\Common Files\BitDefender
2008-04-23 16:37 . 2008-04-23 16:37 <DIR> d-------- E:\Documents and Settings\Shane\Application Data\AdobeUM
2008-04-23 08:29 . 2008-04-23 08:29 41,296 --a------ E:\WINDOWS\system32\xfcodec.dll
2008-04-22 23:02 . 2008-04-22 23:02 <DIR> d-------- E:\Documents and Settings\Shane\Application Data\vlc
2008-04-22 22:56 . 2008-05-07 22:43 <DIR> d---s---- E:\WINDOWS\Downloaded Program Files
2008-04-19 20:48 . 2008-04-19 20:49 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\WinZip
2008-04-18 10:33 . 2008-04-18 10:33 <DIR> d-------- E:\Program Files\Black Isle
2008-04-17 11:39 . 2008-04-17 11:39 260 --a------ E:\WINDOWS\_delis32.ini
2008-04-16 08:27 . 2008-05-01 00:06 <DIR> d-------- E:\Documents and Settings\Shane\Application Data\Xfire
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-10 00:22 --------- d-----w E:\Documents and Settings\Shane\Application Data\mIRC
2008-05-09 23:50 --------- d-----w E:\Program Files\mIRC
2008-05-08 09:22 --------- d-----w E:\Program Files\Common Files\Wise Installation Wizard
2008-05-08 07:41 --------- d---a-w E:\Documents and Settings\All Users\Application Data\TEMP
2008-05-06 11:29 --------- d-----w E:\Program Files\LimeWire
2008-05-06 06:37 --------- d-----w E:\Documents and Settings\Shane\Application Data\uTorrent
2008-05-04 11:25 --------- d-----w E:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-30 12:00 --------- d-----w E:\Program Files\Microsoft Works
2008-04-26 12:39 --------- d-----w E:\Program Files\ESET
2008-04-23 05:27 --------- d-----w E:\Documents and Settings\Shane\Application Data\Orbit
2008-04-18 00:47 --------- d--h--w E:\Program Files\InstallShield Installation Information
2008-04-17 14:51 --------- d-----w E:\Program Files\Common Files\Logitech
2008-04-17 01:24 717,296 ----a-w E:\WINDOWS\system32\drivers\sptd.sys
2008-04-09 01:26 --------- d-----w E:\Program Files\iPod
2008-04-09 01:24 --------- d-----w E:\Program Files\QuickTime
2008-04-09 01:22 --------- d-----w E:\Program Files\Apple Software Update
2008-04-09 01:21 --------- d-----w E:\Program Files\Common Files\Apple
2008-04-06 03:50 --------- d-----w E:\Program Files\ACW
2008-04-06 03:12 --------- d-----w E:\Documents and Settings\Shane\Application Data\BitTorrent
2008-03-27 08:18 --------- d-----w E:\Program Files\Messenger Plus! Live
2008-03-27 08:18 --------- d-----w E:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-03-27 08:16 --------- d-----w E:\Program Files\Windows Live
2008-03-27 08:03 --------- d-----w E:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-26 13:55 --------- d-----w E:\Documents and Settings\Shane\Application Data\DivX
2008-03-25 05:14 --------- d-----w E:\Program Files\Unlocker
2008-03-21 06:16 278,984 ----a-w E:\WINDOWS\system32\drivers\atksgt.sys
2008-03-21 06:16 25,416 ----a-w E:\WINDOWS\system32\drivers\lirsgt.sys
2008-03-21 06:00 --------- d-----w E:\Documents and Settings\Shane\Application Data\DAEMON Tools Pro
2008-03-20 21:32 --------- d-----w E:\Documents and Settings\Shane\Application Data\OLYMPUS
2008-03-19 12:20 --------- d-----w E:\Documents and Settings\Shane\Application Data\Nexon
2008-03-11 11:48 --------- d-----w E:\Program Files\Lavasoft
2008-03-07 04:45 2,560 ----a-w E:\WINDOWS\_MSRSTRT.EXE
2004-03-11 03:27 40,960 ----a-w E:\Program Files\Uninstall_CDS.exe
2007-08-28 08:33 23 --sha-w E:\WINDOWS\system32\efdedff_d.dll
2005-09-24 11:06 7,537 -csha-w E:\WINDOWS\system32\rerolpxei.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="E:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 10:34 5724184]
"ctfmon.exe"="E:\WINDOWS\system32\ctfmon.exe" [2004-08-08 15:00 15360]
"Rainlendar2"="E:\Program Files\Rainlendar2\Rainlendar2.exe" [2007-07-24 17:12 1298432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MULTIMEDIA KEYBOARD"="E:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2001-10-18 16:54 163840]
"NvCplDaemon"="E:\WINDOWS\system32\NvCpl.dll" [2007-12-05 00:41 8523776]
"egui"="E:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-03-01 04:54 1443072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="E:\WINDOWS\system32\CTFMON.EXE" [2004-08-08 15:00 15360]
"DWQueuedReporting"="E:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 18:29 39264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisallowCpl"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="E:\\WINDOWS\\system32\\logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
iexplorer.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
"VIDC.XFR1"= xfcodec.dll
"vidc.ffds"= F:\Program Files\Codecs\ffdshow\ffdshow.ax
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"UxTuneUp"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)
"CiSvc"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"WLSetupSvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=E:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"FirefoxUltimateOptimizer"="F:\My Documents\Game Stuff\firefox-ultimate-optimizer-11\Firefox Ultimate Optimizer.exe"
"MSConfig"=E:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe /auto
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"E:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"E:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"E:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"F:\\Program Files\\Xfire\\xfire.exe"=
"E:\\Program Files\\mIRC\\mirc.exe"=
"F:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:warcraft 3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\AutorunsDisabled\{21DB17A7-9EB9-0768-D9C5-22A71AD280F1}]
E:\WINDOWS\system32:svchost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{21DB17A7-9EB9-0768-D9C5-22A71AD280F1}]
Disabeld
.
Contents of the 'Scheduled Tasks' folder
"2008-05-10 00:30:05 E:\WINDOWS\Tasks\MP Scheduled Scan.job"
- E:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-10 10:27:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
E:\Program Files\Windows Defender\MsMpEng.exe
E:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
E:\Program Files\ESET\ESET Smart Security\ekrn.exe
E:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
E:\WINDOWS\system32\nvsvc32.exe
E:\Program Files\Netropa\Multimedia Keyboard\Traymon.exe
E:\Program Files\Netropa\Onscreen Display\osd.exe
E:\Program Files\Windows Live\Messenger\usnsvc.exe
.
**************************************************************************
.
Completion time: 2008-05-10 10:32:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-10 00:32:01
Pre-Run: 25,980,502,016 bytes free
Post-Run: 25,865,031,680 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /TUTag=OCM2S2
E:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
178 --- E O F --- 2008-05-09 02:50:09