ComboFix 09-03-19.02 - Administrator 2009-03-20 21:34:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1251.1.1033.18.1015.358 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-02-20 to 2009-03-20 )))))))))))))))))))))))))))))))
.
2009-03-20 21:26 . 2009-03-20 21:31 <DIR> d--h----- c:\windows\$hf_mig$
2009-03-20 21:20 . 2009-03-20 21:26 <DIR> d-------- c:\windows\LastGood
2009-03-20 21:13 . 2009-03-20 21:13 <DIR> d-------- c:\program files\Trend Micro
2009-03-19 17:46 . 2009-03-19 17:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-03-19 17:22 . 2009-03-19 17:22 <DIR> d-------- c:\program files\Messenger Plus! Live
2009-03-19 02:23 . 2009-03-19 02:23 <DIR> d-------- c:\program files\K-Lite Codec Pack
2009-03-19 00:58 . 2009-03-19 00:58 0 --a------ c:\windows\vpc32.INI
2009-03-19 00:51 . 2009-03-20 21:33 <DIR> d-------- c:\program files\Symantec AntiVirus
2009-03-19 00:51 . 2009-03-19 00:51 <DIR> d-------- c:\program files\Symantec
2009-03-19 00:51 . 2009-03-19 00:57 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2009-03-19 00:51 . 2009-03-19 00:51 <DIR> d-------- c:\documents and settings\All Users\Application Data\Symantec
2009-03-19 00:51 . 2005-04-01 20:36 123,200 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
2009-03-19 00:51 . 2005-04-01 20:36 91,856 --a------ c:\windows\system32\S32EVNT1.DLL
2009-03-18 22:54 . 2009-03-18 22:54 <DIR> d-------- c:\program files\TeamViewer
2009-03-18 22:54 . 2009-03-18 22:54 <DIR> d-------- c:\documents and settings\Administrator\temp
2009-03-18 22:54 . 2009-03-18 22:54 <DIR> d-------- c:\documents and settings\Administrator\Application Data\TeamViewer
2009-03-18 21:28 . 2009-03-18 21:28 56 --ah----- c:\windows\system32\ezsidmv.dat
2009-03-18 21:27 . 2009-03-20 00:09 <DIR> d-------- c:\documents and settings\Administrator\Application Data\skypePM
2009-03-18 21:02 . 2009-03-19 02:37 69 --a------ c:\windows\NeroDigital.ini
2009-03-18 19:31 . 2009-03-19 09:09 <DIR> d-------- c:\program files\XoftSpySE
2009-03-18 18:15 . 2009-03-18 18:15 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-18 18:15 . 2009-03-18 18:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-18 18:15 . 2009-03-18 18:15 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-03-18 18:15 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-18 18:15 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-18 17:15 . 2009-03-18 17:15 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-18 16:24 . 2009-03-20 21:35 <DIR> dr------- C:\CS27
2009-03-18 15:52 . 2009-03-18 15:52 <DIR> d-------- c:\program files\Sun
2009-03-18 15:51 . 2009-03-18 17:15 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-18 15:50 . 2009-03-18 17:15 <DIR> d-------- c:\program files\Java
2009-03-18 15:50 . 2009-03-18 15:50 <DIR> d-------- c:\program files\Common Files\Java
2009-03-18 15:37 . 2009-03-18 15:37 <DIR> d-------- c:\program files\Webteh
2009-03-18 15:37 . 2009-03-18 19:44 <DIR> d-------- c:\documents and settings\Administrator\Application Data\BSplayer PRO
2009-03-18 15:34 . 2009-03-18 15:35 <DIR> d-------- c:\program files\Winamp
2009-03-18 15:34 . 2009-03-18 15:35 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Winamp
2009-03-18 15:33 . 2009-03-20 21:10 <DIR> d-------- c:\program files\DNA
2009-03-18 15:33 . 2009-03-18 15:33 <DIR> d-------- c:\program files\BitTorrent
2009-03-18 15:33 . 2009-03-18 15:33 <DIR> d-------- c:\program files\AskSearch
2009-03-18 15:33 . 2009-03-18 15:33 <DIR> d-------- c:\program files\AskBarDis
2009-03-18 15:33 . 2009-03-20 21:30 <DIR> d-------- c:\documents and settings\Administrator\Application Data\DNA
2009-03-18 15:33 . 2009-03-20 20:45 <DIR> d-------- c:\documents and settings\Administrator\Application Data\BitTorrent
2009-03-18 15:13 . 2009-03-18 15:13 <DIR> d-------- c:\documents and settings\Administrator\Contacts
2009-03-18 15:11 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2009-03-18 15:11 . 2001-08-17 13:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2009-03-18 15:10 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2009-03-18 15:10 . 2001-08-17 14:02 9,600 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2009-03-17 16:33 . 2009-03-17 16:33 0 --a------ c:\windows\nsreg.dat
2009-03-17 14:37 . 2009-03-17 14:37 940,794 --a------ c:\windows\system32\LoopyMusic.wav
2009-03-17 14:37 . 2007-01-13 02:45 172,032 -ra------ c:\windows\system32\igfxres.dll
2009-03-17 14:37 . 2009-03-17 14:37 146,650 --a------ c:\windows\system32\BuzzingBee.wav
2009-03-17 14:35 . 2009-03-17 14:35 <DIR> d-------- c:\windows\OPTIONS
2009-03-17 14:35 . 2009-03-17 14:35 <DIR> d-------- c:\documents and settings\Administrator\Application Data\InstallShield
2009-03-17 14:35 . 2008-07-01 04:27 108,800 -ra------ c:\windows\system32\drivers\Rtenicxp.sys
2009-03-17 14:35 . 2008-07-21 17:14 9,728 -ra------ c:\windows\system32\RtNicProp32.dll
2009-03-17 14:33 . 2007-11-22 09:40 16,858,112 -r------- c:\windows\RTHDCPL.exe
2009-03-17 14:33 . 2007-03-23 12:19 9,715,200 -r------- c:\windows\RTLCPL.exe
2009-03-17 14:33 . 2007-11-27 13:06 4,630,016 -r------- c:\windows\system32\drivers\RtkHDAud.sys
2009-03-17 14:33 . 2006-05-04 09:26 2,808,832 -r------- c:\windows\alcwzrd.exe
2009-03-17 14:33 . 2007-06-28 09:44 2,165,760 -r------- c:\windows\MicCal.exe
2009-03-17 14:33 . 2007-11-20 11:15 1,826,816 -r------- c:\windows\SkyTel.exe
2009-03-17 14:33 . 2007-11-07 10:31 1,191,936 -r------- c:\windows\RtlUpd.exe
2009-03-17 14:33 . 2006-08-17 23:58 282,624 -ra------ c:\windows\system32\RTSndMgr.cpl
2009-03-17 14:33 . 2006-07-21 09:14 86,016 -r------- c:\windows\SoundMan.exe
2009-03-17 14:33 . 2005-05-03 11:43 69,632 -r------- c:\windows\Alcmtr.exe
2009-03-17 14:33 . 2005-02-25 04:35 22,752 --a------ c:\windows\system32\spupdsvc.exe
2009-03-17 14:32 . 2009-03-17 14:32 <DIR> d-------- c:\program files\Realtek
2009-03-17 14:31 . 2009-03-17 14:31 <DIR> d-------- c:\windows\system32\Lang
2009-03-17 14:31 . 2007-01-18 04:22 389,120 -ra------ c:\windows\system32\igxpun.exe
2009-03-17 14:31 . 2006-11-10 01:25 319,456 -ra------ c:\windows\system32\difxapi.dll
2009-03-17 14:31 . 2006-01-23 03:29 121,232 -ra------ c:\windows\system32\IScrNBR.bmp
2009-03-17 14:31 . 2006-01-23 03:29 121,232 -ra------ c:\windows\system32\IScrNB.bmp
2009-03-17 14:30 . 2009-03-17 14:30 <DIR> d-------- c:\program files\Intel
2009-03-17 14:30 . 2008-07-16 09:05 53,248 -ra------ c:\windows\system32\CSVer.dll
2009-03-17 14:29 . 2009-03-17 14:29 <DIR> d-------- C:\Intel
2009-03-17 14:29 . 2006-10-11 04:33 10,288 --a------ c:\windows\system32\drivers\ASUSHWIO.SYS
2009-03-17 14:29 . 2009-03-17 14:29 5,537 --a------ c:\windows\Ascd_tmp.ini
2009-03-17 14:06 . 2009-03-17 14:06 268 --ah----- C:\sqmdata00.sqm
2009-03-17 14:06 . 2009-03-17 14:06 244 --ah----- C:\sqmnoopt00.sqm
2009-03-17 14:06 . 2009-03-17 14:06 172 --ah----- C:\sqmnoopt01.sqm
2009-03-17 14:06 . 2009-03-17 14:06 172 --ah----- C:\sqmdata01.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-20 20:36 --------- d-----w c:\documents and settings\Administrator\Application Data\Skype
2009-03-17 13:35 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-17 13:32 315,392 ----a-w c:\windows\HideWin.exe
2009-03-17 13:32 --------- d-----w c:\program files\Common Files\InstallShield
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-29 17:24 325000 --a------ c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-03-18 342848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-01-15 37376]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-18 136600]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2005-04-17 85184]
"RTHDCPL"="RTHDCPL.EXE" [2007-11-22 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2002-12-31 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\CS27\\mIRC.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2005-04-17 124608]
--- Other Services/Drivers In Memory ---
*Deregistered* - EraserUtilDrv10910
.
Contents of the 'Scheduled Tasks' folder
2009-03-20 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2009-03-11 15:05]
2009-03-18 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2009-03-11 15:05]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gpb2ccl0.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-03-20 21:35:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-03-20 21:37:10
ComboFix-quarantined-files.txt 2009-03-20 20:37:01
Pre-Run: 18.641.362.944 bytes free
Post-Run: 18,694,656,000 bytes free
177 --- E O F --- 2009-03-20 20:26:30
|