ComboFix 08-01-23.2 - Wes 2008-01-23 15:12:19.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1608 [GMT -8:00]
Running from: C:\Documents and Settings\Wes\Desktop\ComboFix(2).exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Wes\Application Data\DOBE~1
C:\Documents and Settings\Wes\Application Data\DOBE~1\?dobe\
C:\Games\Valve\Steam\steam .exe
c:\games\valve\steam\steam.exe
C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon .exe
C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect .exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Creative\SB Drive Det\SBDrvDet .exe
C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol .exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\outerinfo
C:\Program Files\Temporary
C:\Program Files\Temporary\kernInst.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe
C:\WINDOWS\system32\000080.exe
C:\WINDOWS\system32\drivers\sfsync02.sys
C:\WINDOWS\system32\gebcy.dll
C:\WINDOWS\system32\gebcy.exe
C:\WINDOWS\system32\icroso~1
C:\WINDOWS\system32\icroso~1\j?vaw.exe
C:\WINDOWS\system32\jsxioyxq.dll
C:\WINDOWS\system32\qxyoixsj.ini
C:\WINDOWS\system32\RCX13.tmp
C:\WINDOWS\system32\RCX14.tmp
C:\WINDOWS\system32\tjlqrkno.exe
C:\WINDOWS\system32\wnscpsv.exe
C:\WINDOWS\system32\ycbeg.ini
C:\WINDOWS\system32\ycbeg.ini2
Code:
<pre>
C:\Games\Valve\Steam\steam .exe ---> QooBox
C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon .exe ---> QooBox
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe ---> QooBox
C:\Program Files\Creative\MediaSource\Detector\CTDetect .exe ---> QooBox
C:\Program Files\Creative\SB Drive Det\SBDrvDet .exe ---> QooBox
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol .exe ---> QooBox
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe ---> QooBox
</pre>
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_SFSYNC02
-------\DomainService
-------\nm
-------\sfsync02
((((((((((((((((((((((((( Files Created from 2007-12-23 to 2008-01-23 )))))))))))))))))))))))))))))))
.
2008-01-23 15:11 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-23 15:06 . 2008-01-23 15:06 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-01-23 14:41 . 2008-01-23 15:05 <DIR> d-------- C:\VundoFix Backups
2008-01-23 12:12 . 2008-01-23 12:12 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-22 23:40 . 2008-01-22 23:40 1,109,185 ---hs---- C:\WINDOWS\system32\mimvoykv.ini
2008-01-22 12:20 . 2008-01-22 12:20 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-22 12:20 . 2008-01-22 12:20 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-22 12:16 . 2008-01-22 12:36 256 --a------ C:\WINDOWS\system32\pool.bin
2008-01-22 11:21 . 2007-01-18 10:24 26,496 -ra------ C:\WINDOWS\system32\drivers\RimSerial.sys
2008-01-22 11:20 . 2008-01-22 11:20 <DIR> d-------- C:\Program Files\Research In Motion
2008-01-22 11:20 . 2008-01-22 11:20 <DIR> d-------- C:\Program Files\Common Files\Research In Motion
2008-01-22 10:24 . 2008-01-22 10:24 <DIR> d-------- C:\WINDOWS\65F1CF6331E0450B96F34A88BE7361A6.TMP
2008-01-22 08:32 . 2008-01-22 11:32 1,109,125 ---hs---- C:\WINDOWS\system32\jumtsiod.ini
2008-01-22 08:27 . 2008-01-22 08:27 1,105,926 ---hs---- C:\WINDOWS\system32\shqytknh.ini
2008-01-13 11:19 . 2008-01-13 11:19 31,074 --a------ C:\WINDOWS\system32\drivers\Partizan.sys
2008-01-13 11:11 . 2008-01-13 11:26 <DIR> d-------- C:\Program Files\Dot1XCfg
2008-01-13 11:11 . 2008-01-13 11:11 25,600 --a------ C:\WINDOWS\system32\Partizan.exe
2008-01-13 11:09 . C:\WINDOWS\(2) C:\ComboFix\winstart.bat
2008-01-13 11:03 . 2008-01-13 11:03 336,384 --a------ C:\WINDOWS\system32\GEBCY.DLL.del
2008-01-13 10:58 . 2008-01-13 10:58 40,448 --a------ C:\WINDOWS\system32\VTUTSRO.DLL.del
2008-01-13 10:57 . 2007-11-01 05:44 60,928 --a------ C:\WINDOWS\system32\LQZLDAR.DLL.del
2008-01-13 10:56 . 2008-01-13 10:56 6,144 --a------ C:\info.exe
2008-01-10 20:38 . 2008-01-10 20:38 <DIR> d-------- C:\Program Files\CEVO
2008-01-10 20:38 . 2007-03-13 17:19 1,017,545 --a------ C:\WINDOWS\system32\cpuz.exe
2008-01-10 20:38 . 2006-03-31 14:48 119,056 --a------ C:\WINDOWS\system32\reg_c3.exe
2008-01-10 20:38 . 2007-03-13 16:26 73,728 --a------ C:\WINDOWS\system32\pv_c3.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 21:13 --------- d-----w C:\Program Files\mIRC
2008-01-22 23:40 --------- d-----w C:\Program Files\NZBomatic
2008-01-22 19:25 --------- d-----w C:\Program Files\Roxio
2008-01-22 19:25 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2008-01-22 19:24 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-01-22 18:25 --------- d-----w C:\Program Files\Best Buy Rhapsody
2008-01-13 19:28 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-13 19:03 --------- d-----w C:\Program Files\DAEMON Tools
2008-01-13 16:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-01-08 22:10 --------- d-----w C:\Program Files\DivX
2007-12-21 03:05 --------- d-----w C:\Program Files\Common Files\AOL
2007-12-21 03:05 --------- d-----w C:\Program Files\AIM
2007-12-20 02:46 --------- d-----w C:\Program Files\AIM6
2007-12-18 12:31 --------- d-----w C:\Program Files\Viewpoint
2007-12-18 12:15 --------- d-----w C:\Program Files\Common Files\Nullsoft
2007-12-06 21:37 --------- d-----w C:\Program Files\SmartFTP Client 2.5 Setup Files
2007-12-06 21:37 --------- d-----w C:\Program Files\SmartFTP Client
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{56c92c00-8db1-4415-9dae-c665d26da0a9}]
C:\WINDOWS\system32\hkmybmlu.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [ ]
"Aim6"="" []
"Steam"="c:\games\valve\steam\steam.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [ ]
"SBDrvDet"="C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" [ ]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 00:07 8491008]
"nwiz"="nwiz.exe" [2007-09-17 00:07 1626112 C:\WINDOWS\system32\nwiz.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-03-28 16:38 94208 C:\WINDOWS\KHALMNPR.Exe]
"Launch LCDMon"="C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe" [ ]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 00:07 81920]
"CTHelper"="CTHELPER.EXE" [2006-08-11 13:56 17920 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 13:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [ ]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
backup=C:\WINDOWS\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-10-10 18:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2008-01-13 11:03 481280 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DHzpColorBoost]
C:\Windows\System32\DHzpColor.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\gebcy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nTrayFw]
--a------ 2005-12-21 10:52 270336 C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2005-12-22 01:56 155648 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
--a------ 2005-09-19 00:53 1687552 C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
--a------ 2005-09-19 00:29 163840 C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
--a------ 2004-04-23 14:28 77824 C:\Program Files\Logitech\Profiler\lwemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-06-14 17:32 132760 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;C:\WINDOWS\system32\DRIVERS\nvcchflt.sys [2005-02-11 02:11]
R2 PfDetNT;PfDetNT;C:\WINDOWS\System32\drivers\PfModNT.sys [2006-08-11 13:56]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-20 16:00:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-23 15:16:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Creative Detector = "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R???w0??w????*??w???w@x??O??w????m???p???????????????l???l??????????wO??w????m???p???????????????k!?s???w???w???????????w???????w??j????????w???????w???w???????s????g??w???w???????w???w???????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.