ComboFix 08-02-18.1 - johnpeter 2008-02-19 12:45:34.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.400 [GMT -6:00]
Running from: C:\Documents and Settings\johnpeter\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\johnpeter\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\SYSTEM32\apnlxsyc.ini
C:\WINDOWS\SYSTEM32\miaviviw.ini
C:\WINDOWS\SYSTEM32\qocohufm.ini
C:\WINDOWS\SYSTEM32\ryxtnowo.ini
C:\WINDOWS\SYSTEM32\vwcdklke.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\SYSTEM32\apnlxsyc.ini
C:\WINDOWS\SYSTEM32\miaviviw.ini
C:\WINDOWS\SYSTEM32\qocohufm.ini
C:\WINDOWS\SYSTEM32\ryxtnowo.ini
C:\WINDOWS\SYSTEM32\vwcdklke.ini
.
((((((((((((((((((((((((( Files Created from 2008-01-19 to 2008-02-19 )))))))))))))))))))))))))))))))
.
2008-02-17 12:40 . 2008-02-17 12:40 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-09 14:27 . 2008-02-09 17:09 149 --a------ C:\WINDOWS\wininit.ini
2008-02-07 21:54 . 2008-02-07 21:55 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-07 21:54 . 2008-02-08 07:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-07 21:33 . 2008-02-07 21:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-07 21:32 . 2008-02-07 21:32 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-07 21:18 . 2008-02-17 05:11 <DIR> d-------- C:\hijackthis
2008-02-05 22:24 . 2008-02-05 22:24 70,023,706 --a------ C:\ickythump.zip
2008-02-05 15:15 . 2003-09-08 05:08 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-02-02 01:33 . 2008-02-02 01:33 <DIR> d-------- C:\Registry Mechanic v7.0.0.1010
2008-02-02 01:23 . 2008-02-02 01:23 <DIR> d-------- C:\Startuplist
2008-01-31 23:22 . 2008-01-31 23:22 230 --a------ C:\WINDOWS\SYSTEM32\spupdsvc.inf
2008-01-30 22:17 . 2008-01-30 22:17 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-01-30 18:36 . 2008-01-30 18:36 <DIR> d-------- C:\Documents and Settings\johnpeter\Application Data\acccore
2008-01-30 18:35 . 2008-01-30 18:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-01-30 18:33 . 2008-01-30 18:57 <DIR> d-------- C:\Program Files\AIM6
2008-01-27 19:48 . 2008-01-30 17:45 <DIR> d-------- C:\Documents and Settings\johnpeter\Application Data\U3
2008-01-26 10:20 . 2008-01-30 23:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 03:33 --------- d-----w C:\Program Files\Lavasoft
2008-02-08 03:02 --------- d-----w C:\Documents and Settings\johnpeter\Application Data\uTorrent
2008-02-07 21:45 --------- d-----w C:\Program Files\Soulseek-Test
2008-02-06 21:19 --------- d-----w C:\Program Files\Opera
2008-02-02 07:17 --------- d-----w C:\Program Files\Java
2008-01-31 21:21 --------- d-----w C:\Program Files\AIM
2008-01-31 06:12 --------- d-----w C:\Program Files\Common Files\Adaptec Shared
2008-01-31 05:55 --------- d-----w C:\Program Files\Google
2008-01-31 04:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-31 00:51 --------- d-----w C:\Program Files\Common Files\aol
2008-01-31 00:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-01-26 18:18 --------- d-----w C:\Program Files\Yahoo!
2008-01-26 16:28 --------- d-----w C:\Program Files\Real
2008-01-26 16:28 --------- d-----w C:\Program Files\Common Files\Real
2008-01-26 16:27 --------- d---a-w C:\Program Files\Dynamic Toolbar
2008-01-26 16:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-26 16:26 --------- d-----w C:\Program Files\CyberLink
2008-01-26 16:24 --------- d-----w C:\Program Files\Paint.NET
2008-01-18 18:15 --------- d-----w C:\Program Files\McAfee
2008-01-02 17:48 --------- d-----w C:\Program Files\LimeWire
2007-12-31 19:06 --------- d-----w C:\Documents and Settings\johnpeter\Application Data\LimeWire
2007-12-31 02:01 --------- d-----w C:\Program Files\Secunia
2007-12-28 21:15 --------- d-----w C:\Documents and Settings\peter\Application Data\Talkback
2007-12-19 20:41 --------- d-----w C:\Program Files\Apple Software Update
2007-12-19 19:51 --------- d-----w C:\Program Files\iTunes
2007-12-19 19:50 --------- d-----w C:\Program Files\iPod
2007-12-19 19:45 --------- d-----w C:\Program Files\QuickTime
2007-12-14 17:32 12,632 ----a-w C:\WINDOWS\SYSTEM32\lsdelete.exe
2007-12-11 01:50 45,102,138 ----a-w C:\localh2007-09-13.AKGck93.cabbage.flac16_64kb_mp3.zip
2007-12-07 01:07 659,456 ----a-w C:\WINDOWS\SYSTEM32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\SYSTEM32\oleaut32.dll
2007-12-03 07:37 73,280 ----a-w C:\WINDOWS\SYSTEM32\oruurwvm.dll
2007-11-29 01:04 42,645,243 ----a-w C:\lh2007-11-24_64kb_mp3.zip
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3c890edb-a8f6-4fcd-8d9c-bc9995dd97b5}]
C:\WINDOWS\system32\vrpddfmc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 10:15 50528]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-20 19:55 68856]
"AOL Fast Start"="C:\America Online 9.0\AOL.exe" [2005-07-11 23:17 50776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.exe" [2004-08-04 01:56 158208]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^johnpeter^Start Menu^Programs^Startup^Secunia PSI (RC1).lnk]
path=C:\Documents and Settings\johnpeter\Start Menu\Programs\Startup\Secunia PSI (RC1).lnk
backup=C:\WINDOWS\pss\Secunia PSI (RC1).lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2406ac81]
C:\WINDOWS\system32\nkuksnaq.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2wSysTray]
--------- 2004-05-25 05:24 393216 C:\Program Files\2Wire\2PortalMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2008-01-03 10:15 50528 C:\Program Files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
--a------ 2005-07-11 23:17 50776 C:\America Online 9.0\AOL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 06:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
--a------ 2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-06-01 12:32 94208 C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM27359f1d]
C:\WINDOWS\system32\jpqtecrk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 01:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
--a------ 2004-02-28 11:12 144896 C:\Program Files\AIM\\DeadAIM.ocm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2007-03-15 11:09 460784 C:\Program Files\DellSupport\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
-ra------ 2002-08-14 17:22 28672 C:\WINDOWS\System32\DSentry.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyDVDMon]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-09-25 18:52 50736 C:\Program Files\Common Files\AOL\1102181951\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2005-10-19 07:59 126976 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2005-10-19 07:59 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightMonitor 01]
--a------ 2003-07-14 13:30 98304 C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 12:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OCAudioIni]
--a------ 2005-12-24 13:55 57344 C:\Program Files\One-click Audio Converter\OCAudioIni.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
--a------ 2004-04-05 15:33 99480 C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QAGENT]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 10:56 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-05-20 19:55 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wcmdmgr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\windows auto update]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
--a------ 2003-07-11 13:51 57344 C:\Program Files\Yahoo!\browser\ybrwicon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BM27359f1d"=Rundll32.exe "C:\WINDOWS\system32\jpqtecrk.dll",s
R2 mrtRate;mrtRate;C:\WINDOWS\system32\drivers\mrtRate.sys [2001-02-28 09:42]
S3 PSI;PSI;C:\WINDOWS\system32\DRIVERS\psi_mf.sys [2007-09-20 19:52]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{92c76b7e-cf8b-11dc-a963-000d727562da}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-02-16 17:11:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-15 07:18:42 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-01-01 07:00:07 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-19 12:50:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-19 12:53:07
ComboFix-quarantined-files.txt 2008-02-19 18:52:45
ComboFix2.txt 2008-02-19 00:29:03
.
2008-02-16 07:11:35 --- E O F ---