How are we looking now?
COMBO FIX LOGComboFix 08-08-23.03 - Dan 2008-08-24 17:16:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.460 [GMT -4:00]
Running from: C:\Documents and Settings\Dan\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - system32: deleted 12 bytes in 1 streams.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Dan\Application Data\.#
C:\Documents and Settings\Dan\Application Data\.#\MBX@908@B048E0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@908@B048F0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@A9C@B048E0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@A9C@B048F0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@ADC@B048E0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@ADC@B048F0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@B08@B048E0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@B08@B048F0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@BB4@B048E0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@BB4@B048F0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@DC8@B048E0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@DC8@B048F0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@EFC@B048E0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@EFC@B048F0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@F5C@B048E0.###
C:\Documents and Settings\Dan\Application Data\.#\MBX@F5C@B048F0.###
C:\Documents and Settings\Dan\Application Data\macromedia\Flash Player\#SharedObjects\ASM2FXSM\interclick.com
C:\Documents and Settings\Dan\Application Data\macromedia\Flash Player\#SharedObjects\ASM2FXSM\interclick.com\ud.sol
C:\Documents and Settings\Dan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Dan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Dan\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
.
((((((((((((((((((((((((( Files Created from 2008-07-24 to 2008-08-24 )))))))))))))))))))))))))))))))
.
2008-08-24 12:37 . 2008-08-24 12:45 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-24 12:37 . 2008-08-24 12:37 <DIR> d-------- C:\Documents and Settings\Dan\Application Data\Malwarebytes
2008-08-24 12:37 . 2008-08-24 12:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-24 12:37 . 2008-08-17 15:05 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-24 12:37 . 2008-08-17 15:05 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-23 15:41 . 2008-08-23 15:41 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-21 16:48 . 2008-08-21 18:12 <DIR> d-------- C:\Program Files\CommView
2008-08-21 16:48 . 2008-06-06 12:54 47,144 --a------ C:\WINDOWS\system32\tsnotify.dll
2008-08-21 16:48 . 2008-06-06 12:54 39,976 --a------ C:\WINDOWS\system32\drivers\tscomm.sys
2008-08-21 16:48 . 2007-06-19 23:35 24,096 --a------ C:\WINDOWS\system32\drivers\ts_lb.sys
2008-08-21 16:48 . 2006-12-07 22:04 19,240 --a------ C:\WINDOWS\system32\drivers\cv2k1.sys
2008-08-21 13:36 . 2007-07-11 11:11 888,832 --a------ C:\WINDOWS\system32\securenet.dll
2008-08-21 13:35 . 2008-08-21 13:36 <DIR> d-------- C:\Program Files\Hide My IP 2008
2008-08-20 03:48 . 2008-08-20 03:48 0 --a------ C:\WINDOWS\system32\330D.tmp
2008-08-20 03:46 . 2008-08-20 03:46 0 --a------ C:\WINDOWS\system32\32D9.tmp
2008-08-19 19:27 . 2008-08-19 19:27 0 --a------ C:\WINDOWS\system32\1BAD.tmp
2008-08-19 19:25 . 2008-08-19 19:25 0 --a------ C:\WINDOWS\system32\1B9D.tmp
2008-08-18 18:08 . 2008-08-18 18:08 0 --a------ C:\WINDOWS\system32\9.tmp
2008-08-18 18:07 . 2008-08-18 18:07 0 --a------ C:\WINDOWS\system32\2.tmp
2008-08-18 18:03 . 2008-08-18 18:03 0 --a------ C:\WINDOWS\system32\17.tmp
2008-08-18 18:01 . 2008-08-18 18:01 0 --a------ C:\WINDOWS\system32\4.tmp
2008-08-16 22:05 . 2008-08-24 17:25 <DIR> d-------- C:\Program Files\Steam
2008-08-03 14:05 . 2008-08-03 14:06 <DIR> d-------- C:\Program Files\Astonia3
2008-07-28 21:45 . 2003-11-04 15:11 159,744 --a------ C:\WINDOWS\system32\lfpng13n.dll
2008-07-28 21:45 . 2003-05-22 16:31 55,808 --a------ C:\WINDOWS\system32\lfpsd13n.dll
2008-07-27 23:40 . 2008-07-27 23:40 <DIR> d-------- C:\Program Files\dvd43
2008-07-27 23:40 . 2008-07-27 23:40 18,816 --a------ C:\WINDOWS\system32\drivers\dvd43llh.sys
2008-07-27 23:36 . 2008-07-27 23:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-07-27 23:35 . 2008-07-28 17:07 <DIR> d-------- C:\Program Files\NCH Software
2008-07-27 23:35 . 2008-07-27 23:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2008-07-27 23:33 . 2008-07-27 23:33 <DIR> d-------- C:\Documents and Settings\Dan\Application Data\Search Settings
2008-07-27 23:14 . 2008-07-28 17:10 <DIR> d-------- C:\Program Files\Free Easy Burner
2008-07-27 13:51 . 2008-07-27 14:01 <DIR> d-------- C:\Program Files\MyMobster
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-24 16:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-24 07:02 --------- d-----w C:\Program Files\DNA
2008-08-20 18:33 --------- d-----w C:\Program Files\Graal
2008-08-17 02:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-17 02:03 --------- d-----w C:\Program Files\Conquer 2.0
2008-08-17 02:03 --------- d-----w C:\Program Files\Cheat Engine
2008-07-28 21:07 --------- d-----w C:\Program Files\Yahoo!
2008-07-23 04:31 --------- d-----w C:\Program Files\DVDneXtCOPY2
2008-07-23 04:31 --------- d-----w C:\Program Files\Common Files\DistributeShield
2008-07-23 04:31 --------- d-----w C:\Program Files\AoA DVD Copy
2008-07-22 16:55 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-22 15:42 --------- d-----w C:\Documents and Settings\Dan\Application Data\dvdcss
2008-07-22 14:41 --------- d-----w C:\Program Files\Common Files\DVDnextCOPY2
2008-07-21 15:41 --------- d-----w C:\Program Files\Common Files\Astonsoft
2008-07-21 15:41 --------- d-----w C:\Program Files\Astonsoft
2008-07-21 15:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Astonsoft
2008-07-21 15:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\SlySoft
2008-07-13 04:48 --------- d-----w C:\Program Files\QuickTime
2008-07-11 19:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-07-11 18:44 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-11 18:10 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 00:12 0 ----a-w C:\Documents and Settings\Dan\jagex_runescape_preferences.dat
2008-06-24 22:44 --------- d-----w C:\Documents and Settings\Dan\Application Data\LimeWire
2008-06-24 19:20 --------- d-----w C:\Documents and Settings\Dan\Application Data\Azureus
2008-06-24 19:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:38 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 12:15 50528]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-02-28 23:06 2321600]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-08-16 23:03 1271032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"F-Secure Manager"="C:\Program Files\Charter High-Speed Security Suite\Common\FSM32.EXE" [2007-11-01 07:42 182936]
"F-Secure TNB"="C:\Program Files\Charter High-Speed Security Suite\FSGUI\TNBUtil.exe" [2007-11-01 07:42 739936]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 02:00 90112]
"diagent"="C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 02:01 135264]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47 31016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe" [2007-05-02 05:15 75520]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [2008-04-09 10:00 826880]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2008-03-17 08:21]
R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\Charter High-Speed Security Suite\HIPS\fshs.sys [2008-02-13 07:14]
R1 ts_lb;ts_lb;C:\WINDOWS\system32\drivers\ts_lb.sys [2007-06-19 23:35]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-03 18:31]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\Charter High-Speed Security Suite\Anti-Virus\minifilter\fsgk.sys [2007-11-01 07:42]
R3 SecureSrv;SecureSrv;C:\Program Files\Hide My IP 2008\SecureSrv.exe [2008-03-13 15:36]
R3 TSCOMM;CommStudio Virtual Adapter by TamoSoft;C:\WINDOWS\system32\DRIVERS\tscomm.sys [2008-06-06 12:54]
S3 CV2K1;CommView Network Monitor;C:\WINDOWS\system32\DRIVERS\cv2k1.sys [2006-12-07 22:04]
S3 DBKDRVR54;DBKDRVR54;C:\Program Files\Cheat Engine\dbk32.sys []
S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\Charter High-Speed Security Suite\Anti-Virus\Win2K\FSfilter.sys [2007-11-01 07:42]
S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\Charter High-Speed Security Suite\Anti-Virus\Win2K\FSrec.sys [2007-11-01 07:42]
.
Contents of the 'Scheduled Tasks' folder
2008-08-15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-08-24 C:\WINDOWS\Tasks\Scheduled scanning task.job
- C:\PROGRA~1\CHARTE~1\ANTI-V~1\fsav.exe [2007-11-01 07:42]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://usatoday.com/
R1 -: HKCU-SearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*
http://www.yahoo.com
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 -: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 -: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 -: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 -: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O16 -: RaptisoftGameLoader - hxxp://www.miniclip.com/games/hamsterball/en/raptisoftgameloader.cab
C:\WINDOWS\Downloaded Program Files\OSD28E7.OSD
C:\WINDOWS\Downloaded Program Files\RSGameLoader.dll
O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
C:\WINDOWS\Downloaded Program Files\SysReqLab3.osd
C:\WINDOWS\Downloaded Program Files\sysreqlab3.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-24 17:23:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\securenet.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Charter High-Speed Security Suite\Anti-Virus\fsgk32st.exe
C:\Program Files\Charter High-Speed Security Suite\Common\FSMA32.EXE
C:\Program Files\Charter High-Speed Security Suite\Anti-Virus\fsgk32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Charter High-Speed Security Suite\Anti-Virus\fssm32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Charter High-Speed Security Suite\Common\FSLAUNCH.EXE
.
**************************************************************************
.
Completion time: 2008-08-24 17:35:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-24 21:35:03
Pre-Run: 1,048,473,600 bytes free
Post-Run: 3,157,749,760 bytes free
209 --- E O F --- 2008-08-19 21:57:45