ComboFix 07-10-05.3 - cisbell 2007-10-05 8:55:41.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.599 [GMT -5:00]
Running from: C:\Documents and Settings\cisbell\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\cisbell\Desktop\CFScript.txt
* Created a new restore point
FILE::
C:\Documents and Settings\cisbell\Start Menu\Programs\Startup\TA_Start.lnk
C:\Program Files\Internet Explorer\prokycovyv.html
C:\Program Files\Online Services\howyk22011.exe
C:\WINDOWS\lwdyxmlA.exe
C:\WINDOWS\plite731.exe
C:\WINDOWS\pss\TA_Start.lnkStartup
C:\WINDOWS\retadpu1000106.exe
C:\WINDOWS\system32\pdilddeh.dll
C:\WINDOWS\system32\rjkxiifr.dll
C:\WINDOWS\system32\sqehhqe.dll
C:\WINDOWS\TISKY002.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pss\TA_Start.lnkStartup
.
((((((((((((((((((((((((( Files Created from 2007-09-05 to 2007-10-05 )))))))))))))))))))))))))))))))
.
2007-09-17 14:46 <DIR> d-------- C:\Program Files\Atomic Clock Sync
2007-09-17 12:42 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-09-17 12:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-09-17 11:34 <DIR> d-------- C:\VundoFix Backups
2007-09-17 11:12 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-17 10:01 <DIR> d-------- C:\Documents and Settings\cisbell\Application Data\F-Secure
2007-09-17 09:54 70,960 --a------ C:\WINDOWS\system32\drivers\fsdfw.sys
2007-09-17 09:54 33,552 --a------ C:\WINDOWS\system32\drivers\fsndis5.sys
2007-09-17 09:53 118,842 -r------- C:\WINDOWS\bwUnin-6.3.2.116-7681197L.exe
2007-09-17 09:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\F-Secure
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-17 09:52 --------- d-------- C:\Program Files\F-Secure
2007-08-27 13:18 --------- d-------- C:\Program Files\iTunes
2007-08-27 13:17 --------- d-------- C:\Program Files\iPod
2007-08-06 16:56 --------- d-------- C:\Documents and Settings\cisbell\Application Data\Downloaded Installations
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\dllcache\wups.dll
2007-07-19 01:59 3583488 --a------ C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-12 18:31 765952 --a------ C:\WINDOWS\system32\dllcache\vgx.dll
.
((((((((((((((((((((((((((((( snapshot_2007-09-17_112512.18 )))))))))))))))))))))))))))))))))))))))))
.
----a-w 135,168 2007-09-28 14:06:08 C:\WINDOWS\catchme.exe
----a-r 40,960 2007-09-24 13:26:12 C:\WINDOWS\Installer\{1223DED9-93E9-430C-BF08-579B9841BE2C}\AltiView_Porgrams_Sh_1223DED993E9430CBF08579B9841BE2C.exe
----a-r 2,441,216 2007-09-24 13:26:12 C:\WINDOWS\Installer\{1223DED9-93E9-430C-BF08-579B9841BE2C}\AltiView_Startup_Sho_1223DED993E9430CBF08579B9841BE2C.exe
----a-r 40,960 2007-09-24 13:26:12 C:\WINDOWS\Installer\{1223DED9-93E9-430C-BF08-579B9841BE2C}\ARPPRODUCTICON.exe
----a-w 279,552 2007-10-05 15:07:31 C:\WINDOWS\system32\swreg.exe
----a-w 213,048 2005-05-24 16:27:16 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
----a-w 94,208 2007-09-07 16:29:00 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
----a-w 946,176 2007-09-07 16:29:00 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
----a-w 109,056 2007-07-20 05:47:22 C:\WINDOWS\catchme.exe
----a-r 40,960 2006-02-23 16:40:43 C:\WINDOWS\Installer\{1223DED9-93E9-430C-BF08-579B9841BE2C}\AltiView_Porgrams_Sh_1223DED993E9430CBF08579B9841BE2C.exe
----a-r 2,441,216 2006-02-23 16:40:43 C:\WINDOWS\Installer\{1223DED9-93E9-430C-BF08-579B9841BE2C}\AltiView_Startup_Sho_1223DED993E9430CBF08579B9841BE2C.exe
----a-r 40,960 2006-02-23 16:40:43 C:\WINDOWS\Installer\{1223DED9-93E9-430C-BF08-579B9841BE2C}\ARPPRODUCTICON.exe
----a-w 279,552 2007-07-22 23:39:27 C:\WINDOWS\system32\swreg.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 22:05]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-03-10 14:01 C:\WINDOWS\KHALMNPR.Exe]
"F-Secure Manager"="C:\Program Files\F-Secure\Common\FSM32.exe" [2005-10-25 20:51]
"F-Secure TNB"="C:\Program Files\F-Secure\TNB\TNBUtil.exe" [2004-05-27 03:57]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 22:49]
C:\Documents and Settings\cisbell\Start Menu\Programs\Startup\
Launch Microsoft Office Outlook.lnk - C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE [2003-07-14 22:45:18]
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe [2007-07-20 12:57:16]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AltiView.lnk - C:\Program Files\Altigen\AltiView\AltiView.exe [2004-06-17 14:39:06]
F-Secure Automatic Update.lnk - C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe [2007-09-17 09:53:32]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
C:\Program Files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"C:\Program Files\DellSupport\DSAgnt.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure Manager]
"C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure TNB]
"C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
"C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"C:\Program Files\Dell\Media Experience\PCMService.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter]
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys
R2 BackWeb Plug-in - 7681197;F-Secure Automatic Update;C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
R2 F-Secure Filter;F-Secure File System Filter;\??\C:\Program Files\F-Secure\Anti-Virus\Win2K\FSfilter.sys
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;\??\C:\Program Files\F-Secure\Anti-Virus\Win2K\FSgk.sys
R2 F-Secure Recognizer;F-Secure File System Recognizer;\??\C:\Program Files\F-Secure\Anti-Virus\Win2K\FSrec.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\LaunchU3.exe -a
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-05 08:59:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-05 9:01:48
C:\ComboFix-quarantined-files.txt ... 2007-10-05 09:01
C:\ComboFix2.txt ... 2007-09-17 11:25
.
--- E O F ---