ComboFix 08-06-20.4 - brad.munro 2008-06-30 19:53:52.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.661 [GMT 10:00]
Running from: E:\Internet\Downloads\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM87d50535.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\cuhndsxa.ini
C:\WINDOWS\system32\EOrCffii.ini
C:\WINDOWS\system32\EOrCffii.ini2
C:\WINDOWS\system32\fgblclma.ini
C:\WINDOWS\system32\ftrdioon.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\vyfiqfev.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-30 )))))))))))))))))))))))))))))))
.
2008-06-30 17:04 . 2008-06-30 17:04 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\Malwarebytes
2008-06-30 17:04 . 2008-06-30 17:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-30 17:04 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-30 17:04 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-29 19:16 . 2008-06-29 19:16 56,312 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-06-29 14:24 . 2008-06-29 14:24 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-06-29 11:29 . 2004-08-04 17:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-06-29 10:49 . 2008-06-29 10:49 <DIR> d-------- C:\WINDOWS\Sun
2008-06-29 10:31 . 2008-06-13 23:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-29 10:31 . 2008-06-13 23:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-28 22:28 . 2008-06-30 15:50 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-06-28 22:28 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-06-28 15:39 . 2008-06-28 15:39 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-27 22:56 . 2008-06-27 22:56 <DIR> d-------- C:\Program Files\Java
2008-06-27 22:56 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-27 22:55 . 2008-06-27 22:55 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-27 14:40 . 2008-06-30 17:00 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\Muchobene
2008-06-26 14:16 . 2008-06-26 15:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-24 17:05 . 2008-06-27 14:50 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\skypePM
2008-06-24 17:05 . 2008-06-27 16:06 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\Skype
2008-06-24 17:05 . 2008-06-24 17:05 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-06-24 17:04 . 2008-06-24 17:04 <DIR> d-------- C:\Program Files\Skype
2008-06-24 17:04 . 2008-06-24 17:04 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-06-24 17:04 . 2008-06-24 17:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-06-20 13:49 . 2008-06-20 13:49 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-06-18 21:13 . 2008-06-18 21:13 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-06-16 21:42 . 2008-06-16 21:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-16 19:57 . 2008-06-16 19:57 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\acccore
2008-06-16 19:56 . 2008-06-30 17:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-06-16 19:56 . 2008-06-16 19:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-06-16 19:56 . 2008-06-16 19:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-06-16 19:56 . 2008-06-16 19:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\acccore
2008-06-16 19:55 . 2008-06-16 19:55 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-06-16 19:52 . 2008-06-16 19:57 <DIR> d-------- C:\Program Files\AIM6
2008-06-16 19:52 . 2008-06-16 19:57 385 --ah----- C:\IPH.PH
2008-06-15 11:59 . 2001-08-17 13:56 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2008-06-15 11:59 . 2001-08-17 13:56 7,552 --a--c--- C:\WINDOWS\system32\dllcache\sonypvu1.sys
2008-06-15 11:58 . 2008-06-21 13:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-06-15 11:41 . 2008-06-15 11:41 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-06-15 11:09 . 2008-06-15 11:09 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\DAEMON Tools
2008-06-15 11:09 . 2008-06-15 11:09 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-06-14 20:26 . 2008-06-14 20:26 <DIR> d-------- C:\Program Files\uTorrent
2008-06-14 20:26 . 2008-06-26 20:09 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\uTorrent
2008-06-14 15:54 . 2008-06-15 12:51 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-06-14 10:16 . 2008-06-14 10:16 <DIR> d-------- C:\Documents and Settings\debbie.munro\Application Data\Talkback
2008-06-14 10:15 . 2008-06-14 10:15 <DIR> d-------- C:\Documents and Settings\debbie.munro
2008-06-12 21:58 . 2008-06-12 21:58 409,600 --a------ C:\WINDOWS\system32\wrap_oal.dll
2008-06-12 21:58 . 2008-06-12 21:58 114,688 --a------ C:\WINDOWS\system32\OpenAL32.dll
2008-06-12 21:58 . 2007-06-06 09:40 5,663 --a------ C:\WINDOWS\system32\ludap17.ini
2008-06-12 21:58 . 2007-05-23 09:53 75 --a------ C:\WINDOWS\system32\ctzapxx.ini
2008-06-12 17:17 . 2008-06-12 17:17 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\Creative
2008-06-12 16:46 . 2008-06-13 09:57 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\AccurateRip
2008-06-12 15:47 . 2008-06-12 22:00 584 --a------ C:\WINDOWS\system32\settingsbkup.sfm
2008-06-12 15:47 . 2008-06-12 22:00 584 --a------ C:\WINDOWS\system32\settings.sfm
2008-06-12 14:33 . 2008-06-15 11:47 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-06-12 14:31 . 2008-06-14 15:54 1,244 --a------ C:\WINDOWS\mozver.dat
2008-06-12 14:24 . 2004-01-14 11:10 163,840 --a------ C:\WINDOWS\BJPSUNST.EXE
2008-06-12 14:23 . 2003-09-18 14:32 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-06-12 14:23 . 2003-09-18 14:32 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-06-12 14:22 . 2008-06-12 14:22 0 --a------ C:\WINDOWS\OpPrintServer.INI
2008-06-12 14:19 . 2004-06-07 15:00 116,736 --a------ C:\WINDOWS\system32\CNMLM6d.DLL
2008-06-12 14:19 . 2004-06-07 15:00 7,680 --a------ C:\WINDOWS\system32\CNMVS6d.DLL
2008-06-12 14:18 . 2008-06-12 14:18 <DIR> d-------- C:\WINDOWS\StartHtmico
2008-06-12 14:18 . 2008-06-12 14:18 <DIR> d-------- C:\WINDOWS\IP5000
2008-06-12 14:18 . 2008-06-12 14:18 <DIR> d--h----- C:\BJPrinter
2008-06-12 14:18 . 2004-06-05 01:34 86,016 -ra------ C:\WINDOWS\system32\CNMCP6d.exe
2008-06-12 14:11 . 2008-06-12 14:24 <DIR> d-------- C:\Program Files\Canon
2008-06-12 14:01 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-06-12 14:01 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-06-12 11:49 . 2008-06-12 11:49 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\Apple Computer
2008-06-12 11:45 . 2008-06-12 20:32 <DIR> d-------- C:\Program Files\QuickTime
2008-06-12 11:45 . 2008-06-12 11:45 <DIR> d-------- C:\Program Files\iPod
2008-06-12 11:45 . 2008-06-12 11:45 <DIR> d-------- C:\Program Files\Bonjour
2008-06-12 11:45 . 2008-06-12 11:45 <DIR> d-------- C:\Program Files\Apple Software Update
2008-06-12 11:45 . 2008-06-12 11:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-12 11:44 . 2008-06-12 11:44 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-06-12 11:44 . 2008-06-12 11:44 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-06-12 11:44 . 2008-06-12 11:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-06-12 11:44 . 2008-01-15 19:39 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2008-06-12 11:43 . 2008-06-12 11:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-06-12 11:42 . 2008-06-12 11:42 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\vlc
2008-06-12 11:32 . 2008-06-12 11:32 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\Talkback
2008-06-12 11:31 . 2004-08-04 16:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-06-12 11:27 . 2008-06-30 19:45 <DIR> d-------- C:\Documents and Settings\brad.munro\Application Data\foobar2000
2008-06-12 11:22 . 2008-06-30 17:11 <DIR> d-------- C:\Documents and Settings\brad.munro
2008-06-12 11:01 . 2006-10-27 12:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-06-12 11:00 . 2008-06-12 11:00 <DIR> d-------- C:\Program Files\MSBuild
2008-06-12 11:00 . 2008-06-12 11:00 <DIR> d-------- C:\Program Files\Microsoft Works
2008-06-12 10:57 . 2008-06-12 10:59 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-06-12 10:57 . 2008-06-25 21:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-12 10:56 . 2008-06-12 10:56 <DIR> dr-h----- C:\MSOCache
2008-06-12 10:38 . 2008-06-12 10:38 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-12 10:30 . 2008-06-12 10:30 <DIR> d-------- C:\WINDOWS\system32\windows media
2008-06-12 10:30 . 2008-06-12 10:30 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2008-06-12 10:30 . 2008-06-12 10:30 <DIR> d-------- C:\Program Files\Windows Media Components
2008-06-12 10:29 . 2004-03-16 05:34 24,576 --------- C:\WINDOWS\system32\UleadPhotoExplorer85_Res.dll
2008-06-12 10:29 . 2004-03-16 05:33 24,576 --------- C:\WINDOWS\system32\Ulead Photo Explorer 85.scr
2008-06-12 10:25 . 2008-06-12 10:29 <DIR> d-------- C:\Program Files\Ulead Systems
2008-06-12 10:25 . 2008-06-12 10:25 <DIR> d-------- C:\Program Files\Common Files\VideoMate
2008-06-12 10:25 . 2008-06-12 10:29 <DIR> d-------- C:\Program Files\Common Files\Ulead Systems
2008-06-12 10:25 . 2008-06-12 10:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-06-12 10:25 . 2003-04-03 09:24 950,272 --a------ C:\WINDOWS\system32\u32Prod.dll
2008-06-12 10:25 . 2003-02-22 13:42 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-06-12 10:25 . 2003-02-19 03:23 122,880 --a------ C:\WINDOWS\system32\u32Comm.dll
2008-06-12 10:25 . 2002-09-18 03:19 73,728 --a------ C:\WINDOWS\system32\PhilipsVBI.ax
2008-06-12 10:25 . 2003-04-18 09:34 61,440 --a------ C:\WINDOWS\system32\u32Cfg.dll
2008-06-12 10:25 . 2002-08-03 14:25 53,248 --a------ C:\WINDOWS\system32\UVSC.DLL
2008-06-12 10:25 . 2003-01-10 05:58 24,576 --a------ C:\WINDOWS\system32\U32SN.DLL
2008-06-12 10:24 . 2008-06-12 10:26 <DIR> d-------- C:\Program Files\VideoMate
2008-06-12 10:18 . 2000-05-22 18:58 647,872 --------- C:\WINDOWS\system32\Mscomct2.ocx
2008-06-12 10:18 . 1999-10-11 11:00 41,984 --------- C:\WINDOWS\Ctregrun.exe
2008-06-12 10:15 . 2008-06-12 10:15 <DIR> d-------- C:\WINDOWS\system32\Data
2008-06-12 10:13 . 2008-06-12 10:18 <DIR> d-------- C:\Program Files\Creative
2008-06-12 10:12 . 99 C:\WINDOWS\E
2008-06-12 10:07 . 2003-03-04 13:56 145,408 -ra------ C:\WINDOWS\system32\drivers\e100b325.sys
2008-06-12 10:07 . 2003-03-04 13:56 145,408 --a--c--- C:\WINDOWS\system32\dllcache\e100b325.sys
2008-06-12 10:07 . 2003-03-03 17:26 118,784 -ra------ C:\WINDOWS\system32\Prounstl.exe
2008-06-12 10:07 . 2003-02-11 08:18 102,400 -ra------ C:\WINDOWS\system32\drivers\ianswxp.sys
2008-06-12 10:07 . 2002-12-29 06:00 24,064 -ra------ C:\WINDOWS\system32\IntelNic.dll
2008-06-12 10:07 . 2003-02-03 07:26 12,288 -ra------ C:\WINDOWS\system32\e100bmsg.dll
2008-06-12 10:07 . 2002-06-27 07:53 5,110 -ra------ C:\WINDOWS\system32\e100b325.din
2008-06-12 10:06 . 2008-06-12 10:06 <DIR> d-------- C:\Program Files\Gigabyte
2008-06-12 10:06 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-06-12 10:04 . 2008-06-12 10:07 <DIR> d-------- C:\Program Files\Intel
2008-06-12 10:03 . 2008-06-12 21:59 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-11 23:50 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
2007-12-17 12:43 27,648 --sh--w C:\WINDOWS\system32\Smab0.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 17:56 15360]
"Aim6"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-12 09:24 86016]
"CTSysVol"="C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe" [2003-05-03 02:53 57344]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 18:00 90112]
"Ulead AutoDetector v2"="C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2004-08-28 12:22 90112]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 17:47 31016]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-11 08:27 385024]
"P17Helper"="P17.dll" [2005-05-03 19:38 64512 C:\WINDOWS\system32\P17.dll]
"Easy-PrintToolBox"="C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 11:10 409600]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 88363 C:\WINDOWS\AGRSMMSG.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ComproRemoteDTV.lnk - C:\Program Files\Common Files\VideoMate\ComproRemoteDTV.exe [2008-06-12 10:25:01 139264]
ComproSchedulerDTV.lnk - C:\Program Files\Common Files\VideoMate\ComproSchedulerDTV.exe [2008-06-12 10:25:01 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"E:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"E:\\Program Files\\AIM\\aim.exe"=
"E:\\Program Files\\Miranda IM\\miranda32.exe"=
"E:\\Program Files\\Trillian\\trillian.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 09:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 09:16]
R3 VMHybrid;VMHybrid service;C:\WINDOWS\system32\DRIVERS\VMHybrid.sys [2005-04-13 02:49]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-30 19:57:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\MsPMSPSv.exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-06-30 19:59:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-30 09:59:16
Pre-Run: 23,653,416,960 bytes free
Post-Run: 23,577,784,320 bytes free
232 --- E O F --- 2008-06-30 06:55:14