ComboFix 08-11-07.01 - Benjamin Lee 2008-11-09 14:03:46.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.165 [GMT -5:00]
Running from: c:\documents and settings\Benjamin Lee\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Benjamin Lee\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\windows\system32\domviqpl.dll
c:\windows\system32\hlljuuwb.dll
c:\windows\system32\pomssiwp.dll
c:\windows\system32\qphvceek.dll
c:\windows\system32\tijglkur.dll
c:\windows\system32\vufefuiq.dll
c:\windows\system32\xvwrfw.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\domviqpl.dll
c:\windows\system32\hlljuuwb.dll
c:\windows\system32\pomssiwp.dll
c:\windows\system32\qphvceek.dll
c:\windows\system32\tijglkur.dll
c:\windows\system32\vufefuiq.dll
c:\windows\system32\xvwrfw.dll
.
((((((((((((((((((((((((( Files Created from 2008-10-09 to 2008-11-09 )))))))))))))))))))))))))))))))
.
2008-11-07 17:41 . 2008-11-07 18:16 <DIR> d-------- c:\windows\system32\CatRoot_bak
2008-11-07 11:58 . 2008-11-07 11:58 <DIR> d-------- c:\program files\Trend Micro
2008-11-06 21:17 . 2008-11-06 21:17 <DIR> d-------- c:\program files\Motorola
2008-11-06 21:06 . 2008-11-06 21:06 230 --a------ c:\windows\system32\spupdsvc.inf
2008-11-06 20:52 . 2008-02-28 13:26 1,414,440 --a------ c:\windows\system32\ShellManager310E2D762.dll
2008-11-06 20:52 . 2008-02-28 13:01 774,144 --a------ c:\windows\system32\NEROINSTAEC43759.DB
2008-10-13 23:09 . 2008-10-13 23:54 520 --a------ c:\windows\system32\tmp.reg
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-07 03:04 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-07 02:51 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-07 02:40 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-07 02:14 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-07 01:54 --------- d-----w c:\program files\Common Files\Nero
2008-11-07 01:54 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-11-07 01:35 --------- d-----w c:\program files\Sony
2008-11-07 01:33 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-10-31 02:48 --------- d-----w c:\documents and settings\Benjamin Lee\Application Data\Move Networks
2008-09-14 18:33 132,224 ----a-w c:\windows\system32\woisshpn.dll
2008-02-17 02:23 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-12-03 18:07 253,440 ----a-w c:\program files\Notepad2.exe
2006-06-20 14:13 81,920 -c--a-w c:\program files\sherlock.exe
2008-02-28 18:30 8,784 ----a-w c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2008-02-28 18:33 245,408 ----a-w c:\program files\mozilla firefox\plugins\unicows.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-22 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-26 4632576]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
c:\documents and settings\Benjamin Lee\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk.disabled [2007-06-09 947]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2007-11-15 18:46 87352 c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3IV2"= 3ivxVfWCodec.dll
"vidc.X264"= x264vfw.dll
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
"msacm.l3codec"= l3codecp.acm
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"gStart"=c:\garmin\gStart.exe
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"FaxMonitor"=c:\program files\IPFax\FaxMonitor.exe
"HostManager"=c:\program files\Common Files\AOL\1150913539\ee\AOLSoftware.exe
"IPHSend"=c:\program files\Common Files\AOL\IPHSend\IPHSend.exe
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"nwiz"=nwiz.exe /installquiet
"POINTER"=point32.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Run StartupMonitor"=StartupMonitor.exe
"Apoint"=c:\program files\Apoint\Apoint.exe
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ABC\\abc.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1150913539\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1150913539\\ee\\aim6.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2007-08-03 46112]
R2 MSCamSvc;MSCamSvc;c:\program files\Microsoft LifeCam\MSCamS32.exe [2006-10-13 207664]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
R3 GTICARD;GTICARD;c:\windows\system32\DRIVERS\gticard.sys [2003-10-23 76160]
R3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\wdmirror.sys [2006-05-03 9984]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [ ]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [2007-02-27 17792]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [2007-01-23 7680]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\DRIVERS\motodrv.sys [2006-12-14 40832]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys [2007-02-27 21504]
S3 Nmea;Sprint Connection Manager - emulates the NMEA ports;c:\windows\system32\DRIVERS\pctnullport.sys [ ]
S3 PCASp50;PCASp50 NDIS Protocol Driver;c:\windows\system32\Drivers\PCASp50.sys [2007-10-12 27072]
S3 qcusbmdm;Qualcomm Proprietary USB Driver (PID 3197);c:\windows\system32\DRIVERS\qcusbmdm.sys [2003-11-06 32352]
S3 qcusbser;Qualcomm Diagnostic Port;c:\windows\system32\DRIVERS\qcusbser.sys [2003-11-06 32352]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\DRIVERS\VX6000Xp.sys [2006-10-13 2383152]
S3 WnsDrvr;WnsDrvr;c:\windows\system32\drivers\WnsDrvr.sys [2007-12-13 25952]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09889ac2-e76c-11db-85b0-00904b2da1f8}]
\Shell\AutoRun\command - F:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09889ac3-e76c-11db-85b0-00904b2da1f8}]
\Shell\AutoRun\command - G:\setupSNK.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
2008-11-09 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-07-30 14:45]
2008-11-07 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-08-14 13:39]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-09 14:08:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-09 14:14:58
ComboFix-quarantined-files.txt 2008-11-09 19:14:07
ComboFix2.txt 2008-11-08 21:41:33
ComboFix3.txt 2008-11-08 04:44:45
Pre-Run: 7,675,310,080 bytes free
Post-Run: 7,652,548,608 bytes free
161 --- E O F --- 2008-07-23 07:06:13