ComboFix Log:
ComboFix 07-11-08.1 - Dan 2007-11-14 15:54:47.4 - NTFSx86
Running from: C:\Documents and Settings\Dan\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\windows\system32\explorer.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-14 to 2007-11-14 )))))))))))))))))))))))))))))))
.
2007-11-14 15:32 30,841 --a------ C:\WINDOWS\system32\dskfhfab.exe
2007-11-13 18:24 31,622 --a------ C:\WINDOWS\system32\tutrge.exe
2007-11-11 17:17 2,432 --a------ C:\WINDOWS\system32\unpr.sys
2007-11-08 17:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-07 16:08 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-07 15:52 32,768 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-11-05 18:57 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-05 18:40 85,568 --a------ C:\WINDOWS\system32\fbydlbaw.dll
2007-11-05 15:27 83,008 --a------ C:\WINDOWS\system32\wqridibx.dll
2007-11-05 15:24 1 --a------ C:\WINDOWS\system32\rc.dat
2007-11-05 15:24 1 --a------ C:\WINDOWS\system32\ps1.dat
2007-11-05 15:24 1 --a------ C:\WINDOWS\system32\cookie1.dat
2007-11-03 14:13 52,224 --a------ C:\WINDOWS\system32\rasmoesa.dll
2007-11-03 14:11 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2007-11-03 14:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2007-11-03 13:48 <DIR> d-------- C:\Program Files\Photoshop
2007-11-01 18:27 <DIR> dr-hs---- C:\Volume Information
2007-11-01 18:26 <DIR> d-------- C:\WINDOWS\Instant Lock
2007-11-01 18:26 <DIR> d-------- C:\Program Files\Instant Lock
2007-10-31 15:32 <DIR> d-------- C:\Program Files\DriveMounter
2007-10-28 17:42 <DIR> d-------- C:\Program Files\Mac Startup Screen
2007-10-28 17:40 <DIR> d-------- C:\Documents and Settings\Dan\Application Data\Nubs
2007-10-28 17:34 <DIR> d-------- C:\Program Files\Concentrate
2007-10-28 17:27 <DIR> d--h----- C:\WINDOWS\PIF
2007-10-28 17:27 <DIR> d-------- C:\Program Files\Finderbar 1.5
2007-10-28 17:27 46,592 --a------ C:\WINDOWS\zipinst.exe
2007-10-28 17:21 <DIR> d-------- C:\Program Files\ICO-PNG
2007-10-27 13:35 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-10-26 22:29 <DIR> d-------- C:\Documents and Settings\Dan\Application Data\Alien Skin
2007-10-23 21:02 <DIR> d-------- C:\Program Files\RK Launcher
2007-10-23 20:06 <DIR> d-------- C:\Program Files\RocketDock
2007-10-22 20:30 <DIR> d-------- C:\Program Files\Atlantis Xtreme V0.9.1
2007-10-21 12:02 <DIR> d-------- C:\Documents and Settings\Dan\Application Data\HP
2007-10-21 11:47 20,280 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2007-10-20 18:35 <DIR> d-------- C:\Program Files\Star Trek Legacy
2007-10-20 13:20 177,496 --a------ C:\WINDOWS\system32\wdfproc.dll
2007-10-18 13:41 85,848 --a------ C:\WINDOWS\system32\drivers\pwipf6.sys
2007-10-16 17:49 <DIR> d-------- C:\Program Files\Activision
2007-10-16 17:39 <DIR> d-------- C:\Program Files\Alcohol Soft
2007-10-16 17:32 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-10-16 16:39 <DIR> d-------- C:\Documents and Settings\Dan\Application Data\DivX
2007-10-16 16:36 <DIR> d-------- C:\Program Files\Google
2007-10-15 18:24 <DIR> d-------- C:\Program Files\DivX
2007-10-15 13:03 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2007-10-15 13:03 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2007-10-15 12:12 <DIR> d-------- C:\Program Files\Xvid
2007-10-15 12:08 28,672 --a------ C:\WINDOWS\system32\Alphablending.dll
2007-10-15 11:06 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-10-15 10:54 <DIR> d-------- C:\Documents and Settings\Dan\Application Data\CandyLabs
2007-10-14 18:10 <DIR> d-------- C:\Program Files\MSBuild
2007-10-14 18:02 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2007-10-14 17:59 <DIR> d-------- C:\Program Files\Reference Assemblies
2007-10-14 17:58 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-11 09:01 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-11 08:14 --------- d-----w C:\Documents and Settings\Dan\Application Data\Azureus
2007-11-09 13:22 --------- d-----w C:\Program Files\Motorola Phone Tools
2007-11-09 13:17 --------- d-----w C:\Program Files\Avanquest update
2007-11-09 09:49 4,624,384 ----a-w C:\WINDOWS\system32\logonuiX.exe
2007-11-09 09:46 163,840 ----a-w C:\WINDOWS\system32\drivers\vidstub.sys
2007-11-08 11:06 --------- d-----w C:\Documents and Settings\Dan\Application Data\LimeWire
2007-11-07 09:45 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-11-06 09:49 --------- d-----w C:\Program Files\Webroot
2007-11-03 01:59 --------- d-----w C:\Program Files\Trillian
2007-10-31 08:57 --------- d-----w C:\Documents and Settings\Dan\Application Data\Matrix Y2K
2007-10-28 09:18 --------- d-----w C:\Program Files\iTunes
2007-10-21 02:45 164 ----a-w C:\install.dat
2007-10-17 11:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Webroot
2007-10-16 07:36 --------- d-----w C:\Program Files\Mozilla Thunderbird
2007-10-15 01:53 --------- d-----w C:\Program Files\WS_FTP Pro
2007-10-14 12:36 --------- d-----w C:\Program Files\Common Files\Stardock
2007-10-14 12:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-14 12:30 --------- d-----w C:\Program Files\Macromedia
2007-10-14 12:26 --------- d-----w C:\Program Files\AutoSizer
2007-10-11 08:17 --------- d-----w C:\Program Files\Matrix Y2K
2007-10-10 11:25 --------- d-----w C:\Documents and Settings\Dan\Application Data\SmartFTP
2007-10-09 13:06 --------- d-----w C:\Program Files\Azureus
2007-10-09 02:54 --------- d-----w C:\Documents and Settings\Dan\Application Data\CyberLink
2007-10-02 16:32 --------- d-----w C:\Program Files\Bonjour
2007-10-01 08:40 1,526,072 ----a-w C:\WINDOWS\WRSetup.dll
2007-10-01 08:24 23,864 ----a-w C:\WINDOWS\system32\drivers\sskbfd.sys
2007-10-01 08:24 21,816 ----a-w C:\WINDOWS\system32\drivers\sshrmd.sys
2007-10-01 08:24 163,640 ----a-w C:\WINDOWS\system32\drivers\ssidrv.sys
2007-09-29 12:45 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-29 12:26 --------- d-----w C:\Documents and Settings\Dan\Application Data\SpinTop
2007-09-29 12:25 94,208 ----a-w C:\WINDOWS\system32\ScrUnZip.dll
2007-09-29 12:25 908,716 ----a-w C:\WINDOWS\system32\GFC 2006.SCR
2007-09-29 12:25 129,536 ----a-w C:\WINDOWS\system32\IJL15.dll
2007-09-29 10:54 --------- d-----w C:\Program Files\ChaosAbout100
2007-09-28 16:08 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-09-28 16:07 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-09-28 16:07 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-09-28 16:07 532,480 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-09-28 16:07 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-09-28 16:07 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-09-28 16:07 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-09-28 16:07 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-09-28 16:07 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-09-28 16:07 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-09-28 16:07 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-09-28 16:05 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-28 16:05 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-28 16:05 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-09-28 16:05 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-28 16:05 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-09-28 16:05 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-09-28 16:05 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-09-28 16:05 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-09-28 16:05 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-09-28 16:05 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-09-28 16:05 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-09-28 16:05 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-09-28 16:05 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-09-28 13:23 --------- d-----w C:\Documents and Settings\Dan\Application Data\Talkback
2007-09-28 09:31 --------- d-----w C:\Program Files\iPod
2007-09-26 06:42 58,792 ----a-w C:\WINDOWS\system32\wbload.dll
2007-09-22 12:41 --------- d-----w C:\Program Files\LemonCord
2007-09-22 09:23 --------- d-----w C:\Program Files\Desktop Icon Toy
2007-09-15 03:36 --------- d-----w C:\Program Files\Styler
2007-09-14 12:26 --------- d-----w C:\Program Files\finexer
2007-09-14 12:11 --------- d-----w C:\Documents and Settings\Dan\Application Data\AveDesk
2007-09-14 12:04 --------- d-----w C:\Documents and Settings\Dan\Application Data\FindeXer
2007-09-14 11:32 --------- d-----w C:\Documents and Settings\Dan\Application Data\Styler
2007-09-14 09:46 --------- d-----w C:\Program Files\avedesk13
2007-09-14 09:16 --------- d-----w C:\Program Files\YzShadow
2007-09-14 09:16 --------- d-----w C:\Program Files\WinRoll
2007-09-14 09:16 --------- d-----w C:\Program Files\UberIcon
2007-09-14 09:16 --------- d-----w C:\Program Files\Tiger System Preferences v2
2007-09-02 07:27 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2007-08-27 09:47 7,852 ----a-w C:\WINDOWS\system32\mcdmsg7.dll
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-02 09:48 92,064 ----a-w C:\Documents and Settings\Dan\mqdmmdm.sys
2007-08-02 09:48 9,232 ----a-w C:\Documents and Settings\Dan\mqdmmdfl.sys
2007-08-02 09:48 79,328 ----a-w C:\Documents and Settings\Dan\mqdmserd.sys
2007-08-02 09:48 66,656 ----a-w C:\Documents and Settings\Dan\mqdmbus.sys
2007-08-02 09:48 6,208 ----a-w C:\Documents and Settings\Dan\mqdmcmnt.sys
2007-08-02 09:48 5,936 ----a-w C:\Documents and Settings\Dan\mqdmwhnt.sys
2007-08-02 09:48 4,048 ----a-w C:\Documents and Settings\Dan\mqdmcr.sys
2007-08-02 09:48 25,600 ----a-w C:\Documents and Settings\Dan\usbsermptxp.sys
2007-08-02 09:48 22,768 ----a-w C:\Documents and Settings\Dan\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{264426f7-9772-43c1-a02e-14bcb29bda36}]
2007-11-05 15:27 83008 --a------ C:\WINDOWS\system32\wqridibx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{320635D7-379D-48C3-B183-ABD0C4B20E69}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C87FA4A3-2474-4a3f-B413-67D515905024}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ImageShackUtil"="C:\Program Files\ImageShack\QuickShot\QuickShot.exe" []
"Webroot Desktop Firewall"="C:\Program Files\Webroot\Desktop Firewall\WDF.exe" [2007-10-20 13:20]
"System Files Updater"="C:\WINDOWS\FlyakiteOSX\System Files Updater.exe" [2006-01-15 15:31]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 04:43]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-06-30 14:33]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 07:24]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 21:15]
"LogonStudio"="C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-03 19:38]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 16:44 C:\WINDOWS\KHALMNPR.Exe]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 15:42]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 00:12]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 17:54]
"d0ed3d80"="rundll32.exe" [2004-08-12 23:04 C:\WINDOWS\system32\rundll32.exe]
"BootSkin Startup Jobs"="C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" [2004-04-26 17:21]
"Windows Logon Application"="C:\WINDOWS\system32\logon.exe" [2007-06-13 19:23]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"Windows Explorer"="C:\WINDOWS\system32\explorer.exe" []
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 17:40]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 01:24]
"DesktopIconToy"="C:\Program Files\Desktop Icon Toy\DesktopIconToy.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 22:56]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll 2005-01-31 16:13 49152 C:\PROGRA~1\COMMON~1\Stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~2\WINDOW~1\wbsrv.dll 2007-09-24 20:08 229376 C:\PROGRA~1\Stardock\OBJECT~2\WINDOW~1\WbSrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup"
.
Contents of the 'Scheduled Tasks' folder
"2007-09-11 09:52:20 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-12 08:00:22 C:\WINDOWS\Tasks\wrSpySweeper_L5D90EFAFC01D49D88C2490292CB7F309.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-14 16:02:26
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-14 16:04:12
.
--- E O F ---