ComboFix 08-01-11.1 - Jonathan 2008-01-11 16:01:26.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1590 [GMT -5:00]
Running from: C:\Documents and Settings\Jonathan\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-12-11 to 2008-01-11 )))))))))))))))))))))))))))))))
.
2008-01-11 16:00 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-11 02:13 . 2008-01-11 02:13 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-10 23:32 . 2008-01-10 23:32 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-10 23:32 . 2008-01-10 23:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-28 16:45 . 2007-12-28 16:55 <DIR> d-------- C:\RegSearch
2007-12-26 18:43 . 2007-12-26 18:47 <DIR> d-------- C:\Documents and Settings\Jonathan\Application Data\Roxio
2007-12-26 18:42 . 2007-12-26 18:42 <DIR> d-------- C:\Program Files\InterActual
2007-12-26 18:39 . 2007-12-26 18:40 <DIR> d-------- C:\WINDOWS\system32\DLA
2007-12-26 18:39 . 2007-03-12 01:25 99,848 --a------ C:\WINDOWS\system32\drivers\DRVMCDB.SYS
2007-12-26 18:39 . 2007-03-13 16:13 92,920 --a------ C:\WINDOWS\DLA.EXE
2007-12-26 18:39 . 2007-03-13 16:13 56,056 --a------ C:\WINDOWS\system32\DLAAPI_W.DLL
2007-12-26 18:39 . 2007-02-09 12:34 51,768 --a------ C:\WINDOWS\system32\drivers\DRVNDDM.SYS
2007-12-26 18:39 . 2007-02-08 20:05 28,120 --a------ C:\WINDOWS\system32\drivers\DLARTL_M.SYS
2007-12-26 18:39 . 2007-02-08 20:05 12,856 --a------ C:\WINDOWS\system32\drivers\DLACDBHM.SYS
2007-12-26 18:38 . 2007-12-26 18:38 <DIR> d-------- C:\Program Files\Common Files\SureThing Shared
2007-12-26 18:37 . 2007-12-26 18:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sonic
2007-12-26 18:35 . 2007-12-26 18:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Roxio
2007-12-26 18:34 . 2007-12-26 18:39 <DIR> d-------- C:\Program Files\Roxio
2007-12-26 18:34 . 2007-12-26 18:38 <DIR> d-------- C:\Program Files\Common Files\Sonic Shared
2007-12-26 18:34 . 2007-12-26 18:34 <DIR> d-------- C:\Program Files\Common Files\Roxio Shared
2007-12-26 16:17 . 2007-12-26 16:17 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-12-26 16:10 . 2007-07-09 08:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-12-26 15:58 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2007-12-26 15:58 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2007-12-26 15:58 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2007-12-26 15:58 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2007-12-24 22:28 . 2007-12-31 18:37 430 --a------ C:\WINDOWS\asfbinapp.INI
2007-12-24 17:29 . 2008-01-10 20:40 <DIR> d-------- C:\Documents and Settings\Jonathan\Application Data\Winff
2007-12-24 06:26 . 2007-12-24 06:26 0 --a------ C:\winamp.ini
2007-12-24 02:52 . 2007-12-24 02:52 <DIR> d-------- C:\WINDOWS\ERUNT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-11 20:56 --------- d-----w C:\Documents and Settings\Jonathan\Application Data\Azureus
2008-01-10 02:38 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-09 06:04 --------- d-----w C:\Documents and Settings\Jonathan\Application Data\uTorrent
2008-01-01 01:26 --------- d-----w C:\Documents and Settings\Jonathan\Application Data\DVD Flick
2007-12-26 23:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-26 21:48 359,808 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2007-12-24 11:51 --------- d-----w C:\Program Files\VERITAS Software
2007-12-24 07:14 --------- d-----w C:\Program Files\Sony
2007-12-24 05:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-19 23:23 --------- d-----w C:\Program Files\Norton AntiVirus
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-05-10 00:34 47,360 ----a-w C:\Documents and Settings\Jonathan\Application Data\pcouffin.sys
2007-03-23 03:39 87,608 ----a-w C:\Documents and Settings\Jonathan\Application Data\ezpinst.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ProtoWall"="C:\Program Files\Dudez\ProtoWall\ProtoWall.exe" [2005-01-27 05:55 741376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2003-03-03 21:44 323584 C:\WINDOWS\system32\nwiz.exe]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 00:08 28672]
"Logitech Utility"="Logi_MwX.Exe" [2003-03-04 04:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-06-05 16:34 2352352]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-02-17 10:05 59040]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-10-20 20:07 100056]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 12:29 40960]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2004-01-05 02:27 176128]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 16:28 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 07:38 241664]
"SNPSTD2"="C:\WINDOWS\vsnpstd2.exe" [2004-01-05 17:34 40960]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"DMXLauncher"="C:\Program Files\Roxio\Media Experience\DMXLauncher.exe" [2007-02-12 03:24 109304]
"RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2007-03-13 09:05 1116920]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 04:19:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ATIModeChange"=Ati2mdxx.exe
"IgfxTray"=C:\WINDOWS\System32\igfxtray.exe
"PCDRealtime"=C:\WINDOWS\realtime.exe
"RoxioAudioCentral"="C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
"HPDJ Taskbar Utility"=C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
"AGRSMMSG"=AGRSMMSG.exe
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
"RoxioDragToDisc"=C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
"DeadAIM"=rundll32.exe "D:\Programs\Aim\\DeadAIM.ocm",ExportedCheckODLs
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe
"ZTgServerSwitch"=c:\program files\support.com\client\lserver\server.vbs
R1 bbcap;bbcap;C:\WINDOWS\system32\DRIVERS\bbcap.sys [2005-07-08 05:14]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05]
R3 ProtoWall;ProtoWall Network Service;C:\WINDOWS\system32\DRIVERS\ProtoWall.sys [2004-08-12 10:29]
S3 snpstd2;USB PC Camera (SN9C103);C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-03-22 20:31]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-05 05:18:20 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Jonathan.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
"2006-09-20 13:00:23 C:\WINDOWS\Tasks\Wake Up Mix (Vol 1).job"
- D:\Music\Ripped\My Playlists\Wake Up Mix (Vol 2) 50 Cent Edition.wpl
"2006-09-13 16:30:36 C:\WINDOWS\Tasks\Wake Up Mix 2.job"
- D:\Music\Ripped\My Playlists\Wake Up Mix (Vol 1).wpl
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-11 16:05:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-11 16:08:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-11 21:08:26
So one thing I noticed is this:
"DeadAIM"=rundll32.exe "D:\Programs\Aim\\DeadAIM.ocm",ExportedCheckODLs
But I do not have this on my computer anymore could this be causing the problem?