latest logs
as requested
O4 - HKCU\..\Run: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
noticed this line in the hjt log in the 04's which you said was the start up files... it looks suspicious and have checked and deleted the programme aleady ....can this line be deleted???
ComboFix 08-03-26.3 - Mark 2008-03-31 8:53:06.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.188 [GMT 1:00]
Running from: C:\Documents and Settings\Mark\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mark\Desktop\CFscript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\Motive\btbb\pskill.exel
.
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-31 )))))))))))))))))))))))))))))))
.
2008-03-22 22:36 . 2008-03-22 22:36 <DIR> d-------- C:\Documents and Settings\Mark\Application Data\Malwarebytes
2008-03-22 22:35 . 2008-03-22 22:36 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-22 22:35 . 2008-03-22 22:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-22 18:02 . 2008-03-30 14:59 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-03-22 18:02 . 2008-03-30 14:15 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-03-22 18:02 . 2008-03-30 14:15 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-03-20 17:59 . 2008-03-29 22:31 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-03-18 20:53 . 2008-02-22 03:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-18 20:51 . 2008-03-18 20:51 <DIR> d-------- C:\Program Files\Common Files\Java
2008-03-15 16:41 . 2008-03-30 14:48 <DIR> d-------- C:\Program Files\Windows Defender
2008-03-15 11:37 . 2008-03-15 11:37 244 --ah----- C:\sqmnoopt19.sqm
2008-03-15 11:37 . 2008-03-15 11:37 232 --ah----- C:\sqmdata19.sqm
2008-03-15 11:36 . 2008-03-15 11:36 244 --ah----- C:\sqmnoopt18.sqm
2008-03-15 11:36 . 2008-03-15 11:36 232 --ah----- C:\sqmdata18.sqm
2008-03-15 11:32 . 2008-03-15 11:32 244 --ah----- C:\sqmnoopt17.sqm
2008-03-15 11:32 . 2008-03-15 11:32 232 --ah----- C:\sqmdata17.sqm
2008-03-07 15:03 . 2008-03-07 15:03 625,032 --a------ C:\WINDOWS\system32\SymNeti.dll
2008-03-07 15:03 . 2008-03-07 15:03 242,056 --a------ C:\WINDOWS\system32\SymRedir.dll
2008-03-07 14:40 . 2008-03-07 14:40 13,035 --a------ C:\WINDOWS\system32\drivers\SymRedir.cat
2008-03-07 14:40 . 2008-03-07 14:40 1,358 --a------ C:\WINDOWS\system32\drivers\SymRedir.inf
2008-03-07 14:39 . 2008-03-07 14:39 191,536 --a------ C:\WINDOWS\system32\drivers\symtdi.sys
2008-03-07 14:39 . 2008-03-07 14:39 145,968 --a------ C:\WINDOWS\system32\drivers\symfw.sys
2008-03-07 14:39 . 2008-03-07 14:39 39,984 --a------ C:\WINDOWS\system32\drivers\symids.sys
2008-03-07 14:39 . 2008-03-07 14:39 37,936 --a------ C:\WINDOWS\system32\drivers\symndisv.sys
2008-03-07 14:39 . 2008-03-07 14:39 35,120 --a------ C:\WINDOWS\system32\drivers\symndis.sys
2008-03-07 14:39 . 2008-03-07 14:39 27,696 --a------ C:\WINDOWS\system32\drivers\symredrv.sys
2008-03-07 14:39 . 2008-03-07 14:39 12,848 --a------ C:\WINDOWS\system32\drivers\symdns.sys
2008-03-03 23:55 . 2008-03-03 23:58 <DIR> d-------- C:\Program Files\Windows Live
2008-03-03 23:55 . 2008-03-03 23:57 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-03 23:54 . 2008-03-03 23:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-03 23:34 . 2008-03-06 22:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-03 23:34 . 2008-03-06 22:32 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-03-03 23:34 . 2008-03-06 22:32 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-03 14:39 . 2008-03-03 15:10 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-03 14:39 . 2008-03-03 15:10 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-03-03 14:38 . 2008-03-30 14:48 <DIR> d-------- C:\Program Files\Symantec
2008-03-03 14:38 . 2008-03-25 00:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-03 14:37 . 2008-03-31 01:01 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-02-27 13:20 . 2008-02-27 13:20 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-27 10:19 . 2008-02-27 10:19 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-27 10:19 . 2008-02-27 10:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-22 21:46 . 2008-02-22 22:21 419 --a------ C:\WINDOWS\wininit.ini
2008-02-22 21:12 . 2008-03-30 14:48 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-22 21:12 . 2008-02-22 21:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-22 20:20 . 2008-02-22 20:28 <DIR> d-------- C:\Documents and Settings\Mark\Application Data\RegSweep
2008-02-19 11:33 . 2008-02-19 11:33 <DIR> d-------- C:\Program Files\Motive
2008-02-19 11:33 . 2008-02-19 11:35 <DIR> d-------- C:\Program Files\BT Broadband Desktop Help
2008-02-14 18:15 . 2008-02-14 18:15 268 --ah----- C:\sqmdata16.sqm
2008-02-14 18:15 . 2008-02-14 18:15 244 --ah----- C:\sqmnoopt16.sqm
2008-02-14 01:07 . 2008-02-14 01:15 16 --a------ C:\WINDOWS\system32\coh.cache
2008-02-14 00:48 . 2008-03-03 15:10 10,740 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-14 00:48 . 2008-03-03 15:10 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-11 10:40 . 2008-02-11 10:40 2,715,648 --a------ C:\WINDOWS\system32\OnlineScanner.ocx
2008-02-11 10:39 . 2008-02-11 10:39 253,952 --a------ C:\WINDOWS\system32\OnlineScannerDLLA.dll
2008-02-11 10:39 . 2008-02-11 10:39 237,568 --a------ C:\WINDOWS\system32\OnlineScannerDLLW.dll
2008-02-08 14:53 . 2008-02-08 14:53 110,592 --a------ C:\WINDOWS\system32\OnlineScannerLang.dll
2008-02-05 09:48 . 2008-02-05 09:48 77,824 --a------ C:\WINDOWS\system32\OnlineScannerUninstaller.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-30 13:40 --------- d-----w C:\Program Files\BT Broadband Talk Softphone
2008-03-30 13:39 --------- d-----w C:\Program Files\BT Auto Backup
2008-03-30 13:18 --------- d-----w C:\Program Files\AC3Filter
2008-03-30 13:07 --------- d-----w C:\Documents and Settings\Mark\Application Data\Skype
2008-03-30 12:53 --------- d-----w C:\Documents and Settings\Mark\Application Data\skypePM
2008-03-29 16:38 --------- d-----w C:\Documents and Settings\Mark\Application Data\LimeWire
2008-03-26 14:24 --------- d-----w C:\Program Files\QuickTime
2008-03-26 14:10 --------- d-----w C:\Program Files\Common Files\Motive
2008-03-26 14:09 --------- d-----w C:\Program Files\btbb_wcm
2008-03-22 22:03 --------- d-----w C:\Program Files\MSN Messenger
2008-03-21 10:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Motive
2008-03-18 19:53 --------- d-----w C:\Program Files\Java
2008-03-03 16:29 --------- d-----w C:\Program Files\Microsoft Works
2008-03-03 13:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-02-26 18:46 61,480 ----a-w C:\Documents and Settings\Mark\GoToAssistDownloadHelper.exe
2008-02-19 10:41 --------- d-----w C:\Documents and Settings\Mark\Application Data\Motive
2008-02-19 10:31 --------- d-----w C:\Program Files\BTHomeHub
2008-02-17 19:20 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-02-17 19:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-02-15 22:54 --------- d-----w C:\Program Files\Google
2008-02-15 20:10 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-13 00:14 --------- d-----w C:\Program Files\LimeWire
2008-02-13 00:13 --------- d-----w C:\Documents and Settings\Mark\Application Data\uTorrent
2008-02-06 00:58 --------- d-----w C:\Program Files\DivX
2008-02-06 00:47 --------- d-----w C:\Documents and Settings\Mark\Application Data\Microgaming
2008-02-05 10:05 --------- d-----w C:\Program Files\PKR
2008-01-04 21:59 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-01-04 21:58 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-01-04 21:58 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-01-04 21:58 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-01-04 21:57 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-01-04 21:57 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-01-04 21:57 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-01-04 21:57 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-01-04 21:57 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-01-04 21:57 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-01-04 21:57 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-01-04 21:57 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-01-04 21:57 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-01-04 21:57 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-01-04 21:57 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-01-04 21:57 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-01-04 21:56 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-01-04 21:56 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-12-22 17:19 557,056 ----a-w C:\Documents and Settings\Mark\GoToAssist_phone__319_en.exe
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-11-28 17:55 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((( snapshot@2008-03-28_11.20.27.53 )))))))))))))))))))))))))))))))))))))))))
.
- 2000-08-31 08:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2000-08-31 07:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2006-12-18 15:36:36 312,840 ----a-w C:\WINDOWS\KingComIE.dll
- 2000-08-31 08:00:00 28,160 ----a-w C:\WINDOWS\Nircmd.exe
+ 2000-08-31 07:00:00 28,160 ----a-w C:\WINDOWS\Nircmd.exe
- 2008-02-19 14:26:49 63,528 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-03-30 12:15:25 63,644 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-02-19 14:26:49 406,328 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-30 12:15:25 406,636 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2000-08-31 08:00:00 161,792 ----a-w C:\WINDOWS\system32\swreg.exe
+ 2000-08-31 07:00:00 161,792 ----a-w C:\WINDOWS\system32\swreg.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 13:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"BTAgile"="C:\Program Files\BT Broadband Talk Softphone\BTAgile.exe" [2007-06-18 10:39 61440]
"SRS Audio Sandbox"="C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdslTaskBar"="stmctrl.dll" [2004-08-27 09:20 167936 C:\WINDOWS\system32\stmctrl.dll]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2006-02-28 13:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-02-12 16:57 188416]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-02-12 16:59 77824]
"OlStatusMon"="C:\Program Files\Olivetti\ANY_WAY\olDvcStatus.exe" [2006-01-03 15:23 94208]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 17:19 129536]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 06:59 115816]
"osCheck"="C:\PROGRA~1\Symantec\osCheck.exe" [2007-01-14 08:11 771704]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 20:20 866584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-02-28 13:00 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BT Broadband Desktop Help.lnk - C:\Program Files\BT Broadband Desktop Help\bin\matcli.exe [2008-02-19 11:33:24 217088]
BTTray.lnk - C:\Program Files\Sitecom\Bluetooth Software\BTTray.exe [2004-10-01 15:12:18 565309]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YOP]
--a------ 2007-06-26 14:48 509224 C:\PROGRA~1\Yahoo!\YOP\yop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\BT Broadband Talk Softphone\\BTSoftphone.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2004-07-06 13:28]
R3 TaurusPci;ADSL Modem PCI Service;C:\WINDOWS\system32\DRIVERS\toruspci.sys [2004-08-25 11:10]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-03-31 00:58:51 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-03-30 11:46:02 C:\WINDOWS\Tasks\Norton Security Online - Run Full System Scan - Mark.job"
- C:\PROGRA~1\Symantec\Norton AntiVirus\Navw32.exeh/TASK:
"2008-02-24 18:34:13 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-31 08:57:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-03-31 9:00:12
ComboFix-quarantined-files.txt 2008-03-31 07:59:05
ComboFix2.txt 2008-03-29 11:13:38
ComboFix3.txt 2008-03-28 11:21:40
Pre-Run: 65,845,411,840 bytes free
Post-Run: 67,315,023,872 bytes free
.
2008-03-27 22:46:35 --- E O F ---