ComboFix 08-01-16.1 - Compaq_Administrator 2008-01-17 14:12:38.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.489 [GMT -4:00]
Running from: C:\Documents and Settings\Compaq_Administrator\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
/wow section - STAGE 7
/wow section - STAGE 8
/wow section - STAGE 10
/wow section - STAGE 30A
/wow section - STAGE 31
/wow section - STAGE 33
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\basesrv.dll
.
((((((((((((((((((((((((( Files Created from 2007-12-17 to 2008-01-17 )))))))))))))))))))))))))))))))
.
2008-01-17 14:06 . 2000-08-31 08:00 51,200 --a--c--- C:\WINDOWS\NirCmd.exe
2008-01-15 19:48 . 2008-01-15 19:48 <DIR> d----c--- C:\Program Files\Windows Installer Clean Up
2008-01-15 19:48 . 2008-01-15 19:48 <DIR> d----c--- C:\Program Files\MSECACHE
2008-01-15 14:09 . 2008-01-17 01:23 <DIR> d----c--- C:\Program Files\Norton 360
2008-01-15 14:07 . 2008-01-16 16:44 <DIR> d----c--- C:\Program Files\Symantec
2008-01-15 14:07 . 2008-01-15 14:11 115,000 --a--c--- C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-15 14:07 . 2008-01-15 14:11 48,776 --a--c--- C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-15 14:06 . 2008-01-17 01:24 <DIR> d----c--- C:\Program Files\Common Files\Symantec Shared
2008-01-15 13:58 . 2008-01-17 14:20 <DIR> d-a--c--- C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-15 13:14 . 2008-01-16 22:35 <DIR> d----c--- C:\Program Files\Spyware Doctor
2008-01-15 13:14 . 2008-01-15 13:14 <DIR> d----c--- C:\Documents and Settings\Compaq_Administrator\Application Data\PC Tools
2008-01-15 13:14 . 2008-01-15 13:14 74,240 --a--c--- C:\WINDOWS\system32\drivers\iksyssec.sys
2008-01-15 13:14 . 2008-01-15 13:14 56,832 --a--c--- C:\WINDOWS\system32\drivers\iksysflt.sys
2008-01-15 13:14 . 2007-10-18 00:14 41,288 --a--c--- C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-01-15 13:14 . 2007-10-18 00:16 29,000 --a--c--- C:\WINDOWS\system32\drivers\kcom.sys
2008-01-15 12:09 . 2008-01-15 13:16 51,355 --a--c--- C:\WINDOWS\system32\muzika.xm
2008-01-15 11:22 . 2007-09-24 23:31 69,632 --a--c--- C:\WINDOWS\system32\javacpl.cpl
2008-01-15 11:20 . 2008-01-15 11:20 15,852,952 --a--c--- C:\Program Files\jre-6u4-windows-i586-p.exe
2008-01-15 11:19 . 2008-01-15 11:20 <DIR> d----c--- C:\Documents and Settings\Compaq_Administrator\.SunDownloadManager
2008-01-15 01:02 . 2008-01-15 07:09 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-01-15 00:29 . 2008-01-15 00:29 2,154 --a--c--- C:\WINDOWS\system32\tmmute.ini
2008-01-15 00:27 . 2008-01-15 00:27 <DIR> d----c--- C:\Program Files\CCleaner
2008-01-13 14:10 . 2008-01-13 14:10 <DIR> d----c--- C:\WINDOWS\system32\Kaspersky Lab
2008-01-13 14:10 . 2008-01-13 14:10 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-12 15:25 . 2008-01-15 07:09 <DIR> d----c--- C:\Program Files\Trend Micro
2008-01-12 15:22 . 2008-01-12 20:29 <DIR> d----c--- C:\Documents and Settings\Compaq_Administrator\Application Data\HouseCall 6.6
2008-01-12 13:48 . 2008-01-12 13:48 <DIR> d----c--- C:\WINDOWS\RegistryBooster 2
2008-01-12 13:48 . 2008-01-12 13:48 <DIR> d----c--- C:\Program Files\RegistryBooster 2
2008-01-12 12:31 . 2008-01-12 21:38 <DIR> d----c--- C:\Program Files\Uniblue
2008-01-12 12:31 . 2008-01-12 21:38 <DIR> d----c--- C:\Documents and Settings\Compaq_Administrator\Application Data\Uniblue
2008-01-12 12:31 . 2008-01-12 12:31 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Uniblue
2008-01-11 17:03 . 2008-01-11 17:03 268 --ah-c--- C:\sqmdata06.sqm
2008-01-11 17:03 . 2008-01-11 17:03 244 --ah-c--- C:\sqmnoopt06.sqm
2008-01-10 12:23 . 2008-01-10 17:01 512 --a--c--- C:\drmHeader.bin
2008-01-09 12:18 . 2008-01-09 12:18 268 --ah-c--- C:\sqmdata05.sqm
2008-01-09 12:18 . 2008-01-09 12:18 244 --ah-c--- C:\sqmnoopt05.sqm
2008-01-09 08:59 . 2008-01-09 08:59 268 --ah-c--- C:\sqmdata04.sqm
2008-01-09 08:59 . 2008-01-09 08:59 244 --ah-c--- C:\sqmnoopt04.sqm
2008-01-07 00:17 . 2008-01-07 00:17 268 --ah-c--- C:\sqmdata03.sqm
2008-01-07 00:17 . 2008-01-07 00:17 244 --ah-c--- C:\sqmnoopt03.sqm
2008-01-07 00:13 . 2008-01-07 00:13 268 --ah-c--- C:\sqmdata02.sqm
2008-01-07 00:13 . 2008-01-07 00:13 244 --ah-c--- C:\sqmnoopt02.sqm
2008-01-06 22:42 . 2008-01-06 22:42 <DIR> d----c--- C:\Documents and Settings\Compaq_Administrator\Application Data\???????sAppData
2008-01-06 13:31 . 2008-01-06 13:31 <DIR> d----c--- C:\Program Files\Common Files\EasyInfo
2008-01-06 11:12 . 2008-01-06 11:12 <DIR> d----c--- C:\Program Files\Electronic Arts
2007-12-22 12:04 . 2007-12-22 12:04 <DIR> d----c--- C:\Documents and Settings\Compaq_Administrator\Application Data\Sony Corporation
2007-12-20 14:53 . 2007-12-20 14:57 <DIR> d----c--- C:\Documents and Settings\Compaq_Administrator\Application Data\DAEMON Tools
2007-12-20 14:52 . 2007-12-20 14:53 <DIR> d----c--- C:\Program Files\DAEMON Tools Lite
2007-12-19 22:27 . 2007-12-19 22:27 715,248 --a--c--- C:\WINDOWS\system32\drivers\sptd.sys
2007-12-19 11:27 . 2007-12-19 11:27 <DIR> d----c--- C:\My Recorder
2007-12-19 11:27 . 2007-12-19 11:27 194 --a--c--- C:\WINDOWS\WAVrj.ini
2007-12-19 11:26 . 2007-12-19 11:26 <DIR> d----c--- C:\Program Files\HiFisoftware
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-17 18:19 --------- dc----w C:\Documents and Settings\Compaq_Administrator\Application Data\uTorrent
2008-01-17 05:23 --------- dc----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-17 04:40 22,328 -c--a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-17 04:40 107,832 -c--a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-01-15 18:11 806 -c--a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-15 18:11 8,014 -c--a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-15 15:22 --------- dc----w C:\Program Files\Java
2008-01-15 10:49 --------- dc----w C:\Documents and Settings\Compaq_Administrator\Application Data\MegauploadToolbar
2008-01-15 04:26 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-13 17:39 --------- dc----w C:\Program Files\Return to Castle Wolfenstein
2008-01-13 01:45 --------- dc----w C:\Program Files\eMule
2008-01-12 20:01 --------- dc----w C:\Program Files\Call of Duty
2008-01-12 00:18 --------- dc----w C:\Program Files\Registry Repair
2008-01-09 12:45 --------- dc----w C:\Documents and Settings\Compaq_Administrator\Application Data\Ahead
2008-01-09 12:45 --------- dc----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-01-09 12:00 --------- dc----w C:\Program Files\Total Video Converter
2008-01-07 21:38 --------- dc----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-07 02:42 --------- dc----w C:\Documents and Settings\Compaq_Administrator\Application Data\???????sAppData
2008-01-06 15:12 --------- dc-h--w C:\Program Files\InstallShield Installation Information
2007-12-22 18:17 --------- dc----w C:\Documents and Settings\Compaq_Administrator\Application Data\Skype
2007-12-19 15:19 --------- dc----w C:\Program Files\Mp3 My Mp3 2.0
2007-12-14 23:49 --------- dc----w C:\Program Files\DVD Shrink
2007-12-13 17:21 3,186 -c--a-w C:\WINDOWS\system32\tmp.reg
2007-12-13 05:47 --------- dc----w C:\Program Files\MegauploadToolbar
2007-12-07 19:13 --------- dc----w C:\Program Files\Activision
2007-12-07 17:29 --------- dc----w C:\Program Files\Raven
2007-12-07 03:07 --------- dc----w C:\Program Files\DivX
2007-12-06 14:33 --------- dc----w C:\Program Files\GameShadow
2007-12-06 14:23 98,304 -c--a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-12-06 14:09 --------- dc----w C:\Program Files\Eidos
2007-12-04 20:37 --------- dc----w C:\Documents and Settings\Compaq_Administrator\Application Data\vlc
2007-12-04 20:36 --------- dc----w C:\Program Files\VideoLAN
2007-12-04 01:33 823,296 -c--a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-12-04 01:33 823,296 -c--a-w C:\WINDOWS\system32\divx_xx07.dll
2007-12-04 01:33 802,816 -c--a-w C:\WINDOWS\system32\divx_xx11.dll
2007-12-04 01:33 682,496 -c--a-w C:\WINDOWS\system32\DivX.dll
2007-12-03 14:26 --------- dc----w C:\Program Files\Common Files\Ahead
2007-12-03 14:25 --------- dc----w C:\Documents and Settings\All Users\Application Data\Nero
2007-11-30 03:36 520,192 -c--a-w C:\WINDOWS\system32\hitman_ss.scr
2007-11-29 22:30 200,704 -c--a-w C:\WINDOWS\system32\ssldivx.dll
2007-11-29 22:30 1,044,480 -c--a-w C:\WINDOWS\system32\libdivx.dll
2007-11-29 22:28 81,920 -c--a-w C:\WINDOWS\system32\dpl100.dll
2007-11-29 22:28 196,608 -c--a-w C:\WINDOWS\system32\dtu100.dll
2007-11-28 21:55 156,992 -c--a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 21:53 593,920 -c--a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-11-28 21:53 57,344 -c--a-w C:\WINDOWS\system32\dpv11.dll
2007-11-28 21:53 53,248 -c--a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-11-28 21:53 344,064 -c--a-w C:\WINDOWS\system32\dpus11.dll
2007-11-28 21:53 294,912 -c--a-w C:\WINDOWS\system32\dpu11.dll
2007-11-28 21:53 294,912 -c--a-w C:\WINDOWS\system32\dpu10.dll
2007-11-28 21:52 12,288 -c--a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-11-23 16:42 --------- dc----w C:\Documents and Settings\Compaq_Administrator\Application Data\Image Zone Express
2007-11-23 03:45 --------- dc----w C:\Program Files\UnH Solutions
2007-11-13 05:39 33,540 -c--a-w C:\WINDOWS\system32\CoreFLACDecoder-uninstall.exe
2007-11-07 09:26 721,920 -c----w C:\WINDOWS\system32\lsasrv.dll
2007-10-31 17:17 54,824 -c--a-w C:\WINDOWS\agrsmdel.exe
2007-10-29 22:35 1,287,680 -c--a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 21:40 222,720 -c--a-w C:\WINDOWS\system32\wmasf.dll
2007-10-25 07:57 16,855,552 -c--a-w C:\WINDOWS\RTHDCPL.EXE
2007-10-19 04:04 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-10-19 01:51 163,206 -c--a-w C:\WINDOWS\Audio Converter Pro Uninstaller.exe
2007-10-19 00:43 315,392 -c--a-w C:\WINDOWS\HideWin.exe
2007-10-18 15:31 51,224 -c--a-w C:\WINDOWS\system32\sirenacm.dll
2006-02-19 17:28 12,288 -c--a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 00:00 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 19:03 152872]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2005-08-18 09:15 1359872]
"Uniblue RegistryBooster 2"="C:\Program Files\RegistryBooster 2\RegistryBooster.exe" [2007-10-08 16:26 1863960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-30 00:01 67584]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 02:19 77312 C:\WINDOWS\arpwrmsg.exe]
"DISCover"="C:\Program Files\DISC\DISCover.exe" [2006-03-16 05:12 1077248]
"DiscUpdateManager"="C:\Program Files\DISC\DiscUpdMgr.exe" [2006-03-16 05:11 61440]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-23 01:14 237568]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 01:34 249856]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 15:24 54840]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51 39792]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 02:50 221184]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 15:44 61440]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-09 21:50 7311360]
"nwiz"="nwiz.exe" [2006-05-09 21:50 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-05-09 21:50 86016]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-25 03:57 16855552 C:\WINDOWS\RTHDCPL.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24 1065800]
C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-05-25 14:46:52]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe [2006-05-25 15:35:02]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TP CfgWiz"="C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\SymCuw.exe" -G:{2D617065-1C52-4240-B5BC-C0AE12157777} -T:Config
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-01-13 01:38:42 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-01-13 01:38:41 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-01-12 16:47:47 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2007-10-18 23:38:44 C:\WINDOWS\Tasks\Warranty Reminder 11 month.job"
- c:\windows\system32\pcintro\reminder\Warranty_Reminder_11_month\Warranty_Reminder_11_month.bat
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-17 14:21:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\csrss.exe
-> C:\WINDOWS\system32\basesrv.dll
.
Completion time: 2008-01-17 14:22:51 - machine was rebooted [Compaq_Administrator]
ComboFix-quarantined-files.txt 2008-01-17 18:22:49
.
2008-01-09 16:04:10 --- E O F ---