ComboFix 07-10-17.8@ - Administrator 2007-10-19 20:38:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.650 [GMT -4:00]
Running from: C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\winpop
.
((((((((((((((((((((((((( Files Created from 2007-09-20 to 2007-10-20 )))))))))))))))))))))))))))))))
.
2007-10-19 20:37 51,200 --a------ C:\WINDOWS.0\NirCmd.exe
2007-10-19 01:23 212 --a------ C:\delete.bat
2007-10-10 22:20 112,840 --a------ C:\WINDOWS.0\system32\drivers\msfwhlpr.sys
2007-10-10 22:20 88,008 --a------ C:\WINDOWS.0\system32\drivers\msfwdrv.sys
2007-10-09 15:53 582,656 -----c--- C:\WINDOWS.0\system32\dllcache\rpcrt4.dll
2007-10-08 15:51 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Google Updater
2007-10-08 14:34 459,264 -----c--- C:\WINDOWS.0\system32\dllcache\msfeeds.dll
2007-10-08 14:34 267,776 -----c--- C:\WINDOWS.0\system32\dllcache\iertutil.dll
2007-10-08 14:34 52,224 -----c--- C:\WINDOWS.0\system32\dllcache\msfeedsbs.dll
2007-10-08 14:34 13,824 -----c--- C:\WINDOWS.0\system32\dllcache\ieudinit.exe
2007-10-08 14:33 6,058,496 -----c--- C:\WINDOWS.0\system32\dllcache\ieframe.dll
2007-10-08 14:33 2,455,488 -----c--- C:\WINDOWS.0\system32\dllcache\ieapfltr.dat
2007-10-08 14:33 383,488 -----c--- C:\WINDOWS.0\system32\dllcache\ieapfltr.dll
2007-10-08 14:33 33,792 --a--c--- C:\WINDOWS.0\system32\dllcache\custsat.dll
2007-10-08 10:45 <DIR> d-------- C:\Program Files\draw up
2007-10-08 02:01 <DIR> d-------- C:\WINDOWS.0\system32\Kaspersky Lab
2007-10-08 02:01 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Kaspersky Lab
2007-10-08 01:40 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-05 13:31 <DIR> d-------- C:\Program Files\Free Audio Pack
2007-10-05 13:31 141,312 --a------ C:\WINDOWS.0\system32\MSCMCFR.DLL
2007-10-05 13:31 119,568 --a------ C:\WINDOWS.0\system32\VB6FR.DLL
2007-10-05 13:31 101,888 --a------ C:\WINDOWS.0\system32\VB6STKIT.DLL
2007-10-05 13:31 59,904 --a------ C:\WINDOWS.0\system32\Mscc2fr.dll
2007-10-05 13:31 32,768 --a------ C:\WINDOWS.0\system32\CMDLGFR.DLL
2007-10-05 13:31 21,504 --a------ C:\WINDOWS.0\system32\TABCTFR.DLL
2007-10-05 13:31 15,360 --a------ C:\WINDOWS.0\system32\inetfr.DLL
2007-10-04 23:11 <DIR> d-------- C:\WINDOWS.0\system32\ActiveScan
2007-10-04 22:26 <DIR> d-------- C:\Program Files\DivoCodec
2007-09-24 21:34 356,352 --ah----- C:\WINDOWS.0\system32\nvudisp.exe
2007-09-24 21:31 356,352 --a------ C:\WINDOWS.0\system32\NVUNINST.EXE
2007-09-24 21:16 <DIR> d-------- C:\WINDOWS.0\NV14884076.TMP
2007-09-24 21:04 <DIR> d-------- C:\WINDOWS.0\system32\AGEIA
2007-09-24 21:04 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-24 21:04 <DIR> d-------- C:\Program Files\AGEIA Technologies
2007-09-24 18:30 <DIR> d-------- C:\Program Files\Windows Live
2007-09-24 18:30 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS.0\Application Data\WLInstaller
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-19 23:33 --------- d-----w C:\Program Files\Steam
2007-10-19 23:08 0 ----a-w C:\WINDOWS.0\system32\drivers\lvuvc.hs
2007-10-19 21:14 --------- d-----w C:\Program Files\Java
2007-10-19 15:51 --------- d-----w C:\Program Files\Microsoft Windows OneCare Live
2007-10-19 15:44 --------- d-----w C:\Program Files\Google
2007-10-19 15:43 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2007-10-19 05:20 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\uTorrent
2007-10-19 05:20 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\uTorrent
2007-10-19 05:20 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\uTorrent
2007-10-18 01:22 --------- d-----w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Spybot - Search & Destroy
2007-10-17 21:57 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\dvdcss
2007-10-17 21:57 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\dvdcss
2007-10-17 21:57 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\dvdcss
2007-09-30 04:47 --------- d-----w C:\Program Files\World of Warcraft
2007-09-28 20:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-28 20:36 --------- d-----w C:\Program Files\Red Storm Entertainment
2007-09-25 00:57 --------- d-----w C:\Program Files\Ubisoft
2007-09-24 22:36 --------- d-----w C:\Program Files\MSN Messenger
2007-09-20 21:28 --------- d-----w C:\Program Files\DivX
2007-09-18 02:34 --------- d-----w C:\Program Files\MSXML 6.0
2007-09-18 02:34 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-09-18 00:25 --------- d-----w C:\Program Files\MSXML 4.0
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS.0\system32\divx_xx0c.dll
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS.0\system32\divx_xx07.dll
2007-09-17 18:22 802,816 ----a-w C:\WINDOWS.0\system32\divx_xx11.dll
2007-09-17 18:22 739,840 ----a-w C:\WINDOWS.0\system32\DivX.dll
2007-09-17 05:57 --------- d-----w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\avg7
2007-09-15 22:55 --------- d-----w C:\Program Files\Common Files\Logitech
2007-09-15 22:53 --------- d-----w C:\Program Files\Logitech
2007-09-15 22:53 --------- d-----w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Logitech
2007-09-12 16:13 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\AVG7
2007-09-12 16:13 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\AVG7
2007-09-12 16:13 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\AVG7
2007-09-11 23:14 156,992 ----a-w C:\WINDOWS.0\system32\DivXCodecVersionChecker.exe
2007-09-11 05:08 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2007-09-02 20:47 --------- d-----w C:\Program Files\Common Files\DirectX
2007-09-02 06:37 --------- d-----w C:\Program Files\Microsoft Games
2007-09-02 06:37 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\Microsoft Games
2007-09-02 06:37 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\Microsoft Games
2007-09-02 06:37 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\Microsoft Games
2007-08-28 04:59 --------- d-----w C:\Program Files\GameSpy Arcade
2007-08-28 04:58 --------- d-----w C:\Program Files\Jagged Alliance 2 Gold
2007-08-28 04:56 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\Thunderbird
2007-08-28 04:56 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\Thunderbird
2007-08-28 04:56 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\Thunderbird
2007-08-26 05:41 --------- d-----w C:\Documents and Settings\All Users.WINDOWS.0\Application Data\NVIDIA
2007-08-22 23:19 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\Command & Conquer 3 Tiberium Wars
2007-08-22 23:19 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\Command & Conquer 3 Tiberium Wars
2007-08-22 23:19 --------- d-----w C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\Command & Conquer 3 Tiberium Wars
2007-08-22 23:11 107,888 ----a-w C:\WINDOWS.0\system32\CmdLineExt.dll
2007-08-22 23:11 --------- d--h--r C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\SecuROM
2007-08-22 23:11 --------- d--h--r C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\SecuROM
2007-08-22 23:11 --------- d--h--r C:\Documents and Settings\Administrator.JERUSE-1A91B5ED\Application Data\SecuROM
2007-08-22 16:51 97,152 ----a-w C:\WINDOWS.0\system32\drivers\Rtnicxp.sys
2007-08-21 18:37 --------- d-----w C:\Program Files\Electronic Arts
2007-08-21 06:25 683,520 ----a-w C:\WINDOWS.0\system32\inetcomm.dll
2007-08-21 00:26 81,920 ----a-w C:\WINDOWS.0\system32\dpl100.dll
2007-08-21 00:26 196,608 ----a-w C:\WINDOWS.0\system32\dtu100.dll
2007-08-16 20:17 51,568 ----a-w C:\WINDOWS.0\system32\sirenacm.dll
2007-08-15 22:33 524,288 ----a-w C:\WINDOWS.0\system32\DivXsm.exe
2007-08-15 22:33 3,596,288 ----a-w C:\WINDOWS.0\system32\qt-dx331.dll
2007-08-15 22:33 200,704 ----a-w C:\WINDOWS.0\system32\ssldivx.dll
2007-08-15 22:33 129,784 ------w C:\WINDOWS.0\system32\pxafs.dll
2007-08-15 22:33 120,056 ------w C:\WINDOWS.0\system32\pxcpyi64.exe
2007-08-15 22:33 118,520 ------w C:\WINDOWS.0\system32\pxinsi64.exe
2007-08-15 22:33 1,044,480 ----a-w C:\WINDOWS.0\system32\libdivx.dll
2007-08-15 22:31 593,920 ----a-w C:\WINDOWS.0\system32\dpuGUI11.dll
2007-08-15 22:31 57,344 ----a-w C:\WINDOWS.0\system32\dpv11.dll
2007-08-15 22:31 53,248 ----a-w C:\WINDOWS.0\system32\dpuGUI10.dll
2007-08-15 22:31 344,064 ----a-w C:\WINDOWS.0\system32\dpus11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS.0\system32\dpu11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS.0\system32\dpu10.dll
2007-08-15 22:30 12,288 ----a-w C:\WINDOWS.0\system32\DivXWMPExtType.dll
2007-08-13 22:54 413,696 ----a-w C:\WINDOWS.0\system32\vbscript.dll
2007-08-13 22:54 156,160 ----a-w C:\WINDOWS.0\system32\msls31.dll
2007-08-13 22:45 78,336 ----a-w C:\WINDOWS.0\system32\ieencode.dll
2007-08-13 22:44 40,960 ----a-w C:\WINDOWS.0\system32\licmgr10.dll
2007-08-13 22:39 71,680 ----a-w C:\WINDOWS.0\system32\admparse.dll
2007-08-13 22:39 55,296 ----a-w C:\WINDOWS.0\system32\iesetup.dll
2007-08-13 22:36 36,352 ----a-w C:\WINDOWS.0\system32\imgutil.dll
2007-08-13 22:32 45,568 ----a-w C:\WINDOWS.0\system32\mshta.exe
2007-08-13 22:01 48,128 ----a-w C:\WINDOWS.0\system32\mshtmler.dll
2007-07-30 23:19 92,504 ----a-w C:\WINDOWS.0\system32\cdm.dll
2007-07-30 23:19 549,720 ----a-w C:\WINDOWS.0\system32\wuapi.dll
2007-07-30 23:19 53,080 ----a-w C:\WINDOWS.0\system32\wuauclt.exe
2007-07-30 23:19 43,352 ----a-w C:\WINDOWS.0\system32\wups2.dll
2007-07-30 23:19 325,976 ----a-w C:\WINDOWS.0\system32\wucltui.dll
2007-07-30 23:19 271,224 ----a-w C:\WINDOWS.0\system32\mucltui.dll
2007-07-30 23:19 207,736 ----a-w C:\WINDOWS.0\system32\muweb.dll
2007-07-30 23:19 203,096 ----a-w C:\WINDOWS.0\system32\wuweb.dll
2007-07-30 23:19 1,712,984 ----a-w C:\WINDOWS.0\system32\wuaueng.dll
2007-07-30 23:18 33,624 ----a-w C:\WINDOWS.0\system32\wups.dll
2004-10-01 19:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-02-18 06:23]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-06-26 09:46]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2006-06-26 10:34]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2007-10-01 09:53]
"NvCplDaemon"="C:\WINDOWS.0\system32\NvCpl.dll" [2007-06-29 00:43]
"nwiz"="nwiz.exe" [2007-06-29 00:43 C:\WINDOWS.0\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS.0\system32\NvMcTray.dll" [2007-06-29 00:43]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17]
"NeroFilterCheck"="C:\WINDOWS.0\system32\NeroCheck.exe" [2001-07-09 10:50]
"LVCOMSX"="C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-06-26 10:33]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS.0\system32\ctfmon.exe" [2002-12-31 08:00]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-08 15:51]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-08-16 16:19]
C:\Documents and Settings\All Users.WINDOWS.0\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-10-08 15:51:50]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Balmdrv]
C:\DOCUME~1\ADMINI~1.JER\APPLIC~1\DRAWUP~1\Style Readme.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Love default global mess]
C:\Documents and Settings\All Users.WINDOWS.0\Application Data\great coal love default\Flap Dumb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
R0 viamraid;viamraid;C:\WINDOWS.0\system32\DRIVERS\viamraid.sys
R1 MSFWHLPR;MSFWHLPR;C:\WINDOWS.0\system32\DRIVERS\msfwhlpr.sys
R2 MSFWDrv;MSFWDrv;C:\WINDOWS.0\system32\DRIVERS\msfwdrv.sys
R2 msfwsvc;OneCare Firewall;"C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe"
R2 OneCareMP;OneCare AntiSpyware and AntiVirus;"C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe"
R3 cmudax;C-Media High Definition Audio Interface;C:\WINDOWS.0\system32\drivers\cmudax.sys
R3 MpFilter;Microsoft Malware Protection Driver;C:\WINDOWS.0\system32\DRIVERS\MpFilter.sys
*Newly Created Service* - CATCHME
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6225563D-07E1-7DDA-064D-60DB26537706}]
C:\WINDOWS.0\Servcrypt\servcrypt.exe s
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-19 20:41:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-19 20:42:57
.
--- E O F ---
HJT log in next post