Combo Fix Log
ComboFix 08-02-13.2 - heather 2008-02-13 6:48:35.1 - NTFSx86
Running from: C:\Documents and Settings\heather\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\isapnpp.sys
C:\DOCUME~1\heather\MYDOCU~1\FNTS~1\s?oolsv.exe
C:\Documents and Settings\heather\My Documents\FNTS~1
C:\Documents and Settings\heather\My Documents\FNTS~1\s?oolsv.exe
C:\Program Files\Common Files\sstem~1
C:\Program Files\Common Files\sstem~1\s?stem\
C:\Program Files\outerinfo
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\bundles
C:\WINDOWS\bundles\2504041019.exe
C:\WINDOWS\bundles\bs5-vwqouc.exe
C:\WINDOWS\bundles\CSV7P070.exe
C:\WINDOWS\bundles\james_dh.exe
C:\WINDOWS\bundles\optimizejames.exe
C:\WINDOWS\bundles\setup_silent_26221.exe
C:\WINDOWS\bundles\SSK_B5.EXE
C:\WINDOWS\racle~1
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\drivers\isapnpp.sys
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe
C:\WINDOWS\system32\pac.txt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_ISAPNPP
-------\isapnpp
((((((((((((((((((((((((( Files Created from 2008-01-13 to 2008-02-13 )))))))))))))))))))))))))))))))
.
2008-02-12 12:42 . 2008-02-12 12:43 <DIR> d-------- C:\Documents and Settings\heather\Application Data\Walgreens
2008-02-12 12:42 . 2008-02-12 12:43 <DIR> d-------- C:\DOCUME~1\heather\APPLIC~1\Walgreens
2008-02-10 14:01 . 2008-02-10 14:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2008-02-10 14:00 . 2008-02-10 14:00 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-02-10 10:57 . 2008-02-10 10:57 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-10 10:57 . 2008-02-10 10:57 3,447 --a------ C:\WINDOWS\unins000.dat
2008-02-02 15:07 . 2008-02-02 15:07 <DIR> d-------- C:\Documents and Settings\heather\Application Data\Leadertech
2008-02-02 15:07 . 2008-02-02 15:07 <DIR> d-------- C:\DOCUME~1\heather\APPLIC~1\Leadertech
2008-01-30 15:09 . 2008-01-30 15:09 <DIR> d-------- C:\Documents and Settings\heather\Application Data\Viewpoint
2008-01-30 15:09 . 2008-01-30 15:09 <DIR> d-------- C:\DOCUME~1\heather\APPLIC~1\Viewpoint
2008-01-25 18:21 . 2004-04-13 19:20 929,792 -ra------ C:\WINDOWS\SYSTEM32\PRISME5.dll
2008-01-25 18:21 . 2004-04-13 19:20 15,781 -ra------ C:\WINDOWS\SYSTEM32\DRIVERS\mdc8021x.sys
2008-01-25 18:19 . 2008-01-25 19:11 <DIR> d-------- C:\Program Files\2Wire
2008-01-24 19:32 . 2008-01-29 17:17 <DIR> d-------- C:\Program Files\Dot1XCfg
2008-01-24 19:29 . 2008-01-24 19:32 <DIR> d-------- C:\WINDOWS\SYSTEM32\wnzs6
2008-01-24 19:29 . 2008-01-24 19:29 <DIR> d-------- C:\WINDOWS\SYSTEM32\ni4
2008-01-24 19:29 . 2008-01-24 19:29 <DIR> d-------- C:\WINDOWS\SYSTEM32\etz1
2008-01-24 19:29 . 2008-01-24 19:38 <DIR> d-------- C:\WINDOWS\SYSTEM32\comg7
2008-01-24 19:29 . 2008-01-24 19:29 <DIR> d-------- C:\Temp\gTiis19
2008-01-24 19:29 . 2008-01-24 19:29 <DIR> d-------- C:\Temp\cXzz9
2008-01-24 17:40 . 2008-02-13 07:00 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-24 17:40 . 2008-01-24 17:40 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-24 17:39 . 2008-01-24 17:39 <DIR> d-------- C:\Program Files\iPod
2008-01-24 17:38 . 2008-01-24 17:39 <DIR> d-------- C:\Program Files\iTunes
2008-01-24 17:36 . 2008-01-24 17:37 <DIR> d-------- C:\Program Files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-12 20:36 --------- d-----w C:\Documents and Settings\heather\Application Data\AdobeUM
2008-02-12 20:36 --------- d-----w C:\DOCUME~1\heather\APPLIC~1\AdobeUM
2008-02-12 18:53 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
2008-02-12 01:30 --------- d-----w C:\Program Files\Trend Micro
2008-02-10 17:00 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-10 16:58 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2008-02-10 16:19 --------- d-----w C:\Documents and Settings\heather\Application Data\uTorrent
2008-02-10 16:19 --------- d-----w C:\DOCUME~1\heather\APPLIC~1\uTorrent
2008-02-02 21:12 --------- d-----w C:\Documents and Settings\heather\Application Data\Sonic
2008-02-02 21:12 --------- d-----w C:\DOCUME~1\heather\APPLIC~1\Sonic
2008-01-26 00:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-28 20:02 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-28 19:51 --------- d-----w C:\Program Files\Netflix
2007-12-28 04:03 --------- d-----w C:\Documents and Settings\heather\Application Data\Apple Computer
2007-12-28 04:03 --------- d-----w C:\DOCUME~1\heather\APPLIC~1\Apple Computer
2007-12-24 00:51 --------- d-----w C:\Program Files\Red Kawa
2007-12-24 00:51 --------- d-----w C:\Program Files\AviSynth 2.5
2007-12-24 00:07 --------- d-----w C:\Documents and Settings\heather\Application Data\DivX
2007-12-24 00:07 --------- d-----w C:\DOCUME~1\heather\APPLIC~1\DivX
2007-12-23 20:07 --------- d-----w C:\Program Files\DivX
2007-12-23 16:44 --------- d-----w C:\Program Files\uTorrent
2007-12-20 03:52 --------- d-----w C:\Program Files\MSXML 6.0
2007-12-20 02:05 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-12-20 02:03 --------- d-----w C:\Program Files\Common Files\Apple
2007-12-20 02:03 --------- d-----w C:\Program Files\Apple Software Update
2007-12-20 02:02 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-12-19 18:01 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Roxio
2007-12-19 18:01 --------- d-----w C:\Documents and Settings\heather\Application Data\Roxio
2007-12-19 18:01 --------- d-----w C:\DOCUME~1\heather\APPLIC~1\Roxio
2007-12-19 17:56 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Roxio
2007-12-19 17:51 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-12-19 17:50 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2007-12-19 17:50 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
2007-12-19 17:49 --------- d-----w C:\Program Files\Roxio
2007-12-19 17:48 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2007-12-19 17:38 --------- d-----w C:\Program Files\Common Files\Research In Motion
2007-12-19 17:37 --------- d-----w C:\Program Files\Research In Motion
2007-12-19 16:09 --------- d-----w C:\Documents and Settings\heather\Application Data\Research In Motion
2007-12-19 16:09 --------- d-----w C:\DOCUME~1\heather\APPLIC~1\Research In Motion
2007-11-04 07:13 95 ----a-w C:\Program Files\dal.lst
2006-11-02 16:29 403 ----a-w C:\Program Files\flt.lst
2006-11-02 16:29 121 ----a-w C:\Program Files\ModMenu.act
2004-06-17 00:46 157,903 ---ha-w C:\Program Files\ACT.GID
2004-06-16 23:58 267,654 ----a-w C:\Program Files\Uninst6.isu
2004-06-16 23:54 32,768 ------w C:\Program Files\Info.dll
2004-06-16 23:54 10,000 ----a-w C:\Program Files\ActInfo.dat
2004-02-19 08:52 4,544 ------w C:\Documents and Settings\Devices\TPDSupportedDevices_ML.bin
2003-10-29 09:47 491,520 ------w C:\Documents and Settings\IMix\mL_Mixer.dll
2003-04-30 19:47 5,877 ----a-w C:\Program Files\readme.txt
2003-04-27 17:10 671,788 ----a-w C:\Program Files\adal.dll
2003-04-27 17:07 45,056 ----a-w C:\Program Files\rcadal.dll
2003-04-24 14:22 5,337,138 ----a-w C:\Program Files\act.exe
2003-04-24 14:21 69,682 ----a-w C:\Program Files\wprep.awf
2003-04-24 14:21 360,499 ----a-w C:\Program Files\actole.dll
2003-04-24 14:20 577,587 ----a-w C:\Program Files\rptsys.dll
2003-04-24 14:19 131,123 ----a-w C:\Program Files\faxreq.dll
2003-04-24 09:23 49,205 ----a-w C:\Program Files\Uninstal.dll
2003-04-24 09:23 483,380 ----a-w C:\Program Files\inetcom.dll
2003-04-24 09:23 41,012 ----a-w C:\Program Files\actinet.ame
2003-04-24 09:23 40,960 ----a-w C:\Program Files\rcpicker.dll
2003-04-24 09:23 352,303 ----a-w C:\Program Files\picker.dll
2003-04-24 09:23 32,768 ----a-w C:\Program Files\rcinetcom.dll
2003-04-24 09:23 28,672 ----a-w C:\Program Files\rcactinet.dll
2003-04-24 09:23 24,576 ----a-w C:\Program Files\rcUninstal.dll
2003-04-24 09:23 16,384 ----a-w C:\Program Files\finis.exe
2003-04-24 09:23 1,216,512 ----a-w C:\Program Files\actsprng.dat
2003-04-24 09:22 90,112 ----a-w C:\Program Files\Act6Intf.dll
2003-04-24 09:22 45,109 ----a-w C:\Program Files\ActEvent.ocx
2003-04-24 09:22 45,107 ----a-w C:\Program Files\ActCmd.dll
2003-04-24 09:22 45,056 ----a-w C:\Program Files\ActTRLog.dll
2003-04-24 09:22 36,364 ----a-w C:\Program Files\ActOle.tlb
2003-04-24 09:22 32,841 ----a-w C:\Program Files\actreg.exe
2003-04-24 09:22 258 ----a-w C:\Program Files\ActCmd.tlb
2003-04-24 09:22 24,576 ----a-w C:\Program Files\rcActOle.dll
2003-04-24 09:21 32,768 ----a-w C:\Program Files\rcactptp.dll
2003-04-24 09:21 278,589 ----a-w C:\Program Files\SideACT.exe
2003-04-24 09:21 143,360 ----a-w C:\Program Files\ActUpdt.exe
2003-04-24 09:21 106,547 ----a-w C:\Program Files\actptp.exe
2003-04-24 09:21 102,400 ----a-w C:\Program Files\rcSideACT.dll
2003-04-24 09:20 90,163 ----a-w C:\Program Files\DrvWd6.wpi
2003-04-24 09:20 36,914 ----a-w C:\Program Files\wprtf.awf
2003-04-24 09:20 348,210 ----a-w C:\Program Files\actwp.wpi
2003-04-24 09:20 28,672 ----a-w C:\Program Files\rcwprep.dll
2003-04-24 09:20 28,672 ----a-w C:\Program Files\rcDrvWd6.wpi
2003-04-24 09:20 28,672 ----a-w C:\Program Files\rcdrvact32.dll
2003-04-24 09:20 24,639 ----a-w C:\Program Files\ActZip.dll
2003-04-24 09:20 24,576 ----a-w C:\Program Files\rcwptxt.dll
2003-04-24 09:20 24,576 ----a-w C:\Program Files\rcwprtf.dll
2003-04-24 09:20 24,576 ----a-w C:\Program Files\rcwpbmp.dll
2003-04-24 09:20 24,576 ----a-w C:\Program Files\rcActZip.dll
2003-04-24 09:20 200,757 ----a-w C:\Program Files\drvact32.dll
2003-04-24 09:20 20,530 ----a-w C:\Program Files\wptxt.awf
2003-04-24 09:20 20,530 ----a-w C:\Program Files\wpbmp.awf
2003-04-24 09:18 86,016 ----a-w C:\Program Files\rcactwp.wpi
2003-04-24 09:17 65,587 ----a-w C:\Program Files\palmin.flt
2003-04-24 09:17 24,576 ----a-w C:\Program Files\rcpalmin.dll
2003-04-24 09:17 233,520 ----a-w C:\Program Files\ace.flt
2003-04-24 09:16 41,013 ----a-w C:\Program Files\ccxexprt.flt
2003-04-24 09:16 36,911 ----a-w C:\Program Files\qa.flt
2003-04-24 09:16 36,864 ----a-w C:\Program Files\rcNEWTON.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0A2FDC32-6C11-4463-B4C9-1DFAA5C84224}]
C:\WINDOWS\System32\vjrbx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3934EFC2-5621-2DAC-5312-5D00B6CD8BB1}]
C:\WINDOWS\system32\ioxzs.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-24 07:13 68856]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
"Rqulance"="C:\Documents and Settings\heather\My Documents\F?nts\s?oolsv.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2004-10-26 12:01 921600 C:\WINDOWS\SYSTEM32\nwiz.exe]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" [2007-03-29 07:10 394952]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-26 12:01 4632576]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" [ ]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 22:37:56 217194]
SideACT!.lnk - C:\Program Files\SideACT.exe [2004-06-16 17:54:47 278589]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^heather^Start Menu^Programs^Startup^BlackBerry Desktop Redirector.lnk]
path=C:\Documents and Settings\heather\Start Menu\Programs\Startup\BlackBerry Desktop Redirector.lnk
backup=C:\WINDOWS\pss\BlackBerry Desktop Redirector.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 03:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2004-06-07 13:50 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
--a------ 2007-08-16 08:56 236016 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-10-24 07:13 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 15:38]
R3 LSWPCv4;Wireless-B Notebook Adapter Driver;C:\WINDOWS\system32\DRIVERS\rtl8180.sys [2003-10-01 10:54]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-13 07:00:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\TEMP\DJF9B6.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
.
**************************************************************************
.
Completion time: 2008-02-13 7:07:28 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-13 13:07:23
.
2008-01-19 19:28:13 --- E O F ---