combo fix log
ComboFix 08-10-07.01 - Mob 2008-10-07 20:44:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.213 [GMT 1:00]
Running from: C:\Documents and Settings\Mob\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\20luwBX1.exe.a_a
C:\WINDOWS\system32\disk.dll
C:\WINDOWS\system32\x83UYUa8.exe.a_a
.
((((((((((((((((((((((((( Files Created from 2008-09-07 to 2008-10-07 )))))))))))))))))))))))))))))))
.
2008-10-07 20:14 . 2008-10-07 20:14 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-07 16:20 . 2008-10-07 16:20 <DIR> d-------- C:\Program Files\Sun
2008-10-06 20:50 . 2008-10-06 20:50 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-10-06 20:50 . 2008-10-06 20:50 <DIR> d-------- C:\WINDOWS\system32\en
2008-10-06 20:50 . 2008-10-06 20:50 <DIR> d-------- C:\WINDOWS\system32\bits
2008-10-06 20:50 . 2008-10-06 20:50 <DIR> d-------- C:\WINDOWS\l2schemas
2008-10-06 20:33 . 2008-10-06 21:06 2,675 --a------ C:\WINDOWS\imsins.BAK
2008-10-06 09:35 . 2008-10-06 09:35 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-09-19 20:40 . 2008-04-14 01:12 69,120 --------- C:\WINDOWS\system32\wlanapi.dll
2008-09-19 20:38 . 2008-04-14 01:12 1,306,624 --------- C:\WINDOWS\system32\msxml6.dll
2008-09-19 20:37 . 2008-04-13 17:36 144,384 --------- C:\WINDOWS\system32\drivers\hdaudbus.sys
2008-09-19 20:37 . 2008-04-14 01:11 61,440 --------- C:\WINDOWS\system32\kmsvc.dll
2008-09-19 20:37 . 2008-04-14 01:11 37,376 --------- C:\WINDOWS\system32\l2gpstore.dll
2008-09-19 20:37 . 2006-12-28 20:01 19,569 --a------ C:\WINDOWS\
006079_.tmp
2008-09-19 20:37 . 2008-04-14 01:12 10,752 --------- C:\WINDOWS\system32\smtpapi.dll
2008-09-19 20:37 . 2008-04-14 01:12 9,728 --------- C:\WINDOWS\system32\rwnh.dll
2008-09-19 20:37 . 2008-04-14 01:09 6,144 --------- C:\WINDOWS\system32\kbdpash.dll
2008-09-19 20:37 . 2008-04-14 01:09 6,144 --------- C:\WINDOWS\system32\kbdnepr.dll
2008-09-19 20:37 . 2008-04-14 01:09 6,144 --------- C:\WINDOWS\system32\kbdiultn.dll
2008-09-19 20:37 . 2008-04-14 01:09 6,144 --------- C:\WINDOWS\system32\kbdbhc.dll
2008-09-19 20:37 . 2007-06-21 06:52 974 --------- C:\WINDOWS\system32\pid.inf
2008-09-19 10:25 . 2007-01-18 13:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-09-19 10:01 . 2008-10-07 20:54 17,176,608 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-19 10:01 . 2008-10-07 16:24 201,644 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-19 09:55 . 2008-09-19 09:55 <DIR> d-------- C:\Program Files\ZoneAlarmSB
2008-09-19 09:47 . 2008-07-09 09:05 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-09-19 09:44 . 2008-09-19 09:44 <DIR> d-------- C:\Program Files\Zone Labs
2008-09-19 09:44 . 2008-07-09 09:05 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2008-09-19 09:44 . 2008-10-07 16:27 352,918 --a------ C:\WINDOWS\system32\vsconfig.xml
2008-09-19 09:13 . 2008-09-24 11:03 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-19 09:12 . 2008-09-24 09:42 <DIR> d-------- C:\Program Files\SpywareBlaster
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-07 15:18 --------- d-----w C:\Program Files\Java
2008-10-06 16:54 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-10-06 16:51 --------- d-----w C:\Documents and Settings\Mob\Application Data\AVG7
2008-10-06 16:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-09-24 08:45 44,544 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-09-22 22:22 74,240 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-09-19 22:07 77,824 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-09-19 09:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-16 15:18 --------- d-----w C:\Program Files\World of Warcraft
2008-08-22 13:44 71,680 ----a-w C:\WINDOWS\system32\LoveFly.dll
2008-08-21 18:48 --------- d-----w C:\Documents and Settings\Mob\Application Data\Ventrilo
2008-08-15 19:42 --------- d-----w C:\Program Files\Ventrilo
2008-08-15 19:41 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 21:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2001-11-23 04:08 712,704 ----a-r C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2004-06-01 196608]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 106496]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-05-21 221184]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"tsnp2std"="C:\WINDOWS\tsnp2std.exe" [2005-11-14 110592]
"snp2std"="C:\WINDOWS\vsnp2std.exe" [2005-11-16 344064]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-15 579584]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-04-07 180269]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 286720]
"LXSUPMON"="C:\WINDOWS\system32\LXSUPMON.EXE" [2002-01-28 885760]
"NSLauncher"="C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 2658304]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-27 219136]
C:\Documents and Settings\Mob\Start Menu\Programs\Startup\
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 64864]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Bob^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=C:\Documents and Settings\Bob\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2004-11-30 22:10 344064 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--------- 2004-06-01 11:46 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--------- 2004-06-01 12:09 458752 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--------- 2004-06-01 12:03 217088 C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
-ra------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-10-19 21:16 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
--a------ 2006-06-02 16:33 1003520 C:\Program Files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2005-04-07 11:42 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
--a------ 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Real\\RealPlayer\\trueplay.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enGB-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enGB-patch-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
S3 HwIOctl;HwIOctl;C:\Documents and Settings\Bob\Desktop\HwIOctl.sys [ ]
S3 Memctl;Memctl;C:\Documents and Settings\Bob\Desktop\Memctl.sys [ ]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD);C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2005-11-18 10192896]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-10-06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]
2008-10-03 C:\WINDOWS\Tasks\At1.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-09-28 C:\WINDOWS\Tasks\At10.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-06 C:\WINDOWS\Tasks\At11.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-06 C:\WINDOWS\Tasks\At12.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-06 C:\WINDOWS\Tasks\At13.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-07 C:\WINDOWS\Tasks\At14.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-06 C:\WINDOWS\Tasks\At15.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-06 C:\WINDOWS\Tasks\At16.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-06 C:\WINDOWS\Tasks\At17.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-07 C:\WINDOWS\Tasks\At18.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-07 C:\WINDOWS\Tasks\At19.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-04 C:\WINDOWS\Tasks\At2.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-07 C:\WINDOWS\Tasks\At20.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-07 C:\WINDOWS\Tasks\At21.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-06 C:\WINDOWS\Tasks\At22.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-05 C:\WINDOWS\Tasks\At23.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-03 C:\WINDOWS\Tasks\At24.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-03 C:\WINDOWS\Tasks\At25.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-04 C:\WINDOWS\Tasks\At26.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-04 C:\WINDOWS\Tasks\At27.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-05 C:\WINDOWS\Tasks\At28.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-05 C:\WINDOWS\Tasks\At29.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-04 C:\WINDOWS\Tasks\At3.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-05 C:\WINDOWS\Tasks\At30.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-05 C:\WINDOWS\Tasks\At31.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-05 C:\WINDOWS\Tasks\At32.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-03 C:\WINDOWS\Tasks\At33.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-09-28 C:\WINDOWS\Tasks\At34.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-06 C:\WINDOWS\Tasks\At35.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-06 C:\WINDOWS\Tasks\At36.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-06 C:\WINDOWS\Tasks\At37.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-07 C:\WINDOWS\Tasks\At38.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-06 C:\WINDOWS\Tasks\At39.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-05 C:\WINDOWS\Tasks\At4.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-06 C:\WINDOWS\Tasks\At40.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-06 C:\WINDOWS\Tasks\At41.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-07 C:\WINDOWS\Tasks\At42.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-07 C:\WINDOWS\Tasks\At43.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-07 C:\WINDOWS\Tasks\At44.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-07 C:\WINDOWS\Tasks\At45.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-06 C:\WINDOWS\Tasks\At46.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-05 C:\WINDOWS\Tasks\At47.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-03 C:\WINDOWS\Tasks\At48.job
- C:\WINDOWS\system32\20luwBX1.exe []
2008-10-05 C:\WINDOWS\Tasks\At5.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-05 C:\WINDOWS\Tasks\At6.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-05 C:\WINDOWS\Tasks\At7.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-05 C:\WINDOWS\Tasks\At8.job
- C:\WINDOWS\system32\x83UYUa8.exe []
2008-10-03 C:\WINDOWS\Tasks\At9.job
- C:\WINDOWS\system32\x83UYUa8.exe []
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Tesco Insert Detect - C:\Program Files\Tesco\Picture Suite\InsDetect.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
HKU-Default-Run-swg - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-iTunesHelper - C:\Program Files\iTunes\iTunesHelper.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Mob\Application Data\Mozilla\Firefox\Profiles\e7573cvk.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPZoneSB.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-07 20:54:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-07 21:01:13
ComboFix-quarantined-files.txt 2008-10-07 20:00:34
Pre-Run: 50,221,699,072 bytes free
Post-Run: 50,340,921,344 bytes free
290 --- E O F --- 2008-10-07 12:09:27