ComboFix 08-07-05.1 - Owner 2008-07-07 12:34:29.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.714 [GMT -4:00]
Running from: C:\Documents and Settings\Owner.OLUIGBO-9MC03P2\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\blphcefhj0er0g.scr
C:\WINDOWS\system32\phcefhj0er0g.bmp
.
((((((((((((((((((((((((( Files Created from 2008-06-07 to 2008-07-07 )))))))))))))))))))))))))))))))
.
2008-07-02 04:36 . 2006-06-19 23:19 155,648 --a------ C:\WINDOWS\system32\igfxtray.exe
2008-07-02 04:36 . 2006-06-19 23:18 114,688 --a------ C:\WINDOWS\system32\hkcmd.exe
2008-06-26 18:41 . 2008-06-26 18:41 <DIR> d-------- C:\Documents and Settings\Owner.OLUIGBO-9MC03P2\Application Data\AXPFixer
2008-06-26 18:38 . 2008-06-26 18:41 <DIR> d-------- C:\Program Files\AXPFixer
2008-06-24 12:17 . 2008-06-24 12:17 <DIR> d-------- C:\Documents and Settings\Owner.OLUIGBO-9MC03P2\Application Data\rhcafhj0er0g
2008-06-17 03:53 . 2008-06-21 15:28 <DIR> d--hs---- C:\WINDOWS\T2x1aWdibw
2008-06-16 14:20 . 2008-06-16 14:20 <DIR> d-------- C:\Documents and Settings\Owner.OLUIGBO-9MC03P2\Application Data\Malwarebytes
2008-06-16 14:19 . 2008-06-16 14:20 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-16 14:19 . 2008-06-16 14:19 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-06-16 14:19 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-16 14:19 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-16 00:29 . 2008-06-16 00:29 4,286 --a------ C:\WINDOWS\system32\Jamster.ico
2008-06-15 02:51 . 2008-06-15 02:51 <DIR> d-------- C:\Documents and Settings\Administrator.OLUIGBO-9MC03P2\Application Data\Viewpoint
2008-06-15 02:50 . 2008-06-15 02:50 <DIR> d-------- C:\Documents and Settings\Administrator.OLUIGBO-9MC03P2\Application Data\AOL
2008-06-15 02:49 . 2008-06-15 02:49 <DIR> d-------- C:\Documents and Settings\Administrator.OLUIGBO-9MC03P2
2008-06-15 02:15 . 2008-06-15 02:15 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-15 02:03 . 2008-06-15 02:03 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-06-15 02:03 . 2008-06-15 02:03 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-06-15 01:20 . 2008-06-15 01:20 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-06-15 01:06 . 2002-09-03 09:00 4,224 --a------ C:\WINDOWS\system32\beep.sys
2008-06-15 01:05 . 2008-06-15 01:05 <DIR> d-------- C:\Program Files\uTorrent
2008-06-15 01:05 . 2008-06-21 15:30 <DIR> d-------- C:\Documents and Settings\Owner.OLUIGBO-9MC03P2\Application Data\uTorrent
2008-06-10 16:45 . 2008-06-13 09:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-02 13:16 --------- d-----w C:\Program Files\QuickTime
2008-06-29 15:12 --------- d-----w C:\Program Files\Viewpoint
2008-06-29 15:12 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
2008-06-27 04:39 316 ----a-w C:\drmHeader.bin
2008-06-27 02:26 --------- d-----w C:\Program Files\DivX
2008-06-26 09:36 16,896 ----a-w C:\WINDOWS\system32\svchost.exe
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-05-30 23:22 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-05-30 23:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\DivX.dll
2008-05-30 23:22 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-05-30 23:22 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-05-30 23:22 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-05-30 23:22 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-05-23 15:16 --------- d-----w C:\Program Files\MSXML 4.0
2008-05-22 22:22 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-05-22 22:22 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-05-22 22:22 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-05-22 22:22 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:22 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-05-22 22:22 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-05-22 22:22 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-05-22 22:20 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-22 22:20 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-05-22 22:19 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-05-22 22:19 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-22 22:18 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-22 07:29 --------- d-----w C:\Documents and Settings\Owner.OLUIGBO-9MC03P2\Application Data\Apple Computer
2008-05-15 20:08 --------- d-----w C:\Program Files\iTunes
2008-05-15 20:07 --------- d-----w C:\Program Files\iPod
2008-05-15 20:06 --------- d-----w C:\Program Files\Bonjour
2008-05-15 20:04 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
2008-05-15 20:03 --------- d-----w C:\Program Files\Apple Software Update
2008-05-15 20:02 --------- d-----w C:\Program Files\Common Files\Apple
2008-05-15 20:02 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple
2008-05-14 04:29 --------- d-----w C:\Program Files\Movie Joiner
2008-05-13 21:01 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Motive
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:04 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2006-08-11 00:47 17,528 ----a-w C:\Documents and Settings\Owner.OLUIGBO-9MC03P2\Application Data\GDIPFONTCACHEV1.DAT
2003-11-15 20:22 58,264 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2005-07-29 20:24 472 --sha-r C:\WINDOWS\T2x1aWdibw\nZUYuqx2vT.vbs
.
------- Sigcheck -------
2002-09-03 09:00 12800 0f7d9c87b0ce1fa520473119752c6f79 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2004-08-04 03:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2008-06-26 05:36 16896 35de7705f9fb23992740523b5c9fdac5 C:\WINDOWS\system32\svchost.exe
2002-09-03 09:00 516608 2246d8d8f4714a2cedb21ab9b1849abb C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2004-08-04 03:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2004-08-04 03:56 505856 481addbb21037489eacfcb308b1be2b0 C:\WINDOWS\system32\winlogon.exe
2007-06-13 06:23 1035264 666c5d9dbced0cdfd48285103f8e2808 C:\WINDOWS\explorer.exe
2007-06-13 07:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2002-09-03 09:00 1004032 a82b28bfc2e4455fe43022a498c0ef0a C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 03:56 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2004-08-04 03:56 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2002-09-03 09:00 101376 e3df4a0252d287c44606ee55355e1623 C:\WINDOWS\$NtServicePackUninstall$\services.exe
2004-08-04 03:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\ServicePackFiles\i386\services.exe
2004-08-04 03:56 110080 77f48ea251a503aae5fc0e7af4a425d7 C:\WINDOWS\system32\services.exe
2002-09-03 09:00 11776 b2b6ba905d0e3f8a32a0eb3b4051807b C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
2004-08-04 03:56 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\ServicePackFiles\i386\lsass.exe
2004-08-04 03:56 14336 d1320ba74a3866c2859b0518080cf84c C:\WINDOWS\system32\lsass.exe
2005-06-10 19:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\$hf_mig$\KB896423\SP2GDR\spoolsv.exe
2005-06-10 20:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 19:55 53248 6b4bf97957a0b8795811975d4bf1acfe C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 03:56 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2002-09-03 09:00 51200 9b4155ba58192d4073082b8fc5d42612 C:\WINDOWS\$NtUninstallKB896423_0$\spoolsv.exe
2004-08-04 03:56 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2005-06-10 19:53 58368 e1f9dbda12cbef81cf3d771d45c7dea5 C:\WINDOWS\system32\spoolsv.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-28_13.07.31.03 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-28 16:49:26 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-07 03:08:57 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-r 71,216 2006-10-23 12:50:37 C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="C:\Program Files\America Online 9.0e\AOL.EXE" [2005-07-12 06:17 50776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2006-06-19 23:19 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2006-06-19 23:18 114688]
"HostManager"="C:\Program Files\Common Files\AOL\1150817884\ee\AOLSoftware.exe" [2006-03-10 18:22 48280]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [N/A]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [N/A]
"AOLSPScheduler"="C:\Program Files\Common Files\AOL\1150817884\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe" [2006-11-20 16:42 8784]
"sscRun"="C:\Program Files\Common Files\AOL\1150817884\ee\SSCRun.exe" [N/A]
"OASClnt"="C:\Program Files\mcafee.com\antivirus\oasclnt.exe" [N/A]
"EmailScan"="C:\Program Files\mcafee.com\antivirus\mcvsescn.exe" [N/A]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [N/A]
"MPFExe"="C:\Program Files\mcafee.com\personal firewall\MPfTray.exe" [N/A]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 17:42 79448]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2007-08-29 19:02 26112]
"Verizon_McciTrayApp"="C:\Program Files\Verizon\McciTrayApp.exe" [2007-06-06 19:52 936960]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 15:20 2061816]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
ZyXEL G-220 v2 Wireless Adapter Utility.lnk - C:\Program Files\ZyXEL\ZyXEL G-220 v2 Wireless Adapter Utility\ZyXEL G-220 v2.exe [2007-09-17 16:11:27 10891264]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\seppgm.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\seppgs.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
--a------ 2002-10-03 20:50 684032 C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2007-08-29 19:02 26112 C:\Program Files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hot Key Kbd 9910 Daemon]
--------- 2001-01-03 15:50 66048 C:\WINDOWS\system32\SK9910DM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PROMon.exe]
--a------ 2002-04-18 18:32 73728 C:\WINDOWS\system32\PROMon.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America Online 9.0e\\waol.exe"=
"C:\\Program Files\\ZyXEL\\ZyXEL G-220 v2 Wireless Adapter Utility\\ZyXEL G-220 v2.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
R2 RioPNP;RioPNP;C:\WINDOWS\system32\drivers\RioPNP.sys [2000-06-06 10:29]
R2 ZDCNDIS5;ZDCNDIS5 NDIS Protocol Driver;C:\WINDOWS\System32\ZDCNDIS5.sys [2006-08-17 10:03]
R3 ZG760_XP;ZyXEL 802.11g XG762 1211 Driver;C:\WINDOWS\system32\DRIVERS\WlanGZXP.sys [2006-08-17 10:03]
S1 seppgm;TCP x IP2 Kernel;C:\WINDOWS\System32\seppgm.sys []
S2 seppgs;TCP x IP2 Kernel32;C:\WINDOWS\System32\seppgm.sys []
S3 {BEE686B9-4C84-4487-9D72-9F40F051E973};{BEE686B9-4C84-4487-9D72-9F40F051E973};C:\WINDOWS\System32\svchost.exe [2008-06-26 05:36]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
{BEE686B9-4C84-4487-9D72-9F40F051E973}
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-07 12:40:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{BEE686B9-4C84-4487-9D72-9F40F051E973}]
"ServiceDll"="C:\DOCUME~1\OWNER~1.OLU\LOCALS~1\Temp\25E.tmp"
.
Completion time: 2008-07-07 12:44:56
ComboFix-quarantined-files.txt 2008-07-07 16:43:52
ComboFix2.txt 2008-06-29 15:44:39
ComboFix3.txt 2008-06-28 19:33:29
ComboFix4.txt 2008-06-28 17:10:41
Pre-Run: 9,850,032,128 bytes free
Post-Run: 10,020,999,168 bytes free
211 --- E O F --- 2008-06-20 06:54:47