soulfly626
New member
ComboFix 07-07-31 - "cem" 2007-08-01 11:31:46.3 [GMT -7:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.True
Command switches used :: C:\Documents and Settings\cem\Desktop\CFScript.txt
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Temp
C:\Temp\0c2\tmpFF.log
C:\Temp\brr\tmpZTF.log
C:\VundoFix Backups
C:\VundoFix Backups\oqtss.bak1.bad
C:\VundoFix Backups\oqtss.ini.bad
C:\VundoFix Backups\sstqo.dll.bad
C:\VundoFix Backups\ttutv.bak1.bad
C:\VundoFix Backups\ttutv.bak2.bad
C:\VundoFix Backups\ttutv.ini.bad
C:\VundoFix Backups\ttutv.ini2.bad
C:\VundoFix Backups\ttutv.tmp.bad
C:\VundoFix Backups\vtutt.dll.bad
C:\WINDOWS\SYSTEM32\appmgmt
C:\WINDOWS\SYSTEM32\rtlsawgb.dll
((((((((((((((((((((((((( Files Created from 2007-07-01 to 2007-08-01 )))))))))))))))))))))))))))))))
2007-07-31 17:33 396,288 --a------ C:\Program Files\cem.exe
2007-07-31 17:31 <DIR> d-------- C:\Deckard
2007-07-31 08:26 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-07-30 17:37 22,112 -ra------ C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.sys
2007-07-30 16:59 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-30 16:04 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-07-30 16:04 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-30 14:11 396,288 --a------ C:\Program Files\HijackThis.exe
2007-07-30 12:42 <DIR> d-------- C:\Program Files\Trend Micro
2007-07-26 18:14 <DIR> d-------- C:\Program Files\Norton Internet Security
2007-07-26 17:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Symantec Temporary Files
2007-07-26 15:21 <DIR> d-------- C:\DOCUME~1\cem\.housecall6.6
2007-07-26 14:56 113,152 --a------ C:\WINDOWS\SYSTEM32\ncdmfcx.dll
2007-07-26 12:11 89,088 --a------ C:\WINDOWS\SYSTEM32\atl71.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-01 10:28 7211 --a------ C:\Program Files\hijackthis.log
2007-07-31 17:33 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-07-30 16:36 --------- d-------- C:\Program Files\Viewpoint
2007-07-26 18:20 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-07-26 18:20 8014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-07-26 18:20 48776 --a--c--- C:\WINDOWS\system32\S32EVNT1.DLL
2007-07-26 18:20 115000 --a--c--- C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-07-26 18:20 --------- d-------- C:\Program Files\Symantec
2007-07-26 17:46 --------- d-------- C:\Program Files\Norton AntiVirus
2007-05-16 08:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-12-18 01:20]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"mmtask"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2006-01-17 14:03]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-06-04 19:05]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-06-25 22:00]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
C:\Documents and Settings\cem\Start Menu\Programs\Startup\
DESKTOP.INI [2004-03-20 10:58:38]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cenlpdstatus.exe [2004-03-01 13:24:00]
DESKTOP.INI [2004-03-20 10:58:38]
R1 SRTSP;SRTSP;C:\WINDOWS\system32\Drivers\SRTSP.SYS
R1 SRTSPX;SRTSPX;C:\WINDOWS\system32\Drivers\SRTSPX.SYS
R2 CenLPD;CenLPD;C:\Program Files\Century\TinyTERM\NetUtils\Cenlpd.exe
R2 dsunidrv;DellSupport UniDriver;C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver;C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
S3 DSproct;DSproct;\??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
S3 SRTSPL;SRTSPL;C:\WINDOWS\system32\Drivers\SRTSPL.SYS
S4 agpCPQ;Compaq AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
*Newly Created Service* - COMHOST
Contents of the 'Scheduled Tasks' folder
2007-07-27 03:40:21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2007-07-27 01:32:56 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - cem.job - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-01 11:37:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-01 11:39:23
C:\ComboFix-quarantined-files.txt ... 2007-08-01 11:38
C:\ComboFix2.txt ... 2007-08-01 10:22
C:\ComboFix3.txt ... 2007-07-30 17:23
--- E O F ---
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.True
Command switches used :: C:\Documents and Settings\cem\Desktop\CFScript.txt
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Temp
C:\Temp\0c2\tmpFF.log
C:\Temp\brr\tmpZTF.log
C:\VundoFix Backups
C:\VundoFix Backups\oqtss.bak1.bad
C:\VundoFix Backups\oqtss.ini.bad
C:\VundoFix Backups\sstqo.dll.bad
C:\VundoFix Backups\ttutv.bak1.bad
C:\VundoFix Backups\ttutv.bak2.bad
C:\VundoFix Backups\ttutv.ini.bad
C:\VundoFix Backups\ttutv.ini2.bad
C:\VundoFix Backups\ttutv.tmp.bad
C:\VundoFix Backups\vtutt.dll.bad
C:\WINDOWS\SYSTEM32\appmgmt
C:\WINDOWS\SYSTEM32\rtlsawgb.dll
((((((((((((((((((((((((( Files Created from 2007-07-01 to 2007-08-01 )))))))))))))))))))))))))))))))
2007-07-31 17:33 396,288 --a------ C:\Program Files\cem.exe
2007-07-31 17:31 <DIR> d-------- C:\Deckard
2007-07-31 08:26 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-07-30 17:37 22,112 -ra------ C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.sys
2007-07-30 16:59 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-30 16:04 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-07-30 16:04 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-30 14:11 396,288 --a------ C:\Program Files\HijackThis.exe
2007-07-30 12:42 <DIR> d-------- C:\Program Files\Trend Micro
2007-07-26 18:14 <DIR> d-------- C:\Program Files\Norton Internet Security
2007-07-26 17:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Symantec Temporary Files
2007-07-26 15:21 <DIR> d-------- C:\DOCUME~1\cem\.housecall6.6
2007-07-26 14:56 113,152 --a------ C:\WINDOWS\SYSTEM32\ncdmfcx.dll
2007-07-26 12:11 89,088 --a------ C:\WINDOWS\SYSTEM32\atl71.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-01 10:28 7211 --a------ C:\Program Files\hijackthis.log
2007-07-31 17:33 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-07-30 16:36 --------- d-------- C:\Program Files\Viewpoint
2007-07-26 18:20 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-07-26 18:20 8014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-07-26 18:20 48776 --a--c--- C:\WINDOWS\system32\S32EVNT1.DLL
2007-07-26 18:20 115000 --a--c--- C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-07-26 18:20 --------- d-------- C:\Program Files\Symantec
2007-07-26 17:46 --------- d-------- C:\Program Files\Norton AntiVirus
2007-05-16 08:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-12-18 01:20]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"mmtask"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2006-01-17 14:03]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-06-04 19:05]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-06-25 22:00]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
C:\Documents and Settings\cem\Start Menu\Programs\Startup\
DESKTOP.INI [2004-03-20 10:58:38]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cenlpdstatus.exe [2004-03-01 13:24:00]
DESKTOP.INI [2004-03-20 10:58:38]
R1 SRTSP;SRTSP;C:\WINDOWS\system32\Drivers\SRTSP.SYS
R1 SRTSPX;SRTSPX;C:\WINDOWS\system32\Drivers\SRTSPX.SYS
R2 CenLPD;CenLPD;C:\Program Files\Century\TinyTERM\NetUtils\Cenlpd.exe
R2 dsunidrv;DellSupport UniDriver;C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver;C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
S3 DSproct;DSproct;\??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
S3 SRTSPL;SRTSPL;C:\WINDOWS\system32\Drivers\SRTSPL.SYS
S4 agpCPQ;Compaq AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
*Newly Created Service* - COMHOST
Contents of the 'Scheduled Tasks' folder
2007-07-27 03:40:21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2007-07-27 01:32:56 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - cem.job - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-01 11:37:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-01 11:39:23
C:\ComboFix-quarantined-files.txt ... 2007-08-01 11:38
C:\ComboFix2.txt ... 2007-08-01 10:22
C:\ComboFix3.txt ... 2007-07-30 17:23
--- E O F ---