ComboFix 08-03-10.1 - susi 2008-03-11 19:04:08.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.107 [GMT -5:00]
Running from: D:\combofix\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\sanR24
C:\Temp\sanR24\lDii.log
C:\WINDOWS\BM43161bdb.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\setup.exe
C:\WINDOWS\system32\ajoovwcy.dll
C:\WINDOWS\system32\awtqrrp.dll
C:\WINDOWS\system32\c4
C:\WINDOWS\system32\c4\np89104.exe
C:\WINDOWS\system32\cbxuv.dll
C:\WINDOWS\system32\crvhauiv.dll
C:\WINDOWS\system32\ctxfctgs.dll
C:\WINDOWS\system32\dqrteggb.dll
C:\WINDOWS\system32\eygnyumq.ini
C:\WINDOWS\system32\fmhxjpgi.dll
C:\WINDOWS\system32\gtlmfppp.ini
C:\WINDOWS\system32\hmgwcimr.dll
C:\WINDOWS\system32\iDlo01
C:\WINDOWS\system32\iDlo01\iDlo011065.exe
C:\WINDOWS\system32\iibmnner.ini
C:\WINDOWS\system32\k8
C:\WINDOWS\system32\k8\ravecom3.exe
C:\WINDOWS\system32\mantec~1
C:\WINDOWS\system32\mantec~1\??mantec\
C:\WINDOWS\system32\mantec~1\alg.exe
C:\WINDOWS\system32\n5
C:\WINDOWS\system32\n5\rvdll36.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pppfmltg.dll
C:\WINDOWS\system32\qfgqqtnw.dll
C:\WINDOWS\system32\qmuyngye.dll
C:\WINDOWS\system32\rennmbii.dll
C:\WINDOWS\system32\s7
C:\WINDOWS\system32\s7\gbsu011.exe
C:\WINDOWS\system32\vuxbc.ini
C:\WINDOWS\system32\vuxbc.ini2
C:\WINDOWS\system32\x3
C:\WINDOWS\system32\x3\philcom3.exe
C:\WINDOWS\system32\ydpwyudf.dll
C:\WINDOWS\system32\yljmrdti.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\TnIDriver
((((((((((((((((((((((((( Files Created from 2008-02-12 to 2008-03-12 )))))))))))))))))))))))))))))))
.
2008-03-10 12:44 . 2008-03-11 12:08 354 ---hs---- C:\WINDOWS\system32\bucjgukv.ini
2008-03-08 16:34 . 2008-03-08 16:34 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-08 16:34 . 2008-03-08 16:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-07 21:30 . 2008-03-07 21:30 88 --a------ C:\WINDOWS\wininit.ini
2008-03-02 19:23 . 2008-03-02 19:21 691,545 --a------ C:\WINDOWS\unins000.exe
2008-03-02 19:23 . 2008-03-02 19:23 2,549 --a------ C:\WINDOWS\unins000.dat
2008-03-02 19:15 . 2008-03-02 19:15 <DIR> d--hs---- C:\WINDOWS\c3VzaQ
2008-03-02 19:15 . 2008-03-02 19:15 37,376 --a------ C:\WINDOWS\17PHolmes1000106.exe
2008-03-02 19:14 . 2008-03-11 19:05 <DIR> d-------- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-11 22:22 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-11 17:09 --------- d-----w C:\Documents and Settings\susi\Application Data\LimeWire
2008-03-03 00:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-03 00:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-27 20:24 --------- d-----w C:\Program Files\PartyGaming
2007-07-23 22:57 722,176 ----a-w C:\Documents and Settings\susi\gotomypc_428.exe
2005-08-02 22:46 187,904 --sha-r C:\WINDOWS\c3VzaQ\asappsrv.dll
2005-08-02 22:58 293,888 --sha-r C:\WINDOWS\c3VzaQ\command.exe
2005-07-29 22:24 472 --sha-r C:\WINDOWS\c3VzaQ\wapWuk.vbs
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06B88097-BD0B-4FC5-8359-B55DB4226801}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{34EAF8DD-56C9-46FB-A059-BF4D68588ECC}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{59B08651-F35B-45DB-BC69-48E3F9910799}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5EC28252-1512-44DB-AB22-A513CF33C3A9}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8365217B-DE2C-44DA-9ADD-1EE2F5598CC9}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A0430F44-9F72-4AFE-8C49-468B7E96E979}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A77F925A-C900-44E1-B1A2-59247226F17C}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e1da753b-d238-4df1-a08e-f77edba62f85}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ED120D76-BF31-412C-A99B-783C6676E128}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-01-31 21:04 171448]
"HoldPoll"="C:\DOCUME~1\susi\APPLIC~1\FLAGCD~1\Manager Wave Axis.exe" [ ]
"BitDownload"="D:\V3m downloader\BitDownload\BitDownload.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2003-11-07 20:21 114688]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-04-27 23:10 335872]
"Mouse Suite 98 Daemon"="ICO.EXE" []
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2003-12-12 01:03 167936]
"HKSERV.EXE"="C:\Program Files\Sony\HotKey Utility\HKserv.exe" [2004-02-13 01:01 98304]
"VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2004-01-17 05:36 135168]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 13:29 40960]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-12-22 17:45 71280]
"URLLSTCK.exe"="C:\Program Files\Norton Internet Security\UrlLstCk.exe" [2003-12-11 19:35 70800]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 00:08 28672]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-02-12 11:22 95960]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48 36975]
"QuickTime Task"="D:\rosetta stone\languages\support\qttask.exe" [2006-08-30 20:42 98304]
"IdleWindowJumpInfo"="C:\Documents and Settings\All Users\Application Data\Closestopidlewindow\style mp3.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 05:06 40048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-03-07 00:06 5181440]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HPAiODevice(hp officejet d series) - 1.lnk - C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe [2002-09-26 14:47:54 491582]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2006-10-17 02:43:22 960032]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqrrp]
awtqrrp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
S3 motccgp;Motorola USB Composite Device Driver;C:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-02-16 13:35]
S3 motccgpfl;MotCcgpFlService;C:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-23 21:03]
S3 motport;Motorola USB Diagnostic Port;C:\WINDOWS\system32\DRIVERS\motport.sys [2007-02-13 02:12]
.
Contents of the 'Scheduled Tasks' folder
"2008-03-12 01:00:01 C:\WINDOWS\Tasks\B5444B5B94C7C9E7.job"
- c:\docume~1\susi\applic~1\flagcd~1\Blue Win Deaf.exe
"2005-01-21 05:37:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - susi.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\NAVW32.EXEh/task:
"2008-03-08 02:00:53 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task:
"2004-12-23 02:23:11 C:\WINDOWS\Tasks\Registration reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2004-12-23 02:23:12 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2008-03-11 21:44:18 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-11 20:24:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\System32\Ati2evxx.exe
D:\Sprint\Mobile Broadband\SMBAUtilSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
D:\LimeWire\LimeWire.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
.
**************************************************************************
.
Completion time: 2008-03-11 20:29:01 - machine was rebooted [susi]
ComboFix-quarantined-files.txt 2008-03-12 01:28:53
.
2008-02-24 01:40:40 --- E O F ---