combofix log
ComboFix 08-02-25.3 - HP_Owner 2008-02-28 21:16:17.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.980 [GMT -5:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\search_res.txt
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000007_.tmp.dll
C:\WINDOWS\system32\_000010_.tmp.dll
C:\WINDOWS\system32\_000011_.tmp.dll
C:\WINDOWS\system32\_000012_.tmp.dll
D:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://softworldnetwork.com
hxxp://onsafepro.com
.
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-29 )))))))))))))))))))))))))))))))
.
2008-02-27 16:00 . 2008-02-27 16:00 27,080 --a------ C:\export-run.reg
2008-02-25 17:04 . 2008-02-25 15:14 <DIR> d-------- C:\SDfix
2008-02-24 19:26 . 2008-02-24 19:26 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-22 17:06 . 2008-02-22 17:06 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-22 17:06 . 2008-02-22 17:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-22 00:17 . 2008-02-23 00:07 <DIR> d-------- C:\Program Files\RegCure
2008-02-22 00:14 . 2008-02-22 00:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-02-22 00:09 . 2008-02-22 00:10 <DIR> d-------- C:\Program Files\CCleaner
2008-02-21 23:05 . 2008-02-21 23:05 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-21 23:05 . 2008-02-21 23:05 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-21 23:05 . 2008-02-21 23:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-21 21:41 . 2008-02-21 21:41 100,979,236 --a------ C:\regbak.reg
2008-02-21 01:02 . 2008-02-21 01:56 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-20 20:25 . 2008-02-20 20:25 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-20 20:25 . 2008-02-20 20:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-20 06:35 . 2008-02-20 06:35 917,504 --a------ C:\WINDOWS\system32\FLASH.OCX
2008-02-19 22:53 . 2008-02-20 18:13 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-19 00:58 . 2008-02-19 00:58 25 --a------ C:\WINDOWS\cdplayer.ini
2008-02-18 20:00 . 2008-02-18 20:00 <DIR> d-------- C:\Program Files\DVDFab HD Decrypter 4
2008-01-29 16:33 . 2008-01-12 18:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-29 16:33 . 2008-01-15 09:54 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-29 16:33 . 2008-01-15 05:28 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-29 02:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-27 00:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-02-26 02:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-22 05:09 --------- d-----w C:\Program Files\Yahoo!
2008-02-19 01:02 --------- d-----w C:\Program Files\Google
2008-02-10 18:25 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-22 08:31 --------- d-----w C:\Program Files\iTunes
2008-01-22 08:31 --------- d-----w C:\Program Files\iPod
2008-01-22 08:30 --------- d-----w C:\Program Files\QuickTime
2008-01-17 21:42 --------- d-----w C:\Program Files\Norton 360
2008-01-17 01:04 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-17 01:04 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-17 01:04 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-17 01:04 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-17 01:04 --------- d-----w C:\Program Files\Symantec
2008-01-11 21:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-08 04:35 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-01-08 03:03 --------- d-----w C:\Program Files\THQ
2008-01-07 23:14 --------- d-----w C:\Program Files\Microsoft Games
2008-01-07 23:05 --------- d-----w C:\Program Files\Sierra Entertainment
2008-01-05 20:27 --------- d-----w C:\Program Files\DIFX
2008-01-05 20:19 --------- d-----w C:\Program Files\Sega
2008-01-04 04:13 --------- d-----w C:\Program Files\Common Files\EasyInfo
2008-01-03 06:06 --------- d-----w C:\Program Files\9Dragons
2008-01-03 06:02 --------- d-----w C:\Program Files\Warcraft III
2008-01-02 22:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\ATI
2008-01-02 21:18 --------- d-----w C:\Program Files\ATI Technologies
2007-12-29 20:24 --------- d-----w C:\Program Files\DVD Decrypter
2007-12-28 22:05 --------- d-----w C:\Program Files\ahead
2007-12-28 18:18 --------- d-----w C:\Program Files\DVD Shrink
2007-12-28 18:17 --------- d-----w C:\Program Files\DVDFab Decrypter
2007-12-28 17:06 --------- d-----w C:\Program Files\MSBuild
2007-12-28 17:02 --------- d-----w C:\Program Files\Reference Assemblies
2007-12-19 23:01 347,136 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-14 16:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-12 02:18 164 ----a-w C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
2007-12-08 05:21 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-05 19:17 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2007-12-05 05:26 2,782,208 ----a-w C:\WINDOWS\system32\dllcache\ati2mtag.sys
2007-12-05 03:05 368,640 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-12-05 03:04 269,312 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2007-12-05 02:56 147,456 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2007-12-05 02:55 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2007-12-05 02:55 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-12-05 02:55 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2007-12-05 02:55 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2007-12-05 02:54 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2007-12-05 02:53 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-12-05 02:53 495,616 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2007-12-05 02:48 9,535,488 ----a-w C:\WINDOWS\system32\atioglx2.dll
2007-12-05 02:44 3,175,584 ----a-w C:\WINDOWS\system32\ati3duag.dll
2007-12-05 02:33 1,640,192 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2007-12-05 02:19 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll
2007-12-05 02:19 385,024 ----a-w C:\WINDOWS\system32\atikvmag.dll
2007-12-05 02:17 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2007-12-05 02:14 180,224 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2007-12-05 02:11 499,712 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-01-01 18:49 349 -c--a-w C:\Program Files\INSTALL.LOG
2006-02-19 11:28 12,288 -c--a-w C:\WINDOWS\Fonts\RandFont.dll
2005-03-29 19:37 456,384 -c--a-w C:\WINDOWS\inf\WPN311\WPN311.sys
2005-01-27 15:59 35,232 -c--a-w C:\WINDOWS\inf\WPN311\ME_INST.EXE
2005-01-27 15:59 26,112 -c--a-w C:\WINDOWS\inf\WPN311\install.exe
2003-12-18 16:33 20,102 -c--a-w C:\Program Files\Readme.txt
2003-09-03 12:46 10,960 -c--a-w C:\Program Files\EULA.txt
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-06-11 09:58 147456]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 20:54 116072]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-28 05:24 180269]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WPN311 Wireless Assistant.lnk - C:\Program Files\NETGEAR\WPN311\wlancfg5.exe [2005-04-19 15:40:34 4521984]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates From HP.lnk]
backup=C:\WINDOWS\pss\Updates From HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a--c--- 2005-05-03 10:43 69632 C:\WINDOWS\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2007-07-17 20:54 116072 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPBootOp]
--a------ 2006-02-15 18:34 249856 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
--a------ 2007-03-05 16:57 1103480 C:\Program Files\Download Manager\DLM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 03:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDrProfiler]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a--c--- 2005-07-22 18:14 237568 C:\WINDOWS\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a--c--- 2007-10-25 03:57 16855552 C:\WINDOWS\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2006-11-10 12:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-11-28 05:24 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\NETGEAR\\WPN311\\wlancfg5.exe"=
"C:\\Program Files\\Microsoft Games\\Rise of Nations\\thrones.exe"=
"C:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Sega\\Universe At War Earth Assault\\UAWEA.exe"=
"C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"=
"C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"=
"C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"=
"C:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R3 NeroCd2k;NeroCd2k;C:\WINDOWS\system32\drivers\NeroCd2k.sys [2001-04-16 05:54]
S3 ewdmaudn;ewdmaudn;C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\ewdmaudn.sys []
S3 Symantec RemoteAssist;Symantec RemoteAssist;"C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe" [2008-01-29 16:09]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-26 04:00:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-28 22:00:00 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-02-28 08:41:59 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-02-21 06:32:31 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-28 21:17:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-28 21:19:05
ComboFix-quarantined-files.txt 2008-02-29 02:18:38
.
2008-02-14 08:03:00 --- E O F ---