combo fix
ComboFix 08-01-23.1C - Scott Bronson 2008-01-27 0:22:31.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.3091 [GMT -5:00]
Running from: I:\Documents and Settings\Scott Bronson\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2007-12-27 to 2008-01-27 )))))))))))))))))))))))))))))))
.
2008-01-27 00:22 . 2000-08-31 08:00 51,200 --a------ I:\WINDOWS\Nircmd.exe
2008-01-26 23:25 . 2008-01-27 00:16 <DIR> d-------- I:\Program Files\SUPERAntiSpyware
2008-01-24 05:00 . 2008-01-26 23:16 23 --a------ I:\WINDOWS\BlendSettings.ini
2008-01-24 03:47 . 2008-01-25 05:35 <DIR> d-------- I:\Program Files\Bethesda Softworks
2008-01-24 03:34 . 2008-01-24 03:34 <DIR> d-------- I:\Program Files\PowerISO
2008-01-24 03:26 . 2008-01-24 03:26 <DIR> d-------- I:\Program Files\DAEMON Tools Lite
2008-01-24 03:24 . 2008-01-24 03:24 716,272 --a------ I:\WINDOWS\system32\drivers\sptd.sys
2008-01-23 04:47 . 2003-03-31 07:00 13,463,552 --a--c--- I:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-01-23 04:46 . 2008-01-23 04:46 749 -rah----- I:\WINDOWS\WindowsShell.Manifest
2008-01-23 04:46 . 2008-01-23 04:46 749 -rah----- I:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-01-23 04:46 . 2008-01-23 04:46 749 -rah----- I:\WINDOWS\system32\sapi.cpl.manifest
2008-01-23 04:46 . 2008-01-23 04:46 749 -rah----- I:\WINDOWS\system32\ncpa.cpl.manifest
2008-01-23 04:46 . 2008-01-23 04:46 488 -rah----- I:\WINDOWS\system32\logonui.exe.manifest
2008-01-23 04:35 . 2003-03-31 07:00 24,661 --a------ I:\WINDOWS\system32\spxcoins.dll
2008-01-23 04:35 . 2003-03-31 07:00 24,661 --a--c--- I:\WINDOWS\system32\dllcache\spxcoins.dll
2008-01-23 04:35 . 2003-03-31 07:00 13,312 --a------ I:\WINDOWS\system32\irclass.dll
2008-01-23 04:35 . 2003-03-31 07:00 13,312 --a--c--- I:\WINDOWS\system32\dllcache\irclass.dll
2008-01-23 04:27 . 2007-11-30 03:45 210 ---hs---- I:\BOOT.BAK
2008-01-23 01:39 . 2004-02-27 00:00 962,612 --a------ I:\WINDOWS\system32\mfc42d.dll
2008-01-23 01:39 . 2004-02-17 00:00 434,252 --a------ I:\WINDOWS\system32\MSVCRTD.DLL
2008-01-23 01:19 . 2008-01-23 01:39 <DIR> d-------- I:\Program Files\ASUS
2008-01-23 01:19 . 2006-01-10 03:50 24,576 -ra------ I:\WINDOWS\system32\AsIO.dll
2008-01-23 01:19 . 2006-10-18 14:12 12,664 -ra------ I:\WINDOWS\system32\drivers\AsIO.sys
2008-01-23 01:19 . 2006-10-19 03:11 12,096 --a------ I:\WINDOWS\system32\drivers\AsInsHelp64.sys
2008-01-23 01:19 . 2006-10-19 03:11 10,304 --a------ I:\WINDOWS\system32\drivers\AsInsHelp32.sys
2008-01-21 14:45 . 2008-01-21 14:45 <DIR> d-------- I:\Program Files\Lavasoft
2008-01-21 14:45 . 2008-01-26 23:25 <DIR> d-------- I:\Program Files\Common Files\Wise Installation Wizard
2008-01-20 17:44 . 2008-01-20 17:44 <DIR> d-------- I:\Program Files\7-Zip
2008-01-20 02:07 . 2008-01-20 02:07 33,292 --a------ I:\WINDOWS\system32\drivers\scdemu.sys
2008-01-18 06:12 . 2008-01-18 06:12 <DIR> d-------- I:\WINDOWS\system32\93949
2008-01-18 02:41 . 2008-01-20 17:52 <DIR> d-------- I:\Program Files\SlySoft
2008-01-17 21:51 . 2008-01-17 21:51 <DIR> d-------- I:\Program Files\Yahoo! Games
2008-01-17 13:49 . 2008-01-17 13:49 <DIR> d-------- I:\WINDOWS\system32\embedded
2008-01-17 13:49 . 2008-01-17 13:49 <DIR> d-------- I:\Program Files\DVDIdle Pro
2008-01-17 04:32 . 2008-01-17 04:32 <DIR> d-------- I:\Program Files\uTorrent
2008-01-17 02:34 . 2086-01-17 03:14 <DIR> d-------- I:\Program Files\Dot1XCfg
2008-01-17 02:32 . 2008-01-17 02:32 24 ---hs---- I:\WINDOWS\S961A9559.tmp
2008-01-10 18:55 . 2008-01-10 18:55 97,216 --a------ I:\WINDOWS\system32\drivers\AnyDVD.sys
2008-01-10 12:33 . 2008-01-24 03:12 <DIR> d-------- I:\THE_BOURNE_ULTIMATUM
2008-01-05 16:50 . 2008-01-05 16:50 28 --a------ I:\WINDOWS\DVDFabGold.INI
2008-01-05 13:14 . 2008-01-16 12:59 <DIR> d-------- I:\DVDFabPlatinum_Temp
2008-01-05 13:12 . 2008-01-05 13:14 <DIR> d-------- I:\Program Files\DVDFab Platinum
2008-01-02 17:42 . 2008-01-17 04:57 <DIR> d-------- I:\Program Files\DVDFab Platinum 4
2007-12-30 12:20 . 2008-01-05 14:09 <DIR> d-------- I:\delete me
2007-12-29 16:02 . 2007-12-29 16:02 <DIR> d-------- I:\Program Files\DVD Shrink
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-25 20:28 --------- d-----w I:\Program Files\Trend Micro
2008-01-24 08:47 --------- d--h--w I:\Program Files\InstallShield Installation Information
2008-01-23 06:18 --------- d-----w I:\Program Files\Common Files\InstallShield
2008-01-02 22:42 47,360 ----a-w I:\WINDOWS\system32\drivers\pcouffin.sys
2007-12-31 22:50 --------- d-----w I:\Program Files\Common Files\Ahead
2007-12-30 06:50 --------- d-----w I:\Program Files\Google
2007-12-29 20:56 --------- d-----w I:\Program Files\Common Files\Ulead Systems
2007-12-25 21:12 --------- d-----w I:\Program Files\Verizon Wireless
2007-12-24 02:22 --------- d-----w I:\Program Files\Windows Installer Clean Up
2007-12-24 02:22 --------- d-----w I:\Program Files\MSECACHE
2007-12-24 01:50 --------- d-----w I:\Program Files\QuickTime
2007-12-23 22:34 --------- d-----w I:\Program Files\iTunes
2007-12-23 22:34 --------- d-----w I:\Program Files\iPod
2007-12-23 22:32 --------- d-----w I:\Program Files\Common Files\Apple
2007-12-23 22:32 --------- d-----w I:\Program Files\Apple Software Update
2007-12-14 16:32 12,632 ----a-w I:\WINDOWS\system32\lsdelete.exe
2007-12-11 02:29 --------- d-----w I:\Program Files\Yahoo!
2007-12-11 02:07 --------- d-----w I:\Program Files\Common Files\Scanner
2007-12-09 05:07 --------- d-----w I:\Program Files\AWS
2007-12-09 05:05 --------- d-----w I:\Program Files\WeatherMan
2007-12-04 01:03 --------- d-----w I:\Program Files\C-Media 6501 Sound
2007-12-03 02:39 --------- d-----w I:\Program Files\LimeWire
2007-12-02 23:39 --------- d-----w I:\Program Files\Microsoft Games
2007-12-02 23:36 --------- d-----w I:\Program Files\Hasbro Interactive
2007-12-02 04:46 --------- d-----w I:\Program Files\Opera
2007-12-02 02:50 --------- d-----w I:\Program Files\The Weather Exchange Installer
2007-12-02 00:15 --------- d-----w I:\Program Files\Essentials Codec Pack
2007-12-01 23:57 --------- d-----w I:\Program Files\Nero
2007-12-01 21:31 --------- d-----w I:\Program Files\DivX
2007-12-01 21:12 --------- d-----w I:\Program Files\Windows Media Connect 2
2007-12-01 18:36 --------- d-----w I:\Program Files\Common Files\HP
2007-12-01 09:23 --------- d-----w I:\Program Files\Java
2007-12-01 09:10 --------- d-----w I:\Program Files\Common Files\Java
2007-12-01 08:26 --------- d-----w I:\Program Files\MSXML 4.0
2007-11-30 17:53 --------- d-----w I:\Program Files\Microsoft Works
2007-11-30 17:43 --------- d-----w I:\Program Files\HP
2007-11-30 17:43 --------- d-----w I:\Program Files\Hewlett-Packard
2007-11-30 17:42 --------- d-----w I:\Program Files\Common Files\Hewlett-Packard
2007-11-30 17:34 --------- d-----w I:\Program Files\Ulead Systems
2007-11-30 17:07 --------- d-----w I:\Program Files\DIFX
2007-11-30 17:00 --------- d--h--w I:\Program Files\Uninstall Information
2007-11-30 16:56 --------- d-----w I:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1D6CF66A-65AF-0536-F0BE-60A3E4F8F099}]
I:\WINDOWS\system32\mtqlus.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{631FFD69-69AA-0502-F0BE-60A3E4F8F099}]
I:\WINDOWS\system32\mtqlus.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="I:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"OE"="I:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2008-01-23 02:25 488712]
"Weather"="I:\Program Files\AWS\WeatherBug\Weather.exe" [2008-01-23 02:25 1347584]
"MSMSGS"="I:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"SUPERAntiSpyware"="I:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="I:\WINDOWS\system32\NvCpl.dll" [2007-06-28 11:43 8466432]
"UfSeAgnt.exe"="I:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-01-23 02:25 1393928]
"E3E4E7E"="EAEBE.exe" []
"AsusStartupHelp"="I:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe" [2008-01-23 02:25 363008]
"Launch PC Probe II"="I:\Program Files\ASUS\PC Probe II\Probe2.exe" [2008-01-23 02:25 2129408]
"nwiz"="nwiz.exe" [2007-06-28 11:43 1626112 I:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="I:\WINDOWS\system32\tscupgrd.exe" [2004-08-03 22:59 44544]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= I:\PROGRA~1\DVDIDL~1\DVDShell.dll [2004-10-09 20:18 49152]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= I:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
I:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 I:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=I:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=I:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=I:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=I:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\I:^Documents and Settings^Scott Bronson^Start Menu^Programs^Startup^MEMonitor.lnk]
path=I:\Documents and Settings\Scott Bronson\Start Menu\Programs\Startup\MEMonitor.lnk
backup=I:\WINDOWS\pss\MEMonitor.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
--a------ 2008-01-18 02:38 1637312 I:\Documents and Settings\Scott Bronson\My Documents\Downloads\AnyDVD & AnyDVD HD 6.3.0.0 - Final\AnyDVD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
I:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C6501Sound]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 00:56 15360 I:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-01-17 11:51 486856 I:\Program Files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2006-02-19 05:41 49152 I:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 12:10 267048 I:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Codec Update Service]
--a------ 2007-04-08 11:44 303104 I:\Program Files\Essentials Codec Pack\update.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 11:24 1694208 I:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
I:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-09 19:53 153136 I:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-06-28 11:43 8466432 I:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-06-28 11:43 81920 I:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-06-28 11:43 1626112 I:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OE]
--a------ 2008-01-23 02:25 488712 I:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-01-20 02:05 217088 I:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 10:56 286720 I:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--a------ 2007-08-31 16:46 1460560 I:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 04:11 132496 I:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-01-23 02:25 68856 I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
--a------ 2003-11-18 20:20 45056 I:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Photo Express Calendar Checker]
--a------ 2004-01-12 23:40 69632 I:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
I:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
--a------ 2008-01-23 02:25 1347584 I:\Program Files\AWS\WeatherBug\Weather.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-03-01 21:11 4670968 I:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NMIndexingService"=3 (0x3)
R3 cm102u32;C-Media CM6501 Like Sound Interface;I:\WINDOWS\system32\drivers\c6501.sys [2006-09-05 04:04]
S3 usbprint;Microsoft USB PRINTER Class;I:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 02:01]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\OblivionLauncher.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-19 15:53:01 I:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- I:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-27 00:23:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-27 0:23:58
.
2008-01-26 12:00:17 --- E O F ---