ComboFix 08-03-04.5 - Administrator 2008-03-04 22:01:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1207 [GMT -5:00]
Running from: F:\Documents and Settings\Administrator\My Documents\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
F:\WINDOWS\system32\awtqo.dll
F:\WINDOWS\system32\cbxvvsq.dll
F:\WINDOWS\system32\oqtwa.ini
F:\WINDOWS\system32\oqtwa.ini2
.
((((((((((((((((((((((((( Files Created from 2008-02-05 to 2008-03-05 )))))))))))))))))))))))))))))))
.
2008-03-04 22:01 . 2008-03-04 22:01 6,736 --a------ F:\WINDOWS\system32\drivers\PROCEXP90.SYS
2008-03-04 18:07 . 2008-03-04 18:52 <DIR> d-------- F:\VundoFix Backups
2008-03-03 12:13 . 2008-02-02 18:04 215,144 -ra------ F:\WINDOWS\patchw32.dll
2008-03-03 12:11 . 2008-02-02 18:04 215,144 -ra------ F:\WINDOWS\pw32a.dll
2008-03-03 11:53 . 2008-03-03 11:53 <DIR> d-------- F:\Program Files\Norton Ghost
2008-03-03 11:53 . 2007-12-20 17:13 136,416 --a------ F:\WINDOWS\system32\drivers\symsnap.sys
2008-03-03 11:53 . 2008-01-19 20:12 128,104 --a------ F:\WINDOWS\system32\drivers\WimFltr.sys
2008-03-03 11:53 . 2008-01-19 19:45 38,112 --a------ F:\WINDOWS\system32\drivers\v2imount.sys
2008-03-03 11:53 . 2008-01-19 19:40 15,088 --a------ F:\WINDOWS\system32\drivers\vproeventmonitor.sys
2008-03-03 11:42 . 2008-03-04 18:58 <DIR> d-a------ F:\Documents and Settings\All Users\Application Data\TEMP
2008-03-03 11:42 . 2004-08-30 21:00 1,244,672 --a------ F:\WINDOWS\system32\WinSpooler.exe
2008-03-03 11:42 . 2008-03-03 11:42 37,888 --a------ F:\WINDOWS\system32\rar.exe
2008-03-01 20:35 . 2008-03-03 23:42 54,156 --ah----- F:\WINDOWS\QTFont.qfn
2008-03-01 20:35 . 2008-03-01 20:35 1,409 --a------ F:\WINDOWS\QTFont.for
2008-03-01 20:30 . 2008-03-01 20:31 <DIR> d-------- F:\Program Files\QuickTime
2008-02-29 12:05 . 2008-02-29 12:05 <DIR> d-------- F:\WINDOWS\BBSTORE
2008-02-29 12:04 . 2008-02-29 12:04 <DIR> d-------- F:\Program Files\The Learning Company
2008-02-29 11:56 . 2008-02-29 11:56 0 --a------ F:\WINDOWS\SETUP32.INI
2008-02-16 00:22 . 2008-02-16 00:22 0 --a------ F:\WINDOWS\Textart.INI
2008-02-09 14:05 . 2008-02-09 14:05 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Meridian93
2008-02-08 20:30 . 2008-02-09 17:36 <DIR> d-------- F:\Program Files\MagicFarm
2008-02-06 06:19 . 2008-02-25 11:24 244 --ah----- F:\sqmnoopt19.sqm
2008-02-06 06:19 . 2008-02-25 11:15 244 --ah----- F:\sqmnoopt18.sqm
2008-02-06 06:19 . 2008-02-25 11:24 232 --ah----- F:\sqmdata19.sqm
2008-02-06 06:19 . 2008-02-25 11:15 232 --ah----- F:\sqmdata18.sqm
2008-02-05 05:14 . 2008-02-24 08:17 244 --ah----- F:\sqmnoopt17.sqm
2008-02-05 05:14 . 2008-02-24 08:17 244 --ah----- F:\sqmnoopt16.sqm
2008-02-05 05:14 . 2008-02-24 08:17 232 --ah----- F:\sqmdata17.sqm
2008-02-05 05:14 . 2008-02-24 08:17 232 --ah----- F:\sqmdata16.sqm
2008-02-05 05:07 . 2008-02-28 15:51 244 --ah----- F:\sqmnoopt15.sqm
2008-02-05 05:07 . 2008-02-28 15:50 244 --ah----- F:\sqmnoopt14.sqm
2008-02-05 05:07 . 2008-02-28 15:51 232 --ah----- F:\sqmdata15.sqm
2008-02-05 05:07 . 2008-02-28 15:50 232 --ah----- F:\sqmdata14.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 20:25 --------- d-----w F:\Program Files\ESPNMotion
2008-03-03 17:19 --------- d-----w F:\Documents and Settings\Administrator\Application Data\Symantec
2008-03-03 17:02 --------- d-----w F:\Documents and Settings\All Users\Application Data\Symantec
2008-03-03 16:53 --------- d-----w F:\Program Files\Common Files\Symantec Shared
2008-02-28 17:28 --------- d-----w F:\Program Files\Disney Interactive
2008-02-25 22:47 --------- d-----w F:\Program Files\Norton SystemWorks
2008-02-25 22:35 --------- d-----w F:\Program Files\I LOVE Kittens
2008-02-24 17:03 --------- d-----w F:\Program Files\I LOVE Puppies
2008-02-11 22:11 --------- d-----w F:\Program Files\Monarch The Butterfly King
2008-02-06 04:38 --------- d-----w F:\Documents and Settings\Administrator\Application Data\Aim
2008-01-24 00:08 --------- d-----w F:\Program Files\The Digital Field Trip to The Rainforest Demo
2008-01-23 00:55 --------- d-----w F:\Program Files\Atlantis Quest
2008-01-20 00:31 15,664 ----a-w F:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-01-18 08:26 --------- d-----w F:\Program Files\Virtual Earth 3D
2008-01-17 13:16 --------- d-----w F:\Program Files\Upromise
2008-01-16 01:15 --------- d-----w F:\Documents and Settings\Administrator\Application Data\upromise
2008-01-15 14:54 10,537 ----a-w F:\WINDOWS\system32\drivers\coh_mon.cat
2008-01-15 10:28 706 ----a-w F:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-12 23:32 23,904 ----a-w F:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-12 18:06 --------- d-----w F:\Documents and Settings\Administrator\Application Data\cerasus.media
2008-01-12 03:01 --------- d-----w F:\Program Files\MoneyMania
2008-01-11 18:02 --------- d-----w F:\Program Files\ReflexiveArcade
2007-12-23 06:39 8,388,608,000 --sha-w F:\gobackio.bin
2007-09-09 17:14 8,422,640 ----a-w F:\Documents and Settings\Administrator\Plus51R2.exe
2006-12-16 14:30 19,203,280 ----a-w F:\Documents and Settings\Administrator\nsb-install-8-1-2.exe
2006-09-26 01:33 457 ----a-w F:\Program Files\INSTALL.LOG
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-01-31 02:16 116088 --a------ F:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BB4CE310-DC6D-40BD-8550-897C95E3D56F}]
F:\WINDOWS\system32\pmnno.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="F:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [2004-08-10 06:00 15360]
"swg"="F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-24 22:35 68856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="F:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 18:03 152872]
"Upromise"="F:\Program Files\Upromise\Upromise.exe" [2007-07-10 15:00 385024]
"Upromise Update"="F:\Program Files\Upromise\UpromiseUa.exe" [2007-07-10 15:00 147456]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="F:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56 64512]
"AudioDrvEmulator"="F:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 17:25 49152]
"CTHelper"="CTHELPER.EXE" [2005-08-08 01:10 16384 F:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2005-08-08 01:10 18944 F:\WINDOWS\system32\CTXFIHLP.EXE]
"UpdReg"="F:\WINDOWS\UpdReg.EXE" [2000-05-11 00:00 90112]
"ATIPTA"="F:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-14 21:05 344064]
"ISUSPM Startup"="F:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 15:30 249856]
"ISUSScheduler"="F:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 15:30 81920]
"DMXLauncher"="F:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2006-05-03 02:12 98304]
"DVDLauncher"="F:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 15:19 53248]
"SunJavaUpdateSched"="F:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"D-Link AirPlus G"="F:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-03-18 03:34 1228800]
"ANIWZCS2Service"="F:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 16:49 49152]
"HP Software Update"="F:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11 49152]
"CTDVDDET"="F:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 00:00 45056]
"VolPanel"="F:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-07-11 10:34 122880]
"TkBellExe"="F:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-04-17 06:14 185896]
"QuickFinder Scheduler"="F:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2006-07-04 23:01 77892]
"NeroFilterCheck"="F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 14:57 153136]
"HP Component Manager"="F:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38 241664]
"ccApp"="F:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-31 13:15 51048]
"NSWosCheck"="F:\Program Files\Norton SystemWorks\osCheck.exe" [2007-09-18 08:22 25472]
"osCheck"="F:\Program Files\Norton AntiVirus\osCheck.exe" [2007-08-24 23:53 714608]
"QuickTime Task"="F:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"Norton Ghost 14.0"="F:\Program Files\Norton Ghost\Agent\VProTray.exe" [2008-02-02 18:30 2245984]
"UserFaultCheck"="F:\WINDOWS\system32\dumprep 0 -u" [ ]
F:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 04:19:24 237568]
Kodak EasyShare software.lnk - F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 04:33:46 282624]
Norton GoBack.lnk - F:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe [2006-07-19 11:45:12 861872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= F:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= F:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"WinUpdating"= WinUpdating.exe
"Windows Printing Driver"= WinSpooler.exe
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{ADA4AB54-F034-41A4-9A68-95DF06976B68}"= F:\WINDOWS\system32\cbxvvsq.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"F:\\Program Files\\Messenger\\msmsgs.exe"=
"F:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"F:\\Program Files\\BitLord\\BitLord.exe"=
"F:\\Program Files\\ICQ\\Icq.exe"=
"F:\\Program Files\\AIM\\aim.exe"=
"F:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"F:\\Program Files\\MSN Messenger\\livecall.exe"=
R2 LiveUpdate Notice;LiveUpdate Notice;"F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;F:\WINDOWS\system32\dllhost.exe [2004-08-10 06:00]
R3 atinewp2;ATI eHomeWonder, WDM Video CODEC;F:\WINDOWS\system32\DRIVERS\atinewp2.sys [2004-07-27 20:43]
R3 ha20x2k;Creative 20X HAL Driver;F:\WINDOWS\system32\drivers\ha20x2k.sys [2005-08-08 00:54]
R3 SymIMMP;SymIMMP;F:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
S3 COH_Mon;COH_Mon;F:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-01-12 18:32]
S3 SymIM;Symantec Network Security Intermediate Filter Service;F:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{45b87b6d-e837-11db-8dc0-00123f7e4544}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{45b87b6e-e837-11db-8dc0-00123f7e4544}]
\Shell\AutoRun\command - LinksysConnectPC.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5258a6d5-525d-11dc-8e06-00123f7e4544}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{813479e6-d2d4-11db-8db4-00123f7e4544}]
\Shell\AutoRun\command - C:\LinksysConnectPC.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9ceef8d5-6cce-11db-8d92-00123f7e4544}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a08e6d68-1792-11dc-8dcd-00123f7e4544}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bf71c475-4bf3-11dc-8e02-00123f7e4544}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc285b1c-58a4-11dc-8e09-00123f7e4544}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-03-02 01:11:03 F:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- F:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-23 13:28:01 F:\WINDOWS\Tasks\EasyShare Registration Task.job"
- F:\WINDOWS\system32\rundll32.exelF:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registration_7.5.30.2.sxt _RegistrationOffer@16
"2008-03-04 01:00:04 F:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Administrator.job"
- F:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
"2008-02-25 22:47:28 F:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- F:\Program Files\Norton SystemWorks\OBC.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-04 22:13:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
F:\WINDOWS\system32\Ati2evxx.exe
F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
F:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
F:\WINDOWS\SYSTEM32\CTXFISPI.EXE
F:\WINDOWS\system32\CTsvcCDA.EXE
F:\WINDOWS\eHome\ehRecvr.exe
F:\WINDOWS\eHome\ehSched.exe
F:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
F:\Program Files\Norton Ghost\Agent\VProSvc.exe
F:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
F:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
F:\WINDOWS\ehome\mcrdsvc.exe
F:\WINDOWS\system32\imapi.exe
F:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
F:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
F:\WINDOWS\system32\msdtc.exe
F:\WINDOWS\eHome\ehmsas.exe
F:\Program Files\HP\hpcoretech\comp\hpdarc.exe
.
**************************************************************************
.
Completion time: 2008-03-04 22:20:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-05 03:20:48
.
2008-02-14 08:03:28 --- E O F ---