ComboFix 08-01-23.1C - Kim 2008-01-24 20:03:27.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.64 [GMT -5:00]
Running from: C:\Documents and Settings\Kim\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2007-12-25 to 2008-01-25 )))))))))))))))))))))))))))))))
.
2008-01-24 18:49 . 2008-01-24 18:49 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-24 00:21 . 2008-01-24 00:21 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-01-23 23:32 . 2008-01-23 23:43 <DIR> d-------- C:\Program Files\RegCure
2008-01-23 22:52 . 2004-10-25 15:18 131,072 --a------ C:\WINDOWS\system32\ypclsp.dll
2008-01-23 22:52 . 2003-05-19 16:07 86,016 --a------ C:\WINDOWS\system32\YPcservice.exe
2008-01-23 22:40 . 2008-01-23 22:40 <DIR> d-------- C:\WINDOWS\system32\AEABB2AFB2B4B0B
2008-01-23 21:34 . 2008-01-23 21:34 <DIR> d-------- C:\Program Files\Dot1XCfg
2008-01-23 21:31 . 2008-01-23 21:31 <DIR> d-------- C:\WINDOWS\system32\nGpxx01
2008-01-23 21:31 . 2008-01-23 21:31 <DIR> d-------- C:\temp\cXzz9
2008-01-23 15:26 . 2008-01-23 15:26 <DIR> d-------- C:\Program Files\Google
2008-01-23 10:43 . 2008-01-23 10:43 827,392 --a------ C:\WINDOWS\system32\FLASH.OCX
2008-01-23 10:26 . 2008-01-23 10:26 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-01-22 22:25 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-22 22:18 . 2008-01-22 22:18 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-01-22 14:42 . 2001-10-11 11:26 65,536 --a------ C:\WINDOWS\system32\YCRWin32.dll
2008-01-17 16:48 . 2007-07-09 08:09 584,192 --a--c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-01-17 16:42 . 2008-01-17 16:42 <DIR> d-------- C:\Deckard
2008-01-17 16:00 . 2008-01-23 10:25 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-17 15:18 . 2008-01-17 15:18 164 --a------ C:\install.dat
2008-01-15 08:50 . 2008-01-15 08:50 <DIR> d-------- C:\Program Files\Common Files\iS3
2008-01-11 18:42 . 2008-01-11 18:42 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-11 18:42 . 2008-01-11 18:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-11 13:31 . 2006-04-04 15:45 2,400,648 --a------ C:\WINDOWS\system32\madiousb.dll
2008-01-11 13:31 . 2006-04-04 14:42 186,368 --a------ C:\WINDOWS\system32\M-AudioFastTrackControlPanelApplet.cpl
2008-01-11 13:31 . 2006-04-04 14:42 106,112 --a------ C:\WINDOWS\system32\drivers\mausbft.sys
2008-01-11 13:31 . 2006-04-04 14:42 19,456 --a------ C:\WINDOWS\system32\mausbasio.dll
2008-01-11 13:30 . 2008-01-11 13:30 <DIR> d-------- C:\Program Files\M-Audio Fast Track USB
2008-01-10 20:15 . 2008-01-15 08:44 483,328 --a------ C:\WINDOWS\system32\hphmon05.exe
2008-01-10 20:15 . 2008-01-15 08:44 155,648 --a------ C:\WINDOWS\system32\igfxtray.exe
2008-01-10 20:15 . 2008-01-15 08:44 118,784 --a------ C:\WINDOWS\system32\hkcmd.exe
2008-01-10 20:15 . 2008-01-11 13:21 99,840 --a------ C:\WINDOWS\system32\M-AudioTaskBarIcon.exe
2008-01-10 20:15 . 2008-01-12 03:26 52,736 --a------ C:\WINDOWS\system\hpsysdrv.exe
2008-01-10 18:46 . 2008-01-10 18:46 337,408 --a------ C:\WINDOWS\system32\RCX148.tmp
2008-01-10 15:41 . 2008-01-10 15:41 337,408 --a------ C:\WINDOWS\system32\RCX135.tmp
2008-01-10 11:14 . 2008-01-12 03:39 181 --a------ C:\WINDOWS\system\hpsysdrv .DAT
2008-01-10 01:41 . 2008-01-10 01:41 <DIR> d-------- C:\WINDOWS\system32\vt8
2008-01-10 01:41 . 2008-01-10 01:41 <DIR> d-------- C:\WINDOWS\system32\ob3
2008-01-10 01:41 . 2008-01-10 01:41 <DIR> d-------- C:\WINDOWS\system32\mp2
2008-01-10 01:41 . 2008-01-10 01:41 <DIR> d-------- C:\WINDOWS\system32\edcA01
2008-01-10 01:41 . 2008-01-10 01:41 <DIR> d-------- C:\WINDOWS\system32\che9
2008-01-10 01:41 . 2008-01-10 01:41 <DIR> d-------- C:\temp\Ryuan1
2008-01-06 14:30 . 2004-08-04 00:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-01-06 14:30 . 2004-08-04 00:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-01-05 16:49 . 2007-01-31 10:58 6,246 --a------ C:\WINDOWS\atty.ico
2008-01-05 16:48 . 2008-01-05 16:48 <DIR> d-------- C:\WINDOWS\Motive
2008-01-05 16:48 . 2008-01-07 19:46 <DIR> d-------- C:\Program Files\SBC Self Support Tool
2008-01-05 16:48 . 2008-01-07 19:46 <DIR> d-------- C:\Program Files\Common Files\Motive
2008-01-05 16:48 . 2005-05-10 01:36 81,920 --a------ C:\WINDOWS\system32\W32n50.dll
2008-01-05 16:48 . 2005-05-10 01:36 17,162 --a------ C:\WINDOWS\system32\Pcandis5.sys
2008-01-05 16:48 . 2005-05-10 01:36 16,848 --a------ C:\WINDOWS\system32\Pcandis4.sys
2008-01-05 16:48 . 2005-05-10 01:36 16,073 --a------ C:\WINDOWS\system32\Pcandis3.vxd
2008-01-05 16:30 . 2008-01-05 16:30 <DIR> d-------- C:\Program Files\BroadJump
2008-01-05 16:13 . 2001-01-12 16:09 313,856 --a------ C:\WINDOWS\system32\dx3j.dll
2008-01-05 16:13 . 2001-01-12 18:04 171,280 --a------ C:\WINDOWS\system32\jit.dll
2008-01-05 16:13 . 2001-01-12 18:04 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2008-01-05 16:13 . 2001-01-12 18:04 46,352 --a------ C:\WINDOWS\setdebug.exe
2008-01-05 16:13 . 2001-01-12 16:27 7,315 --a------ C:\WINDOWS\system32\javasup.vxd
2008-01-05 16:13 . 2001-01-12 16:10 6,550 --a------ C:\WINDOWS\jautoexp.dat
2008-01-05 16:08 . 2007-01-31 10:58 266,240 --------- C:\WINDOWS\SBCDSL.exe
2008-01-05 16:08 . 2007-01-31 10:58 6,345 -ra------ C:\WINDOWS\system32\DevMngr.vxd
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-24 05:23 --------- d-----w C:\Program Files\MSN Messenger
2008-01-23 15:24 --------- d-----w C:\Program Files\WildTangent
2008-01-23 15:20 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-11 18:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 16:14 498,176 ----a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\msconfig.exe.tmp
2008-01-09 16:17 --------- d-----w C:\Program Files\The Weather Channel FW
2008-01-06 19:32 --------- d-----w C:\Program Files\M-Audio
2008-01-05 21:13 155,995 ----a-w C:\WINDOWS\Java\Packages\KLFVT75N.ZIP
2007-12-19 13:24 --------- d-----w C:\Program Files\FreeSolitaire
2007-12-04 14:56 93,264 -c--a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
.
((((((((((((((((((((((((((((( snapshot_2008-01-24_19.05.26.90 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-25 00:59:18 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_4b0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [ ]
"NVIEW"="nview.dll" [2003-08-19 04:56 852038 C:\WINDOWS\system32\nview.dll]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-18 20:47 8720384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2008-01-15 08:44 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2008-01-15 08:44 118784]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [ ]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2008-01-15 08:44 483328]
"VTTimer"="VTTimer.exe" [2003-05-08 01:32 36864 C:\WINDOWS\system32\VTTimer.exe]
"LTMSG"="LTMSG.exe" [2003-07-14 19:52 40960 C:\WINDOWS\ltmsg.exe]
"NetscapeClient"="" []
"nwiz"="nwiz.exe" [2003-08-19 04:56 323584 C:\WINDOWS\system32\nwiz.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-10-21 13:28 29696 C:\WINDOWS\KHALMNPR.Exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [ ]
"RegistryMechanic"="" []
"YPC"="C:\PROGRA~1\Yahoo!\PARENT~1\ypc.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-18 20:47 8720384]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 18:28:24 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 18:50:52 53248]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-12-15 16:48:46 67128]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\KEM.exe [2007-01-07 14:56:00 581632]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SBC Self Support Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SBC Self Support Tool.lnk
backup=C:\WINDOWS\pss\SBC Self Support Tool.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupNotify]
--a------ 2008-01-22 14:30 24576 c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
--a------ 2004-10-21 13:28 29696 C:\WINDOWS\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\M-Audio Taskbar Icon]
--a------ 2008-01-11 13:21 99840 C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2007-12-18 20:47 8720384 C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2003-08-19 04:56 323584 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2005-03-19 19:13 98304 C:\Program Files\QuickTime\qttask.exe
S1 ati1xbxxx;ati1xbxxx;C:\WINDOWS\system32\drivers\ati1xbxxx.sys []
S2 nvcap;nVidia WDM Video Capture (universal);C:\WINDOWS\system32\DRIVERS\nvcap.sys [2003-07-30 04:15]
S2 NVXBAR;nVidia WDM A/V Crossbar;C:\WINDOWS\system32\DRIVERS\NVxbar.sys [2003-07-30 04:15]
S3 ADSFilter;ADSFilter - (Aluria Filter Driver);C:\WINDOWS\system32\DRIVERS\ADSFilter.sys []
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys []
S3 DzlUsb;Dazzle DVC USB Device;C:\WINDOWS\system32\DRIVERS\DzlUsb.sys [1999-09-17 11:28]
S3 MAUSBFT;Service for M-Audio Fast Track USB (WDM);C:\WINDOWS\system32\DRIVERS\mausbft.sys [2006-04-04 14:42]
.
Contents of the 'Scheduled Tasks' folder
"2006-10-04 22:22:46 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
"2008-01-24 22:00:00 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-24 08:00:00 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-24 20:07:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\Logitech\SetPoint\lgscroll.dll
.
Completion time: 2008-01-24 20:08:53
ComboFix-quarantined-files.txt 2008-01-25 01:08:50
ComboFix2.txt 2008-01-25 00:05:51
ComboFix3.txt 2008-01-24 16:45:31
ComboFix4.txt 2008-01-23 22:25:55
ComboFix5.txt 2008-01-23 19:21:05
.
2008-01-22 09:02:07 --- E O F ---