Combo Fix Log
ComboFix 07-09-18.4 - "David" 2007-09-19 18:25:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1412 [GMT 9.5:30]
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\creobtqb.dll
C:\WINDOWS\system32\glbnaeee.exe
C:\WINDOWS\system32\pqstv.bak1
C:\WINDOWS\system32\pqstv.bak2
C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\qovirhbv.exe
C:\WINDOWS\system32\qpuoflav.exe
C:\WINDOWS\system32\sfhgxdwf.exe
C:\WINDOWS\system32\vtsqp.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-08-19 to 2007-09-19 )))))))))))))))))))))))))))))))
.
2007-09-19 18:28 125,504 --a------ C:\WINDOWS\system32\snalnkfo.dll
2007-09-19 18:24 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-13 21:05 <DIR> d-------- C:\Program Files\Windows Defender
2007-09-12 22:02 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-12 19:33 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-09-12 19:21 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
2007-09-11 23:00 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-09-11 23:00 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-11 20:25 <DIR> d-------- C:\VundoFix Backups
2007-09-10 18:32 <DIR> d-------- C:\Program Files\Lavasoft
2007-09-10 18:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-09-10 18:31 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-10 17:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-09 17:31 44,054 --a------ C:\WINDOWS\system32\cbxxxuu.dll.vir
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-13 21:31 --------- d-------- C:\DOCUME~1\David\APPLIC~1\Skype
2007-08-29 17:46 --------- d-------- C:\Program Files\EPSON Print CD
2007-08-08 05:18 25160 --a------ C:\WINDOWS\system32\drivers\ElbyCDIO.sys
2007-08-07 19:36 --------- d-------- C:\Program Files\ptrk
2007-08-07 13:58 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-07 13:56 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-08-06 22:07 --------- d-------- C:\DOCUME~1\David\APPLIC~1\Help
2007-08-05 16:09 --------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Sonic
2007-08-05 16:09 --------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\EPSON
2007-08-05 16:09 --------- d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\ATI
2007-08-05 12:53 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-05 12:37 --------- d-------- C:\Program Files\Photomatix
2007-08-02 07:38 --------- d-------- C:\Program Files\PowerQuest
2007-08-01 20:24 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Acronis
2007-08-01 20:20 99776 --a------ C:\WINDOWS\system32\drivers\snapman.sys
2007-08-01 20:20 388000 --a------ C:\WINDOWS\system32\drivers\timntr.sys
2007-08-01 20:20 32288 --a------ C:\WINDOWS\system32\drivers\tifsfilt.sys
2007-08-01 20:20 --------- d-------- C:\Program Files\Common Files\Acronis
2007-08-01 20:20 --------- d-------- C:\Program Files\Acronis
2007-07-30 20:51 --------- d-------- C:\Program Files\Libronix DLS
2007-07-30 20:50 --------- d-------- C:\DOCUME~1\David\APPLIC~1\Libronix DLS
2007-07-30 20:50 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Libronix DLS
2007-07-30 20:45 --------- d-------- C:\Program Files\NETGEAR
2007-07-23 19:33 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-07-23 19:32 --------- d-------- C:\Program Files\Symantec
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{632AB9DB-EE1E-43B0-AA06-4DD209EE33BF}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6AB56860-8A95-4C5B-9BB6-5379100B100D}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CF46BFB3-2ACC-441b-B82B-36B9562C7FF1}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UpdaterUI.exe" [2005-12-07 02:55]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 19:00]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 14:03 C:\WINDOWS\system32\TWEAKUI.CPL]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 16:41]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 13:48]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-08-06 08:27]
"IMONTRAY"="C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe" [2005-05-02 21:21]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 14:07]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-01-04 16:19]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"EEventManager"="C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2006-10-12 15:57]
"GhostStartTrayApp"="C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe" [2002-08-14 15:21]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageWorkstation\TrueImageMonitor.exe" [2006-07-21 09:03]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageWorkstation\TimounterMonitor.exe" [2006-07-21 00:15]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-07-21 00:13]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 13:39]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111v2\WG111v2.exe [2007-08-05 12:53:18]
C:\DOCUME~1\David\STARTM~1\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= C:\PROGRA~1\DVDREG~1\DVDShell.dll [2004-10-09 15:18 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxxxuu]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\system32\ocipjvcq.dll",forkonce
R0 megasas;megasas;C:\WINDOWS\system32\DRIVERS\megasas.sys
R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R0 vmscsi;vmscsi;C:\WINDOWS\system32\DRIVERS\vmscsi.sys
R0 ZetSFD;ZetSFD;C:\WINDOWS\system32\DRIVERS\ZetSFD.sys
R1 GhPciScan;GhostPciScanner;\??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys
R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys
R2 SFSZ;DataPlow SFS for Zetera Storage Devices;C:\WINDOWS\system32\drivers\sfsz.sys
R2 SIODRV;SIODRV;\??\C:\WINDOWS\system32\drivers\SIODRV.SYS
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
R2 Z-SANService;Z-SAN Service;C:\Program Files\NETGEAR\NETGEAR Storage Central Manager Utility\Z-SANService.exe
R3 smbusp;Intel(R) SMBus 2.0 Driver;C:\WINDOWS\system32\DRIVERS\smb.sys
R3 ZetBus;Zetera Virtual Bus;C:\WINDOWS\system32\DRIVERS\ZetBus.sys
S3 EntDrv51;EntDrv51;\??\C:\WINDOWS\system32\drivers\EntDrv51.sys
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys
S3 ZetMPD;ZetMPD;C:\WINDOWS\system32\DRIVERS\ZetMPD.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57dfae85-f92a-11db-aeab-000cf1ecf584}]
audit\command- G:\ezflash.exe
AutoRun\command- G:\ezflash.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-09-19 16:31:00 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2007-09-20 08:31:44 C:\WINDOWS\Tasks\Update Software.job"
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-20 18:01:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-20 18:03:44 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-20 18:03
.
--- E O F ---