combofix log attached
ComboFix 07-11-08.1 - Peter 2007-11-11 16:04:17.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.771 [GMT 0:00]
Running from: C:\Documents and Settings\Peter\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-11 to 2007-11-11 )))))))))))))))))))))))))))))))
.
2007-11-10 17:49 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-10 15:53 <DIR> d-------- C:\WINDOWS\ERUNT
2007-11-10 11:30 <DIR> d-------- C:\VundoFix Backups
2007-11-09 10:25 <DIR> d-------- C:\Hijackthis
2007-11-09 10:22 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-07 09:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-06 12:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver
2007-11-06 12:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2007-11-06 12:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AOL
2007-11-05 08:17 <DIR> d-------- C:\Documents and Settings\Peter\Application Data\Ahead
2007-11-04 17:23 <DIR> d-------- C:\Program Files\Nero
2007-11-04 17:23 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-11-04 11:53 <DIR> d-------- C:\Program Files\uTorrent
2007-11-03 11:18 <DIR> d-------- C:\WINDOWS\pss
2007-10-11 07:09 582,656 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-11 10:55 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-11 10:00 --------- d-----w C:\Program Files\Napster
2007-11-10 10:39 --------- d-----w C:\Program Files\DesignPro
2007-11-04 17:06 --------- d-----w C:\Program Files\Ahead
2007-11-02 21:57 --------- d-----w C:\Program Files\Norton Internet Security
2007-10-28 17:42 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-28 17:42 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-28 17:42 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-28 17:42 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-28 17:42 --------- d-----w C:\Program Files\Symantec
2007-10-01 14:49 98,184 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
2007-10-01 14:49 542,088 ----a-w C:\WINDOWS\system32\SymNeti.dll
2007-10-01 14:49 31,624 ----a-w C:\WINDOWS\system32\drivers\symids.sys
2007-10-01 14:49 28,040 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
2007-10-01 14:49 23,944 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
2007-10-01 14:49 189,320 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
2007-10-01 14:49 161,160 ----a-w C:\WINDOWS\system32\SymRedir.dll
2007-10-01 14:48 12,680 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
2007-10-01 10:36 --------- d-----w C:\Documents and Settings\Peter\Application Data\DivX
2007-09-27 09:37 --------- d-----w C:\Documents and Settings\Peter\Application Data\Talkback
2007-09-27 09:36 --------- d-----w C:\Program Files\DivX
2007-09-18 07:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 18:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 18:22 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-09-16 12:55 --------- d-----w C:\Program Files\MagicISO
2007-09-16 12:54 --------- d-----w C:\Program Files\BigFix
2007-09-15 18:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-14 10:07 --------- d-----w C:\Documents and Settings\Peter\Application Data\AdobeUM
2007-09-11 23:14 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 00:26 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-08-21 00:26 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-08-15 22:33 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-08-15 22:33 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-08-15 22:33 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-08-15 22:33 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-08-15 22:33 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-08-15 22:33 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-08-15 22:33 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-08-15 22:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-08-15 22:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-08-15 22:31 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-08-15 22:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-08-15 22:30 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-07-30 12:27 98,416 ----a-w C:\Documents and Settings\Erica\Application Data\GDIPFONTCACHEV1.DAT
2007-05-03 09:09 98,416 ----a-w C:\Documents and Settings\Peter\Application Data\GDIPFONTCACHEV1.DAT
2007-03-27 18:02 98,416 ----a-w C:\Documents and Settings\Matthew\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( snapshot@2007-11-10_18.02.07.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-11 15:31:47 42,540 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CHotkey"="zHotkey.exe" [2003-06-03 10:01 C:\WINDOWS\zHotkey.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 18:42]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-12-04 23:44]
"HPHUPD05"="C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe" [2003-11-12 22:12]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38]
"HPHmon05"="C:\WINDOWS\system32\hphmon05.exe" [2004-02-02 19:41]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-22 21:19]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11:06]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-19 11:06]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 22:32]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 23:56 C:\WINDOWS\system32\bthprops.cpl]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 05:03]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 05:03]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [2006-06-29 13:17]
"HostManager"="C:\Program Files\Common Files\AOL\1164538981\ee\AOLHostManager.exe" [2005-07-29 16:53]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 06:55]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 17:30]
"NWEReboot"="" []
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"749cab75"="C:\WINDOWS\system32\dvsvvdxg.dll" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-03 21:42]
"kdx"="C:\WINDOWS\kdx\KHost.exe" [2005-12-12 11:23]
"Nero PhotoShow Media Manager"="C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 13:32]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Exif Launcher.lnk - C:\Program Files\FinePixViewer\QuickDCF.exe [2006-01-15 18:28:52]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
S3 DCamUSBDigitalCamera;Digital Camera;C:\WINDOWS\system32\Drivers\mpixvid.sys
S3 DVBT_Loader;Geniatech DVB-T Adapter firmware loader;C:\WINDOWS\system32\Drivers\DVBT_Loader.sys
S3 GenDTV;Geniatech DVB-T receiver Driver;C:\WINDOWS\system32\Drivers\Geniausb.sys
S3 PciTest;WinMTA PCI Service;\??\C:\WINDOWS\SYSTEM32\DRIVERS\pcitest.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{316abf62-85f9-11da-b260-00038a000015}]
\Shell\AutoRun\command - D:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{64e132b1-9ecf-11da-b298-00038a000015}]
\Shell\AutoRun\command - G:\setupSNK.exe
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-11-04 18:50:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-11 15:06:01 C:\WINDOWS\Tasks\HP Usg Daily.job"
- C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\pexpress\hphped05.exe
"2007-10-26 19:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Peter.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
"2007-11-11 16:05:00 C:\WINDOWS\Tasks\User_Feed_Synchronization-{7D6A7340-2AE9-42C3-9886-205055162D74}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-11 16:09:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-11 16:10:22
C:\ComboFix2.txt ... 2007-11-10 18:46
C:\ComboFix3.txt ... 2007-11-10 18:05
.
--- E O F ---