combofix log
Here is the new combofix log
ComboFix 08-01-11.3 - Andrew's 2008-01-18 21:30:55.6 - NTFSx86
Running from: C:\Documents and Settings\Andrew's\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Andrew's\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched .exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr .exe
C:\Program Files\Unlocker\UnlockerAssistant .exe
C:\Program Files\Unlocker\UnlockerAssistant .exe
C:\WINDOWS\system32\srutv.ini2
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched .exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr .exe
C:\Program Files\Unlocker\UnlockerAssistant .exe
C:\Program Files\Unlocker\UnlockerAssistant .exe
C:\WINDOWS\system32\srutv.ini
C:\WINDOWS\system32\srutv.ini2
C:\WINDOWS\system32\vturs.dll
C:\WINDOWS\system32\vturs.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-18 to 2008-01-18 )))))))))))))))))))))))))))))))
.
2008-01-17 19:59 . 2008-01-17 19:59 <DIR> d-------- C:\Program Files\Sun
2008-01-17 19:58 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-01-17 19:06 . 2008-01-17 19:06 <DIR> d-------- C:\Program Files\Common Files\Java
2008-01-17 11:40 . 2008-01-17 11:40 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-16 18:29 . 2008-01-16 18:29 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-01-15 21:13 . 2008-01-15 21:13 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-01-15 17:07 . 2006-01-05 05:49 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-01-15 17:07 . 2006-01-05 06:05 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-14 11:59 . 2008-01-16 18:29 <DIR> d-------- C:\VundoFix Backups
2008-01-12 21:00 . 2008-01-12 21:00 680,960 --a------ C:\WINDOWS\isRS-000.tmp
2008-01-10 12:15 . 2008-01-10 12:41 455,168 --a------ C:\WINDOWS\system32\dllcache\tintsetp.exe
2008-01-10 12:15 . 2008-01-17 14:24 208,952 --a------ C:\WINDOWS\system32\dllcache\imjpmig.exe
2008-01-10 12:15 . 2008-01-10 12:41 59,392 --a------ C:\WINDOWS\system32\dllcache\imscinst.exe
2008-01-09 12:09 . 2008-01-18 11:08 15,360 --a------ C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-09 12:09 . 2008-01-18 22:00 15,360 --a------ C:\WINDOWS\system32\ctfmon.exe
2008-01-09 11:26 . 2008-01-09 11:26 <DIR> d-------- C:\Program Files\DVD Shrink
2008-01-06 14:07 . 2008-01-06 14:17 <DIR> d-------- C:\Program Files\UrbanTerror
2008-01-01 17:38 . 2008-01-01 17:38 <DIR> d-------- C:\Program Files\Paradox Entertainment
2007-12-21 15:22 . 2007-12-21 15:22 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\SUPERAntiSpyware.com
2007-12-21 07:54 . 2005-04-27 08:42 104,593 --a------ C:\WINDOWS\system32\drivers\MPIXVID.SYS
2007-12-21 07:54 . 2004-06-29 01:16 25,575 --a------ C:\WINDOWS\system32\drivers\USBCamAT.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-18 11:00 --------- d-----w C:\Program Files\Lexmark X1100 Series
2008-01-18 00:29 --------- d-----w C:\Program Files\QuickTime
2008-01-17 11:39 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd6749.sys
2008-01-17 08:58 --------- d-----w C:\Program Files\Java
2008-01-17 00:09 --------- d-----w C:\Documents and Settings\Andrew's\Application Data\uTorrent
2008-01-16 23:58 --------- d-----w C:\Documents and Settings\Andrew's\Application Data\Vso
2008-01-16 08:03 --------- d-----w C:\Documents and Settings\Andrew's\Application Data\LimeWire
2008-01-12 13:24 --------- d-----w C:\Program Files\DivoCodec
2008-01-12 09:55 --------- d-----w C:\Program Files\DivX
2008-01-09 01:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-08 23:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-08 02:04 --------- d-----w C:\Program Files\Firefly Studios
2008-01-06 01:52 --------- d-----w C:\Program Files\WinISO
2008-01-06 01:52 --------- d-----w C:\Program Files\EGOSOFT
2007-12-21 23:03 --------- d-----w C:\Program Files\SUPERAntiSpyware
2007-12-21 23:03 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-21 23:03 --------- d-----w C:\Documents and Settings\Andrew's\Application Data\SUPERAntiSpyware.com
2007-12-20 20:54 --------- d-----w C:\Program Files\Digital Camera
2007-12-16 10:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\vsosdk
2007-12-14 07:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-11 11:20 --------- d-----w C:\Program Files\MagicDisc
2007-12-11 10:06 --------- d-----w C:\Program Files\iSofter
2007-12-10 11:12 --------- d-----w C:\Documents and Settings\Andrew's\Application Data\DivX
2007-12-10 10:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
2007-12-10 10:30 --------- d-----w C:\Program Files\Elaborate Bytes
2007-11-29 22:30 43,528 ----a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-11-28 04:18 --------- d-----w C:\Program Files\SlySoft
2007-11-28 04:12 --------- d-----w C:\Documents and Settings\Andrew's\Application Data\SlySoft
2007-11-28 04:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\SlySoft
2007-11-24 05:53 --------- d-----w C:\Program Files\Oberon Media
2007-11-24 05:44 --------- d-----w C:\Program Files\Google
2007-11-22 12:06 --------- d-----w C:\Program Files\LimeWire
2007-11-20 00:09 104,320 ----a-w C:\WINDOWS\system32\drivers\Rtnicxp.sys
2007-10-31 02:17 54,824 ----a-w C:\WINDOWS\agrsmdel.exe
2007-10-26 06:21 47,360 ----a-w C:\Documents and Settings\Andrew's\Application Data\pcouffin.sys
2007-06-01 11:46 2,608 ----a-w C:\Documents and Settings\Andrew's\Application Data\wklnhst.dat
2007-01-10 10:05 3,696 -c--a-w C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
.
Code:
<pre>
----a-w 39,792 2008-01-18 11:00:14 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
----a-w 68,856 2008-01-18 11:00:19 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
----a-w 144,784 2008-01-18 11:00:19 C:\Program Files\Java\jre1.6.0_04\bin\jusched .exe
----a-w 57,344 2008-01-18 11:00:18 C:\Program Files\Lexmark X1100 Series\lxbkbmgr .exe
----a-w 347,136 2008-01-18 11:00:48 C:\Program Files\Unlocker\UnlockerAssistant .exe
----a-w 347,136 2008-01-18 10:32:14 C:\Program Files\Unlocker\UnlockerAssistant .exe
</pre>
((((((((((((((((((((((((((((( snapshot@2008-01-18_11.35.50.04 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-18 00:15:38 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-18 10:30:31 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-18 00:15:38 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-18 10:30:31 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-18 00:15:38 1,417,216 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-18 10:30:31 1,417,216 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-18 00:15:38 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-18 10:30:32 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-18 00:15:38 6,127,616 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-18 10:30:32 6,127,616 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-18 00:15:38 274,432 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-18 10:30:32 274,432 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
- 2008-01-17 03:24:04 208,952 ----a-w C:\WINDOWS\ime\imjp8_1\imjpmig.exe
+ 2008-01-18 11:00:38 540,160 ----a-w C:\WINDOWS\ime\imjp8_1\IMJPMIG.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40A871FE-BCDB-4101-9373-16EB16586370}]
2008-01-18 22:00 326144 --a------ C:\WINDOWS\system32\vturs.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-18 11:08 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-18 11:18 426496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-18 21:31 370688]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2008-01-17 14:24 208952]
"PCDrProfiler"="" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2008-01-18 11:18 398848]
"Ashampoo AntiSpyWare Guard"="C:\Program Files\Ashampoo\Ashampoo AntiSpyWare\AntiSpyWareGuard.exe" [ ]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant .exe" [2008-01-18 22:00 347136]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2008-01-18 11:08 478720]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\vturs.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\vturs
S3 bfastfao;bfastfao;C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\bfastfao.sys []
S3 BOCDRIVE;BOClean Kernel Monitor.;C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-01-18 03:02:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-14 01:31:06 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Hewlett-Packard\SDP\HPSdpApp.exef/remind /LaunchPoint reminder /App C:\Program Files\Hewlett-Packard\Easy Internet signup\StartEIS.aml
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-18 22:00:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\vturs.dll
-> C:\Program Files\Unlocker\UnlockerHook.dll
.
Completion time: 2008-01-18 22:06:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-18 11:06:11
ComboFix2.txt 2008-01-18 00:36:19
ComboFix3.txt 2008-01-17 11:52:15
ComboFix4.txt 2008-01-14 07:06:40
ComboFix5.txt 2008-01-12 08:30:06
.
2008-01-09 00:09:23 --- E O F ---