ComboFix Log
***Im posting an abbreviated version, see notes***
ComboFix 08-01-23.2 - Derk 2008-01-23 18:47:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.598 [GMT -5:00]
Running from: C:\Documents and Settings\Derk\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\blp\API\Office Tools\bbxlcmd .exe
C:\Documents and Settings\Derk\My Documents\pos1000.tmp
C:\Documents and Settings\Derk\My Documents\pos1001.tmp
C:\Documents and Settings\Derk\My Documents\pos1002.tmp
C:\Documents and Settings\Derk\My Documents\pos1003.tmp
C:\Documents and Settings\Derk\My Documents\pos1004.tmp
C:\Documents and Settings\Derk\My Documents\pos1005.tmp
C:\Documents and Settings\Derk\My Documents\pos1006.tmp
C:\Documents and Settings\Derk\My Documents\pos1007.tmp
C:\Documents and Settings\Derk\My Documents\pos1008.tmp
****bla bla bla...goes on through posFFF.tmp****
C:\Documents and Settings\Derk\My Documents\posFFF.tmp
C:\pos10.tmp
C:\pos100.tmp
C:\pos1000.tmp
C:\pos1001.tmp
C:\pos1002.tmp
C:\pos1003.tmp
C:\pos1004.tmp
C:\pos1005.tmp
C:\pos1006.tmp
C:\pos1007.tmp
C:\pos1008.tmp
C:\pos1009.tmp
C:\pos100A.tmp
C:\pos100B.tmp
C:\pos100C.tmp
C:\pos100D.tmp
C:\pos100E.tmp
C:\pos100F.tmp
C:\pos101.tmp
****bla bla bla, again goes on through posFFF.tmp****
C:\posFFF.tmp
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\McAfee.com\Agent\mcagent .exe
C:\Program Files\QdrDrive
C:\Program Files\WinAble
C:\Program Files\Windows Defender\MSASCui .exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\SYSTEM32\ihkmp.ini
C:\WINDOWS\SYSTEM32\ihkmp.ini2
C:\WINDOWS\system32\jzbkqfvl.dllbox
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\pmkhi.dll
C:\WINDOWS\system32\RCX32.tmp
C:\WINDOWS\system32\RCX33.tmp
Code:
<pre>
C:\blp\API\Office Tools\bbxlcmd .exe ---> QooBox
C:\Program Files\Common Files\Real\Update_OB\realsched .exe ---> QooBox
C:\Program Files\McAfee.com\Agent\mcagent .exe ---> QooBox
C:\Program Files\Windows Defender\MSASCui .exe ---> QooBox
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe ---> QooBox
</pre>
.
.
((((((((((((((((((((((((( Files Created from 2007-12-24 to 2008-01-24 )))))))))))))))))))))))))))))))
.
2008-01-23 18:43 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-23 16:25 . 2008-01-23 18:37 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-23 16:24 . 2008-01-23 16:24 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-23 11:47 . 2008-01-23 11:47 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-01-23 11:45 . 2008-01-23 11:45 499,712 --a------ C:\WINDOWS\SYSTEM32\msvcp71.dll
2008-01-23 11:45 . 2008-01-23 11:45 348,160 --a------ C:\WINDOWS\SYSTEM32\msvcr71.dll
2008-01-23 11:29 . 2008-01-23 11:31 23,392 --a------ C:\WINDOWS\SYSTEM32\nscompat.tlb
2008-01-23 11:29 . 2008-01-23 11:31 16,832 --a------ C:\WINDOWS\SYSTEM32\amcompat.tlb
2008-01-22 14:03 . 2008-01-22 14:03 <DIR> d-------- C:\WINDOWS\SYSTEM32\LogFiles
2008-01-21 20:08 . 2008-01-21 20:08 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-21 15:48 . 2008-01-21 15:48 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-01-20 17:21 . 2008-01-22 13:05 <DIR> d-------- C:\VundoFix Backups
2008-01-08 17:39 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\SYSTEM32\msonpmon.dll
2008-01-08 16:45 . 2008-01-08 16:45 <DIR> d-------- C:\Program Files\MSBuild
2008-01-08 16:31 . 2008-01-08 16:31 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-01-08 16:23 . 2008-01-08 16:23 <DIR> dr-h----- C:\MSOCache
2008-01-07 20:16 . 2008-01-07 20:16 630,784 --a------ C:\WINDOWS\SYSTEM32\divxdec.ax
2008-01-06 22:25 . 2008-01-20 11:48 <DIR> d-------- C:\Program Files\QuickTime
2008-01-06 14:46 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\SYSTEM32\ptpusd.dll
2008-01-06 14:46 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbscan.sys
2008-01-06 14:46 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\usbscan.sys
2008-01-06 14:46 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\SYSTEM32\ptpusb.dll
2008-01-04 16:59 . 2008-01-04 16:59 524,288 --a------ C:\WINDOWS\SYSTEM32\DivXsm.exe
2008-01-04 16:59 . 2008-01-04 16:59 4,816 --a------ C:\WINDOWS\SYSTEM32\divxsm.tlb
2008-01-04 16:58 . 2008-01-04 16:58 3,596,288 --a------ C:\WINDOWS\SYSTEM32\qt-dx331.dll
2008-01-04 16:58 . 2008-01-04 16:58 1,044,480 --a------ C:\WINDOWS\SYSTEM32\libdivx.dll
2008-01-04 16:58 . 2008-01-04 16:58 200,704 --a------ C:\WINDOWS\SYSTEM32\ssldivx.dll
2008-01-04 16:56 . 2008-01-04 16:56 156,992 --a------ C:\WINDOWS\SYSTEM32\DivXCodecVersionChecker.exe
2008-01-04 16:56 . 2008-01-04 16:56 12,288 --a------ C:\WINDOWS\SYSTEM32\DivXWMPExtType.dll
2008-01-02 23:26 . 2008-01-23 19:30 4,958,588 --a------ C:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.CDF
2008-01-02 23:26 . 2008-01-23 19:30 4,958,588 --------- C:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.BAK
2008-01-02 23:23 . 2008-01-23 19:30 30,912 --a------ C:\WINDOWS\SYSTEM32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
2008-01-02 23:23 . 2008-01-23 19:30 30,912 --a------ C:\WINDOWS\SYSTEM32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
2008-01-02 23:23 . 2008-01-23 19:30 30,120 --a------ C:\WINDOWS\SYSTEM32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
2008-01-02 23:23 . 2008-01-23 19:30 30,120 --a------ C:\WINDOWS\SYSTEM32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
2008-01-02 23:23 . 2008-01-23 19:30 11,564 --a------ C:\WINDOWS\SYSTEM32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
2008-01-02 23:23 . 2008-01-23 19:30 1,080 --a------ C:\WINDOWS\SYSTEM32\settingsbkup.sfm
2008-01-02 23:23 . 2008-01-23 19:30 1,080 --a------ C:\WINDOWS\SYSTEM32\settings.sfm
2008-01-02 17:55 . 2008-01-02 17:55 409,600 --a------ C:\WINDOWS\SYSTEM32\wrap_oal.dll
2008-01-02 17:55 . 2008-01-02 17:55 86,016 --a------ C:\WINDOWS\SYSTEM32\OpenAL32.dll
2008-01-02 17:50 . 2006-08-11 15:14 86,446 --a------ C:\WINDOWS\SYSTEM32\instwdm.ini
2008-01-02 17:50 . 2006-08-11 14:55 10,240 --a------ C:\WINDOWS\CTDCRES.DLL
2008-01-02 17:50 . 2006-08-11 14:56 3,072 --a------ C:\WINDOWS\CTXFIRES.DLL
2008-01-02 17:28 . 2003-06-12 23:25 7,062 --a------ C:\WINDOWS\SYSTEM32\audiopid.vxd
2008-01-02 13:58 . 2008-01-02 16:47 1,828 --a------ C:\WINDOWS\SYSTEM32\CTHELPER.RPT
2008-01-02 11:55 . 2008-01-22 14:07 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-01-02 11:48 . 2008-01-23 10:33 <DIR> d-------- C:\WINDOWS\SYSTEM32\DRIVERS\UMDF
2007-12-29 10:04 . 2008-01-09 09:43 90,112 --a------ C:\WINDOWS\UpdReg .EXE
2007-12-29 10:04 . 2008-01-09 09:43 28,672 --a------ C:\WINDOWS\SYSTEM32\DSentry .exe
2007-12-29 10:03 . 2008-01-20 23:41 15,360 --a------ C:\WINDOWS\SYSTEM32\ctfmon .exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-24 00:29 --------- d-----w C:\Program Files\Windows Defender
2008-01-23 16:54 --------- d-----w C:\Program Files\DivX
2008-01-23 16:46 --------- d-----w C:\Program Files\Common Files\Real
2008-01-23 16:45 --------- d-----w C:\Program Files\Real
2008-01-22 19:31 --------- d-----w C:\Program Files\McAfee
2008-01-20 16:17 --------- d-----w C:\Program Files\FileZilla
2008-01-08 21:46 --------- d-----w C:\Program Files\Microsoft Works
2008-01-04 21:58 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-01-03 04:22 --------- d-----w C:\Program Files\Creative
2008-01-02 22:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-02 19:23 --------- d-----w C:\Program Files\Maxtor
2007-12-21 18:58 3,012 ----a-w C:\drmHeader.bin
.
Code:
<pre>
----a-w 335,872 2008-01-03 15:31:24 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
----a-w 110,592 2008-01-08 14:20:45 C:\Program Files\Common Files\Sonic\Update Manager\sgtray .exe
----a-w 45,056 2008-01-09 14:43:10 C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet .EXE
----a-w 49,152 2008-01-09 14:43:07 C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol .exe
----a-w 204,800 2008-01-08 14:20:41 C:\Program Files\Dell\Media Experience\PCMService .exe
----a-w 712,704 2008-01-02 18:57:04 C:\Program Files\Maxtor\ManagerApp\Onetouch .exe
----a-w 81,920 2008-01-02 18:57:01 C:\Program Files\Maxtor\OneTouch Status\maxmenumgr .exe
----a-w 1,694,208 2007-12-31 17:18:25 C:\Program Files\Messenger\MSMSGS .EXE
----a-w 33,648 2008-01-11 23:08:35 C:\Program Files\Microsoft Office\Office12\GrooveMonitor .exe
----a-w 286,720 2008-01-13 20:51:14 C:\Program Files\QuickTime\qttask .exe
----a-w 90,112 2008-01-09 14:43:12 C:\WINDOWS\UpdReg .EXE
----a-w 15,360 2008-01-21 04:41:33 C:\WINDOWS\SYSTEM32\ctfmon .exe
----a-w 28,672 2008-01-09 14:43:15 C:\WINDOWS\SYSTEM32\DSentry .exe
----a-w 114,744 2008-01-09 14:43:07 C:\WINDOWS\SYSTEM32\dla\tfswctrl .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{be24949a-9713-48a3-a5f6-64b8016a2907}]
C:\WINDOWS\system32\ssavhnkx.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sonic RecordNow!"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]
"SB Audigy 2 Startup Menu"=" /L:ENG" []
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 12:24 28672 C:\WINDOWS\SYSTEM32\Ati2mdxx.exe]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [ ]
"CTSysVol"="C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [ ]
"CTDVDDet"="C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [ ]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [ ]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [ ]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [ ]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [ ]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [ ]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2008-01-23 18:47 582992]
"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 17920 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 18944 C:\WINDOWS\SYSTEM32\CTXFIHLP.EXE]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-23 18:47 185896]
C:\Documents and Settings\Derk\Start Menu\Programs\Startup\
palmOne Registration.lnk - C:\Program Files\Palm\register.exe [2005-09-19 12:20:36 2367488]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2004-01-15 21:49:48 49254]
HotSync Manager.lnk - C:\Program Files\Palm\Hotsync.exe [2004-06-09 14:16:08 471040]
HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\Palm\Hotsync.exe [2004-06-09 14:16:08 471040]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\pmkhi.exe
.
Contents of the 'Scheduled Tasks' folder
"2004-01-08 00:30:00 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE
"2007-07-14 14:32:30 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2007-07-14 14:32:28 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-01-24 00:35:57 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-23 19:36:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************