ComboFix log II
Thanks. Sorry for the delay.
ComboFix 07-10-23.1 - Grant 2007-10-22 20:12:21.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.173 [GMT -7:00]
Running from: C:\Documents and Settings\Grant\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Grant\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-09-23 to 2007-10-23 )))))))))))))))))))))))))))))))
.
2007-10-14 18:13 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-14 13:21 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-10-13 19:46 <DIR> d-------- C:\WINDOWS\Performance
2007-10-13 19:45 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2007-10-13 00:44 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-10-13 00:39 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-10-10 15:30 582,656 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-07 21:06 128,896 --------- C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-10-07 21:06 23,040 --------- C:\WINDOWS\system32\dllcache\fltmc.exe
2007-10-07 21:06 16,896 --------- C:\WINDOWS\system32\dllcache\fltlib.dll
2007-10-07 21:03 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-10-07 20:29 6,058,496 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-07 20:29 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-10-07 20:29 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-07 20:29 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-07 20:29 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-07 20:29 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-07 20:29 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-07 18:20 <DIR> d-------- C:\Program Files\Norton AntiVirus
2007-10-07 17:21 <DIR> d-------- C:\Documents and Settings\All Users\Symantec Temporary Files
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-13 05:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-10-12 06:33 --------- d-----w C:\Program Files\Sonic
2007-10-08 01:44 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-08 01:44 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-08 01:44 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-08 01:44 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-08 01:44 --------- d-----w C:\Program Files\Symantec
2007-09-30 16:29 --------- d-----w C:\Program Files\Dl_cats
2007-09-20 22:21 --------- d-----w C:\Program Files\Lavasoft
2007-09-20 22:08 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-09-20 03:56 --------- d-----w C:\Program Files\DivX
2007-09-18 21:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-18 21:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-18 21:44 10,658 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-18 21:44 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-18 21:44 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-18 21:44 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-18 21:43 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-18 21:43 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-18 21:43 278,576 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-09-15 02:58 --------- d-----w C:\Program Files\Movie Outline 2.0
2007-09-15 02:03 --------- d-----w C:\Program Files\Common Files\Adobe
2007-09-15 01:56 --------- d-----w C:\Documents and Settings\Grant\Application Data\AdobeUM
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 10:04 824,832 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 477,696 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 3,584,512 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 07:34 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-08-14 01:54 413,696 ----a-w C:\WINDOWS\system32\vbscript.dll
2007-08-14 01:54 413,696 ------w C:\WINDOWS\system32\dllcache\vbscript.dll
2007-08-14 01:54 33,792 ----a-w C:\WINDOWS\system32\dllcache\custsat.dll
2007-08-14 01:54 191,488 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-14 01:54 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2007-08-14 01:54 156,160 ----a-w C:\WINDOWS\system32\dllcache\msls31.dll
2007-08-14 01:45 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2007-08-14 01:45 78,336 ------w C:\WINDOWS\system32\dllcache\ieencode.dll
2007-08-14 01:44 69,120 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-14 01:44 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-14 01:44 40,960 ------w C:\WINDOWS\system32\dllcache\licmgr10.dll
2007-08-14 01:42 17,408 ------w C:\WINDOWS\system32\dllcache\corpol.dll
2007-08-14 01:39 92,672 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-14 01:39 71,680 ----a-w C:\WINDOWS\system32\admparse.dll
2007-08-14 01:39 71,680 ------w C:\WINDOWS\system32\dllcache\admparse.dll
2007-08-14 01:39 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
2007-08-14 01:39 55,296 ------w C:\WINDOWS\system32\dllcache\iesetup.dll
2007-08-14 01:38 491,520 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-08-14 01:36 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-14 01:36 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2007-08-14 01:36 36,352 ------w C:\WINDOWS\system32\dllcache\imgutil.dll
2007-08-14 01:35 346,624 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-14 01:32 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2007-08-14 01:32 45,568 ------w C:\WINDOWS\system32\dllcache\mshta.exe
2007-08-14 01:18 60,416 ------w C:\WINDOWS\system32\dllcache\hmmapi.dll
2007-08-14 01:01 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
2007-08-14 01:01 48,128 ------w C:\WINDOWS\system32\dllcache\mshtmler.dll
2007-07-31 02:19 92,504 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-31 02:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 02:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 02:19 549,720 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-31 02:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 02:19 53,080 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-31 02:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 02:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 02:19 325,976 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-31 02:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 02:19 203,096 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-31 02:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 02:19 1,712,984 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-31 02:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-07-31 02:18 33,624 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2007-07-26 23:06 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-07-26 23:06 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-03-18 20:14:59 56 --sh--r C:\WINDOWS\system32\496E49D0A2.sys
2007-03-18 20:14:59 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-24 04:36]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 08:09]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 08:06]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 08:10]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 15:48]
"SigmatelSysTrayApp"="stsystra.exe" [2005-08-23 21:42 C:\WINDOWS\stsystra.exe]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" []
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-08-01 14:00]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 14:19]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 14:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 14:50]
"DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 06:50]
"dlccmon.exe"="C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 08:40]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-03-10 13:01 C:\WINDOWS\KHALMNPR.Exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 11:54]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 15:53]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-06-04 19:05]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-06-25 22:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00]
R0 PzWDM;PzWDM;C:\WINDOWS\system32\Drivers\PzWDM.sys
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-10-23 03:00:27 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Grant.job"
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-22 20:15:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-22 20:16:05
C:\ComboFix2.txt ... 2007-10-14 18:30
.
--- E O F ---