gerhardvdm28
New member
Help...!
I have attached a word doc with spyware scan results from my PC. Spybot can only identify one of the 14 virusses (see attachement SpyNoMore)....also, after removing this thing, it automatically re-appears.....:spider: Help.....I don't want to spend money on Spyware that is useless....!!!
Thanx
Gerhard
All these virusses are situated in HKEY_LOCAL_MACHINE...
ComboFix 08-01-04.1 - Gerry 2008-01-05 22:27:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1350 [GMT 2:00]
Running from: C:\Documents and Settings\Gerry\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kdsug.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.
2008-01-05 22:26 . 2008-01-05 22:27 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\Skype
2008-01-05 22:25 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-05 22:05 . 2008-01-05 22:05 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-01-05 22:05 . 2008-01-05 22:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-01-05 10:09 . 2008-01-05 10:09 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-05 10:09 . 2008-01-05 10:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-05 09:34 . 2008-01-05 10:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-03 21:44 . 2008-01-03 21:44 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\RegistrySmart
2008-01-03 21:43 . 2008-01-03 22:01 <DIR> d-------- C:\Program Files\RegistrySmart
2008-01-03 21:17 . 2008-01-05 12:18 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-03 21:03 . 2008-01-03 21:03 138,752 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-01-03 20:54 . 2008-01-04 22:06 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-01-03 20:54 . 2008-01-03 20:54 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\PC Tools
2008-01-03 20:54 . 2008-01-03 20:56 74,240 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-01-03 20:54 . 2008-01-03 20:56 56,832 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-01-03 20:54 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-01-03 20:54 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-01-03 20:53 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-01-03 20:49 . 2008-01-03 20:49 <DIR> d--h----- C:\WINDOWS\PIF
2008-01-03 20:39 . 2008-01-05 00:16 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-01-03 20:39 . 2008-01-03 20:39 <DIR> d-------- C:\Program Files\Crawler
2008-01-03 20:39 . 2008-01-05 17:50 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\Spyware Terminator
2008-01-03 20:39 . 2008-01-04 23:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-01-03 18:04 . 2008-01-03 18:04 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\Symantec
2008-01-03 13:09 . 2008-01-03 15:53 <DIR> d-------- C:\Program Files\Norton AntiVirus
2008-01-03 13:06 . 2008-01-03 18:04 <DIR> d-------- C:\Program Files\Norton SystemWorks
2008-01-03 13:06 . 2008-01-03 15:50 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-03 13:06 . 2008-01-03 15:50 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-03 13:05 . 2008-01-03 15:50 <DIR> d-------- C:\Program Files\Symantec
2008-01-03 13:05 . 2008-01-03 15:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-03 00:41 . 2008-01-03 00:41 <DIR> d-------- C:\Program Files\CheckIt
2008-01-02 22:07 . 2008-01-02 22:07 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\Grisoft
2008-01-02 22:07 . 2008-01-02 22:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-02 22:07 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-02 22:05 . 2007-11-26 10:38 238,848 --a------ C:\WINDOWS\UNBOC.EXE
2008-01-02 22:05 . 2007-05-08 17:01 208,896 --a------ C:\WINDOWS\CMDLIC.DLL
2008-01-02 22:05 . 2006-02-28 14:00 22,528 --a------ C:\WINDOWS\system32\wsock32.dlb
2008-01-02 21:46 . 2008-01-02 21:46 <DIR> d-------- C:\Program Files\Windows Defender
2008-01-02 21:21 . 2008-01-02 23:53 <DIR> d-------- C:\Program Files\SpyNoMore
2008-01-02 21:21 . 2008-01-02 21:21 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2007-12-25 13:07 . 2007-12-25 13:09 165,437 --a------ C:\WINDOWS\system32\nvapps.xml
2007-12-25 13:06 . 2007-12-25 13:06 <DIR> d-------- C:\WINDOWS\nview
2007-12-25 13:06 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-12-25 13:06 . 2007-12-05 01:41 356,352 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-12-25 13:06 . 2007-12-05 01:41 17,737 --a------ C:\WINDOWS\system32\nvdisp.nvu
2007-12-24 14:27 . 2007-12-24 14:39 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\Yahoo!
2007-12-24 14:17 . 2007-12-24 14:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-12-24 14:15 . 2007-12-24 14:39 <DIR> d-------- C:\Program Files\Yahoo!
2007-12-22 16:53 . 2007-12-22 16:53 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Intel
2007-12-22 16:53 . 2007-12-22 16:53 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\FaxCtr
2007-12-22 16:07 . 2007-05-31 19:30 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2007-12-22 16:07 . 2007-05-31 19:29 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 20:13 --------- d-----w C:\Program Files\Google
2008-01-05 20:05 --------- d-----w C:\Program Files\Skype
2008-01-05 10:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-01-05 08:08 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-04 21:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-04 20:11 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-03 13:50 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-03 13:50 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-02 17:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-12-25 15:31 --------- d-----w C:\Program Files\DVD Shrink
2007-12-25 15:30 --------- d-----w C:\Program Files\DVD Decrypter
2007-12-04 23:41 7,435,392 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-12-03 19:40 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-12-03 18:20 22,328 ----a-w C:\Documents and Settings\Gerry\Application Data\PnkBstrK.sys
2007-11-30 21:57 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-11-30 21:57 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-11-30 21:57 279,088 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-11-30 21:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-11-30 21:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-11-30 21:57 10,545 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-11-30 21:57 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-11-30 21:57 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-11-30 21:57 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-20 17:36 --------- d-----w C:\Documents and Settings\Gerry\Application Data\NeroDCTemplates
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 05:48 --------- d-----w C:\Program Files\e-Sword
2007-10-29 18:26 5,953,620 ----a-w C:\WINDOWS\F-18 Hornet.scr
2007-10-28 15:07 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-10-28 15:07 245,760 ------w C:\WINDOWS\Setup1.exe
2007-10-22 16:59 21,184 ----a-w C:\Documents and Settings\Gerry\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 12:32 81920]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 14:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-15 06:03 16132608 C:\WINDOWS\RTHDCPL.exe]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-02-24 19:29 196709]
"ipTray.exe"="C:\Program Files\Intel\IDU\iptray.exe" [2006-12-28 18:07 2242328]
"LXCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-07-20 15:44 73728]
"lxccmon.exe"="C:\Program Files\Lexmark 3300 Series\lxccmon.exe" [2005-07-21 02:16 192512]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 11:36 299008]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" [2007-12-26 16:50 1212368]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-10-28 08:38 107112]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-06 04:22 26248]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-01-03 20:44 2834432]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24 1065800]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-09-02 22:02:34]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-01-03 21:03]
R2 BCMNTIO;BCMNTIO;C:\PROGRA~1\CheckIt\DIAGNO~1\BCMNTIO.sys [2004-03-05 17:09]
R2 MAPMEM;MAPMEM;C:\PROGRA~1\CheckIt\DIAGNO~1\MAPMEM.sys [2004-03-05 17:09]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2007-09-02 21:08]
R3 NPDriver;Norton UnErase Protection Driver;C:\WINDOWS\system32\Drivers\NPDRIVER.SYS [2006-10-10 15:17]
S3 BOCDRIVE;BOClean Kernel Monitor.;C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys []
S3 BTNetFilter;Bluetooth Network Filter;C:\WINDOWS\system32\drivers\BTNetFilter.sys [2004-12-16 16:32]
S3 Netcom3;NetCom3 Service;C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe []
S3 SDdriver;SDdriver;C:\WINDOWS\system32\Drivers\sddriver.sys [2005-11-04 04:43]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ed74b7e-8558-11dc-8804-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ed74b7f-8558-11dc-8804-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34324157-846e-11dc-8800-101111111111}]
\Shell\AutoRun\command - I:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34324158-846e-11dc-8800-101111111111}]
\Shell\AutoRun\command - I:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4d28870f-7f01-11dc-87f0-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f5f942a-8560-11dc-8805-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68d6372a-7e50-11dc-87ed-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68d6372b-7e50-11dc-87ed-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0a2075c-8563-11dc-8807-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0a2075d-8563-11dc-8807-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0a2075e-8563-11dc-8807-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d94e72a4-8c8f-11dc-8811-965bf849a81f}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-05 20:28:15 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-01-03 13:39:04 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Gerry.job"
- C:\PROGRA~1\NORTON~2\Navw32.exeh/TASK:
"2007-12-28 18:11:56 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Gerry.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/TASK:
"2008-01-03 11:07:00 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Norton SystemWorks\OBC.exe
"2008-01-03 19:44:35 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.ex
- C:\Program Files\RegistrySmart
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-05 22:36:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-05 22:38:40 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-05 20:38:35
.
2008-01-04 20:10:37 --- E O F ---
I have attached a word doc with spyware scan results from my PC. Spybot can only identify one of the 14 virusses (see attachement SpyNoMore)....also, after removing this thing, it automatically re-appears.....:spider: Help.....I don't want to spend money on Spyware that is useless....!!!
Thanx
Gerhard
All these virusses are situated in HKEY_LOCAL_MACHINE...
ComboFix 08-01-04.1 - Gerry 2008-01-05 22:27:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1350 [GMT 2:00]
Running from: C:\Documents and Settings\Gerry\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kdsug.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.
2008-01-05 22:26 . 2008-01-05 22:27 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\Skype
2008-01-05 22:25 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-05 22:05 . 2008-01-05 22:05 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-01-05 22:05 . 2008-01-05 22:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-01-05 10:09 . 2008-01-05 10:09 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-05 10:09 . 2008-01-05 10:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-05 09:34 . 2008-01-05 10:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-03 21:44 . 2008-01-03 21:44 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\RegistrySmart
2008-01-03 21:43 . 2008-01-03 22:01 <DIR> d-------- C:\Program Files\RegistrySmart
2008-01-03 21:17 . 2008-01-05 12:18 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-03 21:03 . 2008-01-03 21:03 138,752 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-01-03 20:54 . 2008-01-04 22:06 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-01-03 20:54 . 2008-01-03 20:54 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\PC Tools
2008-01-03 20:54 . 2008-01-03 20:56 74,240 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-01-03 20:54 . 2008-01-03 20:56 56,832 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-01-03 20:54 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-01-03 20:54 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-01-03 20:53 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-01-03 20:49 . 2008-01-03 20:49 <DIR> d--h----- C:\WINDOWS\PIF
2008-01-03 20:39 . 2008-01-05 00:16 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-01-03 20:39 . 2008-01-03 20:39 <DIR> d-------- C:\Program Files\Crawler
2008-01-03 20:39 . 2008-01-05 17:50 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\Spyware Terminator
2008-01-03 20:39 . 2008-01-04 23:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-01-03 18:04 . 2008-01-03 18:04 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\Symantec
2008-01-03 13:09 . 2008-01-03 15:53 <DIR> d-------- C:\Program Files\Norton AntiVirus
2008-01-03 13:06 . 2008-01-03 18:04 <DIR> d-------- C:\Program Files\Norton SystemWorks
2008-01-03 13:06 . 2008-01-03 15:50 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-03 13:06 . 2008-01-03 15:50 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-03 13:05 . 2008-01-03 15:50 <DIR> d-------- C:\Program Files\Symantec
2008-01-03 13:05 . 2008-01-03 15:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-03 00:41 . 2008-01-03 00:41 <DIR> d-------- C:\Program Files\CheckIt
2008-01-02 22:07 . 2008-01-02 22:07 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\Grisoft
2008-01-02 22:07 . 2008-01-02 22:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-02 22:07 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-02 22:05 . 2007-11-26 10:38 238,848 --a------ C:\WINDOWS\UNBOC.EXE
2008-01-02 22:05 . 2007-05-08 17:01 208,896 --a------ C:\WINDOWS\CMDLIC.DLL
2008-01-02 22:05 . 2006-02-28 14:00 22,528 --a------ C:\WINDOWS\system32\wsock32.dlb
2008-01-02 21:46 . 2008-01-02 21:46 <DIR> d-------- C:\Program Files\Windows Defender
2008-01-02 21:21 . 2008-01-02 23:53 <DIR> d-------- C:\Program Files\SpyNoMore
2008-01-02 21:21 . 2008-01-02 21:21 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2007-12-25 13:07 . 2007-12-25 13:09 165,437 --a------ C:\WINDOWS\system32\nvapps.xml
2007-12-25 13:06 . 2007-12-25 13:06 <DIR> d-------- C:\WINDOWS\nview
2007-12-25 13:06 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-12-25 13:06 . 2007-12-05 01:41 356,352 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-12-25 13:06 . 2007-12-05 01:41 17,737 --a------ C:\WINDOWS\system32\nvdisp.nvu
2007-12-24 14:27 . 2007-12-24 14:39 <DIR> d-------- C:\Documents and Settings\Gerry\Application Data\Yahoo!
2007-12-24 14:17 . 2007-12-24 14:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-12-24 14:15 . 2007-12-24 14:39 <DIR> d-------- C:\Program Files\Yahoo!
2007-12-22 16:53 . 2007-12-22 16:53 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Intel
2007-12-22 16:53 . 2007-12-22 16:53 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\FaxCtr
2007-12-22 16:07 . 2007-05-31 19:30 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2007-12-22 16:07 . 2007-05-31 19:29 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 20:13 --------- d-----w C:\Program Files\Google
2008-01-05 20:05 --------- d-----w C:\Program Files\Skype
2008-01-05 10:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-01-05 08:08 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-04 21:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-04 20:11 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-03 13:50 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-03 13:50 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-02 17:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-12-25 15:31 --------- d-----w C:\Program Files\DVD Shrink
2007-12-25 15:30 --------- d-----w C:\Program Files\DVD Decrypter
2007-12-04 23:41 7,435,392 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-12-03 19:40 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-12-03 18:20 22,328 ----a-w C:\Documents and Settings\Gerry\Application Data\PnkBstrK.sys
2007-11-30 21:57 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-11-30 21:57 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-11-30 21:57 279,088 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-11-30 21:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-11-30 21:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-11-30 21:57 10,545 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-11-30 21:57 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-11-30 21:57 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-11-30 21:57 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-20 17:36 --------- d-----w C:\Documents and Settings\Gerry\Application Data\NeroDCTemplates
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 05:48 --------- d-----w C:\Program Files\e-Sword
2007-10-29 18:26 5,953,620 ----a-w C:\WINDOWS\F-18 Hornet.scr
2007-10-28 15:07 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-10-28 15:07 245,760 ------w C:\WINDOWS\Setup1.exe
2007-10-22 16:59 21,184 ----a-w C:\Documents and Settings\Gerry\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 12:32 81920]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 14:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-15 06:03 16132608 C:\WINDOWS\RTHDCPL.exe]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-02-24 19:29 196709]
"ipTray.exe"="C:\Program Files\Intel\IDU\iptray.exe" [2006-12-28 18:07 2242328]
"LXCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-07-20 15:44 73728]
"lxccmon.exe"="C:\Program Files\Lexmark 3300 Series\lxccmon.exe" [2005-07-21 02:16 192512]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 11:36 299008]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" [2007-12-26 16:50 1212368]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-10-28 08:38 107112]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-06 04:22 26248]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-01-03 20:44 2834432]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24 1065800]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-09-02 22:02:34]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-01-03 21:03]
R2 BCMNTIO;BCMNTIO;C:\PROGRA~1\CheckIt\DIAGNO~1\BCMNTIO.sys [2004-03-05 17:09]
R2 MAPMEM;MAPMEM;C:\PROGRA~1\CheckIt\DIAGNO~1\MAPMEM.sys [2004-03-05 17:09]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2007-09-02 21:08]
R3 NPDriver;Norton UnErase Protection Driver;C:\WINDOWS\system32\Drivers\NPDRIVER.SYS [2006-10-10 15:17]
S3 BOCDRIVE;BOClean Kernel Monitor.;C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys []
S3 BTNetFilter;Bluetooth Network Filter;C:\WINDOWS\system32\drivers\BTNetFilter.sys [2004-12-16 16:32]
S3 Netcom3;NetCom3 Service;C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe []
S3 SDdriver;SDdriver;C:\WINDOWS\system32\Drivers\sddriver.sys [2005-11-04 04:43]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ed74b7e-8558-11dc-8804-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ed74b7f-8558-11dc-8804-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34324157-846e-11dc-8800-101111111111}]
\Shell\AutoRun\command - I:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34324158-846e-11dc-8800-101111111111}]
\Shell\AutoRun\command - I:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4d28870f-7f01-11dc-87f0-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f5f942a-8560-11dc-8805-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68d6372a-7e50-11dc-87ed-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68d6372b-7e50-11dc-87ed-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0a2075c-8563-11dc-8807-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0a2075d-8563-11dc-8807-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0a2075e-8563-11dc-8807-101111111111}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d94e72a4-8c8f-11dc-8811-965bf849a81f}]
\Shell\AutoRun\command - H:\VMC_PBStarter.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-05 20:28:15 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-01-03 13:39:04 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Gerry.job"
- C:\PROGRA~1\NORTON~2\Navw32.exeh/TASK:
"2007-12-28 18:11:56 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Gerry.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/TASK:
"2008-01-03 11:07:00 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Norton SystemWorks\OBC.exe
"2008-01-03 19:44:35 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.ex
- C:\Program Files\RegistrySmart
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-05 22:36:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-05 22:38:40 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-05 20:38:35
.
2008-01-04 20:10:37 --- E O F ---
Last edited by a moderator: