ComboFix 07-12-04.3 - Administrator 2007-12-05 10:38:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.145 [GMT 8:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\ResErrors.log
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\install.exe
C:\Program Files\outlook
C:\UGA6P
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\npdtubdv.dllbox
C:\WINDOWS\system32\o2
C:\WINDOWS\system32\o2\banedll2.exe
C:\WINDOWS\system32\pskill.exe
C:\WINDOWS\system32\z1
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_FMTR
((((((((((((((((((((((((( Files Created from 2007-11-05 to 2007-12-05 )))))))))))))))))))))))))))))))
.
2007-12-05 10:23 . 2007-12-05 10:23 <DIR> d-------- C:\WINDOWS\ERUNT
2007-12-03 12:30 . 2007-12-03 12:30 <DIR> d-------- C:\Documents and Settings\Administrator\Incomplete
2007-12-03 12:30 . 2007-12-05 10:21 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2007-12-03 12:28 . 2007-07-12 02:22 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-03 12:27 . 2007-12-03 12:28 <DIR> d-------- C:\Program Files\Java
2007-12-03 12:26 . 2007-12-03 12:28 <DIR> d-------- C:\Program Files\LimeWire
2007-12-03 12:26 . 2007-12-03 12:26 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-01 04:35 . 2007-12-01 04:35 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-12-01 04:03 . 2007-12-01 04:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-01 03:53 . 2006-09-06 00:03 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-01 03:52 . 2007-12-02 04:34 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-01 03:52 . 2007-12-01 03:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-01 03:52 . 2007-12-01 03:52 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-12-01 03:37 . 2007-12-01 03:37 167 --a------ C:\Documents and Settings\Administrator\2514.bat
2007-12-01 03:04 . 2007-12-01 03:04 <DIR> d-------- C:\Program Files\Windows Live Favorites
2007-11-29 13:21 . 2007-12-01 03:37 776,177 ---hs---- C:\WINDOWS\system32\nglsbncj.ini
2007-11-29 03:29 . 2007-11-29 03:29 167 --a------ C:\Documents and Settings\Administrator\8931.bat
2007-11-28 13:20 . 2007-11-29 13:21 772,637 ---hs---- C:\WINDOWS\system32\quvdjhjs.ini
2007-11-27 13:15 . 2007-11-28 13:16 781,212 ---hs---- C:\WINDOWS\system32\hcoagpcm.ini
2007-11-27 13:10 . 2007-11-27 13:10 167 --a------ C:\Documents and Settings\Administrator\2326.bat
2007-11-27 13:08 . 2007-11-27 13:08 <DIR> d-------- C:\WINDOWS\system32\xircom
2007-11-27 13:08 . 2007-11-27 13:08 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-11-26 14:22 . 2001-03-08 18:30 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-11-26 13:48 . 2007-11-27 13:09 780,311 ---hs---- C:\WINDOWS\system32\dfxhjjyv.ini
2007-11-26 12:17 . 2007-11-26 12:17 167 --a------ C:\Documents and Settings\Administrator\9266.bat
2007-11-25 13:19 . 2007-12-01 03:37 36,864 --a------ C:\Documents and Settings\Administrator\winlogo.exe
2007-11-25 13:19 . 2007-11-25 13:19 167 --a------ C:\Documents and Settings\Administrator\2526.bat
2007-11-25 12:42 . 2007-12-01 13:57 99,166 --ahs---- C:\WINDOWS\system32\knnmp.ini2
2007-11-25 12:42 . 2007-12-01 13:56 99,166 --ahs---- C:\WINDOWS\system32\knnmp.ini
2007-11-25 12:37 . 2007-11-25 12:37 531 --a------ C:\WINDOWS\system32\z.dat
2007-11-25 12:37 . 2007-11-25 12:37 293 --a------ C:\WINDOWS\system32\x.dat
2007-11-25 12:37 . 2007-11-25 12:37 167 --a------ C:\WINDOWS\system32\8712.bat
2007-11-25 12:36 . 2007-12-05 10:27 <DIR> d-------- C:\Temp
2007-11-25 12:36 . 2007-11-25 12:42 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-11-25 10:17 . 2007-11-25 10:34 286,720 --a------ C:\WINDOWS\iun506.exe
2007-11-20 13:01 . 2006-09-17 06:49 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2007-11-20 12:48 . 2006-09-17 06:49 52,736 --a------ C:\WINDOWS\system32\drivers\i8042prt.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-01-04 12:14 --------- d-----w C:\Program Files\Marvell
2008-01-04 12:13 --------- d-----w C:\Program Files\Mavell
2008-01-04 06:44 --------- d-----w C:\Program Files\ASUS Motherboard
2008-01-04 06:44 --------- d-----w C:\Program Files\ASUS Graphics Driver
2008-01-04 06:39 --------- d-----w C:\Program Files\Microsoft Works
2008-01-04 06:38 --------- d-----w C:\Program Files\Microsoft.NET
2008-01-04 06:37 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-01-04 06:12 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Talkback
2008-01-04 06:10 --------- d-----w C:\Program Files\TuneUp Utilities 2006
2008-01-04 06:10 --------- d-----w C:\Program Files\Skype
2008-01-04 06:10 --------- d-----w C:\Program Files\KGB Archiver
2008-01-04 06:10 --------- d-----w C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-01-04 06:09 --------- d-----w C:\Program Files\Symantec
2008-01-04 06:09 --------- d-----w C:\Program Files\SiSoftware
2008-01-04 06:07 --------- d-----w C:\Program Files\Paint.NET
2008-01-04 06:02 --------- d-----w C:\Program Files\Nero
2008-01-04 06:02 --------- d-----w C:\Program Files\Common Files\Ahead
2008-01-04 06:01 --------- d---a-w C:\Program Files\(uTorrent)
2008-01-04 06:01 --------- d---a-w C:\Program Files\(Media Player Classic)
2008-01-04 06:01 --------- d---a-w C:\Program Files\(IE7_Standalone)
2008-01-04 06:01 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-01-04 06:00 39,488 ----a-w C:\WINDOWS\system32\drivers\Pcouffin.sys
2008-01-04 06:00 --------- d---a-w C:\Program Files\Google
2008-01-04 06:00 --------- d---a-w C:\Program Files\(Gspot)
2008-01-04 06:00 --------- d---a-w C:\Program Files\(CWSRemover)
2008-01-04 06:00 --------- d---a-w C:\Program Files\(cpuz)
2008-01-04 06:00 --------- d-----w C:\Program Files\D-Tools
2008-01-04 06:00 --------- d-----w C:\Program Files\CloneDVD
2008-01-04 06:00 --------- d-----w C:\Program Files\CCleaner
2008-01-04 05:59 --------- d-----w C:\Program Files\WinAVIVideoConverter
2008-01-04 05:59 --------- d-----w C:\Program Files\SlySoft
2008-01-04 05:59 --------- d-----w C:\Program Files\Alcohol Soft
2008-01-04 05:58 --------- d-----w C:\Program Files\Lavasoft
2008-01-04 05:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-01-04 05:57 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-01-04 05:57 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-04 05:52 --------- d-----w C:\Program Files\7-Zip
2008-01-04 05:41 --------- d-----w C:\Program Files\WPIclose
2008-01-04 05:39 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-01-04 05:39 --------- d-----w C:\Program Files\Common Files\NVIDIA Shared
2008-01-04 05:37 --------- d-----w C:\Program Files\eXPerience
2008-01-04 05:31 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-01 20:43 --------- d---a-w C:\Program Files\(HijackThis)
2007-12-01 03:45 --------- d-----w C:\Program Files\Logitech
2007-11-30 19:52 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-30 19:11 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-14 19:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-12 05:28 --------- d-----w C:\Program Files\iTunes
2007-11-12 05:27 --------- d-----w C:\Program Files\iPod
2007-10-31 06:09 30,464 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2007-10-22 20:52 --------- d-----w C:\Documents and Settings\Administrator\Application Data\SlySoft
2007-10-14 08:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\NVIDIA
2007-10-14 08:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-10-12 19:58 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_C oinstaller_Critical.Wdf
2007-10-12 19:58 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_0 1005.Wdf
2007-10-07 04:07 --------- d-----w C:\Program Files\Motorola Phone Tools
2007-10-07 04:04 --------- d-----w C:\Program Files\Common Files\Motorola Shared
2007-10-07 04:03 92,064 ----a-w C:\Documents and Settings\Administrator\mqdmmdm.sys
2007-10-07 04:03 9,232 ----a-w C:\Documents and Settings\Administrator\mqdmmdfl.sys
2007-10-07 04:03 79,328 ----a-w C:\Documents and Settings\Administrator\mqdmserd.sys
2007-10-07 04:03 66,656 ----a-w C:\Documents and Settings\Administrator\mqdmbus.sys
2007-10-07 04:03 6,208 ----a-w C:\Documents and Settings\Administrator\mqdmcmnt.sys
2007-10-07 04:03 5,936 ----a-w C:\Documents and Settings\Administrator\mqdmwhnt.sys
2007-10-07 04:03 4,048 ----a-w C:\Documents and Settings\Administrator\mqdmcr.sys
2007-10-07 04:03 25,600 ----a-w C:\Documents and Settings\Administrator\usbsermptxp.sys
2007-10-07 04:03 22,768 ----a-w C:\Documents and Settings\Administrator\usbsermpt.sys
2007-10-07 00:25 --------- d-----w C:\Program Files\Avanquest update
2007-10-05 03:37 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AdobeUM
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{76C79E8C-DE23-4987-8CB9-8D05579B94F8}]
C:\PROGRAM FILES\LOGITECH\HONE83122.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe" [2007-02-23 16:19]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-10-01 20:00]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-06-21 11:42 C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="RUNDLL32.exe" [2006-10-01 20:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2006-09-02 02:54 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2006-10-01 20:00 C:\WINDOWS\system32\rundll32.exe]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-21 01:12]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 10:12]
"Logitech Hardware Abstraction Layer"="C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2006-07-19 12:03]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 12:03 C:\WINDOWS\KHALMNPR.Exe]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-08-03 09:44]
"LVCOMSX"="C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-08-03 13:29]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-02-14 02:29]
"QuickTime Task"="C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"e4c1f26f"="C:\WINDOWS\system32\jcnbslgn.dll" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-12-01 03:55]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2007-09-17 22:19:14]
Zapu Acceleration Engine.lnk - C:\Program Files\Zapu\Zapu\wincm.exe [2007-05-20]
Zapu.lnk - C:\Program Files\Zapu\Zapu\wDivi.exe [2007-05-20]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2008-01-04 13:57:52]
Java SATARaid.lnk - C:\Program Files\Silicon Image\Java SATARaid\run.bat [2007-02-23 16:50:32]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe [2007-02-23 16:19:36]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-01-06 05:37:31]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoRecentDocsMenu"= 1 (0x1)
"NoRecentDocsHistory"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoRecentDocsMenu"= 1 (0x1)
"NoRecentDocsHistory"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bu s.sys
R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346pr t.sys
R0 ndisrd;ndisrd;C:\WINDOWS\system32\drivers\ndisrd.s ys
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;C:\WINDOWS\system32\DRIVERS\nvcchflt.sys
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\DRIVERS\SI3112r.sys
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepK E.sys
R3 camvid20;Philips ToUcam Camera; Video;C:\WINDOWS\system32\DRIVERS\camdrv21.sys
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-05 01:42:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-05 02:31:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
************************************************** ************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-05 10:53:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
************************************************** ************************
.
Completion time: 2007-12-05 10:55:48 - machine was rebooted
.
--- E O F ---