ComboFix 08-06-15.4 - Peelzy 2008-06-15 22:26:31.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.1308 [GMT -4:00]
Running from: C:\Users\Peelzy\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-16 to 2008-06-16 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-06-15 23:07 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-15 22:58 --------- d-----w C:\ProgramData\Google Updater
2008-06-15 20:49 --------- d-----w C:\Users\Peelzy\AppData\Roaming\uTorrent
2008-06-15 20:44 --------- d-----w C:\Program Files\Norton Security Scan
2008-06-14 17:49 --------- dc----w C:\Program Files\Final Draft Tagger
2008-06-14 17:49 --------- dc----w C:\Program Files\Final Draft 7
2008-06-14 17:49 --------- d-----w C:\ProgramData\Final Draft
2008-06-14 17:48 13,312 ----a-w C:\Windows\System32\paplso.dll
2008-06-14 17:47 --------- dc----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-14 15:22 --------- dc----w C:\Program Files\Common Files\PX Storage Engine
2008-06-14 10:55 --------- d-----w C:\Program Files\Windows Mail
2008-06-12 02:24 --------- d-----w C:\Users\Peelzy\AppData\Roaming\ZoomBrowser EX
2008-06-12 02:09 --------- d-----w C:\ProgramData\ZoomBrowser
2008-06-06 05:32 --------- d-----w C:\Users\Peelzy\AppData\Roaming\Canon
2008-06-06 02:42 --------- dc----w C:\Program Files\Canon
2008-06-04 21:24 --------- d-----w C:\Users\Peelzy\AppData\Roaming\OpenOffice.org2
2008-06-01 22:41 --------- dc----w C:\Program Files\Common Files\Skype
2008-06-01 22:41 --------- d-----w C:\Users\Peelzy\AppData\Roaming\Skype
2008-05-30 03:19 --------- dc----w C:\Program Files\iTunes
2008-05-30 03:19 --------- dc----w C:\Program Files\iPod
2008-05-30 03:18 --------- dc----w C:\Program Files\QuickTime
2008-05-17 13:23 --------- dc----w C:\Program Files\Safari
2008-05-17 13:20 --------- dc----w C:\Program Files\Apple Software Update
2008-05-16 03:29 --------- d---a-w C:\ProgramData\TEMP
2008-05-10 03:30 14,848 ----a-w C:\Windows\System32\wshrm.dll
2008-05-10 01:21 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
2008-04-26 08:02 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-04-25 04:23 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-04-25 04:23 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-04-25 04:23 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-25 04:22 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-03-28 23:03 129,520 ------w C:\Windows\System32\PxAFS.DLL
2007-10-16 00:20 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-20 13:51 815104]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Wind ows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\Windows\pss\Digital Line Detect.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Wind ows^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\Windows\pss\Google Updater.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Wind ows^Start Menu^Programs^Startup^QuickSet.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk
backup=C:\Windows\pss\QuickSet.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Peelzy^AppData^Roami ng^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=C:\Users\Peelzy\AppData\Roaming\Microsoft\Win dows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=C:\Windows\pss\OpenOffice.org 2.3.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Peelzy^AppData^Roami ng^Microsoft^Windows^Start Menu^Programs^Startup^WordWeb.lnk]
path=C:\Users\Peelzy\AppData\Roaming\Microsoft\Win dows\Start Menu\Programs\Startup\WordWeb.lnk
backup=C:\Windows\pss\WordWeb.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a--c--- 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
--a--c--- 2006-07-11 18:12 90112 C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
--a------ 2006-11-21 20:52 1540096 C:\Windows\system32\WLTRAY.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2007-03-15 13:09 460784 C:\Program Files\DellSupport\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
--a--c--- 2007-07-30 15:40 16384 c:\dell\dsca.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
--a--c--- 2007-05-25 02:03 17920 C:\Dell\E-Center\EULALauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-09-27 15:33 1862144 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
--a------ 2007-01-01 17:22 3739648 C:\Program Files\Google\Google Talk\googletalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2006-10-03 12:37 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a--c--- 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MskAgentexe]
C:\Program Files\McAfee\MSK\MskAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a--c--- 2007-10-18 12:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
--------- 2006-10-20 18:23 118784 C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
C:\Program Files\Spyware Doctor\SDTrayApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 2007-02-08 01:11 303104 C:\Windows\sttray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-04-23 17:45 22058792 C:\Program Files\Skype\\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-10-15 13:13 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2006-11-20 13:51 815104 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2007-09-27 22:52 1006264 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
--a------ 2006-11-02 08:34 2159104 C:\Windows\System32\oobefldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2006-11-02 08:34 201728 C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\FirewallRules]
"{881E06B2-1B5C-4688-8CD5-C9DFD3036842}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{C5D7AE26-63B0-47A6-9805-2EA6BC973888}"= UDP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{53BED0B2-1EA9-4B14-B72D-F1604E53BE22}"= TCP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{942F63FA-B235-4FF7-A86C-8D748D037AF0}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{1955ADAF-9348-4539-B914-1E726A720BC1}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{EDAE0B23-DA7C-4841-868F-1F0D8D5BB77D}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{5337734F-EE6E-4164-83EB-98723ED4A172}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{8ABD19A9-6623-40B8-A6E8-79CF46514DC5}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{ADACAE74-EDA2-49AA-ADF8-302FAD71A83A}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"TCP Query User{A354B29F-CFE3-4FA4-9ED0-27C5148D463B}C:\\program files\\online tv & radio stations\\onlinetv.exe"= UDP:C:\program files\online tv & radio stations\onlinetv.exe:OnlineTV
"UDP Query User{5D4B5136-446F-47FE-8597-A8C0F0EBB397}C:\\program files\\online tv & radio stations\\onlinetv.exe"= TCP:C:\program files\online tv & radio stations\onlinetv.exe:OnlineTV
"TCP Query User{ADE4D08B-DC84-46F7-81E5-93ECDF6EB3AB}C:\\program files\\sopcast\\sopcast.exe"= UDP:C:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{5F405949-9157-4B6A-A9B1-ABB18F675FAA}C:\\program files\\sopcast\\sopcast.exe"= TCP:C:\program files\sopcast\sopcast.exe:SopCast Main Application
"TCP Query User{597B92A4-E61A-4132-9743-38512F71D581}C:\\users\\peelzy\\appdata\\roaming\\ sopcast\\adv\\sopadver.exe"= UDP:C:\users\peelzy\appdata\roaming\sopcast\adv\so padver.exe:sopadver.exe
"UDP Query User{6A0751E3-7782-4D72-BDBF-79815332748E}C:\\users\\peelzy\\appdata\\roaming\\ sopcast\\adv\\sopadver.exe"= TCP:C:\users\peelzy\appdata\roaming\sopcast\adv\so padver.exe:sopadver.exe
"TCP Query User{5FFF29E5-BCF6-40C7-86BF-B6B1305E304C}C:\\program files\\ppstream\\ppstream.exe"= UDP:C:\program files\ppstream\ppstream.exe:PPS????
"UDP Query User{3DAE7E4B-78D4-4317-B817-51B9CE9D3C1E}C:\\program files\\ppstream\\ppstream.exe"= TCP:C:\program files\ppstream\ppstream.exe:PPS????
"{80871BA7-EB2F-493F-B772-69E6E548AE83}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{3F81E15F-38D7-433B-A38F-FBB1AD96F7C1}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{A58C82B5-69D1-4DF9-8AA5-11D270130EAA}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A7EFC44B-EF2B-48B1-813D-5115FC2958B6}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{06D33097-16C1-476A-9A9C-7CB18E982E91}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{B4863B2B-7AC6-4AD0-8245-E788B1D66112}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{AF0D453E-3E7C-4FA7-8CE9-57D9D2BBB2AC}"= TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{10681B51-EF32-4872-AF29-563DA2A52CA7}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{0FA59B3B-727B-453D-8088-070115B25A54}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|S vc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\PPStream\\PPStream.exe"= C:\Program Files\PPStream\PPStream.exe:*:Enabled:PPSÍøÂçµçÊÓ
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 11:22]
R3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-25 01:46]
S3 RimSerPort;RIM Virtual Serial Port;C:\Windows\system32\DRIVERS\RimSerial.sys [2005-08-16 13:02]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\F]
\shell\AutoRun\command - "F:\Install FreeAgent Tools.exe" /run
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{024927e2-ad86-11dc-8fd8-001c2398bbc5}]
\shell\AutoRun\command - F:\WD_Windows_Tools\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{3ae1afaf-f357-11dc-b695-001c2398bbc5}]
\shell\AutoRun\command - "F:\Install FreeAgent Tools.exe" /run
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{7e21f387-a74a-11dc-8a23-001c2398bbc5}]
\shell\AutoRun\command - wd_windows_tools\setup.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-14 02:54:16 C:\Windows\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-15 22:29:17
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-06-15 22:30:48
ComboFix-quarantined-files.txt 2008-06-16 02:30:30
The system cannot find message text for message number 0x2379 in the message file for Application.
The system cannot find message text for message number 0x2379 in the message file for Application.
188 --- E O F --- 2008-06-14 23:59:25