ComboFix 08-09-14.01 - Jeven 2008-09-14 16:22:17.1 - NTFSx86
Running from: C:\Documents and Settings\Jeven\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Jeven\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\system32\actskn43.ocx
.
((((((((((((((((((((((((( Files Created from 2008-08-14 to 2008-09-14 )))))))))))))))))))))))))))))))
.
2008-09-14 15:59 . 2008-09-14 15:59 <DIR> d-------- C:\Documents and Settings\Jeven\Application Data\Malwarebytes
2008-09-14 15:58 . 2008-09-14 15:59 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-14 15:58 . 2008-09-14 15:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-14 15:58 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-14 15:58 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-14 15:49 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-14 14:14 . 2008-09-14 14:14 <DIR> d-------- C:\WINDOWS\ERUNT
2008-09-14 14:09 . 2008-09-14 14:09 <DIR> d-------- C:\SDFix
2008-09-14 14:04 . 2008-09-14 14:04 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2008-09-14 11:52 . 2008-09-14 11:52 <DIR> d--hs---- C:\Documents and Settings\LocalService.NT AUTHORITY
2008-09-14 11:47 . 2008-09-14 11:47 <DIR> d-------- C:\WINDOWS\system32\SpycatcherAgentSetupTemp
2008-09-14 05:45 . 2008-09-14 11:35 <DIR> d--h----- C:\$AVG8.VAULT$
2008-09-14 04:46 . 2008-09-14 04:50 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-09-14 04:46 . 2008-09-14 04:46 <DIR> d-------- C:\Program Files\AVG
2008-09-14 04:46 . 2008-09-14 04:46 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-14 04:46 . 2008-09-14 04:46 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-14 04:46 . 2008-09-14 04:46 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-09-14 04:45 . 2008-09-14 04:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-09-13 01:31 . 2008-09-13 01:31 39,424 --a------ C:\Documents and Settings\Jeven\xrt_opye.exe
2008-09-12 17:49 . 2008-09-12 17:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\HPQ
2008-09-06 17:27 . 2008-09-12 17:42 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-05 15:14 . 2007-12-24 17:37 138,384 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-08-31 02:43 . 2008-08-31 02:46 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-08-30 23:15 . 2008-08-30 23:15 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-30 22:52 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-08-30 22:52 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-30 02:54 . 2008-07-18 22:07 270,880 --a------ C:\WINDOWS\system32\mucltui.dll
2008-08-30 02:54 . 2008-07-18 22:07 210,976 --a------ C:\WINDOWS\system32\muweb.dll
2008-08-30 02:54 . 2008-07-18 22:07 29,728 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-08-21 15:17 . 2008-08-21 15:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Reflexive
2008-08-21 15:16 . 2008-08-21 15:48 <DIR> d-------- C:\Program Files\Music Catch
2008-08-17 01:54 . 2008-09-10 11:40 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-08-17 01:54 . 2008-08-17 01:54 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-14 19:55 --------- d-----w C:\Program Files\Java
2008-09-14 03:21 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-12 21:43 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-09-09 02:23 --------- d-----w C:\Documents and Settings\Jeven\Application Data\uTorrent
2008-09-08 22:04 --------- d-----w C:\Program Files\Magic Workstation
2008-09-08 21:43 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-06 14:18 --------- d-----w C:\Documents and Settings\Jeven\Application Data\Move Networks
2008-09-05 19:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-05 19:14 --------- d-----w C:\Program Files\Trend Micro
2008-08-31 19:23 10 ----a-w C:\Documents and Settings\All Users\Application Data\mmrpplic.dat
2008-08-20 03:18 --------- d-----w C:\Documents and Settings\Jeven\Application Data\Publish Providers
2008-08-12 09:43 --------- d-----w C:\Program Files\Puzzle Quest
2008-08-12 01:32 --------- d-----w C:\Program Files\Lavasoft
2008-08-12 01:31 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-12 01:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-07 21:11 --------- d-----w C:\Program Files\Jewel Quest Solitaire II
2008-08-01 23:50 --------- d-----w C:\Program Files\OpenAL
2008-07-29 19:07 --------- d-----w C:\Program Files\AIM
2008-07-26 19:20 --------- d-----w C:\Program Files\Gold Rush Treasure Hunt
2008-07-26 18:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\GameHouse
2008-07-22 03:59 --------- d-----w C:\Program Files\Advanced GIF Optimizer
2008-07-20 21:07 --------- d-----w C:\Program Files\Astro Avenger 2
2008-07-20 06:38 --------- d-----w C:\Documents and Settings\Jeven\Application Data\Skype
2008-07-20 04:44 --------- d-----w C:\Program Files\Drop Em Deluxe
2008-07-19 17:08 --------- d-----w C:\Program Files\Jewel Quest III
2008-07-19 16:04 --------- d-----w C:\Program Files\Diablo II
2008-07-17 05:27 --------- d-----w C:\Documents and Settings\Jeven\Application Data\iWin
2008-03-26 21:29 0 -c--a-w C:\Program Files\temp01
2008-03-03 07:40 774,144 -c--a-w C:\Program Files\RngInterstitial.dll
2007-07-15 17:48 1,158 ----a-w C:\Documents and Settings\Jeven\Application Data\wklnhst.dat
2007-05-09 19:43 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2007-02-28 01:35 356,352 ----a-w C:\Documents and Settings\Jeven\cwshredder.dll
2006-06-09 08:41 0 -c--a-w C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
2007-12-17 12:43 27,648 --sh--w C:\WINDOWS\system32\Smab0.dll
.
------- Sigcheck -------
2004-08-04 08:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\SoftwareDistribution\Download\
0d3b5d19cc06db007bbe6584808bfa9e\backup\winlogon.exe
2008-09-13 01:32 502272 9b1bd82bd0761b5ba986af66d2809c30 C:\WINDOWS\system32\winlogon.exe
2004-08-04 08:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\dllcache\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-10 253952]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 282624]
"SMSERIAL"="sm56hlpr.exe" [2005-01-24 C:\WINDOWS\sm56hlpr.exe]
C:\Documents and Settings\Jeven\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)
"RevertWebViewSecurity"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\Documents and Settings\Jeven\Desktop\News folder\News and such.html
FriendlyName=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\utorrent\\utorrent.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\HydraIRC\\HydraIRC.exe"=
"C:\\Program Files\\GameHouse\\Wheel of Fortune\\Wheel of Fortune.exe"=
"C:\\Program Files\\MSN Games\\JEOPARDY! Deluxe\\JEOPARDY! Deluxe.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Risk II\\RiskII.RWG"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 16512]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\SETUP.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKCU-Main,Default_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R0 -: HKLM-Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R0 -: HKLM-Main,Search Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 -: HKCU-SearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O8 -: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O16 -: {32305793-C19A-48E7-AD2F-D87FF7B264A4} - hxxp://download.tenebril.com/pub/bin/scanner2008/TenebrilSpywareScanner.ocx
C:\WINDOWS\Downloaded Program Files\TenebrilSpywareScanner.ocx
O16 -: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game02.zylom.com/activex/zylomgamesplayer.cab
C:\WINDOWS\Downloaded Program Files\ZylomGamesPlayer.inf
C:\WINDOWS\Downloaded Program Files\zylomgamesplayer.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-14 16:35:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-14 16:47:14
ComboFix-quarantined-files.txt 2008-09-14 20:46:24
Pre-Run: 16,301,805,568 bytes free
Post-Run: 17,817,219,072 bytes free
181 --- E O F --- 2008-09-14 03:50:07