com bo log:
ComboFix 08-10-10.09 - user 2008-10-11 13:28:39.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.68 [GMT 8:00]
Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\TG.PIF
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\ciodms.dll
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\gprmsgse.axz
C:\WINDOWS\system32\gscpx32r.det
C:\WINDOWS\system32\musz1s.dll
C:\WINDOWS\system32\musz2s.dll
C:\WINDOWS\system32\Packet.dll
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ACPIDISK
-------\Legacy_NPF
-------\Legacy_RESSDT
-------\Legacy_ZESOFT
-------\Service_npf
-------\Service_RESSDT
((((((((((((((((((((((((( Files Created from 2008-09-11 to 2008-10-11 )))))))))))))))))))))))))))))))
.
2008-10-09 23:15 . 2008-10-09 01:33 <DIR> d-------- C:\SDFix
2008-10-09 20:21 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-10-09 20:12 . 2008-10-09 20:12 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-08 23:24 . 2008-10-08 23:24 <DIR> d-------- C:\Program Files\Symantec
2008-10-08 23:24 . 2008-10-08 23:24 124,464 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-10-08 23:24 . 2008-10-08 23:24 60,808 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-10-08 23:24 . 2008-10-08 23:24 35,888 -ra------ C:\WINDOWS\system32\drivers\SymIM.sys
2008-10-08 23:24 . 2008-10-08 23:24 10,635 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-10-08 23:24 . 2008-10-08 23:24 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-10-08 23:23 . 2008-10-08 23:23 <DIR> d-------- C:\WINDOWS\system32\drivers\NAV
2008-10-08 23:23 . 2008-10-08 23:23 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-10-08 23:23 . 2008-10-08 23:23 <DIR> d-------- C:\Program Files\Norton AntiVirus
2008-10-08 23:23 . 2008-10-08 23:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Norton
2008-10-08 23:17 . 2008-10-08 23:17 <DIR> d-------- C:\Program Files\NortonInstaller
2008-10-08 23:17 . 2008-10-08 23:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PCSettings
2008-10-08 23:17 . 2008-10-08 23:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-10-08 21:22 . 2008-10-08 21:22 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-10-08 21:22 . 2008-10-08 21:22 <DIR> d-------- C:\WINDOWS\system32\en
2008-10-08 21:22 . 2008-10-08 21:22 <DIR> d-------- C:\WINDOWS\system32\bits
2008-10-08 21:22 . 2008-10-08 21:22 <DIR> d-------- C:\WINDOWS\l2schemas
2008-10-08 20:17 . 2008-10-08 20:17 <DIR> d-------- C:\Documents and Settings\user\Application Data\Malwarebytes
2008-10-08 20:16 . 2008-10-08 20:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-08 19:21 . 2008-10-08 19:21 <DIR> d-------- C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com
2008-10-08 19:21 . 2008-10-08 19:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-10-08 00:06 . 2008-04-14 08:12 897,024 --------- C:\WINDOWS\system32\dllcache\wmspdmoe.dll
2008-10-08 00:05 . 2008-04-14 08:12 786,432 --------- C:\WINDOWS\system32\dllcache\migrate.exe
2008-10-08 00:04 . 2008-04-14 08:12 774,144 --------- C:\WINDOWS\system32\dllcache\setup_wm.exe
2008-10-08 00:04 . 2008-04-14 08:12 259,072 --------- C:\WINDOWS\system32\dllcache\msnetobj.dll
2008-10-08 00:04 . 2008-04-14 08:12 233,472 --------- C:\WINDOWS\system32\dllcache\wmpdxm.dll
2008-10-08 00:04 . 2008-04-14 08:12 226,816 --------- C:\WINDOWS\system32\dllcache\npdrmv2.dll
2008-10-08 00:04 . 2008-04-14 02:40 10,240 --------- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-10-08 00:04 . 2008-04-14 08:11 9,216 --------- C:\WINDOWS\system32\dot3dlg.dll
2008-10-08 00:04 . 2008-04-14 08:11 7,168 --------- C:\WINDOWS\system32\bitsprx4.dll
2008-10-08 00:04 . 2008-04-14 08:09 6,144 --------- C:\WINDOWS\system32\kbdpash.dll
2008-10-08 00:04 . 2008-04-14 08:09 6,144 --------- C:\WINDOWS\system32\kbdnepr.dll
2008-10-08 00:04 . 2008-04-14 08:09 6,144 --------- C:\WINDOWS\system32\kbdiultn.dll
2008-10-08 00:04 . 2008-04-14 08:09 6,144 --------- C:\WINDOWS\system32\kbdbhc.dll
2008-10-08 00:02 . 2008-04-14 01:28 2,940,928 --------- C:\WINDOWS\system32\dllcache\wmploc.dll
2008-10-08 00:01 . 2008-04-14 08:10 844,314 --------- C:\WINDOWS\system32\dllcache\msdxm.ocx
2008-10-08 00:00 . 2002-11-04 19:02 613,334 --------- C:\WINDOWS\system32\dllcache\wmplayer.chm
2008-10-07 23:59 . 2001-08-18 20:00 572,557 --------- C:\WINDOWS\system32\dllcache\rtuner.wmv
2008-10-06 23:45 . 2007-08-13 18:54 33,792 --a------ C:\WINDOWS\system32\dllcache\custsat.dll
2008-10-06 21:24 . 2008-10-06 21:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-10-06 21:21 . 2008-10-06 21:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-10-04 11:56 . 2008-06-13 19:05 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-10-04 11:55 . 2008-04-12 03:04 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-10-04 11:55 . 2008-05-08 22:02 203,136 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-10-04 11:53 . 2008-05-01 22:33 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-10-03 21:02 . 2008-10-03 21:02 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-10-03 20:38 . 2008-04-14 08:12 59,392 --------- C:\WINDOWS\system32\logman.exe
2008-10-03 20:38 . 2008-04-14 08:12 9,216 --------- C:\WINDOWS\system32\proxycfg.exe
2008-10-03 20:35 . 2008-10-03 20:35 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-10-03 20:32 . 2007-08-10 20:46 26,488 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-10-03 20:32 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\
002296_.tmp
2008-10-03 20:29 . 2008-10-03 20:29 <DIR> d-------- C:\WINDOWS\EHome
2008-10-02 21:48 . 2008-10-02 21:48 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-10-02 20:59 . 2003-03-19 05:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-10-01 22:38 . 2008-10-01 22:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-01 17:33 . 2008-10-01 17:35 25,994 --a------ C:\WINDOWS\rdlll.exe
2008-10-01 16:53 . 2008-10-01 17:07 79,722 --a------ C:\WINDOWS\iggbq.exe
2008-09-27 17:51 . 2003-04-17 21:26 79 --a------ C:\WINDOWS\delay.reg
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-25 13:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-08-24 08:59 --------- d-----w C:\Program Files\Axis Communications
2008-08-05 15:27 451,984 ----a-w C:\msgr8sg.exe
2008-07-23 16:48 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-07-18 14:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 14:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 14:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 14:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 14:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 14:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 14:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 14:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 14:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 14:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 14:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-28 3660848]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 106496]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-07-23 4616192]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-16 479232]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-02 3739648]
"SoundMan"="SOUNDMAN.EXE" [2003-08-15 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2003-07-23 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="C:\WINDOWS\System32\NVMCTRAY.DLL" [2003-07-23 49152]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2004-11-18 106560]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2005-04-15 65588]
TL-WN321G Wireless Utility.lnk - C:\Program Files\TP-LINK\TL-WN321G Wireless Utility\Installer\WINXP\TWCU.exe [2008-08-03 622592]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 SymEFA;Symantec Extended File Attributes;C:\WINDOWS\system32\drivers\NAV\1000000.07D\SYMEFA.SYS [2008-10-08 309296]
R1 BHDrvx86;Symantec Heuristics Driver;C:\WINDOWS\system32\drivers\NAV\1000000.07D\BHDrvx86.sys [2008-10-08 254512]
R1 ccHP;Symantec Hash Provider;C:\WINDOWS\system32\drivers\NAV\1000000.07D\ccHPx86.sys [2008-10-08 362544]
R1 IDSxpx86;IDSxpx86;C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20081009.001\IDSxpx86.sys [2008-10-08 274808]
R2 Norton AntiVirus;Norton AntiVirus;C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe /s Norton AntiVirus /m C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.0.0.125\diMaster.dll [ ]
R3 C4C_BSC2;C4C_BSC2;C:\WINDOWS\system32\DRIVERS\C4C_BSC2.sys [2002-07-08 84788]
.
- - - - ORPHANS REMOVED - - - -
BHO-{230027AB-F81C-4C23-966D-F8475133F487} - C:\WINDOWS\System32\ibli.dll
HKLM-Explorer_Run-kvtrwkcc.exe - C:\WINDOWS\System32\kvtrwkcc.exe
HKLM-Explorer_Run-pksetexd.exe - C:\WINDOWS\System32\pksetexd.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R0 -: HKLM-Main,Search Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-SearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
O8 -: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 -: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 -: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 -: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 -: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 -: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 -: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 -: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O18 -: Filter: text/plain - {DAC9A865-0B0B-4F31-A899-434CFF920B7C} - %~$path:i
O16 -: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://61.17.186.182/activex/AMC.cab
C:\WINDOWS\Downloaded Program Files\setup.inf
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-11 13:32:39
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\NORTON ANTIVIRUS\NORTON ANTIVIRUS\ENGINE\16.0.0.125\CCSVCHST.EXE
C:\WINDOWS\SYSTEM32\USTORSRV.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRAM FILES\NORTON ANTIVIRUS\NORTON ANTIVIRUS\ENGINE\16.0.0.125\CCSVCHST.EXE
.
**************************************************************************
.
Completion time: 2008-10-11 13:38:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-11 05:37:56
Pre-Run: 67,597,926,400 bytes free
Post-Run: 67,812,327,424 bytes free
201 --- E O F --- 2008-10-09 15:33:55