ComboFix 08-05-09.1 - Jeff Hansen 2008-05-10 21:26:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.166 [GMT -4:00]
Running from: C:\Documents and Settings\Jeff Hansen\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Guest\err.log
C:\Documents and Settings\Jeff Hansen\Application Data\macromedia\Flash Player\#SharedObjects\JLWWAZY2\www.broadcaster.com
C:\Documents and Settings\Jeff Hansen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Jeff Hansen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Jeff Hansen\err.log
C:\Documents and Settings\Jeff Hansen\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\Jeff Hansen\Local Settings\Temporary Internet Files\bestwiner.stt
C:\Documents and Settings\Jeff Hansen\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Program Files\Common Files\{34F43~1
C:\Program Files\Common Files\{34F43~1\Uninstall.exe
C:\Program Files\Common Files\{34F43~2
C:\Program Files\Common Files\{C4F43~1
C:\Program Files\CPV
C:\Program Files\inetget2
C:\Program Files\inetget2\sacatapo821058.exe
C:\Program Files\ISM
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\JavaCore
C:\Program Files\JavaCore\JavaCore.exe
C:\Program Files\JavaCore\UnInstall.exe
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrPack
C:\Program Files\QdrPack\QdrPack15.exe
C:\Program Files\Temporary
C:\WA6P
C:\WINDOWS\b104.exe
C:\WINDOWS\b148.exe
C:\WINDOWS\b149.exe
C:\WINDOWS\b152.exe
C:\WINDOWS\b155.exe
C:\WINDOWS\b156.exe
C:\WINDOWS\b999.exe
C:\WINDOWS\mrofinu1535.exe
C:\WINDOWS\system32\components
C:\WINDOWS\system32\dgjlm.ini2
C:\WINDOWS\system32\dgjlm.tmp
C:\WINDOWS\system32\iyspawlq.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mevrkpsw.ini
C:\WINDOWS\system32\mlnmp.bak1
C:\WINDOWS\system32\mlnmp.bak2
C:\WINDOWS\system32\mlnmp.ini
C:\WINDOWS\system32\mlnmp.ini2
C:\WINDOWS\system32\mlnmp.tmp
C:\WINDOWS\system32\nnnmjgHy.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_COM+_MESSAGES
((((((((((((((((((((((((( Files Created from 2008-04-11 to 2008-05-11 )))))))))))))))))))))))))))))))
.
2008-05-10 12:55 . 2008-05-10 12:55 <DIR> d-------- C:\Program Files\Spcron
2008-05-10 12:50 . 2008-05-10 12:50 <DIR> d-------- C:\Program Files\Svconr
2008-05-09 22:31 . 2008-05-09 22:32 <DIR> d-------- C:\Documents and Settings\Jeff Hansen\.limewire
2008-05-09 19:22 . 2008-05-09 19:22 <DIR> d-------- C:\Documents and Settings\Jeff Hansen\Application Data\Lavasoft
2008-05-09 12:40 . 2008-02-12 14:45 48 --a------ C:\Documents and Settings\Jeff Hansen\readme.bat
2008-05-09 10:45 . 2008-05-09 10:45 <DIR> d-------- C:\Program Files\Common Files\Macromedia Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-11 01:39 --------- d-----w C:\Program Files\Steam
2008-05-11 01:38 --------- d-----w C:\Documents and Settings\Jeff Hansen\Application Data\WTablet
2008-05-11 01:37 --------- d-----w C:\Documents and Settings\LocalService\Application Data\WTablet
2008-05-08 21:33 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-08 21:27 --------- d-----w C:\Documents and Settings\Jeff Hansen\Application Data\AdobeUM
2008-03-26 21:40 --------- d-----w C:\Program Files\LimeWire
2008-03-26 17:45 --------- d-----w C:\Program Files\Kate's Video Converter
2008-02-10 03:21 15 ----a-w C:\Documents and Settings\Jeff Hansen\StopWZC.bat
2008-02-10 03:20 16 ----a-w C:\Documents and Settings\Jeff Hansen\StartWZC.bat
2008-01-09 21:20 251 ----a-w C:\Program Files\wt3d.ini
2007-03-23 14:39 382 ----a-w C:\Documents and Settings\Jeff Hansen\Application Data\internaldb1942.dat
2007-03-23 14:38 69,632 ----a-w C:\Documents and Settings\Jeff Hansen\Application Data\internaldb4827.dat
2007-03-23 14:38 151 ----a-w C:\Documents and Settings\Jeff Hansen\Application Data\internaldb292.dat
2007-03-23 14:38 0 ----a-w C:\Documents and Settings\Jeff Hansen\Application Data\internaldb2391.dat
2006-11-30 03:42 49 ----a-w C:\Documents and Settings\Jeff Hansen\Application Data\internaldb41.dat
2006-11-29 15:46 6,144 ----a-w C:\Documents and Settings\Guest\Application Data\internaldb1362.dat
2006-11-22 06:52 0 ----a-w C:\Program Files\Common Files\err.log
2006-11-18 17:08 0 ----a-w C:\Documents and Settings\Jeff Hansen\Application Data\internaldb5436.dat
2006-11-16 20:07 9,216 ----a-w C:\Documents and Settings\Jeff Hansen\Application Data\internaldb9040.dat
2006-11-16 20:07 0 ----a-w C:\Documents and Settings\Jeff Hansen\Application Data\internaldb1912.dat
2006-11-16 04:57 0 ----a-w C:\Documents and Settings\Jeff Hansen\Application Data\internaldb4604.dat
2006-11-16 04:57 0 ----a-w C:\Documents and Settings\Jeff Hansen\Application Data\internaldb3902.dat
2006-11-16 04:57 0 ----a-w C:\Documents and Settings\Jeff Hansen\Application Data\internaldb153.dat
2006-11-04 21:03 7,048 ----a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2007-12-06 23:10 88 --sh--r C:\WINDOWS\system32\41457874FA.sys
2007-09-10 18:07 56 --sh--r C:\WINDOWS\system32\FA74784541.sys
2007-12-06 23:10 6,580 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E1550C1-DB0B-4B2D-B338-CA5DCF368E13}]
C:\WINDOWS\system32\pwlosnmw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7C0AA32-5656-42F4-BF96-09ED9F459BD9}]
2008-02-07 21:07 217088 --a------ C:\Program Files\Messenger\kywokelyt821058.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E93121AD-7C67-417A-A6A5-87C60214AC80}]
C:\WINDOWS\system32\pmnlm.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
"Steam"="c:\program files\steam\steam.exe" [2008-04-01 19:03 1271032]
"Svconr"="C:\Program Files\Svconr\Svconr.exe" [2008-05-10 12:50 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 17:44 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 17:41 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 17:45 118784]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-12-19 09:08 1347584]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 12:56 761947]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2007-03-23 14:31 230512]
"CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2007-03-23 14:31 185456]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2006-07-21 10:43 407032]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-07 19:15 180269]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 17:30 282624 C:\WINDOWS\stsystra.exe]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42 267064]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-16 02:37 57344]
C:\Documents and Settings\Jeff Hansen\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2005-03-09 15:57:14 81920]
Microsoft Office Shortcut Bar.Lnk [2007-04-02 15:06:31 761]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-12-25 09:30:07 784912]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-09-26 23:45:57 106560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll 2007-11-15 11:10 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlm]
C:\WINDOWS\system32\pmnlm.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\Opera\\Opera.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Program Files\\Steam\\SteamApps\\hippiegothie\\team fortress 2\\hl2.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2006-02-14 17:18]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2006-11-15 15:55]
S3 SaiH0461;SaiH0461;C:\WINDOWS\system32\DRIVERS\SaiH0461.sys [2006-08-08 13:25]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-05-05 15:24:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-11 01:37:22 C:\WINDOWS\Tasks\Winter Fun Wallpaper Changer.job"
- C:\Documents and Settings\All Users\Start Menu\Programs\Winter Fun Pack 2004 for Windows XP\Winter Fun Wallpaper Changer.lnk
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-10 21:39:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Yahoo!\Antivirus\iSafe.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2008-05-10 21:45:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-11 01:45:30
Pre-Run: 10,848,620,544 bytes free
Post-Run: 10,703,892,480 bytes free
220 --- E O F --- 2008-04-11 07:09:05