ComboFix 07-11-08.3 - Owner 2007-11-11 12:53:18.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.562 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\My Documents\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
.
((((((((((((((((((((((((( Files Created from 2007-10-11 to 2007-11-11 )))))))))))))))))))))))))))))))
.
2007-11-11 12:51 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-11 10:16 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2007-11-11 09:20 <DIR> d-------- C:\WINDOWS\LastGood
2007-11-11 08:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-11 08:35 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-11 08:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-11 07:25 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-05 20:35 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\MP3Rocket
2007-11-05 20:27 <DIR> d-------- C:\Program Files\MP3 Rocket
2007-10-21 09:32 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\.wyzo
2007-10-19 20:51 <DIR> d-------- C:\Program Files\iTunes
2007-10-19 20:47 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-10-19 20:47 <DIR> d-------- C:\Program Files\Apple Software Update
2007-10-19 20:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-11 13:35 --------- d-----w C:\Program Files\Lavasoft
2007-11-11 11:54 --------- d-----w C:\Program Files\Symantec AntiVirus
2007-11-11 11:54 --------- d-----w C:\Program Files\Microsoft Home Publishing
2007-11-06 01:33 --------- d-----w C:\Program Files\Java
2007-11-06 01:29 --------- d-----w C:\Program Files\LimeWire
2007-11-01 20:13 --------- d-----w C:\Documents and Settings\Owner\Application Data\WeatherBug
2007-10-21 14:32 --------- d-----w C:\Documents and Settings\Owner\Application Data\.wyzo
2007-10-21 14:24 --------- d-----w C:\Program Files\Motive
2007-10-21 14:24 --------- d-----w C:\Program Files\IrfanView
2007-10-20 01:51 --------- d-----w C:\Program Files\iPod
2007-10-20 01:49 --------- d-----w C:\Program Files\QuickTime
2007-10-05 20:50 --------- d-----w C:\Program Files\Cucusoft
2007-09-26 00:31 --------- d-----w C:\Documents and Settings\Owner\Application Data\DMCache
2007-09-18 22:35 --------- d-----w C:\Program Files\MSN Messenger
2007-08-22 15:01 1,598,759 --sh--w C:\WINDOWS\system32\jjkmp.ini2
2007-08-22 13:05 1,589,947 --sh--w C:\WINDOWS\system32\jjkmp.bak2
2007-08-21 23:26 1,590,504 --sh--w C:\WINDOWS\system32\jjkmp.bak1
2007-08-21 06:15 683,520 ------w C:\WINDOWS\system32\inetcomm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LightSurf.lnk]
backup=C:\WINDOWS\pss\LightSurf.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sprint FastConnect virtual assistant.lnk]
backup=C:\WINDOWS\pss\Sprint FastConnect virtual assistant.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
C:\PROGRA~1\SPRINT~1\SMARTB~1\MotiveSB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
R0 _wff;_wff;C:\WINDOWS\system32\drivers\_wff.sys
R3 FVNETusb;Linksys Wireless-B USB Network Adapter v2.8 Driver;C:\WINDOWS\system32\DRIVERS\vnet558x.sys
S3 GcKernel;Microsoft SideWinder Value Add - Filter Driver;C:\WINDOWS\system32\DRIVERS\GcKernel.sys
S3 HIDSwvd;Microsoft SideWinder Virtual HID Device Mini-Driver;C:\WINDOWS\system32\DRIVERS\HIDSwvd.sys
S3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS\system32\Drivers\Icam3.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d2b75a6-cfe1-11d8-a628-806d6172696f}]
\Shell\AutoRun\command - D:\Info.exe folder.htt 480 480
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-10-20 01:47:52 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-11-11 12:54:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-11 12:55:12
.
--- E O F ---
Oh man, it worked I can go onto websites now and it doesn't go back to the original webpage after I log in!
thank you!