ComboFix 07-11-08.3 - Owner 2007-11-17 6:37:28.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.101 [GMT -8:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\SCURIT~1
C:\Documents and Settings\Administrator\Application Data\SCURIT~1\s?curity\
C:\Documents and Settings\Administrator\My Documents\YSTEM3~1
C:\Documents and Settings\Owner\Application Data\SCURIT~1
C:\Documents and Settings\Owner\Application Data\SCURIT~1\s?curity\
C:\Program Files\Common Files\icroso~1.net
C:\Program Files\Common Files\icroso~1.net\t?skmgr.exe
C:\Temp\xOe
C:\WINDOWS\b.exe
C:\WINDOWS\Fonts\acrsecI.fon
C:\WINDOWS\system32\app.exe
C:\WINDOWS\system32\config\systemprofile\Application Data\SCURIT~1
C:\WINDOWS\system32\config\systemprofile\Application Data\SCURIT~1\s?curity\
C:\WINDOWS\system32\config\systemprofile\My Documents\YSTEM3~1
C:\WINDOWS\system32\dccdd.bak1
C:\WINDOWS\system32\dccdd.bak2
C:\WINDOWS\system32\dccdd.ini
C:\WINDOWS\system32\ddccd.dll
C:\WINDOWS\system32\gebcdab.dll
C:\WINDOWS\system32\mljgfeb.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\winlogo.exe
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 )))))))))))))))))))))))))))))))
.
2007-11-17 06:34 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-16 17:07 <DIR> d-------- C:\Documents and Settings\Administrator\DoctorWeb
2007-11-16 02:30 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2007-11-16 01:54 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Grisoft
2007-11-16 01:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-16 01:53 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-13 05:08 58,368 --a------ C:\Documents and Settings\Administrator\app.exe
2007-11-13 05:08 167 --a------ C:\Documents and Settings\Administrator\6173.bat
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-11-13 04:16 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Shared
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Incomplete
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo! Messenger
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo!
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\WhenU
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Viewpoint
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\VERITAS
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Share-to-Web Upload Folder
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Musicmatch
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\MSNInstaller
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\MSN6
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Motive
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\McAfee.com Personal Firewall
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Lexmark Imaging Studio
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Lavasoft
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterVideo
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterTrust
2007-11-13 04:16 <DIR> d--h----- C:\Documents and Settings\Administrator\Application Data\GTek
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Freedom
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Corel
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\ArcSoft
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AOL
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2007-11-13 04:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2007-11-13 04:16 389,120 --a------ C:\Documents and Settings\Administrator\remote.exe
2007-11-13 04:16 32,768 --a------ C:\Documents and Settings\Administrator\winlogo.exe
2007-11-12 23:18 <DIR> d-------- C:\WINDOWS\LastGood
2007-11-12 18:24 <DIR> d-------- C:\sdfix'
2007-10-28 22:58 33,588 -ra------ C:\WINDOWS\system32\drivers\wanatw4.sys
2007-10-28 13:47 151,552 --a------ C:\WINDOWS\system32\igfxres.dll
2007-10-28 13:45 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
2007-10-28 13:41 58,368 --a------ C:\WINDOWS\system32\config\systemprofile\app.exe
2007-10-28 13:41 167 --a------ C:\WINDOWS\system32\config\systemprofile\6173.bat
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Incomplete
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\You've Got Pictures Screensaver
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Yahoo! Messenger
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Yahoo!
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\WhenU
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Viewpoint
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Symantec
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Musicmatch
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\MSNInstaller
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\MSN6
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Motive
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\McAfee.com Personal Firewall
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\LimeWire
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Lexmark Imaging Studio
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Lavasoft
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\InterVideo
2007-10-28 13:18 <DIR> d--h----- C:\WINDOWS\system32\config\systemprofile\Application Data\GTek
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Freedom
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Corel
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\AVG7
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\ArcSoft
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\AOL
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Aim
2007-10-28 13:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\AdobeUM
2007-10-28 13:18 389,120 --a------ C:\WINDOWS\system32\config\systemprofile\remote.exe
2007-10-28 13:18 32,768 --a------ C:\WINDOWS\system32\config\systemprofile\winlogo.exe
2007-10-28 13:17 <DIR> d---s---- C:\WINDOWS\system32\config\systemprofile\UserData
2007-10-28 13:17 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Shared
2007-10-28 13:17 51,072 --a------ C:\WINDOWS\system32\drivers\i8042prt.sys
2007-10-28 13:17 23,424 --a------ C:\WINDOWS\system32\drivers\kbdclass.sys
2007-10-28 13:14 58,368 --a------ C:\Documents and Settings\Default User\app.exe
2007-10-28 13:14 167 --a------ C:\Documents and Settings\Default User\6173.bat
2007-10-28 12:45 <DIR> d---s---- C:\Documents and Settings\Default User\UserData
2007-10-28 12:45 <DIR> d-------- C:\Documents and Settings\Default User\Shared
2007-10-28 12:45 <DIR> d-------- C:\Documents and Settings\Default User\Incomplete
2007-10-28 12:45 389,120 --a------ C:\Documents and Settings\Default User\remote.exe
2007-10-28 12:45 32,768 --a------ C:\Documents and Settings\Default User\winlogo.exe
2007-10-28 01:50 56,832 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-10-28 01:50 50,048 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-10-28 01:50 7,040 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-10-28 01:50 5,120 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-10-28 01:50 4,608 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2007-10-28 01:50 2,816 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-10-28 01:47 134,272 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2007-10-28 01:47 57,856 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-10-28 01:47 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-10-26 00:33 <DIR> d-------- C:\WINDOWS\pss
2007-10-23 00:04 <DIR> d-------- C:\Program Files\NoAdware5.0
2007-10-22 22:40 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-10-22 22:20 58,368 --------- C:\Documents and Settings\Owner\app.exe
2007-10-22 22:20 167 --a------ C:\Documents and Settings\Owner\6173.bat
2007-10-22 22:18 32,768 --a------ C:\Documents and Settings\Owner\winlogo.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 13:13 --------- d-----w C:\Program Files\LimeWire
2007-11-15 11:13 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2007-11-13 07:44 --------- d-----w C:\Program Files\RecordNow
2007-11-13 07:42 --------- d-----w C:\Program Files\Corel
2007-11-13 07:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-13 07:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-13 07:14 --------- d-----w C:\Program Files\Hewlett-Packard
2007-11-13 07:11 --------- d-----w C:\Program Files\HP Instant Support
2007-11-13 06:00 --------- d-----w C:\Program Files\WildTangent
2007-11-13 05:59 --------- d-----w C:\Program Files\Simple Backup for My Pictures
2007-11-12 12:33 --------- d-----w C:\Program Files\Java
2007-11-12 08:16 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-29 06:56 28,164 ----a-w C:\WINDOWS\system32\drivers\MxlW2k.sys
2007-10-28 22:07 --------- d-----w C:\Program Files\Quicken
2007-10-28 22:05 --------- d-----w C:\Program Files\AWS
2007-10-28 21:46 4,108 --sha-r C:\WINDOWS\system32\drivers\HP_D7218F-ABA 554Y_YUU_Pavi_QMX309S_E31NAheBLU4_4_INBGV - Northwood Brookdale-G Validation Board_SIntel Corporation_V_B6.00_T030207_WXH1_L409_M248_J41_7Intel_8Celeron_92.19_1_N10EC8139_P_Z11C1044E_K_A808624C5_U808624C2.MRK
2007-10-26 02:25 --------- d-----w C:\Program Files\CallWave
2007-10-23 22:48 --------- d-----w C:\Program Files\WinISD
2007-10-13 07:47 --------- d-----w C:\Program Files\Lx_cats
2007-10-11 22:04 --------- d-----w C:\Program Files\uTorrent
2007-10-08 15:45 --------- d-----w C:\Program Files\DAEMON Tools SearchBar
2007-10-05 23:36 --------- d-----w C:\Program Files\DAEMON Tools
2007-10-05 23:36 --------- d-----w C:\Documents and Settings\Owner\Application Data\WhenU
2007-10-05 23:14 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2006-03-10 19:46 389,120 ----a-w C:\Documents and Settings\Owner\remote.exe
2004-09-14 04:37 208,614 -c--a-w C:\Program Files\systemsoappro.exe
2004-09-05 19:36 5,815,952 -c--a-w C:\Program Files\zlsSetup_51_011.exe
2004-08-04 17:57 20,480 ----a-w C:\Program Files\log.exe
2001-01-06 15:03 125,154 -c--a-w C:\Program Files\Qutrit.exe
2006-03-24 05:16:13 723,105 --sh--w C:\WINDOWS\system32\stutv.bak1
2006-03-28 06:34:34 647,949 --sh--w C:\WINDOWS\system32\stutv.bak2
2006-03-28 07:53:18 648,087 --sh--w C:\WINDOWS\system32\stutv.ini2
2005-03-01 18:29:18 140,288 --sha-r C:\WINDOWS\system32\config\systemprofile\Desktop\PhoTags Express\Setup.exe
2004-12-15 09:14:32 39,936 --sha-r C:\WINDOWS\system32\config\systemprofile\Desktop\PhoTags Express\_Setupx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BlockTracker"="c:\hp\bin\BlockTracker.exe" []
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2002-09-09 07:05]
"AutoTBar"="C:\hp\bin\autotbar.exe" []
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 21:42]
"NvCplDaemon"="NvQTwk" []
"nwiz"="nwiz.exe" [2002-09-30 23:39 C:\WINDOWS\system32\nwiz.exe]
"_Res"="c:\hp\bin\cloaker c:\hp\bin\SetRes\SetRes.bat" []
"PS2"="C:\WINDOWS\system32\ps2.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-03-10 16:52]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll" [2002-09-30 23:39 C:\WINDOWS\system32\nview.dll]
"AOL Fast Start"="C:\Program Files\America Online 9.0a\AOL.exe" [2005-07-12 06:17]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-20 22:08]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Stardust Wallpaper Control 2003.lnk - C:\WINDOWS\WCMain.exe [2003-10-27 09:51:45]
Verizon Online Support Center.lnk - C:\Program Files\Verizon Online\bin\matcli.exe [2006-03-10 10:54:56]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
S3 PCDRDRV;Pcdr Helper Driver;\??\C:\PROGRA~1\PC-DOC~1\DIAGNO~1\PCDRDRV.sys
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-17 06:42:36
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-17 6:48:11 - machine was rebooted
.
--- E O F ---