ComboFix 07-10-26.4 - Administrator 2007-10-27 10:16:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.165 [GMT 1:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\onoes.exe
C:\Program Files\3
C:\Program Files\3\Mobile Broadband Modem Manager\configMMM.ini
C:\Program Files\3\Mobile Broadband Modem Manager\DefaultMMM.ini
C:\Program Files\3\Mobile Broadband Modem Manager\Driver.ini
C:\Program Files\3\Mobile Broadband Modem Manager\MMModem.cnt
C:\Program Files\3\Mobile Broadband Modem Manager\MMModem.exe
C:\Program Files\3\Mobile Broadband Modem Manager\MMMODEM.HLP
C:\Program Files\outlook
C:\Program Files\outlook\outlook.exe
C:\Program Files\outlook\p.zip
C:\Program Files\outlook\v.tmp
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tracert.com
.
((((((((((((((((((((((((( Files Created from 2007-09-27 to 2007-10-27 )))))))))))))))))))))))))))))))
.
2007-10-27 10:15 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-22 10:57 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-10-22 10:57 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-10-22 10:57 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-10-22 10:57 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-22 10:57 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-22 10:57 1,464 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-10 12:45 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-10-09 15:43 <DIR> d-------- C:\Documents and Settings\Administrator\Shared
2007-10-09 15:43 <DIR> d-------- C:\Documents and Settings\Administrator\Incomplete
2007-10-09 15:42 <DIR> d-------- C:\Program Files\Java
2007-10-09 15:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2007-10-09 15:41 <DIR> d-------- C:\Program Files\Common Files\Java
2007-10-09 15:40 <DIR> d-------- C:\Program Files\LimeWire
2007-10-07 17:37 <DIR> d-------- C:\Documents and Settings\Administrator\Phone Browser
2007-10-02 16:02 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-10-01 17:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Final Draft
2007-10-01 16:59 <DIR> d-------- C:\Program Files\Final Draft Tagger
2007-10-01 16:59 <DIR> d-------- C:\Program Files\Final Draft 7
2007-10-01 16:59 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-01 16:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Final Draft
2007-10-01 16:20 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2007-10-01 16:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2007-10-01 16:17 24,064 --------- C:\WINDOWS\system32\msxml3a.dll
2007-10-01 16:16 <DIR> d-------- C:\Program Files\CyberLink
2007-10-01 16:14 <DIR> d-------- C:\PDVDBD
2007-10-01 15:49 <DIR> d-------- C:\Documents and Settings\Administrator\Contacts
2007-10-01 15:48 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
2007-10-01 15:47 <DIR> d-------- C:\Program Files\Windows Desktop Search
2007-10-01 15:47 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-10-01 15:46 <DIR> d-------- C:\Program Files\Windows Live Favorites
2007-10-01 15:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-10-01 15:46 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-10-01 15:46 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2007-10-01 15:46 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-10-01 15:45 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2007-10-01 15:44 <DIR> d-------- C:\Program Files\MSN Messenger
2007-10-01 15:31 <DIR> d-------- C:\Program Files\PowerISO
2007-10-01 14:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Suite
2007-10-01 14:20 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Nokia
2007-10-01 14:19 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-10-01 14:19 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2007-10-01 14:19 <DIR> d-------- C:\Program Files\Nokia
2007-10-01 14:19 <DIR> d-------- C:\Program Files\DIFX
2007-10-01 14:19 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2007-10-01 14:19 <DIR> d-------- C:\Program Files\Common Files\Nokia
2007-10-01 14:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Installations
2007-10-01 14:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\PC Suite
2007-10-01 14:19 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2007-10-01 14:19 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2007-10-01 14:19 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2007-10-01 14:19 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2007-10-01 14:19 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys
2007-10-01 14:19 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-01 15:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-01 15:16 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-01 12:45 9,897 ----a-w C:\WINDOWS\nmwcdcp.sys
2007-10-01 12:45 89,728 ----a-w C:\WINDOWS\usbvsp.sys
2007-10-01 12:45 87,456 ----a-w C:\WINDOWS\k600mdm.sys
2007-10-01 12:45 84,480 ----a-w C:\WINDOWS\U81xmdm.sys
2007-10-01 12:45 8,704 ----a-w C:\WINDOWS\nmwcdc.sys
2007-10-01 12:45 79,248 ----a-w C:\WINDOWS\k600mgmt.sys
2007-10-01 12:45 77,472 ----a-w C:\WINDOWS\U81xmgmt.sys
2007-10-01 12:45 77,072 ----a-w C:\WINDOWS\k600obex.sys
2007-10-01 12:45 75,456 ----a-w C:\WINDOWS\U81xobex.sys
2007-10-01 12:45 6,672 ----a-w C:\WINDOWS\U81xwh95.sys
2007-10-01 12:45 6,672 ----a-w C:\WINDOWS\k600wh95.sys
2007-10-01 12:45 6,144 ----a-w C:\WINDOWS\U81xcmnt.sys
2007-10-01 12:45 6,112 ----a-w C:\WINDOWS\k600cmnt.sys
2007-10-01 12:45 6,096 ----a-w C:\WINDOWS\k600mdfl.sys
2007-10-01 12:45 6,064 ----a-w C:\WINDOWS\U81xmdfl.sys
2007-10-01 12:45 52,384 ----a-w C:\WINDOWS\k600bus.sys
2007-10-01 12:45 52,352 ----a-w C:\WINDOWS\U81xbus.sys
2007-10-01 12:45 52,193 ----a-w C:\WINDOWS\lgusbmdm.sys
2007-10-01 12:45 50,200 ----a-w C:\WINDOWS\lgusbsdm.sys
2007-10-01 12:45 5,744 ----a-w C:\WINDOWS\U81xwhnt.sys
2007-10-01 12:45 5,744 ----a-w C:\WINDOWS\k600whnt.sys
2007-10-01 12:45 48,128 ----a-w C:\WINDOWS\nmwcdcls.dll
2007-10-01 12:45 46,810 ----a-w C:\WINDOWS\ctl_w2kh.sys
2007-10-01 12:45 43,264 ----a-w C:\WINDOWS\urusbc.sys
2007-10-01 12:45 43,264 ----a-w C:\WINDOWS\liusbc.sys
2007-10-01 12:45 43,136 ----a-w C:\WINDOWS\n808usbc.sys
2007-10-01 12:45 41,520 ----a-w C:\WINDOWS\CCPORT.SYS
2007-10-01 12:45 4,608 ----a-w C:\WINDOWS\nmwcdlog.dll
2007-10-01 12:45 4,048 ----a-w C:\WINDOWS\U81xcr.sys
2007-10-01 12:45 39,036 ----a-w C:\WINDOWS\lgusbmodem.sys
2007-10-01 12:45 38,144 ----a-w C:\WINDOWS\lgusbdiag.sys
2007-10-01 12:45 37,120 ----a-w C:\WINDOWS\n808usbm.sys
2007-10-01 12:45 37,120 ----a-w C:\WINDOWS\mdm_w2kh.sys
2007-10-01 12:45 36,352 ----a-w C:\WINDOWS\urusbm.sys
2007-10-01 12:45 36,352 ----a-w C:\WINDOWS\liusbm.sys
2007-10-01 12:45 337,320 ----a-w C:\WINDOWS\difxapi.dll
2007-10-01 12:45 33,920 ----a-w C:\WINDOWS\urusbo.sys
2007-10-01 12:45 33,920 ----a-w C:\WINDOWS\liusbo.sys
2007-10-01 12:45 33,664 ----a-w C:\WINDOWS\n808usbo.sys
2007-10-01 12:45 33,536 ----a-w C:\WINDOWS\obx_w2kh.sys
2007-10-01 12:45 31,232 ----a-w C:\WINDOWS\nmwcdcocls.dll
2007-10-01 12:45 3,984 ----a-w C:\WINDOWS\k600cr.sys
2007-10-01 12:45 28,304 ----a-w C:\WINDOWS\tac_w2kh.sys
2007-10-01 12:45 25,856 ----a-w C:\WINDOWS\urusba.sys
2007-10-01 12:45 25,856 ----a-w C:\WINDOWS\liusba.sys
2007-10-01 12:45 25,344 ----a-w C:\WINDOWS\n808usba.sys
2007-10-01 12:45 22,328 ----a-w C:\WINDOWS\lgbus9x.sys
2007-10-01 12:45 22,048 ----a-w C:\WINDOWS\cocpyinf.dll
2007-10-01 12:45 21,344 ----a-w C:\WINDOWS\lgusbbus.sys
2007-10-01 12:45 21,296 ----a-w C:\WINDOWS\USBSER.SYS
2007-10-01 12:45 14,458 ----a-w C:\WINDOWS\enu_w2kh.sys
2007-10-01 12:45 13,696 ----a-w C:\WINDOWS\n808usbe.sys
2007-10-01 12:45 13,312 ----a-w C:\WINDOWS\nmwcdcm.sys
2007-10-01 12:45 13,312 ----a-w C:\WINDOWS\nmwcdcj.sys
2007-10-01 12:45 127,488 ----a-w C:\WINDOWS\nmwcd.sys
2007-10-01 12:45 12,928 ----a-w C:\WINDOWS\urusbe.sys
2007-10-01 12:45 12,928 ----a-w C:\WINDOWS\liusbe.sys
2007-10-01 12:45 10,672 ----a-w C:\WINDOWS\k600cm95.sys
2007-10-01 12:45 10,640 ----a-w C:\WINDOWS\U81xcm95.sys
2007-10-01 12:32 --------- d-----w C:\Program Files\DVD Region+CSS Free
2007-10-01 12:04 92,720 ----a-w C:\WINDOWS\system32\hgfs.dll
2007-10-01 12:04 92,464 ----a-r C:\WINDOWS\system32\vmx_fb.dll
2007-10-01 12:04 89,088 ----a-w C:\WINDOWS\system32\atl71.dll
2007-10-01 12:04 63,280 ----a-r C:\WINDOWS\system32\drivers\vmx_svga.sys
2007-10-01 12:04 36,400 ----a-w C:\WINDOWS\system32\drivers\lgtosync.sys
2007-10-01 12:04 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2007-10-01 12:04 34,992 ----a-r C:\WINDOWS\system32\drivers\vmxnet.sys
2007-10-01 12:04 33,840 ----a-w C:\WINDOWS\system32\vmGuestLib.dll
2007-10-01 12:04 17,968 ----a-r C:\WINDOWS\system32\drivers\vmscsi.sys
2007-10-01 12:04 16,688 ----a-r C:\WINDOWS\system32\vmx_mode.dll
2007-10-01 12:04 11,696 ----a-r C:\WINDOWS\system32\drivers\vmmouse.sys
2007-10-01 12:04 102,704 ----a-w C:\WINDOWS\system32\drivers\hgfs.sys
2007-10-01 12:04 1,060,864 ----a-w C:\WINDOWS\system32\mfc71.dll
2007-10-01 12:04 1,047,552 ----a-w C:\WINDOWS\system32\mfc71u.dll
2007-10-01 12:04 --------- d-----w C:\Program Files\VMware
2007-10-01 12:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\VMware
2007-10-01 12:01 --------- d-----w C:\Program Files\microsoft frontpage
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-07-30 18:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 18:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 18:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 18:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 18:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 18:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 18:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VMware Tools"="C:\Program Files\VMware\VMware Tools\VMwareTray.exe" [2007-10-01 13:04]
"VMware User Process"="C:\Program Files\VMware\VMware Tools\VMwareUser.exe" [2007-10-01 13:04]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 15:10]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 01:05]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-12-06 18:37]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 22:55]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2007-09-17 15:19:14]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 22:44:08]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= C:\PROGRA~1\DVDREG~1\DVDShell.dll [2004-10-09 15:18 49152]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 13:11 233472]
R0 vmscsi;vmscsi;C:\WINDOWS\system32\drivers\vmscsi.sys
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};\??\C:\Program Files\CyberLink\PowerDVD\
000.fcl
R2 hgfs;hgfs;C:\WINDOWS\system32\DRIVERS\hgfs.sys
R2 LGTO_Sync;Sync Driver;\??\C:\WINDOWS\system32\Drivers\lgtosync.sys
R2 VMMEMCTL;VMware server memory controller;\??\C:\Program Files\VMware\VMware Tools\Drivers\memctl\vmmemctl.sys
R2 VMTools;VMware Tools Service;"C:\Program Files\VMware\VMware Tools\VMwareService.exe"
R2 VMware Physical Disk Helper Service;VMware Physical Disk Helper Service;"C:\Program Files\VMware\VMware Tools\vmacthlp.exe"
R3 vmmouse;VMware Pointing Device;C:\WINDOWS\system32\DRIVERS\vmmouse.sys
R3 vmx_svga;vmx_svga;C:\WINDOWS\system32\DRIVERS\vmx_svga.sys
R3 vmxnet;VMware Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\vmxnet.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-10-27 09:16:03 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-27 10:18:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-27 10:18:50 - machine was rebooted
.
--- E O F ---