Ok, when I first downloaded and ran RenV.exe, it made this log:
Ran on Thu 01/17/2008 - 20:32:05.10
—-a-w 50,528 2008-01-13 23:45:51 C:\Program Files\AIM6\aim6 .exe
—-a-w 51,048 2008-01-14 02:17:22 C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w 61,440 2008-01-13 23:45:58 C:\Program Files\Dot1XCfg\Dot1XCfg .exe
—-a-w 132,496 2008-01-13 23:45:49 C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe
—-a-w 155,648 2008-01-14 05:35:10 C:\Program Files\QuickTime\qttask .exe
—-a-w 155,648 2008-01-14 05:35:11 C:\Program Files\QuickTime\qttask .exe
—-a-w 155,648 2008-01-14 05:35:11 C:\Program Files\QuickTime\qttask .exe
—-a-w 155,648 2008-01-14 05:35:12 C:\Program Files\QuickTime\qttask .exe
—-a-w 155,648 2008-01-14 05:35:12 C:\Program Files\QuickTime\qttask .exe
—-a-w 158,208 2008-01-14 04:17:42 C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
—-a-w 15,360 2008-01-14 04:23:57 C:\WINDOWS\system32\ctfmon .exe
—-a-w 126,976 2008-01-13 23:45:45 C:\WINDOWS\system32\hkcmd .exe
—-a-w 155,648 2008-01-14 02:17:11 C:\WINDOWS\system32\igfxtray .exe
Entries: 13 (13)
Directories: 0 Files: 13
Bytes: 1,529,944 Blocks: 2,989
After I took that log and did this "Drag log.txt from desktop that RenV created on top of RenV.exe", it displayed this log….oops, basically the log it displayed had only the "ccApp .exe" line. I noticed the first log it made was still the same and I had no clue where the new log was saved, so i copied the new log's contents and thought I saved it into a new file on the desktop I named log2.txt. After running combofix, it rebooted my PC. The contents of log2.txt is empty, so i'm thinking I forgot to paste it before reboot. ><
Anywho…when it booted after the combofix reboot, I got an AIM icon and an icon saying Update Available for Java in the task bar, neither were loading since being infected. New ComboFix log:
ComboFix 08-01-17.3 - Administrator 2008-01-17 20:40:22.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.253 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\PROGRA~1\COMMON~1\FNTS~1\services.exe
C:\Program Files\AIM6\aim6 .exe
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\Program Files\Dot1XCfg\Dot1XCfg .exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\WINDOWS\mrofinu72.exe
C:\WINDOWS\mrofinu72.exe.tmp
C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\gebcc.exe
C:\WINDOWS\system32\hkcmd .exe
C:\WINDOWS\system32\igfxtray .exe
C:\WINDOWS\system32\poc.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Program Files\Bonjour
C:\Program Files\Bonjour\About Bonjour.rtf
C:\Program Files\Bonjour\dns_sd.jar
C:\Program Files\Bonjour\ExplorerPlugin.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\da.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\de.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\en.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\es.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\ExplorerPluginResources.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\fi.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\fr.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\it.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\ja.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\ko.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\nl.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\no.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\sv.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\zh_CN.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\ExplorerPlugin.Resources\zh_TW.lproj\ExplorerPluginLocalized.dll
C:\Program Files\Bonjour\mdnsNSP.dll
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Bonjour\PrinterWizard.exe
C:\Program Files\Bonjour\PrinterWizard.Resources\da.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\de.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\en.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\es.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\fi.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\fr.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\it.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\ja.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\ko.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\nl.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\no.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\PrinterWizardResources.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\sv.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\zh_CN.lproj\PrinterWizardLocalized.dll
C:\Program Files\Bonjour\PrinterWizard.Resources\zh_TW.lproj\PrinterWizardLocalized.dll
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Common\VistaBoot.sdll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentMgr.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\Cursors.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\VETScriptInterpreter.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\NewComponents\VMPVideo2.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.xpt
C:\WINDOWS\mrofinu72.exe.tmp
.
((((((((((((((((((((((((( Files Created from 2007-12-18 to 2008-01-18 )))))))))))))))))))))))))))))))
.
2008-01-17 20:37 . 2008-01-13 21:17 155,648 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-17 20:37 . 2008-01-13 18:45 126,976 –a—— C:\WINDOWS\system32\hkcmd.exe
2008-01-16 18:59 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-14 03:00 . 2008-01-14 03:00 d——– C:\Program Files\MSXML 4.0
2008-01-13 23:41 . 2008-01-14 19:06 d——– C:\Program Files\Norton Internet Security
2008-01-13 23:39 . 2008-01-13 23:56 d——– C:\Program Files\Symantec
2008-01-13 23:39 . 2008-01-13 23:56 123,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-13 23:39 . 2008-01-13 23:56 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-13 21:54 . 2008-01-13 21:53 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-01-13 21:53 . 2008-01-13 21:55 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-01-13 21:52 . 2008-01-13 21:52 d——– C:\WINDOWS\Sun
2008-01-13 20:49 . 2008-01-13 20:49 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-13 20:15 . 2008-01-13 20:15 d——– C:\Program Files\Windows Sidebar
2008-01-13 19:51 . 2008-01-13 23:56 10,740 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-13 19:51 . 2008-01-13 23:56 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-13 19:48 . 2008-01-17 19:23 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-13 19:45 . 2008-01-17 20:41 d——– C:\Program Files\Common Files\Symantec Shared
2008-01-13 19:17 . 2008-01-13 19:17 d——– C:\Documents and Settings\All Users\Symantec Temporary Files
2008-01-13 03:37 . 2008-01-13 03:37 4,286 –a—— C:\WINDOWS\system32\MobileSidewalk.ico
2008-01-13 03:10 . 2008-01-17 20:37 d——– C:\Program Files\Dot1XCfg
2008-01-09 02:40 . 2008-01-12 22:11 d——– C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-01-09 02:40 . 2007-07-12 02:22 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-01-09 02:39 . 2008-01-09 02:40 d——– C:\Program Files\Java
2008-01-09 02:38 . 2008-01-09 02:40 d——– C:\Program Files\LimeWire
2008-01-09 02:38 . 2008-01-09 02:38 d——– C:\Program Files\Common Files\Java
2008-01-07 17:21 . 2008-01-13 01:15 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-07 17:21 . 2008-01-07 17:21 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-07 16:21 . 2008-01-07 16:21 d——– C:\WINDOWS\Downloaded Installations
2008-01-07 16:20 . 2008-01-17 20:37 d——– C:\Program Files\QuickTime
2008-01-07 16:20 . 2008-01-07 16:20 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-07 16:19 . 2008-01-07 16:19 d——– C:\WINDOWS\system32\BWKDLogs
2008-01-07 16:19 . 2008-01-07 16:19 d——– C:\Program Files\Common Files\Kodak
2008-01-07 16:19 . 2008-01-07 16:19 d——– C:\KPCMS
2008-01-07 16:19 . 2004-08-04 00:56 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2008-01-07 16:19 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-01-07 16:19 . 2004-08-03 22:58 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-01-07 16:19 . 2001-08-17 22:36 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2008-01-07 16:18 . 2008-01-07 16:18 d——– C:\WINDOWS\system32\color
2008-01-07 16:17 . 2008-01-07 16:17 d——– C:\Documents and Settings\All Users\Application Data\Kodak
2008-01-07 16:16 . 2008-01-07 16:20 d——– C:\Program Files\Kodak
2008-01-07 00:41 . 2008-01-07 00:41 d——– C:\Program Files\DivX
2008-01-07 00:41 . 2006-04-18 17:34 109,568 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-01-07 00:41 . 2006-04-18 17:34 108,544 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-01-07 00:16 . 2008-01-07 00:16 d——– C:\Program Files\Winamp
2008-01-07 00:16 . 2008-01-07 00:20 d——– C:\Documents and Settings\Administrator\Application Data\Winamp
2008-01-03 16:59 . 2008-01-03 16:59 d——– C:\Documents and Settings\Administrator\Application Data\acccore
2008-01-03 16:57 . 2008-01-03 16:57 d——– C:\Program Files\Common Files\AOL
2008-01-03 16:57 . 2008-01-03 16:57 d——– C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-01-03 16:57 . 2008-01-03 16:57 d——– C:\Documents and Settings\All Users\Application Data\AOL
2008-01-03 16:56 . 2008-01-17 20:37 d——– C:\Program Files\AIM6
2008-01-03 16:56 . 2008-01-03 16:58 528 –ah—– C:\IPH.PH
2008-01-01 21:33 . 2008-01-01 21:33 d——– C:\Program Files\Lavasoft
2008-01-01 21:33 . 2008-01-01 21:33 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-01 21:32 . 2008-01-01 21:32 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-01-01 21:15 . 2008-01-01 21:15 d——– C:\Program Files\MSXML 6.0
2008-01-01 21:02 . 2005-10-19 08:59 163,840 –a—— C:\WINDOWS\system32\igfxres.dll
2008-01-01 20:59 . 2007-10-10 18:55 6,065,664 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-01 20:59 . 2007-06-30 22:31 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-01 20:59 . 2007-06-30 22:36 991,232 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-01 20:59 . 2007-10-10 18:55 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-01 20:59 . 2007-10-10 18:55 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-01 20:59 . 2007-10-10 18:55 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-01 20:59 . 2007-10-10 18:55 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-01 20:59 . 2007-10-10 18:55 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-01 20:59 . 2007-10-10 05:59 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-01 20:56 . 2007-08-13 18:54 33,792 –a–c— C:\WINDOWS\system32\dllcache\custsat.dll
2008-01-01 20:53 . 2008-01-01 20:53 d——– C:\Program Files\MSBuild
2008-01-01 20:49 . 2008-01-01 21:20 d——– C:\WINDOWS\system32\XPSViewer
2008-01-01 20:49 . 2008-01-01 20:49 d——– C:\Program Files\Reference Assemblies
2008-01-01 20:48 . 2006-06-29 13:07 14,048 ——— C:\WINDOWS\system32\spmsg2.dll
2008-01-01 20:45 . 2008-01-01 20:45 d——– C:\Program Files\Windows Media Connect 2
2008-01-01 20:44 . 2008-01-01 20:44 d——– C:\WINDOWS\system32\LogFiles
2008-01-01 20:44 . 2008-01-01 20:44 d——– C:\WINDOWS\system32\drivers\UMDF
2008-01-01 20:33 . 2008-01-01 20:34 d——– C:\WINDOWS\system32\URTTemp
2008-01-01 20:25 . 2007-07-09 08:16 582,656 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-01-01 20:18 . 2006-11-13 01:02 288,768 ——— C:\WINDOWS\system32\rhttpaa.dll
2008-01-01 20:18 . 2006-11-13 01:02 116,736 –a—— C:\WINDOWS\system32\aaclient.dll
2008-01-01 20:18 . 2006-11-13 01:02 36,352 ——— C:\WINDOWS\system32\tsgqec.dll
2008-01-01 19:56 . 2008-01-14 02:19 d–h—– C:\WINDOWS\$hf_mig$
2008-01-01 19:46 . 2007-07-30 19:19 43,352 –a—— C:\WINDOWS\system32\wups2.dll
2008-01-01 19:46 . 2007-07-30 19:18 34,136 –a—— C:\WINDOWS\system32\wucltui.dll.mui
2008-01-01 19:46 . 2007-07-30 19:19 25,944 –a—— C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-01-01 19:46 . 2007-07-30 19:19 25,944 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2008-01-01 19:46 . 2007-07-30 19:18 20,312 –a—— C:\WINDOWS\system32\wuaueng.dll.mui
2008-01-01 19:45 . 2008-01-01 19:45 d–hs—- C:\Documents and Settings\Administrator\UserData
2008-01-01 19:32 . 2008-01-01 19:32 d——– C:\Program Files\Analog Devices
2008-01-01 19:28 . 2008-01-01 19:28 d——– C:\WINDOWS\Drivers
2008-01-01 19:27 . 2008-01-01 19:27 d——– C:\drvrtmp
2008-01-01 19:27 . 2003-02-11 09:58 126,976 –a—— C:\WINDOWS\system32\e1000msg.dll
2008-01-01 19:27 . 2003-07-11 10:58 121,856 –a—— C:\WINDOWS\system32\drivers\e1000325.sys
2008-01-01 19:27 . 2003-07-11 12:15 118,784 –a—— C:\WINDOWS\system32\Prounstl.exe
2008-01-01 19:27 . 2002-12-29 05:00 24,064 –a—— C:\WINDOWS\system32\IntelNic.dll
2008-01-01 19:27 . 2002-09-03 02:34 2,725 -ra—— C:\WINDOWS\system32\e1000325.din
2008-01-01 19:26 . 2008-01-01 19:26 d——– C:\dell
2008-01-01 18:45 . 2008-01-01 18:45 d——– C:\Program Files\Intel
2008-01-01 18:45 . 2008-01-01 19:32 d–h—– C:\Program Files\InstallShield Installation Information
2008-01-01 18:44 . 2008-01-07 16:20 d——– C:\Program Files\Common Files\InstallShield
2008-01-01 18:05 . 2008-01-01 18:05 d—s—- C:\WINDOWS\system32\Microsoft
2008-01-01 18:01 . 2008-01-01 20:37 316,640 –a—— C:\WINDOWS\WMSysPr9.prx
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-14 04:17 158,208 —-a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig.exe
2008-01-01 22:23 ——— d—–w C:\Program Files\microsoft frontpage
2007-12-01 04:57 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
.
((((((((((((((((((((((((((((( snapshot@2008-01-17_19.08.15.28 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-17 00:00:09 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-18 01:40:16 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-17 00:00:09 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-18 01:40:17 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-17 00:00:09 1,798,144 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-18 01:40:17 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-17 00:00:10 151,552 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-18 01:40:17 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-17 00:00:10 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-18 01:40:17 1,798,144 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-17 00:00:10 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-18 01:40:17 151,552 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
- 2004-08-04 05:56:50 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
+ 2008-01-14 04:23:57 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
- 2004-08-04 05:56:50 15,360 -c–a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
+ 2008-01-14 04:23:57 15,360 -c–a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
- 2004-08-04 05:56:54 158,208 -c–a-w C:\WINDOWS\system32\dllcache\msconfig.exe
+ 2008-01-14 04:17:42 158,208 -c–a-w C:\WINDOWS\system32\dllcache\msconfig.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2007-08-24 22:51 316784 –a—— C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-01-13 23:42 116088 –a—— C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 22:51 316784]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-13 18:45 50528]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-13 23:23 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2008-01-13 18:45 132496]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-14 19:10 51048]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2008-01-14 19:10 714608]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-01-13 23:23 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dot1XCfg]
–a—— 2008-01-13 18:45 61440 C:\Program Files\Dot1XCfg\Dot1XCfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
–a—— 2008-01-13 18:45 126976 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\gebcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu72.exe
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-08-25 00:07]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" []
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2007-05-29 13:55]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-15 01:46:30 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Administrator.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-17 20:43:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-17 20:46:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-18 01:45:46
ComboFix2.txt 2008-01-18 01:15:09
ComboFix3.txt 2008-01-18 00:51:15
ComboFix4.txt 2008-01-18 00:08:42
.
2008-01-14 08:02:56 — E O F —