Hello again
I did what you told me with combofix. For privacy reasons I don't include the folders from my directories, in the pasted log
I hope that wasn't necesary for your analysis. If you want something in specific let me know
Thank you so much for your assistance! Waiting for your next instructions
ComboFix 08-09-04.09 - webcat 2008-09-05 18:36:16.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1253.1.1033.18.1541 [GMT 3:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\webcat\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2008-08-05 to 2008-09-05 )))))))))))))))))))))))))))))))
.
2008-09-05 17:30 . 2008-09-05 17:30 d——– C:\_OTMoveIt
2008-09-03 22:11 . 2008-09-03 22:11 d——– C:\WINDOWS\Sun
2008-09-03 22:10 . 2008-09-03 22:10 d——– C:\Program Files\Java
2008-09-03 22:10 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-03 22:07 . 2008-09-03 22:07 d——– C:\Program Files\Common Files\Java
2008-09-03 21:55 . 2008-09-03 21:55 d——– C:\Documents and Settings\webcat\Application Data\Malwarebytes
2008-09-03 21:54 . 2008-09-03 21:55 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-03 21:54 . 2008-09-03 21:54 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-03 21:54 . 2008-09-02 00:16 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-03 21:54 . 2008-09-02 00:16 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-03 19:16 . 2008-09-03 19:16 d——– C:\rsit
2008-09-03 19:16 . 2008-09-03 19:16 d——– C:\Program Files\trend micro
2008-09-03 18:47 . 2008-09-03 18:48 d——– C:\WINDOWS\ERUNT
2008-09-03 18:22 . 2008-09-03 18:22 d——– C:\Documents and Settings\Administrator
2008-09-03 17:24 . 2008-09-03 19:13 d——– C:\SDFix
2008-09-03 13:48 . 2008-09-03 13:48 d——– C:\Program Files\ERUNT
2008-09-03 03:00 . 2008-09-03 03:00 d——– C:\Program Files\Spybot - Search & Destroy
2008-09-03 03:00 . 2008-09-03 03:03 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-01 19:23 . 2008-09-01 19:25 d——– C:\Program Files\Ultra DVD Creator
2008-09-01 19:23 . 2007-04-12 14:19 129,024 –a—— C:\WINDOWS\system32\AVERM.dll
2008-09-01 19:23 . 2006-09-26 13:57 28,672 –a—— C:\WINDOWS\system32\AVEQT.dll
2008-08-26 01:47 . 2008-08-30 22:14 d——– C:\Program Files\Microsoft Silverlight
2008-08-23 18:55 . 2008-08-23 18:55 d——– C:\Program Files\City Interactive
2008-08-20 23:04 . 2008-08-20 23:04 d——– C:\Program Files\Alwil Software
2008-08-18 15:21 . 2008-08-18 15:21 d——– C:\Output
2008-08-18 14:37 . 2008-08-18 14:37 34 –ah—– C:\WINDOWS\system32\DVDRipperDiamond_sysquict.dat
2008-08-18 14:36 . 2008-08-18 14:39 d——– C:\Program Files\Aglare DVD Ripper Platinum
2008-08-18 14:28 . 2008-08-18 14:28 1,409 –a—— C:\WINDOWS\system32\tmp2F378.FOT
2008-08-18 12:12 . 2008-08-18 17:09 d——– C:\Groovita
2008-08-16 19:38 . 2008-08-16 19:38 d——– C:\Documents and Settings\webcat\Application Data\Mask Pro 4.0
2008-08-16 15:46 . 2008-08-16 15:51 d——– C:\Program Files\onOne Software
2008-08-16 15:46 . 2008-08-16 15:58 d——– C:\Documents and Settings\webcat\Application Data\onOne Software
2008-08-10 21:04 . 2008-08-10 21:31 d——– C:\Documents and Settings\webcat\Application Data\Queue Manager
2008-08-10 21:00 . 2008-08-10 21:03 d——– C:\Documents and Settings\webcat\Application Data\Poser Pro
2008-08-10 20:56 . 2008-08-10 20:56 d——– C:\Program Files\Smith Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-05 15:21 ——— d—–w C:\Documents and Settings\webcat\Application Data\WTablet
2008-09-03 19:07 ——— d—–w C:\Documents and Settings\webcat\Application Data\MxBoost
2008-09-02 19:18 ——— d—–w C:\Program Files\Maxthon2
2008-09-02 18:11 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-09-01 16:42 ——— d—–w C:\Documents and Settings\webcat\Application Data\Roxio
2008-08-25 11:55 ——— d—–w C:\Documents and Settings\LocalService\Application Data\WTablet
2008-08-16 12:51 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-12 19:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-04 19:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\MainType
2008-08-04 14:17 ——— d—–w C:\Program Files\High-Logic
2008-08-04 14:17 ——— d—–w C:\Documents and Settings\webcat\Application Data\MainType
2008-08-04 13:48 ——— d—–w C:\Program Files\iTunes
2008-08-04 13:47 ——— d—–w C:\Program Files\iPod
2008-07-20 20:14 ——— d—–w C:\Program Files\QuickTime
2008-07-20 14:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Avira
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-07 13:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2008-06-24 16:43 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\DOWNLOADS —-
((((((((((((((((((((((((((((( snapshot@2008-09-03_19.52.02.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-06-09 22:21:01 135,168 —-a-w C:\WINDOWS\system32\java.exe
+ 2008-06-09 22:21:04 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-09 23:32:34 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
+ 2008-09-05 15:20:57 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_568.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-26 15360]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2008-04-26 67128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 81920]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 1884160]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2007-08-24 240112]
"DMXLauncher"="C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe" [2007-08-14 113136]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"P17Helper"="P17.dll" [2005-05-03 C:\WINDOWS\system32\P17.dll]
"nwiz"="nwiz.exe" [2007-12-05 C:\WINDOWS\system32\nwiz.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-01-26 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 53248]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-04-26 67128]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-06-28 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\BitSpirit\\BitSpirit.exe"=
"C:\\Program Files\\Microsoft Games\\Viva Pinata\\Viva Pinata.exe"=
"C:\\AppServ\\Apache2.2\\bin\\httpd.exe"=
"C:\\Program Files\\Maxthon2\\Modules\\MxDownloader\\MxDownloadServer.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 c2scsi;c2scsi;C:\WINDOWS\system32\drivers\c2scsi.sys [2007-01-10 244736]
R2 Apache2.2;Apache2.2;C:\AppServ\Apache2.2\bin\httpd.exe [2008-01-17 24635]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 TabletServiceWacom;TabletServiceWacom;C:\WINDOWS\system32\Wacom_Tablet.exe [2007-09-07 1373480]
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 11312]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 12848]
R3 WacomVKHid;Virtual Keyboard Driver;C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys [2007-02-16 11440]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe [2007-08-24 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [2007-08-24 309744]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [2007-08-24 166384]
S2 SessionLauncher;SessionLauncher;C:\DOCUME~1\webcat\LOCALS~1\Temp\DX9\SessionLauncher.exe [ ]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2007-08-24 72176]
S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2007-08-24 1083888]
.
Contents of the 'Scheduled Tasks' folder
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-05 18:36:29
Windows 5.1.2600 Service Pack 3, v.3300 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mysql]
"ImagePath"="C:\AppServ\MySQL\bin\mysqld –defaults-file=C:\AppServ\MySQL\my.ini mysql"
.
Completion time: 2008-09-05 18:40:08
ComboFix-quarantined-files.txt 2008-09-05 15:39:24
ComboFix2.txt 2008-09-03 17:22:18
ComboFix3.txt 2008-09-03 16:53:18
Pre-Run: 357,871,800,320 bytes free
Post-Run: 357,838,782,464 bytes free
125009 — E O F — 2008-08-30 21:05:12