Ginga
When I ran ComboFix it said there was an update and asked me to update it.
I didn't update it, and did the scan anyway. Should I update it and re-do the scan?
Anyway here's the Log of it.
ComboFix 08-09-25.03 - Alex 2008-09-29 21:44:27.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.250 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Alex\Cookies\alex@cubics[1].txt
C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
C:\WINDOWS\Install.txt
C:\WINDOWS\system32\comsa32.sys
C:\WINDOWS\system32\Install.txt
C:\WINDOWS\system32\rtl60.bpl
C:\WINDOWS\system32\tpszxyd.sys
.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-29 )))))))))))))))))))))))))))))))
.
2008-09-27 20:46 . 2008-09-27 20:46 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-09-25 13:51 . 2008-09-25 15:27 d——– C:\Program Files\Daemons Ring Gunz
2008-09-25 08:57 . 2008-09-25 09:03 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-25 08:57 . 2008-09-25 08:57 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-25 08:57 . 2008-09-25 08:57 d——– C:\Documents and Settings\Alex\Application Data\Malwarebytes
2008-09-25 08:57 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-25 08:57 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-25 05:49 . 2008-09-28 13:33 d——– C:\Documents and Settings\Everyone Else\Contacts
2008-09-24 07:55 . 2008-07-18 22:09 25,800 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2008-09-24 06:59 . 2008-09-24 06:59 d——– C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-09-24 06:43 . 2008-09-24 06:43 d——– C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-09-22 18:11 . 2008-09-22 18:11 d——– C:\Documents and Settings\Everyone Else\Application Data\Ventrilo
2008-09-19 07:01 . 2008-09-19 07:15 d–h—– C:\Documents and Settings\Everyone Else\Application Data\ijjigame
2008-09-19 06:55 . 2008-09-19 07:18 d——– C:\Documents and Settings\Everyone Else\Application Data\AVGTOOLBAR
2008-09-19 06:48 . 2008-09-29 21:19 d——– C:\Documents and Settings\Everyone Else
2008-09-19 06:45 . 2008-09-19 06:45 d——– C:\Documents and Settings\Administrator
2008-09-18 03:32 . 2008-09-18 03:32 410,976 –a—— C:\WINDOWS\system32\deploytk.dll
2008-09-18 03:02 . 2008-09-18 03:02 d——– C:\Program Files\CCleaner
2008-09-18 02:40 . 2008-09-18 02:40 d——– C:\Program Files\Trend Micro
2008-09-17 20:44 . 2008-04-23 14:02 157,152 –a—— C:\WINDOWS\system32\PubPlugin.dll
2008-09-13 05:45 . 2008-09-13 04:46 41,117 –a—— C:\HackTasic.DLL.rar
2008-09-09 00:13 . 2008-09-09 00:13 7,680 –ahs—- C:\WINDOWS\Thumbs.db
2008-09-08 01:21 . 2008-09-19 06:58 d——– C:\Program Files\Saga
2008-09-07 23:38 . 2008-09-07 23:38 d——– C:\Program Files\Common Files\Blizzard Entertainment
2008-09-05 23:30 . 2008-09-05 23:30 241,704 —–c— C:\WINDOWS\system32\dllcache\wgaLogon.dll
2008-09-05 23:29 . 2008-09-05 23:29 917,032 —–c— C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-09-03 11:33 . 2008-09-03 11:33 d——– C:\WINDOWS\Sun
2008-09-01 00:01 . 2008-09-01 19:05 d——– C:\Documents and Settings\Alex\Application Data\GarageGames
2008-08-29 01:30 . 2008-08-29 01:30 25 –a—— C:\WINDOWS\TDH_Launcher.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-18 02:31 ——— d—–w C:\Program Files\Java
2008-09-18 01:58 ——— d—–w C:\Documents and Settings\Alex\Application Data\IGN_DLM
2008-09-16 01:03 ——— d–h–w C:\Documents and Settings\Alex\Application Data\ijjigame
2008-09-05 15:54 ——— d—–w C:\Program Files\TuneUp Utilities 2008
2008-09-01 06:11 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-30 00:33 97,928 —-a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-27 18:33 ——— d—–w C:\Documents and Settings\Alex\Application Data\Trash
2008-08-25 07:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sony
2008-08-25 07:16 ——— d—–w C:\Documents and Settings\Alex\Application Data\Sony
2008-08-25 07:11 ——— d—–w C:\Program Files\Sony Ericsson
2008-08-25 07:11 ——— d—–w C:\Program Files\Sony
2008-08-25 07:11 ——— d—–w C:\Program Files\Common Files\Sony Shared
2008-08-25 07:07 ——— d—–w C:\Program Files\Apple Software Update
2008-08-25 07:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-25 07:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2008-08-25 07:00 ——— d—–w C:\Program Files\Sony Setup
2008-08-25 07:00 ——— d—–w C:\Documents and Settings\Alex\Application Data\Sony Setup
2008-08-23 23:37 ——— d—–w C:\Documents and Settings\Alex\Application Data\Ventrilo
2008-08-23 23:36 ——— d—–w C:\Program Files\Ventrilo
2008-08-23 23:36 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-21 19:31 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-08-21 19:29 ——— d—–w C:\Program Files\Windows Live
2008-08-21 18:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-21 02:05 ——— d—–w C:\Documents and Settings\Alex\Application Data\TigerPlayer
2008-08-21 02:02 ——— d—–w C:\Program Files\MpcStar
2008-08-21 01:24 ——— d—–w C:\Documents and Settings\Alex\Application Data\FrostWire
2008-08-20 17:06 ——— d—–w C:\Program Files\Common Files\Java
2008-08-20 16:33 ——— d—–w C:\Program Files\MSBuild
2008-08-20 16:32 ——— d—–w C:\Program Files\Reference Assemblies
2008-08-20 16:26 ——— d—–w C:\Program Files\MSXML 6.0
2008-08-19 06:19 ——— dcsh–w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-15 06:18 355,584 —-a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-15 06:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-15 06:18 ——— d—–w C:\Documents and Settings\Alex\Application Data\TuneUp Software
2008-08-14 10:08 ——— d—–w C:\Documents and Settings\Alex\Application Data\MSNInstaller
2008-08-12 08:38 ——— d—–w C:\Program Files\Google
2008-08-12 06:46 ——— d—–w C:\Program Files\Common Files\INCA Shared
2008-08-12 06:43 ——— d—–w C:\Program Files\NHN USA
2008-08-12 06:00 ——— d—–w C:\Documents and Settings\Alex\Application Data\AVGTOOLBAR
2008-08-12 05:54 ——— d—–w C:\Program Files\BitComet
2008-08-12 05:07 ——— d—–w C:\Program Files\K-Lite Codec Pack
2008-08-12 04:43 76,040 —-a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-12 04:43 10,520 —-a-w C:\WINDOWS\system32\avgrsstx.dll
2008-08-12 04:43 ——— d—–w C:\Program Files\AVG
2008-08-12 04:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-08-12 03:32 ——— d—–w C:\Program Files\microsoft frontpage
2008-08-06 14:27 499,712 —-a-w C:\WINDOWS\system32\msvcp71.dll
2008-07-31 09:41 68,616 —-a-w C:\WINDOWS\system32\XAPOFX1_1.dll
2008-07-31 09:41 238,088 —-a-w C:\WINDOWS\system32\xactengine3_2.dll
2008-07-31 09:40 509,448 —-a-w C:\WINDOWS\system32\XAudio2_2.dll
2008-07-25 08:34 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-07-25 08:34 683,520 —-a-w C:\WINDOWS\system32\divx.dll
2008-07-23 16:50 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-21 15:14 9,728 —-a-w C:\WINDOWS\system32\RtNicProp32.dll
2008-07-18 21:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-12 07:18 467,984 —-a-w C:\WINDOWS\system32\d3dx10_39.dll
2008-07-12 07:18 3,851,784 —-a-w C:\WINDOWS\system32\D3DX9_39.dll
2008-07-12 07:18 1,493,528 —-a-w C:\WINDOWS\system32\D3DCompiler_39.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
.
((((((((((((((((((((((((((((( snapshot@2008-09-26_ 5.25.21.07 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-26 03:58:14 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-27 12:14:33 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-26 03:58:14 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-27 12:14:33 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-26 03:58:14 278,528 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-27 12:14:33 278,528 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-04-23 12:54:50 100,488 —-a-w C:\WINDOWS\system32\drivers\s115mgmt.sys
+ 2008-09-29 18:59:28 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_740.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-18 140696]
"QuickTime Task"="C:\Program Files\MpcStar\Codecs\QuickTime\qttask.exe" [2008-05-27 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"vidc.tscc"= C:\PROGRA~1\MpcStar\Codecs\tscc\tsccvid.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"solewxte"=2 (0x2)
"wsldoekd"=2 (0x2)
"tdydowkc"=2 (0x2)
"roytctm"=2 (0x2)
"noytcyr"=2 (0x2)
"afisicx"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"HijackThis startup scan"=C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\ijji\\ENGLISH\\u_gunz.exe"=
"C:\\ijji\\ENGLISH\\Gunz\\GunzLauncher.exe"=
"C:\\ijji\\ENGLISH\\Gunz\\Gunz.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"C:\\Program Files\\Daemons Ring Gunz\\DRGunZ.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19205:TCP"= 19205:TCP:BitComet 19205 TCP
"19205:UDP"= 19205:UDP:BitComet 19205 UDP
"8000:TCP"= 8000:TCP:Ijji Gunz 8000 TCP
"8000:UDP"= 8000:UDP:Ijji Gunz 8000 UDP
"7750:TCP"= 7750:TCP:Ijji Gunz 7750 TCP
"7750:UDP"= 7750:UDP:Ijji Gunz 7750 UDP
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-30 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-30 875288]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-30 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-12 76040]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-09-18 152984]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R3 STAC97NA;SigmaTel 3D Environmental Audio;C:\WINDOWS\system32\drivers\stac97na.sys [2002-09-20 296179]
R3 STAC97NH;STAC97NH;C:\WINDOWS\system32\drivers\stac97nh.sys [2002-09-20 231983]
S0 ibnd;ibnd;C:\WINDOWS\system32\drivers\mmuacggp.sys [ ]
S3 dump_wmimmc;dump_wmimmc;C:\ijji\ENGLISH\Gunz\GameGuard\dump_wmimmc.sys [ ]
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;C:\DOCUME~1\Alex\LOCALS~1\Temp\Rar$EX25.062\MoonLight Engine 1196.4\IlvMoney1215.sys [ ]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);C:\WINDOWS\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-08-15 355584]
S3 XDva092;XDva092;C:\WINDOWS\system32\XDva092.sys [ ]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\em6etqkv.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.com
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin2.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin3.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin4.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin5.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-29 21:48:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-29 21:51:40
ComboFix-quarantined-files.txt 2008-09-29 20:51:30
ComboFix2.txt 2008-09-26 04:26:00
Pre-Run: 97,230,274,560 bytes free
Post-Run: 97,435,439,104 bytes free
232
I didn't update it, and did the scan anyway. Should I update it and re-do the scan?
Anyway here's the Log of it.
ComboFix 08-09-25.03 - Alex 2008-09-29 21:44:27.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.250 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Alex\Cookies\alex@cubics[1].txt
C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
C:\WINDOWS\Install.txt
C:\WINDOWS\system32\comsa32.sys
C:\WINDOWS\system32\Install.txt
C:\WINDOWS\system32\rtl60.bpl
C:\WINDOWS\system32\tpszxyd.sys
.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-29 )))))))))))))))))))))))))))))))
.
2008-09-27 20:46 . 2008-09-27 20:46 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-09-25 13:51 . 2008-09-25 15:27 d——– C:\Program Files\Daemons Ring Gunz
2008-09-25 08:57 . 2008-09-25 09:03 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-25 08:57 . 2008-09-25 08:57 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-25 08:57 . 2008-09-25 08:57 d——– C:\Documents and Settings\Alex\Application Data\Malwarebytes
2008-09-25 08:57 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-25 08:57 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-25 05:49 . 2008-09-28 13:33 d——– C:\Documents and Settings\Everyone Else\Contacts
2008-09-24 07:55 . 2008-07-18 22:09 25,800 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2008-09-24 06:59 . 2008-09-24 06:59 d——– C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-09-24 06:43 . 2008-09-24 06:43 d——– C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-09-22 18:11 . 2008-09-22 18:11 d——– C:\Documents and Settings\Everyone Else\Application Data\Ventrilo
2008-09-19 07:01 . 2008-09-19 07:15 d–h—– C:\Documents and Settings\Everyone Else\Application Data\ijjigame
2008-09-19 06:55 . 2008-09-19 07:18 d——– C:\Documents and Settings\Everyone Else\Application Data\AVGTOOLBAR
2008-09-19 06:48 . 2008-09-29 21:19 d——– C:\Documents and Settings\Everyone Else
2008-09-19 06:45 . 2008-09-19 06:45 d——– C:\Documents and Settings\Administrator
2008-09-18 03:32 . 2008-09-18 03:32 410,976 –a—— C:\WINDOWS\system32\deploytk.dll
2008-09-18 03:02 . 2008-09-18 03:02 d——– C:\Program Files\CCleaner
2008-09-18 02:40 . 2008-09-18 02:40 d——– C:\Program Files\Trend Micro
2008-09-17 20:44 . 2008-04-23 14:02 157,152 –a—— C:\WINDOWS\system32\PubPlugin.dll
2008-09-13 05:45 . 2008-09-13 04:46 41,117 –a—— C:\HackTasic.DLL.rar
2008-09-09 00:13 . 2008-09-09 00:13 7,680 –ahs—- C:\WINDOWS\Thumbs.db
2008-09-08 01:21 . 2008-09-19 06:58 d——– C:\Program Files\Saga
2008-09-07 23:38 . 2008-09-07 23:38 d——– C:\Program Files\Common Files\Blizzard Entertainment
2008-09-05 23:30 . 2008-09-05 23:30 241,704 —–c— C:\WINDOWS\system32\dllcache\wgaLogon.dll
2008-09-05 23:29 . 2008-09-05 23:29 917,032 —–c— C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-09-03 11:33 . 2008-09-03 11:33 d——– C:\WINDOWS\Sun
2008-09-01 00:01 . 2008-09-01 19:05 d——– C:\Documents and Settings\Alex\Application Data\GarageGames
2008-08-29 01:30 . 2008-08-29 01:30 25 –a—— C:\WINDOWS\TDH_Launcher.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-18 02:31 ——— d—–w C:\Program Files\Java
2008-09-18 01:58 ——— d—–w C:\Documents and Settings\Alex\Application Data\IGN_DLM
2008-09-16 01:03 ——— d–h–w C:\Documents and Settings\Alex\Application Data\ijjigame
2008-09-05 15:54 ——— d—–w C:\Program Files\TuneUp Utilities 2008
2008-09-01 06:11 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-30 00:33 97,928 —-a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-27 18:33 ——— d—–w C:\Documents and Settings\Alex\Application Data\Trash
2008-08-25 07:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sony
2008-08-25 07:16 ——— d—–w C:\Documents and Settings\Alex\Application Data\Sony
2008-08-25 07:11 ——— d—–w C:\Program Files\Sony Ericsson
2008-08-25 07:11 ——— d—–w C:\Program Files\Sony
2008-08-25 07:11 ——— d—–w C:\Program Files\Common Files\Sony Shared
2008-08-25 07:07 ——— d—–w C:\Program Files\Apple Software Update
2008-08-25 07:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-25 07:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2008-08-25 07:00 ——— d—–w C:\Program Files\Sony Setup
2008-08-25 07:00 ——— d—–w C:\Documents and Settings\Alex\Application Data\Sony Setup
2008-08-23 23:37 ——— d—–w C:\Documents and Settings\Alex\Application Data\Ventrilo
2008-08-23 23:36 ——— d—–w C:\Program Files\Ventrilo
2008-08-23 23:36 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-21 19:31 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-08-21 19:29 ——— d—–w C:\Program Files\Windows Live
2008-08-21 18:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-21 02:05 ——— d—–w C:\Documents and Settings\Alex\Application Data\TigerPlayer
2008-08-21 02:02 ——— d—–w C:\Program Files\MpcStar
2008-08-21 01:24 ——— d—–w C:\Documents and Settings\Alex\Application Data\FrostWire
2008-08-20 17:06 ——— d—–w C:\Program Files\Common Files\Java
2008-08-20 16:33 ——— d—–w C:\Program Files\MSBuild
2008-08-20 16:32 ——— d—–w C:\Program Files\Reference Assemblies
2008-08-20 16:26 ——— d—–w C:\Program Files\MSXML 6.0
2008-08-19 06:19 ——— dcsh–w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-15 06:18 355,584 —-a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-15 06:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-15 06:18 ——— d—–w C:\Documents and Settings\Alex\Application Data\TuneUp Software
2008-08-14 10:08 ——— d—–w C:\Documents and Settings\Alex\Application Data\MSNInstaller
2008-08-12 08:38 ——— d—–w C:\Program Files\Google
2008-08-12 06:46 ——— d—–w C:\Program Files\Common Files\INCA Shared
2008-08-12 06:43 ——— d—–w C:\Program Files\NHN USA
2008-08-12 06:00 ——— d—–w C:\Documents and Settings\Alex\Application Data\AVGTOOLBAR
2008-08-12 05:54 ——— d—–w C:\Program Files\BitComet
2008-08-12 05:07 ——— d—–w C:\Program Files\K-Lite Codec Pack
2008-08-12 04:43 76,040 —-a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-12 04:43 10,520 —-a-w C:\WINDOWS\system32\avgrsstx.dll
2008-08-12 04:43 ——— d—–w C:\Program Files\AVG
2008-08-12 04:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-08-12 03:32 ——— d—–w C:\Program Files\microsoft frontpage
2008-08-06 14:27 499,712 —-a-w C:\WINDOWS\system32\msvcp71.dll
2008-07-31 09:41 68,616 —-a-w C:\WINDOWS\system32\XAPOFX1_1.dll
2008-07-31 09:41 238,088 —-a-w C:\WINDOWS\system32\xactengine3_2.dll
2008-07-31 09:40 509,448 —-a-w C:\WINDOWS\system32\XAudio2_2.dll
2008-07-25 08:34 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-07-25 08:34 683,520 —-a-w C:\WINDOWS\system32\divx.dll
2008-07-23 16:50 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-21 15:14 9,728 —-a-w C:\WINDOWS\system32\RtNicProp32.dll
2008-07-18 21:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-12 07:18 467,984 —-a-w C:\WINDOWS\system32\d3dx10_39.dll
2008-07-12 07:18 3,851,784 —-a-w C:\WINDOWS\system32\D3DX9_39.dll
2008-07-12 07:18 1,493,528 —-a-w C:\WINDOWS\system32\D3DCompiler_39.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
.
((((((((((((((((((((((((((((( snapshot@2008-09-26_ 5.25.21.07 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-26 03:58:14 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-27 12:14:33 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-26 03:58:14 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-27 12:14:33 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-26 03:58:14 278,528 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-27 12:14:33 278,528 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-04-23 12:54:50 100,488 —-a-w C:\WINDOWS\system32\drivers\s115mgmt.sys
+ 2008-09-29 18:59:28 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_740.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-18 140696]
"QuickTime Task"="C:\Program Files\MpcStar\Codecs\QuickTime\qttask.exe" [2008-05-27 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"vidc.tscc"= C:\PROGRA~1\MpcStar\Codecs\tscc\tsccvid.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"solewxte"=2 (0x2)
"wsldoekd"=2 (0x2)
"tdydowkc"=2 (0x2)
"roytctm"=2 (0x2)
"noytcyr"=2 (0x2)
"afisicx"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"HijackThis startup scan"=C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\ijji\\ENGLISH\\u_gunz.exe"=
"C:\\ijji\\ENGLISH\\Gunz\\GunzLauncher.exe"=
"C:\\ijji\\ENGLISH\\Gunz\\Gunz.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"C:\\Program Files\\Daemons Ring Gunz\\DRGunZ.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19205:TCP"= 19205:TCP:BitComet 19205 TCP
"19205:UDP"= 19205:UDP:BitComet 19205 UDP
"8000:TCP"= 8000:TCP:Ijji Gunz 8000 TCP
"8000:UDP"= 8000:UDP:Ijji Gunz 8000 UDP
"7750:TCP"= 7750:TCP:Ijji Gunz 7750 TCP
"7750:UDP"= 7750:UDP:Ijji Gunz 7750 UDP
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-30 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-30 875288]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-30 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-12 76040]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-09-18 152984]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R3 STAC97NA;SigmaTel 3D Environmental Audio;C:\WINDOWS\system32\drivers\stac97na.sys [2002-09-20 296179]
R3 STAC97NH;STAC97NH;C:\WINDOWS\system32\drivers\stac97nh.sys [2002-09-20 231983]
S0 ibnd;ibnd;C:\WINDOWS\system32\drivers\mmuacggp.sys [ ]
S3 dump_wmimmc;dump_wmimmc;C:\ijji\ENGLISH\Gunz\GameGuard\dump_wmimmc.sys [ ]
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;C:\DOCUME~1\Alex\LOCALS~1\Temp\Rar$EX25.062\MoonLight Engine 1196.4\IlvMoney1215.sys [ ]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);C:\WINDOWS\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-08-15 355584]
S3 XDva092;XDva092;C:\WINDOWS\system32\XDva092.sys [ ]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\em6etqkv.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.com
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin2.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin3.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin4.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin5.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-29 21:48:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-29 21:51:40
ComboFix-quarantined-files.txt 2008-09-29 20:51:30
ComboFix2.txt 2008-09-26 04:26:00
Pre-Run: 97,230,274,560 bytes free
Post-Run: 97,435,439,104 bytes free
232