ComboFix 08-10-25.01 - Owner 2008-10-27 9:10:36.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.681 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Owner\Application Data\inst.exe
C:\WINDOWS\system32\frakwtsg.ini
C:\WINDOWS\system32\gjRtvGgh.ini
C:\WINDOWS\system32\gjRtvGgh.ini2
C:\WINDOWS\system32\gstwkarf.dll
C:\WINDOWS\System32\hgGvtRjg.dll
C:\WINDOWS\system32\ljJASLFX.dll
C:\WINDOWS\system32\ppwzsg.dll
C:\WINDOWS\system32\woikisqh.exe
C:\WINDOWS\system32\yrldajir.dll
.
((((((((((((((((((((((((( Files Created from 2008-09-27 to 2008-10-27 )))))))))))))))))))))))))))))))
.
2008-10-26 21:07 . 2008-10-26 21:07 d——– C:\_OTScanIt
2008-10-24 19:33 . 2008-10-24 19:33 d——– C:\Documents and Settings\All Users\Application Data\Nero
2008-10-24 16:49 . 2008-10-24 18:44 736,024,576 –a—— C:\Ratatouille[2007]DvDrip[Eng]-aXXo.avi
2008-10-24 16:47 . 2008-10-24 16:47 28,836 –a—— C:\[isoHunt] Ratatouille[2007]DvDrip[Eng]-aXXo.avi.3882156.TPB.torrent
2008-10-24 16:02 . 2008-10-24 16:02 2,422 –a—— C:\WINDOWS\system32\wpa.bak
2008-10-23 19:13 . 2008-10-23 19:13 d——– C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-10-23 16:24 . 2008-10-23 16:24 d——– C:\Program Files\Trend Micro
2008-10-23 16:24 . 2008-10-23 16:24 499,568 –a—— C:\hijackthis_v2.0.2.zip
2008-10-22 21:18 . 2008-10-22 21:45 4,681,420,800 –a—— C:\SEX_AND_THE_CITY.ISO
2008-10-22 20:55 . 2008-10-22 20:55 d——– C:\SEX_AND_THE_CITY
2008-10-22 20:49 . 2008-10-22 20:49 d——– C:\Documents and Settings\All Users\Application Data\SlySoft
2008-10-22 20:47 . 2008-10-22 20:47 d——– C:\Program Files\SlySoft
2008-10-22 20:29 . 2008-10-23 10:17 d——– C:\AnyDVD HD 6.4.5.6
2008-10-22 20:04 . 2008-10-22 20:46 d——– C:\Documents and Settings\Owner\Application Data\Vso
2008-10-22 20:04 . 2008-10-22 20:09 d——– C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
2008-10-22 20:04 . 2008-10-22 20:36 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2008-10-22 20:04 . 2008-10-22 20:46 47,360 –a—— C:\Documents and Settings\Owner\Application Data\pcouffin.sys
2008-10-22 18:11 . 2008-10-22 18:11 d——– C:\touch-tone terorists junkyard willie 4 CD collection
2008-10-21 16:46 . 2008-10-21 16:46 d——– C:\Program Files\Nero 7.10.1.0
2008-10-21 13:37 . 2008-10-21 13:37 12,754,672 –a—— C:\MP10Setup.exe
2008-10-21 13:28 . 2008-10-21 14:05 182,002,016 –a—— C:\Program Files\Nero-7.10.1.0_eng_full.exe
2008-10-20 17:42 . 2008-10-20 17:42 d——– C:\Grey's Anatomy - Season 1 DVD
2008-10-20 17:35 . 2008-10-20 17:35 47,052 –a—— C:\[isoHunt] Grey____s_Anatomy_Season_3.3938747.TPB.torrent
2008-10-15 12:06 . 2008-10-15 12:06 d——– C:\Documents and Settings\Owner\Application Data\Hewlett-Packard
2008-10-14 10:13 . 2006-09-13 00:09 1,110,528 –a—— C:\WINDOWS\system32\msxml3.dll
2008-10-14 10:13 . 2004-08-04 02:56 100,352 –a—— C:\WINDOWS\system32\6to4svc.dll
2008-10-14 10:12 . 2006-07-13 03:41 199,936 –a—— C:\WINDOWS\system32\drivers\rmcast.sys
2008-10-14 10:09 . 2006-03-16 19:49 25,600 –a—— C:\WINDOWS\system32\verclsid.exe
2008-10-14 10:07 . 2005-07-25 23:31 68,608 –a—— C:\WINDOWS\system32\olecli32.dll
2008-10-14 10:07 . 2005-07-25 23:31 35,328 –a—— C:\WINDOWS\system32\olecnv32.dll
2008-10-14 10:03 . 2005-01-10 20:20 118,272 –a—— C:\WINDOWS\system32\dllcache\dhtmled.ocx
2008-10-14 10:02 . 2005-04-22 00:20 51,712 –a–c— C:\WINDOWS\system32\dllcache\agentdpv.dll
2008-10-14 09:57 . 2008-10-14 09:57 d——– C:\WINDOWS\provisioning
2008-10-14 09:57 . 2008-10-14 10:35 d——– C:\WINDOWS\peernet
2008-10-14 09:49 . 2008-10-14 09:49 d——– C:\WINDOWS\EHome
2008-10-10 19:07 . 2008-10-10 19:08 67,167,528 –a—— C:\iTunes801Setup.exe
2008-10-10 18:58 . 2008-10-10 18:58 d——– C:\WINDOWS\Applian FLV Player
2008-10-10 18:58 . 2008-10-10 18:58 d——– C:\Program Files\FLV Player
2008-10-10 18:58 . 2008-10-10 18:58 2,569,112 –a—— C:\FLVPlayerSetup.exe
2008-10-10 13:53 . 2008-10-21 16:38 d——– C:\Documents and Settings\All Users\Application Data\Ahead
2008-10-10 13:48 . 2008-10-10 18:45 d——– C:\Program Files\Save
2008-10-10 13:47 . 2008-10-10 13:48 d——– C:\Program Files\DaemonTools_WhenUSave_Installer
2008-10-10 13:45 . 2008-10-10 13:45 d——– C:\Program Files\DAEMON Tools
2008-10-10 13:43 . 2008-10-10 13:43 1,802,208 –a—— C:\daemon4091-x86.exe
2008-10-10 13:43 . 2008-10-10 13:43 682,232 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2008-10-08 16:44 . 2008-10-22 22:00 d——– C:\WINDOWS\system32\NtmsData
2008-10-08 13:40 . 2008-10-08 15:42 2,819,883,008 –a—— C:\{KingOfKings} - Rosetta Stone 2007 DVDR .ISO
2008-10-08 12:02 . 2008-10-14 13:04 d——– C:\Documents and Settings\Owner\Application Data\Creative
2008-10-04 20:58 . 2004-08-02 13:20 7,208 –a—— C:\WINDOWS\system32\secupd.sig
2008-10-04 20:58 . 2004-08-02 13:20 4,569 –a—— C:\WINDOWS\system32\secupd.dat
2008-10-04 19:22 . 2008-10-04 19:22 d——– C:\WINDOWS\system32\bits
2008-10-04 19:21 . 2008-10-12 22:37 d–h—– C:\WINDOWS\$hf_mig$
2008-10-04 19:10 . 2008-07-18 21:09 563,912 –a—— C:\WINDOWS\system32\wuapi.dll
2008-10-04 19:10 . 2008-07-18 21:09 325,832 –a—— C:\WINDOWS\system32\wucltui.dll
2008-10-04 19:10 . 2008-07-18 21:09 215,752 –a—— C:\WINDOWS\system32\wuaucpl.cpl
2008-10-04 19:10 . 2008-07-18 21:09 205,000 –a—— C:\WINDOWS\system32\wuweb.dll
2008-10-04 19:10 . 2004-08-03 13:03 186,136 –a—— C:\WINDOWS\system32\wuaueng1.dll
2008-10-04 19:10 . 2004-08-03 13:01 167,704 –a—— C:\WINDOWS\system32\wuauclt1.exe
2008-10-04 19:10 . 2008-07-18 21:10 36,552 –a—— C:\WINDOWS\system32\wups.dll
2008-10-03 17:15 . 2008-10-03 17:15 d—s—- C:\Documents and Settings\Owner\UserData
2008-10-03 17:13 . 2008-10-03 17:14 d——– C:\Program Files\Total Video Converter
2008-10-03 17:12 . 2008-10-03 17:12 7,647,053 –a—— C:\tvcnew.exe
2008-10-03 12:34 . 2008-10-03 12:35 d——– C:\Documents and Settings\Owner\Application Data\TotalRecorder
2008-10-03 12:33 . 2008-10-03 12:33 d——– C:\Program Files\HighCriteria
2008-10-03 12:33 . 2008-04-17 00:34 120,472 –a—— C:\WINDOWS\system32\drivers\TotRec7.sys
2008-10-03 12:33 . 2008-04-12 11:29 106,496 –a—— C:\WINDOWS\system32\DrvTrNTl.dll
2008-10-03 12:33 . 2008-04-17 00:34 59,032 –a—— C:\WINDOWS\system32\DrvTrNTm.dll
2008-10-03 12:16 . 2008-10-03 12:16 d——– C:\Program Files\SmitfraudFix
2008-10-03 12:16 . 2008-10-03 12:16 1,578,805 –a—— C:\SmitfraudFix.exe
2008-10-03 12:13 . 2008-10-03 12:13 d——– C:\Program Files\DVD Decrypter
2008-10-03 12:08 . 2008-10-03 12:08 d——– C:\Program Files\DVD Shrink
2008-10-03 12:08 . 2008-10-22 21:16 d——– C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-10-03 09:47 . 2008-10-26 21:52 69 –a—— C:\WINDOWS\NeroDigital.ini
2008-10-02 22:58 . 2008-10-24 19:26 d——– C:\Documents and Settings\Owner\Application Data\Azureus
2008-10-02 21:36 . 2008-10-24 21:55 d——– C:\Documents and Settings\Owner\Application Data\Ahead
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-25 00:35 ——— d—–w C:\Program Files\Common Files\Ahead
2008-10-14 15:27 797,184 —-a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-10-14 15:27 2,867,712 —-a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-10-03 22:13 664 —-a-w C:\Program Files\Total Video Player.lnk
2008-10-03 16:56 ——— d—–w C:\Program Files\Vuze
2008-10-03 03:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\Azureus
2008-10-03 03:58 ——— d—–w C:\Program Files\AskSBar
2008-10-03 02:33 ——— d—–w C:\Program Files\Nero
2008-10-03 02:09 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-10-03 01:33 ——— d—–w C:\Program Files\Creative
2008-10-03 01:30 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-10-03 01:29 ——— d–h–w C:\Program Files\Creative Installation Information
2008-10-03 01:29 ——— d—–w C:\Program Files\Common Files\Creative
2008-10-03 01:25 ——— d—–w C:\Documents and Settings\All Users\Application Data\Creative
2008-10-03 01:17 ——— d—–w C:\Program Files\Hewlett-Packard
2008-10-03 01:10 ——— d—–w C:\Program Files\Common Files\Hewlett-Packard
2008-10-03 01:04 7,508,608 —-a-w C:\Program Files\Firefox Setup 3.0.3.exe
2008-10-03 00:57 ——— d—–w C:\Program Files\Zone Labs
2008-10-03 00:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Broderbund LLC
2008-10-03 00:50 ——— d—–w C:\Program Files\Realtek AC97
2008-10-03 00:50 ——— d—–w C:\Program Files\Driver
2008-10-03 00:49 ——— d—–w C:\Program Files\S3
2008-10-03 00:46 ——— d—–w C:\Program Files\VIA
2008-10-03 00:28 ——— d—–w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-09-13 700416]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.EXE" [2004-11-15 1670144]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-03 165784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTRegRun"="C:\WINDOWS\CTRegRun.EXE" [1999-10-10 41984]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 147456]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 28672]
ZoneAlarm Pro.lnk - C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe [2008-10-02 422984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=ppwzsg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"= DrvTrNTm.dll
"wave"= DrvTrNTm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
R0 ViBus;ViBus;C:\WINDOWS\System32\DRIVERS\ViBus.sys [2007-10-18 16896]
R0 videX32;videX32;C:\WINDOWS\System32\DRIVERS\videX32.sys [2007-09-21 9216]
R0 ViPrt;VIA SATA IDE Device Driver;C:\WINDOWS\System32\DRIVERS\ViPrt.sys [2007-10-18 52224]
R1 BIOS;BIOS;C:\WINDOWS\System32\drivers\BIOS.sys [2005-03-16 13696]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys [2007-02-27 42496]
R3 TotRec7;Total Recorder WDM audio driver;C:\WINDOWS\System32\drivers\TotRec7.sys [2008-04-17 120472]
.
Contents of the 'Scheduled Tasks' folder
2008-10-15 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1222996893.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]
2008-10-15 C:\WINDOWS\Tasks\WebReg 20081015130630.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqwrg.exe [2003-04-06 00:01]
.
- - - - ORPHANS REMOVED - - - -
BHO-{463E51E1-790A-4E1F-A61D-B09E8C7301D1} - C:\WINDOWS\System32\hgGvtRjg.dll
BHO-{599BF2E2-52FE-4D84-85EB-18457A18CEBF} - C:\WINDOWS\System32\rqRJDvUN.dll
BHO-{DD153FDB-E2FB-40D2-8E36-F21C36B51DAD} - C:\WINDOWS\system32\ljJASLFX.dll
BHO-{f791cd8e-6542-4a39-b533-410a7d4d3025} - C:\WINDOWS\System32\ppwzsg.dll
HKLM-Run-d8b20a17 - C:\WINDOWS\System32\gstwkarf.dll
ShellExecuteHooks-{DD153FDB-E2FB-40D2-8E36-F21C36B51DAD} - C:\WINDOWS\system32\ljJASLFX.dll
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://yahoo.com
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-27 09:13:53
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
.
**************************************************************************
.
Completion time: 2008-10-27 9:16:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-27 14:16:29
Pre-Run: 92,207,144,960 bytes free
Post-Run: 92,346,298,368 bytes free
winxpsp1_en_hom_bf.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
209 — E O F — 2008-10-22 02:32:15