ComboFix 07-09-21.2 - "Bradley Ross" 2007-09-26 22:26:10.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.369 [GMT -4:00]
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\d.exe
C:\DOCUME~1\BRADLE~1\APPLIC~1\macromedia\Flash Player\#SharedObjects\66JKGQ7C\
www.broadcaster.com
C:\DOCUME~1\BRADLE~1\APPLIC~1\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
www.broadcaster.com
C:\DOCUME~1\BRADLE~1\APPLIC~1\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
www.broadcaster.com\settings.sol
C:\Program Files\inetget2
C:\WINDOWS\4_cha.exe
C:\WINDOWS\hosts
C:\WINDOWS\system32\0_exception.nls
C:\WINDOWS\system32\comi2.dll
C:\WINDOWS\system32\cookie.dat
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\help.txt
C:\WINDOWS\system32\hwidbvmc.exe
C:\WINDOWS\system32\MailSpectre.exe
C:\WINDOWS\system32\msvcrtd.exe
C:\WINDOWS\system32\pfxzmtaim.dll
C:\WINDOWS\system32\pfxzmtforum.dll
C:\WINDOWS\system32\pfxzmtgtal.dll
C:\WINDOWS\system32\pfxzmticq.dll
C:\WINDOWS\system32\pfxzmtsmt.dll
C:\WINDOWS\system32\pfxzmtsmtspm.dll
C:\WINDOWS\system32\pfxzmtwbmail.dll
C:\WINDOWS\system32\pfxzmtymsg.dll
C:\WINDOWS\system32\ps.dat
C:\WINDOWS\wr.txt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_RUNTIME
-------\LEGACY_RUNTIME2
-------\LEGACY_SMTPDRV
-------\runtime
((((((((((((((((((((((((( Files Created from 2007-08-27 to 2007-09-27 )))))))))))))))))))))))))))))))
.
2007-09-26 22:25 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-23 22:19 2,886 --a------ C:\WINDOWS\system32\tmp.reg
2007-09-23 15:17 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-23 15:15 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-09-23 15:15 <DIR> d-------- C:\DOCUME~1\BRADLE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-19 20:38 <DIR> d-------- C:\Program Files\WMV9_VCM
2007-09-15 23:29 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-15 21:40 <DIR> dr-h----- C:\DOCUME~1\BRADLE~1\APPLIC~1\SecuROM
2007-09-15 20:33 <DIR> d-------- C:\Program Files\EA Sports
2007-09-15 14:28 <DIR> d-------- C:\Program Files\uTorrent
2007-09-13 07:38 360 --a------ C:\drmHeader.bin
2007-09-10 20:44 <DIR> d-------- C:\Program Files\Refworks
2007-09-05 00:33 <DIR> d-------- C:\Program Files\Eastside UK
2007-09-02 14:14 <DIR> d-------- C:\Program Files\SEGA
2007-08-26 19:15 <DIR> d-------- C:\Program Files\Sword of The New World
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-23 21:47 --------- d-------- C:\DOCUME~1\BRADLE~1\APPLIC~1\uTorrent
2007-09-23 15:15 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-22 11:02 --------- d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-09-16 08:05 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-09-03 22:32 --------- d-------- C:\Program Files\DivX
2007-08-26 14:26 --------- d-------- C:\Program Files\eMule
2007-08-12 09:34 --------- d-------- C:\Program Files\FlashGet
2007-08-04 13:00 --------- d-------- C:\DOCUME~1\BRADLE~1\APPLIC~1\My The Lord of the Rings, The Rise of the Witch-king Files
2007-08-02 01:18 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-28 13:24 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\{B9DFDEF4-3471-4379-BDBB-DEDA8A9809DF}
2007-07-28 13:23 --------- d-------- C:\Program Files\Sports Mogul
2007-07-28 13:05 54328 --a------ C:\xjbmuatt.exe
2007-07-28 13:05 44233 --a------ C:\mxlhjyw.exe
2007-07-28 13:05 44233 --a------ C:\mxlhjyw(2).exe
2007-07-28 13:05 20992 --a------ C:\rnep.exe
2007-07-28 13:05 1536 --a------ C:\isygaao.exe
2007-06-29 02:38 188416 --a------ C:\WINDOWS\mgrab.exe
2006-02-25 05:49:04 801 -csha-w C:\WINDOWS\system32\mmf(2)(2).sys
2006-04-10 20:32:45 801 -csha-w C:\WINDOWS\system32\mmf(2).sys
2006-02-25 03:54:54 801 -csha-w C:\WINDOWS\system32\mmf(3)(2).sys
2007-06-01 10:56:00 1,657 --sha-w C:\WINDOWS\system32\mmf(3).sys
2006-02-22 03:06:10 801 -csha-w C:\WINDOWS\system32\mmf(4)(2).sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{040FA520-78C6-41ce-81D0-9E733ABC1A29}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5345A7A1-805A-4923-B505-86B2FEBA3FE0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f015f320-ab08-11db-abbd-0800200c9a66}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="atiptaxx.exe" [2005-05-12 21:05 C:\WINDOWS\system32\atiptaxx.exe]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2004-05-06 16:12]
"CeEPOWER"="C:\Program Files\TOSHIBA\Power Management\CePMTray.exe" [2004-05-20 13:21]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-04-21 04:04]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-02-03 17:47]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 18:00 C:\WINDOWS\agrsmmsg.exe]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-03-15 14:17]
"EzButton"="C:\Program Files\EzButton\EzButton.EXE" [2004-05-13 22:29]
"WildTangent CDA"="C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" [2005-03-28 21:24]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 12:24]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 19:50]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-12-04 19:43]
"RegistryMechanic"="" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 06:24]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2005-08-18 15:49]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2007-05-03 17:43]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2003-08-06 16:23:32]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2004-05-22 17:02:18]
C:\DOCUME~1\BRADLE~1\STARTM~1\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 20:16:50]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell ExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\180sa]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
"C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\Apoint2K\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VVSN]
R1 atitray;atitray;\??\C:\Program Files\Radeon Omega Drivers\v2.6.42\ATI Tray Tools\atitray.sys
R1 ECioctl;ECioctl;C:\WINDOWS\system32\Drivers\ECioctl.sys
R1 SrvcEKIOMngr;SrvcEKIOMngr;C:\WINDOWS\system32\Drivers\EKIoMngr.sys
R1 SrvcEPIOMngr;SrvcEPIOMngr;C:\WINDOWS\system32\Drivers\EPIoMngr.sys
R1 SrvcSSIOMngr;SrvcSSIOMngr;C:\WINDOWS\system32\Drivers\SSIoMngr.sys
R1 SrvcTPIOMngr;SrvcTPIOMngr;C:\WINDOWS\system32\Drivers\TPIoMngr.sys
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys
R3 EMSCR;EMSCR;C:\WINDOWS\system32\DRIVERS\EMS7SK.sys
R3 EPOWER;Compal E-POWER Driver;C:\WINDOWS\system32\Drivers\hkdrv.sys
R3 ESDCR;ESDCR;C:\WINDOWS\system32\DRIVERS\ESD7SK.sys
R3 ESMCR;ESMCR;C:\WINDOWS\system32\DRIVERS\ESM7SK.sys
S2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe
S3 CachemanXPService;CachemanXP;C:\PROGRA~1\CACHEM~1\CachemanXP.exe
S3 SQLAgent$MICROSOFTBCM;SQLAgent$MICROSOFTBCM;C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlagent.EXE -i MICROSOFTBCM
S3 XDva020;XDva020;\??\C:\WINDOWS\system32\XDva020.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\E]
AutoRun\command- E:\OblivionLauncher.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-09-25 12:42:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-08-04 17:43:30 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1102185484.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-26 22:33:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\QTFont.for
C:\WINDOWS\QTFont.qfn
scan completed successfully
hidden files: 2
**************************************************************************
.
Completion time: 2007-09-26 22:34:42 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-26 22:34
.
--- E O F ---