ComboFix 08-01-20.1 - Derek Goh Jia Jun 2008-01-22 0:31:08.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.791 [GMT 8:00]
Running from: C:\Documents and Settings\Derek Goh Jia Jun\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\system32\ComboFix.exe
C:\WINDOWS\system32\kavo.exe
C:\WINDOWS\system32\kavo0.dll
C:\WINDOWS\system32\kavo1.dll
.
((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))
.
2008-01-22 00:30 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-21 17:31 . 2008-01-21 17:47 <DIR> d-------- C:\Documents and Settings\Derek Goh Jia Jun\DoctorWeb
2008-01-20 23:54 . 2008-01-20 23:54 <DIR> d-------- C:\Documents and Settings\Derek Goh Jia Jun\Application Data\Grisoft
2008-01-20 23:54 . 2007-05-30 20:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-20 22:24 . 2008-01-20 22:24 118,785 -r-hs---- C:\lg.cmd
2008-01-20 15:38 . 2001-08-17 19:00 50,620 --a------ C:\WINDOWS\system32\command.com.bak
2008-01-20 15:38 . 2001-08-30 21:02 2,577 --a------ C:\WINDOWS\system32\config.nt.bak
2008-01-20 15:38 . 2001-08-17 19:00 1,688 --a------ C:\WINDOWS\system32\autoexec.nt.bak
2008-01-18 22:36 . 2008-01-18 22:37 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-18 15:49 . 2008-01-20 16:10 115,227 -r-hs---- C:\8e9gmih.bat
2008-01-17 23:55 . 2008-01-18 23:42 <DIR> d-------- C:\sysclean
2008-01-15 20:42 . 2008-01-21 22:16 <DIR> d-------- C:\Program Files\mIRC
2008-01-15 20:42 . 2008-01-22 00:15 <DIR> d-------- C:\Documents and Settings\Derek Goh Jia Jun\Application Data\mIRC
2008-01-15 14:54 . 2008-01-15 14:54 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-15 14:10 . 2008-01-18 23:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-15 14:00 . 2008-01-15 14:00 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-15 14:00 . 2008-01-15 14:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-14 19:45 . 2008-01-14 19:45 <DIR> d-------- C:\Program Files\Alwil Software
2008-01-14 18:18 . 2005-10-07 06:04 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-14 18:18 . 2005-10-07 06:02 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-01-14 18:10 . 2008-01-14 18:10 <DIR> d--h----- C:\WINDOWS\PIF
2008-01-09 19:17 . 2008-01-09 19:17 <DIR> d-------- C:\Documents and Settings\Derek Goh Jia Jun\Application Data\DAEMON Tools
2008-01-09 19:13 . 2008-01-09 19:13 715,248 --a------ C:\WINDOWS\system32\drivers\sptd.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 15:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-18 15:41 --------- d-----w C:\Program Files\Microsoft AntiSpyware
2008-01-17 05:29 --------- d-----w C:\Program Files\TorqueShowToolPro-1-04
2008-01-14 08:45 --------- d-----w C:\Documents and Settings\Derek Goh Jia Jun\Application Data\U3
2008-01-11 17:02 --------- d-----w C:\Documents and Settings\Derek Goh Jia Jun\Application Data\Azureus
2008-01-09 11:33 --------- d-----w C:\Program Files\PPLive
2008-01-09 11:33 --------- d-----w C:\Program Files\MSN Messenger
2007-12-25 08:22 --------- d-----w C:\Program Files\Azureus
2007-12-22 08:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Outspark
2007-12-09 14:35 85,024 ----a-w C:\Documents and Settings\Derek Goh Jia Jun\Application Data\GDIPFONTCACHEV1.DAT
2007-12-06 14:30 --------- d-----w C:\Documents and Settings\Derek Goh Jia Jun\Application Data\Serious Magic
2007-12-06 14:28 --------- d-----w C:\Program Files\Serious Magic
2007-12-06 14:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Serious Magic
2007-11-22 15:28 --------- d-----w C:\Program Files\Common Files\DirectX
2007-11-14 07:26 450,560 ------w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 10:16 3,058,688 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 09:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 09:40 227,328 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:36 8,454,656 ------w C:\WINDOWS\system32\dllcache\shell32.dll
2006-01-10 07:04 144 ----a-w C:\Documents and Settings\Derek Goh Jia Jun\Application Data\wklnhst.dat
2006-04-11 10:35 56 --sh--r C:\WINDOWS\system32\4718ACC7A3.sys
2006-04-11 10:35 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 16:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-30 21:05 344064]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2005-08-29 19:30 102400]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-08-19 18:07 737369]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-10-13 16:04 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-10-07 06:02 98304]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-08-01 14:26 233534]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 21:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 21:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 21:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 21:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 21:00 455168]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-25 16:07 579072]
"Syncronization"="C:\WINDOWS\system32\msync.exe" [ ]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 01:06 487424]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 17:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-26 13:42 219136]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 00:24 1694208]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-01-10 16:41:34 113664]
EPSON Status Monitor 3 Environment Check(3).lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE [2002-06-10 12:01:00 131584]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
Windows Desktop Search.lnk - C:\Program Files\MSN Toolbar Suite\DS\
02.01.0000.2217\en-us\bin\WindowsSearch.exe [2005-05-25 10:16:54 229888]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-01-10 17:00:58 106560]
S3 se44bus;Sony Ericsson Device 068 driver (WDM);C:\WINDOWS\system32\DRIVERS\se44bus.sys [2006-11-30 14:58]
S3 se44mdfl;Sony Ericsson Device 068 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\se44mdfl.sys [2006-11-30 14:58]
S3 se44mdm;Sony Ericsson Device 068 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\se44mdm.sys [2006-11-30 14:58]
S3 se44mgmt;Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\se44mgmt.sys [2006-11-30 14:58]
S3 se44nd5;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS);C:\WINDOWS\system32\DRIVERS\se44nd5.sys [2006-11-30 14:58]
S3 se44obex;Sony Ericsson Device 068 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\se44obex.sys [2006-11-30 14:58]
S3 se44unic;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM);C:\WINDOWS\system32\DRIVERS\se44unic.sys [2006-11-30 14:58]
S3 wampapache;wampapache;"c:\wamp\apache2\bin\Apache.exe" [2006-07-27 14:55]
S3 wampmysqld;wampmysqld;c:\wamp\mysql\bin\mysqld-nt.exe [2006-10-22 04:30]
S3 XDva008;XDva008;C:\WINDOWS\system32\XDva008.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\C]
\Shell\AutoRun\command - C:\lg.cmd
\Shell\explore\Command - C:\lg.cmd
\Shell\open\Command - C:\lg.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{13c4ac58-840f-11db-9cc1-00163536269f}]
\Shell\AutoRun\command - E:\f.cmd
\Shell\explore\Command - E:\f.cmd
\Shell\open\Command - E:\f.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{29177842-a460-11db-9d36-00163536269f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Boot.exe e
\Shell\Open\command - E:\Boot.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{29177847-a460-11db-9d36-00163536269f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(&0)\command - Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{765514d5-e551-11da-9ad0-00163536269f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(&0)\command - Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{95c078c4-126b-11db-9b55-00163536269f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Boot.exe e
\Shell\Open\command - Boot.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{c373ec38-7470-11db-9c8a-00163536269f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Boot.exe e
\Shell\Open\command - Boot.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{c373ec3b-7470-11db-9c8a-00163536269f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(&0)\command - Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{f547f528-9fb4-11db-9d26-00163536269f}]
\Shell\AutoRun\command - E:\PStart.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{f7494320-b34e-11db-9d6f-00163536269f}]
\Shell\AutoRun\command - ie.exe
\Shell\explore\Command - ie.exe
\Shell\open\Command - ie.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{ff7a6f3b-00d3-11db-9b14-00163536269f}]
\Shell\AutoRun\command - ie.exe
\Shell\explore\Command - ie.exe
\Shell\open\Command - ie.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-21 14:25:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-22 00:37:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe???????????????|?????? ???B?????????????hLC? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-22 0:38:34
ComboFix-quarantined-files.txt 2008-01-21 16:38:08
.
2008-01-09 13:00:33 --- E O F ---