ComboFix 08-04-01.2 - Owner 2008-04-02 9:07:28.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.352 [GMT -8:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Installer\{0c55ad9b-a0f0-465a-85bd-2685246a7e5f}\VolumeSrv.dll
C:\WINDOWS\Installer\{0f6491d5-e82e-4a2b-ba96-32cdf7dc9011}\WinUnknown.dll
C:\WINDOWS\Installer\{4af4c047-e7ab-4db9-b416-cbf63d160d13}\DriveRam.dll
C:\WINDOWS\Installer\{5cb8c0f2-2438-4d3c-bb08-3b60b43e2868}\BootSrv.dll
C:\WINDOWS\Installer\{b9fd27bd-db41-4e28-8c7b-2b5264f60333}\ServiceKernel.dll
C:\WINDOWS\Installer\{c57c60ce-6189-425f-b02e-40c708a3d474}\VolumeDrv.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-02 to 2008-04-02 )))))))))))))))))))))))))))))))
.
2008-03-31 18:42 . 2008-03-31 18:42 <DIR> d-------- C:\Program Files\Support Tools
2008-03-31 18:14 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-03-31 18:14 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-03-31 15:24 . 2008-03-31 15:24 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-30 20:17 . 2008-03-30 20:17 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-30 20:16 . 2008-03-30 20:27 <DIR> d-------- C:\SDFix
2008-03-30 18:59 . 2008-03-30 18:59 <DIR> dr------- C:\Documents and Settings\All Users\Application Data\systemerrorfixer
2008-03-30 18:58 . 2005-09-20 09:31 135,168 --a------ C:\WINDOWS\system32\igfxres.dll
2008-03-30 18:57 . 2008-03-30 18:57 13,690 --a------ C:\WINDOWS\system32\wpa.bak
2008-03-30 18:52 . 2006-02-28 04:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-03-30 18:51 . 2006-02-28 04:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-03-30 18:50 . 2004-05-12 23:39 876,653 --a--c--- C:\WINDOWS\system32\dllcache\fp4awel.dll
2008-03-30 18:49 . 2008-03-30 18:49 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-03-30 18:49 . 2008-03-30 18:49 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-03-30 18:49 . 2008-03-30 18:49 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-03-30 18:49 . 2008-03-30 18:49 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-03-30 18:49 . 2008-03-30 18:49 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-03-25 22:14 . 2008-03-25 22:14 <DIR> d-------- C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP
2008-03-23 22:31 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-03-23 21:17 . 2008-03-23 21:17 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Sammsoft
2008-03-23 21:16 . 2008-03-23 21:17 <DIR> d-------- C:\Program Files\Advanced Registry Optimizer
2008-03-23 20:29 . 2008-03-23 20:29 <DIR> d-------- C:\Program Files\PC-Cleaner
2008-03-23 19:48 . 2008-03-23 20:18 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-23 19:48 . 2008-03-23 19:48 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-23 19:48 . 2008-03-23 19:48 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2008-03-23 19:48 . 2008-03-23 19:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-23 18:13 . 2008-03-23 18:13 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-23 18:13 . 2008-03-23 18:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-23 12:16 . 2006-03-16 16:38 28,672 --a------ C:\WINDOWS\system32\verclsid.exe
2008-03-23 12:13 . 2008-03-23 12:15 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-03-23 11:08 . 2008-03-25 22:14 <DIR> d-------- C:\Program Files\Symantec
2008-03-23 11:08 . 2008-03-25 22:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-23 10:58 . 2008-03-25 22:38 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-23 10:39 . 2004-10-07 13:39 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2008-03-23 10:39 . 2004-10-07 13:39 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-03-23 10:39 . 2004-10-07 13:39 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-03-23 10:39 . 2004-10-07 13:39 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2008-03-23 10:39 . 2001-03-08 18:30 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2008-03-23 10:30 . 2008-03-23 10:30 <DIR> d-------- C:\Program Files\Google
2008-03-23 10:30 . 2008-03-25 21:19 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-23 09:39 . 2008-03-23 09:39 <DIR> d-------- C:\Program Files\RegCure
2008-03-22 22:11 . 2008-03-30 19:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\zshgtgru
2008-03-22 21:16 . 2008-03-22 21:16 <DIR> d-------- C:\Program Files\Intel
2008-03-22 21:16 . 2007-12-20 01:43 248,448 --a------ C:\WINDOWS\system32\PROUnstl.exe
2008-03-22 21:16 . 2006-01-12 14:52 1,904 --a------ C:\WINDOWS\system32\SetupBD.din
2008-03-22 21:03 . 2008-03-22 21:03 444 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-03-22 21:00 . 2007-11-16 10:55 165,496 --a------ C:\WINDOWS\system32\drivers\e100b325.sys
2008-03-22 20:55 . 2008-03-22 20:55 <DIR> d---s---- C:\Documents and Settings\Owner\UserData
2008-03-21 20:30 . 2008-03-21 20:30 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-03-21 20:30 . 2008-03-21 20:30 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-03-21 20:29 . 2008-03-21 20:29 <DIR> d-------- C:\WINDOWS\Cache
2008-03-21 20:22 . 2005-02-22 15:53 221,184 --a------ C:\WINDOWS\system32\wlanapi.dll
2008-03-21 20:22 . 2005-03-16 19:09 143,360 --a------ C:\WINDOWS\system32\WlanApp.dll
2008-03-21 20:22 . 2004-10-22 13:42 49,152 --a------ C:\WINDOWS\system32\AQCKGen.dll
2008-03-21 20:02 . 2008-03-21 20:36 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-03-21 20:01 . 2008-03-21 20:36 <DIR> d-------- C:\Program Files\Common Files\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-22 03:51 --------- d-----w C:\Program Files\Driver-Soft
2008-03-22 03:08 --------- d-----w C:\Program Files\microsoft frontpage
2008-01-05 03:41 176,128 ----a-w C:\WINDOWS\system32\Ncs2Setp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-03-23 10:30 171448]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]
"AROReminder"="" []
"uubxfuzx"="C:\WINDOWS\system32\tajcvyjk.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemErrorFixer"="C:\Program Files\SystemErrorFixer\SysRep.exe" [ ]
"cwriter"="C:\Program Files\SystemErrorFixer\ucookw.exe" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36 114688]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shell executehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-04-02 16:44:17 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-03-23 17:40:00 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-02 09:08:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-02 9:09:13
ComboFix-quarantined-files.txt 2008-04-02 17:08:58
Pre-Run: 33,317,597,184 bytes free
Post-Run: 33,316,691,968 bytes free
.
2008-04-02 05:02:44 --- E O F ---
Adobe Flash Player ActiveX
Adobe Reader 6.0.1
Advanced Registry Optimizer
Driver Genius Professional Edition 2007
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Intel(R) Extreme Graphics 2 Driver
Intel(R) Network Connections 12.4.38.0
LiveUpdate (Symantec Corporation)
LiveUpdate (Symantec Corporation)
Microsoft Visual C++ 2005 Redistributable
RegCure 1.5.0.0
Spybot - Search & Destroy
SUPERAntiSpyware Free Edition
Windows Support Tools