ComboFix 08-05-12.1 - admin 2008-05-13 22:38:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1039 [GMT 1:00]
Running from: G:\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\win
C:\WINDOWS\system32\win\klog.dat
.
((((((((((((((((((((((((( Files Created from 2008-04-13 to 2008-05-13 )))))))))))))))))))))))))))))))
.
2008-05-07 21:25 . 2008-05-13 20:20 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-07 21:25 . 2008-05-07 21:25 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-28 12:08 . 2008-04-28 12:15 1,988 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-28 11:29 . 2008-04-28 11:29 <DIR> d-------- C:\Documents and Settings\admin\Application Data\Malwarebytes
2008-04-28 11:27 . 2008-04-28 11:27 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-28 11:27 . 2008-04-28 11:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-28 11:26 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-04-28 11:26 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-04-28 11:26 . 2008-04-24 08:10 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-28 11:26 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-28 11:26 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-04-28 11:26 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-04-28 11:26 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-28 11:26 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-28 11:16 . 2008-04-28 11:25 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-28 09:43 . 2008-04-28 09:44 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-04-26 12:24 . 2008-04-26 12:24 268 --ah----- C:\sqmdata02.sqm
2008-04-26 12:24 . 2008-04-26 12:24 244 --ah----- C:\sqmnoopt02.sqm
2008-04-16 15:41 . 2008-05-13 19:06 9,554,916 --a------ C:\WINDOWS\system32\mswinsck.ocx
2008-04-16 15:41 . 2008-05-13 19:06 28,160 --a------ C:\WINDOWS\system32\zlib.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-13 00:14 --------- d-----w C:\Documents and Settings\admin\Application Data\uTorrent
2008-05-12 23:31 --------- d-----w C:\Program Files\mIRC
2008-05-11 11:51 --------- d-----w C:\Documents and Settings\admin\Application Data\LimeWire
2008-05-06 17:53 --------- d-----w C:\Program Files\Trillian
2008-04-27 23:20 --------- d-----w C:\Program Files\uTorrent
2008-04-17 17:21 --------- d-----w C:\Documents and Settings\admin\Application Data\dvdcss
2008-04-11 18:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trymedia
2008-04-11 18:57 --------- d-----w C:\Program Files\BFG
2008-03-28 10:18 --------- d-----w C:\Documents and Settings\admin\Application Data\Skype
2008-03-19 19:44 --------- d-----w C:\Program Files\Disc2Phone
2008-03-19 16:45 --------- d-----w C:\Program Files\Java
2002-08-29 12:00 332,854 --sh--w C:\Documents and Settings\admin\Application Data\fhGCpT5SW.exe
2001-11-23 04:08 712,704 ----a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"odQJ4"="C:\Documents and Settings\admin\Application Data\fhGCpT5SW.exe" [2002-08-29 13:00 332854]
"0mjy9e"="C:\Documents and Settings\admin\Application Data\fhGCpT5SW.exe" [2002-08-29 13:00 332854]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 18:37 79224]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"Ey3vUw"="C:\Documents and Settings\admin\Application Data\fhGCpT5SW.exe" [2002-08-29 13:00 332854]
"73mroWuB"="C:\Documents and Settings\admin\Application Data\fhGCpT5SW.exe" [2002-08-29 13:00 332854]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:56 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shell executehooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= C:\Program Files\DVD Region+CSS Free\DVDShell.dll [2004-10-09 16:18 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"vidc.yv12"= yv12vfw.dll
"msacm.ac3filter"= ac3filter.acm
"msacm.divxa32"= divxa32.acm
"VIDC.FFDS"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 13:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 11:56 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2005-10-26 17:17 159744 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 18:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 18:35]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-05-08 13:46:20 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-13 22:41:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-13 22:42:34
ComboFix-quarantined-files.txt 2008-05-13 21:42:24
Pre-Run: 1,802,678,272 bytes free
Post-Run: 2,618,736,640 bytes free
131 --- E O F --- 2007-11-14 03:01:45