ComboFix 07-11-01.1 - The Sexy Amps' 2007-11-03 12:25:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.79 [GMT 0:00]
Running from: C:\Documents and Settings\The Sexy Amps'\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\The Sexy Amps'\Application Data\install_en[1].exe
C:\Program Files\ivideocodec
C:\Program Files\ivideocodec\ot.ico
C:\Program Files\ivideocodec\ts.ico
C:\UGA6P
C:\WINDOWS\system32\dbnmpnt.dll
C:\WINDOWS\system32\drivers\pvhwydib.dat
C:\WINDOWS\system32\drivers\vnafudcc.dat
C:\WINDOWS\system32\mbsrm32.exe
C:\WINDOWS\system32\u2g.f
C:\WINDOWS\system32\UBSauthenticateAXC.ocx
C:\WINDOWS\system32\winiconmon.ico
C:\WINDOWS\system32\wsnpoem
C:\WINDOWS\system32\wsnpoem\audio.dll.cla
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_MGLPEWGN
-------\mglpewgn
((((((((((((((((((((((((( Files Created from 2007-10-03 to 2007-11-03 )))))))))))))))))))))))))))))))
.
2007-11-03 12:23 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-01 20:24 <DIR> d-------- C:\WINDOWS\ERUNT
2007-10-30 22:17 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-30 17:19 32 --ahs---- C:\WINDOWS\system32\{D825281E-EB8E-4036-A2FC-3ACA1BD68CBD}.dat
2007-10-30 17:19 32 --ahs---- C:\WINDOWS\{A91AD121-2F9B-4CED-97B4-236F62AEC177}.dat
2007-10-30 17:19 14 --a------ C:\WINDOWS\system32\SR2.dat
2007-10-30 17:18 83,672 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-30 17:18 73,224 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-30 17:18 34,578 --a------ C:\WINDOWS\system32\drivers\NPDRIVER.SYS
2007-10-30 17:17 <DIR> d-------- C:\Program Files\Norton AntiVirus
2007-10-30 16:53 156,301 --a------ C:\WINDOWS\system32\drivers\GoBack2K.sys
2007-10-30 16:53 15,024 --a------ C:\WINDOWS\system32\drivers\GBFSHook.sys
2007-10-30 16:53 3,945 --a------ C:\WINDOWS\system32\drivers\GBDevice.sys
2007-10-29 15:23 <DIR> d-------- C:\Program Files\AdwareRemover2007
2007-10-28 07:39 <DIR> d-------- C:\Documents and Settings\The Sexy Amps'\Application Data\PCSecureSystem
2007-10-28 07:39 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-03 12:31 62,348 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-03 12:31 5,345,312 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-10-30 17:20 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-10-30 17:18 --------- d-----w C:\Program Files\Symantec
2007-10-30 17:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-30 17:12 --------- d-----w C:\Program Files\Norton SystemWorks
2007-10-29 22:25 --------- d-----w C:\Program Files\Leeds United FC - DNA
2007-10-29 16:55 --------- d-----w C:\Program Files\Common Files\DriveCleaner Freeware
2007-10-13 05:59 --------- d-----w C:\Documents and Settings\The Sexy Amps'\Application Data\MSN6
2007-09-20 10:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-09-14 21:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Driving Test Success
2007-09-14 20:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hazard Perception Training
2007-09-14 20:39 --------- d-----w C:\Program Files\Hazard Perception 2003-2004
2007-09-09 07:57 --------- d-----w C:\Program Files\Microsoft Works
2007-09-06 15:14 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2007-09-06 15:14 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2007-08-30 13:39 2,560 ----a-w C:\sysfpob.exe
2007-06-17 07:24 30,240 ----a-w C:\Documents and Settings\The Sexy Amps'\Application Data\GDIPFONTCACHEV1.DAT
2005-11-03 23:29 72,832 ----a-r C:\WINDOWS\inf\CamAvb.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1da7dbe8-c51b-4ae4-bc6e-21863349b0b4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{77701e16-9bfe-4b63-a5b4-7bd156758a37}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-02-21 14:11]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2005-09-25 18:11]
"NeroCheck"="C:\WINDOWS\system32\\NeroCheck.exe" [2005-09-25 18:11]
"EPSON Stylus DX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.exe" [2005-02-08 04:00]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 03:03]
"Ulead Photo Express Calendar Checker"="C:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe" [2004-01-12 20:40]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 18:05]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-28 13:12]
"C:\DOCUME~1\THESEX~1\LOCALS~1\Temp\update.exe"="C:\Program Files\MSN\MSNCoreFiles\update.exe" [2002-10-16 13:31]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 15:14]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2002-08-19 22:22]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-08-19 22:23]
"Advanced Tools Check"="C:\PROGRA~1\NORTON~2\AdvTools\ADVCHK.EXE" [2002-08-26 22:35]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" []
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" []
"Leeds United FC - Desktop News Alerts"="C:\Program Files\Leeds United FC - DNA\launch.exe" [2006-10-10 09:15]
"AdwareRemover2007"="C:\Program Files\AdwareRemover2007\AdwareRemover2007.exe" [2007-10-29 15:23]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"NTSF MICROSOFT SYSTEM"=winsis32.exe
"PcSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
GoBack.lnk - C:\Program Files\Roxio\GoBack\GBTray.exe [2007-10-30 16:53:20]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
S3 CamAv;SAMSUNG Video Capture;C:\WINDOWS\system32\Drivers\CamAv.sys
S3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYS
.
Contents of the 'Scheduled Tasks' folder
"2007-10-30 18:41:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-10-30 17:31:31 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~2\NAVW32.exe
"2007-11-03 12:42:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-03 12:40:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs = ??????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C:\\DOCUME~1\\THESEX~1\\LOCALS~1\\Temp\\update.exe"="C:\\Program Files\\MSN\\MSNCoreFiles\\update.exe"
.
Completion time: 2007-11-03 12:45:39 - machine was rebooted
.
--- E O F ---