ComboFix 08-04-16.2 - TJ 2008-04-24 18:07:43.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.74 [GMT -5:00]
Running from: C:\Documents and Settings\TJ\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\TJ\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\Program Files\PC-Antispyware\PC-Antispyware.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\TEMP
C:\Documents and Settings\All Users\Application Data\TEMP\DFC5A2B2.TMP
.
((((((((((((((((((((((((( Files Created from 2008-03-24 to 2008-04-24 )))))))))))))))))))))))))))))))
.
2008-04-21 11:41 . 2008-04-21 11:41 708 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-21 11:40 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-04-21 11:40 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-04-21 11:40 . 2008-04-14 19:28 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-21 11:40 . 2008-04-21 10:01 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-21 11:40 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-04-21 11:40 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-21 11:40 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-17 14:24 . 2008-04-17 14:25 <DIR> d-------- C:\Documents and Settings\TEMP
2008-04-16 22:04 . 2008-04-16 22:04 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-14 17:35 . 2008-04-14 17:35 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-14 17:35 . 2008-04-14 17:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-14 17:31 . 2008-04-14 17:31 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-14 17:18 . 2008-04-20 02:25 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-14 17:03 . 2008-04-14 17:13 <DIR> d-------- C:\Program Files\XoftSpySE
2008-04-10 15:42 . 2008-04-10 16:11 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-04-10 14:51 . 2008-04-10 14:51 <DIR> d-------- C:\Program Files\Windows Defender
2008-04-09 03:06 . 2008-04-09 03:06 206 --a------ C:\WINDOWS\system32\MRT.INI
2008-04-07 13:58 . 2008-04-14 18:31 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-03-31 16:25 . 2008-03-31 16:25 831,488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 16:25 . 2008-03-31 16:25 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 16:25 . 2008-03-31 16:25 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 16:25 . 2008-03-31 16:25 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 16:25 . 2008-03-31 16:25 682,496 --a------ C:\WINDOWS\system32\DivX.dll
2008-03-31 16:25 . 2008-03-31 16:25 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-24 14:45 . 2008-03-24 14:45 630,784 --a------ C:\WINDOWS\system32\divxdec.ax
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-20 19:21 --------- d-----w C:\Program Files\DivX
2008-04-20 07:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-15 02:07 --------- d-----w C:\Documents and Settings\TJ\Application Data\uTorrent
2008-04-14 20:38 --------- d-----w C:\Program Files\LimeWire
2008-03-25 02:23 --------- d-----w C:\Documents and Settings\TJ\Application Data\LimeWire
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:32 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-01-28 07:31 188,416 ----a-w C:\WINDOWS\java\PARTYPokerDir\PARTYPokerDA.dll
.
((((((((((((((((((((((((((((( snapshot@2008-04-16_20.05.03.17 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-14 23:33:57 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-20 07:25:38 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-04-15 15:43:37 377,408 ----a-w C:\WINDOWS\SoftwareDistribution\Download\Install\mpas-d.exe
- 2008-04-14 23:39:00 60,308 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-20 07:30:17 60,308 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-04-14 23:39:00 396,934 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-20 07:30:17 396,934 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 04:42 144784]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\utorrent\\utorrent.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19037:TCP"= 19037:TCP:BitComet 19037 TCP
"19037:UDP"= 19037:UDP:BitComet 19037 UDP
.
Contents of the 'Scheduled Tasks' folder
"2008-04-24 07:07:12 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-24 18:10:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-24 18:12:08
ComboFix-quarantined-files.txt 2008-04-24 23:12:04
ComboFix2.txt 2008-04-19 19:09:45
ComboFix3.txt 2008-04-17 01:05:30
Pre-Run: 2,258,907,136 bytes free
Post-Run: 2,876,698,624 bytes free
.
2008-04-23 00:16:18 --- E O F ---
Logfile of HijackThis v1.99.1
Scan saved at 6:13:57 PM, on 4/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/def ... earch.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Backgammon -
http://download.games.yahoo.com/games/c ... /at1_x.cabO16 - DPF: Yahoo! Bingo -
http://download.games.yahoo.com/games/c ... /xt0_x.cabO16 - DPF: Yahoo! Canasta -
http://download.games.yahoo.com/games/c ... /yt1_x.cabO16 - DPF: Yahoo! Checkers -
http://download.games.yahoo.com/games/c ... /kt4_x.cabO16 - DPF: Yahoo! MahJong Solitaire -
http://download2.games.yahoo.com/games/ ... jst4_x.cabO16 - DPF: Yahoo! Poker -
http://download.games.yahoo.com/games/c ... /pt3_x.cabO16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/c ... poti_x.cabO16 - DPF: Yahoo! Spades -
http://download.games.yahoo.com/games/c ... /st2_x.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/Shar ... vSniff.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {343CE214-9998-4B21-A151-FFE970167297} -
http://xscanner.spyshredderscanner.com/ ... ebinst.cabO16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resour ... ase370.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/Shar ... /cabsa.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
http://download.games.yahoo.com/games/w ... der_v6.cabO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe