ComboFix Log
ComboFix 08-05-21.3 - James 2008-05-25 8:55:36.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.242 [GMT 10:00]
Running from: G:\virus stuff\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\James\Application Data\ezpinst.log
C:\Documents and Settings\James\Application Data\inst.exe
C:\WINDOWS\clofghls.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-24 to 2008-05-24 )))))))))))))))))))))))))))))))
.
2008-05-22 20:04 . 2008-05-22 20:05 <DIR> d-------- C:\Program Files\DebugMode
2008-05-22 19:21 . 2008-05-22 19:21 <DIR> d-------- C:\Program Files\Free Audio Pack
2008-05-22 19:21 . 2003-08-07 15:01 237,568 --a------ C:\WINDOWS\system32\lame_enc.dll
2008-05-11 21:09 . 2008-05-11 21:09 <DIR> d-------- C:\Program Files\Windows Defender
2008-05-11 18:17 . 2008-05-11 21:07 234 --a------ C:\Documents and Settings\James\dl.exe
2008-04-30 19:52 . 2008-05-11 19:30 <DIR> d-------- C:\WINDOWS\speech
2008-04-30 19:52 . 2008-04-30 19:52 <DIR> d-------- C:\DVDVideoSoft
2008-04-30 19:48 . 2008-05-11 19:36 <DIR> d-------- C:\Program Files\Convert
2008-04-30 19:48 . 2008-04-30 19:48 <DIR> d-------- C:\Program Files\Blaiz Enterprises
2008-04-30 19:45 . 2008-04-30 19:51 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-04-30 17:22 . 2008-04-11 11:51 <DIR> d-------- C:\Documents and Settings\James\.gimp-2.4
2008-04-30 17:21 . 2008-04-30 19:48 <DIR> d-------- C:\Program Files\GIMP-2.0
2008-04-27 17:19 . 2008-05-11 19:35 <DIR> d-------- C:\Program Files\ReadPlease 2003
2008-04-27 14:46 . 2005-02-24 14:10 2,084,864 --a------ C:\WINDOWS\system32\AudDesign.dll
2008-04-27 14:46 . 2005-03-11 19:37 1,986,560 --a------ C:\WINDOWS\system32\AudFile.dll
2008-04-27 14:46 . 2005-02-24 14:11 1,212,416 --a------ C:\WINDOWS\system32\AudioInfos.dll
2008-04-27 14:46 . 2005-02-24 14:11 479,232 --a------ C:\WINDOWS\system32\AudioVisu.dll
2008-04-27 14:46 . 2005-02-24 17:21 458,752 --a------ C:\WINDOWS\system32\AudPlayer.dll
2008-04-27 14:46 . 2005-03-10 18:00 454,656 --a------ C:\WINDOWS\system32\AudioRecord.dll
2008-04-27 14:46 . 2005-02-24 14:10 417,792 --a------ C:\WINDOWS\system32\AudDisplay.dll
2008-04-27 14:46 . 2005-02-24 13:51 348,160 --a------ C:\WINDOWS\system32\WMAFile.dll
2008-04-27 14:46 . 2005-01-10 12:54 116,296 --a------ C:\WINDOWS\system32\NCTWMAProfiles.prx
2008-04-27 11:26 . 2008-04-27 18:01 263,168 --a------ C:\WINDOWS\system32\TweakUI.exe
2008-04-27 11:26 . 2002-06-21 15:09 160,217 --a------ C:\WINDOWS\system32\PowerToysLicense.rtf
2008-04-26 16:12 . 2008-04-30 19:51 <DIR> d-------- C:\Documents and Settings\James\Application Data\Nvu
2008-04-25 13:18 . 2008-04-30 19:48 <DIR> d-------- C:\Program Files\Hide Windows
2008-04-25 13:16 . 2008-05-11 19:36 <DIR> d-------- C:\Program Files\Nvu
2008-04-25 13:10 . 2008-05-11 19:36 <DIR> d-------- C:\Program Files\7-Zip
2008-04-25 13:07 . 2008-05-25 07:25 <DIR> d-------- C:\Program Files\Taskbar Shuffle
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-24 09:03 --------- d-----w C:\Documents and Settings\James\Application Data\Any Video Converter
2008-05-11 09:35 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-11 09:35 --------- d-----w C:\Program Files\VIDEOzilla
2008-05-11 09:35 --------- d-----w C:\Program Files\VectorWorks 12.5.1
2008-05-11 09:35 --------- d-----w C:\Program Files\Turret Wars
2008-05-11 09:35 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-11 05:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-10 09:54 196,608 ----a-w C:\WINDOWS\system32\TubeFinder.exe
2008-04-30 10:36 --------- d-----w C:\Program Files\Macromedia
2008-04-30 10:35 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-04-27 08:00 94,208 -c--a-w C:\WINDOWS\system32\igfxext.exe
2008-04-27 07:59 9,728 -c--a-w C:\WINDOWS\system32\cisvc.exe
2008-04-27 07:58 772,096 -c--a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\helpctr.exe
2008-04-27 07:58 747,520 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\helpsvc.exe
2008-04-27 07:58 741,376 -c--a-w C:\WINDOWS\iun6002.exe
2008-04-27 07:58 72,704 ----a-w C:\WINDOWS\notepad.exe
2008-04-27 07:58 38,912 -c--a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\notiflag.exe
2008-04-27 07:58 310,272 ----a-w C:\WINDOWS\IsUninst.exe
2008-04-27 07:58 22,528 -c--a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\hscupd.exe
2008-04-27 07:58 162,304 -c--a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\msconfig.exe
2008-04-27 07:58 154,624 -c--a-w C:\WINDOWS\PCHEALTH\UploadLB\Binaries\uploadm.exe
2008-04-27 07:58 150,016 -c--a-w C:\WINDOWS\regedit.exe
2008-04-27 07:58 103,424 -c--a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\HelpHost.exe
2008-04-27 07:57 9,728 ----a-w C:\WINDOWS\delttsul.exe
2008-04-27 07:57 380,928 -c--a-w C:\WINDOWS\Help\Tours\mmTour\tour.exe
2008-04-27 07:57 14,336 ----a-w C:\WINDOWS\hh.exe
2008-04-14 00:47 --------- d-----w C:\Program Files\Infogrames
2008-04-13 01:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-13 00:57 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-04-13 00:47 --------- d-----w C:\Documents and Settings\James\Application Data\AVS4YOU
2008-04-13 00:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-04-13 00:32 --------- d-----w C:\Program Files\Ashampoo
2008-04-13 00:32 --------- d-----w C:\Documents and Settings\James\Application Data\Ashampoo
2008-04-11 05:26 --------- d-----w C:\Program Files\Google
2008-03-30 08:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-30 03:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Pinnacle VideoSpin
2008-03-30 03:03 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-30 02:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\VideoSpin
2008-03-30 02:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Pinnacle
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-25 09:28 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-02-25 09:28 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2007-10-20 23:40 47,360 -c--a-w C:\Documents and Settings\James\Application Data\pcouffin.sys
2007-05-19 07:26 16 -csha-w C:\WINDOWS\emjlhgdm.dat
.
------- Sigcheck -------
2008-04-27 17:55 2060544 86f88c7e4f9baeaeee6f6ce0c0ca962d C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2008-04-27 17:56 2063104 21ed0d422ad9c6e476afec47dd9e8b87 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-04-27 17:56 1873408 3d8cb7ea3ee8c1f33f9d858256f75246 C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2008-04-27 17:56 2018816 f610be5d7da1ce9dfda6b9a708c700ab C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2008-04-27 17:57 2018816 e49eeb20d18d7ed4402eaac167b82c58 C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2008-04-27 17:57 2061312 aa4dea75ac68120641664c6205bfd561 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2008-04-27 17:59 2060544 f8408d01888b6b670983a2a0059a4ae2 C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2008-04-27 18:01 2019328 07364e9c91bd375af1486d8b53baff54 C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-27 18:00 2061312 aa4dea75ac68120641664c6205bfd561 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2008-04-27 17:47 1961984]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2008-05-25 07:28 167936]
"Taskbar Shuffle"="C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe" [2008-05-25 07:29 822272]
"Hide Windows 2.0"="C:\Program Files\Hide Windows\Hide Windows 2.0.exe" [2008-05-25 07:28 221184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-03-11 10:24 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 10:11 114688]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-03-11 10:45 774144]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2008-04-27 18:01 155648]
"PE2CKFNT SE"="C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [2008-04-27 17:53 30720]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-25 19:28 185896]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 17:30 45632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-25 07:29 286720]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-04-27 17:50 33280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-27 18:01 57856 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 37888]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 733184]
Favourites -- 4 and 5 Star Rated.lnk - C:\Documents and Settings\James\My Documents\My Music\My Playlists\My Favourites.wpl [2007-11-01 18:55:18 118907]
Photo Express Calendar Checker SE.lnk - C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe [2007-11-08 16:40:11 58880]
Windows Media Player.lnk - C:\Program Files\Windows Media Player\wmplayer.exe [2005-01-28 13:44:28 67584]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\iTunes\\iTunes.exe"=
R2 ScFBPNT2;CanoScan FBP2 Port Driver;C:\WINDOWS\system32\drivers\ScFBPNT2.SYS [1999-05-21 01:00]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 08:05]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c086a790-ecdd-11dc-9eb9-000cf17faae0}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d6571ac8-6cf4-11dc-90a9-000cf17faae0}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-05-24 21:45:44 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-25 08:59:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-05-25 9:02:33
ComboFix-quarantined-files.txt 2008-05-24 23:01:31
Pre-Run: 6,692,642,816 bytes free
Post-Run: 6,734,999,552 bytes free
166 --- E O F --- 2008-04-27 06:29:54