koolkid12349
New Member
ComboFix 08-04-26.5 - Chris Scanlon 2008-04-27 14:49:55.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.316 [GMT -4:00]
Running from: C:\Documents and Settings\Chris Scanlon\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\XP Antivirus
C:\Program Files\XP Antivirus\xpa .exe
C:\temp\tn3
C:\WINDOWS\mrofinu1188.exe.tmp
C:\WINDOWS\smdat32a.sys
C:\WINDOWS\smdat32m.sys
C:\WINDOWS\TEMP\600.exe
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_NWSAPAGENT
-------\Service_6to4
-------\Service_NwSapAgent
((((((((((((((((((((((((( Files Created from 2008-03-27 to 2008-04-27 )))))))))))))))))))))))))))))))
.
2008-04-27 14:58 . 2008-04-27 14:58 <DIR> d-------- C:\Temp\tn3
2008-04-27 02:34 . 2008-04-27 02:41 <DIR> d-------- C:\Program Files\Acoustica Mixcraft 4
2008-04-26 23:17 . 2008-01-11 17:39 145,408 --a------ C:\WINDOWS\system32\ZuneMTPZ.dll
2008-04-26 23:17 . 2008-01-11 17:39 70,656 --a------ C:\WINDOWS\system32\ZuneIpTransport.dll
2008-04-26 23:17 . 2008-01-11 17:39 62,464 --a------ C:\WINDOWS\system32\ZuneUsbTransport.dll
2008-04-26 23:17 . 2008-01-11 17:39 35,840 --a------ C:\WINDOWS\system32\ZuneUsbCOnnection.dll
2008-04-20 19:35 . 2008-04-20 19:35 <DIR> d-------- C:\Program Files\AIM Search
2008-04-17 22:22 . 2008-04-17 22:23 <DIR> d-------- C:\Program Files\Magic Video Converter
2008-04-17 22:22 . 2003-03-19 11:03 544,768 --a------ C:\WINDOWS\system32\msvcr71d.dll
2008-04-15 20:14 . 2008-04-15 20:14 <DIR> d-------- C:\Program Files\DAP
2008-04-15 20:14 . 2008-04-15 20:14 479,298 --a------ C:\WINDOWS\system32\wbocx.ocx
2008-04-15 20:14 . 2008-04-15 20:14 172,032 --a------ C:\WINDOWS\system32\AniGIF.ocx
2008-04-15 20:14 . 2008-04-15 20:14 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll
2008-04-14 18:50 . 2008-04-14 18:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SwiftKit
2008-04-14 18:38 . 2008-04-14 18:38 <DIR> d-------- C:\Program Files\Ascentive
2008-04-14 18:38 . 2008-04-14 18:38 <DIR> d-------- C:\Documents and Settings\Chris Scanlon\Application Data\InstallShield
2008-04-14 18:38 . 2007-08-10 12:56 303,104 --a------ C:\WINDOWS\system32\ciplListBar.ocx
2008-04-14 18:38 . 2008-03-12 14:13 208,896 --a------ C:\WINDOWS\system32\ConTest.dll
2008-04-14 18:38 . 2007-08-10 12:56 155,648 --a------ C:\WINDOWS\system32\ciplImageList.ocx
2008-04-02 13:58 . 2008-04-02 13:58 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-04-02 13:02 . 2008-04-13 14:22 <DIR> d-------- C:\Program Files\HyCam2
2008-04-02 01:51 . 2008-04-02 01:51 <DIR> d-------- C:\Documents and Settings\Chris Scanlon\Application Data\acccore
2008-04-02 01:47 . 2008-04-20 19:35 <DIR> d-------- C:\Program Files\AIM6
2008-04-02 01:47 . 2008-04-20 19:35 1,003 --ah----- C:\IPH.PH
2008-03-27 23:46 . 2008-03-27 23:46 <DIR> d-------- C:\Program Files\uTorrent
2008-03-27 23:46 . 2008-04-21 16:14 <DIR> d-------- C:\Documents and Settings\Chris Scanlon\Application Data\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 18:58 167,545 ----a-w C:\WINDOWS\system32\drivers\core.cache.dsk
2008-04-27 18:44 --------- d-----w C:\Program Files\BellSouth Internet Tools
2008-04-27 17:21 --------- d-----w C:\Documents and Settings\Chris Scanlon\Application Data\teamspeak2
2008-04-27 16:31 --------- d-----w C:\Program Files\AIMTunes
2008-04-27 06:41 --------- d-----w C:\Program Files\Acoustica Shared Effects
2008-04-27 03:22 --------- d-----w C:\Documents and Settings\Chris Scanlon\Application Data\LimeWire
2008-04-27 03:18 --------- d-----w C:\Program Files\Zune
2008-04-20 23:42 --------- d-----w C:\Program Files\LimeWire
2008-04-20 19:28 --------- d-----w C:\Program Files\NCH Swift Sound
2008-04-20 19:28 --------- d-----w C:\Documents and Settings\Chris Scanlon\Application Data\NCH Swift Sound
2008-04-16 00:14 --------- d-----w C:\Program Files\Google
2008-04-14 22:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-03 06:37 7,606 ----a-w C:\Documents and Settings\Chris Scanlon\Application Data\wklnhst.dat
2008-04-02 05:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-25 19:48 --------- d-----w C:\Program Files\Java
2008-03-16 19:08 --------- d-----w C:\Documents and Settings\Chris Scanlon\Application Data\Move Networks
2008-03-10 21:39 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-03-03 02:17 --------- d-----w C:\Program Files\Unity
2008-03-02 19:01 --------- d-----w C:\Program Files\GoldWave
2008-03-02 18:46 --------- d-----w C:\Program Files\Acoustica Spin It Again
2008-02-29 04:29 --------- d-----w C:\Program Files\iTunes
2008-02-29 04:29 --------- d-----w C:\Program Files\iPod
2008-02-21 01:57 60,968 ----a-w C:\Documents and Settings\Lisa Scanlon\GoToAssistDownloadHelper.exe
2008-01-28 02:22 14,336 ----a-w C:\Documents and Settings\Chris Scanlon\Application Data\nuupo .exe
2008-01-27 04:09 34,816 ----a-w C:\info.exe
2008-01-20 23:48 489,984 ----a-w C:\Documents and Settings\Chris Scanlon\installer.exe
2008-01-14 23:47 10 ----a-w C:\Program Files\.autoreg
2008-01-06 08:44 19,456 ----a-w C:\Documents and Settings\Chris Scanlon\Application Data\yuj.exe
2008-01-06 08:44 19,456 ----a-w C:\Documents and Settings\Chris Scanlon\Application Data\qbdsqxfkb.exe
2008-01-06 08:44 19,456 ----a-w C:\Documents and Settings\Chris Scanlon\Application Data\hsqt.exe
2007-12-13 21:31 75,232 ----a-w C:\Documents and Settings\Chris Scanlon\Application Data\GDIPFONTCACHEV1.DAT
2007-08-06 17:12 10,385,200 ----a-w C:\Documents and Settings\Chris Scanlon\HC41Installer.exe
2007-08-06 04:32 212,849 ----a-w C:\Program Files\hijackthis.zip
2007-05-20 18:01 0 ----a-w C:\Documents and Settings\Chris Scanlon\HC4Installer.exe
2007-05-20 01:17 628 ----a-w C:\Documents and Settings\Sean Scanlon\Application Data\wklnhst.dat
2006-12-06 03:14 1,178 ----a-w C:\Documents and Settings\Lisa Scanlon\Application Data\wklnhst.dat
2006-05-07 06:05 251 -c--a-w C:\Program Files\wt3d.ini
2006-05-16 02:08 56 -csh--r C:\WINDOWS\system32\DA7BA0A167.sys
2006-05-16 02:08 3,350 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 1,896,448 2006-01-10 21:56:58 C:\Program Files\BellSouth\Alert Manager\bak\BellSouthAlertManager.exe
----a-w 86,016 2006-03-27 22:55:43 C:\Program Files\BellSouth Internet Tools\bak\blsloader.exe
----a-w 50,736 2006-09-26 00:52:48 C:\Program Files\Common Files\AOL\1149387323\ee\bak\AOLSoftware.exe
----a-r 71,216 2006-10-23 12:50:37 C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe
----a-w 81,920 2005-06-10 16:44:02 C:\Program Files\Common Files\InstallShield\UpdateService\bak\issch.exe
----a-w 180,269 2006-08-06 06:07:05 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 1,159,168 2005-02-23 17:08:50 C:\Program Files\Creative\VoiceCenter\bak\AndreaVC.exe
----a-w 49,152 2004-09-13 20:49:00 C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe
----a-w 221,184 2003-09-04 02:12:44 C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe
----a-w 132,496 2007-07-12 08:00:36 C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe
----a-w 24,592 2007-09-26 20:46:04 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
----a-w 67,128 2007-02-27 05:26:37 C:\Program Files\Logitech\Desktop Messenger\8876480\Program\bak\LogitechDesktopMessenger.exe
----a-w 458,752 2005-06-08 19:24:32 C:\Program Files\Logitech\Video\bak\ISStart.exe
----a-w 217,088 2005-06-08 19:14:44 C:\Program Files\Logitech\Video\bak\LogiTray.exe
----a-w 8,192 2005-10-06 14:34:18 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mimboot.exe
----a-w 512,004 2007-09-10 02:13:03 C:\Program Files\NCH Swift Sound\RecordPad\bak\recordpad.exe
----a-w 98,304 2005-11-19 02:05:36 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 385,024 2008-02-01 04:13:08 C:\Program Files\QuickTime\QTTask.exe
----a-w 1,318,912 2007-06-21 18:06:28 C:\Program Files\SUPERAntiSpyware\bak\SUPERAntiSpyware.exe
----a-w 1,318,912 2007-06-21 19:06:28 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
----a-w 1,277,952 2005-08-31 19:14:52 C:\Program Files\Support.com\BellSouth\bak\hcenter.exe
----a-w 376,832 2007-09-11 09:31:36 C:\QooBox\Quarantine\C\Program Files\ISM\bak\ISMModule4.exe.vir
----a-w 24,592 2007-09-26 20:46:04 C:\QooBox\Quarantine\C\Program Files\ISM\ISMModule4.exe.vir
----a-w 189,009 2008-01-05 03:22:28 C:\QooBox\Quarantine\C\Program Files\ISM\bak\synupd.exe.vir
----a-w 200,763 2007-12-29 23:25:27 C:\QooBox\Quarantine\C\Program Files\ISM2\bak\cringupd.exe.vir
----a-w 335,872 2007-09-21 16:18:02 C:\QooBox\Quarantine\C\Program Files\ISM2\bak\ISMPack5.exe.vir
----a-w 24,592 2007-09-26 20:46:04 C:\QooBox\Quarantine\C\Program Files\ISM2\ISMPack5.exe.vir
----a-w 64,512 2005-08-05 19:56:34 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 77,824 2005-04-05 12:19:18 C:\WINDOWS\system32\bak\hkcmd.exe
----a-w 114,688 2005-04-05 12:23:14 C:\WINDOWS\system32\bak\igfxpers.exe
----a-w 94,208 2005-04-05 12:22:32 C:\WINDOWS\system32\bak\igfxtray.exe
----a-w 221,184 2005-07-19 21:32:18 C:\WINDOWS\system32\bak\LVCOMSX.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22}]
2008-03-25 16:49 111968 --a------ C:\Program Files\AIM Search\AOLSearch.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C835EC2A-1D13-43A9-4CAB-69D5BC5B0D5A}]
C:\Program Files\MSN\quzajeciv396.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [ ]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"Cxnqs"="C:\Documents and Settings\Chris Scanlon\Application Data\M?crosoft.NET\d?xplore.exe" [ ]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 15:06 1318912]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [ ]
"QdrModule9"="C:\Program Files\QdrModule\QdrModule9.exe" [ ]
"Dot1XCfg"="C:\Program Files\Dot1XCfg\Dot1XCfg.exe" [ ]
"Router"="C:\Program Files\Router\Router.exe" [ ]
"Uaol"="C:\PROGRA~1\RACLE~1\explorer.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-03-25 16:21 50528]
"Performance Center"="C:\Program Files\Ascentive\Performance Center\ApcMain.exe" [2008-03-13 17:35 3239936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"A8AAAAB2ACAEB2B7B"="9092929A94969A9.exe" [2007-12-14 08:40 120832 C:\WINDOWS\system32\9092929A94969A9.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2008-01-11 17:54 166304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 14:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 14:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll 2008-02-20 21:57 10792 C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Lisa Scanlon^Start Menu^Programs^Startup^Webshots.lnk]
path=C:\Documents and Settings\Lisa Scanlon\Start Menu\Programs\Startup\Webshots.lnk
backup=C:\WINDOWS\pss\Webshots.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\8fPfHq5]
C:\WINDOWS\ogrycvw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\A8AAAAB2ACAEB2B7B]
--a------ 2007-12-14 08:40 120832 C:\WINDOWS\system32\9092929A94969A9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BellSouthAlertManager.exe]
C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\blspcloader]
C:\Program Files\BellSouth Internet Tools\blsloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
C:\Program Files\DellSupport\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleUpdate]
C:\Program Files\Internet Explorer\5384.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1149387323\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-02-19 14:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\pmnno.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
C:\WINDOWS\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecordPadRun]
C:\Program Files\NCH Swift Sound\RecordPad\recordpad.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tgcmd]
C:\Program Files\Support.com\BellSouth\hcenter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Updater]
C:\WINDOWS\system32\updater\explorer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoiceCenter]
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
--a------ 2008-01-11 17:54 166304 c:\Program Files\Zune\ZuneLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Gh'þ9Óœû3rÅWC:]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Gh'þ9Óœû3rÅWC:\Program Files]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Gh'þ9Óœû3rÅWC:\Program Files\ISTsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Gh'þ9Óœû3rÅWC:\Program Files\ISTsvc\istsvc.exe]
C:\WINDOWS\ogrycvw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Lh'þ9Óœð3rÅWC:]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Lh'þ9Óœð3rÅWC:\Program Files]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Lh'þ9Óœð3rÅWC:\Program Files\ISTsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Lh'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe]
C:\WINDOWS\ogrycvw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWC:]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWC:\Program Files]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWC:\Program Files\ISTsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe]
C:\WINDOWS\ogrycvw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
R1 beepp;beepp;C:\WINDOWS\system32\drivers\beepp.sys [2008-01-11 16:42]
R2 CKVC;Security Service;C:\WINDOWS\system32\svcd\svchost.exe [2008-01-27 00:09]
R2 hdfile;hdfile;C:\WINDOWS\system32\hdfile.sys [2008-01-23 22:04]
R2 hdport;hdport;C:\WINDOWS\system32\hdport.sys [2008-01-23 22:04]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
R2 znntzs;znntzs;C:\WINDOWS\system32\svchost.exe [2004-08-10 07:00]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-01-11 17:39]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-01-11 17:54]
S3 DISK_DRIVE32;DISK_DRIVE32;C:\DOCUME~1\CHRISS~1\LOCALS~1\Temp\Rar$EX00.532\U1CE\UCE\disk_1024.sys []
S3 GoToAssist;GoToAssist;"C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe" Start=service []
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-01-11 17:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
qzbjwn REG_MULTI_SZ qzbjwn
znntzs REG_MULTI_SZ znntzs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-04-26 21:29:23 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-27 14:58:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\DOCUME~1\CHRISS~1\LOCALS~1\Temp\qtplugin.log 4158 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> c:\windows\system32\znntzs.dll
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\AOL\1149387323\ee\AOLDesktop.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-04-27 15:08:49 - machine was rebooted [Chris Scanlon]
ComboFix-quarantined-files.txt 2008-04-27 19:08:19
ComboFix2.txt 2008-02-03 23:52:22
ComboFix3.txt 2008-02-03 23:37:56
Pre-Run: 31,229,177,856 bytes free
Post-Run: 33,682,194,432 bytes free
375 --- E O F --- 2008-04-12 17:06:11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.316 [GMT -4:00]
Running from: C:\Documents and Settings\Chris Scanlon\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\XP Antivirus
C:\Program Files\XP Antivirus\xpa .exe
C:\temp\tn3
C:\WINDOWS\mrofinu1188.exe.tmp
C:\WINDOWS\smdat32a.sys
C:\WINDOWS\smdat32m.sys
C:\WINDOWS\TEMP\600.exe
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_NWSAPAGENT
-------\Service_6to4
-------\Service_NwSapAgent
((((((((((((((((((((((((( Files Created from 2008-03-27 to 2008-04-27 )))))))))))))))))))))))))))))))
.
2008-04-27 14:58 . 2008-04-27 14:58 <DIR> d-------- C:\Temp\tn3
2008-04-27 02:34 . 2008-04-27 02:41 <DIR> d-------- C:\Program Files\Acoustica Mixcraft 4
2008-04-26 23:17 . 2008-01-11 17:39 145,408 --a------ C:\WINDOWS\system32\ZuneMTPZ.dll
2008-04-26 23:17 . 2008-01-11 17:39 70,656 --a------ C:\WINDOWS\system32\ZuneIpTransport.dll
2008-04-26 23:17 . 2008-01-11 17:39 62,464 --a------ C:\WINDOWS\system32\ZuneUsbTransport.dll
2008-04-26 23:17 . 2008-01-11 17:39 35,840 --a------ C:\WINDOWS\system32\ZuneUsbCOnnection.dll
2008-04-20 19:35 . 2008-04-20 19:35 <DIR> d-------- C:\Program Files\AIM Search
2008-04-17 22:22 . 2008-04-17 22:23 <DIR> d-------- C:\Program Files\Magic Video Converter
2008-04-17 22:22 . 2003-03-19 11:03 544,768 --a------ C:\WINDOWS\system32\msvcr71d.dll
2008-04-15 20:14 . 2008-04-15 20:14 <DIR> d-------- C:\Program Files\DAP
2008-04-15 20:14 . 2008-04-15 20:14 479,298 --a------ C:\WINDOWS\system32\wbocx.ocx
2008-04-15 20:14 . 2008-04-15 20:14 172,032 --a------ C:\WINDOWS\system32\AniGIF.ocx
2008-04-15 20:14 . 2008-04-15 20:14 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll
2008-04-14 18:50 . 2008-04-14 18:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SwiftKit
2008-04-14 18:38 . 2008-04-14 18:38 <DIR> d-------- C:\Program Files\Ascentive
2008-04-14 18:38 . 2008-04-14 18:38 <DIR> d-------- C:\Documents and Settings\Chris Scanlon\Application Data\InstallShield
2008-04-14 18:38 . 2007-08-10 12:56 303,104 --a------ C:\WINDOWS\system32\ciplListBar.ocx
2008-04-14 18:38 . 2008-03-12 14:13 208,896 --a------ C:\WINDOWS\system32\ConTest.dll
2008-04-14 18:38 . 2007-08-10 12:56 155,648 --a------ C:\WINDOWS\system32\ciplImageList.ocx
2008-04-02 13:58 . 2008-04-02 13:58 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-04-02 13:02 . 2008-04-13 14:22 <DIR> d-------- C:\Program Files\HyCam2
2008-04-02 01:51 . 2008-04-02 01:51 <DIR> d-------- C:\Documents and Settings\Chris Scanlon\Application Data\acccore
2008-04-02 01:47 . 2008-04-20 19:35 <DIR> d-------- C:\Program Files\AIM6
2008-04-02 01:47 . 2008-04-20 19:35 1,003 --ah----- C:\IPH.PH
2008-03-27 23:46 . 2008-03-27 23:46 <DIR> d-------- C:\Program Files\uTorrent
2008-03-27 23:46 . 2008-04-21 16:14 <DIR> d-------- C:\Documents and Settings\Chris Scanlon\Application Data\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 18:58 167,545 ----a-w C:\WINDOWS\system32\drivers\core.cache.dsk
2008-04-27 18:44 --------- d-----w C:\Program Files\BellSouth Internet Tools
2008-04-27 17:21 --------- d-----w C:\Documents and Settings\Chris Scanlon\Application Data\teamspeak2
2008-04-27 16:31 --------- d-----w C:\Program Files\AIMTunes
2008-04-27 06:41 --------- d-----w C:\Program Files\Acoustica Shared Effects
2008-04-27 03:22 --------- d-----w C:\Documents and Settings\Chris Scanlon\Application Data\LimeWire
2008-04-27 03:18 --------- d-----w C:\Program Files\Zune
2008-04-20 23:42 --------- d-----w C:\Program Files\LimeWire
2008-04-20 19:28 --------- d-----w C:\Program Files\NCH Swift Sound
2008-04-20 19:28 --------- d-----w C:\Documents and Settings\Chris Scanlon\Application Data\NCH Swift Sound
2008-04-16 00:14 --------- d-----w C:\Program Files\Google
2008-04-14 22:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-03 06:37 7,606 ----a-w C:\Documents and Settings\Chris Scanlon\Application Data\wklnhst.dat
2008-04-02 05:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-25 19:48 --------- d-----w C:\Program Files\Java
2008-03-16 19:08 --------- d-----w C:\Documents and Settings\Chris Scanlon\Application Data\Move Networks
2008-03-10 21:39 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-03-03 02:17 --------- d-----w C:\Program Files\Unity
2008-03-02 19:01 --------- d-----w C:\Program Files\GoldWave
2008-03-02 18:46 --------- d-----w C:\Program Files\Acoustica Spin It Again
2008-02-29 04:29 --------- d-----w C:\Program Files\iTunes
2008-02-29 04:29 --------- d-----w C:\Program Files\iPod
2008-02-21 01:57 60,968 ----a-w C:\Documents and Settings\Lisa Scanlon\GoToAssistDownloadHelper.exe
2008-01-28 02:22 14,336 ----a-w C:\Documents and Settings\Chris Scanlon\Application Data\nuupo .exe
2008-01-27 04:09 34,816 ----a-w C:\info.exe
2008-01-20 23:48 489,984 ----a-w C:\Documents and Settings\Chris Scanlon\installer.exe
2008-01-14 23:47 10 ----a-w C:\Program Files\.autoreg
2008-01-06 08:44 19,456 ----a-w C:\Documents and Settings\Chris Scanlon\Application Data\yuj.exe
2008-01-06 08:44 19,456 ----a-w C:\Documents and Settings\Chris Scanlon\Application Data\qbdsqxfkb.exe
2008-01-06 08:44 19,456 ----a-w C:\Documents and Settings\Chris Scanlon\Application Data\hsqt.exe
2007-12-13 21:31 75,232 ----a-w C:\Documents and Settings\Chris Scanlon\Application Data\GDIPFONTCACHEV1.DAT
2007-08-06 17:12 10,385,200 ----a-w C:\Documents and Settings\Chris Scanlon\HC41Installer.exe
2007-08-06 04:32 212,849 ----a-w C:\Program Files\hijackthis.zip
2007-05-20 18:01 0 ----a-w C:\Documents and Settings\Chris Scanlon\HC4Installer.exe
2007-05-20 01:17 628 ----a-w C:\Documents and Settings\Sean Scanlon\Application Data\wklnhst.dat
2006-12-06 03:14 1,178 ----a-w C:\Documents and Settings\Lisa Scanlon\Application Data\wklnhst.dat
2006-05-07 06:05 251 -c--a-w C:\Program Files\wt3d.ini
2006-05-16 02:08 56 -csh--r C:\WINDOWS\system32\DA7BA0A167.sys
2006-05-16 02:08 3,350 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
Code:
<pre>
----a-w 14,336 2008-01-28 02:22:34 C:\Documents and Settings\Chris Scanlon\Application Data\nuupo .exe
----a-w 6,382,974 2008-01-13 06:38:07 C:\Documents and Settings\Chris Scanlon\Shared\MPEG AVI to DVD VCD SVCD Converter Pro Full Version Cucusoft\Cucusoft Apple TV Video Converter .exe
----a-w 50,528 2008-01-16 22:37:30 C:\Program Files\AOL 9.1\AOL .EXE
----a-w 24,592 2008-01-17 22:37:06 C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager .exe
----a-w 24,592 2008-01-26 01:26:00 C:\Program Files\BellSouth Internet Tools\blsloader .exe
----a-w 41,824 2008-01-17 02:51:35 C:\Program Files\Common Files\AOL\1149387323\ee\AOLSoftware .exe
----a-w 71,216 2008-01-17 22:37:09 C:\Program Files\Common Files\AOL\ACS\AOLDial .exe
----a-w 24,592 2008-01-16 01:31:37 C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
----a-w 36,040 2008-01-17 02:49:58 C:\Program Files\Common Files\Microsoft Shared\DW\dwtrig20 .exe
----a-w 24,592 2008-01-17 02:49:30 C:\Program Files\Common Files\Real\Update_OB\realsched .exe
----a-w 24,592 2008-01-16 01:31:30 C:\Program Files\Creative\VoiceCenter\AndreaVC .exe
----a-w 460,784 2008-01-26 02:34:41 C:\Program Files\DellSupport\DSAgnt .exe
----a-w 61,440 2008-01-19 01:48:15 C:\Program Files\Dot1XCfg\Dot1XCfg .exe
----a-w 171,448 2008-01-16 01:32:21 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
----a-w 24,592 2008-01-17 02:49:25 C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
----a-w 24,592 2008-01-16 01:31:30 C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
----a-w 176,128 2008-01-19 01:48:10 C:\Program Files\Internet Explorer\5384 .EXE
----a-w 267,048 2008-02-01 01:10:55 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 132,496 2008-01-18 19:17:00 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
----a-w 24,592 2008-01-14 23:37:47 C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
----a-w 24,592 2008-01-17 22:37:06 C:\Program Files\Logitech\Video\LogiTray .exe
----a-w 196,608 2008-01-30 03:30:53 C:\Program Files\Logitech\Video\ManifestEngine .exe
----a-w 1,694,208 2008-01-30 03:30:46 C:\Program Files\Messenger\msmsgs .exe
----a-w 24,592 2008-01-17 02:49:23 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mimboot .exe
----a-w 24,592 2008-01-17 02:49:32 C:\Program Files\NCH Swift Sound\RecordPad\recordpad .exe
----a-w 385,024 2008-02-01 01:10:55 C:\Program Files\QuickTime\qttask .exe
----a-w 1,318,912 2008-01-14 23:37:52 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
----a-w 24,592 2008-01-17 02:49:23 C:\Program Files\Support.com\BellSouth\hcenter .exe
----a-w 166,304 2008-01-21 18:26:22 C:\Program Files\Zune\ZuneLauncher .exe
----a-w 24,592 2008-01-16 01:31:24 C:\WINDOWS\ehome\ehtray .exe
----a-w 839,685 2008-01-17 22:37:23 C:\WINDOWS\Fonts\svchost .exe
----a-w 24,592 2008-01-16 01:31:27 C:\WINDOWS\system32\hkcmd .exe
----a-w 50,688 2008-02-03 23:10:06 C:\WINDOWS\system32\ieupdates .exe
----a-w 24,592 2008-01-16 01:31:26 C:\WINDOWS\system32\igfxpers .exe
----a-w 24,592 2008-01-16 01:31:24 C:\WINDOWS\system32\igfxtray .exe
----a-w 24,592 2008-01-17 02:49:22 C:\WINDOWS\system32\LVCOMSX .EXE
----a-w 1,478,612 2008-01-17 22:37:21 C:\WINDOWS\system32\updater\explorer .exe
</pre>
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 1,896,448 2006-01-10 21:56:58 C:\Program Files\BellSouth\Alert Manager\bak\BellSouthAlertManager.exe
----a-w 86,016 2006-03-27 22:55:43 C:\Program Files\BellSouth Internet Tools\bak\blsloader.exe
----a-w 50,736 2006-09-26 00:52:48 C:\Program Files\Common Files\AOL\1149387323\ee\bak\AOLSoftware.exe
----a-r 71,216 2006-10-23 12:50:37 C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe
----a-w 81,920 2005-06-10 16:44:02 C:\Program Files\Common Files\InstallShield\UpdateService\bak\issch.exe
----a-w 180,269 2006-08-06 06:07:05 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 1,159,168 2005-02-23 17:08:50 C:\Program Files\Creative\VoiceCenter\bak\AndreaVC.exe
----a-w 49,152 2004-09-13 20:49:00 C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe
----a-w 221,184 2003-09-04 02:12:44 C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe
----a-w 132,496 2007-07-12 08:00:36 C:\Program Files\Java\jre1.6.0_02\bin\bak\jusched.exe
----a-w 24,592 2007-09-26 20:46:04 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
----a-w 67,128 2007-02-27 05:26:37 C:\Program Files\Logitech\Desktop Messenger\8876480\Program\bak\LogitechDesktopMessenger.exe
----a-w 458,752 2005-06-08 19:24:32 C:\Program Files\Logitech\Video\bak\ISStart.exe
----a-w 217,088 2005-06-08 19:14:44 C:\Program Files\Logitech\Video\bak\LogiTray.exe
----a-w 8,192 2005-10-06 14:34:18 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mimboot.exe
----a-w 512,004 2007-09-10 02:13:03 C:\Program Files\NCH Swift Sound\RecordPad\bak\recordpad.exe
----a-w 98,304 2005-11-19 02:05:36 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 385,024 2008-02-01 04:13:08 C:\Program Files\QuickTime\QTTask.exe
----a-w 1,318,912 2007-06-21 18:06:28 C:\Program Files\SUPERAntiSpyware\bak\SUPERAntiSpyware.exe
----a-w 1,318,912 2007-06-21 19:06:28 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
----a-w 1,277,952 2005-08-31 19:14:52 C:\Program Files\Support.com\BellSouth\bak\hcenter.exe
----a-w 376,832 2007-09-11 09:31:36 C:\QooBox\Quarantine\C\Program Files\ISM\bak\ISMModule4.exe.vir
----a-w 24,592 2007-09-26 20:46:04 C:\QooBox\Quarantine\C\Program Files\ISM\ISMModule4.exe.vir
----a-w 189,009 2008-01-05 03:22:28 C:\QooBox\Quarantine\C\Program Files\ISM\bak\synupd.exe.vir
----a-w 200,763 2007-12-29 23:25:27 C:\QooBox\Quarantine\C\Program Files\ISM2\bak\cringupd.exe.vir
----a-w 335,872 2007-09-21 16:18:02 C:\QooBox\Quarantine\C\Program Files\ISM2\bak\ISMPack5.exe.vir
----a-w 24,592 2007-09-26 20:46:04 C:\QooBox\Quarantine\C\Program Files\ISM2\ISMPack5.exe.vir
----a-w 64,512 2005-08-05 19:56:34 C:\WINDOWS\ehome\bak\ehtray.exe
----a-w 77,824 2005-04-05 12:19:18 C:\WINDOWS\system32\bak\hkcmd.exe
----a-w 114,688 2005-04-05 12:23:14 C:\WINDOWS\system32\bak\igfxpers.exe
----a-w 94,208 2005-04-05 12:22:32 C:\WINDOWS\system32\bak\igfxtray.exe
----a-w 221,184 2005-07-19 21:32:18 C:\WINDOWS\system32\bak\LVCOMSX.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22}]
2008-03-25 16:49 111968 --a------ C:\Program Files\AIM Search\AOLSearch.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C835EC2A-1D13-43A9-4CAB-69D5BC5B0D5A}]
C:\Program Files\MSN\quzajeciv396.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [ ]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"Cxnqs"="C:\Documents and Settings\Chris Scanlon\Application Data\M?crosoft.NET\d?xplore.exe" [ ]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 15:06 1318912]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [ ]
"QdrModule9"="C:\Program Files\QdrModule\QdrModule9.exe" [ ]
"Dot1XCfg"="C:\Program Files\Dot1XCfg\Dot1XCfg.exe" [ ]
"Router"="C:\Program Files\Router\Router.exe" [ ]
"Uaol"="C:\PROGRA~1\RACLE~1\explorer.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-03-25 16:21 50528]
"Performance Center"="C:\Program Files\Ascentive\Performance Center\ApcMain.exe" [2008-03-13 17:35 3239936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"A8AAAAB2ACAEB2B7B"="9092929A94969A9.exe" [2007-12-14 08:40 120832 C:\WINDOWS\system32\9092929A94969A9.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2008-01-11 17:54 166304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 14:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 14:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll 2008-02-20 21:57 10792 C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Lisa Scanlon^Start Menu^Programs^Startup^Webshots.lnk]
path=C:\Documents and Settings\Lisa Scanlon\Start Menu\Programs\Startup\Webshots.lnk
backup=C:\WINDOWS\pss\Webshots.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\8fPfHq5]
C:\WINDOWS\ogrycvw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\A8AAAAB2ACAEB2B7B]
--a------ 2007-12-14 08:40 120832 C:\WINDOWS\system32\9092929A94969A9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BellSouthAlertManager.exe]
C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\blspcloader]
C:\Program Files\BellSouth Internet Tools\blsloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
C:\Program Files\DellSupport\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleUpdate]
C:\Program Files\Internet Explorer\5384.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1149387323\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-02-19 14:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\pmnno.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
C:\WINDOWS\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecordPadRun]
C:\Program Files\NCH Swift Sound\RecordPad\recordpad.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tgcmd]
C:\Program Files\Support.com\BellSouth\hcenter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Updater]
C:\WINDOWS\system32\updater\explorer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoiceCenter]
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
--a------ 2008-01-11 17:54 166304 c:\Program Files\Zune\ZuneLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Gh'þ9Óœû3rÅWC:]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Gh'þ9Óœû3rÅWC:\Program Files]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Gh'þ9Óœû3rÅWC:\Program Files\ISTsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Gh'þ9Óœû3rÅWC:\Program Files\ISTsvc\istsvc.exe]
C:\WINDOWS\ogrycvw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Lh'þ9Óœð3rÅWC:]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Lh'þ9Óœð3rÅWC:\Program Files]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Lh'þ9Óœð3rÅWC:\Program Files\ISTsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²# Lh'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe]
C:\WINDOWS\ogrycvw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWC:]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWC:\Program Files]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWC:\Program Files\ISTsvc]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWC:\Program Files\ISTsvc\istsvc.exe]
C:\WINDOWS\ogrycvw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
R1 beepp;beepp;C:\WINDOWS\system32\drivers\beepp.sys [2008-01-11 16:42]
R2 CKVC;Security Service;C:\WINDOWS\system32\svcd\svchost.exe [2008-01-27 00:09]
R2 hdfile;hdfile;C:\WINDOWS\system32\hdfile.sys [2008-01-23 22:04]
R2 hdport;hdport;C:\WINDOWS\system32\hdport.sys [2008-01-23 22:04]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
R2 znntzs;znntzs;C:\WINDOWS\system32\svchost.exe [2004-08-10 07:00]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-01-11 17:39]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-01-11 17:54]
S3 DISK_DRIVE32;DISK_DRIVE32;C:\DOCUME~1\CHRISS~1\LOCALS~1\Temp\Rar$EX00.532\U1CE\UCE\disk_1024.sys []
S3 GoToAssist;GoToAssist;"C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe" Start=service []
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-01-11 17:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
qzbjwn REG_MULTI_SZ qzbjwn
znntzs REG_MULTI_SZ znntzs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-04-26 21:29:23 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-27 14:58:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\DOCUME~1\CHRISS~1\LOCALS~1\Temp\qtplugin.log 4158 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> c:\windows\system32\znntzs.dll
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\AOL\1149387323\ee\AOLDesktop.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-04-27 15:08:49 - machine was rebooted [Chris Scanlon]
ComboFix-quarantined-files.txt 2008-04-27 19:08:19
ComboFix2.txt 2008-02-03 23:52:22
ComboFix3.txt 2008-02-03 23:37:56
Pre-Run: 31,229,177,856 bytes free
Post-Run: 33,682,194,432 bytes free
375 --- E O F --- 2008-04-12 17:06:11