there it is...
ComboFix 07-11-01.1 - LuBo 2007-11-04 18:50:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1251.1.1033.18.485 [GMT -5:00]
Running from: C:\Documents and Settings\LuBo\My Documents\Downloads\Programs\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-10-04 to 2007-11-04 )))))))))))))))))))))))))))))))
.
2007-11-04 18:49 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-04 12:26 <DIR> d-------- C:\Program Files\XoftSpySE
2007-11-03 17:57 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-02 23:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2007-11-02 19:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2007-11-02 19:33 <DIR> d-------- C:\WINDOWS\DA15D5355E1D4076B5208571346D6238.TMP
2007-11-02 18:52 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-10-28 00:29 <DIR> dr-h----- C:\Documents and Settings\LuBo\Application Data\SecuROM
2007-10-28 00:29 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-10-27 18:20 <DIR> d-------- C:\Documents and Settings\LuBo\Application Data\IDM
2007-10-27 17:52 <DIR> d-------- C:\Program Files\Rockstar Games
2007-10-26 16:04 <DIR> d-------- C:\Program Files\KONAMI
2007-10-25 19:19 <DIR> d-------- C:\WINDOWS\system32\Trick Daddy Screensaver dir
2007-10-25 19:15 202,240 --a------ C:\WINDOWS\system32\Trick Daddy Screensaver.scr
2007-10-25 08:27 30,728 --a------ C:\WINDOWS\system32\drivers\epfwtdir.sys
2007-10-25 08:25 33,800 --a------ C:\WINDOWS\system32\drivers\eamon.sys
2007-10-25 08:25 27,144 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
2007-10-24 15:56 <DIR> d-------- C:\Program Files\Ubisoft
2007-10-24 15:45 <DIR> d-------- C:\Program Files\Mplayer
2007-10-24 15:30 <DIR> d-------- C:\Program Files\EA SPORTS
2007-10-22 01:14 1,156 --a------ C:\WINDOWS\mozver.dat
2007-10-21 12:08 <DIR> d-------- C:\Program Files\Internet Download Manager
2007-10-21 11:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\sentinel
2007-10-21 11:28 <DIR> d-------- C:\Program Files\Easiestutils
2007-10-14 12:27 <DIR> d-------- C:\Program Files\Google
2007-10-09 19:07 <DIR> d-------- C:\Documents and Settings\LuBo\Application Data\Ahead
2007-10-09 19:04 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-10-09 18:56 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-10-09 12:20 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-04 23:48 --------- d-----w C:\Program Files\Orbitdownloader
2007-11-04 23:48 --------- d-----w C:\Documents and Settings\LuBo\Application Data\Orbit
2007-11-04 23:41 --------- d-----w C:\Program Files\Steam
2007-11-04 23:38 --------- d-----w C:\Documents and Settings\LuBo\Application Data\Skype
2007-11-04 23:33 --------- d-----w C:\Documents and Settings\LuBo\Application Data\DMCache
2007-11-04 05:38 --------- d-----w C:\Program Files\SwiftSwitch
2007-10-27 22:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-27 16:30 --------- d-----w C:\Documents and Settings\LuBo\Application Data\LimeWire
2007-10-26 21:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\SwiftSwitch
2007-10-24 21:03 11,973 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-24 19:41 --------- d-----w C:\Program Files\Dictionary
2007-10-23 17:22 --------- d-----w C:\Program Files\Java
2007-10-10 00:04 --------- d-----w C:\Program Files\Nero
2007-10-10 00:00 --------- d-----w C:\Program Files\Common Files\Simple Star Shared
2007-10-10 00:00 --------- d-----w C:\Documents and Settings\LuBo\Application Data\Nero
2007-10-10 00:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2007-10-03 18:48 --------- d-----w C:\Program Files\Arjaloc
2007-09-30 16:47 --------- d-----w C:\Program Files\Zoom Player
2007-09-30 16:47 --------- d-----w C:\Program Files\SHOUTcast Source
2007-09-30 16:47 --------- d-----w C:\Program Files\RealMedia
2007-09-30 16:47 --------- d-----w C:\Program Files\OpenSource Flash Video Splitter
2007-09-30 16:47 --------- d-----w C:\Program Files\Haali
2007-09-30 16:47 --------- d-----w C:\Program Files\DScaler5
2007-09-30 16:47 --------- d-----w C:\Program Files\DS-MP3 Source
2007-09-30 16:47 --------- d-----w C:\Program Files\DirectVobSub
2007-09-30 16:47 --------- d-----w C:\Program Files\CD Audio Reader Filter
2007-09-30 16:45 --------- d-----w C:\Documents and Settings\LuBo\Application Data\Media Player Classic
2007-09-29 22:50 --------- d-----w C:\Documents and Settings\LuBo\Application Data\ATI
2007-09-29 22:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\ATI
2007-09-29 22:48 --------- d-----w C:\Program Files\ATI Technologies
2007-09-26 21:20 --------- d-----w C:\Program Files\MSN Messenger
2007-09-26 21:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-09-26 19:12 --------- d-----w C:\Program Files\MTA San Andreas
2007-09-25 00:08 --------- d-----w C:\Program Files\Creative Zone
2007-09-23 03:33 --------- d-----w C:\Program Files\EnsignGames
2007-09-23 03:03 --------- d-----w C:\Documents and Settings\LuBo\Application Data\Oxin's Style!
2007-09-22 22:49 --------- d-----w C:\Program Files\BitLord
2007-09-22 21:41 --------- d-----w C:\Program Files\San Andreas Mod Installer
2007-09-22 04:43 --------- d-----w C:\Program Files\Winamp
2007-09-22 04:39 --------- d-----w C:\Documents and Settings\LuBo\Application Data\DivX
2007-09-22 04:26 --------- d-----w C:\Program Files\WinCustomize
2007-09-22 04:22 --------- d-----w C:\Program Files\Stardock
2007-09-22 04:22 --------- d-----w C:\Program Files\Common Files\Stardock
2007-09-22 04:13 --------- d-----w C:\Program Files\DivX
2007-09-22 04:10 --------- d-----w C:\Program Files\VideoLAN
2007-09-22 04:10 --------- d-----w C:\Documents and Settings\LuBo\Application Data\vlc
2007-09-22 04:08 --------- d-----w C:\Program Files\Winamp Voice Control
2007-09-22 04:08 --------- d-----w C:\Program Files\Webteh
2007-09-22 04:07 --------- d-----w C:\Program Files\VirtualDJ
2007-09-22 04:07 --------- d-----w C:\Program Files\DFX
2007-09-22 04:05 --------- d-----w C:\Program Files\GeoVid
2007-09-22 04:05 --------- d-----w C:\Documents and Settings\LuBo\Application Data\GeoVid
2007-09-22 04:03 --------- d-----w C:\Program Files\PowerISO
2007-09-22 03:56 --------- d-----w C:\Program Files\QuickTime
2007-09-22 03:56 --------- d-----w C:\Documents and Settings\LuBo\Application Data\InterVideo
2007-09-22 03:55 --------- d-----w C:\Program Files\InterVideo Information Service
2007-09-22 03:55 --------- d-----w C:\Program Files\Common Files\Ulead
2007-09-22 03:55 --------- d-----w C:\Program Files\Apple Software Update
2007-09-22 03:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-09-22 03:54 --------- d-----w C:\Program Files\InterVideo
2007-09-22 03:54 --------- d-----w C:\Program Files\Common Files\InterVideo
2007-09-22 03:54 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-09-22 03:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-09-22 03:51 --------- d-----w C:\Program Files\HyCam2
2007-09-22 03:48 --------- d-----w C:\Program Files\NeroInstall.bak
2007-09-22 03:39 --------- d-----w C:\Documents and Settings\LuBo\Application Data\Simple Star
2007-09-22 03:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Simple Star Shared
2007-09-22 03:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bluetooth
2007-09-22 03:26 --------- d-----w C:\Program Files\SVD
2007-09-22 03:26 --------- d-----w C:\Program Files\FDRLab
2007-09-22 03:26 --------- d-----w C:\Program Files\CursorXP
2007-09-22 03:25 --------- d-----w C:\Program Files\Bluetooth Remote Control
2007-09-22 03:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Logishrd
2007-09-22 03:10 --------- d-----w C:\Program Files\Logitech
2007-09-22 03:10 --------- d-----w C:\Program Files\Common Files\logishrd
2007-09-22 03:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Logitech
2007-09-22 02:27 --------- d-----w C:\Program Files\MSXML 6.0
2007-09-22 02:26 --------- d-----w C:\Program Files\MSBuild
2007-09-22 02:23 --------- d-----w C:\Program Files\Reference Assemblies
2007-09-22 02:22 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-09-22 00:22 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd1997.sys
2007-09-21 23:39 --------- d-----w C:\Program Files\MSXML 4.0
2007-09-21 23:35 --------- d-----w C:\Program Files\XP Codec Pack
2007-09-21 23:11 --------- d-----w C:\Program Files\DVD Shrink
2007-09-21 23:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-09-21 23:08 --------- d-----w C:\Program Files\LimeWire
2007-09-21 23:08 --------- d-----w C:\Program Files\Filesweb
2007-09-21 23:05 --------- d--ha-w C:\Documents and Settings\All Users\Application Data\GTek
2007-09-21 23:05 --------- d--h--w C:\Documents and Settings\LuBo\Application Data\GTek
2007-09-21 23:05 --------- d-----w C:\Program Files\Video DVD Maker
2007-09-21 23:05 --------- d-----w C:\Program Files\Linksys EasyLink Advisor
2007-09-21 23:05 --------- d-----w C:\Documents and Settings\Default User\Application Data\Gtek
2007-09-21 23:02 --------- d-----w C:\Program Files\Common Files\Adobe
2007-09-21 22:54 --------- d-----w C:\Program Files\Real
2007-09-21 22:54 --------- d-----w C:\Program Files\Common Files\xing shared
2007-09-21 22:54 --------- d-----w C:\Program Files\Common Files\Real
2007-09-21 22:53 --------- d-----w C:\Program Files\XVid;-)
2007-09-21 22:52 --------- d-----w C:\Program Files\MPEG4 Direct Maker
2007-09-21 22:48 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-09-21 22:48 --------- d-----w C:\Program Files\Common Files\L&H
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TRIXX"="C:\Program Files\TRIXX\TRIXX.exe" [2005-08-16 06:18]
"TkBellExe"="C:\Program Files\RealMedia\Update_OB\realsched.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 14:57]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2006-05-20 05:13]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" []
"LogonStudio"="C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-03 17:38]
"LogitechVideo[inspector]"="C:\Program Files\Logitech\Video\InstallHelper.exe" []
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 15:02]
"Logitech Utility"="Logi_MwX.Exe" [2003-03-04 04:50 C:\WINDOWS\LOGI_MWX.EXE]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 16:34]
"HPHUPD08"="C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 11:35]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 22:12]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 02:56 C:\WINDOWS\system32\bthprops.cpl]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-10-25 08:26]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"Steam"="c:\program files\steam\steam.exe" [2007-10-04 21:11]
"Nero PhotoShow Media Manager"="C:\PROGRA~1\Nero\PHOTOS~1\data\Xtras\mssysmgr.exe" []
"CursorXP"="C:\Program Files\CursorXP\CursorXP.exe" [2003-03-01 16:25]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" []
"DLD.EXE"="C:\Program Files\Download Direct\DLD.exe" []
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2007-10-27 18:21]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
FlexType 2K.lnk - C:\WINDOWS\Datecs\Flex2K.exe [2007-09-21 17:32:51]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2006-03-25 10:54 176128 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger Agent.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLD.EXE]
C:\Program Files\Download Direct\DLD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyLinkAdvisor]
"C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
"C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
R1 easdrv;easdrv;C:\WINDOWS\system32\DRIVERS\easdrv.sys
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
R1 TRIXX;TRIXX;\??\C:\Program Files\TRIXX\TRIXXDriver.sys
R2 eamon;EAMON;C:\WINDOWS\system32\DRIVERS\eamon.sys
R2 ekrn;Eset Service;"C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe"
R2 elagopro;GoProto Protocol Driver for LELA;C:\WINDOWS\system32\DRIVERS\elagopro.sys
R2 elaunidr;UniDriver for LELA;C:\WINDOWS\system32\DRIVERS\elaunidr.sys
R3 n558;N558 Bluetooth USB Filter Driver;C:\WINDOWS\system32\Drivers\n558.sys
S3 EhttpSrv;Eset HTTP Server;"C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe"
S3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-11-03 16:41:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-02 19:00:19 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2007-11-04 17:35:48 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-04 18:52:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-04 18:53:34
.
--- E O F ---