ComboFix 07-09-08 - "William xxxxxxx" 2007-09-07 13:50:48.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.602 [GMT -7:00]
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\WILLIA~1\Desktop\Error Cleaner.url
C:\DOCUME~1\WILLIA~1\Desktop\internet.lnk
C:\DOCUME~1\WILLIA~1\Desktop\Privacy Protector.url
C:\DOCUME~1\WILLIA~1\Desktop\Spyware&Malware Protection.url
C:\DOCUME~1\WILLIA~1\FAVORI~1\Error Cleaner.url
C:\DOCUME~1\WILLIA~1\FAVORI~1\Privacy Protector.url
C:\DOCUME~1\WILLIA~1\FAVORI~1\Spyware&Malware Protection.url
C:\Program Files\VideoAccessCodec
C:\Program Files\VideoAccessCodec\install.ico
C:\Program Files\VideoAccessCodec\Uninstall.exe
C:\Program Files\VideoAccessCodec\VideoAccessCodec.ocx
C:\WINDOWS\dat.txt
C:\WINDOWS\main_uninstaller.exe
C:\WINDOWS\msmdev.dll
C:\WINDOWS\msmhost.dll
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\rs.txt
((((((((((((((((((((((((( Files Created from 2007-08-08 to 2007-09-08 )))))))))))))))))))))))))))))))
.
2007-09-07 13:50 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-08-26 09:48 <DIR> d-------- C:\Program Files\Microsoft Hardware
2007-08-26 09:46 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2007-08-26 09:46 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2007-08-17 17:54 <DIR> d-------- C:\DOCUME~1\WILLIA~1\APPLIC~1\ZoomBrowser EX
2007-08-17 17:51 <DIR> d-------- C:\DOCUME~1\WILLIA~1\APPLIC~1\Canon
2007-08-17 17:48 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ZoomBrowser
2007-08-17 17:47 <DIR> d-------- C:\Program Files\Common Files\Canon
2007-08-17 17:47 <DIR> d-------- C:\Program Files\Canon
2007-08-17 17:07 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2007-08-17 17:07 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2007-08-14 18:47 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-08-09 16:28 <DIR> d-------- C:\Program Files\1-2-3 Word Search Maker
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-07 13:23 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-09-07 12:36 --------- d-------- C:\DOCUME~1\WILLIA~1\APPLIC~1\OpenOffice.org2
2007-07-26 14:17 --------- d-------- C:\DOCUME~1\WILLIA~1\APPLIC~1\Google
2007-07-26 14:06 --------- d-------- C:\Program Files\Google
2007-07-25 15:05 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-07-13 18:16 --------- d-------- C:\Program Files\Norton AntiVirus
2007-07-13 18:14 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-07-13 18:14 8014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-07-13 18:14 115000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-07-13 18:14 --------- d-------- C:\Program Files\Symantec
2007-07-13 18:13 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-06-13 03:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-01-23 19:46 6126 --a------ C:\DOCUME~1\WILLIA~1\xx_tempopt.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-22 22:19]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"HPHmon05"="C:\WINDOWS\system32\hphmon05.exe" [2003-08-20 14:15]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 11:12]
"HPHUPD05"="C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-20 14:23]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-25 07:14]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-31 21:30]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"POINTER"="point32.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-29 06:16]
C:\DOCUME~1\WILLIA~1\STARTM~1\Programs\Startup\
OpenOffice.org 2.2.lnk - C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 16:54:56]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lightsurf.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Lightsurf.lnk
backup=C:\WINDOWS\pss\Lightsurf.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SATARaid.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SATARaid.lnk
backup=C:\WINDOWS\pss\SATARaid.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nForce Tray Options]
sstray.exe /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
R0 Si3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\DRIVERS\si3112r.sys
R3 ALABULK;Fujifilm USB MemoryCard ReaderWriter device driver;C:\WINDOWS\system32\Drivers\ALABULK2.sys
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
R3 WmHidLo;Logitech WingMan USB Filter Driver;C:\WINDOWS\system32\drivers\WmHidLo.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-09-03 16:39:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-07-29 14:56:00 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#7900#CN39D310DXEV.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-07 18:56:00 C:\WINDOWS\Tasks\HP Usg Daily.job"
- C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\pexpress\hphped05.exe
"2007-09-01 03:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - William Neiswender.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-08 13:55:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-09-08 13:57:38 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-08 13:57
.
--- E O F ---