ComboFix 08-08-04.09 - Mike 2008-08-05 23:12:20.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1666 [GMT -4:00]
Running from: C:\Documents and Settings\Mike\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Mike\Application Data\macromedia\Flash Player\#SharedObjects\MRCB85P5\interclick.com
C:\Documents and Settings\Mike\Application Data\macromedia\Flash Player\#SharedObjects\MRCB85P5\interclick.com\ud.sol
C:\Documents and Settings\Mike\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Mike\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\install.exe
C:\WINDOWS\system32\shell31.dll
C:\WINDOWS\wiaservb.log
.
((((((((((((((((((((((((( Files Created from 2008-07-06 to 2008-08-06 )))))))))))))))))))))))))))))))
.
2008-08-05 16:16 . 2008-08-05 16:16 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-05 16:16 . 2008-08-05 16:16 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\Malwarebytes
2008-08-05 16:16 . 2008-08-05 16:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-05 16:16 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-05 16:16 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-05 16:08 . 2008-08-05 16:08 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-05 11:50 . 2008-08-05 11:50 29 --a------ C:\WINDOWS\system32\epfforii.tmp
2008-08-05 11:49 . 2003-07-16 12:21 18,688 --a------ C:\WINDOWS\system32\drivers\cdaudio.sys
2008-08-05 11:49 . 2003-07-16 12:21 18,688 --a--c--- C:\WINDOWS\system32\dllcache\cdaudio.sys
2008-08-04 13:05 . 2008-08-04 13:14 <DIR> d-------- C:\Program Files\MVPSavReader
2008-08-04 13:05 . 1998-06-01 00:00 1,056,768 --a------ C:\WINDOWS\system32\MSJet35.dll
2008-08-04 13:05 . 1998-06-01 00:00 417,792 --a------ C:\WINDOWS\system32\MsRepl35.dll
2008-08-04 13:05 . 1998-06-01 00:00 262,144 --a------ C:\WINDOWS\system32\MSRD2x35.dll
2008-08-04 13:05 . 1998-06-01 00:00 139,264 --a------ C:\WINDOWS\system32\MSJInt35.dll
2008-08-04 13:05 . 1996-12-05 00:00 77,824 --a------ C:\WINDOWS\system32\ODBCTL32.dll
2008-08-04 13:05 . 1998-06-01 00:00 36,864 --a------ C:\WINDOWS\system32\MSJtEr35.dll
2008-07-31 11:17 . 1997-01-16 00:00 71,680 --a------ C:\WINDOWS\ST5UNST.EXE
2008-07-31 11:17 . 2008-07-31 11:17 670 --a------ C:\WINDOWS\ST5UNST.000
2008-07-30 15:31 . 2008-08-03 19:33 463 --a------ C:\WINDOWS\EAGRAPH.INI
2008-07-29 17:55 . 2008-07-29 17:55 0 --a------ C:\WINDOWS\wincmd.ini
2008-07-29 17:47 . 2008-07-29 17:47 <DIR> d-------- C:\Program Files\kraw
2008-07-28 22:12 . 2008-07-28 22:38 <DIR> d-------- C:\Program Files\HmelyoffLabs
2008-07-27 19:37 . 2004-12-10 10:06 327,680 --a------ C:\WINDOWS\system32\vp6dec.ax
2008-07-27 19:37 . 2007-04-12 15:01 118,832 --a------ C:\WINDOWS\system32\SHW32.DLL
2008-07-26 18:30 . 2008-07-26 18:31 <DIR> d-------- C:\Program Files\iTunes
2008-07-26 18:30 . 2008-07-26 18:30 <DIR> d-------- C:\Program Files\iPod
2008-07-15 19:09 . 2008-07-15 19:09 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-07-11 20:33 . 2008-07-11 20:36 <DIR> d-------- C:\Xampp
2008-07-11 18:10 . 2008-07-11 18:10 <DIR> d-------- C:\Program Files\CoreFTP
2008-07-11 18:10 . 2008-07-11 18:22 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\CoreFTP
2008-07-10 18:54 . 2008-07-10 18:54 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
2008-07-10 18:54 . 2008-07-10 18:54 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\TuneUp Software
2008-07-10 18:54 . 2008-07-10 18:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-07-10 18:54 . 2008-07-10 18:54 307,968 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-07-10 18:54 . 2008-02-27 13:15 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-07-10 18:53 . 2008-07-10 18:53 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-10 18:39 . 2008-07-10 18:55 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-07-10 14:53 . 2008-07-10 14:53 <DIR> d-------- C:\Program Files\ffdshow
2008-07-10 14:53 . 2008-06-22 20:33 60,273 --a------ C:\WINDOWS\system32\pthreadGC2.dll
2008-07-10 14:53 . 2008-06-22 20:33 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-07-10 14:53 . 2008-06-22 20:33 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-05 20:15 --------- d-----w C:\Program Files\Viewpoint
2008-08-05 20:15 --------- d-----w C:\Documents and Settings\Mike\Application Data\Viewpoint
2008-08-05 20:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-05 16:28 --------- d-s---w C:\Program Files\Xfire
2008-08-05 15:58 --------- d-----w C:\Documents and Settings\Mike\Application Data\uTorrent
2008-08-05 15:49 33,056 ----a-w C:\WINDOWS\system32\userinit.exe
2008-07-28 00:00 --------- d-----w C:\Program Files\Common Files\EasyInfo
2008-07-27 23:56 --------- d-----w C:\Program Files\EA SPORTS
2008-07-27 23:49 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-07-27 23:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-26 22:30 --------- d-----w C:\Program Files\Bonjour
2008-07-21 22:22 --------- d-----w C:\Documents and Settings\Mike\Application Data\Xfire
2008-07-15 22:09 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-15 22:08 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-07-07 12:03 --------- d-----w C:\Program Files\McAfee
2008-07-05 19:29 --------- d-----w C:\Documents and Settings\Mike\Application Data\Hamachi
2008-07-05 19:24 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-07-04 02:51 --------- d-----w C:\Documents and Settings\Guest\Application Data\Realtime Soft
2008-07-03 16:47 --------- d-----w C:\Program Files\QuickTime
2008-07-03 16:44 --------- d-----w C:\Program Files\Common Files\Apple
2008-07-03 16:41 --------- d-----w C:\Program Files\Apple Software Update
2008-07-01 00:54 --------- d-----w C:\Program Files\Common Files\McAfee
2008-06-20 07:06 --------- d-----w C:\Program Files\FlashGet
2008-06-15 15:12 --------- d-----w C:\Program Files\UltraMon
2008-06-15 15:12 --------- d-----w C:\Program Files\Common Files\Realtime Soft
2008-06-15 15:12 --------- d-----w C:\Documents and Settings\Mike\Application Data\Realtime Soft
2008-06-15 15:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Realtime Soft
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2007-12-11 22:01 22,328 ----a-w C:\Documents and Settings\Mike\Application Data\PnkBstrK.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WhatPulse"="C:\Program Files\WhatPulse\WhatPulse.exe" [2006-08-21 13:48 665600]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 12:15 50528]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 05:39 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 15:07 188416]
"HPHmon04"="C:\WINDOWS\system32\hphmon04.exe" [2006-01-06 15:07 348160]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-07-12 01:19 7626752]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-07-12 01:19 86016]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 16:49 77824]
"Start WingMan Profiler"="C:\Program Files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 11:38 88584]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-01-05 17:21 566872]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]
"Malwarebytes Anti-Malware (reboot)"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [2008-07-30 20:07 1187448]
"SkyTel"="SkyTel.EXE" [2006-05-16 06:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-14 02:00 16050176 C:\WINDOWS\RTHDCPL.EXE]
"nwiz"="nwiz.exe" [2006-07-12 01:19 1519616 C:\WINDOWS\system32\nwiz.exe]
C:\Documents and Settings\Mike\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 20:16:50 113664]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
GN-WP01GS Utility.lnk - C:\Program Files\Gigabyte\Gigabyte WP01GS Wireless PCI Adapter SoftAP\Installer\WINXP\RaUI.exe [2007-08-06 13:32:20 720896]
UltraMon.lnk - C:\WINDOWS\Installer\{AF0FA6D7-96F3-468A-ABB7-28BE006EA8E9}\IcoUltraMon.ico [2008-06-15 11:12:37 29310]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2008-01-03 12:15 50528 C:\Program Files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
--a------ 2007-09-25 04:10 2007088 C:\Program Files\FlashGet\flashget.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-07-10 10:51 289064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
--a------ 2008-04-29 19:56 158624 c:\Program Files\Zune\ZuneLauncher.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America's Army\\System\\ArmyOps.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\FlashGet\\FlashGet.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 19:39]
S2 Apache2.2;Apache2.2;C:\Xampp\apache\bin\apache.exe [2008-06-14 13:02]
S2 UltraMonUtility;UltraMon Utility Driver;C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [2006-09-24 20:22]
S2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2008-04-13 20:12]
S2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 19:56]
S3 LUDrv32;LUDrv32;D:\FXDrv32.sys []
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-07-10 18:54]
S3 UltraMonMirror;UltraMonMirror;C:\WINDOWS\system32\DRIVERS\UltraMonMirror.sys [2006-09-24 20:23]
S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;C:\WINDOWS\system32\DRIVERS\netusbxp.sys [2002-02-20 03:34]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 19:56]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
2008-08-05 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 14:24]
2008-07-30 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-07-15 C:\WINDOWS\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-08-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-C:\WINDOWS\system32\kduxh.exe - C:\WINDOWS\system32\kduxh.exe
MSConfigStartUp-BearFlix - C:\Program Files\BearFlix\BearFlix.exe
MSConfigStartUp-BitTorrent - C:\Program Files\BitTorrent\bittorrent.exe
MSConfigStartUp-BlazeServoTool - C:\Program Files\BlazeVideo\BlazeDVD 5 Professional\MediaDetector.exe
MSConfigStartUp-DAEMON Tools Pro Agent - C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
MSConfigStartUp-Free Download Manager - C:\Program Files\Free Download Manager\fdm.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\zyovmwla.default\
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-05 23:15:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\DOCUME~1\Mike\LOCALS~1\Temp\RGI5E.tmp 7075 bytes
C:\WINDOWS\system32\drivers\Olfv55.sys 124928 bytes executable
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C:\\WINDOWS\\system32\\kduxh.exe"="C:\\WINDOWS\\system32\\kduxh.exe"
.
Completion time: 2008-08-05 23:20:27
ComboFix-quarantined-files.txt 2008-08-06 03:19:25
Pre-Run: 87,672,279,040 bytes free
Post-Run: 88,271,028,224 bytes free
218 --- E O F --- 2008-06-20 07:01:30