ComboFix 08-11-16.04 - Charlene 2008-11-16 21:12:26.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.181 [GMT -6:00]
Running from: c:\documents and settings\Charlene\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Charlene\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-10-17 to 2008-11-17 )))))))))))))))))))))))))))))))
.
2096-10-24 08:38 . 2096-10-24 08:38 39,936 --a--c--- C:\Cassini.8BF
2008-11-14 19:22 . 2008-11-14 19:23 <DIR> d-------- c:\program files\New Folder
2008-11-14 19:22 . 2008-11-14 19:22 <DIR> d----c--- C:\New Folder
2008-10-28 16:42 . 2008-10-28 16:42 <DIR> d-------- c:\program files\Alwil Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-17 03:02 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-17 00:25 --------- dc----w c:\documents and settings\All Users\Application Data\Google Updater
2008-11-15 02:54 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-11-12 13:59 3,350 --sha-w c:\windows\SYSTEM32\KGyGaAvL.sys
2008-11-05 04:36 --------- d-----w c:\program files\Fonts
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ------w c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
2008-10-22 22:10 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 22:10 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-20 03:02 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-10-16 13:26 --------- d-----w c:\program files\trend micro
2008-10-16 03:12 --------- d-----w c:\program files\Java
2008-10-15 16:57 332,800 ------w c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-10 15:25 --------- d-----w c:\documents and settings\Charlene\Application Data\Sammsoft
2008-10-07 22:44 --------- d-----w c:\program files\Microsoft AntiSpyware
2008-10-07 22:26 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-10-07 22:26 60,800 ----a-w c:\windows\SYSTEM32\S32EVNT1.DLL
2008-10-07 22:26 123,952 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2008-10-07 22:26 10,671 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-10-07 22:26 --------- d-----w c:\program files\Symantec
2008-10-07 08:10 348,160 ----a-w c:\windows\SYSTEM32\msvcr71.dll
2008-10-07 08:10 --------- d-----w c:\program files\Common Files\xing shared
2008-10-07 08:10 --------- d-----w c:\program files\Common Files\Real
2008-10-07 02:10 --------- d-----w c:\program files\EsetOnlineScanner
2008-10-03 17:41 6,066,176 ------w c:\windows\SYSTEM32\DLLCACHE\ieframe.dll
2008-10-02 03:01 --------- d-----w c:\program files\Common Files\Adobe
2008-09-30 22:43 1,286,152 ----a-w c:\windows\SYSTEM32\msxml4.dll
2008-09-29 20:10 --------- dc----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-29 20:10 --------- d-----w c:\documents and settings\Charlene\Application Data\SUPERAntiSpyware.com
2008-09-29 20:08 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-09-29 12:51 --------- dc----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-09-29 12:51 --------- d-----w c:\documents and settings\Charlene\Application Data\Malwarebytes
2008-09-19 19:18 --------- d-----w c:\documents and settings\Charlene\Application Data\Filter Forge
2008-09-15 11:57 1,846,016 ----a-w c:\windows\SYSTEM32\win32k.sys
2008-09-15 11:57 1,846,016 ------w c:\windows\SYSTEM32\DLLCACHE\win32k.sys
2008-09-04 16:42 1,106,944 ----a-w c:\windows\SYSTEM32\msxml3.dll
2008-09-04 16:42 1,106,944 ------w c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
2008-08-28 10:04 333,056 ------w c:\windows\SYSTEM32\DLLCACHE\srv.sys
2008-08-27 08:24 3,593,216 ----a-w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
2008-08-25 08:38 13,824 ------w c:\windows\SYSTEM32\DLLCACHE\ieudinit.exe
2008-08-25 08:37 70,656 ------w c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
2008-08-23 05:56 635,848 ------w c:\windows\SYSTEM32\DLLCACHE\iexplore.exe
2008-08-23 05:54 161,792 ------w c:\windows\SYSTEM32\DLLCACHE\ieakui.dll
2008-04-07 01:36 6,039,144 ----a-w c:\program files\Firefox Setup 2.0.0.13.exe
2007-06-07 21:59 29,176 ----a-w c:\program files\TranslatePlugInSetup.zip
2006-12-30 23:06 3,262,369 ----a-w c:\program files\alzip.exe
2006-12-30 22:42 1,035,271 ----a-w c:\program files\wrar362.exe
2006-06-09 02:51 0 ----a-w c:\program files\pspbrwse.jbf
2006-04-06 01:37 0 ---ha-w c:\documents and settings\Charlene\hpothb07.dat
2005-06-01 01:53 89,088 ----a-w c:\program files\TranslatePlugInSetup.msi
2003-01-31 09:43 6,065,152 ----a-w c:\program files\Mystical.exe
2003-01-31 00:20 1,396,736 ----a-w c:\program files\Mystical_PlugIn.8bf
2001-07-17 21:15 66,680 ----a-w c:\program files\ARDS1.ttf
1998-12-09 10:53 99,840 ----a-w c:\program files\Common Files\IRAABOUT.DLL
1998-12-09 10:53 70,144 ----a-w c:\program files\Common Files\IRAMDMTR.DLL
1998-12-09 10:53 48,640 ----a-w c:\program files\Common Files\IRALPTTR.DLL
1998-12-09 10:53 31,744 ----a-w c:\program files\Common Files\IRAWEBTR.DLL
1998-12-09 10:53 186,368 ----a-w c:\program files\Common Files\IRAREG.DLL
1998-12-09 10:53 17,920 ----a-w c:\program files\Common Files\IRASRIAL.DLL
2007-09-21 20:25 88 --sh--r c:\windows\SYSTEM32\41A9B94B56.sys
.
(((((((((((((((((((((((((((((
snapshot@2008-10-16_17.16.42.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-05-05 09:41:45 453,120 ------w c:\windows\Driver Cache\I386\mrxsmb.sys
+ 2008-10-24 11:10:42 453,632 ------w c:\windows\Driver Cache\I386\mrxsmb.sys
- 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 02:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2008-11-12 09:00:46 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
- 2000-08-31 13:00:00 28,672 ----a-w c:\windows\NIRCMD.exe
+ 2000-08-31 14:00:00 28,672 ----a-w c:\windows\NIRCMD.exe
- 2000-08-31 13:00:00 161,792 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 14:00:00 161,792 ----a-w c:\windows\SWREG.exe
- 2008-10-07 19:19:40 16,721,856 ----a-w c:\windows\SYSTEM32\MRT.exe
+ 2008-11-04 00:10:25 17,318,336 ----a-w c:\windows\SYSTEM32\MRT.exe
- 2006-08-17 12:28:27 332,288 ----a-w c:\windows\SYSTEM32\netapi32.dll
+ 2008-10-15 16:57:55 332,800 ----a-w c:\windows\SYSTEM32\netapi32.dll
- 2008-03-26 20:40:30 53,436 ----a-w c:\windows\SYSTEM32\PERFC009.DAT
+ 2008-11-05 02:49:37 53,436 ----a-w c:\windows\SYSTEM32\PERFC009.DAT
- 2008-03-26 20:40:30 381,692 ----a-w c:\windows\SYSTEM32\PERFH009.DAT
+ 2008-11-05 02:49:37 381,692 ----a-w c:\windows\SYSTEM32\PERFH009.DAT
- 2007-11-30 11:18:51 17,272 ------w c:\windows\SYSTEM32\spmsg.dll
+ 2008-07-08 13:02:01 17,272 ------w c:\windows\SYSTEM32\spmsg.dll
+ 2008-09-30 22:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2008-09-30 22:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 57344]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-14 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-02-03 98304]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\PMremind.exe [2005-02-14 442368]
Forget Me Not.lnk - c:\program files\Broderbund\AG CreataCard\AGRemind.exe [2008-09-15 323584]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
HP Image Zone Fast Start.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2005-05-11 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]
Symantec Fax Starter Edition Port.lnk - c:\program files\Microsoft Office\Office\1033\OLFSNT40.EXE [1998-12-23 45568]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2005-02-03 122880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Charlene^Start Menu^Programs^Startup^UMAX VistaAccess.lnk]
path=c:\documents and settings\Charlene\Start Menu\Programs\Startup\UMAX VistaAccess.lnk
backup=c:\windows\pss\UMAX VistaAccess.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Abacast\\Abaclient.exe"=
"c:\\Program Files\\MUSICMATCH\\Musicmatch Jukebox\\mm_server.exe"=
"c:\\WINDOWS\\SYSTEM32\\USMT\\MIGWIZ.EXE"=
"c:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R2 LiveUpdate Notice;LiveUpdate Notice;"c:\program files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [2008-01-25 149352]
R2 WUSB54Gv42SVC;WUSB54Gv42SVC;"c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv42.exe" [2007-07-16 53307]
S3 ALABULKO;OLYMPUS USB Media Adapter device driver;c:\windows\system32\Drivers\ALABLK2o.sys [2002-11-09 34914]
S3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\COH_Mon.sys [2008-01-12 23888]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{077bb372-e791-11dc-9deb-82fd64bbcb41}]
\Shell\AutoRun\command - D:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7835e403-0636-11dd-9df6-001111b562a6}]
\Shell\AutoRun\command - D:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc16b8e9-10db-11dd-9df8-001111b562a6}]
\Shell\AutoRun\command - D:\LaunchU3.exe -a
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2008-11-13 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Charlene.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2008-02-07 08:05]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-16 21:17:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-16 21:23:13
ComboFix-quarantined-files.txt 2008-11-17 03:22:18
ComboFix2.txt 2008-11-17 01:24:45
ComboFix3.txt 2008-11-16 04:10:21
ComboFix4.txt 2008-11-15 23:16:30
ComboFix5.txt 2008-11-17 03:11:30
Pre-Run: 42,164,215,808 bytes free
Post-Run: 42,164,862,976 bytes free
187 --- E O F --- 2008-11-12 09:05:41