ComboFix 08-07-05.1 - IAN 2008-07-07 12:02:37.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.652 [GMT 1:00]
Running from: D:\Documents and Settings\IAN\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\WINDOWS\BM8b4abea7.txt
D:\WINDOWS\cookies.ini
D:\WINDOWS\pskt.ini
D:\WINDOWS\system32\albcxaag.ini
D:\WINDOWS\system32\artloskh.ini
D:\WINDOWS\system32\ehhgQqss.ini
D:\WINDOWS\system32\ehhgQqss.ini2
D:\WINDOWS\system32\gaaxcbla.dll
D:\WINDOWS\system32\geBuVPjh.dll
D:\WINDOWS\system32\hjPVuBeg.ini
D:\WINDOWS\system32\hjPVuBeg.ini2
D:\WINDOWS\system32\htpqnyas.dll
D:\WINDOWS\system32\hwyqvmjq.dll
D:\WINDOWS\system32\iocydi.dll
D:\WINDOWS\system32\iqbuyz.dll
D:\WINDOWS\system32\ixugjhdp.dll
D:\WINDOWS\system32\lhoskcdj.dll
D:\WINDOWS\system32\licabpel.ini
D:\WINDOWS\system32\lwbyiojh.dll
D:\WINDOWS\system32\mcrh.tmp
D:\WINDOWS\system32\mcxbua.dll
D:\WINDOWS\system32\mjpcytgk.dll
D:\WINDOWS\system32\mnfgqvdg.ini
D:\WINDOWS\system32\MWyGffii.ini
D:\WINDOWS\system32\MWyGffii.ini2
D:\WINDOWS\system32\mxvextio.dll
D:\WINDOWS\system32\necyaq.dll
D:\WINDOWS\system32\resymcem.ini
D:\WINDOWS\system32\rQHaXoPi.dll
D:\WINDOWS\system32\smtdhx.dll
D:\WINDOWS\system32\soltge.dll
D:\WINDOWS\system32\srqdoitv.ini
D:\WINDOWS\system32\SuCIiSBc.ini
D:\WINDOWS\system32\SuCIiSBc.ini2
D:\WINDOWS\system32\tofascwd.dll
D:\WINDOWS\system32\uakuypqu.ini
D:\WINDOWS\system32\uelmsxpm.dll
D:\WINDOWS\system32\xujunn.dll
D:\WINDOWS\system32\yhijidmy.ini
D:\WINDOWS\system32\zbrihi.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-07 to 2008-07-07 )))))))))))))))))))))))))))))))
.
2008-07-02 16:59 . 2008-03-25 02:37 69,632 --a------ D:\WINDOWS\system32\javacpl.cpl
2008-07-02 16:58 . 2008-07-02 16:59 <DIR> d-------- D:\Program Files\Java
2008-07-02 16:57 . 2008-07-02 16:57 <DIR> d-------- D:\Program Files\Common Files\Java
2008-07-02 16:53 . 2008-07-02 16:53 <DIR> d-------- D:\Program Files\SDM20
2008-07-02 12:28 . 2008-07-02 12:54 <DIR> d-------- D:\Documents and Settings\IAN\DoctorWeb
2008-06-30 15:48 . 2008-06-30 15:48 <DIR> d-------- D:\Program Files\Trend Micro
2008-06-29 18:01 . 2008-07-07 10:32 <DIR> d-------- D:\Program Files\EsetOnlineScanner
2008-06-29 14:19 . 2008-06-29 15:06 <DIR> d-------- D:\Program Files\CA Yahoo! Anti-Spy
2008-06-29 12:38 . 2008-06-28 14:16 34,296 --a------ D:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-29 12:38 . 2008-06-28 14:16 17,144 --a------ D:\WINDOWS\system32\drivers\mbam.sys
2008-06-28 00:59 . 2008-07-04 11:02 110,419 --a------ D:\WINDOWS\BM8b4abea7.xml
2008-06-21 22:05 . 2008-06-21 22:05 188 --a------ D:\Documents and Settings\IAN\Application Data\wklnhst.dat
2008-06-11 04:58 . 2008-06-13 14:10 272,128 --------- D:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 04:58 . 2008-06-13 14:10 272,128 -----c--- D:\WINDOWS\system32\dllcache\bthport.sys
2008-06-07 23:22 . 2008-06-07 23:22 <DIR> d-------- D:\Program Files\Common Files\xing shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-07-04 09:00 --------- d-----w D:\Program Files\SUPERAntiSpyware
2008-07-04 09:00 --------- d-----w D:\Documents and Settings\IAN\Application Data\SUPERAntiSpyware.com
2008-07-04 08:59 --------- d-----w D:\Program Files\Common Files\Wise Installation Wizard
2008-07-02 15:40 --------- d-----w D:\Program Files\mIRC
2008-06-29 11:38 --------- d-----w D:\Program Files\Malwarebytes' Anti-Malware
2008-06-27 19:56 --------- d-----w D:\Program Files\InterActual
2008-06-21 20:10 --------- d--h--r D:\Documents and Settings\IAN\Application Data\yahoo!
2008-06-21 20:10 --------- d-----w D:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-06-07 22:22 --------- d-----w D:\Program Files\Common Files\Real
2008-06-02 01:19 --------- d-----w D:\Program Files\Picasa2
2008-05-12 07:43 --------- d-----w D:\Documents and Settings\IAN\Application Data\Samsung
2008-05-12 07:42 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-05-12 07:39 --------- d-----w D:\Program Files\Samsung
2008-05-12 05:42 --------- d-----w D:\Program Files\Passwords Plus
2008-05-10 21:59 --------- d-----w D:\Documents and Settings\IAN\Application Data\U3
2008-05-08 12:28 202,752 ------w D:\WINDOWS\system32\drivers\rmcast.sys
2008-04-12 13:34 744 -c--a-w D:\Documents and Settings\IAN\Application Data\filterclsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-09-10 08:46 68856]
"SUPERAntiSpyware"="D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"AAWTray"="D:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 15:53 88024]
"SunJavaUpdateSched"="D:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"TkBellExe"="D:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-07 23:21 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"Picasa Media Detector"="D:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 02:23 443968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce]
"SetDefaultMidi"="MIDIDEF.EXE" [2002-12-03 23:16 49152 D:\WINDOWS\mididef.exe]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "D:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.DVSD"= pdvcodec.dll
"msacm.dvacm"= D:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin Wireless USB Utility.lnk]
path=D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Belkin Wireless USB Utility.lnk
backup=D:\WINDOWS\pss\Belkin Wireless USB Utility.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Status Monitor.lnk]
path=D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Status Monitor.lnk
backup=D:\WINDOWS\pss\Status Monitor.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^IAN^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=D:\Documents and Settings\IAN\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=D:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AAWTray]
--a------ 2007-08-08 15:53 88024 D:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a--c--- 2008-01-11 23:16 39792 D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
-ra------ 2007-03-01 11:37 2321600 D:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamMonitor]
--a--c--- 2002-10-07 00:23 90112 D:\Program Files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter2.0]
--------- 2005-05-17 17:42 933888 D:\Program Files\Brother\ControlCenter2\brctrcen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
-----c--- 2004-08-03 23:56 15360 D:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a--c--- 2003-05-07 20:56 188416 D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
--a--c--- 2005-03-17 14:45 40960 D:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a--c--- 2005-01-18 17:07 196608 D:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a--c--- 2005-01-18 17:47 458752 D:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a------ 2005-01-18 17:37 217088 D:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
--a------ 2004-10-08 11:52 221184 D:\WINDOWS\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 12:34 5724184 D:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2001-07-09 02:50 155648 D:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
--a--c--- 2005-03-17 14:25 57393 D:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2008-02-26 02:23 443968 D:\Program Files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
-----c--- 2005-06-10 01:48 98304 D:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefPrt]
--------- 2005-01-26 18:02 49152 D:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
--a--c--- 2002-04-17 11:42 69632 D:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
-ra--c--- 2003-10-14 10:22 155648 D:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2008-05-28 10:33 1506544 D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-09-10 08:46 68856 D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-06-07 23:21 185896 D:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--------- 2003-08-19 01:01 110592 D:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
--a------ 2003-05-28 18:59 28672 D:\WINDOWS\system32\cthelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"D:\\Program Files\\Messenger\\msmsgs.exe"=
"D:\\Documents and Settings\\IAN\\Desktop\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*

isabled:@xpsp2res.dll,-22009
R1 aswSP;avast! Self Protection;D:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 00:20]
R2 aswFsBlk;aswFsBlk;D:\WINDOWS\system32\DRIVERS\aswF sBlk.sys [2008-05-16 00:16]
R3 hcwPVRP2;Hauppauge WinTV-PVR PCI II (Encoder-16);D:\WINDOWS\system32\DRIVERS\hcwPVRP2.sys [2003-12-02 16:23]
S3 av100s2k;av100s2k;D:\WINDOWS\system32\DRIVERS\av10 0s2k.sys [2003-02-18 20:25]
S3 av100u2k;av100u2k;D:\WINDOWS\system32\DRIVERS\av10 0u2k.sys [2003-03-12 06:05]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);D:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;D:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;D:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{621016f2-c154-11dc-a25f-00173f901d36}]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-07-07 08:27:00 D:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- D:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-06-24 16:46:00 D:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#240#CN386230RMJ5.job"
- D:\Program Files\HP\hpcoretech\comp\hpdarc.exe#/#Hewlett-Packard#240#CN386230RMJ5
.
- - - - ORPHANS REMOVED - - - -
BHO-{6EA695DA-7CBA-4424-A819-F54B93548890} - D:\WINDOWS\system32\opnnnnND.dll
BHO-{7062A567-23A9-42CC-A94A-1EA27D5D2D3A} - D:\WINDOWS\system32\ssqQghhe.dll
BHO-{8AB5FF87-4173-4FFE-80A7-A512D98A6419} - D:\WINDOWS\system32\iiffGyWM.dll
BHO-{FFBAA195-D7B4-4872-AFAD-73349920EADC} - D:\WINDOWS\system32\cBSiICuS.dll
HKLM-Run-0873b249 - D:\WINDOWS\system32\gaaxcbla.dll
MSConfigStartUp-0873b249 - D:\WINDOWS\system32\hneeqsdk.dll
MSConfigStartUp-BM8b4abea7 - D:\WINDOWS\system32\gbaopiqy.dll
MSConfigStartUp-ImInstaller_IncrediMail - D:\DOCUME~1\IAN\LOCALS~1\Temp\ImInstaller\IncrediM ail\incredimail_install[1].exe
MSConfigStartUp-tbon - D:\Program Files\TBONBin\tbon.exe
MSConfigStartUp-Uniblue RegistryBooster 2 - D:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
MSConfigStartUp-updateMgr - D:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
MSConfigStartUp-VideoCall - D:\Program Files\Logitech\VideoCall\VideoCall.exe
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-07 12:16:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\WINDOWS\system32\brss01a.exe
D:\WINDOWS\system32\imapi.exe
D:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
D:\WINDOWS\system32\wdfmgr.exe
D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
D:\WINDOWS\system32\WgaTray.exe
.
************************************************** ************************
.
Completion time: 2008-07-07 12:22:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-07 11:22:26
Pre-Run: 137,730,969,600 bytes free
Post-Run: 139,066,327,040 bytes free
246 --- E O F --- 2008-06-20 02:02:00