Thomas
Full Member
  


Gender: 
Posts: 197
|
 |
Re: hey tom
« Reply #3 on: Jan 17th, 2009, 2:17pm » |
Quote Modify
|
ComboFix 09-01-16.01 - Compaq_Owner 2009-01-16 15:57:40.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.222.58 [GMT -5:00] Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2008-12-16 to 2009-01-16 ))))))))))))))))))))))))))))))) . 2009-01-15 20:04 . 2009-01-15 20:04<DIR>d--------c:\windows\system32\scripting 2009-01-15 20:04 . 2009-01-15 20:04<DIR>d--------c:\windows\system32\en 2009-01-15 20:04 . 2009-01-15 20:04<DIR>d--------c:\windows\system32\bits 2009-01-15 20:04 . 2009-01-15 20:04<DIR>d--------c:\windows\l2schemas 2009-01-15 20:01 . 2009-01-15 20:05<DIR>d--------c:\windows\ServicePackFiles 2009-01-15 19:50 . 2009-01-15 19:50<DIR>d--------c:\windows\EHome 2009-01-15 19:41 . 2008-04-13 19:124,274,816---------c:\windows\system32\nv4_disp.dll 2009-01-15 19:40 . 2008-04-13 19:11870,784---------c:\windows\system32\ati3d1ag.dll 2009-01-15 02:49 . 2008-09-21 19:441,697,449--a------c:\windows\system32\vba6.dll 2009-01-14 13:24 . 2009-01-14 13:24<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\DivX 2009-01-14 12:25 . 2006-01-20 14:19389,120--a------c:\windows\system32\actskn43.ocx 2009-01-14 01:03 . 2008-12-11 05:57333,952---------c:\windows\system32\dllcache\srv.sys 2009-01-13 21:49 . 2008-10-16 14:06268,648--a------c:\windows\system32\mucltui.dll 2009-01-13 21:49 . 2008-10-16 14:0627,496--a------c:\windows\system32\mucltui.dll.mui 2009-01-13 09:41 . 2009-01-13 09:41209,608--a------c:\windows\system32\tabctl32.ocx 2009-01-13 09:38 . 2004-12-25 08:2790,112--a------c:\windows\system32\YMSG12Crypt.dll 2009-01-13 09:38 . 2007-06-30 14:5949,152--a------c:\windows\system32\Wavefx32.dll 2009-01-13 09:24 . 2005-03-24 14:4398,304--a------c:\windows\system32\KewlButtonz.ocx 2009-01-13 08:42 . 2009-01-13 08:42<DIR>d--------c:\program files\Yahoo! 2009-01-13 08:42 . 2009-01-13 08:44<DIR>d--------c:\documents and settings\All Users\Application Data\Yahoo! 2009-01-13 08:27 . 2004-03-08 19:00212,240---------c:\windows\system32\Richtx32.ocx 2009-01-13 08:27 . 2004-07-01 02:5690,112--a------c:\windows\system32\YMSG12ENCRYPT.dll 2009-01-13 08:21 . 2009-01-15 02:53115,920--a------c:\windows\system32\msinet.ocx 2009-01-13 08:19 . 2009-01-13 08:19152,848--a------c:\windows\system32\comdlg32.ocx 2009-01-13 08:18 . 2008-10-31 06:46124,688--a------c:\windows\system32\MSWinSck.ocx 2009-01-13 07:24 . 2009-01-13 07:24<DIR>d--------c:\program files\Microsoft Silverlight 2009-01-13 07:24 . 2009-01-13 07:24<DIR>d--------c:\program files\Microsoft CAPICOM 2.1.0.2 2009-01-13 06:59 . 2009-01-13 06:59<DIR>d--------c:\program files\MSXML 6.0 2009-01-13 06:47 . 2009-01-13 06:47<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\Windows Search 2009-01-13 06:29 . 2009-01-13 06:29<DIR>d--------c:\program files\MSBuild 2009-01-13 06:25 . 2009-01-13 07:01<DIR>d--------c:\windows\system32\XPSViewer 2009-01-13 06:24 . 2009-01-13 06:24<DIR>d--------c:\program files\Reference Assemblies 2009-01-13 06:22 . 2006-06-29 13:0714,048---------c:\windows\system32\spmsg2.dll 2009-01-13 06:21 . 2009-01-13 06:22<DIR>d--------C:\b4bc081899d727a63443850c12 2009-01-13 06:20 . 2009-01-13 06:20<DIR>d--------c:\windows\system32\GroupPolicy 2009-01-13 06:20 . 2009-01-13 06:20<DIR>d--------c:\program files\Windows Desktop Search 2009-01-13 06:20 . 2009-01-13 06:20<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\Windows Desktop Search 2009-01-13 06:17 . 2009-01-13 06:17<DIR>d--------c:\program files\Windows Media Connect 2 2009-01-13 06:15 . 2009-01-13 08:02<DIR>d--------c:\windows\system32\LogFiles 2009-01-13 06:15 . 2009-01-13 06:16<DIR>d--------c:\windows\system32\drivers\UMDF 2009-01-13 06:01 . 2008-04-13 19:12290,304---------c:\windows\system32\rhttpaa.dll 2009-01-13 06:01 . 2008-04-13 19:11136,192---------c:\windows\system32\aaclient.dll 2009-01-13 06:01 . 2008-04-13 19:1253,248---------c:\windows\system32\tsgqec.dll 2009-01-13 05:33 . 2008-10-16 15:386,066,176---------c:\windows\system32\dllcache\ieframe.dll 2009-01-13 05:33 . 2007-04-17 04:322,455,488---------c:\windows\system32\dllcache\ieapfltr.dat 2009-01-13 05:33 . 2007-03-08 00:10991,232---------c:\windows\system32\dllcache\ieframe.dll.mui 2009-01-13 05:33 . 2008-10-16 15:38459,264---------c:\windows\system32\dllcache\msfeeds.dll 2009-01-13 05:33 . 2008-10-16 15:38383,488---------c:\windows\system32\dllcache\ieapfltr.dll 2009-01-13 05:33 . 2008-10-16 15:38267,776---------c:\windows\system32\dllcache\iertutil.dll 2009-01-13 05:33 . 2008-10-16 15:3863,488---------c:\windows\system32\dllcache\icardie.dll 2009-01-13 05:33 . 2008-10-16 15:3852,224---------c:\windows\system32\dllcache\msfeedsbs.dll 2009-01-13 05:33 . 2008-10-16 08:1113,824---------c:\windows\system32\dllcache\ieudinit.exe 2009-01-13 04:57 . 2008-09-15 07:121,846,400---------c:\windows\system32\dllcache\win32k.sys 2009-01-13 04:56 . 2008-08-14 05:112,189,184---------c:\windows\system32\dllcache\ntoskrnl.exe 2009-01-13 04:56 . 2008-08-14 05:092,145,280---------c:\windows\system32\dllcache\ntkrnlmp.exe 2009-01-13 04:56 . 2008-08-14 04:332,066,048---------c:\windows\system32\dllcache\ntkrnlpa.exe 2009-01-13 04:56 . 2008-08-14 04:332,023,936---------c:\windows\system32\dllcache\ntkrpamp.exe 2009-01-13 04:56 . 2008-04-11 14:04691,712---------c:\windows\system32\dllcache\inetcomm.dll 2009-01-13 04:56 . 2008-05-08 09:02203,136---------c:\windows\system32\dllcache\rmcast.sys 2009-01-13 04:55 . 2008-10-24 06:21455,296---------c:\windows\system32\dllcache\mrxsmb.sys 2009-01-13 04:55 . 2008-06-13 06:05272,128---------c:\windows\system32\drivers\bthport.sys 2009-01-13 04:55 . 2008-06-13 06:05272,128---------c:\windows\system32\dllcache\bthport.sys 2009-01-13 04:52 . 2008-10-15 11:34337,408---------c:\windows\system32\dllcache\netapi32.dll 2009-01-13 03:58 . 2009-01-13 04:44246--a------c:\windows\system\hpsysdrv.dat 2009-01-13 03:55 . 2009-01-13 02:08<DIR>d--------c:\windows\I386 2009-01-13 03:21 . 2009-01-13 03:21<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\MySpace 2009-01-13 03:20 . 2009-01-13 03:20<DIR>d--------c:\program files\MySpace 2009-01-13 03:15 . 2009-01-13 08:14<DIR>d--------c:\documents and settings\Compaq_Owner\Contacts 2009-01-13 03:13 . 2009-01-16 06:58<DIR>d--------c:\program files\MSN Messenger 2009-01-13 02:41 . 2009-01-13 02:41<DIR>d--------c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-01-13 02:40 . 2009-01-16 15:39<DIR>d--------c:\program files\SUPERAntiSpyware 2009-01-13 02:40 . 2009-01-13 02:40<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\SUPERAntiSpyware.com 2009-01-13 02:39 . 2009-01-13 02:39<DIR>d--------c:\program files\Common Files\Wise Installation Wizard 2009-01-13 02:37 . 2009-01-13 02:38<DIR>d--------c:\program files\CCleaner 2009-01-13 02:34 . 2009-01-16 15:55<DIR>d-a------c:\documents and settings\All Users\Application Data\TEMP 2009-01-13 02:04 . 2009-01-13 02:04410,984--a------c:\windows\system32\deploytk.dll 2009-01-13 02:04 . 2009-01-13 02:0473,728--a------c:\windows\system32\javacpl.cpl 2009-01-13 01:33 . 2009-01-13 01:34<DIR>d--------c:\program files\iTunes 2009-01-13 01:33 . 2009-01-13 01:33<DIR>d--------c:\program files\iPod 2009-01-13 01:33 . 2009-01-13 01:34<DIR>d--------c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2009-01-13 01:32 . 2009-01-13 01:32<DIR>d--------c:\program files\Bonjour 2009-01-13 01:31 . 2009-01-13 01:32<DIR>d--------c:\program files\QuickTime 2009-01-13 01:30 . 2009-01-13 03:13<DIR>d----c---c:\windows\system32\DRVSTORE 2009-01-13 01:30 . 2009-01-13 01:33<DIR>d--------c:\program files\Common Files\Apple 2009-01-13 01:30 . 2009-01-13 01:30<DIR>d--------c:\program files\Apple Software Update 2009-01-13 01:30 . 2009-01-13 01:30<DIR>d--------c:\documents and settings\All Users\Application Data\Apple 2009-01-13 01:28 . 2009-01-13 01:28<DIR>d--------c:\program files\DivX 2009-01-13 01:27 . 2009-01-13 01:27<DIR>d--------c:\program files\AC3Filter 2009-01-13 01:27 . 2008-07-09 03:05421,888--a------c:\windows\system32\ac3filter.acm 2009-01-13 01:22 . 2008-04-13 13:395,504--a------c:\windows\system32\drivers\mstee.sys 2009-01-13 01:21 . 2008-04-13 13:4685,248--a------c:\windows\system32\drivers\nabtsfec.sys 2009-01-13 01:21 . 2008-04-13 13:4619,200--a------c:\windows\system32\drivers\wstcodec.sys 2009-01-13 01:21 . 2008-04-13 13:4617,024--a------c:\windows\system32\drivers\ccdecode.sys 2009-01-13 01:21 . 2008-04-13 19:1216,384--a------c:\windows\system32\ipsink.ax 2009-01-13 01:21 . 2008-04-13 13:4615,232--a------c:\windows\system32\drivers\streamip.sys 2009-01-13 01:21 . 2008-04-13 13:4611,136--a------c:\windows\system32\drivers\slip.sys 2009-01-13 01:21 . 2008-04-13 13:4610,880--a------c:\windows\system32\drivers\ndisip.sys 2009-01-13 01:20 . 2008-04-13 19:1291,136--a------c:\windows\system32\kswdmcap.ax 2009-01-13 01:20 . 2008-04-13 19:1261,952--a------c:\windows\system32\kstvtune.ax 2009-01-13 01:20 . 2008-04-13 19:1253,760--a------c:\windows\system32\vfwwdm32.dll 2009-01-13 01:20 . 2008-04-13 19:1243,008--a------c:\windows\system32\ksxbar.ax 2009-01-13 01:20 . 2008-04-13 19:1228,672--a------c:\windows\system32\vidcap.ax 2009-01-13 01:16 . 2009-01-13 01:16<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\TrojanHunter 2009-01-13 01:10 . 2009-01-13 01:16<DIR>d--------c:\program files\TrojanHunter 5.0 2009-01-13 00:53 . 2009-01-13 00:53<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\Digital Asphyxia 2009-01-13 00:53 . 2009-01-13 00:53<DIR>d--------c:\documents and settings\All Users\Application Data\Digital Asphyxia 2009-01-13 00:52 . 2009-01-13 00:52<DIR>d--------c:\program files\Digital Asphyxia 2009-01-13 00:52 . 2009-01-13 00:52<DIR>d--------c:\documents and settings\All Users\Application Data\Tarma Installer 2009-01-13 00:48 . 2009-01-13 00:48<DIR>d--------c:\program files\Common Files\NSV 2009-01-13 00:45 . 2009-01-13 00:52<DIR>d--------c:\program files\Winamp 2009-01-13 00:45 . 2009-01-16 15:021,125--a------c:\windows\winamp.ini 2009-01-13 00:35 . 2009-01-13 00:35<DIR>d--------c:\program files\Trend Micro 2009-01-13 00:30 . 2009-01-13 00:30<DIR>d--------c:\program files\7-Zip 2009-01-13 00:28 . 2009-01-13 00:28<DIR>d--------c:\program files\uTorrent 2009-01-13 00:28 . 2009-01-16 15:41<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\uTorrent 2009-01-13 00:22 . 2009-01-16 15:04<DIR>d--------c:\program files\Malwarebytes' Anti-Malware 2009-01-13 00:22 . 2009-01-13 00:22<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes 2009-01-13 00:22 . 2009-01-13 00:22<DIR>d--------c:\documents and settings\All Users\Application Data\Malwarebytes 2009-01-13 00:22 . 2009-01-14 16:1138,496--a------c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-13 00:22 . 2009-01-14 16:1115,504--a------c:\windows\system32\drivers\mbam.sys 2009-01-13 00:12 . 2004-08-04 07:00221,184--a------c:\windows\system32\wmpns.dll 2009-01-13 00:12 . 2009-01-13 00:121,857-rahs----c:\windows\system32\drivers\103C_HP_CPC_ED861AA-ABA SR1603WM NA540_YC_0Pres_QCNH542_E54NAheRED2_48_IAmberine M_SASUSTek Computer INC._V1.03_B3.08_T050913_WXH2_L409_M223_J80_7AMD_8Sempron_91.79_#051225_ N10EC8139_Z14F12F20_G10025954.MRK 2009-01-13 00:10 . 2005-08-08 17:50<DIR>d--------c:\documents and settings\Compaq_Owner\WINDOWS 2009-01-13 00:10 . 2005-08-08 17:54<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\SampleView 2009-01-13 00:10 . 2005-08-08 17:49<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\Apple Computer . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-13 07:03---------d-----wc:\program files\Java 2009-01-13 06:56---------d--h--wc:\program files\InstallShield Installation Information 2009-01-13 06:54---------d-----wc:\program files\Common Files\InstallShield 2009-01-13 06:31---------d-----wc:\documents and settings\All Users\Application Data\Apple Computer 2008-12-11 10:57333,952----a-wc:\windows\system32\drivers\srv.sys 2008-12-02 11:05118,656----a-wc:\windows\system32\drivers\Rtnicxp.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Y!TunnelPro"="c:\program files\Digital Asphyxia\Y!TunnelPro 2.5\YTPro.exe" [2008-09-27 1412608] "RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-16 1830128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "THGuard"="c:\program files\TrojanHunter 5.0\THGuard.exe" [2008-10-24 1056928] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-13 136600] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-01-14 399504] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.ac3filter"= ac3filter.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Digital Asphyxia\\Y!TunnelPro 2.5\\YTPro.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= "c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"= R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-12-22 8944] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-12-22 55024] R3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;c:\windows\system32\drivers\ubVeo532.sys [2002-07-01 95232] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-01-13 15504] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-22 7408] R4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-01-13 170640] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}] \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480 . Contents of the 'Scheduled Tasks' folder 2009-01-15 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34] . - - - - ORPHANS REMOVED - - - - ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file) . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405 &bd=presario&pf=desktop&parm1=seconduser uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8 mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405 &bd=presario&pf=desktop&parm1=seconduser uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s . ************************************************************************ ** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-01-16 16:01:38 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(640) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\Ati2evxx.dll . Completion time: 2009-01-16 16:05:17 ComboFix-quarantined-files.txt 2009-01-16 21:05:12 Pre-Run: 59,323,842,560 bytes free Post-Run: 59,308,896,256 bytes free 226--- E O F ---2009-01-16 10:58:01
|