case
Newbie


Posts: 8
|
 |
Re: Unable To Move or Copy Files
« Reply #3 on: Mar 4th, 2008, 1:57pm » |
Quote Modify
|
ComboFix 08-03-03.17 - Casey 2008-03-04 11:33:53.1 - NTFSx86 Running from: C:\Documents and Settings\Casey\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\uninstall.exe . ((((((((((((((((((((((((( Files Created from 2008-02-04 to 2008-03-04 ))))))))))))))))))))))))))))))) . 2008-03-03 15:11 . 2008-03-03 15:11<DIR>d--------C:\Program Files\Trend Micro 2008-03-03 11:13 . 2008-03-03 11:13<DIR>d--------C:\Documents and Settings\Casey\Application Data\TrojanHunter 2008-03-03 09:53 . 2008-03-03 09:53<DIR>d--------C:\Program Files\CCleaner 2008-03-03 09:52 . 2008-03-03 09:52<DIR>d--------C:\Program Files\TrojanHunter 5.0 2008-02-28 18:15 . 2008-02-28 18:15<DIR>d--------C:\Documents and Settings\Administrator\Application Data\teamspeak2 2008-02-26 23:40 . 2008-03-04 11:19<DIR>d--------C:\Documents and Settings\Casey\Application Data\AVG7 2008-02-26 23:40 . 2008-02-26 23:40110,592--a------C:\WINDOWS\system32\avgfwafu.dll 2008-02-26 23:39 . 2008-02-29 18:49<DIR>d--------C:\Documents and Settings\All Users\Application Data\avg7 2008-02-26 23:24 . 2008-02-26 23:24<DIR>d--------C:\Documents and Settings\Casey\Application Data\Grisoft 2008-02-26 23:24 . 2008-02-26 23:29<DIR>d--------C:\Documents and Settings\All Users\Application Data\Grisoft 2008-02-26 23:24 . 2007-05-30 04:1010,872--a------C:\WINDOWS\system32\drivers\AvgAsCln.sys 2008-02-26 16:32 . 2004-06-01 13:37<DIR>d--------C:\Documents and Settings\Administrator\WINDOWS 2008-02-26 16:32 . 2004-06-01 13:48<DIR>d--------C:\Documents and Settings\Administrator\Application Data\Symantec 2008-02-26 16:32 . 2004-06-01 15:08<DIR>d--------C:\Documents and Settings\Administrator\Application Data\CyberLink 2008-02-26 13:08 . 2008-02-26 13:22<DIR>d--------C:\Program Files\Antivirus Protection 2008-02-25 12:48 . 2008-02-25 20:23824--a------C:\WINDOWS\system32\svchost . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-03-04 19:1817,962----a-wC:\WINDOWS\system32\drivers\GVTDrv.sys 2008-03-03 22:50---------d-----wC:\Program Files\Common Files\Wise Installation Wizard 2008-03-03 17:54---------d-----wC:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-02-26 21:01---------d-----wC:\Program Files\Yahoo! 2008-02-26 20:57---------d-----wC:\Program Files\Game Elements 2008-02-26 20:56---------d-----wC:\Program Files\Half Life 2 2008-02-26 20:39---------d-----wC:\Program Files\Spybot - Search & Destroy 2008-02-05 09:01---------d-----wC:\Documents and Settings\Casey\Application Data\Skype 2008-01-30 20:39---------d-----wC:\Program Files\World of Warcraft 2008-01-16 02:45---------d-----wC:\Program Files\iTunes 2008-01-16 02:45---------d-----wC:\Program Files\iPod 2008-01-16 02:41---------d-----wC:\Program Files\QuickTime 2008-01-14 18:51---------d-----wC:\Program Files\Common Files\Adobe 2008-01-13 22:00---------d--h--wC:\Program Files\InstallShield Installation Information 2007-12-07 02:21824,832----a-wC:\WINDOWS\system32\wininet.dll 2007-12-04 18:38550,912----a-wC:\WINDOWS\system32\oleaut32.dll 2006-02-09 12:405,928----a-wC:\Documents and Settings\All Users\Application Data\ypinfo.bin . ------- Sigcheck ------- 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe -c----w 12,800 2003-03-31 12:00:00 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe -c----w 14,336 2004-08-04 07:56:57 C:\WINDOWS\ServicePackFiles\i386\svchost.exe ----a-w 14,336 2004-08-04 07:56:57 C:\WINDOWS\system32\svchost.exe b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\user32.dll -c--a-w 577,024 2005-03-02 18:19:56 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll ----a-w 578,048 2007-03-08 15:48:36 C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll -c----w 560,128 2003-09-25 16:49:02 C:\WINDOWS\$NtServicePackUninstall$\user32.dll -c----w 577,024 2004-08-04 07:56:46 C:\WINDOWS\$NtUninstallKB890859$\user32.dll -c----w 577,024 2005-03-02 18:09:30 C:\WINDOWS\$NtUninstallKB925902$\user32.dll -c----w 577,024 2004-08-04 07:56:46 C:\WINDOWS\ServicePackFiles\i386\user32.dll ----a-w 577,536 2007-03-08 15:36:28 C:\WINDOWS\system32\user32.dll -c----w 577,536 2007-03-08 15:36:28 C:\WINDOWS\system32\dllcache\user32.dll 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll -c----w 75,264 2003-03-31 12:00:00 C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll -c----w 82,944 2004-08-04 07:56:46 C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll ----a-w 82,944 2004-08-04 07:56:46 C:\WINDOWS\system32\ws2_32.dll 806d274c9a6c3aaea5eae8e4af841e04 C:\WINDOWS\system32\wininet.dll -c--a-w 656,896 2004-09-29 18:27:41 C:\WINDOWS\$hf_mig$\KB834707\SP2QFE\wininet.dll -c--a-w 657,920 2005-01-27 17:08:42 C:\WINDOWS\$hf_mig$\KB867282\SP2QFE\wininet.dll -c--a-w 658,944 2005-05-02 20:57:24 C:\WINDOWS\$hf_mig$\KB883939\SP2QFE\wininet.dll -c--a-w 657,920 2005-03-10 07:43:23 C:\WINDOWS\$hf_mig$\KB890923\SP2QFE\wininet.dll -c--a-w 660,480 2005-09-02 23:53:41 C:\WINDOWS\$hf_mig$\KB896688\SP2QFE\wininet.dll -c--a-w 659,456 2005-07-03 02:09:33 C:\WINDOWS\$hf_mig$\KB896727\SP2QFE\wininet.dll -c--a-w 661,504 2005-10-21 03:38:08 C:\WINDOWS\$hf_mig$\KB905915\SP2QFE\wininet.dll -c--a-w 663,552 2006-03-04 03:58:52 C:\WINDOWS\$hf_mig$\KB912812\SP2QFE\wininet.dll ----a-w 663,552 2006-05-10 05:25:22 C:\WINDOWS\$hf_mig$\KB916281\SP2QFE\wininet.dll ----a-w 664,576 2006-06-23 11:25:31 C:\WINDOWS\$hf_mig$\KB918899\SP2QFE\wininet.dll ----a-w 664,576 2006-09-14 08:31:30 C:\WINDOWS\$hf_mig$\KB922760\SP2QFE\wininet.dll ----a-w 664,576 2006-10-23 15:34:22 C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\wininet.dll ----a-w 823,296 2007-03-07 17:40:29 C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\wininet.dll ----a-w 823,808 2007-04-25 09:08:34 C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\wininet.dll ----a-w 824,320 2007-06-27 14:40:03 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll ----a-w 825,344 2007-08-20 10:02:11 C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll ----a-w 825,344 2007-10-10 23:47:29 C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll ----a-w 825,344 2007-12-07 02:01:13 C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll -c----w 588,288 2004-02-07 01:05:06 C:\WINDOWS\$NtServicePackUninstall$\wininet.dll -c----w 656,384 2004-08-04 07:56:46 C:\WINDOWS\$NtUninstallKB834707$\wininet.dll -c----w 656,896 2004-09-29 18:47:04 C:\WINDOWS\$NtUninstallKB867282$\wininet.dll -c----w 656,896 2005-03-10 08:02:35 C:\WINDOWS\$NtUninstallKB883939$\wininet.dll -c----w 656,896 2005-01-27 17:13:18 C:\WINDOWS\$NtUninstallKB890923$\wininet.dll -c----w 658,432 2005-07-03 02:11:30 C:\WINDOWS\$NtUninstallKB896688$\wininet.dll -c----w 657,920 2005-05-02 20:52:36 C:\WINDOWS\$NtUninstallKB896727$\wininet.dll -c----w 658,432 2005-09-02 23:52:06 C:\WINDOWS\$NtUninstallKB905915$\wininet.dll -c----w 658,432 2005-10-21 03:39:30 C:\WINDOWS\$NtUninstallKB912812$\wininet.dll -c----w 658,432 2006-03-04 03:33:45 C:\WINDOWS\$NtUninstallKB916281$\wininet.dll -c----w 658,432 2006-05-10 05:23:03 C:\WINDOWS\$NtUninstallKB918899$\wininet.dll -c----w 658,944 2006-06-23 11:02:52 C:\WINDOWS\$NtUninstallKB922760$\wininet.dll -c----w 658,944 2006-10-23 15:17:53 C:\WINDOWS\$NtUninstallKB925454$\wininet.dll -c----w 658,944 2006-09-14 08:39:55 C:\WINDOWS\$NtUninstallKB925454_0$\wininet.dll -c--a-w 664,576 2006-10-23 15:34:22 C:\WINDOWS\ie7\wininet.dll -c----w 818,688 2006-11-08 05:03:36 C:\WINDOWS\ie7updates\KB928090-IE7\wininet.dll -c----w 822,784 2007-01-12 17:27:42 C:\WINDOWS\ie7updates\KB931768-IE7\wininet.dll -c----w 822,784 2007-03-07 17:45:18 C:\WINDOWS\ie7updates\KB933566-IE7\wininet.dll -c----w 822,784 2007-04-25 08:41:17 C:\WINDOWS\ie7updates\KB937143-IE7\wininet.dll -c----w 823,808 2007-06-27 14:34:59 C:\WINDOWS\ie7updates\KB939653-IE7\wininet.dll -c----w 824,832 2007-08-20 10:04:43 C:\WINDOWS\ie7updates\KB942615-IE7\wininet.dll -c----w 824,832 2007-10-10 23:56:00 C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll -c----w 656,384 2004-08-04 07:56:46 C:\WINDOWS\ServicePackFiles\i386\wininet.dll ----a-w 824,832 2007-12-07 02:21:48 C:\WINDOWS\system32\wininet.dll -c--a-w 824,832 2007-12-07 02:21:48 C:\WINDOWS\system32\dllcache\wininet.dll 90caff4b094573449a0872a0f919b178 C:\WINDOWS\system32\drivers\tcpip.sys -c--a-w 359,936 2005-05-25 19:07:12 C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys -c--a-w 360,448 2006-01-13 17:07:08 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys ----a-w 360,576 2006-04-20 12:18:35 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys ----a-w 360,832 2007-10-30 16:53:32 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys -c----w 332,928 2003-03-31 12:00:00 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys -c----w 359,040 2004-08-04 06:14:40 C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys -c----w 359,808 2005-05-25 19:04:02 C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys -c----w 359,808 2006-01-13 02:28:14 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys -c----w 359,808 2006-04-20 11:51:50 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys -c----w 359,040 2004-08-04 06:14:40 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys -c----w 360,064 2007-10-30 17:20:55 C:\WINDOWS\system32\dllcache\tcpip.sys ----a-w 360,064 2007-10-30 17:20:55 C:\WINDOWS\system32\drivers\tcpip.sys 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe -c----w 516,608 2003-03-31 12:00:00 C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe -c----w 502,272 2004-08-04 07:56:57 C:\WINDOWS\ServicePackFiles\i386\winlogon.exe ----a-w 502,272 2004-08-04 07:56:57 C:\WINDOWS\system32\winlogon.exe 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys -c----w 167,552 2003-03-31 12:00:00 C:\WINDOWS\$NtServicePackUninstall$\ndis.sys -c----w 182,912 2004-08-04 06:14:28 C:\WINDOWS\ServicePackFiles\i386\ndis.sys ----a-w 182,912 2004-08-04 06:14:28 C:\WINDOWS\system32\drivers\ndis.sys 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys -c----w 29,056 2004-08-04 06:00:06 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys ------w 29,056 2004-08-04 06:00:06 C:\WINDOWS\system32\drivers\ip6fw.sys 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\system32\ntkrnlpa.exe -c--a-w 2,056,832 2005-03-02 00:36:40 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe ----a-w 2,059,392 2006-12-19 16:12:16 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe ----a-w 2,059,392 2007-02-28 09:15:56 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe -c----w 1,949,440 2003-04-24 15:57:54 C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe -c----w 2,056,832 2004-08-04 05:58:58 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe -c----w 2,056,832 2005-03-02 00:34:40 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe -c----w 2,057,600 2006-12-19 12:55:39 C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe ------w 2,057,600 2007-02-28 08:38:55 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe -c----w 2,056,832 2004-08-04 05:58:58 C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe ----a-w 2,057,600 2007-02-28 08:38:55 C:\WINDOWS\system32\ntkrnlpa.exe -c----w 2,057,600 2007-02-28 08:38:55 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\system32\ntoskrnl.exe -c--a-w 2,179,456 2005-03-02 01:04:22 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe ----a-w 2,182,016 2006-12-19 16:51:12 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe ----a-w 2,182,144 2007-02-28 09:55:14 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe -c----w 1,925,760 2003-04-24 15:57:50 C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe -c----w 2,180,992 2004-08-04 06:19:59 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe -c----w 2,179,328 2005-03-02 00:59:53 C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe -c----w 2,180,352 2006-12-19 14:17:19 C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe ------w 2,180,352 2007-02-28 09:10:57 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe -c----w 2,180,992 2004-08-04 06:19:59 C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe ----a-w 2,180,352 2007-02-28 09:10:57 C:\WINDOWS\system32\ntoskrnl.exe -c----w 2,180,352 2007-02-28 09:10:57 C:\WINDOWS\system32\dllcache\ntoskrnl.exe 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\explorer.exe ----a-w 1,033,216 2007-06-13 10:23:07 C:\WINDOWS\explorer.exe ----a-w 1,033,216 2007-06-13 11:26:03 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe -c----w 1,004,032 2003-03-31 12:00:00 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe -c----w 1,032,192 2004-08-04 07:56:49 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe ------w 1,032,192 2004-08-04 07:56:49 C:\WINDOWS\ServicePackFiles\i386\explorer.exe -c----w 1,033,216 2007-06-13 10:23:07 C:\WINDOWS\system32\dllcache\explorer.exe . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4BC3449-CC77-B4E6-1C0D-AE7B571CC0B1}] C:\DOCUME~1\Chip\APPLIC~1\CASTID~1\DoesFour.exe [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "sect hope"="C:\DOCUME~1\Casey\APPLIC~1\2TYPEM~1\GLOBAL PLATFORM.exe" [ ] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360] "Steam"="" [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "svvkshhzyek"="C:\WINDOWS\System32\bjhbsw.exe" [ ] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496] "satmat"="C:\WINDOWS\satmat.exe" [ ] "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 18:42 32768] "THIS MIX PLAN BAT"="C:\Documents and Settings\All Users\Application Data\settings new this mix\barb each.exe" [ ] "CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2005-12-15 09:05 230512] "CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2005-12-15 09:05 185456] "YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2005-04-22 19:49 397312] "PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2004-03-10 16:26 406016] "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 16:41 45056] "VGAUtil"="C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe" [2007-09-17 14:26 544768] "NWEReboot"="" [] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648] "DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 16:05 81920] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 03:10 55824 C:\WINDOWS\KHALMNPR.Exe] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25 6731312] "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-26 23:39 579072] "THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [2008-02-08 11:22 1047712] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-26 23:39 219136] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll 2007-11-15 10:10 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Event Planner Reminders Tray Icon.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Event Planner Reminders Tray Icon.lnk backup=C:\WINDOWS\pss\Event Planner Reminders Tray Icon.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
|
|
IP Logged |
|
|
|