ComboFix 08-02-25.2 - Owner 2008-02-24 19:28:30.3 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
FILE ::
C:\WINDOWS\system32\D4988260E1.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\D4988260E1.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-25 to 2008-02-25 )))))))))))))))))))))))))))))))
.
2008-02-24 10:14 . 2008-02-24 10:14 <DIR> d-------- C:\Program Files\Defraggler
2008-02-23 10:23 . 2008-02-23 10:36 <DIR> d-------- C:\Program Files\Creatrix
2008-02-18 20:27 . 2008-02-18 20:27 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-18 20:27 . 2008-02-18 20:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-18 19:44 . 2008-02-18 19:44 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-18 19:17 . 2008-02-22 17:48 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-18 19:17 . 2008-02-18 19:17 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-31 21:14 . 2008-01-31 21:14 <DIR> d-------- C:\Program Files\LimeWire
2008-01-31 19:13 . 2008-01-31 21:03 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-01-30 20:01 . 2005-08-27 02:38 1,435,272 --a------ C:\WINDOWS\system32\Flash.ocx
2008-01-30 20:01 . 2003-11-19 14:59 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2008-01-30 20:01 . 2004-05-11 10:56 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2008-01-30 20:01 . 2004-02-05 21:53 389,120 --a------ C:\WINDOWS\system32\ACTSKN43.OCX
2008-01-30 20:01 . 2004-01-09 11:54 188,416 --a------ C:\WINDOWS\system32\actsplash.ocx
2008-01-30 20:01 . 2004-03-09 00:00 131,856 --a------ C:\WINDOWS\system32\MSADODC.ocx
2008-01-30 20:01 . 2001-03-28 23:02 89,088 --a------ C:\WINDOWS\system32\ProgressBar4.ocx
2008-01-30 20:01 . 1999-01-26 19:36 11,012 --a------ C:\WINDOWS\system32\threadapi.tlb
2008-01-27 18:03 . 2008-01-27 18:03 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Eyeblaster
2008-01-27 18:02 . 2008-01-27 18:02 <DIR> d-------- C:\My Games
2008-01-27 18:02 . 2008-01-27 18:02 <DIR> d-------- C:\My Download Files
2008-01-27 18:01 . 2008-01-27 18:01 774,144 --a------ C:\Program Files\RngInterstitial.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 23:31 --------- d-----w C:\Documents and Settings\Owner\Application Data\Audacity
2008-02-24 23:30 --------- d-----w C:\Documents and Settings\Owner\Application Data\MSN6
2008-02-24 08:11 --------- d-----w C:\Program Files\Audacity 1.3 Beta (Unicode)
2008-02-24 03:11 --------- d-----w C:\Program Files\REAPER
2008-02-20 03:35 --------- d-----w C:\Program Files\Trend Micro
2008-02-18 00:39 --------- d-----w C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-02-18 00:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-02-01 03:58 --------- d-----w C:\Program Files\DigiTech
2008-02-01 02:11 --------- d-----w C:\Documents and Settings\Owner\Application Data\REAPER
2008-01-28 02:07 --------- d-----w C:\Program Files\Real
2008-01-28 02:07 --------- d-----w C:\Program Files\Common Files\Real
2008-01-20 19:40 --------- d-----w C:\Documents and Settings\Owner\Application Data\Sports Stats 2.0
2008-01-20 19:39 --------- d-----w C:\Program Files\NCH Swift Sound
2008-01-20 19:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-01-14 17:27 --------- d-----w C:\Program Files\BrowsingAdvisor
2008-01-14 00:22 --------- d-----w C:\Documents and Settings\Owner\Application Data\NCH Swift Sound
2008-01-12 03:53 --------- d-----w C:\Program Files\PlayMP3z
2008-01-03 04:04 --------- d-----w C:\Program Files\Microsoft Games
2008-01-03 03:18 --------- d-----w C:\Program Files\MSN Games
2007-12-31 21:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-31 00:31 --------- d-----w C:\Program Files\GameSpy Arcade
2007-12-31 00:02 --------- d-----w C:\Program Files\EA GAMES
2007-12-30 22:33 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-12-28 05:37 --------- d-----w C:\Program Files\Common Files\EasyInfo
2007-12-14 19:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-12-04 04:36 368,640 ----a-w C:\WINDOWS\system32\ReWire.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 11:00 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 06:47 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 06:47 688218]
"SMSERIAL"="sm56hlpr.exe" [2006-01-11 09:22 544768 C:\WINDOWS\sm56hlpr.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2005-12-26 17:20 413696 C:\WINDOWS\stsystra.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 02:01 32768]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 11:17 94208]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 11:17 118784]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 11:13 77824]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 11:30 139264]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-11-11 20:40 1236992]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-06-18 16:19 98304]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" []
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 17:17 443968]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2006-06-18 16:14:20 2168360]
Windows Desktop Search.lnk - C:\Program Files\MSN Toolbar Suite\DS\[u]0[/u]2.05.0001.1119\en-us\bin\WindowsSearch.exe [2005-09-20 17:10:04 238080]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-24 10:17:02 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-24 19:30:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-24 19:31:27
ComboFix-quarantined-files.txt 2008-02-25 03:31:09
ComboFix2.txt 2008-02-22 00:24:17
.
2008-02-21 23:37:34 --- E O F ---