ComboFix 08-05-25.3 - Luke 2008-05-27 13:06:11.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1625 [GMT -5:00]
Running from: C:\Documents and Settings\Luke\Desktop\Computer Problem\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((( Files Created from 2008-04-27 to 2008-05-27 )))))))))))))))))))))))))))))))
.
2008-05-26 23:00 . 2008-05-26 23:00 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-26 23:00 . 2008-05-26 23:00 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\InstallShield
2008-05-26 22:59 . 2007-11-27 22:51 35,216 --a------ C:\WINDOWS\system32\drivers\TMPassthru.sys
2008-05-26 17:42 . 2008-05-26 17:42 <DIR> d-------- C:\Program Files\winMd5Sum
2008-05-26 16:40 . 2008-05-26 16:40 <DIR> d-------- C:\VundoFix Backups
2008-05-26 11:10 . 2008-05-26 11:10 <DIR> d-------- C:\Snort
2008-05-24 22:56 . 2004-08-04 07:00 68,608 --a--c--- C:\WINDOWS\system32\dllcache\plugin.ocx
2008-05-24 17:09 . 2008-05-24 19:28 <DIR> d-------- C:\cygwin
2008-05-24 15:59 . 2008-05-24 15:59 98 --a------ C:\index.ini
2008-05-24 15:54 . 2008-05-24 15:54 <DIR> d-------- C:\Program Files\a-squared HiJackFree
2008-05-24 13:11 . 2008-05-24 13:11 <DIR> d-------- C:\Program Files\PrevxCSI
2008-05-24 13:11 . 2008-05-26 13:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-05-24 13:11 . 2008-05-24 13:11 17,408 --a------ C:\WINDOWS\system32\drivers\pxark.sys
2008-05-24 13:06 . 2008-05-24 13:06 <DIR> d-------- C:\Deckard
2008-05-23 23:10 . 2008-05-24 21:28 <DIR> d-------- C:\Program Files\Deep System Explorer
2008-05-20 16:10 . 2008-05-20 16:10 <DIR> d-------- C:\Program Files\Alwil Software
2008-05-20 16:07 . 2008-05-20 16:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-05-19 22:08 . 2008-05-19 22:08 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\Wireshark
2008-05-19 21:55 . 2008-05-19 21:57 <DIR> d-------- C:\Program Files\Wireshark
2008-05-18 22:56 . 2008-05-26 14:03 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-18 22:56 . 2008-05-18 22:56 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-18 22:56 . 2008-05-18 22:56 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\SUPERAntiSpyware.com
2008-05-18 22:56 . 2008-05-18 22:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-18 22:04 . 2008-05-18 22:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BOC426
2008-05-18 22:04 . 2008-03-28 09:17 212,728 --a------ C:\WINDOWS\CMDLIC.DLL
2008-05-18 22:04 . 2008-03-28 09:16 205,560 --a------ C:\WINDOWS\UNBOC.EXE
2008-05-18 22:04 . 2004-08-04 07:00 22,528 --a------ C:\WINDOWS\system32\wsock32.dlb
2008-05-18 22:04 . 2008-05-27 13:05 8,353 --a------ C:\WINDOWS\BOC426.INI
2008-05-18 19:37 . 2008-05-18 19:37 163 --a------ C:\WINDOWS\ieprxmon.ini
2008-05-18 19:35 . 2008-05-18 19:35 <DIR> d-------- C:\Program Files\Internet Explorer Proxy Monitor
2008-05-18 11:39 . 2008-05-18 11:39 <DIR> d-------- C:\Program Files\TypeFaster
2008-05-18 10:37 . 2008-05-18 10:41 <DIR> d-------- C:\Program Files\Robot Battle
2008-05-17 17:08 . 2008-05-17 17:08 139,008 --a------ C:\WINDOWS\system32\guard32.dll
2008-05-17 17:08 . 2008-05-17 17:08 87,312 --a------ C:\WINDOWS\system32\drivers\cmdguard.sys
2008-05-17 17:08 . 2008-05-17 17:08 23,824 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-05-17 16:50 . 2008-05-17 16:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-05-16 23:20 . 2008-05-17 10:41 <DIR> d-------- C:\Program Files\Hamachi(3)
2008-05-15 21:06 . 2008-05-17 10:41 <DIR> d-------- C:\Program Files\LithUnwrap
2008-05-15 15:30 . 2008-05-14 17:43 573,494 --a------ C:\Documents and Settings\Luke\md3toase.exe
2008-05-15 14:16 . 2008-05-17 10:41 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\Anvil Studio
2008-05-15 14:13 . 2008-05-17 10:41 <DIR> d-------- C:\Program Files\Anvil Studio
2008-05-14 17:37 . 2008-05-17 13:26 <DIR> d-------- C:\gmax
2008-05-13 15:12 . 2008-05-13 15:12 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\BSplayer Pro
2008-05-13 15:12 . 2008-05-13 15:20 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\BSplayer
2008-05-11 12:23 . 2008-05-11 12:23 <DIR> d-------- C:\WINDOWS\system32\FFSJ
2008-05-11 12:23 . 2008-05-11 12:23 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\FFSJ
2008-05-11 12:23 . 2008-05-11 12:23 704,793 --a------ C:\WINDOWS\unins000.exe
2008-05-11 12:23 . 2008-05-11 12:23 3,703 --a------ C:\WINDOWS\unins000.dat
2008-05-08 15:07 . 2008-05-08 15:11 <DIR> d-------- C:\Program Files\DreMule
2008-05-02 23:15 . 2008-05-02 23:15 <DIR> d-------- C:\Program Files\RayViewer 1.07
2008-05-02 15:36 . 2008-05-02 15:36 <DIR> d-------- C:\Program Files\Pixelformer
2008-05-02 09:31 . 2008-05-17 10:42 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\AVGTOOLBAR
2008-04-29 19:57 . 2008-04-29 19:57 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-27 18:04 --------- d-----w C:\Program Files\CallWave
2008-05-27 04:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-27 03:35 --------- d-----w C:\Documents and Settings\Luke\Application Data\.purple
2008-05-26 18:01 --------- d-----w C:\Program Files\Google
2008-05-25 04:50 --------- d-----w C:\Program Files\ViStart
2008-05-24 17:30 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-05-24 04:27 --------- d-----w C:\Program Files\Net Tools
2008-05-24 03:41 --------- d-----w C:\Program Files\e-Sword
2008-05-23 22:30 --------- d-----w C:\Documents and Settings\Luke\Application Data\gtk-2.0
2008-05-21 19:59 --------- d-----w C:\Documents and Settings\Luke\Application Data\Xfire
2008-05-20 02:56 --------- d-----w C:\Program Files\WinPcap
2008-05-19 03:04 --------- d-----w C:\Program Files\COMODO
2008-05-18 16:12 --------- d-----w C:\Program Files\Dictionary
2008-05-17 22:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Comodo
2008-05-17 22:08 --------- d-----w C:\Documents and Settings\Luke\Application Data\Comodo
2008-05-17 21:41 --------- d-----w C:\Program Files\eMule
2008-05-17 15:42 --------- d-----w C:\Documents and Settings\Luke\Application Data\Hamachi
2008-05-17 15:41 --------- d-----w C:\Program Files\Xfire
2008-05-17 04:00 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-05-13 21:50 --------- d-----w C:\Program Files\TrueTransparency
2008-05-12 21:23 --------- d-----w C:\Program Files\GameSpy Arcade
2008-05-12 19:38 --------- d-----w C:\Program Files\ePSXe160
2008-05-09 21:05 --------- d-----w C:\Program Files\ZModeler
2008-05-07 20:31 --------- d-----w C:\Program Files\Thoosje Sidebar V2.3
2008-05-03 17:43 --------- d-----w C:\Documents and Settings\Luke\Application Data\FileZilla
2008-04-29 15:28 --------- d-----w C:\Program Files\NT Registry Tweaker
2008-04-26 23:59 --------- d-----w C:\Program Files\Drempels
2008-04-26 18:18 --------- d-----w C:\Documents and Settings\Luke\Application Data\flightgear.org
2008-04-25 18:45 --------- d-----w C:\Program Files\FlightGear
2008-04-22 19:34 90 ----a-w C:\Program Files\ndkoptions.txt
2008-04-21 21:00 --------- d-----w C:\Program Files\Kyodai
2008-04-19 15:12 --------- d-----w C:\Program Files\Dydelf
2008-04-17 21:33 --------- d-----w C:\Documents and Settings\Luke\Application Data\Subversion
2008-04-17 16:59 --------- d-----w C:\Program Files\Dolphin
2008-04-17 04:56 --------- d-----w C:\Program Files\RootQuest
2008-04-17 02:00 --------- d-----w C:\Documents and Settings\Luke\Application Data\Atari
2008-04-17 01:59 --------- d-----w C:\Program Files\Common Files\PocketSoft
2008-04-17 01:59 --------- d-----w C:\Documents and Settings\Luke\Application Data\Leadertech
2008-04-17 01:57 --------- d-----w C:\Program Files\Atari
2008-04-16 19:56 --------- d-----w C:\Program Files\Paint.NET
2008-04-16 04:06 --------- d-----w C:\Documents and Settings\Luke\Application Data\fltk.org
2008-04-15 22:52 --------- d-----w C:\Program Files\Pidgin
2008-04-13 03:35 --------- d-----w C:\Program Files\Maxis
2008-04-13 03:00 --------- d-----w C:\Program Files\FRONTIER GROOVE
2008-04-12 03:55 --------- d-----w C:\Program Files\PSXMemTool
2008-04-09 20:24 --------- d-----w C:\Program Files\RingThree
2008-04-09 00:37 --------- d-----w C:\Program Files\Sherlock Software
2008-04-09 00:33 --------- d-----w C:\Program Files\PF.Magic
2008-04-08 20:06 --------- d-----w C:\Program Files\FTD.COM
2008-04-08 20:05 796,672 ----a-w C:\WINDOWS\GPInstall.exe
2008-04-07 19:27 --------- d-----w C:\Program Files\ScreenSaver.com
2008-04-07 18:50 --------- d-----w C:\Program Files\Kids 4 Truth International
2008-04-07 18:19 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-06 03:31 --------- d-----w C:\Program Files\Howie
2008-04-06 01:42 --------- d-----w C:\Program Files\iLReco the LEO IRC interface
2008-04-05 23:59 --------- d-----w C:\Program Files\AdiIRC
2008-04-04 21:13 --------- d-----w C:\Program Files\Deebot
2008-03-31 22:07 --------- d-----w C:\Program Files\Desktop Activity Recorder
2008-03-31 19:41 --------- d-----w C:\Program Files\ViRC
2008-03-28 19:02 --------- d-----w C:\Documents and Settings\Luke\Application Data\KVIrc
2008-03-28 01:38 --------- d-----w C:\Program Files\KVIrc
2008-03-27 21:50 --------- d-----w C:\Documents and Settings\Luke\Application Data\Winamp
2008-03-27 21:25 --------- d-----w C:\Program Files\Winamp
2008-03-27 20:02 --------- d-----w C:\Program Files\Acclaim Entertainment
2008-03-20 15:41 49,152 ----a-w C:\WINDOWS\system32\SysTrayDll.dll
2008-03-13 16:21 39,424 ----a-w C:\WINDOWS\zipinst.exe
2008-03-04 01:01 830,464 ----a-w C:\WINDOWS\system32\wininet.dll
2008-03-04 01:01 434,176 ----a-w C:\WINDOWS\system32\vbscript.dll
2008-03-04 01:01 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2008-03-04 01:01 142,848 ------w C:\WINDOWS\system32\IESetting.dll
2008-03-04 00:53 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2008-03-04 00:52 41,984 ----a-w C:\WINDOWS\system32\licmgr10.dll
2008-03-04 00:52 17,920 ----a-w C:\WINDOWS\system32\corpol.dll
2008-03-04 00:51 69,120 ----a-w C:\WINDOWS\system32\iesetup.dll
2008-03-04 00:51 69,120 ----a-w C:\WINDOWS\system32\admparse.dll
2008-03-04 00:50 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
2008-03-04 00:50 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2008-03-04 00:50 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2007-12-19 01:39 1,069,184 ----a-w C:\Documents and Settings\Luke\ivcon.exe
2007-11-25 19:46 40 ----a-w C:\Documents and Settings\Luke\language.dat
2007-11-09 00:58 1,396,736 ----a-w C:\WINDOWS\system32\config\systemprofile\NTUSER(2).DAT
2004-10-01 20:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2004-08-13 22:38 241,664 ----a-w C:\Documents and Settings\Luke\sniffit.exe
2002-07-29 19:40 155,648 ----a-w C:\Documents and Settings\Luke\ase2prm.exe
2002-04-12 16:29 29,184 ----a-w C:\Documents and Settings\Luke\rvshade.exe
2002-04-12 16:29 29,184 ----a-w C:\Documents and Settings\Luke\rvcolor.exe
2002-04-12 16:29 28,672 ----a-w C:\Documents and Settings\Luke\findump.exe
2002-04-12 16:29 28,160 ----a-w C:\Documents and Settings\Luke\rvweird.exe
2002-04-12 16:29 27,648 ----a-w C:\Documents and Settings\Luke\rvtrans.exe
2002-04-12 16:29 27,648 ----a-w C:\Documents and Settings\Luke\rvmark.exe
2002-04-12 16:29 27,648 ----a-w C:\Documents and Settings\Luke\rvcenter.exe
2000-02-16 16:03 14,552 ----a-w C:\Documents and Settings\Luke\RV-DBLSD.EXE
2000-01-17 16:50 31,365 ----a-w C:\Documents and Settings\Luke\RV-SIZER.EXE
1999-12-15 22:00 19,311 ----a-w C:\Documents and Settings\Luke\RV-REMAP.EXE
1999-11-25 18:21 40,960 ----a-w C:\Documents and Settings\Luke\PRM2NCP.EXE
1997-06-09 11:27 36,864 ----a-w C:\Documents and Settings\Luke\TMD2LWO.EXE
2006-05-03 09:06 163,328 --sha-r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sha-r C:\WINDOWS\system32\msfDX.dll
.
------- Sigcheck -------
2005-03-01 19:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2007-02-28 04:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2007-02-28 03:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\sp2gdr\ntkrnlpa.exe
2005-03-01 19:34 2056832 81013f36b21c7f72cf784cc6731e0002 C:\WINDOWS\SoftwareDistribution\Download\dc3b8fb011c281dea1cb7a45f880da78\sp2gdr\ntkrnlpa.exe
2004-08-04 07:00 2068608 471aeecdb0937bd3617f52772250251a C:\WINDOWS\system32\ntkrnlpa.exe
2004-08-04 07:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2004-08-04 07:00 2068608 471aeecdb0937bd3617f52772250251a C:\WINDOWS\system32\VIRepair\ntkrnlpa.exe
2004-08-04 07:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\system32\VITrans\ntkrnlpa.exe
2005-03-01 20:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2007-02-28 04:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2007-02-28 04:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\sp2gdr\ntoskrnl.exe
2005-03-01 19:59 2179328 4d4cf2c14550a4b7718e94a6e581856e C:\WINDOWS\SoftwareDistribution\Download\dc3b8fb011c281dea1cb7a45f880da78\sp2gdr\ntoskrnl.exe
2004-08-04 07:00 2192768 cd20e140a91dea9564a89ba430b04b68 C:\WINDOWS\system32\ntoskrnl.exe
2004-08-04 07:00 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2004-08-04 07:00 2192768 cd20e140a91dea9564a89ba430b04b68 C:\WINDOWS\system32\VIRepair\ntoskrnl.exe
2004-08-04 07:00 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\system32\VITrans\ntoskrnl.exe
2004-08-04 07:00 1422336 4b0011b8e35843966a3ce5685058420f C:\WINDOWS\explorer.exe
2007-06-13 06:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 05:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2gdr\explorer.exe
2004-08-04 07:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\system32\dllcache\explorer.exe
2004-08-04 07:00 1422336 4b0011b8e35843966a3ce5685058420f C:\WINDOWS\system32\VIRepair\explorer.exe
2004-08-04 07:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\system32\VITrans\explorer.exe
.
((((((((((((((((((((((((((((( snapshot[at]2008-05-25_20.05.59.65 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-26 00:59:40 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-27 18:03:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-27 18:04:10 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_584.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-04-01 16:16 5562368]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-05-17 17:08 1572608]
"BOC-426"="C:\PROGRA~1\Comodo\CBOClean\BOC426.exe" [2008-04-10 11:08 351480]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 18:19 79224]
"TMRUBottedTray"="C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe" [2007-12-19 00:18 288088]
C:\Documents and Settings\Luke\Start Menu\Programs\Startup\
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [2008-03-14 18:00:46 546816]
NYKO Gamepad Mapping Tools.lnk - C:\Program Files\NYKO\Gamepad Mapping Tools\ngpmap.exe [2007-10-29 20:03:49 416768]
WordWeb.lnk - C:\Program Files\WordWeb\wweb32.exe [2007-11-01 19:55:04 19968]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
CallWave.lnk - C:\Program Files\CallWave\IAM.exe [2007-10-28 23:01:58 1590352]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):76,69,73,74,61,75,69,2e,65,78,65,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\uniime32]
uniime32.dll 2004-05-14 13:01 10752 C:\WINDOWS\system32\uniime32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll
"msacm.ac3filter"= ac3filter.acm
"msacm.divxa32"= divxa32.acm
"msvideo3"= STVqx3tg.dll
"vidc.mpng"= C:\Program Files\t[at]b\
0.958\686\tabdec.dll
"vidc.mvjp"= C:\Program Files\t[at]b\
0.958\686\tabdec.dll
"vidc.444p"= C:\Program Files\t[at]b\
0.958\686\tabdec.dll
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Luke^Start Menu^Programs^Startup^Drempels Desktop.lnk]
path=C:\Documents and Settings\Luke\Start Menu\Programs\Startup\Drempels Desktop.lnk
backup=C:\WINDOWS\pss\Drempels Desktop.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LClock]
--a------ 2004-09-20 01:27 65536 C:\Program Files\LClock\LClock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
--a------ 2007-11-23 22:24 249856 C:\Program Files\lg_fwupdate\fwupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2005-04-01 16:16 86016 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-10-29 21:21 77824 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-ra------ 2005-08-17 05:39 90112 C:\WINDOWS\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-10-29 14:49 77824 C:\Program Files\Java\jre1.6.0\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vista Sidebar]
--a------ 2007-11-20 13:51 524288 C:\Program Files\Vista Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Maya5PLEHelpServer"=3 (0x3)
"WZCSVC"=2 (0x2)
"SCardSvr"=3 (0x3)
"aspnet_state"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"True Transparency"=C:\Program Files\TrueTransparency\TrueTransparency.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"nwiz"=nwiz.exe /install
"SoundMan"=SOUNDMAN.EXE
"WinFast Schedule"=C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Pidgin\\pidgin.exe"=
"C:\\Program Files\\K'NEX\\game.exe"=
"C:\\Program Files\\Hasbro\\Boggle\\Boggle.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\CallWave\\IAM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1317:TCP"= 1317:TCP:messenger
R0 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2008-05-24 13:11]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 18:20]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-05-17 17:08]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-05-17 17:08]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 18:16]
R2 BT848;WinFast TV2000 XP WDM Video Capture;C:\WINDOWS\system32\drivers\wf2kvcap.sys [2006-04-20 14:50]
R2 CSIScanner;CSIScanner;"C:\Program Files\PrevxCSI\prevxcsi.exe" /service []
R2 Pctspk;PCTEL Speaker Phone;C:\WINDOWS\system32\pctspk.exe [2001-08-17 17:36]
R2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;C:\WINDOWS\system32\drivers\wf2ktunr.sys [2006-04-20 15:20]
R2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;C:\WINDOWS\system32\drivers\wf2kxbar.sys [2006-04-20 14:49]
R3 Ptserlp;PCTEL Serial Device Driver for PCI;C:\WINDOWS\system32\DRIVERS\ptserlp.sys [2001-08-17 08:28]
R3 STVqx3;Intel Play QX3 Microscope;C:\WINDOWS\system32\drivers\STVqx3.sys [2001-04-12 14:04]
R3 TMPassthruMP;TMPassthruMP;C:\WINDOWS\system32\DRIVERS\TMPassthru.sys [2007-11-27 22:51]
S1 HekkoVirtualCD;Hekko Virtual CD Driver;C:\WINDOWS\system32\Drivers\hvcd.sys []
S2 RUBotted;Trend Micro RUBotted Service;"C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe" [2007-12-19 00:18]
S3 DarkSpy;DarkSpy;C:\WINDOWS\system32\DarkSpyKernel.sys []
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 15:22]
S3 TMPassthru;Trend Micro Passthru Ndis Service;C:\WINDOWS\system32\DRIVERS\TMPassthru.sys [2007-11-27 22:51]
S3 WFIOCTL;WFIOCTL;C:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS [2005-01-06 16:55]
S4 Maya5PLEHelpServer;Alias Maya 5.0 PLE Help Server;"C:\Program Files\AliasWavefront\Maya 5.0 Personal Learning Edition\docs\Wrapper.exe" -s "C:\Program Files\AliasWavefront\Maya 5.0 Personal Learning Edition\docs/Wrapper.conf" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Z]
\Shell\AutoRun\command - Z:\.\Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5c39b5dd-85d0-11dc-a05d-ac4146196c01}]
\Shell\AutoRun\command - H:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eab94e0c-8595-11dc-a19d-806d6172696f}]
\Shell\AutoRun\command - E:\start.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-27 13:08:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\C:\DOCUME~1\Luke\LOCALS~1\Temp\ASFWHide"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\guard32.dll
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\guard32.dll
.
Completion time: 2008-05-27 13:10:21
ComboFix-quarantined-files.txt 2008-05-27 18:10:16
ComboFix2.txt 2008-05-26 01:06:13
Pre-Run: 259,261,153,280 bytes free
Post-Run: 259,248,238,592 bytes free
335 --- E O F --- 2008-03-31 04:04:00
I'm following a long with the malware hacking pdf for now. I think I may be able to unpack the UPX file and view the source. If possible we can get a better understanding on what it infects and how to repair it.
RUBotted, of course, turned up nothing. But it says it's monitoring my network for changes so we will wait and see. Also, I was unable to install it the first time I tried (I was online) it said unable to finish "process terminated", once I got offline I was able to install it. My guess is the guy on the tunnel didn't want me to have it.