ComboFix 08-10-06.03 - Administrator 10/08/2008 2:43:27.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1256.1.1033.18.1458 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\inst.exe
C:\WINDOWS\system32\msssc.dll
C:\WINDOWS\system32\vfolx32n.dll
.
((((((((((((((((((((((((( Files Created from 2008-09-07 to 2008-10-07 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-07 23:56 96,170,016 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-07 23:54 --------- d-----w C:\Documents and Settings\Administrator\Application Data\SlipStream
2008-10-07 23:53 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DMCache
2008-10-07 23:49 1,127,552 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-07 23:28 --------- d-----w C:\Program Files\2D and 3D Animator
2008-10-07 23:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\PY_Software
2008-10-07 22:20 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-07 22:18 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2008-10-07 21:38 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Thinstall
2008-10-07 19:44 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-10-07 19:44 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ACD Systems
2008-10-07 19:43 --------- d-----w C:\Program Files\ACD Systems
2008-10-07 19:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-10-07 19:22 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Vso
2008-10-07 17:56 --------- d-----w C:\Program Files\ONSPEED
2008-10-07 17:42 --------- d-----w C:\Program Files\DVDFab 5
2008-10-07 17:29 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Screaming Bee
2008-10-07 17:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Screaming Bee
2008-10-07 17:23 --------- d-----w C:\Program Files\Screaming Bee
2008-10-07 17:23 --------- d-----w C:\Program Files\Common Files\Screaming Bee
2008-10-07 17:19 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-10-07 17:19 47,360 ----a-w C:\Documents and Settings\Administrator\Application Data\pcouffin.sys
2008-10-07 14:03 --------- d-----w C:\Program Files\REALTEK RTL8187 Wireless LAN Driver and Utility
2008-10-07 05:44 --------- d-----w C:\Program Files\AV Vcs 6.0 DIAMOND
2008-10-07 03:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-10-07 02:20 --------- d-----w C:\Documents and Settings\Administrator\Application Data\EBookSys
2008-10-07 01:35 --------- d-----w C:\Program Files\Enter the Internet Registry
2008-10-07 00:54 --------- d-----w C:\Program Files\CCleaner
2008-10-06 22:15 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-10-06 22:15 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-10-06 22:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-06 21:36 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Naviscope
2008-10-06 21:35 --------- d-----w C:\Program Files\Naviscope
2008-10-06 20:13 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InterVideo
2008-10-06 19:40 --------- d-----w C:\Program Files\GifCreator
2008-10-06 19:40 --------- d-----w C:\Program Files\Common Files\Xuisoft
2008-10-06 19:01 --------- d-----w C:\Program Files\AD Sound Recorder
2008-10-06 18:32 --------- d-----w C:\Program Files\XP Codec Pack
2008-10-06 15:46 --------- d-----w C:\Program Files\ma-config.com
2008-10-06 15:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-10-06 04:10 --------- d-----w C:\Program Files\Windows Defender
2008-10-05 20:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
2008-10-05 20:04 --------- d-----w C:\Program Files\bfgclient
2008-10-05 19:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\hpqwmi
2008-10-05 19:27 --------- d-----w C:\Program Files\InterVideo
2008-10-05 18:09 --------- d-----w C:\Documents and Settings\Administrator\Application Data\USBSafelyRemove
2008-10-05 16:00 --------- d-----w C:\Program Files\E-Book Systems
2008-10-05 04:59 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-10-05 04:54 --------- d-----w C:\Program Files\GetSmile
2008-10-05 04:54 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Sofrayt
2008-10-05 04:43 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-10-05 03:36 --------- d-----w C:\Documents and Settings\Administrator\Application Data\zweitgeist
2008-10-05 01:59 --------- d-----w C:\Program Files\DivX
2008-10-05 01:59 --------- d-----w C:\Program Files\Amadis Software
2008-10-05 01:47 --------- d-----w C:\Documents and Settings\Administrator.HOME-C99DA1934D\Application Data\BitDefender
2008-10-05 01:37 --------- d-----w C:\Documents and Settings\Administrator.HOME-C99DA1934D\Application Data\Thinstall
2008-10-05 00:55 --------- d-----w C:\Program Files\msaccrt
2008-10-04 23:53 --------- d-----w C:\Program Files\Serious Magic
2008-10-04 23:53 --------- d-----w C:\Program Files\Common Files\Serious Magic
2008-10-04 23:40 --------- d-----w C:\Program Files\Mediator 7 Std
2008-10-04 23:18 --------- d-----w C:\Program Files\NetWaiting
2008-10-04 18:31 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-10-04 18:31 --------- d-----w C:\Program Files\Boilsoft Video Joiner
2008-10-04 18:29 --------- d-----w C:\Program Files\Spyware Doctor
2008-10-04 16:22 --------- d-----w C:\Program Files\MSBuild
2008-10-04 16:20 --------- d-----w C:\Program Files\Reference Assemblies
2008-10-04 14:31 --------- d-----w C:\Program Files\FLVPlayer4Free
2008-10-04 14:31 --------- d-----w C:\Documents and Settings\Administrator.HOME-C99DA1934D\Application Data\FLVPlayer4Free
2008-10-03 17:27 --------- d-----w C:\Program Files\Your Uninstaller 2008
2008-10-03 16:19 103,944 ------w C:\WINDOWS\system32\drivers\bdfndisf.sys
2008-10-03 16:03 --------- d-----w C:\Program Files\Blackstar
2008-10-03 05:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\BitDefender
2008-10-03 04:58 --------- d-----w C:\Program Files\Common Files\BitDefender
2008-10-03 04:58 --------- d-----w C:\Program Files\BitDefender
2008-10-03 04:58 --------- d-----w C:\Documents and Settings\Administrator\Application Data\BitDefender
2008-10-03 04:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-10-03 04:14 --------- d-----w C:\Program Files\Java
2008-10-02 06:45 --------- d-----w C:\Program Files\Abadisoft
2008-10-01 18:13 --------- d-----w C:\Documents and Settings\Administrator\Application Data\CyberScrub
2008-10-01 18:13 --------- d-----w C:\Documents and Settings\Administrator\Application Data\cleaner
2008-10-01 13:23 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ArcSoft
2008-10-01 08:13 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-09-30 09:25 --------- d-----w C:\Program Files\USB Disk Security
2008-09-29 09:06 --------- d-----w C:\Program Files\Microsoft Works
2008-09-29 09:05 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-09-29 08:51 --------- d-----w C:\Program Files\TaskSwitchXP
2008-09-29 08:51 --------- d-----w C:\Program Files\MSN Messenger
2008-09-29 02:28 --------- d-----w C:\Program Files\Windows Live
2008-09-28 15:08 --------- d-----w C:\Program Files\Reshade
2008-09-27 12:22 --------- d-----w C:\Documents and Settings\LocalService\Application Data\IEPro
2008-09-27 11:15 --------- d-----w C:\Program Files\ShiningMorning
2008-09-27 03:29 --------- d-----w C:\Program Files\Internet Download Manager
2008-09-27 02:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-27 02:09 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-27 01:10 --------- d-----w C:\Program Files\Total Video Converter
2008-09-27 01:00 --------- d-----w C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-09-26 21:50 --------- d-----w C:\Program Files\Windows Doctor
2008-09-26 21:35 --------- d-----w C:\Program Files\File Recover
2008-09-26 11:49 --------- d-----w C:\Program Files\Extra DVD Copy
2008-09-26 11:48 81,920 ----a-w C:\Documents and Settings\Administrator\Application Data\ezpinst.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATI Launchpad"="C:\Program Files\ATI Multimedia\main\launchpd.exe" [11/05/2004 04:16 AM 106573]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 03:12 AM 15360]
"IDMan"="C:\program files\Internet Download Manager\IDMan.exe" [09/26/2008 06:10 AM 2606512]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 09:34 PM 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [07/12/2007 02:00 PM 132496]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [11/03/2004 08:10 PM 344064]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [10/05/2008 04:34 AM 185872]
"SlipStream"="C:\Program Files\ONSPEED\onspeedcore.exe" [10/19/2007 05:50 AM 344064]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
naviscope.lnk - C:\Program Files\Naviscope\naviscope.exe [2008-10-07 1277440]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ONSPEED.lnk - C:\Program Files\ONSPEED\onspeedgui.exe [2008-10-07 229376]
REALTEK RTL8187 Wireless LAN Utility.lnk - C:\Program Files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe [2008-10-07 737280]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-04-03 415072]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"VIDC.YU12"= ATIYUV12.DLL
"VIDC.FFDS"= ffdshow.ax
"msacm.ac3filter"= ac3filter.acm
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^naviscope.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\naviscope.lnk
backup=C:\WINDOWS\pss\naviscope.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]
--a------ 11/05/2004 04:16 AM 106573 C:\Program Files\ATI Multimedia\main\LaunchPd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 11/03/2004 08:10 PM 344064 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 04/14/2008 03:12 AM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 09/26/2008 06:10 AM 2606512 C:\Program Files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 10/18/2007 09:34 PM 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 09/21/2008 02:32 PM 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TaskSwitchXP]
--a------ 08/05/2006 01:29 AM 62976 C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 10/05/2008 04:34 AM 185872 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\REALTEK RTL8187 Wireless LAN Driver and Utility\\RtWLan.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Naviscope\\naviscope.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\K-Lite Codec Pack\\Filters\\ac3config.exe"=
"C:\\Documents and Settings\\Administrator\\My Documents\\skype.exe"=
R0 mcctl;mcctl;C:\WINDOWS\system32\drivers\mcctl.sys [05/15/2006 09:19 AM 4864]
R1 is-4H38Adrv;is-4H38Adrv;C:\WINDOWS\system32\DRIVERS\51341924.sys [07/09/2008 12:54 AM 148496]
R2 BDVEDISK;BDVEDISK;C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys [07/02/2008 12:07 PM 82568]
R2 CAMTHWDM;WebcamMax, WDM Video Capture;C:\WINDOWS\system32\DRIVERS\CAMTHWDM.sys [03/11/2008 04:14 PM 941784]
R2 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [09/02/2008 04:14 PM 191656]
R2 thdudf;TOSHIBA UDF2.5 Reader File System Driver;C:\WINDOWS\system32\DRIVERS\thdudf.sys [11/11/2006 12:25 PM 66944]
R3 bdfm;BDFM;C:\WINDOWS\system32\drivers\bdfm.sys [08/13/2008 04:40 AM 108864]
R3 dalwdmservice;dal service;C:\WINDOWS\system32\drivers\dalwdm.sys [03/31/2004 09:00 AM 73216]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys [09/26/2006 11:21 PM 21920]
S0 ipzesxf;ipzesxf;C:\WINDOWS\system32\drivers\vmjohpv.sys [ ]
S3 Arrakis3;BitDefender Arrakis Server;C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [07/17/2008 12:06 PM 118784]
S3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [10/03/2008 07:19 PM 103944]
S3 mcdevice;mcdevice;C:\WINDOWS\system32\DRIVERS\mcdevice.sys [05/19/2006 08:20 PM 27648]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [01/11/2007 01:20 PM 194304]
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [10/02/2002 09:57 AM 13532]
S3 SKYNET;TechniSat DVB-PC TV Star PCI;C:\WINDOWS\system32\DRIVERS\SkyNET.SYS [03/14/2006 04:22 AM 349184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
s of the 'Scheduled Tasks' folder
2008-10-07 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [11/03/2006 07:20 PM]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKLM-Run-Device Detector - DevDetect.exe
Notify-NavLogon - (no file)
MSConfigStartUp-ccApp - C:\Program Files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-vptray - C:\PROGRA~1\SYMANT~1\VPTray.exe
.
------- Supplementary Scan -------
.
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://go.compaq.com/1Q00CDT/0409/bl7.asp
R1 -: HKCU-Internet Settings,ProxyServer = http=127.0.0.1:5405;ftp=127.0.0.1:5405;https=127.0.0.1:5405;socks=127.0.0.1:5405
R1 -: HKCU-Internet Settings,ProxyOverride = <local>;127.0.0.1:5405;*update.microsoft.com;*windowsupdate.com;download.microsoft.com;codecs.microsoft.com;activex.microsoft.com;liveupdate.symantecliveupdate.com;download.mcafee.com;*.phobos.apple.com;update.adobe.com;*.networkassociates.com;*.nai.com;service1.symantec.com;*.f863.mail.yahoo.com;*.apple.com.edgesuite.net;idisk.apple.com;*.hotmail.com;*.hotmail.msn.com;sitebuilder.wanadoo.co.uk;*.car4rental.com;10.*;192.*;172.*;*.mysite.wanadoo-members.co.uk;mysite.orange.co.uk;*.mysite.orange.co.uk;update.microsoft.com;windowsupdate.microsoft.com;stats.microsoft.com;c.microsoft.com;*.mysite.wanadoo-members.co.uk;mysite.orange.co.uk;*.mysite.orange.co.uk;*.symantec.com;download.onspeed.com;*windowsupdate.microsoft.com;liveupdate.symantec.com;click2service.tele2.se;*.click2service.tele2.se;*.microsoft.com;wanadoo-members.co.uk/sitename;sitename.mysite.wanadoo-members.co.uk;mysite.orange.co.uk/sitename;sitename.mysite.orange.co.uk;mail.tesco.net;mail.live.com;*.mail.yahoo.com;*.update.microsoft.com;swupdate.apple.com;wsidecar.apple.com;appldnld.apple.com.edgesuite.net;*.bbt.yahoo.co.jp;webmail.tugab.bg;localhost
O8 -: Download all links with IDM - C:\program files\Internet Download Manager\IEGetAll.htm
O8 -: Download FLV video with IDM - C:\program files\Internet Download Manager\IEGetVL.htm
O8 -: Download with IDM - C:\program files\Internet Download Manager\IEExt.htm
O8 -: Show All Original Images - C:\Program Files\ONSPEED\gui_resource.dll/327
O8 -: Show Original Image - C:\Program Files\ONSPEED\gui_resource.dll/328
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_3_1.cab
C:\WINDOWS\Downloaded Program Files\hardwaredetection.inf
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-10-08 02:52:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 10/08/2008 2:59:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-07 23:59:04
Pre-Run: 55,648,821,248 bytes free
Post-Run: 55,594,098,688 bytes free
257 --- E O F --- 2008-10-06 22:32:58