ComboFix 07-12-21.4 - Halcomb 2007-12-20 19:38:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.490 [GMT -5:00]
Running from: C:\Documents and Settings\Halcomb\Desktop\ComboFix.exe
* Created a new restore point
.
The following files were disabled during the run:
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Halcomb\Application Data\macromedia\Flash Player\#SharedObjects\MR9U69DM\
www.broadcaster.com
C:\Documents and Settings\Halcomb\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
www.broadcaster.com
C:\Documents and Settings\Halcomb\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
www.broadcaster.com\settings.sol
C:\WINDOWS\cookies.ini
C:\WINDOWS\setup.exe
C:\WINDOWS\system32\gebxvsr.dll
C:\WINDOWS\system32\sstts.dll
C:\WINDOWS\system32\sttss.ini
C:\WINDOWS\system32\sttss.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-11-21 to 2007-12-21 )))))))))))))))))))))))))))))))
.
2007-12-20 03:50 . 2007-12-20 03:50 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-12-19 23:36 . 2007-12-20 03:46 <DIR> d-------- C:\hjt
2007-12-19 22:07 . 2007-12-19 22:07 <DIR> d-------- C:\bintheredunthat
2007-12-19 21:44 . 2007-12-19 21:44 <DIR> d-------- C:\bfu
2007-12-19 15:15 . 2007-12-19 15:15 <DIR> d-------- C:\Documents and Settings\Halcomb\Application Data\Grisoft
2007-12-19 14:09 . 2007-12-19 14:09 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2007-12-19 14:04 . 2007-12-19 14:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-19 14:04 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-19 14:02 . 2007-12-19 14:02 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2007-12-19 14:02 . 2007-12-10 19:47 163,640 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2007-12-19 14:02 . 2007-12-10 19:47 23,864 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2007-12-19 14:02 . 2007-12-10 19:47 21,816 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2007-12-19 14:02 . 2007-12-10 19:47 20,280 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2007-12-19 14:01 . 2007-12-19 14:01 <DIR> d-------- C:\Program Files\Webroot
2007-12-19 14:01 . 2007-12-19 14:01 <DIR> d-------- C:\Documents and Settings\Halcomb\Application Data\Webroot
2007-12-19 14:01 . 2007-12-19 14:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2007-12-19 14:01 . 2007-12-10 20:08 1,526,584 --a------ C:\WINDOWS\WRSetup.dll
2007-12-19 14:00 . 2007-12-19 14:00 164 --a------ C:\install.dat
2007-12-19 13:56 . 2007-12-19 22:00 <DIR> d-------- C:\VundoFix Backups
2007-12-19 13:49 . 2007-12-19 13:49 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2007-12-19 13:46 . 2006-10-17 12:31 66,048 --a------ C:\WINDOWS\ieResetIcons.exe
2007-12-18 03:06 . 2007-12-19 01:35 986,094 --ahs---- C:\WINDOWS\system32\rrgxvqtc.ini
2007-12-17 12:42 . 2007-12-18 03:00 970,958 --ahs---- C:\WINDOWS\system32\tjwonivn.ini
2007-12-17 12:27 . 2007-12-19 01:25 <DIR> d-------- C:\Program Files\Winamp Remote
2007-12-17 12:27 . 2007-12-17 12:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\OrbNetworks
2007-12-17 12:26 . 2007-12-17 12:30 <DIR> d-------- C:\Program Files\Winamp
2007-12-17 12:26 . 2007-12-17 12:46 <DIR> d-------- C:\Documents and Settings\Halcomb\Application Data\Winamp
2007-12-17 12:26 . 2007-03-07 18:51 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2007-12-17 01:06 . 2007-12-17 01:10 1,056 -r-hs---- C:\WINDOWS\PCGWIN32.LI4
2007-12-17 00:31 . 2007-12-19 02:00 3,546 --a------ C:\WINDOWS\system32\tmp.reg
2007-12-17 00:30 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-12-17 00:30 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-12-17 00:30 . 2007-12-13 19:40 77,824 --a------ C:\WINDOWS\system32\IEDFix.exe
2007-12-17 00:30 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-12-17 00:30 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-12-02 12:20 . 2007-12-02 12:21 <DIR> d-------- C:\Program Files\Project64 1.6
2007-11-22 02:08 . 2007-11-22 02:43 <DIR> d-------- C:\Program Files\wgens170
2007-11-22 02:07 . 2007-11-22 02:07 <DIR> d-------- C:\sega genesis
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2007-12-21 00:33 --------- d-----w C:\Program Files\Viewpoint
2007-12-21 00:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-20 09:05 --------- d-----w C:\Documents and Settings\Halcomb\Application Data\uTorrent
2007-12-19 19:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-19 18:45 --------- d-----w C:\Program Files\Yahoo!
2007-12-19 18:41 --------- d-----w C:\Program Files\Soulseek
2007-12-19 18:41 --------- d-----w C:\Program Files\MegaSpoof
2007-12-19 18:39 --------- d-----w C:\Program Files\QPST
2007-12-19 18:36 --------- d-----w C:\Program Files\Photomatix
2007-12-19 18:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Napster
2007-12-19 18:31 --------- d-----w C:\Documents and Settings\Halcomb\Application Data\Move Networks
2007-12-19 18:29 --------- d-----w C:\Program Files\MAIET
2007-12-19 18:28 --------- d-----w C:\Program Files\Java
2007-12-19 18:27 --------- d-----w C:\Program Files\Sony
2007-12-19 18:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Corporation
2007-12-19 18:25 --------- d-----w C:\Program Files\EphPod
2007-12-19 18:23 --------- d-----w C:\Program Files\DivX
2007-12-19 18:22 --------- d-----w C:\Program Files\DIKO
2007-12-19 18:19 --------- d-----w C:\Program Files\SlySoft
2007-12-19 06:45 --------- d-----w C:\Program Files\QuickTime Alternative
2007-12-17 18:15 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-17 16:54 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-17 09:16 --------- d-----w C:\Program Files\Trillian
2007-12-09 20:07 --------- d-----w C:\Program Files\ArtMoney
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-01-06 00:11 0 ----a-w C:\Documents and Settings\Halcomb\aim-away.exe
2006-09-08 19:49 718 ----a-w C:\Documents and Settings\Halcomb\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 05:48]
"Aim6"="" []
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-11-17 22:47]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-19 23:08]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2005-12-14 01:43]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 17:12]
"VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-12 00:36]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-10 07:00 C:\WINDOWS\system32\rundll32.exe]
"Switcher.exe"="C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-11-24 14:47]
"VAIOCameraUtility"="C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-01 05:20]
"Logitech Hardware Abstraction Layer"="C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE" [2006-07-19 11:03]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 01:41]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-09-11 14:30]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 11:03 C:\WINDOWS\KHALMNPR.Exe]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-06 12:11]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-10-06 12:13]
"Persistence"="C:\WINDOWS\system32\igfxpers.ex e" [2006-10-06 12:10]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 17:44]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03

22]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-10-15 21:09:01]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2005-05-20 20:42 73728 C:\WINDOWS\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM Sniffer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyScreenCam]
C:\Program Files\My Screen Cam\scrcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime Alternative\QTTask.exe -atboottime
R0 SSFS0BB9;Spy Sweeper File System Filer Driver: 0BB9;C:\WINDOWS\system32\Drivers\SSFS0BB9.SYS [2007-12-10 19:47]
R2 FwcAgent;Firewall Client Agent;"C:\Program Files\Microsoft Firewall Client 2004\FwcAgent.exe" [2006-05-29 22:10]
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepK E.sys [2006-09-01 11:32]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB []
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21 sony.sys [2006-02-21 21:32]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys []
S3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2005-12-27 18:22]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB []
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{6d65cb8a-bf63-11da-981c-806d6172696f}]
\Shell\AutoRun\command - E:\sony\Autorun.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-09 02:05:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-19 19:02:26 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe&/ScheduleSweep=wrSpySweeperTrialSweep
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- C:\
.
************************************************** ************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-20 19:49:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2007-12-20 19:51:34 - machine was rebooted
.
2007-12-20 08:24:11 --- E O F ---