Zee
ComboFix 08-07-13.6 - Lim Zee Hui 2008-07-14 12:10:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.0.1252.1.1033.18.74 [GMT 8:00]
Running from: C:\Documents and Settings\Lim Zee Hui\Desktop\2ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Lim Zee Hui\My Documents\My Videos\Desktop.ini
C:\WINDOWS\config.ini
C:\WINDOWS\system32\geBSjijk.dll
C:\WINDOWS\system32\hgGaAttt.dll
C:\WINDOWS\system32\ssqNEULe.dll
C:\WINDOWS\system32\UCbLlUvw.ini
C:\WINDOWS\system32\UCbLlUvw.ini2
C:\WINDOWS\system32\wvUlLbCU.dll
D:\LiveUpdateCopy.exe
.
((((((((((((((((((((((((( Files Created from 2008-06-14 to 2008-07-14 )))))))))))))))))))))))))))))))
.
2008-07-14 11:58 . 2008-07-14 11:58 <DIR> d-------- C:\Deckard
2008-07-14 00:11 . 2008-07-14 06:03 <DIR> d-------- C:\Documents and Settings\Lim Zee Hui\DoctorWeb
2008-07-13 23:53 . 2008-07-13 23:53 <DIR> d-------- C:\WINDOWS\ERUNT
2008-07-13 22:32 . 2008-07-13 22:32 <DIR> d-------- C:\Documents and Settings\Lim Zee Hui\Application Data\Uniblue
2008-07-03 18:29 . 2008-07-03 18:29 <DIR> d-------- C:\WINDOWS\system32\bits
2008-07-03 18:28 . 2004-07-02 06:08 361,984 --a--c--- C:\WINDOWS\system32\dllcache\qmgr.dll
2008-07-03 18:28 . 2004-07-02 06:08 331,776 --a------ C:\WINDOWS\system32\winhttp.dll
2008-07-03 18:28 . 2004-07-01 07:59 158,720 --a------ C:\WINDOWS\system32\xpob2res.dll
2008-07-03 18:28 . 2004-07-02 06:08 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2008-07-03 18:28 . 2004-07-02 06:08 17,408 --a--c--- C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2008-07-03 18:28 . 2004-07-02 06:08 7,680 -----c--- C:\WINDOWS\system32\dllcache\bitsprx2.dll
2008-07-03 18:28 . 2004-07-02 06:08 7,680 --a------ C:\WINDOWS\system32\bitsprx2.dll
2008-07-03 18:28 . 2004-07-02 06:08 7,168 -----c--- C:\WINDOWS\system32\dllcache\bitsprx3.dll
2008-07-03 18:28 . 2004-07-02 06:08 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2008-07-03 18:27 . 2007-07-30 19:19 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2008-07-03 18:27 . 2007-07-30 19:19 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2008-07-03 18:27 . 2007-07-30 19:19 216,408 --a------ C:\WINDOWS\system32\wuaucpl.cpl
2008-07-03 18:27 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-07-03 18:27 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-07-03 18:27 . 2007-07-30 19:18 33,624 --a------ C:\WINDOWS\system32\wups.dll
2008-07-03 18:27 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-07-03 18:27 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-07-03 18:27 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-07-03 17:53 . 2008-07-03 17:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-07-03 14:42 . 2008-07-03 14:42 <DIR> d-------- C:\unzipped
2008-07-03 14:27 . 2008-07-13 19:49 1,278 --a------ C:\WINDOWS\mgutil_reg.ini
2008-07-03 14:26 . 2008-07-13 19:49 142 --a------ C:\WINDOWS\mgutil_win.ini
2008-06-19 18:43 . 2008-06-19 18:43 <DIR> d-------- C:\Documents and Settings\Father & Mother\Application Data\GetRightToGo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-13 16:34 58,880 ----a-w C:\WINDOWS\Internet Logs\xDB2B.tmp
2008-07-13 16:34 16,384 ----a-w C:\WINDOWS\Internet Logs\xDB2C.tmp
2008-07-13 15:16 358,400 ----a-w C:\WINDOWS\Internet Logs\xDB29.tmp
2008-07-13 15:16 2,097,152 ----a-w C:\WINDOWS\Internet Logs\xDB2A.tmp
2008-07-13 14:35 312,320 ----a-w C:\WINDOWS\Internet Logs\xDB27.tmp
2008-07-13 14:35 100,864 ----a-w C:\WINDOWS\Internet Logs\xDB28.tmp
2008-07-13 14:04 47,104 ----a-w C:\WINDOWS\Internet Logs\xDB25.tmp
2008-07-13 14:04 14,336 ----a-w C:\WINDOWS\Internet Logs\xDB26.tmp
2008-07-13 13:18 3,101,696 ----a-w C:\WINDOWS\Internet Logs\xDB22.tmp
2008-07-13 13:18 12,800 ----a-w C:\WINDOWS\Internet Logs\xDB24.tmp
2008-07-13 13:13 50,176 ----a-w C:\WINDOWS\Internet Logs\xDB21.tmp
2008-07-13 11:53 39,424 ----a-w C:\WINDOWS\Internet Logs\xDB1F.tmp
2008-07-13 11:53 3,123,712 ----a-w C:\WINDOWS\Internet Logs\xDB1E.tmp
2008-07-13 11:51 3,121,152 ----a-w C:\WINDOWS\Internet Logs\xDB20.tmp
2008-07-13 10:32 3,101,696 ----a-w C:\WINDOWS\Internet Logs\xDB1C.tmp
2008-07-13 10:32 14,848 ----a-w C:\WINDOWS\Internet Logs\xDB1D.tmp
2008-07-13 08:40 90,624 ----a-w C:\WINDOWS\Internet Logs\xDB1B.tmp
2008-07-13 08:40 3,101,696 ----a-w C:\WINDOWS\Internet Logs\xDB1A.tmp
2008-07-13 01:53 413,184 ----a-w C:\WINDOWS\Internet Logs\xDB19.tmp
2008-07-13 01:53 3,119,104 ----a-w C:\WINDOWS\Internet Logs\xDB18.tmp
2008-07-12 15:23 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-07-12 04:47 21,504 ----a-w C:\WINDOWS\Internet Logs\xDB17.tmp
2008-07-12 04:46 3,103,744 ----a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2008-07-12 04:34 39,424 ----a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2008-07-12 04:34 3,103,744 ----a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2008-07-10 18:34 3,103,744 ----a-w C:\WINDOWS\Internet Logs\xDB12.tmp
2008-07-10 18:34 153,600 ----a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2008-07-10 12:00 3,101,696 ----a-w C:\WINDOWS\Internet Logs\xDB10.tmp
2008-07-10 12:00 20,480 ----a-w C:\WINDOWS\Internet Logs\xDB11.tmp
2008-07-10 11:52 3,103,744 ----a-w C:\WINDOWS\Internet Logs\xDBE.tmp
2008-07-10 11:52 16,896 ----a-w C:\WINDOWS\Internet Logs\xDBF.tmp
2008-07-10 11:45 3,102,208 ----a-w C:\WINDOWS\Internet Logs\xDBC.tmp
2008-07-10 11:45 204,288 ----a-w C:\WINDOWS\Internet Logs\xDBD.tmp
2008-07-10 10:36 3,101,696 ----a-w C:\WINDOWS\Internet Logs\xDB23.tmp
2008-07-10 09:37 3,100,672 ----a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2008-07-09 15:09 3,102,208 ----a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2008-07-09 15:09 27,648 ----a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2008-07-09 14:07 41,472 ----a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2008-07-09 14:07 3,101,696 ----a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2008-07-09 08:22 3,100,672 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2008-07-09 08:18 3,108,864 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2008-07-09 08:18 105,984 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2008-07-08 14:17 3,101,696 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-07-08 14:17 28,160 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-07-08 04:59 3,111,424 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-07-03 09:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-07-03 07:15 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-26 11:05 --------- d-----w C:\Program Files\Olympus
2008-06-26 11:04 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-20 15:30 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-19 17:08 --------- d-----w C:\Program Files\Shockwave.com
2008-06-10 04:57 --------- d-----w C:\Documents and Settings\Father & Mother\Application Data\Flood Light Games
2008-06-10 04:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Flood Light Games
2008-06-10 04:56 --------- d-----w C:\Documents and Settings\Father & Mother\Application Data\PlayFirst
2008-06-09 14:43 --------- d-----w C:\Documents and Settings\Father & Mother\Application Data\ViquaSoft
2008-06-04 14:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-06-04 14:42 --------- d-----w C:\Program Files\ReflexiveArcade
2008-06-04 14:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
2008-05-31 15:38 --------- d-----w C:\Documents and Settings\Guest\Application Data\Grisoft
2008-05-23 15:59 28,064 ----a-w C:\Documents and Settings\Father & Mother\Application Data\GDIPFONTCACHEV1.DAT
2008-05-13 11:46 65,552 ----a-w C:\WINDOWS\system32\KeOS386.DLL
2008-04-27 10:59 2,829 ----a-w C:\WINDOWS\War3Unin.pif
2008-04-27 10:59 139,264 ----a-w C:\WINDOWS\War3Unin.exe
2008-04-27 07:58 37,348 ----a-w C:\WINDOWS\system32\tcpipbak.reg
2007-02-21 08:42 31,088 ----a-w C:\Documents and Settings\Lim Zee Hui\Application Data\GDIPFONTCACHEV1.DAT
2007-12-30 16:29 11,270 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2001-08-23 20:00 13312]
"GSA Cleandrive"="D:\GSA Cleandrive\Cleandrive.exe" [2008-06-24 14:58 2977280]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2001-08-02 07:14 1077277]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54 5674352]
"Uniblue RegistryBooster 2"="D:\RegistryBooster 2\RegistryBooster.exe" [2008-05-05 12:22 1923352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-04-07 00:07 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 03:03 49263]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-17 11:42 58728]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2004-05-17 04:56 697624]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-04-06 21:56 100056]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2001-08-23 20:00 208949]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2001-08-23 20:00 77824]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE" [2001-08-23 20:00 737360]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE" [2001-08-23 20:00 737360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2001-08-02 07:14 1077277]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-02-04 19:17:01 113664]
BTTray.lnk - C:\Program Files\Belkin\Bluetooth Software\BTTray.exe [2004-10-01 15:12:18 565309]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 1 (0x1)
"NoStrCmpLogical"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoStrCmpLogical"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LightFrame 3.lnk]
backup=C:\WINDOWS\pss\LightFrame 3.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2003-04-07 00:19 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"AME_CSA"=rundll32 amecsa.cpl,RUN_DLL
"Microsoft Windows System"=Wincbr.exe
"Intel Driver"=Wincbr.exe
R3 AmeAtmPc;AmeAtmPc;C:\WINDOWS\System32\DRIVERS\AmeAtmPc.sys [2002-02-22 11:14]
S1 HWIODRV;HWIODRV;C:\WINDOWS\System32\HWIODRV.SYS []
S3 AtmElan;ATM Emulated LAN;C:\WINDOWS\System32\DRIVERS\atmlane.sys [2001-08-23 20:00]
S3 AtmLane;ATM LAN Emulation;C:\WINDOWS\System32\DRIVERS\atmlane.sys [2001-08-23 20:00]
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\System32\DRIVERS\usbprint.sys [2001-08-17 14:00]
.
Contents of the 'Scheduled Tasks' folder
"2007-06-15 16:52:05 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Lim Zee Ying.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-14 12:16:45
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMNTOR.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
.
**************************************************************************
.
Completion time: 2008-07-14 13:00:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-14 05:00:43
Pre-Run: 5,871,001,600 bytes free
Post-Run: 6,140,096,512 bytes free
209
Post Edited (shanellate) : 14-07-2008 07:36:46 GMT