
Originally Posted by
Budfred
Yes, you have some garbage... The last time you requested help, you never responded... Please follow through this time...
Sorry
Anywho, the ComboFix log:
ComboFix 08-01-17.1 - Alex Johnson 2008-01-16 15:44:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1382 [GMT -5:00]
Running from: C:\Documents and Settings\Alex Johnson\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Alex Johnson\Application Data\antivirus.exe
C:\Documents and Settings\Alex Johnson\Application Data\printer.exe
C:\Documents and Settings\Alex Johnson\Application Data\trant.exe
C:\Documents and Settings\Alex Johnson\Application Data\ultra
C:\Documents and Settings\Alex Johnson\Application Data\ultra\uninstall.bat
C:\Documents and Settings\Alex Johnson\Start Menu\Programs\Startup\findfast .exe
C:\Documents and Settings\Alex Johnson\Start Menu\Programs\Startup\findfast.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Apple Keyboard Support\KbdMgr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Helper
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\OinFP.exe
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\Outerinfo.dll
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\spoolsv.exe
c:\program files\steam\steam.exe
C:\Program Files\ucleaner_setup.exe
C:\Program Files\Ultimate Cleaner
C:\Program Files\Ultimate Defender
C:\WINDOWS\avp .exe
C:\WINDOWS\avp .exe
C:\WINDOWS\inf\ultra.inf
C:\WINDOWS\mgrs.exe
C:\WINDOWS\shell.exe
C:\WINDOWS\Spyware Remover.ico
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\printer .exe
C:\WINDOWS\system32\printer.exe
C:\WINDOWS\system32\rrqss.ini
C:\WINDOWS\system32\rrqss.ini2
C:\WINDOWS\system32\spoolvs .exe
C:\WINDOWS\system32\spoolvs.exe
C:\WINDOWS\system32\ssqrr.dll
C:\WINDOWS\system32\ssqrr.exe
C:\WINDOWS\system32\xlibgfl254.dll
Code:
<pre>
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe ---> Reader_sl.exe
C:\Program Files\Apple Keyboard Support\KbdMgr .exe ---> KbdMgr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe ---> atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper .exe ---> iTunesHelper.exe
C:\Program Files\Steam\steam .exe ---> steam.exe
C:\WINDOWS\system32\ctfmon .exe ---> QooBox
C:\WINDOWS\system32\printer .exe ---> QooBox
C:\WINDOWS\system32\spoolvs .exe ---> QooBox
</pre>
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_NPF
((((((((((((((((((((((((( Files Created from 2007-12-17 to 2008-01-17 )))))))))))))))))))))))))))))))
.
2008-01-16 15:41 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-15 19:59 . 2008-01-15 19:59 11,264 --a------ C:\Program Files\1289265.exe
2008-01-15 02:12 . 2008-01-15 18:42 <DIR> d-------- C:\VundoFix Backups
2008-01-15 02:04 . 2008-01-15 02:04 103,424 --a------ C:\WINDOWS\system32\drvtuw.dll
2008-01-15 00:57 . 2008-01-15 15:09 172,032 --a------ C:\WINDOWS\system32\Brightness .exe
2008-01-15 00:57 . 2008-01-15 02:01 65,536 --a------ C:\WINDOWS\system32\AppleTime .exe
2008-01-15 00:25 . 2008-01-15 00:25 11,264 --a------ C:\Program Files\6020156.exe
2008-01-15 00:25 . 2008-01-15 19:59 745 --a------ C:\WINDOWS\wininit.ini
2008-01-15 00:02 . 2008-01-15 15:36 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-15 00:02 . 2008-01-15 00:02 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-14 23:55 . 2008-01-14 23:55 103,424 --a------ C:\WINDOWS\system32\drvpep.dll
2008-01-14 22:53 . 2008-01-14 22:53 <DIR> d-------- C:\Program Files\ecm100
2008-01-14 22:22 . 2008-01-14 22:22 715,248 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-01-14 22:11 . 2008-01-14 22:18 <DIR> d-------- C:\Program Files\aoe3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-01-17 20:55 --------- d-----w C:\Program Files\Steam
2008-01-17 20:53 --------- d-----w C:\Program Files\iTunes
2008-01-17 20:53 --------- d-----w C:\Program Files\Apple Keyboard Support
2008-01-17 20:50 --------- d-----w C:\Program Files\QuickTime
2008-01-03 02:09 --------- d-s---w C:\Program Files\HLSW
2008-01-03 02:07 --------- d-----w C:\Program Files\Octoshape Streaming Services
2008-01-01 05:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-20 00:38 --------- d-----w C:\Documents and Settings\Alex Johnson\Application Data\Azureus
2007-12-17 04:36 --------- d-----w C:\Program Files\World of Warcraft
2007-11-23 07:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-11-21 08:20 --------- d-----w C:\Program Files\Viewpoint
2007-11-21 08:20 --------- d-----w C:\Program Files\Starcraft
2007-11-21 08:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-21 08:19 --------- d-----w C:\Program Files\Elecard
2007-11-21 08:04 --------- d-----w C:\Documents and Settings\Alex Johnson\Application Data\dvdcss
2007-11-21 00:40 --------- d-----w C:\Program Files\Ventrilo
2007-11-21 00:39 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-03-12 01:27 1,202,101 ----a-w C:\Program Files\wrar37b4.exe
.
Code:
<pre>
----a-w 65,536 2008-01-15 07:01:25 C:\WINDOWS\system32\AppleTime .exe
----a-w 172,032 2008-01-15 20:09:46 C:\WINDOWS\system32\Brightness .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"Steam"="c:\program files\steam\steam.exe" [2008-01-16 15:36 1266936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2008-01-16 15:36 344064]
"Apple_KbdMgr"="C:\Program Files\Apple Keyboard Support\KbdMgr.exe" [2008-01-16 15:36 315392]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 07:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"AppleTime"="C:\WINDOWS\system32\AppleTime.exe " [ ]
"Brightness"="C:\WINDOWS\system32\Brightness.e xe" [ ]
"SigmatelSysTrayApp"="sttray.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-16 15:36 256576]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-16 15:36 40048]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [ ]
"Winupdate Engine"="C:\WINDOWS\system32\wupeng.exe" [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddccdde]
ddccdde.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ,
R2 KeyAgent;KeyAgent;C:\WINDOWS\system32\drivers\KeyA gent.sys [2006-10-24 17:38]
R2 keymagic;USB Keyboard HID Filter;C:\WINDOWS\system32\DRIVERS\KeyMagic.sys [2006-10-24 17:38]
R3 aapltp;Apple Trackpad Driver;C:\WINDOWS\system32\DRIVERS\aapltp.sys [2006-10-19 11:15]
R3 StartupDiskDriver;StartupDiskDriver;C:\WINDOWS\sys tem32\DRIVERS\StartupDiskDriver.sys [2006-09-26 17:20]
S3 aapltctp;Apple Trackpad filter;C:\WINDOWS\system32\DRIVERS\aapltctp.sys [2006-10-19 11:15]
S3 BLUETOOTH_KICKER;Apple Bluetooth Kicker Driver;C:\WINDOWS\system32\Drivers\BthKicker.sys [2006-08-24 23:45]
S3 iSightUpdate;iSight Update Driver;C:\WINDOWS\system32\DRIVERS\iSightUP.sys [2006-09-05 14:08]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{b67709ec-c31c-11dc-9cc1-0017f2b72e78}]
\Shell\AutoRun\command - F:\autorun.exe
\Shell\directx\command - F:\DirectX9\dxsetup.exe
\Shell\setup\command - F:\setup.exe
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-17 15:55:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-01-17 15:59:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-17 20:59:39