New HijackThis Logs
ComboFix 07-09-17.2 - "mihai" 2007-09-17 11:10:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.474 [GMT -4:00]
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
E:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007
E:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\Abbr
E:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\ActivationCode
E:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007\Data\ProductCode
E:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\WinAntiVirus Pro 2007
E:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\WinAntiVirus Pro 2007\Reinstall or Uninstall WinAntiVirus Pro 2007.lnk
E:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\WinAntiVirus Pro 2007\WinAntiVirus Pro 2007 Manual.lnk
E:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\WinAntiVirus Pro 2007\WinAntiVirus Pro 2007.lnk
E:\DOCUME~1\anca\APPLIC~1\WinAntiVirus Pro 2007
E:\DOCUME~1\anca\APPLIC~1\WinAntiVirus Pro 2007\history.db
E:\DOCUME~1\anca\APPLIC~1\WinAntiVirus Pro 2007\Logs\wa7Support.log
E:\DOCUME~1\anca\APPLIC~1\WinAntiVirus Pro 2007\Logs\winav.log
E:\DOCUME~1\anca\APPLIC~1\WinAntiVirus Pro 2007\PGE.dat
E:\DOCUME~1\anca\err.log
E:\DOCUME~1\anca\ResErrors.log
E:\DOCUME~1\anca\STARTM~1\Programs\Startup\info.exe
E:\DOCUME~1\gabi\APPLIC~1\WinAntiVirus Pro 2007
E:\DOCUME~1\gabi\APPLIC~1\WinAntiVirus Pro 2007\Logs\winav.log
E:\DOCUME~1\gabi\err.log
E:\DOCUME~1\gabi\ResErrors.log
E:\DOCUME~1\gabi\STARTM~1\Programs\Startup\info.exe
E:\DOCUME~1\mihai\err.log
E:\DOCUME~1\mihai\ResErrors.log
E:\DOCUME~1\mihai\STARTM~1\Programs\WebMediaPlayer
E:\DOCUME~1\mihai\STARTM~1\Programs\WebMediaPlayer\WebMediaPlayer.lnk
E:\DOCUME~1\mihai\STARTM~1\Programs\WebMediaPlayer\Website.lnk
E:\Program Files\Common Files\companion wizard
E:\Program Files\Common Files\Companion Wizard\CompWiz.xml
E:\Program Files\Common Files\companion wizard\CompWiz.xml
E:\Program Files\Common Files\winantivirus pro 2007
E:\Program Files\Common Files\WinAntiVirus Pro 2007\err.log
E:\Program Files\Common Files\winantivirus pro 2007\err.log
E:\UGA6P
E:\WINDOWS\explore.exe
E:\WINDOWS\pack.epk
E:\WINDOWS\system32\gogpasppop.dat
E:\WINDOWS\system32\gogpasppop_nav.dat
E:\WINDOWS\system32\gogpasppop_navps.dat
E:\WINDOWS\system32\nvs2.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_FOPF
-------\LEGACY_FOPN
((((((((((((((((((((((((( Files Created from 2007-08-17 to 2007-09-17 )))))))))))))))))))))))))))))))
.
2007-09-17 11:09 51,200 --a------ E:\WINDOWS\NirCmd.exe
2007-09-17 10:22 187,184 --a------ E:\DOCUME~1\mihai\pskill.exe
2007-09-17 10:19 187,184 --a------ E:\pskill.exe
2007-09-17 10:01 <DIR> d-------- E:\Program Files\Trend Micro
2007-09-16 12:52 <DIR> d-------- E:\WINDOWS\BDOSCAN8
2007-09-16 12:35 <DIR> d-------- E:\Program Files\Enigma Software Group
2007-09-16 11:31 8,295,200 --ahs---- E:\WINDOWS\system32\drivers\fidbox.dat
2007-09-16 11:31 15,648 --ahs---- E:\WINDOWS\system32\drivers\fidbox2.dat
2007-09-16 11:31 <DIR> d-------- E:\Program Files\Kaspersky Lab
2007-09-16 11:24 <DIR> d-------- E:\Program Files\XoftSpySE
2007-09-16 06:19 <DIR> d-------- E:\Program Files\Windows Live Safety Center
2007-09-13 20:18 <DIR> d-------- E:\Program Files\Windows Defender
2007-09-12 18:29 10,872 --a------ E:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-12 18:19 <DIR> d-------- E:\DOCUME~1\mihai\APPLIC~1\AntiSpyware
2007-09-11 20:20 8,704 --a------ E:\WINDOWS\system32\SpOrder.dll
2007-09-11 15:46 <DIR> d-------- E:\DOCUME~1\NETWOR~1\APPLIC~1\Google
2007-09-11 15:21 626,688 --a------ E:\WINDOWS\system32\msvcr80.dll
2007-09-11 14:21 39,424 --a------ E:\WINDOWS\system32\vtr.dll
2007-09-04 20:40 <DIR> d-------- E:\Program Files\AdVantage
2007-08-31 16:08 <DIR> d-------- E:\WINDOWS\MACROMED
2007-08-31 16:08 <DIR> d-------- E:\WINDOWS\A3W_DATA
2007-08-25 10:16 <DIR> d-------- E:\WINDOWS\MaxTV
2007-08-25 10:16 <DIR> d-------- E:\Program Files\DMV
2007-08-25 09:10 <DIR> d-------- E:\DOCUME~1\mihai\APPLIC~1\Unreal Streaming
2007-08-23 15:47 <DIR> d-------- E:\Program Files\iTunes
2007-08-23 15:47 <DIR> d-------- E:\Program Files\iPod
2007-08-18 10:31 <DIR> d-------- E:\Program Files\Get-Torrent
2007-08-18 10:31 <DIR> d-------- E:\DOCUME~1\mihai\APPLIC~1\Get-Torrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-17 11:17 3056 --ahs---- E:\WINDOWS\system32\drivers\fidbox2.idx
2007-09-17 11:17 14768 --ahs---- E:\WINDOWS\system32\drivers\fidbox.idx
2007-09-16 12:15 --------- d-------- E:\DOCUME~1\mihai\APPLIC~1\BitTorrent
2007-09-13 06:51 --------- d-------- E:\Program Files\Lx_cats
2007-09-06 06:09 801144 --a------ E:\WINDOWS\system32\aswBoot.exe
2007-09-06 06:03 23152 --a------ E:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-05 18:55 --------- d-------- E:\Program Files\BitTorrent
2007-09-04 20:46 --------- d-------- E:\DOCUME~1\mihai\APPLIC~1\BSplayer
2007-08-15 09:27 --------- d-------- E:\Program Files\MSXML 4.0
2007-08-03 21:10 --------- dr-h----- E:\DOCUME~1\mihai\APPLIC~1\yahoo!
2007-08-01 11:08 --------- d-------- E:\Program Files\TVUPlayer
2007-08-01 11:08 --------- d-------- E:\DOCUME~1\mihai\APPLIC~1\TVU Networks
2007-07-30 19:19 92504 --a------ E:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ E:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ E:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ E:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ E:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 --a------ E:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 --a------ E:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a------ E:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ E:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ E:\WINDOWS\system32\wups.dll
2007-07-22 08:18 --------- d-------- E:\Program Files\DivX
2007-07-22 08:18 --------- d-------- E:\DOCUME~1\mihai\APPLIC~1\Talkback
2007-07-21 09:25 --------- d-------- E:\Program Files\Yahoo!
2007-07-19 16:05 --------- d-------- E:\DOCUME~1\gabi\APPLIC~1\CyberLink
2007-07-09 15:07 524288 --a------ E:\WINDOWS\system32\DivXsm.exe
2007-07-09 15:07 3596288 --a------ E:\WINDOWS\system32\qt-dx331.dll
2007-07-09 15:07 200704 --a------ E:\WINDOWS\system32\ssldivx.dll
2007-07-09 15:07 1044480 --a------ E:\WINDOWS\system32\libdivx.dll
2007-07-09 15:05 823296 --a------ E:\WINDOWS\system32\divx_xx0c.dll
2007-07-09 15:05 823296 --a------ E:\WINDOWS\system32\divx_xx07.dll
2007-07-09 15:05 802816 --a------ E:\WINDOWS\system32\divx_xx11.dll
2007-07-09 15:05 740442 --a------ E:\WINDOWS\system32\DivX.dll
2007-07-09 15:05 73728 --a------ E:\WINDOWS\system32\dpl100.dll
2007-07-09 15:05 593920 --a------ E:\WINDOWS\system32\dpuGUI11.dll
2007-07-09 15:05 57344 --a------ E:\WINDOWS\system32\dpv11.dll
2007-07-09 15:05 53248 --a------ E:\WINDOWS\system32\dpuGUI10.dll
2007-07-09 15:05 344064 --a------ E:\WINDOWS\system32\dpus11.dll
2007-07-09 15:05 294912 --a------ E:\WINDOWS\system32\dpu11.dll
2007-07-09 15:05 294912 --a------ E:\WINDOWS\system32\dpu10.dll
2007-07-09 15:05 196608 --a------ E:\WINDOWS\system32\dtu100.dll
2007-07-09 15:05 124472 --a------ E:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-07-09 15:05 12288 --a------ E:\WINDOWS\system32\DivXWMPExtType.dll
2007-06-26 02:08 1104896 --a------ E:\WINDOWS\system32\msxml3.dll
2007-06-19 09:31 282112 --a------ E:\WINDOWS\system32\gdi32.dll
2005-09-23 18:49 12288 --a------ E:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="E:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 08:43]
"SoundMan"="SOUNDMAN.EXE" [2005-07-22 03:00 E:\WINDOWS\SOUNDMAN.EXE]
"SynTPEnh"="E:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-08-18 22:07]
"Wireless Console 2"="E:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-12 08:07]
"TkBellExe"="E:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-03-19 11:38]
"RemoteControl"="E:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-11 21:01]
"NeroFilterCheck"="E:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 10:40]
"HControl"="E:\WINDOWS\ATK0100\HControl.exe" [2006-01-05 07:56]
"SunJavaUpdateSched"="E:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Lto Manager"="E:\Program Files\Quick GPS Connection Data Download Manager\DesktopLtoManager.exe" [2006-04-13 10:59]
"Adobe Reader Speed Launcher"="E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"LXCFCATS"="E:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 13:47]
"QuickTime Task"="E:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"iTunesHelper"="E:\Program Files\iTunes\iTunesHelper.exe" [2007-08-15 20:15]
"!AVG Anti-Spyware"="E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]
"Windows Defender"="E:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"kis"="E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" [2006-03-24 19:09]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="E:\WINDOWS\system32\ctfmon.exe" [2006-02-28 08:00]
"Yahoo! Pager"="E:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-07-16 15:17]
"H/PC Connection Agent"="E:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 19:44]
"BitTorrent"="E:\Program Files\BitTorrent\bittorrent.exe" [2007-03-01 19:11]
"swg"="E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-30 10:04]
E:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
HP Photosmart Premier Fast Start.lnk - E:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-23 19:39:30]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
R2 sbbotdi;sbbotdi;\??\E:\PROGRA~1\SPEEDB~1\sbbotdi.sys
R2 ugiipqd;Unigraphics Plot Server (ugiipqd);E:\WINDOWS\system32\spool\ugplot\ugiipqd.exe
R3 ASNDIS5;ASNDIS5 Protocol Driver;\??\E:\WINDOWS\system32\ASNDIS5.SYS
R3 HSFHWSIS;HSFHWSIS;E:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys
S2 Unigraphics License Server (uglmd);Unigraphics License Server (uglmd);"E:\Program Files\EDS\License Servers\UGNXFLEXlm\lmgrd.exe"
S3 FXDRV;FXDRV;\??\D:\Fxdrv.sys
S3 MSIRCOMM;Microsoft IR Communications Driver;E:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-09-17 07:00:00 E:\WINDOWS\Tasks\AntiSpyware Scheduled Scan.job"
- E:\Program Files\AntiSpywareApp\AntiSpyware.exe
"2007-09-13 18:44:02 E:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- E:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-17 15:22:06 E:\WINDOWS\Tasks\MP Scheduled Scan.job"
- E:\Program Files\Windows Defender\MpCmdRun.exe
"2007-09-06 07:00:00 E:\WINDOWS\Tasks\RegCure.job"
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-09-17 11:21:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-17 11:26:50 - machine was rebooted
E:\ComboFix-quarantined-files.txt ... 2007-09-17 11:26
.
--- E O F ---
Thank You!