Gentlemen, my reports
No anti root kit was found.
ComboFix 08-04-16.5 - Owner 2008-04-18 13:35:47.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.280 [GMT -4:00]
Running from: C:\Documents and Settings\Owner\My Documents\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-18 to 2008-04-18 )))))))))))))))))))))))))))))))
.
2008-04-18 13:32 . 2008-04-18 13:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-18 13:25 . 2008-04-18 13:25 3,190 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-17 07:48 . 2008-04-17 07:48 <DIR> d-------- C:\VundoFix Backups
2008-04-17 07:24 . 2008-04-14 19:28 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-17 07:24 . 2008-04-12 13:49 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-17 07:24 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-17 07:03 . 2008-04-17 07:04 <DIR> d-------- C:\Program Files\CCleaner
2008-04-17 06:56 . 2008-04-17 06:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-17 06:55 . 2008-04-17 06:55 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-17 06:41 . 2008-04-17 06:41 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Grisoft
2008-04-17 06:41 . 2007-05-30 08:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-08 14:04 . 2008-04-08 14:04 <DIR> d-------- C:\Program Files\ZoneAlarmSB
2008-04-08 14:00 . 2008-03-13 23:11 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2008-04-02 16:22 . 2008-04-02 16:22 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\iolo
2008-04-02 16:22 . 2008-04-02 16:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\iolo
2008-04-02 16:22 . 2008-04-02 16:22 406 --a------ C:\WINDOWS\system32\ioloBootDefrag.cfg
2008-03-25 16:20 . 2008-03-25 16:20 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Uniblue
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-18 10:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-17 20:26 12,380 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-17 20:26 1,654,816 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-17 12:22 --------- d-----w C:\Program Files\Java
2008-04-17 10:58 --------- d-----w C:\Program Files\Lavasoft
2008-04-17 10:58 --------- d-----w C:\Documents and Settings\Owner\Application Data\Lavasoft
2008-04-17 10:51 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-04-16 18:20 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-04-16 18:20 --------- d-----w C:\Program Files\Diablo II
2008-04-15 15:03 --------- d-----w C:\Program Files\Bat
2008-04-13 18:21 1,350,656 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-17 23:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-03-17 23:57 --------- d-----w C:\Program Files\Zone Labs
2008-03-15 04:57 9,292 ---ha-w C:\WINDOWS\system32\BIT10F.tmp
2008-03-14 03:11 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-15 19:44 21,840 -c--atw C:\WINDOWS\system32\SIntfNT.dll
2008-02-15 19:44 17,212 -c--atw C:\WINDOWS\system32\SIntf32.dll
2008-02-15 19:44 12,067 -c--atw C:\WINDOWS\system32\SIntf16.dll
2007-09-23 12:22 439,296 ----a-w C:\Documents and Settings\Administrator\GoToAssist_phone__317_en.exe
.
((((((((((((((((((((((((((((( snapshot@2008-04-17_16.01.47.73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-17 19:32:34 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-18 11:12:55 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{13197ace-6851-45c3-a7ff-c281324d5489}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4e1075f4-eec4-4a86-add7-cd5f52858c31}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8674aea0-9d3d-11d9-99dc-00600f9a01f1}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2008-04-08 14:04 262144 --a------ C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ffff0001-0002-101a-a3c9-08002b2f49fb}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" [2008-04-08 14:04 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-04-08 14:04 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"NVIEW"="rundll32.exe" [2004-08-04 03:56 33280 C:\WINDOWS\system32\rundll32.exe]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45 313472]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="C:\WINDOWS\system32\Macromed\SHOCKW~1\SWHELP~2.exe" [2007-08-07 18:20 391144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04 52736]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-08-20 15:51 118784]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 23:02 61440]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 11:01 110592]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 00:42 212992]
"VTTimer"="VTTimer.exe" []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-09 11:47 71328]
"LTMSG"="LTMSG.exe" [2003-07-14 20:52 40960 C:\WINDOWS\ltmsg.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 19:57 81920]
"Sunkist2k"="C:\Program Files\Multimedia Card Reader\shwicon2k.exe" [2003-08-14 20:11 139264]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-12 07:23 172032]
"mmtask"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2003-07-23 19:37 53248]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2006-06-04 21:05 100056]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 16:45 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-06-04 21:51 282624]
"DigiSrv"="C:\WINDOWS\Twain_32\DigiCam\DigiSrv.exe" [2003-08-07 10:26 180304]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-08-20 15:55 155648]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-11-21 13:38 35328]
"Verizon_McciTrayApp"="C:\Program Files\Verizon\McciTrayApp.exe" [2007-03-11 17:37 936960]
"HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 21:24 49152]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-13 23:11 919016]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25 6731312]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 17:40 5367608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-01-02 14:01:26 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\AIM95\\aim.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
S3 SQTECH913C;DigiCam;C:\WINDOWS\system32\DRIVERS\Capt913c.sys [2004-03-16 19:46]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-16 03:00:06 C:\WINDOWS\Tasks\wrSpySweeper_LF2EAC68977544984A9167D51FD94D9A8.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe>/ScheduleSweep=wrSpySweeper_LF2EAC68977544984A9167D51FD94D9A8
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- A:\
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-18 13:40:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-18 13:42:32
ComboFix-quarantined-files.txt 2008-04-18 17:42:12
ComboFix2.txt 2008-04-17 20:02:36
Pre-Run: 178,515,525,632 bytes free
Post-Run: 178,507,530,240 bytes free
.
2008-04-09 07:08:03 --- E O F ---