" " - 2007-07-03 1:43:03 - ComboFix 07-06-27.7 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\profsy.html
C:\Program Files\myglobalsearch
C:\Program Files\myglobalsearch\bar\History\search
C:\WINDOWS\180ax.exe
C:\WINDOWS\2020search.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\bi.dll
C:\WINDOWS\biprep.exe
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\flt.dll
C:\WINDOWS\mspphe.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\pbar.dll
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\satmat.exe
C:\WINDOWS\stcloader.exe
C:\WINDOWS\susp.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\bund1
C:\WINDOWS\system32\bund1\temp.txt
C:\WINDOWS\system32\drv32dta
C:\WINDOWS\system32\drv32dta\klg.tmp
C:\WINDOWS\system32\drv32dta\pstore_070510_195537.txt
C:\WINDOWS\system32\drv32dta\pstore_070510_214722.txt
C:\WINDOWS\system32\drv32dta\pstore_070511_110202.txt
C:\WINDOWS\system32\drv32dta\pstore_070512_210629.txt
C:\WINDOWS\system32\drv32dta\pstore_070513_213841.txt
C:\WINDOWS\system32\drv32dta\pstore_070514_144117.txt
C:\WINDOWS\system32\drv32dta\pstore_070514_144455.txt
C:\WINDOWS\system32\drv32dta\pstore_070515_160610.txt
C:\WINDOWS\system32\drv32dta\pstore_070516_160115.txt
C:\WINDOWS\system32\drv32dta\pstore_070517_115257.txt
C:\WINDOWS\system32\drv32dta\pstore_070517_150040.txt
C:\WINDOWS\system32\drv32dta\pstore_070517_151649.txt
C:\WINDOWS\system32\drv32dta\pstore_070517_234706.txt
C:\WINDOWS\system32\drv32dta\pstore_070518_002850.txt
C:\WINDOWS\system32\drv32dta\pstore_070518_113727.txt
C:\WINDOWS\system32\drv32dta\pstore_070520_165324.txt
C:\WINDOWS\system32\drv32dta\pstore_070521_115532.txt
C:\WINDOWS\system32\drv32dta\pstore_070521_195922.txt
C:\WINDOWS\system32\drv32dta\pstore_070522_141111.txt
C:\WINDOWS\system32\drv32dta\pstore_070522_161713.txt
C:\WINDOWS\system32\drv32dta\pstore_070522_220247.txt
C:\WINDOWS\system32\drv32dta\pstore_070522_225532.txt
C:\WINDOWS\system32\drv32dta\pstore_070522_235357.txt
C:\WINDOWS\system32\drv32dta\pstore_070523_114702.txt
C:\WINDOWS\system32\drv32dta\pstore_070523_151029.txt
C:\WINDOWS\system32\drv32dta\pstore_070524_150515.txt
C:\WINDOWS\system32\drv32dta\pstore_070525_115812.txt
C:\WINDOWS\system32\drv32dta\pstore_070525_135440.txt
C:\WINDOWS\system32\drv32dta\pstore_070529_162116.txt
C:\WINDOWS\system32\drv32dta\pstore_070529_165233.txt
C:\WINDOWS\system32\drv32dta\pstore_070530_015231.txt
C:\WINDOWS\system32\drv32dta\pstore_070530_110934.txt
C:\WINDOWS\system32\drv32dta\pstore_070530_173353.txt
C:\WINDOWS\system32\drv32dta\pstore_070531_113259.txt
C:\WINDOWS\system32\drv32dta\pstore_070531_145120.txt
C:\WINDOWS\system32\drv32dta\pstore_070601_193636.txt
C:\WINDOWS\system32\drv32dta\pstore_070602_220056.txt
C:\WINDOWS\system32\drv32dta\pstore_070603_150119.txt
C:\WINDOWS\system32\drv32dta\pstore_070603_213838.txt
C:\WINDOWS\system32\drv32dta\pstore_070604_152622.txt
C:\WINDOWS\system32\drv32dta\pstore_070605_160649.txt
C:\WINDOWS\system32\drv32dta\pstore_070605_161301.txt
C:\WINDOWS\system32\drv32dta\pstore_070606_160458.txt
C:\WINDOWS\system32\drv32dta\pstore_070607_023529.txt
C:\WINDOWS\system32\drv32dta\pstore_070607_170428.txt
C:\WINDOWS\system32\drv32dta\pstore_070608_205459.txt
C:\WINDOWS\system32\drv32dta\pstore_070610_020459.txt
C:\WINDOWS\system32\drv32dta\pstore_070610_220405.txt
C:\WINDOWS\system32\drv32dta\pstore_070611_160039.txt
C:\WINDOWS\system32\drv32dta\pstore_070612_160652.txt
C:\WINDOWS\system32\drv32dta\pstore_070612_221849.txt
C:\WINDOWS\system32\drv32dta\pstore_070612_223309.txt
C:\WINDOWS\system32\drv32dta\pstore_070612_225033.txt
C:\WINDOWS\system32\drv32dta\pstore_070613_164005.txt
C:\WINDOWS\system32\drv32dta\pstore_070613_233850.txt
C:\WINDOWS\system32\drv32dta\pstore_070614_151254.txt
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll
C:\WINDOWS\wml.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
((((((((((((((((((((((((( Files Created from 2007-06-03 to 2007-07-03 )))))))))))))))))))))))))))))))
2007-07-03 01:41 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-07-03 00:16 <DIR> d-------- C:\DOCUME~1\ZACTHI~1\DoctorWeb
2007-07-03 00:01 <DIR> d-------- C:\WINDOWS\ERUNT
2007-07-03 00:00 <DIR> d-------- C:\bintheredunthat
2007-06-18 23:23 <DIR> d-------- C:\WINDOWS\system32\qchrqilr
2007-06-18 21:58 99,072 --a------ C:\qchrqilr1.exe
2007-06-18 21:58 94,464 --a------ C:\qchrqilr3.exe
2007-06-18 21:58 286,720 --a------ C:\WINDOWS\system32\scchk32.exe
2007-06-18 21:58 100,096 --a------ C:\qchrqilr2.exe
2007-06-14 02:18 4 --a------ C:\WINDOWS\system32\stfv.bin
2007-06-14 02:18 12 --a------ C:\WINDOWS\system32\sl.bin
2007-06-14 02:17 25,856 --a------ C:\WINDOWS\vxddsk.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-27 06:11:45 190,560 ----a-w C:\DOCUME~1\ZACTHI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
2007-06-20 21:07:57 -------- d-----w C:\DOCUME~1\ZACTHI~1\APPLIC~1\AdobeUM
2007-06-07 01:28:15 -------- d-----w C:\Program Files\AIM6
2007-06-04 23:09:05 -------- d--h--w C:\Program Files\WindowsUpdate
2007-05-31 18:51:40 388 ----a-w C:\WINDOWS\urls.dat
2007-05-31 18:51:40 18,906 ----a-w C:\WINDOWS\htmlcode.dat
2007-05-23 20:50:17 -------- d-----w C:\DOCUME~1\ZACTHI~1\APPLIC~1\U3
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-03 00:39:44 -------- d-----w C:\DOCUME~1\ZACTHI~1\APPLIC~1\ZangoToolbar
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-19 04:04:55 552 ----a-w C:\WINDOWS\system32\d3d8caps.dat
2007-04-19 03:50:40 167 ----a-w C:\WINDOWS\system32\3090.bat
2007-04-19 03:50:27 128 ----a-w C:\WINDOWS\system32\ap.exe
2007-04-19 03:49:42 8,464 ----a-w C:\WINDOWS\system32\sporder.dll
2007-04-19 03:49:29 32,768 ----a-w C:\WINDOWS\system32\setup9x.exe
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 21:38]
{31FF080D-12A3-439A-A2EF-4BA95A3148E8}=C:\Program Files\GetRight\xx2gr.dll [2006-07-17 17:11]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll [2006-12-15 04:23]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-09-28 15:40]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-09-28 15:40]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 21:07 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-09-28 15:52 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-09-28 15:48 C:\WINDOWS\ALCWZRD.EXE]
"SMSERIAL"="sm56hlpr.exe" [2005-09-28 15:46 C:\WINDOWS\sm56hlpr.exe]
"nwiz"="nwiz.exe" [2005-09-28 15:39 C:\WINDOWS\system32\nwiz.exe]
"InstantOn"="C:\Program Files\CyberLink\PowerCinema Linux\ion_install.exe" [2005-05-11 21:28]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 00:24]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-08-06 20:48]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 08:00 C:\WINDOWS\system32\bthprops.cpl]
"BootSkin Startup Jobs"="C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" [2004-04-26 17:21]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-12-10 13:45 C:\WINDOWS\KHALMNPR.Exe]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [2004-04-23 12:00]
"PCLEPCI"="C:\PROGRA~1\Pinnacle\PPE\PPE.EXE" [2004-02-03 16:13]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-02-06 01:53]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 18:05]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-21 13:14]
"MsgCenterExe"="C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" []
"VerizonServicepoint.exe"="C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe" [2006-02-01 18:33]
"A Verizon App"="C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE" [2005-05-23 13:20]
"Motive SmartBridge"="C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe" [2005-04-13 19:51]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 03:41]
"Personal Firewall"="C:\Program Files\Lavasoft\Personal Firewall\lpfw.exe" [2005-11-03 15:43]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 04:23]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"CursorXP"="C:\Program Files\CursorXP\CursorXP.exe" [2005-01-19 17:34]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 17:17]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
Source= C:\Program Files\Common Files\profsy.html
FriendlyName=
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 10:13]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EOUApp]
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
C:\Program Files\VIA\RAID\raid_tool.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{41ebc66e-a9ad-11db-ac13-0012f09606ab}]
AutoRun\command- G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d5a508cc-096e-11dc-acf4-0012f09606ab}]
AutoRun\command- F:\LaunchU3.exe -a
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{Y479C6D0-OTRW-U5GH-S1EE-E02310B4E666}
C:\WINDOWS\system32\tmrsrv32.exe
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-07-03 01:48:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001105-0000-1000-8000-00805f9b34fb}]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]
Completion time: 2007-07-03 1:50:33 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-03 01:50
--- E O F ---
hwfutczk.exe;C:\Documents and Settings\All Users\Application Data;Trojan.Swizzor;Deleted.;
Temp_NAME_;C:\Documents and Settings\Zac Thiele\Local Settings;Trojan.DownLoader.based;Deleted.;
backup-20070702-235318-392.dll;C:\Program Files\HijackThis\backups;Trojan.DownLoader.24732;Deleted.;
Process.exe;C:\SDFix\apps;Tool.Prockill;Incurable.Moved.;
A0005658.dll;C:\System Volume Information\_restore{A8FB012F-BFEC-4849-8A67-726196FE896A}\RP38;Trojan.DownLoader.24818;Deleted.; A0006241.exe;C:\System Volume Information\_restore{A8FB012F-BFEC-4849-8A67-726196FE896A}\RP46;Trojan.LowZones.234;Deleted.; A0006242.exe;C:\System Volume Information\_restore{A8FB012F-BFEC-4849-8A67-726196FE896A}\RP46;BackDoor.Generic.1409;Deleted.; A0006259.exe;C:\System Volume Information\_restore{A8FB012F-BFEC-4849-8A67-726196FE896A}\RP46;Trojan.LowZones.234;Deleted.; A0006260.exe;C:\System Volume Information\_restore{A8FB012F-BFEC-4849-8A67-726196FE896A}\RP46;BackDoor.Generic.1409;Deleted.; A0006298.exe;C:\System Volume Information\_restore{A8FB012F-BFEC-4849-8A67-726196FE896A}\RP46;Trojan.Swizzor;Deleted.; A0006299.dll;C:\System Volume Information\_restore{A8FB012F-BFEC-4849-8A67-726196FE896A}\RP46;Trojan.DownLoader.24732;Deleted.; os1zn2mO7Z.exe;C:\WINDOWS;Trojan.Swizzor;Deleted.;
6VTbJnDH.dll;C:\WINDOWS\system32;Trojan.DownLoader.24732;Deleted.;
actskn45.ocx;C:\WINDOWS\system32;Trojan.Isbar.439;Deleted.;
msdn_lib.dll.bak;C:\WINDOWS\system32;Trojan.DownLoader.24818;Deleted.;
msorcl32.exe;C:\WINDOWS\system32;BackDoor.Generic.1599;Deleted.;
wmvds32.dll;C:\WINDOWS\system32;Trojan.DownLoader.23174;Deleted.;
SDFix: Version 1.89
Run by Zac Thiele on Tue 07/03/2007 at 12:04 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
core
ImagePath:
system32\drivers\core.sys
core - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Missing Security Center Service
Restoring Missing SharedAccess Service
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINDOWS\csrss.exe - Deleted
C:\WINDOWS\ieredir.exe - Deleted
C:\WINDOWS\preredir.exe - Deleted
C:\WINDOWS\system32\~.exe - Deleted
C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\install.exe - Deleted
Removing Temp Files...
ADS Check:
Checking C:\WINDOWS
C:\WINDOWS
No streams found.
Checking C:\WINDOWS\system32
C:\WINDOWS\system32
No streams found.
Checking C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.
Checking C:\WINDOWS\system32\ntoskrnl.exe
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files:
---------------
Backups Folder: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
C:\Documents and Settings\Zac Thiele\Desktop\Unused Desktop Shortcuts\Word\MSDE2000\SQLRESLD.DLL
C:\Documents and Settings\Zac Thiele\Application Data\U3\temp\Launchpad Removal.exe
C:\Documents and Settings\Zac Thiele\Application Data\Verizon\VSP\downloads\vz-sas-tutorials-2006-09_v2.18467.zip.dir\en\images\Thumbs.db
Finished