ComboFix 07-12-30.1 - Edwin Tan 2007-12-30 22:24:11.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1543 [GMT 8:00]
Running from: D:\ComboFix.exe
Command switches used :: D:\CFScript.txt
* Created a new restore point
FILE
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\symlcsv1.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\QuickTime\QTTask .exe
C:\symlcsv1.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-30 )))))))))))))))))))))))))))))))
.
2007-12-25 00:41 . 2007-12-25 00:41 d-------- C:\Program Files\Trend Micro
2007-12-21 10:21 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-12-21 10:21 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2007-12-21 10:21 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2007-12-21 00:02 . 2007-12-30 21:59 d-------- C:\Program Files\MSN Messenger
2007-12-20 22:38 . 2007-12-20 22:38 d-------- C:\Program Files\Windows Live
2007-12-20 22:38 . 2007-12-20 22:38 d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-20 22:38 . 2007-12-20 22:38 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-11-30 23:57 . 2007-11-30 23:57 317,616 --a------ C:\WINDOWS\system32\drivers\srtspl.sys
2007-11-30 23:57 . 2007-11-30 23:57 279,088 --a------ C:\WINDOWS\system32\drivers\srtsp.sys
2007-11-30 23:57 . 2007-11-30 23:57 43,696 --a------ C:\WINDOWS\system32\drivers\srtspx.sys
2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspx.cat
2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspl.cat
2007-11-30 23:57 . 2007-11-30 23:57 10,545 --a------ C:\WINDOWS\system32\drivers\srtsp.cat
2007-11-30 23:57 . 2007-11-30 23:57 1,430 --a------ C:\WINDOWS\system32\drivers\srtspl.inf
2007-11-30 23:57 . 2007-11-30 23:57 1,421 --a------ C:\WINDOWS\system32\drivers\srtspx.inf
2007-11-30 23:57 . 2007-11-30 23:57 1,415 --a------ C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-17 23:58 . 2007-12-30 12:30 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-11-17 23:58 . 2007-11-17 23:58 1,409 --a------ C:\WINDOWS\QTFont.for
2007-11-17 23:57 . 2007-12-30 22:24 d-------- C:\Program Files\QuickTime
2007-11-17 23:57 . 2007-12-30 21:59 d-------- C:\Program Files\iTunes
2007-11-17 23:57 . 2007-11-17 23:57 d-------- C:\Program Files\iPod
2007-11-17 23:57 . 2007-11-17 23:57 d-------- C:\Documents and Settings\Edwin Tan\Application Data\Apple Computer
2007-11-17 23:57 . 2007-11-17 23:57 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-17 23:56 . 2007-11-17 23:56 d-------- C:\Program Files\Common Files\Apple
2007-11-17 23:56 . 2007-11-17 23:56 d-------- C:\Program Files\Apple Software Update
2007-11-17 23:56 . 2007-11-17 23:56 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2007-11-17 23:56 . 2007-10-31 14:09 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2007-11-14 23:43 . 2007-11-14 23:43 65,536 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2007-11-14 23:43 . 2007-11-14 23:43 49,152 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-30 14:05 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-30 13:59 --------- d-----w C:\Program Files\Microsoft IntelliType Pro
2007-12-30 13:59 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2007-12-30 04:38 --------- d-----w C:\Program Files\Norton AntiVirus
2007-12-30 04:38 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-30 04:30 15,360 ----a-w C:\WINDOWS\system32\ctfmon.exe
2007-12-13 07:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-13 07:33 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-13 07:33 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-13 07:33 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-13 07:33 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-13 07:33 --------- d-----w C:\Program Files\Symantec
2007-11-20 02:34 --------- d-----w C:\Program Files\Java
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 11:55 625,032 ----a-w C:\WINDOWS\system32\SymNeti.dll
2007-10-30 11:55 39,856 ----a-w C:\WINDOWS\system32\drivers\symids.sys
2007-10-30 11:55 37,936 ----a-w C:\WINDOWS\system32\drivers\symndisv.sys
2007-10-30 11:55 35,120 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
2007-10-30 11:55 27,696 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
2007-10-30 11:55 242,056 ----a-w C:\WINDOWS\system32\SymRedir.dll
2007-10-30 11:55 191,536 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
2007-10-30 11:55 145,968 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
2007-10-30 11:55 12,848 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
2007-10-30 11:24 12,963 ----a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2007-10-30 11:24 1,358 ----a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 09:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-25 15:12 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
.
((((((((((((((((((((((((((((( snapshot@2007-12-30_21.03.35.96 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-03 14:32:00 208,952 ----a-w C:\WINDOWS\ime\imjp8_1\imjpmig.exe
+ 2007-12-30 04:30:06 208,952 ----a-w C:\WINDOWS\ime\imjp8_1\imjpmig.exe
+ 2007-12-30 14:05:40 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81100000003}\SC_Reader.exe
- 2004-08-03 16:56:50 15,360 -c--a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
+ 2007-12-30 04:30:15 15,360 -c--a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
- 2004-08-03 14:32:00 208,952 -c--a-w C:\WINDOWS\system32\dllcache\imjpmig.exe
+ 2007-12-30 04:30:06 208,952 -c--a-w C:\WINDOWS\system32\dllcache\imjpmig.exe
- 2004-08-03 14:31:50 59,392 -c--a-w C:\WINDOWS\system32\dllcache\imscinst.exe
+ 2007-12-30 04:30:07 59,392 -c--a-w C:\WINDOWS\system32\dllcache\imscinst.exe
- 2004-08-03 14:32:16 455,168 -c--a-w C:\WINDOWS\system32\dllcache\tintsetp.exe
+ 2007-12-30 04:30:09 455,168 -c--a-w C:\WINDOWS\system32\dllcache\tintsetp.exe
- 2004-08-03 14:31:50 59,392 ----a-w C:\WINDOWS\system32\IME\PINTLGNT\imscinst.exe
+ 2007-12-30 04:30:07 59,392 ----a-w C:\WINDOWS\system32\IME\PINTLGNT\imscinst.exe
- 2004-08-03 14:32:16 455,168 ----a-w C:\WINDOWS\system32\IME\TINTLGNT\tintsetp.exe
+ 2007-12-30 04:30:09 455,168 ----a-w C:\WINDOWS\system32\IME\TINTLGNT\tintsetp.exe
+ 2007-12-30 14:22:15 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_a4c.dat
+ 2006-06-05 06:14:28 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
+ 2006-06-05 06:14:28 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
+ 2006-06-05 06:14:28 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-12-30 12:30]
"ares"="C:\Program Files\Ares\Ares.exe" []
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" []
"36X Raid Configurer"="C:\WINDOWS\System32\JMRaidSetup.exe" []
"SkyTel"="SkyTel.EXE" [2006-05-16 18:04 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 17:21 C:\WINDOWS\RTHDCPL.exe]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2007-12-30 12:30]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2007-12-30 12:30]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2007-12-30 12:30]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2007-12-30 12:30]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
"NoToolbarsOnTaskbar"= 0 (0x0)
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-06-08 17:59]
.
Contents of the 'Scheduled Tasks' folder
"2007-12-27 14:57:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-06-11 12:14:50 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Edwin Tan.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-30 22:25:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-30 22:25:22
C:\qoobox\ComboFix-quarantined-files.txt 2007-12-30 14:25:10
C:\qoobox\ComboFix2.txt 2007-12-30 13:04:03
.
2007-12-20 16:20:36 --- E O F ---