Hello,
I have been infested with ise32 Property window which keep appearing on window start up. I have scan my computer with Norton 360 and Window defender but to no avail. I would appreciate your help to solve them problem.
Below is the Logfile. I look forward to your reply.
Thank you.
Best reguards,
Leo
ComboFix 08-06-20.4 - xiaoleo 2008-06-27 1:49:14.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1669 [GMT 8:00]
Running from: C:\Users\xiaoleo\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-05-26 to 2008-06-26 )))))))))))))))))))))))))))))))
.
2008-06-25 19:26 . 2008-06-25 19:26 <DIR> d-------- C:\Windows\System32\Adobe
2008-06-24 01:48 . 2008-06-27 01:02 <DIR> d-------- C:\Program Files\Garena
2008-06-23 23:25 . 2008-06-24 21:51 <DIR> d-------- C:\Users\xiaoleo\AppData\Roaming\Hamachi
2008-06-23 23:24 . 2008-06-23 23:25 <DIR> d-------- C:\Program Files\Hamachi
2008-06-23 23:24 . 2008-06-23 23:24 25,280 --a------ C:\Windows\System32\drivers\hamachi.sys
2008-06-20 22:09 . 2008-06-20 22:09 <DIR> d-------- C:\Users\xiaoleo\AppData\Roaming\Fujitsu
2008-06-15 00:17 . 2008-04-23 12:27 1,244,672 --a------ C:\Windows\System32\mcmde.dll
2008-06-15 00:17 . 2008-04-23 12:27 428,032 --a------ C:\Windows\System32\EncDec.dll
2008-06-15 00:17 . 2008-04-23 12:27 292,352 --a------ C:\Windows\System32\psisdecd.dll
2008-06-15 00:17 . 2008-04-23 12:26 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-06-15 00:17 . 2008-04-23 12:26 80,896 --a------ C:\Windows\System32\MSNP.ax
2008-06-15 00:17 . 2008-04-23 12:26 68,608 --a------ C:\Windows\System32\Mpeg2Data.ax
2008-06-15 00:17 . 2008-04-23 12:26 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-06-13 14:14 . 2008-06-13 14:14 24,112 --a------ C:\Windows\System32\drivers\SymIMV.sys
2008-06-13 14:14 . 2008-06-13 14:14 13,093 --a------ C:\Windows\System32\drivers\SymRedir.cat
2008-06-13 14:14 . 2008-06-13 14:14 1,611 --a------ C:\Windows\System32\drivers\SymRedir.inf
2008-06-13 14:13 . 2008-06-13 14:13 184,240 --a------ C:\Windows\System32\drivers\symtdi.sys
2008-06-13 14:13 . 2008-06-13 14:13 96,432 --a------ C:\Windows\System32\drivers\symfw.sys
2008-06-13 14:13 . 2008-06-13 14:13 41,008 --a------ C:\Windows\System32\drivers\symndisv.sys
2008-06-13 14:13 . 2008-06-13 14:13 38,576 --a------ C:\Windows\System32\drivers\symids.sys
2008-06-13 14:13 . 2008-06-13 14:13 22,320 --a------ C:\Windows\System32\drivers\symredrv.sys
2008-06-13 14:13 . 2008-06-13 14:13 13,616 --a------ C:\Windows\System32\drivers\symdns.sys
2008-05-29 00:07 . 2008-03-08 08:37 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-29 00:07 . 2008-03-08 12:30 1,686,528 --a------ C:\Windows\System32\gameux.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-26 17:51 --------- d-----w C:\Users\xiaoleo\AppData\Roaming\Skype
2008-06-26 16:01 --------- d-----w C:\Users\xiaoleo\AppData\Roaming\skypePM
2008-06-23 17:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-20 16:59 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-14 07:07 --------- d-----w C:\Program Files\Windows Mail
2008-06-03 05:17 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2008-06-03 05:17 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2008-06-03 05:17 10,671 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2008-06-03 05:17 --------- d-----w C:\Program Files\Symantec
2008-05-29 18:53 --------- d-----w C:\Program Files\Norton 360
2008-05-29 17:19 --------- d-----w C:\PROGRA~2\Microsoft Help
2008-05-22 13:20 --------- d-----w C:\Program Files\Counter-Strike
2008-05-21 16:38 --------- d-----w C:\Program Files\jGRASP
2008-05-21 12:38 --------- d-----w C:\Program Files\Microsoft Office Communicator
2008-05-21 11:54 --------- d-----w C:\Program Files\MSBuild
2008-05-21 11:51 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-05-13 14:55 --------- d-----w C:\Program Files\Common Files\Motive
2008-05-13 12:39 --------- d-----w C:\Users\xiaoleo\AppData\Roaming\Motive
2008-05-13 12:14 --------- d-----w C:\PROGRA~2\Motive
2008-05-10 16:24 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-10 03:30 14,848 ----a-w C:\Windows\System32\wshrm.dll
2008-05-10 01:21 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
2008-04-26 11:05 --------- d-----w C:\Program Files\Apple Software Update
2008-04-26 08:02 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-04-26 06:00 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-26 04:45 --------- d-----w C:\Program Files\iTunes
2008-04-26 04:45 --------- d-----w C:\Program Files\iPod
2008-04-26 04:32 --------- d-----w C:\Program Files\Bonjour
2008-04-26 04:30 --------- d-----w C:\Program Files\QuickTime
2008-04-26 04:30 --------- d-----w C:\PROGRA~2\Apple Computer
2008-04-26 04:25 --------- d-----w C:\Program Files\Common Files\Apple
2008-04-26 04:25 --------- d-----w C:\PROGRA~2\Apple
2008-04-25 04:23 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-04-25 04:23 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-04-25 04:23 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-25 04:22 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-26 09:45 32 ----a-w C:\Users\All Users\ezsid.dat
2008-02-26 09:45 32 ----a-w C:\PROGRA~2\ezsid.dat
2007-11-14 00:24 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-06-17 14:23 349552 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-04-01 18:06 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@={4433A54A-1AC8-432F-90FC-85F045CF383C}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@={F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@={476D0EA3-80F9-48B5-B70B-05E677C9C148}
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-02-26 16:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-02-26 16:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-02-26 16:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-22 23:40 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 20:34 2159104 C:\Windows\System32\oobefldr.dll]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 17:22 21898024]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 20:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 20:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"LoadFUJ02E3"="C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe" [2006-11-18 07:38 80688]
"IndicatorUtility"="C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2006-11-08 06:45 97072]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-19 14:50 4702208 C:\Windows\RtHDVCpl.exe]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-09-21 09:58 154136]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-09-21 09:58 129560]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-15 11:53 894512]
"331BigDog"="C:\Windows\VM331_STI.EXE" [2007-07-02 13:59 192512]
"ATSwpNav"="C:\Program Files\Fingerprint Sensor\ATSwpNav -run" [ ]
"TvOutSwitch"="c:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe" [2007-09-30 23:59 106496]
"PSUtility"="c:\Program Files\Fujitsu\PSUtility\TrayManager.exe" [2006-10-30 00:37 136744]
"SSUtility"="c:\Program Files\Fujitsu\SSUtility\FJSSDMN.exe" [2006-11-12 11:02 239144]
"LoadFujitsuQuickTouch"="C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe" [2006-11-26 09:09 260912]
"LoadBtnHnd"="C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe" [2006-11-13 08:13 68400]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 13:01 71216]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 14:17 52256]
"OmniPass"="C:\Program Files\Softex\OmniPass\scureapp.exe" [2007-11-03 05:34 2564096]
"ArcSoft Connection Service"="C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 14:14 98616]
"FJUPDNV_Chitose"="C:\Program Files\Fujitsu\updnavi\updatenv.exe" [2007-08-01 23:18 167936]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-19 03:37 51048]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [2008-02-26 22:50 988512]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"PCDrProfiler"="C:\Program Files\Fujitsu Hardware Diagnostics Tool\RunProfiler.exe" [2007-10-05 01:28 73728]
C:\Users\xiaoleo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-02-23 17:14:32 368640]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-08-03 11:41:52 2760704]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{42CA7ED3-1CDF-4F96-BDF5-ADE68EE3D41A}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{D94B800C-6A79-45A2-9F9D-FC5754391E8E}"= C:\Program Files\CyberLink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{8DEFCEEC-4149-4A64-8B71-CFE40E5149A6}"= C:\Program Files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{6A0AA60D-D6D0-4058-8BCB-13C0E65A9160}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{C8C716B9-DB44-40AC-8A41-D3D856867DFB}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{9E5FDAA2-0E1D-4320-8710-D45AFF20421C}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"{CB185D18-C492-4720-9DC9-D11DE0AC915E}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{56A1F001-85FB-4D52-AD54-CD95DAFBB161}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{7FE14F8C-B5BC-44CC-AF3B-CBA3DC99168E}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{2A453B3F-09CF-4A48-9425-9AD3B7C1E3CF}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{0FD3FA6B-6754-4F36-B8CD-AA8E1A7561B0}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{0EB8B3AF-07DB-41E9-8A48-40EDF577ACC6}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{37723FA4-0C70-426A-A73A-A53F63DEEF56}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4AAF87EF-FA13-4C63-902A-1CA19DA8C6AE}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5142AE1F-075F-4D52-9610-B2D3DD14047C}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{FD859AFF-632D-41F6-AFA2-54CDE4A41964}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 FJGSDisk;G-Sensor Application Filter Driver;C:\Windows\system32\DRIVERS\FJGSDisk.sys [2007-12-22 08:02]
R0 O2MDRDR;O2MDRDR;C:\Windows\system32\DRIVERS\o2media.sys [2006-10-03 13:23]
R0 O2SDRDR;O2SDRDR;C:\Windows\system32\DRIVERS\o2sd.sys [2007-05-11 16:56]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080623.001\IDSvix86.sys [2008-02-15 14:56]
R2 ACDaemon;ArcSoft Connect Daemon;C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-04-17 14:14]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R2 PowerSavingUtilityService;PowerSavingUtilityService;c:\Program Files\Fujitsu\PSUtility\PSUService.exe [2006-10-30 00:37]
R2 UpdateNaviInstallService;UpdateNaviInstallService;C:\Program Files\Fujitsu\updnavi\updnvsrv.exe [2007-08-01 23:20]
R3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;C:\Windows\system32\DRIVERS\FUJ02E3.sys [2006-11-01 03:59]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-09-13 15:23]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-06-13 14:13]
R3 vm331avs;VC0334 USB2.0 Digital Camera;C:\Windows\system32\Drivers\vm331avs.sys [2007-09-28 19:05]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-18 10:24]
S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2008-02-05 14:21]
S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2008-02-05 14:30]
S3 SMSCIRDA;SMSC Infrared Device Driver;C:\Windows\system32\DRIVERS\SMSCirda.sys [2006-11-02 15:30]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{00dc48d1-4326-11dd-b43b-0017428dfe18}]
\shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d385005-27dd-11dd-90af-0017428dfe18}]
\shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d44f4101-21a2-11dd-885c-0017428dfe18}]
\shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1f8fe00-2e15-11dd-905a-0017428dfe18}]
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\system.exe
\shell\Explore\command - F:\system.exe
\shell\Open\command - F:\system.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-06-26 17:50:12 C:\Windows\Tasks\User_Feed_Synchronization-{58C6E034-A679-48D2-AB8D-48C5DB2EA99E}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-27 01:51:12
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\Explorer.exe
-> C:\Program Files\Softex\OmniPass\SCUREDLL.dll
.
Completion time: 2008-06-27 1:52:09
ComboFix-quarantined-files.txt 2008-06-26 17:52:01
Pre-Run: 60,779,073,536 bytes free
Post-Run: 60,859,699,200 bytes free
220 --- E O F --- 2008-06-26 12:35:40
I have been infested with ise32 Property window which keep appearing on window start up. I have scan my computer with Norton 360 and Window defender but to no avail. I would appreciate your help to solve them problem.
Below is the Logfile. I look forward to your reply.
Thank you.
Best reguards,
Leo
ComboFix 08-06-20.4 - xiaoleo 2008-06-27 1:49:14.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1669 [GMT 8:00]
Running from: C:\Users\xiaoleo\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-05-26 to 2008-06-26 )))))))))))))))))))))))))))))))
.
2008-06-25 19:26 . 2008-06-25 19:26 <DIR> d-------- C:\Windows\System32\Adobe
2008-06-24 01:48 . 2008-06-27 01:02 <DIR> d-------- C:\Program Files\Garena
2008-06-23 23:25 . 2008-06-24 21:51 <DIR> d-------- C:\Users\xiaoleo\AppData\Roaming\Hamachi
2008-06-23 23:24 . 2008-06-23 23:25 <DIR> d-------- C:\Program Files\Hamachi
2008-06-23 23:24 . 2008-06-23 23:24 25,280 --a------ C:\Windows\System32\drivers\hamachi.sys
2008-06-20 22:09 . 2008-06-20 22:09 <DIR> d-------- C:\Users\xiaoleo\AppData\Roaming\Fujitsu
2008-06-15 00:17 . 2008-04-23 12:27 1,244,672 --a------ C:\Windows\System32\mcmde.dll
2008-06-15 00:17 . 2008-04-23 12:27 428,032 --a------ C:\Windows\System32\EncDec.dll
2008-06-15 00:17 . 2008-04-23 12:27 292,352 --a------ C:\Windows\System32\psisdecd.dll
2008-06-15 00:17 . 2008-04-23 12:26 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-06-15 00:17 . 2008-04-23 12:26 80,896 --a------ C:\Windows\System32\MSNP.ax
2008-06-15 00:17 . 2008-04-23 12:26 68,608 --a------ C:\Windows\System32\Mpeg2Data.ax
2008-06-15 00:17 . 2008-04-23 12:26 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-06-13 14:14 . 2008-06-13 14:14 24,112 --a------ C:\Windows\System32\drivers\SymIMV.sys
2008-06-13 14:14 . 2008-06-13 14:14 13,093 --a------ C:\Windows\System32\drivers\SymRedir.cat
2008-06-13 14:14 . 2008-06-13 14:14 1,611 --a------ C:\Windows\System32\drivers\SymRedir.inf
2008-06-13 14:13 . 2008-06-13 14:13 184,240 --a------ C:\Windows\System32\drivers\symtdi.sys
2008-06-13 14:13 . 2008-06-13 14:13 96,432 --a------ C:\Windows\System32\drivers\symfw.sys
2008-06-13 14:13 . 2008-06-13 14:13 41,008 --a------ C:\Windows\System32\drivers\symndisv.sys
2008-06-13 14:13 . 2008-06-13 14:13 38,576 --a------ C:\Windows\System32\drivers\symids.sys
2008-06-13 14:13 . 2008-06-13 14:13 22,320 --a------ C:\Windows\System32\drivers\symredrv.sys
2008-06-13 14:13 . 2008-06-13 14:13 13,616 --a------ C:\Windows\System32\drivers\symdns.sys
2008-05-29 00:07 . 2008-03-08 08:37 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-29 00:07 . 2008-03-08 12:30 1,686,528 --a------ C:\Windows\System32\gameux.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-26 17:51 --------- d-----w C:\Users\xiaoleo\AppData\Roaming\Skype
2008-06-26 16:01 --------- d-----w C:\Users\xiaoleo\AppData\Roaming\skypePM
2008-06-23 17:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-20 16:59 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-14 07:07 --------- d-----w C:\Program Files\Windows Mail
2008-06-03 05:17 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2008-06-03 05:17 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2008-06-03 05:17 10,671 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2008-06-03 05:17 --------- d-----w C:\Program Files\Symantec
2008-05-29 18:53 --------- d-----w C:\Program Files\Norton 360
2008-05-29 17:19 --------- d-----w C:\PROGRA~2\Microsoft Help
2008-05-22 13:20 --------- d-----w C:\Program Files\Counter-Strike
2008-05-21 16:38 --------- d-----w C:\Program Files\jGRASP
2008-05-21 12:38 --------- d-----w C:\Program Files\Microsoft Office Communicator
2008-05-21 11:54 --------- d-----w C:\Program Files\MSBuild
2008-05-21 11:51 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-05-13 14:55 --------- d-----w C:\Program Files\Common Files\Motive
2008-05-13 12:39 --------- d-----w C:\Users\xiaoleo\AppData\Roaming\Motive
2008-05-13 12:14 --------- d-----w C:\PROGRA~2\Motive
2008-05-10 16:24 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-10 03:30 14,848 ----a-w C:\Windows\System32\wshrm.dll
2008-05-10 01:21 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
2008-04-26 11:05 --------- d-----w C:\Program Files\Apple Software Update
2008-04-26 08:02 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-04-26 06:00 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-26 04:45 --------- d-----w C:\Program Files\iTunes
2008-04-26 04:45 --------- d-----w C:\Program Files\iPod
2008-04-26 04:32 --------- d-----w C:\Program Files\Bonjour
2008-04-26 04:30 --------- d-----w C:\Program Files\QuickTime
2008-04-26 04:30 --------- d-----w C:\PROGRA~2\Apple Computer
2008-04-26 04:25 --------- d-----w C:\Program Files\Common Files\Apple
2008-04-26 04:25 --------- d-----w C:\PROGRA~2\Apple
2008-04-25 04:23 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-04-25 04:23 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-04-25 04:23 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-25 04:22 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-26 09:45 32 ----a-w C:\Users\All Users\ezsid.dat
2008-02-26 09:45 32 ----a-w C:\PROGRA~2\ezsid.dat
2007-11-14 00:24 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-06-17 14:23 349552 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-04-01 18:06 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@={4433A54A-1AC8-432F-90FC-85F045CF383C}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@={F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@={476D0EA3-80F9-48B5-B70B-05E677C9C148}
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-02-26 16:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-02-26 16:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-02-26 16:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-22 23:40 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 20:34 2159104 C:\Windows\System32\oobefldr.dll]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 17:22 21898024]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 20:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 20:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"LoadFUJ02E3"="C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe" [2006-11-18 07:38 80688]
"IndicatorUtility"="C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2006-11-08 06:45 97072]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-19 14:50 4702208 C:\Windows\RtHDVCpl.exe]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-09-21 09:58 154136]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-09-21 09:58 129560]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-15 11:53 894512]
"331BigDog"="C:\Windows\VM331_STI.EXE" [2007-07-02 13:59 192512]
"ATSwpNav"="C:\Program Files\Fingerprint Sensor\ATSwpNav -run" [ ]
"TvOutSwitch"="c:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe" [2007-09-30 23:59 106496]
"PSUtility"="c:\Program Files\Fujitsu\PSUtility\TrayManager.exe" [2006-10-30 00:37 136744]
"SSUtility"="c:\Program Files\Fujitsu\SSUtility\FJSSDMN.exe" [2006-11-12 11:02 239144]
"LoadFujitsuQuickTouch"="C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe" [2006-11-26 09:09 260912]
"LoadBtnHnd"="C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe" [2006-11-13 08:13 68400]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 13:01 71216]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 14:17 52256]
"OmniPass"="C:\Program Files\Softex\OmniPass\scureapp.exe" [2007-11-03 05:34 2564096]
"ArcSoft Connection Service"="C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 14:14 98616]
"FJUPDNV_Chitose"="C:\Program Files\Fujitsu\updnavi\updatenv.exe" [2007-08-01 23:18 167936]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-19 03:37 51048]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [2008-02-26 22:50 988512]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"PCDrProfiler"="C:\Program Files\Fujitsu Hardware Diagnostics Tool\RunProfiler.exe" [2007-10-05 01:28 73728]
C:\Users\xiaoleo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-02-23 17:14:32 368640]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-08-03 11:41:52 2760704]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{42CA7ED3-1CDF-4F96-BDF5-ADE68EE3D41A}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{D94B800C-6A79-45A2-9F9D-FC5754391E8E}"= C:\Program Files\CyberLink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{8DEFCEEC-4149-4A64-8B71-CFE40E5149A6}"= C:\Program Files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{6A0AA60D-D6D0-4058-8BCB-13C0E65A9160}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{C8C716B9-DB44-40AC-8A41-D3D856867DFB}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{9E5FDAA2-0E1D-4320-8710-D45AFF20421C}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"{CB185D18-C492-4720-9DC9-D11DE0AC915E}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{56A1F001-85FB-4D52-AD54-CD95DAFBB161}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{7FE14F8C-B5BC-44CC-AF3B-CBA3DC99168E}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{2A453B3F-09CF-4A48-9425-9AD3B7C1E3CF}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{0FD3FA6B-6754-4F36-B8CD-AA8E1A7561B0}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{0EB8B3AF-07DB-41E9-8A48-40EDF577ACC6}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{37723FA4-0C70-426A-A73A-A53F63DEEF56}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4AAF87EF-FA13-4C63-902A-1CA19DA8C6AE}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5142AE1F-075F-4D52-9610-B2D3DD14047C}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{FD859AFF-632D-41F6-AFA2-54CDE4A41964}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 FJGSDisk;G-Sensor Application Filter Driver;C:\Windows\system32\DRIVERS\FJGSDisk.sys [2007-12-22 08:02]
R0 O2MDRDR;O2MDRDR;C:\Windows\system32\DRIVERS\o2media.sys [2006-10-03 13:23]
R0 O2SDRDR;O2SDRDR;C:\Windows\system32\DRIVERS\o2sd.sys [2007-05-11 16:56]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080623.001\IDSvix86.sys [2008-02-15 14:56]
R2 ACDaemon;ArcSoft Connect Daemon;C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-04-17 14:14]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R2 PowerSavingUtilityService;PowerSavingUtilityService;c:\Program Files\Fujitsu\PSUtility\PSUService.exe [2006-10-30 00:37]
R2 UpdateNaviInstallService;UpdateNaviInstallService;C:\Program Files\Fujitsu\updnavi\updnvsrv.exe [2007-08-01 23:20]
R3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;C:\Windows\system32\DRIVERS\FUJ02E3.sys [2006-11-01 03:59]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-09-13 15:23]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-06-13 14:13]
R3 vm331avs;VC0334 USB2.0 Digital Camera;C:\Windows\system32\Drivers\vm331avs.sys [2007-09-28 19:05]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-18 10:24]
S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2008-02-05 14:21]
S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2008-02-05 14:30]
S3 SMSCIRDA;SMSC Infrared Device Driver;C:\Windows\system32\DRIVERS\SMSCirda.sys [2006-11-02 15:30]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{00dc48d1-4326-11dd-b43b-0017428dfe18}]
\shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d385005-27dd-11dd-90af-0017428dfe18}]
\shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d44f4101-21a2-11dd-885c-0017428dfe18}]
\shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1f8fe00-2e15-11dd-905a-0017428dfe18}]
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\system.exe
\shell\Explore\command - F:\system.exe
\shell\Open\command - F:\system.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-06-26 17:50:12 C:\Windows\Tasks\User_Feed_Synchronization-{58C6E034-A679-48D2-AB8D-48C5DB2EA99E}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-27 01:51:12
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\Explorer.exe
-> C:\Program Files\Softex\OmniPass\SCUREDLL.dll
.
Completion time: 2008-06-27 1:52:09
ComboFix-quarantined-files.txt 2008-06-26 17:52:01
Pre-Run: 60,779,073,536 bytes free
Post-Run: 60,859,699,200 bytes free
220 --- E O F --- 2008-06-26 12:35:40

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top









