ComboFix Log
ComboFix 08-09-28.05 - Customer 2008-09-30 6:28:59.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.63 [GMT -5:00]
Running from: C:\Documents and Settings\Customer\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-30 )))))))))))))))))))))))))))))))
.
2008-09-29 21:19 . 2008-09-29 21:19 <DIR> d-------- C:\Documents and Settings\Customer\Application Data\Malwarebytes
2008-09-29 21:19 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-29 21:18 . 2008-09-29 21:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-29 21:18 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-29 21:17 . 2008-09-29 21:23 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-28 15:22 . 2008-09-28 15:22 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-09-18 17:57 . 2008-09-28 15:11 1,636 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-08-29 16:11 . 2008-08-29 16:11 249,592 --a------ C:\WINDOWS\system32\cssdll32.dll
2008-08-29 16:10 . 2008-08-29 16:10 <DIR> d-------- C:\Program Files\AskSBar
2008-08-29 15:50 . 2008-08-29 15:50 <DIR> d-------- C:\Documents and Settings\Customer\Application Data\Comodo
2008-08-29 15:50 . 2008-08-29 17:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-08-29 15:50 . 2008-08-29 15:49 143,104 --a------ C:\WINDOWS\system32\guard32.dll
2008-08-29 15:50 . 2008-08-29 15:49 87,056 --a------ C:\WINDOWS\system32\drivers\cmdguard.sys
2008-08-29 15:50 . 2008-08-29 15:49 24,208 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-08-29 15:49 . 2008-08-29 16:11 <DIR> d-------- C:\Program Files\COMODO
2008-08-29 11:49 . 2008-08-29 11:49 <DIR> d-------- C:\Program Files\Avira
2008-08-29 11:49 . 2008-08-29 11:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-08-27 15:04 . 2008-08-27 15:18 <DIR> d-------- C:\Program Files\Byron
2008-08-27 15:01 . 1999-03-23 09:12 299,520 --a------ C:\WINDOWS\uninst.exe
2008-08-26 10:15 . 2008-08-26 10:15 <DIR> d-------- C:\Program Files\Apple Software Update
2008-08-25 16:53 . 2008-08-25 16:53 <DIR> d-------- C:\Documents and Settings\Customer\Application Data\F-Secure
2008-08-25 16:14 . 2008-08-29 11:58 <DIR> d-------- C:\Program Files\EMBARQ Online Security
2008-08-25 16:13 . 2008-08-29 11:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\F-Secure
2008-08-25 16:12 . 2008-08-25 16:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\fssg
2008-08-24 02:34 . 2008-08-24 02:34 <DIR> d-------- C:\Program Files\Microsoft Reader
2008-08-24 02:34 . 2003-06-05 17:15 57,436 --a------ C:\WINDOWS\DASShp.dll
2008-08-23 19:20 . 2008-08-23 19:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\QB9 S.R.L
2008-08-22 18:26 . 2008-08-22 18:29 <DIR> d-------- C:\Documents and Settings\Customer\Application Data\Snood
2008-08-22 18:18 . 2008-08-22 18:29 <DIR> d-------- C:\Program Files\Snood Deluxe
2008-08-19 21:10 . 2008-09-06 07:40 <DIR> d-------- C:\Program Files\Ragu Recipe Widget
2008-08-18 17:34 . 2008-08-18 17:34 <DIR> d-------- C:\Documents and Settings\Customer\Application Data\Gaijin Ent
2008-08-17 22:32 . 2008-06-21 16:28 37,033 --------- C:\WINDOWS\FRGT.ico
2008-08-17 22:31 . 2008-08-17 22:31 <DIR> d-------- C:\Remote Programs
2008-08-17 22:31 . 2008-08-17 22:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Free Ride Games
2008-08-17 22:31 . 2008-08-17 22:31 64 --a------ C:\WINDOWS\GPlrLanc.dat
2008-08-17 22:30 . 2008-06-17 16:31 53,305 --------- C:\WINDOWS\ExentInfo.exe
2008-08-17 22:29 . 2008-08-17 22:42 <DIR> d-------- C:\Program Files\Free Ride Games
2008-08-17 20:58 . 2008-08-17 20:58 <DIR> d-------- C:\Documents and Settings\Customer\Application Data\SpinTop
2008-08-17 15:42 . 2008-08-18 16:24 <DIR> d-------- C:\Program Files\Zylom Games
2008-08-14 00:19 . 2008-08-14 00:19 <DIR> d-------- C:\Program Files\Microsoft
2008-08-13 23:45 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-08-13 23:41 . 2008-08-13 23:41 <DIR> d-------- C:\Program Files\Microsoft Works
2008-08-13 23:38 . 2008-08-13 23:38 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-08-13 23:31 . 2008-08-13 23:32 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-08-13 23:29 . 2008-09-21 12:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-13 23:27 . 2008-08-13 23:27 <DIR> dr-h----- C:\MSOCache
2008-08-07 19:47 . 2008-08-07 19:47 <DIR> d-------- C:\WINDOWS\Claris
2008-08-07 19:47 . 2008-08-07 19:54 <DIR> d-------- C:\Program Files\CookBook
2008-08-07 19:47 . 1999-12-17 10:13 80,880 --a------ C:\WINDOWS\unvise.exe
2008-08-07 19:47 . 1999-10-22 09:22 32,768 --a------ C:\WINDOWS\unvise32.dll
2008-08-01 04:41 . 2008-08-01 04:41 <DIR> d-------- C:\Program Files\Lavasoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-30 11:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-30 11:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-28 20:21 --------- d-----w C:\Program Files\Common Files\Real
2008-09-28 20:19 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-09-28 20:19 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-09-15 15:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-30 08:36 --------- d-----w C:\Documents and Settings\Customer\Application Data\Yahoo!
2008-08-29 23:04 --------- d-----w C:\Program Files\Total Security 2007
2008-08-26 15:19 --------- d-----w C:\Documents and Settings\Customer\Application Data\Apple Computer
2008-08-26 14:47 --------- d-----w C:\Program Files\iWin.com
2008-08-26 14:40 --------- d-----w C:\Program Files\RealArcade
2008-08-25 21:04 --------- d-----w C:\Program Files\SpywareBlaster
2008-08-24 07:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-18 21:22 --------- d-----w C:\Documents and Settings\Customer\Application Data\EMBARQTOOLBAR
2008-08-17 21:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zylom
2008-08-14 05:57 --------- d-----w C:\Program Files\GraphicView32
2008-08-14 05:48 --------- d-----w C:\Program Files\Conference
2008-08-09 14:56 --------- d-----w C:\Program Files\MozyHome
2008-08-08 00:47 2,531 ----a-w C:\Program Files\uninstal.log
2008-07-31 14:51 --------- d-----w C:\Documents and Settings\Customer\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-07-28 19:51 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-07-28 19:39 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-28 16:14 --------- d-----w C:\Program Files\R-TT
2008-07-28 16:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-19 03:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 03:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 03:10 45,768 -c--a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 03:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 03:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 03:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 03:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 03:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 03:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 03:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 00:07 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-07-03 03:29 691,545 ----a-w C:\WINDOWS\unins001.exe
2008-07-03 02:12 0 ----a-w C:\Documents and Settings\Customer\jagex_runescape_preferences.dat
2008-06-24 23:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:36 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:36 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:36 147,968 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:44 360,960 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:32 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\dllcache\bthport.sys
2007-08-06 16:23 81 -c--a-w C:\Program Files\MRWINCD.INI
2005-10-21 11:38 14 -c--a-w C:\Documents and Settings\Guest\iphist.dat
2005-06-16 23:23 774,144 -c--a-w C:\Program Files\RngInterstitial.dll
2005-05-22 14:12 20,798,256 -c--a-w C:\Program Files\AdbeRdr70_enu_full.exe
2005-05-22 14:02 6,811,904 -c--a-w C:\Program Files\psa2011se_us.exe
2005-05-22 14:00 494,704 -c--a-w C:\Program Files\ytb01_efgsip.exe
1996-09-20 02:36 389,152 -c--a-w C:\Program Files\MRWIN32.EXE
1996-08-29 20:06 766 -c--a-w C:\Program Files\MRWINCD.ICO
1994-02-15 23:23 60,774 -c--a-w C:\Program Files\MRWIN.HLP
2005-06-12 20:05 56 -csh--r C:\WINDOWS\system32\D80FFE410C.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{AB26BF6C-BB04-4F00-8F98-BDE786CDE97D}"= "C:\WINDOWS\system32\EFOToolbar.dll" [2008-03-31 278528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{AB26BF6C-BB04-4F00-8F98-BDE786CDE97D}"= "C:\WINDOWS\system32\EFOToolbar.dll" [2008-03-31 278528]
[HKEY_CLASSES_ROOT\clsid\{ab26bf6c-bb04-4f00-8f98-bde786cde97d}]
[HKEY_CLASSES_ROOT\EFOToolbar.EFOObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{668611E3-7EC2-44EF-BF11-2D814E19FAA3}]
[HKEY_CLASSES_ROOT\EFOToolbar.EFOObj]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4A9D-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4A9D-BDFE-192AAD5099B1}]
2008-07-14 10:26 2405680 --a------ C:\Program Files\MozyHome\mozyshell1.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40F7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40F7-AB77-51FF9D6DEB20}]
2008-07-14 10:26 2405680 --a------ C:\Program Files\MozyHome\mozyshell1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Motive SmartBridge"="C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe" [2006-04-21 438359]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 413696]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"COMODO SafeSurf"="C:\Program Files\COMODO\SafeSurf\cssurf.exe" [2008-08-29 278264]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-08-29 1655552]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-09-28 185872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Exetender"="C:\Program Files\Free Ride Games\GPlayer.exe" [2008-06-17 2057728]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
EMBARQ Help.lnk - C:\Program Files\Virtual Assistant\bin\matcli.exe [2008-06-27 217088]
MozyHome Status.lnk - C:\Program Files\MozyHome\mozystat.exe [2008-07-20 2311472]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax DllCmd 4.0.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eFax DllCmd 4.0.lnk
backup=C:\WINDOWS\pss\eFax DllCmd 4.0.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Tray Menu 4.0.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eFax Tray Menu 4.0.lnk
backup=C:\WINDOWS\pss\eFax Tray Menu 4.0.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Customer^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\Customer\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Customer^Start Menu^Programs^Startup^TypeItIn.lnk]
path=C:\Documents and Settings\Customer\Start Menu\Programs\Startup\TypeItIn.lnk
backup=C:\WINDOWS\pss\TypeItIn.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-08-29 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-08-29 24208]
R1 mozyFilter;mozyFilter;C:\WINDOWS\system32\DRIVERS\mozy.sys [2008-06-11 53752]
R2 iWinGamesInstaller;iWinGamesInstaller;C:\Program Files\iWin Games\iWinGamesInstaller.exe [2008-07-07 78104]
R2 McciCMService;McciCMService;C:\Program Files\Common Files\Motive\McciCMService.exe [2008-04-01 303104]
R2 X4HSX32Ex;X4HSX32Ex;C:\Program Files\Free Ride Games\X4HSX32Ex.Sys [2007-11-14 29856]
R3 SiSV;SiSV;C:\WINDOWS\system32\DRIVERS\SiSV.sys [2001-08-17 50432]
S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2008-04-01 19712]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [ ]
S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2008-04-01 18304]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [ ]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Customer\Application Data\Mozilla\Firefox\Profiles\zxb0z8lg.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://sckesc.owotw.com/
FF -: plugin - C:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF -: plugin - C:\Program Files\Free Ride Games\npExentCtl.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Microsoft\Office Live\npOLW.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\nppopcaploader.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npqtplugin8.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF -: plugin - C:\Program Files\QuickTime\Plugins\npqtplugin8.dll
FF -: plugin - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-30 06:40:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\MozyHome\mozyshell1.dll
-> ?:\WINDOWS\system32\mydocs.dll
-> ?:\WINDOWS\system32\mydocs.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\MozyHome\mozybackup.exe
.
**************************************************************************
.
Completion time: 2008-09-30 6:55:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-30 11:54:48
ComboFix2.txt 2008-07-27 16:47:07
Pre-Run: 28,776,972,288 bytes free
Post-Run: 28,730,753,024 bytes free
246 --- E O F --- 2008-09-10 08:08:42