ComboFix 09-01-21.04 - JJ 2009-01-22 8:43:55.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.249 [GMT -8:00]
Running from: c:\documents and settings\JJ.HOME\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\SYSTEM32\qWadfMoq.ini
c:\windows\SYSTEM32\qWadfMoq.ini2
c:\windows\system32\tqojrttt.ini
c:\windows\system32\tshxtbqo.ini
.
((((((((((((((((((((((((( Files Created from 2008-12-22 to 2009-01-22 )))))))))))))))))))))))))))))))
.
2009-01-22 08:28 . 2009-01-22 08:28 <DIR> d--hs---- C:\FOUND.006
2009-01-20 19:02 . 2009-01-20 19:02 <DIR> d--hs---- C:\FOUND.005
2009-01-15 11:08 . 2009-01-15 11:08 <DIR> d--hs---- C:\FOUND.004
2009-01-14 00:14 . 2009-01-13 22:18 <DIR> d-------- C:\32788R22FWJFW.0.tmp
2009-01-13 23:59 . 2009-01-13 23:59 <DIR> d-------- c:\program files\Trend Micro
2009-01-13 23:21 . 2009-01-22 08:49 1,104 --a------ c:\windows\ordzblzj
2009-01-13 11:35 . 2009-01-13 11:35 <DIR> d--h----- C:\$AVG8.VAULT$
2009-01-12 11:00 . 2009-01-12 11:00 <DIR> d-------- c:\windows\SYSTEM32\DRIVERS\Avg
2009-01-12 11:00 . 2009-01-12 11:00 <DIR> d-------- c:\documents and settings\JJ.HOME\Application Data\AVGTOOLBAR
2009-01-12 11:00 . 2009-01-12 11:00 97,928 --a------ c:\windows\SYSTEM32\DRIVERS\avgldx86.sys
2009-01-12 11:00 . 2009-01-12 11:00 10,520 --a------ c:\windows\SYSTEM32\avgrsstx.dll
2009-01-12 10:59 . 2009-01-12 10:59 <DIR> d-------- c:\program files\AVG
2009-01-12 10:59 . 2009-01-12 10:59 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\avg8
2009-01-12 01:02 . 2009-01-12 01:02 <DIR> d-------- c:\program files\2K Games
2009-01-12 00:46 . 2009-01-12 00:46 <DIR> d--hs---- C:\FOUND.003
2009-01-03 17:28 . 2009-01-03 17:28 <DIR> d-------- c:\program files\Microsoft Silverlight
2008-12-30 00:02 . 2008-12-30 00:02 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-22 00:18 33,688 ----a-w c:\documents and settings\JJ.HOME\Application Data\GDIPFONTCACHEV1.DAT
2008-12-14 00:16 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-13 06:40 3,593,216 ------w c:\windows\SYSTEM32\dllcache\mshtml.dll
2008-12-05 06:25 --------- d-----w c:\program files\Common Files\AOL
2008-12-05 06:25 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Viewpoint
2008-12-05 06:25 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\AOL OCP
2008-12-05 06:25 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\AOL
2008-12-04 05:29 --------- d-----w c:\program files\desktopsites
2008-12-04 02:42 --------- d-----w c:\program files\Logitech
2008-10-24 11:21 455,296 ------w c:\windows\SYSTEM32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
2008-10-23 12:36 286,720 ------w c:\windows\SYSTEM32\dllcache\gdi32.dll
2007-11-13 23:49 32 ----a-r c:\documents and settings\All Users\hash.dat
2000-06-21 00:37 271 --sh--w c:\program files\desktop.ini
2000-06-21 00:37 23,357 ---h--w c:\program files\folder.htt
2008-09-11 01:34 32,768 --sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091020080911\index.dat
.
((((((((((((((((((((((((((((( snapshot@2009-01-18_13.19.11.84 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-12 1261336]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Hawking Wireless Utility.lnk - c:\program files\Hawking\HWU8DD\HWU8DD.exe [2007-12-03 479232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.mpng"= c:\program files\t@b\0.952\686\tabdec.dll
"vidc.mvjp"= c:\program files\t@b\0.952\686\tabdec.dll
"vidc.444p"= c:\program files\t@b\0.952\686\tabdec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^JJ.HOME^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
path=c:\documents and settings\JJ.HOME\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
backup=c:\windows\pss\Logitech . Product Registration.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 17:12 15360 c:\windows\SYSTEM32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a------ 2008-09-22 01:27 133104 c:\documents and settings\JJ.HOME\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gStart]
--a------ 2007-08-23 05:58 1891416 c:\garmin\gStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-11-13 13:39 1289000 c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
--a------ 2008-08-14 17:11 565008 c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
--a------ 2008-08-14 17:15 2407184 c:\program files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 16:45 313472 c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\RAPIMGR.EXE"= c:\program files\Microsoft ActiveSync\RAPIMGR.EXE:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"c:\\Documents and Settings\\JJ.HOME\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\JJ.HOME\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"57506:TCP"= 57506:TCP:Pando P2P TCP Listening Port
"57506:UDP"= 57506:UDP:Pando P2P UDP Listening Port
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [2009-01-12 97928]
R3 ZD1211U(Hawking);Hawking Hi-Gain Wireless-G USB Dish Adapter(Hawking);c:\windows\SYSTEM32\DRIVERS\ZD1211U.sys [2007-12-03 278016]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-12 231704]
S0 ordzblzj;ordzblzj;c:\windows\SYSTEM32\DRIVERS\emvpjnpi.sys []
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;c:\windows\SYSTEM32\DRIVERS\BRGSp50.sys [2007-11-29 20608]
S3 IrCOMM2k;Virtueller Infrarot-Kommunikationsanschluß;c:\windows\system32\DRIVERS\ircomm2k.sys --> c:\windows\system32\DRIVERS\ircomm2k.sys [?]
S3 qcmdmxp;HTC Proprietary USB Driver (PID 0B03);c:\windows\SYSTEM32\DRIVERS\qcmdmxp.sys [2008-06-28 92800]
S3 qcserxp;HTC Diagnostic Port (PID 0B03);c:\windows\SYSTEM32\DRIVERS\qcserxp.sys [2008-06-28 92800]
S4 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" --> c:\program files\Viewpoint\Common\ViewpointService.exe [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{47dc34fe-432c-11dd-abf3-000347fa956b}]
\Shell\AutoRun\command - G:\jfvkcsy.bat
\Shell\explore\Command - G:\jfvkcsy.bat
\Shell\open\Command - G:\jfvkcsy.bat
.
Contents of the 'Scheduled Tasks' folder
2009-01-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-01-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1004336348-1220945662-682003330-1004.job
- c:\documents and settings\JJ.HOME\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-22 01:27]
.
- - - - ORPHANS REMOVED - - - -
BHO-{5F229F22-ED7C-4C56-ABB8-BEE914989939} - c:\windows\system32\qoMfdaWq.dll
BHO-{de455072-86b0-4473-874e-443d34c7bbe7} - c:\windows\system32\ioprpq.dll
HKLM-Run-23561149 - c:\windows\system32\oqbtxhst.dll
MSConfigStartUp-BitTorrent DNA - c:\program files\DNA\btdna.exe
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - d:\progra~1\office\Office10\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {E5B89B1F-4589-4957-BF8D-311D34136041} - hxxp://remotegoat.openmeadow.org/konect/appdata/AxKonectReg.cab
FF - ProfilePath - c:\documents and settings\JJ.HOME\Application Data\Mozilla\Firefox\Profiles\ntgrszwm.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\documents and settings\JJ.HOME\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\JJ.HOME\Local Settings\Application Data\Google\Update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npigl.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-22 08:52:02
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(8088)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\wqbbkhfq.dll
c:\windows\system32\qoMfdaWq.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\LAVASOFT\AD-AWARE\AAWSERVICE.EXE
c:\program files\A-SQUARED FREE\A2SERVICE.EXE
c:\program files\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
c:\program files\AVG\AVG8\AVGWDSVC.EXE
c:\program files\COMMON FILES\LOGISHRD\LVCOMSER\LVCOMSER.EXE
c:\program files\COMMON FILES\LOGISHRD\LVMVFM\LVPRCSRV.EXE
c:\program files\AVG\AVG8\AVGRSX.EXE
c:\program files\COMMON FILES\LOGISHRD\LVCOMSER\LVCOMSER.EXE
c:\program files\AVG\AVG8\AVGTRAY.EXE
c:\program files\MICROSOFT ACTIVESYNC\RAPIMGR.EXE
c:\windows\SoftwareDistribution\Download\Install\windows-kb890830-v2.6-delta.exe
c:\d9f1443112c8e264f675\mrtstub.exe
c:\windows\system32\MRT.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-22 9:03:07 - machine was rebooted [JJ]
ComboFix-quarantined-files.txt 2009-01-22 17:02:42
ComboFix2.txt 2009-01-18 21:21:58
Pre-Run: 6,460,506,112 bytes free
Post-Run: 6,701,711,360 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
211 --- E O F --- 2008-12-18 08:43:06