ComboFix 08-05-28.1 - brian.syfert 2008-05-28 17:11:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1182 [GMT -5:00]
Running from: C:\Documents and Settings\brian.syfert\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\brian.syfert\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMf3f6c98e.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\AaKkmnnn.ini
C:\WINDOWS\system32\AaKkmnnn.ini2
C:\WINDOWS\system32\ancseqwl.dll
C:\WINDOWS\system32\cjxbnxoy.dll
C:\WINDOWS\system32\GOoqAJlm.ini
C:\WINDOWS\system32\GOoqAJlm.ini2
C:\WINDOWS\system32\IlVyyGgh.ini
C:\WINDOWS\system32\IlVyyGgh.ini2
C:\WINDOWS\system32\IPstCcfe.ini
C:\WINDOWS\system32\IPstCcfe.ini2
C:\WINDOWS\system32\lsbgghle.ini
C:\WINDOWS\system32\MabryObj.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pYHhRXyb.ini
C:\WINDOWS\system32\pYHhRXyb.ini2
C:\WINDOWS\system32\rwmskppg.ini
C:\WINDOWS\system32\xusipetm.ini
C:\WINDOWS\system32\yoxnbxjc.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-28 )))))))))))))))))))))))))))))))
.
2008-05-28 16:27 . 2008-05-28 16:27 <DIR> d-------- C:\_OTMoveIt
2008-05-28 12:18 . 2008-05-28 13:01 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-28 12:06 . 2008-05-28 12:06 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-28 12:06 . 2008-05-28 12:06 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-28 12:05 . 2008-05-28 12:19 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-28 12:05 . 2008-05-28 12:27 <DIR> d-------- C:\Documents and Settings\brian.syfert\Application Data\AVGTOOLBAR
2008-05-28 12:04 . 2008-05-28 12:04 <DIR> d-------- C:\Program Files\AVG
2008-05-28 12:04 . 2008-05-28 12:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-27 21:41 . 2008-05-27 21:41 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-27 21:41 . 2008-05-27 21:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-27 17:25 . 2008-05-27 17:25 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-26 16:42 . 2008-05-26 16:40 691,545 --a------ C:\WINDOWS\unins000.exe
2008-05-26 16:42 . 2008-05-26 16:42 2,550 --a------ C:\WINDOWS\unins000.dat
2008-05-26 14:01 . 2008-05-27 12:51 <DIR> d-------- C:\Documents and Settings\brian.syfert\Application Data\U3
2008-05-26 10:42 . 2008-05-26 10:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-05-26 10:30 . 2008-05-26 10:30 <DIR> d-------- C:\HP LJ1320 PCL5 Driver
2008-05-26 09:44 . 2008-05-28 11:00 1,306 --ahs---- C:\WINDOWS\system32\vgmoefgp.ini
2008-05-25 19:40 . 2008-05-25 19:40 <DIR> d-------- C:\WINDOWS\system32\vntiho05
2008-05-25 19:40 . 2008-05-25 19:40 <DIR> d-------- C:\Temp\vtmp2
2008-05-21 20:34 . 2008-05-21 20:34 <DIR> d-------- C:\Program Files\RCA
2008-05-21 09:56 . 2008-05-27 13:43 <DIR> d-------- C:\Documents and Settings\brian.syfert\Application Data\LimeWire
2008-05-14 16:48 . 2008-05-21 21:09 <DIR> d-------- C:\Documents and Settings\brian.syfert\Application Data\Move Networks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-28 22:16 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-05-28 19:40 --------- d-----w C:\Program Files\Dirigo Software
2008-05-28 19:37 --------- d-----w C:\Documents and Settings\brian.syfert\Application Data\Yahoo!
2008-05-28 19:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-05-28 19:36 --------- d-----w C:\Program Files\Yahoo!
2008-05-26 21:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-26 21:44 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-04-17 18:52 --------- d-----w C:\Program Files\Microsoft Location Finder
2008-04-17 18:51 --------- d-----w C:\Program Files\Microsoft MapPoint
2008-04-17 17:28 --------- d-----w C:\Program Files\PENTAX
2008-04-14 15:55 --------- d-----w C:\Program Files\Lavasoft
2008-04-14 15:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-14 15:53 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-29 03:03 --------- d-----w C:\Documents and Settings\brian.syfert\Application Data\CyberLink
2008-03-29 03:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-18 00:53 8,968 ----a-w C:\WINDOWS\system32\KL2DLL.DLL
2008-03-18 00:53 77,824 ----a-w C:\WINDOWS\system32\NWKL2_32.DLL
2008-03-18 00:53 7,440 ----a-w C:\WINDOWS\system32\ppmon.dll
2008-03-18 00:53 40,352 ----a-w C:\WINDOWS\inf\Usbkey.sys
2008-03-18 00:53 33,792 ----a-w C:\WINDOWS\system32\regini.exe
2008-03-18 00:53 28,672 ----a-w C:\WINDOWS\system32\KL2DLL32.DLL
2008-03-18 00:53 24,136 ----a-w C:\WINDOWS\system32\ppmon.exe
2008-03-18 00:53 12,480 ----a-w C:\WINDOWS\system32\KL2N.DLL
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2F2F1A5C-D858-4072-853A-B615F8FEB03A}]
C:\WINDOWS\system32\hgGyyVlI.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3095D50F-F1BA-4BBC-A54D-819EEB7E0898}]
C:\WINDOWS\system32\mlJDuvUL.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{49ACC851-BF65-4C53-A135-E172AA13410C}]
C:\WINDOWS\system32\mlJAqoOG.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{505ab3b0-d74c-4a0d-adfa-5b9840f228c4}]
C:\WINDOWS\system32\gpmarwps.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-28 12:05 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8C1BEEC-73FC-4324-A937-19B3E6B3E978}]
C:\WINDOWS\system32\efcCtsPI.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA0F1B6B-30C6-479C-AE78-D3EC934FDF6E}]
C:\WINDOWS\system32\byXRhHYp.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BF84178B-68C0-406F-8942-4B5ED0E2B8A1}]
C:\WINDOWS\system32\nnnmkKaA.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-28 12:05 2050816]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-28 12:05 2050816]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2007-01-25 18:34 159744]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 12:19 819200]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 12:17 970752]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-05-16 17:50 138008]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-05-16 17:50 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-05-16 17:50 138008]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 15:26 303104 C:\WINDOWS\stsystra.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 14:03 36975]
"ChangeTPMAuth"="C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [ ]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 17:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 17:50 81920]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 18:23 118784]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 18:14 53408]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-06-15 02:40 124656]
"nomtray"="C:\Program Files\NetMotion Client\nomtray.exe" [2005-10-27 13:01 225280]
"f0c5fa12"="C:\WINDOWS\system32\pgfeomgv.dll" [ ]
"RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 10:00 1116920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-28 12:05 1177368]
"BMf3f6c98e"="C:\WINDOWS\system32\dvnvkdys.dll" [ ]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
DSmobileSCAN.lnk - C:\Program Files\PENTAX\DSmobile600\DSmobileSCAN.exe [2006-10-10 05:52:04 827392]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-01-11 21:43:46 2150400]
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2003-09-19 15:46:14 503869]
DSmobileSCAN.lnk - C:\Program Files\PENTAX\DSmobileSCAN\DSmobileSCAN.exe [2007-04-16 21:45:36 391680]
iZone Monitor.lnk - C:\Program Files\ArcSoft\Polaroid iZone PhotoBase\iZone Monitor.exe [2008-03-21 18:52:31 184320]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{3095D50F-F1BA-4BBC-A54D-819EEB7E0898}"= C:\WINDOWS\system32\mlJDuvUL.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJDuvUL]
mlJDuvUL.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CAD Zone\\Crash Zone 8\\CrashZone.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-28 12:06]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 11:35]
R1 fsclm;FIPS Driver;C:\Program Files\NetMotion Client\fsclm.sys [2005-10-27 13:01]
R1 NMDRV;NetMotion Client Driver;C:\Program Files\NetMotion Client\nmdrv.sys [2005-10-27 13:01]
R1 NMRoam;NetMotion Roaming Detection Daemon;C:\WINDOWS\system32\DRIVERS\nmroam.sys [2005-10-27 13:01]
R1 NMutilnt;NetMotion Utility Driver;C:\WINDOWS\system32\drivers\nmutilnt.sys [2005-10-27 13:01]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-28 12:04]
R2 MESSERV;NetMotion Client;C:\Program Files\NetMotion Client\messerv.exe [2005-10-27 13:01]
R3 nmvnic;NMVNIC Network Adapter;C:\WINDOWS\system32\DRIVERS\nmvnic.sys [2005-10-27 13:01]
R3 TcUsb;TC USB Kernel Driver;C:\WINDOWS\system32\Drivers\tcusb.sys [2006-11-13 13:16]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{217fa480-2b3a-11dd-818f-001c230163cf}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-28 17:17:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stacsv.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\hidfind.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
.
**************************************************************************
.
Completion time: 2008-05-28 17:18:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-28 22:17:54
Pre-Run: 9,731,383,296 bytes free
Post-Run: 9,663,598,592 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
228 --- E O F --- 2008-05-17 05:10:27