ComboFix 08-02-25.3 - Stevo 2008-02-27 8:22:54.1 - NTFSx86
Running from: C:\Documents and Settings\Stevo\Local Settings\Temporary Internet Files\Content.IE5\FVVGSJ8G\ComboFix[1].exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\hosts
C:\WINDOWS\system32\_000000_.tmp.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.
2008-02-26 16:44 . 2008-02-26 20:14 <DIR> d-------- C:\Documents and Settings\Stevo\.SunDownloadManager
2008-02-26 16:14 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-26 16:13 . 2008-02-26 16:13 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-26 11:31 . 2008-02-26 11:31 <DIR> d-------- C:\Program Files\CCleaner
2008-02-25 16:27 . 2008-02-26 00:40 <DIR> d-------- C:\fixwareout
2008-02-24 20:06 . 2008-02-24 20:06 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-24 20:06 . 2008-02-24 20:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-24 19:09 . 2008-02-24 19:09 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-24 16:30 . 2008-02-24 16:30 <DIR> d-------- C:\EAGLE_VS_SHARK
2008-02-18 20:04 . 2008-02-18 20:04 441 --a------ C:\WINDOWS\system32\SDRemoveDB.db
2008-02-18 20:03 . 2008-02-18 20:03 63 --a------ C:\WINDOWS\system\SysSD.dll
2008-02-18 20:01 . 2008-02-27 08:14 <DIR> d-------- C:\Program Files\SpywareDetector
2008-02-18 20:01 . 2007-03-19 12:39 270,336 --a------ C:\WINDOWS\system32\CheckDll.dll
2008-02-18 20:01 . 2008-01-25 18:58 67,024 --a------ C:\WINDOWS\system32\CloseAll.exe
2008-02-18 20:01 . 2008-01-30 11:03 6,144 --a------ C:\WINDOWS\system32\SDEarlyDelete.exe
2008-02-18 20:01 . 2005-02-06 09:02 104 --a------ C:\WINDOWS\system32\ProxySettings.ini
2008-02-05 14:11 . 2008-02-05 14:16 <DIR> d-------- C:\Documents and Settings\Nicola\Shared
2008-02-05 14:11 . 2008-02-05 14:16 <DIR> d-------- C:\Documents and Settings\Nicola\Incomplete
2008-02-05 14:09 . 2008-02-05 14:24 <DIR> d-------- C:\Documents and Settings\Nicola\Application Data\LimeWire
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-26 03:31 --------- d-----w C:\Documents and Settings\Stevo\Application Data\AVG7
2008-02-26 03:14 --------- d-----w C:\Program Files\Java
2008-02-25 22:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-17 07:42 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-14 00:32 --------- d-----w C:\Program Files\LimeWire
2008-02-12 03:05 --------- d-----w C:\Program Files\ParetoLogic
2008-02-03 00:17 --------- d-----w C:\Documents and Settings\Michelle\Application Data\AVG7
2008-02-02 19:00 --------- d-----w C:\Documents and Settings\Alan Lennon\Application Data\AVG7
2008-01-25 20:41 --------- d-----w C:\Documents and Settings\Dinah\Application Data\AVG7
2008-01-21 02:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
2008-01-20 05:32 --------- d-----w C:\Program Files\NovaLogic
2008-01-20 05:27 --------- d-----w C:\Program Files\Lavasoft
2008-01-20 04:29 --------- d-----w C:\Program Files\Spyware Doctor
2008-01-15 00:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-14 21:45 --------- d-----w C:\Program Files\RegCure
2008-01-14 21:11 --------- d-----w C:\Documents and Settings\Stevo\Application Data\ParetoLogic
2008-01-14 21:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\ParetoLogic
2008-01-14 21:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2008-01-14 04:35 --------- d-----w C:\Documents and Settings\Nicola\Application Data\AVG7
2008-01-04 03:22 --------- d-----w C:\Program Files\WinClear
2007-12-13 22:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-07-09 01:09 163 ---ha-w C:\Documents and Settings\Michelle\hpothb07.dat
2007-07-09 01:09 161 ---ha-w C:\Documents and Settings\Nicola\hpothb07.dat
2007-02-07 20:41 320 ---ha-w C:\Documents and Settings\Stevo\hpothb07.dat
2004-03-11 01:27 40,960 -c--a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2004-07-26 20:14 1867776]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 16:56 68856]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-04-20 10:57 847872]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 01:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 01:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 01:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 01:00 455168]
"SiSPower"="SiSPower.dll" [2005-01-04 16:54 49152 C:\WINDOWS\system32\SiSPower.dll]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 08:57 143360]
"Profiler"="C:\Program Files\Saitek\Software\Profiler.exe" [2004-01-28 09:19 159744]
"SaiSmart"="C:\Program Files\Saitek\Software\SaiSmart.exe" [2004-01-28 09:19 98304]
"DSLSTATEXE"="C:\Program Files\Dynalink\Adsl\dslstat.exe" [2005-10-20 11:29 299008]
"DSLAGENTEXE"="C:\Program Files\Dynalink\Adsl\dslagent.exe" [2005-10-20 11:29 16384]
"DataLayer"="C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 10:30 1106944]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 07:24 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42 267064]
"SystemTraySD"="C:\Program Files\SpywareDetector\SDSystemTray.exe" [2008-01-28 12:48 706000]
"SDAutoLiveupdate"="C:\Program Files\SpywareDetector\LiveUpdateSD.exe" [2008-02-01 18:31 423376]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 01:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-15 17:06 145920]
C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
OpenOffice.org 1.1.4.lnk - C:\OpenOffice.org1.1.4\program\quickstart.exe [2004-10-28 01:10:00 61440]
C:\Documents and Settings\Dinah\Start Menu\Programs\Startup\
OpenOffice.org 1.1.4.lnk - C:\OpenOffice.org1.1.4\program\quickstart.exe [2004-10-28 01:10:00 61440]
C:\Documents and Settings\Michelle\Start Menu\Programs\Startup\
OpenOffice.org 1.1.4.lnk - C:\OpenOffice.org1.1.4\program\quickstart.exe [2004-10-28 01:10:00 61440]
C:\Documents and Settings\Nicola\Start Menu\Programs\Startup\
OpenOffice.org 1.1.4.lnk - C:\OpenOffice.org1.1.4\program\quickstart.exe [2004-10-28 01:10:00 61440]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2004-06-16 18:34:12 147456]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2004-06-16 18:22:58 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDNotify]
C:\Program Files\SpywareDetector\SDNotify.dll 2008-01-28 11:30 167936 C:\Program Files\SpywareDetector\SDNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Alan Lennon^Start Menu^Programs^Startup^OpenOffice.org 1.1.4.lnk]
path=C:\Documents and Settings\Alan Lennon\Start Menu\Programs\Startup\OpenOffice.org 1.1.4.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 1.1.4.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
backup=C:\WINDOWS\pss\Utility Tray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
--a------ 2007-10-15 17:06 416256 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 12:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 2005-03-22 10:39 167936 C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 07:24 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
--a------ 2005-02-15 14:54 1469680 C:\PROGRA~1\SPYWAR~1\swdoctor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
R3 Intels51;Intel(R) 536EP Modem;C:\WINDOWS\system32\DRIVERS\Intels51.sys [2004-12-10 22:30]
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-06-30 19:01]
S3 SaiH0464;SaiH0464;C:\WINDOWS\system32\DRIVERS\SaiH0464.sys [2004-01-31 02:29]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5cd15308-8926-11d9-bae4-0011d8355d8c}]
\Shell\AutoRun\command - SPEEDY.EXE
.
Contents of the 'Scheduled Tasks' folder
"2006-01-21 05:54:28 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1128831065.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
"2008-02-26 05:00:00 C:\WINDOWS\Tasks\Pareto UNS.job"
- C:\Program Files\Common Files\ParetoLogic\UUS\UUS.dll\Pareto_Update.exe
"2008-02-26 05:00:00 C:\WINDOWS\Tasks\ParetoLogic Registration.job"
- C:\WINDOWS\system32\rundll32.exe@
"2008-02-26 19:16:48 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-02-13 14:00:00 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-27 08:27:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-27 8:32:41
ComboFix-quarantined-files.txt 2008-02-26 19:32:37
.
2007-10-10 20:50:14 --- E O F ---