combofix log
ComboFix 09-09-11.01 - Compaq_Owner 09/12/2009 8:04.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.208 [GMT -4:00]
Running from: c:\documents and settings\Compaq_Owner\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Compaq_Owner\My Documents\backup.reg
c:\documents and settings\Compaq_Owner\My Documents\resistar100606.reg
c:\program files\FunWebProducts
c:\recycler\S-1-5-21-1460280110-2711300710-2143682413-1009
c:\recycler\S-1-5-21-452276026-2241188753-3564204403-1009
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Installer\17a045b.msi
c:\windows\Installer\1990df.msi
c:\windows\Installer\2869b6e.msp
c:\windows\Installer\2869b6f.msp
c:\windows\Installer\2869b70.msp
c:\windows\Installer\77804fd.msp
c:\windows\Installer\77804fe.msp
c:\windows\Installer\77804ff.msp
c:\windows\Installer\7bfcd07.msi
c:\windows\Installer\86b1ba.msp
c:\windows\Installer\cd7478.msp
c:\windows\Installer\cd7479.msp
c:\windows\Installer\cd747a.msp
c:\windows\Installer\cd747b.msp
c:\windows\Installer\cd747c.msp
c:\windows\Installer\cd747d.msp
c:\windows\msa.exe
c:\windows\system32\ps2.bat
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
-- Previous Run --
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
--------
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-08-12 to 2009-09-12 )))))))))))))))))))))))))))))))
.
2009-09-08 04:22 . 2009-09-08 04:22 -------- d-----w- C:\rsit
2009-09-08 04:15 . 2009-09-08 04:18 15 ----a-w- c:\documents and settings\Compaq_Owner\settings.dat
2009-09-07 13:58 . 2009-09-08 04:22 -------- d-----w- c:\program files\Trend Micro
2009-09-06 22:02 . 2009-09-06 22:02 -------- d-----w- c:\windows\system32\wbem\Repository
2009-09-06 21:47 . 2009-09-07 13:06 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-06 21:47 . 2009-09-07 13:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-31 02:04 . 2009-09-06 00:30 -------- d-----w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Deployment
2009-08-15 11:32 . 2009-08-15 11:32 -------- d-----w- c:\program files\MSXML 4.0
2009-08-14 15:02 . 2009-09-12 12:04 -------- dc----w- c:\windows\system32\DRVSTORE
2009-08-14 15:02 . 2009-08-14 15:08 -------- d-----w- c:\program files\WMV9_VCM
2009-08-13 23:59 . 2009-08-13 19:00 82432 ----a-r- c:\windows\system32\msxml4r.dll
2009-08-13 23:59 . 2009-08-13 19:00 44544 ----a-r- c:\windows\system32\msxml4a.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-23 13:34 . 2008-09-30 16:49 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-09-08 17:53 . 2006-09-17 18:38 -------- d-----w- c:\program files\Soulseek-Test
2009-09-08 01:08 . 2009-07-04 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-07 23:51 . 2005-07-16 04:19 -------- d-----w- c:\program files\Maxis
2009-09-07 13:30 . 2006-09-15 22:52 -------- d-----w- c:\program files\SpywareGuard
2009-08-25 14:37 . 2009-07-04 13:46 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-25 14:37 . 2009-07-04 13:46 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-25 14:37 . 2009-07-04 13:46 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-13 10:53 . 2004-10-20 23:50 70800 -c--a-w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:11 . 2004-08-09 04:28 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 00:00 . 2009-08-02 14:29 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-03 00:00 . 2009-08-02 14:29 -------- d-----w- c:\program files\NOS
2009-07-23 22:01 . 2007-03-29 22:00 -------- d--h--w- c:\documents and settings\Compaq_Owner\Application Data\Move Networks
2009-07-21 20:27 . 2008-02-20 21:31 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\LimeWire
2009-07-17 18:55 . 2004-08-09 04:28 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-15 00:49 . 2009-07-04 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-07-14 03:43 . 2004-08-09 04:29 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-04 13:46 . 2009-07-04 13:46 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-26 15:59 . 2004-08-09 04:28 668160 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 15:59 . 2004-08-09 04:28 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-16 14:55 . 2004-08-12 03:51 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-09 04:28 119808 -c--a-w- c:\windows\system32\t2embed.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-24 282624]
c:\documents and settings\Compaq_Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\a a heather\downloads\1ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoCommonGroups"= 0 (0x0)
"NoFileSharing"= 1 (0x1)
"NoPrintSharing"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-25 14:37 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Charter High-Speed Security Suite.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Charter High-Speed Security Suite.lnk
backup=c:\windows\pss\Charter High-Speed Security Suite.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^palmOne Registration.lnk]
path=c:\documents and settings\Compaq_Owner\Start Menu\Programs\Startup\palmOne Registration.lnk
backup=c:\windows\pss\palmOne Registration.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^SpywareGuard.lnk]
backup=c:\windows\pss\SpywareGuard.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV CfgWiz
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/4/2009 9:46 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7/4/2009 9:46 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/4/2009 9:46 AM 297752]
.
Contents of the 'Scheduled Tasks' folder
2009-09-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-09-19 21:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: charter.com\cmph.gld
Trusted Zone: creditplus.com\credit
Trusted Zone: fanniemae.com\desktoporiginator
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: unitedwholesalemortgage.com\www
DPF: {2AB1C516-D654-4D3A-B3D6-2185BBCEB409} - hxxps://24.217.29.219/+CSCOL+/relayp.cab
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {494DE545-6D3C-4F63-9D73-CF408AB248D9} - hxxps://vanillasoft.net/binarys/amiTapiPro.ocx
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-12 08:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(112)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-12 8:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-12 12:25
Pre-Run: 143,219,593,216 bytes free
Post-Run: 143,483,703,296 bytes free
217 --- E O F --- 2009-09-12 07:00