ComboFix 07-12-21.4 - jd 2007-12-25 19:03:34.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.236 [GMT -6:00]
Running from: C:\Documents and Settings\jd\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\jd\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinInjectbw.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinInjectbw1.zip
C:\Documents and Settings\jd\Desktop\Wizit's junk\Runescape\Bots & Autos\Autofighter_Package.zip
C:\Program Files\ComPlus Applications\rtelecirt.html
C:\WINDOWS\system32\nwgcxlbw.dll
C:\windows\system32\nwgcxlbw.dllbox
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinInjectbw.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinInjectbw1.zip
C:\Documents and Settings\jd\Desktop\Wizit's junk\Runescape\Bots & Autos\Autofighter_Package.zip
C:\Program Files\ComPlus Applications\rtelecirt.html
C:\VundoFix Backups
C:\VundoFix Backups\addmorefiles.txt
C:\VundoFix Backups\cfjoyehl.dll.bad
C:\VundoFix Backups\cutcyrpz.dll.bad
C:\VundoFix Backups\cutcyrpz.dllbox.bad
C:\VundoFix Backups\dalprhty.dll.bad
C:\VundoFix Backups\dnikvuqv.dll.bad
C:\VundoFix Backups\enqyaeft.ini.bad
C:\VundoFix Backups\eouqhtkr.dll.bad
C:\VundoFix Backups\gijcqsqh.dll.bad
C:\VundoFix Backups\hqpjlkrf.dll.bad
C:\VundoFix Backups\jscfmmfs.dll.bad
C:\VundoFix Backups\keskugxu.dll.bad
C:\VundoFix Backups\lvesbntv.dll.bad
C:\VundoFix Backups\npgktrlm.dll.bad
C:\VundoFix Backups\ptorrbxj.dll.bad
C:\VundoFix Backups\tbgsjiaa.dll.bad
C:\VundoFix Backups\tfeayqne.dll.bad
C:\VundoFix Backups\tprwdjxj.dll.bad
C:\VundoFix Backups\unpdlupp.dll.bad
C:\VundoFix Backups\vcgunrbq.dll.bad
C:\VundoFix Backups\vdudvqob.dll.bad
C:\VundoFix Backups\vptlfctr.dll.bad
C:\VundoFix Backups\vtnbsevl.ini.bad
C:\VundoFix Backups\xbsimgda.dll.bad
C:\VundoFix Backups\ygbbpvuu.dll.bad
.
((((((((((((((((((((((((( Files Created from 2007-11-26 to 2007-12-26 )))))))))))))))))))))))))))))))
.
2007-12-25 11:38 . 2007-12-25 13:55 74 --a------ C:\WINDOWS\RCAMPEG4VC.ini
2007-12-25 10:53 . 2007-12-25 10:53 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-25 10:53 . 2007-12-25 10:53 <DIR> d-------- C:\WINDOWS\LastGood
2007-12-25 10:53 . 2007-12-25 10:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-24 02:20 . 2007-12-24 02:20 14,033 --a------ C:\posE1C.tmp
2007-12-24 02:12 . 2007-12-24 02:23 <DIR> d-------- C:\Program Files\Runescape Apocalypse Client
2007-12-24 01:39 . 2007-12-24 01:39 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-24 01:39 . 2007-12-25 13:20 <DIR> d-------- C:\Documents and Settings\jd\Application Data\AVG7
2007-12-24 01:38 . 2007-12-24 01:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-24 01:38 . 2007-12-24 02:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-12-22 20:25 . 2007-12-22 20:25 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-21 21:07 . 2007-12-21 21:07 14,033 --a------ C:\posDA8.tmp
2007-12-21 21:06 . 2007-12-21 21:06 14,033 --a------ C:\posC75.tmp
2007-12-21 19:39 . 2007-12-21 19:39 14,033 --a------ C:\posBB7.tmp
2007-12-21 19:38 . 2007-12-21 19:38 14,033 --a------ C:\posAC4.tmp
2007-12-21 16:02 . 2007-12-21 16:02 14,033 --a------ C:\pos9C4.tmp
2007-12-21 16:01 . 2007-12-21 16:01 14,033 --a------ C:\pos94B.tmp
2007-12-21 16:00 . 2007-12-21 16:00 14,033 --a------ C:\pos844.tmp
2007-12-21 13:54 . 2007-12-21 13:54 14,033 --a------ C:\pos5DB.tmp
2007-12-21 13:53 . 2007-12-21 13:53 14,033 --a------ C:\pos4FA.tmp
2007-12-20 15:58 . 2007-12-20 15:58 14,033 --a------ C:\pos811.tmp
2007-12-20 15:57 . 2007-12-20 15:57 14,033 --a------ C:\pos7A4.tmp
2007-12-20 15:56 . 2007-12-20 15:56 14,033 --a------ C:\pos68B.tmp
2007-12-19 21:02 . 2007-12-19 21:02 14,033 --a------ C:\pos3DF.tmp
2007-12-19 21:01 . 2007-12-19 21:01 14,033 --a------ C:\posA.tmp
2007-12-19 20:29 . 2007-12-19 20:29 <DIR> d-------- C:\Documents and Settings\jd\LimeWire Store Purchased
2007-12-19 20:29 . 2007-12-19 20:29 <DIR> d-------- C:\Documents and Settings\jd\LimeWire Shared
2007-12-19 20:29 . 2007-12-25 16:56 <DIR> d-------- C:\Documents and Settings\jd\LimeWire Saved
2007-12-19 20:26 . 2007-12-24 19:23 <DIR> d-------- C:\Program Files\LimeWire
2007-12-19 20:13 . 2007-12-19 20:13 14,033 --a------ C:\posF3.tmp
2007-12-19 20:12 . 2007-12-19 20:13 14,033 --a------ C:\pos43.tmp
2007-12-17 19:33 . 2007-12-17 19:33 <DIR> d-------- C:\Program Files\RCA
2007-12-17 13:20 . 2007-12-22 12:57 143 --a------ C:\WINDOWS\system32\mcrh.tmp
2007-12-17 13:16 . 2007-12-17 13:16 <DIR> dr-h----- C:\Documents and Settings\Kyle\Application Data\yahoo!
2007-12-16 17:47 . 2007-08-03 19:31 <DIR> d-------- C:\Documents and Settings\Kyle\WINDOWS
2007-12-16 17:47 . 2007-12-16 17:47 <DIR> d--hs---- C:\Documents and Settings\Kyle\UserData
2007-12-16 17:47 . 2007-08-03 19:36 <DIR> d-------- C:\Documents and Settings\Kyle\Application Data\McAfee.com Personal Firewall
2007-12-16 17:44 . 2007-12-16 17:44 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2007-12-16 15:22 . 2007-12-22 17:01 2,402 --a------ C:\WINDOWS\wininit.ini
2007-12-16 11:20 . 2007-12-16 19:48 <DIR> d-------- C:\Documents and Settings\jd\Application Data\DivX
2007-12-15 22:16 . 2007-12-16 17:36 <DIR> d-------- C:\Documents and Settings\jd\Application Data\Lavasoft
2007-12-15 19:01 . 2007-12-24 18:49 <DIR> d-------- C:\Temp
2007-12-11 16:35 . 2007-12-11 16:35 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-12-11 16:35 . 2007-12-11 16:35 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2007-12-11 16:34 . 2007-12-11 16:34 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-12-11 16:34 . 2007-12-11 16:34 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-12-11 16:34 . 2007-12-11 16:34 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-12-11 16:32 . 2007-12-11 16:32 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
2007-12-11 16:32 . 2007-12-11 16:32 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-12-11 16:32 . 2007-12-11 16:32 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2007-12-10 19:00 . 2007-12-10 19:00 <DIR> d-------- C:\GMouse20
2007-12-01 23:35 . 2006-09-13 14:52 561,152 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-12-01 23:35 . 2006-09-13 15:01 237,568 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-12-01 23:35 . 2005-12-30 15:34 2,864 --a------ C:\WINDOWS\system32\xvid.inf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-25 22:56 --------- d-----w C:\Documents and Settings\jd\Application Data\LimeWire
2007-12-22 21:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-22 05:26 --------- d-----w C:\Program Files\RegistryFix
2007-12-18 01:25 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-17 19:34 --------- d-----w C:\Program Files\Java
2007-12-11 22:34 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-12-11 22:34 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-12-11 22:34 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-12-11 22:34 129,784 ----a-w C:\WINDOWS\system32\pxafs.dll
2007-12-11 22:34 120,056 ----a-w C:\WINDOWS\system32\pxcpyi64.exe
2007-12-11 22:34 118,520 ----a-w C:\WINDOWS\system32\pxinsi64.exe
2007-12-11 22:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-12-11 22:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-12-11 22:33 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-12-11 22:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-12-11 22:33 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2007-12-11 22:33 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-12-11 22:33 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-12-11 22:33 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-12-11 22:33 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-12-11 22:33 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-12-11 22:33 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-12-11 22:33 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-12-08 19:02 --------- d-----w C:\Program Files\Yahoo!
2007-12-02 05:35 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-18 03:17 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-11-18 03:17 --------- d-----w C:\Program Files\rpg2003
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-03 20:22 --------- d-----w C:\Documents and Settings\jd\Application Data\Yahoo!
2007-11-03 19:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-01 20:04 --------- d-----w C:\Program Files\FileZilla
2007-11-01 14:03 0 ----a-w C:\Documents and Settings\jd\AutoTalkerPro20.exe
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 23:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 00:15 --------- d-----w C:\Program Files\Zune
2007-10-17 17:23 10,752 ----a-w C:\WINDOWS\system32\WhoisCL.exe
2007-09-04 23:56 56 --sh--r C:\WINDOWS\system32\A3D88A52D0.sys
2007-09-04 23:56 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2007-12-24_12.41.06.98 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-24 18:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 21:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 21:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" []
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 16:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-27 18:09]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2007-03-14 16:03]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-24 09:44]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-24 01:38]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-07-20 11:57:16]
C:\Documents and Settings\Kyle\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-07-20 11:57:16]
C:\Documents and Settings\jd\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-07-20 11:57:16]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^DOCUME~1^ALLUSE~1^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\DOCUME~1\ALLUSE~1\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
R3 atimtai;atimtai;C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-17 06:48]
R3 EL556ND5;3Com 10/100 MiniPCI Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\EL556ND5.sys [2001-08-17 06:10]
R3 maestro;ESS Maestro Audio Driver (WDM);C:\WINDOWS\system32\drivers\es198xdl.sys [2002-06-20 16:53]
R3 odysseyIM3;Odyssey Network Services Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM3.sys [2005-06-22 18:54]
S3 MSControlService;Microsoft cache control;C:\WINDOWS\system32\windows []
S3 WDHAALBA;WDHAALBAMiniPCI Winmodem;C:\WINDOWS\system32\DRIVERS\WDHAALBA.sys [2001-08-17 07:28]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0a4aa71-4959-11dc-a30f-0000864da474}]
\Shell\AutoRun\command - D:\setup.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-25 19:06:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-25 19:07:39
C:\ComboFix2.txt ... 2007-12-25 09:47
C:\ComboFix3.txt ... 2007-12-24 19:07
.
2007-12-12 01:06:33 --- E O F ---