ComboFix Log
ComboFix 08-01-23.1C - customer 2008-01-26 12:13:30.2 - NTFSx86
Running from: C:\Documents and Settings\customer\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\customer\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\vdmindvdd.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\temp\tn3
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\vdmindvdd.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_VDMINDVDD
-------\vdmindvdd
((((((((((((((((((((((((( Files Created from 2007-12-26 to 2008-01-26 )))))))))))))))))))))))))))))))
.
2008-01-26 10:36 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-26 09:01 . 2008-01-26 09:01 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-25 15:41 . 2008-01-25 15:41 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-25 11:10 . 2008-01-25 11:10 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-25 09:37 . 2008-01-25 10:10 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-01-24 18:19 . 2007-08-13 18:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2008-01-24 17:57 . 2008-01-25 09:24 229 --a------ C:\WINDOWS\wininit.ini
2008-01-24 17:17 . 2008-01-24 17:17 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-01-24 16:47 . 2006-12-14 07:45 981,760 -----c--- C:\WINDOWS\system32\dllcache\mfc42u.dll
2008-01-24 16:46 . 2007-02-05 14:17 185,344 -----c--- C:\WINDOWS\system32\dllcache\upnphost.dll
2008-01-24 16:45 . 2007-10-30 11:20 360,064 -----c--- C:\WINDOWS\system32\dllcache\tcpip.sys
2008-01-24 16:41 . 2007-07-09 07:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-01-24 16:41 . 2006-08-14 04:34 332,928 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-01-24 16:41 . 2006-08-16 03:37 225,664 -----c--- C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-01-24 16:41 . 2006-08-16 05:58 100,352 -----c--- C:\WINDOWS\system32\dllcache\6to4svc.dll
2008-01-24 16:36 . 2007-10-29 16:43 1,287,680 -----c--- C:\WINDOWS\system32\dllcache\quartz.dll
2008-01-24 16:36 . 2006-10-12 05:09 256,512 -----c--- C:\WINDOWS\system32\dllcache\agentsvr.exe
2008-01-24 16:36 . 2007-03-09 07:46 57,344 --a--c--- C:\WINDOWS\system32\dllcache\agentdpv.dll
2008-01-24 16:36 . 2006-10-12 08:02 42,496 -----c--- C:\WINDOWS\system32\dllcache\agentdp2.dll
2008-01-24 16:32 . 2007-04-16 09:52 984,576 -----c--- C:\WINDOWS\system32\dllcache\kernel32.dll
2008-01-24 16:25 . 2006-05-05 03:41 453,120 -----c--- C:\WINDOWS\system32\dllcache\mrxsmb.sys
2008-01-24 16:25 . 2006-05-05 03:47 174,592 -----c--- C:\WINDOWS\system32\dllcache\rdbss.sys
2008-01-24 16:24 . 2006-08-21 03:14 128,896 -----c--- C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-01-24 16:24 . 2006-08-21 03:14 23,040 -----c--- C:\WINDOWS\system32\dllcache\fltmc.exe
2008-01-24 16:24 . 2006-08-21 06:21 16,896 -----c--- C:\WINDOWS\system32\dllcache\fltlib.dll
2008-01-24 16:05 . 2006-06-22 04:47 181,248 -----c--- C:\WINDOWS\system32\dllcache\rasmans.dll
2008-01-22 11:12 . 2002-12-17 16:23 33,340 --------- C:\WINDOWS\system32\dbmsqlgc.dll
2008-01-22 11:12 . 2002-10-20 14:05 24,576 --------- C:\WINDOWS\system32\dbmsgnet.dll
2008-01-22 11:11 . 2008-01-22 11:11 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-01-22 11:10 . 2008-01-22 11:10 <DIR> d-------- C:\Program Files\Common Files\Laserfiche
2008-01-22 07:25 . 2008-01-23 02:40 <DIR> d-------- C:\WINDOWS\system32\nGpxx01
2008-01-22 07:25 . 2008-01-22 07:25 <DIR> d-------- C:\Temp\cXzz9
2008-01-11 10:56 . 2007-05-30 06:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-11 10:56 . 2007-01-18 06:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-01-10 14:58 . 2008-01-11 11:41 <DIR> d-------- C:\WINDOWS\system32\vt8
2008-01-10 14:58 . 2008-01-10 14:58 <DIR> d-------- C:\WINDOWS\system32\mp2
2008-01-10 14:58 . 2008-01-10 14:58 <DIR> d-------- C:\WINDOWS\system32\ez4
2008-01-10 14:58 . 2008-01-13 17:00 <DIR> d-------- C:\WINDOWS\system32\edcA01
2008-01-10 14:58 . 2008-01-10 14:58 <DIR> d-------- C:\WINDOWS\system32\che9
2008-01-10 14:58 . 2008-01-10 14:58 <DIR> d-------- C:\Temp\Ryuan1
2008-01-07 11:05 . 2008-01-07 11:05 <DIR> d-------- C:\PVSW
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-24 21:51 --------- d-----w C:\Program Files\Ahead
2008-01-22 17:12 --------- d--h--w C:\Program Files\Uninstall Information
2008-01-15 02:27 --------- d-----w C:\Program Files\Lx_cats
2007-12-04 21:37 --------- d-----w C:\Program Files\vghd
2007-11-26 17:06 --------- d-----w C:\Program Files\directx
2007-11-26 17:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-26 17:05 --------- d-----w C:\Program Files\Magellan
2006-02-19 09:28 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((( snapshot@2008-01-26_10.48.23.53 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-26 16:37:25 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-26 18:13:22 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-26 16:37:25 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-26 18:13:22 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-26 16:37:25 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-26 18:13:22 1,421,312 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-26 16:37:25 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-26 18:13:22 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-26 16:37:25 6,664,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-26 18:13:23 6,664,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-26 16:37:26 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-26 18:13:23 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2000-08-31 14:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2008-01-26 18:18:28 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_1e0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8BB68ECD-9443-4F19-8E11-580D6AF98D8F}]
C:\Program Files\MSN\honepaC:\WINDOWS\system32\vt8\tycodllz83122.exe.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 05:47 68856]
"PPScheduler"="C:\Program Files\ScanSoft\PaperPort\PPScheduler.exe" [2006-03-02 13:31 98304]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 01:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 09:22 155648]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2006-03-02 13:11 36864]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2006-03-02 13:12 40960]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"Opware12"="C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe" [2004-02-04 14:44 49152]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 01:49 579072]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-10 09:04 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 07:56:20 73728]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 17:23:32 74308]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WlanUtility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WlanUtility.lnk
backup=C:\WINDOWS\pss\WlanUtility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
--a------ 2001-09-04 02:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2004-03-03 13:00 335872 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 10:24 1694208 C:\Program Files\Messenger\MSMSGS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2004-02-09 02:54 65024 C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2003-04-24 02:44 610304 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a------ 2003-04-24 02:51 110592 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SLService"=2 (0x2)
"ose"=3 (0x3)
"MSI_WLAN_Service"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
R2 MSSQL$LFPLUS;MSSQL$LFPLUS;C:\Program Files\Microsoft SQL Server\MSSQL$LFPLUS\Binn\sqlservr.exe [2002-12-17 17:26]
R2 OneTouch 4.0 Monitor;OneTouch 4.0 Monitor;"C:\Program Files\Visioneer\OneTouch 4.0\OtService.exe" [2006-07-18 01:36]
R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys [2003-08-27 05:02]
R3 M2500;802.11g Wireless Network Driver;C:\WINDOWS\system32\DRIVERS\M2500.sys [2004-02-17 10:24]
R3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys [2003-08-25 13:46]
S3 AX88172;ASIX AX88172 USB2 to Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\ax88172.sys [2003-07-17 21:17]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2005-08-02 15:10]
S3 SQLAgent$LFPLUS;SQLAgent$LFPLUS;C:\Program Files\Microsoft SQL Server\MSSQL$LFPLUS\Binn\sqlagent.EXE [2002-12-17 17:23]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{206ade88-c9a8-11db-97f5-00030d14e9ae}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{60b676c2-3c72-11dc-9835-00030d14e9ae}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1b0d4a1-6ee9-11dc-9848-00030d14e9ae}]
\Shell\AutoRun\command - E:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e81a0640-6d16-11dc-9843-00030d14e9ae}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f59938ea-7a36-11db-97c0-00030d14e9ae}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-26 12:19:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-26 12:24:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-26 18:24:42
ComboFix2.txt 2008-01-26 16:48:47
.
2008-01-26 09:01:08 --- E O F ---