sorry about the pause in our thing here. I did not see that it went into 2 pages but I'm here now
ComboFix 08-01-11.1 - justin2 2008-01-12 16:32:02.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.672 [GMT -9:00]
Running from: C:\Documents and Settings\justin2\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\justin2\Desktop\CFScript.txt C:\Documents and Settings\justin2\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\Documents and Settings\Administrator\Incomplete\T-1667963-TOTALLY HIP TRACK.wma
C:\Documents and Settings\Administrator\Incomplete\T-4076126-Top of Charts - 2005.wma
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\YazzleSudoku.zip
C:\Documents and Settings\justin2\Desktop\Unused Desktop Shortcuts\MagicJellybean Keyfinder and Changer.exe
C:\Program Files\Easy Web Cam\dialler.exe
C:\WINDOWS\system32\qzuoshi.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\YazzleSudoku.zip
C:\Program Files\AskSBar
C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.JAR
C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.MANIFEST
C:\Program Files\AskSBar\bar\1.bin\A2HIGHIN.EXE
C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.JAR
C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.MANIFEST
C:\Program Files\AskSBar\bar\1.bin\A2PLUGIN.DLL
C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
C:\Program Files\AskSBar\bar\1.bin\NPASKSBR.DLL
C:\Program Files\AskSBar\bar\Cache\
01EE48FC
C:\Program Files\AskSBar\bar\Cache\
01EE4C38
C:\Program Files\AskSBar\bar\Cache\
01EE4DAF.bin
C:\Program Files\AskSBar\bar\Cache\
01EE4F75.bin
C:\Program Files\AskSBar\bar\Cache\
01EE511A.bin
C:\Program Files\AskSBar\bar\Cache\
01EE536C.bin
C:\Program Files\AskSBar\bar\Cache\
01EE55ED.bin
C:\Program Files\AskSBar\bar\Cache\
01EE57E1.bin
C:\Program Files\AskSBar\bar\Cache\files.ini
C:\Program Files\AskSBar\bar\History\search2
C:\Program Files\AskSBar\bar\Settings\prevcfg2.htm
C:\Program Files\Easy Web Cam\dialler.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 )))))))))))))))))))))))))))))))
.
2008-01-11 12:21 . 2008-01-11 12:21 <DIR> d-------- C:\WINDOWS\LastGood
2008-01-11 12:16 . 2008-01-11 12:21 <DIR> d-------- C:\Program Files\Panda Security
2008-01-11 08:28 . 2007-05-30 03:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-11 07:55 . 2008-01-11 07:55 <DIR> d-------- C:\VundoFix Backups
2008-01-11 01:57 . 2008-01-11 02:09 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-01-10 22:09 . 2008-01-10 22:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-10 21:39 . 2008-01-10 21:39 <DIR> d-------- C:\KAV
2008-01-10 20:09 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-01-10 20:08 . 2008-01-10 20:09 <DIR> d-------- C:\Program Files\Java
2008-01-10 20:08 . 2008-01-10 20:08 <DIR> d-------- C:\Program Files\Common Files\Java
2008-01-10 13:27 . 2008-01-10 13:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-01-10 12:14 . 2008-01-10 13:55 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-10 12:14 . 2008-01-10 12:14 <DIR> d-------- C:\Documents and Settings\justin2\Application Data\SUPERAntiSpyware.com
2008-01-10 12:14 . 2008-01-10 12:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-10 12:11 . 2008-01-10 12:11 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-10 11:14 . 2008-01-10 11:14 <DIR> d-------- C:\Documents and Settings\justin2\Application Data\Grisoft
2008-01-10 11:14 . 2008-01-10 11:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-08 15:57 . 2008-01-08 15:57 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-31 12:16 . 2007-12-31 12:16 <DIR> d-------- C:\Documents and Settings\justin2\Application Data\Apple Computer
2007-12-31 12:11 . 2008-01-11 00:21 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-31 12:11 . 2007-12-31 12:11 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-31 12:07 . 2008-01-07 23:56 <DIR> d-------- C:\Program Files\QuickTime
2007-12-31 12:07 . 2007-12-31 12:07 <DIR> d-------- C:\Program Files\Apple Software Update
2007-12-31 12:07 . 2007-12-31 12:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-31 12:07 . 2007-12-31 12:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2007-12-28 20:55 . 2007-12-28 20:55 <DIR> d-------- C:\Documents and Settings\justin2\Application Data\Talkback
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-13 01:33 --------- d-----w C:\Program Files\Easy Web Cam
2008-01-07 23:22 --------- d-----w C:\Documents and Settings\justin2\Application Data\FrostWire
2007-12-20 18:46 73,728 ----a-w C:\WINDOWS\system32\dllcache\wmplayer.exe
2007-12-14 06:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-12 20:39 --------- d-----w C:\Program Files\FrostWire
2007-12-04 23:35 --------- d-----w C:\Program Files\Ubi Soft
2007-12-03 03:33 --------- d-----w C:\Program Files\ApexDC++
2007-11-27 19:10 --------- d--h--r C:\Documents and Settings\justin2\Application Data\yahoo!
2007-11-27 19:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-27 18:03 --------- d-----w C:\Program Files\Realtek AC97
2007-11-27 18:03 --------- d-----w C:\Program Files\PC Drivers HeadQuarters(2)
2007-11-27 18:03 --------- d-----w C:\Program Files\PC Drivers HeadQuarters
2007-11-14 07:26 450,560 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 10:16 3,058,688 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 02:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-28 02:40 227,328 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:36 8,454,656 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
.
((((((((((((((((((((((((((((( snapshot@2008-01-11_ 8.13.10.45 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-11 17:11:43 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-13 01:31:40 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-11 17:11:43 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-13 01:31:40 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-11 17:11:44 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-13 01:31:41 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-11 17:11:44 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-13 01:31:41 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-11 17:11:44 3,284,992 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\ntuser.dat
+ 2008-01-13 01:31:41 3,284,992 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\ntuser.dat
- 2008-01-11 17:11:44 151,552 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-13 01:31:41 151,552 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-11 17:19:14 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_3fc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 00:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-03 22:56 53760 C:\WINDOWS\system32\narrator.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ChkAdmin]
--a------ 2002-01-24 17:03 81920 C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvLsnr]
--a------ 2003-05-08 10:34 69632 C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eTrust PestPatrol Active Protection]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2004-11-02 07:59 126976 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2004-11-02 08:03 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--ahs---- 2007-06-12 05:08 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-22 11:22 7700480 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-22 11:22 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
--a------ 2003-05-05 07:57 143360 C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WIN32SL"=2 (0x2)
"SoundMAX Agent Service (default)"=2 (0x2)
"NVSvc"=2 (0x2)
"gusvc"=3 (0x3)
"cpqWebDmi"=2 (0x2)
"cpqdmi"=2 (0x2)
"CpqDfwWebAgent"=2 (0x2)
"CPQALERT"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"EasyFreeWebCam"=
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"nwiz"=nwiz.exe /install
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"DiskeeperSystray"="C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"CPQDFWAG"=C:\WINDOWS\Cpqdiag\CpqDfwAg.exe
R1 ClntMgmt;Compaq Client Management Driver;C:\WINDOWS\system32\Drivers\ClntMgmt.sys [2002-01-16 13:48]
S3 DoradoPC;Conexant VGA Camera;C:\WINDOWS\system32\DRIVERS\drdvid40.sys [2001-12-16 17:33]
S4 CpqDfwWebAgent;Compaq Remote Diagnostics Enabling Agent;C:\WINDOWS\Cpqdiag\Cpqdfwag.exe [2001-10-25 16:56]
S4 cpqWebDmi;Compaq DMI Web Agent;C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe [2002-01-24 17:09]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9636d46-2b44-11dc-a62b-806d6172696f}]
\shell\AutoRun\command - D:\autorun.exe
*Newly Created Service* - AVG_ANTI-SPYWARE_GUARD
*Newly Created Service* - RKPAVPROC
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-12 16:33:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-12 16:34:23
ComboFix-quarantined-files.txt 2008-01-13 01:34:13
ComboFix2.txt 2008-01-11 17:13:42
ComboFix3.txt 2007-10-20 22:16:05
.
2008-01-10 12:01:06 --- E O F ---
and
Adobe Acrobat 4.0
Adobe Flash Player ActiveX
ApexDC++ 0.4.0
Apple Software Update
AVG Anti-Spyware 7.5
CA eTrust PestPatrol
Chessmaster 9000
Compaq Management Agents
Compaq Remote Diagnostics Enabling Agent
Diskeeper Professional Edition
Disney's Active Play, A Bug's Life
Driver Detective
Easy Web Cam
FrostWire 4.13.3
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
HijackThis 2.0.2
HP Product Detection
Intel(R) Extreme Graphics Driver
Intel(R) PRO Network Connections 12.1.12.0
Java(TM) 6 Update 3
Kaspersky Online Scanner
Macromedia Shockwave Player
Microsoft .NET Framework 2.0
Mozilla Firefox (2.0.0.11)
NetInfo
Neverwinter Nights Platinum Edition
NVIDIA Drivers
Opera 9.23
Panda TotalScan
QuickTime
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 8 (KB917734)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926247)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Setup Compaq Software
SiSoftware Sandra Professional 2005 (Win64/32/CE)
SoundMAX
Spybot - Search & Destroy 1.4
SUPERAntiSpyware Free Edition
Tweak UI
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinZip
Yahoo! Install Manager
Yahoo! Internet Mail