middlemancrisis
New member
Hi again, while running the combofix, the AVG scanner kept saying the "ffsdiskk" was infected with Generic10 trojan Horse and no matter if I tried to move it to the vault or heal it did it ever stop coming back up.
Thanks again for your time to help me with this ongoing problem.
ComboFix 08-05-21.3 - Owner 2008-05-24 13:17:27.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.362 [GMT -5:00]
Running from: C:\Users\Owner\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\temp\tn3
C:\Windows\system32\drivers\core.cache.dsk . . . . failed to delete
.
---- Previous Run -------
.
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\Windows\system32\MSINET.oca
C:\Windows\system32\drivers\core.cache.dsk . . . . failed to delete
----- BITS: Possible infected sites -----
hxxp://www.vongo.com
.
((((((((((((((((((((((((( Files Created from 2008-04-24 to 2008-05-24 )))))))))))))))))))))))))))))))
.
2008-05-20 17:09 . 2008-05-20 17:09 <DIR> d-------- C:\_OTMoveIt
2008-05-15 09:06 . 2008-04-22 04:19 683,976 --a------ C:\Windows\System32\drivers\HOSTS
2008-05-11 13:52 . 2008-05-11 13:52 <DIR> d-------- C:\Users\Boo\DoctorWeb
2008-05-09 14:31 . 2008-05-09 14:31 <DIR> d-------- C:\Users\Boo\AppData\Roaming\Malwarebytes
2008-05-09 13:22 . 2008-05-09 13:22 <DIR> d-------- C:\Users\Owner\AppData\Roaming\Malwarebytes
2008-05-09 13:21 . 2008-05-09 13:21 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-05-09 13:21 . 2008-05-09 13:21 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-05-09 13:21 . 2008-05-09 13:21 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-09 13:21 . 2008-05-05 20:46 27,048 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-05-09 13:21 . 2008-05-05 20:46 15,864 --a------ C:\Windows\System32\drivers\mbam.sys
2008-05-08 19:07 . 2008-05-08 19:07 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-05-08 12:11 . 2008-05-08 12:11 <DIR> d-------- C:\KAV
2008-05-08 09:53 . 2008-05-08 09:53 <DIR> d-------- C:\Deckard
2008-05-03 11:21 . 2008-05-03 11:21 151,552 --a------ C:\Windows\System32\WPDMTP.DLL
2008-05-03 11:21 . 2008-05-03 11:21 60,416 --a------ C:\Windows\System32\WPDMTPUS.DLL
2008-05-03 11:21 . 2008-05-03 11:21 33,280 --a------ C:\Windows\System32\WPDCONNS.DLL
2008-05-02 12:22 . 2008-05-02 12:22 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-30 23:17 . 2008-04-30 23:17 <DIR> d-------- C:\Users\Owner\.dwa_store
2008-04-29 17:16 . 2008-04-29 17:16 <DIR> d-------- C:\Program Files\RogueRemover FREE
2008-04-29 16:29 . 2008-04-29 16:29 <DIR> d-------- C:\Users\Boo\AppData\Roaming\Talkback
2008-04-29 12:26 . 2008-04-29 12:26 <DIR> d-------- C:\Users\Owner\AppData\Roaming\Talkback
2008-04-29 12:24 . 2008-04-29 12:24 <DIR> d-------- C:\Users\All Users\Mozilla
2008-04-29 12:23 . 2008-05-23 20:21 <DIR> d-------- C:\Users\All Users\Google Updater
2008-04-29 12:23 . 2008-05-23 20:21 <DIR> d-------- C:\ProgramData\Google Updater
2008-04-29 01:44 . 2008-05-23 11:00 <DIR> d-------- C:\Users\Boo\AppData\Roaming\Spyware Terminator
2008-04-28 23:28 . 2008-05-19 23:26 <DIR> d--h----- C:\$AVG8.VAULT$
2008-04-28 23:26 . 2008-05-22 18:06 <DIR> d-------- C:\Windows\System32\drivers\Avg
2008-04-28 23:26 . 2008-04-28 23:26 96,520 --a------ C:\Windows\System32\drivers\avgldx86.sys
2008-04-28 23:26 . 2008-04-28 23:26 67,080 --a------ C:\Windows\System32\drivers\avgwfpx.sys
2008-04-28 23:26 . 2008-04-28 23:26 10,520 --a------ C:\Windows\System32\avgrsstx.dll
2008-04-28 23:24 . 2008-04-28 23:24 <DIR> d-------- C:\Users\All Users\avg8
2008-04-28 23:24 . 2008-04-28 23:24 <DIR> d-------- C:\ProgramData\avg8
2008-04-28 23:24 . 2008-04-28 23:24 <DIR> d-------- C:\Program Files\AVG
2008-04-28 18:52 . 2008-04-28 18:55 <DIR> d-------- C:\Users\Owner\AppData\Roaming\Spyware Terminator
2008-04-28 18:52 . 2008-05-22 17:57 <DIR> d-------- C:\Users\All Users\Spyware Terminator
2008-04-28 18:52 . 2008-05-22 17:57 <DIR> d-------- C:\ProgramData\Spyware Terminator
2008-04-28 18:52 . 2008-05-23 11:00 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-04-28 18:52 . 2008-04-28 18:52 141,312 --a------ C:\Windows\System32\drivers\sp_rsdrv2.sys
2008-04-28 18:43 . 2008-04-28 18:43 <DIR> d-------- C:\Users\Owner\AppData\Roaming\Yahoo!
2008-04-24 15:01 . 2008-04-24 15:01 <DIR> d-------- C:\Users\Boo\AppData\Roaming\TuneUp Software
2008-04-24 14:39 . 2008-05-21 14:10 167,545 --------- C:\Windows\System32\drivers\core.cache.dsk
2008-04-24 14:39 . 2008-04-24 14:39 86,144 --a------ C:\Windows\System32\drivers\sffdiskk.sys
2008-04-24 14:38 . 2008-04-24 14:38 <DIR> d-------- C:\Temp\zvebs14
2008-04-24 14:38 . 2008-04-24 14:38 <DIR> d-------- C:\Temp\kvebs14
2008-04-24 14:38 . 2008-05-24 13:17 <DIR> d-------- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-22 20:38 --------- d-----w C:\Users\Owner\AppData\Roaming\LimeWire
2008-05-15 14:12 --------- d-----w C:\Users\Boo\AppData\Roaming\LimeWire
2008-05-15 13:39 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-15 13:39 --------- d-----w C:\Program Files\Windows Mail
2008-04-30 03:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-29 17:25 --------- d-----w C:\Program Files\Google
2008-04-29 02:51 --------- d-----w C:\Program Files\Yahoo!
2008-04-28 23:20 --------- d-----w C:\Program Files\HP
2008-04-23 16:56 --------- d-----w C:\Program Files\LimeWire
2008-04-17 19:55 --------- d-----w C:\ProgramData\Roxio
2008-04-17 19:46 --------- d-----w C:\Users\Boo\AppData\Roaming\Roxio
2008-04-17 18:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-17 18:42 --------- d-----w C:\Program Files\ScanSoft
2008-04-17 18:42 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-17 18:40 --------- d-----w C:\ProgramData\Brother
2008-04-16 19:31 --------- d-----w C:\Users\Boo\AppData\Roaming\CyberLink
2008-04-06 19:58 --------- d-----w C:\ProgramData\Kodak
2008-04-06 19:56 --------- d-----w C:\Program Files\Kodak
2008-04-06 19:55 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2008-04-06 19:55 --------- d-----w C:\Program Files\Common Files\Kodak
2007-12-19 21:51 174 --sha-w C:\Program Files\desktop.ini
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-18 23:46 1232896]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 07:35 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 13:38 159744]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-08 21:57 8433664]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-08 21:57 81920]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 15:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 18:12 317128]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 22:36 827392]
"StarzTray"="C:\Program Files\Vongo\VongoTray.exe" [2007-12-12 12:05 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-28 23:25 1177368]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-05-08 18:50 1817600]
"Malwarebytes Anti-Malware Reboot"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [2008-05-05 20:46 1179256]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvSvc"=RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
"WPCUMI"=C:\Windows\system32\WpcUmi.exe
"hpqSRMon"=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy]
"<NO NAME>"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"<NO NAME>"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications]
"<NO NAME>"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"<NO NAME>"=
"C:\\Program Files\\Vongo\\VongoService.exe"= C:\Program Files\Vongo\VongoService.exe:*:enabled:VongoService
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DDB79537-BE1B-49D8-9E35-865252F6818E}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{62DAD364-9054-4450-8B64-1E97F59A49D1}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5BC58A37-88F1-48D7-8BE5-98236F326965}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{977244DC-0C6F-4602-9E5D-F53F4137696A}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{6B76B961-7BC3-47C4-B12A-42CF381A1E0A}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{05F6F3EF-B25C-4001-8372-FE26E6D1B328}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{097692B9-4521-4D1A-9F3E-8E0F924DCDB0}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{F238082B-3978-480D-B122-CF2A1C1231A2}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{C45F953C-C973-4D47-9B6F-8E3786D5C7A2}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{87A0D74F-F719-4D0B-9A9D-EDC91DA7E7E8}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{D1416C4A-9393-4B53-98DF-4EFDC5C80F7D}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{F3387E53-3926-42B7-8D03-04BDD4C0028A}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{8372FB54-1B06-4B1A-ADE0-2C57322D150E}C:\\program files\\vongo\\vongotray.exe"= UDP:C:\program files\vongo\vongotray.exe:StarzTray
"UDP Query User{6F26E3D6-4676-4545-A74F-7F7DBFF950AD}C:\\program files\\vongo\\vongotray.exe"= TCP:C:\program files\vongo\vongotray.exe:StarzTray
"{82342894-DEA7-4B2D-BEE7-C1589D5C9C8C}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
"{E92A9A65-8032-447C-A210-99D735BA97B7}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe
"TCP Query User{E45C5EE2-BFF7-4055-9E3D-20F62E4DCF9D}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{CDF5A335-6626-4A78-85B9-028D55E7908F}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-04-28 23:26]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\Windows\system32\drivers\sp_rsdrv2.sys [2008-04-28 18:52]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-04-28 23:24]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-28 23:24]
R2 UxTuneUp;TuneUp Theme Extension;C:\Windows\System32\svchost.exe [2006-11-02 04:45]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-28 11:44]
R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-04-28 23:26]
R3 nvsmu;nvsmu;C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-16 18:50]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-01-03 10:43]
S3 GameConsoleService;GameConsoleService;"C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe" [2008-01-29 12:09]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-05-09 22:15:00 C:\Windows\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2008-04-07 17:07:43 C:\Windows\Tasks\EasyShare Registration Task.job"
- C:\Windows\system32\rundll32.exeZC:\PROGRA~2\Kodak\EasyShareSetup\$REGIS~1\Registration_7.5.30.2.sxt _RegistrationOffer@16
"2008-05-24 18:30:00 C:\Windows\Tasks\User_Feed_Synchronization-{EAE5730C-A31C-4D96-8182-0282FBFBD7AE}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-24 13:25:38
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-05-24 13:32:30 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-05-24 18:32:19
Pre-Run: 80,621,170,688 bytes free
Post-Run: 80,483,405,824 bytes free
230 --- E O F --- 2008-05-23 16:24:58
Thanks again for your time to help me with this ongoing problem.
ComboFix 08-05-21.3 - Owner 2008-05-24 13:17:27.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.362 [GMT -5:00]
Running from: C:\Users\Owner\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\temp\tn3
C:\Windows\system32\drivers\core.cache.dsk . . . . failed to delete
.
---- Previous Run -------
.
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\Windows\system32\MSINET.oca
C:\Windows\system32\drivers\core.cache.dsk . . . . failed to delete
----- BITS: Possible infected sites -----
hxxp://www.vongo.com
.
((((((((((((((((((((((((( Files Created from 2008-04-24 to 2008-05-24 )))))))))))))))))))))))))))))))
.
2008-05-20 17:09 . 2008-05-20 17:09 <DIR> d-------- C:\_OTMoveIt
2008-05-15 09:06 . 2008-04-22 04:19 683,976 --a------ C:\Windows\System32\drivers\HOSTS
2008-05-11 13:52 . 2008-05-11 13:52 <DIR> d-------- C:\Users\Boo\DoctorWeb
2008-05-09 14:31 . 2008-05-09 14:31 <DIR> d-------- C:\Users\Boo\AppData\Roaming\Malwarebytes
2008-05-09 13:22 . 2008-05-09 13:22 <DIR> d-------- C:\Users\Owner\AppData\Roaming\Malwarebytes
2008-05-09 13:21 . 2008-05-09 13:21 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-05-09 13:21 . 2008-05-09 13:21 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-05-09 13:21 . 2008-05-09 13:21 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-09 13:21 . 2008-05-05 20:46 27,048 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-05-09 13:21 . 2008-05-05 20:46 15,864 --a------ C:\Windows\System32\drivers\mbam.sys
2008-05-08 19:07 . 2008-05-08 19:07 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-05-08 12:11 . 2008-05-08 12:11 <DIR> d-------- C:\KAV
2008-05-08 09:53 . 2008-05-08 09:53 <DIR> d-------- C:\Deckard
2008-05-03 11:21 . 2008-05-03 11:21 151,552 --a------ C:\Windows\System32\WPDMTP.DLL
2008-05-03 11:21 . 2008-05-03 11:21 60,416 --a------ C:\Windows\System32\WPDMTPUS.DLL
2008-05-03 11:21 . 2008-05-03 11:21 33,280 --a------ C:\Windows\System32\WPDCONNS.DLL
2008-05-02 12:22 . 2008-05-02 12:22 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-30 23:17 . 2008-04-30 23:17 <DIR> d-------- C:\Users\Owner\.dwa_store
2008-04-29 17:16 . 2008-04-29 17:16 <DIR> d-------- C:\Program Files\RogueRemover FREE
2008-04-29 16:29 . 2008-04-29 16:29 <DIR> d-------- C:\Users\Boo\AppData\Roaming\Talkback
2008-04-29 12:26 . 2008-04-29 12:26 <DIR> d-------- C:\Users\Owner\AppData\Roaming\Talkback
2008-04-29 12:24 . 2008-04-29 12:24 <DIR> d-------- C:\Users\All Users\Mozilla
2008-04-29 12:23 . 2008-05-23 20:21 <DIR> d-------- C:\Users\All Users\Google Updater
2008-04-29 12:23 . 2008-05-23 20:21 <DIR> d-------- C:\ProgramData\Google Updater
2008-04-29 01:44 . 2008-05-23 11:00 <DIR> d-------- C:\Users\Boo\AppData\Roaming\Spyware Terminator
2008-04-28 23:28 . 2008-05-19 23:26 <DIR> d--h----- C:\$AVG8.VAULT$
2008-04-28 23:26 . 2008-05-22 18:06 <DIR> d-------- C:\Windows\System32\drivers\Avg
2008-04-28 23:26 . 2008-04-28 23:26 96,520 --a------ C:\Windows\System32\drivers\avgldx86.sys
2008-04-28 23:26 . 2008-04-28 23:26 67,080 --a------ C:\Windows\System32\drivers\avgwfpx.sys
2008-04-28 23:26 . 2008-04-28 23:26 10,520 --a------ C:\Windows\System32\avgrsstx.dll
2008-04-28 23:24 . 2008-04-28 23:24 <DIR> d-------- C:\Users\All Users\avg8
2008-04-28 23:24 . 2008-04-28 23:24 <DIR> d-------- C:\ProgramData\avg8
2008-04-28 23:24 . 2008-04-28 23:24 <DIR> d-------- C:\Program Files\AVG
2008-04-28 18:52 . 2008-04-28 18:55 <DIR> d-------- C:\Users\Owner\AppData\Roaming\Spyware Terminator
2008-04-28 18:52 . 2008-05-22 17:57 <DIR> d-------- C:\Users\All Users\Spyware Terminator
2008-04-28 18:52 . 2008-05-22 17:57 <DIR> d-------- C:\ProgramData\Spyware Terminator
2008-04-28 18:52 . 2008-05-23 11:00 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-04-28 18:52 . 2008-04-28 18:52 141,312 --a------ C:\Windows\System32\drivers\sp_rsdrv2.sys
2008-04-28 18:43 . 2008-04-28 18:43 <DIR> d-------- C:\Users\Owner\AppData\Roaming\Yahoo!
2008-04-24 15:01 . 2008-04-24 15:01 <DIR> d-------- C:\Users\Boo\AppData\Roaming\TuneUp Software
2008-04-24 14:39 . 2008-05-21 14:10 167,545 --------- C:\Windows\System32\drivers\core.cache.dsk
2008-04-24 14:39 . 2008-04-24 14:39 86,144 --a------ C:\Windows\System32\drivers\sffdiskk.sys
2008-04-24 14:38 . 2008-04-24 14:38 <DIR> d-------- C:\Temp\zvebs14
2008-04-24 14:38 . 2008-04-24 14:38 <DIR> d-------- C:\Temp\kvebs14
2008-04-24 14:38 . 2008-05-24 13:17 <DIR> d-------- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-22 20:38 --------- d-----w C:\Users\Owner\AppData\Roaming\LimeWire
2008-05-15 14:12 --------- d-----w C:\Users\Boo\AppData\Roaming\LimeWire
2008-05-15 13:39 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-15 13:39 --------- d-----w C:\Program Files\Windows Mail
2008-04-30 03:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-29 17:25 --------- d-----w C:\Program Files\Google
2008-04-29 02:51 --------- d-----w C:\Program Files\Yahoo!
2008-04-28 23:20 --------- d-----w C:\Program Files\HP
2008-04-23 16:56 --------- d-----w C:\Program Files\LimeWire
2008-04-17 19:55 --------- d-----w C:\ProgramData\Roxio
2008-04-17 19:46 --------- d-----w C:\Users\Boo\AppData\Roaming\Roxio
2008-04-17 18:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-17 18:42 --------- d-----w C:\Program Files\ScanSoft
2008-04-17 18:42 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-17 18:40 --------- d-----w C:\ProgramData\Brother
2008-04-16 19:31 --------- d-----w C:\Users\Boo\AppData\Roaming\CyberLink
2008-04-06 19:58 --------- d-----w C:\ProgramData\Kodak
2008-04-06 19:56 --------- d-----w C:\Program Files\Kodak
2008-04-06 19:55 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2008-04-06 19:55 --------- d-----w C:\Program Files\Common Files\Kodak
2007-12-19 21:51 174 --sha-w C:\Program Files\desktop.ini
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-18 23:46 1232896]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 07:35 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 13:38 159744]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-08 21:57 8433664]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-08 21:57 81920]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 15:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 18:12 317128]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 22:36 827392]
"StarzTray"="C:\Program Files\Vongo\VongoTray.exe" [2007-12-12 12:05 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-28 23:25 1177368]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-05-08 18:50 1817600]
"Malwarebytes Anti-Malware Reboot"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [2008-05-05 20:46 1179256]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvSvc"=RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
"WPCUMI"=C:\Windows\system32\WpcUmi.exe
"hpqSRMon"=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy]
"<NO NAME>"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"<NO NAME>"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications]
"<NO NAME>"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"<NO NAME>"=
"C:\\Program Files\\Vongo\\VongoService.exe"= C:\Program Files\Vongo\VongoService.exe:*:enabled:VongoService
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DDB79537-BE1B-49D8-9E35-865252F6818E}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{62DAD364-9054-4450-8B64-1E97F59A49D1}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5BC58A37-88F1-48D7-8BE5-98236F326965}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{977244DC-0C6F-4602-9E5D-F53F4137696A}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{6B76B961-7BC3-47C4-B12A-42CF381A1E0A}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{05F6F3EF-B25C-4001-8372-FE26E6D1B328}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{097692B9-4521-4D1A-9F3E-8E0F924DCDB0}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{F238082B-3978-480D-B122-CF2A1C1231A2}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{C45F953C-C973-4D47-9B6F-8E3786D5C7A2}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{87A0D74F-F719-4D0B-9A9D-EDC91DA7E7E8}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{D1416C4A-9393-4B53-98DF-4EFDC5C80F7D}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{F3387E53-3926-42B7-8D03-04BDD4C0028A}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{8372FB54-1B06-4B1A-ADE0-2C57322D150E}C:\\program files\\vongo\\vongotray.exe"= UDP:C:\program files\vongo\vongotray.exe:StarzTray
"UDP Query User{6F26E3D6-4676-4545-A74F-7F7DBFF950AD}C:\\program files\\vongo\\vongotray.exe"= TCP:C:\program files\vongo\vongotray.exe:StarzTray
"{82342894-DEA7-4B2D-BEE7-C1589D5C9C8C}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
"{E92A9A65-8032-447C-A210-99D735BA97B7}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe
"TCP Query User{E45C5EE2-BFF7-4055-9E3D-20F62E4DCF9D}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{CDF5A335-6626-4A78-85B9-028D55E7908F}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-04-28 23:26]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\Windows\system32\drivers\sp_rsdrv2.sys [2008-04-28 18:52]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-04-28 23:24]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-28 23:24]
R2 UxTuneUp;TuneUp Theme Extension;C:\Windows\System32\svchost.exe [2006-11-02 04:45]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-28 11:44]
R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-04-28 23:26]
R3 nvsmu;nvsmu;C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-16 18:50]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-01-03 10:43]
S3 GameConsoleService;GameConsoleService;"C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe" [2008-01-29 12:09]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-05-09 22:15:00 C:\Windows\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2008-04-07 17:07:43 C:\Windows\Tasks\EasyShare Registration Task.job"
- C:\Windows\system32\rundll32.exeZC:\PROGRA~2\Kodak\EasyShareSetup\$REGIS~1\Registration_7.5.30.2.sxt _RegistrationOffer@16
"2008-05-24 18:30:00 C:\Windows\Tasks\User_Feed_Synchronization-{EAE5730C-A31C-4D96-8182-0282FBFBD7AE}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-24 13:25:38
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-05-24 13:32:30 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-05-24 18:32:19
Pre-Run: 80,621,170,688 bytes free
Post-Run: 80,483,405,824 bytes free
230 --- E O F --- 2008-05-23 16:24:58