ComboFix 07-11-19.3 - Admin 2007-11-22 21:55:35.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.209 [GMT -5:00]
Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Admin\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.
2007-11-22 13:20 <DIR> d-------- C:\VundoFix Backups
2007-11-21 21:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-21 17:07 118 --a------ C:\WINDOWS\system32\MRT.INI
2007-11-21 15:21 80,960 --a------ C:\WINDOWS\system32\mxbhubgd.dll
2007-11-21 14:59 <DIR> d-------- C:\Program Files\CCleaner
2007-11-21 14:32 <DIR> d-------- C:\Program Files\Windows Defender
2007-11-21 14:27 80,960 --a------ C:\WINDOWS\system32\xpywlfue.dll
2007-11-21 14:25 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-11-21 13:21 80,960 --a------ C:\WINDOWS\system32\wxbtuanx.dll
2007-11-09 08:30 583,921 ---hs---- C:\WINDOWS\system32\lwgipqfa.ini
2007-11-09 08:30 88,128 --a------ C:\WINDOWS\system32\afqpigwl.dll
2007-11-09 08:28 77,888 --a------ C:\WINDOWS\system32\kpfxenfo.dll
2007-11-09 08:24 71,232 --a------ C:\WINDOWS\system32\xkiijiyf.exe
2007-11-09 08:22 <DIR> d-------- C:\Program Files\QdrModule
2007-11-09 08:22 441,950 ---hs---- C:\WINDOWS\system32\lnmoq.bak2
2007-11-09 08:22 145,984 --a------ C:\WINDOWS\system32\rxqnbksa.dll
2007-11-08 10:50 4 --a------ C:\WINDOWS\system32\stfv.bin
2007-10-24 20:57 <DIR> d-------- C:\WINDOWS\system32\acespy
2007-10-24 20:19 6,465 ---hs---- C:\WINDOWS\system32\lnmoq.bak1
2007-10-24 20:18 437,315 ---hs---- C:\WINDOWS\system32\lnmoq.ini
2007-10-24 20:16 92 --a------ C:\WINDOWS\system32\sznf.ascii
2007-10-24 20:15 14 --a------ C:\WINDOWS\system32\din.ip
2007-10-24 20:15 4 --a------ C:\WINDOWS\system32\navwanvd.ini
2007-10-24 20:15 2 --a------ C:\WINDOWS\system32\lt.res
2007-10-24 20:13 12,217 --a------ C:\WINDOWS\system32\winlogon.scr
2007-10-24 20:13 12,217 ---hs---- C:\Documents and Settings\Mom and Dad\winmain.exe
2007-10-24 20:13 3,739 --a------ C:\WINDOWS\system32\sft.res
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-21 20:24 --------- d-----w C:\Program Files\SpywareGuard
2007-11-21 20:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-21 20:06 --------- d-----w C:\Program Files\Dell
2007-11-21 20:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-21 20:05 --------- d-----w C:\Program Files\CyberLink
2007-11-08 15:54 --------- d-----w C:\Documents and Settings\Admin\Application Data\Lavasoft
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-17 19:04 --------- d-----w C:\Program Files\Wal-Mart Music Downloads Store
2007-10-17 19:03 --------- d-----w C:\Program Files\Sonic
2007-10-17 19:02 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2007-10-17 18:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-10-17 18:06 --------- d-----w C:\Program Files\Google
2007-10-17 17:54 --------- d-----w C:\Program Files\Common Files\Intuit
2007-10-17 17:24 --------- d-----w C:\Program Files\Java
2007-10-17 17:23 --------- d-----w C:\Program Files\Common Files\Java
2007-10-16 04:43 --------- d-----w C:\Program Files\Trend Micro
2007-10-15 23:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-10-15 23:22 --------- d-----w C:\Program Files\Yahoo!
2007-10-15 23:22 --------- d-----w C:\Program Files\Common Files\Scanner
2007-09-27 11:03 --------- d-----w C:\Documents and Settings\Jen\Application Data\Viewpoint
2007-09-23 18:18 --------- d-----w C:\Documents and Settings\Mom and Dad\Application Data\Walgreens
2007-08-17 00:39 61,648 ----a-w C:\Documents and Settings\Mom and Dad\Application Data\GDIPFONTCACHEV1.DAT
2007-03-16 16:42 53,848 ----a-w C:\Documents and Settings\Admin\Application Data\GDIPFONTCACHEV1.DAT
2006-09-09 00:55 0 ---ha-w C:\Documents and Settings\Jen\hpothb07.dat
2006-08-20 23:26 0 ---ha-w C:\Documents and Settings\Mom and Dad\hpothb07.dat
2006-01-18 01:37 0 ---ha-w C:\Documents and Settings\NetworkService\hpothb07.dat
2005-12-27 16:21 0 ---ha-w C:\Documents and Settings\LocalService\hpothb07.dat
2005-12-27 15:03 164 ---ha-w C:\Documents and Settings\All Users\hpothb07.dat
2005-12-27 15:03 0 ---ha-w C:\Documents and Settings\Administrator\hpothb07.dat
2005-12-27 15:02 0 ---ha-w C:\Documents and Settings\Guest\hpothb07.dat
2005-12-27 15:02 0 ---ha-w C:\Documents and Settings\Default User\hpothb07.dat
2001-11-19 17:14 61,440 ----a-w C:\WINDOWS\inf\i386\gl.dll
2001-10-29 19:30 245,760 ----a-w C:\WINDOWS\inf\i386\viceo.dll
2001-08-17 22:43 32,768 ----a-w C:\WINDOWS\inf\i386\Wiamicro.dll
2005-07-29 20:24 472 --sha-r C:\WINDOWS\QWRtaW4\kqlQuqb.vbs
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-11-29 19:19]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-26 17:22]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 04:40]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-01-31 16:35]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-31 21:10]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 11:26]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-07-20 23:48]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 04:40]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 04:40]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 01:02]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-12-10 18:02]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-12-30 14:19]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-25 09:14]
"HPHUPD05"="C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-20 16:23]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-08-20 14:57]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24]
"HPHmon05"="C:\WINDOWS\system32\hphmon05.exe" [2003-08-20 16:15]
"PrintServer Diagnostic"="C:\Program Files\Print Server\PTP\PSDiagnostic.exe" [2004-11-24 17:09]
"OneTouch Monitor"="C:\Program Files\Visioneer OneTouch\OneTouchMon.exe" [2002-04-16 07:12]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-09-02 10:19]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-26 17:22]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="C:\WINDOWS\system32\Macromed\Flash\GetFlash.exe" [2006-06-22 12:44]
C:\Documents and Settings\Admin\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-07-20 23:41:47]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
C:\WINDOWS\system32\NavLogon.dll 2004-12-30 14:19 55104 C:\WINDOWS\system32\NavLogon.dll
R2 ppsio2;PPDevice;C:\WINDOWS\system32\drivers\ppsio2.sys
S3 BVRPMPR5;BVRPMPR5 NDIS Protocol Driver;\??\D:\INSTAL~E\Core\BVRPMPR5.SYS
S3 O2SCBUS;O2Micro SmartCardBus Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys
S3 pmxscan;Visioneer USB Kernel;C:\WINDOWS\system32\DRIVERS\usbscan.sys
S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;C:\WINDOWS\system32\DRIVERS\netusbxp.sys
.
Contents of the 'Scheduled Tasks' folder
"2006-06-01 13:10:00 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#7700#MY38L133BDK5.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe$/#Hewlett-Packard#7700#MY38L133BDK5
"2007-11-22 18:09:00 C:\WINDOWS\Tasks\HP Usg Daily.job"
- C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\pexpress\hphped05.exe
"2007-11-23 02:48:59 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-22 21:58:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-22 21:59:35
C:\ComboFix2.txt ... 2007-11-22 13:37
.
--- E O F ---