ComboFix 08-09-05.12 - Owner 2008-09-09 20:43:42.4 - NTFSx86
Running from: C:\Documents and Settings\Owner.KBrown\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner.KBrown\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-08-10 to 2008-09-10 )))))))))))))))))))))))))))))))
.
2008-09-09 07:46 . 2008-09-09 07:46 250 --a------ C:\WINDOWS\gmer.ini
2008-09-06 11:32 . 2008-09-06 11:32 <DIR> d-------- C:\rsit
2008-09-01 06:32 . 2008-09-01 06:42 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\AVGTOOLBAR
2008-08-24 08:32 . 2008-08-24 08:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-23 23:04 . 2008-09-08 21:19 <DIR> d--h----- C:\$AVG8.VAULT$
2008-08-23 22:21 . 2008-09-09 10:20 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-08-23 22:21 . 2008-08-23 22:21 <DIR> d-------- C:\Program Files\AVG
2008-08-23 22:21 . 2008-09-09 11:47 <DIR> d-------- C:\Documents and Settings\Owner.KBrown\Application Data\AVGTOOLBAR
2008-08-23 22:21 . 2008-08-24 07:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-08-23 22:21 . 2008-09-01 06:36 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-23 22:21 . 2008-08-23 22:21 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-08-23 17:09 . 2008-08-23 17:44 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-08-23 17:09 . 2008-08-23 17:44 <DIR> d-------- C:\Documents and Settings\Owner.KBrown\Application Data\Spyware Terminator
2008-08-23 17:09 . 2008-08-23 17:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-08-23 17:09 . 2008-08-23 17:09 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-08-23 09:03 . 2008-08-23 09:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-08-23 07:33 . 2008-08-23 07:33 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Yahoo!
2008-08-20 04:29 . 2008-08-20 04:29 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-20 04:29 . 2008-08-20 04:29 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-20 04:29 . 2008-08-20 04:29 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-20 04:29 . 2008-08-20 04:29 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-20 04:25 . 2008-08-20 04:30 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-19 22:13 . 2008-08-19 22:13 <DIR> d-------- C:\Program Files\iPod
2008-08-19 22:12 . 2008-08-19 22:12 <DIR> d-------- C:\Program Files\Bonjour
2008-08-19 21:21 . 2008-04-13 20:12 4,274,816 --------- C:\WINDOWS\system32\nv4_disp.dll
2008-08-19 21:20 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-08-16 23:10 . 2008-08-16 23:10 <DIR> d-------- C:\Program Files\Jetico
2008-08-16 07:08 . 2008-08-16 08:06 <DIR> d-------- C:\Documents and Settings\Owner.KBrown\Application Data\DivX
2008-08-14 20:59 . 2008-04-11 15:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-13 14:02 . 2008-08-17 22:13 <DIR> d-------- C:\Documents and Settings\Owner.KBrown\Application Data\Yahoo!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-07 18:57 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-08-20 02:22 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-20 02:13 --------- d-----w C:\Program Files\iTunes
2008-08-20 02:11 --------- d-----w C:\Program Files\QuickTime
2008-08-20 01:58 --------- d-----w C:\Program Files\Apple Software Update
2008-08-17 09:46 --------- d-----w C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
2008-08-17 09:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-17 09:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-08-17 09:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-17 08:21 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-08-17 08:21 --------- d-----w C:\Program Files\Vonage
2008-08-17 08:21 --------- d-----w C:\Program Files\Shockwave.com
2008-08-17 08:20 --------- d-----w C:\Program Files\PokerStars
2008-08-17 08:19 --------- d-----w C:\Program Files\Napster
2008-08-17 08:19 --------- d-----w C:\Program Files\MSN Encarta Plus
2008-08-17 08:19 --------- d-----w C:\Program Files\Microsoft Works
2008-08-17 08:16 --------- d-----w C:\Program Files\Microsoft Money 2006
2008-08-17 08:16 --------- d-----w C:\Program Files\Microsoft Digital Image 2006
2008-08-17 08:14 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-08-17 08:09 --------- d-----w C:\Program Files\gtw_logo
2008-08-17 08:09 --------- d-----w C:\Program Files\Google
2008-08-17 08:08 --------- d-----w C:\Program Files\FLV Player
2008-08-17 08:08 --------- d-----w C:\Program Files\DivX
2008-08-17 08:07 --------- d-----w C:\Program Files\Coupons
2008-08-17 08:07 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-17 08:04 --------- d-----w C:\Program Files\Common Files\AOL
2008-08-17 08:04 --------- d-----w C:\Program Files\Best Buy Offers
2008-08-17 07:47 --------- d-----w C:\Documents and Settings\Owner.KBrown\Application Data\MSNInstaller
2008-08-17 07:47 --------- d-----w C:\Documents and Settings\Owner.KBrown\Application Data\Move Networks
2008-08-17 07:46 --------- d-----w C:\Documents and Settings\Owner.KBrown\Application Data\mjusbsp
2008-08-13 18:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-08-13 18:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-07-23 00:32 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
.
((((((((((((((((((((((((((((( snapshot@2008-09-08_ 8.14.12.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-09 11:46:49 884,736 ----a-w C:\WINDOWS\gmer.dll
+ 2008-04-18 01:13:02 811,008 ----a-w C:\WINDOWS\gmer.exe
+ 2008-09-09 11:46:49 85,969 ----a-w C:\WINDOWS\system32\drivers\gmer.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-07 1576176]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-06-25 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-09-07 14:57 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.KBrown^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Documents and Settings\Owner.KBrown\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
C:\WINDOWS\system32\WLTRAY [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKAGENTEXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-07-22 20:42 116040 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2005-04-29 00:05 344064 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
--a------ 2008-09-01 06:36 1235736 C:\PROGRA~1\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCWipeTM Startup]
--a------ 2008-01-09 05:56 543272 C:\Program Files\Jetico\BCWipe\BCWipeTM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
--a------ 2008-06-12 15:37 50520 C:\Documents and Settings\Owner.KBrown\Application Data\mjusbsp\cdloader2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 20:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2005-08-06 00:56 64512 C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-07-30 10:47 289064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
--a------ 2005-08-12 19:16 1121792 C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 20:12 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mssadv.exe]
--a------ 2008-09-01 06:36 1235736 C:\PROGRA~1\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a------ 2002-09-14 01:42 212992 C:\WINDOWS\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
--a------ 2005-02-25 20:24 966656 C:\WINDOWS\creator\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-11-10 13:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-02-02 06:21 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2004-11-05 10:47 688218 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a------ 2004-11-05 10:47 98394 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-01 97928]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-01 231704]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-01-25 200576]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;C:\WINDOWS\system32\DRIVERS\el575nd5.sys [2001-08-17 69692]
S3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS\system32\Drivers\Icam3.sys [2001-08-17 141056]
S4 BCSWAP;BCSWAP;C:\WINDOWS\system32\drivers\BCSWAP.sys [2007-09-14 91496]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a36abb5-5e9a-11dd-86b8-0014a596cf1e}]
\Shell\AutoRun\command - F:\autorun.exe
\Shell\phone\command - F:\autorun.exe
*Newly Created Service* - GMER
.
Contents of the 'Scheduled Tasks' folder
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-09 20:47:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-09 20:49:01
ComboFix-quarantined-files.txt 2008-09-10 00:48:30
ComboFix2.txt 2008-09-10 00:09:57
ComboFix3.txt 2008-09-09 11:37:53
ComboFix4.txt 2008-09-08 12:14:46
Pre-Run: 47,535,214,592 bytes free
Post-Run: 47,518,478,336 bytes free
192 --- E O F --- 2008-08-22 09:34:37