ComboFix 08-08-08.04 - user 2008-08-09 12:18:40.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.31 [GMT -4:00]
Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\user\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\Documents and Settings\All Users\Application Data\wbsnkzaf.dll
C:\Documents and Settings\user\6.exe
C:\Documents and Settings\user\Start Menu\Programs\Startup\Glove - Auto Update.lnk
C:\Program Files\TTC.dll
C:\WINDOWS\system32\aipphxbyvhdfmohpt.exe
C:\WINDOWS\system32\drivers\yAhWWSCrIKS.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\wbsnkzaf.dll
C:\Documents and Settings\user\6.exe
C:\Documents and Settings\user\Start Menu\Programs\Startup\Glove - Auto Update.lnk
C:\Program Files\Glove
C:\Program Files\Glove\Glove.dll
C:\Program Files\Glove\Glove.dll.intermediate.manifest
C:\Program Files\Glove\Glove.exe
C:\Program Files\Glove\Glove.original
C:\Program Files\Glove\Gloverg.dll
C:\Program Files\Glove\un_GloveSetup_16754.exe
C:\Program Files\Glove\un_GloveSetup_16754.txt
C:\Program Files\Glove\X_Glove.exe
C:\Program Files\Glove\X_Glove.log
C:\Program Files\TTC.dll
C:\Program Files\VnrBlock
C:\Program Files\VnrBlock\VnrBlock20.exe
C:\Program Files\VnrBlock\xtarga.gz
C:\WINDOWS\system32\aipphxbyvhdfmohpt.exe
C:\WINDOWS\system32\drivers\yAhWWSCrIKS.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_yAhWWSCrIKS.sys
-------\Service_yAhWWSCrIKS.sys
((((((((((((((((((((((((( Files Created from 2008-07-09 to 2008-08-09 )))))))))))))))))))))))))))))))
.
2008-08-08 12:35 . 2003-03-18 16:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-08-08 12:34 . 2008-08-08 12:34 <DIR> d-------- C:\Program Files\Alwil Software
2008-08-08 12:31 . 2008-08-08 14:30 <DIR> d-------- C:\Documents and Settings\Administrator
2008-08-08 12:19 . 2008-08-08 12:19 <DIR> d-------- C:\Program Files\Avira
2008-08-08 12:19 . 2008-08-08 12:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-08-08 09:34 . 2008-08-08 10:30 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-08-08 09:34 . 2005-02-24 23:35 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-08-07 16:17 . 2008-08-07 16:17 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-07 16:17 . 2008-08-07 16:17 <DIR> d-------- C:\WINDOWS\ehome
2008-08-07 16:04 . 2002-07-02 00:38 1,325,568 --a------ C:\WINDOWS\system32\webfldrs.msi
2008-08-07 16:03 . 2002-08-29 06:41 674,816 --a------ C:\WINDOWS\system32\sxs.dll
2008-08-07 16:01 . 2002-08-29 06:41 3,494,303 --------- C:\WINDOWS\system32\nv4_disp.dll
2008-08-07 16:00 . 2002-08-29 06:41 1,677,312 --------- C:\WINDOWS\system32\wmvcore2.dll
2008-08-07 15:59 . 2005-05-04 14:45 2,890,240 --a------ C:\WINDOWS\system32\msi.dll
2008-08-07 15:58 . 2002-08-29 06:41 1,128,960 --a------ C:\WINDOWS\system32\mmcndmgr.dll
2008-08-07 15:57 . 2002-08-29 06:39 290,816 --a------ C:\WINDOWS\system32\l3codeca.acm
2008-08-07 15:55 . 2002-08-29 06:41 1,004,032 --a------ C:\WINDOWS\explorer.exe
2008-08-07 15:54 . 2002-08-29 06:40 1,180,672 --a------ C:\WINDOWS\system32\d3d8.dll
2008-08-07 15:53 . 2002-08-29 06:40 239,616 --a------ C:\WINDOWS\system32\adsnt.dll
2008-08-07 15:53 . 2002-08-29 06:40 162,816 --a------ C:\WINDOWS\system32\adsldp.dll
2008-08-07 15:53 . 2002-08-29 06:40 139,776 --a------ C:\WINDOWS\system32\adsldpc.dll
2008-08-07 15:53 . 2002-08-29 06:40 115,712 --a------ C:\WINDOWS\system32\apphelp.dll
2008-08-07 15:53 . 2002-08-29 06:41 91,648 --a------ C:\WINDOWS\system32\ahui.exe
2008-08-07 15:53 . 2002-08-29 06:40 62,464 --a------ C:\WINDOWS\system32\adsmsext.dll
2008-08-07 15:53 . 2002-08-29 06:40 59,392 --a------ C:\WINDOWS\system32\6to4svc.dll
2008-08-07 15:53 . 2002-08-29 06:41 41,984 --a------ C:\WINDOWS\system32\alg.exe
2008-08-07 15:53 . 2002-08-29 04:05 32,512 --------- C:\WINDOWS\system32\drivers\amdk7.sys
2008-08-07 15:11 . 2008-08-07 15:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-08-04 16:43 . 2008-08-04 16:43 87 --a------ C:\WINDOWS\wininit.ini
2008-08-04 15:18 . 2008-08-07 02:31 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-04 15:18 . 2008-08-07 02:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-04 15:07 . 2008-08-04 15:07 <DIR> d-------- C:\Program Files\AIM Search
2008-08-04 15:06 . 2008-08-04 15:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-04 15:05 . 2008-08-04 15:06 <DIR> d-------- C:\Program Files\Viewpoint
2008-08-04 15:03 . 2008-08-04 15:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-08-04 15:03 . 2008-08-04 15:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-08-04 15:02 . 2008-08-04 19:50 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-08-04 14:59 . 2008-08-04 15:13 428 --ah----- C:\IPH.PH
2008-08-04 14:08 . 2008-08-04 14:08 <DIR> d-------- C:\b46815df4e7bceb32ee9502cc6
2008-08-04 01:31 . 2008-08-09 12:23 0 --a------ C:\WINDOWS\system.ini
2008-08-04 01:26 . 2008-08-04 17:44 <DIR> d---s---- C:\WINDOWS\Downloaded Program Files
2008-08-03 13:34 . 2008-08-03 13:34 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-03 13:30 . 2008-08-03 13:30 0 --a------ C:\WINDOWS\nsreg.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-03 17:22 --------- d-----w C:\Documents and Settings\user\Application Data\MSN6
.
((((((((((((((((((((((((((((( snapshot@2008-08-08_14.35.00.23 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-08 18:34:02 40,190 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-08-08 18:39:07 40,190 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-08 18:34:03 311,842 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-08-08 18:39:07 311,842 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-04-12 05:43 1661304]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Wireless-G Notebook Adapter.lnk - C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe [2008-02-29 22:50:11 36864]
R0 avgntmgr;avgntmgr;C:\WINDOWS\System32\DRIVERS\avgntmgr.sys [2008-01-21 18:11]
R1 avgntdd;avgntdd;C:\WINDOWS\System32\DRIVERS\avgntdd.sys [2008-05-09 13:15]
R2 NICSer_WPC54G;NICSer_WPC54G;C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe [2003-11-13 17:29]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38]
R3 atimtai;atimtai;C:\WINDOWS\System32\DRIVERS\atimtai.sys [2001-08-17 08:48]
R3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;C:\WINDOWS\System32\CBTNDIS5.SYS [2003-07-17 02:28]
R3 EL556ND5;3Com 10/100 MiniPCI Ethernet Adapter Driver;C:\WINDOWS\System32\DRIVERS\EL556ND5.sys [2001-08-17 08:10]
R3 maestro;ESS Maestro 3 Audio Driver (WDM);C:\WINDOWS\System32\drivers\es198x.sys [2001-08-17 08:19]
R3 WDHAALBA;WDHAALBAMiniPCI Winmodem;C:\WINDOWS\System32\DRIVERS\WDHAALBA.sys [2001-08-17 09:28]
R3 WPC54Gv3;Linksys Wireless Notebook Adapter WPC54Gv3 Driver;C:\WINDOWS\System32\DRIVERS\WPC54Gv3.SYS [2006-12-01 03:54]
.
Contents of the 'Scheduled Tasks' folder
2008-08-08 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe []
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-09 12:23:13
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Atievxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
.
**************************************************************************
.
Completion time: 2008-08-09 12:26:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-09 16:26:08
ComboFix2.txt 2008-08-08 18:35:42
Pre-Run: 32,444,461,056 bytes free
Post-Run: 32,433,586,176 bytes free
144 --- E O F --- 2008-08-03 18:43:08
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:29:42 PM, on 8/9/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Atievxx.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (file missing)
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (file missing)
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 3528 bytes
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.31 [GMT -4:00]
Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\user\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\Documents and Settings\All Users\Application Data\wbsnkzaf.dll
C:\Documents and Settings\user\6.exe
C:\Documents and Settings\user\Start Menu\Programs\Startup\Glove - Auto Update.lnk
C:\Program Files\TTC.dll
C:\WINDOWS\system32\aipphxbyvhdfmohpt.exe
C:\WINDOWS\system32\drivers\yAhWWSCrIKS.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\wbsnkzaf.dll
C:\Documents and Settings\user\6.exe
C:\Documents and Settings\user\Start Menu\Programs\Startup\Glove - Auto Update.lnk
C:\Program Files\Glove
C:\Program Files\Glove\Glove.dll
C:\Program Files\Glove\Glove.dll.intermediate.manifest
C:\Program Files\Glove\Glove.exe
C:\Program Files\Glove\Glove.original
C:\Program Files\Glove\Gloverg.dll
C:\Program Files\Glove\un_GloveSetup_16754.exe
C:\Program Files\Glove\un_GloveSetup_16754.txt
C:\Program Files\Glove\X_Glove.exe
C:\Program Files\Glove\X_Glove.log
C:\Program Files\TTC.dll
C:\Program Files\VnrBlock
C:\Program Files\VnrBlock\VnrBlock20.exe
C:\Program Files\VnrBlock\xtarga.gz
C:\WINDOWS\system32\aipphxbyvhdfmohpt.exe
C:\WINDOWS\system32\drivers\yAhWWSCrIKS.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_yAhWWSCrIKS.sys
-------\Service_yAhWWSCrIKS.sys
((((((((((((((((((((((((( Files Created from 2008-07-09 to 2008-08-09 )))))))))))))))))))))))))))))))
.
2008-08-08 12:35 . 2003-03-18 16:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-08-08 12:34 . 2008-08-08 12:34 <DIR> d-------- C:\Program Files\Alwil Software
2008-08-08 12:31 . 2008-08-08 14:30 <DIR> d-------- C:\Documents and Settings\Administrator
2008-08-08 12:19 . 2008-08-08 12:19 <DIR> d-------- C:\Program Files\Avira
2008-08-08 12:19 . 2008-08-08 12:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-08-08 09:34 . 2008-08-08 10:30 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-08-08 09:34 . 2005-02-24 23:35 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-08-07 16:17 . 2008-08-07 16:17 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-07 16:17 . 2008-08-07 16:17 <DIR> d-------- C:\WINDOWS\ehome
2008-08-07 16:04 . 2002-07-02 00:38 1,325,568 --a------ C:\WINDOWS\system32\webfldrs.msi
2008-08-07 16:03 . 2002-08-29 06:41 674,816 --a------ C:\WINDOWS\system32\sxs.dll
2008-08-07 16:01 . 2002-08-29 06:41 3,494,303 --------- C:\WINDOWS\system32\nv4_disp.dll
2008-08-07 16:00 . 2002-08-29 06:41 1,677,312 --------- C:\WINDOWS\system32\wmvcore2.dll
2008-08-07 15:59 . 2005-05-04 14:45 2,890,240 --a------ C:\WINDOWS\system32\msi.dll
2008-08-07 15:58 . 2002-08-29 06:41 1,128,960 --a------ C:\WINDOWS\system32\mmcndmgr.dll
2008-08-07 15:57 . 2002-08-29 06:39 290,816 --a------ C:\WINDOWS\system32\l3codeca.acm
2008-08-07 15:55 . 2002-08-29 06:41 1,004,032 --a------ C:\WINDOWS\explorer.exe
2008-08-07 15:54 . 2002-08-29 06:40 1,180,672 --a------ C:\WINDOWS\system32\d3d8.dll
2008-08-07 15:53 . 2002-08-29 06:40 239,616 --a------ C:\WINDOWS\system32\adsnt.dll
2008-08-07 15:53 . 2002-08-29 06:40 162,816 --a------ C:\WINDOWS\system32\adsldp.dll
2008-08-07 15:53 . 2002-08-29 06:40 139,776 --a------ C:\WINDOWS\system32\adsldpc.dll
2008-08-07 15:53 . 2002-08-29 06:40 115,712 --a------ C:\WINDOWS\system32\apphelp.dll
2008-08-07 15:53 . 2002-08-29 06:41 91,648 --a------ C:\WINDOWS\system32\ahui.exe
2008-08-07 15:53 . 2002-08-29 06:40 62,464 --a------ C:\WINDOWS\system32\adsmsext.dll
2008-08-07 15:53 . 2002-08-29 06:40 59,392 --a------ C:\WINDOWS\system32\6to4svc.dll
2008-08-07 15:53 . 2002-08-29 06:41 41,984 --a------ C:\WINDOWS\system32\alg.exe
2008-08-07 15:53 . 2002-08-29 04:05 32,512 --------- C:\WINDOWS\system32\drivers\amdk7.sys
2008-08-07 15:11 . 2008-08-07 15:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-08-04 16:43 . 2008-08-04 16:43 87 --a------ C:\WINDOWS\wininit.ini
2008-08-04 15:18 . 2008-08-07 02:31 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-04 15:18 . 2008-08-07 02:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-04 15:07 . 2008-08-04 15:07 <DIR> d-------- C:\Program Files\AIM Search
2008-08-04 15:06 . 2008-08-04 15:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-08-04 15:05 . 2008-08-04 15:06 <DIR> d-------- C:\Program Files\Viewpoint
2008-08-04 15:03 . 2008-08-04 15:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-08-04 15:03 . 2008-08-04 15:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-08-04 15:02 . 2008-08-04 19:50 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-08-04 14:59 . 2008-08-04 15:13 428 --ah----- C:\IPH.PH
2008-08-04 14:08 . 2008-08-04 14:08 <DIR> d-------- C:\b46815df4e7bceb32ee9502cc6
2008-08-04 01:31 . 2008-08-09 12:23 0 --a------ C:\WINDOWS\system.ini
2008-08-04 01:26 . 2008-08-04 17:44 <DIR> d---s---- C:\WINDOWS\Downloaded Program Files
2008-08-03 13:34 . 2008-08-03 13:34 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-03 13:30 . 2008-08-03 13:30 0 --a------ C:\WINDOWS\nsreg.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-03 17:22 --------- d-----w C:\Documents and Settings\user\Application Data\MSN6
.
((((((((((((((((((((((((((((( snapshot@2008-08-08_14.35.00.23 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-08 18:34:02 40,190 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-08-08 18:39:07 40,190 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-08 18:34:03 311,842 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-08-08 18:39:07 311,842 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-04-12 05:43 1661304]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Wireless-G Notebook Adapter.lnk - C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe [2008-02-29 22:50:11 36864]
R0 avgntmgr;avgntmgr;C:\WINDOWS\System32\DRIVERS\avgntmgr.sys [2008-01-21 18:11]
R1 avgntdd;avgntdd;C:\WINDOWS\System32\DRIVERS\avgntdd.sys [2008-05-09 13:15]
R2 NICSer_WPC54G;NICSer_WPC54G;C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe [2003-11-13 17:29]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38]
R3 atimtai;atimtai;C:\WINDOWS\System32\DRIVERS\atimtai.sys [2001-08-17 08:48]
R3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;C:\WINDOWS\System32\CBTNDIS5.SYS [2003-07-17 02:28]
R3 EL556ND5;3Com 10/100 MiniPCI Ethernet Adapter Driver;C:\WINDOWS\System32\DRIVERS\EL556ND5.sys [2001-08-17 08:10]
R3 maestro;ESS Maestro 3 Audio Driver (WDM);C:\WINDOWS\System32\drivers\es198x.sys [2001-08-17 08:19]
R3 WDHAALBA;WDHAALBAMiniPCI Winmodem;C:\WINDOWS\System32\DRIVERS\WDHAALBA.sys [2001-08-17 09:28]
R3 WPC54Gv3;Linksys Wireless Notebook Adapter WPC54Gv3 Driver;C:\WINDOWS\System32\DRIVERS\WPC54Gv3.SYS [2006-12-01 03:54]
.
Contents of the 'Scheduled Tasks' folder
2008-08-08 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe []
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-09 12:23:13
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Atievxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
.
**************************************************************************
.
Completion time: 2008-08-09 12:26:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-09 16:26:08
ComboFix2.txt 2008-08-08 18:35:42
Pre-Run: 32,444,461,056 bytes free
Post-Run: 32,433,586,176 bytes free
144 --- E O F --- 2008-08-03 18:43:08
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:29:42 PM, on 8/9/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Atievxx.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (file missing)
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (file missing)
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 3528 bytes