ComboFix log
ComboFix 09-01-21.04 - Holly Wilkins 2009-01-22 17:07:56.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.203 [GMT 0:00]
Running from: c:\documents and settings\Holly Wilkins\Desktop\ComboFxx.exe.exe
Command switches used :: c:\documents and settings\Holly Wilkins\Desktop\CFScript.txt
AV: AVG 7.5.552 *On-access scanning disabled* (Outdated)
* Created a new restore point
FILE ::
c:\program files\Internet Explorer\BTOW Shared Files\btwebcontrol.vll
c:\windows\SYSTEM32\dnpqnxpd.dll
c:\windows\SYSTEM32\rfgfobla.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Internet Explorer\BTOW Shared Files\btwebcontrol.vll
c:\windows\SYSTEM32\dnpqnxpd.dll
c:\windows\SYSTEM32\rfgfobla.dll
.
((((((((((((((((((((((((( Files Created from 2008-12-22 to 2009-01-22 )))))))))))))))))))))))))))))))
.
2009-01-17 21:23 . 2009-01-17 21:23 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll
2009-01-17 21:23 . 2009-01-17 21:23 73,728 --a------ c:\windows\SYSTEM32\javacpl.cpl
2009-01-17 21:12 . 2009-01-17 21:12 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2008-12-24 18:05 . 2008-12-24 18:05 21,361 --a------ c:\windows\SYSTEM32\DRIVERS\AegisP.sys
2008-12-24 18:02 . 2008-12-24 18:02 <DIR> d-------- c:\windows\{745B7758-75C0-4FD8-8CFE-484D569CBD88}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-22 16:56 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-22 16:53 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-19 18:51 --------- d-----w c:\documents and settings\Holly Wilkins\Application Data\AVG7
2009-01-17 21:23 --------- d-----w c:\program files\Java
2009-01-17 21:16 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-01-17 21:11 --------- d-----w c:\program files\Common Files\Adobe
2009-01-17 20:53 --------- d-----w c:\documents and settings\All Users\Application Data\Avg7
2008-12-24 18:04 --------- d-----w c:\program files\Belkin
2008-12-12 17:01 3,067,904 ------w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-11 10:57 333,952 ------w c:\windows\SYSTEM32\DLLCACHE\srv.sys
2008-10-24 11:21 455,296 ------w c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
2008-10-23 12:36 286,720 ------w c:\windows\SYSTEM32\DLLCACHE\gdi32.dll
.
((((((((((((((((((((((((((((( snapshot@2009-01-10_17.44.26.88 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-12 15:06:42 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
- 2000-08-31 08:00:00 28,672 ----a-w c:\windows\NIRCMD.exe
+ 2000-08-31 08:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
- 2003-11-19 15:36:26 24,681 ----a-w c:\windows\SYSTEM32\java.exe
+ 2009-01-17 21:23:11 144,792 ----a-w c:\windows\SYSTEM32\java.exe
- 2003-11-19 15:36:30 28,779 ----a-w c:\windows\SYSTEM32\javaw.exe
+ 2009-01-17 21:23:11 144,792 ----a-w c:\windows\SYSTEM32\javaw.exe
+ 2009-01-17 21:23:11 148,888 ----a-w c:\windows\SYSTEM32\javaws.exe
- 2008-12-09 23:24:37 17,593,280 ----a-w c:\windows\SYSTEM32\MRT.exe
+ 2009-01-10 01:35:28 20,853,704 ----a-w c:\windows\SYSTEM32\MRT.exe
+ 2009-01-22 16:57:48 16,384 ----atw c:\windows\temp\Perflib_Perfdata_688.dat
+ 2006-12-01 22:54:32 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-01 22:54:34 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 22:54:32 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2003-10-27 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-10-27 118784]
"DadApp"="c:\program files\Dell\AccessDirect\dadapp.exe" [2004-03-04 211828]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2004-03-04 487424]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-13 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 536576]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-10-19 590848]
"HostManager"="c:\program files\Common Files\AOL\1174165549\ee\AOLSoftware.exe" [2006-05-24 50760]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-01-26 495616]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-12-23 180269]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-17 136600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2007-10-30 219136]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Belkin F5D8013 N Wireless Notebook Card Utility.lnk - c:\program files\Belkin\F5D8013\Belkinwcui.exe [2008-04-07 1736704]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2004-10-27 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\Program Files\\Common Files\\AOL\\1174165549\\ee\\aim6.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1174165549\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Lavasoft\\Ad-Aware\\Ad-Aware.exe"=
R3 Bonifay;Bonifay;c:\windows\SYSTEM32\DRIVERS\Bonifay.sys [2008-01-03 13056]
R3 RT80x86;Belkin 802.11n Wireless Driver;c:\windows\SYSTEM32\DRIVERS\rt2860.sys [2007-07-28 537216]
S3 3C154A72;3Com OfficeConnect Wireless a/b/g PC Card (3CRWE154A72) Service;c:\windows\SYSTEM32\DRIVERS\3C154A72.sys [2007-04-14 324320]
S3 CA504AV;GSmart Mini 2 WDM Video Capture;c:\windows\SYSTEM32\DRIVERS\CA504AV.SYS [2005-04-04 508394]
S3 Gonzales;Gonzales;c:\windows\SYSTEM32\DRIVERS\Gonzales.sys [2008-01-03 7040]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);c:\windows\SYSTEM32\DRIVERS\sea1bus.sys [2007-07-11 61536]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;c:\windows\SYSTEM32\DRIVERS\sea1mdfl.sys [2007-07-11 9360]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;c:\windows\SYSTEM32\DRIVERS\sea1mdm.sys [2007-07-11 97088]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);c:\windows\SYSTEM32\DRIVERS\sea1mgmt.sys [2007-07-11 88624]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);c:\windows\SYSTEM32\DRIVERS\sea1nd5.sys [2007-07-11 18704]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;c:\windows\SYSTEM32\DRIVERS\sea1obex.sys [2007-07-11 86432]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);c:\windows\SYSTEM32\DRIVERS\sea1unic.sys [2007-07-11 90800]
S3 Sunplus;GSmart Mini 2 Still Image Capture;c:\windows\SYSTEM32\DRIVERS\Bulk504.sys [2005-04-04 10988]
S3 w32n503c;3Com 11Mbps Wireless PC Card (3CRSHPW796) DIS5 Protocol Driver;c:\windows\SYSTEM32\w32n503c.sys [2002-11-22 15360]
.
Contents of the 'Scheduled Tasks' folder
2004-10-30 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\OOBEBALN.EXE [2008-04-14 04:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig?source=gama
mWindow Title = Tiscali 10.0
uInternet Settings,ProxyOverride = 127.0.0.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Holly Wilkins\Application Data\Mozilla\Firefox\Profiles\fus74sfj.default\
FF - prefs.js: browser.startup.homepage - hxxp://by121w.bay121.mail.live.com/mail/InboxLight.aspx?n=170291371|
http://www.google.co.uk/firefox?client=firefox-a&rls=org.mozilla:en-GB:official
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-22 17:10:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Windows\AutorunsDisabled]
"Appinit_Dlls"=""
.
Completion time: 2009-01-22 17:13:38
ComboFix-quarantined-files.txt 2009-01-22 17:13:06
ComboFix2.txt 2009-01-17 21:33:04
ComboFix3.txt 2009-01-10 17:46:37
Pre-Run: 17,034,723,328 bytes free
Post-Run: 17,019,170,816 bytes free
159 --- E O F --- 2009-01-19 21:26:46