ComboFix.txt
Administrator - Fri 12/22/2006 18:22:10.80 Service Pack 4
ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Administrator\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2006-11-22 to 2006-12-22 ))))))))))))))))))))))))))))))))))
2006-12-21 18:23 <DIR> d-------- C:\Documents and Settings\Administrator\DoctorWeb
2006-12-19 21:09 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2006-12-19 21:09 <DIR> d-------- C:\Program Files\Grisoft
2006-12-18 18:26 <DIR> d-------- C:\FOUND.006
2006-12-17 08:57 <DIR> d-------- C:\HiJackThis
2006-12-16 22:45 <DIR> d-------- C:\fixwareout
2006-12-16 16:17 <DIR> d-------- C:\FOUND.005
2006-12-16 15:39 <DIR> d-------- C:\WINDOWS\Minidump
2006-12-16 15:39 <DIR> d-------- C:\FOUND.004
2006-12-14 22:51 <DIR> d-------- C:\WINDOWS\SYSTEM32\drv32dta
2006-12-14 22:20 38,912 --a------ C:\WINDOWS\SYSTEM32\aspi1470512.exe
2006-12-14 22:14 81,920 --a------ C:\WINDOWS\SYSTEM32\Packet.dll
2006-12-14 22:14 61,440 --a------ C:\WINDOWS\SYSTEM32\WanPacket.dll
2006-12-14 22:14 53,299 --a------ C:\WINDOWS\SYSTEM32\pthreadVC.dll
2006-12-14 22:14 32,512 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\npf.sys
2006-12-14 22:14 233,472 --a------ C:\WINDOWS\SYSTEM32\wpcap.dll
2006-12-14 21:58 46,592 --a------ C:\WINDOWS\SYSTEM32\zlbw.dll
2006-12-14 21:55 393 --a------ C:\WINDOWS\SYSTEM32\z16.exe
2006-12-14 21:55 391 --a------ C:\WINDOWS\SYSTEM32\z14.exe
2006-12-14 21:54 5,120 --a------ C:\WINDOWSsystem32alg.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
Rootkit driver pe386 is present. A rootkit scan is required
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SystemTray"="SysTray.Exe"
"Synchronization Manager"="mobsync.exe /logon"
"HP OfficeJet Series 700"="\"C:\\Program Files\\Hewlett-Packard\\HP OfficeJet Series 700 NT\\bin\\ktchnsnk.exe\" -reg \"Software\\Hewlett-Packard\\OfficeJet Series 700\\Install\""
"ConMgr.exe"="\"C:\\Program Files\\EarthLink 5.0\\ConMgr.exe\""
"UpdateMgr.exe"="\"C:\\Program Files\\EarthLink 5.0\\updatemgr.exe\" /NOCM"
"RFX_auto_upgrade"=""
"IW Controlcenter"="C:\\PROGRA~1\\INSTAN~1\\INSTAN~1\\IWCTRL.EXE"
"HPAIO_PrintFolderMgr"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\hpoopm07.exe"
"Gene USB Monitor"="C:\\WINDOWS\\system32\\USBMonit.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TangoManager"="C:\\PROGRA~1\\FRONTI~1\\FRONTI~1\\app\\TANGOM~1.EXE"
"iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SSC_UserPrompt"="\"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe\""
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"SDFix"="C:\\DOCUME~1\\ADMINI~1\\DESKTOP\\SDFIX\\SDFIX\\RUNTHIS.BAT /second"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000003
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,80,00,00,00,00,00,00,00,00,02,00,00,c4,01,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f0,01,00,00,b5,00,00,00,80,00,00,00,76,00,\
00,00,01,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="C:\\DELL\\channel\\DESKTOP\\Index.htm"
"SubscribedURL"="C:\\DELL\\channel\\DESKTOP\\Index.htm"
"FriendlyName"=""
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,aa,01,00,00,9b,00,00,00,a6,00,00,00,3d,01,00,00,ea,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,aa,01,00,00,9b,00,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,01,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,aa,01,00,00,9b,00,00,00,a6,00,00,00,3d,01,\
00,00,01,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
"Source"="131A6951-7F78-11D0-A979-00C04FD705A2"
"SubscribedURL"="131A6951-7F78-11D0-A979-00C04FD705A2"
"FriendlyName"="Internet Explorer Channel Bar"
"Flags"=dword:00000003
"Position"=hex:2c,00,00,00,50,01,00,00,1f,00,00,00,80,00,00,00,76,00,00,00,ec,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,00,03,00,00,13,00,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,01,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,00,03,00,00,13,00,00,00,54,00,00,00,aa,01,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"="C:\\Program Files\\Internet Explorer\\Connection Wizard\\icwconn1.exe /desktop"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000095
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000095
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"Network.ConnectionTray"="{7007ACCF-3202-11D1-AAD2-00805FC1270E}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nwprovau
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20061219-212152-963
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
backup-20061219-212152-718
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
backup-20061219-212152-764
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\System32\nzdd0.dll
backup-20061219-212152-392
O4 - HKLM\..\Run: [rock] rock.exe
backup-20061219-212152-675
O4 - HKLM\..\Run: [WinSysModule] dsrss.exe
backup-20061219-212152-497
O4 - HKLM\..\Run: [SDFix] C:\DOCUME~1\ADMINI~1\Desktop\SDFix\SDFix\RunThis.bat /second
backup-20061219-212152-801
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
http://searchbar.findthewebsiteyouneed.com/
backup-20061219-212152-757
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
backup-20061219-212152-436
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
backup-20061219-212152-128
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
backup-20061219-212152-678
O21 - SSODL: CDRecorder026 - {A3BC5E20-0235-1ABF-9CE1-00AA00512026} - C:\WINDOWS\system32\baagf32.dll (file missing)
backup-20061219-212152-139
O21 - SSODL: LIJKE - {07CE0A0D-AD64-A0A7-9BB6-58AA4D7D07D8} - C:\WINDOWS\system32\jhuiq.dll (file missing)
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Tune-up Application Start.job
C:\WINDOWS\tasks\Maintenance-Defragment programs.job
C:\WINDOWS\tasks\Maintenance-Disk cleanup.job
C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - pbroenen.job
Completion time: Fri 2006-12-22 18:22:45.51
C:\ComboFix.txt ... 06-12-22 18:22