comboofix log
ComboFix 08-01-29.3 - AndrewM 2008-01-29 15:11:40.3 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.252 [GMT -5:00]
Running from: C:\Documents and Settings\AndrewM\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WIN_XP\system32\ddayw.dll
C:\WIN_XP\system32\xxyyvwx.dll
C:\Autorun.inf
C:\WIN_XP\system32\ddayw.dll
C:\WIN_XP\system32\efccccb.dll
C:\WIN_XP\system32\wvuvvvs.dll
C:\WIN_XP\system32\wyadd.ini
C:\WIN_XP\system32\wyadd.ini2
C:\WIN_XP\system32\xxyyvwx.dll
.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))
.
2008-01-28 13:47 . 2008-01-28 13:47 <DIR> d-------- C:\Documents and Settings\AndrewM\.SunDownloadManager
2008-01-28 13:25 . 2008-01-28 13:25 <DIR> d-------- C:\Program Files\Tall Emu
2008-01-28 13:25 . 2008-01-28 13:25 <DIR> d-------- C:\OnlineArmor
2008-01-28 13:25 . 2008-01-28 13:25 <DIR> d-------- C:\Documents and Settings\AndrewM\Application Data\OnlineArmor
2008-01-28 13:25 . 2008-01-28 13:25 <DIR> d-------- C:\Documents and Settings\All Users.WIN_XP\Application Data\OnlineArmor
2008-01-28 13:25 . 2007-11-08 06:37 68,608 --a------ C:\WIN_XP\system32\drivers\OADriver.sys
2008-01-28 13:25 . 2007-09-29 00:06 25,600 --a------ C:\WIN_XP\system32\drivers\OAmon.sys
2008-01-28 13:25 . 2007-09-29 00:06 18,944 --a------ C:\WIN_XP\system32\drivers\ndisrd.sys
2008-01-26 21:04 . 2008-01-26 21:04 <DIR> d-------- C:\Program Files\IrfanView
2008-01-26 14:13 . 2008-01-26 14:13 <DIR> d-------- C:\WIN_XP\system32\Kaspersky Lab
2008-01-26 14:13 . 2008-01-26 14:13 <DIR> d-------- C:\Documents and Settings\All Users.WIN_XP\Application Data\Kaspersky Lab
2008-01-25 12:49 . 2008-01-25 12:49 <DIR> d-------- C:\Program Files\Alwil Software
2008-01-25 12:49 . 2007-12-04 08:04 837,496 --a------ C:\WIN_XP\system32\aswBoot.exe
2008-01-25 12:49 . 2004-01-09 04:13 380,928 --a------ C:\WIN_XP\system32\actskin4.ocx
2008-01-25 12:49 . 2007-12-04 07:54 95,608 --a------ C:\WIN_XP\system32\AvastSS.scr
2008-01-25 12:49 . 2007-12-04 09:55 94,544 --a------ C:\WIN_XP\system32\drivers\aswmon2.sys
2008-01-25 12:49 . 2007-12-04 09:56 93,264 --a------ C:\WIN_XP\system32\drivers\aswmon.sys
2008-01-25 12:49 . 2007-12-04 09:51 42,912 --a------ C:\WIN_XP\system32\drivers\aswTdi.sys
2008-01-25 12:49 . 2007-12-04 09:49 26,624 --a------ C:\WIN_XP\system32\drivers\aavmker4.sys
2008-01-25 12:49 . 2007-12-04 09:53 23,152 --a------ C:\WIN_XP\system32\drivers\aswRdr.sys
2008-01-25 12:28 . 2008-01-25 12:28 <DIR> d-------- C:\Documents and Settings\All Users.WIN_XP\Application Data\Avira
2008-01-19 10:12 . 2008-01-19 10:12 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-16 18:53 . 2008-01-22 21:00 543 --a------ C:\WIN_XP\wininit.ini
2008-01-12 22:36 . 2008-01-12 22:36 <DIR> d-------- C:\SW_BtlFrnt
2008-01-12 22:35 . 2008-01-12 22:35 <DIR> d-------- C:\Program Files\Google
2008-01-12 22:35 . 2008-01-12 22:35 <DIR> d-------- C:\Documents and Settings\Temporary\.limewire
2008-01-01 19:41 . 2008-01-01 19:41 <DIR> d--hs---- C:\FOUND.001
2008-01-01 19:07 . 2008-01-01 19:07 <DIR> d-------- C:\Documents and Settings\All Users.WIN_XP\Application Data\TEMP
2008-01-01 19:07 . 2008-01-01 19:07 1,228,800 --a------ C:\WIN_XP\WoW Glider Cracked.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-16 19:58 --------- d-----w C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\avg7
2007-12-16 19:58 --------- d-----w C:\Documents and Settings\AndrewM\Application Data\avg7
2007-12-16 19:58 --------- d-----w C:\Documents and Settings\All Users.WIN_XP\Application Data\Grisoft
2007-12-16 19:58 --------- d-----w C:\Documents and Settings\All Users.WIN_XP\Application Data\Avg7
2007-12-16 19:57 --------- d-----w C:\Program Files\Bonjour
2007-12-16 19:56 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-12-13 04:43 428 ----a-w C:\Documents and Settings\AndrewM\Application Data\wklnhst.dat
2007-12-10 21:52 --------- d-----w C:\Documents and Settings\AndrewM\Application Data\SystemRequirementsLab
2007-12-07 18:19 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2007-06-10 20:07 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2007-10-20 15:21 1,682 --sha-w C:\WIN_XP\system32\KGyGaAvL.sys
2007-05-22 03:10 56 --sh--r C:\WIN_XP\system32\C28E09FCD9.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 15:06 1135968 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 15:06 1135968]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WIN_XP\system32\NvCpl.dll" [2007-10-04 17:14 8491008]
"nwiz"="nwiz.exe" [2007-10-04 17:14 1626112 C:\WIN_XP\system32\nwiz.exe]
"NvMediaCenter"="C:\WIN_XP\system32\NvMcTray.dll" [2007-10-04 17:14 81920]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"OnlineArmor GUI"="C:\Program Files\Tall Emu\Online Armor\oaui.exe" [2007-11-16 07:51 5029952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WIN_XP\system32\CTFMON.EXE" [2004-08-03 23:56 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-07-27 02:00 145920]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= C:\PROGRA~1\TALLEM~1\ONLINE~1\oaevent.dll [2007-11-16 07:50 633344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WIN_XP^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users.WIN_XP\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WIN_XP\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WIN_XP^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users.WIN_XP\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WIN_XP\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WIN_XP^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users.WIN_XP\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WIN_XP\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^AndrewM^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\AndrewM\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WIN_XP\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^AndrewM^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\AndrewM\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=C:\WIN_XP\pss\PowerReg Scheduler V3.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
--a------ 2007-07-27 02:00 416256 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-03 23:56 15360 C:\WIN_XP\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2007-08-16 07:24 167368 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE]
--a------ 2007-04-22 19:53 360448 C:\Program Files\Micro Innovations\Optical Navigator Mouse\mouse32a.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Location Finder]
--a------ 2005-08-24 18:25 101080 C:\Program Files\Microsoft Location Finder\LocationFinder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-10-04 17:14 8491008 C:\WIN_XP\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-10-04 17:14 81920 C:\WIN_XP\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-10-04 17:14 1626112 C:\WIN_XP\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
--a------ 2007-10-22 19:47 360448 C:\Program Files\Winamp Remote\bin\OrbTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 06:24 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-06-14 18:32 132760 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-09-27 16:05 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VortexTray]
--a------ 2000-08-09 08:59 241664 C:\WIN_XP\au30setp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2007-10-10 00:28 36352 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"GoogleDesktopManager-093007-112848"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
R1 NDISRD;NDISRD;C:\WIN_XP\system32\drivers\NDISRD.sys [2007-09-29 00:06]
R1 OADevice;OADriver;C:\WIN_XP\system32\drivers\OADriver.sys [2007-11-08 06:37]
R1 OAmon;OAmon;C:\WIN_XP\system32\drivers\OAmon.sys [2007-09-29 00:06]
R2 SvcOnlineArmor;Online Armor;"C:\Program Files\Tall Emu\Online Armor\oasrv.exe" [2007-11-16 07:51]
R3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);C:\WIN_XP\system32\drivers\adm8830.sys [2001-08-17 12:19]
.
Contents of the 'Scheduled Tasks' folder
"2007-10-24 01:46:18 C:\WIN_XP\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-29 15:52:07
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WIN_XP\system32\netdde.exe
C:\WIN_XP\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WIN_XP\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
.
**************************************************************************
.
Completion time: 2008-01-29 15:55:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-29 20:55:26