ComboFix 08-01-10.2 - Owner 2008-01-10 11:20:00.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.155 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Owner\Application Data\newsoftware2007install[1].exe
C:\Documents and Settings\Owner\Application Data\ShoppingReport
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Owner\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Documents and Settings\Owner\Application Data\SpamBlocker
C:\Documents and Settings\Owner\Application Data\SpamBlocker\{D494327C-2F41-4304-AA14-E3DDEE71148E}.dat
C:\Documents and Settings\Owner\Application Data\SpamBlockerUtility_Icons
C:\Documents and Settings\Owner\Application Data\SpamBlockerUtility_Icons\MobileSidewalk_2.ico
C:\Documents and Settings\Owner\Application Data\SpamBlockerUtility_Icons\Software_Online_8.ico
C:\Documents and Settings\Owner\Application Data\SpamBlockerUtility_Icons\wallpapere1.ico
C:\Documents and Settings\Owner\ResErrors.log
C:\Program Files\install provider
C:\Program Files\install provider\data.ini
C:\Program Files\install provider\InstallProvider.dlldat
C:\Program Files\install provider\My Downloads.ico
C:\Program Files\install provider\Toolbar.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ajgccqdj.ini
C:\WINDOWS\system32\almbcbyu.dll
C:\WINDOWS\system32\aoodidvo.ini
C:\WINDOWS\system32\awfvqnsj.ini
C:\WINDOWS\system32\ayoegueo.ini
C:\WINDOWS\system32\brxyprml.dll
C:\WINDOWS\system32\cavsbsub.dll
C:\WINDOWS\system32\cieyxbku.ini
C:\WINDOWS\system32\cipxyxva.ini
C:\WINDOWS\system32\cmogsfju.dll
C:\WINDOWS\system32\cprqcmdd.dll
C:\WINDOWS\system32\curswqip.ini
C:\WINDOWS\system32\dadqwiut.dll
C:\WINDOWS\system32\dgseowqw.ini
C:\WINDOWS\system32\drivers\ikuracjg.dat
C:\WINDOWS\system32\dxmas.dll
C:\WINDOWS\system32\ehnvottg.ini
C:\WINDOWS\system32\ekgokqqf.dll
C:\WINDOWS\system32\eqrlyiei.dll
C:\WINDOWS\system32\etgqjxei.dll
C:\WINDOWS\system32\euuwfbwo.dll
C:\WINDOWS\system32\fqaojogn.ini
C:\WINDOWS\system32\fweoqlsv.ini
C:\WINDOWS\system32\gdxpeheb.ini
C:\WINDOWS\system32\ghbycydp.ini
C:\WINDOWS\system32\gmtshsjl.dll
C:\WINDOWS\system32\hhmnxlik.ini
C:\WINDOWS\system32\hkuswkmw.ini
C:\WINDOWS\system32\htsiwjvu.ini
C:\WINDOWS\system32\ijaaucrw.dll
C:\WINDOWS\system32\jhfxyvxf.dll
C:\WINDOWS\system32\jxscarsy.ini
C:\WINDOWS\system32\ksandosg.ini
C:\WINDOWS\system32\ksdvxayo.ini
C:\WINDOWS\system32\kvqbusuj.ini
C:\WINDOWS\system32\llxrytom.ini
C:\WINDOWS\system32\lpeljqev.ini
C:\WINDOWS\system32\mbnpuinl.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\medrrkfw.ini
C:\WINDOWS\system32\mghpryee.ini
C:\WINDOWS\system32\motyrxll.dll
C:\WINDOWS\system32\mqrbnchy.dll
C:\WINDOWS\system32\ngbuwpgb.dll
C:\WINDOWS\system32\nnlyigik.ini
C:\WINDOWS\system32\npfetfym.ini
C:\WINDOWS\system32\obwkwgod.dll
C:\WINDOWS\system32\odsgrexi.dll
C:\WINDOWS\system32\oomqwnmx.ini
C:\WINDOWS\system32\otyylshl.dll
C:\WINDOWS\system32\pknmwnut.ini
C:\WINDOWS\system32\prfbwink.ini
C:\WINDOWS\system32\pynvswqn.dll
C:\WINDOWS\system32\qgptefcg.dll
C:\WINDOWS\system32\rivkjvcb.ini
C:\WINDOWS\system32\runmoscv.dll
C:\WINDOWS\system32\rxnovagd.ini
C:\WINDOWS\system32\tbkqsrbn.dll
C:\WINDOWS\system32\tmhqqyvf.dll
C:\WINDOWS\system32\twixpdas.dll
C:\WINDOWS\system32\tybejycc.ini
C:\WINDOWS\system32\ubticsjk.ini
C:\WINDOWS\system32\ufttoydm.dll
C:\WINDOWS\system32\uhwxkqvq.ini
C:\WINDOWS\system32\uxfvuwnr.ini
C:\WINDOWS\system32\uxpulbdb.ini
C:\WINDOWS\system32\vfcfskdn.ini
C:\WINDOWS\system32\vfcgqefu.ini
C:\WINDOWS\system32\vugksvld.ini
C:\WINDOWS\system32\wbwpygtl.ini
C:\WINDOWS\system32\xbadd.bak1
C:\WINDOWS\system32\xbadd.bak2
C:\WINDOWS\system32\xbadd.ini
C:\WINDOWS\system32\xbiqvdes.dll
C:\WINDOWS\system32\xxqttafd.dll
C:\WINDOWS\system32\yssmnfet.ini
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DUEAVLEL
-------\dueavlel
((((((((((((((((((((((((( Files Created from 2007-12-10 to 2008-01-10 )))))))))))))))))))))))))))))))
.
2008-01-10 11:17 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-07 12:15 . 2008-01-07 12:15 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-07 12:15 . 2008-01-07 12:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-05 14:07 . 2004-08-04 00:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-01-05 14:07 . 2004-08-04 00:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-01-05 14:07 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-01-05 14:07 . 2001-08-17 14:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2007-12-29 16:14 . 2007-12-29 16:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-29 15:59 . 2007-12-29 16:00 242 --a------ C:\WINDOWS\wininit.ini
2007-12-29 15:30 . 2007-12-29 15:30 <DIR> d-------- C:\Program Files\Alwil Software
2007-12-29 15:30 . 2007-12-29 15:30 18,644,496 --a------ C:\setupeng.exe
2007-12-29 15:30 . 2007-12-04 08:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-12-29 15:30 . 2004-01-09 04:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2007-12-29 15:30 . 2007-12-04 07:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-12-29 15:30 . 2007-12-04 09:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-29 15:30 . 2007-12-04 09:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-29 15:30 . 2007-12-04 09:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-29 15:30 . 2007-12-04 09:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-29 15:30 . 2007-12-04 09:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-29 15:19 . 2007-12-29 15:19 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-29 15:10 . 2004-01-20 22:48 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-12-29 15:10 . 2004-01-21 04:48 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-12-29 15:10 . 2004-01-20 22:21 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2007-12-29 15:10 . 2004-01-20 23:29 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2007-12-29 15:10 . 2004-01-21 04:52 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\interMute
2007-12-29 14:53 . 2007-12-29 14:53 127 --a------ C:\WINDOWS\system32\MRT.INI
2007-12-14 08:46 . 2007-12-14 08:46 <DIR> d-------- C:\Documents and Settings\Owner\Documents and Settings
2007-12-14 08:46 . 2007-12-14 08:46 <DIR> d-------- C:\cs
2007-12-13 16:08 . 2007-12-13 16:08 <DIR> dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 22:38 --------- d-----w C:\Documents and Settings\Owner\Application Data\AdobeUM
2007-12-29 20:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-29 20:46 --------- d-----w C:\Program Files\Easy Internet signup
2007-12-29 19:57 3,887 ----a-w C:\WINDOWS\viassary-hp.reg
2007-12-29 19:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-29 19:43 --------- d-----w C:\Documents and Settings\Owner\Application Data\interMute
2007-12-29 19:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-29 19:32 --------- d-----w C:\Program Files\Norton AntiVirus
2007-12-02 14:31 --------- d-----w C:\Documents and Settings\Owner\Application Data\IPSearchToolbarCorp
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A9344DE7-59F2-40F8-9AE7-C203B67444DA}"= C:\Program Files\Install Provider\InstallProvider.dll [ ]
[HKEY_CLASSES_ROOT\clsid\{a9344de7-59f2-40f8-9ae7-c203b67444da}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Organize.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Organize.lnk
backup=C:\WINDOWS\pss\Organize.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\44a77496]
C:\WINDOWS\system32\motyrxll.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-06 22:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
--a------ 2004-06-29 09:06 88363 C:\WINDOWS\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
--a------ 2007-12-04 08:00 79224 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupNotify]
--a------ 2004-01-09 04:34 32768 c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 02:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
--a------ 2003-08-21 06:15 483328 C:\WINDOWS\System32\hphmon05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
--a------ 2003-08-21 06:23 49152 c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a------ 1998-05-07 19:04 52736 c:\windows\system\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
--a------ 2003-02-11 22:02 61440 C:\HP\KBD\KBD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a------ 2003-12-11 04:40 53248 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2003-02-19 23:49 2185800 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
C:\WINDOWS\system32\ps2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ptask]
C:\Program Files\BestsellerAntivirus\ptask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a------ 2003-11-03 19:50 221184 C:\WINDOWS\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecordNow!]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 03:00 132496 c:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sunkist2k]
--a------ 2003-10-29 10:17 135168 C:\Program Files\Multimedia Card Reader\shwicon2k.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-08-24 14:55 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2004-01-20 22:22 151597 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2003-08-19 11:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
--a------ 2004-10-22 11:53 53248 C:\WINDOWS\system32\VTTimer.exe
*Newly Created Service* - HTTPFILTER
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-10 12:47:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-10 12:49:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-10 17:49:12
.
2008-01-10 08:16:46 --- E O F ---