ComboFix 08-01-18.4 - tophman 2008-01-18 17:16:30.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1167 [GMT 0:00]
Running from: C:\Documents and Settings\tophman\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\tophman\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\Documents and Settings\Carin\x.dat
C:\Documents and Settings\Carin\z.dat
C:\Documents and Settings\tophman\x.dat
C:\Documents and Settings\tophman\z.dat
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\system32\afxaegkd.ini
C:\WINDOWS\system32\brdfvsss.ini
C:\WINDOWS\system32\bryvnhyx.ini
C:\WINDOWS\system32\ddcabba.dll
C:\WINDOWS\system32\domfcmim.ini
C:\WINDOWS\system32\exnlwpat.ini
C:\WINDOWS\system32\gdvfxwmg.ini
C:\WINDOWS\system32\gunomwvg.ini
C:\WINDOWS\system32\iaynygvd.ini
C:\WINDOWS\system32\ikvdvjmr.ini
C:\WINDOWS\system32\ivogskfe.dll
C:\WINDOWS\system32\mqpagrsi.ini
C:\WINDOWS\system32\plncakwk.ini
C:\WINDOWS\system32\ptjgrarx.ini
C:\WINDOWS\system32\qeawfrdl.ini
C:\WINDOWS\system32\riglxouk.ini
C:\WINDOWS\system32\rqqugeub.ini
C:\WINDOWS\system32\utrnqsfu.ini
C:\WINDOWS\system32\ydrqhjbn.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Carin\x.dat
C:\Documents and Settings\Carin\z.dat
C:\Documents and Settings\tophman\x.dat
C:\Documents and Settings\tophman\z.dat
C:\WINDOWS\system32\afxaegkd.ini
C:\WINDOWS\system32\brdfvsss.ini
C:\WINDOWS\system32\bryvnhyx.ini
C:\WINDOWS\system32\domfcmim.ini
C:\WINDOWS\system32\exnlwpat.ini
C:\WINDOWS\system32\gdvfxwmg.ini
C:\WINDOWS\system32\gunomwvg.ini
C:\WINDOWS\system32\iaynygvd.ini
C:\WINDOWS\system32\ikvdvjmr.ini
C:\WINDOWS\system32\ivogskfe.dll
C:\WINDOWS\system32\mqpagrsi.ini
C:\WINDOWS\system32\plncakwk.ini
C:\WINDOWS\system32\ptjgrarx.ini
C:\WINDOWS\system32\qeawfrdl.ini
C:\WINDOWS\system32\riglxouk.ini
C:\WINDOWS\system32\rqqugeub.ini
C:\WINDOWS\system32\utrnqsfu.ini
C:\WINDOWS\system32\ydrqhjbn.ini
.
((((((((((((((((((((((((( Files Created from 2007-12-18 to 2008-01-18 )))))))))))))))))))))))))))))))
.
2008-01-06 15:51 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-12-26 10:30 . 2007-12-26 10:31 <DIR> d-------- C:\Documents and Settings\Carin\Application Data\AVG7
2007-12-22 16:55 . 2008-01-18 16:45 <DIR> d-------- C:\Documents and Settings\tophman\Application Data\AVG7
2007-12-20 19:10 . 2007-12-20 19:10 <DIR> d--h----- C:\WINDOWS\PIF
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-18 09:23 --------- d-----w C:\Documents and Settings\lizzy\Application Data\AVG7
2008-01-17 18:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-03 02:58 --------- d-----w C:\Documents and Settings\lizzy\Application Data\Apple Computer
2007-12-20 19:11 --------- d-----w C:\Program Files\Windows Live Safety Center
2007-12-18 17:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-12-17 18:09 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-17 18:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 20:15 --------- d-----w C:\Program Files\Ares
2007-12-09 14:36 --------- d-----w C:\Program Files\LogMeIn
2007-12-08 20:06 --------- d-----w C:\Program Files\Java
2007-12-07 19:49 --------- d-----w C:\Program Files\Trend Micro
2007-12-07 15:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-05 18:48 --------- d-----w C:\Program Files\LimeWire
2007-12-04 16:46 --------- d-----w C:\Program Files\Microsoft Games
2007-12-03 16:58 --------- d-----w C:\Documents and Settings\tophman\Application Data\LimeWire
2007-11-29 19:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-29 12:59 --------- d-----w C:\Program Files\MSBuild
2007-11-29 12:56 --------- d-----w C:\Program Files\Reference Assemblies
2007-11-29 12:49 --------- d-----w C:\Program Files\MSXML 6.0
2007-11-29 12:48 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-11-29 12:30 --------- d-----w C:\Program Files\Google
2007-11-27 13:47 --------- d-----w C:\Program Files\Incomplete
2007-11-27 12:32 --------- d-----w C:\Documents and Settings\lizzy\Application Data\LimeWire
2007-11-27 08:54 --------- d-----w C:\Program Files\IrfanView
2007-11-20 14:34 --------- d-----w C:\Program Files\IGZones
2007-11-19 21:10 147,456 ----a-w C:\WINDOWS\system32\vbzip10.dll
2007-11-15 18:46 87,352 ----a-w C:\WINDOWS\system32\LMIinit.dll
2007-11-15 18:46 83,288 ----a-w C:\WINDOWS\system32\LMIRfsClientNP.dll
2007-11-15 18:46 23,736 ----a-w C:\WINDOWS\system32\lmimirr.dll
2007-11-15 18:46 21,496 ----a-w C:\WINDOWS\system32\LMIport.dll
2007-11-15 18:46 10,040 ----a-w C:\WINDOWS\system32\lmimirr2.dll
2007-11-12 11:45 155,995 ----a-w C:\WINDOWS\java\Packages\75RTBPJL.ZIP
2007-11-12 10:50 127,034 ------r C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-31 13:03 245,408 ----a-w C:\WINDOWS\system32\unicows.dll
2007-10-30 23:42 3,590,656 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 17:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 17:40 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-24 01:47 96,760 ----a-w C:\WINDOWS\system32\dfshim.dll
2007-10-24 01:47 84,480 ----a-w C:\WINDOWS\system32\mscories.dll
2007-10-24 01:47 282,112 ----a-w C:\WINDOWS\system32\mscoree.dll
2007-10-24 01:47 158,720 ----a-w C:\WINDOWS\system32\mscorier.dll
2007-10-18 11:31 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll
.
((((((((((((((((((((((((((((( snapshot@2007-12-17_17.18.50.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-10-30 16:53:32 360,832 ----a-w C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB941644\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB941644\update\updspapi.dll
+ 2007-11-07 09:50:47 727,040 ----a-w C:\WINDOWS\$hf_mig$\KB943485\SP2QFE\lsasrv.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB943485\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB943485\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB943485\update\updspapi.dll
+ 2000-08-31 08:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2008-01-18 17:16:02 1,376,256 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-18 17:16:02 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-18 17:16:02 1,376,256 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-18 17:16:02 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-18 17:16:03 4,644,864 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-18 17:16:03 151,552 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
- 2007-12-08 20:14:48 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-01-06 15:55:17 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-12-08 20:14:48 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-01-06 15:55:17 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-12-08 20:14:48 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-06 15:55:17 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-17 18:09:23 821,856 ----a-w C:\WINDOWS\system32\drivers\avg7core.sys
+ 2007-12-17 18:09:25 4,224 ----a-w C:\WINDOWS\system32\drivers\avg7rsw.sys
+ 2007-12-17 18:09:25 27,776 ----a-w C:\WINDOWS\system32\drivers\avg7rsxp.sys
+ 2007-12-20 19:06:04 10,760 ----a-w C:\WINDOWS\system32\drivers\avgclean.sys
+ 2007-12-20 19:05:50 26,952 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
- 2006-04-20 11:51:50 359,808 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2007-10-30 17:20:55 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2006-11-07 08:42:28 88,560 ----a-r C:\WINDOWS\system32\drivers\w200mgmt.sys
- 2007-12-02 23:00:05 18,684,536 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-01-02 18:21:36 17,642,616 ----a-w C:\WINDOWS\system32\MRT.exe
- 2007-12-13 21:26:50 156,160 ----a-w C:\WINDOWS\system32\swreg.exe
+ 2000-08-31 08:00:00 156,160 ----a-w C:\WINDOWS\system32\swreg.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-12 20:56 68856]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 19:41 16132608 C:\WINDOWS\RTHDCPL.EXE]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 16:41 45056]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 10:35 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 10:37 81920]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 10:22 221184]
"RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 08:00 1116920]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 16:23 118784]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-08-18 08:00 94208]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50 139320]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" [2003-10-07 09:48 147514]
"btbb_wcm_McciTrayApp"="C:\Program Files\btbb_wcm\McciTrayApp.exe" [2005-12-29 10:22 543232]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 16:19 129536]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-09-12 10:20 63048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-20 19:05 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 04:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-17 18:09 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
BT Broadband Desktop Help.lnk - C:\Program Files\BT Total Broadband 210\Help\bin\matcli.exe [2007-11-12 11:45:12]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-29 12:30:02]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-12 10:50:27]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-11-12 10:48:40]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-11-15 18:46 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Host Process]
C:\WINDOWS\Fonts\svchost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
--a------ 2006-02-06 18:52 462935 C:\PROGRA~1\BTTOTA~1\Help\SMARTB~1\BTHelpNotifier.exe
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 09:35]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2007-09-12 10:21]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-09-12 10:20]
S3 DM9USB;DM9601 USB To Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\dm9usb.sys [2002-03-21 09:14]
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-10-24 14:10]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 08:42]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 08:42]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 08:42]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 08:42]
.
Contents of the 'Scheduled Tasks' folder
"2007-12-24 19:42:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-18 09:25:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-18 17:18:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-18 17:19:05
ComboFix-quarantined-files.txt 2008-01-18 17:19:02
ComboFix2.txt 2008-01-06 15:57:57
ComboFix3.txt 2007-12-30 13:52:31
ComboFix4.txt 2007-12-22 17:03:59
ComboFix5.txt 2007-12-17 17:19:13
.
2008-01-10 02:04:37 --- E O F ---