combofix & HJT log
ComboFix 08-01-11.3 - CHEWIE 2008-01-12 14:27:11.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.151 [GMT -8:00]
Running from: C:\Documents and Settings\CHEWIE\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\CHEWIE\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\Documents and Settings\CHEWIE\f.exe
C:\n.bat
C:\WINDOWS\system32\hlrguyax.exe
C:\WINDOWS\system32\jqdexxlb.exe
C:\WINDOWS\system32\kahkexnu.ini
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\system32\vyxdapfw.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\CHEWIE\f.exe
C:\n.bat
C:\WINDOWS\system32\daSgo18
C:\WINDOWS\system32\daSgo18\daSgo182328.exe
C:\WINDOWS\system32\hlrguyax.exe
C:\WINDOWS\system32\jqdexxlb.exe
C:\WINDOWS\system32\kahkexnu.ini
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\system32\vyxdapfw.ini
.
((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))
.
2008-01-12 10:08 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-12-31 19:27 . 2007-12-31 19:27 <DIR> d-------- C:\Documents and Settings\CHEWIE\Application Data\Media Player Classic
2007-12-31 19:26 . 2007-12-31 19:26 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2007-12-31 19:26 . 2006-09-24 16:11 389,120 --a------ C:\WINDOWS\system32\lameACM.acm
2007-12-31 19:26 . 2004-01-25 17:18 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2007-12-31 19:26 . 2007-09-04 17:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2007-12-31 19:26 . 2007-09-21 01:52 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm
2007-12-31 19:26 . 2007-12-24 13:49 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-12-31 19:26 . 2007-07-10 17:10 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2007-12-31 19:26 . 2007-10-03 16:03 414 --a------ C:\WINDOWS\system32\lame_acm.xml
2007-12-26 12:13 . 2007-12-26 12:13 5,092,858 --a------ C:\WINDOWS\Metallica.exe
2007-12-26 12:13 . 2007-12-26 12:13 203,360 --a------ C:\WINDOWS\Metallica.scr
2007-12-26 12:13 . 2007-12-26 12:13 40,960 --a------ C:\WINDOWS\Metallica.dll
2007-12-26 12:13 . 2007-12-26 12:13 18,192 --a------ C:\WINDOWS\Metallica.dat
2007-12-26 10:04 . 2007-12-26 10:04 <DIR> d-------- C:\Documents and Settings\CHEWIE\Application Data\AdobeUM
2007-12-23 09:42 . 2007-12-23 09:42 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-15 11:46 . 2007-12-15 11:47 <DIR> d-------- C:\Program Files\The AD-Police
2007-12-14 18:59 . 2007-12-27 14:18 <DIR> d-------- C:\Documents and Settings\CHEWIE\Application Data\Apple Computer
2007-12-14 18:13 . 2007-12-14 18:13 <DIR> d-------- C:\Program Files\LimeWire
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-12 17:38 --------- d-----w C:\Documents and Settings\CHEWIE\Application Data\LimeWire
2008-01-12 02:37 --------- d-----w C:\Program Files\Common Files\Command Software
2008-01-11 20:37 --------- d-----w C:\Program Files\Common Files\PestPatrol
2007-12-16 20:14 --------- d-----w C:\Program Files\Tunafish
2007-12-15 02:57 --------- d-----w C:\Program Files\Apple Software Update
2007-12-15 01:59 --------- d-----w C:\Program Files\MSN Encarta Plus
2007-12-13 04:40 --------- d-----w C:\Program Files\The Weather Channel FW
2007-12-10 21:48 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2007-12-10 21:48 --------- d-----w C:\Program Files\Real
2007-12-10 21:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winferno
2007-12-05 02:10 --------- d-----w C:\Program Files\Common Files\xing shared
2007-12-05 02:10 --------- d-----w C:\Program Files\Common Files\Real
2007-11-22 21:39 --------- d-----w C:\Documents and Settings\CHEWIE\Application Data\DivX
2007-11-22 02:13 --------- d-----w C:\Program Files\Audacity
2007-11-22 01:56 --------- d-----w C:\Documents and Settings\CHEWIE\Application Data\CyberLink
2007-11-22 01:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2007-11-21 21:41 --------- d-----w C:\Documents and Settings\CHEWIE\Application Data\Motive
2007-11-21 21:04 --------- d-----w C:\Documents and Settings\CHEWIE\Application Data\TELUS
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 00:48 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-10-30 00:48 249,856 ------w C:\WINDOWS\Setup1.exe
.
((((((((((((((((((((((((((((( snapshot@2008-01-12_10.17.27.68 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-12 18:09:12 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-12 22:27:05 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-12 18:09:12 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-12 22:27:05 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-12 18:09:12 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-12 22:27:06 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-12 18:09:12 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-12 22:27:06 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-12 18:09:12 3,133,440 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-12 22:27:06 3,133,440 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-12 18:09:12 184,320 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-12 22:27:06 184,320 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 11:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-10 08:18 270648]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 14:46 28160 C:\WINDOWS\KHALMNPR.Exe]
"TELUS Security service"="C:\Program Files\TELUS\TELUS Security service\Freedom.exe" [2005-05-19 14:56 180278]
"Motive SmartBridge"="C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe" [2007-08-30 17:36 393216]
"TEPA.exe"="C:\Program Files\TELUS\eProtect Advisor\TEPA.exe" [2007-03-20 16:48 2061816]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-04 18:09 185632]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
TELUS eCare.lnk - C:\Program Files\TELUS eCare\bin\matcli.exe [2007-08-30 17:19:12]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Logitech Hardware Abstraction Layer"=KHALMNPR.EXE
"VTTimer"=VTTimer.exe
"SunKistEM"=C:\Program Files\Digital Media Reader\shwiconem.exe
"SoundMan"=SOUNDMAN.EXE
"Recguard"=%WINDIR%\SMINST\RECGUARD.EXE
.
Contents of the 'Scheduled Tasks' folder
"2008-01-07 19:30:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-07 17:01:20 C:\WINDOWS\Tasks\rpc.job"
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-12 14:31:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-12 14:35:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-12 22:35:26
ComboFix2.txt 2008-01-12 18:17:50
.
2008-01-09 03:24:25 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:38:33 PM, on 1/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TELUS\TELUS Security service\Freedom.exe
C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
C:\Program Files\TELUS\eProtect Advisor\TEPA.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TELUS eCare\bin\mpbtn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.emachines.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\TELUS\TELUS Security service\pkR.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\TELUS\TELUS Security service\FreeBHOR.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [TELUS Security service] "C:\Program Files\TELUS\TELUS Security service\Freedom.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [TEPA.exe] "C:\Program Files\TELUS\eProtect Advisor\TEPA.exe" /AUTORUN
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TELUS eCare.lnk = C:\Program Files\TELUS eCare\bin\matcli.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O24 - Desktop Component 1: (no name) -
http://www.humancalendar.com/
--
End of file - 5191 bytes