ComboFix 08-01-16.4 - Jordan 2002-01-02 7:01:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.90 [GMT -6:00]
Running from: C:\Documents and Settings\Jordan\Local Settings\Temporary Internet Files\Content.IE5\52RJ78GH\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\000070.exe
C:\WINDOWS\system32\000080.exe
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-12-16 to 2008-01-16 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-16 05:08 6,514 --sha-w C:\WINDOWS\system32\gjllm.ini2
2008-01-16 05:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2008-01-16 05:04 755,712 ----a-w C:\WINDOWS\system32\PSDrvCheck.exe
2008-01-16 05:04 339,968 ----a-w C:\WINDOWS\system32\mlljg.exe
2008-01-16 05:03 406,016 ----a-w C:\WINDOWS\system32\PSDrvCheck .exe
2008-01-16 05:03 --------- d-----w C:\Program Files\Zune
2008-01-16 05:03 --------- d-----w C:\Program Files\QuickTime
2008-01-16 05:03 --------- d-----w C:\Program Files\CursorXP
2007-11-30 14:21 --------- d-----w C:\Program Files\Windows Installer Clean Up
2007-11-30 14:20 --------- d-----w C:\Program Files\MSECACHE
2003-09-17 19:10 42 ----a-w C:\Program Files\readme.txt
2003-09-17 18:14 27,217,213 ----a-w C:\Program Files\fwmx_2004_en.exe
2003-09-17 16:35 65,924,243 ----a-w C:\Program Files\dwmx2004_trial_en_win.exe
2002-07-26 23:02 153,088 ----a-w C:\Program Files\UNWISE.EXE
2006-08-30 00:07 1,056 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
<pre> ----a-w 2,664,448 2008-01-16 05:03:13 C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\1163D2B46CC742E5A3CC9E4157887751\TalkAndWrite .exe ----a-w 185,896 2008-01-16 05:03:00 C:\Program Files\Common Files\Real\Update_OB\realsched .exe ----a-w 128,000 2008-01-16 05:03:19 C:\Program Files\CursorXP\CursorXP .exe ----a-w 68,856 2008-01-16 05:03:19 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe ----a-w 6,731,312 2008-01-16 05:03:42 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe ----a-w 7,477,760 2002-01-02 06:01:40 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe ----a-w 6,731,312 2002-01-02 12:21:21 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe ----a-w 579,072 2008-01-16 05:03:03 C:\Program Files\Grisoft\AVG7\avgcc .exe ----a-w 49,152 2008-01-16 05:02:58 C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe ----a-w 132,496 2008-01-16 05:02:58 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe ----a-w 67,128 2008-01-16 05:03:19 C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe ----a-w 53,248 2008-01-16 05:02:58 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask .exe ----a-w 196,608 2008-01-16 05:03:07 C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip .exe ----a-w 448,512 2008-01-16 05:03:40 C:\Program Files\QuickTime\qttask .exe ----a-w 448,512 2002-01-02 06:01:29 C:\Program Files\QuickTime\qttask .exe ----a-w 448,512 2002-01-02 14:46:07 C:\Program Files\QuickTime\qttask .exe ----a-w 448,512 2002-01-02 06:04:20 C:\Program Files\QuickTime\qttask .exe ----a-w 24,104 2008-01-16 05:02:59 C:\Program Files\Zune\ZuneLauncher .exe ----a-w 406,016 2008-01-16 05:03:02 C:\WINDOWS\system32\PSDrvCheck .exe </pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A851C5D7-4318-44C4-AB17-E6A997C27216}]
2002-01-02 05:02 336384 --a------ C:\WINDOWS\system32\mlljg.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="" []
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2008-01-16 07:02 434688]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2002-01-02 00:01 436736]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"CursorXP"="C:\Program Files\CursorXP\CursorXP.exe" [2002-01-02 00:01 516608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2002-01-02 00:01 476672]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2008-01-15 23:03 448512]
"nwiz"="nwiz.exe" [2002-12-27 01:48 315392 C:\WINDOWS\system32\nwiz.exe]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2002-12-27 01:48 4263936]
"nForce Tray Options"="sstray.exe" [2002-01-03 05:04 73728 C:\WINDOWS\system32\sstray.exe]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2002-01-02 00:01 394240]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2002-01-02 00:01 391168]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2002-01-02 00:01 526848]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2008-01-15 23:03 365056]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2002-01-02 00:01 1116672]
"TalkAndWrite"="C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\1163D2B46CC742E5A3CC9E4157887751\TalkAndWrite.exe" [2002-01-02 00:01 3009024]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2008-01-15 23:04 755712]
"USB2Check"="C:\WINDOWS\system32\PCLECoInst.dll" [2004-09-21 02:22 73728]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2002-01-02 00:01 569856]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" [2002-01-02 00:01 7477760]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 16:18 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-03-31 12:48:44]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-08-02 11:59:41]
restore.bat [2007-06-28 17:09:29]
Smart Wizard Wireless Settings.lnk - C:\Program Files\NETGEAR\WG121 Configuration Utility\wlancfg8.exe [2005-07-19 20:17:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvsrq]
vtuvsrq.dll
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\mlljg.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\mlljg
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!ewido]
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ewido anti-spyware 4.0 guard"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"Symantec AntiVirus"=2 (0x2)
"SNDSrvc"=3 (0x3)
"DefWatch"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"MSIServer"=3 (0x3)
R0 BsStor;InCD Storage Helper Driver;C:\WINDOWS\system32\DRIVERS\bsstor.sys [2002-06-05 17:07]
R3 ehcifltr;NVIDIA EHCI Debugging Filter;C:\WINDOWS\system32\DRIVERS\usbfltr.sys [2002-09-18 05:48]
R3 wg121;NETGEAR WG121 802.11g Wireless USB2.0 Adapter;C:\WINDOWS\system32\DRIVERS\wg121nd5.sys [2003-11-28 09:18]
S2 NETAPI;Microsoft Net API;"C:\WINDOWS\system32\msapi.exe" []
S3 LUsbKbd;Logitech SetPoint USB Filter Driver;C:\WINDOWS\system32\drivers\LUsbKbd.sys [2005-03-10 12:08]
S4 BsUDF;InCD UDF Driver;C:\WINDOWS\system32\drivers\BsUDF.sys [2003-01-27 13:47]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-15 23:09:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\WINDOWS\system32\mlljg.dll
.
Completion time: 2008-01-15 23:13:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-16 05:13:37
.