Running from: C:\Documents and Settings\debbie\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\debbie\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\aswmklt.dll
C:\WINDOWS\bqxomdo.dll
C:\WINDOWS\dpvtporsot.dll
C:\WINDOWS\elfwgps.dll
C:\WINDOWS\fvqkfsp.exe
C:\WINDOWS\system32\SET87E.tmp
C:\WINDOWS\system32\SET87F.tmp
C:\WINDOWS\system32\SET880.tmp
C:\WINDOWS\system32\SET894.tmp
C:\WINDOWS\system32\SET895.tmp
C:\WINDOWS\system32\SET8A4.tmp
C:\WINDOWS\system32\SET8A5.tmp
C:\WINDOWS\system32\SET8A6.tmp
C:\WINDOWS\system32\SET8CE.tmp
C:\WINDOWS\system32\SET8D8.tmp
C:\WINDOWS\system32\SET8DD.tmp
C:\WINDOWS\system32\SET8E4.tmp
C:\WINDOWS\system32\SET944.tmp
C:\WINDOWS\system32\SET952.tmp
C:\WINDOWS\system32\SET953.tmp
C:\WINDOWS\system32\SET954.tmp
C:\WINDOWS\system32\SET96D.tmp
C:\WINDOWS\system32\SET978.tmp
C:\WINDOWS\system32\SET982.tmp
C:\WINDOWS\system32\SET983.tmp
C:\WINDOWS\system32\SET98A.tmp
C:\WINDOWS\system32\SET98B.tmp
C:\WINDOWS\system32\SET9B0.tmp
C:\WINDOWS\system32\SET9B7.tmp
C:\WINDOWS\system32\SET9CC.tmp
C:\WINDOWS\system32\tmp.reg
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\SET87E.tmp
C:\WINDOWS\system32\SET87F.tmp
C:\WINDOWS\system32\SET880.tmp
C:\WINDOWS\system32\SET894.tmp
C:\WINDOWS\system32\SET895.tmp
C:\WINDOWS\system32\SET8A4.tmp
C:\WINDOWS\system32\SET8A5.tmp
C:\WINDOWS\system32\SET8A6.tmp
C:\WINDOWS\system32\SET8CE.tmp
C:\WINDOWS\system32\SET8D8.tmp
C:\WINDOWS\system32\SET8DD.tmp
C:\WINDOWS\system32\SET8E4.tmp
C:\WINDOWS\system32\SET944.tmp
C:\WINDOWS\system32\SET952.tmp
C:\WINDOWS\system32\SET953.tmp
C:\WINDOWS\system32\SET954.tmp
C:\WINDOWS\system32\SET96D.tmp
C:\WINDOWS\system32\SET978.tmp
C:\WINDOWS\system32\SET982.tmp
C:\WINDOWS\system32\SET983.tmp
C:\WINDOWS\system32\SET98A.tmp
C:\WINDOWS\system32\SET98B.tmp
C:\WINDOWS\system32\SET9B0.tmp
C:\WINDOWS\system32\SET9B7.tmp
C:\WINDOWS\system32\SET9CC.tmp
C:\WINDOWS\system32\tmp.reg
.
((((((((((((((((((((((((( Files Created from 2007-12-25 to 2008-01-25 )))))))))))))))))))))))))))))))
.
2008-01-24 20:28 . 2008-01-24 20:28 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-24 20:14 . 2004-08-03 23:00 260,272 --a------ C:\cmldr
2008-01-24 20:14 . 2008-01-10 18:10 211 --a------ C:\Boot.bak
2008-01-24 19:40 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-24 17:49 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-01-24 17:48 . 2008-01-24 17:48 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-24 17:48 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\dcflhtaqdepg.sys
2008-01-24 17:28 . 2008-01-24 17:48 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-24 17:28 . 2008-01-24 17:28 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-24 17:28 . 2008-01-24 17:28 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-24 17:28 . 2008-01-24 17:28 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-24 17:12 . 2008-01-24 17:44 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-24 17:11 . 2008-01-24 17:11 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-24 16:19 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-23 17:11 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-01-20 15:23 . 2008-01-20 15:58 42 --a------ C:\WINDOWS\FFS20ChtReg.ini
2008-01-19 15:33 . 2008-01-19 15:33 <DIR> d--hs---- C:\found.000
2008-01-19 05:30 . 2008-01-19 05:30 <DIR> d-------- C:\Program Files\Webroot
2008-01-19 05:30 . 2008-01-19 05:49 <DIR> d-------- C:\Program Files\Common Files\Webroot Shared
2008-01-19 05:30 . 2007-11-26 14:50 196,424 --a------ C:\WINDOWS\Unwash6.exe
2008-01-17 17:40 . 2008-01-17 17:44 <DIR> d-------- C:\Program Files\Windows Live
2008-01-17 15:39 . 2004-08-03 23:08 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2008-01-17 15:39 . 2008-01-17 15:39 4,128 --a------ C:\INFCACHE.1
2008-01-15 07:17 . 2008-01-15 07:17 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-14 22:19 . 2008-01-14 22:19 <DIR> d-------- C:\WINDOWS\Sun
2008-01-14 10:08 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-01-14 10:08 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-01-14 10:08 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-01-13 17:42 . 2008-01-13 17:42 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-01-13 17:30 . 2008-01-13 17:38 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-12 03:05 . 2006-08-21 04:14 128,896 --------- C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-01-12 03:05 . 2006-08-21 04:14 23,040 --------- C:\WINDOWS\system32\dllcache\fltmc.exe
2008-01-12 03:05 . 2006-08-21 07:21 16,896 --------- C:\WINDOWS\system32\dllcache\fltlib.dll
2008-01-11 23:48 . 2008-01-11 23:48 <DIR> d-------- C:\Program Files\Alwil Software
2008-01-11 23:09 . 2006-08-21 04:14 128,896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys
2008-01-11 23:02 . 2008-01-11 23:02 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-01-11 23:01 . 2005-07-25 23:39 37,888 --a------ C:\WINDOWS\system32\olecnv32.dll
2008-01-11 22:59 . 2007-02-28 04:55 2,182,144 --a------ C:\WINDOWS\system32\ntoskrnl.exe
2008-01-11 22:59 . 2007-02-28 04:15 2,059,392 --a------ C:\WINDOWS\system32\ntkrnlpa.exe
2008-01-11 21:14 . 2008-01-11 21:14 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-01-11 21:12 . 2008-01-21 04:54 <DIR> d-------- C:\Program Files\Dell Games
2008-01-11 03:20 . 2008-01-19 23:51 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-01-11 03:10 . 2007-07-09 08:09 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-01-11 03:05 . 2006-12-07 00:29 2,374,472 --a------ C:\WINDOWS\system32\SET8D2.tmp
2008-01-11 03:00 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-01-10 22:04 . 2008-01-20 05:41 <DIR> d-------- C:\Program Files\Yahoo!
2008-01-10 18:56 . 2004-08-03 23:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-01-10 18:56 . 2001-08-17 14:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-01-10 18:56 . 2001-08-17 15:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-01-10 18:56 . 2008-01-10 18:56 8,192 --a------ C:\WINDOWS\REGLOCS.OLD
2008-01-10 18:20 . 2008-01-10 18:22 10,740 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-10 18:20 . 2008-01-10 18:22 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-10 18:16 . 2008-01-24 17:45 <DIR> d-------- C:\Program Files\DellSupport
2008-01-10 18:16 . 2005-04-05 20:18 135,168 --a------ C:\WINDOWS\system32\igfxres.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-25 00:51 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-25 00:26 --------- d-----w C:\Program Files\Java
2008-01-24 22:44 --------- d-----w C:\Program Files\GoogleAFE
2008-01-24 22:44 --------- d-----w C:\Program Files\Google
2008-01-21 22:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-11 03:57 --------- d-----w C:\Program Files\Norton Internet Security
2008-01-10 23:22 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-10 23:22 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-10 23:22 --------- d-----w C:\Program Files\Symantec
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-30 09:55 3,065,856 ----a-w C:\WINDOWS\system32\SET8EE.tmp
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\SET9AE.tmp
.
((((((((((((((((((((((((((((( snapshot@2008-01-24_19.53.06.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-25 00:41:01 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-25 02:04:22 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-25 00:41:01 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-25 02:04:22 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-25 00:41:01 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-25 02:04:22 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-25 00:41:02 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-25 02:04:22 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-25 00:41:02 1,445,888 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-25 02:04:22 1,449,984 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-25 00:41:02 151,552 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-25 02:04:22 151,552 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-24 14:01:35 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-01-25 01:28:23 1,445,888 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-01-25 01:28:23 151,552 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-01-24 14:01:35 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-01-25 01:28:22 1,445,888 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-01-25 01:28:22 151,552 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-01-10 18:12 171448]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"ares"="C:\Program Files\Ares\Ares.exe" [ ]
"Window Washer"="C:\Program Files\Webroot\Washer\wwDisp.exe" [2007-11-26 14:50 1222984]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 20:42 1404928]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-04-05 20:22 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-05 20:19 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-05 20:23 114688]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 04:12 94208]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 21:12 221184]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 20:20 8192]
"MMTray"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe" [2005-09-08 20:20 110592]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-11-17 11:33 52848]
"URLLSTCK.exe"="C:\Program Files\Norton Internet Security\UrlLstCk.exe" [2007-01-16 11:26 23168]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-02-25 02:01 169472]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 12:06 106496]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
R2 wwEngineSvc;Window Washer Engine;C:\Program Files\Webroot\Washer\WasherSvc.exe [2007-11-26 14:50]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-19 01:00:28 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - jason.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-24 21:14:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-24 21:17:08
ComboFix-quarantined-files.txt 2008-01-25 02:16:51
ComboFix2.txt 2008-01-25 00:54:27
.
2008-01-15 12:17:56 --- E O F ---