ComboFix 08-04-14.2 - John 2008-04-15 19:26:38.3 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.106 [GMT -4:00]
Running from: C:\Documents and Settings\John\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\John\Desktop\CFScript.txt
FILE ::
c:\windows\system32\drivers\nkv2.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\nkv2.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_USB2_04
((((((((((((((((((((((((( Files Created from 2008-03-15 to 2008-04-15 )))))))))))))))))))))))))))))))
.
2008-04-15 19:12 . 2007-08-14 08:12 5,760 --------- C:\WINDOWS\system32\29.tmp
2008-04-15 18:54 . 2007-08-14 08:12 5,760 --------- C:\WINDOWS\system32\27.tmp
2008-04-15 18:53 . 2008-04-15 18:53 <DIR> d-------- C:\Program Files\Sophos
2008-04-12 11:52 . 2008-04-12 11:52 444 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-04-11 20:17 . 2004-08-04 07:00 1,032,192 --a------ C:\WINDOWS\explorer.exe
2008-04-11 20:12 . 2008-04-11 20:14 <DIR> d-------- C:\Documents and Settings\John\Application Data\AVG7
2008-04-11 20:11 . 2008-04-11 20:11 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-11 20:09 . 2008-04-11 20:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-11 20:09 . 2008-04-11 20:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-11 19:38 . 2008-04-11 19:38 47,104 --a------ C:\23.tmp
2008-04-11 19:38 . 2008-04-11 19:38 3,276 --a------ C:\26.tmp
2008-04-11 19:38 . 2008-04-11 19:38 3,276 --a------ C:\18.tmp
2008-04-11 19:35 . 2008-04-15 17:27 192,512 --a------ C:\WINDOWS\system32\cbOCR.dll
2008-04-11 18:46 . 2008-04-11 18:46 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-11 18:46 . 2008-04-11 18:46 <DIR> d-------- C:\Documents and Settings\John\Application Data\Malwarebytes
2008-04-11 18:46 . 2008-04-11 18:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-11 18:13 . 2008-04-11 18:13 <DIR> d-------- C:\Deckard
2008-04-11 17:21 . 2008-04-11 17:21 3,276 --a------ C:\36.tmp
2008-04-11 17:21 . 2008-04-11 17:21 3,276 --a------ C:\34.tmp
2008-04-11 17:17 . 2008-04-11 17:17 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-11 17:08 . 2008-04-11 17:08 3,276 --a------ C:\33.tmp
2008-04-11 16:55 . 2008-04-11 16:55 3,276 --a------ C:\30.tmp
2008-04-11 16:55 . 2008-04-11 16:55 3,276 --a------ C:\28.tmp
2008-04-11 16:51 . 2008-04-11 16:51 311 --a------ C:\WINDOWS\system32\MRT.INI
2008-04-11 16:46 . 2008-03-01 09:06 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-11 16:46 . 2007-06-30 23:31 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-11 16:46 . 2007-06-30 23:36 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-11 16:46 . 2008-03-01 09:06 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-11 16:46 . 2008-03-01 09:06 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-11 16:46 . 2008-03-01 09:06 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-11 16:46 . 2008-03-01 09:06 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-11 16:46 . 2008-03-01 09:06 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-11 16:46 . 2008-02-22 06:00 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-11 16:21 . 2008-04-11 16:21 3,276 --a------ C:\27.tmp
2008-04-11 16:20 . 2008-04-11 16:21 3,276 --a------ C:\25.tmp
2008-04-11 15:57 . 2008-04-11 15:57 3,276 --a------ C:\24.tmp
2008-04-11 15:57 . 2008-04-11 15:57 3,276 --a------ C:\22.tmp
2008-04-11 15:52 . 2008-04-11 15:52 <DIR> d-------- C:\_OTMoveIt
2008-04-11 14:53 . 2008-04-11 14:53 3,276 --a------ C:\17.tmp
2008-04-11 14:53 . 2008-04-11 14:53 0 --a------ C:\21.tmp
2008-04-11 14:53 . 2008-04-11 14:53 0 --a------ C:\1C.tmp
2008-04-11 14:53 . 2008-04-11 14:53 0 --a------ C:\1B.tmp
2008-04-11 14:53 . 2008-04-11 14:53 0 --a------ C:\1A.tmp
2008-04-11 14:49 . 2008-04-11 14:49 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-11 14:42 . 2008-04-14 16:21 <DIR> d-------- C:\SDFix
2008-04-09 18:23 . 2008-04-09 18:23 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-09 18:22 . 2008-04-09 18:22 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-04-09 18:18 . 2006-03-22 08:34 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Corel
2008-04-09 18:18 . 2008-04-11 20:11 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-09 18:16 . 2008-04-09 18:16 2 --a------ C:\B.tmp
2008-04-09 17:38 . 2008-04-09 17:31 691,545 --a------ C:\WINDOWS\unins000.exe
2008-04-09 17:38 . 2008-04-09 17:38 2,542 --a------ C:\WINDOWS\unins000.dat
2008-04-09 14:05 . 2008-04-09 14:05 0 --a------ C:\20.tmp
2008-04-09 14:04 . 2008-04-09 14:04 0 --a------ C:\1D.tmp
2008-04-09 14:04 . 2008-04-09 14:04 0 --a------ C:\19.tmp
2008-04-09 14:03 . 2008-04-09 14:04 2 --a------ C:\15.tmp
2008-04-09 14:03 . 2008-04-09 14:03 0 --a------ C:\14.tmp
2008-04-09 06:42 . 2008-04-09 06:42 0 --a------ C:\1F.tmp
2008-04-09 06:41 . 2008-04-09 06:41 0 --a------ C:\1E.tmp
2008-04-09 06:36 . 2008-04-09 06:36 0 --a------ C:\16.tmp
2008-04-09 06:35 . 2008-04-09 06:36 2 --a------ C:\13.tmp
2008-04-09 06:35 . 2008-04-09 06:35 0 --a------ C:\F.tmp
2008-04-08 18:58 . 2008-04-08 06:49 160,256 --a------ C:\WINDOWS\system32\AF.tmp
2008-04-08 07:18 . 2008-04-08 07:18 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-04-08 06:50 . 2008-04-08 06:50 2 --a------ C:\12.tmp
2008-04-07 11:25 . 2008-04-07 11:25 2 --a------ C:\6.tmp
2008-04-07 10:50 . 2008-04-07 10:50 29 --a------ C:\WINDOWS\system32\qrfwapis.tmp
2008-04-07 10:49 . 2008-04-07 10:49 0 --a------ C:\2F.tmp
2008-04-07 10:48 . 2008-04-09 14:04 160,256 --a------ C:\WINDOWS\system32\blackster.scr
2008-04-07 10:48 . 2008-04-07 10:48 0 --a------ C:\2E.tmp
2008-04-07 10:48 . 2008-04-07 10:48 0 --a------ C:\2C.tmp
2008-04-07 10:47 . 2008-04-07 10:48 2 --a------ C:\2B.tmp
2008-04-07 10:47 . 2008-04-07 10:47 0 --a------ C:\2A.tmp
2008-04-01 04:12 . 2008-04-01 04:12 16 --a------ C:\s3ck
2008-03-28 16:02 . 2008-03-28 16:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-03-28 16:00 . 2008-03-28 16:01 <DIR> d-------- C:\Program Files\Dell Support Center
2008-03-28 16:00 . 2008-03-28 16:00 <DIR> d-------- C:\Program Files\Common Files\supportsoft
2008-03-20 00:51 . 2008-03-20 00:51 16 --a------ C:\s2p8
2008-03-19 11:34 . 2008-03-19 11:34 16 --a------ C:\s2i4
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-14 10:57 90,112 ----a-w C:\WINDOWS\DUMP612b.tmp
2008-04-11 22:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-04-11 22:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-11 21:42 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-28 19:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-03-20 20:07 --------- d-----w C:\Documents and Settings\John\Application Data\Corel
.
------- Sigcheck -------
2004-08-04 07:00 17408 1b2d5bde0478a770eccb28eb45017cb2 C:\WINDOWS\system32\svchost.exe
2004-08-04 07:00 506368 19aba4dbec658fba6611906ab35c7c2b C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((( snapshot@2008-04-15_18.47.05.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-15 22:05:06 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-15 23:29:58 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 21:04 68856]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-11-14 18:33 8716288]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 21:42 1404928]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 19:48 32881]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 05:12 94208]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-03-22 08:27 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-22 08:27 98304]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44 81920]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 07:20 122940]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-15 03:12 1838592]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 21:20 8192]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 13:06 106496]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2003-12-09 15:02 57344]
"Motive SmartBridge"="C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2006-11-15 08:07 380928]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36 114688]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 17:16 1121792]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-11 20:10 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-11-14 18:33 8716288]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-04-11 20:10 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2006-03-22 08:27:10 156784]
AT&T Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2006-03-25 15:12:21 217088]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-03-22 08:24:19 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Qwc05.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
S3 MEMSWEEP2;MEMSWEEP2;C:\WINDOWS\system32\29.tmp [2007-08-14 08:12]
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-15 19:30:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\C:\WINDOWS\system32\29.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\tsd32.dll
.
Completion time: 2008-04-15 19:35:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-15 23:35:19
ComboFix2.txt 2008-04-15 22:47:29
Pre-Run: 63,280,611,328 bytes free
Post-Run: 63,271,325,696 bytes free
.
2008-02-14 08:03:07 --- E O F ---