ComboFix 08-06-09.3 - Martis 2008-06-10 7:38:14.3 - NTFSx86
Running from: C:\Documents and Settings\Martis\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Martis\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\system\
.
((((((((((((((((((((((((( Files Created from 2008-05-10 to 2008-06-10 )))))))))))))))))))))))))))))))
.
2008-06-09 12:32 . 2008-06-09 12:33 <DIR> d-------- C:\Program Files\Panda Security
2008-06-09 10:53 . 2008-06-09 10:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-09 10:52 . 2008-06-09 13:13 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-06-09 10:52 . 2008-06-09 10:52 <DIR> d-------- C:\Documents and Settings\Martis\Application Data\SUPERAntiSpyware.com
2008-06-09 10:21 . 2008-06-09 10:21 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-09 10:21 . 2008-06-09 10:21 <DIR> d-------- C:\Documents and Settings\Martis\Application Data\Malwarebytes
2008-06-09 10:21 . 2008-06-09 10:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-09 10:21 . 2008-06-05 16:04 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-09 10:21 . 2008-06-05 16:04 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-09 10:20 . 2008-06-09 10:20 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-06-09 09:50 . 2008-06-09 09:50 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-06-09 09:47 . 2008-06-09 09:47 <DIR> d-------- C:\WINDOWS\EHome
2008-06-09 08:10 . 2008-06-09 08:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Dell
2008-06-08 17:47 . 2008-05-12 16:31 622,632 --a------ C:\autoruns.exe
2008-06-08 17:47 . 2008-05-09 13:56 520,232 --a------ C:\autorunsc.exe
2008-06-07 21:26 . 2008-06-09 16:38 <DIR> d--h----- C:\$AVG8.VAULT$
2008-06-07 21:22 . 2008-06-09 08:03 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-07 21:22 . 2008-06-09 08:35 <DIR> d-------- C:\Documents and Settings\Martis\Application Data\AVGTOOLBAR
2008-06-07 21:22 . 2008-06-09 08:02 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-07 21:22 . 2008-06-07 21:22 12,424 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-06-07 21:22 . 2008-06-09 08:01 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-06-07 21:21 . 2008-06-07 21:21 <DIR> d-------- C:\Program Files\AVG
2008-06-07 21:21 . 2008-06-07 21:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-07 21:21 . 2008-06-07 21:21 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-10 12:30 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-09 22:37 6,686 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-06-09 16:11 --------- d-----w C:\Program Files\NetWaiting
2008-06-09 15:51 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-08 02:26 --------- d-----w C:\Program Files\Symantec
2008-06-08 02:26 --------- d-----w C:\Documents and Settings\Martis\Application Data\Symantec
2008-06-08 02:09 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-08 02:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-06-08 01:53 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-20 02:22 145,005 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2008_03_19_21_09_48_small.dmp.zip
2008-03-20 02:22 127,068 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2008_03_19_21_12_40_small.dmp.zip
2008-03-20 02:22 126,576 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2008_03_19_21_11_35_small.dmp.zip
2008-03-20 02:22 120,902 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2008_03_19_21_10_44_small.dmp.zip
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2007-08-14 13:58 774,144 -c--a-w C:\Program Files\RngInterstitial.dll
2006-05-28 15:27 32 -c--a-r C:\Documents and Settings\All Users\hash.dat
2008-02-03 01:13 88 --sh--r C:\WINDOWS\system32\4AFB9750B8.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-09_15.15.35.82 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-09 19:59:50 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-10 12:18:18 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\ARPPRODUCTICON.exe
{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP106\A0135996.ex"
C:\b4edc13ba26a2b5196c5043b55\i386\admin.dll
2004-08-04 00:56 20540 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137080.dll
C:\b4edc13ba26a2b5196c5043b55\i386\admin.exe
2004-08-04 00:56 16439 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137079.exe
C:\b4edc13ba26a2b5196c5043b55\i386\asms\10\msft\windows\gdiplus\gdiplus.dll
2004-08-04 00:57 1712128 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137077.dll
C:\b4edc13ba26a2b5196c5043b55\i386\asms\52\msft\windows\net\dxmrtp\dxmrtp.dll
2004-08-04 00:57 853504 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137072.dll
C:\b4edc13ba26a2b5196c5043b55\i386\asms\52\msft\windows\net\rtcdll\rtcdll.dll
2004-08-04 00:57 991232 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137070.dll
C:\b4edc13ba26a2b5196c5043b55\i386\asms\52\msft\windows\net\rtcres\rtcres.dll
2004-08-04 00:55 132096 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137068.dll
C:\b4edc13ba26a2b5196c5043b55\i386\asms\60\msft\windows\common\controls\comctl32.dll
2004-08-04 00:57 1050624 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137065.dll
C:\b4edc13ba26a2b5196c5043b55\i386\asms\70\msft\windows\mswincrt\msvcirt.dll
2004-08-04 00:57 54784 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137062.dll
C:\b4edc13ba26a2b5196c5043b55\i386\asms\70\msft\windows\mswincrt\msvcrt.dll
2004-08-04 00:57 343040 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137061.dll
C:\b4edc13ba26a2b5196c5043b55\i386\aspnet_isapi.dll
2004-08-03 22:11 200704 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137058.dll
C:\b4edc13ba26a2b5196c5043b55\i386\aspnet_regiis.exe
2004-08-03 22:11 24576 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137055.exe
C:\b4edc13ba26a2b5196c5043b55\i386\aspnet_wp.exe
2004-08-03 22:11 32768 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137054.exe
C:\b4edc13ba26a2b5196c5043b55\i386\author.dll
2004-08-04 00:56 20540 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137053.dll
C:\b4edc13ba26a2b5196c5043b55\i386\author.exe
2004-08-04 00:56 16439 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137052.exe
C:\b4edc13ba26a2b5196c5043b55\i386\autochk.exe
2004-08-04 00:56 588800 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137051.exe
C:\b4edc13ba26a2b5196c5043b55\i386\autofmt.exe
2004-08-04 00:56 580608 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137050.exe
C:\b4edc13ba26a2b5196c5043b55\i386\cabinet.dll
2004-08-04 00:56 59904 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137049.dll
C:\b4edc13ba26a2b5196c5043b55\i386\caspol.exe
2004-07-19 18:54 94208 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137048.exe
C:\b4edc13ba26a2b5196c5043b55\i386\cfgwiz.exe
2004-08-04 00:56 188480 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137047.exe
C:\b4edc13ba26a2b5196c5043b55\i386\corperfmonext.dll
2004-08-03 22:11 69632 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137045.dll
C:\b4edc13ba26a2b5196c5043b55\i386\csc.exe
2004-08-03 22:11 49152 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137043.exe
C:\b4edc13ba26a2b5196c5043b55\i386\cscomp.dll
2004-07-19 18:54 589824 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137042.dll
C:\b4edc13ba26a2b5196c5043b55\i386\dbghelp.dll
2004-08-04 00:56 640000 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137041.dll
C:\b4edc13ba26a2b5196c5043b55\i386\drw\dwwin.exe
2004-08-04 00:56 180224 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137039.exe
C:\b4edc13ba26a2b5196c5043b55\i386\eventlogmessages.dll
2004-07-19 18:54 798720 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137038.dll
C:\b4edc13ba26a2b5196c5043b55\i386\faxpatch.exe
2004-08-04 00:56 20992 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP109\A0137037.exe
C:\b4edc13ba26a2b5196c5043b55\i386\fp4amsft.dll
2008-06-10 07:50 0 C:\ComboFix
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-06-09 08:01 2051328 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-06-09 08:01 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-06-09 08:01 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:54 5674352]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2006-03-13 18:34 200747]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"DellTransferAgent"="C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe" [2007-11-13 16:46 135168]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-09 13:13 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 19:42 1404928]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-04-05 19:22 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-05 19:19 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-05 19:23 114688]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 10:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 10:44 81920]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20 122940]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 14:11 267048]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-09 08:02 1177368]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dell Network Assistant.lnk - C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2006-12-04 17:52:31 7168]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-26 01:49:44 24576]
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-04-19 13:49:52 64864]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-06-09 13:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2008-06-09 13:13 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-06-07 21:22]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-07 21:21]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-07 21:21]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-09 08:01]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-09 08:02]
S1 lusbaudio;Logitech USB Microphone;C:\WINDOWS\system32\drivers\OVSound2.sys [2001-08-17 14:05]
S3 QCAbsee;Logitech QuickCam Web (0801);C:\WINDOWS\system32\DRIVERS\OVCA.sys [2001-08-17 14:05]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-05-09 21:10:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-10 12:24:05 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-10 07:42:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-10 7:50:56
ComboFix-quarantined-files.txt 2008-06-10 12:50:39
ComboFix2.txt 2008-06-09 22:07:48
ComboFix3.txt 2008-06-09 20:16:46
Pre-Run: 40,978,907,136 bytes free
Post-Run: 40,965,521,408 bytes free
217 --- E O F --- 2008-06-09 17:49:20