ComboFix 08-07-09.5 - T.J 2008-07-11 0:49:40.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.358 [GMT -4:00]
Running from: C:\Documents and Settings\T.J\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\T.J\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
FILE ::
C:\WINDOWS\BM9b2700e8.xml
C:\WINDOWS\system32\dpbybkqyhvedhks.exe
C:\WINDOWS\system32\drivers\cd2e4d3f.sys
C:\WINDOWS\system32\g87.exe
C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll
C:\WINDOWS\system32\mouymjwe.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions
)))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\dpbybkqyhvedhks.exe
C:\WINDOWS\system32\g87.exe
C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll
C:\WINDOWS\system32\mouymjwe.tmp
.
((((((((((((((((((((((((( Files Created from 2008-06-11 to 2008-07-11
)))))))))))))))))))))))))))))))
.
2008-07-11 00:07 . 2008-07-11 00:07 <DIR> d-------- C:\Program
Files\SUPERAntiSpyware
2008-07-11 00:07 . 2008-07-11 00:07 <DIR> d-------- C:\Program
Files\Common Files\Wise Installation Wizard
2008-07-11 00:07 . 2008-07-11 00:07 <DIR> d--------
C:\Documents and Settings\T.J\Application Data\SUPERAntiSpyware.com
2008-07-11 00:07 . 2008-07-11 00:07 <DIR> d--------
C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-10 22:52 . 2008-07-10 22:52 <DIR> d-------- C:\Program
Files\Malwarebytes' Anti-Malware
2008-07-10 22:52 . 2008-07-10 22:52 <DIR> d--------
C:\Documents and Settings\T.J\Application Data\Malwarebytes
2008-07-10 22:52 . 2008-07-10 22:52 <DIR> d--------
C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-10 22:52 . 2008-07-07 17:35 34,296 --a------
C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-10 22:52 . 2008-07-07 17:35 17,144 --a------
C:\WINDOWS\system32\drivers\mbam.sys
2008-07-10 17:15 . 2008-07-11 00:56 54,156 --ah-----
C:\WINDOWS\QTFont.qfn
2008-07-10 17:15 . 2008-07-10 17:15 1,409 --a------
C:\WINDOWS\QTFont.for
2008-07-10 17:14 . 2008-07-11 00:54 58,476 --ah-----
C:\WINDOWS\system32\drivers\cd2e4d3f.sys.szcpf.szcpf
2008-07-09 19:53 . 2008-07-11 00:38 58,476 --ah-----
C:\WINDOWS\system32\drivers\cd2e4d3f.sys.szcpf
2008-07-09 19:26 . 2008-07-10 17:31 <DIR> d--------
C:\Documents and Settings\All Users\Application Data\SITEguard
2008-07-09 19:26 . 2008-07-10 17:18 6,792 --a------
C:\WINDOWS\system32\drivers\kgpcpy.cfg
2008-07-09 19:25 . 2008-07-09 19:25 <DIR> d-------- C:\Program
Files\STOPzilla!
2008-07-09 19:25 . 2008-07-09 19:25 <DIR> d-------- C:\Program
Files\Common Files\iS3
2008-07-09 19:25 . 2008-07-11 00:55 <DIR> d--------
C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-07-09 19:00 . 2008-07-09 19:00 <DIR> d-------- C:\Program
Files\Trend Micro
2008-07-09 16:24 . 2008-07-09 16:24 <DIR> d-------- C:\Deckard
2008-07-09 13:56 . 2008-07-10 03:01 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-09 13:50 . 2008-07-10 08:53 <DIR> d--------
C:\WINDOWS\system32\drivers\Avg
2008-07-09 13:50 . 2008-07-09 13:50 <DIR> d-------- C:\Program
Files\AVG
2008-07-09 13:50 . 2008-07-10 17:37 <DIR> d--------
C:\Documents and Settings\T.J\Application Data\AVGTOOLBAR
2008-07-09 13:50 . 2008-07-09 13:50 <DIR> d--------
C:\Documents and Settings\All Users\Application Data\avg8
2008-07-09 13:50 . 2008-07-09 13:50 96,520 --a------
C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-09 13:50 . 2008-07-09 13:50 76,040 --a------
C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-09 13:50 . 2008-07-09 13:50 10,520 --a------
C:\WINDOWS\system32\avgrsstx.dll
2008-07-08 19:34 . 2007-07-30 19:19 271,224 --a------
C:\WINDOWS\system32\mucltui.dll
2008-07-08 19:34 . 2007-07-30 19:19 207,736 --a------
C:\WINDOWS\system32\muweb.dll
2008-07-08 19:34 . 2007-07-30 19:19 30,072 --a------
C:\WINDOWS\system32\mucltui.dll.mui
2008-07-08 19:21 . 2007-11-27 22:56 116,416 --a------
C:\WINDOWS\system32\drivers\msfwhlpr.sys
2008-07-08 19:21 . 2007-11-27 22:56 91,328 --a------
C:\WINDOWS\system32\drivers\msfwdrv.sys
2008-07-08 19:19 . 2008-07-08 19:19 <DIR> d--------
C:\WINDOWS\system32\bits
2008-07-08 19:19 . 2007-03-29 08:56 409,600 ---------
C:\WINDOWS\system32\dllcache\qmgr.dll
2008-07-08 19:19 . 2008-05-15 16:15 53,168 --a------
C:\WINDOWS\system32\drivers\MpFilter.sys
2008-07-08 19:19 . 2007-03-29 08:56 18,944 ---------
C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2008-07-08 19:19 . 2007-03-29 08:56 8,192 ---------
C:\WINDOWS\system32\dllcache\bitsprx2.dll
2008-07-08 19:19 . 2007-03-29 08:56 7,168 ---------
C:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-07-08 19:19 . 2007-03-29 08:56 7,168 ---------
C:\WINDOWS\system32\dllcache\bitsprx3.dll
2008-07-08 19:19 . 2007-03-29 08:56 7,168 --a------
C:\WINDOWS\system32\bitsprx4.dll
2008-07-08 19:14 . 2008-07-10 09:00 <DIR> d-------- C:\Program
Files\Microsoft Windows OneCare Live
2008-07-08 18:17 . 2008-07-08 18:17 36,079 --a------
C:\WINDOWS\alaredun.ini
2008-07-08 00:21 . 2008-07-08 00:21 <DIR> d--------
C:\Documents and Settings\All Users\Application Data\ESET
2008-07-07 23:48 . 2008-07-08 19:02 <DIR> d--------
C:\Documents and Settings\T.J\Application Data\Azureus
2008-07-07 23:48 . 2008-07-07 23:48 <DIR> d--------
C:\Documents and Settings\All Users\Application Data\Azureus
2008-07-07 20:36 . 2008-07-07 20:36 <DIR> d-------- C:\Program
Files\Alwil Software
2008-07-07 17:05 . 2008-07-11 00:07 <DIR> d-------- C:\Program
Files
2008-07-07 13:09 . 2008-07-07 21:35 <DIR> d--------
C:\WINDOWS\system32\4808
2008-07-07 12:12 . 2008-07-07 12:12 9,662 --a------
C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-07-07 12:11 . 2008-07-07 12:11 <DIR> d-------- C:\Program
Files\AskSBar
2008-07-07 12:10 . 2008-07-07 23:51 <DIR> d-------- C:\Program
Files\Vuze
2008-07-07 12:02 . 2008-07-07 21:28 <DIR> d-------- C:\WINDOWS\VC5K
2008-07-07 12:02 . 2008-07-07 21:28 <DIR> d--------
C:\WINDOWS\system32\tfig
2008-07-07 12:02 . 2008-07-08 19:02 <DIR> d--------
C:\WINDOWS\system32\olixds01
2008-07-07 12:02 . 2008-07-07 21:27 <DIR> d--------
C:\WINDOWS\system32\net
2008-07-07 12:02 . 2008-07-07 22:33 <DIR> d--------
C:\WINDOWS\system32\cREG
2008-07-07 12:02 . 2008-07-07 22:32 <DIR> d--------
C:\WINDOWS\system32\1030
2008-07-07 12:02 . 2008-07-07 12:02 <DIR> d-------- C:\Temp\stmpv4
2008-07-07 12:02 . 2008-07-10 17:45 <DIR> d-------- C:\Temp
2008-07-07 12:02 . 2008-07-08 00:04 90,922 --a------
C:\WINDOWS\system32\itaswkecpvtbcwpbq.dll-uninst.exe
2008-07-07 10:49 . 2008-07-07 10:39 <DIR> d-------- C:\kav
2008-07-06 22:14 . 2008-07-08 19:01 <DIR> d-------- C:\Program
Files\Spyware Doctor Enterprise Server
2008-07-06 22:13 . 2008-07-06 22:13 <DIR> d-------- C:\PC Tools
Spyware Doctor Enterprise
2008-07-06 21:59 . 2008-07-08 00:15 <DIR> d-------- C:\Program
Files\XoftSpySE
2008-07-06 21:39 . 2008-07-06 21:39 75 --a------
C:\WINDOWS\st_affiliate.ini
2008-07-06 21:35 . 2008-07-07 10:42 <DIR> d-------- C:\Program
Files\CyberDefender
2008-07-03 15:41 . 2008-07-03 15:41 258,048 -ra------
C:\WINDOWS\system32\SZBase5.dll
2008-06-29 17:25 . 2008-06-29 17:40 4,681,449,472 --a------
C:\SPIDERWICK _AC_D1_169.ISO
2008-06-28 21:49 . 2008-06-28 21:49 8,433 --a------
C:\SPIDERWICK_AC_D1_169.MDS
2008-06-28 21:34 . 2008-06-28 21:49 7,506,722,816 --a------
C:\SPIDERWICK_AC_D1_169.ISO
2008-06-26 11:20 . 2008-06-26 11:20 <DIR> d--------
C:\WINDOWS\Cache
2008-06-26 11:20 . 2008-06-26 11:20 <DIR> d-------- C:\Program
Files\Coupons
2008-06-26 11:20 . 2008-06-26 11:20 206,168 -ra------
C:\WINDOWS\system32\cpnprt2.cid
2008-06-26 10:56 . 2008-06-26 10:56 364,544 -ra------
C:\WINDOWS\system32\IS3DBA5.dll
2008-06-26 10:56 . 2008-06-26 10:56 126,976 -ra------
C:\WINDOWS\system32\IS3HTUI5.dll
2008-06-26 10:55 . 2008-06-26 10:55 372,736 -ra------
C:\WINDOWS\system32\IS3UI5.dll
2008-06-26 10:55 . 2008-06-26 10:55 61,440 -ra------
C:\WINDOWS\system32\IS3Hks5.dll
2008-06-26 10:55 . 2008-06-26 10:55 23,040 -ra------
C:\WINDOWS\system32\IS3XDat5.dll
2008-06-26 10:54 . 2008-06-26 10:54 196,608 -ra------
C:\WINDOWS\system32\IS3Win325.dll
2008-06-26 10:54 . 2008-06-26 10:54 94,208 -ra------
C:\WINDOWS\system32\IS3Inet5.dll
2008-06-26 10:54 . 2008-06-26 10:54 90,112 -ra------
C:\WINDOWS\system32\IS3Svc5.dll
2008-06-26 10:50 . 2008-06-26 10:50 708,608 -ra------
C:\WINDOWS\system32\IS3Base5.dll
2008-06-20 13:41 . 2008-06-20 13:41 245,248 ---------
C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 06:44 . 2008-06-20 06:44 138,368 ---------
C:\WINDOWS\system32\dllcache\afd.sys
2008-06-19 09:53 . 2008-06-19 09:53 <DIR> d--------
C:\Documents and Settings\All Users\Application Data\LogMeIn
2008-06-11 05:38 . 2008-06-13 09:10 272,128 ---------
C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 05:38 . 2008-06-13 09:10 272,128 ---------
C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report
))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-11 04:44 --------- d-----w C:\Program Files\Mozilla
Thunderbird
2008-07-11 04:42 --------- d-----w C:\Documents and
Settings\T.J\Application Data\OpenOffice.org2
2008-07-11 04:37 --------- d-----w C:\Program Files\LogMeIn
2008-07-10 19:02 6,686 ----a-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-07-08 21:21 --------- d-----w C:\Documents and
Settings\T.J\Application Data\AdobeUM
2008-07-08 12:35 --------- d-----w C:\Documents and
Settings\All Users\Application Data\Kodak
2008-07-08 06:52 --------- d-----w C:\Program Files\Kodak
2008-07-08 04:21 --------- d-----w C:\Program Files\ESET
2008-07-08 04:15 --------- d-----w C:\Program Files\Spybot -
Search & Destroy
2008-07-08 04:15 --------- d-----w C:\Documents and
Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-08 04:14 --------- d-----w C:\Program Files\Kaspersky Lab
2008-07-03 19:04 --------- d-----w C:\Documents and
Settings\All Users\Application Data\alamode
2008-06-29 21:24 --------- d-----w C:\Documents and
Settings\All Users\Application Data\DVD Shrink
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 148,992 ----a-w
C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w
C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w
C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w
C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w
C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w
C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-18 17:32 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-06-18 17:32 278,528 ------w C:\WINDOWS\MBWSetup.exe
2008-06-16 17:48 849,144 ----a-w
C:\WINDOWS\system32\auroraupgrade.dll
2008-06-16 14:24 --------- d-----w C:\Program Files\The Weather
Channel FW
2008-06-02 14:52 849,144 ----a-w C:\WINDOWS\system32\wtapi.exe
2008-05-30 18:52 3,921,264 ----a-w
C:\WINDOWS\system32\adbilling.dll
2008-05-28 16:33 83,288 ----a-w
C:\WINDOWS\system32\LMIRfsClientNP.dll
2008-05-28 16:32 87,352 ----a-w C:\WINDOWS\system32\LMIinit.dll
2008-05-28 16:32 24,608 ----a-w C:\WINDOWS\system32\LMIport.dll
2008-05-28 16:32 23,736 ----a-w C:\WINDOWS\system32\lmimirr.dll
2008-05-28 16:32 10,040 ----a-w C:\WINDOWS\system32\lmimirr2.dll
2008-05-20 19:31 1,574,136 ----a-w C:\WINDOWS\system32\wtusers.dll
2008-05-20 17:16 500,984 ----a-w C:\WINDOWS\system32\alabilling.dll
2008-05-19 18:09 3,069,176 ----a-w
C:\WINDOWS\system32\alacontacts.dll
2008-05-13 14:03 34,432 ----a-r
C:\WINDOWS\system32\drivers\SZKG.sys
2008-05-08 17:12 1,398,008 ----a-w C:\WINDOWS\system32\wtfiles.dll
2008-05-08 12:28 202,752 ------w
C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 04:55 1,288,192 ------w
C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-24 02:16 3,591,680 ----a-w
C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:40 625,664 ------w
C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 07:39 70,656 ------w
C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:39 13,824 ------w
C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 05:07 161,792 ------w
C:\WINDOWS\system32\dllcache\ieakui.dll
2008-04-15 16:25 681,208 ----a-w C:\WINDOWS\system32\openreport.exe
2008-04-11 14:27 3,532,144 ----a-w
C:\WINDOWS\system32\filecabinet5.dll
2006-05-11 13:52 630,784 ----a-w C:\Documents and
Settings\T.J\chatlnk.exe
.
((((((((((((((((((((((((((((( snapshot@2008-07-10_17.55.49.96
)))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-10 21:49:27 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-11 04:54:31 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-11 04:07:51 18,944 ----a-r
C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2008-07-11 04:07:51 65,024 ----a-r
C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points
))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 06:00 15360]
"myspaceim"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2006-11-16
17:42 1327104]
"msmsgs"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe"
[2007-01-01 17:22 3739648]
"dw6"="C:\Program Files\The Weather Channel
FW\Desktop\DesktopWeather.exe" [2008-06-10 16:18 785520]
"SUPERAntiSpyware"="C:\Program
Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"sunjavaupdatesched"="C:\Program
Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 18:48 32881]
"realtray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-04-17
08:12 26112]
"quicktime task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11
11:56 286720]
"onecareui"="C:\Program Files\Microsoft Windows OneCare
Live\winssnotify.exe" [2008-06-25 06:48 67112]
"mskdetectorexe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe"
[2005-07-12 20:05 1117184]
"logmein gui"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
[2007-04-17 14:03 63048]
"ituneshelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11
13:10 267048]
"isusscheduler"="C:\Program Files\Common
Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"isuspm startup"="C:\Program Files\Common
Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"google desktop search"="C:\Program Files\Google\Google Desktop
Search\GoogleDesktop.exe" [2006-04-17 08:21 169472]
"ehtray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 15:01 67584]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13
16:48 1443072]
"dmxlauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe"
[2005-10-05 04:12 94208]
"dla"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"atipta"="C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe" [2005-08-05 22:05 344064]
"adobe photo downloader"="C:\Program Files\Adobe\Photoshop Album Starter
Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-09 13:50 1232152]
"sigmatelsystrayapp"="stsystra.exe" [2005-03-23 00:20 339968
C:\WINDOWS\stsystra.exe]
C:\Documents and Settings\T.J\Start Menu\Programs\Startup\
Event Reminder.lnk - C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE
[2007-12-29 21:31:43 325632]
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org
2.1\program\quickstart.exe [2006-11-27 17:45:48 393216]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
[2006-04-17 08:10:11 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExec
uteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program
Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows
nt\currentversion\winlogon\notify\!saswinlogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows
nt\currentversion\winlogon\notify\lmiinit]
2008-05-28 12:32 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\onecaremp]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"KodakCCS"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Authoriz
edApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\a la mode\\Sched\\eSched.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R0 szkg5;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys [2008-05-13 10:03]
R1 avgldx86;AVG Free AVI Loader Driver
x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-09 13:50]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
[2008-03-13 16:52]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe
[2008-07-09 13:50]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
[2008-07-09 13:50]
R2 avgtdix;AVG Free8 Network
Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-09 13:50]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program
Files\LogMeIn\x86\RaInfo.sys [2008-02-28 15:31]
R2 LMIRfsDriver;LogMeIn Remote File System
Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2008-03-07 13:39]
R2 ochealthmon;Windows Live OneCare Health Monitor;C:\Program
Files\Microsoft Windows OneCare Live\OcHealthMon.exe [2008-06-25 06:47]
S1 cd2e4d3f;cd2e4d3f;C:\WINDOWS\system32\drivers\cd2e4d3f.sys []
S3 marsqx5;Digital Blue QX5 V2
Microscope;C:\WINDOWS\system32\DRIVERS\marsqx5.sys [2007-04-02 16:02]
.
Contents of the 'Scheduled Tasks' folder
"2008-07-10 16:15:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer, http://www.gmer.net
Rootkit scan 2008-07-11 00:55:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\Program Files\Common Files\Apple\Mobile Device
Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\LogMeIn\x86\ramaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\system32\locator.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.bin
C:\WINDOWS\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2008-07-11 1:04:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-11 05:03:45
ComboFix2.txt 2008-07-10 23:03:37
ComboFix3.txt 2008-07-10 21:56:42
Pre-Run: 100,250,648,576 bytes free
Post-Run: 100,257,386,496 bytes free
293 --- E O F --- 2008-07-09 07:02:35