ComboFix 08-12-16.03 - Abby and Erika 2008-12-16 15:17:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.465 [GMT -8:00]
Running from: c:\documents and settings\Abby and Erika\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Abby and Erika\Application Data\FunWebProducts
c:\documents and settings\Abby and Erika\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\Abby and Erika\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\IE4 Error Log.txt
c:\windows\system32\config\systemprofile\Desktop\Antivirus 2009.lnk
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\system32\QTWMCI32.DLL
c:\windows\system32\TDSSosvd.dat
c:\windows\Tasks\jshyrpka.job
c:\windows\wiaserviv.log
----- BITS: Possible infected sites -----
hxxp://childhe.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2008-11-16 to 2008-12-16 )))))))))))))))))))))))))))))))
.
2008-12-16 13:14 . 2008-12-16 13:14 <DIR> d-------- c:\documents and settings\Abby and Erika\Application Data\Malwarebytes
2008-12-16 12:28 . 2008-12-16 12:28 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
2008-12-16 12:28 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-16 12:28 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-16 12:27 . 2008-12-16 12:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-16 12:08 . 2008-12-16 12:08 <DIR> d-------- c:\documents and settings\Administrator\Application Data\AVG7
2008-12-16 11:19 . 2008-12-16 12:28 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-10 21:28 . 2008-12-12 17:25 1,725,270 ---hs---- c:\windows\system32\cdpcluws.ini
2008-12-10 20:10 . 2008-12-10 20:15 1,659,851 ---hs---- c:\windows\system32\accefxjh.ini
2008-12-09 20:07 . 2008-12-10 20:08 1,659,851 ---hs---- c:\windows\system32\fglcfhaj.ini
2008-12-08 16:59 . 2008-12-09 17:00 1,620,759 ---hs---- c:\windows\system32\fyrpjiqj.ini
2008-12-07 13:18 . 2008-12-08 16:55 1,598,743 ---hs---- c:\windows\system32\lmrvbxaq.ini
2008-12-06 11:42 . 2008-12-07 13:17 1,479,822 ---hs---- c:\windows\system32\urfqjbgw.ini
2008-12-03 08:40 . 2008-12-03 08:40 <DIR> d-------- c:\program files\AIM Toolbar
2008-12-03 08:40 . 2008-12-03 08:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\AIM Toolbar
2008-12-03 08:40 . 2008-12-03 08:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\acccore
2008-12-02 19:58 . 2008-12-03 08:51 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\gadcom
2008-12-01 21:30 . 2008-12-01 21:30 <DIR> d-------- c:\documents and settings\Abby and Erika\Application Data\Twain
2008-12-01 21:30 . 2008-12-16 15:11 <DIR> dr-h----- C:\$VAULT$.AVG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-16 22:54 --------- d-----w c:\documents and settings\Abby and Erika\Application Data\AVG7
2008-12-16 19:12 --------- d-----w c:\program files\Google
2008-12-16 19:07 21,822 ----a-w c:\documents and settings\Abby and Erika\Application Data\wklnhst.dat
2008-12-16 19:03 --------- d-----w c:\program files\Java
2008-12-16 18:47 --------- d-----w c:\program files\RGB
2008-12-16 18:28 --------- d-----w c:\program files\Viewpoint
2008-12-16 18:28 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-12-04 01:04 --------- d-----w c:\program files\AIM6
2008-12-03 16:07 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-30 02:29 --------- d-----w c:\program files\AIMTunes
2008-11-09 21:37 --------- d-----w c:\program files\Apple Software Update
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-01-19 06:32 104,704 ----a-w c:\documents and settings\Abby and Erika\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-28 395776]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-31 50480]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-23 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-23 86016]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-10-22 590848]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-12-11 267048]
"nwiz"="nwiz.exe" [2006-08-23 c:\windows\system32\nwiz.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 c:\windows\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2007-12-19 219136]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Planner Reminder 2008.lnk - c:\windows\Installer\{747A6A10-DA58-48C2-A1F0-C15514419C8A}\Shortcut_EventPlan_5D0DF1BBD82E4FB2B98E4FDE42EF7EBB.exe [2008-06-20 1718]
Event Planner Reminders.lnk - c:\program files\Sierra\Planner\PLNRnote.exe [2003-03-12 184320]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-12 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=ngqzcn.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" []
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys [2008-12-16 38496]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{300ad734-cb41-11dd-9955-00038a000015}]
\Shell\AutoRun\command - WD_Windows_Tools\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2008-12-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://dashboard.aim.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-16 15:20:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\progra~1\Grisoft\AVG7\avgamsvr.exe
c:\progra~1\Grisoft\AVG7\avgupsvc.exe
c:\progra~1\Grisoft\AVG7\avgemc.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Creative Home\Hallmark Card Studio 2008 Deluxe\Planner\PLNRnote.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2008-12-16 15:23:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-16 23:22:45
Pre-Run: 57,123,913,728 bytes free
Post-Run: 57,299,800,064 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
179 --- E O F --- 2008-11-13 05:58:18