ComboFix 08-12-17.01 - User 2008-12-18 23:24:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.501.163 [GMT -8:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
* Created a new restore point
.
/wow section - STAGE 32A
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\User\Application Data\gadcom
c:\documents and settings\User\Local Settings\Temporary Internet Files\fbk.sts
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2008-11-19 to 2008-12-19 )))))))))))))))))))))))))))))))
.
2008-12-18 20:57 . 2008-12-18 18:18 <DIR> d-------- c:\program files\Common Files\AntiGA 2.0 Addon Tools
2008-12-18 20:50 . 2008-12-18 20:50 <DIR> d-------- c:\program files\K-Lite Codec Pack
2008-12-18 19:06 . 2008-12-18 19:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-12-18 18:11 . 2008-12-18 18:18 <DIR> d-------- c:\windows\system32\drivers\Avg
2008-12-18 18:11 . 2008-12-18 18:11 <DIR> d-------- c:\program files\AVG
2008-12-18 18:11 . 2008-12-18 18:11 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-12-18 18:11 . 2008-12-18 18:11 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys
2008-12-18 18:11 . 2008-12-18 18:11 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-12-18 07:51 . 2008-12-18 07:51 <DIR> d-------- c:\documents and settings\User\Application Data\dvdcss
2008-12-18 03:20 . 2008-12-18 03:20 <DIR> d-------- c:\documents and settings\User\Application Data\vlc
2008-12-17 12:41 . 2008-12-17 12:41 <DIR> d-------- c:\program files\Earth
2008-12-16 23:40 . 2008-12-17 10:58 <DIR> d-------- c:\documents and settings\User\.SunDownloadManager
2008-12-15 23:18 . 2008-12-15 23:21 <DIR> d-------- c:\windows\system32\NtmsData
2008-12-15 10:03 . 2008-12-15 10:03 <DIR> d-------- c:\program files\AL-Software
2008-12-15 09:22 . 2008-12-15 09:22 66 --a------ c:\windows\Power Video Converter.INI
2008-12-15 09:04 . 2008-12-15 09:21 <DIR> d-------- c:\program files\Net2Phone
2008-12-15 09:04 . 1999-11-01 15:04 2,238 --a------ c:\windows\system32\n2p.ico
2008-12-15 09:04 . 1999-11-01 15:04 2,238 --a------ c:\windows\n2p.ico
2008-12-15 09:04 . 2008-12-15 09:11 395 --a------ c:\windows\Net2fone.ini
2008-12-15 08:13 . 2008-12-15 08:14 <DIR> d-------- c:\program files\Yahoo!
2008-12-15 08:05 . 2008-12-15 08:15 <DIR> d-------- c:\documents and settings\User\Contacts
2008-12-13 15:00 . 2006-04-20 05:34 1,213,952 --------- c:\windows\LHFSD2.cab
2008-12-13 15:00 . 2006-04-20 05:34 1,069,568 --------- c:\windows\LHFSD1.CAB
2008-12-13 15:00 . 2006-04-20 05:34 150,594 --------- c:\windows\LHFSD3.cab
2008-12-13 15:00 . 2008-12-13 15:00 332 --a------ c:\windows\ST6UNST.000
2008-12-12 23:11 . 2008-12-12 23:11 1,700,352 --a------ c:\windows\system32\gdiplus.dll
2008-12-12 18:17 . 2008-12-18 18:11 <DIR> d-------- c:\program files\AVG8
2008-12-11 17:37 . 2008-12-11 17:38 <DIR> d-------- c:\documents and settings\User\Application Data\Nero
2008-12-11 17:20 . 2008-12-11 17:34 <DIR> d-------- c:\program files\Common Files\Nero
2008-12-11 17:20 . 2008-12-11 17:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nero
2008-12-11 00:40 . 2008-12-11 00:40 <DIR> d-------- C:\VideoConvert
2008-12-10 23:05 . 2008-12-10 23:05 2,560 --a------ c:\windows\_MSRSTRT.EXE
2008-12-10 21:22 . 2008-12-11 17:27 <DIR> d-------- c:\program files\Nero
2008-12-08 00:25 . 2008-12-08 00:25 <DIR> d-------- c:\windows\Sun
2008-12-07 03:37 . 2004-08-03 11:26 221,184 --a------ c:\windows\system32\wmpns.dll
2008-12-07 03:18 . 2008-12-07 03:18 <DIR> d-------- c:\program files\Java
2008-12-07 03:18 . 2008-12-07 03:18 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-07 03:18 . 2008-12-07 03:18 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-07 02:13 . 2008-12-10 08:05 <DIR> d-------- c:\documents and settings\User\Application Data\skypePM
2008-12-07 02:13 . 2008-12-07 02:13 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-12-07 02:12 . 2008-12-10 10:45 <DIR> d-------- c:\documents and settings\User\Application Data\Skype
2008-12-07 02:10 . 2008-12-07 02:10 <DIR> d-------- c:\program files\Skype
2008-12-07 02:10 . 2008-12-07 02:10 <DIR> d-------- c:\program files\Common Files\Skype
2008-12-07 02:10 . 2008-12-07 02:10 <DIR> d-------- c:\documents and settings\All Users\Application Data\Skype
2008-12-07 00:03 . 2008-12-07 00:03 <DIR> d-------- c:\windows\system32\Adobe
2008-12-04 03:42 . 2008-09-12 02:44 206,256 --a------ c:\windows\system32\idmmbc.dll
2008-12-02 15:32 . 2008-12-18 03:15 <DIR> d-------- c:\program files\VideoLAN
2008-11-27 19:21 . 2008-11-27 20:25 <DIR> d-------- c:\documents and settings\User\Application Data\TeamViewer
2008-11-27 19:20 . 2008-11-27 19:20 <DIR> d-------- c:\documents and settings\User\temp
2008-11-24 23:38 . 2008-11-24 23:38 98,304 --a------ c:\windows\system32\prjChameleon.ocx
2008-11-24 23:34 . 2008-11-24 23:34 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2008-11-24 23:29 . 2008-11-24 23:25 109,248 --a------ c:\windows\system32\MSWINSCK.OCX
2008-11-24 18:34 . 2008-12-15 23:21 <DIR> d-------- c:\program files\Internet Download Manager
2008-11-24 18:34 . 2008-12-18 23:03 <DIR> d-------- c:\documents and settings\User\Application Data\IDM
2008-11-24 14:30 . 2008-12-11 17:57 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-24 14:27 . 2008-11-24 14:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\FlashFXP
2008-11-21 17:02 . 2008-11-22 04:53 120 --a------ c:\windows\AVAideDVDtomkv.ini
2008-11-21 16:18 . 2008-11-21 17:02 1 --a------ c:\windows\system32\AvaideDVDtomkv.dat
2008-11-19 23:22 . 2008-11-19 23:22 <DIR> d-------- c:\program files\Total Video Converter
2008-11-19 05:55 . 2003-03-13 12:51 1,461 --a------ c:\windows\system32\drivers\camcodec.inf
2008-11-19 05:31 . 2008-12-18 23:03 <DIR> d-------- c:\program files\NIIT - Test Engine
2008-11-19 05:30 . 2008-12-18 23:03 <DIR> d-------- c:\program files\Online Testing Database
2008-11-19 05:28 . 2008-11-19 05:31 288 --a------ c:\windows\ODBC.INI
2008-11-19 05:27 . 2008-12-18 23:03 <DIR> d-------- c:\program files\NIIT - Administration
2008-11-19 05:27 . 2008-11-19 05:30 286,720 --------- c:\windows\Setup1.exe
2008-11-19 05:27 . 2008-12-13 15:00 73,216 --a------ c:\windows\ST6UNST.EXE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-19 07:20 --------- d-----w c:\documents and settings\User\Application Data\DMCache
2008-12-19 07:03 --------- d-----w c:\program files\MyPhoneExplorer
2008-12-19 02:11 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-12-19 00:03 --------- d-----w c:\documents and settings\User\Application Data\SolidDocuments
2008-12-18 00:56 --------- d-----w c:\documents and settings\User\Application Data\MyPhoneExplorer
2008-12-17 06:04 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-12 01:29 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-10 23:18 --------- d-----w c:\program files\Common Files\Ahead
2008-11-24 19:31 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-18 08:38 --------- d-----w c:\program files\Free Hide Folder
2008-11-18 08:03 --------- d-----w c:\program files\Creative
2008-11-18 00:02 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-17 22:18 --------- d-----w c:\documents and settings\User\Application Data\Yahoo!
2008-11-16 21:56 --------- d-----w c:\documents and settings\User\Application Data\Talkback
2008-11-16 20:12 --------- d--h--r c:\documents and settings\User\Application Data\SecuROM
2008-11-16 11:03 --------- d-----w c:\program files\Intel
2008-11-15 08:42 --------- d-----w c:\program files\TuneUp Utilities 2007
2008-11-15 07:49 --------- d-----w c:\program files\Common Files\Teleca Shared
2008-11-11 19:51 --------- d-----w c:\program files\AusLogics Disk Defrag
2008-11-11 08:25 --------- d-----w c:\documents and settings\User\Application Data\Ahead
2008-11-11 04:31 --------- d-----w c:\documents and settings\User\Application Data\AdobeUM
2008-11-10 04:16 --------- d-----w c:\documents and settings\User\Application Data\Media Player Classic
2008-11-10 02:34 --------- d-----w c:\program files\MagicDisc
2008-11-10 02:33 --------- d-----w c:\program files\MagicISO
2008-11-10 02:20 --------- d-----w c:\program files\SolidDocuments
2008-11-10 02:17 --------- d-----w c:\documents and settings\All Users\Application Data\SolidDocuments
2008-11-10 02:12 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-10 02:12 --------- d-----w c:\documents and settings\User\Application Data\TuneUp Software
2008-11-10 02:12 --------- d-----w c:\documents and settings\All Users\Application Data\TuneUp Software
2008-11-10 02:09 --------- d-----w c:\program files\Common Files\Adobe
2008-11-10 02:07 --------- d-----w c:\program files\MP3Cutter
2008-11-10 01:56 --------- d-----w c:\program files\Microsoft Works
2008-11-10 01:14 315,392 ----a-w c:\windows\HideWin.exe
2008-11-10 01:14 --------- d-----w c:\program files\Realtek
2008-11-10 01:03 --------- d-----w c:\program files\MSXML 4.0
2008-11-10 00:25 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-12-04 2741680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-12 114688]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-07 136600]
"AVG8_TRAY"="c:\progra~1\AVG8\avgtray.exe" [2008-12-18 1234712]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-12 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-03-12 c:\windows\SkyTel.exe]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKLM\~\startupfolder\C:^Documents and Settings^User^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\documents and settings\User\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Nero BackItUp Scheduler 4.0"=2 (0x2)
"usnjsvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Internet Download Manager\\IEMonitor.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\jusched.exe"=
"c:\\Program Files\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-18 97928]
R1 HFCore;HFCore;\??\c:\windows\system32\drivers\HFCore.sys [2006-03-22 13696]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG8\avgemc.exe [2008-12-18 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG8\avgwdsvc.exe [2008-12-18 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-12-18 76040]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\DRIVERS\s115bus.sys [2008-11-10 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s115mdfl.sys [2008-11-10 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s115mdm.sys [2008-11-10 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s115mgmt.sys [2008-11-10 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s115obex.sys [2008-11-10 98568]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2008-01-25 25088]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-11-25 935208]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2008-12-13 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 16:53]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {592E5CAF-0EA5-4A79-9DCD-CE5F69A50425} = 218.248.255.194 218.248.255.139
TCP: {BBD5C0DA-7DE3-41E0-B6ED-D05B222739ED} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\5up6mnlb.default\
FF - prefs.js: browser.startup.homepage - about blank
FF - component: c:\documents and settings\User\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
ATTENTION: FIREFOX POLICES IS IN FORCE
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.rights.version", 3);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.rights.3.shown", false);
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-18 23:28:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\netdde.exe
c:\program files\AVG8\avgrsx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
c:\windows\system32\wdfmgr.exe
c:\program files\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2008-12-18 23:34:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-19 07:34:17
Pre-Run: 1,350,189,056 bytes free
Post-Run: 1,378,406,400 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
238 --- E O F --- 2008-11-16 08:25:25
Have you done the Eset online scan? If so, please post me the logs as well.[/quote]
Edited by chickov, 18 December 2008 - 11:22 PM.