ComboFix 09-02-04.01 - Gordon Wilder 2009-02-04 23:18:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.0.1252.1.1033.18.511.279 [GMT -8:00]
Running from: c:\documents and settings\Gordon Wilder\desktop\combofix.exe
Command switches used :: /killall
AV: AVG *On-access scanning disabled* (Outdated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\regedit.com
c:\windows\system32\open.ico
.
((((((((((((((((((((((((( Files Created from 2009-01-05 to 2009-02-05 )))))))))))))))))))))))))))))))
.
2009-02-04 20:43 . 2007-06-28 23:43 123,602 --a------ c:\windows\system32\nvapps.nvb
2009-02-04 20:34 . 2001-08-23 04:00 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
2009-02-04 20:33 . 2001-08-23 04:00 10,096,640 --a--c--- c:\windows\system32\dllcache\hwxcht.dll
2009-02-04 20:32 . 2001-05-22 21:15 872,557 --a--c--- c:\windows\system32\dllcache\fp4awel.dll
2009-02-04 20:27 . 2001-08-23 04:00 3,346,432 --a--c--- c:\windows\system32\dllcache\msgr3en.dll
2009-02-04 20:27 . 2001-08-23 04:00 794,686 --a--c--- c:\windows\system32\dllcache\srchui.dll
2009-02-04 20:27 . 2001-08-23 04:00 405,504 --a--c--- c:\windows\system32\dllcache\swflash.ocx
2009-02-04 20:27 . 2001-08-23 04:00 106,562 --a--c--- c:\windows\system32\dllcache\srchctls.dll
2009-02-04 20:27 . 2009-02-04 20:27 749 -rah----- c:\windows\WindowsShell.Manifest
2009-02-04 20:27 . 2009-02-04 20:27 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2009-02-04 20:27 . 2009-02-04 20:27 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2009-02-04 20:27 . 2009-02-04 20:27 749 -rah----- c:\windows\system32\nwc.cpl.manifest
2009-02-04 20:27 . 2009-02-04 20:27 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2009-02-04 20:27 . 2009-02-04 20:27 488 -rah----- c:\windows\system32\logonui.exe.manifest
2009-02-04 20:25 . 2001-08-23 04:00 1,266,688 --a--c--- c:\windows\system32\dllcache\cimwin32.dll
2009-02-04 20:23 . 2001-08-17 13:59 50,048 --a------ c:\windows\system32\drivers\DMusic.sys
2009-02-04 20:23 . 2001-08-17 14:00 5,632 --a------ c:\windows\system32\drivers\splitter.sys
2009-02-04 20:22 . 2001-08-17 13:51 55,808 --a------ c:\windows\system32\drivers\redbook.sys
2009-02-04 20:20 . 2001-08-17 13:50 181,632 --a------ c:\windows\system32\drivers\rdpdr.sys
2009-02-04 20:20 . 2001-08-17 22:38 37,896 --a------ c:\windows\system32\drivers\termdd.sys
2009-02-04 16:53 . 2009-02-04 16:53 <DIR> d-------- c:\documents and settings\Gordon Wilder\Application Data\AVGTOOLBAR
2009-02-03 21:31 . 2009-02-03 21:31 26,624 --a------ c:\windows\system32\drivers\fsbts.sys
2009-01-28 17:37 . 2009-01-28 17:37 <DIR> d-------- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-05 00:50 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-02-04 00:16 --------- d-----w c:\program files\PokerStars
2009-02-03 03:39 --------- d-----w c:\program files\Full Tilt Poker
2009-01-30 00:21 --------- d-----w c:\program files\SpywareBlaster
2009-01-20 05:00 --------- d-----w c:\program files\SpywareGuard
2008-12-22 19:27 --------- d-----w c:\program files\Google
2008-12-16 02:21 --------- d-----w c:\program files\Java
2008-12-10 03:10 --------- d-----w c:\documents and settings\All Users\Application Data\IM
2008-12-10 03:09 --------- d-----w c:\documents and settings\All Users\Application Data\IncrediMail
2007-04-11 05:26 32 -c--a-r c:\documents and settings\All Users\hash.dat
.
------- Sigcheck -------
2008-04-13 10:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\system32\drivers\ip6fw.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 81920]
"ctfmon.exe"="c:\windows\System32\ctfmon.exe" [2001-08-23 13312]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinIt"="c:\program files\ImageIt\ItRun.EXE" [2003-06-25 434176]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-15 136600]
"tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" [2007-03-07 1773568]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AudioDeck.lnk - c:\program files\VIA\VIA Sound Player\mixer\AudioDeck_bmp.exe [2005-11-19 466944]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2009-02-03 26624]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-06-11 282904]
R2 FSHOOK;FSHOOK;c:\windows\system32\drivers\FSHOOK.SYS [2005-11-19 7040]
R3 EUCR;ENE USB Mass Storage;c:\windows\system32\drivers\EUCR6SK.sys [2007-06-22 42240]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys --> c:\windows\System32\Drivers\avgldx86.sys [?]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe --> c:\progra~1\AVG\AVG8\avgemc.exe [?]
S2 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys --> c:\windows\System32\Drivers\avgtdix.sys [?]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\documents and settings\Gordon Wilder\Local Settings\Temp\{63F0F3BD-5B45-44E3-AF18-0003C5DD213D}\fsgk.sys --> c:\documents and settings\Gordon Wilder\Local Settings\Temp\{63F0F3BD-5B45-44E3-AF18-0003C5DD213D}\fsgk.sys [?]
S3 iteio;iteio;c:\windows\system32\drivers\Iteio.sys [2005-11-19 3680]
S3 Vsp;Vsp;c:\windows\system32\drivers\VSP.sys [2005-11-19 3351]
.
Contents of the 'Scheduled Tasks' folder
2007-03-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 14:42]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
HKCU-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
HKLM-Run-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
SharedTaskScheduler-{A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
FF - ProfilePath - c:\documents and settings\Gordon Wilder\Application Data\Mozilla\Firefox\Profiles\tc11s4m1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-04 23:25:32
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\.application\bootstrap]
@DACL=(02 0000)
@="bootstrap.application.1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(636)
c:\windows\system32\ODBC32.dll
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
- - - - - - - > 'lsass.exe'(692)
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
c:\windows\System32\dssenh.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\WgaTray.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Completion time: 2009-02-04 23:29:19 - machine was rebooted [Gordon Wilder]
ComboFix-quarantined-files.txt 2009-02-05 07:28:09
Pre-Run: 94,006,427,648 bytes free
Post-Run: 95,396,761,600 bytes free
163 --- E O F --- 2009-01-14 06:12:48