ComboFix 09-01-21.04 - Jennifer 2009-01-27 17:14:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1448 [GMT -6:00]
Running from: c:\documents and settings\Jennifer\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
AV: Webroot AntiVirus with AntiSpyware *On-access scanning disabled* (Updated)
FW: Webroot Internet Security Essentials *disabled*
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-12-27 to 2009-01-27 )))))))))))))))))))))))))))))))
.
2009-01-26 20:03 . 2009-01-26 20:03 <DIR> d-------- c:\documents and settings\Jennifer\Application Data\Windows Search
2009-01-26 17:56 . 2009-01-26 17:56 <DIR> d--h----- c:\windows\PIF
2009-01-26 16:31 . 2009-01-26 16:31 <DIR> d-------- c:\documents and settings\Jennifer\Application Data\Windows Desktop Search
2009-01-26 16:29 . 2008-03-07 11:02 192,000 --------- c:\windows\system32\dllcache\offfilt.dll
2009-01-26 16:29 . 2008-03-07 11:02 98,304 --------- c:\windows\system32\dllcache\nlhtml.dll
2009-01-26 16:29 . 2008-03-07 11:02 29,696 --------- c:\windows\system32\dllcache\mimefilt.dll
2009-01-24 21:33 . 2009-01-24 23:35 250 --a------ c:\windows\gmer.ini
2009-01-24 13:28 . 2009-01-24 13:28 <DIR> d-------- C:\rsit
2009-01-24 13:28 . 2009-01-26 00:44 <DIR> d-------- c:\program files\trend micro
2009-01-24 13:20 . 2009-01-24 13:20 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-24 13:20 . 2009-01-24 13:20 <DIR> d-------- c:\documents and settings\Jennifer\Application Data\Malwarebytes
2009-01-24 13:20 . 2009-01-24 13:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-24 13:20 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-24 13:20 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-24 13:19 . 2009-01-24 13:20 2,737,800 --a------ c:\program files\mbam-setup.exe
2009-01-23 18:05 . 2009-01-23 18:15 <DIR> d-------- c:\program files\Friendbar
2009-01-21 13:22 . 2009-01-21 13:22 <DIR> d-------- c:\documents and settings\Guest\Application Data\Webroot
2009-01-19 17:36 . 2009-01-19 17:36 <DIR> d-------- c:\program files\Microsoft
2009-01-19 17:34 . 2009-01-19 17:34 <DIR> d-------- c:\windows\system32\GroupPolicy
2009-01-19 17:34 . 2009-01-26 16:31 <DIR> d-------- c:\program files\Windows Desktop Search
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-27 22:09 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-01-27 22:08 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-27 22:08 107,272 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-27 07:03 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-26 00:47 --------- d-----w c:\program files\Lavasoft
2009-01-26 00:47 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-26 00:45 --------- d-----w c:\program files\Paint.NET
2009-01-26 00:44 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-26 00:44 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-01-26 00:44 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-25 07:59 --------- d-----w c:\documents and settings\Jennifer\Application Data\U3
2009-01-20 23:57 --------- d-----w c:\program files\wildblue
2009-01-17 08:27 --------- d-----w c:\program files\Google
2009-01-14 05:05 --------- d-----w c:\documents and settings\Jennifer\Application Data\Move Networks
2009-01-01 08:30 --------- d-----w c:\documents and settings\Jennifer\Application Data\uTorrent
2008-12-25 18:58 164 ----a-w C:\install.dat
2008-12-17 22:31 --------- d-----w c:\program files\Java
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-11-13 23:11 1,553,272 ----a-w c:\windows\WRSetup.dll
2008-04-03 21:28 1,630,151 ----a-w c:\program files\Setup_AltoMP3Gold.exe
2007-12-27 20:03 2,377,626 ----a-w c:\program files\wildblue.zip
2007-12-27 19:03 14,651,472 ----a-w c:\program files\SpySweeperRegSetup_EN.exe
2007-06-02 20:21 21,407,888 ----a-w c:\program files\avg75free_467a1008.exe
2005-12-13 08:07 2,855,080 ----a-w c:\program files\aawsepersonal.exe
2007-12-20 16:30 76 --sh--r c:\windows\CT4CET.bin
2008-10-02 22:58 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008100220081003\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 17:04 238968 --a------ c:\program files\Webroot\Spy Sweeper\Backup\CtxMenu_1_0_0_10.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-20 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-09 851968]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-06 8429568]
"nwiz"="c:\windows\system32\nwiz.exe" [2007-06-06 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-06 81920]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-08-28 36864]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-07-03 1228800]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-05-09 1392640]
"SigmatelSysTrayApp"="c:\windows\stsystra.exe" [2007-07-09 405504]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-20 1838592]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-24 17920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-27 1601304]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-17 136600]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-11-13 6273400]
"NVHotkey"="nvHotkey.dll" [2007-06-06 c:\windows\system32\nvhotkey.dll]
c:\documents and settings\Jennifer\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk.disabled [2008-02-14 947]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-20 50688]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-27 16:08 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe"
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-08-09 29808]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-05-12 325128]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-05-12 107272]
R3 OEM02Afx;Provides a software interface to control audio effects of OEM002 camera.;c:\windows\system32\drivers\OEM02Afx.sys [2007-12-20 141376]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [2007-12-20 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [2007-12-20 7424]
R4 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-03 903960]
R4 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-03 298264]
R4 WRConsumerService;Webroot Client Service;c:\program files\Webroot\Spy Sweeper\WRConsumerService.exe [2008-11-04 1086840]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{78e2bd95-d472-11dd-a24a-001d09aed37c}]
\Shell\AutoRun\command - G:\LinksysConnectPC.exe
.
Contents of the 'Scheduled Tasks' folder
2009-01-27 c:\windows\Tasks\wrSpySweeper_L682DCEC5D84741F98697F43757F82074.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-11-13 17:11]
2009-01-27 c:\windows\Tasks\wrSpySweeper_L682DCEC5D84741F98697F43757F82074.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-11-13 17:11]
2009-01-27 c:\windows\Tasks\wrSpySweeper_L682DCEC5D84741F98697F43757F82074.job
- C:\ [2009-01-27 17:16]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{9A05C602-D252-443A-9997-E86A99B610E2} - (no file)
HKCU-Run-Aim6 - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2071220
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: wildblue.net\myaccount
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-27 17:18:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\windows\system32\searchindexer.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-01-27 17:24:06 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-27 23:24:03
Pre-Run: 83,794,014,208 bytes free
Post-Run: 83,962,265,600 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
201 --- E O F --- 2009-01-14 01:04:46