Oh, sorry about that. Here's the text.
ComboFix 09-07-14.07 - Administrator 07/15/2009 21:17.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3198.2866 [GMT -4:00]
Running from: e:\inbound\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\documents and settings\Administrator\Local Settings\Temporary Internet Files\fbk.sts
d:\recycler\S-1-5-21-1454471165-1580818891-682003330-500
d:\windows\system32\drivers\hjgruiixbnesde.sys
d:\windows\system32\hjgruiiwtavebd.dat
d:\windows\system32\hjgruilukqehbk.dll
d:\windows\system32\hjgruitvqyxbnn.dll
d:\windows\system32\hjgruiuhagfckb.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_hjgruimisakaom
((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 )))))))))))))))))))))))))))))))
.
2009-07-15 02:18 . 2009-07-15 02:19 ——– d—–w- d:\program files\Microsoft Games for Windows - LIVE
2009-07-15 02:18 . 2009-07-15 02:18 ——– d—–w- d:\windows\system32\xlive
2009-07-15 02:12 . 2009-07-15 02:12 ——– d—–w- d:\windows\8AAB4176A747493AA42CB63CFADFD8E3.TMP
2009-07-15 02:09 . 2008-12-30 11:29 4984 —-a-w- d:\windows\system32\drivers\nvphy.bin
2009-07-15 02:09 . 2008-12-30 11:29 446464 —-a-w- d:\windows\system32\nvunrm.exe
2009-07-14 01:26 . 2009-07-14 01:55 ——– d—–w- d:\documents and settings\Administrator\Application Data\Apple Computer
2009-07-14 01:26 . 2009-03-19 20:32 23400 —-a-w- d:\windows\system32\drivers\GEARAspiWDM.sys
2009-07-14 01:26 . 2008-04-17 16:12 107368 —-a-w- d:\windows\system32\GEARAspi.dll
2009-07-14 01:25 . 2009-07-14 01:26 ——– d—–w- d:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-14 01:25 . 2009-07-14 01:25 ——– d—–w- d:\program files\Bonjour
2009-07-14 01:25 . 2009-07-14 01:25 ——– d—–w- d:\documents and settings\All Users\Application Data\Apple Computer
2009-07-14 01:25 . 2009-07-14 01:25 ——– d—–w- d:\program files\QuickTime
2009-07-14 01:25 . 2009-07-14 01:25 ——– d—–w- d:\documents and settings\Administrator\Local Settings\Application Data\Apple
2009-07-14 01:25 . 2009-07-14 01:25 ——– d—–w- d:\program files\Apple Software Update
2009-07-14 01:25 . 2009-07-14 01:25 ——– d—–w- d:\program files\Common Files\Apple
2009-07-14 01:25 . 2009-07-14 01:25 ——– d—–w- d:\documents and settings\All Users\Application Data\Apple
2009-07-14 01:24 . 2009-07-14 01:26 ——– d—–w- d:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2009-07-13 06:07 . 2009-07-13 06:07 ——– d—–w- d:\documents and settings\Administrator\Application Data\DAEMON Tools Lite
2009-07-13 04:29 . 2009-07-13 04:29 664 —-a-w- d:\windows\system32\d3d9caps.dat
2009-07-13 00:26 . 2006-11-01 17:06 162616 —-a-w- D:\RegDelNull.exe
2009-07-12 22:50 . 2004-05-04 16:53 1645320 —-a-w- d:\windows\system32\gdiplus.dll
2009-07-12 19:56 . 2009-07-12 22:46 ——– d—–w- d:\program files\Common Files\Nero
2009-07-10 23:30 . 2009-07-16 00:31 ——– d—–w- d:\windows\system32\NtmsData
2009-07-08 16:35 . 2004-12-19 00:32 38229 ——w- d:\windows\system32\drivers\StMp3Rec.sys
2009-07-08 16:32 . 2009-07-08 16:32 ——– d—–w- d:\windows\Downloaded Installations
2009-07-01 18:39 . 2009-07-01 18:39 ——– d—–w- d:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-06-19 03:05 . 2009-06-19 03:05 ——– d—–w- d:\documents and settings\Administrator\Local Settings\Application Data\Fallout3
2009-06-19 02:43 . 2008-09-16 22:20 121064 ——r- d:\documents and settings\All Users\Application Data\Fallout3\setup.exe
2009-06-19 02:43 . 2009-06-19 02:43 ——– d—–w- d:\documents and settings\All Users\Application Data\Fallout3
2009-06-18 23:50 . 2009-06-18 23:50 ——– d—–w- d:\documents and settings\Administrator\Local Settings\Application Data\Aspyr
2009-06-18 22:23 . 1997-12-17 22:33 304128 —-a-w- d:\windows\IsUninst.exe
2009-06-16 05:35 . 2009-06-16 05:53 96104 —-a-w- d:\windows\system32\drivers\avipbb.sys
2009-06-16 05:35 . 2009-02-13 15:29 22360 —-a-w- d:\windows\system32\drivers\avgntmgr.sys
2009-06-16 05:35 . 2009-02-13 15:17 45416 —-a-w- d:\windows\system32\drivers\avgntdd.sys
2009-06-16 05:24 . 2009-06-16 05:53 55640 —-a-w- d:\windows\system32\drivers\avgntflt.sys
2009-06-16 05:24 . 2009-06-16 05:35 ——– d—–w- d:\documents and settings\All Users\Application Data\Avira
2009-06-16 05:16 . 2009-06-16 05:16 ——– d—–w- d:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-06-16 05:14 . 2009-07-13 20:14 716272 —-a-w- d:\windows\system32\drivers\sptd.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-15 12:07 . 2009-02-26 15:58 ——– d—–w- d:\documents and settings\Administrator\Application Data\uTorrent
2009-07-15 02:12 . 2009-02-26 15:36 ——– d—–w- d:\program files\Common Files\Wise Installation Wizard
2009-07-08 16:32 . 2009-02-26 14:41 ——– d—–w- d:\program files\Common Files\InstallShield
2009-06-30 02:48 . 2009-05-25 23:51 53248 —-a-w- d:\documents and settings\All Users\Application Data\Owl King Publishing\Vantpl8\armaccess.dll
2009-06-20 00:32 . 2009-02-26 14:41 ——– d–h–w- d:\program files\InstallShield Installation Information
2009-06-18 23:48 . 2009-05-25 18:22 107888 —-a-w- d:\windows\system32\CmdLineExt.dll
2009-06-05 17:57 . 2009-06-05 17:57 75048 —-a-w- d:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-01 23:13 . 2009-06-01 23:13 ——– d—–w- d:\program files\Microsoft Synchronization Services
2009-06-01 23:13 . 2009-06-01 23:13 ——– d—–w- d:\program files\Microsoft SQL Server Compact Edition
2009-06-01 23:12 . 2009-06-01 23:05 ——– d—–w- d:\program files\Microsoft.NET
2009-06-01 23:12 . 2009-06-01 23:03 ——– d—–w- d:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-01 23:12 . 2009-06-01 23:12 18368 —-a-w- d:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2009-06-01 23:12 . 2009-06-01 23:12 1650944 —-a-w- d:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2009-06-01 23:11 . 2009-02-27 07:43 119776 —-a-w- d:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-01 23:10 . 2009-06-01 23:05 ——– d—–w- d:\program files\Common Files\Merge Modules
2009-06-01 23:10 . 2009-06-01 23:10 ——– d—–w- d:\documents and settings\All Users\Application Data\PreEmptive Solutions
2009-06-01 23:08 . 2009-06-01 23:05 ——– d—–w- d:\program files\HTML Help Workshop
2009-06-01 23:08 . 2009-06-01 23:02 ——– d—–w- d:\program files\MSBuild
2009-06-01 23:05 . 2009-06-01 23:05 ——– d—–w- d:\program files\Microsoft SDKs
2009-06-01 23:05 . 2009-06-01 23:05 ——– d—–w- d:\program files\CE Remote Tools
2009-06-01 23:04 . 2009-06-01 23:04 ——– d—–w- d:\program files\Microsoft Web Designer Tools
2009-06-01 23:03 . 2009-06-01 23:03 416 —-a-w- d:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2009-06-01 23:02 . 2009-06-01 23:02 ——– d—–w- d:\program files\Reference Assemblies
2009-05-26 03:50 . 2009-05-26 03:50 ——– d—–w- d:\documents and settings\Administrator\Application Data\PlayFirst
2009-05-26 03:49 . 2009-05-26 03:49 ——– d—–w- d:\documents and settings\Administrator\Application Data\Mind Control Software
2009-05-26 03:49 . 2009-05-26 03:49 ——– d—–w- d:\documents and settings\All Users\Application Data\TEMP
2009-05-26 03:33 . 2009-05-24 04:50 30 —-a-w- d:\windows\popcinfo.dat
2009-05-25 23:58 . 2009-05-25 23:58 ——– d—–w- d:\documents and settings\All Users\Application Data\Joyboost
2009-05-25 23:51 . 2009-05-25 23:51 ——– d—–w- d:\documents and settings\Administrator\Application Data\Owl King Publishing
2009-05-25 23:51 . 2009-05-25 23:51 ——– d—–w- d:\documents and settings\All Users\Application Data\Owl King Publishing
2009-05-25 23:49 . 2009-05-25 23:49 ——– d—–w- d:\documents and settings\Administrator\Application Data\mobileweapon
2009-05-25 23:46 . 2009-05-25 23:46 ——– d—–w- d:\program files\Trymedia
2009-05-25 05:19 . 2009-05-25 05:19 4096 —-a-w- d:\windows\d3dx.dat
2009-05-25 04:19 . 2009-05-25 04:19 ——– d—–w- d:\documents and settings\All Users\Application Data\Sandlot Games
2009-05-18 16:04 . 2009-05-18 16:04 ——– d—–w- d:\documents and settings\Administrator\Application Data\Thinstall
2009-05-07 03:03 . 2009-05-07 03:03 356352 —-a-w- d:\windows\eSellerateEngine.dll
2009-04-22 04:20 . 2009-04-22 04:20 14311680 —-a-w- d:\windows\system32\xlive.dll
2009-04-22 04:20 . 2009-04-22 04:20 13642496 —-a-w- d:\windows\system32\xlivefnt.dll
2009-04-08 01:04 . 2009-04-08 01:04 8 –sh–r- d:\windows\system32\7179956351.sys
2009-04-08 01:10 . 2009-04-08 01:04 952 –sha-w- d:\windows\system32\KGyGaAvL.sys
.
——- Sigcheck ——-
[-] 2008-12-30 04:52 361600 5AE1C2695F6523AD98B948F2887D8C5E d:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2009-01-16 13680640]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2009-01-16 86016]
"nwiz"="nwiz.exe" - d:\windows\system32\nwiz.exe [2009-01-16 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" - d:\windows\system32\advpack.dll [2008-04-14 99840]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-09-16 13:44 174328 —-a-w- d:\apps\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=d:\windows\system32\wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)
"VSS"=3 (0x3)
"UPS"=3 (0x3)
"TapiSrv"=3 (0x3)
"SwPrv"=3 (0x3)
"stisvc"=3 (0x3)
"srservice"=2 (0x2)
"Spooler"=3 (0x3)
"SCardSvr"=3 (0x3)
"PSI_SVC_2"=2 (0x2)
"ProtexisLicensing"=2 (0x2)
"ose"=3 (0x3)
"NtLmSsp"=3 (0x3)
"mnmsrvc"=3 (0x3)
"idsvc"=3 (0x3)
"gupdate1c9fa789592dabe"=2 (0x2)
"FontCache3.0.0.0"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"FastUserSwitchingCompatibility"=3 (0x3)
"aspnet_state"=3 (0x3)
"AntiVirWebService"=2 (0x2)
"seclogon"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\Apps\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;d:\apps\Avira\AntiVir Desktop\sched.exe [6/16/2009 1:35 AM 108289]
S2 LF30FS;LF30FS;\??\e:\apps\Lock\LF30XP.sys –> e:\apps\Lock\LF30XP.sys [?]
S3 Ambfilt;Ambfilt;d:\windows\system32\drivers\Ambfilt.sys [3/2/2009 6:24 PM 1684736]
S4 AntiVirMailService;Avira AntiVir MailGuard;d:\apps\Avira\AntiVir Desktop\avmailc.exe [6/16/2009 1:35 AM 194817]
S4 AntiVirWebService;Avira AntiVir WebGuard;d:\apps\Avira\AntiVir Desktop\avwebgrd.exe [6/16/2009 1:35 AM 434945]
S4 gupdate1c9fa789592dabe;Google Update Service (gupdate1c9fa789592dabe);"d:\program files\Google\Update\GoogleUpdate.exe" /svc –> d:\program files\Google\Update\GoogleUpdate.exe [?]
— Other Services/Drivers In Memory —
*NewlyCreated* - ASPI32
*NewlyCreated* - HELPSVC
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-avgnt - d:\apps\Avira\AntiVir PersonalEdition Premium\avgnt.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - d:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\v4m0cxhk.default\
FF - prefs.js: browser.startup.homepage - hxxp://en.wikipedia.org/wiki/Main_Page
FF - plugin: d:\apps\Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: d:\apps\Media\iTunes\Mozilla Plugins\npitunes.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-15 21:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(740)
d:\apps\WindowBlinds\wbsrv.dll
.
Completion time: 2009-07-16 21:24
ComboFix-quarantined-files.txt 2009-07-16 01:24
Pre-Run: 33,721,245,696 bytes free
Post-Run: 33,696,083,968 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(1)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noexecute=alwaysoff /usepmtimer
multi(0)disk(0)rdisk(0)partition(1)\WINXP="Microsoft Windows XP Professional" /fastdetect
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
209