ComboFix 08-03-22.1 - Dave 2008-03-22 21:51:41.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.277 [GMT -4:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\Dave\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
C:\Windows\system32\dmeve.tmp
C:\Windows\system32\dmfeo.tmp
C:\Windows\system32\dmizw.tmp
C:\Windows\system32\dmrkr.tmp
C:\Windows\system32\dmuhw.exe
C:\Windows\system32\dmyyv.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Bonjour
C:\Program Files\Bonjour\About Bonjour.rtf
C:\Program Files\Bonjour\mdnsNSP.dll
C:\Program Files\Bonjour\mDNSResponder.exe
C:\ProgramData\Spybot - Search & Destroy
C:\ProgramData\Spybot - Search & Destroy\Logs\Checks.080304-2036.log
C:\ProgramData\Spybot - Search & Destroy\Logs\Checks.080304-2049.txt
C:\ProgramData\Spybot - Search & Destroy\Logs\Checks.080304-2057.log
C:\ProgramData\Spybot - Search & Destroy\Logs\Checks.080304-2108.txt
C:\ProgramData\Spybot - Search & Destroy\Logs\Checks.080306-1809.log
C:\ProgramData\Spybot - Search & Destroy\Logs\Checks.080306-1820.txt
C:\ProgramData\Spybot - Search & Destroy\Logs\Fixes.080304-2051.txt
C:\ProgramData\Spybot - Search & Destroy\Logs\Fixes.080304-2108.txt
C:\ProgramData\Spybot - Search & Destroy\Logs\Fixes.080306-1849.txt
C:\ProgramData\Spybot - Search & Destroy\Logs\Resident.log
C:\ProgramData\Spybot - Search & Destroy\Logs\Update downloads.log
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDNSChanger.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDNSChanger1.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDNSChanger2.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDNSChanger3.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDNSChanger4.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDNSChanger5.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDownloadersot.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDownloadersot1.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDownloadersot2.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDownloadersot3.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDownloadersot4.zip
C:\Program Files\Windows Defender . . . . failed to delete
C:\Program Files\Windows Defender\en-US\MpAsDesc.dll.mui . . . . failed to delete
C:\Program Files\Windows Defender\en-US\MpEvMsg.dll.mui . . . . failed to delete
C:\Program Files\Windows Defender\en-US\MsMpRes.dll.mui . . . . failed to delete
C:\Program Files\Windows Defender\MpAsDesc.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpClient.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpCmdRun.exe . . . . failed to delete
C:\Program Files\Windows Defender\MpEvMsg.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpOAV.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpRtMon.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpRtPlug.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpSigDwn.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpSoftEx.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpSvc.dll . . . . failed to delete
C:\Program Files\Windows Defender\MSASCui.exe . . . . failed to delete
C:\Program Files\Windows Defender\MsMpCom.dll . . . . failed to delete
C:\Program Files\Windows Defender\MsMpLics.dll . . . . failed to delete
C:\Program Files\Windows Defender\MsMpRes.dll . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-02-23 to 2008-03-23 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-21 20:51 319,456 —-a-w C:\Windows\DIFxAPI.dll
2008-03-21 20:51 315,392 —-a-w C:\Windows\HideWin.exe
2008-03-21 20:51 ——— d—–w C:\Program Files\Realtek
2008-03-21 12:27 ——— d—–w C:\Users\Dave\AppData\Roaming\AVG7
2008-03-16 23:42 ——— d—–w C:\Program Files\Java
2008-03-13 16:33 53,768 —-a-w C:\Windows\system32\drivers\avgwfp.sys
2008-03-07 01:16 ——— d—–w C:\Users\Dave\AppData\Roaming\WinBatch
2008-03-07 01:12 ——— d—–w C:\Program Files\Trend Micro
2008-03-05 10:11 ——— d—–w C:\ProgramData\avg7
2008-03-05 01:15 ——— d—–w C:\Program Files\CleanUp!
2008-03-05 01:13 ——— d—–w C:\Users\Dave\AppData\Roaming\Grisoft
2008-03-05 00:54 ——— d—–w C:\Program Files\InterMute
2008-03-05 00:49 ——— d—–w C:\ProgramData\Lavasoft
2008-03-05 00:48 ——— d—–w C:\Program Files\Lavasoft
2008-03-05 00:47 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-05 00:40 ——— d—–w C:\ProgramData\Grisoft
2008-03-05 00:34 9,216 —-a-w C:\Windows\System32\avgwlntf.dll
2008-03-05 00:18 ——— d—–w C:\ProgramData\Symantec
2008-03-05 00:17 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-05 00:14 ——— d—–w C:\Program Files\Norton Internet Security
2008-03-05 00:12 ——— d—–w C:\Program Files\Symantec
2008-03-01 22:14 ——— d—–w C:\Users\Dave\AppData\Roaming\Apple Computer
2008-03-01 22:13 ——— d—–w C:\ProgramData\Apple Computer
2008-03-01 22:13 ——— d—–w C:\Program Files\iTunes
2008-03-01 22:13 ——— d—–w C:\Program Files\iPod
2008-03-01 22:12 ——— d—–w C:\Program Files\QuickTime
2008-03-01 22:10 ——— d—–w C:\Program Files\Apple Software Update
2008-03-01 22:09 ——— d—–w C:\ProgramData\Apple
2008-03-01 22:09 ——— d—–w C:\Program Files\Common Files\Apple
2008-02-29 23:52 994 —-a-w C:\Users\Dave\AppData\Roaming\wklnhst.dat
2008-02-29 09:12 174 –sha-w C:\Program Files\desktop.ini
2008-02-29 09:08 ——— d—–w C:\Program Files\Windows Sidebar
2008-02-29 09:08 ——— d—–w C:\Program Files\Windows Mail
2008-02-29 09:08 ——— d—–w C:\Program Files\Windows Defender
2008-02-29 09:08 ——— d—–w C:\Program Files\Windows Calendar
2008-02-29 04:09 ——— d—–w C:\ProgramData\WildTangent
2008-02-29 04:08 ——— d—–w C:\Program Files\Microsoft Works
2008-02-29 04:08 ——— d—–w C:\Program Files\Common Files\SureThing Shared
2008-02-29 04:01 ——— d—–w C:\Program Files\HP
2008-02-29 02:17 704,000 —-a-w C:\Windows\System32\PhotoScreensaver.scr
2008-02-29 02:17 67,584 —-a-w C:\Windows\System32\wlanhlp.dll
2008-02-29 02:17 542,720 —-a-w C:\Windows\System32\sysmain.dll
2008-02-29 02:17 502,784 —-a-w C:\Windows\System32\wlansvc.dll
2008-02-29 02:17 47,104 —-a-w C:\Windows\System32\wlanapi.dll
2008-02-29 02:17 297,984 —-a-w C:\Windows\System32\wlansec.dll
2008-02-29 02:17 290,816 —-a-w C:\Windows\System32\wlanmsm.dll
2008-02-29 02:17 258,232 —-a-w C:\Windows\system32\drivers\acpi.sys
2008-02-29 02:17 24,064 —-a-w C:\Windows\System32\wtsapi32.dll
2008-02-29 02:17 2,923,520 —-a-w C:\Windows\explorer.exe
2008-02-29 02:17 2,027,008 —-a-w C:\Windows\System32\win32k.sys
2008-02-29 02:16 49,664 —-a-w C:\Windows\System32\csrsrv.dll
2008-02-29 02:16 376,320 —-a-w C:\Windows\System32\winsrv.dll
2008-02-29 02:16 194,560 —-a-w C:\Windows\System32\WebClnt.dll
2008-02-29 02:16 110,080 —-a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-29 02:08 8,147,968 —-a-w C:\Windows\System32\wmploc.DLL
2008-02-29 02:08 7,680 —-a-w C:\Windows\System32\spwmp.dll
2008-02-29 02:08 4,096 —-a-w C:\Windows\System32\dxmasf.dll
2008-02-29 02:08 356,864 —-a-w C:\Windows\System32\MediaMetadataHandler.dll
2008-02-29 02:07 86,016 —-a-w C:\Windows\System32\icfupgd.dll
2008-02-29 02:07 63,488 —-a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-02-29 02:07 61,952 —-a-w C:\Windows\System32\cmifw.dll
2008-02-29 02:07 396,800 —-a-w C:\Windows\System32\MPSSVC.dll
2008-02-29 02:07 392,192 —-a-w C:\Windows\System32\FirewallAPI.dll
2008-02-29 02:07 23,040 —-a-w C:\Windows\system32\drivers\tunnel.sys
2008-02-29 02:07 178,688 —-a-w C:\Windows\System32\iphlpsvc.dll
2008-02-29 02:07 16,896 —-a-w C:\Windows\System32\wfapigp.dll
2008-02-29 02:07 15,360 —-a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-02-29 02:06 45,112 —-a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-29 02:06 3,504,696 —-a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-29 02:06 3,470,392 —-a-w C:\Windows\System32\ntoskrnl.exe
2008-02-29 02:06 211,000 —-a-w C:\Windows\system32\drivers\volsnap.sys
2008-02-29 02:06 21,560 —-a-w C:\Windows\system32\drivers\atapi.sys
2008-02-29 02:06 154,624 —-a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-29 02:06 15,928 —-a-w C:\Windows\system32\drivers\pciide.sys
2008-02-29 02:06 109,624 —-a-w C:\Windows\system32\drivers\ataport.sys
2008-02-29 02:06 1,191,936 —-a-w C:\Windows\System32\msxml3.dll
2008-02-29 02:06 1,060,920 —-a-w C:\Windows\system32\drivers\ntfs.sys
2008-02-29 02:05 803,328 —-a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-29 02:05 24,064 —-a-w C:\Windows\System32\netcfg.exe
2008-02-29 02:05 22,016 —-a-w C:\Windows\System32\netiougc.exe
2008-02-29 02:05 216,632 —-a-w C:\Windows\system32\drivers\netio.sys
2008-02-29 02:05 167,424 —-a-w C:\Windows\System32\tcpipcfg.dll
2008-02-29 02:04 9,728 —-a-w C:\Windows\System32\LAPRXY.DLL
2008-02-29 02:04 223,232 —-a-w C:\Windows\System32\WMASF.DLL
2008-02-29 02:04 1,327,104 —-a-w C:\Windows\System32\quartz.dll
2008-02-29 02:03 57,856 —-a-w C:\Windows\System32\SLUINotify.dll
2008-02-29 02:03 566,784 —-a-w C:\Windows\System32\SLCommDlg.dll
2008-02-29 02:03 39,936 —-a-w C:\Windows\System32\slcinst.dll
2008-02-29 02:03 351,232 —-a-w C:\Windows\System32\SLUI.exe
2008-02-29 02:03 33,280 —-a-w C:\Windows\System32\slwmi.dll
2008-02-29 02:03 268,288 —-a-w C:\Windows\System32\mcbuilder.exe
2008-02-29 02:03 223,232 —-a-w C:\Windows\System32\SLC.dll
2008-02-29 02:03 2,605,568 —-a-w C:\Windows\System32\SLsvc.exe
2008-02-29 02:03 186,368 —-a-w C:\Windows\System32\SLLUA.exe
2008-02-29 02:02 1,335,296 —-a-w C:\Windows\System32\msxml6.dll
2008-02-29 02:00 53,760 —-a-w C:\Windows\system32\drivers\hdaudbus.sys
2008-02-29 02:00 11,776 —-a-w C:\Windows\System32\sbunattend.exe
2008-02-29 01:59 84,992 —-a-w C:\Windows\system32\drivers\srvnet.sys
2008-02-29 01:59 788,992 —-a-w C:\Windows\System32\rpcrt4.dll
2008-02-29 01:59 58,368 —-a-w C:\Windows\system32\drivers\mrxsmb20.sys
.
((((((((((((((((((((((((((((( snapshot@2008-03-22_21.10.59.99 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-23 00:05:52 67,584 –s-a-w C:\Windows\bootstat.dat
+ 2008-03-23 01:56:08 67,584 –s-a-w C:\Windows\bootstat.dat
- 2008-03-23 00:21:07 262,144 —-a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
+ 2008-03-23 01:21:03 262,144 —-a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
- 2008-03-23 00:07:31 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-03-23 01:56:47 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
- 2008-03-23 01:07:13 262,144 —-a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-03-23 01:51:19 262,144 —-a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-03-23 00:07:25 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-03-23 01:56:47 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-28 22:00 1232896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-03-22 21:54 1006264]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 09:42 65536]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 11:16 65536]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 11:26 4874240 C:\Windows\RtHDVCpl.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 03:11 49152]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-06 21:15 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-06 21:15 8466432]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-06 21:15 81920]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-04 20:38 579072]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25 6731312]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"PCDrProfiler"="C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe" [2006-09-25 21:18 53248]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-04 20:34 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2008-03-04 20:34 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2006-09-14 08:55 61440 C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2007-01-09 22:59 115816 c:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR]
–a—— 2006-11-16 18:59 1480296 C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-02-19 14:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
–a—— 2006-10-26 19:18 22696 c:\Program Files\Norton Internet Security\osCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-02-01 00:13 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3A6DFE6B-E9E0-4E74-B63C-0D01A665F747}"= UDP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{4692530B-2D39-4EAA-892F-7608206D35A3}"= TCP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{812FD908-75A7-402C-8540-1DCD09941946}"= UDP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{59AF12B0-7C58-4191-9C6B-2A4B207C1EBB}"= TCP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{DA9FA734-EBCE-4C21-AB53-0B45EEB1017C}"= C:\Program Files\HP Connections\6811507\Program\HP Connections:HP Connections
"{EEB11FFE-A941-4064-BC5E-98BE939C1495}"= UDP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{BEF4D838-9265-4970-81EC-43D1B60AC8C2}"= TCP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{43C5C446-506B-44F8-8553-6B133AA5AC3A}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{54D48CF0-132F-4D52-9BE2-DD20F81E1956}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{3A5C897F-AD18-4FAD-A376-3943EED7980E}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{4D71ED0C-EC8B-491C-9834-3DE7FB17D623}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{C56F3753-F64E-4641-B3F9-4198B85D0CD9}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{3C054790-59E5-40B7-8451-F668955BA75A}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"TCP Query User{AC0323F3-82C3-4185-ACE3-78D8B35A4E84}C:\\neverwinternights\\nwn\\nwmain.exe"= UDP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"UDP Query User{360C4A4C-A49E-4CD1-96C1-8125F2A6488F}C:\\neverwinternights\\nwn\\nwmain.exe"= TCP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"{9D39AC6B-6E92-4B67-B214-DD93D6A222D0}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{2165788A-6B7D-4139-BECE-DD3F40694DE1}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{44A884F1-0334-4C21-8F53-7AA44105AAFA}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{95327BD8-7D2C-4FED-B825-ECF4287C2C98}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{FE5B654E-3172-4FD7-AA44-38A30335B714}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{1883E59C-77EB-4BE9-9103-7F4FDBB1A9A4}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{C05B81CA-3328-40C3-8867-9574187DADEF}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{EA3D174B-35AC-44CC-B2C6-8A2CD4911485}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20061025.029\IDSvix86.sys [2006-10-19 23:10]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-08-07 15:26]
R3 AvgWFP;AVG7 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfp.sys [2008-03-13 12:33]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2006-10-24 08:40]
S3 Symantec RemoteAssist;Symantec RemoteAssist;"C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe" [2008-01-29 17:09]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d92c04ee-ea43-11dc-b9a0-001a921036cf}]
\shell\AutoRun\command - L:\LaunchU3.exe -a
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-29 09:09:50 C:\Windows\Tasks\HPCeeScheduleForDave.job"
- C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe
"2008-03-22 23:49:31 C:\Windows\Tasks\User_Feed_Synchronization-{A6B763B9-6750-4DE9-80AF-E1887569F446}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-22 21:56:59
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Windows\System32\rundll32.exe
C:\hp\kbd\kbd.exe
.
**************************************************************************
.
Completion time: 2008-03-22 21:59:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-23 01:59:10
ComboFix2.txt 2008-03-23 01:11:13
.
2008-03-01 10:21:14 — E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:12:21 PM, on 3/6/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hp\kbd\kbd.exe
C:\Program Files\HP\HP Software Update\HPWUCli.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.geocities.com/dmdoug66/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [PCDrProfiler] C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe -r
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5DE0D0B-9018-435C-9C90-FE16B98ABBC2}: NameServer = 85.255.114.26,85.255.112.155
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
–
End of file - 8143 bytes