ComboFix 08-05-15.3 - mum 2008-05-17 10:33:07.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.50 [GMT 1:00]
Running from: C:\Documents and Settings\mum\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\mum\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\noskrnl.exe
C:\WINDOWS\system32\ascohgqr.dll
C:\WINDOWS\system32\awtsTKed.dll
C:\WINDOWS\system32\blackster.scr
C:\WINDOWS\system32\cdwhgtcs.ini
C:\WINDOWS\system32\fccaaYpm.dll
C:\WINDOWS\system32\ggabxiai.dll
C:\WINDOWS\system32\khffEVnl.dll
C:\WINDOWS\system32\kr_done1de
C:\WINDOWS\system32\qoMfgdAq.dll
C:\WINDOWS\system32\sctghwdc.dll
C:\WINDOWS\Tasks\AntiSpyware Scheduled Scan.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\ascohgqr.dll
C:\WINDOWS\system32\awtsTKed.dll
C:\WINDOWS\system32\blackster.scr
C:\WINDOWS\system32\cdwhgtcs.ini
C:\WINDOWS\system32\deKTstwa.ini
C:\WINDOWS\system32\deKTstwa.ini2
C:\WINDOWS\system32\fccaaYpm.dll
C:\WINDOWS\system32\jynkmgmu.ini
C:\WINDOWS\system32\khffEVnl.dll
C:\WINDOWS\system32\kr_done1de
C:\WINDOWS\system32\sctghwdc.dll
C:\WINDOWS\Tasks\AntiSpyware Scheduled Scan.job
.
((((((((((((((((((((((((( Files Created from 2008-04-17 to 2008-05-17 )))))))))))))))))))))))))))))))
.
2008-05-17 01:48 . 2008-05-17 01:48 91,776 --a------ C:\WINDOWS\system32\umgmknyj.dll
2008-05-17 01:21 . 2008-05-17 01:21 294 --ahs---- C:\WINDOWS\system32\iaixbagg.ini
2008-05-16 22:29 . 2008-05-16 23:43 <DIR> d-------- C:\SDFix
2008-05-16 22:02 . 2008-05-16 22:02 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-16 17:30 . 2008-05-16 17:30 <DIR> d-------- C:\Documents and Settings\mum\Application Data\Malwarebytes
2008-05-16 17:27 . 2008-05-16 17:28 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-16 17:27 . 2008-05-16 17:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-16 17:27 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-16 17:27 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-13 15:44 . 2008-05-16 15:56 <DIR> d-------- C:\Documents and Settings\mum\Application Data\TmpRecentIcons
2008-05-13 14:06 . 2008-05-13 14:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adsl Software Limited
2008-05-03 19:34 . 2008-03-01 14:06 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-05-03 19:34 . 2007-04-17 10:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-05-03 19:34 . 2007-03-08 06:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-05-03 19:34 . 2008-03-01 14:06 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-05-03 19:34 . 2008-03-01 14:06 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-05-03 19:34 . 2008-03-01 14:06 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-05-03 19:34 . 2008-03-01 14:06 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-05-03 19:34 . 2008-03-01 14:06 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-05-03 19:34 . 2008-02-22 11:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-16 14:48 --------- d-----w C:\Program Files\Trend Micro
2008-05-07 23:34 53,192 ----a-w C:\WINDOWS\system32\drivers\rp_skt32.sys
2008-04-09 13:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-28 17:19 41,984 ----a-w C:\WINDOWS\system32\sp.exe
2008-03-28 09:39 41,984 ----a-w C:\WINDOWS\superproxy.exe
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-17 16:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-17 16:18 --------- d-----w C:\Program Files\DS-3200 Wireless Optical Slimline Deskset
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2005-03-31 22:17 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-16_18.34.39.39 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-16 17:19:08 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-17 10:12:07 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-13 01:55:56 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-05-16 21:31:28 3,391,488 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-05-16 21:31:28 8,192 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-05-13 01:55:56 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-05-16 21:02:25 577,536 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-05-16 21:02:25 8,192 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-05-16 17:19:23 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-05-16 21:27:56 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-05-16 17:19:23 81,920 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-05-16 21:27:56 81,920 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-05-16 17:19:23 81,920 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-16 21:27:56 81,920 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 13:00 15360]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"IndexCleaner"="C:\Program Files\Virgin Broadband\PCguard\IdxClnR.exe" [2007-09-05 15:09 61168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 18:35 32768]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2005-06-10 15:20 1397760]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"SNPSTD2"="C:\WINDOWS\vsnpstd2.exe" [2004-01-05 19:34 40960]
"WireLessMouse"="C:\Program Files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe" [2005-08-30 15:35 303104]
"WireLessKeyboard"="C:\Program Files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe" [2005-08-30 11:51 319488]
"PCguard"="C:\Program Files\Virgin Broadband\PCguard\RPS.exe" [2007-09-05 15:10 310000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"IndexCleaner"="C:\Program Files\Virgin Broadband\PCguard\IdxClnR.exe" [2007-09-05 15:09 61168]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
C:\Documents and Settings\mum\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\-FreedomNeedsReboot]
--a------ 2007-09-05 15:10 13552 C:\Program Files\Virgin Broadband\PCguard\ZkRunOnceR.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadbandadvisor.exe]
--a------ 2007-08-07 19:49 2061552 C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dumprep]
C:\WINDOWS\system32\spoolc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\WINDOWS\system32\Macromed\Flash\FlashUtil9d.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCguard]
--a------ 2007-09-05 15:10 310000 C:\Program Files\Virgin Broadband\PCguard\Rps.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\system32\\sp.exe"=
"C:\\WINDOWS\\superproxy.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 AntiSpyFilter;AntiSpyFilter;C:\WINDOWS\system32\DRIVERS\antispyfilter.sys [2007-08-30 19:08]
S3 FXDRV;FXDRV;E:\Fxdrv.sys []
S3 INFUSB;INFUSB;C:\WINDOWS\system32\drivers\infusb.sys [2007-09-11 12:38]
S3 MBAMCatchMe;MBAMCatchMe;C:\WINDOWS\system32\drivers\mbamcatchme.sys [2008-05-05 20:46]
S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys [2001-08-17 14:47]
S3 Radialpoint Security Services;Virgin Broadband PCguard;C:\WINDOWS\system32\dllhost.exe [2006-02-28 13:00]
S3 snpstd2;USB PC Camera (SN9C103);C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-03-22 22:31]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-17 09:30:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-08 02:00:17 C:\WINDOWS\Tasks\MacroVirus Scheduled Scan.job"
- C:\Program Files\MacroVirus\MacroVirus.ex
- C:\Program Files\MacroVirus
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-17 11:13:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Virgin Broadband\PCguard\Fws.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\Virgin Broadband\PCguard\rpsupdaterr.exe
.
**************************************************************************
.
Completion time: 2008-05-17 11:20:23 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-17 10:20:12
ComboFix2.txt 2008-05-17 00:21:44
ComboFix3.txt 2008-05-16 17:41:20
Pre-Run: 34,141,802,496 bytes free
Post-Run: 34,141,261,824 bytes free
189 --- E O F --- 2008-05-04 22:58:30